


Table of Contents
Share with network
Related Insights
Fifteen years after the financial crisis that led to its creation and six and a half years since the issuance of ASU 2016-13, the implementation date for current expected credit loss methodology (CECL) has finally come and gone. As with many areas of CECL, regulatory guidance explaining when model validations are warranted versus when an internal audit may be appropriate, has been infrequent and ambiguous. To make this determination more confusing, there are wide-ranging definitions of the word “validation” being used by vendors across the industry. In this article, we discuss the difference between an internal audit and a validation and provide some perspective on items to be considered when making the determination as to which is more appropriate for your institution.
[hubspot portal="23546948" id="8511bf87-e8d6-4949-a93f-5c445707f203" type="form"]


Credential overlap, often mistaken for credential stuffing, is a major cybersecurity risk caused by password reuse across multiple accounts. This article explores how attackers exploit this weakness, insights from Elliott Davis penetration tests, and practical strategies to strengthen security and prevent unauthorized access.


The SEC’s new cybersecurity disclosure rules now require public companies to report material cybersecurity incidents within four business days and provide detailed risk management disclosures in annual reports. Organizations must assess the materiality of cyber threats, outline board oversight, and describe management’s role in mitigating risks to ensure transparency for investors.