Bank Internal Audit: Scope, Federal Rules, and Independence

A bank internal audit is an independent, board-directed function that tests whether the bank is managing risk, complying with law, and reporting its finances accurately, and federal regulators expect every insured depository institution to maintain one. The program’s findings feed the board’s oversight and shape what examiners look at during safety and soundness reviews. Its scope reaches nearly everything the bank does: loans, deposits, technology, vendors, consumer disclosures, and financial reporting.

The size and formality of the program scale with the institution. A community bank may run a lean function focused on credit files and Bank Secrecy Act testing. A large holding company operates a full department with specialists in cybersecurity, model risk, and capital planning. The underlying obligation is the same.

What the Internal Audit Function Covers

The OCC identifies four core objectives for a bank’s internal audit program: evaluating internal controls, ensuring safeguarding of assets, testing compliance with laws and regulations, and providing consulting services on new products or significant projects.1Office of the Comptroller of the Currency. Comptrollers Handbook – Internal and External Audits Every significant risk-bearing activity should be covered somewhere in the audit plan, with depth and frequency tied to risk.

Financial Reporting and Credit Risk

Auditors verify that financial statements reflect true asset values and liability levels. That includes reviewing general ledger reconciliations, testing journal entries for proper authorization, and confirming that allowances for loan losses are adequate. Credit risk usually gets the most attention at community and mid-size banks. Auditors look at loan portfolios for excessive concentration in a single industry or geographic area, weak collateral documentation, and lending decisions that deviate from the bank’s approved risk appetite. A loan file missing an appraisal or borrower financials is the kind of thing that gets flagged fast.

For publicly traded banks, Sarbanes-Oxley Section 404 requires management to assess and report on the effectiveness of internal controls over financial reporting, with an independent auditor attesting to that assessment. Banks that are not publicly traded but hold $5 billion or more in assets face a parallel requirement under FDIC Part 363.2eCFR. 12 CFR Part 363 – Annual Independent Audits and Reporting Requirements

BSA/AML and Regulatory Compliance

Bank Secrecy Act compliance is a perennial audit priority. Internal auditors test whether the bank is filing Suspicious Activity Reports when transactions meet the reporting thresholds, maintaining an adequate customer identification program, and running effective anti-money laundering controls. Federal regulations require a SAR when a transaction involves $5,000 or more in funds and the bank suspects money laundering or a BSA violation.3eCFR. 12 CFR 208.62 – Suspicious Activity Reports

Consumer Protection Laws

The Federal Reserve’s examination framework identifies several consumer laws that auditors are expected to test, including the Truth in Lending Act, the Real Estate Settlement Procedures Act, the Equal Credit Opportunity Act, the Home Mortgage Disclosure Act, and the privacy provisions of the Gramm-Leach-Bliley Act.4Federal Reserve. Framework for the Assessment of Consumer Compliance Risk in Bank Holding Companies Examiners look at whether the audit methodology appropriately risk-focuses consumer compliance testing and whether management tracks and resolves findings in this area.

Market Risk and Liquidity

Auditors analyze investment strategies and interest rate sensitivity to confirm that market price swings do not threaten solvency. Liquidity reviews focus on cash reserves, deposit stability, and the bank’s ability to meet its obligations during stress. Internal audit should verify that the Asset and Liability Committee is integrating liquidity risk tolerances into overall management and that equity capital and risk-weighted assets are calculated correctly under applicable capital adequacy rules.

IT and Cybersecurity

Technology is one of the fastest-growing areas of audit scope. The FFIEC’s IT Examination Handbook directs internal auditors to validate that IT controls are designed to mitigate risk and are operating as intended, while remaining fully independent from the design or implementation of those controls.5FFIEC. IT Examination Handbook – Management Booklet Required review areas include:

  • Information security and cybersecurity, including threat intelligence, incident response, and administrative, technical, and physical safeguards.
  • IT governance, including board-approved strategic plans and oversight of IT activities.
  • Business continuity, including enterprise-wide disaster recovery planning and testing of backup systems.
  • Software development controls maintained throughout the system development life cycle.
  • IT operations, including data center controls, network services, and change management.

