HomeIndustriesBanks
Banks and credit unions
IT for banks, from the bank’s side of the exam table.
FFIEC guidance. FDIC IT exams. SOX and ITGC audits. We’ve led a bank’s IT team through them: the people, the policies, the request list, the walkthroughs.
In your vocabulary
What lands on our desk at a bank.
The exam.
The IT request list answered from your systems, not from memory. Evidence filed where next year’s examiner will look.
The audit.
SOX and ITGC controls with named owners, walkthroughs on the calendar, and a complete package for the audit firm.
Policy.
An IT policy set that matches what you actually do. Change management, access, encryption, patching and the rest, aligned to FFIEC and NIST.
Vendors.
Risk reviews before you sign. Release notes read before the core updates. Telecom and software invoices checked before you pay.
Access.
Onboarding, offboarding and role changes that run on approvals and leave a record.
Branches.
Network, devices and sign-in that behave the same at headquarters and at every branch.
Recovery.
Disaster recovery tested against a specific scenario, with the results written up the way your continuity plan requires.
Leadership.
Status your executives will actually read: what’s at risk, what it costs, what’s next.
AI, the careful way
Your people are already using it.
We’ve brought AI into a bank. In this order.
01
Governance.
Who decides, who is accountable, what is off limits. Approved by the steering committee before anyone pilots anything.
02
Vendor risk review.
The questionnaire you’d send any third party, sent to the AI vendors.
03
Controls.
Single sign-on, conditional access, retention and export limits, least-privilege groups.
04
Pilot, then a recommendation.
Named users, scripted tests, measured feedback, and a report executives can act on.
What we’re not
We run it. Someone else checks it.
- Not your auditor.
- Not your information security officer.
- Not your core provider.
Examiners expect the security officer to sit apart from the people running IT. So do we. We run the systems and hand your security officer, your auditors and your examiners the evidence.
We don’t certify compliance, and we don’t sign your exam responses. Management does.
Proof
From inside a bank.
- We’ve led a bank’s IT team: the people, the policies, the FDIC IT exams, the SOX audits.
- We’ve brought AI into a bank the careful way: governance, vendor risk reviews, security controls, then the pilot.
- We built and host a bank’s public website.
- Rules worked under
- FFIEC, NIST, SOX, ITGC, FDIC IT exams, NACHA rule changes
- Delivered inside a bank
- IT policy set, virtualization platform migration, headquarters and branch network rollout, device management rollout, identity workflows, disaster recovery testing, uptime monitoring
Questions
Asked by bankers.
We have an IT officer. Is this still for us?
Often, yes. A capable IT officer usually needs air cover: a plan, a second set of hands on the request list, someone to hold the vendors to scope. Where there’s nobody in the seat, we take it.
Do you work with our core provider and our managed service provider?
Yes, and they stay. We manage scope, releases and invoices the way a staff IT director would.
Can you help us bring in AI?
Yes, in this order: governance, vendor risk review, security controls, a small pilot, a recommendation. We’ve done it inside a bank.
Will you sign our exam responses?
No. Management signs. We build the evidence, and we sit in the walkthroughs if you want us there.
How big does a bank need to be?
Big enough to have an IT exam and a real IT bill. Small enough that a full-time technology executive doesn’t pencil out.
Start here
Two invoices. Two business days.
Send the last two bills from whoever handles your IT. We’ll tell you what you’re paying for, and whether it’s fair. Free.
