11.10.2013 Views

Risk Management Manual of Examination Policies - FDIC

Risk Management Manual of Examination Policies - FDIC

Risk Management Manual of Examination Policies - FDIC

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

INTERNAL ROUTINE AND CONTROLS Section 4.2<br />

following recordkeeping deficiencies are some <strong>of</strong> the more<br />

prevalent encountered during examinations:<br />

• General ledger entries fail to contain an adequate<br />

transaction description,<br />

• Customer loan records are incorrect, inadequate, or<br />

nonexistent,<br />

• Permanent and satisfactory records pertaining to cash<br />

items, overdrafts, and other types <strong>of</strong> suspense or<br />

holding items are lacking,<br />

• Tellers' cash records do not contain adequate details,<br />

• Securities registers, whether processed electronically<br />

or manually, fail to list all necessary information,<br />

• Reconcilement records <strong>of</strong> correspondent bank<br />

accounts are not kept current and/or fail to reflect the<br />

description and disposition <strong>of</strong> outstanding items,<br />

• Details concerning debits and credits to the over and<br />

short accounts are inadequate,<br />

• Accounts and records are not posted on a current<br />

basis,<br />

• Control and subsidiary records <strong>of</strong> outstanding letters<br />

<strong>of</strong> credit or other contingent liabilities are inadequate,<br />

and<br />

• Interbranch or inter<strong>of</strong>fice accounts are not properly<br />

controlled and monitored.<br />

Prenumbered Documents<br />

Sequentially numbered instruments should be used<br />

wherever possible. Prenumbered documents aid in<br />

proving, reconciling, and controlling used and unused<br />

items. Number controls, including printer's confirmation,<br />

should be monitored by a person who is detached from that<br />

particular operation. Unissued, prenumbered instruments<br />

that could be used to obtain funds should be maintained<br />

under dual control or joint custody.<br />

Accounting <strong>Manual</strong><br />

The uniform handling <strong>of</strong> like transactions is essential to the<br />

production <strong>of</strong> reliable reports. Accordingly, it is essential<br />

that instructions be established for processing routine<br />

transactions. In smaller banks where some or all records<br />

are manually produced, it may be advisable to reduce<br />

instructions to writing, possibly in the form <strong>of</strong> an<br />

accounting manual.<br />

In banks where some or all records are computer<br />

generated, there should be an understandable user's guide<br />

for each application readily available for reference by user<br />

departments and personnel. <strong>Manual</strong>s for each application<br />

normally consist <strong>of</strong> a guide provided by the servicer and<br />

supplemented by procedures written by the user. <strong>Manual</strong>s<br />

normally delineate preparation and control source<br />

documents and certain practices pertaining to control over<br />

the movement <strong>of</strong> documents from the user to the servicer<br />

and their return, the daily reconcilement <strong>of</strong> subsystem<br />

totals to the general ledger, and changes to master files.<br />

Protection <strong>of</strong> Physical Assets<br />

A principal method <strong>of</strong> safeguarding assets is to limit access<br />

by authorized personnel. Protection <strong>of</strong> assets can be<br />

accomplished by various procedures, including those listed<br />

below.<br />

Cash Control<br />

Tellers should be provided with their own funds to which<br />

they have sole access. Common cash funds should not be<br />

utilized. Inability to fix responsibility in the event <strong>of</strong> a<br />

difference could be embarrassing and is unfair to all<br />

concerned.<br />

Joint Custody or Dual Control<br />

These two terms are not synonymous, but are <strong>of</strong>ten<br />

discussed in tandem. Joint custody refers to a procedure<br />

whereby two or more persons are equally accountable for<br />

the physical protection <strong>of</strong> certain items or records. An<br />

example consists <strong>of</strong> two keys or combinations, under the<br />

separate control <strong>of</strong> two individuals, which must be used in<br />

order to obtain access to vaults, files or other storage<br />

devices. These custodial responsibilities should be clearly<br />

assigned and communicated to all employees. For this<br />

system to be effective, persons exercising control must<br />

guard their key or combination carefully. If this is done,<br />

only collusion can bypass the important control feature.<br />

Reserve cash, negotiable collateral, investment securities,<br />

trust assets, safekeeping items, reserve supply <strong>of</strong> <strong>of</strong>ficial<br />

checks, unissued electronic debit or credit cards, unissued<br />

traveler's checks, unissued Series E Bonds, the night<br />

depository, electronic banking terminals, dormant deposit<br />

accounts, safe deposit spare locks and keys, and spare keys<br />

to tellers' cash boxes are examples <strong>of</strong> items that should be<br />

under effective joint custody.<br />

Dual control is a related, but slightly different concept in<br />

which the work <strong>of</strong> one person is verified or approved by<br />

another. The purposes <strong>of</strong> involving the second individual<br />

are to ensure that proper authority for the transaction or<br />

activity is given, that the transaction or activity is properly<br />

recorded, and that proper settlement is made. Dual control<br />

in automated systems should be used in the same manner as<br />

in manual systems. Supervisory holds should be placed on<br />

customer accounts requiring special attention. For<br />

example, dormant accounts, collateral accounts, and<br />

accounts with large uncollected funds normally have holds<br />

DSC <strong>Risk</strong> <strong>Management</strong> <strong>Manual</strong> <strong>of</strong> <strong>Examination</strong> <strong>Policies</strong> 4.2-3 Internal Routine and Controls (12-04)<br />

Federal Deposit Insurance Corporation

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!