Audit universe
A complete map captures processes, systems, units, providers and material changes. It is the basis for risk assessment and audit planning.
Internal audit gives management an independent view of whether organisation, risk management and controls work in practice. It examines evidence and follows findings through to remediation.
Audit needs unrestricted information access and a direct reporting line to management. It reviews all activities and processes on a risk basis, including outsourced operations. It must avoid reviewing its own work; advisory activity and project observation require safeguards for independence.
A complete map captures processes, systems, units, providers and material changes. It is the basis for risk assessment and audit planning.
Compliance monitors and advises within its regulatory remit. Audit independently assesses the wider organisation and the effectiveness of control functions.
For banks, the plan is updated annually; WpI MaRisk requires annual risk-based planning for medium-sized investment firms. Planning considers changes and different risk sources and is approved by management. Ad hoc reviews remain possible. Banking MaRisk generally specifies three-year coverage, or five years for non-material processes; higher risks require shorter cycles.
Risk profile, past findings, complaints, incidents, new products, IT changes and outsourcing shape topic, depth and timing.
Questions, scope, timing, expertise and effort should make changes to the plan and emerging risks transparent.
Each review needs documented criteria, samples, working papers and a timely report. Audit distinguishes cause, risk and effect, then tracks agreed actions to demonstrable resolution.
Documents, data and interviews are tested against requirements and real cases. The report describes scope, findings and remedial measures.
Banking MaRisk requires at least quarterly reports to management, immediate escalation of particularly severe findings and monitoring of remediation.
For major initiatives, audit can highlight risks, control gaps and evidence needs early. It does not make product, technology or approval decisions and does not run the project. Its independence for later reviews remains intact.
For a new digital onboarding journey, audit may examine project governance, migration, test evidence, exceptions and handover to business as usual.
Audit charter, audit universe, risk assessment, approved plan, working papers, engagement reports, quarterly reports and action log.
Duties depend on firm type and activity. Under WpI MaRisk, internal audit depends on appropriateness and proportionality. For very small firms, AT 4.4.3 may allow management to perform the tasks or, subject to its conditions, omit the function; the relevant conditions and conflicts of interest need assessment. This overview does not replace an applicability assessment.
Did you know?
How an app can become an activity that requires permission.
Have you explored?
Prepare management profiles and collective suitability reviews.
International market entry / Germany
Considering a local office, a branch or a standalone authorisation in Germany? The appropriate route depends on your home jurisdiction, activities and operating model. 3RMCN combines experience from complex supervisory projects with product, technology and delivery expertise: from entry strategy and key interfaces through to operational readiness.
Discuss your plans ↗Supervisory perspectives
Experience in the context of CySEC (Cyprus), MFSA (Malta), FCA (United Kingdom), the European ESMA framework and MAS (Singapore). ESMA is not a national licensing authority.
International structuring
For incorporation in offshore jurisdictions, relevant specialists from the network can be involved. Jurisdiction, activities and regulatory obligations need to be considered for each project.