Compliance Blog

Dec 08, 2014
Categories: Operations Accounts

NCUA Report; Understanding Risks in Electronic Payment Systems

Written by Bernadette Clair, Senior Regulatory Compliance Counsel

A couple of weeks ago, NCUA released its November 2014 Report. Featured articles include:

***

Understanding Risks in Electronic Payment Systems. One of the articles in this month’s NCUA Report that caught my attention discusses the risks associated with electronic payment systems (ACH, ATM, wire transfers, and remote deposit capture) that credit unions should consider when offering or expanding these services. These risks fall into several familiar categories – credit, fraud, compliance, liquidity, systemic, operational or transactional, strategic, and reputation.

Here’s a snippet from the article, with just a few of the questions that NCUA has developed to help credit unions develop electronic payments risk-management policies and procedures:

“Policy and Procedures — Are our policies sufficient enough to address the risks associated with our credit union’s activities? Do our policies describe program objectives, the board’s risk appetite and tolerances? Have we identified and formally approved all activities the credit union will engage in? Do our written procedures match our current practices? Do our current practices address such things as Bank Secrecy Act or customer identification and verification concerns? Have we established and documented our incident response and communication expectations? Does our credit union have effective internal controls?

Audit — Has my credit union completed an acceptable audit? Was the audit completed by a person independent of my credit union’s operations? Do our internal audits sufficiently identify potential risk across all operational areas? Has my credit union taken action to correct any issues found in the audit?

Risk Assessment — Has our management evaluated the risks associated with electronic payments processing? Is our credit union’s risk assessment commensurate with the type and complexity of our activities? Does the assessment consider all categories of risk? Does it identify inherent risk, risk mitigating controls in place and residual risk?”

For the complete list of questions NCUA has developed, as well as links to several NCUA Letters to Credit Unions containing additional guidance, the article is available in its entirety here.