Skip to content
BOL Conferences
Thread Options
#1956402 - 08/22/14 10:02 PM Vendor Management Audit Program/checklist
Chocaholic Offline
Gold Star
Joined: Aug 2005
Posts: 443
Northwest
Hi,

I realize the FFIEC has a good process for technology related vendors but was looking for a checklist or program to test other high risk or significant vendors . Does anyone have one they would be willing to share or one they would recommend.

2ndly
At our last technology exam we were criticized because we did not include our outsourced Internal Audit firm as a critical vendor. Our thought process was although they do have access to consumer information ... it is only what we provide; they do not actually have access to our system; and while it would be inconvenient there are others we could contract if this one could not provide the service. Our feeling is significant vendor at best. What do others do? If it matters we are under $250 in asset size.

Appreciate any help on both items!

Return to Top
Audit
#1960220 - 09/08/14 09:29 PM Vendor Management Audit Program Chocaholic
CNBAudit Offline
New Poster
Joined: Nov 2013
Posts: 7
We are currently going through our OCC examination and they have suggested that we perform an Internal Audit on our Vendor Management Program. I have been looking for an example of this type of audit and have had no luck. Does anyone have an example audit they would be willing to share with me or if you know somewhere I might be able to find one. Thanks

Return to Top
#1963866 - 09/23/14 02:08 PM Re: Vendor Management Audit Program Chocaholic
Mike Honcho Offline
New Poster
Joined: Apr 2010
Posts: 17
Wisconsin
You could take a look at the FDIC Compliance Manual - https://www.fdic.gov/regulations/compliance/manual/pdf/VII-5.1.pdf. I always use these when I need to build an audit program.

Return to Top
#1964559 - 09/25/14 02:17 PM Re: Vendor Management Audit Program/checklist Chocaholic
RR Jen Offline
Power Poster
RR Jen
Joined: May 2003
Posts: 3,760
Running and riding everywhere ...
Originally Posted By: Chocaholic

2ndly
At our last technology exam we were criticized because we did not include our outsourced Internal Audit firm as a critical vendor. Our thought process was although they do have access to consumer information ... it is only what we provide; they do not actually have access to our system; and while it would be inconvenient there are others we could contract if this one could not provide the service. Our feeling is significant vendor at best. What do others do? If it matters we are under $250 in asset size.



Neither my internal or external audit provider is a "critical" vendor. We are OCC, $455 million in assets.

My logic for excluding them includes:
*The bank can easily function without them tomorrow should they have a disaster and take a week to be back up and running. External audit is two visits a year, internal is 6, they can be rearranged. If they go out of business, there are half a dozen other firms in town I can have in place in no time.
*The confidential information we share with them is only done through secure portals and monitored while on site.

The OCC has not questioned this logic/argument...yet. Hope that helps.
_________________________
I don't need any more negativity in my life...be positive and helpful people or I will kick you in the shins!!!

Return to Top
#1964891 - 09/26/14 12:03 AM Re: Vendor Management Audit Program/checklist Chocaholic
califgirl Offline
Diamond Poster
califgirl
Joined: Mar 2002
Posts: 2,355
The O.C., California
I agree with Jen on this as far as being able to replace these vendors easily. We are also OCC regulated and close to the same size. However, we did add this year a look at the security on these vendors' portals. I would recommend asking for their internal security procedures, as well as a SSAE16, if available, to document your due diligence.
_________________________
I can explain it to you. I can't understand it for you.

Return to Top
#1964990 - 09/26/14 02:45 PM Re: Vendor Management Audit Program/checklist Chocaholic
Beachbum, CRCM Offline
Gold Star
Joined: Dec 2006
Posts: 499
Knee Deep in Regs
FRB regulated, $350 million asset size- Even though the examination concluded our outsourced Internal Audit firm was satisfactory, we too were criticized for not including them in our vendor management audit. Management has decided to add them going forward.
_________________________
What we think, we become.
Buddha

Return to Top
#1965068 - 09/26/14 04:43 PM Re: Vendor Management Audit Program/checklist Chocaholic
RR Jen Offline
Power Poster
RR Jen
Joined: May 2003
Posts: 3,760
Running and riding everywhere ...
I will never cease to be amazed at the different perspectives each regulatory body has on the same guidance.
_________________________
I don't need any more negativity in my life...be positive and helpful people or I will kick you in the shins!!!

Return to Top

Moderator:  Andy_Z