Where Angels Prey

Where Angels Prey is a novel by Ramesh S Arunachalam. Please refer to www.whereangelsprey.com for more information
Showing posts with label AP Micro-Finance Crisis. Show all posts
Showing posts with label AP Micro-Finance Crisis. Show all posts

Friday, December 16, 2011

Lessons from the Indian microfinance crisis, an open letter to Andrew Mitchell

December 16, 2011 


Ramesh S Arunachalam

Two crucial aspects in microfinance—client origination/targeting and loan appraisal—have been neglected in favour of unprecedented growth (caused by a desire to fully commercialise microfinance and rapidly enhance access/outreach of such services) and this has resulted in the present crisis

An open letter to the right honourable Andrew Mitchell, UK International Development Secretary, on lessons from the Indian microfinance crisis

Respected Sir,

Good afternoon! I am delighted that The UK Department for International Development (DFID) is launching SAMRIDHI (a programme promoting microfinance and impact investment in India)  in partnership with SIDBI in your esteemed presence (Sir) at 6pm today, the 16th December (Friday) at the British Council Division, Kasturba Gandhi Marg, New Delhi. Much as I wanted to attend the same, I am unable to do so and hence, this open letter Sir for your kind consideration and necessary action.

 Click Here to READ More

Sunday, October 23, 2011

Bordercrossing Books: “The Journey of Indian Micro-Finance”

October 22, 2011 in Andhra Pradesh Microfinance Crisis, Book Review | Tags: , , , , , |

Book Review by

Ramesh S. Arunachalam, 2011: The Journey of Indian Micro-Finance: Lessons for the Future. Chennai: Aapti Publications.

The microfinance crisis in India which broke out in fall 2010, first imperiling numerous borrowers and then an entire industry, is the most fundamental event in the world of microfinance since the Nobel Peace Prize in 2006. In hindsight, it may even turn out to be the defining moment of microfinance history – never before has the dark side of microfinance, and the vulnerability of the industry, been so brutally exposed to a global audience.

Naturally, these events have attracted a host of opinions and analyses ranging from simply blaming the Andhra government for bringing down a healthy industry, to accusing MFIs of having become worse than loan sharks. And yet, so far, we understand very little of why India’s vast microfinance sector went so far astray. Thankfully, people like Ramesh S. Arunachalam are out to change this.

Click to READ More

Friday, May 6, 2011

A Comparative Analysis of Two Types of Agent Led Micro-Finance Models in India: Imperative For RBI To Build Safe Guards Into Priority Sector Lending Directions…

Ramesh S Arunachalam

Rural Finance Practitioner


The recent RBI announcement with regard to priority sector being used for Micro-Finance NBFCs is a very welcome one and is much appreciated as I posted the other day. However, safeguards are needed to ensure that agents of MFIs do not misuse priority sector funds. Thus, when coming out with the detailed guidelines, I hope that the RBI takes cognizance of two major agent led models prevalent in the Indian micro-finance sector.

Let me make a few other assertions. While the exact scale of the agent models nationally is perhaps not known with precision, there is enough cause to believe that it is reasonably widespread as it has been observed in several places in AP, Tamilnadu, UP, Orissa, West Bengal, Karnataka and parts of Madhya Pradesh. This again needs to be looked into closely by the RBI, which is best positioned to conduct an objective and neutral national study and assess which kind of MFIs are involved and why and also geographic places where the same is widespread - and this needs to be done before the detailed directions regarding priority sector are promulgated... 

That apart, it is also imperative that the RBI looks closely at these models and builds sufficient safeguards against their use through supervision and other means and using various stakeholders including banks. If this (building safeguards) appears difficult, a more practical approach could be for the RBI to consider streamlining and legalizing the Centre Leader Type Agent Model and building greater accountability into this type of arrangement - especially, if the RBI feels that this model can be fitted under the Business Correspondent regulations. However, the political agent Micro-finance model should be banned without question. All of these are aspects that the proposed RBI committee on priority sector could look into and provide guidance on.

Here are the operational details of two agent led micro-finance models as I have seen it on numerous occasions and also heard from several stakeholders. Read on…

Have A Nice Day!













Monday, May 2, 2011

Risk Assessment and Risk-based Auditing At Systemically Important and Large MFIs: Some Practical Guidelines…

Ramesh S Arunachalam
Rural Finance Practitioner  

Risk assessment and risk-based auditing are very critical mechanisms and need to be undertaken at large and systemically important MFIs and this post provides some practical suggestions in this regard…

Risk assessment is a process by which an auditor identifies and evaluates the quantity of the MFIs risks and the quality of its controls over those risks. Through risk-based auditing, the board and auditors use the results of the risk assessments to focus on the areas of greatest risk and to set priorities for audit work. That however does not mean that the audit department can lose sight of or ignore areas that are rated low-risk. An effective risk-based auditing program will ensure adequate audit coverage for all of an MFI’s auditable activities. The frequency and depth of each area’s audit should vary according to the auditor’s risk assessment.

Program Design: Properly designed risk-based audit programs increase audit efficiency and effectiveness. The sophistication and formality of audit approaches will vary for individual MFIs depending on the MFIs’ size, complexity, scope of activities, staff capabilities, quality of control functions, geographic diversity, and technology used. All risk-based audit programs should:
·         Identify all of the MFI’s operations, product lines, services, and functions (i.e., the audit universe).
·         Identify the activities and compliance issues within those operations, product lines, services, and functions that the MFI should audit (i.e., auditable entities).
·         Include profiles of significant operational units, departments, and products that identify business and control risks and document the structure of risk management and internal control systems.
·         Use a measurement or scoring system to rank and evaluate business and control risks of significant operational units, departments, and products.
·         Include board or audit committee approval of risk assessments or the aggregate result thereof and annual risk-based audit plans (that establish internal and external audit schedules, audit cycles, work program scope, and resource allocation for each area to be audited).
·         Implement the audit plan through planning, execution, reporting, and follow-up.
·         Have systems that monitor risk assessments regularly and update them at least annually for all significant operational units (regions or branches), departments, and products.

Risk Matrix and Guidelines: An effective scoring system is critical to a successful risk-based audit program. In establishing a scoring system, directors and management must consider all relevant risk factors so that the system minimizes subjectivity, is understood, and is meaningful. Major risk factors commonly used in scoring systems include:
·         The nature of transactions (e.g., volume, size, liquidity);
·         The nature of the operating environment (e.g., compliance with laws and regulations, complexity of transactions, changes in volume, degree of system and reporting centralization, economic and regulatory environment);
·         Internal controls, security, and MIS;
·         Human resources (e.g., experience of management and staff, turnover, competence, degree of delegation); and
·         Senior management oversight of the audit process.

Auditors or risk managers should develop written guidelines on the use of risk assessment tools and risk factors and review the guidelines with the audit or risk committee. The sophistication and formality of guidelines will vary for individual MFIs depending on their size, complexity, scope of activities, geographic diversity, and technology used. Auditors will use the guidelines to grade or assess major risk areas. These guidelines generally define the basis for assigning risk grades, risk weights, or risk scores (e.g., the basis could be normal industry practices or the MFI’s own historical experiences). They also would define the range of scores or assessments (e.g., low, medium, and high, or a numerical sequence, for example, 1 through 5). The written guidelines should specify:
·         The length of the audit cycles based on the scores or assessments. Audit cycles should not be open-ended. For example, some MFIs set audit cycles at 12 months or less for high-risk areas, 24 months or less for medium-risk areas, and 36 months or less for low-risk areas. However, individual judgment and circumstances at each MFI will determine the length of its audit cycles.
·         Guidelines for overriding risk assessments. The guidelines should specify who could override the assessments, the approval process for such overrides, and the reporting process for overrides. The override process should involve the board or its audit committee, perhaps through final approval authority or through timely notification procedures. Overrides of risk assessments should be more the exception than the rule.
·         Timing of risk assessments for each department or activity. Normally, risks are assessed annually, but they may need to be assessed more often if the MFI or a specific product experiences excessive growth (as between April 2007 – 2009), if MFI staff or activities change significantly, or changes to or new laws and regulations occur.
·         Minimum documentation requirements to support scoring or assessment decisions.

Management Responsibilities: Day-to-day management of the risk-based audit program rests with the internal auditor or internal audit manager, who monitors the audit scope and risk assessments to ensure that audit coverage remains adequate. The internal auditor or audit manager also prepares reports showing the risk rating, planned scope, and audit cycle for each area. The audit manager should confirm the risk assessment system’s reliability at least annually or whenever significant changes occur within a department or function.

Line department managers and auditors should work together in evaluating the risk in all departments and functions. Auditors and line department managers should discuss risk assessments to determine whether they are reasonable. However, the auditors, with concurrence of the board, audit committee or risk committee, should have ultimate responsibility for setting the final risk assessment. Auditors should periodically review the results of internal control processes and analyze financial or operational data for any effect on a risk assessment or weighting. Accordingly, MFI management should keep auditors current on all major changes in departments or functions, such as the introduction of a new product, implementation of a new system, changes in laws or regulations, or changes in organization or staff.

I hope that systemically important MFIs including large NBFCs wake up to have serious internal audits as part of their institutions…this alone can help prevent the kind of institutional lapses that led to the present day crisis…

Have a Nice Day!

Designing The Internal Audit Function At MFIs: Some Critical Issues…

Ramesh S Arunachalam
Rural Finance Practitioner  

Internal auditors play a very critical role in any organization and the same applies to micro-finance.

