When testing the operational effectiveness of an institution's customer risk rating model an auditor finds that the risk rating is not in accordance with the model specification in some cases.After interviewing developers andofficers,the auditor learns the specification document is inaccurate and has not been updated in a timely manner.Which are appropriate corrective action plans'? (Select Two.)
An audit manager identifies that a financial institution (Fl) has not produced a business-level risk assessment in accordance with policy. The senior manager of the Fl assures that assessing risk at the individual client level and aggregating the data is an acceptable approach. How should the audit manager proceed?
During a sample review, the auditor notices that an alert was generated for a large deposit that was inconsistent with the customer profile. The customer has had no other incidents in the past 10 years and has provided documents to confirm the deposit as a property sale. What should the auditor do?
An organization creates a document for its audit committee listing the outstanding audit findings. The list has an executive management owner assigned to each finding, due dates for reporting management's responses and space for management to identity the actions to be taken. Which is a primary purpose of this document?
When sample testing client transaction records, the auditor finds that a client offered to sell a piece of art on a commission basis. A sale was completed and the purchase price was remitted to the client with less commission. What further investigation should the auditor undertake?
When conducting an audit of a money services business (MSB), the frequency of the review depends on the country's regulatory practices and the MSB's.
What model test verifies that alerts indicative of potentially suspicious activity are not missed due to threshold settings?
When assessing the KYC process which should an auditor observe from the customer risk assessment? (Select Two)
A financial institution utilizes an automated daily validation report to validate the accuracy of the data flowing into its monitoring software. An auditor is responsible for testing the data used to create the report. This is an example of testing which type of effectiveness?
When reviewing an entity's sanctions compliance program, the auditor should ensure who is exempt from the Office of Foreign Assets Control's regulations?
Independent testing of the New York branch of a foreign bank is conducted by an outsourced audit firm. The independent testing report should be submitted to which authority in order to provide appropriate level of governance and oversight?
Suspicious activity report testing in the last three audits did not identify any metrics to indicate that volume vanes dramatically each month. Which step should the auditor take next?
Which statements demonstrate an effective use of risk appetite in an organization? (Select Two.)
Which is considered a minimum requirement in a customer identification program?
Which are the most important documents for an auditor to verify that a financial institution has proper controls in place for mitigating its money laundering risk exposure? (Select Two.)
in addition to this investigation report, what Information should the auditor expect to find in the investigative file? (Select Two.)
Which is the most significant risk associated with KYC requirements being considered a low priority not designed into processes and subsequently implemented after the products are already launched?
Which are objectives of the issue confirmation step in the audit issue management process? (Select Two.)
The scoping and planning process of an AML audit of a bank is best guided by review of which document?
A financial institution is auditing its correspondent banking relationships and their respective sanctions compliance programs. Which condition will merit a higher sample size assuming the correspondent banks have a moderate level of risk mitigation?
Which should the auditor recommend to management in terms of the client's risk rating procedures?