Register Today!
In 2017, financial institutions will hear much more about innovative financial technology (FinTech) companies, distributed ledgers (like blockchain), and cryptocurrencies (like Bitcoin). While industry experts agree that “seamless integration with third parties” will be key for institutions going forward, many still fear the threats posed by FinTechs and new technologies transforming financial services. 2017 will be marked by continued “fintegration” (i.e., financial institutions and FinTechs coming together through powerful API platforms that expedite evolution of digital channels, enable mobile-first services, and improve user experience (UX)). These API platforms are what will ultimately give financial institutions the flexibility to partner with a growing array of best-of-breed FinTechs in ways that will enrich, extend, and differentiate their digital services. Join us for a bottom-line look at the latest financial technologies and companies, how banks are leveraging them, and what it all means for community banks and their future.
HIGHLIGHTS
FinTechs, fintegration, and the future of banking
The real threat to community banks: other financial institutions and silent churn
The unbundling and rebundling of banking: collaboration vs. disruption
API platforms: connecting banks and FinTechs
What they are, how they work, and why they matter
API models for now, soon, and later
Blockchain bottom-lined: how and when distributed ledgers will matter
Emerging techs reshaping payments
Voice-commerce; mobile order-ahead-&-pay, buy-online-pick-up-in-store
TAKE-AWAY TOOLKIT
Directory of open APIs: “The Programmable Web” site
Checklist: how to classify and assess FinTechs (disruptors vs. partners)
Employee training log
Quiz you can administer to measure staff learning and a separate answer key
Attendance verification for CE credits provided upon request.
WHO SHOULD ATTEND? This presentation is designed for executives, officers, and staff responsible for the strategy, assessment, and implementation/operation of emerging technologies and FinTech partnerships vital to the ongoing viability of the bank. This topic’s strategic implications also merit the attention of board members participating on the bank’s IT and risk committees.
ABOUT THE PRESENTER – Lee Wetherington, Jack Henry & Associates, Inc.®, Director of Strategic Insight for ProfitStars®, a division of Jack Henry & Associates®. He directs the development of actionable insight and strategy for the financial services industry. To this end, he creates programs, presentations, and articles designed to orient and educate financial executives on the trends and implications of new technologies. Lee has delivered over 400 keynotes nationwide focusing upon opportunities and challenges in payments and the online/mobile/social channels, and is widely renowned for his unique style of comedic delivery. His articles and commentary have been widely published across the financial services industry. Lee received bachelor degrees in Economics and English from Duke University in 1990, and, in 1993, he completed graduate studies at Emory University. In 1995, he earned the distinguished Accredited ACH Professional (AAP) certification from the National Automated Clearing House Association (NACHA).
Showing posts with label IT. Show all posts
Showing posts with label IT. Show all posts
(Recording + Free Digital Download) Hot Issues in Cyber Compliance, Including Recent Changes to the IT Handbook
Email to order the Recording + Free Digital Download
The proactive development of a robust and sustained information security program is critically important to the safety and soundness of your financial institution’s operations. Aligned with NIST’s framework and FFIEC’s Cybersecurity Assessment Tool, the amended Information Security Booklet, one of the 11 booklets that make up the Information Technology Handbook (IT Handbook), was updated to “help examiners measure the adequacy of an institution’s culture, governance, information security program, security operations, and assurance processes.”
This webinar will provide a high-level, non-technical overview of FFIEC’s amendments to the Information Security Booklet and how the updates can impact your financial institution’s information security program.
HIGHLIGHTS
Overview of Information Security Booklet’s examination procedure changes: Elimination of Tier I and Tier II procedures creating a single risk-based safety and soundness examination protocol
Information Security Booklet’s alignment with FFIEC’s cybersecurity assessment tool
FinCEN’s new cyber-event and cyber-enabled crime reporting expectations and impact on monitoring
Overview of FFIEC’s three actionable bullet points to ensure a robust information security program:
Support the institution’s IT risk management process by identifying threats, measuring risk, defining information security requirements, and implementing controls
Integrate with lines of business and support functions in which risk decisions are made
Integrate third-party service provider activities with the information security program
White House statement on the report of the Commission on Enhancing National Cybersecurity
TAKE-AWAY TOOLKIT
FFIEC’s Information Security Booklet weblink (September 2016)
FinCEN’s cyber-event advisory with frequently asked questions (October 2016)
Commission on Enhancing National Cybersecurity report (December 2016)
Automated FFIEC cybersecurity assessment tool spreadsheet (FS-ISAC)
Template for wire authentication and validation procedures
Employee training log
Quiz you can administer to measure staff learning and a separate answer key
Attendance verification for CE credits provided upon request.
WHO SHOULD ATTEND? Risk management, including information security, risk, compliance, audit, and legal staff, as well as board and audit committee members.
