CC Pace About Us Careers Contact Us  

RETAIL BANKING: TOOLKIT FREQUENTLY ASKED QUESTIONS





Online Banking Risk Assessment Toolkit

Why do I need to perform an online banking assessment?
The FFIEC states that increased security measures around “high risk transactions” should be based upon the results of a risk assessment of your online banking system. The risk assessment focuses specifically on the risks presented by lost or stolen usernames and passwords.
Back to top

How does the Toolkit help me comply with the FFIEC's guidance on Internet banking authentication?
The Toolkit provides a best practices based, structured methodlogy for performing the risk assessment and documenting the results. The Risk Assessment report package provides not only the high level information for the Board of Directors but also produces detailed work papers that demonstrate to your regulator that you have performed the risk assessment with adequate due diligence.
Back to top

What does the Toolkit include and how much does it cost?
For a one time fee of $5,500, this toolkit includes three binders and a CD that can be reused on any application-Internet, call center, IVR. Binder One covers Risk Assessment theory and tutorials, the FFIEC specific risk assessment process, workpapers and a copy of the FFIEC Guidance annotated by our banking and security experts. Binder Two contains hard copies of all of the applicable FFIEC IT Workbooks, NIST Risk Assessment Standards and other documentation you will need to support your risk assessment process. Binder Three provides a ready made repository for all of your RA findings and completed workpapers. The CD includes the electronic Risk Assessment Tool and your report templates. If you are not fully satisfied with this Toolkit, we offer a 21 day return policy.
Back to top

Do you provide ongoing support for Toolkit users?
Included with your purchase of the toolkit are two hours of analyst time which may be used to help you determine the risk of your online banking system. In addition we provide technical support via e-mail (toolkitsupport@ccpace.com) and telephone (703.631.6600).
Back to top

The FFIEC Frequently Asked Questions posted on August 15, 2006 state that the same Risk Assessment and Security principles must be applied to telephone banking, call centers and other electronic delivery channels. Does this Online Banking Risk Assessment Toolkit cover those areas?
Yes, it does.  The text surrounding the  toolkit is focused on Internet Banking and overall risk assessment methodology; however, the Risk Assessment Tool may be used for any type of delivery channel. Simply create another project, select the transactions that are performed through that delivery channel, and add any that may be missing.  The methodology is sound for any transaction-based risk assessment you may wish to perform.
Back to top

For more information or to purchase a toolkit by phone, please contact Pam Winks at pwinks@ccpace.com or call 703.631.6600.