No better time to implement a Cloud-Based GRC Solution

Over recent weeks, the ongoing spread of the COVID-19 coronavirus has forced companies around the country to make difficult decisions about how to protect their employees — as well as their communities as a whole.  In an effort to halt the spread of the virus, many organizations are instituting mandatory work-from-home (WFH) policies, engaging with new cloud service providers, and shifting resources toward supporting an expanding remote workforce.  The fast-moving, global reach of the coronavirus has illustrated that a forward-looking approach to risk management is more important than ever. Having a cloud-based tool that streamlines your compliance process should be in all companies’ future strategic discussions.

Strunk offers many great automated cloud-based solutions tools that streamlines compliance and risk management for our clients.  There are many benefits to these cloud-based solutions, especially in today’s environment where some many employees are working from home.  Our software is simple to implement, easy to access, very flexible and is reliable in terms of backing up data for your employees who are at different locations.  Implementing Strunk’s Risk Assessor, Policy Manager, Issue Manager and Vendor Manager software does not require extra hardware or software.  Implementing these tools can be done while business continues as usual which requires no downtime at all.  Strunk has created a new Version 2 of our Risk Assessor which is available to everyone.  Risk Assessor helps our clients complete risk assessments consistent with appropriate regulatory or standards body frameworks in days, instead of weeks.  Clients are able to upgrade for free from Version 1 to Version 2 and Strunk will help transfer results from your current Version 1 assessments.

Given the current coronavirus pandemic, the need for companies to centralize their policies and vendor management is more critical than ever.  Strunk’s Policy Manager software will organize hundreds of policy documents spread across different computer and file systems into a single editable database. With employees working remote, Policy Manager gives employee access to the companies polices for easy access and with the established review dates the system will remind employees to review the policy and make changes.  Centralizing your vendor manager process with Strunk’s Vendor Manager software will automate the process which reduces administrative burden and save time while giving employees who are working remote access to vendor due diligence, providing a practical framework for deciding which vendors to assess in depth, assessing the risks each vendor present, and the monitoring of each vendor performance.

Also, Strunk is offering additional free web training for our client’s employees.  There is no better time than now to get employees who are new or have changed job responsibilities trained on any of Strunk’s GRC software.

Strunk Policy Manager Software Now Includes GRC Policy Templates

In 2015 Strunk launched Risk Manager which has now evolved into a full featured Governance, Risk Management, and Compliance (GRC) solution including Risk Assessor, Policy Manager, Controls Manager, Vendor Manager, Issues Manager, and Skills Manager tools.  Today, as an added service for Risk Manager clients, we are announcing the availability of standard template policies for banks, credit unions, investment advisory firms and broker-dealers.

Policy requirements evolve, and often times organizations find that their existing policy has become outdated, or they don’t have a policy at all to address a particular issue.  No one wants to write a new policy from scratch – particularly regarding a complex issue. So, starting with a vetted template and customizing it to your particular organization is a big benefit both in terms of making sure the policy is complete and saving time. There are a variety of companies that provide policy templates for a fee.  But with Strunk, they are free for Risk Manager clients.

Dan Roderick, Strunk CEO said, ‘Clients have been asking us for quite some time if we can provide them with a specific policy that they don’t currently have in their existing policy manual and each time we would track down a template example for them.  Now we have assembled a database of standard documents to respond to those requests.  In fact, if a client were to ask for an entire manual of standard policies, we can now easily provide those documents.  Policy Manager has been one of the most popular components of the Risk Manager solution – it was the first module we developed five years ago.  This should be a valuable enhancement to our GRC solution.’  The current COVID-19 crisis is one example of an event that can create a need for a new or more thorough policy.  The Pandemic Policy and Plan documents have been frequently requested during the past month.

Policy Management Made Easy

Banks are required to have each and every policy approved by the board of directors on an annual basis. Many financial institutions keep their policies in Word or PDF documents on the back credenza of the officer in charge of each area of the bank. Operational and compliance policies are in the operations area of the bank; lending policies are in the chief lending officer’s file cabinet and accounting policies on the cashier’s desk.

On average, banks have between 40-60 policies that are reviewed throughout the year by the bank’s board and any changes to the policies are updated after board approval. This process can be cumbersome and hectic for most community banks. It doesn’t have to be that way!

Strunk has put together a terrific solution for managing the annual review and policy approval process. Rather than maintaining separate folders of policies, why not have them in one place with access to those who need to read, make changes, or review them periodically? That is what Strunk’s Policy Manager Program does.

Keeping a log of changes for senior management, outside auditors, or the regulators is important. Making updates or changes to policies should be easy to do. Redlined copies of the policies go to the board for approval. Your board only wants to review changes made to policies, not the entire policy. Strunk’s solution does all of this and policies are put into chapters based on each functional area of the bank. You send us your policies; we do all of the work. Access to each policy is given based on user access code. Contact us for a quick demo of the cost effective, yet comprehensive Policy Manager solution.

Cybersecurity Maturity Model Certification (CMMC) Audits Made Easy

Recently the US Federal Government announced plans to impose a cybersecurity audit and certificate program referred to as the Cybersecurity Maturity Model Certification (CMMC), which will be used as a standard requirement for all firms dealing with DoD data.  The CMMC closely follows established frameworks pulling heavily from the NIST CMF and 800-171 publications.  The obvious advantages of using a ubiquitous framework and assessment to ensure compliance with these new regulations helps to reinforce many of the best practices that firms in this space should have already been following.

Each firm must record their policies, procedures, and controls related to the NIST frameworks, showing a clearly delineated map of these relationships for auditors to follow, test, and critique.  The DoD recently announced that they plan to start the audit process in 2020 with more than 60% of firms expected to have completed their requirements by the end of the year.  This leaves firms with sparse time to evaluate and immortalize their processes, with a narrow window to fix non-compliant or lacking areas of their cybersecurity framework.

These moves by the Federal Government and the DoD are being widely celebrated by the cyber defense industry as a win against unintentional release of classified information, and as strong guidance for the industry to help ensure a curb in the currently vulnerable industry.  With a long history of leaks, and hacks, the government consulting and data analytics firms, that make up much of the cyber defense of the country, will be helping to ensure our enemies have one less tool to utilize.

With StrunkAccess Risk and Policy Manager consulting firms are finding a tool that can help navigate through the complicated process of becoming compliant with risk frameworks, helping to protect their companies and clients.  From SOC 2 to NIST to any risk framework, StrunkAccess is an elegant solution utilized to help hundreds of companies evaluate, record, and manage their risks.

Incident Reporting in the Modern Age

As web-based applications started to gain steam bugs, issues, and upgrades became a discussion point around best practices to document and distribute this vital information. With more and more sophisticated ways to streamline communication, release timelines, and as a snapshot of the backlog your team needs to complete, the usefulness of the applications started to become more appealing to industries outside of software development.  From software companies to audit firms to financial firms, closely followed and documented issue response is the most effective and indelible way to ensure your company is addressing all of your issues, from simple to complex.

The growth of users around a few big-name players is projected to explode over the next 5 years, leading to a consolidation of options, creating a homogenous and, in many cases, expensive reality.  In 2019 the average cost of Incident Reporting software was around $3,500/mo.  This mammoth monthly bill is only expected to grow over the next 5 years as firms become more entrenched in their default systems.  The sad fact is much of this Incident Reporting Software hides features behind micro-transactional pricing structures meant to increase the price for marginal benefits as your company grows.

At Strunk we develop tools meant to provide maximum value and functionality, highlighted by our renowned Risk and Compliance tools and Management Efficiency tools, like Issues Manager and Skill Manager. We believe, delivering the tools we love to use to our clients, provides the best outcome for all.  Like all of our tools and modules, Incident Reporting is included with the StrunkAccess GRC suite at no additional cost.  Sign up for a Demo to see all that StrunkAccess has to offer.

Strunk Reports Record Sales

Strunk is proud to report that October was the highest volume software sales month in our history. In addition, October 2019 YTD sales of Risk Manager, our Governance, Risk Management and Compliance management solution, are already up almost 50% relative to full-year 2018. New clients in October range in asset size from just under $100 million to over $1.2 billion.

This success was fueled by Strunk’s strategy to offer a broad range of services, allowing clients to purchase all of our GRC modules, including Risk Assessor, Policy Manager, Controls Manager, Skills Manager, Issues Manager, Vendor Manager plus our hosted ODP Manager software for one affordable price. Clients also signed up for Overdraft Privilege program reviews and implementation of new Overdraft programs.