ABOUT THE PRESENTER – Brian W. Vitale, NCCO, CAMS-Audit, Compliance Advisory Services, earned his Political Science degree from North Central College in 1996 and an MBA from the University of Notre Dame in 2014. Brian was recruited by the National Security Division of the FBI where he specialized in counterterrorism and foreign counterintelligence. In addition, he is a decorated veteran who served in Guantanamo Bay, Cuba in the early 1990s. Subsequent to the FBI, Brian spent many years in banking and finance where his skills led him to the field of Global Operational Risk Management. He has over 23 years of banking, finance, and investigative experience. In July 2011, Brian joined a community financial institution and currently serves as their chief risk and compliance officer. He speaks nationally on BSA, anti-money laundering, enterprise risk management, cybersecurity, and strategy.
The proactive development of a robust and sustained information security program is critically important to the safety and soundness of your financial institution’s operations. Aligned with NIST’s framework and FFIEC’s Cybersecurity Assessment Tool, the amended Information Security Booklet, one of the 11 booklets that make up the Information Technology Handbook (IT Handbook), was updated to “help examiners measure the adequacy of an institution’s culture, governance, information security program, security operations, and assurance processes.”
This webinar will provide a high-level, non-technical overview of FFIEC’s amendments to the Information Security Booklet and how the updates can impact your financial institution’s information security program.
HIGHLIGHTS
Overview of Information Security Booklet’s examination procedure changes: Elimination of Tier I and Tier II procedures creating a single risk-based safety and soundness examination protocol
Information Security Booklet’s alignment with FFIEC’s cybersecurity assessment tool
FinCEN’s new cyber-event and cyber-enabled crime reporting expectations and impact on monitoring
Overview of FFIEC’s three actionable bullet points to ensure a robust information security program:
Support the institution’s IT risk management process by identifying threats, measuring risk, defining information security requirements, and implementing controls
Integrate with lines of business and support functions in which risk decisions are made
Integrate third-party service provider activities with the information security program
White House statement on the report of the Commission on Enhancing National Cybersecurity
TAKE-AWAY TOOLKIT
FFIEC’s Information Security Booklet weblink (September 2016)
FinCEN’s cyber-event advisory with frequently asked questions (October 2016)
Commission on Enhancing National Cybersecurity report (December 2016)
Automated FFIEC cybersecurity assessment tool spreadsheet (FS-ISAC)
Template for wire authentication and validation procedures
Employee training log
Quiz you can administer to measure staff learning and a separate answer key
Attendance verification for CE credits provided upon request.
WHO SHOULD ATTEND? Risk management, including information security, risk, compliance, audit, and legal staff, as well as board and audit committee members.
ABOUT THE PRESENTER – Brian W. Vitale, NCCO, CAMS-Audit, Compliance Advisory Services, earned his Political Science degree from North Central College in 1996 and an MBA from the University of Notre Dame in 2014. Brian was recruited by the National Security Division of the FBI where he specialized in counterterrorism and foreign counterintelligence. In addition, he is a decorated veteran who served in Guantanamo Bay, Cuba in the early 1990s. Subsequent to the FBI, Brian spent many years in banking and finance where his skills led him to the field of Global Operational Risk Management. He has over 23 years of banking, finance, and investigative experience. In July 2011, Brian joined a community financial institution and currently serves as their chief risk and compliance officer. He speaks nationally on BSA, anti-money laundering, enterprise risk management, cybersecurity, and strategy.
Labels:
Auditors,
Compliance,
Cyber Compliance,
EFIEC,
IT,
March,
Risk Management,
Webinar,
Webinars
(Recording + Free Digital Download) Procedural & Compliance Responsibilities of the Board Secretary
Email to order the Recording + Digital Download
In a dynamic industry involving corporate governance, compliance, and director liability, the role of board secretary is more than critical. Examiners routinely ask for, and conduct an in-depth review of board minutes as a part of their regular exam request memo. The minutes must be complete! Examiners (and potentially legal counsel) will scrutinize recordkeeping, the board secretary’s communication with directors/management, and the administration of corporate governance. What are the dos and don’ts of this important role? How can the board secretary be more effective? This session will provide the answers to these questions and more.
In addition, more and more board packages are delivered electronically via iPads and other tablets. What steps can be taken to mitigate risk regarding security and privacy? Best practices for this critical function will be addressed.
HIGHLIGHTS
List of annual policies, officer designations, and other items that need to go to the board
Communication with directors and management, before and after the meeting
Coverage of board and committee meetings – how the secretary’s role changes
Crafting the minutes and supporting documentation
Record retention requirements
Obtaining and maintaining annual documentation requirements (e.g., insider records, board training schedules, etc.)
E-package delivery – including privacy and IT issues and sample procedures
TAKE-AWAY TOOLKIT
Excel spreadsheet for policies and training that go to the board
Electronic media board package considerations and sample procedures
Employee training log
Quiz you can administer to measure staff learning and a separate answer key
Attendance verification for CE credits provided upon request.
