Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk Management Program · CoreTrack
1Risk, Treasury & Financial Control
iRisk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
iiEnterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
iiiRisk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
ivCredit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
vMarket Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
viLiquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
viiOperational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
viiiRisk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
ixTreasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
xFinancial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
xiOperational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

Control Assurance: Independent Confirmation That Controls Work

Control assurance is an independent confirmation that a stated control was designed to meet a stated objective and operated as stated throughout a stated period. The confirmation is given by somebody who does not run the control, rests on evidence rather than opinion, and ends in a written conclusion with a name at the bottom. Assurance never makes a control work. Assurance tests whether the claim that a control works survives.

One distinction carries this whole guide, and it is worth reading twice. A controlSomething an institution does on purpose so that a specific thing does not go wrong. is a thing somebody does. A rating is somebody's opinion of whether that thing works. Control assurance is a test of the rating, not a second opinion about the control. Once assurance is seen to take a claim as its subject rather than the work itself, every other rule in this guide stops being a rule to be remembered and becomes something that could have been worked out: why the person giving it cannot be the person making the claim, why it needs evidence and a sample rather than a conversation, and why it can only ever speak about a stretch of time that has already ended.

What does control assurance actually take as its subject?

Start with a shop on a busy street. The shape is identical and the words are easier. The shutter has to be locked every night. The locking is the control. The owner says, when asked, that it is locked every night without fail, and that statement is a rating: an opinion about the control, offered by the person responsible for it. Now imagine the insurer asks a third person to go and look at the closing register and the camera recording for a stretch of nights chosen at random. The third person is not checking the shutter. The third person is checking the sentence the owner said about the shutter. Everything else follows from that one move.

The move is easy to miss because both things end up as words on paper. The owner's sentence and the third person's sentence read almost identically, and a reader who sees only the output cannot tell which is which. The confusion is not a failure of attention. The confusion is the structural problem the whole practice exists to solve, and it is why the discipline attaches so much weight to who wrote a sentence and on what basis, rather than to how confident the sentence sounds.

A control, an opinion about it, and a test of the opinion THE CONTROL Somebody reconciles the valuation feed an opinion is formed THE RATING The team says it happened every day the test lands here THE ASSURANCE WORK Somebody else tests the days, on evidence and writes a conclusion with a name on it What somebody actually does, and does again every time the trigger comes round. An opinion that the control above works. Dated and signed, and still an opinion. Assurance never touches the control itself. It takes the opinion as its subject and asks whether evidence supports it.
The arrow from the assurance work points at the opinion and not at the control, which is why nothing an assurance team does can make a control operate better and why every rule about who may give it follows from where that arrow lands.

Inside Vindhya Commercial Bank Limited, an invented bank of Rs 96,000 crore whose figures are illustrative throughout, the same three objects are stacked in the same order across nine named processesA named sequence of work with a start, an end and an owner, here numbered PR1 to PR9.. Somebody in the business reconciles the collateral valuation feed before the loan book is marked. The reconciliation is the control. The business then records, in its own annual self assessmentThe exercise in which the people who run a set of controls rate those same controls themselves, on their own cycle., that the control operated effectively. The record is the rating. Somebody in a different reporting line then pulls the evidence for a set of days and tests whether that record survives. The test is the assurance work. All three exist at once, all three produce a sentence, and only the third one has been tested by anybody who could afford to say no.

The distinction rules out a great deal immediately. Assurance does not touch the control, so it cannot fix anything. Assurance cannot make a weak control strong, cannot shorten a queue, cannot stop a feed going stale. Expecting assurance to improve an institution directly means it has quietly been confused with the control itself. Assurance can change what the institution believes about itself. The change is a slower and stranger kind of usefulness, and it is the only kind on offer.

What four things does an assurance conclusion always name?

An assurance conclusion is a paragraph, not a score, and the paragraph has four fixed parts. The paragraph names the control exactly. The second part is the objective the control exists to meet. The third is the period over which the control is said to have operated. The fourth is the evidence the conclusion rests on. A statement missing any one of those four parts is a description of an intention rather than a confirmation of anything, and it cannot be relied on for a decision.

Each part earns its place by what goes wrong without it. Without the control named exactly, nobody can tell later which of the 214 things at this bank was tested, and two people reading the same conclusion can walk away believing different work was done. Without the objective, there is no judging whether the control was the right control at all: a signature collected reliably every day is worthless if the thing it was meant to prevent could happen anyway. Without the period, effective means nothing. A control can be flawless on the day somebody visits and absent for the eleven working days before it. Without the evidence, the sentence is an assertion by a second person rather than the first. A change of author is not a change of instrument.

