Internal audit is the third line of defence in a bank's governance structure. Its role is to provide independent, objective assurance to the board and senior management that the risk management and control frameworks — designed and operated by the first and second lines — are adequate and functioning effectively. In a capital markets context, this is technically demanding work: auditing a trading desk requires understanding derivatives valuation, risk limits, market microstructure, and the regulatory requirements that govern each product and activity.

Independence and Reporting Lines

The independence of internal audit is fundamental to its value. An audit function that reports to the Chief Risk Officer or the Head of Markets is compromised: it cannot independently assess the effectiveness of the people and functions to whom it reports. Best practice, and regulatory expectation, is that the Chief Internal Auditor (CIA) reports functionally to the board audit committee and administratively to the CEO. This dual reporting line preserves independence while maintaining operational connectivity.

The PRA expects to meet with the CIA of significant banks at least annually, separately from management. It reviews the audit function's coverage plan, its resourcing, the independence of its findings, and the quality of management's remediation of issues. A CIA who is routinely overruled by management on audit findings, or whose function lacks the skills and resources to audit complex trading activities effectively, will attract regulatory concern. The PRA's supervisory assessment of a firm's governance includes an explicit view of the quality of its internal audit function.

The Risk-Based Audit Plan

Internal audit does not audit everything every year. Resources are finite, and a risk-based approach prioritises coverage of the areas that pose the greatest risk to the firm. The annual audit plan is built from a risk assessment — typically a universe of auditable entities (individual business lines, functions, processes, and legal entities) each assessed for inherent risk and control quality. High inherent risk combined with low control quality generates a high audit priority; low inherent risk with strong controls may result in reduced or lighter-touch coverage.

For a capital markets bank, the trading desks themselves are typically among the highest-priority audit entities. A desk running large, complex derivative books with significant market risk, model dependency, and regulatory reporting obligations will attract audit attention every one to two years. Support functions — settlement, collateral management, financial reporting — are also on the plan, with frequency calibrated to their risk profile.

The audit plan is approved by the board audit committee and is not merely a management exercise. If the CIA believes that a particular area requires urgent coverage — because of a new product launch, a significant market event, or intelligence suggesting a control weakness — they can add unplanned reviews. Ad hoc reviews requested by management or regulators also sit within the audit plan.

Auditing Trading Controls

A trading controls audit is among the most complex and consequential reviews internal audit can conduct. The key areas of focus include:

Limit Framework

Auditors test whether the limit framework is comprehensive (covering all material risk types: VaR, DV01, notional, stop-loss, counterparty credit), whether limits are set at an appropriate level given the desk's strategy and the firm's risk appetite, and whether the limit monitoring and breach escalation process works effectively. This involves reviewing the approval authorities for limit changes, testing whether limit breaches are escalated promptly, and examining whether senior management and the board receive accurate MI on limit utilisation.

Trade Authorisation

Each trade executed by a desk should be authorised within the desk's product mandate. Auditors test whether the front office is executing only products for which it has approval — checking against the new product approval framework — and whether any unauthorised activities have occurred and been detected. High-profile unauthorised trading cases (Nick Leeson at Barings, Jerome Kerviel at SocGen) have consistently shown failures in basic authorisation and reconciliation controls. Auditors look for these failure modes specifically.

Valuation and P&L

The P&L reported by a trading desk is the product of valuations applied to its positions. Auditors test the independence and reliability of the valuation process — whether pricing is genuinely independent of the traders who manage the positions, whether model valuations are subject to independent price verification (IPV), and whether P&L attribution (explaining daily P&L by risk factor moves) is performed and reviewed. Valuation manipulation — traders marking positions away from fair value to smooth P&L or hide losses — is a perennial risk that audit is specifically designed to catch.

Operational Audit: Settlement and Reconciliation

Behind every trade is an operational chain: confirmation, settlement, cash and securities movements, and reconciliation. Operational failures in this chain can result in financial losses (failed settlements, incorrect cash flows), regulatory breaches (late reporting, client money failures), and reputational damage. Internal audit tests the controls across this chain: the confirmation matching process, the settlement failure management process, the reconciliation between front-office positions and back-office records, and the break investigation and resolution process.

Collateral management is a specific area of operational audit focus. As collateral flows (initial margin, variation margin) under regulatory margin rules have grown enormously post-2016, the operational infrastructure for managing collateral has become a material source of operational risk. Auditors test whether margin calls are issued and received accurately, whether disputes are managed within regulatory timeframes, and whether the collateral inventory is correctly reflected in the firm's financial and regulatory reporting.

Model Audit

Pricing models used by trading desks are subject to model risk — the risk that a model is wrong, misused, or misunderstood, and that errors in model outputs lead to financial losses, mispriced risk, or flawed decisions. Internal audit assesses the model governance framework: whether models are inventoried and classified, whether all models in the inventory have been independently validated, whether models are used within their approved scope, and whether model limitations are communicated to users and reflected in reserves or capital add-ons.

Model audit requires specialist skills. Auditors need to be able to read quantitative model documentation, understand the conceptual basis of common pricing approaches, and assess the quality of validation testing. Many capital markets internal audit teams have dedicated model risk auditors — typically with mathematical finance or quantitative risk backgrounds — to cover this area.

Findings, Ratings, and Remediation

Audit findings are rated by severity. Rating scales vary by firm but typically run from Advisory (minor finding, no significant control failure) through Moderate and Significant to Critical (a material control failure requiring immediate remediation). Critical findings are typically reported immediately to the board audit committee and may be shared with the PRA or FCA depending on the nature of the failure.

Management is required to agree remediation actions and target completion dates for all findings above a minimum rating. The tracking of open findings — ensuring that management delivers on its agreed remediation commitments — is a core ongoing audit activity. Regulators assess the age and volume of open audit findings as an indicator of management's seriousness about the control environment: a large backlog of overdue high-severity findings signals a governance problem.