Featured Product

    FFIEC Issues Booklet on Risk Management Process for IT Infrastructure

    June 30, 2021

    FFIEC issued the "Architecture, Infrastructure, and Operations" booklet of the FFIEC Information Technology Examination Handbook. This booklet provides guidance to examiners on risk management processes that promote sound and controlled execution of information technology architecture, infrastructure, and operations at financial institutions. The examination procedures in this booklet help examiners evaluate an institution’s controls and risk management processes relative to the risks of technology systems and operations that reside in, or are connected to, the institution. The booklet replaces the Operations booklet issued in July 2004.

    The "Architecture, Infrastructure, and Operations" booklet focuses on enterprise-wide, process-oriented approaches that relate to the design of technology within the overall business structure, implementation of IT infrastructure components, and delivery of services and value for customers. The booklet discusses the principles and practices for IT and operations as they relate to safety and soundness, consumer financial protection, and compliance with applicable laws and regulations. It also discusses the management oversight of architecture, infrastructure, and operations and its related components that examiners may encounter during their reviews; these related components include governance; common risk management topics; specific activities of architecture, infrastructure, and operations; and the evolving technologies such as cloud computing, microservices, artificial intelligence, and zero trust architecture. The booklet explains that architecture, infrastructure, and operations are separate but related functions that, together, assist management in overseeing activities related to designing, building, and managing the technology of an entity. It also discusses how appropriate governance of the architecture, infrastructure, and operations functions and related activities can

    • promote risk identification across banks, nonbank financial institutions, bank holding companies, and third-party service providers.
    • support implementation of effective risk management.
    • assist management through the regular assessment of the strategies and plans of an entity
    • promote alignment and integration between the functions.

     

    Related Links

    Keywords: Americas, US, Banking, Governance, Technology Risk, Third-Party Service Providers, Information Technology, Cloud Computing, IT Handbook, FFIEC

    Related Articles
    News

    ESAs Issue Multiple Regulatory Updates for Financial Sector Entities

    The three European Supervisory Authorities (ESAs) issued a letter to inform about delay in the Sustainable Finance Disclosure Regulation (SFDR) mandate, along with a Call for Evidence on greenwashing practices.

    November 15, 2022 WebPage Regulatory News
    News

    ISSB Makes Announcements at COP27; IASB to Propose IFRS 9 Amendments

    The International Sustainability Standards Board (ISSB) of the IFRS Foundations made several announcements at COP27 and with respect to its work on the sustainability standards.

    November 10, 2022 WebPage Regulatory News
    News

    IOSCO Prioritizes Green Disclosures, Greenwashing, and Carbon Markets

    The International Organization for Securities Commissions (IOSCO), at COP27, outlined the regulatory priorities for sustainability disclosures, mitigation of greenwashing, and promotion of integrity in carbon markets.

    November 09, 2022 WebPage Regulatory News
    News

    EBA Finalizes Methodology for Stress Tests, Issues Other Updates

    The European Banking Authority (EBA) issued a statement in the context of COP27, clarified the operationalization of intermediate EU parent undertakings (IPUs) of third-country groups

    November 09, 2022 WebPage Regulatory News
    News

    OSFI Sets Out Work Priorities and Reporting Updates for Banks

    The Office of the Superintendent of Financial Institutions (OSFI) published an annual report on its activities, a report on forward-looking work.

    November 07, 2022 WebPage Regulatory News
    News

    APRA Finalizes Changes to Capital Framework, Issues Other Updates

    The Australian Prudential Regulation Authority (APRA) finalized amendments to the capital framework, announced a review of the prudential framework for groups.

    November 03, 2022 WebPage Regulatory News
    News

    BIS Hub and Central Banks Conduct CBDC and DeFI Pilots

    The Bank for International Settlements (BIS) Innovation Hubs and several central banks are working together on various central bank digital currency (CBDC) pilots.

    November 03, 2022 WebPage Regulatory News
    News

    ECB Sets Deadline for Banks to Meet Its Climate Risk Expectations

    The European Central Bank (ECB) published the results of its thematic review, which shows that banks are still far from adequately managing climate and environmental risks.

    November 02, 2022 WebPage Regulatory News
    News

    ESAs, ECB, & EC Issue Multiple Regulatory Updates for Financial Sector

    Among its recent publications, the European Banking Authority (EBA) published the final standards and guidelines on interest rate risk arising from non-trading book activities (IRRBB)

    October 31, 2022 WebPage Regulatory News
    News

    EC Adopts Final Rules Under CRR, BRRD, and Crowdfunding Regulation

    The European Commission (EC) recently adopted regulations with respect to the calculation of own funds requirements for market risk, the prudential treatment of global systemically important institutions (G-SIIs)

    October 26, 2022 WebPage Regulatory News
    RESULTS 1 - 10 OF 8582