Four parts, and the same sentence with two of them missing Identical shape on both sides. Only the content of the rows differs. A CONFIRMATION 1 THE CONTROL The valuation feed is reconciled and signed before the loan book is marked. 2 THE OBJECTIVE So that no advance is carried at a stale value. 3 THE PERIOD Throughout months 1 to 12. 4 THE EVIDENCE Tested on a sample of days drawn across the whole period, listed in the working papers. A DESCRIPTION 1 THE CONTROL The collateral valuation control is operating effectively. 2 THE OBJECTIVE implied at best, and never written down 3 THE PERIOD not stated 4 THE EVIDENCE not stated Both sentences are true. Only the one on the left can be relied on for anything.
The right hand sentence names a control and reads perfectly well out loud at a meeting, and because it states no period and no evidence it survives being read out even in a year when the control failed for 11 working days.

The four parts are also what makes a conclusion checkable by somebody who was not involved. A person handed the left hand paragraph can go and ask for the working papers, count the days in the sample, notice that the sample never touched month 10, and form their own view of whether the conclusion is strong. A person handed the right hand paragraph has nothing to pull on. Assurance is only useful to the extent that a stranger can interrogate it, and the four parts are exactly the handles a stranger needs. Writing rather than speaking follows from the same requirement: a sentence that has to survive a stranger reading it in six months has to be fixed in place first.

Try it out

A conclusion reads, in full: the collateral valuation control is operating effectively. What is missing?

Breaking Into Quants Bootcamp — Fin Maverick

Who are the three lines, and whose model is that?

Almost everybody organises this with the three linesThe Institute of Internal Auditors' 2020 description of who takes risk, who challenges it and who independently confirms it. model. The model belongs to the Institute of Internal Auditors, restated by them in 2020. A reader who does not know whose idea it is cannot go and read the original, so the attribution is part of the term and belongs in the sentence that uses it. The three lines model is a description of an arrangement rather than a rule imposed by anybody. No supervisor obliges an institution to draw itself in exactly three layers, and institutions that do not still have to answer the same question about who confirms what.

Inside Vindhya Commercial Bank Limited the three jobs sit like this. The first line is the business itself, taking the risk and running the 214 key controls day to day, and it is also the line that rates those controls in its own self assessment. The second line is the risk and compliance function under Sunanda Ravikumar. The function sets the nine policies PL1 to PL9 and challenges how the first line goes about its work. The third line is internal audit under Rustom Batliwala. Internal audit reports to committee G3, the audit committee, and confirms the first line and the second. The third line exists for one reason: neither of the first two can confirm itself, and the arrangement is built to make that impossibility visible rather than to imply that anybody is untrustworthy.

Three different jobs, and only one of them is independent COMMITTEE G3 FIRST LINE The business that takes the risk. Runs the 214 key controls. Rates them in its own self assessment. SECOND LINE Risk and compliance, under Sunanda Ravikumar. Sets policies PL1 to PL9. Challenges how the first line runs the controls. THIRD LINE Internal audit, under Rustom Batliwala. Reports to committee G3. Confirms the first line and the second. the second line challenges the first the third line confirms both of them
The first line runs the 214 key controls and rates them, the second line sets the policies and challenges how they are run, and only the third line reports somewhere neither of the other two controls, which is what makes its conclusion a confirmation rather than a further opinion.

One warning about the picture. Three lines is a description of jobs, not of job titles, and an institution can have all three jobs done properly with two departments or badly with five. The model gives a question to ask of any arrangement: for a given stretch of work, who does it, who challenges it, and who confirms it from somewhere the first two cannot reach. If two of those three answers are the same name, that is the thing worth looking at, and no organisation chart will say so.

Try it out

Whose description is the three lines model, and when was it restated?

Derivatives Foundation Bootcamp — Fin Maverick

Why is a team rating its own control not assurance?

The next sentence is easy to hear as an insult. Read it carefully. A team rating its own control produces a rating, and a rating is not a confirmation, and none of that is an accusation that anybody lied. Consider a person counting their own steps on a walk. There is no cheating, and the number is genuinely believed. The walker also chose when to start counting, decided what counts as a step, and would be the one who has to explain a number that came out badly. Nothing about that requires bad faith to produce a number that leans one way.

