Chapter 005: Who Owns the Numbers?

Section 1: How a Bank Works Financially · Chapter 005 of 100

A reporting failure often exposes a practical ownership gap: nobody can explain who approved the number or its supporting controls. Ownership is not a slogan — it is a designed operating model: named owners, documented handoffs, evidenced controls, and committees that actually challenge. This chapter maps the finance function of a modern bank end to end: its towers, its partners, its committees, and the RACI that makes month-end, regulatory submission and audit possible.

1. Chapter opening

Chapters 001–004 covered what the numbers are. This chapter covers who stands behind them. You will learn the four towers of Finance (financial control, FP&A/business partnering/FTP, regulatory reporting, tax and specialists), the shared backbone (data, systems, controls, change), the three lines of defence as applied to finance, the committee ladder from working group to Board, and the close RACI that assigns every task. Section 1 closes with this chapter because every later block assumes you know which team to call.

2. Learning objectives

By the end of this chapter you will be able to:

  1. Name the four Finance towers and state each tower's core deliverables.
  2. Place Finance alongside Treasury, Risk, Operations, Technology, business lines, Audit and supervisors on one map.
  3. Apply the three-lines-of-defence model to a finance process (for example, ECL provisioning).
  4. Read and construct a close RACI, distinguishing Responsible, Accountable, Consulted and Informed.
  5. Describe the committee ladder (ALCO, capital, disclosure, audit committee, Board) and what each signs off.
  6. Identify operating-model failure patterns: orphan numbers, dual truths, attestation theatre.

3. Business context

Operating models fail quietly and expensively. A bank with brilliant quants still restates earnings if nobody owns the reconciliation between the risk engine and the GL. A bank with strict policies still misses submissions if Regulatory Reporting depends on a spreadsheet only one person understands. Supervisors now assess operating-model effectiveness directly (SREP operational risk, BCBS 239, skilled-person reviews): key-person dependencies, spreadsheet sprawl, unclear attestations and overdue audit findings are graded findings, not housekeeping. For transformation programmes, the operating model decides whether a new system lands in governed hands or amplifies existing chaos.

SymptomRoot causeWhere it surfaces
Two teams report different revenue for one productNo single definition owner; dual martsManagement pack vs FINREP break
Month-end takes 12 working daysManual journals, sequential reconciliations, no flash processLate, low-quality decisions
Audit finding repeats three years runningOwner without authority or budget to fixSupervisory escalation, capital add-on
Submission error discovered by the regulatorReporting QA skipped under time pressureCorrection, resubmission, reputation damage
Nobody can explain an allocationDriver methodology undocumentedProduct mispricing, challenge failure

4. Finance and accounting view

4.1 The four towers

TowerOwnsProducesPartners most with
Financial ControlGL integrity, close, journals, reconciliations, substantiationTrial balance, statutory accounts, audit evidenceOperations, Technology, external audit
FP&A, Business Partnering, FTPPlans, forecasts, product/customer profitability, FTP methodologyBudgets, flash results, business reviewsBusiness lines, Treasury (FTP), Risk (capital allocation)
Regulatory ReportingPrudential/financial/statistical returns, disclosures, XBRLFINREP, COREP, Pillar 3, local returnsRisk, Treasury, Data, supervisors
Tax and specialistsCurrent/deferred tax, Treasury finance, accounting policy, changeTax returns, hedge files, policy manuals, programme deliveryAll towers, advisors, auditors

Centralised models (single global finance utility) gain consistency but lose business intimacy; federated models (finance teams inside each business) gain insight but breed dual truths. Most large banks run a hybrid: central policy, systems and reporting with embedded business partners — and a permanent tension between the two that governance must manage.

4.2 Attestation: ownership made personal

Attestation is the mechanism by which ownership becomes enforceable: named individuals sign that balances are understood, reconciled and supported — at a frequency set by risk and the bank's control policy; submission sign-off authority depends on the relevant form and jurisdiction. Effective attestation packs contain the number, its movement explanation, open breaks with owners and dates, and linked evidence. "Attestation theatre" — signing template packs nobody read — is a favourite audit finding; supervisors increasingly ask to see challenge evidence (queries raised, items sent back), not just signatures.

4.3 Committees that own outcomes

CommitteeChair (typical)Decides / recommendsCadence
ALCOCFO or TreasurerFunding plan, liquidity limits, FTP, balance-sheet shapeMonthly
Capital/Stress committeeCRO/CFOICAAP, stress results, buffers, distributionsQuarterly
Disclosure committeeCFOWhat is published, wording of judgementsPer reporting date
Audit committee (Board)Independent directorAudit findings, accounting judgements, whistleblowingQuarterly
BoardChairStrategy, risk appetite, accounts approval, dividendsMonthly/quarterly
Model risk committeeCROECL, valuation and capital model approvalAs needed

Decisions without a minuted owner and date are not decisions — test this sentence against any committee pack you inherit.

5. Product and customer impact

Customers feel the operating model through consistency and speed: a well-owned product P&L produces stable, explainable pricing; orphan cost allocations produce sudden fee hikes when true costs surface. Complaint handling, redress provisioning and fee transparency all depend on Finance towers cooperating with Operations — mis-sold-product episodes are invariably also operating-model episodes (unclear ownership of product profitability vs sales incentives). For new launches, the product-approval process should require Finance sign-off on recognition, dimensions, FTP treatment and reporting impact before go-live (Section 20 test cases).

6. Regulatory and supervisory view

Supervisors engage the operating model directly: the CFO and heads of control face fit-and-proper expectations; skilled-person (Section 166-style, jurisdiction-dependent) reviews examine reporting controls; SREP grades internal governance; BCBS 239 assesses risk-data aggregation; disclosure rules require named responsibility statements. Enforcement history shows personal accountability regimes (for example the UK Senior Managers Regime) reaching individual executives for control failures — ownership has legal weight, and attestations are discoverable. Regulatory reporting teams must maintain submission calendars, four-eyes checks, query logs and resubmission procedures as examinable artefacts (The Regulatory Reporting Landscape and Submission Governance).

7. Systems and data view

The backbone under the towers: product processors and subledgers (Section 7 of The Bank’s Business Model), the accounting hub and GL, the finance data warehouse and reporting marts, GRC workflow (attestations, findings tracking), and the change pipeline (requirements → build → UAT → parallel run → go-live). Ownership extends to data: each critical data element needs a named owner, a definition, quality rules and lineage documentation (Section 20). The two structural risks are key-person spreadsheets (migrate to governed marts with access control and versioning) and interface ownership gaps (every feed needs a producer owner and a consumer owner with an SLA — breaks in between belong to both until fixed).

8. End to end process

Quarter-end close as the operating model in motion: Day 1–2: subledger freeze, flash P&L, early breaks triaged. Day 3–5: accruals, ECL run, valuations, FTP and allocations posted; reconciliations executed with aged-break escalation. Week 2: management results with variance commentary, business-line attestations collected, disclosure committee reviews judgements. Week 3: audit committee challenge, Board approval, publication; regulatory returns compiled from the locked close with independent QA and four-eyes submission. Week 4 (after): post-mortem — breaks aged, journals analysed, findings logged, automation backlog reprioritised. Mature banks compress this to days; the sequence, not the speed, is the control.

9. Controls and risks

RiskControlEvidence
Orphan numbers (no owner)Ownership register per report/account; RACI per processSigned register, RACI packs
Attestation without challengeMandatory variance thresholds, return-to-sender logsQuery logs, rework records
Key-person dependencyCross-training, governed marts replacing spreadsheetsDependency matrix, migration plan
Findings that never closeTracked actions with dates, owner consequences, audit committee oversightFindings dashboard, closure evidence
Change landing without ownershipRACI in every change ticket; hypercare ownershipSigned go-live readiness, hypercare logs

10. Practical examples

Example A — The 40-million break nobody owned. Risk's loan total and Finance's loan total differ by 40. Each team assumes the other's number is wrong; month-end passes with an unexplained plug. Root cause found weeks later: restructured loans feed the risk engine but bypass the GL interface. Fix: named interface owners both sides, daily automated tie-out, break auto-escalation after two days. Lesson: interfaces need joint ownership by design.

Example B — Good RACI, bad behaviour. A bank documents a perfect close RACI. In practice the Accountable CFO is on leave, the deputy never formally delegated, and attestations stall. Lesson: RACI needs delegation rules and deputies named in advance — test the holiday scenario, not just the happy path.

