I think what areas of internal monitoring that need to be done depends on your level of risk. Definately, areas that have been cited in exams before should be included. Due to all the recent regulatory changes, some areas I identified as Low I actually moved to Moderate due to the increase in regulation. I think if you assign a risk to each regulation, you will get a pretty good idea of what you should be monitoring.