« Turnkey ID Theft Education and Problem | Main | AOL’s $299 PC »

Managing Technology Vendor Compliance

By Jim Bruene on December 8, 2003 2:00 PM | Comments (0)

by Brad Putnam, CEO, Digital Compliance


 

The main screen of an automated compliance- management system powered by Digital Compliance.


When a federal regulator passes through your financial institution during an exam, expect to be asked for your technology-service provider due diligence and vendor risk-management documentation. Due to the dotcom meltdown, the horrific events of 9/11, and more recently the widespread power blackout on the East Coast, federal regulators are demanding far more due diligence on third-party technology vendors. Regulators expect your technology service providers to be financially sound and to have the appropriate security, privacy, and disaster-recovery policies and testing procedures in place.

There is a common misperception that you are not responsible for the safety and soundness of a technology-service provider as long as it is being examined by a Federal Regulating Agency. This is not true. Your senior management is still accountable for overseeing vendor risks such as:

  • ·      Financial stability
  • ·      Compliance with Gramm-Leach-Bliley (GLB)
  • ·      Adequate and tested disaster recovery plans

Each outsourced solution must be carefully investigated and documented prior to implementation. And each year, the due diligence must be reviewed and updated as necessary. These requirements can literally cost your financial institution weeks of time and thousands of dollars. In fact, according to a recent Gartner report, technology spending for risk management will account for 9% of the average financial services IT budget.

One way to reduce the cost of managing technology compliance is to create an automated system that methodically tracks the process, stores records, and generally keeps things from falling through the cracks. Many banks have created compliance systems that are managed by full or part-time staff.

Another option is to use an outside expert to manage the paperwork and project-management burden. My company, Digital Compliance http://www.digitalcomply.com/  
has developed a solution that reduces the burden of managing technology vendors such as:

  • ·      Core processors
  • ·      ATM processors
  • ·      Internet banking, bill payment, and cash-management providers
  • ·      Credit card processors
  • ·      Check printers with online ordering
  • ·      Web-hosting providers
  • ·      Internet-brokerage providers
  • ·      Mortgage processors
  • ·      Aggregation providers


 

A listing of all available due diligence documents for a particular service provider. Documents can be opened online, printed, and saved to disk.

Our system provides point-and-click access to complete up-to-date due diligence documentation for each of your technology vendors in one secure, easy-to-use online service (see screenshot above).

Each vendor’s documentation is maintained and kept current by our staff. You are kept entirely in the loop by an automated communication system. For example, an email alert is sent every time a vendor’s documents are updated or added, so there will be no unpleasant surprises hours before the examiner arrives.

Finally, is it affordable? The great thing about centralizing the documentation and storage process is that all participants can share costs, dramatically reducing total expenditures. Since the service providers pick up much of the cost of organizing and updating the documentation, individual banks pay a nominal fee, typically less than $1000 annually. Not a bad investment considering the consequences of inadequate documentation.          

Brad Putnman is Founder & CEO, Digital Compliance LLC, a privately held company based in Billings Montana; (406) 325-9737, bputnam@digitalcomply.com , or visit  http://www.digitalcomply.com/    

Additional vendor-management resources:

www.ffiec.gov/ffiecinfobase/html_pages/it_01.html

www.bis.org/publ/bcbs98.htm

www.bitsinfo.org/wp.html

Comments (0)

Most Recent Posts:

TrackBack

TrackBack URL for this entry:
http://www.netbanker.com/cgi-bin/mt/mt-t.cgi/1659

Leave a comment

Sponsors

BackBase IntelliResponse Yodlee FinovateEurope 2012

Events

  • FinovateEurope 2012 -- On February 7th, 2012, the second annual FinovateEurope will feature dozens of Europe's newest fintech innovations via a fast-paced demo-only format in the financial capital of London. 7 minutes each on stage. No slides allowed. Come watch the future of fintech in Europe unfold live! Get your ticket today and lock in your spot before it is too late!
  • FinovateSpring 2012 -- On May 8th & 9th, 2012, Finovate will return to San Francisco for our 5th annual west coast showcase of the newest fintech innovations from Silicon Valley and beyond. Each company gets 7 minutes to demo live. No slides allowed. Come watch the future of fintech debut! Get your ticket today and save big!

Research

  • NEW! Online & Mobile Banking Forecast: Current, future and historical usage: 1994 to 2021 - Find out more
  • NEW! Selling Insurance Online (Banking Edition): Can insurance help fill the fee-income gap? - Find out more
  • NEW! True Virtual Banking Has Arrived: BankSimple, Personal Capital, Betterment and others go branchless, paperless and “bank-less” - Find out more
  • 2012 Guide to Online & Mobile Banking Products, Pricing & Strategy: Preparing for a mobile-first world - Find out more
  • Family Banking: Tweens, Teens & their Parents: In a remote banking world, your most-promising prospects aren’t even driving yet! - Find out more

 

   

RSS Subscribe via RSS
RSS Subscribe to Comments



Email:


@NetBanker Twitter Feed



See all @NetBanker tweets