## 1zweea2022001 - Preface

## Source details

**Canonical URL:** [1zweea2022001 - Preface](https://www.imf.org/-/media/files/publications/cr/2022/english/1zweea2022001.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2022/english/1zweea2022001.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2022/english/1zweea2022001.pdf.json)

---

### Preface and mission overview
- At the request of the Reserve Bank of Zimbabwe (RBZ), the Regional Technical Assistance Center for Southern Africa (AFS) conducted a remote mission from April 20 to 30, 2021, to provide guidance in establishing a process for undertaking supervisory examinations remotely due to COVID-19 operational restrictions.
- The mission met with Philip T. Madamombe, Director, Bank Supervision, Audrey Hove, Deputy Director, Bank Supervision and staff of the Bank Supervision Department.
- The mission thanks the RBZ for cooperation and flexibility in undertaking the work remotely.

### Executive summary — purpose and activities
- RBZ is recommencing on-site examinations but, due to COVID-19 operational restrictions, these will need to be undertaken remotely.
- RBZ developed a draft remote examination framework and requested AFS assistance to review it and to provide information on how other supervisors conduct remote examinations.
- The mission:
  - Provided training on international practice of remote examinations presented by supervisors from the Bank of Ghana (BOG), Bank of Thailand (BOT) and the De Nederlandsche Bank (DNB).
  - Reviewed the draft remote examination framework document.
  - Reviewed the RBZ consolidated examination manual to assess feasibility of undertaking supervisory examinations remotely and provided points for consideration.

### Key recommendations (summary)
- Establish and structure remote examinations in accordance with the key points for consideration presented to the RBZ in the training sessions, as outlined in this report.
  - Priority: High
  - Timeframe: Near term
- Revise the draft remote examination framework document in consideration of the feedback provided by the mission – Appendix I.
  - Priority: High
  - Timeframe: Near term
- Timeframe definitions:
  - Near term: < 12 months
  - Medium term: 12 to 24 months

### High-level conclusions on remote modality
- Remote examinations require significant adjustments in communication, scope, IT services, timeframes, information sharing, and realistic assessment limits.
- Remote examinations are generally more time consuming than in-person engagements and multiply potential time delays.
- Communication is harder in the remote modality; videoconferencing rules, written communication and meeting preparation become more important.

### Immediate operational considerations
- Sufficient pre-examination information and thorough assessment of that information is vital.
- Increase emphasis on information sharing and communication between examination team and target institution; include daily check-in and information sharing sessions in schedules.
- Where supervisors rely more on internal control functions’ assessments, be investigative about conclusions and consider internal control functions’ ability to assess operations remotely.
- Communicate limitations of remote examination clearly in closing meetings and examination report; report examination areas out of scope due to remote modality.

---

### Enhancement of the Remote Examination Framework — recommended inclusions
- More detail on specific areas of examination and how remote work will be undertaken.
- Clear duties of the examination team (examiner in charge, team leader, team members).
- Information on examination areas less feasible to perform remotely.
- Practical details on means of remote communication, which tools are to be used, access methods, and responsibilities for setup.
- Appendix I contains a more extensive list of recommendations linked to chapters in the remote examination manual.

### Procedural recommendations (selected from Appendix I)
- Include a section on supervisory approach/process areas affected by remote examination.
- Identify information and communication tools to be used (preferred videoconferencing platform, allowed platforms, secure portals).
- Specify declarations by internal control and risk management functions and Board committees, not only heads of functions.
- Define duties of examination team, responsibilities for organizing and recording virtual meetings, and working paper review requirements.
- Before informing target institution of examination, assess feasibility at that institution and determine feasible scope.
- Communicate change in on-site approach and institutions’ responsibilities for ensuring the process works.
- Consider making submission time for requested information dependent on the target institution’s effort to gather it remotely; current provision allows up to four (4) weeks with part submission within two weeks.
- Add COVID-safe protocols for physical exchange of removable media.
- Specify required attendees for key virtual meetings and receive participant lists in advance for security.
- Before relying on declarations where remote assessment is difficult, consider virtual walkthroughs and other remote assessment methods.
- Specify variations to examination process and procedures as a minimum to enable examiners to explore additional remote assessment methods.
- Include a separate section on examination report expectations, disclaimers on ability to fully assess issues, timing for drafting, and processes for secure storage or disposal of information received in different formats.

---

### Remote examination feasibility by supervision area (summary of findings)
- Areas considered effectively examinable remotely with similar depth:
  - Risk Management
  - Accounting and Finance
  - Governance
  - Compliance
  - Internal Audit
  - Note: Focus should include the bank’s ability to perform these tasks remotely.
- Areas where remote examination is more cumbersome or hampered:
  - Credit Risk: review of credit files may be hampered by digital availability; examination will be more cumbersome and level of depth could be limited.
    - Reconsider the 40% minimum coverage stated in 5.4.5; gain experience with extra time needed to digitize files and base coverage on experience.
    - Avoid bias by not relying solely on already digitized credit files; investigate some non-digitized files.
  - Branch Operations and IT security: suffer most from remote modality because some inspection objectives require physical presence.
    - Branch Operations: examining teller operations, ATMs, deposit boxes, and KYC procedures is ineffective off-site when evidence is physical; account for additional effort by institution to digitize physical documentation when scoping examinations.
  - IT security areas (application, network, host, physical, data security; access rights administration; authentication) are difficult to assess remotely; screen sharing and virtual tours could help achieve minimum objectives.

### Area-specific practical notes (selected from Appendix II)
- Risk Management:
  - Similar scope and assessment as regular on-site examinations; review policies, procedures, committee papers, minutes, management reports remotely.
  - Additional focus on limit monitoring and follow-up of breaches; assess ability to perform risk management while remote.
- Accounting and Finance:
  - Similar scope as regular on-site examinations; policies, procedures, board and management oversight, capital and earnings statements generally digitally accessible.
  - For verification of reliability of financial information, determine if and how accounting system can be accessed pre-examination (remote system access, remote walkthroughs, or specific data extracts).
  - Note data extracts are large files; shared file environment warranted.
- Treasury Activities:
  - Documentation can be accessed remotely; review front/middle/back office functioning in a remote setting to assess operational risk, adherence to four eye principle, and administration of positions.
  - Monitoring liquidity, interest rate, market and FX risks can be examined via digital risk reports and meeting minutes.
- Corporate Governance:
  - Governance framework structure can be examined remotely; focus on how decision making and oversight are affected by remote working.
- Compliance and Internal Audit:
  - Assessable remotely via policies, procedures, reports, and remote interviews; ensure functions are not hampered by remote work.

---

### Appendix III — Remote system access: purpose, methods, limitations, and objectives
- Purpose and methods for direct remote access:
  - Direct remote access to banks’ IT systems will help facilitate remote assessment.
  - Remote access to the bank can most easily be obtained by using the banks own hardware (i.e. receiving a laptop from the bank).
  - The bank would need to set up an internal account for the supervisor with read-only rights.
  - Confidentiality would be protected by moving applications to special supervisory only folders.
  - Alternatively, remote access technologies such as remote desktop protocol, secured virtual private networks, TeamViewer and virtual tour software, could be utilized.
- Limitations and difficult-to-assess IT security areas:
  - Generally, areas of IT security including application security, network security, host security, physical security, data security, access rights administration, authentication, are difficult to assess remotely.
  - However, using direct remote access to bank systems, examinations may be able to undertake the required level of assessment and achieve examination objectives.
- Supervisory objectives achievable via remote access:
  - Making direct portfolio reviews from the source systems.
  - Running stress tests with the banks own software.
- Governance, privacy, and operational considerations:
  - It is noted however that remote access to sensitive IT systems may not be allowed by some target institutions.
  - The supervisor needs to discuss this and assess the security aspects related to remote access and privacy, as well as agree the extent of work and involvement of the target institutions’ IT staff.

*Source: 1zweea2022001 - Preface*

### Preface.................................................................................................................

### 1zweea2022001 - Preface

### Preface
- At the request of the Reserve Bank of Zimbabwe (RBZ), the Regional Technical Assistance Center for Southern Africa (AFS) conducted a remote mission from April 20 to 30, 2021, to provide guidance in establishing a process for undertaking supervisory examinations remotely due to COVID-19 operational restrictions.
- The mission met with Philip T. Madamombe, Director, Bank Supervision, Audrey Hove, Deputy Director, Bank Supervision and staff of the Bank Supervision Department.
- The mission thanks the RBZ for cooperation and flexibility in undertaking the work remotely.

