Skip to content
BOL Conferences
Thread Options
#156765 - 02/04/04 09:29 PM Sample Privacy Audit Program
Anonymous
Unregistered

Would anyone out there be willing to share a sample of a Privacy audit program for Internal Audit?

Return to Top
Audit
#156766 - 02/05/04 05:51 PM Re: Sample Privacy Audit Program
Anonymous
Unregistered

I can offer you one that combines IT and operations privacy controls...

Return to Top
#156767 - 02/06/04 04:04 PM Re: Sample Privacy Audit Program
Anonymous
Unregistered

That would be great if you could provide me with that - my e-mail address is sgeiger@crownbank.net

Return to Top
#156768 - 02/07/04 05:11 PM Re: Sample Privacy Audit Program
Al Miller Offline
Diamond Poster
Al Miller
Joined: Oct 2000
Posts: 2,416
Pleasanton CA USA
I would like that as well. My e-mail is alm@bankvisioninc.com

Thanks in advance.
_________________________
Al Miller, CRCM
Opinions expressed are my own and not necessarily shared by my employer.

Return to Top
#156769 - 02/09/04 07:45 PM Re: Sample Privacy Audit Program
chuck Offline
Member
chuck
Joined: Oct 2003
Posts: 64
northwest missouri
Could I make that three? I would appreciate one also. Charles Friesz banknw@grm.net Thank you in advance.

Return to Top
#156770 - 02/26/04 03:59 PM Re: Sample Privacy Audit Program
Anonymous
Unregistered

Quote:

I can offer you one that combines IT and operations privacy controls...



I haven't heard a response and was wondering if you could still e-mail it to me at sgeiger@crownbank.net?

Return to Top
#156771 - 02/26/04 08:27 PM Re: Sample Privacy Audit Program
Anonymous
Unregistered

Count me in too please - bferguson@amnetmortgage.com

Return to Top
#156772 - 03/01/04 01:15 AM Re: Sample Privacy Audit Program
Anonymous
Unregistered

I would welcome a copy of the privacy audit you mentioned. ses343@aol.com

Many thanks!!

Return to Top
#156773 - 03/01/04 05:52 PM Re: Sample Privacy Audit Program
Sandra1 Offline
New Poster
Joined: Dec 2003
Posts: 3
Arkansas
Please!!!!!send me a copy of that program too.
_________________________
Sandra

Return to Top
#156774 - 03/02/04 03:40 PM Re: Sample Privacy Audit Program
Anonymous
Unregistered

Quote:

I can offer you one that combines IT and operations privacy controls...



OK Mr. Anonymous poster with the Privacy Program, where did you go??????

Return to Top
#156775 - 03/02/04 07:07 PM Re: Sample Privacy Audit Program
Paragon Offline
Diamond Poster
Paragon
Joined: Dec 2003
Posts: 2,164
I'm re-posting this from my prior post, prior thread - it provides a good start on your audit program, but your level of exposure needs to be incorporated within the areas to be audited.


Here are 'some' of the issues. Columns are: Item/Issue, Risk (level), Control (to be audited) and a column to note when tested and by who.

Item/Issue Risk Control Testing/Audit/Other
Internal Documents Medium Locked shredding bins in each facility, shredding delivered to bins at the end of each business day. • Tested by______
• On____________
Internal Communications High Are verbal communication activities between employees and employees and customers with the lobby and other public area of the bank conducted in a private manner? • Tested by______
• On____________
Documents on Desks Non-Business Hours Medium All documents to be locked away during non-business hours. • Tested by______
• On____________
Documents on Desks during business hours Medium Customers documents must be kept out of view of other customers during business hours. • Tested by______
• On____________
Visibility of workstation monitors to public Medium All workstations are required to be faced away form the bank lobby (public areas) – any exception is to be documented, subject to board approval. • Tested by______
• On____________
Retirement of equipment (PC’s) Low All hard drives are erased after retirement. • Tested by______
• On____________
Assess to data center High Electronic locks; authorized personnel only. • Tested by______
• On____________
Employee system access levels (primary system) Medium Employee access levels limited by assigned responsibility; Written policy (IS Security) • Tested by______
• On____________
Privacy Notice on Web Site Low Web site periodically reviewed to assure that privacy notice is posted. • Tested by______
• On____________
Hacking and other external threats to network High Firewall; password procedures; various other written policies (IS Security Policy). • Tested by______
• On____________
Information shared internally throughout the bank Medium Information sharing is limited to employees’ need to know. • Tested by______
• On____________
Training High Information Security (Privacy) training at least annually; document attendance and training material. • Tested by______
• On____________
Customer Telephone inquiries High Employees’ required to fully determine the identity of the caller. • Tested by______
• On____________
Bank adds new technology components, products, services High Procedures in place prior to implementation that address privacy issues. • Tested by______
• On____________
Bank adds new vendor High Vendors that require access to customer data must have an acceptable privacy policy in place; retain copy in files. • Tested by______
• On____________
Current vendors High Contracts must include privacy statements (primary DP vendor, ATM vendor, etc.). • Tested by______
• On____________
Annual Privacy Notice Low Annual privacy notice must be forwarded to customers. • Tested by______
• On____________
Privacy notice – new accounts Low All new account customers are given a copy of the bank’s privacy statement. • Tested by______
• On____________
Information Reporting opt-out High If the bank is providing customer information to a vendor other than a credit reporting agency, data processor of the bank, etc., are customers allowed to opt-out when a request is received? • Tested by______
• On____________
Garbage High In the bank’s garbage periodically checked to assure that no customer information, documents or other private data or documents are being placed in the garbage? • Tested by______
• On____________
Web Site E-Mail High Is there a privacy notice posted on the bank’s web site informing customers that email is not a private mode of communications? • Tested by______
• On____________

Return to Top
#156776 - 03/25/04 03:29 PM Re: Sample Privacy Audit Program
AuditNet Offline
New Poster
Joined: Jan 2004
Posts: 7
Virginia
Please do not solicit users for surveys or sales info without BOL managements permission. This is something we allow advertisers to do. If you want to advertise, contact tobi@bankersonline.com.
Last edited by Andy Z; 05/07/12 07:43 PM.
Return to Top

Moderator:  Andy_Z