Vendor Management: Your Questions Answered
|
|
|
- Caitlin Stewart
- 10 years ago
- Views:
Transcription
1 Vendor Management: Your Questions Answered June 16, 2015 Elizabeth E. McGinn Partner Moorari K. Shah Counsel 1
2 Disclaimer The information contained herein is for informational purposes only; does not constitute legal advice; and, does not necessarily reflect the opinions of BuckleySandler LLP or any of its attorneys or clients. This presentation is not intended to create, and does not create, an attorney-client relationship between you and BuckleySandler LLP, or any of the presenters, and you should not act or rely on any information in this presentation without consulting legal counsel. The information contained in this presentation may or may not reflect the most current legal developments; accordingly, information in this presentation is not promised or guaranteed to be correct or complete, and should not be considered an indication of future results. BuckleySandler LLP expressly disclaims all liability in respect to actions taken or not taken based on any or all of the contents of this presentation. 2
3 Q1: Role of the Board What is expected of the board of directors with respect to vendor management? Setting the tone from the top is a key focus of regulators Full accountability requires treating the outsourced activity as if the service were being performed in-house Alignment with overall business strategy and objectives 3
4 Q2: Building a Vendor Management Function How should a company start to build the framework if the vendor management function has not previously existed? Common question for nonbanks Compliance Management Systems Size and structure vary across financial institutions Many institutions underestimate the necessary resources 4
5 Q3: Use of Cross-Function Teams When should organizations consider using cross-functional teams to support vendor management? Evaluation of activities affecting multiple business lines Include internal audit, information security, human resources, legal and compliance Team advises and assists relationship manager Augment team with outside consultants for expertise 5
6 Q4: Risk Ratings Is there a standard risk rating scale for vendors? General agreement that high-risk vendors include: Customer-facing vendors Those that store sensitive customer information Those that provide mission-critical applications, such as coreprocessing systems Business continuity and disaster recovery services Develop cascading model that is tailored to company s size and complexity of financial products Develop mitigation plan based on risk rating 6
7 Q5: Ongoing Monitoring Focus Areas What are current areas of regulatory focus related to ongoing monitoring? Compliance training Early identification of issues Information security 7
8 Q6: Subcontractors What actions should a financial institution take with respect to oversight of subcontractors? Monitor vendor s reliance on subcontractors Contractual right to audit subcontractors Require vendor to perform due diligence and ongoing monitoring of subcontractors and report results 8
9 Q7: Handling Consumer Complaints What steps should an institution take in its ongoing monitoring of consumer complaints? How should you respond to consumer complaints about a vendor that arrive through the CFPB portal? Assign responsibility for monitoring and responding Vendor point person Move quickly Initial response due in 15 days 60 days to investigate before made public Involve legal and compliance teams Decide whether to choose one of the permitted responses Ongoing monitoring and remediation principles still apply Portal response is not a safe harbor 9
10 Q8: Sufficient Staff What constitutes sufficient staff to onboard and manage third party vendors? Dedicated staff Periodic reviews of ongoing monitoring files: Test for thoroughness of documentation and records and whether they satisfy internal policies and procedures Verify that staff is testing for compliance with applicable laws 10
11 Q9: Transitioning Vendors What should financial institutions consider when terminating a relationship with a service provider? Establishing a replacement vendor Resources required Timing Project plan Managing legal and regulatory compliance during transition Data return, transfer, and destruction Joint intellectual property 11
12 Q10: Re-Negotiating with Vendors How do you re-negotiate vendor contracts to incorporate new regulatory requirements when the vendor has no interest in re-negotiating? Dialogue first Dealing with vendors who refuse or seek significant concessions Contemplate back-up plan with another vendor that will accept the necessary language 12
13 Q11: UDAAP Update What are the latest updates related to UDAAP and service providers? Opt-In cases Mobile cramming Payment program providers Mortgage industry 13
14 Q12: TILA-RESPA Integrated Disclosure Rule What are companies doing to prepare for TRID rule changes? Software vendors Mortgage brokers Training and timing Applications Loan estimates Closing disclosure Closing services Fee estimates and tolerances 14
15 Q13: Possible Future Actions What s coming next? More direct actions against service providers Opt-in is a hot topic Cyber-security/privacy FTC and FCC focus Add-on products Potential expansion of cramming 15
16 Questions Elizabeth McGinn Partner (DC office) (NY office) Moorari Shah Counsel (LA office)
Navigating Vendor Management Issues in Today s Regulatory Environment
Navigating Vendor Management Issues in Today s Regulatory Environment May 6, 2015 Elizabeth E. McGinn, Partner Moorari K. Shah, Counsel 1 Disclaimer The information contained herein is for informational
The Other Side of CFPB Compliance
The Other Side of CFPB Compliance Strengthening your compliance program via vendor management Legal Disclaimer This information is for the use of attendees only. Any distribution, reproduction, copying
Any business relationship between a bank and another entity, by contract or otherwise
An Overview for Bank Directors Managing the Third Party Relationship Patrick Neuman Boardman & Clark LLP Madison, Wisconsin Any business relationship between a bank and another entity, by contract or otherwise
Vendor Management Compliance Top 10 Things Regulators Expect
Vendor Management Compliance Top 10 Things Regulators Expect Paul M. Phillips, CFA Attorney, Adams and Reese Pamela T. Rodriguez, AAP, CIA, CISA EVP, Risk Management & Education, EastPay 2014 EastPay.
Reverse Due Diligence A New Trend In Financial M&A
Portfolio Media. Inc. 860 Broadway, 6th Floor New York, NY 10003 www.law360.com Phone: +1 646 783 7100 Fax: +1 646 783 7161 [email protected] Reverse Due Diligence A New Trend In Financial M&A
Vendor Risk Management in the New Regulatory Environment. kpmg.com
Vendor Risk Management in the New Regulatory Environment kpmg.com Vendor Risk Management in the New Regulatory Environment 2 Vendor Risk Management in the New Regulatory Environment Background Regulators
GUIDANCE FOR MANAGING THIRD-PARTY RISK
GUIDANCE FOR MANAGING THIRD-PARTY RISK Introduction An institution s board of directors and senior management are ultimately responsible for managing activities conducted through third-party relationships,
Guidelines for Financial Institutions Outsourcing of Business Activities, Functions, and Processes Date: July 2004
Guidelines for Financial Institutions Outsourcing of Business Activities, Functions, and Processes Date: July 2004 1. INTRODUCTION Financial institutions outsource business activities, functions and processes
CFPB Readiness Series: Compliant Vendor Management Overview
CFPB Readiness Series: Compliant Vendor Management Overview Legal Disclaimer This information is not intended to be legal advice and may not be used as legal advice. Legal advice must be tailored to the
Risk Management of Outsourced Technology Services. November 28, 2000
Risk Management of Outsourced Technology Services November 28, 2000 Purpose and Background This statement focuses on the risk management process of identifying, measuring, monitoring, and controlling the
Blind spot Banks are increasingly outsourcing more activities to third parties. But they can t outsource the risks.