### Executive Summary
- RBZ is recommencing on-site examinations but, due to COVID-19 operational restrictions, these will need to be undertaken remotely.
- RBZ developed a draft remote examination framework and requested AFS assistance to review it and to provide information on how other supervisors conduct remote examinations.
- The mission:
  - Provided training on international practice of remote examinations presented by supervisors from the Bank of Ghana (BOG), Bank of Thailand (BOT) and the De Nederlandsche Bank (DNB).
  - Reviewed the draft remote examination framework document.
  - Reviewed the RBZ consolidated examination manual to assess feasibility of undertaking supervisory examinations remotely and provided points for consideration.
- Key recommendations focus on communication, scope of examinations, IT services, extended time frames, information sharing, and realistic assessment limits.

### Key Recommendations (Table 1)
- Establish and structure remote examinations in accordance with the key points for consideration presented to the RBZ in the training sessions, as outlined in this report.
  - Priority: High
  - Timeframe: Near term
- Revise the draft remote examination framework document in consideration of the feedback provided by the mission – Appendix I.
  - Priority: High
  - Timeframe: Near term
- Timeframe definitions:
  - Near term: < 12 months
  - Medium term: 12 to 24 months

### I. Introduction
- RBZ requested AFS assistance to review draft remote examination framework and to receive practical information on undertaking on-site examinations remotely.
- The mission reviewed the draft framework, suggested enhancements, and provided practical information for remote examinations.

### II. Key Points for Consideration in Undertaking Remote Examinations
- IT services are critical to effective communication, especially when examiners are remote from their institution.
- Scope and time frame must be carefully considered; remote examinations are more time consuming than in-person engagements.
- Sufficient pre-examination information and thorough assessment of that information is vital.
- Specific points for RBZ to consider:
  - The success of remote examinations largely depends on the effective functioning of IT services. Establish reliable communication to facilitate meeting conferencing, remote walkthroughs, large file sharing and possible remote system access. (See Appendix III)
  - Adjust scope of examinations based on ability to effectively access and assess required counterparts and information; lack of digital availability will hinder effective examination.
  - Allow significantly more time to undertake examinations remotely; remote modality is much more time consuming and multiplies potential time delays.
  - Remote modality makes communication harder: adhere to videoconferencing rules, emphasize written communication and meeting preparation.
  - Increase emphasis on information sharing and communication between examination team and target institution; include daily check-in and information sharing sessions in schedules.
  - Where supervisors rely more on internal control functions’ assessments, be investigative about conclusions and consider internal control functions’ ability to assess operations remotely.
  - Communicate limitations of remote examination clearly in closing meetings and examination report; report examination areas out of scope due to remote modality.

### III. Enhancement of the Remote Examination Framework
- The mission recommends the framework include:
  - More detail on specific areas of examination and how remote work will be undertaken.
  - Clear duties of the examination team (examiner in charge, team leader, team members).
  - Information on examination areas less feasible to perform remotely.
  - Practical details on means of remote communication, which tools are to be used, access methods, and responsibilities for setup.
- Appendix I contains a more extensive list of recommendations linked to chapters in the remote examination manual.

### IV. Remote Examination Feasibility – RBZ Consolidated Examination Manual (Summary)
- The mission reviewed feasibility of undertaking supervisory examinations remotely across examination manual areas; this high-level review complements primary work and is not a full manual review.
- Areas considered effectively examinable remotely with similar depth:
  - Risk Management
  - Accounting and Finance
  - Governance
  - Compliance
  - Internal Audit
  - Focus should include the bank’s ability to perform these tasks remotely.
- Areas where remote examination is more cumbersome or hampered:
  - Credit Risk: review of credit files may be hampered by digital availability; examination will be more cumbersome and level of depth could be limited.
  - Branch Operations and IT security: suffer most from remote modality because some inspection objectives require physical presence.

### Appendix I — Review of Remote Examination Framework (Selected Points for Consideration)
- Include a section on supervisory approach/process areas affected by remote examination.
- Identify information and communication tools to be used (preferred videoconferencing platform, allowed platforms, secure portals).
- Specify declarations by internal control and risk management functions and Board committees, not only heads of functions.
- Define duties of examination team, responsibilities for organizing and recording virtual meetings, and working paper review requirements.
- Before informing target institution of examination, assess feasibility at that institution and determine feasible scope.
- Communicate change in on-site approach and institutions’ responsibilities for ensuring the process works.
- Consider making submission time for requested information dependent on the target institution’s effort to gather it remotely; current provision allows up to four (4) weeks with part submission within two weeks.
- Add COVID-safe protocols for physical exchange of removable media.
- Specify required attendees for key virtual meetings and receive participant lists in advance for security.
- Before relying on declarations where remote assessment is difficult, consider virtual walkthroughs and other remote assessment methods.
- Specify variations to examination process and procedures as a minimum to enable examiners to explore additional remote assessment methods.
- Include a separate section on examination report expectations, disclaimers on ability to fully assess issues, timing for drafting, and processes for secure storage or disposal of information received in different formats.

