Skip to content
BOL Conferences
Thread Options
#1973947 - 11/04/14 03:23 PM System Validation
DebbieB Offline
Junior Member
Joined: Sep 2006
Posts: 37
I was wondering how many of you outsource your system validation or does anyone use your internal auditors.

Return to Top
BSA/AML/CIP/OFAC Forum
#1974064 - 11/04/14 07:50 PM Re: System Validation DebbieB
dcl1963 Offline
100 Club
Joined: Feb 2006
Posts: 178
LA
I serve as Risk-BSA/Compliance/Internal Audit so our external BSA compliance auditors perform a validation/testing on our Core system for BSA purposes. We're looking at a few BSA monitoring/reporting vendors but haven't made a choice yet, so I'm no help there.
_________________________
In God we trust, all others pay cash. . . Jean Shepherd

Return to Top
#1974120 - 11/04/14 09:36 PM Re: System Validation DebbieB
devsfan Offline
Diamond Poster
Joined: Jun 2004
Posts: 1,927
NYC
Please clarify what you mean by system validation since there is a model (rules or alerts) validation, validation that the system works as designed, reconcilliation of data feeds from the core-system, etc. and each could be done by a different individual, department, or outside vendor.

Return to Top
#1974129 - 11/04/14 09:52 PM Re: System Validation DebbieB
osucpa Offline
Diamond Poster
Joined: May 2011
Posts: 1,406
We perform ours in house using the appropriate OCC Bulletin.

Return to Top
#1974181 - 11/05/14 02:43 PM Re: System Validation DebbieB
Pat Patriot Act Offline
Gold Star
Pat Patriot Act
Joined: Apr 2009
Posts: 450
Originally Posted By: DebbieB
I was wondering how many of you outsource your system validation or does anyone use your internal auditors.


IF you're looking to determine whether you should outsource or use Audit, my recommendation would be to hire a firm. BSA/AML system validation requires a level of expertise that your internal auditors likely do not have. Reconciling the core to the AML system and the AML system to the batch filing output is pretty straightforward; but it takes a specialist to identify gaps, confirm models operate as intended, assess the appropriateness of the alert thresholds, and evaluate the overall effectiveness of your suspicious activity detection models, enhanced due diligence identification models, and AML model governance program.

Personally, I advocate a two-prong approach, where BSA/AML employees perform self-testing and also hire a firm to perform an independent periodic system validation.
_________________________
CFE, CAMS

Return to Top
#1974191 - 11/05/14 02:58 PM Re: System Validation Pat Patriot Act
ACBbank Online
Power Poster
ACBbank
Joined: Jul 2006
Posts: 4,351
New York City
Originally Posted By: patsfan
Originally Posted By: DebbieB
I was wondering how many of you outsource your system validation or does anyone use your internal auditors.


Personally, I advocate a two-prong approach, where BSA/AML employees perform self-testing and also hire a firm to perform an independent periodic system validation.


This is exactly what the OCC told me they expected a couple of months ago during our S&S exam.
_________________________
"100 victories in 100 battles isnt the most skillful. Subduing the other's military w/o battle is the most skillful." Sun-Tzu

Return to Top
#1974644 - 11/06/14 12:59 PM Re: System Validation ACBbank
Pat Patriot Act Offline
Gold Star
Pat Patriot Act
Joined: Apr 2009
Posts: 450
Originally Posted By: ACBbank
Originally Posted By: patsfan
Originally Posted By: DebbieB
I was wondering how many of you outsource your system validation or does anyone use your internal auditors.


Personally, I advocate a two-prong approach, where BSA/AML employees perform self-testing and also hire a firm to perform an independent periodic system validation.


This is exactly what the OCC told me they expected a couple of months ago during our S&S exam.


I'm not one of them!!!

Having spent a decade in the trenches as an AML investigator and BSA Officer, I've found trustworthy information to be one of the most important aspects of any program.

I often tell my fellow local BSA Officer friends, if you aren't reconciling data per mapping on a daily basis, you aren't doing it right. I often get the "we don't have the resources" response - to which I say bulls***. If your system doesn't do it already (I believe Verafin does), then make your IT team build a process to run totals on extracts per mapping and totals in transactions BINs on the AML system right after the load happens. Many folks might be surprised how often any given system gets it wrong for some unexpected and unpredictable reason...
_________________________
CFE, CAMS

Return to Top

Moderator:  Andy_Z