Blind spot Banks are increasingly outsourcing more activities to third parties. But they can t outsource the risks. For anyone familiar with the banking industry, it comes as no surprise that banks are
Regulatory Practice Letter December 2012 RPL 12-24
Regulatory Practice Letter December 2012 RPL 12-24 CFPB Nonbank Supervision - Larger Participants for Debt Collection and Credit Reporting Final Rules Executive Summary In February 2012, the Bureau of
SHARED ASSESSMENTS PROGRAM STANDARD INFORMATION GATHERING (SIG) QUESTIONNAIRE 2014 MAPPING TO OCC GUIDANCE (2013-29) ON THIRD PARTY RELATIONSHIPS
SHARED ASSESSMENTS PROGRAM STANDARD INFORMATION GATHERING (SIG) QUESTIONNAIRE 2014 MAPPING TO OCC GUIDANCE (2013-29) ON THIRD PARTY RELATIONSHIPS An overview of how the Shared Assessments Program SIG 2014
Preparing for the Outsourcing Challenge: Legal Due Diligence to Ensure a Winning Service Provider Relationship
THE 4 TH NATIONAL CONFERENCE ON OUTSOURCING IN FINANCIAL SERVICES NEGOTIATING, MANAGING & TERMINATING OUTSOURCING RELATIONSHIPS WHILE ENSURING REGULATORY COMPLIANCE Renaissance Mayflower, Washington, DC
White Paper on Financial Institution Vendor Management
White Paper on Financial Institution Vendor Management Virtually every organization in the modern economy relies to some extent on third-party vendors that facilitate business operations in a wide variety
Table of Contents... 1. Chapter 1 Introduction... 5. 1.1 Goals & Objectives... 5 1.2 Required Review... 5 1.3 Applicability...
... 1 Chapter 1 Introduction... 5 1.1 Goals & Objectives... 5 1.2 Required Review... 5 1.3 Applicability... 5 Chapter 2 Company Culture... 6 Chapter 3 Risk Management Governance... 7 3.1 Board of Directors...
FDIC Updates Guidance on Payment Processor Relationships
February 2012 FDIC Updates Guidance on Payment Processor Relationships BY KEVIN L. PETRASIC In its recently issued Financial Institution Letter, FIL-3-2012, the Federal Deposit Insurance Corporation (
Morgan Stanley. Policy for the Management of Third Party Residential Mortgage Servicing Providers
Morgan Stanley Policy for the Management of Third Party Residential Mortgage Servicing Providers Title Policy for the Management of Third Party Residential Mortgage Servicing Providers Effective Date Owner
Credit Union Liability with Third-Party Processors
World Council of Credit Unions Annual Conference Credit Union Liability with Third-Party Processors Andrew (Andy) Poprawa CEO, Deposit Insurance Corporation of Ontario Canada 1 Credit Union Liability with
PRINCIPLES ON OUTSOURCING OF FINANCIAL SERVICES FOR MARKET INTERMEDIARIES
PRINCIPLES ON OUTSOURCING OF FINANCIAL SERVICES FOR MARKET INTERMEDIARIES TECHNICAL COMMITTEE OF THE INTERNATIONAL ORGANIZATION OF SECURITIES COMMISSIONS FEBRUARY 2005 Preamble The IOSCO Technical Committee
Outsourcing Technology Services A Management Decision
Outsourcing Technology Services A Management Decision A Telephone Seminar for National Banks Tuesday, July 20, 2004 And again on Wednesday, July 21, 2004 Agenda Outsourcing activities and relationships
CFSA Compliance School, Part II: Implementing an Effective Compliance Management System
CFSA Compliance School, Part II: Implementing an Effective Compliance Management System Michelle Hemerley Managing Director FIS Enterprise Governance, Risk & Compliance (EGRC) SoluBon February 2014 Overview
New CFPB mortgage servicing rules present significant challenges for mortgage servicers
New CFPB mortgage servicing rules present significant challenges for mortgage servicers Prepared by: Jose Vivar, Director, McGladrey LLP 312-634-4394, [email protected] Michael Sher, Partner, McGladrey
