Risk Management Within a Financial Institution

Size: px
Start display at page:

Download "Risk Management Within a Financial Institution"

Transcription

1 Washington, DC Atlanta Brussels Denver Dubai Hong Kong London Milan New York Paris San Francisco Singapore Sydney Tokyo Toronto Compliance and Risk Essentials for Financial Services CSPs IAPP Privacy Academy and Cloud Security Alliance September 17th 19th, 2014, San Jose

2 Agenda and Takeaways Agenda I. Regulation, Regulators, and Financial Services (FS) II. III. IV. Problems Facing CSPs in the FI s Market Finding Solutions Communicating with Regulators Takeaways Understand the extraordinary regulatory pressure financial institutions and vendors are under Insight into regulators concerns and guidance Strategies to address regulator and client needs 2

3 I. Regulation, Regulators, and Financial Services (FS) Agenda Overview of Regulators The US Bank Services Act Current Regulatory Environment Vendor Selection Process at Financial Institutions Regulators Approach to Banks Use of Vendors Financial Institution s Views of Regulators and Regulations Financial Institution Governance 3

4 Overview of Regulators The US financial services industry is highly regulated by several different government agencies. Federally insured depository institutions, including state banks that are not members of the Federal Reserve System and state chartered thrift institutions Bank holding companies, savings and loan holding companies, certain state banks and U.S. branches of foreign banks National banks, U.S. federal branches of foreign banks, federally chartered savings institutions Federally chartered or insured credit unions Nonbank mortgage related firms, private student lenders, payday lenders, and consumer businesses of banks with over $10 billion in assets. 4

5 The US Bank Service Company Act The Bank Service Company Act provides statutory authority to the Federal Reserve, the Office of the Comptroller of the Currency, and the Federal Deposit Insurance Corporation to supervise third party servicers (or vendors) that enter into contractual agreements with their regulated financial institutions Promontory Financial Group LLC. All rights reserved. 5

6 Current Regulatory Environment The impact of the recent financial crisis has significantly changed the supervision and regulation of financial institutions. Supervisory attention on the scope and quality of third party risk management has increased (see Appendix). Recent exam activity and enforcement actions as well as updated guidance reinforce long standing supervisory expectations of sound risk management, but also introduce new expectations. Industry wide programs for third party management are undergoing revision and realignment to better meet evolving business objectives and supervisory expectations Financial Services in particular. 6

7 Vendor Selection Process at Financial Institutions Decide to Engage a Third Party or Vendor Conduct Risk Assessment Perform Due Diligence Negotiate Contract Terms Perform Ongoing Monitoring Evaluate whether the decision to hire a third party is consistent with the company s strategic direction and appropriately balances costs and benefits. Conduct a risk assessment to identify risks associated with hiring third party (operational, strategic, compliance, credit, and reputation risks). Assess whether vendor will have access to non public information. Determine whether service providers expertise, internal controls, and financial condition meet internal criteria. Ensure contract or SLA contains termination rights, audit rights to facilitate the company s oversight, and reporting obligations to enable the company to monitor performance and financial condition. After signing an agreement, the company must monitor the third party s performance, internal controls, and financial condition. 7

8 Regulators Approach to Banks Use of Vendors Banks have long outsourced technology, processing, and other operational and support functions to service providers, affiliates, and other third parties. Banking regulators have long maintained that the risks of outsourced activities remain a bank s risks with bank management and boards of directors accountable for their effective management and control. Historically, regulators have focused on management of risks to protect the interests of the bank and in particular on outsourced information technology and processing services with an emphasis on retail oriented banks. Five prongs of regulatory expectations underlie the risk management of third party relationships. 8

9 Regulators Approach to Banks Use of Vendors Business Assessment. Assessment of the strategic fit of potential outsourced activities with an organization s business model, strategy, and operational and risk management capacity; Due Diligence. Comprehensive review of the competencies and reputation of individual prospective vendors and their abilities to meet an organizations business objectives; Contracting. Written contracts identifying the roles and responsibilities of all parties in third party relationships and the consequences of contractual non performance; Ongoing Oversight. Oversight and monitoring of vendor performance, adherence to contract terms, and expectations of risk management; and Governance. Adequacy of the organization s written policies and framework, and its organization and oversight of business units and functions necessary for effective risk management. 9

10 Financial Institution s Views of Regulators and Regulations Regulators will expect you to abide by their guidance absent a good reason Number and depth of regulatory examinations are increasing as are financial and cost pressures Regulatory findings must be avoided or impact could be severe Examination guidance and regulation can be contradictory and ambiguous Relationship with regulators and examiners is critical Inconsistent regulator technical and information security sophistication 10

11 Financial Institution Governance COSO s Internal Control Integrated Framework An internal control is a process, effected by an entityʼs board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in: 1) the effectiveness and efficiency of operations, 2) reliability of reporting, and 3) compliance with applicable laws and regulations. think of it in terms of Accuracy, Integrity, and Completeness 11

12 Financial Institution Governance Types of Controls I. Preventive Controls applied before an activity occurs to provide reasonable assurance that only valid transactions are recognized, approved, and submitted II. Detective Controls performed after an activity occurs to provide reasonable assurance that errors or irregularities are discovered and corrected on a timely basis III. Hard Controls tangible controls such as policies and procedures, segregation of duties, authorizations, etc. 12

13 Financial Institution Governance Types of Controls IV. Soft Controls intangible controls associated with corporate culture such as shared values, ethics, etc. V. Automated Controls associated with IT Controls suitable for high volume or recurring activities VI. Manual Controls performed by people and are more suitable when judgment and discretion are required 13

14 Financial Institution Governance First Line Management and Internal Controls Controls designed into systems and processes, implemented through cascading responsibility structure Responsible for maintaining effective internal controls from day to day Second Line Risk and Compliance Functions Offer guidance on internal control requirements, conduct or oversee risk assessments, and evaluate adherence to defined standards Ensure the first line is working effectively Third Line Internal and External Audit Independently assesses and reports on internal control and recommends corrective actions or enhancements for management consideration and implementation Provides assurance regarding effectiveness of both the first and second lines of defense 14

15 Financial Institution Governance Three Lines of Defense Governing Body / Board / Audit Committee Senior Management 1 st Line of Defense 2 nd Line of Defense Financial Control Security 3 rd Line of Defense External Audit Regulator Management Controls Internal Controls Risk Management Quality Internal Audit Inspection Compliance Source: Institute of Internal Auditors, Position Paper: The Three Lines of Defense in Effective Risk Management and Control, January

16 Financial Institution Governance I. Enterprise Risk Management is designed to help management and boards of directors answer these relevant business questions: A. What are all the risks to our business strategy and operations (coverage)? B. How much risk are we willing to take (risk appetite)? C. How do we govern risk taking (culture, governance, and policies)? D. How do we capture the information we need to manage these risks (risk data and infrastructure)? E. How do we control the risks (control environment)? F. How do we know the size of the various risks (measurement and evaluation)? G. What are we doing about these risks (response)? H. What possible scenarios could hurt us (stress testing)? I. How are various risks interrelated (stress testing)? (Risk Management Association, 2012) 16

