Bank Islam Integrated Annual Report 2020

BANK ISLAM MALAYS IA BERHAD INTEGRATED ANNUAL REPORT 2020 151 ěɁ ɨljǹȢljƺɽ ɽȃlj Ȉȶǁljɥljȶǁljȶƺlj Ɂǹ ŽȶɽljɨȶƃȢ ʍǁȈɽӗ ɽȃlj :Ž ɨljɥɁɨɽɰ ǹʍȶƺɽȈɁȶƃȢȢʰ ɽɁ ɽȃlj 9Ɂƃɨǁ ɽȃɨɁʍǼȃ ɽȃlj 9 K:ӝ ěȃlj ƃȶȶʍƃȢ ƃʍǁȈɽ ɥȢƃȶ Ȉɰ ɨljʤȈljʥljǁ ƃȶǁ ƃɥɥɨɁʤljǁ ƹʰ ɽȃlj 9 K: ɥɨȈɁɨ ɽɁ ɽȃlj ɰɽƃɨɽ Ɂǹ ljƃƺȃ ǹȈȶƃȶƺȈƃȢ ʰljƃɨӝ ěȃlj ƃʍǁȈɽ ɥȢƃȶ ƃǁɁɥɽɰ a risk-based approach in determining the auditable units and frequency of the audits which focused on the following three ӯѶӰ ƺɁȴɥɁȶljȶɽɰӖӸ i. Impact and likelihood of the inherent risk; ii. The respective controls in place; and iii. Existence of effective risk transfer and loss impact reduction practices in minimising potential losses from negligence or fraud. Ž A ƃǁɁɥɽɰ ɽȃlj ɰɽƃȶǁƃɨǁɰ ƃȶǁ ɥɨȈȶƺȈɥȢljɰ ɁʍɽȢȈȶljǁ Ȉȶ ɽȃlj ŽȶɽljɨȶƃȢ :ɁȶɽɨɁȢ yɨƃȴljʥɁɨȟ Ɂǹ :ɁȴȴȈɽɽljlj Ɂǹ ČɥɁȶɰɁɨȈȶǼ ÝɨǼƃȶȈɰƃɽȈɁȶ Ɂǹ ɽȃlj ěɨljƃǁʥƃʰ :ɁȴȴȈɰɰȈɁȶ ӯ:ÝČÝӰ ƃȶǁ ɽȃlj ɁƹȚljƺɽȈʤljɰ ɰljɽ ƹʰ ɽȃlj ŽȶɰɽȈɽʍɽlj Ɂǹ ŽȶɽljɨȶƃȢ ʍǁȈɽɁɨɰԇ ŽȶɽljɨȶƃɽȈɁȶƃȢ ĀɨɁǹljɰɰȈɁȶƃȢ ĀɨƃƺɽȈƺljɰ yɨƃȴljʥɁɨȟ ʥȃȈƺȃ ƺɁȴɥɨȈɰljɰ ɽȃlj ƺɁɨlj ɥɨȈȶƺȈɥȢlj ǹɁɨ ɽȃlj ĀɨɁǹljɰɰȈɁȶƃȢ ĀɨƃƺɽȈƺlj Ɂǹ ŽȶɽljɨȶƃȢ ʍǁȈɽȈȶǼӗ ɽȃlj ǁljǹȈȶȈɽȈɁȶ Ɂǹ ŽȶɽljɨȶƃȢ ʍǁȈɽȈȶǼ ƃȶǁ :Ɂǁlj Ɂǹ KɽȃȈƺɰӝ ěȃlj ɨljɰʍȢɽɰ Ɂǹ ɽȃlj ƃʍǁȈɽ ƺɁȶǁʍƺɽljǁӗ ȈȶƺȢʍǁȈȶǼ Ȉɽɰ ɨȈɰȟɰ ƃȶǁ ɨljƺɁȴȴljȶǁƃɽȈɁȶɰ ƃɨlj ɨljɥɁɨɽljǁ ɽɁ ɽȃlj 9 K: Ɂȶ ƃ ɨljǼʍȢƃɨ ƹƃɰȈɰӝ ĄljɰɁȢʍɽȈɁȶ Ɂǹ ɽȃlj ƃʍǁȈɽ ǹȈȶǁȈȶǼɰ ƃȶǁ ɨljƺɁȴȴljȶǁƃɽȈɁȶɰ ƃɨlj ɥljɨǹɁɨȴljǁ ƹʰ ɽȃlj ÃƃȶƃǼljȴljȶɽ ƃȶǁ ƺȢɁɰljȢʰ Ɂƹɰljɨʤljǁ ƹʰ ɽȃlj ÃƃȶƃǼljȴljȶɽ ʍǁȈɽ :ɁȴȴȈɽɽljlj ʥȃɁɰlj ȴljȴƹljɨɰ ƺɁȴɥɨȈɰlj Ɂǹ ɽȃlj ȴljȴƹljɨɰ Ɂǹ ɽȃlj ČljȶȈɁɨ ÃƃȶƃǼljȴljȶɽӝ Žȶ ƃǁǁȈɽȈɁȶӗ ČȃƃɨȈƃȃ audit reports including their findings, risks and recommendations are notified and deliberated at the SSC meetings. ěȃlj Ž A Ȉɰ ƺɁȴȴȈɽɽljǁ ɽɁ ɥɨɁʤȈǁlj ƃȶ Ȉȶǁljɥljȶǁljȶɽӗ ɁƹȚljƺɽȈʤlj ƃɰɰʍɨƃȶƺlj ƃȶǁ ƃǁʤȈɰɁɨʰ ɰljɨʤȈƺljɰ ɽȃƃɽ ʥȈȢȢ ƃǁǁ ʤƃȢʍlj ƃȶǁ ȈȴɥɨɁʤlj the Bank’s operations. Ž A ƺɽȈʤȈɽȈljɰ Ȉȶ ѵѳѵѳ Āɨljɥƃɨlj ɽȃlj ʍǁȈɽ ĀȢƃȶ ƃȶǁ 9ʍǁǼljɽ ǹɁɨ ƃɥɥɨɁʤƃȢ Ɂǹ ɽȃlj 9 K:ӝ ěȃlj ʍǁȈɽ ĀȢƃȶ ʥƃɰ ǁljʤljȢɁɥljǁ ƹƃɰljǁ Ɂȶ ƃɰɰljɰɰȴljȶɽ of the significant potential risk exposure of the auditable areas; ĀɨɁʤȈǁlj Ȉȶǁljɥljȶǁljȶɽ ƃɰɰljɰɰȴljȶɽ ƃȶǁ ɁƹȚljƺɽȈʤlj ƃɰɰʍɨƃȶƺlj Ɂȶ ɽȃlj ƃǁljɧʍƃƺʰ ƃȶǁ ljǹǹljƺɽȈʤljȶljɰɰ Ɂǹ ȈȶɽljɨȶƃȢ ƺɁȶɽɨɁȢɰ ȈȴɥȢljȴljȶɽljǁ ɽɁ ȴȈɽȈǼƃɽlj ɽȃlj ɨȈɰȟ ljʯɥɁɰʍɨljɰӝ Āɨljɥƃɨlj ƃʍǁȈɽ ɨljɥɁɨɽ ƺɁȶɰȈɰɽȈȶǼ Ɂǹ ɁƹɰljɨʤƃɽȈɁȶɰӗ ȈȴɥɨɁʤljȴljȶɽ ɁɥɥɁɨɽʍȶȈɽȈljɰӗ management responses, deadline for resolution and person-in-charge for implementation including corrective actions by the respective stakeholders; yɁȢȢɁʥӸʍɥ Ɂȶ ɽȃlj ÃƃȶƃǼljȴljȶɽ ƺɁɨɨljƺɽȈʤlj ƃƺɽȈɁȶɰ Ɂȶ ƃʍǁȈɽ Ȉɰɰʍljɰ ɨƃȈɰljǁ ƹʰ ɽȃlj Ž Aӝ AljɽljɨȴȈȶlj