System Audit framework for Mutual Funds / Asset Management Companies (AMCs)
X X X X Extracts X X X X
X X X X Extracts X X X X
....examination of integration of front office system with the back office system, fund accounting system for calculation of net asset values, financial accounting and reporting system for the AMC, Unit-holder administration and servicing systems for customer service, funds flow process, system processes for meeting regulatory requirements, prudential investment limits and access rights to systems interface. 4. Mutual Funds / AMCs are advised to conduct systems audit on an annual basis by an independent CISA / CISM qualified or equivalent auditor to check compliance of the provisions of this circular. 5. Mutual Funds / AMCs are further advised to take necessary steps to put in place systems for implementation of this circular. The exception report as per Annexure 2 should be placed before the Technology Committee for review. The Technology Committee after review shall place the same before the AMC & Trustee Board. Thereafter, exception observation report along with trustee comments starting from the financial year April 2019 - March 2020 should be communicated to SEBI within six months of the respective financial year. Further, System Audit Reports shall be made available for ins....
X X X X Extracts X X X X
X X X X Extracts X X X X
....तिà¤à¥‚ति और विनिमय बोरà¥à¤¡ Securities and Exchange Board of India Application System Location of | HW/OS/DB for DB Server HW/OS/DB for Web Server HW/OS/DB for Web Server server(s) e.g. Front Office System e.g. Back Office System e.g. Email System e.g. Intranet System e.g. File Server System e.g. Finance & Accounting System Page 4 of 25 GB à¤à¤¾à¤°à¤¤à¥€à¤¯ पà¥à¤°à¤¤à¤¿à¤à¥‚ति और विनिमय बोरà¥à¤¡ Securities and Exchange Board of India System Audit Program Checklist The checklist is intended to provide guidance to the Mutual Funds/Asset Management (MFS/AMCS) Companies and Firms/ Companies appointed by MFS/AMCs for performing the systems audit. MFS/AMCS are responsible for ensuring that adequate and effective control environment exists over the IT systems in use for supporting business operations, including that at vendors/third parties supporting operations like Register & Transfer Agents (RTAs), Fund Accountants....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... and Procedures: - Whether a defined and documented IT policy exists and is approved by the BOD? - Is the current state of IT architecture documented including infrastructure, network and application components to show system linkages and dependencies? - Whether defined and documented procedures exist for all components, which amongst others include: a. IT Assets Acquisition (including retrial) b. Logical access management c. Change management d. Backup and recovery e. Automated batch jobs f. Incident management g. Problem management h. Data Center Operations i. Operating systems and database management j. Network and communication management k. End user computing I. Acceptable use of IT assets, etc. - Does IT policy comprise of the IT organization structure, roles and responsibilities of key IT management personnel, IT strategic management process and processes for ensuring adherence with compliance requirements? IT Organization Structure: -Whether a defined organization structure exists with defined authorities, reporting lines and responsibilities related to IT governance including a designated Chief Information O....
X X X X Extracts X X X X
X X X X Extracts X X X X
....i. Network and communication management j. End user computing, in addition consider phone, faxes, photocopiers, scanners, etc. k. Security Operations - logging and monitoring - Whether defined and documented procedures exist for the following: Page 7 of 25 2c 2d INFORMATION SECURITY GB Information Security Risk Management INFORMATION Cyber Security SECURITY 2e INFORMATION SECURITY Information Security Awareness 2f INFORMATION SECURITY Information Privacy à¤à¤¾à¤°à¤¤à¥€à¤¯ पà¥à¤°à¤¤à¤¿à¤à¥‚ति और विनिमय बोरà¥à¤¡ Securities and Exchange Board of India a. Hardening procedures, standards and guidelines for operating systems, databases, servers and network devices b. Use of cryptography c. Third Party Security d. Human Resource controls for information security e. Information classification guidance and process including mechanisms for storage, transmission and disposal of information -Whether the information security framework/ policy is reviewed on an yearly basis at a mini....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... technology, information security and cybersecurity? -Whether background check procedures are performed for all new joiners? Digital Technologies: -Whether the organization has a defined process to identify, develop and implement digital technologies supporting internal and external facing functions? - Whether all digital technologies including mobile applications, web-based portals, mobile websites, cloud storage, etc. are implemented only after performing risk assessment, testing and where required independent reviews? -Whether the organization has a defined and approved social media usage policy to address information security and reputational risks arising out of the same? Third Party Security: - Whether the organization has a defined vendor management framework and is approved by the BOD? - Whether the vendor management framework includes processes to be followed for vendor due diligence, selection, risk assessment, onboarding, contracting and monitoring? - Whether vendors are on boarded only after performing a technical due diligence, risk assessment and background checks? - Whether formal contracts are signed with vendors and i....