Click to return to BOL home page
Banker Store eCard Exchange Vendor Connect Career Connect Learning Connect Bankers Information Network
 

Support for BOL is provided by:

MAIN CONTENT 
Compliance

    Agency Road Maps

    Alphabet Soup

    Compliance Tools

    FACTA/FCRA

    OFAC

Lending

    FACTA/FCRA

    Lending Tools

    SCRA

Marketing

Operations

    Check 21

    Operations Tools

    SAR Resrch Guide

Security

    AML/BSA

    Bank Robbery

    Counterfeits

    ID Fraud/Phishing

    Security Tools

Technology/eBanking

    Info Security


SPECIAL AREAS 
BOL Archives

BOL Blogs

Briefing Archive

Calendar

Court Watch
Em@il Education

Examiner's Corner

Executive Briefing

Infovault

Launch Pad

Site Map

Site Orientation

Top Stories


~ ~ ~
SERVICES 
CrimeDex

Em@il Education

ID Verification

Record Retention


~ ~ ~
SHOP 

Banker Store

Bankers Info Ntwk
Vendor Connect

CONNECT 

Career Connect

Learning Connect

Vendor Connect

Guru Central

INTERACT 

Ask a Guru
Bankers Threads

Contact Us

Give Us Feedback


TOOLS 

60 Second Solutions

Alphabet Soup

Banker Tools

BOL Forms

FUN 

BOL Recipes

eCard Exchange

LEARN MORE 

About Advertising
About Our Sponsors
About Us

Print Friendly! Email This Article! Discuss NOW!
Featured Risk Articles:
USA PATRIOT Act/BSA
Special Articles:

Articles - Tools - Products

ARTICLES
Risk Management in General
Lending
Contingency Planning/Disaster Recovery
ACH
Human Resources
Security / Fraud OFAC Information Technology Risk Assessment
TOOLS
General Risk Assessment Matrix
(right click on link and save the file to your hard drive)


Intrusion Risk Assessment Policy (sample)
From Wayne Barnett, CPA, of Wayne Barnett Software, has provided a sample Intrusion Risk Assessment Policy:
InfoSec Service Provider Risk Assessment Matrix
The extent to which you must monitor the information security practices of a service provider will depend upon the type of entity it is and the sensitivity of the information to which it has access. Mary Beth Guard created this matrix to aid in the analysis of what level of scrutiny is necessary. (See related article.)
Information Security Best Practices Guide
This report explores the nature of the threats facing executives tasked with CMA (Computer-Managed Assets) protection, and discusses ways that the risks associated with those threats can be managed and mitigated. Information Security and/or Internet Banking Risk Assessment Program
Here are a number of tools developed by a BOL user from various information sources for doing a risk assessment on information security and/or Internet Banking. The worksheets cover training issues, board and management oversight, contract issues, due diligence in service providers, oversight of service providers, and risk asseessments for policies ranging from disaster recovery to wire transfers. PDF versions of risk assessment program tools
Word versions of risk assessment program tools (RIGHT click on link and save file)
  • Assignment Sheet - this identifies who will be assigned the specific assessment worksheet. - Word .doc format - must right click on link and save
  • Cover sheet - a cover sheet should be attached to each area being risk assessment, with the "item risk assessed" at the top of the page being changed to match the area assessed. - Word .doc format - must right click on link and save
  • Training for Risk Assessment - Word .doc format - must right click on link and save
  • Vendor Selection - Word .doc format - must right click on link and save
  • Vendor Oversight - Word .doc format - must right click on link and save
  • Vendor Contract Assessment - Word .doc format - must right click on link and save
  • Board and Management Oversight - Word .doc format - must right click on link and save
Internal Audit Risk Assessment
A friend from one of the schools shared this tool with Maris Roush. It is a risk assessment model that would be used to assist with the audit scheduling. The model consists of two pages on Excel. The summary page will give an auditor a tool to prioritize his/her audits. She says it is the best she has seen because it is so simple and management can participate in it so they have a "buy-in".
Instructions: The data sheet is where the items are risk rated by both management and audit/compliance. Audit/Compliance would use column D then "hide" the column before printing and submitting to management for their assessment (column F). Column H calculates the two risk assessments. These assessments are then "pulled" into the Summary page by specific categories. Both use the numberical basis of 1 = low through 5 = high. The column D currently has example numbers in it with the totals coming to 100 in each area. Again this are samples and should not be mistaken as "actual" risk ratings.
Environmental Risk Policy & Program
Any time you loan money on real estate or, worse yet, have to foreclose on real property, there are environmental risk implications to consider. Upon the request of a BOL user, we've unearthed an environmental risk policy and program that Mary Beth Guard drafted back in 1993. If you don't already have such a policy and program, review this to determine where to start. If you do have one, you may still want to take a peek to see if it covers areas yours doesn't.
PATRIOT Act Risk Matrix by Product Line or Area - from Sandy Spring Bank
Alien Identification Procedures
BOL User Leslie Callaway has contributed information that relates to identification of alien customers and risk assessment data relating to lending to aliens, from diplomats to NRAs.
RISK MANAGEMENT PRODUCTS
from the BOL Banker Store





Privacy Policy    Disclaimer   Recommend This Site !   Contact Us


BankersOnline is a free service made possible by the generous support of our advertisers and sponsors. Advertisers and sponsors are not responsible for site content. Please help us keep BankersOnline FREE to all banking professionals. Support our advertisers and sponsors by clicking through to learn more about their products and services.