How To Understand The Risks Of A Financial Institutin

Size: px
Start display at page:

Download "How To Understand The Risks Of A Financial Institutin"

Transcription

1 Guidance n Managing Outsurcing Risk Divisin f Banking Supervisin and Regulatin Divisin f Cnsumer and Cmmunity Affairs Bard f Gvernrs f the Federal Reserve System December 5, 2013

2 Table f Cntents I. Purpse 1 II. Risks frm the Use f Service Prviders 1 III. Bard f Directrs and Senir Management Respnsibilities 2 IV. Service Prvider Risk Management Prgrams 2 A. Risk Assessments 3 B. Due Diligence and Selectin f Service Prviders 3 1. Business Backgrund, Reputatin, and Strategy 4 2. Financial Perfrmance and Cnditin 4 3. Operatins and Internal Cntrls 5 C. Cntract Prvisins and Cnsideratins 5 D. Incentive Cmpensatin Review 9 E. Oversight and Mnitring f Service Prviders 9 F. Business Cntinuity and Cntingency Cnsideratins 10 G. Additinal Risk Cnsideratins 11

3 I. Purpse In additin t traditinal cre bank prcessing and infrmatin technlgy services, financial institutins [Ftnte1 - utsurce peratinal activities such as accunting, appraisal management, internal audit, human resurces, sales and marketing, lan review, asset and wealth management, prcurement, and lan servicing. The Federal Reserve is issuing this guidance t financial institutins t highlight the ptential risks arising frm the use f service prviders and t describe the elements f an apprpriate service prvider risk management prgram. This guidance supplements existing guidance n technlgy service prvider (TSP) risk, [Ftnte2 - and applies t service prvider relatinships where business functins r activities are utsurced. Fr purpses f this guidance, "service prviders" is bradly defined t include all entities [Ftnte3 - that have entered int a cntractual relatinship with a financial institutin t prvide business functins r activities. II. Risks frm the Use f Service Prviders The use f service prviders t perfrm peratinal functins presents varius risks t financial institutins. Sme risks are inherent t the utsurced activity itself, whereas thers are intrduced with the invlvement f a service prvider. If nt managed effectively, the use f service prviders may expse financial institutins t risks that can result in regulatry actin, financial lss, litigatin, and lss f reputatin. Financial institutins shuld cnsider the fllwing risks befre entering int and while managing utsurcing arrangements. Cmpliance risks arise when the services, prducts, r activities f a service prvider fail t cmply with applicable U.S. laws and regulatins. Cncentratin risks arise when utsurced services r prducts are prvided by a limited number f service prviders r are cncentrated in limited gegraphic lcatins. Reputatinal risks arise when actins r pr perfrmance f a service prvider causes the public t frm a negative pinin abut a financial institutin. Fr purpses f this guidance, a "financial institutin" refers t state member banks, bank and savings and lan hlding cmpanies (including their nnbank subsidiaries), and U.S. peratins f freign banking rganizatins.endfftnte1.] Refer t the FFIEC Outsurcing Technlgy Services Bklet (June 2004) at http ://ithandbk.ffiec. gv/itbklets/utsurcing-technlgy-services.aspx.endfftnte2.] Entities may be a bank r nnbank, affiliated r nn-affiliated, regulated r nn-regulated, r dmestic r freign.endfftnte3.] Page 1 f 12

4 Cuntry risks arise when a financial institutin engages a freign-based service prvider, expsing the institutin t pssible ecnmic, scial, and plitical cnditins and events frm the cuntry where the prvider is lcated. Operatinal risks arise when a service prvider expses a financial institutin t lsses due t inadequate r failed internal prcesses r systems r frm external events and human errr. Legal risks arise when a service prvider expses a financial institutin t legal expenses and pssible lawsuits. III. Bard f Directrs and Senir Management Respnsibilities The use f service prviders des nt relieve a financial institutin's bard f directrs and senir management f their respnsibility t ensure that utsurced activities are cnducted in a safe-and-sund manner and in cmpliance with applicable laws and regulatins. Plicies gverning the use f service prviders shuld be established and apprved by the bard f directrs, r an executive cmmittee f the bard. These plicies shuld establish a service prvider risk management prgram that addresses risk assessments and due diligence, standards fr cntract prvisins and cnsideratins, nging mnitring f service prviders, and business cntinuity and cntingency planning. Senir management is respnsible fr ensuring that bard-apprved plicies fr the use f service prviders are apprpriately executed. This includes verseeing the develpment and implementatin f an apprpriate risk management and reprting framewrk that includes elements described in this guidance. Senir management is als respnsible fr regularly reprting t the bard f directrs n adherence t plicies gverning utsurcing arrangements. IV. Service Prvider Risk Management Prgrams A financial institutin's service prvider risk management prgram shuld be riskfcused and prvide versight and cntrls cmmensurate with the level f risk presented by the utsurcing arrangements in which the financial institutin is engaged. It shuld fcus n utsurced activities that have a substantial impact n a financial institutin's financial cnditin; are critical t the institutin's nging peratins; invlve sensitive custmer infrmatin r new bank prducts r services; r pse material cmpliance risk. The depth and frmality f the service prvider risk management prgram will depend n the criticality, cmplexity, and number f material business activities being utsurced. A Page 2 f 12

5 cmmunity banking rganizatin may have critical business activities being utsurced, but the number may be few and t highly reputable service prviders. Therefre, the risk management prgram may be simpler and use less elements and cnsideratins. Fr thse financial institutins that may use hundreds r thusands f service prviders fr numerus business activities that have material risk, the financial institutin may find that they need t use many mre elements and cnsideratins f a service prvider risk management prgram t manage the higher level f risk and reliance n service prviders. While the activities necessary t implement an effective service prvider risk management prgram can vary based n the scpe and nature f a financial institutin's utsurced activities, effective prgrams usually include the fllwing cre elements: A. Risk assessments; B. Due diligence and selectin f service prviders; C. Cntract prvisins and cnsideratins; D. Incentive cmpensatin review; E. Oversight and mnitring f service prviders; and F. Business cntinuity and cntingency plans. A. Risk Assessments Risk assessment f a business activity and the implicatins f perfrming the activity inhuse r having the activity perfrmed by a service prvider are fundamental t the decisin f whether r nt t utsurce. A financial institutin shuld determine whether utsurcing an activity is cnsistent with the strategic directin and verall business strategy f the rganizatin. After that determinatin is made, a financial institutin shuld analyze the benefits and risks f utsurcing the prpsed activity as well as the service prvider risk, and determine cst implicatins fr establishing the utsurcing arrangement. Cnsideratin shuld als be given t the availability f qualified and experienced service prviders t perfrm the service n an nging basis. Additinally, management shuld cnsider the financial institutin's ability and expertise t prvide apprpriate versight and management f the relatinship with the service prvider. This risk assessment shuld be updated at apprpriate intervals cnsistent with the financial institutin's service prvider risk management prgram. A financial institutin shuld revise its risk mitigatin plans, if apprpriate, based n the results f the updated risk assessment. B. Due Diligence and Selectin f Service Prviders A financial institutin shuld cnduct an evaluatin f and perfrm the necessary due diligence fr a prspective service prvider prir t engaging the service prvider. The depth and frmality f the due diligence perfrmed will vary depending n the scpe, cmplexity, and Page 3 f 12

