Chapter 051: The Financial Control Framework

Section 11: Reconciliation, Financial Control and Close · Chapter 051 of 100

This chapter explains the financial control framework from the reporting bank's perspective. Examples are fictional; accounting follows IFRS unless another framework is expressly identified.

1. Chapter opening

A financial control framework assigns responsibility for the number, the process that produces it and the review that supports approval. It covers statutory accounts, management reporting and regulatory returns, with different materiality and submission rules for each. A signed return is evidence of approval; it does not demonstrate that the underlying controls worked.

Define responsibilities using RACI (responsible, accountable, consulted and informed). For a material return, identify the preparer, reviewer, authorised signatory, data owners and deputy. Segregation of duties prevents someone approving their own work; smaller teams may need documented compensating controls rather than a universal three-team structure.

2. Learning objectives

  1. Draft a reporting RACI (prepare/review/attest per return and adjustment).
  2. Apply segregation rules (SoD matrix, privileged-posting controls).
  3. Design attestation packs (number, movement, breaks, evidence, challenge log).
  4. Grade control deficiencies with remediation tracking.
  5. Explain how the framework scales across solo/group returns.

3. Business context

Control design should follow the risk of misstatement: completeness of feeds, accuracy of mappings, cut-off, accounting estimates and management override. Automated calculations still need controlled inputs, approved rules and independent review. A supervisor may respond to deficient controls according to its powers and the facts; no fixed fine, capital add-on or review cost follows automatically.

RoleResponsibilityEvidence
PreparerReconciled calculation and exception identificationWorkpaper and input versions
ReviewerTest the calculation and challenge material judgementReview steps, conclusions and changes
SignatoryDecide whether the submission is supportableApproved final pack and unresolved-item assessment
Data ownerSource completeness and accuracyFeed totals and incident record

4. Finance and accounting view

4.1 RACI and segregation in practice

Specify what each review tests. A financial return needs ledger reconciliation, accounting-policy consistency and disclosure proof. A prudential return also needs exposure, capital and risk-rule testing. Data extraction can be automated or performed within finance; independent approval and access controls must address the actual risks. Maker-checker controls apply to manual journals, mappings and reporting adjustments. Emergency access needs expiry, an independent retrospective review and a record of all activity.

Temporary adjustments carry a rationale, calculation, owner and review date. Their expiry review prevents an unsupported adjustment becoming permanent. Reporting-only adjustments must remain distinguishable from accounting journals: changing a return cell does not correct the GL.

4.2 Attestation and deficiency grading

The pack contains the final return version, reconciliations, movement analysis, validation results, open exceptions, reviewer conclusions and approvals. Quantify the effect of each unresolved item. Escalate an unsupported material number and establish the applicable notification or resubmission process; a deadline does not justify a plug.

Under US PCAOB AS 2201, a material weakness involves a reasonable possibility of a material financial-statement misstatement not being prevented or detected timely. A significant deficiency is less severe but important enough for those overseeing financial reporting. Grade by likelihood, magnitude and compensating controls. Recurrence raises concern and triggers reassessment; it does not automatically change the formal classification. These US ICFR terms are not a universal regulatory-return grading scale.

4.3 Deep dive: challenge analytics and key-person risk quantification

Track coverage, review completion, exception ageing, recurrence and the quality of testing. Zero questions may reflect a well-supported pack; many questions may reflect poor preparation. Neither proves review quality. Avoid query quotas and arbitrary review-time floors, which reward performative questions. Sample whether the reviewer actually tested the important assertions.

Name deputies and test their ability to execute a cycle. Include automation maintainers, rule owners and privileged users in continuity planning. The required training and review cadence follows the bank's risk assessment.

5. Product and customer impact

Accurate reporting supports sound decisions about lending, pricing and distributions. Control failures can conceal customer-impacting errors, such as an incorrect interest accrual. Repairing a reporting classification alone does not establish that the customer balance or payment was correct; assess those separately.

