FD Remediation Tracker Report TPRS Small Team VRC1 – VRO – VRC2 Criticals and “Wholly Outsourced Department”s 1,322 An NDA High December latenoticelog- noreply @spfarm.bok.com 1b 1 Highest Inherent Risk of Compliance, BC, and SRM Regulatory perspective included in annual critical reporting Formerly critical Delegation 14 calendar days Impacts customers broadly enough to threaten market share 100 June 1,069 Financial Crimes Vice President VRC OCC Bulletin 2013-29 FIS Risk Council Analysis based on the nature of the engagement 2/14/2019 Third Party Risk Summary Blank What is the single transaction limit? Overall comments Bank Confidential Data 3/26/2019 Ernst and Young OCC Risk Rating Exempt 2020 BCTier@bokf.com Value Added Reseller Non-US Headquarters or Non-US Operations Monthly Highest Risk Rating of all active Relationships 21 calendar days Any Tier Medium Cuba Coupa 5.01 Access@Work Request Business Process Tiers Push through assigned programs OFAC Hit Shared SLAs VRC1's Evaluation Queue Third Party Provider Management Standard Regenerate SSAE18 Upon a completed Financial Crimes review 5 Property Maintenance Anyone Supplier Name Change Committee Review the file posted in the VMO SharePoint site Moderately Low Third Party Provider Management Policy Ineffective No HIPAA Annual Report Yes Conga 3 Days A completed Materiality Assessment If 1.01 AND 1.17 are applicable False FD Remediation Tracker Report TPRS Small Team VRC1 – VRO – VRC2 Criticals and “Wholly Outsourced Department”s 1,322 An NDA High December latenoticelog- noreply @spfarm.bok.com 1b 1 Highest Inherent Risk of Compliance, BC, and SRM Regulatory perspective included in annual critical reporting Formerly critical Delegation 14 calendar days Impacts customers broadly enough to threaten market share 100 June 1,069 Financial Crimes Vice President VRC OCC Bulletin 2013-29 FIS Risk Council Analysis based on the nature of the engagement 2/14/2019 Third Party Risk Summary Blank What is the single transaction limit? Overall comments Bank Confidential Data 3/26/2019 Ernst and Young OCC Risk Rating Exempt 2020 BCTier@bokf.com Value Added Reseller Non-US Headquarters or Non-US Operations Monthly Highest Risk Rating of all active Relationships 21 calendar days Any Tier Medium Cuba Coupa 5.01 Access@Work Request Business Process Tiers Push through assigned programs OFAC Hit Shared SLAs VRC1's Evaluation Queue Third Party Provider Management Standard Regenerate SSAE18 Upon a completed Financial Crimes review 5 Property Maintenance Anyone Supplier Name Change Committee Review the file posted in the VMO SharePoint site Moderately Low Third Party Provider Management Policy Ineffective No HIPAA Annual Report Yes Conga 3 Days A completed Materiality Assessment If 1.01 AND 1.17 are applicable False
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
FD Remediation Tracker Report
TPRS Small Team
VRC1 – VRO – VRC2
Criticals and “Wholly Outsourced Department”s
1,322
An NDA
High
December
latenoticelog-noreply @spfarm.bok.com
1b
1
Highest Inherent Risk of Compliance, BC, and SRM
Regulatory perspective included in annual critical reporting
Formerly critical
Delegation
14 calendar days
Impacts customers broadly enough to threaten market share
100
June
1,069
Financial Crimes
Vice President
VRC
OCC Bulletin 2013-29
FIS
Risk Council
Analysis based on the nature of the engagement
2/14/2019
Third Party Risk Summary
Blank
What is the single transaction limit?
Overall comments
Bank Confidential Data
3/26/2019
Ernst and Young
OCC
Risk Rating
Exempt
2020
BCTier@bokf.com
Value Added Reseller
Non-US Headquarters or Non-US Operations
Monthly
Highest Risk Rating of all active Relationships
21 calendar days
Any Tier
Medium
Cuba
Coupa
5.01
Access@Work Request
Business Process Tiers
Push through assigned programs
OFAC Hit
Shared SLAs
VRC1's Evaluation Queue
Third Party Provider Management Standard
Regenerate
SSAE18
Upon a completed Financial Crimes review
5
Property Maintenance
Anyone
Supplier Name Change Committee
Review the file posted in the VMO SharePoint site
Moderately Low
Third Party Provider Management Policy
Ineffective
No
HIPAA
Annual Report
Yes
Conga
3 Days
A completed Materiality Assessment
If 1.01 AND 1.17 are applicable
False