17 II. Problems Facing CSPs in the FI s Market Agenda It s complicated... Increased risk (perceived by regulators and FI risk teams) Cloud can be a bad word Cloud has reputational risk Comingled data and services may be considered unreasonable risks Meeting multiple FIs and regulators requirements 17

18 It s complicated... Regulatory requirements Little actual guidance or lots of ambiguity Responsibility is unclear Non compliance impact unclear Who wrote this &#$^? How should risk of cloud use be measured Gap analysis Remediation 18

19 Increased risk (perceived by regulators and FI risk teams) Enforcement action for customer non compliance Customer no longer allowed to use CSP CSP named in enforcement action, but not a party Examination What is a First Day Letter? Enforcement Incidents At your organization Another CSP 19

20 Cloud can be a bad word Regulators dislike Lack of risk transparency Unknown data and processing location Unknown data deletion, security, isolation Client security teams Prefer in house solutions they can review Have blocked or are blocking public cloud use Snowden fallout 20

21 Meeting multiple FIs and regulators requirements Cloud services will need to comply with various interpretations of risk and guidance Ambiguity in guidance will make for ambiguous client requirements CSPs may have hundreds of security questions from some FIs and most will be different from other FIs Cost and resource impacts will grow given the need to develop additional controls and work with FIs vendor management teams 21

22 III. Finding Solutions Agenda Practical Suggestions Sample Control Review 22

23 III. Finding Solutions Embrace and understand guidance and regulation Walk a mile Three words Transparency, transparency, transparency If you are better, be prepared to prove it Provide tools for clients to make risk decisions Prepare clients to represent service value and risk on your behalf You may not be in the room when regulators decide they don t like cloud Be prepared to be examined by regulators Regulatory exams are serious and must be handled appropriately 23

24 III. Finding Solutions Rule Text Requirement Primary Source Citation CSP s Responsibility Title/Source Description Analysis Japan Operations conducted after entry into the room should be managed. FIs should manage operations conducted after entry into the computer and data storage rooms. FISC Security Guidelines on Computer Systems for Banking and Related Financial Institutions (March 2012) (Operational management, O61) Maintain restrictions on what personnel are able to possess and access when entrance to a data storage room is granted, including: (i) Restricted entry; and (ii) Limits on cameras, personal computers, and other recording devices. Meeting Notes 1/3/14 Fall 2013 Asset Management Audit SOC 2 Report CSP does not maintain a separate computer data storage room or preparatory room within its data center. CSP relies on data center controls to protect the computer and data storage location. (i) (ii) CSP does not maintain a separate computer data storage room or preparatory room within its data center. This does not meet regulatory expectations, which call for additional precautions to be in place for computer and data storage areas. Australia Appropriate due diligence would normally ensure an assessment as to the robustness of the IT security risk management framework of the service provider, and alignment with a regulated institution s own framework. Appropriate due diligence should be conducted to ensure the robustness of the IT security risk management framework of the service provider, and the framework's alignment with a regulated institution s own framework. Attachment C: Service provider management; APRA Prudential Practice Guide CPG 234 Management of Security Risk in Information and Information Technology (May 2013) (2, page 23) (i) Maintain an IT security risk management framework; and Cooperate with FI due diligence reviews concerning the framework. Information Security Policy for Technology Roles CSP maintains a documented risk management approach (CSP Risk Management Approach) managed by CSP internal audit. CSP does not provide FI clients with information concerning internal audit techniques, approaches, or findings (ISP Tech Roles). (i) CSP maintains a documented risk management approach; and (ii) CSP does not enable FI clients to review audit information, including risk management documentation, or generally, sufficient internal and security control information for proper due diligence reviews. 24

25 III. Finding Solutions Rule Text Requirement Primary Source Citation CSP's Responsibility Title/Source Description Analysis Australia Appropriate due diligence would normally ensure an assessment as to the robustness of the IT security risk management framework of the service provider, and alignment with a regulated institution s own framework. Appropriate due diligence should be conducted to ensure the robustness of the IT security risk management framework of the service provider, and the framework's alignment with a regulated institution s own framework. Attachment C: Service provider management; APRA Prudential Practice Guide CPG 234 Management of Security Risk in Information and Information Technology (May 2013) (2, page 23) (i) Maintain a IT security risk management framework; and Cooperate with FI due diligence reviews concerning the framework. Information Security Policy for Technology Roles CSP maintains a documented risk management approach (CSP Risk Management Approach) managed by CSP internal audit. CSP does not provide FI clients with information concerning internal audit techniques, approaches, or findings (ISP Tech Roles). (i) CSP maintains a documented risk management approach; and (ii) CSP does not enable FI clients to review audit information, including risk management documentation, or generally, sufficient internal and security control information for proper due diligence reviews. United States It is important that access to customer data is restricted appropriately through effective identity and access management. Access to financial institution customer data must be restricted appropriately through effective identity and access management. Information Security; FFIEC Outsourced Cloud Computing (page 3). Restrict access to FI customer data through effective identity and access management. Service Organization Control 2 Report (2/1/12 1/31/13) Information Security Technical Standards Information Security Policy for All Roles Process Review Narrative Logical Security Meeting Notes (5/4/13) CSP maintains logical security controls, covering both identity and access (physical, logical, and privileged). See Service Organization Control 2 Report (2/1/12 1/31/13) and Process Review Narrative Logical Security for additional information concerning identity and access controls and business practices. CSP maintains various identity and access controls. However, we identified two potential access issues: (i) CSP technical operations employees have access to client data with limited controls and no operational monitoring system; and (ii) customer support third parties maintain customer support access, which allows access to customer data with client permission. 25

26 IV. Communicating with Regulators Organized and managed All meetings and interactions are structured and chaperoned Just the facts Balance transparency with facts Answer the question asked Too much detail opens new lines of questions Single story Regulators don t like multiple versions of truth Be prepared to back up statements with policy, standards, procedures and evidence Do what you say and say what you do 26

27 Communicating with Regulators If regulators ask a question that does not get to the issue, be constructive to inform and explain the systems, method, approach, exceptions, etc. Make sure the right people are in the meeting (if IT systems are under discussion, then the IT team should be represented). The seniority of the attendees at the meeting should also be considered. Listen and be responsive. Keep track of examiner requests. Follow up and ensure timely responses. Avoid the perception of being defensive. Fine to ask examiners to explain their line of questioning, but the bottom line they can ask about or for anything they want. Don't take offense if examiners are asking for something you already provided. Instead, take the opportunity to educate. Be patient and don't express frustration. 27

28 Communicating with Regulators Build credibility systematically Show commitment to the relationship Show contrition when wrong Regulators are rarely uninformed Be thoughtful and measured (no flash) Develop a regulatory strategy Highlight program state (even if it isn t very good) but be prepared to set reasonable milestones and meet them (all of them) 28

