Audit Framework Library

Select frameworks

Results for "Failure to segregate duties"

NIST Cyber security framework 2.0
PR.AA-05

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

EIOPA Guidelines on System of Governance
Section 1, Guideline 1, 1.6

The system of governance should include an adequate transparent organisational structure with a clear allocation and appropriate segregation of responsibilities.

EIOPA Guidelines on System of Governance
Section 2, Guideline 11, 1.31

The undertaking should take into account the respective duties allocated to individual members to ensure appropriate diversity of qualifications, knowledge and relevant experience.

FRC Corporate Governance Code
Section 2, Principle G

The board should include an appropriate combination of executive and non-executive (and, in particular, independent non-executive) directors, such that no one individual or small group of individuals dominates the board’s decision-making. There should be a clear division of responsibilities between the leadership of the board and the executive leadership of the company’s business.

NIST Cyber security framework 2.0
GV.RR-03

Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies

Guidelines on Prevention of Money Laundering and Countering the Financing of Terrorism
4 CUSTOMER DUE DILIGENCE, 4.7

Insurers should not open an account or commence a business relationship, or perform a transaction for a customer if they are unable to verify the identity of the customer or beneficial owner.

EIOPA Guidelines on System of Governance
Section 8, Guideline 37, 1.85

The undertaking should have a written agreement with the service provider which clearly defines the respective rights and obligations of the undertaking and the service provider.

FRC Corporate Governance Code
Section 2, Provision 10

The chair should be independent on appointment when assessed against the circumstances set out in Provision 10. The roles of chair and chief executive should not be exercised by the same individual. A chief executive should not become chair of the same company. If, exceptionally, this is proposed by the board, major shareholders should be consulted ahead of appointment. The board should set out its reasons to all shareholders at the time of the appointment and also publish these on the company website.

IIA Topical Requirement Cyber Security
Governance, B

Roles and responsibilities regarding cybersecurity are clearly defined and communicated across the organization, including the board, senior management, and the three lines model.

Guidelines on Prevention of Money Laundering and Countering the Financing of Terrorism
8 POLITICALLY EXPOSED PERSONS, 8.1

Business relationships with Politically Exposed Persons (“PEPs”) may present higher risks. Insurers must define and identify PEPs, including their family members and close associates, and apply appropriate risk management systems.