6 imprtance f the planned utsurcing arrangement, the financial institutin's familiarity with prspective service prviders, and the reputatin and industry standing f the service prvider. Thrughut the due diligence prcess, financial institutin technical experts and key stakehlders shuld be engaged in the review and apprval prcess as needed. The verall due diligence prcess includes a review f the service prvider with regard t: 1. Business backgrund, reputatin, and strategy; 2. Financial perfrmance and cnditin; and 3. Operatins and internal cntrls. 1. Business Backgrund, Reputatin, and Strategy Financial institutins shuld review a prspective service prvider's status in the industry and crprate histry and qualificatins; review the backgrund and reputatin f the service prvider and its principals; and ensure that the service prvider has an apprpriate backgrund check prgram fr its emplyees. The service prvider's experience in prviding the prpsed service shuld be evaluated in rder t assess its qualificatins and cmpetencies t perfrm the service. The service prvider's business mdel, including its business strategy and missin, service philsphy, quality initiatives, and rganizatinal plicies shuld be evaluated. Financial institutins shuld als cnsider the resiliency and adaptability f the service prvider's business mdel as factrs in assessing the future viability f the prvider t perfrm services. Financial institutins shuld check the service prvider's references t ascertain its perfrmance recrd, and verify any required licenses and certificatins. Financial institutins shuld als verify whether there are any pending legal r regulatry cmpliance issues (fr example, litigatin, regulatry actins, r cmplaints) that are assciated with the prspective service prvider and its principals. 2. Financial Perfrmance and Cnditin Financial institutins shuld review the financial cnditin f the service prvider and its clsely-related affiliates. The financial review may include: The service prvider's mst recent financial statements and annual reprt with regard t utstanding cmmitments, capital strength, liquidity and perating results. The service prvider's sustainability, including factrs such as the length f time that the service prvider has been in business and the service prvider's grwth f market share fr a given service. The ptential impact f the financial institutin's business relatinship n the service prvider's financial cnditin. Page 4 f 12

7 The service prvider's cmmitment (bth in terms f financial and staff resurces) t prvide the cntracted services t the financial institutin fr the duratin f the cntract. The adequacy f the service prvider's insurance cverage. The adequacy f the service prvider's review f the financial cnditin f any subcntractrs. Other current issues the service prvider may be facing that culd affect future financial perfrmance. 3. Operatins and Internal Cntrls Financial institutins are respnsible fr ensuring that services prvided by service prviders cmply with applicable laws and regulatins and are cnsistent with safe-and-sund banking practices. Financial institutins shuld evaluate the adequacy f standards, plicies, and prcedures. Depending n the characteristics f the utsurced activity, sme r all f the fllwing may need t be reviewed: Internal cntrls; Facilities management (such as access requirements r sharing f facilities); Training, including cmpliance training fr staff; Security f systems (fr example, data and equipment); Privacy prtectin f the financial institutin's cnfidential infrmatin; Maintenance and retentin f recrds; Business resumptin and cntingency planning; Systems develpment and maintenance; Service supprt and delivery; Emplyee backgrund checks; and Adherence t applicable laws, regulatins, and supervisry guidance. C. Cntract Prvisins and Cnsideratins Financial institutins shuld understand the service cntract and legal issues assciated with prpsed utsurcing arrangements. The terms f service agreements shuld be defined in written cntracts that have been reviewed by the financial institutin's legal cunsel prir t executin. The characteristics f the business activity being utsurced and the service Page 5 f 12

8 prvider's strategy fr prviding thse services will determine the terms f the cntract. Elements f well-defined cntracts and service agreements usually include: Scpe: Cntracts shuld clearly define the rights and respnsibilities f each party, including: Supprt, maintenance, and custmer service; Cntract timeframes; Cmpliance with applicable laws, regulatins, and regulatry guidance; Training f financial institutin emplyees; The ability t subcntract services; The distributin f any required statements r disclsures t the financial institutin's custmers; Insurance cverage requirements; and Terms gverning the use f the financial institutin's prperty, equipment, and staff. Cst and cmpensatin: Cntracts shuld describe the cmpensatin, variable charges, and any fees t be paid fr nn-recurring items and special requests. Agreements shuld als address which party is respnsible fr the payment f any legal, audit, and examinatin fees related t the activity being perfrmed by the service prvider. Where applicable, agreements shuld address the party respnsible fr the expense, purchasing, and maintenance f any equipment, hardware, sftware r any ther item related t the activity being perfrmed by the service prvider. In additin, financial institutins shuld ensure that any incentives (fr example, in the frm f variable charges, such as fees and/r cmmissins) prvided in cntracts d nt prvide ptential incentives t take imprudent risks n behalf f the institutin. Right t audit: Agreements may prvide fr the right f the institutin r its representatives t audit the service prvider and/r t have access t audit reprts. Agreements shuld define the types f audit reprts the financial institutin will receive and the frequency f the audits and reprts. Establishment and mnitring f perfrmance standards: Agreements shuld define measurable perfrmance standards fr the services r prducts being prvided. Cnfidentiality and security f infrmatin: Cnsistent with applicable laws, regulatins, and supervisry guidance, service prviders shuld ensure the security and cnfidentiality f bth the financial institutin's cnfidential infrmatin and the financial institutin's custmer infrmatin. Infrmatin security measures fr utsurced functins shuld be viewed as if the activity were being perfrmed by the financial institutin and affrded the same prtectins. Financial institutins have a respnsibility t ensure service prviders take apprpriate measures designed t meet Page 6 f 12

9 the bjectives f the infrmatin security guidelines within Federal Financial Institutins Examinatin Cuncil (FFIEC) guidance [Ftnte4 -, as well as cmply with sectin 501(b) f the Gramm-Leach-Bliley Act. These measures shuld be m a p p e d directly t the security prcesses at financial institutins, as well as be included r referenced in agreements between financial institutins and service prviders. Service agreements shuld als address service prvider use f financial institutin infrmatin and its custmer infrmatin. Infrmatin m a d e available t the service prvider shuld be limited t what is needed t prvide the cntracted services. Service prviders m a y reveal cnfidential supervisry infrmatin nly t the extent authrized under applicable laws and regulatins. [Ftnte5 - If service prviders handle any f the financial institutin custmer's Persnal Infrmatin (NPPI), the service prviders must cmply with Nnpublic applicable privacy laws and regulatins. [Ftnte6 - Financial institutins shuld require ntificatin frm service prviders f any breaches invlving the disclsure f N P P I data. Generally, N P P I data is any nnpublic persnally identifiable financial infrmatin; and any list, descriptin, r ther gruping f cnsumers (and publicly available infrmatin pertaining t them) derived using any persnally identifiable financial infrmatin that is nt publicly available. [Ftnte7 - Financial institutins and their service prviders w h maintain, stre, r prcess N P P I data are respnsible fr that infrmatin and any disclsure f it. The security f, retentin f, and access t N P P I data shuld be addressed in any cntracts with service prviders. W h e n a breach r cmprmise f N P P I data ccurs, financial institutins have legal requirements that vary by state and these requirements shuld be m a d e part f the cntracts between the financial institutin and any service prvider that prvides strage, prcessing, r transmissin f N P P I data. Misuse r unauthrized disclsure f cnfidential custmer data by service prviders m a y expse financial institutins t liability r actin by a federal r state regulatry agency. Cntracts shuld clearly authrize and disclse the rles and respnsibilities f financial institutins and service prviders regarding N P P I data. Ownership and license: Agreements shuld define the ability and circumstances under which service prviders m a y use financial institutin prperty inclusive f data, hardware, sftware, and intellectual prperty. Agreements shuld address the wnership and cntrl f any infrmatin generated by service prviders. If financial institutins purchase sftware frm service prviders, escrw agreements m a y be Fr further guidance regarding vendr security practices, refer t the FFIEC Infrmatin Security Bklet (July 2006) at See See See 12 CFR Part 261.EndfFtnte5.] 12 CFR Part 1016.EndfFtnte6.] 12 U.S.C. 6801(b).EndfFtnte7.] P a g e 7 f 1 2

10 needed t ensure that financial institutins have the ability t access the surce cde and prgrams under certain cnditins. [Ftnte8 - Indemnificatin: Agreements shuld prvide fr service prvider indemnificatin f financial institutins fr any claims against financial institutins resulting frm the service prvider's negligence. Default and terminatin: Agreements shuld define events f a cntractual default, list f acceptable remedies, and prvide pprtunities fr curing default. Agreements shuld als define terminatin rights, including change in cntrl, merger r acquisitin, increase in fees, failure t meet perfrmance standards, failure t fulfill the cntractual bligatins, failure t prvide required ntices, and failure t prevent vilatins f law, bankruptcy, clsure, r inslvency. Cntracts shuld include terminatin and ntificatin requirements that prvide financial institutins with sufficient time t transfer services t anther service prvider. Agreements shuld als address a service prvider's preservatin and timely return f financial institutin data, recrds, and ther resurces. Dispute reslutin: Agreements shuld include a dispute reslutin prcess in rder t expedite prblem reslutin and address the cntinuatin f the arrangement between the parties during the dispute reslutin perid. Limits n liability: Service prviders may want t cntractually limit their liability. The bard f directrs and senir management f a financial institutin shuld determine whether the prpsed limitatins are reasnable when cmpared t the risks t the institutin if a service prvider fails t perfrm. [Ftnte9 - Insurance: Service prviders shuld have adequate insurance and prvide financial institutins with prf f insurance. Further, service prviders shuld ntify financial institutins when there is a material change in their insurance cverage. Custmer cmplaints: Agreements shuld specify the respnsibilities f financial institutins and service prviders related t respnding t custmer cmplaints. If service prviders are respnsible fr custmer cmplaint reslutin, agreements shuld prvide fr summary reprts t the financial institutins that track the status and reslutin f cmplaints. Business resumptin and cntingency plan f the service prvider: Agreements shuld address the cntinuatin f services prvided by service prviders in the event f peratinal failures. Agreements shuld address service prvider respnsibility fr Escrw agreements are established with vendrs when buying r leasing prducts that have underlying prprietary sftware. In such agreements, an rganizatin can nly access the surce prgram cde under specific cnditins, such as discntinued prduct supprt r financial inslvency f the vendr.endfftnte8.] Refer t SR letter 06-4, "Interagency Advisry n the Unsafe and Unsund Use f Limitatins n Liability Prvisins in External Audit Engagement Letters," regarding restrictins n the liability limitatins fr external audit engagements at Page 8 f 12

11 backing up infrmatin and maintaining disaster recvery and cntingency plans. Agreements may include a service prvider's respnsibility fr testing f plans and prviding testing results t financial institutins. Freign-based service prviders: Fr agreements with freign-based service prviders, financial institutins shuld cnsider including express chice f law and jurisdictinal prvisins that wuld prvide fr the adjudicatin f all disputes between the tw parties under the laws f a single, specific jurisdictin. Such agreements may be subject t the interpretatin f freign curts relying n lcal laws. Freign law may differ frm U.S. law in the enfrcement f cntracts. As a result, financial institutins shuld seek legal advice regarding the enfrceability f all aspects f prpsed cntracts with freign-based service prviders and the ther legal ramificatins f such arrangements. Subcntracting: If agreements allw fr subcntracting, the same cntractual prvisins shuld apply t the subcntractr. Cntract prvisins shuld clearly state that the primary service prvider has verall accuntability fr all services that the service prvider and its subcntractrs prvide. Agreements shuld define the services that may be subcntracted, the service prvider's due diligence prcess fr engaging and mnitring subcntractrs, and the ntificatin and apprval requirements regarding changes t the service prvider's subcntractrs. Financial institutins shuld pay special attentin t any freign subcntractrs, as infrmatin security and data privacy standards may be different in ther jurisdictins. Additinally, agreements shuld include the service prvider's prcess fr assessing the subcntractr's financial cnditin t fulfill cntractual bligatins. D. Incentive Cmpensatin Review Financial institutins shuld als ensure that an effective prcess is in place t review and apprve any incentive cmpensatin that may be embedded in service prvider cntracts, including a review f whether existing gvernance and cntrls are adequate in light f risks arising frm incentive cmpensatin arrangements. As the service prvider represents the institutin by selling prducts r services n its behalf, the institutin shuld cnsider whether the incentives prvided might encurage the service prvider t take imprudent risks. Inapprpriately structured incentives may result in reputatinal damage, increased litigatin, r ther risks t the financial institutin. An example f an inapprpriate incentive wuld be ne where variable fees r cmmissins encurage the service prvider t direct custmers t prducts with higher prfit margins withut due cnsideratin f whether such prducts are suitable fr the custmer. E. Oversight and Mnitring f Service Prviders T effectively mnitr cntractual requirements, financial institutins shuld establish acceptable perfrmance metrics that the business line r relatinship management determines t be indicative f acceptable perfrmance levels. Financial institutins shuld ensure that Page 9 f 12

12 persnnel with versight and management respnsibilities fr service prviders have the apprpriate level f expertise and stature t manage the utsurcing arrangement. The versight prcess, including the level and frequency f management reprting, shuld be risk-fcused. Higher risk service prviders may require mre frequent assessment and mnitring and may require financial institutins t designate individuals r a grup as a pint f cntact fr thse service prviders. Financial institutins shuld tailr and implement risk mitigatin plans fr higher risk service prviders that may include prcesses such as additinal reprting by the service prvider r heightened mnitring by the financial institutin. Further, mre frequent and stringent mnitring is necessary fr service prviders that exhibit perfrmance, financial, cmpliance, r cntrl cncerns. Fr lwer risk service prviders, the level f mnitring can be lessened. Financial cnditin: Financial institutins shuld have established prcedures t mnitr the financial cnditin f service prviders t evaluate their nging viability. In perfrming these assessments, financial institutins shuld review the mst recent financial statements and annual reprt with regard t utstanding cmmitments, capital strength, liquidity and perating results. If a service prvider relies significantly n subcntractrs t prvide services t financial institutins, then the service prvider's cntrls and due diligence regarding the subcntractrs shuld als be reviewed. Internal cntrls: Fr significant service prvider relatinships, financial institutins shuld assess the adequacy f the prvider's cntrl envirnment. Assessments shuld include reviewing available audits r reprts such as the American Institute f Certified Public Accuntants' Service Organizatin Cntrl 2 reprt. [Ftnte10 - If the service prvider delivers infrmatin technlgy services, the financial institutin can request the FFIEC Technlgy Service Prvider examinatin reprt frm its primary federal regulatr. Security incidents at the service prvider may als necessitate the institutin t elevate its mnitring f the service prvider. Escalatin f versight activities: Financial institutins shuld ensure that risk management prcesses include triggers t escalate versight and mnitring when service prviders are failing t meet perfrmance, cmpliance, cntrl, r viability expectatins. These prcedures shuld include mre frequent and stringent mnitring and fllw-up n identified issues, n-site cntrl reviews, and when an institutin shuld exercise its right t audit a service prvider's adherence t the terms f the agreement. Financial institutins shuld develp criteria fr engaging alternative utsurcing arrangements and terminating the service prvider cntract in the event that identified issues are nt adequately addressed in a timely manner. F. Business Cntinuity and Cntingency Cnsideratins Varius events may affect a service prvider's ability t prvide cntracted services. Fr example, services culd be disrupted by a prvider's perfrmance failure, peratinal disruptin, financial difficulty, r failure f business cntinuity and cntingency plans during peratinal Refer t Page 10 f 12

13 disruptins r natural disasters. Financial institutin cntingency plans shuld fcus n critical services prvided by service prviders and cnsider alternative arrangements in the event that a service prvider is unable t perfrm. [Ftnte1 1 - W h e n preparing cntingency plans, financial institutins shuld: Ensure that a disaster recvery and business cntinuity plan exists with regard t the cntracted services and prducts; Assess the adequacy and effectiveness f a service prvider's disaster recvery and business cntinuity plan and its alignment t their w n plan; D c u m e n t the rles and respnsibilities fr maintaining and testing the service prvider's business cntinuity and cntingency plans; Test the service prvider's business cntinuity and cntingency plans n a peridic basis t ensure adequacy and effectiveness; and Maintain an exit strategy, including a pl f cmparable service prviders, in the event that a cntracted service prvider is unable t perfrm. G. A d d i t i n a l R i s k C n s i d e r a t i n s Suspicius Activity Reprt ( S A R ) reprting functins: The cnfidentiality f suspicius activity reprting m a k e s the utsurcing f any SAR-related functin m r e cmplex. Financial institutins need t identify and mnitr the risks assciated with using service prviders t perfrm certain suspicius activity reprting functins in cmpliance with the B a n k Secrecy Act (BSA). Financial institutin m a n a g e m e n t shuld ensure they understand the risks assciated with such an arrangement and any BSA-specific guidance in this area. Freign-based service prviders: Financial institutins shuld ensure that freign-based service prviders are in cmpliance with applicable U.S. laws, regulatins, and regulatry guidance. Financial institutins m a y als want t cnsider laws and regulatins f the freignbased prvider's cuntry r regulatry authrity regarding the financial institutin's ability t perfrm n-site review f the service prvider's peratins. In additin, financial institutins shuld cnsider the authrity r ability f h m e cuntry supervisrs t gain access t the financial institutin's custmer infrmatin while examining the freign-based service prvider. Internal audit: Financial institutins shuld refer t existing guidance n the engagement f independent public accunting firms and ther utside prfessinals t perfrm w r k that has been traditinally carried ut by internal auditrs. [Ftnte1 2 - The Sarbanes-Oxley Act f Fr further guidance regarding business cntinuity planning with service prviders, refer t the FFIEC Business Cntinuity Bklet (March 2008) at Refer t SR 13-1, "Supplemental Plicy Statement n the Internal Audit Functin and Its Outsurcing," specifically the sectin titled, "Depsitry Institutins Subject t the Annual Audit and Reprting Requirements f Sectin 36 f the FDI Act" at Refer als t SR 03-5, "Amended Interagency Guidance n the Internal Audit Functin and its Outsurcing," particularly the sectin titled, "Institutins Nt Subject t Sectin 36 f the FDI Act that are Neither Public Cmpanies nr Subsidiaries f Public Cmpanies" at End f Ftnte 12.] P a g e 1 1 f 1 2

