Purpose and scope
The purpose of this policy is to identify operational risks, review how existing controls operate, and track any necessary corrective actions.
This document does not mean that the company has a separate or independent internal audit department. The method and people responsible for a review are determined according to the matter’s impact, the expertise required, and any potential conflicts of interest.
Selecting matters for review
Areas for review are selected with regard to risk level, process changes, security or service incidents, customer feedback, and previous findings.
- Priority is given to high-impact or recurring issues.
- The purpose, scope, and required records are defined at the outset of the review.
- Where appropriate, input is obtained from a specialist other than the people directly responsible for the matter.
Risk and control assessment
Risks are assessed with regard to likelihood, business impact, customer impact, and existing controls. The presence of a control in documentation alone is not treated as sufficient; suitable evidence is used to check whether it is operating in practice.
Conducting a review
A review uses documents, records, system outputs, interviews, and sample checks where appropriate. Findings are based on observable circumstances and evidence rather than personal opinion.
The person responsible for the process under review is given an opportunity to explain a finding and provide missing information.
Findings and corrective-action tracking
The impact, proposed corrective action, responsible person, and target date are recorded for each finding. Critical matters are escalated to the relevant senior owner, and completed action is checked separately to determine whether it resolved the issue.
Objectivity and confidentiality
If the person conducting the review has a conflict of interest in the matter, it is disclosed and responsibilities are reconsidered. Customer, employee, and company information accessed during a review is used only for the relevant purpose.
Process improvement
Improvement is not limited to closing errors. Repetitive manual work, unclear responsibilities, unnecessary approvals, inadequate records, and process steps whose performance is not measured may also be considered for improvement.
Review
This policy is reviewed when there is a material change to the relevant service, process, organisational structure, or applicable law. After any necessary revisions, the current text and revision date are published on this page.