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ess to systems is subject to more stringent security controls (such as Privileged Identity Management Solutions, more stringent password parameters, etc.) as compared to normal users? Page 10 of 25 GB à¤à¤¾à¤°à¤¤à¥€à¤¯ पà¥à¤°à¤¤à¤¿à¤à¥‚ति और विनिमय बोरà¥à¤¡ Securities and Exchange Board of India 3c ACCESS Access Administration MANAGEMENT 3d ACCESS MANAGEMENT 3e ACCESS MANAGEMENT Access Authentication Access Review and Monitoring - Whether access rights for privileged users are monitored on periodic basis? - Whether logs of privileged users are stored and reviewed on a periodic basis based on criticality of systems? Access Administration: - Whether role-based and least privilege access mechanisms are in-built into systems to enable authorized access as per job roles? - Whether access administration requests, related approvals/notifications and related actions (creations, revocation and modification) are logged and documented using automated tools with date-time stamps and appropriate evid....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... critical activities including key business transactions, modification of security parameters, masters' updates, and access administration activities are available with details around related user IDs, approvers and date-time stamps. Whether audit trails are retained for evidence, review and audit purposes? -Whether control mechanisms such as periodic reconciliation of user lists with HR lists, deactivation of users with no logins for a defined timeframe, etc. have been deployed to ensure any unauthorized access is timely terminated? Segregation of Duties (SOD): - Whether a defined and documented SOD matrix exists describing key roles within the systems and conflicting rights? - Whether access approvals, creations and modifications are performed based on approved SOD matrix? - Potential SOD conflicts are investigated during periodic access reviews and corrective actions are taken, if any. Physical Access Administration: - Whether defined and documented procedures exist for managing physical access to data center and processing facilities? - Whether creation of physical access requires documentation of appropriate approvals as per authori....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ration changes, capturing the version history and approval history? - Whether appropriate guidance is available for categorization and prioritization of changes? Change Administration: -Whether changes to applications and infrastructure (networks, operating systems and databases), including requests to third party service providers are approved and authorized by both authorized IT and business management personnel, as per defined authorization matrix? -Whether for each change, a risk evaluation process is carried out and results of the same are approved by authorized personnel? -Whether test cases library is maintained and updated to enable comprehensive testing? - Whether changes for relevant applications, including infrastructure changes are tested and documented during User Acceptance testing (UAT). Whether there is a formal signoff of the UAT results provided by the business prior to implementation? - Whether changes for applications, including infrastructure (OS/DB) changes are tested and documented during system, unit, and regression testing, where applicable. Whether there is a formal signoff of the test results by the technology ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ll systems including applications and infrastructure (networks, operating systems, databases, etc.) capturing the version history and approval history? - Whether appropriate guidance is available for categorization and prioritization of incidents? Incident Resolution: - Whether incidents are logged using automated tools with a unique ID assigned to each incident? -Whether incidents are classified based on their severity and urgency. Whether severity of incidents can be changed only by authorized personnel? -Whether a root cause analysis is performed for each incident and documented? - Whether a known error database is maintained for resolution and workaround details for similar incidents? -Whether details of resolution provided against each incident is documented against the ticket logged? - Whether incidents are tracked and monitored for resolution on a timely basis? -Whether recurring incidents are identified and logged as problems? Page 14 of 25 GB à¤à¤¾à¤°à¤¤à¥€à¤¯ पà¥à¤°à¤¤à¤¿à¤à¥‚ति और विनिमय बोरà¥à¤¡ Securities a....
X X X X Extracts X X X X
X X X X Extracts X X X X
....- Whether access to onsite backups are limited to authorized personnel? - Whether backup tapes are sent for offsite storage on a periodic basis? Page 15 of 25 6c BACKUP & RECOVERY Restoration GB à¤à¤¾à¤°à¤¤à¥€à¤¯ पà¥à¤°à¤¤à¤¿à¤à¥‚ति और विनिमय बोरà¥à¤¡ Securities and Exchange Board of India 7 JOB PROCESSING 7a JOB Job Processing PROCESSING 8 8a BUSINESS CONTINUITY PLANNING (BCP) & DISASTER RECOVERY (DR) BUSINESS CONTINUITY PLANNING (BCP) & DISASTER RECOVERY BCP Organization - Whether offsite storage of tapes is monitored on a periodic basis? Restoration: -Whether restoration testing is performed on a periodic basis and issues, if any are resolved? -Whether request based restorations are performed only after obtaining approvals from business head? JOB PROCESSING Job Processing: - Whether documented policies and procedures exist for automated job scheduling, implementation and monitoring capturing version history and approval history? - Whether a....