WHO SHOULD ATTEND? Board secretaries, senior management, and directors.
ABOUT THE PRESENTER – Ann Brode-Harner, Brode Consulting Services, Inc., began her career in 1973 and has continued her service as a consultant to regional and community financial institutions through a wide range of areas including strategic planning, lending, deposits, marketing, training, compliance, and management. Ann is a well-respected presenter and has spoken to audiences across the country for over 25 years. She has presented sessions for numerous state associations and has taught at the School of Banking Administration at the University of Wisconsin as well as many other state banking schools. Ann is the author of “The Bank Deposit Documentation Manual for Front-Line Personnel” published by Bankers Publishing Company, and is well represented in numerous industry publications.
In a dynamic industry involving corporate governance, compliance, and director liability, the role of board secretary is more than critical. Examiners routinely ask for, and conduct an in-depth review of board minutes as a part of their regular exam request memo. The minutes must be complete! Examiners (and potentially legal counsel) will scrutinize recordkeeping, the board secretary’s communication with directors/management, and the administration of corporate governance. What are the dos and don’ts of this important role? How can the board secretary be more effective? This session will provide the answers to these questions and more.
In addition, more and more board packages are delivered electronically via iPads and other tablets. What steps can be taken to mitigate risk regarding security and privacy? Best practices for this critical function will be addressed.
HIGHLIGHTS
List of annual policies, officer designations, and other items that need to go to the board
Communication with directors and management, before and after the meeting
Coverage of board and committee meetings – how the secretary’s role changes
Crafting the minutes and supporting documentation
Record retention requirements
Obtaining and maintaining annual documentation requirements (e.g., insider records, board training schedules, etc.)
E-package delivery – including privacy and IT issues and sample procedures
TAKE-AWAY TOOLKIT
Excel spreadsheet for policies and training that go to the board
Electronic media board package considerations and sample procedures
Employee training log
Quiz you can administer to measure staff learning and a separate answer key
Attendance verification for CE credits provided upon request.
WHO SHOULD ATTEND? Board secretaries, senior management, and directors.
ABOUT THE PRESENTER – Ann Brode-Harner, Brode Consulting Services, Inc., began her career in 1973 and has continued her service as a consultant to regional and community financial institutions through a wide range of areas including strategic planning, lending, deposits, marketing, training, compliance, and management. Ann is a well-respected presenter and has spoken to audiences across the country for over 25 years. She has presented sessions for numerous state associations and has taught at the School of Banking Administration at the University of Wisconsin as well as many other state banking schools. Ann is the author of “The Bank Deposit Documentation Manual for Front-Line Personnel” published by Bankers Publishing Company, and is well represented in numerous industry publications.
Labels:
Board Secretary,
Compliance,
directors,
February,
IT,
Webinar,
Webinars
(Recording + Free Digital Download) ADA Website Compliance Requirements & Common Errors
Email to order the Recording + Free Digital Download
Compliance with the Americans with Disabilities Act (ADA) website regulations is not something you can afford to postpone. Several states are experiencing lawsuits. Your website serves as your 24/7 branch and just like your brick-and-mortar locations, it should provide equal access and opportunities to all. Even though the Department of Justice is not expected to publish formal rules until 2018, they have confirmed that the ADA requires public websites to be accessible now. This session will review guidelines and best practices to prepare a plan to update your website to meet the required accessibility standards.
HIGHLIGHTS
Online barriers for people with disabilities
Solutions to common website accessibility problems
Detailed review of recognized website accessibility guidelines
How ADA requirements affect mobile banking
Action plan to prepare for the necessary updates
TAKE-AWAY TOOLKIT
ADA website compliance checklist
ADA website compliance action plan
Employee training log
Quiz you can administer to measure staff learning and a separate answer key
Attendance verification for CE credits provided upon request.
WHO SHOULD ATTEND? Compliance officers, IT officers, marketing personnel, and staff responsible for website development and maintenance.
ABOUT THE PRESENTER – Dawn Kincaid, Brode Consulting Services, Inc., began her banking career while attending Ohio State University. She has fifteen years’ experience in client service, operations, information technology, administrative and board relations, marketing, and compliance. Most recently Dawn served as the Senior Vice President of Operations for a central-Ohio-based community bank, where she created and refined policies and procedures, conducted self-audits and risk assessments, and organized implementation of new products and services. Dawn has served in the roles of Compliance, BSA/AML, CRA, Privacy, and Security Officer. She has led training initiatives, prepared due diligence information, completed a variety of regulatory applications, and coordinated internal and external audits and exams.
Compliance with the Americans with Disabilities Act (ADA) website regulations is not something you can afford to postpone. Several states are experiencing lawsuits. Your website serves as your 24/7 branch and just like your brick-and-mortar locations, it should provide equal access and opportunities to all. Even though the Department of Justice is not expected to publish formal rules until 2018, they have confirmed that the ADA requires public websites to be accessible now. This session will review guidelines and best practices to prepare a plan to update your website to meet the required accessibility standards.
