Showing posts with label Shari'ah Audit. Show all posts
Showing posts with label Shari'ah Audit. Show all posts

Tuesday, May 20, 2014

My Article Published in the Edge

SHARI’AH AUDIT: FROM COMPLIANCE TO ASSURANCE


From 2012, all Islamic financial institutions (IFIs) in Malaysia are required by Bank Negara Malaysia (BNM) to observe and comply with the Shari’ah Governance Framework (SGF). The SGF is a set of organisational arrangements through which IFIs ensure effective oversight, responsibility and accountability of the board of directors, the management and the Shari’ah Committee. Ultimately, the SGF serves as a guide towards ensuring an operating environment that is compliant with Shari’ah principles.

The SGF, to a certain extent, has successfully reinforced the Shari’ah compliance functions, internal Shari’ah review and audit requirements, supported by an appropriate risk management process and research capability. The implementation of the SGF so far has contributed towards Shari’ah compliance process. However, currently, the Islamic financial industry lacks a robust Shari’ah assurance process.

Shari’ah audit is essentially an assurance process as it should be conducted by independent auditors. Shari’ah audit is needed to fill the gap of Shari'ah compliant activities and services of the IFIs. The stakeholders need to be assured that the institutions that offer Islamic financial services have sufficient levels of Shari’ah assurance processes and controls. Today, mere claims by the IFIs that they are fully Shari’ah compliant may no longer be sufficient. Independent assurance through Shari’ah audit is essential to enhance the integrity and the accountability of the IFIs.

Pitfalls of the SGF

The SGF requires all IFIs to establish Shari’ah audit function that performs annual audits in order to provide an independent assessment of the adequacy and compliance with established policies and procedures, and the adequacy of the Shari'ah governance process. Closer scrutiny of the SGF indicates that the Framework did not sufficiently explain the requirements and the functions of Shari’ah audit. The best example would be the crucial relationship between the Shari’ah audit and the Shari’ah risk management which was not clearly spelled out.

There is also a lack of guidance as to the level of appropriateness of Shari’ah risk management framework. Instead the SGF expects the IFIs to develop their own risk management framework. Realising the uniqueness and complexities of Shari’ah non-compliance risks, Shari’ah risk management function should be properly developed before the IFIs can effectively undertake Shari’ah audit. Shari’ah non-compliance risk indicators and measurement should be clearly identified. In addition, the line of reporting and responsibility on Shari’ah risk management should also be clearly expounded.

On another note, the SGF specifies that the Shari’ah audit shall be performed by the internal auditors, whom are trained and have adequate knowledge of Shari’ah. However, the SGF did not specify the level of Shari’ah knowledge and the specific areas of Shari’ah that they need to equip themselves. The nature of their work requires specialised knowledge of Shari’ah essential for them to carry out their work effectively. The IFIs should also be required to create special positions of Shari’ah auditors within their internal audit division.

The SGF has also purposely excluded the function of external Shari’ah audit. External audit, in contrast to internal audit, represents the third party role to provide check and balance of the Shari’ah assurance requirements. Similar to external financial audit, the absence of external and independent audit reports by qualified Shari’ah auditors will certainly affect the credibility of IFIs in the eyes of stakeholders.

One important governance concern is on the line of authority of Shari’ah audit function. As per the SGF, Shari’ah audit is directly answerable to the audit committee. Unfortunately, the audit committee’s present scope of work is already very demanding. To expect them to plan and to scrutinise the Shari’ah audit would be an additional burden and responsibility that may affect the overall efficiency of audit committee.

Another taken for granted issue is on the role of Shari’ah committee with regards to Shari’ah audit function. There is a dire need for a comprehensive guideline in the case where there is a dispute or different of opinion between the management and the Shari’ah auditors on matters relating to Shari’ah interpretation. By right, all disputes or differences shall be referred to the Shari’ah committee of the IFIs.

In theory, the Shari’ah committee and the Shari’ah auditors should be responsible to jointly plan the Shari’ah audit. Once the Shari’ah audit function is performed by the auditors then it must be reported directly to the Shari’ah committee and the audit committee for deliberations and remedial actions. The final report must then be tabled to the board of directors for their attention and further action.  

The Urgent Need for Shari’ah Audit Framework

The above arguments indicate an urgent need for the Shari’ah Audit Framework that should complement the SGF. The primary objective of this elusive Framework is to provide guidelines for the management to properly discharge their responsibilities according to Shari’ah rules and principles. In addition, the purpose of the Framework is to ensure that the system of internal control for Shari’ah compliance is conceptually sound and effective in its implementation.

