Chapter 005: Who Owns the Numbers?
Section 1: How a Bank Works Financially · Chapter 005 of 100
A reporting failure often exposes a practical ownership gap: nobody can explain who approved the number or its supporting controls. Ownership is not a slogan — it is a designed operating model: named owners, documented handoffs, evidenced controls, and committees that actually challenge. This chapter maps the finance function of a modern bank end to end: its towers, its partners, its committees, and the RACI that makes month-end, regulatory submission and audit possible.
1. Chapter opening
Chapters 001–004 covered what the numbers are. This chapter covers who stands behind them. You will learn the four towers of Finance (financial control, FP&A/business partnering/FTP, regulatory reporting, tax and specialists), the shared backbone (data, systems, controls, change), the three lines of defence as applied to finance, the committee ladder from working group to Board, and the close RACI that assigns every task. Section 1 closes with this chapter because every later block assumes you know which team to call.
2. Learning objectives
By the end of this chapter you will be able to:
- Name the four Finance towers and state each tower's core deliverables.
- Place Finance alongside Treasury, Risk, Operations, Technology, business lines, Audit and supervisors on one map.
- Apply the three-lines-of-defence model to a finance process (for example, ECL provisioning).
- Read and construct a close RACI, distinguishing Responsible, Accountable, Consulted and Informed.
- Describe the committee ladder (ALCO, capital, disclosure, audit committee, Board) and what each signs off.
- Identify operating-model failure patterns: orphan numbers, dual truths, attestation theatre.
3. Business context
Operating models fail quietly and expensively. A bank with brilliant quants still restates earnings if nobody owns the reconciliation between the risk engine and the GL. A bank with strict policies still misses submissions if Regulatory Reporting depends on a spreadsheet only one person understands. Supervisors now assess operating-model effectiveness directly (SREP operational risk, BCBS 239, skilled-person reviews): key-person dependencies, spreadsheet sprawl, unclear attestations and overdue audit findings are graded findings, not housekeeping. For transformation programmes, the operating model decides whether a new system lands in governed hands or amplifies existing chaos.
| Symptom | Root cause | Where it surfaces |
|---|---|---|
| Two teams report different revenue for one product | No single definition owner; dual marts | Management pack vs FINREP break |
| Month-end takes 12 working days | Manual journals, sequential reconciliations, no flash process | Late, low-quality decisions |
| Audit finding repeats three years running | Owner without authority or budget to fix | Supervisory escalation, capital add-on |
| Submission error discovered by the regulator | Reporting QA skipped under time pressure | Correction, resubmission, reputation damage |
| Nobody can explain an allocation | Driver methodology undocumented | Product mispricing, challenge failure |
4. Finance and accounting view
4.1 The four towers
| Tower | Owns | Produces | Partners most with |
|---|---|---|---|
| Financial Control | GL integrity, close, journals, reconciliations, substantiation | Trial balance, statutory accounts, audit evidence | Operations, Technology, external audit |
| FP&A, Business Partnering, FTP | Plans, forecasts, product/customer profitability, FTP methodology | Budgets, flash results, business reviews | Business lines, Treasury (FTP), Risk (capital allocation) |
| Regulatory Reporting | Prudential/financial/statistical returns, disclosures, XBRL | FINREP, COREP, Pillar 3, local returns | Risk, Treasury, Data, supervisors |
| Tax and specialists | Current/deferred tax, Treasury finance, accounting policy, change | Tax returns, hedge files, policy manuals, programme delivery | All towers, advisors, auditors |
Centralised models (single global finance utility) gain consistency but lose business intimacy; federated models (finance teams inside each business) gain insight but breed dual truths. Most large banks run a hybrid: central policy, systems and reporting with embedded business partners — and a permanent tension between the two that governance must manage.
4.2 Attestation: ownership made personal
Attestation is the mechanism by which ownership becomes enforceable: named individuals sign that balances are understood, reconciled and supported — at a frequency set by risk and the bank's control policy; submission sign-off authority depends on the relevant form and jurisdiction. Effective attestation packs contain the number, its movement explanation, open breaks with owners and dates, and linked evidence. "Attestation theatre" — signing template packs nobody read — is a favourite audit finding; supervisors increasingly ask to see challenge evidence (queries raised, items sent back), not just signatures.
4.3 Committees that own outcomes
| Committee | Chair (typical) | Decides / recommends | Cadence |
|---|---|---|---|
| ALCO | CFO or Treasurer | Funding plan, liquidity limits, FTP, balance-sheet shape | Monthly |
| Capital/Stress committee | CRO/CFO | ICAAP, stress results, buffers, distributions | Quarterly |
| Disclosure committee | CFO | What is published, wording of judgements | Per reporting date |
| Audit committee (Board) | Independent director | Audit findings, accounting judgements, whistleblowing | Quarterly |
| Board | Chair | Strategy, risk appetite, accounts approval, dividends | Monthly/quarterly |
| Model risk committee | CRO | ECL, valuation and capital model approval | As needed |
Decisions without a minuted owner and date are not decisions — test this sentence against any committee pack you inherit.
5. Product and customer impact
Customers feel the operating model through consistency and speed: a well-owned product P&L produces stable, explainable pricing; orphan cost allocations produce sudden fee hikes when true costs surface. Complaint handling, redress provisioning and fee transparency all depend on Finance towers cooperating with Operations — mis-sold-product episodes are invariably also operating-model episodes (unclear ownership of product profitability vs sales incentives). For new launches, the product-approval process should require Finance sign-off on recognition, dimensions, FTP treatment and reporting impact before go-live (Section 20 test cases).
6. Regulatory and supervisory view
Supervisors engage the operating model directly: the CFO and heads of control face fit-and-proper expectations; skilled-person (Section 166-style, jurisdiction-dependent) reviews examine reporting controls; SREP grades internal governance; BCBS 239 assesses risk-data aggregation; disclosure rules require named responsibility statements. Enforcement history shows personal accountability regimes (for example the UK Senior Managers Regime) reaching individual executives for control failures — ownership has legal weight, and attestations are discoverable. Regulatory reporting teams must maintain submission calendars, four-eyes checks, query logs and resubmission procedures as examinable artefacts (The Regulatory Reporting Landscape and Submission Governance).
7. Systems and data view
The backbone under the towers: product processors and subledgers (Section 7 of The Bank’s Business Model), the accounting hub and GL, the finance data warehouse and reporting marts, GRC workflow (attestations, findings tracking), and the change pipeline (requirements → build → UAT → parallel run → go-live). Ownership extends to data: each critical data element needs a named owner, a definition, quality rules and lineage documentation (Section 20). The two structural risks are key-person spreadsheets (migrate to governed marts with access control and versioning) and interface ownership gaps (every feed needs a producer owner and a consumer owner with an SLA — breaks in between belong to both until fixed).
8. End to end process
Quarter-end close as the operating model in motion: Day 1–2: subledger freeze, flash P&L, early breaks triaged. Day 3–5: accruals, ECL run, valuations, FTP and allocations posted; reconciliations executed with aged-break escalation. Week 2: management results with variance commentary, business-line attestations collected, disclosure committee reviews judgements. Week 3: audit committee challenge, Board approval, publication; regulatory returns compiled from the locked close with independent QA and four-eyes submission. Week 4 (after): post-mortem — breaks aged, journals analysed, findings logged, automation backlog reprioritised. Mature banks compress this to days; the sequence, not the speed, is the control.
9. Controls and risks
| Risk | Control | Evidence |
|---|---|---|
| Orphan numbers (no owner) | Ownership register per report/account; RACI per process | Signed register, RACI packs |
| Attestation without challenge | Mandatory variance thresholds, return-to-sender logs | Query logs, rework records |
| Key-person dependency | Cross-training, governed marts replacing spreadsheets | Dependency matrix, migration plan |
| Findings that never close | Tracked actions with dates, owner consequences, audit committee oversight | Findings dashboard, closure evidence |
| Change landing without ownership | RACI in every change ticket; hypercare ownership | Signed go-live readiness, hypercare logs |
10. Practical examples
Example A — The 40-million break nobody owned. Risk's loan total and Finance's loan total differ by 40. Each team assumes the other's number is wrong; month-end passes with an unexplained plug. Root cause found weeks later: restructured loans feed the risk engine but bypass the GL interface. Fix: named interface owners both sides, daily automated tie-out, break auto-escalation after two days. Lesson: interfaces need joint ownership by design.
Example B — Good RACI, bad behaviour. A bank documents a perfect close RACI. In practice the Accountable CFO is on leave, the deputy never formally delegated, and attestations stall. Lesson: RACI needs delegation rules and deputies named in advance — test the holiday scenario, not just the happy path.