Strunk CEO Dan Roderick commented, “In just one month we were able to add a record number of new clients across every line of our business and a broad range of software solutions. From my perspective, this is what it’s all about – providing full-featured, easy-to-use tools that also offer clients great value. Our sales team has really knocked it out of the park!”

With Strunk’s Governance, Risk Management, and Compliance (GRC) solution suite clients can greatly enhance internal control and risk management processes and save time. The suite includes:

  • Vendor Manager is a specialized tool for managing vendor risk that standardizes risk assessment methodology and organizes all vendor related documentation.
  • Risk Assessor helps prepare comprehensive risk assessments consistent with regulatory or other requirements, in days, not weeks.
  • Policy Manager organizes all existing policies into a single database, mapped to the relevant standards and control procedures.
  • Controls Manager schedules tests of policy compliance and tracks test results.
  • Issues Manager is a centralized database for tracking all compliance issues and incidents across your entire organization.
  • Skills Manager provides online testing and training to ensure employees are knowledgeable about the organization’s policies.

In addition to our GRC solutions, financial institutions should periodically review their overdraft program to ensure they are not using policies and procedures that are non-compliant with current laws and regulations. Strunk’s comprehensive Overdraft Privilege Program review includes recommendations to increase fee income and ensure compliance. Additionally, clients receive access to our state-of-the-art program management software, ODP Manager.

Doing Risk Assessments Doesn’t Have to be Daunting

Community banks across the county struggle with the risk assessment process and generally they come in the form of Excel Spreadsheets or Word documents. Each functional area of the bank does their regulatory required risk assessment in silo’s and periodically the bank’s board reviews and approves the assessment.

Regulatory scrutiny of BSA/AML, ACH, Fair Lending, Loan Concentrations, Cybersecurity, Information Technology and other areas of the bank have caused financial institutions to spend more time and money focusing on the risks the bank faces. Some banks have declared their compliance officer the chief risk officer as a way to show the regulators that they are on top of enterprise risk management.

Outsourcing some of these functions to vendors is an expensive way to manage the risk assessment process and certainly unnecessary. Strunk’s GRC (Governance, Risk Management and Compliance) solution makes the risk assessment process easy to do and it consolidates all areas of risk the bank faces into one report.

Bank examiners often tell the community bank that they are coming out for the annual exam six weeks to two months prior to actually showing up. Generally, they ask the bank to send an extensive amount of information prior to coming onsite. This gives the regulator time to form their opinion on what risks the bank faces before arriving at the bank.

Strunk’s solution lets the bank tell their story rather than have the regulator tell the bank’s story to them. Comprehensive risk assessments are made easy with Strunk’s GRC and Vendor Management solution.

SOC 2 for Companies vs CPA Firms

SOC 2 reports are becoming ubiquitous for businesses in the B2B market, creating a shared confidence that best business practices are followed and systems are developed with security and data privacy in mind.  StrunkAccess GRC provides a unique SOC 2 experience, and through our conversations with clients we have seen that predictably CPA firms have a much different view of the SOC 2 vs Companies required to have them.

Companies

To compete in today’s market a company must be able to satisfy their customers’ needs.  With many companies now requiring 3rd party verifications from their vendors, the go to responses are an assessment based on how integrated the vendor is within the operations of the requesting company and a SOC 2 report.  From a company’s perspective a SOC 2 is really just a means to lubricate the sales processes and removing barriers or objections to the perspective business.  While a SOC 2 audit can add value to a company by solidifying policies, procedures and controls, the overwhelming sense our clients have relayed to us is a SOC 2 is necessary to help increase their bottom line by doing business with more sophisticated entities.

CPA Firms

While the SOC 2 has been a big boom to the bottom line of CPA firms, many firms realize SOC 2 readiness is a time consuming and onerous process for their clients.  It also winds up delaying the SOC 2 process more than any other part of the audit, especially for first time SOC 2 participants.  Because of this CPA firms concentrate on giving companies tools and examples that can help them fill gaps in their organizational structure.  The issue arises that before a SOC 2 audit no company is fully ready, all companies need to add policies or modify existing policies to close gaps and follow the general outline of the SOC 2 trust principles.  The biggest divergence that we see here is that the CPA controls for SOC 2 vary from firm to firm and can create a maze that is hard for companies to follow, even though the process with the CPA firm may be well established.  The big difference here is that CPA firms are looking at a SOC 2 as an ends, where as companies view them as a means to an end.

Technology Service Provider Contracts

Understanding the increase dependence that financial institutions have on technology service providers, bank regulators have increased their efforts to require banks to appropriately handle third-party risk management.  The Federal Deposit Insurance Corporation (FDIC) has identified gaps noted by some examiners regarding several technology service provider contracts that were inadequate under existing guidance.  These contracts were missing or inadequately addressed key terms, such as:

  • Requiring the service provider to maintain a business continuity plan,
  • Lack standards for data recovery along with appropriate remedies when a recovery standard is missed.
  • Defining key terms in the contracts relevant to business continuity and/or incident response. Contracts lacking these provisions violate the Interagency Guidelines Establishing Information Security Standards, promulgated under the Gramm-Leach-Bliley Act.

Vendors that provide technology related services can create special risks to depository institutions that need to be properly addressed in their service contracts.  The FDIC indicated that it plans to hold the board and senior management of financial institutions accountable for controlling those risks in accordance with the requirements of the law and its existing regulatory guidance.

Financial Institutions should be willing to hold their service providers accountable and negotiate an appropriate contract.  All financial institutions should have provisions that they review for all of their contracts with a robust vendor management program, this will help uncover any weakness in business continuity and data recovery early in the process.

 

Tell Your Story … Before the Examiner Does

Most bankers understand the importance of explaining their philosophy, strategic direction, successes and challenges to directors, auditors, examiners, analysts, and even their fellow executives and employees. They know it’s always better to tell their story before opinions are formed and judgements made about the condition and direction of their institution. Waiting until questions are asked after financial statements or audit reports reflect any weakness, or worse, when examiners arrive on-site, often means responding defensively to what is typically a very good story about management’s ability to identify, measure, monitor and mitigate risks. Given its undeniable importance, the best bankers excel at presenting the facts first and then reinforcing the message about the quality of their management team. If done efficiently, your comprehensive enterprise risk management report will provide the perfect opportunity to tell your story.

The issue is one of timing. Everybody’s busy and nobody has time to continuously repeat what we may naively assume is a message everybody has already heard and retained. But we aren’t always in front of the audience when issues arise. Examiners, for example, spend a considerable amount of time off-site analyzing the institution before coming through your doors. Their pre-work is critical to ensure an effective, risk-focused examination. In the process, it’s inevitable to have opinions formed and even CAMEL ratings roughed-out before speaking with management. Bankers must ensure their own viewpoint is timed to arrive before being judged by examiners, directors, auditors, and others. In particular, your enterprise risk assessments should clearly communicate management’s perspective on all risks, and especially your highest risks.

Equally important is presenting all the facts in a credible manner. The truth eventually comes out, and if people closest to the work fail to acknowledge high risks and other issues before they are obvious, it means they either can’t be trusted because they hid the facts, or they are deficient because they didn’t know the facts. Bankers conduct comprehensive risk assessments for this exact reason: identify the risks and then measure, monitor and mitigate them. ,Risk assessments are fundamental to the business of banking. Done right, they ensure no stone is left unturned and they validate management credibility. They provide the facts backing the story.

Identifying risks comes naturally to most bankers – we’re in the risk taking business after all – but completing and communicating risk assessment results has often been labor intensive and time consuming. If not done efficiently, individual and enterprise risk assessments can drain resources, incur opportunity costs by diverting resources from other important assignments, and lead to frustration and corner-cutting. The key is ensuring individuals closest to the action conduct or oversee the risk assessment in their functional area, but not require them to spend an inordinate amount of time on the work. About an hour each quarter should prove sufficient at most institutions for executives to complete the task…provided they have the right tools to perform the assessment.

Most bankers appreciate how important it is to tell their story to the right audience before opinions are formed and judgement passed. Comprehensive Enterprise Risk Assessments present a golden opportunity to do just that if they can be done efficiently and without draining resources or busting the budget. Enterprise Risk Assessments are the perfect way to back your story with facts.