Chapter 051: The Financial Control Framework
Section 11: Reconciliation, Financial Control and Close · Chapter 051 of 100
This chapter explains the financial control framework from the reporting bank's perspective. Examples are fictional; accounting follows IFRS unless another framework is expressly identified.
1. Chapter opening
A financial control framework assigns responsibility for the number, the process that produces it and the review that supports approval. It covers statutory accounts, management reporting and regulatory returns, with different materiality and submission rules for each. A signed return is evidence of approval; it does not demonstrate that the underlying controls worked.
Define responsibilities using RACI (responsible, accountable, consulted and informed). For a material return, identify the preparer, reviewer, authorised signatory, data owners and deputy. Segregation of duties prevents someone approving their own work; smaller teams may need documented compensating controls rather than a universal three-team structure.
2. Learning objectives
- Draft a reporting RACI (prepare/review/attest per return and adjustment).
- Apply segregation rules (SoD matrix, privileged-posting controls).
- Design attestation packs (number, movement, breaks, evidence, challenge log).
- Grade control deficiencies with remediation tracking.
- Explain how the framework scales across solo/group returns.
3. Business context
Control design should follow the risk of misstatement: completeness of feeds, accuracy of mappings, cut-off, accounting estimates and management override. Automated calculations still need controlled inputs, approved rules and independent review. A supervisor may respond to deficient controls according to its powers and the facts; no fixed fine, capital add-on or review cost follows automatically.
| Role | Responsibility | Evidence |
|---|---|---|
| Preparer | Reconciled calculation and exception identification | Workpaper and input versions |
| Reviewer | Test the calculation and challenge material judgement | Review steps, conclusions and changes |
| Signatory | Decide whether the submission is supportable | Approved final pack and unresolved-item assessment |
| Data owner | Source completeness and accuracy | Feed totals and incident record |
4. Finance and accounting view
4.1 RACI and segregation in practice
Specify what each review tests. A financial return needs ledger reconciliation, accounting-policy consistency and disclosure proof. A prudential return also needs exposure, capital and risk-rule testing. Data extraction can be automated or performed within finance; independent approval and access controls must address the actual risks. Maker-checker controls apply to manual journals, mappings and reporting adjustments. Emergency access needs expiry, an independent retrospective review and a record of all activity.
Temporary adjustments carry a rationale, calculation, owner and review date. Their expiry review prevents an unsupported adjustment becoming permanent. Reporting-only adjustments must remain distinguishable from accounting journals: changing a return cell does not correct the GL.
4.2 Attestation and deficiency grading
The pack contains the final return version, reconciliations, movement analysis, validation results, open exceptions, reviewer conclusions and approvals. Quantify the effect of each unresolved item. Escalate an unsupported material number and establish the applicable notification or resubmission process; a deadline does not justify a plug.
Under US PCAOB AS 2201, a material weakness involves a reasonable possibility of a material financial-statement misstatement not being prevented or detected timely. A significant deficiency is less severe but important enough for those overseeing financial reporting. Grade by likelihood, magnitude and compensating controls. Recurrence raises concern and triggers reassessment; it does not automatically change the formal classification. These US ICFR terms are not a universal regulatory-return grading scale.
4.3 Deep dive: challenge analytics and key-person risk quantification
Track coverage, review completion, exception ageing, recurrence and the quality of testing. Zero questions may reflect a well-supported pack; many questions may reflect poor preparation. Neither proves review quality. Avoid query quotas and arbitrary review-time floors, which reward performative questions. Sample whether the reviewer actually tested the important assertions.
Name deputies and test their ability to execute a cycle. Include automation maintainers, rule owners and privileged users in continuity planning. The required training and review cadence follows the bank's risk assessment.
5. Product and customer impact
Accurate reporting supports sound decisions about lending, pricing and distributions. Control failures can conceal customer-impacting errors, such as an incorrect interest accrual. Repairing a reporting classification alone does not establish that the customer balance or payment was correct; assess those separately.
6. Regulatory and supervisory view
Basel corporate governance principles describe Board oversight and effective control functions. They are international supervisory guidance, implemented through local regimes.
