Skip to main content

Risk Assessments & Documentation Keys to FFIEC Guidance

With the compliance date for the FFIEC’s Internet Banking Authentication right around the corner, several credit unions have expressed their concerns as to the compliance impact their credit union will face if the guidelines for authentication are not fully implemented by January, 2012.
The core principles of the FFIEC guidance include ongoing risk assessments and strategies, layered security controls, and improved customer awareness of online banking risks. The Supplement stresses that the risk assessment(s) involved in the institution’s efforts to comply with the guidelines is not a one-time project. Instead, it’s ongoing:
“Financial institutions should review and update their existing risk assessments as new information becomes available, prior to implementing new electronic financial services, or at least every twelve months.”
The risk assessment(s) aids in determining which online transactions are higher risk than others. And although the guidance applies to all internet banking, it recognizes the fact that financial institutions will have more robust controls as the risk level of the transaction increases. The guidance uses consumer and business banking as an example. Although both would require security controls, the Guidance recognizes that the risk level differs:
“Since the frequency and dollar amounts of these [consumer] transactions are generally lower than commercial transactions, they pose a comparatively lower level of risk. Financial institutions should implement layered security, as described herein, consistent with the risk for covered consumer transactions."
The Guidance goes on to state:
“Since the frequency and dollar amounts of these [business] transactions are generally higher than consumer transactions, they pose a comparatively increased level of risk to the institution and its customer. Financial institutions should implement layered security, as described herein, utilizing controls consistent with the increased level of risk for covered business transactions. Additionally, the Agencies recommend that institutions offer multifactor authentication to their business customers.”
NCUA Letter to Credit Unions 11-CU-09 states:
“Federally insured credit unions will be expected to adapt appropriate strategies from the supplement to strengthen and enhance controls by January 2012. Beginning in 2012, at credit unions offering electronic services, NCUA examiners will evaluate these controls under the enhanced expectations outlined in the supplement.”
Documentation is Key. As credit unions strive towards following the updated guidance, they should be sure to document their progress to show examiners. Highlight the steps the credit union has taken to implement additional security controls as indicated by the risk assessment. Show examiners your plan for continued risk assessments and new controls. If your vendors will be slowly rolling out security enhancements in 2012, document your communications with these vendors so that examiners know you are working on mitigating these risks.
Risk Assessments & Documentation Keys to FFIEC Guidance:
By JiJi Bahhur, Regulatory Compliance Counsel NAFCU
For additional information on the FFIEC Authentication Guidance, check out our June 29th blog post.

Comments

Popular posts from this blog

Update: First Responder Credit Unions Academy (FRCUA) Udates

In an ongoing effort to keep your FRCUA education current, modules are continually updated to reflect current NCUA and other regulatory agency requirements. As an example, BSA 26 now includes  Artificial Intelligence and BSA,  Elder Financial Exploitation,  Pig Butchering & BSA, and Executive Order –  Free and Fair Banking.

Mortgage Rates Tick Down

MCLEAN, Va.--Mortgage rates moved slightly lower this week, with the 30-year fixed-rate mortgage averaging 6.56%, Freddie Mac reported. “Mortgage rates are at a 10-month low,” said Sam Khater, Freddie Mac’s chief economist. “Purchase demand continues to rise on the back of lower rates and solid economic growth. Though many potential homebuyers still face affordability challenges, consistently lower rates may provide them with the impetus to enter the market.” The 30-year FRM averaged 6.56% as of Aug. 28, down from last week when it averaged 6.58%. A year ago at this time, the 30-year FRM averaged 6.35%. The 15-year FRM averaged 5.69%, unchanged from last week. A year ago at this time, the 15-year FRM averaged 5.51%, Freddie Mac said. ____________________________________________ Check out NCOFCU's additional features: First Responder Credit Union Academy Podcasts YouTube Mini's Blog Job Board

SIGN UP FOR YOUR CUSTOM HEALTH INSURANCE SOLUTION TODAY

 https://bizu65.allstatehealth.com/?password=demo ____________________________________________ Check out NCOFCU's additional features: First Responder Credit Union Academy Podcasts YouTube Mini's Blog Job Board

Many CUs Likely to Face New Operating Challenges "Michael Moebs"

04/08/2024 09:04 pm By Ray Birch LAKE FOREST, Ill.—The trend lines don’t lie: Financial institutions charging high overdraft fees will likely face operating challenges in the near future and may even be forced to merge if they don’t follow the market trend of lowering their OD charge. Michael Moebs, economist and chairman of Moebs $ervices, is offering that forecast following his company’s new overdraft study, which has found overall net OD revenue for 2023 was down 5.7%, with banks dipping by 8.1% to $31.4 billion, thrifts falling by 28.6%. and credit unions actually increasing net revenue 2.2%. The study further reveals the m...

Wendelville Fire Chief Andrew Pilecki re-elected to FASNY board

Andrew Pilecki, the current fire chief of Wendelville Volunteer Fire Company, has been re-elected to the board of directors of the Firefighters Association of the State of New York. Pilecki has been a member of the fire service for more than four decades, including the past 22 years as a responder with the Wendelville company. Previously he was an active member of Columbia Hook and Ladder Co. He’s also a former assistant director of emergency management for the City of North Tonawanda. FASNY directors serve five-year terms of office. During his first term, Pilecki was instrumental in supporting the association’s pandemic response, championed fire company recruitment and retention efforts, and worked to amplify the needs of Western New York’s volunteer fire service at the state level, according to FASNY. “I’m honored to be re-elected and to continue advocating for the men and women who volunteer their time, risk their safety and serve their communities across the state,” Pilecki said. “...