


Table of Contents
Share with network
Related Insights
Fifteen years after the financial crisis that led to its creation and six and a half years since the issuance of ASU 2016-13, the implementation date for current expected credit loss methodology (CECL) has finally come and gone. As with many areas of CECL, regulatory guidance explaining when model validations are warranted versus when an internal audit may be appropriate, has been infrequent and ambiguous. To make this determination more confusing, there are wide-ranging definitions of the word “validation” being used by vendors across the industry. In this article, we discuss the difference between an internal audit and a validation and provide some perspective on items to be considered when making the determination as to which is more appropriate for your institution.
[hubspot portal="23546948" id="8511bf87-e8d6-4949-a93f-5c445707f203" type="form"]


Strengthen your cybersecurity with these 8 essential changes based on real-world risk assessments. Learn how to update inventories, secure backups, implement MFA, and develop an incident response plan to protect your organization from cyberattacks.


Discover the top three web application vulnerabilities identified in penetration tests: broken access control, security misconfiguration, and insecure design. Learn how these flaws align with OWASP Top Ten risks and why regular web application testing is essential for cybersecurity.


Discover how Governance, Risk, and Compliance (GRC) tools enhance efficiency, security, and visibility in managing IT and business risks. Learn how automated workflows and real-time reporting can streamline compliance and improve organizational resilience.

Learn how pass-through entity (PTE) tax elections can help business owners bypass the federal SALT deduction cap. Explore state-specific rules, potential tax savings, and key considerations to determine if this election is right for your business.


Understand the differences between automated and manual penetration testing to strengthen your cybersecurity. Learn how expert-led testing mimics real-world cyber threats, uncovers critical vulnerabilities, and enhances your security posture.