VENDOR MANAGEMENT Presented By:



Similar documents
Outsourced Third Party Relationship Management/ Vendor Management. TTS Webinar July 15, 2015 Susan Orr CISA, CISM, CRISC, CRP

So#ware quality assurance - introduc4on. Dr Ana Magazinius

9/13/ /20 Vision for Vendor Management & Oversight. Disclaimer. Bank Service Company Act - FIL-49-99

Vendor Management: An Enterprise-wide Focus. Susan Orr, CISA CISM CRISC CRP Susan Orr Consulting, Ltd.

Vendor Management Compliance Top 10 Things Regulators Expect

Let s Get Nerdy: Inside Tips on Florida s Workers Compensa:on with a Dose of PEOs. Meet Your Presenter. Going Beyond the Basics.

Vendor Management Compliance Top 10 Things Regulators Expect

Payments Cards and Mobile Consul3ng Overview 2013

Legacy Archiving How many lights do you leave on? September 14 th, 2015

Developing Your Roadmap The Association of Independent Colleges and Universities of Massachusetts. October 3, 2013

Panorama Consulting Group. PERFECT Fit ERP Selection Framework

Performance Management. Ch. 9 The Performance Measurement. Mechanism. Chiara Demar8ni UNIVERSITY OF PAVIA. mariachiara.demar8ni@unipv.

Outsourcing Technology Services A Management Decision

Founda'onal IT Governance A Founda'onal Framework for Governing Enterprise IT Adapted from the ISACA COBIT 5 Framework

Protec'ng Informa'on Assets - Week 8 - Business Continuity and Disaster Recovery Planning. MIS 5206 Protec/ng Informa/on Assets Greg Senko

The Emergence of the ISO in Community Banking Patrick H. Whelan CISA IT Security & Compliance Consultant

Data Governance Framework: Bank of Canada

About the Board. Minnesota Board of Behavioral Health and Therapy 10/24/12. Minnesota Board of Behavioral Health and Therapy

IT Change Management Process Training

Introduc)on to the IoT- A methodology

Innovation Quality Flexibility

Phone Systems Buyer s Guide

Overview of Informa.on Technology Procurement.

Interna'onal Standards Ac'vi'es on Cloud Security EVA KUIPER, CISA CISSP HP ENTERPRISE SECURITY SERVICES

Business Continuity Planning Principles and Best Practices Tom Hinkel and Zach Duke

Information and Communications Technology Supply Chain Risk Management (ICT SCRM) AND NIST Cybersecurity Framework

Vendor Management Best Practices

Managing Student Impairment in Counselor Education Programs. Dr. Wendy Greenidge Dr. Belinda Lopez Dr. Michelle Mitcham

Identifying Key Risk Indicator

WSECU Cyber Security Journey. David Luchtel VP IT Infrastructure & Opera:ons

Online Enrollment Op>ons - Sales Training Benefi+ocus.com, Inc. All rights reserved. Confiden>al and Proprietary 1

Capitalize on your carbon management solu4on investment

VENDOR RISK MANAGEMENT UPDATE- ARE YOU AT RISK? Larry L. Llirán, CISA, CISM December 10, 2015 ISACA Puerto Rico Symposium

SECURITY AND EXTERNAL SERVICE PROVIDERS

Effec%ve AX 2012 Upgrade Project Planning and Microso< Sure Step. Arbela Technologies

Supplier Relationship Management. ISM Philadelphia, Inc. September 12, 2013

Splunk for Networking and SDN

How To Perform a SaaS Applica7on Inventory in. 5Simple Steps. A Guide for Informa7on Security Professionals. Share this ebook

Architec;ng Splunk for High Availability and Disaster Recovery

Introduction to Vendor Management

Understanding the Fundamentals of Credit Union Third-Party Vendor Due Diligence

FULLY INTEGRATED GOVERNANCE, RISK MANAGEMENT, COMPLIANCE AND AUDIT SOFTWARE

Interac(ve Broker (UK) Limited Webinar: Proprietary Trading Groups

Pharma CloudAdoption. and Qualification Trends

Don Stewart, MBCP, MBCI, CCP

CiviCRM Implementa/on Case Study

Vendor Compliance Management Series: Performing an Effective Risk Assessment

Privileged Administra0on Best Prac0ces :: September 1, 2015

Help Framework. Ticket Management Ticket Resolu/on Communica/ons. Ticket Assignment Follow up Customer - communica/on System updates Delay management

Service Organizations and the Internal Audit function conference Institute of Internal Auditors in Israel

Identity and Access Positioning of Paradgimo

Connec(ng to the NC Educa(on Cloud

Update on the Financial Condi0on of Hofstra University March, 2013

Project Por)olio Management

Information Technology

elearning: present and future

8 Techniques to Improve Your Bank s Vendor Management Program. IBAT TechMecca

Office of Inspector General

MAXIMIZING THE SUCCESS OF YOUR E-PROCUREMENT TECHNOLOGY INVESTMENT. How to Drive Adop.on, Efficiency, and ROI for the Long Term

Cloud Security & Risk. Adam Cravedi, CISA Senior IT Auditor acravedi@compassitc.com

DTCC Data Quality Survey Industry Report

Vendor Risk Management Financial Organizations

Transcription:

VENDOR MANAGEMENT EXAMINER EXPECTATIONS FOR ASSESSING & MANAGING 3RD PARTY RISK Presented By: Tom Hinkel, VP of Compliance Services Safe Systems, Inc.

