Workpaper Performed Risk
No. Point of Consideration Reference by Rating Comments
G. SECURITY RISK
1 SYSTEM ACCESS (RESTRICTIONS TO ACCESS ONLY)
Obtain the list of authorized personnel with access
1.1 to critical systems.
Verify if access rights are reviewed regularly and
updated for personnel changes (e.g., transfers,
1.2 resignations).
Test user access restrictions by checking system
feature access and reconcile with standard user
1.3 access
Assess if password policies and two-factor
1.4 authentication mechanisms are enforced.
Investigate any security breaches or violations and
1.5 recommend mitigation measures.
2 INSURANCE COVERAGE
Obtain copies of all insurance policies applicable to
the branch, such as property insurance, cash-in-
vault insurance, and general liability insurance.
Confirm their validity, scope of coverage, and
2.1 expiration dates.
Check if security protocols (e.g., alarm systems,
CCTV, security guards) are factored into insurance
requirements. Confirm if these measures are
2.2 implemented as required by the insurer.
Verify that the branch complies with all conditions
specified in the insurance policies, such as
maintaining a security system or reporting incidents
2.3 within a specified timeframe.
Interview branch management and key staff to
assess their awareness of insurance policies,
2.4 coverage limits, and claims procedures.
2.5 Examine the process for monitoring insurance
renewals and ensuring continuous coverage. Assess
whether the branch has a tracking mechanism for
expiring policies.
Document any gaps in insurance coverage,
compliance issues, or security vulnerabilities.
Provide actionable recommendations to mitigate
security risks through enhanced insurance coverage
2.6 or improved protocols.
SURVEILLANCE SYSTEM (AWARENESS OF ALARM
3 SYSTEM PROTOCOLS & CCTV GUIDELINES)
Review the list of alarm system and CCTV users to
3.1 ensure only authorized personnel have access.
Verify if CCTV footage is retained as per the
3.2 cooperative’s policy and regulatory requirements.
Test staff awareness of surveillance protocols by
3.3 conducting interviews or scenarios.
Check if maintenance schedules for surveillance
3.4 systems are followed.
Investigate incidents of system failure and assess if
3.5 protocols are adequate for risk mitigation.
RECORDS MANAGEMENT (ACCESS, CONTROL &
4 DATA PRIVACY)
Review the branch’s document control policy and
4.1 confirm compliance with data privacy regulations.
Verify if sensitive records are stored securely with
4.2 restricted access.
Test if records are retrieved and returned using a
4.3 documented tracking system.
Check for the proper disposal of obsolete records in
4.4 compliance with cooperative policy.
Investigate instances of unauthorized access or
4.5 missing records and recommend corrective actions.
5SSH (ADHERENCE TO CHECKLIST, ACTIVE
COMPLIANCE, FOCAL PERSON PRESENCE AND
5 AWARENESS)
5.1 Check the physical placement of table whether
member can immediately access records with
minimal physical interference.
5.2 Review the branch’s 5SSH checklist to ensure all
items are regularly updated and implemented.
5.3 Conduct a walkthrough to check compliance with
cleanliness, orderliness, and safety standards.
5.4 Verify the presence of the designated focal person
during the walkthrough.
5.5 Interview staff to gauge awareness of 5SSH
principles and compliance requirements.
5.6 Identify areas of non-compliance and recommend
corrective measures.