Principles of Internal Audit for Local Banks Operating in the Kingdom of Saudi Arabia

Chapter 1: Introduction, Definitions, and General Provisions

1- Introduction

  • 1- 1 The Saudi Central Bank issued these principles based on the supervisory and regulatory powers entrusted to it under the following regulations:

    • أ. The Saudi Central Bank Law, issued by Royal Decree No. (M/36) dated 11/04/1442 AH.

    • ب. The Banking Control Law, issued by Royal Decree No. (M/5) dated 22/02/1386 AH.

  • 1- 2 These principles consist of three chapters in their content and context: Chapter One: clarifies the terms used and the general provisions, and Chapter Two: includes a reference to the competencies, roles, and responsibilities of both the Council, the Audit Committee, and the Executive Management regarding internal auditing - in accordance with what is stated in the relevant regulations and instructions - and the requirements for its activation in a concise manner, and Chapter Three: includes detailed, comprehensive, and extensive requirements regarding the activities, functions, roles, tasks, and responsibilities of the unit and its relationship as a third line of defense with the first and second lines of defense, as a tool for oversight and supervision for the bank's management and not a substitute for it. In a manner that meets and assists in complying with the provisions of the regulations, instructions, and best practices, and in a way that takes into account the special nature of banks and the method of application therein.

3- General Provisions

  • 3- 1 The general purpose of these principles is to establish the minimum requirements that enable the unit to perform its activities efficiently and optimally under a unified, broad, and robust framework as a tool to enhance self-control, to lay the foundations for internal auditing, and to improve the operations and activities of the bank. It should be noted that the methods by which these principles are implemented depend on various factors, such as: the size of the bank, the nature and complexity of its operations, its geographical scope, and the regulatory framework and instructions within which it operates.

  • 3- 2 The primary purpose of these principles is to achieve the following main objectives:

    • 1) Protect the bank's assets, continuously ensure the integrity, adequacy, and effectiveness of operations, and the accuracy and reliability of reports in general and financial reports in particular, which are prepared for various purposes and entities, instilling confidence in them, enhancing the data contained therein, and enabling the protection of stakeholders' interests.

    • 2) Enhance compliance with the requirements of regulatory and supervisory authorities, and the commitment of the bank and its employees to the laws, regulations, and instructions.

  • 3- 3 The unit represents the third and final line of defense within the three lines of defense framework, and is directly responsible to the Council and the Audit Committee on a permanent and continuous basis for evaluating and confirming the adequacy and effectiveness of governance, risk management, and control processes, as well as the policies and procedures implemented by the first and second lines of defense, increasing confidence in them, and contributing to their improvement through a systematic, organized, risk-based approach, which optimally utilizes resources by directing financial, administrative, and operational audit activities towards the most critical and significant activities for the bank, and executing them in an objective manner that considers the specified strategies and objectives. The importance of this line of defense is enhanced by its independence, which bolsters its objectivity and credibility, achieves proactive effectiveness, clarifies new insights, identifies future impacts, and promotes appropriate ethics and values, thereby providing the executive management with reasonable assurance that policies and procedures align with the specified expectations.

  • 3- 4 These principles do not undermine the requirements imposed on banks under the laws, regulations, and other relevant instructions.

  • 3- 5 The Central Bank has issued several instructions related to some of its internal audit requirements, and these principles should be read alongside them - as applicable - for example but not limited to the following:

    • 1) The main principles of governance in financial institutions subject to the oversight and supervision of the Central Bank.

    • 2) Principles of conduct and work ethics in financial institutions.

    • 3) Principles of compliance for banks and commercial banks operating in the Kingdom of Saudi Arabia.

    • 4) Anti-Money Laundering and Counter-Terrorism Financing Guide.

    • 5) Rules for bank accounts.

    • 6) Regulatory rules for the operation of self-supervisory units and committees.

    • 7) Principles for combating financial fraud in public banks and financial institutions in the Kingdom.

    • 8) Framework for Sharia governance for local public banks and financial institutions in the Kingdom.

    • 9) Policy for reporting internal violations in financial institutions.

    • 10) Instructions issued regarding risk management.

    • 11) Instructions for outsourcing tasks to third parties.

    • 12) Regulatory guide for information security.

    • 13) Regulatory guide for business continuity.

    • 14) Regulatory guide for IT governance.

  • 3- 6 The internal audit function receives international attention; several international bodies and organizations have issued guiding instructions for it, and reference should be made to and guided by them, including the following bodies and organizations:

    • 1) Basel Committee on Banking Supervision (BCBS).

    • 2) Institute of Internal Auditors (IIA).

    • 3) Committee of Sponsoring Organizations (COSO) of the National Commission for Fraudulent Financial Reporting (Treadway).

Chapter 2: Powers and Responsibilities of the Council and the Executive Management Regarding Internal Audit

Principle (1): The Council's Duties and Responsibilities Regarding Internal Audit

  • 5- To ensure that the General Assembly performs its functions towards the Audit Committee and the specified internal audit, in accordance with the provisions of the Companies Law and its executive regulations, the Corporate Governance Regulations issued by the Capital Market Authority, and the main principles of governance in financial institutions issued by the Central Bank; the Council must do the following:

    • 5- 1 Present effective proposals and recommendations that enable the General Assembly to perform its functions.

