“When embarking on a journey, never ask directions from someone who has never been there!” www.sheehansconsulting.com
Friday, December 30, 2011
Mortgages: Mortgages — How to Get a Rock-Bottom Rate
Thursday, December 29, 2011
15 Ratios Every Board Member Should Know
'via Blog this'
Firefighter's Credit Union Newsroom
'via Blog this'
Wednesday, December 28, 2011
Risk Assessments & Documentation Keys to FFIEC Guidance
With the compliance date for the FFIEC’s Internet Banking Authentication right around the corner, several credit unions have expressed their concerns as to the compliance impact their credit union will face if the guidelines for authentication are not fully implemented by January, 2012.
The core principles of the FFIEC guidance include ongoing risk assessments and strategies, layered security controls, and improved customer awareness of online banking risks. The Supplement stresses that the risk assessment(s) involved in the institution’s efforts to comply with the guidelines is not a one-time project. Instead, it’s ongoing:
“Financial institutions should review and update their existing risk assessments as new information becomes available, prior to implementing new electronic financial services, or at least every twelve months.”
The risk assessment(s) aids in determining which online transactions are higher risk than others. And although the guidance applies to all internet banking, it recognizes the fact that financial institutions will have more robust controls as the risk level of the transaction increases. The guidance uses consumer and business banking as an example. Although both would require security controls, the Guidance recognizes that the risk level differs:
“Since the frequency and dollar amounts of these [consumer] transactions are generally lower than commercial transactions, they pose a comparatively lower level of risk. Financial institutions should implement layered security, as described herein, consistent with the risk for covered consumer transactions."
The Guidance goes on to state:
“Since the frequency and dollar amounts of these [business] transactions are generally higher than consumer transactions, they pose a comparatively increased level of risk to the institution and its customer. Financial institutions should implement layered security, as described herein, utilizing controls consistent with the increased level of risk for covered business transactions. Additionally, the Agencies recommend that institutions offer multifactor authentication to their business customers.”
NCUA Letter to Credit Unions 11-CU-09 states:
Risk Assessments & Documentation Keys to FFIEC Guidance:
By JiJi Bahhur, Regulatory Compliance Counsel NAFCU
“Federally insured credit unions will be expected to adapt appropriate strategies from the supplement to strengthen and enhance controls by January 2012. Beginning in 2012, at credit unions offering electronic services, NCUA examiners will evaluate these controls under the enhanced expectations outlined in the supplement.”
Documentation is Key. As credit unions strive towards following the updated guidance, they should be sure to document their progress to show examiners. Highlight the steps the credit union has taken to implement additional security controls as indicated by the risk assessment. Show examiners your plan for continued risk assessments and new controls. If your vendors will be slowly rolling out security enhancements in 2012, document your communications with these vendors so that examiners know you are working on mitigating these risks.
For additional information on the FFIEC Authentication Guidance, check out our June 29th blog post.
The U.S. Central “Wind Down” - Why It Happened, What It Means
'via Blog this'
EXPLOSIVE DEVICE AT EMS CALL - ALWAYS BE AWARE
'via Blog this'
Florida credit unions boom in 2011 - South Florida Sun-Sentinel.com
'via Blog this'
Tuesday, December 27, 2011
Shared Branching: The Epitome of the Credit Union Philosophy
See all stories on this topic »
S&P/Case-Shiller shows home prices down again in October
According to the latest S&P report, home prices declined 1.1% and 1.2% for the 10- and 20-city composite indexes.
"There was weakness in the monthly statistics, as 19 [...]
FinCEN Extends Deadline for New CTR and SAR Forms
But wait…we’re not out of the woods just yet. Remember that proposal FinCEN issued to mandate electronic CTR and SAR filing? That’s still on the table and the proposed deadline remains June 30, 2012. We blogged about this proposal on September 19th.
Although there will be a short reprieve from mandatory use of the new reports, don’t expect the same for e-filing. Here’s what FinCEN had to say about e-filing in this latest announcement: