Skip to main content

Risk Assessments & Documentation Keys to FFIEC Guidance

With the compliance date for the FFIEC’s Internet Banking Authentication right around the corner, several credit unions have expressed their concerns as to the compliance impact their credit union will face if the guidelines for authentication are not fully implemented by January, 2012.
The core principles of the FFIEC guidance include ongoing risk assessments and strategies, layered security controls, and improved customer awareness of online banking risks. The Supplement stresses that the risk assessment(s) involved in the institution’s efforts to comply with the guidelines is not a one-time project. Instead, it’s ongoing:
“Financial institutions should review and update their existing risk assessments as new information becomes available, prior to implementing new electronic financial services, or at least every twelve months.”
The risk assessment(s) aids in determining which online transactions are higher risk than others. And although the guidance applies to all internet banking, it recognizes the fact that financial institutions will have more robust controls as the risk level of the transaction increases. The guidance uses consumer and business banking as an example. Although both would require security controls, the Guidance recognizes that the risk level differs:
“Since the frequency and dollar amounts of these [consumer] transactions are generally lower than commercial transactions, they pose a comparatively lower level of risk. Financial institutions should implement layered security, as described herein, consistent with the risk for covered consumer transactions."
The Guidance goes on to state:
“Since the frequency and dollar amounts of these [business] transactions are generally higher than consumer transactions, they pose a comparatively increased level of risk to the institution and its customer. Financial institutions should implement layered security, as described herein, utilizing controls consistent with the increased level of risk for covered business transactions. Additionally, the Agencies recommend that institutions offer multifactor authentication to their business customers.”
NCUA Letter to Credit Unions 11-CU-09 states:
“Federally insured credit unions will be expected to adapt appropriate strategies from the supplement to strengthen and enhance controls by January 2012. Beginning in 2012, at credit unions offering electronic services, NCUA examiners will evaluate these controls under the enhanced expectations outlined in the supplement.”
Documentation is Key. As credit unions strive towards following the updated guidance, they should be sure to document their progress to show examiners. Highlight the steps the credit union has taken to implement additional security controls as indicated by the risk assessment. Show examiners your plan for continued risk assessments and new controls. If your vendors will be slowly rolling out security enhancements in 2012, document your communications with these vendors so that examiners know you are working on mitigating these risks.
Risk Assessments & Documentation Keys to FFIEC Guidance:
By JiJi Bahhur, Regulatory Compliance Counsel NAFCU
For additional information on the FFIEC Authentication Guidance, check out our June 29th blog post.

Comments

Popular posts from this blog

Unlocking the Power of Emeritus Board Positions in Credit Unions

  Explore how the Emeritus Board Position in credit unions honors long-serving members, offering them a chance to mentor new leaders while maintaining strategic influence without the responsibilities of active board roles.

Both Sides of The Desk!

With over 50 years of experience in the credit union sector, I have had the privilege of observing and participating in its evolution from various vantage points. My journey has taken me from serving as a dedicated volunteer holding critical leadership roles, including serving on the supervisory committee, as director, and as board chairman, culminating in my tenure as CEO for 12 years and now founder and President/CEO of the National Council of Firefighter Credit Unions . This extensive background has enabled me to " Sit On Both Sides Of The Desk ," blending operational expertise with strategic oversight. In this blog post, I want to share how this dual perspective has enriched my understanding of credit union dynamics and fostered more effective governance. By leveraging the insights gained from years spent navigating both the intricacies of daily operations and the broader strategic objectives, I have witnessed firsthand the transformative power of collaboration, communi...

How To Make Decisions With Conviction—Even Under Pressure

Why strong leaders act when others hesitate — and how to develop that confidence without needing every answer. I’ve watched smart, experienced leaders freeze. And I’ve been in that same position myself. It’s not because we lack information, but because we don’t feel ready to choose. Leaders often get stuck because they’re waiting for the perfect moment to act. They’re thinking through the consequences, weighing the trade-offs, trying to get it right. But the longer they wait, the harder it becomes to move at all. The truth is that the worst decision isn’t always the wrong one. It’s the one you never make. If you’re in a leadership role, you don’t always get the luxury of knowing. You have to move anyway. Not recklessly, not blindly, but with clarity, purpose and conviction. In high-pressure moments, the gap between average leaders and great ones gets exposed. It’s not a gap in intelligence or experience. It’s a gap in decisiveness. Because conviction doesn’t mean certainty—it means mak...

Live - Podcast Understanding The Importance P&L Statements

A Weekly Dose of Innovation for Credit Unions Serving First Responders Welcome to the NCOFCU Podcast: Your Weekly Dose of Innovation. Hosted by Grant Sheehan CCUE | CCUP | CEO, NCOFCU, this podcast is your definitive source for the latest news, insights, and trends in the first responder credit union world.

Fed Kicks Off Two-Days of Meetings Today as Critics, Proponents Respond to Rate Increases; Plus, What CUs Should Expect

CUToday WASHINGTON–The Federal Reserve’s Open Market Committee (FOMC) will kick off two days of meetings today and the decision they announce tomorrow will affect everything from the major U.S. markets to credit unions that are seeing strong loan growth to individual credit union members struggling with monthly bills. The FOMC is widely expected to again raise its benchmark rate as it seeks to cool raging inflation. Among those expecting rates to be higher by Wednesday afternoon is CUNA’s chief economist, Mike Schenk, who expects the Fed will push up rates by 75 basis points. That follows the full one percentage point increase made during the Fed’s July meeting. “That’s pretty substantial, but inflation is over 9%,” said Schenk...