### Appendix II — Remote Examination Feasibility — Points for Consideration by Examination Area (Selected)
- Risk Management:
  - Similar scope and assessment as regular on-site examinations.
  - Review policies, procedures, committee papers, minutes, management reports remotely.
  - Additional focus on limit monitoring and follow-up of breaches; assess ability to perform risk management while remote.
- Accounting and Finance:
  - Similar scope as regular on-site examinations.
  - Policies, procedures, board and management oversight, capital and earnings statements are generally digitally accessible.
  - For verification of reliability of financial information, determine if and how accounting system can be accessed pre-examination (remote system access, remote walkthroughs, or specific data extracts).
  - Note data extracts are large files; shared file environment warranted.
- Credit:
  - Policies and procedures can be examined remotely, but loan portfolio review is cumbersome if files not digitized.
  - Reconsider the 40% minimum coverage stated in 5.4.5; gain experience with extra time needed to digitize files and base coverage on experience.
  - Avoid bias by not relying solely on already digitized credit files; investigate some non-digitized files.
  - For credit administration and monitoring, remote direct access or remote walkthroughs are advisable.
- Treasury Activities:
  - Documentation can be accessed remotely; review front/middle/back office functioning in a remote setting to assess operational risk, adherence to four eye principle, and administration of positions.
  - Monitoring liquidity, interest rate, market and FX risks can be examined via digital risk reports and meeting minutes.
- Corporate Governance:
  - Governance framework structure can be examined remotely.
  - Focus on how decision making and oversight are affected by remote working and whether internal control bodies have access to necessary information.
- Compliance Function:
  - Assessable remotely via policies, procedures, and remote interviews.
- Internal Audit:
  - Assessable remotely via policies, procedures, audit reports, and remote interviews; ensure internal audit is not hampered by remote work.
- Branch Operations:
  - Significantly hampered by remote working; examining teller operations, ATMs, deposit boxes, and KYC procedures is ineffective off-site when evidence is physical.
  - Account for additional effort by institution to digitize physical documentation when scoping examinations.
- Information Technology:
  - IT Governance review (policies, minutes, board and senior management oversight, IT governance, ICT structure, policies, risk assessment, vendor management) can be assessed remotely if information is digitized.
  - IT security areas (application, network, host, physical, data security; access rights administration; authentication) are difficult to assess remotely; screen sharing and virtual tours could help achieve minimum objectives.
  - Internal IT audit and compliance reports can be assessed remotely.

*Source: 1zweea2022001 - Preface*

### APPENDIX III. REMOTE SYSTEM ACCESS

### APPENDIX III. REMOTE SYSTEM ACCESS

### Purpose and methods for direct remote access
- Direct remote access to banks’ IT systems will help facilitate remote assessment.
- Remote access to the bank can most easily be obtained by using the banks own hardware (i.e. receiving a laptop from the bank).
- The bank would need to set up an internal account for the supervisor with read-only rights.
- Confidentiality would be protected by moving applications to special supervisory only folders.
- Alternatively, remote access technologies such as remote desktop protocol, secured virtual private networks, TeamViewer and virtual tour software, could be utilized.

### Limitations and difficult-to-assess IT security areas
- Generally, areas of IT security including application security, network security, host security, physical security, data security, access rights administration, authentication, are difficult to assess remotely.
- However, using direct remote access to bank systems, examinations may be able to undertake the required level of assessment and achieve examination objectives.

### Supervisory objectives achievable via remote access
- Making direct portfolio reviews from the source systems.
- Running stress tests with the banks own software.

### Governance, privacy, and operational considerations
- It is noted however that remote access to sensitive IT systems may not be allowed by some target institutions.
- The supervisor needs to discuss this and assess the security aspects related to remote access and privacy, as well as agree the extent of work and involvement of the target institutions’ IT staff.

*Source: APPENDIX III. REMOTE SYSTEM ACCESS*

---


_Source: https://www.imf.org/-/media/files/publications/cr/2022/english/1zweea2022001.pdf_
