Who Handles your Vendor Management?

Managing the vendors your financial institution does business with is important but it can be time consuming and a stressful project. Some institutions have decided to let third parties manage the risk assessment and vendor due diligence process rather than do it on their own. Strunk’s Vendor Manager solution makes it easy to do risk assessments, manage contracts and other vendor documents and to obtain necessary annual information to ensure risks associated with vendors you do business with is managed appropriately.

Our program provides: 1) A repository of information on each vendor you do business with and 2) The ability to do consistent risk assessments for each vendor. Maintaining a list of key vendor relationships, contracts, insurance certificates, security policies, and other documentation is critical to vendor management. The tickler system notifies the individual assigned to the vendor when contracts come up for renewal or when other documents are due.

Vendor risk assessments can be a hassle and our solution takes a standard approach to ensure the process is consistent and thorough based on the risk (critical, high, moderate or low) per regulatory guidelines. For critical and high risk vendors additional information is obtained from those vendors to complete the risk assessment.

Vendor Management is imperative at all financial institutions and Strunk’s Vendor Manager Solution may be just what you are looking for. Take back the process from outside vendors or make internal vendor due diligence easy and consistent to manage.

Is risk always bad?

In our industry we are accustomed to thinking of risk as something we need to constantly assess and evaluate. At best, this exercise can be laborious and time-consuming. The number of risk factors to consider can run into the hundreds, often with different parts of the organization best qualified to assess each risk. The typical solution, emailing spreadsheets around the organization, is inherently cumbersome and error-prone.

Let’s take a step back and break down what a risk is. The definition of risk is a situation involving exposure to danger. But danger does not always look like we might expect. There is an important distinction to be made as some risks can actually pose a benefit to any company while others cause a greater reason for concern. Without risk, it can become easy to settle into consistency, security and stability.

Wouldn’t you like to know the importance of the risks you face and be able to easily identify them? Strunk’s Risk Manager can help identify risks you may be considering to help grow your business, as well as those risks that may present a greater threat to your organization. It helps to answer the questions:

  • What factors must financial institutions manage against?
  • At this point in time how much risk is each factor creating for us?
  • Do we have adequate management measures in place to manage the inherent risk?
  • And what is the trend – is our situation improving or getting worse?

Risk Manager tracks your risks in a database with fine-grained control over access. It documents your assessment of the inherent risk, the strength of your management of the risk and trend for both. If you must respond to a standards-based set of risks like banking industry requirements or SOC2, explicitly score yourself against these frameworks. The solution will map your policies against control activities to be sure you have appropriate policies in place that address each risk and will allow you to track your risk profile over time.

If you would like to bring together all areas of the risk assessment process into one easy to use format and eliminate your dependency on Excel spreadsheets, invest just 30 minutes to review our solution. Contact us at info@strunkaccess.com to learn more.

Strunk Solution Fall 2020 Features

With Strunk’s most recent release, clients can now utilize new features in Risk Assessor, Policy Manager, Controls Manager, Vendor Manager, Skills Manager and ODP Manager. We’ve been busy!

Risk Assessor now provides the ability to pull multiple bank UBPR Data into one single risk assessment. This will simplify assessments for multi-bank holding companies.

Criteria based auto assignment for reader and editor groups is now available in Policy Manager. Users are able to assign specific documents based on physical location or job title, where assignment of a set of policies and procedures could dynamically change based on these rules. We have also adjusted the way the policy acknowledgement is assigned. Admin users have the ability to request that users read a policy at a configurable number of days in the event that a policy is updated throughout the year, rather than just every 365 days. Users will be notified of necessary policies to review via email.

Controls Manager now supports notification of the group owner rather than simply the control owner. Alerts will be triggered any time a significant change or update is made to a control.

Clients will be excited to see the improvements to Vendor Manager reporting. Users can sort by a customized list of vendor types, vendor risk level and renewal year within all summary reports. Reports will also include whether or not the vendor survey has been completed and if not, what the current status is.

Skills Manager exams have historically been comprised of multiple choice or true false questions. We now support the option to have an open ended comment for specified questions.

Lastly, ODP Manager provides the ability to mark old status codes as inactive or deleted so they no longer show on reports, such as the Status Tracking Report.

If you would like more information on any of Strunk’s new features or products, please contact us at 800.728.3116 or support@strunklp.com.

