Home > Financial Services Information Security Tips > Compliance and Governance Digest > FDIC guidance for managing third party risk
Financial Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE AND GOVERNANCE DIGEST

FDIC guidance for managing third party risk


Michael Rasmussen, Contributor
08.19.2008
Rating: -4.67- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


More on third party management
Outsourcing compliance strategies

Protecting third party processes on all levels
Financial service organizations have aggressively pursued and capitalized on the economies that third party relationships bring to enhance and streamline business and IT operations. Defining an organization's boundaries has become difficult as the extended enterprise of business relationships has built an intricate web that blurs organizational borders. In the past, third party relationships were entered into without much thought of the risk they bring to the business environment.

Regulators have been evaluating third party relationships within financial services organizations for several years; however, organizations lacked clear guidance on how to appease regulators. That changed this past June when the Federal Deposit Insurance Corporation (FDIC) released guidance for managing third party risk.

The FDIC has been active in reviewing financial service organizations risk management practices, along with third party risk, as part of their ongoing normal examination process. Their examination and focus on third party risk includes identifying how the organization assesses, measures, monitors, and controls risk in these extended enterprise relationship.

The common practice of assuring that an indemnity agreement is in place is clearly not enough. An indemnity agreement does not and cannot adequately cover an organizations strategic, operation, and reputation risks. Further, compliance risk is something that cannot be covered in an indemnity agreement. If a financial organization is out of compliance as the result of activities of a third party it is the financial service organization that is held accountable.

Responsibility for risk management is a top-down effort. The FDIC clearly states that responsibility falls on the shoulders of the executive management and board of directors.

The current guidance from the FDIC requires that financial organizations have a four-fold process in managing risks in third party relationships:

Risk assessment: The financial organization is to have a defined approach and process for identifying risks in new and existing third party relationships.

Due diligence in selecting third party relationships: After identifying risk, the organization has to demonstrate that they have a due diligence process in place to select the right third party relationship that minimizes their exposure to risk.

Contract structuring and review: Further, financial organizations are to have a thorough contracting process in place to protect the organization from risk and ensure that the proper controls are in place in the relationship to manage risk and comply with regulations.

Oversight: Finally, the organization is to have board oversight of risk in third party relationships, as well as ongoing assurance by management that risk, controls, and compliance to contractual requirements is in place within these relationships.

Best practices for success
To meet these four requirements, here are some leading practices in financial services firms:

Adoption of a risk assessment methodology: The foundation for any risk management process is a sound risk assessment methodology that outlines the risk identification, assessment, measurement, and monitoring process. Some have turned to the COSO Enterprise Risk Management Framework (.PDF), but many find the approach to be confusing and difficult to apply. The Australia/New Zealand Risk Management Guideline 4360:2004 (.PDF) provides a very flexible risk framework that can be applied to a range of risk management areas -- it is also the basis for a new international ISO standard, ISO 31000, which will be released in draft form to the public in early 2009.

Application of a standard for measuring risk in third party relationships: Not all third party relationships have the same risk profile and impact on a financial organization operation. This requires that some process be in place for the financial service organization to measure the level of risk in proposed, new, and existing third party relationships.

Implement a software platform to manage risk: Managing risk across a web of business relationships is difficult and it is impossible without the use of technology. Leading organizations, within financial services and in other industry verticals, are adopting platforms to manage risk and compliance across their business relationships. Implementation of these platforms include the ability to communicate contracts, policies, procedures and controls; train third party personnel on requirements and expectations; provide a platform for third parties to conduct a self-assessment of their compliance to contracts; and, supply auditors the information they need to independently assess third party relationships. As business partner relationships exist in great numbers and diversity, one option is to implement Software as a Service (SaaS) platforms to manage risk and compliance in the extended enterprise.

Consider the BITS shared assessment program: Finally, financial service organizations should carefully evaluate the ability of BITS/Financial Services Roundtable shared assessment program to ease the burden of contractual and regulatory compliance audits on third party relationships.

About the author:
Michael Rasmussen (mrasmussen@corp-integrity.com) is with Corporate Integrity, LLC. Michael is the authority in understanding governance, risk and compliance (GRC). He is a sought-after keynote speaker, author and collaborator on GRC issues around the world and is noted for being the first analyst to define and model the GRC market for technology and professional services. Corporate Integrity, LLC is a strategy & research advisory firm providing education, research and analysis on enterprise governance, risk management and compliance.


Rate this Tip
To rate tips, you must be a member of SearchFinancialSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Compliance and Governance Digest
PCI 1.2: Seven key changes for financial organizations
PCI DSS 3.1 best practices
How to make information security a company-wide effort
Using an information security council
Information security governance using a risk-based approach
How I learned to stop worrying and love my compliance department
Investigation management tools ease fraud pains
Integrating ethics from top to bottom
Rogue activity thwarted by early warning systems
Red Flags rule: Unclear guidance biggest challenge

Auditing, testing and assessment for financial services compliance
Financial firms fight cyberthreats, brace for difficult year
Proper preparation necessary for successful penetration test
Establishing a practical routine for reviewing security logs
Outsourcing compliance strategies
SIM appliance helps credit unions with compliance, incident response
Protecting third party processes on all levels
Outlining governance frameworks
GRC software alleviates audit process for financial firms
Passing a SOX audit: Lessons learned from an information security professional
Reporter's Notebook: Why failing an audit can lead to success

Business partner and vendor security issues
Identity federation standards ease authentication pains
Protecting partner processes
Financial Information Security Decisions 2008: Presentation downloads
State Street breach highlights encryption limits, vendor due diligence
Missing backup tape prompts identity theft fears for JC Penney customers
Downstream liability makes the case for security spending
Hesitant customers want more out of network access control products
The security risks of extending access to outside software providers
Addressing a bussines's partners weak data security policies

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Common Vulnerabilities and Exposures  (SearchFinancialSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Finance Sector Security - Anti-Phishing, Remote Access Security, Firewall Systems
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts