Independent Internal Audit

Our internal audit consultants have the audit and compliance expertise to ensure institutions comply with laws, regulations, and internal polices in a challenging and dynamic regulatory environment. CrossCheck performs independent tests of an institution’s operations to identify potential control or execution failures at a point in time.

business man reviewing audit documentation

Risk-Based Internal Audit

CrossCheck consultants can execute all or a portion of your operational or compliance internal audits, conduct a firm-wide internal audit risk assessment, and develop a risk-based internal audit plan. An objective assessment of the likelihood and impact of financial, operational, and compliance risks and mitigating controls help focus the internal audit plan.
Internal Audit Risk Assessment & Audit Plan Development

Identification and prioritization of risks allows you to focus on areas most important to meeting your business goals. An objective assessment of the likelihood and impact of financial, operational, and compliance risk and mitigating controls help drive the focal points of your internal audit plan.

Operational Audits

Control design and effectiveness and risk management processes are imperative for well-controlled institutions. Review of policies and procedures, key personnel interviews, and testing will determine the completeness and effectiveness of existing controls in mitigating risks inherent in daily execution of activities. Recommendations address root causes to prevent recurrence.

Auditable areas include:

  • Deposit and Loan Operations
  • Secondary Marketing
  • Branch Operations
  • Accounting
  • Asset Liability Management
  • Funds Management – Investments
  • Payroll/Human Resources
  • Wire Transfer
  • Third-Party/Vendor Management
  • Mortgage Electronic Registration Systems (MERS) Audits
Compliance Audits

An independent compliance audit will assess whether the CMS is operating as intended and maximizes compliance performance. In addition to a full review of the CMS and regulations applicable to a client’s products and services, CrossCheck performs targeted compliance reviews across key regulatory areas.

Compliance audits we perform:

  • Consumer deposit and lending regulations
  • Consumer deposit products and services
  • Loan origination and loan servicing regulations
  • Anti-Money Laundering/Countering the Financing of Terrorism (AML/CFT) regulations
  • Advertising and website regulations
MERS Audit, Quality Assurance, & Reconciliation Services

CrossCheck performs the MERS® audit (Annual Report) due on December 31 that confirms the member’s processes and controls are in place, ensuring compliance with MERS® requirements. In addition, CrossCheck can also perform loan servicing system data reconciliations to MERS® system data and required quality assurance reviews.

Internal Audit FAQs

What risk factors should we prioritize when developing an internal audit plan?

The most effective audit plans are risk-based, multi-year plans supported by a comprehensive audit risk assessment. An internal audit plan should focus on auditable areas with the highest potential impact on financial performance,operational efficiency, and regulatory compliance. Auditable areas include product sales and operations, compliance management systems (CMS), credit quality, third-party/vendor relationships, AML/CFT program, and required third-party audits such as MERS®. Prioritizing risks based on both likelihood and potential impact ensures internal audits are risk-focused, efficient, and aligned with strategic business objectives. Many organizations benefit from a third-party risk assessment to validate their priorities and uncover less obvious vulnerabilities.

What signs indicate potential weaknesses in our internal controls?

Indicators that internal controls could be improved include errors in operational processes, regulatory violations, repeat audit findings, or inconsistent adherence to policies. Other areas to watch are gaps in documentation, delayed follow-up on corrective actions, or customer complaints. A structured, independent audit can help highlight these opportunities and provide practical recommendations to enhance the effectiveness of your control environment.

When would it be helpful to engage an independent review or co-sourced support for our internal audit function?

Situations where additional perspective can add value include limited internal audit resources, new/evolving regulatory requirements, or areas requiring specialized expertise. Organizations experiencing growth, entering new markets, or seeking to enhance audit effectiveness may benefit from independent review or co-sourcing. Partnering with an external audit expert can supplement internal capabilities, provide a fresh perspective, and help ensure your audit coverage aligns with industry best practices and your organization’s risk appetite.

How can our internal audit function help ensure we meet regulatory requirements and satisfy investor expectations?

Internal audits provide objective assurance that operational, financial, and compliance risks are effectively managed. By evaluating control design, testing operational processes, and reviewing adherence to regulatory requirements and an institution’s policies and procedures, internal audits help management ensure compliance with investor and regulatory requirements. Audits also provide actionable insights for remediation, enhancing efficiency, transparency, and supporting regulatory examinations, investor reporting, and overall corporate governance.

How often should we assess the effectiveness of our compliance management system (CMS)?

The frequency of assessing your compliance management system (CMS) should reflect both regulatory expectations and the institution’s risk profile. While a comprehensive annual review provides a baseline of effectiveness, higher-risk areas—such as mortgage lending, AML/CFT programs, or new or changing products or services —warrant more frequent targeted evaluations. Ongoing monitoring and periodic independent audits not only validate that policies and procedures are operating as intended but also provide the board and management with actionable insights to strengthen controls, support regulatory examinations, and reinforce a culture of proactive compliance.

How should institutions adapt internal audit priorities as regulations and business risks evolve?

Institutions should continuously align their internal audit priorities with both the regulatory landscape and the organization’s strategic initiatives and risk appetite. This requires integrating insights from enterprise risk management, emerging regulatory guidance, and operational trends into the audit plan. A dynamic, risk-based audit approach enables leadership to allocate resources efficiently, focus on areas with the greatest potential impact, and anticipate regulatory scrutiny before issues arise. Leveraging external audit partners or industry specialists can provide independent benchmarking, identify emerging risks not yet on internal radars, and guide the audit function toward practices observed in high-performing institutions.

What are the best ways to track corrective actions from previous audit findings?

Tracking corrective actions requires a formalized process, including clear documentation, assigned accountability, and deadlines for remediation. Audit committees should regularly review progress, and management should integrate findings into ongoing risk management discussions. Technology solutions or audit management platforms can streamline tracking, while periodic follow-up audits ensure that remediation is effective and sustainable. Independent auditors can provide assurance that corrective actions address root causes rather than symptoms.

Which compliance areas should we monitor more closely to reduce regulatory fines?

While all compliance areas require oversight, certain areas consistently present higher regulatory risk and warrant focused attention. These include lending related regulations (such as TILA, RESPA, ECOA, Flood Disaster Protection Act) and deposit regulations (such as TISA, Regulation CC, Regulation E), AML/CFT programs, mortgage servicing and MERS® reporting, advertising and marketing compliance. Beyond regulatory requirements, prioritization should consider institutional risk exposure, recent audit findings, and emerging regulatory trends. A risk-based internal audit approach, potentially supplemented by independent or co-sourced expertise, can provide deeper assurance, identify gaps before they escalate, and support proactive management of regulatory expectations.

Representative Engagements

Implementing an Effective Internal Audit Function

A well-established audit function should provide management and key stakeholders with ongoing assurance of the effectiveness of the company’s control environment and risk management processes. Learn how to establish an independent, effective internal audit function that promotes good corporate governance in our whitepaper.

group of businesspeople reviewing plans on devices

Featured Resources

Strengthen Your Internal Audit Oversight

Gain actionable insights and independent assurance to enhance controls, mitigate risk, and support regulatory compliance.