Is it time for your company’s next SOC 2 examination?

If your company is like Strunk, then a SOC 2 exam is an annual topic of conversation and the certification from your CPA firm is something you proudly provide your clients. At Strunk we have built a full-featured solution to help not only manage the policies your organization follows but to tie those policies back to the AICPA’s criteria and to your company’s own internal control procedures.

A SOC 2 audit can be time consuming, frustrating and burdensome. Strunk’s Policy Manager and Controls Manager modules can put much needed structure around this process. We keep on top of changes to the AICPA criteria so that you don’t have to. If changes need to be made to your existing policies as a result of any of these updates, you can easily address those within our software, and all modifications and approvals will be captured in our logs. The application will remind specific users within your organization when control activities need to be tested and the solution even supports breaking up this activity throughout the year so that your team is not focused on such a large task all at once.

The implementation with Strunk is extremely straightforward. Your company will submit your current policies for upload and creation within our system. If you are missing policies in any area we will provide you with a template document for you to customize but you will not need to start from scratch! We will work with your team to map these documents to the AICPA criteria in our solution.

Most companies are using Excel to track control activities. We ask that you simply provide this list of test procedures and we will set them up within the solution as well. Our Policy Map will provide a linked relationship from criteria to policies to controls. Once all of your company specific information has been uploaded and created we will host a training webinar for your team. It’s that simple.

Let Strunk help simplify and organize this process for you so that you can focus on what you do best – serving your clients.

Testing Employee Policy Knowledge

How often do you check to see if your employees know what polices or procedures your financial institution has in place? Security and ethics policies should be read from time to time and compliance to those policies should be tracked.

Strunk’s Skills Manager program is one module of our overall Risk Management solution. It gives you the ability to set up templates for course study, take tests to ensure knowledge of a policy or procedure and track the results of the tests to provide a pass/fail result.

Skills Manager is a unique tool that can be used by the human resources department for company-wide deployment or by individual departments of your organization. Power Point slides can be imported and set up to discuss product knowledge and then each employee can be assigned a test to see if they were knowledgeable of certain policies and procedures.

The tracking of the results within Skills Manager is important for audits and certifications. Through Strunk’s Policy Manager solution, reader logs can be tracked to ensure that your employees are reading pertinent policies. Then through Skills Manager you can test to see if your employees understand those policies.

Strunk’s solution to risk management includes Risk Assessor, Policy Manager, Controls Manager, Vendor Manager, Issues Manager and Skills Manager along with our Overdraft Privilege Manager program. Contact us to learn more.

Ensure Contract Completeness with Strunk’s Contract Review

Having a well written contract with your vendor is a critical aspect in your vendor manager life cycle.  The contract is important as it sets forth the terms and conditions of the relationship with the vendor.  Vendor contracts are legal agreements that clearly set forth the provisions and conditions of the work or services that the vendor provides.  Because the contract is the foundation for the relationship with the vendor, a complete contract review should be done before the agreement is signed.

Strunk has created a Contract Review feature in our Vendor Manager solution to help ensure your contract does not have any gaps and that each provision is understood with clear expectations.  Contract Review will assist in clearly identifying what each party’s role is and who is responsible for each area.  This will prevent any issue between the financial institution and the vendor.  Regulations require that contracts contain key provisions such as confidentiality, service level agreements, and mutual rights and responsibilities.  A thorough review of your vendor contract should be done both prior to signing a new contract and while reviewing existing contracts for renewals.  Strunk’s Vendor Contract Review will help clients address significant risk controls and regulatory compliance within each of their vendors activities.

Are your User Accounts up-to-date?

Part of effectively using Strunk’s cloud-based Governance, Risk Management and Compliance software is regularly reviewing, maintaining, and updating your user records and access. Our software provides your administrators with tools to make this process easier, rather than updating user records one by one. However, admins always have the option to view and change an individual user’s record and access rights.

A list of all users can be exported as a PDF for reporting purposes. In addition to the basic user information, it also includes each user’s roles and last login. To simplify adding new users and deactivating former employees, an automatic User file import can be set up. Once configured, a file containing all current users will be uploaded and processed on a scheduled basis. This allows you to add and deactivate users in a timely manner.