11. Diagrams

Figure 1. Who owns and challenges controls? Who owns and challenges controls?

Figure 2. Finance responsibilities and hand-offs. Finance responsibilities and hand-offs

Figure 3. A close responsibility example. A close responsibility example

12. Tables

Table 1 — Who to call: finance responsibility map

QuestionFirst callSecond call
Why doesn't this reconcile?Financial Control / Operations (interface owners)Technology (feed health)
Is this product really profitable?Business Finance partner (FP&A)FTP desk, Risk (capital/ECL)
What goes in this regulatory cell?Regulatory Reporting (taxonomy owner)Data office (lineage), Risk (method)
Can we recognise this income now?Accounting PolicyExternal audit (judgement call)
Who signs this off?Close/submission RACICFO office, committee secretary
Why did the auditor flag this?Control owner named in findingInternal Audit (scope/evidence)

Table 2 — Operating-model maturity self-check

LevelCloseReconciliationsAttestationChange
1. HeroicWeeks, manual, key-personSpreadsheets, plugsSignatures without readingLands unowned
2. ManagedCalendar exists, mostly metStandard templates, aged breaksQueries happen sometimesRACI drafted late
3. ControlledFlash + locked closeAutomated matching, joint interface ownersChallenge evidencedOwnership before go-live
4. TrustedDays, analytics-led reviewBreaks prevented upstreamBoard-grade challenge packsHypercare to steady state

13. Illustrative bank case study

The restatement that was really an ownership failure. A bank restated two years of results after discovering fee income recognised on the wrong trigger across several products. Every control existed on paper: a policy, a checklist, an attestation. Investigation found the policy owner had moved roles with no successor named, attestations were signed from summary packs, and Internal Audit had flagged the gap a year earlier with the finding still open. The numbers were fixed in a quarter; the operating model took two years (new owners, governed engines, evidenced challenge). Lesson: controls without owners are decorations. (Fictional training case; no specific bank or event is asserted.)

14. BA, developer, tester and operations guidance

  • BA: Start every finance change with the as-is RACI and ownership register; name the owner of each new report, feed and control in the requirements — unnamed deliverables become orphans at go-live.
  • Developer: Build attestation, four-eyes approval and evidence attachment into workflows, not email; log who approved what, when, on which data version.
  • Tester: Test delegation (approver absent), segregation (maker cannot check own work), and evidence completeness (submission without attachment is rejected) — the negative paths auditors probe.
  • Operations: Publish the daily ownership dashboard: unreconciled breaks by owner and age, journals awaiting checker, attestations outstanding. Visibility creates ownership faster than memos.

15. Common mistakes

  1. Confusing doing the work (Responsible) with answering for it (Accountable) — one clearly identified accountable owner per task.
  2. Listing the Board as Accountable for operational tasks it cannot perform.
  3. Attesting from summaries without inspecting breaks and evidence.
  4. Leaving interface ownership split ("producer says sent, consumer says not received") with no joint tie-out.
  5. Treating audit findings as audit's problem — findings belong to the control owner, audit only tracks.

16. Key takeaways

  1. Four towers (control, FP&A/FTP, regulatory reporting, tax/specialists) share one backbone and serve the same ledger.
  2. Finance teams that prepare accounts and operate controls are management first-line roles; designated oversight functions may perform second-line challenge; Internal Audit independently assures.
  3. Attestation without evidenced challenge is theatre; supervisors now test for the challenge.
  4. RACI plus delegation rules plus committee minutes = ownership you can prove.
  5. Connect business economics, financial statements, profit, liquidity/capital constraints and accountable ownership before approving a finance process.

17. References and verification notes

  • IIA: Three Lines Model: first- and second-line roles sit within management; Internal Audit provides independent third-line assurance. A Finance department is not automatically second line.

  • Three-lines model per IIA guidance as adapted by major bank governance frameworks; personal-accountability regimes (for example UK SMR), skilled-person review powers and SREP governance grading are jurisdiction-specific — verify local applicability.

  • BCBS 239 principles govern risk-data aggregation; reporting-control expectations sit in supervisory reporting frameworks (EBA reporting framework, PRA rulebook, Fed/FDIC/OCC rules, RBI directions) — confirm the current version in force.

  • Committee names and cadences are typical large-bank practice, not legal requirements; adapt to the institution's governance manual.