Skip to content
BOL Conferences
Thread Options
#1984527 - 12/20/14 01:32 PM Social Media
3-2-Go Offline
Gold Star
3-2-Go
Joined: Nov 2008
Posts: 403
East
Does the Social Media Policy need to be approved by the BOD annually?

Return to Top
eBanking / Technology
#1984530 - 12/20/14 10:07 PM Re: Social Media 3-2-Go
rlcarey Offline
10K Club
rlcarey
Joined: Jul 2001
Posts: 83,363
Galveston, TX
Considering there is no specific requirement to have a social media policy, it is really up to the bank to determine how they would like to manage the process.
_________________________
The opinions expressed here should not be construed to be those of my employer: PPDocs.com

Return to Top
#1984563 - 12/22/14 03:25 PM Re: Social Media 3-2-Go
Russ Horn Offline
100 Club
Russ Horn
Joined: May 2008
Posts: 139
In the Social Media: Consumer Compliance Risk Management Guidance issued by the FFIEC in December 2013, under section III (Compliance Risk Management Expectations for Social Media), states, "A financial institutions should have a risk management program that allows it to identify, measure, monitor, and control the risks related to social media...."

It goes on to describe, "Components of a risk management program should include the following..." and lists 7 components expected to be in the social media risk management program - the second of those components is "Policies and procedures" and the final component is related to reporting - the reporting section states, "Parameters for providing appropriate reporting to the financial institution's board of directors or senior management that enable periodic evaluation of the effectiveness of the social media program and whether the program is achieving its stated objectives."

So, the guidance doesn't really give a specific approval frequency - just "periodic" - I would suggest the frequency of reporting would likely be based on your involvement in social media - but a minimum of annually is probably not a bad idea.

I hope this helps some.

Thanks,
Russ
_________________________
Russ Horn, CISA, CISSP, CRISC
CoNetrix
rhorn@conetrix.com

Return to Top
#1984608 - 12/22/14 05:27 PM Re: Social Media Russ Horn
3-2-Go Offline
Gold Star
3-2-Go
Joined: Nov 2008
Posts: 403
East
Thank you!

Return to Top
#1984771 - 12/23/14 01:18 PM Re: Social Media 3-2-Go
Andy_Z Offline
10K Club
Andy_Z
Joined: Oct 2000
Posts: 27,750
On the Net
First, it isn't a required policy but you have many, many more policies than are "required" by law. Second, the idea of periodic reaffirmations of your policies isn't to adopt changes, but a confirmation that that the current policy is the direction the board wants the bank to follow. So I recommend an annual review of all policies. It worked well in my community bank, but it isn't a one size fits all.
_________________________
AndyZ CRCM
My opinions are not necessarily my employers.
R+R-R=R+R
Rules and Regs minus Relationships equals Resentment and Rebellion. John Maxwell

Return to Top

Moderator:  Andy_Z