For other maintenance of existing users, admins can export the current user list to an Excel file. Any necessary updates can be made directly in the file and an admin will import the updated file to make the appropriate changes in the software.

Please contact Strunk Support at support@strunkaccess.com with any questions or for training on these helpful features. It is easier than ever before to keep your information up to date.

Solve your SOC 2 Anxiety

Getting a SOC 2 report and examination is only part of the battle, keeping up with your stated obligations and consistent re-examination means your company has to live a SOC 2 life.  Throughout the year testing, reviewing, and revising controls can take up a substantial portion of time and attention.  Utilizing Excel spreadsheets, PDFs, and Word docs can lead to a nightmare for version control and compatibility issues.  Utilizing proven techniques to manage your SOC 2 can and will cut down on your time utilization and stress surrounding your consistent re-examination.
The average SOC 2 examination can take around a month of document negotiations with your auditors, followed by a week in house exam.  Utilizing a strong system that contains all of your pertinent information empowers your auditors with easy access to vital information while having a minimal impact on your daily routine.  This information flow, allows your auditors to see your control framework, and testing schedules, as well as the results and evidence for those tests, giving the auditors nearly a perfect picture of your company’s readiness.
While the perfect SOC 2 examination can be hard to attain, it shouldn’t be difficult to maintain. Strunk’s GRC is one of the few tools that help to walk your company from new SOC 2 to expert, our tools are able to help inform your process and reduce the time and effort you pay toward yearly SOC 2 obligations.  Our platform has a full set of template SOC 2 policies and controls, as well as one of the most thoughtfully crafted framework management systems on the market.

Power your team through continuing education with Strunk’s Skills Manager

If you are a Risk Assessor or Policy Manager user today, you may not be aware that Skills Manager is packaged with your solution. In order for your organization policies to be effective, your employees need to know the material. Skills Manager also lets you determine if your employees remember key aspects of those policies by periodically testing employee knowledge.

Through its Courses feature Skills Manager provides simple online training experiences to help your employees brush up on key policy details. For this online training you are able to create a library of training slides, either from text or exported from PowerPoint. You then will combine slides to develop courses and assign courses to your employees. It’s that simple! Users will then take courses via our online portal, with the ability to stop and pick up where they left off as needed prior to the due date.

Once Courses are complete you can then use the Exams module to test employee knowledge. Like Courses, you will create a library of exam questions that you can then assign to exams and then exams to users. Subsequently you will set parameters for frequency with which users must take exams and set parameters for a passing score or merit score. Your employees can show their knowledge of the material within each Course.

Strunk CEO Dan Roderick says “We launched Skills Manager V2 earlier this month and it’s easier to use than ever! It’s a great way to test employee policy knowledge and document results – particularly on those policies where periodic employee acknowledgement is required.”

Skills Manager also contains a user searchable document library for storing relevant reference materials that can be used as needed throughout the year.

The importance of a thorough risk management process

Managing risk is a fundamental process for any business and is crucial to achieve ongoing success for any company. Strunk’s Risk Manager solution provides a systematic process to ensure that you organization 1) knows your risks, 2) has policies to mitigate key risks, 3) is able to verify that policies are followed, and 4) can easily prove to others – management, board, examiners – that you follow this structured process. Risks may hinder or even prevent your business from achieving its goals, cause operational disruption, financial loss, or escalating cost. By performing a risk assessment, you can mitigate key risk indicators by taking them into account early on and developing action plans to reduce and effectively manage risk.

Risk management should not be confined to just one department in the organization or be the sole responsibility of a certain group of employees – it should be an integral part of everyone’s job. Strunk’s Risk Manager software will allow you to involve as many individuals in your organization as you like in the risk management process, keep all of the key components of your risk management process in one place, and gain a better understanding of the nature of the risks facing your organization. Many Risk Manager clients only use one or two modules but are not making full use of the entire solution. By using all of the modules in Risk Manager it will help you establish a more cohesive and stronger risk management environment. The new Version 2 of Risk Assessor is available and can help streamline your risk assessment process even further and save time. If you are a client that currently has Version 1, Strunk can help transfer results from Version 1 into Version 2 for no additional cost. Also, if you have staff members that have not yet been trained on any of the Risk Manager modules because they are new or their job responsibilities have changed, Strunk will do additional web based training for no additional charge.