Skip to main content

Risk Assessment Methodology

No: 43037826 Date(g): 1/12/2021 | Date(h): 26/4/1443 Status: In-Force

Effective from 2021-12-01 - Nov 30 2021
To view other versions open the versions tab on the right

45-The risk assessment methodology should include the following:
  1-45Documented and detailed guidelines that outline and assist internal auditors in classifying risks when preparing each observation.
  2-45Documented and detailed guidelines for assessing risks in the overall audit report.
  3-45Identification of quantitative and qualitative factors necessary to facilitate understanding and consistent application by audit staff.
  4-45Classification of internal violation reports from the bank—of which the audit unit should receive copies—based on their risk level and the extent of compliance with reaching the competent authority in the bank and their documentation.
  5-45All instances of non-compliance with central bank instructions should be classified as high risk unless the non-classification is supported by specific justifications approved by the compliance unit. These justifications should be based on a risk classification mechanism that includes the size and impact of the non-compliance.