Just a moment...

Top
Help
×

By creating an account you can:

Logo TaxTMI
>
Call Us / Help / Feedback

Contact Us At :

E-mail: [email protected]

Call / WhatsApp at: +91 99117 96707

For more information, Check Contact Us

FAQs :

To know Frequently Asked Questions, Check FAQs

Most Asked Video Tutorials :

For more tutorials, Check Video Tutorials

Submit Feedback/Suggestion :

Email :
Please provide your email address so we can follow up on your feedback.
Category :
Description :
Min 15 characters0/2000
TMI Blog
Home / RSS

System Audit of Professional Clearing Members (PCMs)

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....uded under the scope of System Audit. 4. PCMs are also required to submit information with regard to exceptional major Non-Compliances (NCs)/ minor NCs observed in the System Audit as per format enclosed as Annexure 4 and are required to categorically highlight those observations/NCs/suggestions pointed out in the System Audit (current and previous) which remain open. 5. The Systems Audit report including compliance with SEBI/CCs circulars/guidelines and exceptional observation format along with compliance status of previous year observations shall be placed before the Governing Board of the PCM and then the report along with the comments of the Management of the PCM shall be communicated to CCs within one month of completion of audit. 6. All CCs are jointly advised to devise the appropriate uniform penalty structure for PCMs to ensure that system audit reports are submitted to them within defined timelines as well as audit observations are closed within defined timelines. 7. The provisions of the Circular shall come into force with immediate effect. The first audit shall be conducted for FY 2023-24. 8. The circular is issued with the approval of the competent author....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... f. The audit shall be conducted for each financial year. Further, the audit shall be completed within 2 months from the end of the audit period. The Audit report shall be submitted to CCs within one month of completion of the Audit, after approval of the Governing Board (or equivalent governance structure as applicable to the entity). PCMs, who have conducted clearing activities during the audit period are liable for submission of the System Audit report. g. In the Audit report, the Auditor shall include its comments on whether the areas covered in the Audit are in compliance with the norms/ directions/ advices issued by SEBI, Clearing Corporation, internal policy of the PCM, etc. Further, the Audit report shall also include specific non- compliances (NCs), observations for minor deviations and suggestions for improvement. The audit report shall take previous audit reports into consideration and cover any open items therein. The Auditor should indicate if a follow-on audit is required to review the status of NCs. h. For each of the NCs/ observations and suggestions made by the Auditor, specific corrective action as deemed fit may be taken by the PCM. The manage....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....audit must have experience in / direct access to experienced resources in the areas covered under TOR. It is recommended that resources deployed by the Auditor for the purpose of system audit shall have relevant industry recognized certifications e.g. CISA (Certified Information Systems Auditor) from ISACA, CISM (Certified Information Securities Manager) from ISACA, GSNA (GIAC Systems and Network Auditor), CISSP (Certified Information Systems Security Professional) from International Information Systems Security Certification Consortium, commonly known as (ISC). c. The Auditor shall have experience in working on Network audit/IT audit/governance/IT service management frameworks and processes conforming to industry leading practices like CobiT/ ISO 27001 and beyond. d. The Auditor should have the capability to undertake forensic audit and undertake such audit as part of system audit, if required. e. The Auditor must not have any conflict of interest in conducting fair, objective and independent audit of the PCM. It should not have been engaged over the last three years in any consulting engagement with any departments / units of the entity being audited. ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....tem Audit Program - Terms of Reference (TOR) 1. The scope of audit shall encompass all the IT resources including hardware, software, network, policies, procedures etc. of PCMs (Primary Data Centre (PDC), Disaster Recovery Site (DRS) and Near Site (NS), if applicable). 2. IT environment 2.1. Organization details a. Name b. Address c. IT team size (in house- employees) d. IT team size (vendors) 2.2. IT and network set up and usage a. PDC, DRS, NS and Regional/ Branch offices (location, owned/ outsourced), if applicable b. Connectivity amongst PDC, NS and DRS, if applicable c. IT infrastructure / applications pertaining to the activities done as a PCM. d. System Architecture e. Network architecture f. Telecommunication network 3. IT Governance 3.1. Whether IT Governance framework exists to include the following: a. IT organization structure including roles and responsibilities of key IT personnel; b. IT governance processes including policy making, implementation and monitoring to ensure that the governance principles are followed; 3.2. IT policies and proc....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....Symbol wise User Order / Quantity limit, User / Branch Order Limit, Order Price limit) and also exceeded corresponding margin availability of clients. Whether deviations from such pre-defined limits are captured by the system, documented and corrective steps taken. c. Log Management - Whether the system maintains logs of alerts / changes / deletion / activation / deactivation of client codes and logs of changes to the risk management parameters mentioned above. Whether the system allows only authorized users to set the risk parameter in the RMS. 4.3. Software change control a. Whether pre-implementation review of application controls (including controls over change management) was undertaken. b. Adherence to secure Software Development Life Cycle (SDLC) / Software Testing Life Cycle (STLC) standards/ methodologies c. Whether post implementation review of application controls was undertaken. d. Is the review of processes to ensure data integrity post implementation of new application or system followed by implementation team? e. User awareness f. Processing of new feature request g. Fault reporting / tracking....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....re, network) performance over the period b. Current system utilization 4.8. Business Continuity / Disaster Recovery Facilities a. Business Continuity Planning (BCP) manual, including Business Impact Analysis (BIA), Risk Assessment and Disaster Recovery (DR) process, Roles and responsibilities of Incident Response Team (IRT) /Crisis Management Team (CMT), if applicable, employees, support/outsourced staff. b. Implementation of policies c. Back-up procedures and recovery mechanism using back-ups. d. Storage of Back-up (Remote site, DRS etc.) e. Redundancy - Equipment, Network, Site etc. f. DRS installation and Drills - Management statement on targeted resumption capability (in terms of time required & extent of loss of data) g. Evidence of achieving the set targets during the DR drills in event of various disaster scenarios., if applicable h. Debrief / review of any actual event when the DR/BCP was invoked during the year, if applicable. i. User awareness and training j. Is Recovery Time Objective (RTO) /Recovery Process Objective (RPO) during Business Impact Assessment (BIA) documen....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....technology complaints 10.2 Whether all complaints received are brought to their logical conclusion? 11. Any other Item(s) 11.1 Observation(s) based on previous Audit Report (s) 11.2 Any new direction/instruction that may be informed by Clearing Corporation and/or SEBI.   Annexure 3 Format for monitoring compliance with requirements emanating from SEBI and Clearing Corporation (CC) circulars/guidelines/advisories related to technology Sl. No. Date of SEBI/CC circular/ directions/ advice, etc. Subject Technological requirements specified by SEBI/CC in brief Mechanism put in place by the PCMs Non compliances with SEBI/CC circulars/ directions, etc. Compliance status (Open/ closed) Comments of the Management Time-line for taking corrective action in case of open observations                                                                         ....