Each of the three structural reasons survives even when everybody involved is careful and honest, so each is worth naming separately. First, the rater chose the scope: normal days, one-off exceptions, gaps already fixed. Every one of those calls was theirs. Second, the rater carries the consequence: a rating of not effective becomes a findingA written record that a tested control did not do what was claimed for it. against their own work, and a person who has to live with an answer is not the ideal person to reach it. Third, the rater has no separate evidence trail: they know what usually happens. Knowing what usually happens is a different and weaker thing than a record of what did happen on named days.

Two readings of one year, produced by opposite processes Identical rows. Only the process behind each column differs. THE SELF ASSESSMENT INDEPENDENT TESTING WHO RATES The people who run the controls People who do not run them WHAT IT RESTS ON What they believe about their own work Evidence they gathered and kept WHAT IT CAN FIND Only what it already suspects Things nobody had flagged THE DENOMINATOR All 214 key controls All 214 key controls THE ANSWER 196 effective, 91.6 per cent 172 effective, 80.4 per cent Both answers are stated on the same 214 controls, which is the only way the two can be put side by side.
Two columns of identical shape reach 91.6 per cent and 80.4 per cent on the same 214 controls, and the only difference between them is who produced the number and whether anybody outside the work looked at evidence.

The two percentages carry a trap under them that has caught careful readers before. The independent work at this invented bank tested design on all 214 controls and then tested operation only on the 198 that survived the design test, finding 172 of those 198 effective. Quoting that as 86.9 per cent and setting it beside the business's 91.6 per cent is tempting, and it would make the gap look like a rounding difference. The two figures sit on different denominators and putting them side by side is simply wrong. Stated like for like, both on the full population of 214 key controls, it is 91.6 per cent against 80.4 per cent, and the honest gap is 11.2 percentage points rather than the comfortable 4.7 the mismatched pair suggests.

Try it out

A team rates its own control effective, writes down the evidence it looked at, and has its manager sign the rating. Is that assurance?

What does independent mean here, and how independent is enough?

IndependenceA property of the person giving assurance: they do not run the control, do not report to whoever does, and cannot have their conclusion edited by them. is a property of a person and their reporting arrangements, not a property of a method. Independence read this way is the most useful idea available for judging a real institution. The reading turns a vague word into three questions that can be asked out loud and answered. Do they run the control themselves? Do they report to whoever does? Can that person edit the conclusion before it goes anywhere? Any one yes turns the output back into a rating, however careful the testing that produced it was.

Watch how sharply the third question bites. Somebody can sit in a completely separate function, gather beautiful evidence, and reach a hard conclusion, and then hand a draft to the head of the business who then asks for the wording to be softened before it goes to a committee. The testing was independent. The conclusion is not: the person it was about edited it. The editing is why an internal audit function's reporting route to committee G3 matters more than the seating plan: the route is what makes the last question answerable with a no.

Three questions, and any one yes makes it a rating Do they run the control themselves? yes no Do they report to whoever does? yes no Can that person edit the conclusion? yes no The output is a rating. It can still be careful, evidenced and honest. It is simply not a confirmation, because the person giving it would have to report a failure of their own work to give a different answer. No amount of method repairs that. This is assurance.
Three yes or no questions about the person rather than the method decide whether an output is a rating or a confirmation, and a single yes at any of the three sends the result into the red panel no matter how good the testing was.

How independent is enough, then? Enough is when all three answers are no for the specific conclusion in question, and the honest answer is that this is a threshold rather than a scale. There is no such thing as slightly independent for the purpose of relying on a sentence. The weight a conclusion carries once it clears the threshold does vary, and vary a lot, and the weight depends on the evidence and the sample rather than on the person. Independence is what makes a conclusion admissible; the evidence is what makes it strong.

Is a control the whole of internal control?

No, and the reason is worth twenty seconds because it bounds what any amount of control assurance can be worth. The five component structure of internal control belongs to the Committee of Sponsoring Organizations of the Treadway Commission, published in 1992 and updated in 2013, and control activities are one of those five components. The others describe the environment people work in, how the institution decides what could go wrong, how information moves and how anybody keeps watch over the whole arrangement.