The Shari’ah Audit Framework is needed to clearly specify the roles and functions of both the internal and the external Shari’ah auditors. Shari’ah auditors should have direct and regular communications with all levels of management and the Shari’ah committee. Knowing the sensitivity of some Shari’ah issues, there should not be any scope limitation and restriction of access to evidences, documents, reports etc. in order for the Shari’ah auditors to undertake their work. This is to ensure the efficiency and the effectiveness of Shari’ah audit function.

The need for a more robust Shari’ah assurance function – not just Shari’ah compliance - should be considered seriously by BNM. The need for a comprehensive Shari’ah Audit Framework to guide the industry is long overdue. The issues raised above are only `tips on the iceberg’ and certainly there are many other outstanding issues facing the Islamic financial industry. The imperative next step is the need for a comprehensive guideline on Shari’ah audit to ensure that all activities and operations of the IFIs truly in compliance with Shari’ah.

Shariah Audit Conference 2014


This article has argued for the need of a more robust Shari’ah audit function and guidelines. Realising the increasing demand for greater integrity and transparency of IFIs, the Institute of Internal Auditors Malaysia (IIAM) will organise a Shariah Audit Conference 2014 after a successful inaugural event organised by the industry’s association in 2011. IIAM in collaboration with the Islamic Banking and Finance Institute Malaysia (IBFIM) will organise this important event on 20th and 21st May 2014 at Hotel Istana, Kuala Lumpur. This event will hopefully be able to discuss the pertinent issues of Shari’ah audit and to explore future direction of this nascent industry. The shift of focus from Shari’ah compliance to Shari’ah assurance is indeed crucial to enhance the public confidence of the IFis which in turn contributes toward sustainable growth of the Islamic financial industry.

Friday, April 25, 2014

Shari'ah Audit: The Way Forward

Shari'ah audit for Islamic financial institutions (IFIs) is an emerging practice. Shari'ah audit is important to provide Shari'ah assurance rather than just Shari'ah compliance. It is crucial to ensure credibility and enhance integrity of IFIs. Shari'ah Governance Framework (SGF 2011) has charted the path for Shariah audit in Malaysia. Many IFIs have started embarking on Shari'ah audit. Some are still struggling to practice as Shari'ah audit needs the understanding and the expertise of both the financial services and the Shari'ah.

The shift of focus from internal compliance to independence assurance is a requirement and no longer an option. It is not enough to claim that they are Shari'ah compliance without a robust practice of Shari'ah assurance through internal or/and external audit. More importantly now is the importance to link Shariah assurance and Shari'ah risk management. The SGF 2011 does not address this critical link sufficiently. I believed the next step of development is to develop a robust methodology for risk identification, risk measurement, risk mitigation etc. for Shari'ah non-compliance risk.

At the end of next month, there will be a conference to be organised by Institute of Internal Auditors Malaysia on Shari'ah Audit. They have requested me to write an article to promote the conference in the Edge. Hopefully, I will be able to write a piece of my thought soon. I intend to write on the importance of linking Shari'ah audit and Shari'ah risk management. The link is to ensure proper management and reporting of Shari'ah risk management (pre event) and Shari'ah audit (post event).    

Thursday, June 2, 2011

Exposure Draft Shari'ah Audit Framework

Alhamdulillah, after extensive works, research and meetings for 8 months i.e. from September 2010 to May 2011, the exposure draft of the Shari'ah Audit Framework finally completed. This 9th. June, we will have the fourth feedback sessions from the industry players and working group members. We hope in July ISRA will organise a Thematic Workshop to get wider feedbacks from industry and stakeholders. I pray hard that the final output later to be presented to BNM will be a success. A small contribution towards a integrity of IFIs in Malaysia, inshaallah.

Saturday, November 27, 2010

Shari'ah Audit Framework

Currently, I am heading a research group to develop Shari'ah Audit Framework for Islamic financial institutions. This research group is part of ISRA (International Shari'ah Research Academy of Islamic Finance), a research arm of Bank Negara Malaysia (BNM). This Framework will then be considered by BNM to be implemented later, inshaallah. The Framework will complement the Shari'ah Governance Frameowrk recently issued also by BNM.

The Framework will address a number of issues such as Shari'ah risk management, Shari'ah internal control system, internal Shari'ah audit, and external Shari'ah audit. The research group has started work in September 2010, and we hope to complete the task latest by the end of February 2010. The proposed Framework will be subjected a number due process especially feedbacks from industry players who will be affected by the Framework.

On the 15th. and 16th. of December 2010, I will be involved in a Workshop on Shari'ah Audit for Islamic Finance to be organised by CERT (Centre for Research and Training), a local established training provider in Islamic finance in Malaysia. This Workshop hopefully will share with the participants the issues on Shari'ah governance and audit in a more focussed discussion.

Thanks.