6. Regulatory and supervisory view

Basel corporate governance principles describe Board oversight and effective control functions. They are international supervisory guidance, implemented through local regimes.

For US reporting issuers, SOX section 404 management assessment and auditor attestation requirements depend on issuer status and exemptions; they do not apply identically to every listed bank worldwide. PCAOB AS 2201 governs an applicable integrated audit. The UK Corporate Governance Code 2024 uses a comply-or-explain framework. Provision 29 applies for financial years beginning on or after 1 January 2026 and calls for a Board declaration concerning material controls; it does not itself impose a SOX-style external auditor attestation. Personal accountability depends on the relevant regime and individual conduct, not automatic liability for every error.

7. Systems and data view

Use a control register linked to systems, return versions and evidence. Access management should prevent self-approval and log emergency overrides. Preserve signed packs without overwriting; later corrections create a new version linked to the original. Set retention by applicable legal, supervisory and bank-policy requirements rather than a universal five-to-seven-year rule.

8. End to end process

  1. Scope the numbers and identify their assertions.
  2. Assign owners, reviewers, signatories and deputies.
  3. Run controls and quantify exceptions.
  4. Review material judgements and resolve or escalate defects.
  5. Approve the final version and retain evidence.
  6. Investigate deficiencies, remediate and re-test effectiveness.

9. Controls and risks

RiskControlEvidence
Self-approved adjustmentIndependent approval and access restrictionsUser and approval logs
Ineffective reviewRisk-based review procedures and quality samplingReperformed workpaper
Missing deputyTested cover for critical activitiesCompleted cover cycle
Repeat deficiencySeverity reassessment and root-cause repairRemediation and re-test
Pre-signed packSignature linked to final approved versionVersion and timestamp

10. Practical examples

Fictional example: 40 quarterly packs took an average 12 minutes to review. An independent sample found that the reviewer had not checked exposure mappings in three material returns. The issue is the omitted procedure, not the average time or number of queries. The bank revises the review checklist, provides capacity and re-tests the next cycle. If average review time rises to 45 minutes, the extra time for 40 packs is 40 × 33/60 = 22 reviewer-hours, excluding training or preparation.

11. Diagrams

Figure 1. Financial control cycle. Financial control cycle Figure 2. Financial control roles. Financial control roles Figure 3. Deficiency management. Deficiency management

12. Tables

ChangePreparerIndependent approvalFollow-up
Manual journalFinance analystApproved finance reviewerSubstantiation
Return mappingReporting specialistReporting policy ownerRegression checks
Emergency accessAccess administratorAuthorised managerExpiry and activity review
Temporary top-sideReporting preparerReviewer and signatory as requiredReversal or renewed evidence

13. Fictional banking case study

A fictional bank had complete signature coverage but weak reconciliation evidence. Reviewers relied on a dashboard that excluded aged breaks. Internal audit identified two incorrectly mapped balances. The bank assessed prior submissions, corrected affected returns through the applicable process and redesigned its review pack. No invented enforcement outcome is needed: the learning point is that signatures and green status cannot replace proof.

14. BA, developer, tester and operations guidance

Business analysts should specify assertions, responsibilities and exception gates. Developers should link approvals to immutable input and output versions. Testers should attempt self-approval, stale-pack approval and expired emergency access. Operations should maintain deputies and track remediation to tested closure.

15. Common mistakes

  1. Treating signature coverage as proof of effective review.
  2. Using query quotas as a quality metric.
  3. Applying US ICFR definitions universally.
  4. Allowing temporary adjustments or emergency access to persist.
  5. Closing findings without testing the repair.

16. Key takeaways

Controls need an owner, an executable procedure and retained evidence. Independent review must address material assertions. Deficiencies need proportionate assessment and tested remediation. Listing, issuer status and jurisdiction determine formal attestation obligations.

17. References and verification notes