14 2002 specifically prhibits a registered public accunting firm frm perfrming certain nn-audit services fr a public cmpany client fr whm it perfrms financial statement audits. Risk management activities: Financial institutins may utsurce varius risk management activities, such as aspects f interest rate risk and mdel risk management. Financial institutins shuld require service prviders t prvide infrmatin that demnstrates develpmental evidence explaining the prduct cmpnents, design, and intended use, t determine whether the prducts and/r services are apprpriate fr the institutin's expsures and risks. [Ftnte13 - Financial institutins shuld als have standards and prcesses in place fr ensuring that service prviders ffering mdel risk management services, such as validatin, d s in a way that is cnsistent with existing mdel risk management guidance. Refer t SR 11-7, "Guidance n Mdel Risk Management" which infrms financial institutins f the imprtance and risk t the use f mdels and the supervisry expectatins that financial institutins shuld adhere t. gv/bankinfreg/srletters/sr1107.htmendfftnte13.] Page 12 f 12

Vendor Management. Federal Deposit Insurance Corporation Division of Risk Management Supervision Atlanta Regional Office.

Vendor Management. Federal Deposit Insurance Corporation Division of Risk Management Supervision Atlanta Regional Office. Vendr Management Federal Depsit Insurance Crpratin Divisin f Risk Management Supervisin Atlanta Reginal Office June 18, 2014 1 Agenda Intrductin Vendr Management Overview Regulatry Expectatins Bard and

More information

Outsourcing arrangements

Outsourcing arrangements Rules Ntice Guidance Nte Dealer Member Rules Please distribute internally t: Internal Audit Legal and Cmpliance Operatins Regulatry Accunting Senir Management Cntacts: Luis Piergeti Vice President, Financial

More information

Internal Audit Charter and operating standards

Internal Audit Charter and operating standards Internal Audit Charter and perating standards 2 1 verview This dcument sets ut the basis fr internal audit: (i) the Internal Audit charter, which establishes the framewrk fr Internal Audit; and (ii) hw

More information

SecurityNational Mortgage Company Vendor Management Program

SecurityNational Mortgage Company Vendor Management Program SecurityNatinal Mrtgage Cmpany Vendr Management Prgram CONTENTS OVERVIEW... 1 VENDOR RISKS... 3 Strategic Risk... 3 Reputatin Risk... 3 Operatinal Risk... 3 Transactin Risk... 4 Credit Risk... 4 Cmpliance

More information

Audit Committee Charter

Audit Committee Charter Audit Cmmittee Charter Membership The Audit Cmmittee (the "Cmmittee") f the Bard f Directrs (the "Bard") f Philip Mrris Internatinal Inc. (the "Cmpany") shall cnsist f at least three directrs all f whm

More information

COPIES-F.Y.I., INC. Policies and Procedures Data Security Policy

COPIES-F.Y.I., INC. Policies and Procedures Data Security Policy COPIES-F.Y.I., INC. Plicies and Prcedures Data Security Plicy Page 2 f 7 Preamble Mst f Cpies FYI, Incrprated financial, administrative, research, and clinical systems are accessible thrugh the campus

More information

MSB FINANCIAL CORP. MILLINGTON BANK AUDIT COMMITTEE CHARTER

MSB FINANCIAL CORP. MILLINGTON BANK AUDIT COMMITTEE CHARTER MSB FINANCIAL CORP. MILLINGTON BANK AUDIT COMMITTEE CHARTER This Audit Cmmittee Charter has been amended as f July 17, 2015. The Audit Cmmittee shall review and reassess this Charter annually and recmmend

More information

Key Steps for Organizations in Responding to Privacy Breaches

Key Steps for Organizations in Responding to Privacy Breaches Key Steps fr Organizatins in Respnding t Privacy Breaches Purpse The purpse f this dcument is t prvide guidance t private sectr rganizatins, bth small and large, when a privacy breach ccurs. Organizatins

More information

CMS Eligibility Requirements Checklist for MSSP ACO Participation

CMS Eligibility Requirements Checklist for MSSP ACO Participation ATTACHMENT 1 CMS Eligibility Requirements Checklist fr MSSP ACO Participatin 1. General Eligibility Requirements ACO participants wrk tgether t manage and crdinate care fr Medicare fee-fr-service beneficiaries.

More information

FINANCIAL SERVICES FLASH REPORT

FINANCIAL SERVICES FLASH REPORT FINANCIAL SERVICES FLASH REPORT Draft Regulatry Cmpliance Management Guideline Released by the Office f the Superintendent f Financial Institutins May 5, 2014 On April 30, 2014, the Office f the Superintendent

More information

CASSOWARY COAST REGIONAL COUNCIL POLICY ENTERPRISE RISK MANAGEMENT

CASSOWARY COAST REGIONAL COUNCIL POLICY ENTERPRISE RISK MANAGEMENT CASSOWARY COAST REGIONAL COUNCIL POLICY ENTERPRISE RISK MANAGEMENT Plicy Number: 2.20 1. Authrity Lcal Gvernment Act 2009 Lcal Gvernment Regulatin 2012 AS/NZS ISO 31000-2009 Risk Management Principles

More information

Sources of Federal Government and Employee Information

Sources of Federal Government and Employee Information Inf Surce Surces f Federal Gvernment and Emplyee Infrmatin Ridley Terminals Inc. TABLE OF CONTENTS General Infrmatin Intrductin t Inf Surce Backgrund Respnsibilities Institutinal Functins, Prgram and Activities

More information

Audit Committee Charter. St Andrew s Insurance (Australia) Pty Ltd St Andrew s Life Insurance Pty Ltd St Andrew s Australia Services Pty Ltd

Audit Committee Charter. St Andrew s Insurance (Australia) Pty Ltd St Andrew s Life Insurance Pty Ltd St Andrew s Australia Services Pty Ltd Audit Cmmittee Charter St Andrew s Insurance (Australia) Pty Ltd St Andrew s Life Insurance Pty Ltd St Andrew s Australia Services Pty Ltd Versin 2.0, 22 February 2016 Apprver Bard f Directrs St Andrew

More information

POLICY 1390 Information Technology Continuity of Business Planning Issued: June 4, 2009 Revised: June 12, 2014

POLICY 1390 Information Technology Continuity of Business Planning Issued: June 4, 2009 Revised: June 12, 2014 State f Michigan POLICY 1390 Infrmatin Technlgy Cntinuity f Business Planning Issued: June 4, 2009 Revised: June 12, 2014 SUBJECT: APPLICATION: PURPOSE: CONTACT AGENCY: Plicy fr Infrmatin Technlgy (IT)

More information

TO: Chief Executive Officers of all National Banks, Department and Division Heads, and all Examining Personnel

