See Audithink's Latest Events →

Audithink for Banking: Internal Audit Software Compliant with POJK 1/2019

Commercial bank operations office

Topic Recommendations

Share Article

Ready To Improve Your Internal Audit Process?

Discover Audithink's full features and choose a pricing plan that works for your audit team. Start audit transformation now!

Audithink is designed to support commercial bank SKAI needs under POJK 1/2019: risk-based audits, audit trails, and follow-up monitoring.
Table Of Contents

The internal audit function at commercial banks is explicitly regulated by the Financial Services Authority (OJK) through POJK No. 1/POJK.03/2019 on the Implementation of the Internal Audit Function at Commercial Banks. This regulation requires a Satuan Kerja Audit Intern (SKAI) structure that is independent from operational units, a documented audit charter, and an audit process that can be traced whenever examined by supervisors.

This article discusses the internal audit challenges specific to the banking sector, the core provisions of POJK 1/2019 relevant to SKAI, and how Audithink's existing product capabilities are designed to support those needs.

Disclosure: Audithink is our product. At the time this article was written, we did not have a published bank case study. The implementation example mentioned below (PT Timah Tbk) is from the mining sector and is included solely as evidence of the product's general capabilities, not a claim of use in the banking sector.

Commercial bank office building

Internal Audit Challenges in Banking

  • SKAI independence from operational units must be genuinely reflected in the reporting structure and process trail, not just written into the audit charter.
  • High transaction and branch volume, making manual sample-based audits insufficient to provide adequate risk coverage.
  • The need for an audit trail that cannot be unilaterally altered, given that OJK examiners can request evidence of the audit process at any time.
  • Broad risk coverage, ranging from credit and operational risk to money laundering and terrorism financing risk (APU-PPT), all of which must be reflected in the audit program.
  • Reporting to the board of commissioners and audit committee which must take place regularly and be neatly documented as part of the internal audit function's accountability.

Relevant Regulations and Standards: POJK No. 1/POJK.03/2019

POJK No. 1/POJK.03/2019 on the Implementation of the Internal Audit Function at Commercial Banks requires every bank to establish an SKAI with a position independent from operational units, draw up an internal audit charter approved by the board of directors and acknowledged by the board of commissioners, and carry out audits based on an annual plan that takes risk into account.

We cover a more in-depth mapping of this regulation, including how it compares with other sector regulations such as those for state-owned enterprises and government, in Regulations Internal Audit Software Must Meet in Indonesia. For general guidance on banking internal audit compliance, also see A Guide to Banking Internal Audit and OJK Compliance.

Audithink Modules Relevant to Banking

The following capabilities are general features already available in Audithink, designed so they can be directed to support SKAI needs under POJK 1/2019:

  • Risk-based audit planning, helping SKAI draw up an annual audit plan that prioritizes the units and risks with the highest impact, in line with the risk-based audit principle expected by the regulation.
  • Digital working papers with an audit trail recorded automatically, supporting the need to document the audit process so it can be shown to OJK examiners.
  • Tiered access structure and approval workflow that can be configured to match the SKAI's independence structure from operational units.
  • Automatic finding logging and follow-up monitoring until fully resolved, with reminders sent to auditees.
  • Dashboard and automated reports that can be prepared for periodic reporting needs to the board of commissioners and audit committee.

How Audithink Supports POJK 1/2019 Compliance

Audithink is built to accommodate the need for risk-based internal audits that are independent from operational units, as required by POJK 1/2019. The approval workflow, working paper storage, and follow-up logging are designed to be configurable to each bank's SKAI structure, so the audit process can be documented consistently and is ready to be shown during examinations.

As an illustration of the product's general capabilities, not a claim of use in the banking sector, PT Timah Tbk (mining sector) recorded its audit process becoming about three times faster and paper usage dropping by about 80 percent after using Audithink. More details at the PT Timah Tbk case study. We do not yet have a bank as a client published as a case study, and we do not claim similar results automatically apply to the banking sector.

For coverage of money laundering and terrorism financing risk, which is also part of a bank's audit program, see Guide to APU-PPT Audit Strategy for Bank Fraud Detection.

FAQ About Audithink for Banking

Has Audithink been used by banks in Indonesia?

We do not currently have a bank client with a published case study. This article explains how Audithink's existing product capabilities are designed to align with SKAI needs under POJK 1/2019, not a claim that any specific bank is already using it.

Is Audithink certified or approved by OJK?

No. Audithink is a commercial internal audit software and not a product specifically certified or approved by OJK. Compliance with POJK 1/2019 remains the responsibility of the bank as the regulated entity; the software only helps run and document the process.

What is the difference between SKAI, SPI, and APIP?

SKAI (Satuan Kerja Audit Intern) is the term used in the banking sector under POJK, SPI (Satuan Pengawas Intern) is used within state-owned enterprises, while APIP (Aparat Pengawasan Intern Pemerintah) is used in government agencies. All three carry out the internal audit function under different regulatory frameworks, as discussed in Internal Audit Software Regulations in Indonesia.

Is audit software alone enough to comply with POJK 1/2019?

No. POJK 1/2019 requires an organizational structure, functional independence, and an audit charter formally established by the bank. Audit software helps run and document that process consistently, but compliance still depends on how the bank designs its SKAI structure and policies.

Can Audithink be customized to follow a specific bank's audit charter?

Audithink's workflow structure, risk categories, and report formats can be adapted to match the methodology and audit charter in place at your organization. Share your bank's specific audit charter requirements during the demo so our team can assess the fit.

See also:

Conclusion

Compliance with POJK 1/2019 begins with the structure and policies the bank establishes for its SKAI, with audit software playing a role in supporting the consistency and documentation of the process.

If you would like to discuss how Audithink can be configured to support your bank's SKAI needs, schedule an Audithink demo with our team.

Find out how the implementation of the audit application can have a positive impact on the company on an ongoing basis.

Consultation on Your Needs

Related Articles

FAQ questions about the Audithink product
Palm oil plantation seen from above
Tin mining activity in Indonesia