HIGHLIGHTS
Online barriers for people with disabilities
Solutions to common website accessibility problems
Detailed review of recognized website accessibility guidelines
How ADA requirements affect mobile banking
Action plan to prepare for the necessary updates
TAKE-AWAY TOOLKIT
ADA website compliance checklist
ADA website compliance action plan
Employee training log
Quiz you can administer to measure staff learning and a separate answer key
Attendance verification for CE credits provided upon request.
WHO SHOULD ATTEND? Compliance officers, IT officers, marketing personnel, and staff responsible for website development and maintenance.
ABOUT THE PRESENTER – Dawn Kincaid, Brode Consulting Services, Inc., began her banking career while attending Ohio State University. She has fifteen years’ experience in client service, operations, information technology, administrative and board relations, marketing, and compliance. Most recently Dawn served as the Senior Vice President of Operations for a central-Ohio-based community bank, where she created and refined policies and procedures, conducted self-audits and risk assessments, and organized implementation of new products and services. Dawn has served in the roles of Compliance, BSA/AML, CRA, Privacy, and Security Officer. She has led training initiatives, prepared due diligence information, completed a variety of regulatory applications, and coordinated internal and external audits and exams.
(ON DEMAND) The Growing Scope of Vendor Management: Business Continuity, Cyber Security, Contract Negotiation & More
Email to order the Recording + Free Digital Download
Regulatory oversight and scrutiny of financial institutions’ third-party risk management practices have increased considerably. There is growing pressure on the risk management structure at every institution. Whether it’s heightened focus on cyber security, the need for more rigorous monitoring, or the basics of good vendor management, how can a responsible compliance manager keep up? This webinar will provide an overview of the regulations, real-life examiner expectations, and best practices from a vendor management perspective.
HIGHLIGHTS
Basic principles of vendor management
Review of regulatory authorities’ guidance
Common pitfalls and how to avoid them
Framework for creating a manageable and scalable third-party risk management program
TAKE-AWAY TOOLKIT
Cheat sheet on the core concepts of vendor management, including links to regulatory guidance
Vendor management due diligence checklist
Exam preparation e-book
Employee training log
Quiz you can administer to measure staff learning and a separate answer key
Attendance verification for CE credits provided upon request.
WHO SHOULD ATTEND? Compliance personnel, IT management, internal auditors, risk management staff, chief operating officers, and chief risk officers.
ABOUT THE PRESENTER – Branan Cooper, Venminder, Chief Risk Officer who has over 25 years’ experience in the financial industry with a focus on the management of internal processes and controls – most notably in third-party risk and operational compliance. Branan joined Venminder from Bancorp Bank where he was senior VP and Director of Third-Party Risk Management. He has held similar positions with PartnersFirst, the credit card division of Western Alliance Bancorp, and at MBNA America. A frequent speaker at industry events, Branan received his Bachelor’s from Duke University and completed the Graduate School of Retail Bank Management and the ABA’s Graduate School of Compliance Management.
Regulatory oversight and scrutiny of financial institutions’ third-party risk management practices have increased considerably. There is growing pressure on the risk management structure at every institution. Whether it’s heightened focus on cyber security, the need for more rigorous monitoring, or the basics of good vendor management, how can a responsible compliance manager keep up? This webinar will provide an overview of the regulations, real-life examiner expectations, and best practices from a vendor management perspective.
HIGHLIGHTS
Basic principles of vendor management
Review of regulatory authorities’ guidance
Common pitfalls and how to avoid them
Framework for creating a manageable and scalable third-party risk management program
TAKE-AWAY TOOLKIT
Cheat sheet on the core concepts of vendor management, including links to regulatory guidance
Vendor management due diligence checklist
Exam preparation e-book
Employee training log
Quiz you can administer to measure staff learning and a separate answer key
Attendance verification for CE credits provided upon request.
WHO SHOULD ATTEND? Compliance personnel, IT management, internal auditors, risk management staff, chief operating officers, and chief risk officers.
ABOUT THE PRESENTER – Branan Cooper, Venminder, Chief Risk Officer who has over 25 years’ experience in the financial industry with a focus on the management of internal processes and controls – most notably in third-party risk and operational compliance. Branan joined Venminder from Bancorp Bank where he was senior VP and Director of Third-Party Risk Management. He has held similar positions with PartnersFirst, the credit card division of Western Alliance Bancorp, and at MBNA America. A frequent speaker at industry events, Branan received his Bachelor’s from Duke University and completed the Graduate School of Retail Bank Management and the ABA’s Graduate School of Compliance Management.
