Home > Compliance Management Tips > Compliance Tips > Financial regulatory compliance best practices, tips
Compliance Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE TIPS

Financial regulatory compliance best practices, tips


Elisabeth Horwitt
02.13.2008
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Financial regulatory compliance has always been a moving target for financial-sector CIOs. They must cope not only with new regulations, but also with auditors' changing interpretations of existing guidelines. Emerging technologies and scandals in the business world introduce new risks that must be taken into account in the ongoing work of hammering out an effective compliance strategy.

Keeping up is not easy. Here are some best practices and tips on how CIOs can best address today's regulatory environment and prepare to meet the developments and changes that may be coming in the near future.

New technology, new risks

Deploying new technologies, however useful, often introduces new security risks and financial regulatory compliance issues, experts warn. "One of the biggest challenges is the explosion of the ways we communicate, and the devices we use to always stay 'on,'" said Diana Kelley, a partner at consulting firm SecurityCurve in Amherst, N.H. Cell phones and personal digital assistants, useful as they are, have introduced security vulnerabilities that companies must address, federal regulations state with increasing precision.

In recent years, several major investment firms paid fines totaling tens of millions of dollars for failing to protect instant messaging (IM) content adequately. Regulations now require that IM content be archived in secure and searchable formats, and that IM communication channels be "monitored for correct usage, integrity, security," Kelley noted.

Trying to prohibit the use of a technology such as IM is often worse than useless, because it simply drives usage underground. Better to allow IM under controlled conditions, over secure channels, Kelley advised.

Know your current business events...


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Financial services compliance requirements
Online privacy: New rules for melding e-commerce and information
Security and compliance can go together, when done in the right order
PCI DSS compliance fails to raise the bar on financial fraud
Security and privacy top IT agenda for Massachusetts CIO
Mass. officials, compliance officers debate data protection law
Twitter security risks, popularity spark regulatory concerns
Top regulatory compliance trends that will affect IT in 2009
SEC commish, FINRA head: Reform financial services regulations
Financial crimes resulting in increased compliance enforcement
Enforcement date for FACT's Red Flags Rule approaches

Risk management and compliance
Facing uncertainty, IT turns to governance, risk and compliance, ERM
FTC compliance mandates new rules for social media marketing
How to design an FTC compliance program for social media marketing
GPS devices, geolocation data create privacy, security risks
Threat management for information systems relies on categorization
Mass. data protection regulation passes big test in public hearing
Does using ISO 27000 to comply with PCI DSS make for better security?
FTC pursuing HIPAA violations as a matter of consumer protection
Are mandatory business continuity management standards good business?
PCI DSS compliance requires better management of vendor risk

Financial and accounting software for compliance
How the SEC's proposed IFRS will affect your accounting systems
SEC filings may soon require XBRL -- to your advantage

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Fair Credit Reporting Act (FCRA)  (SearchCompliance.com)
XBRL  (SearchCompliance.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Technical decision makers need to think creatively about how events in the business world may affect the financial regulatory environment. In response to the recent subprime mortgage uproar, auditors are starting to demand that firms retain, secure and readily provide complete data on the financial risk posed by investment vehicles, Kelley reported.

Furthermore, post-9/11 and Hurricane Katrina, auditors want proof that a firm's IT infrastructure can withstand specific disasters and security events, noted Norbert Nowicki, systems and technology practice leader at auditing firm Accume Partners.

"They are asking, 'Are you prepared for a pandemic? Can you continue doing business if the Exchange goes down?'" No longer satisfied with penetration tests that simulate attacks, "They want to know, 'Where are your hot sites? How are they secured? What controls are in place?'" Nowicki said.

Keep an eye on Basel II

While it's still too early to determine all its implications, Basel II will definitely affect IT compliance efforts, according to Richard E. Mackey Jr., vice president of consulting at SystemExperts Corp. in Sudbury, Mass.

The recently created international business standard requires that large financial institutions have enough cash on hand to cover all potential risks. This means companies will need to prove to auditors and regulators that systems used to calculate financial risk are tamper-proof, and that the data is secure, Mackey said.

Watch your partner's back

The Graham-Leach-Bliley Act and various privacy laws now require financial firms to make sure their business partners take the same security measures as they do. "If doing business with a partner results in loss or damage to your data, or a customer's data or assets, you are also accountable," Kelley warned.

The same goes for vendors to whom you have outsourced backup and storage or financial applications or Web hosting. "If your disks get lost off the back of a vendor's truck," you're still liable, Kelley said.

Performing security reviews of dozens or perhaps hundreds of partners can be cost-prohibitive for large financial firms, Mackey noted. Try limiting the amount and type of information shared with partners, he advised. For example, avoid sharing Social Security numbers, and send only the information a partner needs -- not an entire file.

Don't overdo it

In recent years, the Securities and Exchange Commission has significantly clarified what companies need to focus on to comply. Even so, companies spent $6 billion on Sarbanes-Oxley Act compliance in 2007, according to AMR Research Inc. in Boston.

A large portion of those expenditures were not necessary, according to Accume's Nowicki. Companies should not attempt to address every single process and system, but rather focus on key processes and business critical elements within the IT infrastructure, he advised.

The good news is, as financial regulations mature, regulators are clarifying and even easing some compliance requirements. For example, regulators initially required financial institutions to hand out a physical device, such as a token, as well as a password, to any customer who wanted to access their systems via the Web. Regulators eventually realized this was impractical and backed off.

If only all compliance requirements were so reasonable.

Elizabeth Horwitt is a contributing writer based in Waban, Mass.


Rate this Tip
To rate tips, you must be a member of SearchCompliance.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsBlogsMultimediaWhite PapersProducts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts