Technology Planning and Risk Services

Technological advancements have made it possible for financial institutions to offer products and services that were once inconceivable, but have also introduced new costs, risks and technical and operational challenges. Choosing the right systems strategy is paramount, but the selection, management, assessment and maintenance of these systems can be a daunting task. Are you building an IT silo, or a leading edge IT organization that drives business performance improvement throughout your bank. IT Assessment and Planning Management develops programs to remain competitive investing in technology based resources to improve its products and services, business operations and reporting. These technology investments, combined with the additional pressure to comply with federal and state mandates such as the Gramm-Leach-Bliley Act, have forced many institutions to invest heavily in technology creating major internal projects, consuming the time and resources of key personnel, increasing costs and adding to an IT infrastructure that requires its own maintenance – staff, policies, procedures, risk management documentation and hardware, vendor relationships and data communications. The challenge remains, but now may be getting more costly, more complex and more resource intrusive, is to ensure that these and any future technology investments result in improved business performance, accomplishing target business objectives while improving security and minimizing impact on IT operations. Developing an IT plan and updating it annually in concert with your business or strategic plan is a best practice and crucial to controlling costs and making sure key objectives are met. IT Selection and Implementation

Whether an in-house or service bureau core systems environment, the IT/vendor acquisition process is extremely important and the results of such selections have long lastly implications. NEBSG professionals have substantial experienced vendor selection experience with community banks. We bring deep firsthand knowledge of many of the strengths and weaknesses of all the core banking application systems and we bring proven selection project tools and techniques. Our resources pull in your IT plans, verify or obtain your business requirements and position all your bank departments and key personnel to efficiently compare and contrast computing core systems. We are independent of these vendors and your in-house personnel and help to obtain an unbiased fact-based decision. IT Risk Management and Control We have witnessed a veritable siege on our community bank clients. Bank regulators as well as the highly relevant IT threats have demanded that community bank IT Departments get up-to-speed quickly on IT command and control – policies, procedure, risk assessments, audits, etc.. We help your IT Department respond to and/or prepare for Sarbanes-Oxley Act and FDICIA internal control requirements. Our roles can be supportive to your management in preparing control procedure and documentation or we can be independent testers of compliance.

Sometimes implementation of internal control and improved IT security has been viewed by certain bank IT managers as a need to create a “wall” between IT and the business units. This is not so, and can and should be avoided. IT is a crucial service function to all business units

and must remain highly accessible and efficient in supporting other functions. Our NEBSG professionals work with our business partners, Sage Data Security and MM&T, to provide our clients with an experienced team of information technology experts and specialists. How Can NEBSG Help? We provide our clients with an experienced team of banking and information technology professionals who can develop and deploy cost-effective solutions that support and enhance your strategic goals and objective. Information Technology Planning

• Assessment of the IT environment
• Organization, personnel and vendors
• Software, business requirements and user needs
• IT Infrastructure considerations – hardware, check processing/scanners, servers, operating systems, network, cold storage, data communications, etc.
• Evaluation of In-house and service bureau operating alternatives
• IT project management and

Information Security/Risk Analysis:

• IT Risk assessment,
• Disaster Recovery/Business Continuity Planning
• Out-sourced ISO function
• Application/Hardware/Function Risk Assessments
• IT Vendor Risk Assessments

Management Reporting and MIS

• Management reporting needs assessment and design –enterprise or functional (requirements definition)
• Data base identification, definition and data migration and availability assessment and planning
• Data management planning

IT Policies, Procedures and Risk Management

• IT Policy and procedures review and comments
• Drafting policies and IT operating procedures
• IT Committee and governance structure
• IT Risk Assessments

Systems Selection

• Vendor contract review and cost benchmarking
• Business application selection assistance – G/L, Loan Origination Systems, CRM systems, Retail Banking Systems
• Enterprise core banking systems selection project management
• Vendor Contract negotiation
• Evaluation of in-process or completed vendor/system selection process

Conversion Project Management

• Enterprise systems conversion project team support, coordination and management
• Project plan development/review
• Conversion readiness assessment
• Data mapping/parameter setting
• Test script creation and assistance
• Balancing and reconciliation assistance
• Conversion working papers development and maintenance

For and further detail on NEBSG’s IT consulting services, please call Tom Grottke or Jennifer Healy at (860)436-6149.