Labels:
Auditors,
Compliance,
Cyber Security,
December,
IT,
Risk Management,
Vendor Management,
Webinar,
Webinars
(ON DEMAND) Director Series: What the Board Needs to Know to Manage IT
Email to Order the Recording + Free Digital Download
How much trouble would your institution be in if its computer systems could not be used for three days? Today’s financial institutions are tremendously dependent on their information systems – in fact they can’t live without them. Proper supervision, governance, and oversight are critical to the success of the bank.
This webinar will explore the directors’ role in providing governance and supervision related to IT management. It will address the necessary frequency and depth of risk assessments; how to structure a standards-based change management process; the core elements of a vulnerability monitoring and management program; and oversight of the incident response program.
HIGHLIGHTS
Review of the FFIEC’s updated guidance for IT risk management (ITRM) including risk identification and management
Change-management and exception-management processes:
System and software development life cycle
Vulnerability management
How to balance the institution’s needs within the constraints of vendor/service provider management
TAKE-AWAY TOOLKIT
Sample policies for vulnerability management
Sample table top exercise for testing your institution’s cyber-incident-response program
Employee training log
Quiz you can administer to measure staff learning and a separate answer key
Attendance verification for CE credits provided upon request.
WHO SHOULD ATTEND? Board members, CEOs, staff responsible for management and oversight of internal audit, IT audit, risk management, and operational management.
ABOUT THE PRESENTER – Randy Romes, CISSP, CRISC, MCP, CliftonLarsonAllen LLP, has been a consultant since 1999 and brings a strong background in computer technology, physics, and education. As a Principal in the Information Security Services Group, Randy leads a team of technology and industry specialists and is responsible for the continuing development of the open-source, Unix, and Windows applications used in security audits. Randy has been involved in developing numerous leading-edge hacking/testing methods and security service offerings. A featured speaker at national information and security management conferences, Randy holds multiple certifications, a Master’s in Educational Technology from the University of Saint Thomas, and a Bachelor’s in Education from the University of Wisconsin – Madison. In addition, he is an instructor at the Graduate School of Banking at the University of Colorado in Boulder.
How much trouble would your institution be in if its computer systems could not be used for three days? Today’s financial institutions are tremendously dependent on their information systems – in fact they can’t live without them. Proper supervision, governance, and oversight are critical to the success of the bank.
This webinar will explore the directors’ role in providing governance and supervision related to IT management. It will address the necessary frequency and depth of risk assessments; how to structure a standards-based change management process; the core elements of a vulnerability monitoring and management program; and oversight of the incident response program.
HIGHLIGHTS
Review of the FFIEC’s updated guidance for IT risk management (ITRM) including risk identification and management
Change-management and exception-management processes:
System and software development life cycle
Vulnerability management
How to balance the institution’s needs within the constraints of vendor/service provider management
TAKE-AWAY TOOLKIT
Sample policies for vulnerability management
Sample table top exercise for testing your institution’s cyber-incident-response program
Employee training log
Quiz you can administer to measure staff learning and a separate answer key
Attendance verification for CE credits provided upon request.
WHO SHOULD ATTEND? Board members, CEOs, staff responsible for management and oversight of internal audit, IT audit, risk management, and operational management.
ABOUT THE PRESENTER – Randy Romes, CISSP, CRISC, MCP, CliftonLarsonAllen LLP, has been a consultant since 1999 and brings a strong background in computer technology, physics, and education. As a Principal in the Information Security Services Group, Randy leads a team of technology and industry specialists and is responsible for the continuing development of the open-source, Unix, and Windows applications used in security audits. Randy has been involved in developing numerous leading-edge hacking/testing methods and security service offerings. A featured speaker at national information and security management conferences, Randy holds multiple certifications, a Master’s in Educational Technology from the University of Saint Thomas, and a Bachelor’s in Education from the University of Wisconsin – Madison. In addition, he is an instructor at the Graduate School of Banking at the University of Colorado in Boulder.
(ON DEMAND) Cyber Series: Customer Authentication & Validation: The New Normal in Risk Mitigation
Email to Order the Recording + Free Digital Download
Gone are the days when authenticating your accountholders included affirmation of mother’s maiden name, Social Security number, and date of birth. As the industry shifts to increased mobile and other remote electronic technologies, accountholder authentication and validation is no longer a table-stakes exercise. Rather, it is a strategically important enterprise-risk mitigation process. Unfortunately, fraudsters evolve along with technology. This webinar will identify a proactive and evolving accountholder authentication and validation framework through enhanced and proven procedures that thwart account takeover, identity theft, and monetary and reputational loss.
HIGHLIGHTS
Case study: how we fell victim to social engineering and the resulting changes to accountholder authentication and validation
BSA CIP onboarding requirements and authentication best practices
FFIEC guidance for multi-factor authentication
Something you know (password or passphrase)
Something you have (tokenization)
Something you are (biometric)
Pitfalls of self-authenticated commercial accountholder requests
High-level overview of NIST electronic authentication guideline
TAKE-AWAY TOOLKIT
Publication: FFIEC’s Authentication in an Internet Banking Environment
Publication: NIST Special Publication 800-63-2: Electronic Authentication Guideline
Wire transfer callback procedures
Employee training log
Quiz you can administer to measure staff learning and a separate answer key
Attendance verification for CE credits provided upon request.
