risk assessments. why perform a risk assessment fulfills requirements empowers management to make...

Download RISK ASSESSMENTS. WHY PERFORM A RISK ASSESSMENT  Fulfills Requirements  Empowers management to make informed strategic decisions  Identifies areas

If you can't read please download the document

Upload: corey-gyles-merritt

Post on 18-Jan-2018

220 views

Category:

Documents


0 download

DESCRIPTION

 Fulfills Requirements  Empowers management to make informed strategic decisions  Identifies areas where controls are needed BENEFITS

TRANSCRIPT

RISK ASSESSMENTS WHY PERFORM A RISK ASSESSMENT Fulfills Requirements Empowers management to make informed strategic decisions Identifies areas where controls are needed BENEFITS REQUIRED RISK ASSESSMENTS Can be required for almost any major area of credit union operations The following are specifically mentioned in regulation or guidance: BSA OFAC Customer/Member Identification Program IT/Information Security ID Theft Red Flag Vendor Management Disaster Recovery/Business Continuity Online Banking (multi-factor authentication) Remote Deposit Capture REQUIRED RISK ASSESSMENTS MAKING INFORMED DECISIONS Risk can never be entirely eliminated. Management must determine appetite for risk Using risk assessments will help credit unions continue to provide meaningful products and services to members while including necessary safeguards Common risks for small credit unions Snakes Silos Sinkholes MAKING INFORMED DECISIONS Risk assessments help you identify unintended consequences SNAKES Risk assessments help you determine vulnerabilities created when one person has control over vital systems or has all the expertise/knowledge in the credit union SILOS SINKHOLES Risk assessment help you prepare for the unexpected OUTCOME OF A RISK ASSESSMENT Reject the plan Accept the plan Accept the plan and minimize risk with controls OUTCOME OF A RISK ASSESSMENT PERFORMING A RISK ASSESSMENT Uncomplicated process for an uncomplicated institution Risks are probably already well known Control measures are probably already in place or easy to implement Follow an easy four step process: Identify risk/risk area Determine the overall degree of risk Identify areas of concern Decide on precautions (controls) BASIC RULES What areas of an operation are vulnerable or what could go wrong? Use risk assessment guidance Ask others Past experiences IDENTIFY THE RISK AREA How likely is it that a specific area could cause problems? How likely is it that a specific event could come to pass? EVALUATE THE DEGREE OF RISK Zero risk? What/who might be harmed and why? For each risk, be clear about who/what might be harmed; it will help identify the best way of managing the risk. IDENTIFY AREAS OF CONCERN Reasonable and practicable SMART controls DECIDE ON CONTROLS Systems Monitoring Accountability Response Training SMART CONTROLS FINAL THOUGHTS Record your findings and implement them Develop procedures Review your risk assessment and update if necessary FINAL THOUGHTS