29 Questions? Stacy Coleman Ryan Smyth (619) Michael Spadea

30 Appendix Selected Additional Sources of Information: COMMITTEE OF SPONSORING ORGANIZATIONS OF THE TREADWAY COMMISSION, Internal Control Integrated Framework, May 2013, Executive Summary. BASEL COMMITTEE ON BANKING SUPERVISION, Principles for the Sound Management of Operational Risk, Jun INSTITUTE OF INTERNAL AUDITORS, IAA Position Paper: The Three Lines of Defense in Effective Risk Management and Control, Jan OFFICE OF THE COMPTROLLER OF THE CURRENCY, OCC Bulletin Description: Risk Management Guidance, Oct issuances/bulletins/2013/bulletin html BOARD OF GOVERNORS OF THE FEDERAL RESERVE SYSTEM, Guidance on Managing Outsourcing Risk, Dec

31 Appendix Selected Additional Sources of Information by Jurisdiction: Australia AUSTRALIAN PRUDENTIAL REGULATION AUTHORITY, Prudential Practice Guide CPG 234 Management of Security Risk in Information and Information Technology, May Practice Guide CPG 234 Management of Security Risk May 2013.pdf AUSTRALIAN PRUDENTIAL REGULATION AUTHORITY, Outsourcing and Offshoring Specific considerations when using cloud computing services, Nov on outsourcing and offshoring adi gili final.pdf France AUTORITÉ DE CONTRÔLE PRUDENTIEL, Anlyses et Syntheses The risks associated with cloud computing, Jul france.fr/fileadmin/user_upload/acp/publications/analysessyntheses/ The risks associated with cloud computing.pdf 31

32 Appendix France COMMISSION NATIONALE DE L'INFORMATIQUE ET DES LIBERTÉS, Recommendations for companies planning to use Cloud computing services se_cloud_computing_services.pdf Japan FISC (The Center for Financial Industry Information Systems), FISC Security Guidelines on Computer Systems for Banking and Related Financial Institutions, Mar MINISTRY OF ECONOMY, TRADE AND INDUSTRY, Information Security Management Guidelines for the Use of Cloud Services, Apr

33 Appendix Further Information on Controls: Preventive Controls applied before an activity occurs to provide reasonable assurance that only valid transactions are recognized, approved and submitted. Detective Controls performed after an activity occurs to provide reasonable assurance that errors or irregularities are discovered and corrected on a timely basis. Hard Controls tangible controls such as policies and procedures, segregation of duties, authorizations, etc. Soft Controls intangible controls associated with corporate culture such as shared values, ethics, etc. Automated Controls associated with IT Controls suitable for high volume or recurring activities Manual Controls performed by people and are more suitable when judgment and discretion are required 33

34 Appendix Preventive Controls Hard A. Information processing: IT Controls (Automated or manual) General controls: over data centers operations, software acquisition, systems development and maintenance (policies and procedures for: change management, software version control, incident escalation/management, business continuity/disaster recovery) Access controls: user IDs and passwords restrict unauthorized access to key systems Application controls: apply to programs that process transactions to ensure that activity is valid, properly authorized and accurate (automated checks for: completeness, validity, authorization, authentication, etc.) B. Physical controls: Safeguarding assets and records: limiting access to computer programs and data files (safes, vaults, safety deposit boxes, locked warehouses, pass key/fingerprint/optical access, alarm systems, security cameras) C. Segregation of duties: Assigning different people the responsibilities for authorizing transactions, recording transactions, and maintaining custody of assets (Cash controls, A/P controls, etc.) Supervisory reviews/approval prior to transaction processing Detective Controls Hard A. Operational/Financial performance reviews: Reconciliations: e.g., bank reconciliations are performed timely, by a different party than the person who writes checks Analyses and edit reports: timely generation and review of unusual transactions; analyses of actual performance vs. budget, forecasts, and prior performance 34

35 Appendix Preventive Controls Soft A. Elements of corporate culture: Corporate leadership and culture the tone at the top Competence High ethical standards Trust Openness Shared Values 35

36 Appendix Banks must adhere to certain regulatory requirements regarding internal control, which direct banks to operate in a safe and sound manner, comply with laws and regulations, and prepare accurate financial statements Laws and regulations that establish minimum requirements for internal control for national banks include: 12 CFR 30 Safety and Soundness Standards Establishes managerial and operational standards for all insured national banks, including internal control, which includes clear lines of authority and responsibility, effective risk assessment, timely and accurate reporting, and proper safeguarding of assets 12 CFR 363 Annual Independent Audits and Reporting Requirements Applies to national banks with over $500 million in assets, banks must submit an annual report to the OCC and FDIC, which includes managementʼs assessment of the effectiveness of the banks internal control and procedures for financial reporting and compliance with designated laws and regulations 15 USC 78m Securities and Exchange Act of 1934 Requires banks and holding companies with registered securities to develop and maintain a system of internal accounting controls The formality of the control system will depend primarily on the size of the bank, the complexity of its operations, and its risk profile 36

37 Appendix We are no longer willing to accept audit and risk management functions that are simply satisfactory. We are looking for excellence. Thomas J. Curry, Comptroller of the Currency November 15,

Office of Inspector General

Office of Inspector General Audit Report OIG-14-034 Not Sufficiently Documented April 21, 2014 Office of Inspector General Department of the Treasury Contents Audit Report Background... 2 Results of Audit... 4 OCC Has Updated Guidance

More information

6/8/2016 OVERVIEW. Page 1 of 9

6/8/2016 OVERVIEW. Page 1 of 9 OVERVIEW Attachment Supervisory Guidance for Assessing Risk Management at Supervised Institutions with Total Consolidated Assets Less than $50 Billion [Fotnote1 6/8/2016 Managing risks is fundamental to

More information

BOARD OF GOVERNORS FEDERAL RESERVE SYSTEM

BOARD OF GOVERNORS FEDERAL RESERVE SYSTEM BOARD OF GOVERNORS OF THE FEDERAL RESERVE SYSTEM WASHINGTON, D.C. 20551 DIVISION OF BANKING SUPERVISION AND REGULATION DIVISION OF CONSUMER AND COMMUNITY AFFAIRS SR 12-17 CA 12-14 December 17, 2012 TO

More information

Microsoft Pty Ltd. Australian Financial System Inquiry: Response to request for further submissions

Microsoft Pty Ltd. Australian Financial System Inquiry: Response to request for further submissions Microsoft Pty Ltd Australian Financial System Inquiry: Response to request for further submissions August 2014 1 Response in relation to Chapter 9 of the Interim Report Microsoft is pleased to respond

More information

To: Our Clients and Friends March 25, 2014

To: Our Clients and Friends March 25, 2014 Financial Services Group To: Our Clients and Friends March 25, 2014 A Significant Change Is Occurring Regarding Regulatory Oversight of Banks and Their Third Party Relationships. Both Banks and their Vendors

More information

FINANCIAL SERVICES FLASH REPORT

FINANCIAL SERVICES FLASH REPORT FINANCIAL SERVICES FLASH REPORT OCC Finalizes Its Heightened Standards for Large Financial Institutions September 15, 2014 Transforming Heightened Expectations to Minimum Standards On September 2, 2014,

More information

Compliance Risk Management Survey A Point of View

Compliance Risk Management Survey A Point of View FINANCIAL SERVICES Compliance Risk Management Survey A Point of View July 2014 kpmg.com Compliance Risk Management Survey A Point of View 3 Introduction As the financial crisis unfolded, regulators looked