The practical consequence is a limit rather than a definition. When somebody at this invented bank tests the 214 key controls and reaches a conclusion, they have tested one component of five. Four fifths of what the structure describes was never on the test sheet, so an institution can pass every control activity test and still have a weak internal control system. None of that is a criticism of control testing. The limit is the reason a conclusion about controls is always narrower than the sentence people would like to read out of it, and why an audit committee that hears a control conclusion and relaxes about internal control generally has quietly widened the claim.

Attribution here is not decoration either. Anyone can go and read the original structure, and a reader who is only ever told about five components without being told whose five they are has been handed a piece of furniture instead of an idea they can check.

What is a key control, and who decided that 214 of them are key?

A key controlA control the institution has decided it would notice the absence of, so the one it tests. is not a special kind of control. A key control is an ordinary control that somebody put on a list. There was never going to be enough time, money or attention to test everything anybody does. Vindhya Commercial Bank Limited runs 214 of them across nine named processes, PR1 to PR9, from account opening at one end through to financial reporting and close at the other. The number 214 is a decision, not a measurement. Nobody discovered that 214 controls were key. Somebody, at some point before any evidence existed, drew a line.

Consider a household with one salary coming in. There are dozens of small habits keeping the month intact: checking the balance before a big purchase, keeping the rent transfer on a standing instruction, keeping a buffer nobody touches. Naming the three whose absence would be noticed within a week is easily done, and those three are the household's key controls. The other habits still matter. The remaining habits are simply not the ones to watch when only three can be watched. The word key does not mean important. The word means chosen, and chosen before anybody looked.

How a population of 214 was chosen, and what happened to it the chosen edge everything people do not counted anywhere in the record 214 chosen as key 214 198 passed design 16 198 172 effective 26 16 172 The 42 findings are exactly the 214 less the 172, being 26 operating failures and 16 design gaps. Nothing outside the 214 was ever going to be found, and this bank's record does not say how many things that leaves out.
The top bar has no number against it because this invented bank never counted how many things people do, and every conclusion below it is bounded by a line somebody drew across that uncounted population before any testing began.

Read downward, the bars show the population shrinking twice, for two different reasons. Design was tested on all 214 controls and 198 passed, so 16 carried a design gap: they would not have met their objective even if somebody performed them perfectly every single day. Operation was then tested on the 198 that survived, and 172 passed, so 26 controls were well designed and did not happen reliably. End to end, 172 of the 214 key controls were effective, or 80.4 per cent, and the 42 that were not are exactly the 16 design gaps plus the 26 operating failures. The two shortfalls need completely different repairs: a design gap is fixed by changing the control, an operating failure by making the control actually happen.

Now look back at the top bar, the one with no number on it. The record at this invented bank does not say how many things people do in total, so nobody can state what share of the real population the 214 represents. The missing number is not sloppiness in the example, it is the ordinary condition. Every assurance conclusion is bounded by a choice of population that was made before any evidence existed, and the choice is almost never quoted alongside the result. When somebody states that 80.4 per cent of controls were effective, the useful follow up is not about the 80.4. The follow up is: effective out of what, and who picked it.

Try it out

Why does an institution call 214 controls key rather than testing everything people do?

Try it out

Independent testing at this invented bank raised 42 findings. The business had already said 18 controls were not working. Before the arithmetic: can the second number explain away the first?

Debt Capital Markets Bootcamp — Fin Maverick

What did the two readings of this bank's year actually produce?

Two readings of one year exist inside Vindhya Commercial Bank Limited, and both of them are honest. The first is the business's own. Its self assessment covered all 214 key controls and rated 196 of them effective, or 91.6 per cent, leaving 18 that the business itself said were not working. The second is independent. Testing produced 42 findings, being the 16 design gaps and the 26 operating failures already met above, one finding written per failed control.

What was readWho produced itResultOn 214 controls
The self assessmentThe first line, rating its own controls196 rated effective, 18 rated not effective91.6 per cent
Independent testing, designTesters outside the first line198 designed effectively, 16 design gaps92.5 per cent
Independent testing, operationTesters outside the first line, on the 198 that passed design172 operated effectively, 26 operating failures80.4 per cent
The 42 findingsIndependent testing16 design gaps plus 26 operating failures19.6 per cent

Held up together, the two readings leave something missing. The bank's record does not say how many of the 18 controls the business flagged are among the 42 findings that testing raised. Nobody measured the overlap. The record does not need to: the overlap is bounded by arithmetic rather than by evidence. 196 controls rated effective plus 42 findings is 238. There are only 214 controls in the population. So at least 238 less 214, being 24 findings, must sit on controls the business had rated effective, no matter how the unmeasured overlap turns out.

196 rated effective plus 42 findings, against 214 controls The 42 findings laid on the end of the 196 the business rated effective 214 controls exist 238 196 rated effective 18 24 18 at most 24 at least 196 plus 42 is 238. There are only 214 controls. So at least 24 of the findings landed on controls the business had already rated effective, whatever the overlap turns out to be.
The 42 findings are laid on the end of the 196 controls the business rated effective, and because the population stops at 214 the last 24 of those findings have nowhere to sit except on controls that had already been signed off as working.

Look at the same number from the other direction and it lands in the same place. The business rated 196 controls effective and independent testing found 172 effective, and 196 less 172 is 24. The floor of 24 findings on controls rated effective and the like for like gap of 24 controls between the two readings are one fact reached by two routes, not two findings that happen to agree. As a share, those 24 findings are 11.2 per cent of the 214 key controls. The same 11.2 percentage points separate 91.6 per cent from 80.4 per cent. The arithmetic keeps closing on itself. Closing on itself is a good sign that nothing has been smuggled in.

State the result carefully. The careful version is stronger than the dramatic one. The floor is not a claim that the business was wrong about 24 controls in some blameworthy way, and it is not an estimate of how much the business did not know. The floor is measured: at least 24 findings, and possibly as many as all 42, fell on ground the business believed was solid. Unlike an estimate, a floor carries no assumption anybody can dispute it away with, so a floor is the most useful thing an argument can put in front of a committee.

Try it out

The business rated 196 of 214 controls effective and independent testing raised 42 findings. Before moving the control below: what is the smallest number of findings that could possibly be news to the business?

Play with it

Try to push the count of new findings below 24 by moving the unmeasured overlap

One variable moves: k, how many of the 18 controls the business itself rated not effective also carry one of the 42 findings. Everything else is held: 214 controls, 196 rated effective, 42 findings, one finding per failed control. The overlap k was never measured at this invented bank and appears nowhere in its record. The absence of k is the entire reason the control is here. Drag it as far as it will go and watch where the block stops.

0 of 1818 of 1818 of 18
Where the 42 findings sit inside the 214 controls The business's reading 196 rated effective 18 Left of the divide: 196 controls the business rated effective. Right of it: 18 it rated not effective. Where the 42 findings actually landed 24 18 the floor of 24 the 214 controls end here Whatever the overlap, the block never stops right of the dashed line. Overlap set to 18 of the 18 controls the business rated not effective. Every count belongs to one invented bank.
HELD CONSTANT
42 on 214
FINDINGS NEW TO THE BUSINESS
24
SHARE OF THE 42 FINDINGS
57.1 per cent
SHARE OF THE 214 CONTROLS
11.2 per cent
With 18 of the 18 controls the business itself flagged also carrying a finding, 24 of the 42 findings landed on controls the business had rated effective, being 57.1 per cent of the findings and 11.2 per cent of the 214 controls. Even if all 18 controls the business flagged are among the findings, 24 findings still landed on controls it had rated effective.
Educational illustration. Three readings in plain words, so they survive without the control: at k of 0, where none of the flagged controls carries a finding, all 42 findings are new to the business, being 100 per cent of them. At k of 9, 33 are new, being 78.6 per cent. At k of 18, the largest overlap arithmetically possible since the business flagged only 18 controls, 24 are new, being 57.1 per cent of the 42 findings and 11.2 per cent of the 214 controls. The count never falls below 24 whatever k is. The overlap k was never measured and is not in this invented bank's record; the control exists to show that the conclusion does not depend on it.

Reading the self assessment result as the assurance result

Both numbers are a percentage of controls working. Both arrive in the same committee paper, in the same month, set in the same typeface. One of them is 91.6 per cent and the other is 80.4 per cent. The one that travels is 91.6 per cent: it is the biggest, it is ready earliest, and it is the most comfortable thing anybody in the room could say out loud. The travelling figure is also the only one of the two that nobody outside the work ever tested.

The cost is exact and it is the floor established above. At least 24 of the 42 findings sat on controls inside that 91.6 per cent, so the figure that reads as reassurance is precisely the figure concealing the findings. Committee G3, the audit committee, receives the findings and the year's assessment. The committee is not given a reason to ask which of two numbers in front of it was produced by the people being reported on.

Nobody falsified anything, and that matters for how the situation should be handled. The business rated what it believed, and belief is not the same instrument as evidence. The failure is not in the 91.6 per cent at all. The failure is in a committee receiving one number where two exist, with nothing in front of it to say which one was tested and which one was asserted.

One number reaches the committee, and it is the untested one MONTHLY PAPER TO COMMITTEE G3 CONTROLS EFFECTIVE 91.6 per cent Who produced the figure: not stated. TESTED FIGURE the independently tested figure, absent The figure that travels is the biggest, the earliest and the most flattering. It is also the only one of the two that nobody tested. At least 24 of the year's 42 findings sit inside it. Nobody falsified anything. The business rated what it believed, and belief is not the same instrument as evidence.
The paper carries a large comfortable figure with no author against it and an empty space where the tested figure would sit, which is what lets one of two correct numbers reach a committee while the other one never leaves the working papers.
Try it out

The audit committee receives one figure: 91.6 per cent of controls effective. What should it ask first?

Risk Management Program Bootcamp — Fin Maverick

Where do the expectations on an Indian bank and an Indian board come from?

Everything so far is jurisdiction free. Nothing about testing a claim on evidence is Indian, and an institution anywhere would recognise the four parts of a conclusion and the three questions about independence. The duty is not jurisdiction free: who is obliged to report on internal control, to whom, in what form, and with what independent opinion attached. The duty comes from a statute and from professional standards.

A section number, a threshold, an applicability test or an effective date is exactly the kind of thing that changes, and a statement carrying one becomes wrong quietly, without anybody noticing that it has. Naming a body and a duty stays true. Knowing where to look is also a skill that survives the next amendment. A remembered fact does not.

Attribution and jurisdiction

Where the borrowed models come from, and where an Indian institution's duties sit

The three lines used in this guide are the model of the Institute of Internal Auditors, restated by them in 2020, and the attribution belongs in the sentence that uses it rather than in a footnote at the bottom. The five component structure of internal control belongs to the Committee of Sponsoring Organizations of the Treadway Commission, published in 1992 and updated in 2013, and the same rule applies to it. Neither is a rule anywhere. Both are descriptions that institutions and their supervisors found useful enough to keep using.

The set of duties an Indian company and an Indian bank carry is not jurisdiction free. The Companies Act places a reporting duty on the board and on the auditor in respect of internal financial controls, and the text of it, who it applies to, who is exempt and the form the report takes all sit with the Ministry of Corporate Affairs at mca.gov.in. The assurance standard and the guidance note that govern how work of this kind is performed and reported sit with the Institute of Chartered Accountants of India at icai.org. The additional rules binding a bank, including its risk management arrangements and the standing of its internal audit function, sit with the Reserve Bank of India at rbi.org.in.

Section numbers, rule numbers, thresholds, applicability tests, exemptions, ratios, sampling minimums and effective dates all change by amendment, and none of them should be carried away from a worked illustration. The current text sits with the bodies named above and has to be read there.

Try it out

Which body holds the text of the Indian reporting duty on internal financial controls?

Value at Risk and What It Hides — free micro-course from Fin Maverick

What can control assurance never tell?

Three limits sit inside every assurance conclusion ever written, and none of them is a defect. The three limits are the instrument itself. An assurance conclusion is a statement about a stretch of time that has already closed, reached from a sample rather than from everything, by somebody who was not standing there while the work happened. Read that sentence slowly. Each of its three clauses removes a different thing people want the conclusion to give them.

Take the period first. A conclusion that 172 of the 214 key controls at this invented bank operated effectively describes a year that has ended. The conclusion is in the past tense on purpose. Nothing in it is a statement about this morning, and a control that was effective through twelve months can stop working on the first day of the thirteenth without making the conclusion wrong. The collateral valuation control in process PR3 sits inside that same population of 214 and then failed for 11 working days in month 10, with no monitoring control noticing. The two facts are exactly the shape of the problem: the conclusion and the failure are not in contradiction, they are answers to different questions.

Take the sample next. Testing looks at named days and named items, not at every occurrence. Looking at every occurrence would cost more than the control is worth. The trade is sensible and it has a price: a clean sample is consistent with a control that fails sometimes, and the rarer the failure the larger the sample would have to be before a clean result meant much. The third limit is the one people forget. The tester was not there. The tester is reading records made by other people, and a record is a claim too. Assurance reduces how much is taken on trust, and it never gets that quantity to zero.

