March 15, 2011 9:58 PM
Posted by: David Schneier
Audit,
bank,
banking,
compliance,
credit union,
CU,
exam,
examiner,
FDIC,
GLBA,
NCUA,
OCC,
oversight,
regulations,
regulatory,
Regulatory ComplianceI was catching up on my industry emails the other day and buried in my FDIC email folder was Financial Institution Letter FIL-13-2011, sent out on March 1st. Truthfully I usually pay close attention to their Friday afternoon blasts regarding bank closings and only skim the rest. But this one...
March 8, 2011 4:58 PM
Posted by: David Schneier
assessment,
Audit,
bank,
banking,
compliance,
credit union,
CU,
exam,
examination,
examiner,
exams,
governance,
GRC,
regulation,
regulatory,
Regulatory Compliance,
risk,
risk assessmentWe were having an internal conversation this past week about governance, risk, and compliance (GRC) and I was asked about its role in the small and...
January 8, 2011 5:41 PM
Posted by: David Schneier
Audit,
bcp,
BIA,
business continuity plan,
business impact analysis,
exam,
examiners,
FFIEC,
GLBA,
regulatory,
Regulatory Compliance,
risk,
risk assessmentOne of the first things I had to work on this week (and thus one of the first things to work on in the new year) was finalizing a report from last year. The report covered the results of a Business Continuity Plan desktop test and the client needed some clarifications around the results.
I've...
September 20, 2010 8:28 PM
Posted by: David Schneier
Audit,
compliance,
exam,
examination,
GLBA,
HIPAA,
NCUA,
NERC,
PCI,
regulatory,
Regulatory Compliance,
risk,
risk assessment,
SOXI stumbled upon an old nemesis of mine recently and the bad taste it left in my mouth continues to offend my senses.
In an industry where there are standards that define how standards should be written and websites dedicated to dissecting each standard so that everyone can understand what the...
April 16, 2010 4:56 PM
Posted by: David Schneier
Audit,
bcp,
business continuity planning,
compliance,
exam,
examiner,
FDIC,
NCUA,
Regulatory Compliance,
vendor,
Vendor ManagementIf I haven't already shared this with you, I'm a partner in a regulatory compliance advisory firm. We offer services to the banking sector that pretty much cover the entirety of the information security spectrum. And as you might imagine, there's a fair amount of sales and marketing that go...