Role of Internal Auditors: The primary role of internal auditors is to independently and objectively review and evaluate an MFIs activities to maintain or improve the efficiency and effectiveness of risk management, internal controls, and corporate governance. They do this by:
·         Evaluating the reliability, adequacy, and effectiveness of accounting, operating, and administrative controls.
·         Ensuring that MFI internal controls result in prompt and accurate recording of transactions and proper safeguarding of assets.
·         Determining whether an MFI complies with laws and regulations and adheres to established policies.
·         Determining whether management is taking appropriate steps to address current and prior control deficiencies and audit report recommendations.

Internal auditors must understand an MFIs strategic direction, objectives, products, services, processes as well as clients to conduct these activities and make a judgement on the above. The auditors then communicate findings to the board of directors or its audit committee, who then will brief and discuss with senior management.

In addition, internal auditors often have a role in transformation activities. This role may include such duties as helping the board and management evaluate safeguards and controls, including appropriate documentation and audit trails, during the transformation process at the MFI – this is a very critical issue as many MFIs transform to become for profits from non-profits

Oversight and Structure: MFIs should conduct their internal audit activities according to existing professional standards and guidance. But how the internal audit function is accomplished depends on the MFI’s size, complexity, scope of activities, and risk profile, as well as the responsibilities assigned to the internal auditor by the board of directors.

In larger MFIs, a chief auditor and a full-time internal audit staff may accomplish the internal audit function. In other MFIs, the internal audit function may be accomplished by one or two employees or a holding company or even by an outside vendor. In many small MFIs, the officer or employee designated as a part-time auditor may also have operational responsibilities. In any case, to maintain independence, the person responsible for accomplishing the internal audit function should be independent of whatever area is being audited and should report findings directly to the board or its audit committee.

The audit committee should position the internal audit function in the institution’s organizational structure such that the function will perform its duties with impartiality and not be unduly influenced by managers of day-to-day operations. The ideal organizational arrangement is having the internal audit function report directly and solely to the audit committee regarding both internal audit issues and administrative matters, e.g., resources, budget, and compensation.

Some MFIs place the manager of internal audit under a dual reporting arrangement: functionally accountable to the audit committee for matters such as the design of audit plans and the review of audit scope and audit findings, while reporting to a senior executive on administrative matters. Such an arrangement potentially limits the internal audit manager’s independence and objectivity when auditing the senior executive’s lines of business. Thus, chief financial officer, controller, or other similar positions should generally be excluded from overseeing the internal audit activities even in a dual role. In structuring the reporting hierarchy, the audit committee should weigh this risk of diminished independence against the benefit of reduced administrative burden in adopting a dual reporting organizational structure. Under a dual reporting arrangement, the internal audit function’s objectivity and organizational stature is best served when the internal audit manager reports administratively to the chief executive officer.

That said, the best option of course is to ensure that the internal audit departmental head reports directly to the board or audit committee of the MFI, to ensure that all potential and real conflicts of interests are negated…

Have A Nice Day!

Thursday, April 28, 2011

Risk Management Systems in MFIs: Three Critical Aspects For Supervisory Examiners, Regulators, Bankers, Investors and Other Stakeholders…

Ramesh S Arunachalam
Rural Finance Practitioner  

Please recall that the Malegam committee report has recommended on-site supervision of large NBFC MFIs (although it is yet be accepted by the RBI). The key issue is that if the MCR proposals are accepted, then, supervisors will have to carry on examinations in such large NBFC MFIs, which would be some kind of a first for them. This post seeks to highlight some critical risk management issues for such supervisory/examination missions as well as the monitoring visits undertaken by bankers, investors and others including credit rating agencies. Read on…    

First, when examiners or other stakeholders assess risk management systems, they need to consider the MFI’s policies, processes, personnel, and control systems. If any of these areas is deficient, so is the MFI’s risk management. 

·         Policies are statements of actions adopted by the MFI to pursue certain results. Policies often set standards (on risk tolerances, for example) and should be consistent with a MFI’s underlying mission, values, and principles. A policy review should always be triggered when a MFI’s activities or standards change. The burgeoning growth experienced by the large Indian MFIs from April 2007 onwards should have prompted this…

·         Processes are the procedures, programs, and practices that impose order on the MFI’s pursuit of its objectives. Processes define how daily activities are carried out. Effective processes are consistent with the underlying policies and are governed by appropriate checks and balances (e.g., internal controls). Again, the phenomenal growth and the kind of results achieved in expanding client and portfolio outreach during the period April 2007 to March 2009 in India should certainly have caused the micro-finance industry (all stakeholders) to closely look (inward) at key processes. In fact, this would have clearly shown that the desire for faster growth and greater efficiency perhaps resulted in MFIs adopting short cuts in the various processes. Much of the process mapping and re-engineering done during this period achieved one impact very successfully – it reduced client level interaction and simply eliminated client relationship building in several places, to help MFIs gain efficiencies. Soon MFIs were just talking to various kinds of intermediaries (call them agents or business correspondents and the like) to add more clients and get them quicker than competition

·         Personnel are the MFI staff and managers that execute or oversee processes. Personnel should be qualified and competent, and should perform as expected. They should understand the MFI’s mission, values, policies, and processes. MFIs should design compensation programs to attract, develop, and retain qualified personnel. In addition, compensation programs should be structured in a manner that encourages strong risk management practices. Transformation (a key happening in Indian micro-finance) and consolidation present complicated personnel challenges. Any MFI transformation plan should lay out strategies for adding/retaining staff essential to risk management. Now, the huge growth in the aforementioned period coupled with fast rapid transformation meant that staff turnover was very high and all and sundry were hired and put into positions, without requisite training and orientation. In fact, because the staff were not committed to the original mission, in many MFIs, the mission that percolated to the field got hugely diluted and was focused on mindless and reckless growth, without considering the risks. Frauds and related strategies (like agency micro-finance model) were increasingly used to add more clients in a short time. Overall, the above factors again led to critical risk management issues being given a go by – in many cases, they existed on paper at the headquarters or regional offices but were hardly evident during implementation.

·         Control systems are the tools and information systems (e.g., internal/external audit programs) that MFI managers use to measure performance, make decisions about risk, and assess the effectiveness of processes. Feedback should be timely, accurate, and pertinent.  Now, when policies, processes and personnel are out of tune and literally perpetuate risk management, control systems will not work on the ground and that is what happened from April 2007 onwards in many MFIs

Thus, as noted above, it is critical for stakeholders to look at MFI policies, processes, personnel and control systems to come to a proper conclusion with regard to the MFI’s risk management system. 

Second, because market conditions and MFI structures vary, no single risk management system may work for all kinds of MFIs. The sophistication of risk management systems should be proportionate to the risks present and the size and complexity of an MFI, its operational environment and the like. As an MFI grows more diverse and complex in terms of its products, delivery models, capital sourcing, client demographics and the like, the sophistication of its risk management must also keep pace. Thus, risk management systems of large MFIs must be sufficiently comprehensive to enable senior management to identify and effectively manage the risk throughout the MFI’s diverse operations. Two other aspects deserve special mention here: a) In large MFIs, the focus of (examination) would have to be on the overall integrity and effectiveness of risk management systems; and b) Periodic validation must be a vital component of such large MFI examinations as only then can the integrity of these risk management systems over time be assessed. 

Third, sound risk management systems should be able to identify the key risks, measure them appropriately, monitor it continuously and control them where possible and necessary. These aspects are described below:

·         Identify risk: To properly identify risks, an MFI must recognize and understand existing risks and risks that may arise from new business initiatives, including risks that originate in sister institutions (subsidiaries in case of MFI holding companies) and/or affiliates, and those that arise from external market forces, or regulatory or statutory changes. Risk identification should be a continuing process, and should occur at both the transaction and portfolio level. A MFI must also identify interdependencies and correlations, across portfolios and lines of business, that may amplify risk exposures. Proper risk identification is critical for MFIs undergoing transformation (from one legal form to another) and consolidations to ensure that risks are appropriately addressed. Risk identification in transforming and consolidating MFIs begins with the establishment of uniform definitions of risk; a common language helps to ensure the success of transformation and consolidation.

·         Measure risk: Accurate and timely measurement of risk is essential to effective risk management. A MFI that does not have risk measurement tools has limited ability to control or monitor risk levels. Further, more sophisticated measurement tools are needed as the complexity of the risk increases. An MFI should periodically test to make sure that the measurement tools it uses are accurate. Sound risk measurement tools assess the risks of individual transactions and portfolios, as well as interdependencies, correlations, and aggregate risks across portfolios and lines of business. During MFI transformations and consolidations, the effectiveness of risk measurement tools is often impaired because of the technological incompatibility of the transforming systems or other problems of integration – I have seen this in some of the largest India MFIs that transformed activities from a society/MBT to an NBFC and the MIS and related integration was simply out of tune. Consequently, the resulting (new) company must make a concerted effort to ensure that risks are appropriately measured across the consolidated entity. Larger, more complex MFIs must assess the effect of increased transaction volume across all risk categories.

·         Monitor risk: MFIs should monitor risk levels to ensure timely review of risk positions and exceptions. Monitoring reports should be timely, accurate, and informative and should be distributed to appropriate individuals to ensure action, when needed. In many cases, I have seen reports being generated but gathering dust. Further, for large and complex MFIs, monitoring is essential to ensure that management’s decisions are implemented for all geographies, products, and legal entities (including Mutual Benefit Trusts – MBTs, that are a part of many Indian MFIs).

