IT Examiner School
IT Management Component Rating IT management rating is based on FFIEC Uniform Rating System for Information Technology (URSIT) InTREx process (depository institutions) calls for assigning a Management component rating for IT Like CAMELS, this component rating plays a key role in the overall URSIT composite rating & is rated on the same criteria, but based solely on IT/operations activities Additional URSIT information, components & ratings are discussed in other modules
Management Module Conclusions • Management has significant responsibilities in overseeing IT activities • Poor oversight could cause reputational risk • Could result in significant impact to entity • Statutes & Guidance • Establish best practices • Establish requirements • IT findings usually occur because: • Management didn’t adequately perform their duties and responsibilities
Made with FlippingBook Digital Publishing Software