Branchsoft Technologies LLC

Independent Information Technology Audits for Credit Unions

Strengthen Security. Reduce Risk. Meet Regulatory Expectations.

Professional, independent IT audit services designed specifically for small and mid-sized credit unions.

Give your Board and management a clear, objective view of your Information Security Program, technology controls, and regulatory readiness.

Why an Independent IT Audit?

Technology supports every part of a credit union’s operations. An independent IT Audit evaluates whether key controls are appropriately designed, implemented, and operating effectively. It also helps demonstrate sound governance and a meaningful commitment to protecting member information.

Designed for Credit UnionsBranchsoft Technologies combines more than 37 years of Credit Union IT experience with an independent, practical audit approach focused on the needs of community-based financial institutions.

What We Review

Governance & Oversight

Information Security Program, Board oversight, IT governance, policies, procedures, and risk assessments.

Access & Security

User access, administrator accounts, endpoint security, network controls, physical security, and patch management.

Resilience & Recovery

Backups, disaster recovery, business continuity, incident response, and operational preparedness.

Monitoring & Awareness

Logging, security monitoring, employee awareness training, and review of available testing reports.

Vendor Management

Third-party oversight, vendor due diligence, contract considerations, and available SOC or audit reports.

Regulatory Alignment

Applicable NCUA expectations, FFIEC guidance, NCUA Part 748, and recognized industry practices.

Our Audit Process

Pre-engagement document request
Management and staff interviews
Review of policies and supporting evidence
Observation of selected safeguards
Evaluation against recognized guidance
Clear reporting to management and the Board

What You Receive

  • Executive Summary for management and the Board
  • Comprehensive Information Technology Audit Report
  • Risk-ranked findings
  • Practical recommendations for improvement
  • Management response section
  • Overall audit conclusion, when applicable

Why Branchsoft?

  • More than 37 years of Credit Union IT experience
  • Independent, objective, and vendor-neutral
  • Focused specifically on Credit Union technology
  • Practical recommendations—not generic checklists
  • Personal service from the auditor performing the work
  • Fixed-fee engagements
Independent of Your Technology ProvidersYour MSP or core provider may support your systems, but an independent auditor evaluates governance, oversight, evidence, and control effectiveness without a service-provider conflict of interest.

Engagement Snapshot

Typical Fieldwork Approximately one business day on-site
Final Report Generally issued within 2–4 weeks
Audience Management and the Board of Directors
Approach Independent, risk-focused, and practical
Pricing Fixed-fee engagements

Professional Guidance

Our methodology incorporates applicable guidance from the National Credit Union Administration, the FFIEC Information Security Examination Handbook, selected NIST Cybersecurity Framework references, and accepted IT auditing practices.

Common Audit Procedures

  • Documentation and policy review
  • Management and staff interviews
  • Observation of physical safeguards
  • Review of selected system evidence
  • Sampling of selected controls
  • Review of available vulnerability scan and penetration testing reports

Ready to Learn More?

A well-designed audit should do more than identify problems. It should help your Credit Union understand risk, prioritize improvements, and provide both the Board and management with clear, actionable information.

To learn more about our IT audit process and review the terms of our engagement, generate a customized Letter of Engagement for your Credit Union. You can review the letter at your convenience before deciding whether to sign and return it.

Generate Letter of Engagement

This service is an independent Information Technology Audit. It is not a penetration test, vulnerability assessment, forensic examination, or comprehensive technical configuration assessment unless specifically included under a separate written agreement.