TO: Chief Executive Officers of all National Banks, Department and Division Heads, and all Examining Personnel AL 96-7 Subject: Credit Card Preapprved Slicitatins TO: Chief Executive Officers f all Natinal Banks, Department and Divisin Heads, and all Examining Persnnel PURPOSE The purpse f this advisry letter is

More information

THE CITY UNIVERSITY OF NEW YORK IDENTITY THEFT PREVENTION PROGRAM

THE CITY UNIVERSITY OF NEW YORK IDENTITY THEFT PREVENTION PROGRAM THE CITY UNIVERSITY OF NEW YORK IDENTITY THEFT PREVENTION PROGRAM 1. Prgram Adptin The City University f New Yrk (the "University") develped this Identity Theft Preventin Prgram (the "Prgram") pursuant

More information

DALBAR Due Diligence: Trust, but Verify

DALBAR Due Diligence: Trust, but Verify BEST INTEREST INVESTMENT RECOMMENDATIONS Advisr Rle under Best Interest Regulatins January 27, 2016 In the era when the cntractual bligatin is t act in the client s best interest, investment decisins can

More information

CHARTER OF THE COMPENSATION COMMITTEE OF THE BOARD OF DIRECTORS OF UPLAND SOFTWARE, INC.

CHARTER OF THE COMPENSATION COMMITTEE OF THE BOARD OF DIRECTORS OF UPLAND SOFTWARE, INC. CHARTER OF THE COMPENSATION COMMITTEE OF THE BOARD OF DIRECTORS OF UPLAND SOFTWARE, INC. PURPOSE The purpse f the Cmpensatin Cmmittee f the Bard f Directrs (the Bard ) f Upland Sftware, Inc. (the Cmpany

More information

Personal Data Security Breach Management Policy

Personal Data Security Breach Management Policy Persnal Data Security Breach Management Plicy 1.0 Purpse The Data Prtectin Acts 1988 and 2003 impse bligatins n data cntrllers in Western Care Assciatin t prcess persnal data entrusted t them in a manner

More information

Risk Management Policy AGL Energy Limited

Risk Management Policy AGL Energy Limited Risk Management Plicy AGL Energy Limited AUGUST 2014 Table f Cntents 1. Abut this Dcument... 2 2. Plicy Statement... 2 3. Purpse... 2 4. AGL Risk Cntext... 3 5. Scpe... 3 6. Objectives... 3 7. Accuntabilities...

More information

GUIDANCE FOR BUSINESS ASSOCIATES

GUIDANCE FOR BUSINESS ASSOCIATES GUIDANCE FOR BUSINESS ASSOCIATES This Guidance fr Business Assciates dcument is intended t verview UPMCs expectatins, as well as t prvide additinal resurces and infrmatin, t UPMC s HIPAA business assciates.

More information

FAFSA / DREAM ACT COMPLETION PROGRAM AGREEMENT

FAFSA / DREAM ACT COMPLETION PROGRAM AGREEMENT FAFSA / DREAM ACT COMPLETION PROGRAM AGREEMENT If using US Pstal Service, please return t: Califrnia Student Aid Cmmissin Prgram Administratin & Services Divisin ATTN: Institutinal Supprt P.O. Bx 419028

More information

Project Open Hand Atlanta. Health Insurance Portability and Accountability Act (HIPAA) NOTICE OF PRIVACY PRACTICES

Project Open Hand Atlanta. Health Insurance Portability and Accountability Act (HIPAA) NOTICE OF PRIVACY PRACTICES Prject Open Hand Atlanta Effective Date: April 14, 2003 Health Insurance Prtability and Accuntability Act (HIPAA) The Health Insurance Prtability and Accuntability Act f 1996 (HIPAA) directs health care

More information

THIRD PARTY PROCUREMENT PROCEDURES

THIRD PARTY PROCUREMENT PROCEDURES ADDENDUM #1 THIRD PARTY PROCUREMENT PROCEDURES NORTH CENTRAL TEXAS COUNCIL OF GOVERNMENTS TRANSPORTATION DEPARTMENT JUNE 2011 OVERVIEW These prcedures establish standards and guidelines fr the Nrth Central

More information

NYU Langone Medical Center NYU Hospitals Center NYU School of Medicine

NYU Langone Medical Center NYU Hospitals Center NYU School of Medicine Title: Identity Theft Prgram Effective Date: July 2009 NYU Langne Medical Center NYU Hspitals Center NYU Schl f Medicine POLICY It is the plicy f the NYU Langne Medical Center t educate and train staff

More information

VCU Payment Card Policy

VCU Payment Card Policy VCU Payment Card Plicy Plicy Type: Administrative Respnsible Office: Treasury Services Initial Plicy Apprved: 12/05/2013 Current Revisin Apprved: 12/05/2013 Plicy Statement and Purpse The purpse f this

More information

WHAT YOU NEED TO KNOW ABOUT. Protecting your Privacy

WHAT YOU NEED TO KNOW ABOUT. Protecting your Privacy WHAT YOU NEED TO KNOW ABOUT Prtecting yur Privacy YOUR PRIVACY IS OUR PRIORITY Credit unins have a histry f respecting the privacy f ur members and custmers. Yur Bard f Directrs has adpted the Credit Unin

More information

Chapter 7 Business Continuity and Risk Management

Chapter 7 Business Continuity and Risk Management Chapter 7 Business Cntinuity and Risk Management Sectin 01 Business Cntinuity Management 070101 Initiating the Business Cntinuity Plan (BCP) Purpse: T establish the apprpriate level f business cntinuity

More information

GENERAL MOTORS COMPANY AUDIT COMMITTEE CHARTER. Most Recently Amended: December 8, 2015

GENERAL MOTORS COMPANY AUDIT COMMITTEE CHARTER. Most Recently Amended: December 8, 2015 GENERAL MOTORS COMPANY AUDIT COMMITTEE CHARTER Mst Recently Amended: December 8, 2015 Purpse The purpse f the Audit Cmmittee is t assist the Bard f Directrs f General Mtrs Cmpany in its versight f the

More information

Presentation: The Demise of SAS 70 - What s Next?

Presentation: The Demise of SAS 70 - What s Next? Presentatin: The Demise f SAS 70 - What s Next? September 15, 2011 1 Presenters: Jeffrey Ziplw - Partner BlumShapir Jennifer Gerasimv Senir Manager Delitte. SAS 70 Backgrund and Overview Purpse f a SAS

More information

SECTION J QUALITY ASSURANCE AND IMPROVEMENT PROGRAM

SECTION J QUALITY ASSURANCE AND IMPROVEMENT PROGRAM Audit Manual Sectin J SECTION J QUALITY ASSURANCE AND IMPROVEMENT PROGRAM Ref. Plicy and Practice Requirements IIA Standards and Other references J 1 Plicy: The Head f Internal Audit shall develp and maintain

More information

Request for Resume (RFR) CATS II Master Contract. All Master Contract Provisions Apply

Request for Resume (RFR) CATS II Master Contract. All Master Contract Provisions Apply Sectin 1 General Infrmatin RFR Number: (Reference BPO Number) Functinal Area (Enter One Only) F50B3400026 7 Infrmatin System Security Labr Categry A single supprt resurce may be engaged fr a perid nt t

More information

In-House Counsel Day Priorities for 2012. Cloud Computing the benefits, potential risks and security for the future

In-House Counsel Day Priorities for 2012. Cloud Computing the benefits, potential risks and security for the future In-Huse Cunsel Day Pririties fr 2012 Clud Cmputing the benefits, ptential risks and security fr the future Presented by David Richardsn Thursday 1 March 2012 WIN: What in-huse lawyers need Knwledge, supprt

More information

ERISA Compliance FAQs: Fiduciary Responsibilities

ERISA Compliance FAQs: Fiduciary Responsibilities Brught t yu by Mrris & Reynlds Insurance ERISA Cmpliance FAQs: Fiduciary Respnsibilities The Emplyee Retirement Incme Security Act f 1974 (ERISA) is a federal law that sets minimum standards fr emplyee