·         Control risk: MFIs should establish and communicate risk limits through policies, standards, and procedures that define responsibility and authority. These limits should serve as a means to control exposures to the various risks associated with the MFI’s activities. The limits should be tools that management can adjust when conditions or risk tolerances change. MFIs should also have a process to authorize and document exceptions or changes to risk limits when warranted. In MFIs transforming or consolidating, the transition should be tightly controlled; business plans, lines of authority, and accountability should be clear. Large, complex MFIs should have strong risk controls covering all geographies, products, and legal entities to prevent undue concentrations of risk.

Again, while the field of risk management is at its nascent best in Indian micro-finance, that should not deter us from asking the right questions during monitoring and supervisory examinations and I hope that various stakeholders involved in this crucial aspect recognize and seek to redress this on the ground in real time…

Have A Nice Day!

Monitoring The Quality of Internal Control in MFIs: Suggested Guiding Questions for Bankers, Investors, Regulators, Supervisors and Other Stakeholders…

Ramesh S Arunachalam
Rural Finance Practitioner  

As part of Malegam committee recommendations, micro-finance NBFCs are likely to come under supervision of the RBI, although the recommendations are as yet to be accepted by the Central Bank. Likewise, the RBI appointed working group on NBFC supervision, headed by former RBI deputy governor, Mrs Usha Thorat should also be recommending strategies for supervision of NBFCs (including NBFC MFIs).

In both cases, supervisors (examiners) would have to look at the formal/informal internal control and monitoring procedures at NBFC MFIs. That said, the key issue here is what questions should such supervisors and/or examiners ask to get appropriate information with regard to the quality of internal controls when they visit these NBFC MFIs. Please that these same questions are equally valid for bankers and investors who want to understand the quality of internal controls at NBFC MFIs. Likewise, these questions can also be suitably modified and used for MFIs incorporated as section 25 companies, cooperatives and the like.

Accordingly, this post provides a basic DRAFT questionnaire and it should assist supervisors (as well as regulators, examiners, bankers, investors and others) obtain critical information about an MFI’s formal/informal internal control and monitoring procedures. Depending on the specific characteristics and size of the MFI including legal form, the various stakeholders can also add and/or delete questions as appropriate.

Before moving on to the draft questionnaire, two specific issues deserve to be highlighted here. First, supervisors (or other stakeholders intending to judge quality of internal control) should preferably meet with the MFI’s chief executive officer (CEO), or the person most directly responsible for internal control (if it is not the CEO), to first conduct discussions on several aspects including board and management oversight, segregation of duties, dual control, employee policies, audit functions and the like. Second, they must also obtain and review appropriate reports and other information that substantiate management’s assertions on internal control (e.g., audit engagement letters, internal and external audit reports and management letters/responses, board reports, organizational charts, and policy/procedural manuals).  And to assist them in the above tasks, a set of key questions are given below:

Board and Management Oversight
  1. What goals and objectives have you (CEO or person directly responsible for internal control) and the board established for internal control (e.g., management oversight, dual control, rotation of duties, timing/frequency or reconciliations, internal control reviews, risk assessments, and frequency and scope of internal control audits)? Who is chiefly responsible for ensuring that those controls are adhered to? Does any one individual significantly influence board decisions or control activities?
  2. What accounting and information systems are in place to account for transactions, assets, and liabilities and ensure that risk-taking activities are within policy guidelines?
  3. What type of operational, financial, managerial, and compliance-related reports does the board receive concerning risk assessments and internal control? How frequently does it receive them? Who is involved in their preparation?
  4. What written board-approved policies and procedures addressing internal control, risk assessments, and ethics/conduct are in place?
  5. Who monitors compliance with internal control policies and procedures? Who performs risk assessments? What issues have been noted within the last 12 months?
  6. Do the board and its representatives have complete access to MFI records?
  7. How do you establish what are the proper controls for new or significantly revised products, services, or operational procedures? How do you evaluate the risks associated with planned or potential new products or activities or changes to existing products or activities? Are audit or other control review personnel involved when discussing, designing and implementing such products or activities? How are technology issues and risks considered and addressed?
  8. What new or significantly revised products, services, or operational procedures have you introduced since the last examination (will not apply when examination it happens first time)? What do you anticipate introducing within the next 12 months?
  9. What are the most significant risks facing the MFI today? What processes do you have in place to assess and control those risks?
Control Policies, Procedures, and Activities
  1. In general, describe your internal control process for ensuring segregation and rotation of duties. Are these applied MFI-wide, to all operational areas?  If not, why not?
  2. How do you ensure that the same employee does not originate a transaction, process it, and reconcile the general ledger account? How are approval authorities put in place, communicated to employees, and periodically tested?
  3. How often does someone independent of a specific function or department review reconciliations and other pertinent internal control to ensure that (1) reconciliations are timely and performed by an appropriate person, (2) out of date items are being researched for disposition, and (3) old items are charged off in a timely manner?
  4. In general, describe your dual control process over the MFI’s cash, cash collateral, official checks, and other such items.
  5. How do you ensure you have trained and qualified employees, including back-up employees, for all risk-taking activities and positions in the MFI?
  6. Do you have employee policies/procedures that assist in detecting breaches of internal control (e.g., pre-employment criminal background investigation, vacation policies, rotation of duty policies, frequency of obtaining employee credit reports, sampling employee accounts, and reporting of policy overrides/exceptions)?
  7. How do you communicate to employees, and do they understand, their roles in the control system, how their activities relate to others, and their accountability for the activities they conduct?
Audits
  1. How does the board review qualifications and independence of internal and external auditors?
Internal Audit
  1. Does the MFI have an internal audit or other control review function?
  2. Are any internal audit activities outsourced to another party? If yes, to whom? How are outsourced arrangements and activities supervised and managed?
  3. Describe the internal auditor’s educational background and experience. Who approves the hiring of key internal audit personnel?
  4. What other duties does the internal auditor perform?
  5. To whom does the internal auditor report? Who completes the internal auditor’s annual evaluation?
  6. Describe the scope and frequency of internal audits.
  7. Does the audit scope include an assessment of risk and internal control? Is compliance with established ethics/conduct policies periodically tested?
  8. Who reviews the internal audit report (department head, line manager, senior management, audit committee, board)? How frequent are reports and follow-up reviews? How do you ensure that the board or management is able to understand and act on findings? Who follows up on deficiencies (department head, line manager, internal auditor, Audit Committee)? What tests ensure that corrective action has been implemented? Who does the testing?
External Audit
  1. Which of the following types of external audits does the MFI receive:
  • Opinion audit (full financial statements).
  • Attestation report on internal control.
  • Opinion audit (balance sheet only).
  • Agreed-upon procedures (i.e., director’s exam).
  1. Who performs the MFI’s external audit (independent chartered accountant or other independent party) and how long have they been doing the MFI’s audit work? What was the cost of the most recent audit? What non-audit services does the external auditor or other outside party provide for the MFI? What are the fees for these services?
  2. Describe the scope and frequency of external audits and non-audit services.
  3. Is the opinion audit performed accounting to nationally (and globally) accepted accounting standards? Is the report on internal control performed to attestation standards? For non-opinion audits or internal control attestation engagements, does the scope specifically include an assessment and testing of financial reporting controls or other internal control? If so, who decides which control functions will be tested and validated?
  4. Who receives and reviews the external audit report or other reports issued by the external auditor (audit committee or board)?  How frequent are reports and follow-up reviews? Are reports sufficiently detailed to allow the board or management to understand and act on findings? Who follows up on deficiencies (department head/line manager, auditor, audit committee, etc.)? What tests ensure that corrective action has been implemented? Who does the testing?
  5. Who determines whether the external audit scope and frequency are adequate? Who ensures that the MFI received what they contracted for? In other words, who ensures that the audit embodies what is in the engagement letter, specifically in the statement of scope?
General Assessment
  1. How do you (the CEO or person in charge of the internal controls at the MFI) rate your overall internal control and monitoring procedures at the MFI - strong, satisfactory, or weak?
  2. What areas do you think exhibit the most operational risk given the MFI’s internal control environment, culture, and characteristics including size and growth strategy?
  3. What areas do you think exhibit the least operational risk given the MFI’s internal control environment, culture, and characteristics including size and growth strategy?

    The above starter’s and other questions can be used to get critical information on an MFIs internal control systems across a range of activities by supervisors, examiners and other stakeholders. And depending on the information received, further examination can be conducted and assessments made…

    And before I sign off, I would like to reiterate that we need to build up greater awareness in the entire micro-finance industry with regard to having (high) quality and appropriate internal controls, in real time (and not just on paper) and on the ground. That alone can perhaps be the long term insurance against AP like crisis situations in the future…
Have A Nice Day!

Wednesday, April 27, 2011

Board and Management Oversight in Internal Controls: That is Where The Buck Really Stops…

Ramesh S Arunachalam
Rural Finance Practitioner  

I recently heard a few commercial bankers mention that much of the problems in India micro-finance can be attributed to the consistent failure of the board and senior management of MFIs to create a strong and positive control environment. I told them that I felt the same way and had in fact written about it in a small measure in a previous blog post (http://microfinance-in-india.blogspot.com/2010/11/strengthening-internal-controls-during.html.

