Directive No. 04/2003/CT-NHNN of the Governor of the State Bank of Vietnam on Strengthening Internal Control and Internal Audit Work to Enhance Quality of Operations and Prevent Risks. This Directive applies to units under the State Bank of Vietnam and its branches in centrally governed cities and provinces.
适用范围
Heads of units under the State Bank of Vietnam, Directors of State Bank of Vietnam Branches in centrally governed cities and provinces
要点
- Heads of units and branch directors must organize the implementation of internal control work according to Chapter II of the Internal Control and Internal Audit Regulations of the State Bank of Vietnam.
- Must establish an internal self-control environment ensuring operational safety, including issuing working regulations for the leadership board of the unit and assigning internal control responsibilities.
- Units must regularly conduct self-inspection activities in handling staff duties, seriously rectifying any issues discovered through internal control work.
- The Accounting and Finance Department shall provide specific guidance on password change deadlines and security code usage in electronic fund transfers.
- The Information Technology Department shall specify the usage period for security codes in inter-bank electronic payments, study and apply technical solutions to ensure safety.
🌐 本文件的社会影响
- Positive impact: Enhancing the quality of operations and preventing risks for the State Bank of Vietnam.
- Negative impact: May increase workload for units and individuals during the implementation of new regulations.
❓ 常见问题
What should heads of units under the State Bank of Vietnam do?
Must organize the implementation of internal control work according to Chapter II of the Internal Control and Internal Audit Regulations of the State Bank of Vietnam.
How should units establish an internal self-control environment?
Including issuing working regulations for the leadership board of the unit and assigning internal control responsibilities to each department and individual based on dual control principles.
What is the effective duration of this Directive?
This Directive takes effect fifteen days after its publication in the Official Gazette.
What should the Information Technology Department of the State Bank of Vietnam do?
Must specify the usage period for security codes in inter-bank electronic payments and study and apply technical solutions to ensure safety.
What is the responsibility of the Accounting and Finance Department?
Provide specific guidance on password change deadlines and security code usage in electronic fund transfers to enhance security and confidentiality.
全文
DIRECTIVE
OF THE HEAD OF THE STATE BANK
Regarding the strengthening of internal control and internal audit work at state-owned commercial banks
In recent years, the internal control and internal audit work at the State Bank have gradually become systematic, stable, and of high quality, positively impacting the operational efficiency of units under the State Bank. The heads of these units have recognized the significance and importance of internal control work, thus showing concern and organizing the implementation of internal control activities effectively within their own units. The Department of Internal Audit, with its advisory role to the Governor in the field of internal control and internal audit at the State Bank, has frequently directed internal control operations at various units and branches, and conducted internal audits well, ensuring that units under the State Bank comply with laws, implement state and State Bank policies properly, minimize asset loss risks, and enhance the responsibility of each unit and individual during the execution of tasks. Staff involved in internal control and internal audit at units and branches have also made significant efforts to fulfill their assigned tasks.
______________________
However, alongside the achievements, internal control and internal audit work at the State Bank have also revealed some shortcomings: Some units still undervalue self-inspection and internal control work, leading to non-compliance with legal regulations, state mechanisms, and State Bank policies, inadequate adherence to operational procedures; Supervisory inspection work by higher-level staff, particularly direct superiors regarding subordinates' work, has not been comprehensive or regular; Individual staff members' self-control responsibilities for their work are not high enough, mutual inspection and supervision among staff members are not sufficiently emphasized; Certain high-risk operations lack timely and adequate guidance documents or strict implementation of safety regulations, resulting in violations and potential asset losses such as breaches of confidentiality principles in managing and using access passwords for the State Bank's electronic payment system, IT applications in cash vault operations, and violations of safety regulations and entry-exit procedures for cash vaults. At some units and branches, unit heads and branch directors have not adequately focused on or directly directed internal control work, thereby limiting the effectiveness of internal control activities within their units.
