The Statement of Internal Control establishes the Board’s commitment to uphold the highest standards for the Group’s financial management and reporting and compliance with laws and regulations. Operational efficiency is upheld through delegating authority to specific management committees, who collectively report to the Board, ensuring tangible and intangible risks are effectively and proactively managed across the Group.
Responsibility
The Board affirms its commitment to overall responsibility and oversight of the BPMB Group’s internal control system, ensuring its safeguards of stakeholders’ interests and Group’s assets. It remains informed about developments in risk and governance to maintain effectiveness. Recognising the need for adaptable controls, the Board updates internal control and risk management systems to align with evolving business environments and process improvements.
Appropriate control structures are in place for identifying, evaluating, monitoring, and responding to significant risks, aligning with business objectives.
The Management is accountable to the Board and is responsible for implementing risk and control, with regular assessments ensuring the system’s adequacy, effectiveness, efficiency, integrity, viability and robustness.
Key Internal Control Processes
The key processes that the Board has established in reviewing the adequacy and effectiveness of the internal control system include the following:
Establish the Management’s role with regards to internal controls
The roles of the Management include, but are not limited to:
- Identifying and evaluating the risks faced towards the achievement of business objectives and strategies;
- Formulating relevant policies and procedures to manage these risks;
- Monitoring the effectiveness of the implementation of the internal control system;
- Implementing remedial actions to address compliance deficiencies; and
- Reporting to the Board on any changes to the risks and the corrective actions taken in a timely manner.
Internal Audit Function— Group Internal Audit (GIA)
GIA conducts periodic reviews of the Group’s business and operations to provide independent assurance to the Board on the adequacy and effectiveness of risk management, internal control systems, and governance processes as well as providing advisory services and insight to stakeholders for enhancing operational value and improvement. The processes and activities are guided by the Audit Charter, relevant regulatory guidelines, Group’s Code of Ethics and the International Professional Practices Framework (IPPF) issued by the Institute of Internal Auditors (IIA).
The audit engagements are carried out based on the Annual Audit Plan (AAP) as approved by the Board Audit Committee (BAC), formulated using a risk-based approach that considers regulatory requirements, emerging risks (such as asset quality, sustainability, and cybersecurity), previous audit ratings as well as feedback from Management, Shariah Committee (SC), and Board.
GIA assesses selected auditable functions and areas within the identified audit scope, focusing on risk exposure, compliance with approved policies, procedures, laws, regulations, and benchmarking against best practices. The GIA also conducts investigations and special reviews on any alleged negligence, fraud and misconduct as reported or requested by the Board or its subcommittees.
In evaluating internal control measures, GIA adheres to the five (5) components of the Internal Control Integrated Framework by the Committee of Sponsoring Organisations of the Treadway Commission (COSO), namely control environment, risk assessment, control activities, information and communication, and monitoring activities.
COSO Internal Control Framework
- Control Environment
- Risk Assessment
- Control Activities
- Information & Communication
- Monitoring Activities
The audit results, including identified risks and recommendations, are regularly reported to the Board Audit Committee (BAC). Audit findings resolutions are monitored and discussed at both the Audit Issue Resolution Committee (AIRC) and BAC meetings. Shariah audit findings are presented to the SC, where potential Shariah noncompliance (SNC) issues are deliberated and confirmed.
GIA continually enhances its capabilities by improving internal audit processes, benchmarking against industry standards and upskilling internal auditors through various training programmes, professional memberships, certifications, and co-engagement with reputable external consultants for specific audit engagements. Quality Assurance and Improvement Programme (QAIP) reviews are conducted yearly through self-assessment and at least once every five years by the qualified external independent reviewer to assess GIA’s service quality and conformance with the International Professional Practices Framework (IPPF) standards by the Institute of Internal Auditors (IIA).
Independent Role
To uphold the independence and objectivity of the audit role, the Chief Internal Auditor (CIA) reports functionally to the BAC and administratively to the Group Chief Executive Officer (GCEO). The Group has established the AIRC, comprising senior management representatives, to ensure adequate deliberation of the highlighted issues and findings.
Other Internal Control Processes and Structures
The other key elements of the internal control system established by the Board that provides effective governance and oversight of internal controls include:
Board Committees
The Board is supported by various other Board committees (other than the BAC), which include the Board Credit Committee (BCC), Board Nomination & Remuneration Committee (BNRC), Board Risk Management Committee (BRMC), Board Information Technology Committee (BITC) and Shariah Committee (SC). As outlined in the Terms of Reference (TOR), these committees have the authority to examine all relevant matters within their respective scopes and report their recommendations to the Board.
Management Committees
The Management has established several Executive-level Committees to aid and bolster the oversight responsibilities of the various Board Committees across key areas of business operations. These Committees (other than the AIRC) comprise the Group Management Committee (GMC), Group Credit Committee (GCC), Management Risk Committee (MRC), Asset and Liability Committee (ALCO), Management Tender Committee (MTC), Management Information Technology Committee (MITC), Group Human Resource Committee (GHRC), Crisis Management Team (CMT), and Whistleblowing Committee (WBC).
Business Plan and Performance Review
The Board deliberates and approves the annual business plan as well as the budget for the financial year. Performance achievements are reviewed on a monthly basis against the targeted results, allowing time for the appropriate responses and required remedial actions to be taken. The Board consistently reviews reports from the Management on the key operating statistics as well as other pertinent matters, including legal and regulatory issues.
Audit Issue Resolution Committee (AIRC)
The AIRC facilitates the BAC in ensuring comprehensive deliberation of the findings and recommendations highlighted in the audit reports. The AIRC also oversees the implementation of action plans to resolve the audit issues. Minutes from AIRC meetings together with the relevant audit reports are subsequently tabled to the BAC.
Board Audit Committee (BAC)
Chaired by an Independent Non-Executive Director, the BAC serves as a Board committee dedicated to facilitating dependable and transparent financial reporting processes across the Group, while also supervising the effectiveness of the internal audit function. The BAC actively monitors GIA’s independence, scope of work, and resource allocation, approving the Annual Audit Plan and determining the frequency of internal audit activities. All decisions and recommendations made by the BAC are communicated to relevant stakeholders for corrective actions, ensuring follow-through until issues are resolved.
Policies, Standard Operating Procedures (SOPs) and Authority Limits
The Group’s business and operational policies and standard operating procedures (SOPs) are documented and accessible to all employees across the Group. These policies and SOPs undergo regular review and updates by the respective business and functional units through a structured review process to accommodate changes in laws and regulations, as well as the changes in the business and operational environment.
Delegation of authority, including authorised limits at various levels of Management in the Group, are documented and designed to ensure accountability and responsibility.
Code of Ethics and Conduct
The Code of Ethics and Conduct (the Code) outlines the standards of ethical banking practices to uphold confidence in the security and integrity of the Group’s business operations. Applicable to all Bank employees, the Code complies with the Malaysian laws and internal Bank policies. All employees are expected to conduct business and represent the Group with the highest ethical, legal and professional standards.
Group Organisational Structure
Under the Board’s supervision, Management has established a clear organisational structure with defined reporting lines that enable the delegation of authority and responsibility across the Group. Implementation of the three lines of defence model further enhances business and operational requirements, reinforcing the maintenance of a robust control environment.