More information

Data Protection Act Data security breach management

Data Protection Act Data security breach management Data Prtectin Act Data security breach management The seventh data prtectin principle requires that rganisatins prcessing persnal data take apprpriate measures against unauthrised r unlawful prcessing

More information

ENTERPRISE RISK MANAGEMENT ENTERPRISE RISK MANAGEMENT POLICY

ENTERPRISE RISK MANAGEMENT ENTERPRISE RISK MANAGEMENT POLICY ENTERPRISE RISK MANAGEMENT POLICY Plicy N. 10014 Review Date Octber 1, 2014 Effective Date March 1, 2014 Crss- Respnsibility Vice President, Reference Administratin Apprver Executive Cuncil 1. 1. Plicy

More information

10 th May 2010. Dear Peter, Re: Audit Quality in Australia: A Strategic Review

10 th May 2010. Dear Peter, Re: Audit Quality in Australia: A Strategic Review 10 th May 2010 Mr. Peter Levy Audit Quality Strategic Review Crpratins and Financial Services Divisin The Treasury Langtn Crescent PARKES ACT 2600 Dear Peter, Re: Audit Quality in Australia: A Strategic

More information

Appendix H. Annual Risk Assessment and Audit Plan 2013/14

Appendix H. Annual Risk Assessment and Audit Plan 2013/14 Annual Risk Assessment and Audit Plan 2013/14 Internal Audit Department September 25, 2013 Table f Cntents Intrductin.. 3 Risk Assessment Prcess... 4 Page 2 Intrductin Each year, the Internal Audit Department

More information

University of Texas at Dallas Policy for Accepting Credit Card and Electronic Payments

University of Texas at Dallas Policy for Accepting Credit Card and Electronic Payments University f Texas at Dallas Plicy fr Accepting Credit Card and Electrnic Payments Cntents: Purpse Applicability Plicy Statement Respnsibilities f a Merchant Department Prcess t Becme a Merchant Department

More information

Change Management Process

Change Management Process Change Management Prcess B1.10 Change Management Prcess 1. Intrductin This plicy utlines [Yur Cmpany] s apprach t managing change within the rganisatin. All changes in strategy, activities and prcesses

More information

HIPAA Compliance 101. Important Terms. Pittsburgh Computer Solutions 724-942-1337

HIPAA Compliance 101. Important Terms. Pittsburgh Computer Solutions 724-942-1337 HIPAA Cmpliance 101 Imprtant Terms Cvered Entities (CAs) The HIPAA Privacy Rule refers t three specific grups as cvered entities, including health plans, healthcare clearinghuses, and health care prviders

More information

Better Practice Guide Financial Considerations for Government use of Cloud Computing

Better Practice Guide Financial Considerations for Government use of Cloud Computing Better Practice Guide Financial Cnsideratins fr Gvernment use f Clud Cmputing Nvember 2011 Intrductin Many Australian Gvernment agencies are in the prcess f cnsidering the adptin f clud-based slutins.

More information

GUIDELINE INFORMATION MANAGEMENT (IM) PROGRAM PLAN

GUIDELINE INFORMATION MANAGEMENT (IM) PROGRAM PLAN Gvernment f Newfundland and Labradr Office f the Chief Infrmatin Officer Infrmatin Management Branch GUIDELINE INFORMATION MANAGEMENT (IM) PROGRAM PLAN Guideline (Definitin): OCIO Guidelines derive frm

More information

Information Security Policy

Information Security Policy Purpse The risk t Charlestn Suthern University, its emplyees and students frm data lss and identity theft is f significant cncern t the University and can be reduced nly thrugh the cmbined effrts f every

More information

A Comparison of UK and Chinese Broking Regulation

A Comparison of UK and Chinese Broking Regulation A Cmparisn f UK and Chinese Brking Regulatin David Cupe Partner +44 (0)203 553 4884 david.cupe@ec3legal.cm The fllwing tables are a cmparisn f UK and Chinese brking regulatins including the Llyd s regulatins.

More information

NAIC Replacement Requirements For Certain Life Insurance Policies And Annuity Contracts

NAIC Replacement Requirements For Certain Life Insurance Policies And Annuity Contracts NAIC Replacement Requirements Fr Certain Life Insurance Plicies And Annuity Cntracts Duties f Prducers If a transactin invlves a replacement, the prducer must leave with the applicant, at the time an applicatin

More information

Hampton Roads Orthopaedics & Sports Medicine. Notice of Privacy Practices

Hampton Roads Orthopaedics & Sports Medicine. Notice of Privacy Practices This is being prvided t yu as a requirement f the privacy regulatins issued under the Health Insurance Prtability and Accuntability Act f 1996 (HIPAA). This ntice describes hw HROSM may use and disclse

More information

Corporate Standards for data quality and the collation of data for external presentation

Corporate Standards for data quality and the collation of data for external presentation The University f Kent Crprate Standards fr data quality and the cllatin f data fr external presentatin This paper intrduces a set f standards with the aim f safeguarding the University s psitin in published

More information

Creating an Ethical Culture and Protecting Your Bottom Line:

Creating an Ethical Culture and Protecting Your Bottom Line: Creating an Ethical Culture and Prtecting Yur Bttm Line: Best Practices fr Crprate Cdes f Cnduct Nte: The infrmatin belw and all infrmatin n this website is nt meant t be taken as legal advice. Please

More information

Process for Responding to Privacy Breaches

Process for Responding to Privacy Breaches Prcess fr Respnding t Privacy Breaches 1. Purpse 1.1 This dcument sets ut the steps that ministries must fllw when respnding t a privacy breach. It must be read in cnjunctin with the Infrmatin Incident

More information

Business Continuity Management Policy

Business Continuity Management Policy Business Cntinuity Management Plicy Versin: 1.0 Last Amendment: Apprved by: Library Cuncil f New Suth Wales Plicy wner/spnsr: Directr, Operatins and Chief Financial Officer Plicy Cntact Officer: Senir

More information

MANITOBA SECURITIES COMMISSION STRATEGIC PLAN 2013-2016

MANITOBA SECURITIES COMMISSION STRATEGIC PLAN 2013-2016 MANITOBA SECURITIES COMMISSION STRATEGIC PLAN 2013-2016 The Manitba Securities Cmmissin (the Cmmissin) is a divisin f the Manitba Financial Services Agency (MFSA). The ther divisin is the Financial Institutins

More information

E-Business Strategies For a Cmpany s Bard

E-Business Strategies For a Cmpany s Bard DATATEC LIMITED BOARD CHARTER / TERMS OF REFERENCE 1. CONSTITUTION The primary bjective f the Cmpany s Bard Charter is t set ut the rle and respnsibilities f the Bard f Directrs ( the Bard ) as well as

More information

HIPAA Notice of Privacy Practices. Central Ohio Surgical Associates, Inc.

HIPAA Notice of Privacy Practices. Central Ohio Surgical Associates, Inc. HIPAA Ntice f Privacy Practices Central Ohi Surgical Assciates, Inc. THIS NOTICE OF PRIVACY PRACTICES (THE NOTICE ) DESCRIBES HOW HEALTH INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN

More information

TrustED Briefing Series:

TrustED Briefing Series: TrustED Briefing Series: Since 2001, TrustCC has prvided IT audits and security assessments t hundreds f financial institutins thrugh ut the United States. Our TrustED Briefing Series are white papers

More information

How To Write An Ehsms Training, Awareness And Competency Procedure

How To Write An Ehsms Training, Awareness And Competency Procedure Envirnmental, Health & Safety Management System (EHSMS) Dcument Number: 00122 Issue Date: 05/07/2014 Training, Awareness and Cmpetency Prcedure Revisin Number: 7 Prepared By: Stalcup, Bryce Apprved By:

More information

Human Resources Policy pol-020

Human Resources Policy pol-020 Human Resurces Plicy pl-020 Versin: 2.00 Last amendment: Jul 2014 Next Review: Jul 2017 Apprved By: Cuncil Date: 04 May 2005 Cntact Officer: Directr, Office f Human Resurce Services INTRODUCTION The University

More information

Communicating Deficiencies in Internal Control to Those Charged with Governance and Management

Communicating Deficiencies in Internal Control to Those Charged with Governance and Management Internatinal Auditing and Assurance Standards Bard ISA 265 April 2009 Internatinal Standard n Auditing Cmmunicating Deficiencies in Internal Cntrl t Thse Charged with Gvernance and Management Internatinal

More information

Major capital investment in councils. Good practice checklist for project managers

Major capital investment in councils. Good practice checklist for project managers Majr capital investment in cuncils checklist fr prject managers Prepared by Audit Sctland March 2013 b The Accunts Cmmissin The Accunts Cmmissin is a statutry, independent bdy which, thrugh the audit prcess,

More information

Systems Support - Extended

Systems Support - Extended 1 General Overview This is a Service Level Agreement ( SLA ) between and the Enterprise Windws Services t dcument: The technlgy services the Enterprise Windws Services prvides t the custmer. The targets

More information

Information Security Incident Response Plan

Information Security Incident Response Plan Infrmatin Security Incident Respnse Plan Agency: Date: Cntact: 1 TABLE OF CONTENTS Intrductin... 3 Authrity... 4 Terms and Definitins... 4 Rles and Respnsibilities... 5 Prgram... 6 Educatin and Awareness...