Managing Outsourcing Arrangements
Guidance Note GGN 221.1 Managing Outsourcing Arrangements 1. This Guidance Note provides further detail on the requirements for managing material outsourcing arrangements (refer Prudential Standard GPS
TO: Chief Executive Officers of National Banks, Federal Branches and Data-Processing Centers, Department and Division Heads, and Examining Personnel
AL 2000 12 O OCC ADVISORY LETTER Comptroller of the Currency Administrator of National Banks Subject: Risk Management of Outsourcing Technology Services TO: Chief Executive Officers of National Banks,
9/13/2013. 20/20 Vision for Vendor Management & Oversight. Disclaimer. Bank Service Company Act - FIL-49-99
20/20 Vision for Vendor Management & Oversight 2013 WBA Technology Conference September 17, 2013 Ken M. Shaurette, CISSP, CISA, CISM, CRISC, IAM Director IT Services Disclaimer The views set forth are
Vendor Management Compliance Top 10 Things Regulators Expect
Vendor Management Compliance Top 10 Things Regulators Expect Peter Davey, AAP VP & Director, Enterprise Payments, CapitalOne Pamela T. Rodriguez, AAP, CIA, CISA EVP, Risk Management & Education, EastPay
Regulatory Practice Letter September 2012 RPL 12-17
Regulatory Practice Letter September 2012 RPL 12-17 Mortgage Servicing Standards - CFPB Proposed Rule Executive Summary The Bureau of Consumer Financial Protection ( CFBP or Bureau ) released two proposed
II. Compliance Examinations - Compliance Management System. Compliance Management System. Introduction. Board of Directors and Management Oversight
Compliance Management System Introduction Financial institutions operate in a dynamic environment influenced by industry consolidation, convergence of financial services, emerging technology, and market
Who s Your Vendor? Secondary Market Compliance and Title Agent Vendor Management
Who s Your Vendor? Secondary Market Compliance and Title Agent Vendor Management 2015 LBA Bank Counsel Conference Marx Sterbcow, Managing Attorney, Sterbcow Law Group The Bureau s Scrutiny of Vendor Management
Cloud Computing: Legal Risks and Best Practices
Cloud Computing: Legal Risks and Best Practices A Bennett Jones Presentation Toronto, Ontario Lisa Abe-Oldenburg, Partner Bennett Jones LLP November 7, 2012 Introduction Security and Data Privacy Recent
Reference Guide: Loan Estimate (LE) TILA- RESPA Integrated Disclosure (TRID) Rule Requirements
Reference Guide: Loan Estimate (LE) TILA- RESPA Integrated Disclosure (TRID) Rule Requirements The purpose of this document is to provide a reference guide for the Loan Estimate (LE) TILA-RESPA Integrated
Financial Services Guidance Note Outsourcing
Financial Services Guidance Note Issued: April 2005 Revised: August 2007 Table of Contents 1. Introduction... 3 1.1 Background... 3 1.2 Definitions... 3 2. Guiding Principles... 5 3. Key Risks of... 14
Vendor Management. Outsourcing Technology Services
Vendor Management Outsourcing Technology Services Objectives Board and Senior Management Responsibilities Risk Management Program Risk Assessment Service Provider Selection Contracts Ongoing Monitoring
Company Name Vendor Management Policy and Procedure. Table of Contents
Policy and Procedure Table of Contents Table of Contents... i Introduction... 1 Risks of Using Vendors... 1 Vendor Due Diligence... 2 Monitoring... 2 Section 1 Personnel... 1 Section 2 - Outside Vendors
Goldman Sachs Residential Mortgage Servicing Vendor Management Policy Addendum U.S.-Based Program
Goldman Sachs Residential Mortgage Servicing Vendor Management Policy Addendum U.S.-Based Program Effective Date: January 27, 2014 Vendor Management Policy Addendum TABLE OF CONTENTS 1. INTRODUCTION...
