Bankers Threads
Click to return to BOL home page

Learn more about

MEMBERS

GeoData Vision
























Have a Question?
Looking for a
Product or
Service?

Our Vendor
Advisory Board






Topic Options
#1178179 - 05/07/09 01:37 PM FDIC Examination - Disaster Recovery
QUINCY Online
Gold Star

Registered: 08/14/08
Posts: 449
Loc: SO ILL
Is the FDIC emphasizing more on Disaster Recovery during examinations more? My CEO is freaking out cus he went to a conference and some guy told him they were.


Edited by Ken_Pegasus (07/30/09 08:01 AM)
_________________________
"I find pastrami to be the most sensual of the cured meats"

Top
#1178713 - 05/08/09 12:20 AM Re: FDIC Examination [Re: QUINCY]
rlcarey Offline
Compliance is my life

Registered: 07/16/01
Posts: 23861
Loc: Galveston, TX
Can you say Swine Flu or Hurricane Ike or wild fires in CA???
_________________________
The opinions expressed are my own, take them or leave them.

Top
#1181810 - 05/12/09 04:08 PM Re: FDIC Examination [Re: rlcarey]
QUINCY Online
Gold Star

Registered: 08/14/08
Posts: 449
Loc: SO ILL
No hurricane damage or wild fires likely where i live, i guess what i was asking is if anyone has been through an FDIC exam recently where Disaster Recovery was emphasized more than in past exams?
_________________________
"I find pastrami to be the most sensual of the cured meats"

Top
#1182180 - 05/13/09 10:01 AM Re: FDIC Examination [Re: QUINCY]
blvsinangels Online
Gold Star

Registered: 08/15/03
Posts: 354
We just finished an FDIC exam and I would have to answer yes to your question. Make sure you have a plan in place, a risk assessment done and that your plan has been tested. Make sure your policy and assessment are board approved and that your IT committee or other board approved committee is aware of your plan and the results of your testing.

Top
#1183711 - 05/14/09 01:49 PM Re: FDIC Examination [Re: blvsinangels]
Just Jay Online
Compliance is my life

Registered: 10/26/06
Posts: 10132
Loc: Behind the cheddar curtain
In the last 10 months, S&S and Compliance exams... neither group said boo about DR.
_________________________
Is this respa thing I keep hearing about something I should be concerned with?

Top
#1183723 - 05/14/09 01:56 PM Re: FDIC Examination [Re: Just Jay]
rlcarey Offline
Compliance is my life

Registered: 07/16/01
Posts: 23861
Loc: Galveston, TX
"In the last 10 months, S&S and Compliance exams... neither group said boo about DR."

That is because it is part of the IT exam.
_________________________
The opinions expressed are my own, take them or leave them.

Top
#1188863 - 05/21/09 05:24 PM Re: FDIC Examination [Re: rlcarey]
bcook Offline
New Poster

Registered: 01/30/09
Posts: 22
Loc: Missouri
Yes, DR/BR is a hot topic with most examining bodies right now.

We are making sure our audit clients have a Business Impact Analysis, Risk Assessment, Pandemic Plan (as part of DR plan), and that they address alternative sources of cash.
_________________________
“Life is tough, but it's tougher when you're stupid.”
-John Wayne

Top
#1224502 - 07/30/09 07:57 AM Re: FDIC Examination [Re: QUINCY]
Ken_Pegasus Offline
Power Poster

Registered: 08/30/01
Posts: 9729
Loc: Another trip around the sun
Quote:
No hurricane damage or wild fires likely where i live...


The western portion of our state, just across the river from where you are, suffered an incredible ice storm in January. Two days later I had to call 30 banks in that area. Only 4 of them answered the phone. Their contingency plans got a real test. Some were proud. Some were embarrassed.

The value of thoughtful testing was summed up by the banker who told me about their new state of the art back up branch (complete with diesel generator) that seamlessly absorbed all bank operations. The only exception being the fact that their was no water pressure and the modern commodes did not have tanks that could be filled manually. They could not flush the toilets.

Think about everything...
_________________________
Try? There is "do" and "do not," there is no "try." Yoda

Top
#1224780 - 07/30/09 11:20 AM Re: FDIC Examination [Re: Ken_Pegasus]
Pizza Queen Offline
Power Poster

Registered: 05/29/01
Posts: 6909
Loc: New England
Just make sure you're testing your plan, fully!
_________________________
Those who bring sunshine into the lives of others cannot keep it from themselves.- James Barrie


http://www.firstgiving.com/angelfund
www.alsa.org

Top
#1231108 - 08/11/09 03:22 PM Re: FDIC Examination [Re: Pizza Queen]
Dazed&Confuzed Offline
100 Club

Registered: 04/11/03
Posts: 101
Loc: Overlooking a beautiful ocean
Our S&S and compliance exam also ended in the last 8 months - which included IT - nothing mentioned.

Top
#1231281 - 08/11/09 08:17 PM Re: FDIC Examination [Re: Dazed&Confuzed]
Curious Offline
New Poster

Registered: 05/07/04
Posts: 10
Definitely Disaster Recovery Plan (DRP) and Business Continuity Plan (BCP) are getting increasing attention from examiners.
Make sure your BCP is in place, is supported by a Business Impact Analysis (BIA), the plan has all the elements (including pandemic flu preparedness/response), it has been approved by the board, appropriate dissemination of the BCP/training of staff has been done, the DRP has been tested and results documented and shared with senior management.

Top
#1231348 - 08/12/09 08:52 AM Re: FDIC Examination [Re: Curious]
HappyGilmore Online
Compliance is my life

Registered: 06/11/04
Posts: 13511
Loc: Who'dat nation
Every OCC exam we have focuses on this. We test annually, and living in hurricane central, we have had to deploy it on more than 1 occassion. We also notify the OCC when we have deployed for contingency purposes - it is a courtesy move on our part but it lets them make a "note" in our file that not only have we tested but deployed and worked.
_________________________
Occams Razor - it's not just for shaving!


Top
#1244361 - 09/03/09 10:30 AM Re: FDIC Examination [Re: HappyGilmore]
Veni Vidi Suasi Offline
New Poster

Registered: 12/28/06
Posts: 7
I recommend making sure the testing you do is correlated to the results of your Business Impact Analysis. For example, if wire transfers are a critical function at your institution, make sure you test those recovery plans accordingly. The days of just testing your core system are over. . .

Top
#1278283 - 11/02/09 10:37 AM Re: FDIC Examination [Re: Veni Vidi Suasi]
Susan Orr Offline
New Poster

Registered: 08/05/08
Posts: 12
Loc: Illinois
Whether or not your BCP is being looked at will most likely depend on the region, the agency, and the examination. Reviewing the BCP is a key part of the IT examination and the responses I am getting from many institutions across the country is it was a main focus, I am also seeing more criticisms in examination reports. But again, like with any other area - it is going to depend on the agency and the examiners focus and will very likely be all over the board. Better to be prepared than risk not having a comprehensive plan in place that includes a good BIA and testing plan. The two areas I see cited the most.
_________________________
Susan Orr, CISA CRP CISM
susan@susanorrconsulting.com
630.499.0276

Top


Moderator:  Dana Turner