More information

Environment Protection Authority

Environment Protection Authority Envirnment Prtectin Authrity EPA Cmplaints Management Plicy Intrductin This plicy sets ut the purpse, principles and prcess fr hw custmer feedback, including cmplaints, will be managed in the EPA t imprve

More information

STANDARDISATION IN E-ARCHIVING

STANDARDISATION IN E-ARCHIVING STANDARDISATION IN E-ARCHIVING R E Q U I R E M E N T S A N D C O N T R O L S F O R D I G I T I S AT I O N A N D E - A R C H I V I N G S E R V I C E P R O V I D E R S Alain Wahl 1 Requirements and cntrls

More information

BLUE RIDGE COMMUNITY AND TECHNICAL COLLEGE BOARD OF GOVERNORS

BLUE RIDGE COMMUNITY AND TECHNICAL COLLEGE BOARD OF GOVERNORS BLUE RIDGE COMMUNITY AND TECHNICAL COLLEGE BOARD OF GOVERNORS SERIES: 1 General Rules RULE: 17.1 Recrd Retentin Scpe: The purpse f this rule is t establish the systematic review, retentin and destructin

More information

National Australia Bank Limited Group Disclosure & External Communications Policy

National Australia Bank Limited Group Disclosure & External Communications Policy Natinal Australia Bank Limited Grup Disclsure & External Cmmunicatins Plicy Grup Disclsure & External Cmmunicatins Plicy Page 2 f 7 Grup Disclsure & External Cmmunicatins Plicy ( the Plicy ) 1. Overview

More information

RUTGERS POLICY. Responsible Executive: Vice President for Information Technology and Chief Information Officer

RUTGERS POLICY. Responsible Executive: Vice President for Information Technology and Chief Information Officer RUTGERS POLICY Sectin: 70.1.1 Sectin Title: Infrmatin Technlgy Plicy Name: Acceptable Use Plicy fr Infrmatin Technlgy Resurces Frmerly Bk: N/A Apprval Authrity: Senir Vice President fr Administratin Respnsible

More information

expertise hp services valupack consulting description security review service for Linux

expertise hp services valupack consulting description security review service for Linux expertise hp services valupack cnsulting descriptin security review service fr Linux Cpyright services prvided, infrmatin is prtected under cpyright by Hewlett-Packard Cmpany Unpublished Wrk -- ALL RIGHTS

More information

AUDIT AND RISK COMMITTEE TERMS OF REFERENCE

AUDIT AND RISK COMMITTEE TERMS OF REFERENCE AUDIT AND RISK COMMITTEE TERMS OF REFERENCE 1. TITLE OF COMMITTEE Audit and Risk Cmmittee 2. ESTABLISHMENT The Audit and Risk Cmmittee is established under Part 3 Sectin 19(1) f the Charles Darwin University

More information

IT CHANGE MANAGEMENT POLICY

IT CHANGE MANAGEMENT POLICY IT CHANGE MANAGEMENT POLICY Effective Date May 19, 2016 Crss-Reference 1. IT Operatins and Maintenance Plicy 2. IT Security Incident Management Plicy Respnsibility Apprver Review Schedule 1. Plicy Statement

More information

Business Plan Overview

Business Plan Overview Business Plan Overview Organizatin and Cntent Summary A business plan is a descriptin f yur business, including yur prduct yur market, yur peple and yur financing needs. Yu shuld cnsider that a well prepared

More information

HEALTH INFORMATION EXCHANGE GRANTS CRITERIA

HEALTH INFORMATION EXCHANGE GRANTS CRITERIA 1 HEALTH INFORMATION EXCHANGE GRANTS CRITERIA INTRODUCTION On August, 20 th, the federal Office f the Natinal Crdinatr fr Health Infrmatin Technlgy (ONC) released an pprtunity fr states t apply fr between

More information

TITLE: Supplier Contracting Guidelines Process: FIN_PS_PSG_050 Replaces: Manual Sections 6.4, 7.1, 7.5, 7.6, 7.11 Effective Date: 10/1/2014 Contents

TITLE: Supplier Contracting Guidelines Process: FIN_PS_PSG_050 Replaces: Manual Sections 6.4, 7.1, 7.5, 7.6, 7.11 Effective Date: 10/1/2014 Contents TITLE: Supplier Cntracting Guidelines Prcess: FIN_PS_PSG_050 Replaces: Manual Sectins 6.4, 7.1, 7.5, 7.6, 7.11 Cntents 1 Abut university supplier cntracting... 2 2 When is a cntract required?... 2 3 Wh

More information

Multi-Year Accessibility Policy and Plan for NSF Canada and NSF International Strategic Registrations Canada Company, 2014-2021

Multi-Year Accessibility Policy and Plan for NSF Canada and NSF International Strategic Registrations Canada Company, 2014-2021 Multi-Year Accessibility Plicy and Plan fr NSF Canada and NSF Internatinal Strategic Registratins Canada Cmpany, 2014-2021 This 2014-21 accessibility plan utlines the plicies and actins that NSF Canada

More information

Privacy and Security Training Policy (PS.Pol.051)

Privacy and Security Training Policy (PS.Pol.051) Privacy and Security Training Plicy (PS.Pl.051) Purpse T define the plicies and prcedures fr prviding privacy and security training in respect f the CnnectingGTA Slutin. Definitins Electrnic Service Prvider

More information

ATTACHMENT U THIRD PARTY AUDITOR/CONSULTANT QUALIFICATION GUIDELINE

ATTACHMENT U THIRD PARTY AUDITOR/CONSULTANT QUALIFICATION GUIDELINE ATTACHMENT U THIRD PARTY AUDITOR/CONSULTANT QUALIFICATION GUIDELINE 1 INTRODUCTION Third party auditr/cnsultant plays an imprtant rle in decmmissining t ensure that all critical decmmissining activities

More information

Template on written coordination and cooperation arrangements of the supervisory college established for the <XY> Group/<A> Institution

Template on written coordination and cooperation arrangements of the supervisory college established for the <XY> Group/<A> Institution COORDINATION AND COOPERATION ARRANGEMENTS EBA/RTS/2014/16 EBA/ITS/2014/07 Annex II Template n written crdinatin and cperatin arrangements f the supervisry cllege established fr the Grup/ Institutin

More information

TITLE: RECORDS AND INFORMATION MANAGEMENT POLICY

TITLE: RECORDS AND INFORMATION MANAGEMENT POLICY TITLE: RECORDS AND INFORMATION MANAGEMENT POLICY REFERENCE NUMBER: 14/103368 RESPONSIBLE DEPARTMENT: Crprate Services APPLICABLE LEGISLATION: State Recrds Act 1997 Lcal Gvernment Act 1999 Crpratins Act

More information

Purpose Statement. Objectives

Purpose Statement. Objectives Apprved by Academic Affairs Cuncil, June 24, 2014 Faculty Handbk Part VI: Other Plicies and Prcedures Sectin R. Intellectual Prperty Classified Emplyee Handbk Part VI: Other Plicies and Prcedures Sectin

More information

TEB REMUNERATION POLICY

TEB REMUNERATION POLICY TEB REMUNERATION POLICY TEB Human Resurces 2013 1 / 11 Table f Cntents A/ Intrductin... 2 B/ Purpse... 3 C/ Scpe... 3 D/ Preparatin f the Remuneratin Plicy... 3 E/ Gvernance and administratin f the prcess...