11. Diagrams
Figure 1. Who owns and challenges controls?
Figure 2. Finance responsibilities and hand-offs.
Figure 3. A close responsibility example.
12. Tables
Table 1 — Who to call: finance responsibility map
| Question | First call | Second call |
|---|---|---|
| Why doesn't this reconcile? | Financial Control / Operations (interface owners) | Technology (feed health) |
| Is this product really profitable? | Business Finance partner (FP&A) | FTP desk, Risk (capital/ECL) |
| What goes in this regulatory cell? | Regulatory Reporting (taxonomy owner) | Data office (lineage), Risk (method) |
| Can we recognise this income now? | Accounting Policy | External audit (judgement call) |
| Who signs this off? | Close/submission RACI | CFO office, committee secretary |
| Why did the auditor flag this? | Control owner named in finding | Internal Audit (scope/evidence) |
Table 2 — Operating-model maturity self-check
| Level | Close | Reconciliations | Attestation | Change |
|---|---|---|---|---|
| 1. Heroic | Weeks, manual, key-person | Spreadsheets, plugs | Signatures without reading | Lands unowned |
| 2. Managed | Calendar exists, mostly met | Standard templates, aged breaks | Queries happen sometimes | RACI drafted late |
| 3. Controlled | Flash + locked close | Automated matching, joint interface owners | Challenge evidenced | Ownership before go-live |
| 4. Trusted | Days, analytics-led review | Breaks prevented upstream | Board-grade challenge packs | Hypercare to steady state |
13. Illustrative bank case study
The restatement that was really an ownership failure. A bank restated two years of results after discovering fee income recognised on the wrong trigger across several products. Every control existed on paper: a policy, a checklist, an attestation. Investigation found the policy owner had moved roles with no successor named, attestations were signed from summary packs, and Internal Audit had flagged the gap a year earlier with the finding still open. The numbers were fixed in a quarter; the operating model took two years (new owners, governed engines, evidenced challenge). Lesson: controls without owners are decorations. (Fictional training case; no specific bank or event is asserted.)
14. BA, developer, tester and operations guidance
- BA: Start every finance change with the as-is RACI and ownership register; name the owner of each new report, feed and control in the requirements — unnamed deliverables become orphans at go-live.
- Developer: Build attestation, four-eyes approval and evidence attachment into workflows, not email; log who approved what, when, on which data version.
- Tester: Test delegation (approver absent), segregation (maker cannot check own work), and evidence completeness (submission without attachment is rejected) — the negative paths auditors probe.
- Operations: Publish the daily ownership dashboard: unreconciled breaks by owner and age, journals awaiting checker, attestations outstanding. Visibility creates ownership faster than memos.
15. Common mistakes
- Confusing doing the work (Responsible) with answering for it (Accountable) — one clearly identified accountable owner per task.
- Listing the Board as Accountable for operational tasks it cannot perform.
- Attesting from summaries without inspecting breaks and evidence.
- Leaving interface ownership split ("producer says sent, consumer says not received") with no joint tie-out.
- Treating audit findings as audit's problem — findings belong to the control owner, audit only tracks.
16. Key takeaways
- Four towers (control, FP&A/FTP, regulatory reporting, tax/specialists) share one backbone and serve the same ledger.
- Finance teams that prepare accounts and operate controls are management first-line roles; designated oversight functions may perform second-line challenge; Internal Audit independently assures.
- Attestation without evidenced challenge is theatre; supervisors now test for the challenge.
- RACI plus delegation rules plus committee minutes = ownership you can prove.
- Connect business economics, financial statements, profit, liquidity/capital constraints and accountable ownership before approving a finance process.
17. References and verification notes
-
IIA: Three Lines Model: first- and second-line roles sit within management; Internal Audit provides independent third-line assurance. A Finance department is not automatically second line.
-
Three-lines model per IIA guidance as adapted by major bank governance frameworks; personal-accountability regimes (for example UK SMR), skilled-person review powers and SREP governance grading are jurisdiction-specific — verify local applicability.
-
BCBS 239 principles govern risk-data aggregation; reporting-control expectations sit in supervisory reporting frameworks (EBA reporting framework, PRA rulebook, Fed/FDIC/OCC rules, RBI directions) — confirm the current version in force.
-
Committee names and cadences are typical large-bank practice, not legal requirements; adapt to the institution's governance manual.