What the conclusion covers, and what it says nothing about the period the conclusion covers, now closed each mark is a day somebody actually looked at; the gaps are days nobody saw ? 1 2 3 4 5 6 7 8 9 10 11 12 today month 10: 11 working days The conclusion is in the past tense on purpose, and no part of it reaches right of the last tick. The control that failed in month 10 sits inside the same 214 the conclusion is about.
The bracket closes at month 12 and the marks under it are days somebody looked at rather than a continuous line, so a control failing for 11 working days in month 10 can sit inside the same period the conclusion describes without the conclusion being wrong.

There is one more thing assurance cannot tell, and it is the quietest of the four. Assurance cannot speak to anything outside the population somebody chose. Nothing beyond the 214 key controls was on the sheet, so nothing beyond them was ever going to appear in a finding, however badly it was working. A conclusion is bounded above by the evidence and bounded below by a decision taken before any evidence existed, and only one of those two bounds is ever printed alongside the result.

Try it out

Internal audit concludes that 172 of 214 key controls operated effectively last year. What does that establish about this morning?

Value at Risk and What It Hides teaches you to compute value at risk three ways, interpret the figure, and say precisely what it refuses to describe.

How does somebody outside an institution ever use this?

Most readers will never test a control. Readers will read conclusions that other people reached, and that is where the habit below pays for itself. Somebody lending to a business, analysing one, sitting on a board of a small company or simply choosing where to put a deposit is constantly handed sentences of the form the control is working. The single most useful habit available is to ask two things of any such sentence: which of the four parts it actually names, then which of the three independence questions its author would have to answer no to.

The habit is easiest to practise on small claims, where the shape is identical and the stakes are low. A landlord says the building's fire equipment is checked. Which equipment, checked against what standard, over what period, and evidenced how, and is the person making the claim the person who does the checking? A supplier says its quality process is reliable. A school says its transport arrangements are safe. In every case, four parts and three questions. In most cases the sentence names one part and answers yes to at least one question, and that fixes exactly how much weight it can carry.

Now scale it up. Somebody reading Vindhya Commercial Bank Limited from outside, with its Rs 96,000 crore of assets, will see a statement that internal controls were effective and will be tempted to treat it as a summary of how well run the institution is. It is not. The statement is a past tense conclusion, on a sample, over a chosen population of 214 controls, about one of the five components of internal control. The right response to a control conclusion is not more confidence or less confidence, it is a sharper question: effective over what period, out of what population, tested by whom, and who could have edited the answer. Four questions, thirty seconds, and they work on a bank, a supplier and a landlord in exactly the same way.

One habit is worth taking away above all others. When two figures about the same thing arrive together, ask which one somebody tested before asking which one to believe. At this bank the two figures were 91.6 per cent and 80.4 per cent, and the difference between them was not accuracy. The difference was authorship.

The subject stops here. How a risk and control self assessment is actually run, who fills it in, on what cycle and with what challenge, is covered separately under operational risk, and its result is used here as a claim without the process behind it being re-taught. How an operational loss is measured and booked, how duties are separated, how exceptions are handled, how a cause is traced and what a near miss register is for are all covered separately in the same place. Committee structure, charters, the policy set and escalation are covered separately under risk governance, and committee G3 appears here only as the reader of the year's conclusion. The five stages a control travels through, the grid that records who is checking what across the three lines, how a finding is written in its five parts, how a finding is rated, what happens to it afterwards and how long the resulting issues stay open are each taken up separately, as are the Indian reporting requirement on internal financial controls and the judgement that turns a deficiency into a material weakness. The audit of the financial statements themselves sits with accounting and audit. Instruments are explained elsewhere.

Sources

SourceDocumentSite
Ministry of Corporate AffairsThe Companies Act duty on internal financial controls: the text, who it applies to, who is exempt, and the form the report takesmca.gov.in
Institute of Chartered Accountants of IndiaThe assurance standard and the guidance note behind independent work on controls, including how sufficiency of evidence is framedicai.org
Reserve Bank of IndiaWhat binds a bank in India on internal control, risk management arrangements and the standing of the internal audit functionrbi.org.in

Vindhya Commercial Bank Limited, Sunanda Ravikumar and Rustom Batliwala are invented.
Educational material. Not advice on any investment, tax, budget or market position.

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.