160 likes | 289 Views
FACTA ID Theft Programs. Auditing for Compliance Steven Nyren, CRCM Sheshunoff Consulting & Solutions BCAC Program – September 2008. ID Theft. “Obviously crime pays, or there’d be no crime” - G. Gordon Libby. The Challenge:. Each institution must develop and implement a program to:
E N D
FACTA ID Theft Programs Auditing for Compliance Steven Nyren, CRCM Sheshunoff Consulting & Solutions BCAC Program – September 2008
ID Theft “Obviously crime pays, or there’d be no crime” - G. Gordon Libby
The Challenge: Each institution must develop and implement a program to: • detect • prevent, and • mitigate identity theft
IDENTITY THEFT PROGRAMS THE $100,000 QUESTION: • How do we know we’ve accomplished our goal?
IDENTITY THEFT PROGRAM Ways to validate your program: • Monitoring • Audit
Monitoring Use of Periodic Reviews: • Monitoring Checklists, where applicable • Testing to confirm compliance • Performed by line unit and/or compliance professional • Object is to identify and resolve issues before an audit or exam
Validating the Program Auditing • More detailed scope and less frequent than monitoring • Independent perspective • May be conducted by Internal auditor and/or outside auditor or other qualified third party
Auditing for Compliance • Process Documentation • Risk Assessment • Controls • Response Program • Training • Administration
RED FLAG CHECK UP Are you ready for the examiners? • Is the Program fully documented? • Does it make sense? • Does practice match policy? • Is it effective?
Risk Assessment • Does it consider? • Methods of opening Covered Accounts • Methods of accessing Covered Accounts • The Bank’s history with identity theft • Current fraud controls • Inherent and residual risks • The Bank’s overall ID Theft risk
Controls • Are controls adequately documented? • Are all applicable red flags addressed? • Are they working as intended?
Response Program • Is the method of documenting response actions to red flag incidents adequate? • What is management’s oversight method – centralized; department level? • Are the responses adequate?
Training • Was it comprehensive? • Has it been documented? • Has it been completed?
Resources • Regulatory Guidance • Industry Websites (Bankersonline.com, ABA.com, etc.) • Seminars and webinars
Can It All Be Done? “Energy and persistence conquer all things.” - Benjamin Franklin
Conclusion • Questions?