To promptly address these issues and improve the quality of internal control and internal audit work at the State Bank in the future, the Governor of the State Bank issues the following directive:
1. Heads of units under the State Bank and Directors of provincial and centrally-administered city branches shall organize the implementation of internal control work within their units comprehensively, regularly, and effectively according to Chapter II of the Internal Control and Internal Audit Regulation of the State Bank issued pursuant to Decision No. 486/2003/QĐ-NHNN dated May 19, 2003 of the Governor of the State Bank, ensuring compliance with laws, state mechanisms, State Bank regulations, and operational procedures, preventing potential risks in all aspects of unit activities. Unit heads and branch directors shall directly oversee internal control work and be responsible before the Governor for the quality of internal control activities within their units.
2. Heads of units and branch directors must establish a safe operating environment through internal self-control, including: Issuing working regulations for unit leadership bodies, delegating and distributing internal control responsibilities to departments within the unit based on dual control principles, ensuring every task has both an executor and a reviewer; Leaders at each level must assess the risk level of each operation to develop appropriate control measures; Regularly and promptly disseminate relevant national regulatory documents related to banking activities, State Bank regulations, and operational procedures to all unit staff; Establish internal reporting, democratic financial transparency, and information sharing systems within the unit; Managers at each level within the unit must fully follow the supervisory review process when handling tasks.
3. Heads of units under the State Bank and Directors of provincial and centrally-administered city branches shall instruct functional departments within their units to regularly and systematically carry out self-inspection activities in handling staff tasks; Seriously and promptly correct deficiencies and shortcomings identified through internal control and internal audit work; Prevent recurrence of previously identified and recommended deficiencies. Directors of the State Bank Trading Departments and provincial and centrally-administered city branch directors shall specify the usage period and change requirements for electronic signatures in inter-bank electronic payments.
4. The Accounting and Finance Department shall be responsible for providing specific guidelines on the change period for access passwords and security codes in electronic fund transfer systems to enhance security and confidentiality in the management and use of the State Bank's electronic fund transfer system.
5. The Banking Information Technology Department shall specify the usage period for security codes in inter-bank electronic payments; Study and apply technical solutions to automatically invalidate access passwords, security codes, and electronic signatures after a specified usage period as per State Bank regulations, compelling authorized issuers to reissue security codes and electronic signatures, and users to change access program passwords to ensure safety and reduce risks in accounting and bank electronic payment transactions.
5. The Banking Technology Information Center shall specify the period for using security code keys in inter-bank electronic payments; study the application of technical solutions to automatically render access passwords, security code keys, and electronic signatures invalid after a certain period of use as prescribed by the State Bank, compelling authorized issuers to reissue security code keys and electronic signatures, and obliging users to change access program passwords to ensure safety and minimize risks in accounting and bank electronic payment transactions.
6. The Radio and Treasury Department shall be responsible for implementing and supervising the implementation of regulations on ensuring safety in regular treasury operations, particularly the entry and exit procedures for treasuries. Strictly monitor the compliance with management and usage rules for operational software application passwords in treasury business.
7. The Internal Audit Division must strengthen inspection, supervision, and internal audit activities for all units under the State Bank to ensure adherence to current national regulations, State Bank regulations, and effective and safe management of assets and financial resources at each unit and throughout the entire State Bank system. The Internal Control Departments (internal control units) at provincial and municipal branches, the Administration Bureau, the Trading Department, and the State Bank Representative Office in Ho Chi Minh City shall conduct internal controls over all areas of operation according to the methods and procedures outlined by the Internal Audit Division, ensuring that operations comply with current regulations and preventing risks. In cases where serious violations causing state asset losses are discovered, the Internal Controller has the right to report directly to the Governor through the Internal Audit Division.
8. This Directive shall take effect fifteen days from the date of publication in the Official Gazette.
Heads of units under the State Bank, Directors of provincial and centrally-administered municipal branches of the State Bank shall be responsible for studying, comprehending, and effectively implementing this Directive, and reporting the results of its implementation to the Central State Bank as directed by the Internal Audit Division. The Director of the Internal Audit Division shall be responsible for directing, inspecting, and compiling the results of implementation by units to report to the Governor of the State Bank.
关系图
点击文件即可打开。红色边框=改变效力的关系。