Agenda Blurred Lines: Defini/on of vendor Recent regulatory expecta/ons for vendor management Due diligence (pre- contract) Contracts 6 vendor management steps to take NOW

Tradi/onal defini/on: Vendor vs. Service Provider Vendor anyone with whom you have a contractual rela/onship Service Provider Vendor that provides a bank- related service (BSCA). check and deposit sor/ng and pos/ng, computa/on and pos/ng of interest and other credits and charges, prepara/on and mailing of checks, statements, no/ces, and similar items, or any other clerical, bookkeeping, accoun/ng, sta/s/cal, or similar func/ons performed for a depository ins/tu/on.

Current defini/on: Vendor vs. Service Provider Term "service providers" is broadly defined to include all en//es* that have entered into a contractual rela/onship with a financial ins/tu/on to provide business func/ons or ac/vi/es. Federal Reserve * En//es may be a bank or nonbank, affiliated or non- affiliated, regulated or non- regulated, or domes/c or foreign. A third- party rela/onship is any business arrangement between a bank and another en/ty, by contract or otherwise.* - OCC * Third- party rela/onships include ac/vi/es that involve outsourced products and services, use of independent consultants Third- party rela/onships generally do not include customer rela/onships.

FFIEC Financial ins/tu/ons increasingly rely on service providers, soxware vendors, and other third par/es. Financial ins/tu/ons are responsible for risks associated with the ac/vi/es of third- party service providers with which they contract. An effec/ve outsourcing oversight program should provide the framework for management to understand, monitor, measure, and control the risks associated with outsourcing.

Vendor Management What s New? Increased vendor selec/on & pre- contract due diligence Strategic goals (decision to outsource) Concentra/on risk Cri/cality of service (highly cri/cal vendors may need to be assigned to a senior officer for oversight - OCC) Vendor use of sub- contractors BCP review (opera/onal risk) Expanded Risk Assessments (not just NPI) Cri/cality Complexity Reputa/onal risk

Vendor Management What s New? (cont.) Increased on- going oversight Contracts Third- party report (audits) - SAS- 70 vs. SOC 1, 2, 3 Regulatory examina/on reports BOD repor/ng Assess ALL vendors

Due Diligence 1. During the product selec/on process, prior to contrac/ng for the product or service Reputa/on, strategic fit, etc. 2. AXer the vendor has been selected, and prior to implementa/on RFP s vs. contracts 3. Post implementa/on, and ongoing as long as the rela/onship exists Tradi/onal vendor management program

Due Diligence Pre- Contract Product / Service is in alignment with strategic plan? Outsourcing is best op/on? RFP/RFI U/lized? Product / Service Cloud Based? Vendor Business Con/nuity RTO's Reviewed?

Due Diligence Checklist

Due Diligence Checklist

Due Diligence Checklist

Controls Controls Trust but Verify Financial Statements Contracts & Service Level Agreements (SLA s) Incident Response Plans (include actual incidents) DR/BCP Plans (RTO s aligned?) Regulatory Examina/on Reports Third- party audit reviews (SAS 70 phased out)

Controls According to the FFIEC Handbook on Outsourcing Technology Services The is the single most important control in the outsourcing process. A. Ini/al due diligence process B. Review of third- party audit reports C. Contract D. Risk Assessment E. Vendor s financial stability

Controls The contract is the legally binding document that defines all aspects of the servicing rela/onship. A wrijen contract should be present in all servicing rela/onships. This includes instances where the service provider is affiliated with the ins/tu/on. The contract is the single most important control in the outsourcing process.

Contracts

Contracts

Contracts

Contracts

Regulatory Examination Reports The Agencies conduct IT- related examina/ons of financial ins/tu/ons and their TSPs based on the guidelines contained in the IT Handbooks. Uses URSIT (Uniform Ra/ng System for Informa/on Technology) ra/ngs Each TSP examined for IT is assigned a summary or composite ra/ng based on the overall results of the evalua/on.

Regulatory Examination Reports The financial ins/tu/on must inquire from their primary federal regulator (PFR) whether or not they have completed an examina/on of the vendor (or TSP). If the PFR indicates they have, the ins/tu/on may request a summary of the exam (called a Report of Examina/on, or ROE), which will not contain the actual score. Instead the ROE contains an Open Sec/on, which contains all significant examina/on findings and conclusions. The excep/on to this is if the TSP scores a 4 or lower (i.e. 4 or 5), in which case the regulator will proac/vely provide a summary of the exam to each ins/tu/on serviced by the TSP.

Next Steps? 6 Changes to Make to your Vendor Management Program Now ü Remove references to SAS 70, replace with Third- party Review ü Rank Vendors Use Tiered Approach (H, M, L, or Tier I, Tier II, Tier III) ü Add Vendor Management responsibili/es to IT Steering Commijee (or equivalent). High risk vendors may require senior management sponsor. ü Manage contract expira/on dates and auto- renewal clauses ü Review SOC reports ü Request examina/on reports

Questions? Tom Hinkel CISA, CRISC, CCSA, CRMA VP of Compliance Services Safe Systems, Inc. tom@safesystems.com www.complianceguru.com The Compliance and Technology Partner for Financial Ins8tu8ons