Thread Options
|
#39712 - 10/30/02 09:13 PM
Re: Flood audit writeup...finish this sentence
|
10K Club
Joined: Oct 2000
Posts: 27,769
On the Net
|
Additionally, "vendor" is receiving nonpublic personal information and a specific privacy/confidentiality clause is needed to protect the bank and customer information.
_________________________
AndyZ CRCM My opinions are not necessarily my employers. R+R-R=R+R Rules and Regs minus Relationships equals Resentment and Rebellion. John Maxwell
|
Return to Top
|
|
|
|
#39717 - 10/30/02 09:50 PM
Re: Flood audit writeup...finish this sentence
|
10K Club
Joined: Oct 2000
Posts: 27,769
On the Net
|
I disagree and am cautious. What if your customer applying for the refi says he's suddenly getting calls to sell him flood insurance? Where might those come from? I believe this fits into vendor management and a confidentiality clause is warranted. Certainly it isn't as vital as with your Internet Banking provider, but important still the same.
_________________________
AndyZ CRCM My opinions are not necessarily my employers. R+R-R=R+R Rules and Regs minus Relationships equals Resentment and Rebellion. John Maxwell
|
Return to Top
|
|
|
|
#39719 - 10/30/02 10:14 PM
Re: Flood audit writeup...finish this sentence
|
10K Club
Joined: Oct 2000
Posts: 27,769
On the Net
|
I want to say that my last exam request letter even asked who received any customer information and for copies of agreements such as this.
_________________________
AndyZ CRCM My opinions are not necessarily my employers. R+R-R=R+R Rules and Regs minus Relationships equals Resentment and Rebellion. John Maxwell
|
Return to Top
|
|
|
|
#39720 - 10/31/02 12:28 PM
Re: Flood audit writeup...finish this sentence
|
10K Club
Joined: Sep 2002
Posts: 13,965
TN
|
I thought a confidentiality clause was required for ALL third party vendors.
_________________________
My Opinions Only
|
Return to Top
|
|
|
|
#39721 - 10/31/02 02:06 PM
Re: Flood audit writeup...finish this sentence
|
10K Club
Joined: Oct 2000
Posts: 27,769
On the Net
|
It wouldn't have to be in an agreement with all, the paper supplies we get, periodicals or software, but anytime customer information is used, it should be.
(Side bar - Actually it may become an issue on some software beyond the mainframe now. There are some who have read the new Microsoft EULAs and MS says you grant them access to the computer memory files. Those obviously may have NPPI on them and raises privacy issues.)
I was trying to find my notes on Vendor Management from an OCC conference but I can't. I don't work with that much but I want to say there are some guidelines published on this.
_________________________
AndyZ CRCM My opinions are not necessarily my employers. R+R-R=R+R Rules and Regs minus Relationships equals Resentment and Rebellion. John Maxwell
|
Return to Top
|
|
|
|
#39722 - 10/31/02 04:28 PM
Re: Flood audit writeup...finish this sentence
|
100 Club
Joined: Apr 2002
Posts: 215
|
Many flood zone determination vendors now include Life of Loan (LOL) coverage at basically no additional cost.
This requires a contract since it is backed by the vendor's Errors and Omissions insurance.
On the other hand, try to avoid a long term exclusive contract. The technology is changing quickly. Vendors are integrating from the front end, the loan origination system, to assorted services such as appraisal, title search, flood insurance, ad infinitum.
_________________________
Regards,
CarlD
|
Return to Top
|
|
|
|
#39727 - 11/01/02 04:14 AM
Re: Flood audit writeup...finish this sentence
|
10K Club
Joined: Oct 2000
Posts: 27,769
On the Net
|
From the Interagency Guidelines on SCI.
A service provider is a person or entity that maintains, processes, or otherwise is permitted
access to customer information through its provisions of services directly to the bank.
Institutions must exercise due diligence in selecting service providers, including reviewing the
service provider’s information security program or measures used by the service provider to
protect the institution’s customer information. In addition, contracts entered into after March 5,
2001 must require that the service provider implement appropriate measures designed to meet the
objectives of the Guidelines. By July 1, 2003, all contracts are subject to this requirement.
It is one thing to say the info is available to the public. But it is another to profess that this is John, this is a house John owns, John is getting a loan, John's house is in a flood zone, John needs insurance.
_________________________
AndyZ CRCM My opinions are not necessarily my employers. R+R-R=R+R Rules and Regs minus Relationships equals Resentment and Rebellion. John Maxwell
|
Return to Top
|
|
|
|
|
|