By Ray Birch
DES MOINES, Iowa—As credit unions hustled to assist members and keep their teams safe as the pandemic struck, one analysis reveals there were some big gaps in CU business continuity plans related to a host of issues ranging from third parties to the testing of plans to remote systems availability and more.
And one of those gaps is an area PolicyWorks says was easy to overlook—vendors.
“I think one of the biggest misses for credit unions--and I don’t want to say they forgot--was that they didn't tend to follow up with the vendors they use today and learn what their vendors are doing from a (business continuity plan) perspective,” stated Jeremy Smith, PolicyWorks’ director of client partnerships.
Smith’s comments are being featured as part of a series in CUToday.info examining how strategic planning is changing in 2020 as a result of the coronavirus pandemic and resulting economic and consumer behavior changes. The first installment in the series can be found here; the second here.
Smith pointed to a PolicyWorks study that polled 115 CUs seeking answers to questions that assessed their performance during the pandemic. “I just think that flew under the radar, and a lot of folks just didn't really account for vendors in their plans.”
Smith emphasized third-party vendors are closely intertwined with the majority of credit union operations today, making most essential to continued operations.
Smith said another finding worthy of attention is that most CU business continuity plans failed to even consider how a pandemic might affect the operations of businesses across the country.
“The study shows that less than half, or 44%, of credit unions contacted their critical suppliers and vendors during the COVID-19 crisis to ensure services would be maintained,” Smith shared. “Credit unions rely on so many partnerships and technologies to give members services; this kind of task can seem overwhelming.”
Start With One Bite
With credit unions still dealing with the pandemic while also attempting to put together their own plans for 2021, Smith’s recommendation is credit unions take on the challenge “one bite at a time.”
“Maintain a collection of documented BCPs from vendors. Request updated BCPs and the findings from vendors’ BCP testing annually,” he recommended. “Credit unions should share their own documented BCPs and test results with each vendor annually, as well.”
Smith further suggested business continuity team members each have a set of vendors to contact during a widespread emergency, accompanied by the creation a cloud-based spreadsheet to capture findings and bring to the top those vendors that appear to be red flags.
One reason for the gaps in many BCP plans, according to Smith, is credit unions often create plans, put them on shelves and never revisit or test the plan, often over an extended period.
“Credit unions know they need to have a plan, but I think for a lot of folks they may have just had the plan sitting around … kind of checking the box,” Smith said.
Room for E-Improvement
As CUToday.info extensively reported, there are numerous examples from throughout the CU community of successful and quick transitions to remote workforces. Yet Smith cautioned technology remains a prime area for improvement should another crisis strike.
In the PolicyWorks’ study, eight out of 10 credit unions that assessed their business continuity plans found they were not able to conduct critical functions remotely.
“This means just 20% were prepared to continue key processes, such as payroll and production, without team members onsite,” Smith explained. “While it may be tempting to think of this as an IT issue, BCP teams can have tremendous influence on how well—or even if—the credit union’s systems and business records are available to remote teams.”
What’s Often Lacking
According to Smith, the ideal BCP includes strategies for prioritizing and preparing systems and data for a range of disruptive events. Yet those strategies were often lacking with many CU plans.
“The simple inclusion of items will help you understand what the business has defined as successful disaster preparation—a list of the systems and applications without which the credit union could not operate,” he said. “These are the systems and applications that, if interrupted, would result in serious impacts to financial, regulatory, legal, production or member experience processes.”
To that end, Smith noted a credit union’s business continuity plan should include contingencies for operating systems and applications that depend on either one key employee or the inverse, require a large number of employees.
“This should also include a list of cross-trained employees and the systems and applications they can operate if necessary,” he said.
A Surprise
One way to avoid the surprise of discovering just what the plan is lacking when an emergency or crisis arrives is to instead conduct “surprise” testing of sytems, applications and staff, Smith told CUToday.info.
“Without prior warning, employees are instructed to perform their duties from a home workspace and to report successes and failures to a designated manager,” Smith said.
But what is perhaps most important, Smith said, is establishing procedures for regular maintenance and testing of a secure, remote file repository that stores critical data and documents.
“I think credit unions fell down pretty badly in their plans regarding remote systems availability,” he said, citing study findings. “I think one of the biggest things we found is not that people didn’t have the technology to work remotely, such as laptops, is credit unions failed in keeping people connected with regard to access to key resources, such as a centralized file repository.”
One Final Finding
Finally, Smith said the study revealed credit union plans were inconsistent when it came to planning around how lobby closings and processes for serving members would be handled across all locations.
“There weren't any hard and fast rules around staying open or closing an office,” Smith explained. “Credit unions were a little wishy-washy here, and a lot of decisions depended on the local conditions, the local membership and community. They need more formal rules and guidelines here.”
