Skip to content
IT21

Financial Services and Banking

Walk into the exam already knowing the findings

The examination window is on the calendar and your last report left open items that were supposed to be closed by now. You are reasonably sure they aren't.

An examiner will find what you already suspect. The vendor file that has not been refreshed since the contract was signed. The user account belonging to someone who left in March. The board packet that reports on technology risk in a paragraph of adjectives. None of it is a surprise inside the institution. It becomes expensive only because it is documented by someone outside it, in a report that goes to your board and follows you into the next cycle.

Community banks and credit unions rarely have a staffing problem here. They have a sequencing problem. Everything is due, nothing is prioritized, and the people who could fix it are also running daily operations.

IT21 works the technology side of examination readiness: access and change controls, business continuity and its testing, third-party risk, incident response, and the evidence trail that shows a control operated rather than merely existed. We write findings in the language the Federal Financial Institutions Examination Council (FFIEC) handbooks use, because a finding phrased in your consultant’s private vocabulary has to be translated twice.

What you get:

  • A pre-examination review against the Federal Financial Institutions Examination Council (FFIEC) handbooks, with findings written the way an examiner would write them
  • Open Matters Requiring Attention tracked to closure with evidence attached, not status colors on a slide
  • Vendor and third-party oversight files brought current for the vendors that actually matter
  • Board and committee reporting that gives directors enough to ask a real question
  • Wire and payment controls reviewed end to end, including the approval step that exists only in habit

Assess is a mock examination. Transform is closing the gaps in the order an examiner would weight them, which is not always the order that feels most urgent internally. Optimize is the cycle work between examinations — the reviews, the testing, the board reporting rhythm — so the next window is a retrieval exercise.

There is a difference between advice from someone who has read the handbook and advice from someone who has been the Director of Information Security answering to the Office of the Comptroller of the Currency for a bank’s security architecture. That history is why we tend to be blunt about what will not survive testing.

[PROOF: bank or credit union engagement — asset size, region, examination outcome — supply]

The IT Risk & Readiness Assessment is the low-commitment start. It is measured against a recognized governance framework your examiners already work from, and it produces a ranked list of what an examination would raise. Better to read that from us first.

  • Assess
  • Transform
  • Optimize

Oscar Chacon, CISA

Certified Information Systems Auditor since 1997

Not sure where you stand? Start with the assessment.

Request the Assessment

FFIEC examination readiness — a brief

A mock examination, findings written the way an examiner would write them, Matters Requiring Attention tracked to closure with evidence, and board reporting that holds up.

Get the PDF — enter your email

HubSpot form — assessment-request — not configured

Set portalId and forms.assessment-request in src/lib/hubspot.ts.

Email
Company
Submit

Start with the IT Risk & Readiness Assessment

A defined engagement, measured against a recognized control framework, that shows you which controls exist, which are documented but not operating, and which are absent — before you commit a budget.