IT Examiner School - Oct 2025
Internal Use Only
Development and Acquisition
Internal Use Only
Development & Acquisition Learning Objectives
Explain the FFIEC Development & Acquisition expectations for project management, including Decision Factors DA.1 and DA.2 . Describe the key stages of the System Development Life Cycle (SDLC) and how risk management and control integration should occur throughout. Identify the roles and responsibilities of senior management and the board in overseeing major IT development or acquisition initiatives. Recognize the artifacts and documentation examiners typically request (e.g., project charters, risk logs, testing evidence, post implementation reviews). Assess warning signs of weak project management (e.g., poor oversight, uncontrolled scope changes, lack of risk tracking). Apply FFIEC examiner focus points to evaluate an institution’s project management practices during an IT exam or assessment.
Made with FlippingBook Learn more on our blog