Click to return to BOL home page
Banker Store Read A Reg Vendor Connect Career Connect Learning Connect Bankers Information Network
 

Support for BOL is provided by:

MAIN CONTENT 
Compliance

    Agency Road Maps

    Alphabet Soup

    Compliance Tools

    FACTA/FCRA

    OFAC

Lending

    FACTA/FCRA

    Lending Tools

    SCRA

Marketing

Operations

    Check 21

    Operations Tools

    SAR Resrch Guide

Security

    AML/BSA

    Bank Robbery

    Counterfeits

    ID Fraud/Phishing

    Security Tools

Technology/eBanking

    Info Security


SPECIAL AREAS 
BOL Archives

BOL Blogs

Briefing Archive

Calendar

Court Watch

e-Card Exchange

Examiner's Corner

Executive Briefing

HR Corner

Infovault

Launch Pad

Regulator Roadmaps

Risk Management

Site Map

Site Orientation

Top Stories


~ ~ ~
SERVICES 
CrimeDex

Em@il Education

ID Verification


~ ~ ~
SHOP 

Banker Store

Bankers Info Ntwk
Vendor Connect

CONNECT 

Career Connect

Learning Connect

Vendor Connect

Guru Central

INTERACT 

Ask a Guru
Bankers Threads

Contact Us

Give Us Feedback


TOOLS 

BOL Toolbar

60 Second Solutions

Alphabet Soup

Banker Tools

BOL Forms

FUN 

BOL Recipes

eCard Exchange

LEARN MORE 


About Our Sponsors
About Us






Print Friendly! Email This Article! Discuss NOW!

Whom Do We Notify?
Answer by Ryan Rasske, BOL Guru
Guru BIOS

Question: We have been notified by VISA Fraud that 23 of our customers debit cards may have been compromised. We have notified each affected customers. To date we have not identified any loss. Do we need to: 1) file a SAR?, 2) notify law enforcement? or 3) notify the FDIC?

Answer: Based on your question, I am assuming you have already assessed the incident to determine what customer information may have been compromised. The findings of your assessment will determine what action steps you or your “response team” must take. Financial institutions are encouraged to implement a response program that will address situations where “sensitive” customer information may have been breached.

According to the Interagency Guidance, “sensitive” customer information is defined as a customer’s name, address, or telephone number in conjunction with the customers social security number, drivers license number, account number, credit or debit card number, personal identification number or password that would permit access to a customers account. Sensitive customer information also includes any combination of components of customer’s information that would allow someone to access the customer’s account.

If the compromised data includes “sensitive” information (regardless of the loss amount), you will need to (1) notify your primary Federal regulator as soon as possible to explaining the situation, (2) take steps to prevent additional unauthorized access to customer information, and (3) work closely with your legal counsel, senior management, and regulator to determine if a SAR is required.

First published on BankersOnline.com 10/03/05





Open the newly required
"UAD" .XML appraisals
Download Free UAD Reader


Privacy Policy    Disclaimer   Recommend This Site !   Contact Us


BankersOnline is a free service made possible by the generous support of our advertisers and sponsors. Advertisers and sponsors are not responsible for site content. Please help us keep BankersOnline FREE to all banking professionals. Support our advertisers and sponsors by clicking through to learn more about their products and services.