Bank internal controls are the policies, procedures, and structural safeguards a bank uses to protect its assets, keep its financial records accurate, and stay in compliance with federal law. Most U.S. banks organize those controls around the COSO framework, layer specific safeguards like segregation of duties and access restrictions on top of it, and rely on internal and external auditors to verify the whole system works. Federal statutes set the floor for what must exist, and regulators grade the result during examinations.
The COSO Framework
The Committee of Sponsoring Organizations of the Treadway Commission published its Internal Control—Integrated Framework in 1992 and updated it in 2013. That 2013 version remains the dominant internal control model at U.S. financial institutions.1Committee of Sponsoring Organizations of the Treadway Commission. Internal Control It breaks internal control into five components, all of which must be present and functioning together.
- Control environment. The ethical tone and professional standards set by the board and senior leadership, including integrity expectations, organizational structure, and reporting lines.
- Risk assessment. Identifying threats to the bank’s objectives, including the potential for fraud, and deciding which risks need active management.
- Control activities. The specific policies and procedures put in place to address identified risks, from transaction approval requirements to technology access controls.
- Information and communication. The systems that move data up, down, and across the organization so people at every level can do their jobs.
- Monitoring activities. Ongoing evaluations and targeted reviews that confirm the other four components are working, and that route deficiencies to the people who can fix them.
The components don’t operate in isolation. A weak control environment undermines even well-designed control activities, and poor information flow leaves risk assessment blind. Regulators evaluate them as a system, not a checklist. Beneath the five components sit seventeen supporting principles that give the framework operational detail; banks use them to design and test individual controls, and examiners use them to structure their reviews.
Safeguards That Prevent Loss
Framework components matter, but the controls that actually stop theft and error are concrete. Segregation of duties splits a transaction across separate people. The basic stages are initiation, approval, recording, and reconciliation, and no one person should handle all of them. When the employee who authorizes a loan is different from the employee who disburses the funds, the bank has built a checkpoint that makes fraud significantly harder to execute without collusion.
Dual control reinforces the same idea for high-risk tasks. Opening a main vault typically requires two codes or keys held by different employees; neither person can complete the task alone. Joint custody works similarly for cash reserves and negotiable instruments, requiring two or more authorized individuals to be present before anyone can access or move them. These aren’t formalities. The vast majority of internal theft at banks involves someone who had both opportunity and unmonitored access.
Cash verification adds another layer. Each teller’s cash should be counted periodically on a surprise basis by an officer or other designated official, and a record of the count must be retained.2Office of the Comptroller of the Currency. Comptrollers Handbook: Cash Accounts The surprise element is the point. Scheduled counts give dishonest employees time to prepare.
Least Privilege for System Access
The digital counterpart to physical safeguards is the principle of least privilege: every user, process, and system gets the minimum level of access needed to do the job and nothing more. A loan processor who needs to read customer credit files shouldn’t also be able to modify account balances. Federal examiners expect banks to apply this across all information systems, limit the number of employees with system-level access, and log the use of any elevated privileges.3FFIEC (Federal Financial Institutions Examination Council). Information Security Booklet
In practice this means separate accounts for privileged access, no shared administrative passwords, disabled default accounts on new software, and periodic reviews of who has access to what. When someone changes roles or leaves, their access profile should be updated immediately. Stale access rights are one of the most common audit findings and one of the easiest to exploit.
IT and Cybersecurity Controls
Technology controls have become as important as physical safeguards. The FFIEC’s Information Security Booklet lays out expectations for logical access controls, encryption, and monitoring during IT examinations.3FFIEC (Federal Financial Institutions Examination Council). Information Security Booklet Banks must encrypt customer information both in transit and at rest, with encryption strength matched to the sensitivity of the data. Key management, meaning how encryption keys are generated, stored, rotated, and retired, is a frequent area of examiner scrutiny because a mishandled key can render encryption useless.
The Gramm-Leach-Bliley Act’s Safeguards Rule adds legally binding requirements on top of that guidance. Banks must maintain a written information security program overseen by a designated qualified individual, implement multi-factor authentication for anyone accessing information systems, conduct annual penetration testing and vulnerability assessments at least every six months, and maintain an incident response plan.4eCFR. Standards for Safeguarding Customer Information (16 CFR Part 314) The qualified individual must report in writing to the board at least annually on the status of the program and any material issues.
Business continuity planning intersects with IT controls. The FFIEC doesn’t mandate a specific testing frequency but expects banks to exercise and test their continuity plans at appropriate intervals, whenever new risks emerge, or when significant operational changes occur. Scale and frequency should match the institution’s size and complexity.
BSA and AML Internal Controls
Bank Secrecy Act compliance is one of the most consequential control areas. Examiners evaluate whether the bank’s internal controls are designed to ensure ongoing compliance with anti-money-laundering requirements, whether they incorporate the bank’s own risk assessment, whether they provide for continuity when staff or operations change, and whether they support oversight of the technology systems that back compliance.5FFIEC BSA/AML Examination Manual. Assessing the BSA/AML Compliance Program – BSA/AML Internal Controls
The FFIEC specifically expects BSA internal controls to incorporate dual controls and segregation of duties wherever feasible. The classic example: the employee who completes a suspicious activity report shouldn’t also decide whether to file it. The board of directors bears ultimate responsibility for maintaining an adequate BSA control system, and its sophistication should match the bank’s size, complexity, and risk profile.
Third-Party Vendor Oversight
Banks increasingly rely on outside vendors for payment processing, cloud computing, loan servicing, and other core functions. Federal regulators treat those relationships as extensions of the bank’s own operations, which means internal controls must extend to cover vendor risk. Interagency guidance published in 2023 establishes a five-stage life cycle for managing third-party relationships: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination.6Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management
Most of the internal control work happens during due diligence. Before signing a contract, the bank should evaluate the vendor’s financial stability, information security practices, regulatory compliance record, disaster recovery capabilities, and reliance on its own subcontractors. Contracts should include audit rights and require remediation of identified problems. Once the relationship is active, ongoing monitoring confirms the vendor continues to meet its obligations and that its controls remain adequate. Examiners will downgrade a bank’s ratings when they find that management has outsourced a function without maintaining oversight. The activity can be outsourced; the responsibility cannot.
Internal and External Audit
Two audit functions verify that internal controls work. They serve different masters and look at different things, but both ultimately report to the board of directors.
Internal Audit
Internal auditors operate continuously from inside the bank, reviewing whether existing procedures are adequate and whether employees are following them. They report directly to the audit committee of the board, not to the management team whose work they’re evaluating. That reporting line is essential. An internal audit function that reports to the CFO has an obvious conflict of interest when it finds problems in the finance department.7Bank for International Settlements. The Internal Audit Function in Banks The Basel Committee states that internal audit should have sufficient authority, independence, resources, and access to the board to carry out its mandate.
Internal auditors assess compliance across the organization, test whether controls are designed and operating effectively, and flag deficiencies for remediation. Their work feeds directly into the board’s understanding of institutional risk. The FDIC expects examiners to evaluate whether the board or audit committee actively reviews the effectiveness of the internal audit function, including reviewing audit reports and meeting regularly with auditors.8Federal Deposit Insurance Corporation. Internal and External Audit Evaluation
External Audit
External audit is an annual examination by an independent accounting firm. The external auditor opines on whether the bank’s financial statements are fairly presented and, for larger institutions, whether internal controls over financial reporting are effective. The Sarbanes-Oxley Act requires management of publicly traded banks to include an annual assessment of internal control effectiveness in their filings, and the external auditor must separately attest to and report on that assessment.9U.S. Securities and Exchange Commission. SEC Proposes Additional Disclosures, Prohibitions to Implement Sarbanes-Oxley Act Smaller public companies that qualify as non-accelerated filers or smaller reporting companies with annual revenues below $100 million are exempt from the auditor attestation requirement, though they still must include management’s own assessment.
Audit Committee Independence
The audit committee sits between the board and both audit functions, and its composition is heavily regulated for publicly traded banks. Every member must be an independent director, meaning they cannot accept consulting or advisory fees from the institution beyond their board compensation and cannot be an affiliated person of the bank or its subsidiaries.10eCFR. 17 CFR 240.10A-3 – Listing Standards Relating to Audit Committees Public companies must also disclose whether at least one audit committee member qualifies as a financial expert, meaning someone with an understanding of accounting principles, financial statements, internal controls, and audit committee functions, gained through direct experience as a senior financial officer, accountant, auditor, or supervisor over those functions. If the bank has no financial expert on the committee, it must disclose that fact and explain why.11U.S. Securities and Exchange Commission. Disclosure Required by Sections 406 and 407 of the Sarbanes-Oxley Act of 2002
How Control Deficiencies Are Classified
When auditors find problems, the severity of the finding determines who needs to know and how urgently. The SEC defines two levels that matter most for public institutions.
