Skip to main content

Risk Assessments & Documentation Keys to FFIEC Guidance

With the compliance date for the FFIEC’s Internet Banking Authentication right around the corner, several credit unions have expressed their concerns as to the compliance impact their credit union will face if the guidelines for authentication are not fully implemented by January, 2012.
The core principles of the FFIEC guidance include ongoing risk assessments and strategies, layered security controls, and improved customer awareness of online banking risks. The Supplement stresses that the risk assessment(s) involved in the institution’s efforts to comply with the guidelines is not a one-time project. Instead, it’s ongoing:
“Financial institutions should review and update their existing risk assessments as new information becomes available, prior to implementing new electronic financial services, or at least every twelve months.”
The risk assessment(s) aids in determining which online transactions are higher risk than others. And although the guidance applies to all internet banking, it recognizes the fact that financial institutions will have more robust controls as the risk level of the transaction increases. The guidance uses consumer and business banking as an example. Although both would require security controls, the Guidance recognizes that the risk level differs:
“Since the frequency and dollar amounts of these [consumer] transactions are generally lower than commercial transactions, they pose a comparatively lower level of risk. Financial institutions should implement layered security, as described herein, consistent with the risk for covered consumer transactions."
The Guidance goes on to state:
“Since the frequency and dollar amounts of these [business] transactions are generally higher than consumer transactions, they pose a comparatively increased level of risk to the institution and its customer. Financial institutions should implement layered security, as described herein, utilizing controls consistent with the increased level of risk for covered business transactions. Additionally, the Agencies recommend that institutions offer multifactor authentication to their business customers.”
NCUA Letter to Credit Unions 11-CU-09 states:
“Federally insured credit unions will be expected to adapt appropriate strategies from the supplement to strengthen and enhance controls by January 2012. Beginning in 2012, at credit unions offering electronic services, NCUA examiners will evaluate these controls under the enhanced expectations outlined in the supplement.”
Documentation is Key. As credit unions strive towards following the updated guidance, they should be sure to document their progress to show examiners. Highlight the steps the credit union has taken to implement additional security controls as indicated by the risk assessment. Show examiners your plan for continued risk assessments and new controls. If your vendors will be slowly rolling out security enhancements in 2012, document your communications with these vendors so that examiners know you are working on mitigating these risks.
Risk Assessments & Documentation Keys to FFIEC Guidance:
By JiJi Bahhur, Regulatory Compliance Counsel NAFCU
For additional information on the FFIEC Authentication Guidance, check out our June 29th blog post.

Comments

Popular posts from this blog

NCOFCU Newsletter

The Bucket Coach is a financial advice book designed by Fire Services Credit Union, Tronto, Canada. and written exclusively for Fire Fighters It's a practical guide for household financial management, including investments, credit and mortgages, and retirement. Developed with contributions from Fire Fighters," NCOFCU Newsletter : " Kevin Connolly Chief Executive Officer    Fire Services Credit Union Phone: 416-440-1294 ext 301  Toll Free: 1-866-833-3285 E-mail:  kevin@firecreditunion.ca 1997 Avenue Rd Toronto, ON M5M 4A3 

Sunday Reading - What is the Dow Jones?

    What is the Dow Jones? Created in 1896, the Dow Jones Industrial Average is one of the world’s oldest and most widely recognized stock indexes—a measure tracking the stock performance of a selected group of companies ( see most recent data ). Originally designed to track America’s leading industrial firms, the Dow has evolved into a cultural and financial shorthand for the health of the US economy. As of 2025, it measures 30 major companies —like McDonald's, Boeing, and Nike—across sectors such as technology, healthcare, finance, and consumer goods.  Unlike most modern indexes, which are weighted by the total value of a company’s shares, the DJIA uses a price-weighted formula —meaning stocks with higher share prices exert more influence, regardless of company size. The DJIA has been updated 59 times since its creation to reflect changes in the US economy ( see ch...

New from AutoLink

New from AutoLink

The Role and Hazards of an Interim Executive

  The Role and Hazards of an Interim Executive Leadership transitions are rarely smooth. A change at the top can trigger uncertainty, speculation, and anxiety. Staff worry about their jobs, members wonder about continuity, and boards feel the weight of stewarding the organization through uncertain change. The utilization of an interim executive director is meant to stabilize the organization and allow the board enough space and capacity to find the right successor leader. Here’s a catch: if an interim executive is also a candidate for the successor role, the very purpose of an interim engagement is compromised. With an Interim, there’s always a second wave of anxiety Every leadership transition comes with some anxiety. The staff sometimes don’t know what’s going on. The board is worried about continuity, and members may be worried about joining. One task of an interim is to absorb some of that anxiety and provide reassurance that things are moving forward. But there is al...

Powell Rejects Any Plan for Fed to Intervene in Secondary Market to Bring Down Rates

  Frank Diekmann October 20, 2025 2:22 am No Comments PHILADELPHIA–Federal Reserve Chair Jerome Powell said there are no plans for the central bank to directly intervene in secondary mortgage markets in an attempt to help bring down mortgage rates, an idea some have proposed as a means of addressing the affordability crisis In housing. Jerome Powell Speaking at the  National Association for Business Economics  conference in Philadelphia, Powell spoke to the Fed’s progress with “quantitative tightening,” that is, its work to reduce the more than $6 trillion of securities it holds on its  balance sheet . Read more about the Balance Sheet HERE Those holdings include approximately $2 trillion in mortgage-backed securities (MBS), which are bundles of home loans that are packaged together and sold to investors, usually by middlemen  Fannie Mae and Freddie Mac , noted Realtor.com. Rolling Off Balance Sheet As the report noted, the Fed dramatically increased M...