Skip to content

Auditing and Ethics · Audit of Banks

Understanding Bank Systems and Internal Controls (Audit of Banks)

Updated 4 October 2026 · Fact-checked

A bank runs on a core banking solution (CBS), where all branches share one central database. In audit, you first understand the bank's systems and controls, including IT general and application controls. Then you test them and decide how much substantive work is needed, especially on advances.

Understand Understanding Bank Systems and Internal Controls

A bank handles huge volumes of small transactions every day. Cash, deposits, loans, transfers and interest run through software, not ledgers. So you cannot audit a bank by checking vouchers one by one. You must first understand how the systems work and whether controls can be relied on.

Most banks use a core banking solution (CBS). Branches connect to a central server and one database. A customer can deposit at one branch and withdraw at another. Interest, charges and balances are often computed by the system. Many other systems feed into it, such as ATMs, internet and mobile banking, payment systems and treasury.

Bank controls fall into two groups. Manual controls include the maker-checker principle, dual custody of cash and keys, authorisation limits, branch inspections and reconciliations. IT controls include general controls and application controls. IT general controls cover access security, program change management, data backup and recovery, and IT operations. Application controls sit inside the software, such as input validation, system-enforced limits, auto-computation of interest, and exception reports.

Your approach follows the standard audit risk model. Understand the bank and its IT environment. Identify risks of material misstatement. Test the design and operation of key controls. Where controls are strong, reduce substantive testing. Where they are weak, or the data cannot be relied on, increase it. In a branch audit, you also depend on reports from the head office or the central IT team, and you should know what the branch auditor can and cannot verify.

A key point is that CBS reports are only as reliable as the controls behind them. For example, if the system classifies a loan account as a non-performing asset (NPA) automatically, you should test whether the parameters, such as the overdue days logic, are correctly set before relying on the output.

Key rules to remember

Control reliance logic
Stronger tested controls → lower control risk → less substantive testing; weaker controls → more substantive testing
This is the core reasoning for any answer on testing controls. Reliance needs testing of operating effectiveness, not just understanding.
Two types of IT controls
IT controls = General controls (environment) + Application controls (within the software)
Name both types in answers. General controls support the proper working of application controls.
Maker-checker
Maker enters the transaction; a different person (checker) verifies and authorises it
A key segregation of duties control in CBS. Never let one person do both for the same transaction.
IT general control areas
Access security + Program change + Data backup/recovery + IT operations
Use these four as a checklist when asked about the IT environment of a bank branch.

How to solve Understanding Bank Systems and Internal Controls questions

Use this method for questions asking how an auditor understands, evaluates or tests bank systems and controls.

  1. 1Identify what the question asks: understanding systems, evaluating controls, testing IT, or auditing a specific area like advances.
  2. 2State the bank context briefly: CBS, shared central database, high volumes, reliance on system reports.
  3. 3List the relevant controls in two groups: manual controls and IT controls (general and application).
  4. 4Explain how you understand them: enquiry, inspection of documents, observation, and walkthrough of a transaction.
  5. 5Explain how you test them: test of controls on a sample, check access rights, exception reports, reconciliations and system parameters.
  6. 6Link the result to the audit approach: reliance means reduced substantive procedures; weakness means extended substantive procedures.
  7. 7Mention reporting or communication: weaknesses in controls go to management and those charged with governance.
  8. 8Close with a one-line conclusion tied to the facts in the question.

Quickest way: MCQ elimination and a step-mark format

When to use it: Use this under time pressure, for both the 30 marks of MCQs and the 70 marks of descriptive answers.

  1. For MCQs, spot the control type in the stem: access, change, backup (general) or validation, limits, auto-calculation (application).
  2. Eliminate options that say the auditor can rely on controls without testing them. This is almost always wrong.
  3. Eliminate options that say IT controls replace the need for any substantive work. Controls reduce, not remove, substantive testing.
  4. For written answers, use the skeleton: Context, Controls, Audit procedure, Conclusion. Write each as a short bullet.
  5. Use headings like General controls and Application controls so the examiner sees the marks points quickly.
  6. Always end with the effect on audit approach: more or less substantive testing.

Common mistakes in Understanding Bank Systems and Internal Controls

  • Treating understanding of controls as the same as testing them.

    Both words appear together in the syllabus, so they blur.

    Fix: Understanding means knowing design and implementation. Testing means checking operating effectiveness over the period. Write both separately.

  • Confusing IT general controls with application controls.

    Both relate to software, so students use the terms loosely.

