Monitoring is an element within a Compliance Management System (CMS). Monitoring intends to identify weaknesses in a company’s compliance activities using a risk based approach. Monitoring is generally more frequent and less formal than an audit. It may be carried out by the business unit and does not require independence from the business or compliance function that an audit program normally does. Conversely, an audit is generally less frequent and more formal than monitoring. Audits are carried out by an institution’s internal audit department or outside contracted party and are generally independent of the business or compliance function where the controls exist; however, similar processes are used to make a risk-based monitoring or audit schedule.
A7 uses these resources as guidance for building a schedule:
- The OCC’s Compliance Management System Handbook – the most relevant section is labeled Monitoring
- The CFPB’s Examination Procedures for Compliance Management Review – the most relevant section is labeled Monitoring and/or Audit – Examination Objectives
- Industry-specific guidance from the regulator or risk management body
A Risk-Based Monitoring Schedule is a Foundational Element for Risk-Based Programs.
Whether we are talking about the Compliance Management System, BSA, or a specific risk-based approach to compliance elements like privacy or banking regulations, to name a few, a risk-based monitoring schedule allows effective coverage of compliance by prioritizing when the business will focus on each issue. While this process can be daunting, a starter schedule can be prepared in 30 minutes. To guide your schedule, look at the company’s risk assessments, policies, and exam and review feedback (Feedback).
A risk-based monitoring or audit schedule calls for a ranking system that is consistently employed, where the reviews prioritize high-risk areas but also schedule lower risks on a periodic basis. This approach results in a schedule that can be easily defended as risk-based.
Risk Assessments
The company’s risk assessments (Enterprise Risk, Compliance, BSA, ID Theft, UDAP, etc.) can all be used to help
- Identify regulations applicable to the company to understand what areas monitoring needs to cover
- Determine the inherent and residual risk the company is exposed to for prioritization
- Recognize the quality of controls in place to focus monitoring activities on the key controls
A7 reviews the risk profile from each risk assessment to determine the regulations the company is exposed to, frequency of monitoring, and the depth of the monitoring activity.
Policies
The company’s compliance policies should be used to
- Identify regulations the company is exposed to in order to understand what areas monitoring needs to cover
- Determine minimum requirements for monitoring frequency and depth
- Recognize the company’s or regulatory expectations of control to determine the breadth of monitoring activities
A7 reviews the policies to determine the regulations the company is exposed to, company and regulatory expectations of monitoring frequency, the depth of the monitoring activity, and control requirements.
Feedback
The Feedback the company receives should affect the schedule based on
- Findings, violations, and gaps identified
- Regulations the company is being reviewed against
- Effectiveness of the controls
A7 reviews Feedback to increase the priority of a monitoring or audit activity to be in line with the risk the exam or review feedback has identified.
Control Framework
Risk-based monitoring schedules are more consistent and easier to develop when the company identifies its desired control framework. The control framework allows the officer to identify when control activities meet the company’s expectation based on the inherent risk of the issue. Setting a control framework helps the company identify when enough control has been established, potentially reducing both the cost of compliance and customer friction. Finally, a control framework will allow you to tailor the depth of monitoring efforts to the company’s expectations, reducing scope creep.
Need a control framework or haven’t established a standard? Schedule a 30-minute review with A7, and we will provide a qualitative and quantitative description of your control framework standard.
Or, download ACCCE’s Control Framework: Control Maturity Framework – ACCCE. It is an easily adaptable example that is free for members and nonmembers.
Monitoring and Audit Activities Decrease Risk
A risk-based monitoring or audit schedule allows broader and deeper coverage of the company’s compliance by prioritizing when the business will focus on each compliance issue applicable to the company. The risk-based monitoring schedule reduces overhead costs and is a cost-effective approach when compared to relying solely on internal or external audit. When developing the company’s monitoring schedule use existing risk assessments, policies, and Feedback to prioritizes high-risk areas.
Adding a formal control framework to your schedule provides the context for prioritization and depth of monitoring and management responses and actions. Setting a control framework helps the company identify when enough control has been established, potentially reducing the cost of compliance and customer friction.
Not sure where to start with your risk-based monitoring or audit schedule? Schedule a free 30-minute call with A7 to attain and review a schedule tailored to your company.
