Updated : 17 Mar 2023
  • Annual audit planning
  •  
    • Group Internal Audit (GIA) adopts a risk-based approach to develop the annual audit plan, which is focused on top and emerging risks facing the HKEX Group. At least annually, audit teams perform risk assessments to evaluate the key risks associated with the business, corporate and second line functions of the Group. The risk assessment process incorporates a top-down and bottom-up process to identify, assess and challenge the key risk exposures of HKEX which is then built into the audit plan.
    • Independent reviews of different financial, IT, business and functional operations and activities are conducted with resources focusing on areas with higher risk. Ad hoc reviews are also conducted on areas of concern identified by the Audit Committee, GIA and the management.
  • Analysing the process and assessing controls
  •  
    • Audit procedures include evaluation of the design and operating effectiveness of key controls to mitigate the risk exposure in the area audited.
    • Data analytics and innovation audit tools are used to enhance audit efficiency, increase sampling coverage and provide insights to management and relevant stakeholders.
  • Communicating results and monitoring follow-up actions
  •  
    • Internal audit reports are issued to the accountable executives of the responsible Division/Department, and copied to Chief Executive Officer, Group Risk Management and Group Compliance informing them of the identified control deficiencies together with agreed management actions.
    • Significant internal control weaknesses are brought to the attention of management and the Audit Committee on a timely basis and if necessary, to the Board and to the Management Committee. GIA activities are reported to the Audit Committee regularly.
    • GIA performs audit issue closure validation to evaluate the design and operating effectiveness of controls for management actions that address audit issues. Results of the issue closure validation are reported to the Audit Committee regularly.