Professional, independent IT audit services designed specifically for small and mid-sized credit unions.
Technology supports every part of a credit union’s operations. An independent IT Audit evaluates whether key controls are appropriately designed, implemented, and operating effectively. It also helps demonstrate sound governance and a meaningful commitment to protecting member information.
Information Security Program, Board oversight, IT governance, policies, procedures, and risk assessments.
User access, administrator accounts, endpoint security, network controls, physical security, and patch management.
Backups, disaster recovery, business continuity, incident response, and operational preparedness.
Logging, security monitoring, employee awareness training, and review of available testing reports.
Third-party oversight, vendor due diligence, contract considerations, and available SOC or audit reports.
Applicable NCUA expectations, FFIEC guidance, NCUA Part 748, and recognized industry practices.
| Typical Fieldwork | Approximately one business day on-site |
|---|---|
| Final Report | Generally issued within 2–4 weeks |
| Audience | Management and the Board of Directors |
| Approach | Independent, risk-focused, and practical |
| Pricing | Fixed-fee engagements |
Our methodology incorporates applicable guidance from the National Credit Union Administration, the FFIEC Information Security Examination Handbook, selected NIST Cybersecurity Framework references, and accepted IT auditing practices.
To learn more about our IT audit process and review the terms of our engagement, generate a customized Letter of Engagement for your Credit Union. You can review the letter at your convenience before deciding whether to sign and return it.
This service is an independent Information Technology Audit. It is not a penetration test, vulnerability assessment, forensic examination, or comprehensive technical configuration assessment unless specifically included under a separate written agreement.