ʥȃljɽȃljɨ ƺɁɨɨljƺɽȈʤlj actions taken have generally achieved the desired results to mitigate the risk exposures; ĄljɥɁɨɽ ɽɁ ɽȃlj 9 K:ӗ ɽȃlj ǹȈȶƃȢ ƃʍǁȈɽ ɨljɥɁɨɽ ȃȈǼȃȢȈǼȃɽȈȶǼ ɽȃlj ƃʍǁȈɽ ɥȢƃȶ ƺɁʤljɨƃǼljӗ ƃʍǁȈɽ ɰƺɁɥlj ƃȶǁ ɨȈɰȟɰ ƺɁʤljɨljǁӗ ƃʍǁȈɽ rating, significant audit findings, findings escalated for Management’s immediate action and status of corrective ƃƺɽȈɁȶɰӝ ɽɁɽƃȢ Ɂǹ Ѵѵѵ ƃʍǁȈɽɰ ӯljʯƺȢʍǁȈȶǼ ȈȶʤljɰɽȈǼƃɽȈɁȶɰӰ ʥljɨlj ƺɁȶǁʍƺɽljǁ ǹɁɨ ɽȃlj {ɨɁʍɥ Ȉȶ yťѵѳѵѳӢ ĄljɥɁɨɽ ɽɁ ɽȃlj 9 K: ɽȃlj ƃǁljɧʍƃƺʰӗ ɨljȢȈƃƹȈȢȈɽʰӗ ȈȶɽljǼɨȈɽʰ ƃȶǁ ƺɁȴɥȢȈƃȶƺlj ɁǹӖ – risk management, internal controls and governance processes; – Information Technology, stress testing procedures and practices and the back-up system to cover for contingencies and disaster; ӵ ĄljǼʍȢƃɽɁɨʰ ɨljɥɁɨɽȈȶǼӗ ƃƺƺɁʍȶɽȈȶǼ ɨljƺɁɨǁɰӗ ǹȈȶƃȶƺȈƃȢ ɨljɥɁɨɽɰ ƃȶǁ ȴƃȶƃǼljȴljȶɽ ȈȶǹɁɨȴƃɽȈɁȶӢ ĄljʤȈljʥ ƺɁȴɥȢȈƃȶƺlj ʥȈɽȃ ɨljȢljʤƃȶɽ ȢljǼƃȢӗ ɨljǼʍȢƃɽɁɨʰ ƃȶǁ ȈȶɽljɨȶƃȢ ɥɁȢȈƺȈljɰ ƃɰ ʥljȢȢ ƃɰ Ȉȶ ƺɁȴɥȢȈƃȶƺlj ʥȈɽȃ ČȃƃɨȈƃȃ ɨʍȢljɰ ƃȶǁ ɥɨȈȶƺȈɥȢljɰ ƃɰ ǁljɽljɨȴȈȶljǁ ƹʰ ɽȃlj ČȃƃɨȈƃȃ ČʍɥljɨʤȈɰɁɨʰ :ɁʍȶƺȈȢ ƃȶǁ ČȃƃɨȈƃȃ :ɁȴɥȢȈƃȶƺlj ĀɁȢȈƺʰӝ ĀɨɁʤȈǁlj Ȉȶǁljɥljȶǁljȶɽ ƃɰɰljɰɰȴljȶɽ Ɂȶ ɽȃlj ljǹǹljƺɽȈʤljȶljɰɰ Ɂǹ ɽȃlj 9ʍɰȈȶljɰɰ :ɁȶɽȈȶʍȈɽʰ ĀȢƃȶӣAȈɰƃɰɽljɨ ĄljƺɁʤljɨʰ ĀȢƃȶ ɽɁ ensure resumption of business activities is not hampered.

RkJQdWJsaXNoZXIy NDgzMzc=