11.10.2013 Views

Risk Management Manual of Examination Policies - FDIC

Risk Management Manual of Examination Policies - FDIC

Risk Management Manual of Examination Policies - FDIC

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

REPORT OF EXAMINATION INSTRUCTIONS Section 16.1<br />

PURPOSE<br />

INFORMATION TECHNOLOGY ASSESSMENT (ITA)<br />

With the release <strong>of</strong> the IT-MERIT and IT General Work Program, all financial institutions are classified according<br />

to their technology risk pr<strong>of</strong>ile (I, II, III, or IV). Furthermore, all institutions receive, at a minimum, an IT<br />

composite rating. For embedded IT examinations, the ITA page should convey assigned IT composite and/or<br />

component rating(s), as well as all significant IT examination conclusions, recommendations, and management<br />

responses.<br />

WHEN TO INCLUDE<br />

In general, IT findings are embedded within the risk management ROE, using the ITA page, unless a separate cover<br />

IT ROE is required. A separate cover Report is required for:<br />

• Institutions with a composite rating <strong>of</strong> 3, 4, or 5 at the current IT examination;<br />

• Independent data centers or institutions that perform core data processing services for other <strong>FDIC</strong>-insured<br />

financial institutions (including affiliated institutions); or<br />

• Type IV IT examinations.<br />

ASSIGNING AND DISCLOSING RATINGS<br />

The following table summarizes outstanding guidance regarding assigning and disclosing ratings under the Uniform<br />

Rating System for Information Technology (URSIT).<br />

Assign and Disclose –<br />

Composite URSIT Rating Only<br />

Full URSIT Rating<br />

PAGE STRUCTURE AND ORDER<br />

Numerical Ratings<br />

In These Situations -<br />

• Type I examinations<br />

• Type II examinations if all component ratings warrant a 1 or 2 rating<br />

• Type II examinations if any component rating or the composite rating<br />

warrants a 3, 4, or 5 (Note that a composite rating <strong>of</strong> 3, 4, or 5 would<br />

require a separate cover IT Report.)<br />

• Type III examinations<br />

• Type IV examinations (requires a separate cover IT Report)<br />

The ITA page, as formatted by Genesys, includes a grid at the top <strong>of</strong> the first page to display the component and<br />

composite ratings for the current and two prior IT examinations. Ratings for the current examination should be<br />

assigned and disclosed based on the guidance summarized in the above table. Prior examination ratings shown<br />

should reflect ratings disclosed at those examinations. For example, even if the current examination only requires a<br />

DSC <strong>Risk</strong> <strong>Management</strong> <strong>Manual</strong> <strong>of</strong> <strong>Examination</strong> <strong>Policies</strong> 16.1-17 Report <strong>of</strong> <strong>Examination</strong> Instructions (12-04)<br />

Federal Deposit Insurance Corporation

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!