X X X X Extracts X X X X
X X X X Extracts X X X X
....onsibilities f. Maintenance schedules g. Awareness and education activities h. Resumption procedures i. Responsibilities of employees j. Emergency and fall back procedures BCP Plan: - Whether a BIA is conducted including identification of critical processes within the organization and their dependencies on other processes, vendor dependencies and resources. Whether Recovery Time Objective (RTO) and Recovery Point Objective (RPO) has been calculated as part of the BIA. Whether the BIA is approved by the business, technology and risk teams? -Whether a Risk Assessment is conducted for all critical processes identified in the BIA including identification of risks and threats and their impact, probability and priority. Whether the RA is conducted across parameters including people, processes and technology. Has the organization identified and implemented appropriate procedures and systems for risk mitigation? - Whether a documented BCP plan exists and is approved by the BOD. Whether the BCP is developed based on the approved methodology and includes at a minimum the following: a. Organization's strategy for BCP Page 17 of 25 GB ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....¤µà¤¿à¤¨à¤¿à¤®à¤¯ बोरà¥à¤¡ Securities and Exchange Board of India 9 BUSINESS CONTROLS 9a BUSINESS CONTROLS Master Controls (Investment management, Front Office, Middle Office, Back Office, Fund Accounting, Registrar & Transfer Agent) 9b BUSINESS CONTROLS Front Office and Back Office Operations and software components at the primary and DR sites? BUSINESS CONTROLS Master Controls (Investment management, Front Office, Middle Office, Back Office, Fund Accounting and Registrar & Transfer Agent): - Whether new schemes/ funds are created in the system through an automated maker checker mechanism and based on the Scheme Information Documentation (SID) and information received from authorized sources? - Whether new customer accounts are created and assigned schemes/funds based on the agreement signed with the customers? -Whether access to create/update/delete any master data (Customer/Scheme/ Securities/Broker/ Subscriptions/ Redemptions etc.) is restricted only to the authorized individuals? - Whether changes to masters are performed through an automated maker ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ecified in the Ninth Schedule of the Mutual Fund Regulations with respect to accounting policies? - Whether the system monitors adherence to policies related to documentation of rationale for valuation including inter-scheme transfers? Investor Servicing (Registrar & Transfer Agent): - Whether automated maker checker controls have been implemented for processing subscription and redemption requests? - Whether appropriate field level validations and mandatory checks are built in the system during subscription and redemption? - Whether the system has the capability to maintain the record of all types of transactions executed on behalf of the investor for specific scheme/ investment? - Whether the system has appropriate controls on brokerage computation and payouts? Fund Accounting: - Whether NAV calculations, if automated are accurately calculated? - Whether end of day reconciliations (cash recon, portfolio recon, pricing recon, etc.) are performed to ensure no deals are missed from reporting to the fund accountant for processing and complete data is processed for safekeeping? -Whether details of the expenses accrued by the client (M....
X X X X Extracts X X X X
X X X X Extracts X X X X
....n (Observation) Reporting Format Note: Mutual Funds are expected to submit following information with regards to exceptions observed in the System Audit, including open observations from previous audit report. Name of the Mutual Fund: Systems Audit Report Date: Table 1: High/Medium risk exceptions observed in the System Audit, including open observations from previous audit report Audit Objective S Checklist No. Question Audit Objective Heading Department Description Name Observation of Risk Rating Auditor's Audited By Recommendation Whether similar issue was Management observed in any Comment with target of the previous 2 date Trustee Comment Number audits Description of relevant Table heads 1. S No. This indicates the serial number of the observation. 2. Audit Objective Checklist Question Number - This indicates question number in the guideline audit checklist 3. Audit Objective Heading - This indicates heading in the guideline audit checklist Department Name - name of auditee department to which the observation pertains to e.g. PMS, R&TA, IT, Admin etc. Description o....
X X X X Extracts X X X X
X X X X Extracts X X X X
....eading Objective Description of Observation Risk Rating Question Number Low Management Comment with Trustee Comment target date Description of relevant Table heads 1. S No. This indicates the serial number of the observation. 2. Audit Objective Checklist Question Number - This indicates question number in the guideline audit checklist 3. Audit Objective Heading - This indicates heading in the guideline audit checklist 4. Description of Observation - Description of the observation in sufficient detail 5. Risk Rating - Observation's rating based on its impact and severity to reflect risk exposure. 6. Management Comment with target date - Management action plan/taken to address the observation and/ or implementation of auditor's recommendation with target date to address/implement. 7. Trustee Comment Trustee comments with respect to management action plan/taken to address the observation and/ or implementation of auditor's recommendation with target date to address/implement Page 24 of 25 GB à¤à¤¾à¤°à¤¤à¥€à¤¯ पà¥à¤°à¤¤à¤¿à¤à¥‚ति और विà¤....
TaxTMI