Monday, November 28, 2016

JD解密系列(一) - Quality Assurance (QA) / Testing and Monitoring

我會開一個系列是用真實的銀行招聘廣告(Job description)去講講業界裏不同的從業員所從事的工作內容,以及他們日常都是做些甚麼的(A day in the life of ….)。以下這個JD是金融界炙手可熱的工種﹕Quality Assurance (QA)/ Monitoring and Testing

Employer: Bank of America / Merrill Lynch
Job title: Testing Specialist


你會納悶,銀行不是工廠,為甚麼要做Quality Assurance和testing?對,連服務業也要做抽樣檢查(sample testing)。
既然是服務業,沒有產品,那麼我們抽樣的是甚麼?這是取決於這個要檢查的銀行業務性質。這原本是傳統上內審和外審部門(Internal and External Auditors)做的工作,不過隨著銀行面對的違規風險(Compliance risk)日增,等待每幾年一次的內審或比較沒有內部員工熟識業務的外審未夠有效,於是各營業部門紛紛增聘自家的查考人員。讓我們繼續看看這個JD的職責範圍﹕

Job Description and Role Responsibilities
The Testing Specialist, under supervision, conducts independent transactional and process testing on a team in support of needs identified by Compliance and Operational Risk Officers. A test is defined in the Independent Testing Enterprise Policy as "an independent point-in-time examination of one or more processes, controls, policies and procedures or data sources utilized for managing risk to assess the effectiveness of the control environment. A test is focused on answering a specific objective and has a pre-defined pass/fail criteria." Compliance testing may include activities such as automated surveillance and transaction level testing and may be performed onsite.

The Testing Specialist is accountable for quality testing execution, reporting and analysis of results. This role may participate in test script development and test design. The Testing Specialist contributes to the identification of themes and trends at the front line unit, control function and enterprise level. This role is an individual contributor in the Test Execution function. This role work closely with Line of Business Compliance in terms of new surveillance development, model and parameter review and escalation. You will work closely with global surveillance counterparts and IT in surveillance development and global projects and assist in gathering information and preparing responses to regulatory/audit exams.




外行人是有點難明白的。讓我舉分行的客戶經理(Relationship Manager, RM)銷售產品一個流程為例﹕
測試目的(Test objective)﹕確保分行銷售產品過程合符監管機構及內部守則
測試範圍(Controls to be tested)﹕
- 客戶經理須參考客戶的風險承受能力推銷相應的產品
- 如果產品超出客戶的風險承受能力,客戶經理必須得到循相關程序披露有關風險,並得到客戶的明確同意
測試程序(Test script)﹕
- 從過去六個月裏抽出六個客戶經理成功銷售產品紀錄
- 查考產品的風險級數是否在客戶的風險承受能力評級以內
- 如以上為否,查考客戶明確同意的證據(Evidence)

負責Quality Assurance/ Testing & Monitoring 的同事便是要和管理層討論有哪些高風險的流程需要測試﹑該測試甚麼﹑如何測試等等,以及在進行測試後歸納結果供管理層參考。

JD裏還提到surveillance 一詞,這主要是用在前枱(Front office)交易上,用系統報告取得異常活動的數據供合規部門分析是否有違規,下篇再講

延伸閱讀﹕
Compliance 行業前景
Compliance manager 一天的工作內容
金融業從業員的特別守則- 金融犯罪

想看更多? - Like 大投行小人物 Facebook專頁

No comments:

Post a Comment