    • 5- 2 Monitor any developments that occur in the regulations, rules, and instructions related to internal audit from the relevant authorities from time to time.

  • 6- Although the Audit Committee operates independently from the Council and the executive management, this does not exempt the Council - in accordance with the main principles of governance in financial institutions - from the responsibility of effective oversight of the Audit Committee and following up on its work and duties assigned to it.

  • 7- The Council is responsible for the roles and responsibilities of the executive management towards the internal audit, including the following responsibilities:

    • 7- 1 The ultimate responsibility for ensuring that the executive management establishes and maintains an appropriate internal control framework that is efficient and effective, which identifies all risks faced by the bank, measures them, monitors them, and manages them.

    • 7- 2 Ensure the review of the effectiveness and efficiency of the internal control system based on the information provided by the Audit Unit, but not limited to it alone.

  • 8- Without prejudice to the powers, tasks, and responsibilities of the Council, in accordance with the relevant instructions of the Central Bank and other regulatory authorities; it is responsible towards the Audit Unit for continuously ensuring the following:

    • 8- 1 Taking all necessary measures to ensure the existence and continuity of a permanent, independent, and effective internal audit unit in the bank, and periodically updating its organization and work policy.

    • 8- 2 Ensuring that the size of the unit and the qualifications and competencies of its head and employees are commensurate with the size of the bank, the nature of its business, the automated systems in use, and the level of complexity of its organizational structure.

    • 8- 3 Ensuring that the Audit Committee conducts an independent external evaluation of the quality of the unit's performance at least once every five years.

Principle (2): Duties and Responsibilities of the Audit Committee towards the Unit

  • 9- Without prejudice to the competencies, tasks, and responsibilities of the Audit Committee as defined by the relevant regulations and instructions issued by the Central Bank and other regulatory authorities; it is responsible for the following requirements for effective supervision:

    • 9- 1 Recommending to the Board the approval of the organizational structure of the unit, and reviewing it periodically whenever necessary.

    • 9- 2 Recommending to the Board the appointment, reappointment, or dismissal of the head of the unit or accepting their resignation.

    • 9- 3 Ensuring the presence of appropriate human resources in the unit in terms of quantity, qualifications, and skills, especially in specialized topics, including, for example, units such as: financial treasury, international financial reporting standards, anti-money laundering and counter-terrorism financing, technology/cybersecurity risks, governance, Basel standards, liquidity, credit, and provisioning, among others.

    • 9- 4 Studying and approving the audit plan prepared by the head of the unit based on the results of the annual risk assessment, including the scope of the plan and the budget allocated for it.

    • 9- 5 Approving the strategy of the unit prepared by its head and monitoring its performance alongside the performance of the annual audit plan, in accordance with the strategy and overall objectives of the bank, after coordinating with the relevant authority in the bank.

    • 9- 6 Studying and discussing internal audit reports.

    • 9- 7 Reviewing the performance of the unit to ensure its ability to fulfill its responsibilities independently and objectively.

    • 9- 8 Approving performance measurement indicators for the head of the unit and evaluating their performance.

    • 9- 9 Ensuring that the head of the unit possesses integrity and the ability to perform their duties honestly, diligently, and responsibly, and ensuring compliance with regulations and instructions, and that they have not previously been involved in any violations.

    • 9- 10 Ensuring that the executive management takes the necessary corrective actions in a timely and appropriate manner to address weaknesses in controls, compliance issues with policies, regulations, and instructions, and other violations and observations, as well as deficiencies identified by the audit unit and reported on and recommended.

    • 9- 11 Conducting the required independent external evaluation - in accordance with the approved audit policy - to verify the quality of the unit's work at least once every five years.

Principle (3): The Duties and Responsibilities of the Executive Management Regarding Internal Audit

  • 10- The executive administration is responsible for the following:

    • 10- 1 Establishing and implementing an appropriate and effective system and procedures for internal control and maintaining them.

    • 10- 2 Fully and unconditionally enabling the unit to access all records, reach individuals, systems, and buildings, and provide them with the necessary information, data, and clarifications to perform their tasks in a timely and appropriate manner.

    • 10- 3 Informing the unit of any updates, initiatives, projects, products, new operational changes, or any amendments to policies and procedures in the bank's units.

    • 10- 4 Ensuring the identification of all related risks (known or anticipated) and reporting them to the unit at an early stage.

    • 10- 5 Sharing its assessment of various risks with the unit to enable it to plan the review based on a risk-based approach.

    • 10- 6 Taking corrective measures and actions in a timely and appropriate manner regarding all findings and recommendations received from the unit.

    • 10- 7 Encouraging the invitation of representatives from the unit to attend meetings of various administrative committees as permanent invitees, without granting them the right to vote on its decisions.

    • 10- 8 Including key performance indicators for the executive administration that reflect its effectiveness in addressing the observations monitored by the unit in a timely and appropriate manner.

Chapter 3: Powers, Duties, and Responsibilities of the Unit

Next section title

Next section content