On September 29, 2023, the Federal Deposit Insurance Corporation (FDIC) published FIL-52-2023 announcing the updated Information Technology Risk Examination (InTREx) procedures. If you're curious about what changed, you've come to the right place.
InTREx was initially published in 2016 (see FIL-43-2016). Since that time, InTREx has been used by the FDIC, Federal Reserve, and several of the state banking agencies to examine banks' technology and cybersecurity practices.
In early 2023, InTREx was audited by the Office of Inspector General (OIG). According to the OIG's report, InTREx was pretty outdated and inconsistent with current guidance recommendations. For example, since 2016, the following FFIEC guidance was updated:
Following the audit, the FDIC announced plans to address the recommendations and got to work.
While InTREx looks largely the same today as it did before the update, there were some notable changes. In addition to the guidance updates, here are four updates you don't want to miss. Download the redline version of the work program to see a list of changes to the core modules.
This is the questionnaire at the beginning of the document. The updated profile was streamlined and its size was cut in half. (The 2016 version had 26 questions and the 2023 version now has 13 questions.)
To get there, they did a lot of merging and removing questions. For example:
It wasn't all about streamlining though. The updated profile now features questions and answers on new and relevant topics, such as:
In short, these are quality-of-life improvements. They make the profile more accurate, more relevant, and easier to complete, which is always a welcomed change.
The Audit core module received a few minor updates, primarily for formatting and clarity.
For example, in the 2016 version, the Decision Factors were listed at the beginning of the section. In the 2023 version, the Decision Factors are embedded into the program. This makes the module read more like a process and requires less jumping around the document.
There were a couple notable textual changes, as well. Here's a comparison of those.
|
Procedure Changes |
Comment |
|
Procedure 2 – Board and Management Support Evaluate the quality of oversight and support provided by the Board of Directors and management. Consider the following:
|
In the 2023 version, the first bullet was removed, which seems appropriate, since the answer could be determined by the answer to the second bullet. |
|
Procedure 8 – Control Evaluation Evaluate the ability of the IT audit function to accurately assess, test, and report the effectiveness of controls. Consider the following:
|
These updates provide examiners with a few additional recommendations for determining control effectiveness. The 2023 version encourages examiners to look at recent audit findings, the bank's audit risk assessment, and a control impact assessment. |
|
Procedure 4 – Risk Assessment Process Establishment of Board-approved audit plans and schedules based on risk |
The 2016 version used the phrase "audit cycles" which is less clear than "audit plans and schedules based on risk." |
|
Procedure 9 – Auditor Expertise and Training
|
This update clarifies that both internal and external auditors should be receiving ongoing training. |
|
Procedure 10 – Audit Monitoring and Resolution
|
These updates indicate an emphasis on audit finding resolution. Finding resolution should be prioritized and performed in a timely manner. |
While both changes are new items for examiners to review, both are related to recent regulation and emerging risks, so they seem like reasonable additions to the program.
There were two minor changes in the Management core module.
While both changes are new items for examiners to review, both are related to recent regulation and emerging risks, so they seem like reasonable additions to the program.
Of the entire program, this module received the most updates. This is not surprising, as the OIG report indicated this module had already received some voluntary updates by the InTREx committee in 2019.
Here is a summary of the changes:
This Support and Delivery section was arguably the most outdated, so it makes sense that it was also the most refreshed. For a full listing of changes, download the redline version of the work program, provided by Tandem.
The InTREx program is a staple of the technology examination process for community banks. This update modernizes the program, while avoiding additional regulatory burden for examiners or the banks being examined.
Tandem Cybersecurity Assessment simplifies examination prep with common frameworks, including the FDIC InTREx program. Our web application streamlines the process of performing a cybersecurity control self-assessment with intuitive assessment tools, robust reporting, peer benchmarking, notifications, and more.
Sign up and get started for free at Tandem.App/Cybersecurity.