Minimizing Legal and Compliance Risk for Credit Furnishers
Minimizing Legal and Compliance Risk for Credit Furnishers Wednesday, November 18, 2015 2:00 p.m. 3:00 p.m. EST Webinar Speakers Jonathan L. Pompan, Esq., Partner and Co-Chair Consumer Financial Protection
Vendor Management: Who the CFPB is Watching and Who They Are Expecting You to be Watching
Vendor Management: Who the CFPB is Watching and Who They Are Expecting You to be Watching John Barnes 713.210.7441 [email protected] Jessica Hinkie 713.210.7405 [email protected] Kat Statman
Managing third-party relationships: It s complicated
Regulatory November 2013 brief A publication of PwC s financial services regulatory practice Managing third-party relationships: It s complicated Overview On October 30, 2013, the Office of the Comptroller
Checklist for a Watertight Cloud Computing Contract
Checklist for a Watertight Cloud Computing Contract Companies of all industries are recognizing the need and benefit of moving some if not all of their IT infrastructure to a Cloud whether public or private.
Third Party Relationships
3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 A B D INTRODUCTION AND PURPOSE Background Yes/No Comments 1. Does the credit union maintain a list of the third party
RISK AND COMPLIANCE COMMITTEE CHARTER
1. GENERAL SCOPE AND AUTHORITY 1.1 Introduction This charter governs the operations of the Risk & Compliance Committee of Redflex Holdings Limited (RHL or Company). 1.2 Purpose The Risk & Compliance Committee
How to Assess Legal Risk Management Practices
How to Assess s Strategy Areas for Assessment: A number of strategic areas that you may wish to start with are included in the matrix below. We invite comments on additional areas to include. Law Department
Prudential Practice Guide
Prudential Practice Guide PPG 231 Outsourcing October 2006 www.apra.gov.au Australian Prudential Regulation Authority Disclaimer and copyright This prudential practice guide is not legal advice and users
COMPLIANCE MANAGEMENT SYSTEM
COMPLIANCE MANAGEMENT SYSTEM INTRODUCTION Financial institutions operate in a dynamic environment influenced by industry consolidation, convergence of financial services, emerging technology, and market
Understanding the CFPB s TILA-RESPA Integrated Disclosures. Marvin Stone SVP, Business Integration CFPB Program Manager Stewart Title Guaranty Corp.
Understanding the CFPB s TILA-RESPA Integrated Disclosures Marvin Stone SVP, Business Integration CFPB Program Manager Stewart Title Guaranty Corp. A Brief History. Truth-in-Lending Act (TILA) of 1968
The New Third-Party Oversight Framework: Trust but Verify kpmg.com
Financial Services Regulatory Point of View The New Third-Party Oversight Framework: Trust but Verify kpmg.com The New Third-Party Oversight Framework: Trust but Verify 1 Financial services regulatory
VENDOR RISK MANAGEMENT UPDATE- ARE YOU AT RISK? Larry L. Llirán, CISA, CISM December 10, 2015 ISACA Puerto Rico Symposium
1 VENDOR RISK MANAGEMENT UPDATE- ARE YOU AT RISK? Larry L. Llirán, CISA, CISM December 10, 2015 ISACA Puerto Rico Symposium 2 Agenda Introduction Vendor Management what is? Available Guidance Vendor Management
Board Responsibility. A bank can outsource a task, but it cannot outsource the responsibility.