More information

FINANCIAL OPTIONS. 2. For non-insured patients, payment is due on the day of service.

FINANCIAL OPTIONS. 2. For non-insured patients, payment is due on the day of service. FINANCIAL OPTIONS 1. Fr thse patients wh carry dental insurance, all c-payments are due n date f service. We will file yur claim as a service t yu, and will d ur very best t maximize yur benefits. We accept

More information

Junior Medical Officer. Supervision Guideline SAMPLE ONLY

Junior Medical Officer. Supervision Guideline SAMPLE ONLY Junir Medical Officer Supervisin Guideline SAMPLE ONLY Versin 1.0 February 2011 The Junir Dctr Supervisin Guideline has been develped by SA IMET t prvide facilities with a plicy guideline. Facilities may

More information

How To Ensure Your Health Care Is Safe

How To Ensure Your Health Care Is Safe Guidelines fr Custdians t assess cmpliance with the Persnal Health Infrmatin Privacy and Access Act (PHIPAA) This dcument is designed t help custdians evaluate readiness fr cmpliance with PHIPAA and t

More information

Bl$wing the Whistle $n the New Whistlebl$wer Pr$tecti$ns Created by the D$dd-Frank Act. By: Michael James L$mbardin$

Bl$wing the Whistle $n the New Whistlebl$wer Pr$tecti$ns Created by the D$dd-Frank Act. By: Michael James L$mbardin$ Oct$ber 22, 2010 Bl$wing the Whistle $n the New Whistlebl$wer Pr$tecti$ns Created by the D$dd-Frank Act By: Michael James L$mbardin$ The "D&dd-Frank Wall Street Ref&rm and C&nsumer Pr&tecti&n Act" (D&dd-Frank)

More information

How To Manage An Infrmatin Security Gvernance Prgram

How To Manage An Infrmatin Security Gvernance Prgram CCISO Ttal Duratin: 10 Days, 80 Hurs Dmain 1: Gvernance Qualifying areas under Dmain 1 include (but are nt limited t) the fllwing: Define, implement, manage and maintain an infrmatin security gvernance

More information

Roles and Responsibilities

Roles and Responsibilities Rles and Respnsibilities 1. Rle f the Bard The Bard, which is elected by the sharehlders, is the ultimate decisin-making bdy f the Cmpany, except with respect t matters reserved t sharehlders. The primary

More information

Johnston Public Schools Special Education Procedural Manual. IEP Overview

Johnston Public Schools Special Education Procedural Manual. IEP Overview Jhnstn Public Schls Special Educatin Prcedural Manual IEP Overview Definitin The Individualized Educatin Prgram (IEP) is a written plan fr the apprpriate educatin f students with disabilities. It is a

More information

JOB DESCRIPTION FORM

JOB DESCRIPTION FORM ADDITIONAL INFORMATION ON THE FOLLOWING POST: BUILT ENVIRONMENT MANAGEMENT CLUSTER OFFICE OF THE DEPUTY CITY MANAGER: BUILT ENVIRONMENT MANAGEMENT CLUSTER EXECUTIVE DIRECTOR: LAND, PROPERTY AND ASSET MANAGEMENT

More information

Waitemata District Health Board, 15 Shea Terrace, Takapuna

Waitemata District Health Board, 15 Shea Terrace, Takapuna Date: Octber 2015 Jb Title: Quality and Audit Manager Department: Planning, Funding and Outcmes Unit Lcatin: Waitemata District Health Bard, 15 Shea Terrace, Takapuna Reprting t: Directr Funding Direct

More information

Version: Modified By: Date: Approved By: Date: 1.0 Michael Hawkins October 29, 2013 Dan Bowden November 2013

Version: Modified By: Date: Approved By: Date: 1.0 Michael Hawkins October 29, 2013 Dan Bowden November 2013 Versin: Mdified By: Date: Apprved By: Date: 1.0 Michael Hawkins Octber 29, 2013 Dan Bwden Nvember 2013 Rule 4-004J Payment Card Industry (PCI) Patch Management (prpsed) 01.1 Purpse The purpse f the Patch

More information

UNIVERSITY OF CALIFORNIA MERCED PERFORMANCE MANAGEMENT GUIDELINES

UNIVERSITY OF CALIFORNIA MERCED PERFORMANCE MANAGEMENT GUIDELINES UNIVERSITY OF CALIFORNIA MERCED PERFORMANCE MANAGEMENT GUIDELINES REFERENCES AND RELATED POLICIES A. UC PPSM 2 -Definitin f Terms B. UC PPSM 12 -Nndiscriminatin in Emplyment C. UC PPSM 14 -Affirmative

More information

IFRS Discussion Group

IFRS Discussion Group IFRS Discussin Grup Reprt n the Public Meeting February 26, 2014 The IFRS Discussin Grup is a discussin frum nly. The Grup s purpse is t assist the Accunting Standards Bard (AcSB) regarding issues arising

More information

PENETRATION TEST OF THE INDIAN HEALTH SERVICE S COMPUTER NETWORK

PENETRATION TEST OF THE INDIAN HEALTH SERVICE S COMPUTER NETWORK Department f Health and Human Services OFFICE OF INSPECTOR GENERAL PENETRATION TEST OF THE INDIAN HEALTH SERVICE S COMPUTER NETWORK Inquiries abut this reprt may be addressed t the Office f Public Affairs

More information

Comment Call (10-20)

Comment Call (10-20) Cmment Call (10-20) T: Frm: All Affiliated Credit Unin CEOs Vernica Madsen Directr f Cmpliance & General Cunsel Date: December 13, 2010 RE: Crprate Credit Unins Summary NCUA is issuing prpsed amendments

More information

Plus500CY Ltd. Statement on Privacy and Cookie Policy

Plus500CY Ltd. Statement on Privacy and Cookie Policy Plus500CY Ltd. Statement n Privacy and Ckie Plicy Statement n Privacy and Ckie Plicy This website is perated by Plus500CY Ltd. ("we, us r ur"). It is ur plicy t respect the cnfidentiality f infrmatin and

More information

REQUEST FOR PROPOSAL SECURITY SERVICES

REQUEST FOR PROPOSAL SECURITY SERVICES REQUEST FOR PROPOSAL SECURITY SERVICES Sectin I INTRODUCTION [Cmpany] is seeking prpsals frm qualified Cntractrs t prvide unifrmed security service fr [Cmpany] facilities at [Lcatin(s)]. This dcument is

More information

E-ALERT Financial Institutions

E-ALERT Financial Institutions E-ALERT Financial Institutins BEIJING BRUSSELS LONDON NEW YORK SAN DIEGO SAN FRANCISCO SILICON VALLEY WASHINGTON www.cv.cm March 19, 2010 SENATE FINANCIAL REFORM LEGISLATION ADDRESSES PROPRIETARY TRADING

More information

FERRIS STATE UNIVERSITY SCHOOL of NURSING CODE of CONDUCT

FERRIS STATE UNIVERSITY SCHOOL of NURSING CODE of CONDUCT 1 FERRIS STATE UNIVERSITY SCHOOL f NURSING CODE f CONDUCT The Schl f Nursing (SON) at Ferris State University uphlds the University Cde f Student Cnduct and the American Nurses Assciatin Cde f Ethics.

More information

0820.02 Workers Disability Compensation Claims Procedures Issued: January 1, 1994 Revised: March 29, 2012

0820.02 Workers Disability Compensation Claims Procedures Issued: January 1, 1994 Revised: March 29, 2012 State f Michigan Administrative Guide t State Gvernment 0820.02 Wrkers Disability Cmpensatin Claims Prcedures Issued: January 1, 1994 Revised: March 29, 2012 SUBJECT: APPLICATION: PURPOSE: CONTACT AGENCY:

More information