In part 2 of the Basic Banking and Credit for New Americans series, take a deeper dive into banking in the U.S. Learn how to choose the right bank, type of account, and financial services that best fit your unique financial and personal situation.
Download ⚹⚹⚹ https://tlniurl.com/2zCoUK
This Resource Center is frequently updated, and you may sign up for email updates on important regulatory guidance, cybersecurity alerts, and other information related to cybersecurity in the financial services sector by going to the DFS Email Updates Signup Page and subscribing to Cybersecurity Updates. These emails will come from the email address [email protected].
Under N.Y. Banking Law 590(2)(b-1), an Exempt Mortgage Loan Servicer needs to notify DFS that it will act as a servicer. Since the notification is not an authorization from the Department, an exempt Mortgage Loan Servicer is not a Covered Entity under 500.1(e). However, if an Exempt Mortgage Loan Servicer also holds a license, registration, or received approval under the provisions of Part 418.2(e), it will be considered a Covered Entity and required to comply with the Cybersecurity Regulation. Given the increasing cybersecurity risks that all financial services organizations face, DFS strongly encourages all financial institutions, including those Exempt Mortgage Loan Servicers that are not Covered Entities, to adopt cybersecurity protections consistent with those required by Part 500.
Yes. Section 500.17(a) requires a Covered Entity that has been impacted by a Cybersecurity Event that occurred at one of its Third-Party Service Providers to notify DFS if the Covered Entity is also required to notify any government body, self-regulatory agency, or any other supervisory body. This is required of the Covered Entity even if the Third-Party Service Provider also notifies DFS. Reporting Cybersecurity Events such as these enables the Department to more rapidly identify techniques used by attackers and alert industry, respond quickly to new threats, and continue to protect consumers and the financial services industry.
Unfortunately, ransomware attacks continue to threaten financial services companies and their customers. DFS, like the FBI and other regulators, recommends against paying ransoms. While Covered Entities are not prohibited from making such payments, as of December 1, 2023, a Covered Entity that has made an extortion payment in connection with a cybersecurity event that occurred on its Information Systems must file a Notice of Extortion Payment within 24 hours of payment. Within 30 days of payment, the Covered Entity will be required to provide the reasons payment was necessary, alternatives to payment that were considered and the diligence, or research, it conducted to find these alternatives. Furthermore, the Covered Entity must describe the diligence it performed to ensure compliance with all applicable rules and regulations including those of the Office of Foreign Assets Control. 500.17(c). To notify DFS of an extortion payment, please go to the DFS Portal and follow the Instructions on How to Report an Extortion Payment (PDF).
To safeguard financial services organizations and the confidential information of New Yorkers, DFS uses a multi-pronged approach to monitor cyber risk. The cyber supervision program supplements traditional examinations with new types of information-gathering and analysis activities intended to create a holistic view of the cybersecurity risk posture of the thousands of New York financial services firms regulated by DFS.
DFS will periodically ask Covered Entities to complete assessment questionnaires, such as the Cybersecurity and Information Technology Baseline Risk Questionnaire. Such questionnaires will be independent of the examination process and are based on similar assessments used by industry and insurers to assess risk for financial services companies.
The CIP rule acknowledges that there may be circumstances in which a firm may be able to rely on the performance by another financial institution of some or all of the elements of a firm's CIP. Therefore, the rule provides that a CIP may include procedures specifying when the broker-dealer will rely on the performance by another financial institution (including an affiliate) of any procedures of the broker-dealer's CIP, with respect to any customer of the broker-dealer that is opening an account or has established an account or similar business relationship with the other financial institution to provide or engage in services, dealings, or other financial transactions.
Per the Bank Secrecy Act, every year you must report certain foreign financial accounts, such as bank accounts, brokerage accounts and mutual funds, to the Treasury Department and keep certain records of those accounts. You report the accounts by filing a Report of Foreign Bank and Financial Accounts (FBAR) on Financial Crimes Enforcement Network (FinCEN) Form 114.
The FDIC provides a wealth of resources for consumers, bankers, analysts, and other stakeholders. Browse our collection of financial education materials, data tools, documentation of laws and regulations, information on important initiatives, and more.
To promote and assure the financial health, stability, quality and integrity of Vermont financial service providers. The Department also strives to secure full access for Vermonters to financial services and to protect the public through the consistent enforcement of the laws and regulations necessary to the operation of a safe, sound and responsible marketplace and through consumer outreach and education.
Q: Does Regulation Best Interest apply if a broker-dealer makes a recommendation of a securities transaction or investment strategy involving securities to a regulated financial services industry professional for his or her own account?
Broker-dealers are currently subject to supervisory obligations under federal securities laws and regulations, as well as applicable self-regulatory organization rules, and broker-dealers could choose to satisfy the Compliance Obligation by adjusting/building upon their current systems of supervision and compliance, as opposed to creating entirely new systems. (Posted February 11, 2020)
A person associated with a registered public accounting firm shall not take or omit to take an action knowing, or recklessly not knowing, that the act or omission would directly and substantially contribute to a violation by that registered public accounting firm of the Act, the Rules of the Board, the provisions of the securities laws relating to the preparation and issuance of audit reports and the obligations and liabilities of accountants with respect thereto, including the rules of the Commission issued under the Act, or professional standards.
Note 1: Under Rule 3520, a registered public accounting firm or associated person's independence obligation with respect to an audit client encompasses not only an obligation to satisfy the independence criteria applicable to the engagement set out in the rules and standards of the PCAOB, but also an obligation to satisfy all other independence criteria applicable to the engagement, including the independence criteria set out in the rules and regulations of the Commission under the federal securities laws.
Note 2: Rule 3520 applies only to those associated persons of a registered public accounting firm required to be independent of the firm's audit client by standards, rules or regulations of the Board or Commission or other applicable independence criteria.
A registered public accounting firm is not independent of an issuer audit client if the firm, or any affiliate of the firm, during the professional engagement period provides any tax service to a person in a financial reporting oversight role at the issuer audit client, or an immediate family member of such person, unless -
Note: In an engagement for an issuer audit client whose financial statements for the first time will be required to be audited pursuant to the standards of the PCAOB, the provision of tax services to a person covered by Rule 3523 before the earlier of the date that the firm: (1) signed an initial engagement letter or other agreement to perform an audit pursuant to the standards of the PCAOB, or (2) began procedures to do so, does not impair a registered public accounting firm's independence under Rule 3523.
In connection with seeking audit committee pre-approval to perform for an issuer audit client any permissible non-audit service related to internal control over financial reporting, a registered public accounting firm shall -
A money services business that conducts currency exchange or money transmission activities as defined by Chapter 152 of the Texas Finance Code must be licensed by the Department. However, a licensed money service business (MSB) may appoint authorized delegates to conduct money transmission on its behalf that are not individually licensed by the Department. The Department is responsible to protect the interests of Texas consumers who use MSBs by ensuring the overall financial condition of the MSB is sound and the MSB is properly monitoring transactions to deter money laundering, terrorist funding, or financial crimes from occurring.
Any and all persons designated and authorized to transact business on behalf of an account. Each account holder's signature needs to be on file with the bank. The signature authorizes that person to conduct business on behalf of the account. See related questions about Joint Account Holder Overdraft Opt-In, Joint Account Check Endorsement, and Joint Account Liability.
A computerized facility used by member depository institutions to electronically combine, sort, and distribute inter-bank credits and debits. ACHs process electronic transfers of government securities and provided customer services, such as direct deposit of customers' salaries and government benefit payments (i.e., social security, welfare, and veterans' entitlements), and preauthorized transfers. See related questions about Electronic Transactions.
760c119bf3