More information

Washington Update. Payments News from our Nation s Capital. October 2014. Contents. CFPB Finalizes Two Rules Related to International Money Transfers

Washington Update. Payments News from our Nation s Capital. October 2014. Contents. CFPB Finalizes Two Rules Related to International Money Transfers Washington Update Payments News from our Nation s Capital October 2014 Contents CFPB Finalizes Two Rules Related to International Money Transfers $25 per Issue $200 Annual Subscription Authors: Craig Saperstein

More information

Preparing for the Outsourcing Challenge: Legal Due Diligence to Ensure a Winning Service Provider Relationship

Preparing for the Outsourcing Challenge: Legal Due Diligence to Ensure a Winning Service Provider Relationship THE 4 TH NATIONAL CONFERENCE ON OUTSOURCING IN FINANCIAL SERVICES NEGOTIATING, MANAGING & TERMINATING OUTSOURCING RELATIONSHIPS WHILE ENSURING REGULATORY COMPLIANCE Renaissance Mayflower, Washington, DC

More information

OCC 98-3 OCC BULLETIN

OCC 98-3 OCC BULLETIN To: Chief Executive Officers and Chief Information Officers of all National Banks, General Managers of Federal Branches and Agencies, Deputy Comptrollers, Department and Division Heads, and Examining Personnel

More information

The Future of Insurance Regulation: A Global Perspective ACLI Executive Roundtable

The Future of Insurance Regulation: A Global Perspective ACLI Executive Roundtable Washington, DC Atlanta Brussels Dubai Hong Kong London Milan New York Paris San Francisco Singapore Sydney Tokyo Toronto The Future of Insurance Regulation: A Global Perspective ACLI Executive Roundtable

More information

Cloud Computing Risks in Financial Services Companies: How Attorneys Can Best Help In An Increasingly SaaS-ified World

Cloud Computing Risks in Financial Services Companies: How Attorneys Can Best Help In An Increasingly SaaS-ified World Cloud Computing Risks in Financial Services Companies: How Attorneys Can Best Help In An Increasingly SaaS-ified World July 30, 2015 Sutherland Webinar Michael Steinig 202.383.0804 Michael.Steinig@sutherland.com

More information

Board means the Board of Directors of each of Scentre Group Limited, Scentre Management Limited, RE1 Limited and RE2 Limited.

Board means the Board of Directors of each of Scentre Group Limited, Scentre Management Limited, RE1 Limited and RE2 Limited. Board Charter SCENTRE GROUP LIMITED ABN 66 001 671 496 SCENTRE MANAGEMENT LIMITED ABN 41 001 670 579 AFS Licence No: 230329 as responsible entity of Scentre Group Trust 1 ABN 55 191 750 378 ARSN 090 849

More information

TO: Chief Executive Officers of National Banks, Federal Branches and Data-Processing Centers, Department and Division Heads, and Examining Personnel

TO: Chief Executive Officers of National Banks, Federal Branches and Data-Processing Centers, Department and Division Heads, and Examining Personnel AL 2000 12 O OCC ADVISORY LETTER Comptroller of the Currency Administrator of National Banks Subject: Risk Management of Outsourcing Technology Services TO: Chief Executive Officers of National Banks,

More information

GUIDANCE NOTE FOR DEPOSIT-TAKERS. Operational Risk Management. March 2012

GUIDANCE NOTE FOR DEPOSIT-TAKERS. Operational Risk Management. March 2012 GUIDANCE NOTE FOR DEPOSIT-TAKERS Operational Risk Management March 2012 Version 1.0 Contents Page No 1 Introduction 2 2 Overview 3 Operational risk - fundamental principles and governance 3 Fundamental

More information

CFPB Consumer Laws and Regulations

CFPB Consumer Laws and Regulations Secure and Fair Enforcement for Mortgage Licensing Act 1 The Secure and Fair Enforcement for Mortgage Licensing Act of 2008 2 () was enacted on July 30, 2008, and mandates a nationwide licensing and registration

More information

DEPARTMENT OF THE TREASURY. Office of the Comptroller of the Currency. 12 CFR Parts 30 and 170. [Docket ID OCC-2014-0001] RIN 1557-AD78

DEPARTMENT OF THE TREASURY. Office of the Comptroller of the Currency. 12 CFR Parts 30 and 170. [Docket ID OCC-2014-0001] RIN 1557-AD78 DEPARTMENT OF THE TREASURY Office of the Comptroller of the Currency 12 CFR Parts 30 and 170 [Docket ID OCC-2014-0001] RIN 1557-AD78 OCC Guidelines Establishing Heightened Standards for Certain Large Insured

More information

AGA Kansas City Chapter Data Analytics & Continuous Monitoring

AGA Kansas City Chapter Data Analytics & Continuous Monitoring AGA Kansas City Chapter Data Analytics & Continuous Monitoring Agenda Market Overview & Drivers for Change Key challenges that organizations face Data Analytics What is data analytics and how can it help

More information

FFIEC Cybersecurity Assessment Tool

FFIEC Cybersecurity Assessment Tool Overview In light of the increasing volume and sophistication of cyber threats, the Federal Financial Institutions Examination Council 1 (FFIEC) developed the Cybersecurity Tool (), on behalf of its members,

More information

WHITE PAPER THIRD PARTY MANAGEMENT: FUNDAMENTALS

WHITE PAPER THIRD PARTY MANAGEMENT: FUNDAMENTALS THIRD PARTY MANAGEMENT: FUNDAMENTALS by Linda Tuck Chapman Sponsored by Third Party Management Fundamentals Third Party Management isn t new, but its importance is growing in every industry and the financial

More information

Any business relationship between a bank and another entity, by contract or otherwise

Any business relationship between a bank and another entity, by contract or otherwise An Overview for Bank Directors Managing the Third Party Relationship Patrick Neuman Boardman & Clark LLP Madison, Wisconsin Any business relationship between a bank and another entity, by contract or otherwise

More information

Outsourcing Technology Services A Management Decision

Outsourcing Technology Services A Management Decision Outsourcing Technology Services A Management Decision A Telephone Seminar for National Banks Tuesday, July 20, 2004 And again on Wednesday, July 21, 2004 Agenda Outsourcing activities and relationships

More information

Key Considerations of Regulatory Compliance in the Public Cloud

Key Considerations of Regulatory Compliance in the Public Cloud Key Considerations of Regulatory Compliance in the Public Cloud W. Noel Haskins-Hafer CRMA, CISA, CISM, CFE, CGEIT, CRISC 10 April, 2013 w_haskins-hafer@intuit.com Disclaimer Unless otherwise specified,

More information

Navigating Vendor Management Issues in Today s Regulatory Environment

Navigating Vendor Management Issues in Today s Regulatory Environment Navigating Vendor Management Issues in Today s Regulatory Environment May 6, 2015 Elizabeth E. McGinn, Partner Moorari K. Shah, Counsel 1 Disclaimer The information contained herein is for informational

More information

FinTech Webinar Series: Vendor Management Principles

FinTech Webinar Series: Vendor Management Principles FinTech Webinar Series: Vendor Management Principles Evolving Best Practices of Bank Service Providers February 14, 2013 Speakers Russell Bruemmer Partner Eric Mogilnicki Partner Jeffrey Hydrick Special