I am writing this post because these bankers wanted me to highlight the key issues in detail pertaining to the roles of the board and senior management with regard to control environment…especially, based on happenings from the field during the last 6 months

At the outset, let me clarify that the hallmark of a positive control environment is a commitment by the board of directors and senior management to strong controls. And that is where the buck really stops and I hope MFIs will learn from the present Indian crisis and ensure this in real time…Read on…and here are some practical suggestions…

First, as noted above, an MFI’s board of directors and management are mainly responsible for establishing and maintaining an effective internal control system that meets statutory and regulatory requirements and responds to changes in the MFI’s environment and conditions. Thus, they must ensure that the system operates as intended and is modified appropriately when circumstances dictate – as is presently the case in India and especially given the multiple lending, use of agents, frauds and other happenings (of not-so-good processes). I hope that MFI boards and management have begun looking at various field realities in this regard

Second, the board and management must also ensure that the MFI’s information systems produce pertinent, timely and reliable/valid information in a form that will enable staff, auditors, and others stakeholders (as appropriate) to carry out their respective responsibilities. This is a very vital aspect and again, the MIS of many MFIs falls short of required standards on several facets and I again hope that MFI boards and management have started to address the various deficiencies in an honest manner. Please see following post in this regard - http://microfinance-in-india.blogspot.com/2010/11/understanding-state-of-management.html

Third, the board (of directors), which oversees the control system in general, approves and reviews the business strategies and policies that govern the system. They are therefore also responsible for: (a) understanding risk limits and setting acceptable ones for the MFI’s major business activities; (b) establishing the organizational control structure; and (c) making sure that senior management identifies, measures, monitors, and controls risks as well as monitors internal control effectiveness. I really hope that the MFI boards, especially with nominee directors from institutions like SIDBI and other investors, begin to perform these functions seriously

Among other things, this would require MFI boards to: (1) discuss periodically the internal control system’s effectiveness with management; (2) review internal control evaluations conducted by management, auditors, and other stakeholders in a timely manner; (3) monitor management’s actions on auditor and other third party reviewers’ (like staff of rating companies or supervisors, if the Malegam Committee Report is implemented) internal control recommendations and concerns; and (4) periodically review the MFI’s strategy and risk limits. If the board lacks the time, it could also consider delegating these duties and responsibilities to an audit committee, risk committee, or both – this of course would depend on the size and structure of the MFI in question. I would strong recommend that MFI boards have a separate risk committee other than the audit committee

Fourth, senior management oversees operations and provides leadership and direction for the communication and monitoring of control policies, practices, and processes. In effect, they (are to) implement the board’s strategies and policies by establishing effective internal control and delegating or allocating control duties and responsibilities to appropriate personnel. Senior management is also responsible for performing background checks on staff members before they are hired and ensuring that they are qualified, experienced, trained, and compensated to effectively conduct control activities. I hope that senior management in MFIs start to focus on these tasks with utmost seriousness and urgency. Much of the problems that have occurred in Andhra Pradesh relates to lack of appropriate and trained personnel with regard to maintaining effective internal controls and that needs to be addressed at various (MFI) levels immediately

Fifth, organizations grow and the environment changes and therefore the board and management must continually evaluate whether the control system’s methods, records, and procedures are proper in relation to the MFI’s changing asset size, organizational and ownership characteristics, business activities, operational and environmental complexity, risk profile, methods of processing and maintaining data, legal and regulatory requirements and the like. Assuming that the world of tomorrow or today is the same as that of yesterday is a serious flaw that was committed by many MFIs with regard to their control environment and this needs to be addressed immediately

Last but not the least, the board of directors must ensure that management properly considers the risks and control issues of emerging MIS and related technologies, enhanced information systems, and various of electronic/mobile banking. These issues typically include: more users with access to information systems; less segregated duties; a shift from paper to electronic audit trails; a lack of appropriate standards and controls for end-user systems; and, more complex contingency planning and recovery planning for information systems.

Thus, board and senior management can play a very useful and positive role in continually shaping the control environment and they must do so on a regular basis – I really wish that the enthusiasm to serve on MFIs boards is also accompanied by the drive and desire to work with MFIs to enable them to improve their somewhat nascent (control) systems in comparison to their burgeoning growth and complex operational environment. This is undoubtedly a priority task for most MFIs, especially in the crisis ridden Indian micro-finance industry…

Have A Nice Day!

Critical Internal Control Components in MFIs: Some Simple Ideas…

Ramesh S Arunachalam
Rural Finance Practitioner 

I was recently talking to an MFI manager and he said that there is lack of clarity with regard to some of the concepts of internal control systems at MFIs. I attempt to highlight key issues in this post…in a simple and practical manner…

The formality of any control system will depend largely on a MFI’s size, the complexity of its operations, and its risk profile. Less formal and structured internal control systems at community MFIs can be as effective as more formal and structured internal control systems at larger and more complex MFIs. That said, every effective (internal) control system should have the following:
A.      A control environment.
B.     Risk assessment.
C.     Control activities.
D.     Accounting, information, and communication systems.
E.     Self-assessment or monitoring.