    Fix: General controls cover the environment: access, change, backup, operations. Application controls work inside a specific program: validations, limits, auto-computation.

  • Relying on CBS reports without checking the system parameters behind them.

    Computer output looks authoritative.

    Fix: Test key parameters such as interest rates, overdue day counts and NPA tagging logic before relying on the reports.

  • Writing only about manual controls like cash handling in a CBS bank.

    Older textbooks and simple examples focus on vouchers and cash.

    Fix: Always include IT controls when the question mentions CBS, a central database or an IT environment.

  • Ignoring segregation of duties and the maker-checker principle.

    Students list controls generically and miss the key bank one.

    Fix: Mention that the maker and checker must be different people with separate user IDs and access rights.

  • Saying weak controls mean the auditor cannot complete the audit.

    Students over-read control weakness as a scope problem.

    Fix: Weak controls mean higher assessed risk, so you do more substantive work and communicate the weaknesses. Only a lack of evidence affects the opinion.

Worked examples

Example 1

You are auditing a bank branch that operates on CBS. Explain how you would obtain an understanding of the IT environment and what you would look for in IT general controls.

Show the solution
  1. Start with understanding: enquire about the CBS used, who manages it, how the branch connects to the central server, and which other systems feed it, such as ATM and internet banking.
  2. Identify what depends on IT: interest computation, NPA tagging, balances and MIS reports.
  3. Access security: check that users have unique IDs, role-based access, strong passwords, timely removal of access for leavers, and restricted privileged access.
  4. Program change: check that changes to the software are authorised, tested and approved before moving to live use.
  5. Data backup and recovery: check regular backups, offsite storage and a tested disaster recovery plan.
  6. IT operations: check monitoring of batch jobs, handling of failures and incident logging.
  7. Link to approach: if general controls are effective, you may rely on application controls after testing them; if not, expand substantive testing.

Answer: Understand the CBS architecture and its dependencies, then evaluate general controls in four areas: access security, program change, data backup and recovery, and IT operations. Reliance on application controls and system reports depends on these being effective; otherwise extend substantive procedures.

Example 2

During the audit of a bank branch you find that the same officer both enters and authorises loan disbursements in the CBS. How do you view this, and what do you do?

Show the solution
  1. Identify the control: the maker-checker principle requires separate people to enter and authorise.
  2. Note the weakness: one person doing both removes segregation of duties and raises the risk of error or fraud in disbursements.
  3. Check how it happened: review access rights, user ID allocation and whether the system permits this or if a workaround exists.
  4. Assess the impact: treat the control as ineffective, so control risk for advances rises.
  5. Respond: increase substantive testing of disbursements, such as checking sanction letters, documentation, security creation and end-use for a larger sample.
  6. Review related exception reports and look for unusual or large disbursements by that user.
  7. Communicate: report the weakness to management and those charged with governance, and document the matter in working papers.

Answer: This is a significant control weakness because maker-checker is broken. You treat the control as ineffective, raise assessed risk for advances, extend substantive testing of disbursements, and communicate the deficiency in writing.

Exam tips

  • Whenever a question mentions CBS, answer in two blocks: general controls and application controls. This covers the full marks structure.
  • In MCQs, any option that suggests relying on controls with no testing, or skipping substantive work entirely, is nearly always wrong.
  • Use the four-part skeleton Context, Controls, Procedure, Conclusion in written answers so each part earns step marks.
  • For questions on advances, link internal controls to sanction, documentation, disbursement and monitoring, and say how weak controls change your sample size.
  • Remember the branch auditor's limits: some centralised processes sit at the head office, so mention reliance on reports or confirmations from there.

Practice questions from Audit of Banks

Understanding Bank Systems and Internal Controls in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Understanding Bank Systems and Internal Controls: frequently asked questions

What is a core banking solution in bank audit?

It is a centralised system where all branches operate on one shared database. Customers can transact at any branch, and the system computes interest, charges and balances. For the auditor, the main point is that audit evidence depends heavily on system reliability and IT controls.

What are the main internal controls in a bank?

They include manual controls such as the maker-checker principle, dual custody, authorisation limits and reconciliations. They also include IT controls, both general and application. You test these to decide how much substantive checking is needed.

How is the IT environment audited at a bank branch?

You understand the systems in use and test the IT general controls: access security, program change, data backup and recovery, and IT operations. Then you test relevant application controls such as validations and automatic calculations. The results shape your substantive procedures.

Can the auditor rely on CBS reports directly?

Only after checking that the controls behind the reports work and that key system parameters are correct. Without that, you need to test the underlying data through substantive procedures.