Third-Party Risk Board Responsibility The Board of Directors and senior management are ultimately responsible for managing activities conducted through third-party relationships as if the activity were
CFPB COMPLIANCE: Interaction Between Compliance Assessments and Systems Issues
CFPB COMPLIANCE: Interaction Between Compliance Assessments and Systems Issues Presented by: Stefanie H. Jackman Consumer Financial Services Group 678.420.9490 [email protected] Trevor Salter Consumer
Considerations for firms thinking of using third-party technology (off-the-shelf) banking solutions
Financial Conduct Authority Considerations for firms thinking of using third-party technology (off-the-shelf) banking solutions Introduction 1. A firm has many choices when designing its operating model
LRES Corporation. Best Business Practices for an Appraisal Management Company
LRES Corporation Best Business Practices for an Appraisal Management Company [This document outlines the key principles and characteristics of an appraisal management company. The contents contained within
Data Management: Considerations for Integrating Compliance Requirements At Home and Abroad. Toronto, Ontario June 14, 2005
Data Management: Considerations for Integrating Compliance Requirements At Home and Abroad Toronto, Ontario June 14, 2005 Outsourcing Update: New Contractual Options and Risks Lisa K. Abe June 14, 2005
Draft Guidelines on Outsourcing of activities by Insurance Companies
November 8, 2010 To All Insurers Draft Guidelines on Outsourcing of activities by Insurance Companies Reference: 1. INV/CIR/031/2004-05 dated 27 th July, 2004 2. INV/CIR/058/2004-05 dated 28 th December,
Statement of the Office of the Comptroller of the Currency. Provided to the Subcommittee on Financial Institutions and Consumer Protection
Statement of the Office of the Comptroller of the Currency Provided to the Subcommittee on Financial Institutions and Consumer Protection Senate Committee on Banking, Housing, and Urban Affairs Shining
FINRA Regulation of Broker-Dealer Due Diligence in Regulation D Offerings
FINRA Regulation of Broker-Dealer Due Diligence in Regulation D Offerings EDWARD G. ROSENBLATT, MCGUIREWOODS LLP, WITH PRACTICAL LAW CORPORATE & SECURITIES This Note discusses broker-dealers' affirmative
IT Governance Charter
Version : 1.01 Date : 16 September 2009 IT Governance Network South Africa USA UK Switzerland www.itgovernance.co.za [email protected] 0825588732 IT Governance Network, Copyright 2009 Page 1 1 Terms
New Regulations and Mortgage Document Management: What it Means for Mortgage Servicers
New Regulations and Mortgage Document Management: What it Means for Mortgage Servicers CT Representation Services New Regulations and Mortgage Document Management: What it Means for Mortgage Servicers
Understanding SOC Reports for Effective Vendor Management. Jason T. Clinton January 26, 2016
Understanding SOC Reports for Effective Vendor Management Jason T. Clinton January 26, 2016 MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2012 Wolf & Company, P.C. Before we
OCC 98-3 OCC BULLETIN
To: Chief Executive Officers and Chief Information Officers of all National Banks, General Managers of Federal Branches and Agencies, Deputy Comptrollers, Department and Division Heads, and Examining Personnel
Title Insurance and Settlement Company Best Practices. American Land Title Association
Title Insurance and Settlement Company Best Practices American Land Title Association Current Forces at Work Dodd Frank Wall Street Reform & Consumer Protection Act of 2010 Established the Consumer Financial
How To Be Ethical With Lead Generation
Lender Accountability for Lead Generation Tips, Tools and Regs That You Should Know About Presented by: Sarah Hulbert, 1 st Reverse Mortgage USA (Moderator) Bill Trask, Security 1 Lending Jean Noble, Urban
A Best Practice Guide
A Best Practice Guide Contents Introduction [2] The Benefits of Implementing a Privacy Management Programme [3] Developing a Comprehensive Privacy Management Programme [3] Part A Baseline Fundamentals
BOARD OF DIRECTORS RESPONSIBILITIES FOR COMPLIANCE MANAGEMENT SYSTEMS
BOARD OF DIRECTORS RESPONSIBILITIES FOR COMPLIANCE MANAGEMENT SYSTEMS Shannon Phillips Jr. Independent Bankers Association of Texas 1700 Rio Grande Street Austin, Texas 78701 [email protected] 512.275.2221
Data Privacy & Security: Essential Questions Every Business Must Ask
Data Privacy & Security: Essential Questions Every Business Must Ask Presented by: Riddell Williams P.S. Riddell Williams P.S. May 6, 2015 #4841-4703-9779 Innocent? 2 Overview 3 basic questions every business
The CIPM certification is comprised of two domains: Privacy Program Governance (I) and Privacy Program Operational Life Cycle (II).
Page 1 of 7 The CIPM certification is comprised of two domains: Privacy Program Governance (I) and Privacy Program Operational Life Cycle (II). Domain I provides a solid foundation for the governance of
