October 22, 2012 2:09 PM
Posted by: David Schneier
ACH,
assess,
assessment,
assessments,
Audit,
auditor,
audits,
banking,
banks,
business,
CISA,
CISO,
community bank,
compliance,
credit unions,
CU,
exam,
examination,
examinations,
examiner,
examiners,
exams,
FFIEC,
financial institutions,
general controls,
GLBA,
identify theft,
identity theft,
information security,
information security office,
Information Technology General Controls,
internal audit,
internal controls,
ITGC,
NPPI,
observations,
oversight,
personally identifiable informaiton,
PII,
privacy,
risk assess,
risk assessment,
risk assessments,
risk management,
risk-based,
risksA few years back when I first cut over to working somewhat exclusively with financial institutions I memorized an elevator speech that still somewhat defines who I am and what I do professionally. Part of the speech pointed out that my firm helped "banks and credit unions meet regulatory...
August 8, 2012 6:21 PM
Posted by: David Schneier
Audit,
auditor,
audits,
bank,
banking,
banks,
Board,
Board of Directors,
BoD,
business,
community bank,
compliance,
control,
controls,
exam,
examination,
examinations,
examiner,
examiners,
exams,
financial institutions,
fraud,
governance,
regulation,
regulations,
regulations audit,
regulatory,
regulatory guidance,
SOXI have an odd relationship with management reporting. I know it's a necessity and quite often see clear value in what's packaged for senior management and board review. But a significant piece of the reporting content comes in the form of metrics and, well, whenever I hear the term it conjures...
February 3, 2012 5:58 PM
Posted by: David Schneier
Audit,
auditor,
compliance,
controls,
exam,
examiner,
FFICE,
GLBA,
governance,
GRC,
internal controls,
NCUA,
regulations,
regulatory,
Regulatory Compliance,
riskI was sitting in a meeting this week listening to a group of very bright people talking about an initiative centered on installing a software solution and I realized something rather disturbing; somewhere along the way in our industry governance, risk and compliance has started melting together and...
August 28, 2011 3:17 PM
Posted by: David Schneier
Audit,
auditor,
bcp,
business continuity,
business continuity plan,
compliance,
disaster,
disaster recovery,
DR,
exam,
examiner,
GLBA,
NCUA,
regulations,
regulatory,
Regulatory ComplianceI'm violating my own standards by using such an easy topic to blog about but it's too big to ignore. With the increasing insanity being inspired by 2011's first true hurricane I'd be remiss if I didn't at least explore the impact this is going to have on the business community.
I just heard...