Skip to content

Industry

Financial services and credit unions

The controls here look like those in any well run business. The difference is evidence: an examiner asks you to demonstrate that a control operated throughout a period, not that it is switched on today. That single requirement shapes how everything gets configured.

What examiners actually test

Evidence over time

not configuration today

A control switched on last week rarely satisfies a requirement to demonstrate it operated all year.

Six obligations that shape the build

Financial services IT obligations and what each requires
ObligationWhat it covers
GLBA SafeguardsThe baseline obligation for anyone holding customer financial informationWritten programme, named accountable individual, risk assessment
Examination readinessExaminers test whether controls operate, not whether they exist on paperEvidence produced on demand, not assembled on request
Vendor oversightYour IT provider is a vendor subject to this, including their own controlsDue diligence and contractual security obligations
Incident notificationThe clock starts at discovery, so detection speed has regulatory consequencesDefined timeframes to regulators and members
Access control and reviewStanding access is a recurring examination findingLeast privilege over member data, periodically reviewed
Business continuityTesting evidence is required, not just a plan documentTested, documented, with defined recovery objectives

General information about regulatory expectations, not legal advice. Confirm your specific obligations with counsel or your regulator.

Five recurring findings

Each of these describes an institution doing the right thing and being unable to prove it.

  • A risk assessment that exists but has not been updated since the environment changed
  • Access reviews scheduled but not evidenced, so nobody can show they happened
  • Vendor due diligence performed at onboarding and never repeated
  • A business continuity plan that has never been tested, or tested without a record
  • Multi factor authentication deployed on most systems but not all, with no documented exception

Evidence should be a by-product

The failure pattern in this sector is not weak controls, it is controls that operate informally. Access genuinely is reviewed, because a manager looks at the list every few months. Backups genuinely are tested, because someone tried a restore last spring. Neither is recorded.

The fix is to make the record automatic. Access reviews run on a schedule with a logged sign off. Restore tests produce a report filed without anyone deciding to file it. Change management captures who approved what and when as part of doing the change rather than as a separate task.

Set up that way, examination preparation stops being a project and becomes a matter of retrieving what already exists.

Common questions

Answered before you ask.

How is this different from ordinary managed IT?

The technical controls are broadly the same. What differs is that everything has to be evidenced and repeatable, because an examiner will ask you to demonstrate that a control operated over a period rather than that it is configured today. That changes how logging, access review and change management are set up from the beginning, and it makes documentation a deliverable rather than a by-product.

Our core banking provider handles security. What is left for us?

Everything outside the core. Your network, workstations, email, identities, staff devices and any system that connects to the core remain your responsibility, and they are where incidents in this sector generally begin. The core provider's certification covers their platform. It does not transfer your obligations, and examiners will look at your side of the line specifically.

How quickly do we have to report an incident?

That depends on the regulator, the type of institution and the nature of the incident, and the timeframes have generally been tightening. What matters operationally is that the clock typically starts at discovery, which means detection capability has direct regulatory consequences. An institution that finds an incident in an hour is in a materially different position from one that finds it in a fortnight, before anything else is considered.

Can an IT provider support us through an examination?

For the technology portion, yes. That means producing evidence of technical controls, answering technical questions directly and remediating technical findings on a defined timeline. The examination itself remains the institution's responsibility and the accountable individual has to be internal. What a provider removes is the scramble to assemble evidence, by having it accumulate continuously instead.

Get an examination readiness review.

Which technical controls you can evidence today, which you cannot, and what it takes to close the gap. Written findings either way.

CallFree assessment