A significant deficiency is a weakness in internal control over financial reporting serious enough to merit the attention of those responsible for oversight of the bank’s financial reporting. It doesn’t necessarily mean a misstatement has occurred, but it signals a gap worth addressing.12U.S. Securities and Exchange Commission. Definition of the Term Significant Deficiency (Release Nos. 33-8829; 34-56203)
A material weakness is more severe. It means there is a reasonable possibility that a material misstatement in the financial statements could go undetected. When management or auditors identify a material weakness, the bank cannot conclude that its internal controls are effective. For publicly traded institutions, this finding must be disclosed in the annual report and can trigger regulatory scrutiny, rating downgrades, and market consequences. The practical difference between the two categories often comes down to judgment about likelihood and magnitude, which is why the SEC left flexibility in the definitions rather than imposing rigid numerical thresholds.
Federal Statutes Behind the Requirements
Several federal statutes impose internal control obligations on banks. The requirements scale up based on the institution’s size and whether its securities are publicly traded.
Securities Exchange Act, Section 13(b)
Any company with securities registered under the Exchange Act, including publicly traded banks, must maintain books and records that accurately reflect its transactions and a system of internal accounting controls sufficient to provide reasonable assurance that transactions are properly authorized, recorded, and reconciled against actual assets.13Office of the Law Revision Counsel. 15 USC 78m – Periodical and Other Reports The mandate is broad: transactions must happen only with management’s authorization, get recorded in a way that supports accurate financial statements, and access to assets must be limited to authorized personnel. Violations can result in civil penalties and SEC enforcement actions.
Sarbanes-Oxley, Sections 302, 404, and 906
SOX layers additional requirements on top of the Exchange Act. Section 404 requires management to include an assessment of internal control effectiveness in each annual report, and for larger filers, an independent auditor must attest to that assessment.14U.S. Securities and Exchange Commission. Sarbanes-Oxley Section 404 Costs and Remediation of Deficiencies The criminal teeth come from Section 906, which requires CEOs and CFOs to certify that their periodic reports comply with the law and fairly present the company’s financial condition. A knowing false certification carries up to a $1 million fine and 10 years in prison. A willful false certification doubles the exposure to $5 million and 20 years.15Office of the Law Revision Counsel. 18 USC 1350 – Failure of Corporate Officers to Certify Financial Reports
FDICIA for Non-Public Banks
Banks that aren’t publicly traded still face internal control mandates if they’re large enough. The Federal Deposit Insurance Corporation Improvement Act, implemented through 12 CFR Part 363, applies to any insured depository institution with at least $1 billion in consolidated total assets. At that threshold, the bank must engage an independent public accountant and prepare annual financial statements.16eCFR. 12 CFR Part 363 – Annual Independent Audits and Reporting Requirements
At $5 billion in assets, the obligations ratchet up. Management must provide a written assessment of the effectiveness of internal controls over financial reporting, identify the framework used (typically COSO), disclose any material weaknesses, and cannot conclude that controls are effective if any material weakness exists. The external auditor must separately examine and attest to management’s assessment. This mirrors the SOX 404 regime for banks that never went public but grew large enough to pose systemic risk.
How Examiners Rate Internal Controls
Federal regulators examine insured banks on a recurring cycle. The baseline is a full-scope, on-site examination at least once every 12 months. Smaller, well-run institutions can qualify for an extended 18-month cycle if they have less than $3 billion in assets, are well capitalized, received top composite and management ratings at their last exam, aren’t under any enforcement order, and haven’t undergone a change in control during the prior year.17eCFR. 12 CFR 337.12 – Frequency of Examination The FDIC can examine more frequently if it sees a reason to.
Examiners evaluate each bank using the CAMELS rating system, which scores six components: Capital adequacy, Asset quality, Management, Earnings, Liquidity, and Sensitivity to market risk. Internal controls directly affect the Management component, which evaluates the board’s and management’s ability to identify, measure, monitor, and control institutional risks. The FDIC explicitly considers the adequacy of internal controls and audits as a factor in assigning the Management rating.18Federal Deposit Insurance Corporation. Section 1.1 – Basic Examination Concepts and Guidelines
A Management rating of 1 indicates strong risk management with risks consistently and effectively controlled. A rating of 3 signals less than satisfactory practices, with significant risks potentially going unmanaged. At a 4 or 5, the FDIC considers risk management deficient or critically deficient, potentially threatening the institution’s viability. Poor internal controls can drag down the Management component, which pulls down the composite CAMELS rating. A weak composite rating can restrict the bank’s ability to expand, increase its deposit insurance premiums, and trigger formal enforcement proceedings.