What We Do
Fixed-fee, exam-ready advisory for banks and credit unions
Offering 1
A board-ready controls reality check, calibrated to your charter
Best for
- Upcoming exam or audit within the next 90 to 180 days
- Inconsistent controls or evidence across business and technology
- Repeat findings or themes from prior cycles
What you receive
- Plain-language risk and control maturity snapshot
- Top ten prioritized gaps with remediation actions and suggested owners
- Evidence readiness pack: what evidence, where it lives, who owns it, and the cadence
- Board-ready readout plus a 30, 60, 90 day operator plan
Engagement timeline
Phase 1
Health Check
2 to 6 weeks
Phase 2(optional)
Remediation
Scoped to gaps
Offering 2
Publish-ready documentation that reflects how you actually operate
Best for
- Documentation that no longer reflects current operations
- Unclear ownership across policies, standards, and procedures
- Upcoming exam or audit putting documentation in scope
What you receive
- Publish-ready policies, standards, and procedures
- Clear roles, ownership, and evidence expectations
- Exam-prep pack with examiner request list and evidence map
- 30, 60, 90 day roadmap for the remaining estate
Two tracks, sold separately. Track A covers business and operational documentation. Track B covers technology documentation. Engagements can run in parallel or sequentially based on scope and capacity.
Engagement timeline
Phase 1
Documentation Assessment
1 to 6 weeks
Phase 2
Documentation Sprint
2 to 6 weeks per document
Calibrated to your charter and your stack
Engagements align to the supervisory authority that examines you and the technical frameworks your control environment is built on.
Charter alignment
Work product references the supervisory authority and exam expectations specific to your charter.
- OCC
- FDIC
- Federal Reserve
- NCUA
- State Supervisory Authorities
Technical framework flexibility
Technology controls map to the frameworks your second line and examiners already use.
- NIST Cybersecurity Framework
- FFIEC
- CIS Controls v8
- ISO/IEC 27001 / 27002
- COBIT 2019
A 15-minute triage call to find the fastest path.
Start a Conversation