More information

Effective AML Model Risk Management for Financial Institutions: The Six Critical Components

Effective AML Model Risk Management for Financial Institutions: The Six Critical Components August 2012 Effective AML Model Risk Management for Financial Institutions: The Six Critical Components A White Paper by John A. Epperson, Arjun Kalra, and Brookton N. Behm Audit Tax Advisory Risk Performance

More information

Office of Inspector General Evaluation of the Consumer Financial Protection Bureau s Consumer Response Unit

Office of Inspector General Evaluation of the Consumer Financial Protection Bureau s Consumer Response Unit Office of Inspector General Evaluation of the Consumer Financial Protection Bureau s Consumer Response Unit Consumer Financial Protection Bureau September 2012 September 28, 2012 MEMORANDUM TO: FROM: SUBJECT:

More information

UNITED STATES OF AMERICA DEPARTMENT OF THE TREASURY OFFICE OF THE COMPTROLLER OF THE CURRENCY ) ) ) ) ) ) ) ) ) ) ) ) STIPULATION AND CONSENT ORDER

UNITED STATES OF AMERICA DEPARTMENT OF THE TREASURY OFFICE OF THE COMPTROLLER OF THE CURRENCY ) ) ) ) ) ) ) ) ) ) ) ) STIPULATION AND CONSENT ORDER UNITED STATES OF AMERICA DEPARTMENT OF THE TREASURY OFFICE OF THE COMPTROLLER OF THE CURRENCY #2005-12 In the Matter of: Chicago Title Insurance Company Settlement Agent for: Whitney National Bank New

More information

Sample Financial institution Risk Management Policy 2011

Sample Financial institution Risk Management Policy 2011 Sample Financial institution Risk Management Policy 2011 1 Contents Risk Management Program...2 Internal Control and Risk Management Diagram... 2 General Control Environment... 2 Specific Internal Control

More information

Blind spot Banks are increasingly outsourcing more activities to third parties. But they can t outsource the risks.

Blind spot Banks are increasingly outsourcing more activities to third parties. But they can t outsource the risks. Blind spot Banks are increasingly outsourcing more activities to third parties. But they can t outsource the risks. For anyone familiar with the banking industry, it comes as no surprise that banks are

More information

Guide to Internal Control Over Financial Reporting

Guide to Internal Control Over Financial Reporting Guide to Internal Control Over Financial Reporting The Center for Audit Quality prepared this Guide to provide an overview for the general public of internal control over financial reporting ( ICFR ).

More information

Putting the Management Back in Vendor Management February 20, 2014

Putting the Management Back in Vendor Management February 20, 2014 Putting the Management Back in Vendor Management February 20, 2014 Moderator: Brian O Reilly The Collingwood Group, LLC Panelists: Calvin Hagins, CFPB Ken Markison, MBA Jonathan McKernan, Wilmer Hale Dan

More information

Risk Management of Outsourced Technology Services. November 28, 2000

Risk Management of Outsourced Technology Services. November 28, 2000 Risk Management of Outsourced Technology Services November 28, 2000 Purpose and Background This statement focuses on the risk management process of identifying, measuring, monitoring, and controlling the

More information

Defining and Managing Reputation Risk

Defining and Managing Reputation Risk BEIJING BRUSSELS CHICAGO DALLAS FRANKFURT GENEVA HONG KONG HOUSTON LONDON LOS ANGELES NEW YORK PALO ALTO SAN FRANCISCO SHANGHAI SINGAPORE SYDNEY TOKYO WASHINGTON, D.C. Defining and Managing Reputation

More information

Remarks by. Thomas J. Curry Comptroller of the Currency. At the. Bank Information Technology Training Conference. Atlanta.

Remarks by. Thomas J. Curry Comptroller of the Currency. At the. Bank Information Technology Training Conference. Atlanta. Remarks by Thomas J. Curry Comptroller of the Currency At the Bank Information Technology Training Conference Atlanta October 2, 2012 Good morning everyone. Thank you, Carolyn, for your gracious introduction,

More information

White Paper on Financial Institution Vendor Management

White Paper on Financial Institution Vendor Management White Paper on Financial Institution Vendor Management Virtually every organization in the modern economy relies to some extent on third-party vendors that facilitate business operations in a wide variety

More information

The New Third-Party Oversight Framework: Trust but Verify kpmg.com

The New Third-Party Oversight Framework: Trust but Verify kpmg.com Financial Services Regulatory Point of View The New Third-Party Oversight Framework: Trust but Verify kpmg.com The New Third-Party Oversight Framework: Trust but Verify 1 Financial services regulatory

More information

Risks and Precautions with Title Lending

Risks and Precautions with Title Lending AL 2000 11 O OCC ADVISORY LETTER Comptroller of the Currency Administrator of National Banks Subject: Title Loan Programs TO: Chief Executive Officers of All National Banks, Department and Division Heads,

More information

Vendor Management Compliance Top 10 Things Regulators Expect

Vendor Management Compliance Top 10 Things Regulators Expect Vendor Management Compliance Top 10 Things Regulators Expect Paul M. Phillips, CFA Attorney, Adams and Reese Pamela T. Rodriguez, AAP, CIA, CISA EVP, Risk Management & Education, EastPay 2014 EastPay.

More information

Morgan Stanley. Policy for the Management of Third Party Residential Mortgage Servicing Providers

Morgan Stanley. Policy for the Management of Third Party Residential Mortgage Servicing Providers Morgan Stanley Policy for the Management of Third Party Residential Mortgage Servicing Providers Title Policy for the Management of Third Party Residential Mortgage Servicing Providers Effective Date Owner

More information

2014 Financial Services Industry Compliance Benchmark Study

2014 Financial Services Industry Compliance Benchmark Study 2014 Financial Services Industry Compliance Benchmark Study Presented By: and Executive Summary Beginning in early December 2013, SAI Global Compliance conducted a survey among compliance professionals

More information

GUIDANCE FOR MANAGING THIRD-PARTY RISK

GUIDANCE FOR MANAGING THIRD-PARTY RISK GUIDANCE FOR MANAGING THIRD-PARTY RISK Introduction An institution s board of directors and senior management are ultimately responsible for managing activities conducted through third-party relationships,

More information

Consumer Affairs Laws Section 1380 and Regulations

Consumer Affairs Laws Section 1380 and Regulations Insurance Consumer Protection The Gramm-Leach-Bliley Financial Services Modernization Act (the Act) was enacted on November 12, 1999. Section 305 of the Act required the federal banking agencies (the Agencies)

More information

Risk governance: OCC codifies risk standards, paving the way for increased enforcement actions

Risk governance: OCC codifies risk standards, paving the way for increased enforcement actions Regulatory February 2014 brief A publication of PwC s financial services regulatory practice Risk governance: OCC codifies risk standards, paving the way for increased enforcement actions The Office of

More information

Guidelines for Financial Institutions Outsourcing of Business Activities, Functions, and Processes Date: July 2004

Guidelines for Financial Institutions Outsourcing of Business Activities, Functions, and Processes Date: July 2004 Guidelines for Financial Institutions Outsourcing of Business Activities, Functions, and Processes Date: July 2004 1. INTRODUCTION Financial institutions outsource business activities, functions and processes

