2014 Annual Report
The Audit Committee’s assessment of Internal Audit, Internal Control, Risk Management and Regulatory Compliance Functions; Committee Activities during the reporting period

Internal audit, internal control and risk management activities at Türkiye Finans are carried out by the Board of Auditors, the Internal Control Department, and the Risk Management Center, all of whose duties and responsibilities are spelled out in published regulations and which are organizationally independent of each other. The activities of these units are coordinated by the Audit Committee acting on behalf of the Board of Directors. The Regulatory Compliance Department also reports to the Board of Directors through the Audit Committee.

Internal Audit (Board of Auditors)

The Board of Auditors reports to the Board of Directors through the Audit Committee. The Board of Auditors is responsible for performing audits, inspections and investigations on behalf of the Board of Directors in line with the schedule and instructions provided by the Chairman.

The Board’s fundamental objective is to provide independent and impartial compliance and consultancy services that safeguard the activities of the Bank and its affiliates subject to consolidation and generate added value. Operating within currently applicable laws and related external regulatory frameworks, and the Bank’s own strategies, policies, principles and targets, the board provides assurance to the Senior Management concerning the effective and sufficiency of the Bank’s internal control, risk management systems and governance processes. The board aims to help the Bank reach its targets by introducing a systemic and disciplined approach in order to evaluate and improve the related systems.

Within the scope of the 2014 audit plan, audit activities were conducted in various selected Branches and units in the Headquarters based on the risk-oriented audit approach. In addition, audits into the information systems were maintained by IS inspectors. With these audit activities, investigations and inspections regarding the board’s declaration were conducted.

As a result of the audit activities, incomplete and improper applications are reported to the Audit Committee on a quarterly basis, and their completion statuses are followed.

Detailed training programs were prepared to increase the knowledge level of inspectors as well as bringing their personal developments to highest level. Accordingly, internal and external trainings were received.

As of 31 December 2014, the staff of the Board of Auditors consisted of 42 people.

Internal Control

The Internal Control Department is responsible for overseeing all aspects of Türkiye Finans’s organization and activities so as to ensure that the bank’s business is conducted effectively, productively, and in a manner consistent with the requirements of Banking Law and regulations, the bank’s policies and rules, and ordinary banking practices and also for ensuring the reliability, integrity, and timely accessibility of the accounting and financial reporting systems and of the information contained therein. The Internal Control Department reports directly to the Board of Directors and provides information to the bank’s senior management. Another function of the Internal Control Department is to develop early warning systems capable of identifying risks in advance and taking measures accordingly.

The Internal Control Department conducts its activities through 5 main services: Central Control, On-site Control, Information Systems and Compliance Checks, Reporting and Action Tracking and Risk Monitoring Self-Assessment.

Within the scope of the 2014 control plan, risk oriented control activities were conducted in the branches. At the same time, control design and test activities as well as inquiry investigations including controls within the scope of board’s declaration were conducted in the Headquarters’ units.

As a result of control activities, any incomplete and improper applications are reported to the Audit Committee on a quarterly basis and their completion statuses are followed.

Detailed training programs were prepared to increase the level of knowledge of internal control personnel as well as bringing their personal developments to the highest level. Internal and external training was provided accordingly.

As of 31 December 2014, the staff of the Internal Control Department consisted of 38 people.

Risk Management

Türkiye Finans’s risk management structure consists of the Board of Directors, the Audit Committee, and the Risk Management Center. The aim of the risk management system is to provide identifying, measuring, reporting, monitoring and controlling following risks: consolidated or unconsolidated risks through policies that are set to monitor the qualification and level of activities in parallel with the risk-reward structure of the Bank’s future cash flows, monitoring and changing these activities when necessary; and risks stemming from transactions made with the risk group in which the Bank is involved.

Risk management activities carried out in 2014 are summarized below.

Identification and Measurement of Risks

Risks that the Bank is exposed to due within the context of Regulation on Internal Systems of Banks and Internal Capital Adequacy Assessment Process, other related legislation and internationally accepted standards are identified, measured, reported and monitored under the main titles of Credit Risk, Market Risk, Liquidity Risk and Operational Risk by considering the best implementations

Within this scope, the annual Internal Capital Adequacy Assessment Process (ICAAP) report is prepared. In addition to above mentioned risk types, the Bank also considers other types of risks. Türkiye Finans quantifies the potential impacts of these risks and monitors them regularly. As part of ICAAP, the Bank carries both the measurement of risks regarding the current period and the anticipation of risks that the bank may be exposed to in the future, and such risks are considered in stress test activities.

In addition, Türkiye Finans monitors new product designs and changes in the Bank’s internal policies and procedures as well as business flows. Accordingly, the Bank conducts risk and impact assessments. Moreover, risks regarding support services which will be taken are analyzed.

Türkiye Finans utilizes statistical risk measurement and rating systems which are developed individually for all customer and credit types to effectively measure and manage risks. These systems are regularly monitored and their validation activities are carried out. Remedial actions are taken if necessary.

Details of activities conducted within the scope of measurement and rating of risks are given in “Information about Risk Management Policies on the Basis of Risk Type” section under the related risk category title.

Risk Monitoring and Reporting

The Risk Management Center seeks to understand, in advance, all changes and trends in the markets that the Bank operates in and the conditions by following economic data. The Risk Management Center reports its risk analysis and measurements to related units, the Senior Management and the Audit Committee. In addition, it also reports to the BRSA.

Necessary monitoring activities are conducted in view of the importance and materiality criteria on the basis of all risk types. Details which are categorized into risk types are provided in the “Information about Risk Management Policies on the Basis of Risk Types” section.

As of 31 December 2014, the Risk Management Center was staffed by 15 people. In order to enhance the personal and occupational development of the personnel, the staff participated in internal and external training, conferences and seminars. In doing so, the Bank continuously seeks to increase the level of knowledge in the field of risk management.

Regulatory Compliance

The Regulatory Compliance Department operates to monitor compliance risk by effectively managing it within the framework of related legislation, regulations and standards while also creating awareness around the Bank.

The main duties and responsibilities of the department are as follows: to fulfill compliance monitoring activities within the framework of “Regulation on Internal Systems of Banks and Internal Capital Adequacy Assessment Process”, conducting the Compliance Program in line with the law on the Prevention of Money-Laundering and Financing Terrorism, providing full compliance with the provisions of “the Law no.5549 about Prevention of Money- Laundering and Financing Terrorism (the Law)”, notifying the Bank management and related units in a timely manner of changes in legislation by following them; coordinating, monitoring and reporting compliance activities related to changes in legislation; managing notifications received through Ethics Line, conducting activities to settle ethics culture in the Bank, Preventing Money-Laundering and Financing Terrorism, carrying out training activities within the scope of Ethical Principles.

The Regulator Compliance Department is structured on three services: Product and Services Compliance Control Service, Struggle for Money-Laundering Service and External Legislation Coordination Service. As of 31 December 2014, the staff of the department consisted of 12 people. In 2012, the name of the MASAK Compliance Service was changed to the Service to Tackle Money Laundering. This service is divided functionally as “Enforcement Monitoring and Analysis” and “Suspicious Transaction Monitoring and Analysis”.

In 2014, training on “Prevention of Money-Laundering and Financing Terrorism” was provided to 23% of the personnel through attendance learning, and 79% of the personnel through distance learning. In the same period, 23% of the personnel received “Compliance and Ethical Principles Training” through attendance learning and 18% of personnel took this training through distance learning.

Audit Committee

Lama Ghazzaoui
Member, Audit Committee
Oğuz KAYHAN
Member, Audit Committee