WHO SHOULD ATTEND? Operations, frontline account opening, information technology, and information security personnel, as well as auditors, compliance staff, risk staff, board members, and audit committee members.
ABOUT THE PRESENTER – Brian Vitale, NCCO, CAMS-Audit, Compliance Advisory Services, earned his Political Science degree from North Central College in 1996 and an MBA from the University of Notre Dame in 2014. Brian was recruited by the National Security Division of the FBI where he specialized in counterterrorism and foreign counterintelligence. In addition, he is a decorated veteran who served in Guantanamo Bay, Cuba in the early 1990s. Subsequent to the FBI, Brian spent many years in banking and finance where his skills led him to the field of Global Operational Risk Management. He has over twenty years of banking, finance, and investigative experience. In July 2011, Brian joined a community financial institution and currently serves as their chief risk and compliance officer. He speaks nationally on BSA, anti-money laundering, enterprise risk management, cybersecurity, and strategy.
Gone are the days when authenticating your accountholders included affirmation of mother’s maiden name, Social Security number, and date of birth. As the industry shifts to increased mobile and other remote electronic technologies, accountholder authentication and validation is no longer a table-stakes exercise. Rather, it is a strategically important enterprise-risk mitigation process. Unfortunately, fraudsters evolve along with technology. This webinar will identify a proactive and evolving accountholder authentication and validation framework through enhanced and proven procedures that thwart account takeover, identity theft, and monetary and reputational loss.
HIGHLIGHTS
Case study: how we fell victim to social engineering and the resulting changes to accountholder authentication and validation
BSA CIP onboarding requirements and authentication best practices
FFIEC guidance for multi-factor authentication
Something you know (password or passphrase)
Something you have (tokenization)
Something you are (biometric)
Pitfalls of self-authenticated commercial accountholder requests
High-level overview of NIST electronic authentication guideline
TAKE-AWAY TOOLKIT
Publication: FFIEC’s Authentication in an Internet Banking Environment
Publication: NIST Special Publication 800-63-2: Electronic Authentication Guideline
Wire transfer callback procedures
Employee training log
Quiz you can administer to measure staff learning and a separate answer key
Attendance verification for CE credits provided upon request.
WHO SHOULD ATTEND? Operations, frontline account opening, information technology, and information security personnel, as well as auditors, compliance staff, risk staff, board members, and audit committee members.
ABOUT THE PRESENTER – Brian Vitale, NCCO, CAMS-Audit, Compliance Advisory Services, earned his Political Science degree from North Central College in 1996 and an MBA from the University of Notre Dame in 2014. Brian was recruited by the National Security Division of the FBI where he specialized in counterterrorism and foreign counterintelligence. In addition, he is a decorated veteran who served in Guantanamo Bay, Cuba in the early 1990s. Subsequent to the FBI, Brian spent many years in banking and finance where his skills led him to the field of Global Operational Risk Management. He has over twenty years of banking, finance, and investigative experience. In July 2011, Brian joined a community financial institution and currently serves as their chief risk and compliance officer. He speaks nationally on BSA, anti-money laundering, enterprise risk management, cybersecurity, and strategy.
Labels:
Audit Committee,
Auditors,
Board Members,
Cyber Series,
Frontline,
IT,
November,
Operations,
Risk,
Risk Staff,
Webinar,
Webinars
(ON DEMAND) E-Mail Risks, Rules, Records & Regulations
Email to Order Archived Webinar!
Much has changed since financial institutions first started using email two decades ago. Today’s email is not confined to office desktops and laptops. Employees use smartphones and tablets (institution-owned and personal) to transmit email, text messages, instant messages, and other forms of electronic messaging. Thus, the likelihood of legal, regulatory, security, and data breach disasters is greater than ever. Mobile device use can prompt FLSA overtime claims by employees claiming they were required to work off the clock and without pay.
Email records are of increasing concern, thanks to the pervasive use of mobile devices. There is mounting confusion about the preservation, protection, and production of business record email and other forms of electronically stored information. Email hacker attacks and data breaches can put financial institutions at risk of regulatory noncompliance, financial penalties, and negative publicity. Inappropriate email content can lead financial institutions into court, battling harassment, discrimination, and hostile work environment claims. Attend this webinar for an up-to-date look at email risks, rules, records, and regulations.