A) The control environment reflects the board of directors’ and management’s commitment to internal control. It provides discipline and structure to the control system. Elements of the control environment include:
1)      The organizational structure of the institution. Here, one would look at issues such as:
o       Is the MFI’s organization centralized or decentralized?
o       Are authorities and lines of responsibilities clear?
o       Is there commensurate authority with responsibility to ensure that things get done?
o       Are reporting relationships well designed?
o       Are there any conflicts of interest
2)      Management’s philosophy and operating style. Likewise, the key aspects here are:
Ø      Is the MFI’s business strategy formal or informal?
Ø      Is its philosophy and operating style conservative or aggressive?
Ø      Does it have risk strategies and have they been successful?
3)      The integrity, ethics, and competence of personnel.
4)      The external influences that affect the MFI’s operations and risk management practices (e.g., independent audits).
5)      The attention (time, effort and resources) and direction provided by the board of directors and its committees, especially the audit or risk management committees.
6)      The effectiveness (including implementation) of human resources policies and procedures.

B) Risk assessment is the identification, measurement, and analysis of risks, both internal and external, controllable and uncontrollable, at individual unit levels and for the MFI as a whole. Management must assess all risks (including political risk) facing the MFI because uncontrolled risk-taking can prevent the MFI from reaching its objectives or can jeopardize its operations. Effective risk assessments help determine what the risks are, what controls are needed, and how they should be managed. This is something that was, by and large, ignored by many MFIs and it is one of the main reasons for the problems in the ground in Indian micro-finance

C) Control activities are the policies, procedures, and practices established to help ensure that MFI personnel carry out board and management directives at every business level throughout the MFI. These activities help ensure that the board and management act to control risks that could prevent a MFI from attaining its objectives. They should typically include:
·         Reviews of operating performance and exception reports. For example, senior management regularly should review reports showing financial results to date versus budget amounts, and the loan department manager should review weekly reports on delinquencies or documentation exceptions.
·         Approvals and authorization for transactions and activities. For example, an appropriate level of management should approve and authorize all transactions over a specified limit, and authorization should require dual signatures.
·         Segregation of duties to reduce a person’s opportunity to commit and conceal fraud or errors. For example, assets should not be in the custody of the person who authorizes or records transactions. Please see following post on increasing frauds at MFIs: http://microfinance-in-india.blogspot.com/2010/11/has-burgeoning-growth-caused-increasing.html and related post: http://microfinance-in-india.blogspot.com/2011/04/mfi-staff-srinivasi-agent-amulu-and.html
·         The requirement that officers and employees in sensitive positions be absent for at least two to three consecutive weeks each year.
·         Design and use of documents and records to help ensure that transactions and events are recorded. For example, using pre-numbered documents (receipts) facilitates monitoring.
·         Safeguards for access to and use of assets and records. To safeguard data processing areas, for example, a MFI should secure facilities and control access to computer programs and data files.
·         Independent checks on whether jobs are getting done and recorded amounts are accurate. Examples of independent checks include account reconciliation, computer-programmed controls, management review of reports that summarize account balances, and user review of computer-generated reports.

In reality, some MFIs have written internal control procedures in all areas but having them (on paper) is not enough. Staff and personnel at various levels must understand control procedures and follow them conscientiously in practice. That is what was missing at some Indian MFIs in the present crisis

D) Accounting, information, and communication systems capture and impart pertinent, timely and reliable/valid (accurate) information in a form that enables the board, management, and employees to carry out their responsibilities. Accounting systems are the methods and records that identify, assemble, analyze, classify, record, and report a MFI’s transactions. Information and communication systems enable all personnel to understand their roles in the control system, how their roles relate to others, and their accountability. Information systems produce reports on operations, finance, and compliance that enable management and the board to run the MFI. Communication systems facilitate dissemination of this information throughout the MFI and to external parties such as shareholders, lenders, investors, regulators, supervisors and clients

E) Self-assessment or monitoring is the MFI’s own oversight of the control system’s performance. Self-assessments are evaluations of departmental or operational controls by persons within the area. Ongoing monitoring should be part of the normal course of daily operations and activities. Internal and external audit functions, as part of the monitoring system, may provide independent assessments of the quality and effectiveness of a control system’s design and performance. All MFI personnel should share responsibility for self-assessment or monitoring; everyone should understand his or her responsibility to report any breaches of the control system.

Thus, a strong control culture at an MFI would typically incorporate qualified personnel, effective risk identification and analysis, clear designation and appropriate separation of responsibilities, accurate and timely flow of reliable/valid information, and established monitoring and follow-up processes[i]. And I hope that Indian MFIs start to review their control systems, using the above (simple) framework and work towards building a better internal control system that is not only appropriate to their operational environment but also the size and complexity of their overall micro-finance operations

Have A Nice Day!



[i] For example, the lending area should have (1) a board of directors active in approving and monitoring loan policies and practices; (2) a loan review function that evaluates the risk and quality of loan portfolios; (3) policies and procedures governing, among other things, types of loans, loan approvals, maturity limits, rate structures, and collateral requirements (if the MFI is using individual lending and is delivering larger livelihood loans); and (4) information systems that allow for proper management and monitoring of the lending area.