Branchsoft Technologies LLC

Independent Information Technology Audits for Credit Unions

Strengthen Security. Reduce Risk. Meet Regulatory Expectations.

Professional, independent IT audit services designed specifically for small and mid-sized credit unions.

Give your Board and management a clear, objective view of your Information Security Program, technology controls, and regulatory readiness.

Why an Independent IT Audit?

Technology supports every part of a credit union’s operations. An independent IT Audit evaluates whether key controls are appropriately designed, implemented, and operating effectively. It also helps demonstrate sound governance and a meaningful commitment to protecting member information.

Designed for Credit UnionsBranchsoft Technologies combines more than 37 years of Credit Union IT experience with an independent, practical audit approach focused on the needs of community-based financial institutions.

What We Review

Governance & Oversight

Information Security Program, Board oversight, IT governance, policies, procedures, and risk assessments.

Access & Security

User access, administrator accounts, endpoint security, network controls, physical security, and patch management.

Resilience & Recovery

Backups, disaster recovery, business continuity, incident response, and operational preparedness.

Monitoring & Awareness

Logging, security monitoring, employee awareness training, and review of available testing reports.

Vendor Management

Third-party oversight, vendor due diligence, contract considerations, and available SOC or audit reports.

Regulatory Alignment

Applicable NCUA expectations, FFIEC guidance, NCUA Part 748, and recognized industry practices.

Our Audit Process

Pre-engagement document request
Management and staff interviews
Review of policies and supporting evidence
Observation of selected safeguards
Evaluation against recognized guidance
Clear reporting to management and the Board

What You Receive

  • Executive Summary for management and the Board
  • Comprehensive Information Technology Audit Report
  • Risk-ranked findings
  • Practical recommendations for improvement
  • Management response section
  • Overall audit conclusion, when applicable

Why Branchsoft?

  • More than 37 years of Credit Union IT experience
  • Independent, objective, and vendor-neutral
  • Focused specifically on Credit Union technology
  • Practical recommendations—not generic checklists
  • Personal service from the auditor performing the work
  • Fixed-fee engagements
Independent of Your Technology ProvidersYour MSP or core provider may support your systems, but an independent auditor evaluates governance, oversight, evidence, and control effectiveness without a service-provider conflict of interest.

Engagement Snapshot

Typical FieldworkApproximately one business day on-site
Final ReportGenerally issued within 2–4 weeks
AudienceManagement and the Board of Directors
ApproachIndependent, risk-focused, and practical
PricingFixed-fee engagements

Professional Guidance

Our methodology incorporates applicable guidance from the National Credit Union Administration, the FFIEC Information Security Examination Handbook, selected NIST Cybersecurity Framework references, and accepted IT auditing practices.

Common Audit Procedures

  • Documentation and policy review
  • Management and staff interviews
  • Observation of physical safeguards
  • Review of selected system evidence
  • Sampling of selected controls
  • Review of available vulnerability scan and penetration testing reports

Let’s Talk About Your Next IT Audit

A well-designed audit should do more than identify problems. It should help your Credit Union understand risk, prioritize improvements, and provide the Board with clear, useful information.

John Pruitt
President
Branchsoft Technologies LLC
11532 Hague Rd
Fishers, IN 46038
317-507-4858

Independent IT Auditor

This service is an independent Information Technology Audit. It is not a penetration test, vulnerability assessment, forensic examination, or comprehensive technical configuration assessment unless specifically included under a separate written agreement.