Past version: Effective from 01 Jan 2019 to 31 Dec 2018

(1) Internal Controls and Risk Management Systems

An issuer should have adequate and effective systems of internal controls (including financial, operational, compliance and information technology controls) and risk management systems. The audit committee may commission an independent audit on internal controls and risk management systems for its assurance, or where it is not satisfied with the systems of internal controls and risk management.
(2) Suspected Fraud Or Irregularity

If the audit committee of an issuer becomes aware of any suspected fraud or irregularity, or suspected infringement of any Singapore laws or regulations or rules of the Exchange or any other regulatory authority in Singapore, which has or is likely to have a material impact on the issuer's operating results or financial position, the audit committee must discuss such matter with the external auditor and, at an appropriate time, report the matter to the board.
(3) Internal Audit

An issuer must establish and maintain on an ongoing basis, an effective internal audit function that is adequately resourced and independent of the activities it audits.

Amended on 29 September 201129 September 2011 and 1 January 20191 January 2019.