More information

DEPARTMENT OF THE TREASURY. Office of the Comptroller of the Currency. 12 CFR Parts 30 and 170. [Docket ID OCC-2014-001] RIN 1557-AD78

DEPARTMENT OF THE TREASURY. Office of the Comptroller of the Currency. 12 CFR Parts 30 and 170. [Docket ID OCC-2014-001] RIN 1557-AD78 DEPARTMENT OF THE TREASURY Office of the Comptroller of the Currency 12 CFR Parts 30 and 170 [Docket ID OCC-2014-001] RIN 1557-AD78 OCC Guidelines Establishing Heightened Standards for Certain Large Insured

More information

MISSION VALUES. The guide has been printed by:

MISSION VALUES. The guide has been printed by: www.cudgc.sk.ca MISSION We instill public confidence in Saskatchewan credit unions by guaranteeing deposits. As the primary prudential and solvency regulator, we promote responsible governance by credit

More information

INFORMATION TECHNOLOGY OFFICER S QUESTIONNAIRE. Instructions for Completing the Information Technology Examination Officer s Questionnaire

INFORMATION TECHNOLOGY OFFICER S QUESTIONNAIRE. Instructions for Completing the Information Technology Examination Officer s Questionnaire Institution Charter Date of Exam Prepared By INFORMATION TECHLOGY OFFICER S QUESTIONNAIRE Instructions for Completing the Information Technology Examination Officer s Questionnaire The Information Technology

More information

COMMENTARY. occ and fdic Guidance on Supervisory Concerns and Expectations Regarding Deposit Advance Products JONES DAY

COMMENTARY. occ and fdic Guidance on Supervisory Concerns and Expectations Regarding Deposit Advance Products JONES DAY December 2013 JONES DAY COMMENTARY occ and fdic Guidance on Supervisory Concerns and Expectations Regarding Deposit Advance Products The Office of the Comptroller of the Currency ( OCC ) and the Federal

More information

Asset Management. Comptroller s Handbook. Comptroller of the Currency Administrator of National Banks

Asset Management. Comptroller s Handbook. Comptroller of the Currency Administrator of National Banks AM- Comptroller of the Currency Administrator of National Banks Comptroller s Handbook 20 AM Asset Management Asset Management UOperations and Controls Table of Contents Asset Management Operations and

More information

Validating Third Party Software Erica M. Torres, CRCM

Validating Third Party Software Erica M. Torres, CRCM Validating Third Party Software Erica M. Torres, CRCM Michigan Bankers Association Risk Management & Compliance Institute September 29, 2014 MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT

More information

Federal Reserve System. Framework for Risk-Focused Supervision of Large Complex Institutions

Federal Reserve System. Framework for Risk-Focused Supervision of Large Complex Institutions Federal Reserve System Framework for Risk-Focused Supervision of Large Complex Institutions This handbook contains references to hypothetical banking organizations. All financial information cited for

More information

GUIDELINES FOR THE MANAGEMENT OF OPERATIONAL RISK FOR CREDIT UNIONS

GUIDELINES FOR THE MANAGEMENT OF OPERATIONAL RISK FOR CREDIT UNIONS SUPERVISORY AND REGULATORY GUIDELINES Guidelines Issued: 22 December 2015 GUIDELINES FOR THE MANAGEMENT OF OPERATIONAL RISK FOR CREDIT UNIONS 1. INTRODUCTION 1.1 The Central Bank of The Bahamas ( the Central

More information

MEDIA RELEASE. IOSCO reports on business continuity plans for trading venues and intermediaries

MEDIA RELEASE. IOSCO reports on business continuity plans for trading venues and intermediaries IOSCO/MR/54/2015 Madrid, 22 December 2015 IOSCO reports on business continuity plans for trading venues and intermediaries The Board of the (IOSCO) today published two reports that seek to enhance the

More information

Frequently Asked Questions: Identity Theft Red Flags and Address Discrepancies

Frequently Asked Questions: Identity Theft Red Flags and Address Discrepancies Frequently Asked Questions: Identity Theft Red Flags and Address Discrepancies The staff of the Board of Governors of the Federal Reserve System (FRB), Federal Deposit Insurance Corporation (FDIC), National

More information

Board Risk & Compliance Committee Charter

Board Risk & Compliance Committee Charter Board Risk & Compliance Charter 10 December 2015 PURPOSE 1) The purpose of the Westpac Banking Corporation (Westpac) Board Risk & Compliance () is to assist the Board of Westpac (Board) as the Board oversees

More information

UNITED STATES OF AMERICA BEFORE THE BOARD OF GOVERNORS OF THE FEDERAL RESERVE SYSTEM WASHINGTON, DC.

UNITED STATES OF AMERICA BEFORE THE BOARD OF GOVERNORS OF THE FEDERAL RESERVE SYSTEM WASHINGTON, DC. UNITED STATES OF AMERICA BEFORE THE BOARD OF GOVERNORS OF THE FEDERAL RESERVE SYSTEM WASHINGTON, DC. FEDERAL DEPOSIT INSURANCE CORPORATION WASHINGTON, D.C. OFFICER OF COMPTROLLER OF THE CURRENCY WASHINGTON,

More information

Privacy Governance and Compliance Framework Accountability

Privacy Governance and Compliance Framework Accountability Privacy Governance and Framework Accountability Agenda Global Data Protection and Privacy (DPP) Organization Structure Privacy The 3 Lines of Defense (LOD) Model: Overview Privacy The 3 Lines of Defense

More information

November 8, 2000. The Honorable Alan Greenspan Chairman Board of Governors of the Federal Reserve System

November 8, 2000. The Honorable Alan Greenspan Chairman Board of Governors of the Federal Reserve System United States General Accounting Office Washington, DC 20548 November 8, 2000 The Honorable Alan Greenspan Chairman Board of Governors of the Federal Reserve System The Honorable John D. Hawke, Jr. Comptroller

More information

Supporting Effective Compliance Programs

Supporting Effective Compliance Programs October 2015 Supporting Effective Compliance Programs The Oversight Roles of the Board Audit and Risk Committees in Regulatory Compliance By Paul Osborne, CPA, CAMS, AMLP, and Peggy Sepp, CIA To be effective,

More information

FDIC Updates Guidance on Payment Processor Relationships

FDIC Updates Guidance on Payment Processor Relationships February 2012 FDIC Updates Guidance on Payment Processor Relationships BY KEVIN L. PETRASIC In its recently issued Financial Institution Letter, FIL-3-2012, the Federal Deposit Insurance Corporation (

More information

Regulatory Practice Letter February 2014 RPL 14-05

Regulatory Practice Letter February 2014 RPL 14-05 Regulatory Practice Letter February 2014 RPL 14-05 CFPB Nonbank Supervision of International Money Transfer Providers Proposed Rule Executive Summary The Consumer Financial Protection Bureau (CFPB or Bureau)

More information

Board Responsibility. A bank can outsource a task, but it cannot outsource the responsibility.

