Regulatory Reality:

regulatory


February 3, 2012  5:58 PM

Governance, risk and compliance – related but not the same.



Posted by: David Schneier
Audit, auditor, compliance, controls, exam, examiner, FFICE, GLBA, governance, GRC, internal controls, NCUA, regulations, regulatory, Regulatory Compliance, risk

I was sitting in a meeting this week listening to a group of very bright people talking about an initiative centered on installing a software solution and I realized something rather disturbing; somewhere along the way in our industry governance, risk and compliance has started melting together and...

January 8, 2012  9:27 PM

Maintaining compliance is often the Missing Link.



Posted by: David Schneier
assess, assessment, Audit, compliance, exam, examination, examiner, FDIC, GLBA, NCUA, regulations, regulatory, Regulatory Compliance, risk, risk assess, risk assessment

I've been in the solutions selling business on and off for about a decade but exclusively so over these past four years.  Up until becoming a partner in my current practice I pretty much was always only involved in helping sell the solution and usually implementing it before moving on.  Seldom...


December 22, 2011  9:44 PM

Why I don’t trust hosted or SaaS solutions.



Posted by: David Schneier
assessment, Audit, compliance, GLBA, NPPI, PCI, PII, regulatory, Regulatory Compliance, risk, risk assessment

Let me begin by sharing a story from the way back files.   In the mid 80’s when I was first starting out in my career I was working as a junior programmer in Manhattan.  Courtesy of playing on the corporate softball team I became acquainted with a fairly diverse group of...


December 5, 2011  11:54 PM

The trouble with GRC.



Posted by: David Schneier
assessments, Audit, compliance, governance, GRC, regulations, regulatory, Regulatory Compliance, regulatory guidance, risk, risk assessments

I love GRC, at least the concept.  I've gotten way more than my fair share of print time expounding on its many virtues and how it continues to make inroads into so many organizations.  It's the next and necessary step in the evolution of audit and compliance, a fact (yes, fact) of which I'm...


November 18, 2011  12:22 PM

Why vendor management is a big GLBA deal.



Posted by: David Schneier
assessment, Audit, compliance, FDIC, Federal Reserve Bank, FRB, GLBA, NCUA, OCC, OTC, regulations, regulatory, Regulatory Compliance, risk, risk assessment, vendor, Vendor Management, vendor risk, vendor risk rating

I don't think I'm due to post about vendor management again at least until January 2012 (I try to limit topics to twice a year) but I've had something kicking around my head for a few days now and it needs a proper vetting. Does anyone know why vendor management is such a big issue for banking...


November 11, 2011  7:41 PM

Vishing, Smishing and Phishing: No end in sight.



Posted by: David Schneier
assessment, Audit, compliance, GLBA, hack, hacker, NCUA, phish, phishing, red flags, red flags identity theft, regulatory, Regulatory Compliance, scam, smish, smishing, vish, vishing

This is something akin to my annual public service announcement (PSA) for anyone who has cash-on-hand, a bank account, an investment account or perhaps even a piggy bank:  As long as you have money there's someone out there right now scheming to try and take it away from you. I'm having that...


October 26, 2011  8:36 PM

Who examines the examiners?



Posted by: David Schneier
assessment, bcp, business continuity plan, GLBA, NCUA, NCUA Part 748, regulations audit, regulatory, Regulatory Compliance, risk, risk assessment, Vendor Management

I remember conducting a risk assessment a few years back for a credit union in which they were missing just about every artifact necessary to prove compliance with NCUA Part 748 (if you're not already aware, thats GLBA for credit unions).  It was, for lack of a better term, a...


October 13, 2011  10:42 PM

Does everyone value their privacy or is it just me?



Posted by: David Schneier
compliance, Facebook, identify theft, LinkedIn, NPPI, PCI, PII, privacy, regulatory, Regulatory Compliance, Security

I just came to find out that I’m old.  It was somewhat sudden and sort of unexpected as I’m not quite half way to one hundred and have fooled myself into thinking that old doesn’t roll in until somewhere beyond sixty.  But apparently one persons middle-aged...


October 3, 2011  10:39 PM

Dodd-Frank Section 165(d) : Is this really what was needed?



Posted by: David Schneier
bcp, business continuity, business continuity plan, compliance, Dodd-Frank, FDIC, GLBA, NCUA, regulations, regulatory, Regulatory Compliance, too big too fail

Ever since Dodd-Frank legislation first started rolling down the turnpike towards the banking industry I've been reading and listening to all manner of rhetoric about how none of it's going to solve any problems, that it's going to impede the business of banking and force money to be deposited and...


September 14, 2011  6:27 AM

A new twist on regulatory guidance.



Posted by: David Schneier
assessment, Audit, bcp, business, business continuity, business continuity planning, compliance, disaster recovery, DR, GLBA, NCUA, regulation, regulatory, Regulatory Compliance, risk, risk assessment, vendor, Vendor Management

One of the oddity's of my career is how some issues present themselves in a wide range of my clients despite the fact that there's often no meaningful way to compare them in size.  Some have a single compliance person who is part Compliance Officer and part Information Security Officer and some...


Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to: