Skip to content
BOL Conferences
Thread Options
#1419000 - 07/22/10 09:32 PM Remote Deposit Capture Risk Analysis
one auditor Offline
100 Club
Joined: Apr 2004
Posts: 104
Midwest
I am auditing the bank's remote deposit capture (RDC) function and have received their risk assessment which to my surprise does not inlcude the usual column headings found on a traditional risk assessment. This particular assessment has two headings: "Scope of Capture Application" and "Answer Results"; from reading the content under these two column headings it does not address risk, risk mitigation, impact, liklihood, etc. This format in my opinion, after reading the information on it, is nothing more than an internal control questionaire.

Can anyone share with me the categories employed on a RDC risk assessment along with specific risks concerns related to the RDC function? Any help would be very much appreciated.



Thank you.

Return to Top
Audit
#1420870 - 07/28/10 04:14 PM Re: Remote Deposit Capture Risk Analysis one auditor
BTJ Offline
Member
Joined: Sep 2007
Posts: 83
FDIC Financial Institution Letter FIL-4-2009 concerning risk management of remote deposit capture:
http://www.fdic.gov/news/news/financial/2009/fil09004.html


Below is a suggested Action Plan:

Any institution that is planning on implementing or has already implemented Remote Deposit Capture would:
-Conduct a risk assessment to identify and risk-rate each type of threat and risk exposure relating to RDC activities, determine the existing controls currently in place, and determine which high risk activities require additional mitigation;
-Ensure that contracts and agreements are comprehensive and sufficiently identify roles, responsibilities, and liabilities of each party to effectively minimize compliance and legal risks;
-Implement appropriate policies to establish procedures and controls to help mitigate risks associated with RDC;
-Conduct customer due diligence procedures to determine suitability for new and existing customers requesting to use the institution’s RDC delivery system;
-Develop a training program to provide initial and on-going training to RDC customers;
-Address the recovery and resumption of RDC operations within the institution’s business continuity plan;
-Consider RDC when updating the business impact analysis and include RDC in the testing strategy; and
-Develop a process for monitoring RDC operations and customer activity through reports, reviews, and periodic risk assessments.

Return to Top
#1420906 - 07/28/10 05:08 PM Re: Remote Deposit Capture Risk Analysis one auditor
one auditor Offline
100 Club
Joined: Apr 2004
Posts: 104
Midwest
Thank you.

Return to Top

Moderator:  Andy_Z