Board Responsibility. A bank can outsource a task, but it cannot outsource the responsibility. Third-Party Risk Board Responsibility The Board of Directors and senior management are ultimately responsible for managing activities conducted through third-party relationships as if the activity were

More information

OUTSOURCING INVOLVING SHARED COMPUTING SERVICES (INCLUDING CLOUD) 6 July 2015

OUTSOURCING INVOLVING SHARED COMPUTING SERVICES (INCLUDING CLOUD) 6 July 2015 OUTSOURCING INVOLVING SHARED COMPUTING SERVICES (INCLUDING CLOUD) 6 July 2015 Disclaimer and Copyright While APRA endeavours to ensure the quality of this publication, it does not accept any responsibility

More information

Vendor Risk Management in the New Regulatory Environment. kpmg.com

Vendor Risk Management in the New Regulatory Environment. kpmg.com Vendor Risk Management in the New Regulatory Environment kpmg.com Vendor Risk Management in the New Regulatory Environment 2 Vendor Risk Management in the New Regulatory Environment Background Regulators

More information

Large Bank Supervision

Large Bank Supervision EP- BS O Comptroller of the Currency Administrator of National Banks Large Bank Supervision Comptroller s Handbook January 2010 Updated September 2012 for BSA/AML Updated May 2013 for Risk Definitions

More information

2015 CEO & Board University Cybersecurity on the Rise. Matthew J. Putvinski, CPA, CISA, CISSP

2015 CEO & Board University Cybersecurity on the Rise. Matthew J. Putvinski, CPA, CISA, CISSP 2015 CEO & Board University Cybersecurity on the Rise Matthew J. Putvinski, CPA, CISA, CISSP MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2011 Wolf & Company, P.C. About Wolf

More information

Vendor Management Compliance Top 10 Things Regulators Expect

Vendor Management Compliance Top 10 Things Regulators Expect Vendor Management Compliance Top 10 Things Regulators Expect Peter Davey, AAP VP & Director, Enterprise Payments, CapitalOne Pamela T. Rodriguez, AAP, CIA, CISA EVP, Risk Management & Education, EastPay

More information

Consumer Financial Services. Industry-leading counsel in regulatory compliance, product development, and litigation. Attorney Advertising

Consumer Financial Services. Industry-leading counsel in regulatory compliance, product development, and litigation. Attorney Advertising Consumer Financial Services Industry-leading counsel in regulatory compliance, product development, and litigation Attorney Advertising Recognized for national excellence by Chambers. Vast regulatory experience.

More information

Liquidity Coverage Ratio: Liquidity Risk Measurement, Standards, and Monitoring

Liquidity Coverage Ratio: Liquidity Risk Measurement, Standards, and Monitoring ni LPL Financial 97S5 Towne Centre Drive San Diego, CA 92121-196S S5S 450 9606 office January 31, 2014 Office of the Comptroller of the Currency 400 7 th Street, S.W., Suite 3E-218 Mail Stop 9W-11 Washington,

More information

Data Privacy and Gramm- Leach-Bliley Act Section 501(b)

Data Privacy and Gramm- Leach-Bliley Act Section 501(b) Data Privacy and Gramm- Leach-Bliley Act Section 501(b) October 2007 2007 Enterprise Risk Management, Inc. Agenda Introduction and Fundamentals Gramm-Leach-Bliley Act, Section 501(b) GLBA Life Cycle Enforcement

More information

Featured Article Federal Red Flag and Related Identity Theft Prevention Rules: Is Your Organization in Compliance?

Featured Article Federal Red Flag and Related Identity Theft Prevention Rules: Is Your Organization in Compliance? Featured Article Federal Red Flag and Related Identity Theft Prevention Rules: Is Your Organization in Compliance? Article contributed by: Nancy L. Perkins, Arnold & Porter LLP As of November 1, 2008,

More information

Remarks by Thomas J. Curry Comptroller of the Currency Before the New England Council Boston, Massachusetts May 16, 2014

Remarks by Thomas J. Curry Comptroller of the Currency Before the New England Council Boston, Massachusetts May 16, 2014 Remarks by Thomas J. Curry Comptroller of the Currency Before the New England Council Boston, Massachusetts May 16, 2014 It s a pleasure to be with you back home in Boston. I was here just six weeks ago

More information

Effective Model Risk Management for Financial Institutions: The Six Critical Components

Effective Model Risk Management for Financial Institutions: The Six Critical Components January 2013 Effective Model Risk Management for Financial Institutions: The Six Critical Components A White Paper by Brookton N. Behm, John A. Epperson, and Arjun Kalra Audit Tax Advisory Risk Performance

More information

Privacy of Consumer Financial Information

Privacy of Consumer Financial Information Background and Overview Introduction Title V, Subtitle A of the Gramm-Leach-Bliley Act ( GLBA ) 1 governs the treatment of nonpublic personal information about consumers by financial institutions. Section

More information

GAO. Standards for Internal Control in the Federal Government. Internal Control. United States General Accounting Office.

GAO. Standards for Internal Control in the Federal Government. Internal Control. United States General Accounting Office. GAO United States General Accounting Office Internal Control November 1999 Standards for Internal Control in the Federal Government GAO/AIMD-00-21.3.1 Foreword Federal policymakers and program managers

More information

SUMMARY: This proposed rule would implement section 165(i) of the Dodd-Frank Wall

SUMMARY: This proposed rule would implement section 165(i) of the Dodd-Frank Wall DEPARTMENT OF THE TREASURY Office of the Comptroller of the Currency 12 CFR Part 46 [Docket ID OCC-2011-0029] RIN 1557-AD58 Annual Stress Test AGENCY: Office of the Comptroller of the Currency ( OCC ).

More information

Part A OVERVIEW...1. 1. Introduction...1. 2. Applicability...2. 3. Legal Provision...2. Part B SOUND DATA MANAGEMENT AND MIS PRACTICES...

Part A OVERVIEW...1. 1. Introduction...1. 2. Applicability...2. 3. Legal Provision...2. Part B SOUND DATA MANAGEMENT AND MIS PRACTICES... Part A OVERVIEW...1 1. Introduction...1 2. Applicability...2 3. Legal Provision...2 Part B SOUND DATA MANAGEMENT AND MIS PRACTICES...3 4. Guiding Principles...3 Part C IMPLEMENTATION...13 5. Implementation

More information

Understanding SAS 70 Reports on Internal Control

Understanding SAS 70 Reports on Internal Control Understanding SAS 70 Reports on Internal Control PwC Agenda Internal Control Reporting: A Focus on SAS 70 Trends affecting internal control reporting Discussion points for Mutual Fund Directors with management

More information

Corporate Governor. New COSO Framework links IT and business process

Corporate Governor. New COSO Framework links IT and business process Corporate Governor Providing vision and advice for management, boards of directors and audit committees Summer 2014 New COSO Framework links IT and business process Michael Rose, Partner, Business Advisory

More information

THIRD PARTY SUPPLIER RISK MANAGEMENT. Meeting Emerging Financial Services Regulatory Requirements. By Joseph Yacura, ISG Director. www.isg-one.