HIGHLIGHTS
What every financial institution needs to know about email use, content, records, and risks in 2016
How a strategic email management program can help anticipate and deflect legal liabilities, regulatory disasters, data breaches, and other email risks
Best practices to ensure legal, regulatory, and organizational compliance
Why and how you must preserve, protect, and produce email business records
Email business records versus transitory messaging
Email risks and rules apply to text messaging (mobile email) and IM (turbocharged email)
Establishing best practices-based email, FLSA, BYOD, and COPE policies
E-discovery risks and rules
How email policy supported by training and technology can help support your legal position
Best practices to manage email content and use at work, home, and on the road
Tips for effective email policy training
Monitoring rules: reconciling privacy expectations with legal realities
Real-life email disaster stories in the financial industry
TAKE-AWAY TOOLKIT
Article: What to Think About Before You Hit Send
Article: Writing Effective Email: Communications Channels Best Practices
Fact Sheet: Netiquette Rules
Employee training log
Quiz you can administer to measure staff learning and a separate answer key
Attendance verification for CE credits provided upon request.
WHO SHOULD ATTEND? Compliance officers, risk managers, records managers, branch managers, human resources staff, IT personnel, and others who manage the financial institution’s email system, policy, and records will benefit from this program. It will also be valuable for staff who use email for business communication.
ABOUT THE PRESENTER – Nancy Flynn, The ePolicy Institute™ , is a recognized expert on workplace policy, communication, and compliance, Nancy Flynn is the founder and executive director of The ePolicy Institute and Business Writing Institute. She provides training, coaching, and consulting services to clients seeking to minimize compliance risks and maximize communication skills. Nancy is the author of 13 books, including “Writing Effective E-Mail,” “The ePolicy Toolkit,” and “The Social Media Handbook.” An in-demand trainer, she conducts seminars, webinars, and one-on-one coaching for financial institutions, financial services firms, and other clients worldwide. She also serves as an expert witness in litigation related to workplace email and web use.
Much has changed since financial institutions first started using email two decades ago. Today’s email is not confined to office desktops and laptops. Employees use smartphones and tablets (institution-owned and personal) to transmit email, text messages, instant messages, and other forms of electronic messaging. Thus, the likelihood of legal, regulatory, security, and data breach disasters is greater than ever. Mobile device use can prompt FLSA overtime claims by employees claiming they were required to work off the clock and without pay.
Email records are of increasing concern, thanks to the pervasive use of mobile devices. There is mounting confusion about the preservation, protection, and production of business record email and other forms of electronically stored information. Email hacker attacks and data breaches can put financial institutions at risk of regulatory noncompliance, financial penalties, and negative publicity. Inappropriate email content can lead financial institutions into court, battling harassment, discrimination, and hostile work environment claims. Attend this webinar for an up-to-date look at email risks, rules, records, and regulations.
HIGHLIGHTS
What every financial institution needs to know about email use, content, records, and risks in 2016
How a strategic email management program can help anticipate and deflect legal liabilities, regulatory disasters, data breaches, and other email risks
Best practices to ensure legal, regulatory, and organizational compliance
Why and how you must preserve, protect, and produce email business records
Email business records versus transitory messaging
Email risks and rules apply to text messaging (mobile email) and IM (turbocharged email)
Establishing best practices-based email, FLSA, BYOD, and COPE policies
E-discovery risks and rules
How email policy supported by training and technology can help support your legal position
Best practices to manage email content and use at work, home, and on the road
Tips for effective email policy training
Monitoring rules: reconciling privacy expectations with legal realities
Real-life email disaster stories in the financial industry
TAKE-AWAY TOOLKIT
Article: What to Think About Before You Hit Send
Article: Writing Effective Email: Communications Channels Best Practices
Fact Sheet: Netiquette Rules
Employee training log
Quiz you can administer to measure staff learning and a separate answer key
Attendance verification for CE credits provided upon request.
WHO SHOULD ATTEND? Compliance officers, risk managers, records managers, branch managers, human resources staff, IT personnel, and others who manage the financial institution’s email system, policy, and records will benefit from this program. It will also be valuable for staff who use email for business communication.
ABOUT THE PRESENTER – Nancy Flynn, The ePolicy Institute™ , is a recognized expert on workplace policy, communication, and compliance, Nancy Flynn is the founder and executive director of The ePolicy Institute and Business Writing Institute. She provides training, coaching, and consulting services to clients seeking to minimize compliance risks and maximize communication skills. Nancy is the author of 13 books, including “Writing Effective E-Mail,” “The ePolicy Toolkit,” and “The Social Media Handbook.” An in-demand trainer, she conducts seminars, webinars, and one-on-one coaching for financial institutions, financial services firms, and other clients worldwide. She also serves as an expert witness in litigation related to workplace email and web use.
Labels:
August,
branch managers,
BYOD,
Compliance,
Compliance Officers,
COPE,
E-mail Risks,
Email,
FLSA,
HR,
IM,
IT,
risk managers,
Webinar,
Webinars
(ON DEMAND) New FFIEC Guidance on Mobile Financial Services: Evolving Delivery Channels vs. Risk Management Expectations
Email to Order Archived Webinar!
In April 2016, the FFIEC revised their IT Examination Handbook for Retail Payment Systems with the introduction of the new Appendix E: Mobile Financial Services. State and federal regulatory agencies and your internal auditors are almost certainly revising their audit scopes based on this new guidance. As such, expect your next electronic banking or information security audit to include an enterprise-wide risk management review to measure how effectively you manage and mitigate evolving mobile channel risks. This webinar will provide best-practice implementation guidance to flatten the regulatory expectation curve in establishing clear internal control risk assessment protocols to identify, measure, mitigate, and monitor these evolving mobile delivery channel risks.
HIGHLIGHTS
Overview and high-level breakdown of FFIEC’s IT Examination Handbook for Retail Payment Systems
Purpose, scope, and background of Retail Payment Systems new Appendix E: Mobile Financial Services
Definition of mobile financial services and evolution of multifactor approach to risk mitigation
The seven objectives of the Mobile Financial Services’ [Audit] Work-Program to identify your institution’s inherent mobile financial services risks measured against the adequacy of your internal and/or third-party controls
TAKE-AWAY TOOLKIT
Link to Retail Payment Systems new Appendix E: Mobile Financial Services
Sample mobile financial services risk assessment templates
Multifactor risk assessment template
Employee training log
Quiz you can administer to measure staff learning and a separate answer key
Attendance verification for CE credits provided upon request.
WHO SHOULD ATTEND? Electronic processing/information technology/information security personnel, as well as auditors, compliance staff, risk personnel, board members, and audit committee members.
ABOUT THE PRESENTER – Brian Vitale, NCCO, CAMS-Audit, Compliance Advisory Services, earned his Political Science degree from North Central College in 1996 and an MBA from the University of Notre Dame in 2014. Brian was recruited by the National Security Division of the FBI where he specialized in counterterrorism and foreign counterintelligence. In addition, he is a decorated veteran who served in Guantanamo Bay, Cuba in the early 1990s. Subsequent to the FBI, Brian spent many years in banking and finance where his skills led him to the field of Global Operational Risk Management. He has over twenty years of banking, finance, and investigative experience. In July 2011, Brian joined a community financial institution and currently serves as their chief risk and compliance officer. He speaks nationally on BSA, anti-money laundering, enterprise risk management, cybersecurity, and strategy.
In April 2016, the FFIEC revised their IT Examination Handbook for Retail Payment Systems with the introduction of the new Appendix E: Mobile Financial Services. State and federal regulatory agencies and your internal auditors are almost certainly revising their audit scopes based on this new guidance. As such, expect your next electronic banking or information security audit to include an enterprise-wide risk management review to measure how effectively you manage and mitigate evolving mobile channel risks. This webinar will provide best-practice implementation guidance to flatten the regulatory expectation curve in establishing clear internal control risk assessment protocols to identify, measure, mitigate, and monitor these evolving mobile delivery channel risks.
HIGHLIGHTS
Overview and high-level breakdown of FFIEC’s IT Examination Handbook for Retail Payment Systems
Purpose, scope, and background of Retail Payment Systems new Appendix E: Mobile Financial Services
Definition of mobile financial services and evolution of multifactor approach to risk mitigation
The seven objectives of the Mobile Financial Services’ [Audit] Work-Program to identify your institution’s inherent mobile financial services risks measured against the adequacy of your internal and/or third-party controls
TAKE-AWAY TOOLKIT
Link to Retail Payment Systems new Appendix E: Mobile Financial Services
Sample mobile financial services risk assessment templates
Multifactor risk assessment template
Employee training log
Quiz you can administer to measure staff learning and a separate answer key
Attendance verification for CE credits provided upon request.
WHO SHOULD ATTEND? Electronic processing/information technology/information security personnel, as well as auditors, compliance staff, risk personnel, board members, and audit committee members.
ABOUT THE PRESENTER – Brian Vitale, NCCO, CAMS-Audit, Compliance Advisory Services, earned his Political Science degree from North Central College in 1996 and an MBA from the University of Notre Dame in 2014. Brian was recruited by the National Security Division of the FBI where he specialized in counterterrorism and foreign counterintelligence. In addition, he is a decorated veteran who served in Guantanamo Bay, Cuba in the early 1990s. Subsequent to the FBI, Brian spent many years in banking and finance where his skills led him to the field of Global Operational Risk Management. He has over twenty years of banking, finance, and investigative experience. In July 2011, Brian joined a community financial institution and currently serves as their chief risk and compliance officer. He speaks nationally on BSA, anti-money laundering, enterprise risk management, cybersecurity, and strategy.
Labels:
Auditors,
Compliance,
EFIEC,
Financial Services,
IT,
July,
Risk Management,
Risk Personnel,
Webinar,
Webinars
Subscribe to:
Posts (Atom)