Operational Audit
The challenge
Operational audit, in banking as in insurance, is no longer the formal compliance exercise it once was. Under pressure from supervisors and post-2008 requirements, it has become a strategic second-line function : its role is to ensure that the frameworks for risk, models, data, and reporting actually work the way they are supposed to.
To do that, it has to be able to ask the right questions, identify the gaps between procedure and practice, and demand credible remediation plans. A weak operational audit function is today a signal of prudential fragility.
OMOTE Advisory supports internal audit departments and independent control functions on their methodology, their process reviews, and the conduct of their engagements on risk and finance topics.
Our Approach
We approach audit with the same stance that runs through all of our work: audit is a practitioner's job, not a methodologist's.
Auditing an internal PD model means understanding credit modeling. Auditing a process that produces ALM indicators means knowing the metrics. Auditing a risk-data framework means mastering BCBS 239.
It is this dual competence — audit method plus subject-matter expertise — that gives our advisory work its value in this discipline. Our audit engagements are never led by generalist auditors: they are entrusted to practitioners of the very domain they are auditing.
Areas of focus
Independent review
Independent review of models, processes and key indicators on risk, ALM and finance topics — aligned with SR 11-7 and TRIM principles, and with the expectations of European supervisors. Includes Business Model Assessment (BMA) reviews and review of the KPIs and KRIs used by steering functions.
Internal audits
Preparation and execution of internal audits on prudential programs and ongoing transformations.
Internal control
Strengthening of internal control frameworks within Risk and Finance functions — risk mapping, articulation between first and second lines of defense, consistency with regulatory and accounting requirements.
Post-audit follow-up and remediation
Execution of action plans, supervisory dialogue, validation of corrections, support through to clearance of findings.