For US reporting issuers, SOX section 404 management assessment and auditor attestation requirements depend on issuer status and exemptions; they do not apply identically to every listed bank worldwide. PCAOB AS 2201 governs an applicable integrated audit. The UK Corporate Governance Code 2024 uses a comply-or-explain framework. Provision 29 applies for financial years beginning on or after 1 January 2026 and calls for a Board declaration concerning material controls; it does not itself impose a SOX-style external auditor attestation. Personal accountability depends on the relevant regime and individual conduct, not automatic liability for every error.
7. Systems and data view
Use a control register linked to systems, return versions and evidence. Access management should prevent self-approval and log emergency overrides. Preserve signed packs without overwriting; later corrections create a new version linked to the original. Set retention by applicable legal, supervisory and bank-policy requirements rather than a universal five-to-seven-year rule.
8. End to end process
- Scope the numbers and identify their assertions.
- Assign owners, reviewers, signatories and deputies.
- Run controls and quantify exceptions.
- Review material judgements and resolve or escalate defects.
- Approve the final version and retain evidence.
- Investigate deficiencies, remediate and re-test effectiveness.
9. Controls and risks
| Risk | Control | Evidence |
|---|---|---|
| Self-approved adjustment | Independent approval and access restrictions | User and approval logs |
| Ineffective review | Risk-based review procedures and quality sampling | Reperformed workpaper |
| Missing deputy | Tested cover for critical activities | Completed cover cycle |
| Repeat deficiency | Severity reassessment and root-cause repair | Remediation and re-test |
| Pre-signed pack | Signature linked to final approved version | Version and timestamp |
10. Practical examples
Fictional example: 40 quarterly packs took an average 12 minutes to review. An independent sample found that the reviewer had not checked exposure mappings in three material returns. The issue is the omitted procedure, not the average time or number of queries. The bank revises the review checklist, provides capacity and re-tests the next cycle. If average review time rises to 45 minutes, the extra time for 40 packs is 40 × 33/60 = 22 reviewer-hours, excluding training or preparation.
11. Diagrams
Figure 1. Financial control cycle.
Figure 2. Financial control roles.
Figure 3. Deficiency management.
12. Tables
| Change | Preparer | Independent approval | Follow-up |
|---|---|---|---|
| Manual journal | Finance analyst | Approved finance reviewer | Substantiation |
| Return mapping | Reporting specialist | Reporting policy owner | Regression checks |
| Emergency access | Access administrator | Authorised manager | Expiry and activity review |
| Temporary top-side | Reporting preparer | Reviewer and signatory as required | Reversal or renewed evidence |
13. Fictional banking case study
A fictional bank had complete signature coverage but weak reconciliation evidence. Reviewers relied on a dashboard that excluded aged breaks. Internal audit identified two incorrectly mapped balances. The bank assessed prior submissions, corrected affected returns through the applicable process and redesigned its review pack. No invented enforcement outcome is needed: the learning point is that signatures and green status cannot replace proof.
14. BA, developer, tester and operations guidance
Business analysts should specify assertions, responsibilities and exception gates. Developers should link approvals to immutable input and output versions. Testers should attempt self-approval, stale-pack approval and expired emergency access. Operations should maintain deputies and track remediation to tested closure.
15. Common mistakes
- Treating signature coverage as proof of effective review.
- Using query quotas as a quality metric.
- Applying US ICFR definitions universally.
- Allowing temporary adjustments or emergency access to persist.
- Closing findings without testing the repair.
16. Key takeaways
Controls need an owner, an executable procedure and retained evidence. Independent review must address material assertions. Deficiencies need proportionate assessment and tested remediation. Listing, issuer status and jurisdiction determine formal attestation obligations.
17. References and verification notes
- Basel corporate governance principles: oversight and internal controls.
- PCAOB AS 2201: applicable US ICFR audit and deficiency definitions; amendments effective 15 December 2026 are not assumed effective at 3 October 2026.
- FRC UK Corporate Governance Code 2024: Code scope and Provision 29 timing.
- Examples and operating designs are fictional; local legal duties and submission rules remain controlling.