THIRD PARTY SUPPLIER RISK MANAGEMENT. Meeting Emerging Financial Services Regulatory Requirements. By Joseph Yacura, ISG Director. www.isg-one. THIRD PARTY SUPPLIER RISK MANAGEMENT Meeting Emerging Financial Services Regulatory Requirements By Joseph Yacura, ISG Director www.isg-one.com INTRODUCTION U.S. and Canadian financial services companies

More information

Acquia Comments on EU Recommendations for Data Processing in the Cloud

Acquia Comments on EU Recommendations for Data Processing in the Cloud Acquia Comments on EU Recommendations for Data Processing in the Cloud Executive Summary On July 1, 2012, European Union (EU) data protection regulators provided guidelines for service providers processing

More information

IT audit updates. Current hot topics and key considerations. IT risk assessment leading practices

IT audit updates. Current hot topics and key considerations. IT risk assessment leading practices IT audit updates Current hot topics and key considerations Contents IT risk assessment leading practices IT risks to consider in your audit plan IT SOX considerations and risks COSO 2013 and IT considerations

More information

VENDOR RISK MANAGEMENT UPDATE- ARE YOU AT RISK? Larry L. Llirán, CISA, CISM December 10, 2015 ISACA Puerto Rico Symposium

VENDOR RISK MANAGEMENT UPDATE- ARE YOU AT RISK? Larry L. Llirán, CISA, CISM December 10, 2015 ISACA Puerto Rico Symposium 1 VENDOR RISK MANAGEMENT UPDATE- ARE YOU AT RISK? Larry L. Llirán, CISA, CISM December 10, 2015 ISACA Puerto Rico Symposium 2 Agenda Introduction Vendor Management what is? Available Guidance Vendor Management

More information

Third-Party Risk Management: Busting Myths and Telling Truths

Third-Party Risk Management: Busting Myths and Telling Truths Third-Party Risk Management: Busting Myths and Telling Truths Richik Sarkar, Esq. McDonald Hopkins LLC 600 Superior Avenue, East, Suite 2100 Cleveland, OH 44114 (216) 430-2009 rsarkar@mcdonaldhopkins.com

More information

Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement

Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement Understanding the Entity and Its Environment 1667 AU Section 314 Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement (Supersedes SAS No. 55.) Source: SAS No. 109.

More information

Financial Institutions

Financial Institutions Financial Institutions April 2008 ALBANY AMSTERDAM ATLANTA BOCA RATON BOSTON CHICAGO DALLAS DELAWARE DENVER FORT LAUDERDALE HOUSTON LAS VEGAS LOS ANGELES MIAMI NEW JERSEY NEW YORK ORANGE COUNTY ORLANDO

More information

The Definition of Leveraged Lending

The Definition of Leveraged Lending The Definition of Leveraged Lending Definitional Expectations for Financial Institutions Under the Final Guidance Leveraged Lending The March 2013 Interagency Guidance on Leveraged Lending ( Guidance or

More information

BOARD OF GOVERNORS FEDERAL RESERVE SYSTEM

BOARD OF GOVERNORS FEDERAL RESERVE SYSTEM BOARD OF GOVERNORS OF THE FEDERAL RESERVE SYSTEM WASHINGTON, D.C. 20551 DIVISION OF BANKING SUPERVISION AND REGULATION DIVISION OF CONSUMER AND COMMUNITY AFFAIRS SR 05-23 / CA 05-10 December 1, 2005 TO

More information

FEDERAL DEPOSIT INSURANCE CORPORATION WASHINGTON, D.C. CALIFORNIA DEPARTMENT OF FINANCIAL INSTITUTIONS SAN FRANCISCO, CALIFORNIA

FEDERAL DEPOSIT INSURANCE CORPORATION WASHINGTON, D.C. CALIFORNIA DEPARTMENT OF FINANCIAL INSTITUTIONS SAN FRANCISCO, CALIFORNIA FEDERAL DEPOSIT INSURANCE CORPORATION WASHINGTON, D.C. CALIFORNIA DEPARTMENT OF FINANCIAL INSTITUTIONS SAN FRANCISCO, CALIFORNIA ) ) In the Matter of ) ) CONSENT ORDER BANAMEX USA ) CENTURY CITY, CALIFORNIA

More information

Compliance and Ethics at the Federal Reserve Bank of New York

Compliance and Ethics at the Federal Reserve Bank of New York Compliance and Ethics at the Federal Reserve Bank of New York Operational Risk and Internal Audit Course Marina Adams, Compliance Officer and AVP David K. Clune, Compliance and Ethics Officer Kevin White,

More information

Privacy Impact Assessment of the Nationwide Mortgage Licensing System and Registry

Privacy Impact Assessment of the Nationwide Mortgage Licensing System and Registry Privacy Impact Assessment of the Nationwide Mortgage Licensing System and Registry Program or application name: Nationwide Mortgage Licensing System and Registry (NMLSR) System Owner: Board of Governors

More information

M-IC. Comptroller of the Currency Administrator of National Banks. Internal Control. Comptroller s Handbook. January 2001.

M-IC. Comptroller of the Currency Administrator of National Banks. Internal Control. Comptroller s Handbook. January 2001. M-IC Comptroller of the Currency Administrator of National Banks January 2001 M Management Table of Contents OVERVIEW... 1 BACKGROUND... 1 Objectives... 2 Regulatory Requirements... 3 Components... 5 OCC

More information

30-SECOND SUMMARY The Federal Reserve and the Office of the Comptroller of the Currency (OCC)

30-SECOND SUMMARY The Federal Reserve and the Office of the Comptroller of the Currency (OCC) 30-SECOND SUMMARY The Federal Reserve and the Office of the Comptroller of the Currency (OCC) have issued extensive new guidance to financial institutions about the use of third parties to perform functions

More information

Information Technology Risks

Information Technology Risks Information Technology Risks Heidi Richards Board 1 Overview Supervision of IT Risks Internet Banking: What s Different? Information Technology Risks Financial Operational Compliance Supervisory Approaches

More information

INFORMATION DEVELOPMENT CO., LTD.

INFORMATION DEVELOPMENT CO., LTD. INFORMATION DEVELOPMENT CO., LTD. Financial results of Apr. 2014-Mar. 2015 June 2015 President and Representative Director Masaki Funakoshi TSE 1st section Code:4709 1 Today s Presentation 1. Performance

More information

Several months ago, the Federal Trade Commission (the FTC or

Several months ago, the Federal Trade Commission (the FTC or FTC s Red Flags Rule: Delays Suggest Confusion on the Part of the Industry Lisa J. Sotto and Boris Segalis The authors examine the elements of the Red Flags Rule and explain how to comply with its requirements.

More information

Vendor Risk Management Financial Organizations

Vendor Risk Management Financial Organizations Webinar Series Vendor Risk Management Financial Organizations Bob Justus Chief Security Officer Allgress Randy Potts Managing Consultant FishNet Security Bob Justus Chief Security Officer, Allgress Current

More information

Client Update Basel Committee 2015 Corporate Governance Principles

Client Update Basel Committee 2015 Corporate Governance Principles 1 Client Update Basel Committee 2015 Corporate Governance Principles NEW YORK Gregory J. Lyons gjlyons @debevoise.com Paul M. Rodel pmrodel@debevoise.com Eric T. Juergens etjuergens@debevoise.com Caroline

More information