Third-Party Vendors

Using an outside vendor does not transfer the bank’s responsibility to operate safely and comply with the law. Auditors review vendor relationships across the full life cycle, from initial due diligence through ongoing monitoring and termination. The OCC’s 2024 guidance for community banks emphasizes that audit coverage should scale to risk, with the most rigorous oversight going to vendors supporting critical activities like core processing, payment networks, and customer-facing technology.6Office of the Comptroller of the Currency. Third-Party Risk Management – A Guide for Community Banks

Auditors check whether contracts grant the bank access to vendor audit reports, SOC reports, and self-assessments, and whether the bank is actually reviewing those reports rather than filing them away. Repeat findings at a vendor, data breaches, or service interruptions should be escalated through the bank’s risk management framework. Examiners frequently find gaps here: the contract gives the bank the right to audit, and nobody is exercising it.

The Federal Rules That Govern the Function

The foundational expectation comes from the interagency policy statement issued jointly in 2003 by the Federal Reserve, FDIC, OCC, and the former Office of Thrift Supervision. That policy makes the board of directors and senior management responsible for maintaining an effective internal audit program and prohibits delegating that responsibility to outside parties.7Office of the Comptroller of the Currency. Interagency Policy Statement on the Internal Audit Function and Its Outsourcing It also sets independence standards aligned with Sarbanes-Oxley, including a prohibition on using the same accounting firm for both external audit and outsourced internal audit work at publicly held banks or those subject to FDIC Part 363.

FDIC Part 363 layers structural requirements on top, tied to asset size. Banks with $1 billion or more in consolidated total assets must file annual audit reports and establish an audit committee of outside directors, with the majority independent of management. Once a bank crosses $5 billion in total assets, the requirements tighten: the audit committee must be fully independent, at least two members must have banking or financial management expertise, and management must formally assess the effectiveness of internal controls over financial reporting each year, with an independent accountant attesting to that assessment.2eCFR. 12 CFR Part 363 – Annual Independent Audits and Reporting Requirements

The Federal Reserve supplements these rules for larger institutions. SR 13-1, revised in October 2025, addresses the governance, operational effectiveness, and outsourcing of internal audit at state member banks and holding companies with $10 billion or more in consolidated assets.8Federal Reserve. Supplemental Policy Statement on the Internal Audit Function and Its Outsourcing The OCC’s Comptroller’s Handbook further requires a risk-based approach, with audit frequency and depth scaled to the risk profile of each business line.1Office of the Comptroller of the Currency. Comptrollers Handbook – Internal and External Audits

Independence, Charter, and Reporting Lines

Every bank should maintain a board-approved internal audit charter that defines the purpose, authority, and reporting lines of the function. The charter is not a formality. It establishes the chief audit executive’s unrestricted access to all bank records, personnel, and physical locations, and it protects the audit team from interference by the departments they review. The charter should be reviewed and reapproved periodically, and examiners will ask to see it.1Office of the Comptroller of the Currency. Comptrollers Handbook – Internal and External Audits

Independence hinges on reporting structure. The chief audit executive should report functionally to the audit committee or the full board, which approves the audit plan, budget, and the appointment or removal of the chief auditor. Administrative reporting typically runs to the CEO, covering things like expense approvals and performance evaluations. This dual reporting prevents operating managers from burying unflattering findings. In large banks subject to heightened supervisory standards, the OCC requires the chief audit executive to be positioned no more than one level below the CEO.1Office of the Comptroller of the Currency. Comptrollers Handbook – Internal and External Audits

The audit committee carries its own obligations. For institutions over $5 billion in assets, FDIC regulations define independence with specificity: a director is not considered independent if they served as a consultant, advisor, or employee of the bank within the preceding three years, or received more than $120,000 in direct or indirect compensation from the institution during any twelve-month period in the last three years, excluding director fees.2eCFR. 12 CFR Part 363 – Annual Independent Audits and Reporting Requirements

How an Audit Actually Gets Done

Before any fieldwork, the audit team performs a risk assessment across the bank’s entire audit universe, meaning every department, process, and system that could be audited. Each auditable unit is scored on factors like transaction volume, regulatory sensitivity, time since the last audit, prior findings, and operational complexity. Higher-risk areas get audited more often and in greater depth. The assessment is documented and shared with the audit committee, and it forms the basis for the annual audit plan.

For each planned engagement, auditors gather preliminary documents: prior audit reports (internal and external), organizational charts, policy manuals, and general ledger data. They look for high-volume accounts and unusual fluctuations that signal where testing should concentrate. That information feeds a Risk and Control Matrix, which maps specific process risks to the controls designed to mitigate them. The matrix becomes the backbone of the Audit Work Program, a detailed roadmap that dictates which controls get tested, what sample sizes to use, and what documentation the auditor needs to collect.

The onsite phase executes that program through transaction testing, staff interviews, and direct observation. Auditors use statistical sampling to select transactions from the general ledger data gathered during planning. Sample sizes depend on the confidence level required, the expected error rate, and the size of the population. For a loan file review, a sample might range from a couple dozen files to well over a hundred, depending on portfolio size and risk factors.9Office of the Comptroller of the Currency. Comptrollers Handbook – Sampling Methodologies When errors appear in the initial sample, testing expands to determine whether the problem is isolated or systemic.

Transaction testing runs alongside walkthroughs of operational areas. During a walkthrough, the auditor watches employees do their daily work and compares what actually happens to what the policy manual says should happen. That is where auditors catch the workarounds nobody documented: an approval step skipped to hit a processing deadline, or a segregation-of-duties control undermined because two roles were consolidated during a staffing reduction. Those gaps between written policy and actual practice are among the most common findings.

Reporting Findings and Tracking Remediation

After fieldwork wraps, the audit team drafts a formal report that categorizes each finding by severity, typically high, medium, or low risk. High-risk findings represent significant threats to the bank’s financial condition, regulatory standing, or customer data. A finding that the bank is failing to file required Suspicious Activity Reports, for example, would almost certainly be rated high risk. The draft goes to the management team responsible for the audited area, giving them a chance to respond formally and propose corrective actions.

The final report is submitted to the audit committee and senior management. Federal examiners expect these reports to include an overall opinion on the effectiveness of internal controls, a record of management’s commitments to resolve each finding, and a tracking mechanism for unresolved issues.10Federal Deposit Insurance Corporation. Examination Policies Manual – Internal and External Audit Evaluation Banks generally set tighter remediation deadlines for high-risk findings, though no single federal regulation prescribes a universal timeframe. The audit department tracks management’s progress and performs follow-up testing to confirm corrective actions actually work before closing a finding.

How Examiners Use the Work

Internal audit work does not stay inside the bank. Federal examiners use audit reports and board committee minutes during the preliminary phase of safety and soundness examinations to identify prior concerns and focus their own testing. They evaluate whether the audit committee is actively reviewing internal audit results, whether management is correcting identified weaknesses on a timely basis, and whether the audit function keeps a formal record of unresolved exceptions.10Federal Deposit Insurance Corporation. Examination Policies Manual – Internal and External Audit Evaluation When examiners find that a bank’s own auditors identified a control weakness six months ago and management still has not addressed it, the regulatory conversation gets uncomfortable quickly.

Examiners also assess the quality of the audit work itself: scope and relevance of testing, sampling methodology, and whether findings align with what the examiners see independently. A strong, well-resourced audit function can streamline the examination process. A weak or underfunded one almost guarantees deeper regulatory scrutiny.

Quality Assurance and Outsourcing

Professional standards require every internal audit function to maintain a quality assurance and improvement program. That program has two parts: ongoing internal assessments, which the chief audit executive conducts at least annually and reports to the board, and external assessments performed at least once every five years by a qualified independent assessor. The external review evaluates whether the audit function conforms to applicable professional standards and is achieving its performance objectives.

Banks that lack the staff or expertise to run a full in-house program can outsource or co-source the function, but the board’s responsibility does not transfer with it. Federal interagency policy requires a written engagement letter defining the scope, frequency, cost, and reporting obligations. The vendor cannot perform management functions, make management decisions, or approve operating policies. All audit reports and workpapers remain the bank’s property, and regulators must have full access to them.11Office of the Comptroller of the Currency. Interagency Policy Statement on the Internal Audit Function and Its Outsourcing A publicly held bank or one subject to FDIC Part 363 cannot use the same accounting firm for both its external audit and its outsourced internal audit work, since the firm would effectively be auditing its own conclusions.