11.10.2013 Views

Risk Management Manual of Examination Policies - FDIC

Risk Management Manual of Examination Policies - FDIC

Risk Management Manual of Examination Policies - FDIC

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

REPORT OF EXAMINATION INSTRUCTIONS Section 16.1<br />

composite rating, if a prior examination disclosed a full URSIT rating, the full rating should be shown for that prior<br />

examination.<br />

Below the grid, the examiner should include the appropriate composite rating paragraph, as taken from the Uniform<br />

Rating System for Information Technology.<br />

Required Comments<br />

Scope <strong>of</strong> <strong>Examination</strong> – Include a brief statement outlining the IT examination scope/areas reviewed. This should<br />

include the scope <strong>of</strong> review covering the bank’s efforts to comply with Interagency Guidelines Establishing<br />

Standards for Safeguarding Customer Information (Appendix B to Part 364 <strong>of</strong> the <strong>FDIC</strong> Rules and Regulations. It is<br />

not necessary to include a detailed description <strong>of</strong> the bank’s IT functions.<br />

Supporting Comments – Comments should be prepared on an “exception only” basis as much as possible; however,<br />

they should support the ratings assigned and recommendations presented, and document management’s responses to<br />

recommendations. Address issues in order <strong>of</strong> priority and risk. Significant issues should be brought forward to the<br />

ECC page. Use descriptive subheadings, bulleted or numbered lists, and other such devices as needed to promote<br />

readability. For example, component ratings paragraphs would be appropriate when full URSIT ratings are<br />

assigned.<br />

<strong>Management</strong> Discussions – Identify bank <strong>of</strong>ficials with whom IT operations and examination findings were<br />

discussed.<br />

Report <strong>of</strong> <strong>Examination</strong> Instructions (12-04) 16.1-18 DSC <strong>Risk</strong> <strong>Management</strong> <strong>Manual</strong> <strong>of</strong> <strong>Examination</strong> <strong>Policies</strong><br />

Federal Deposit Insurance Corporation

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!