Latest Blog Articles

Read the Latest Blog Posts
Knowledge. Useful. Quick. 


Stay up-to-date by reading useful articles from industry thought leaders who tackle common challenges and discuss current or proposed industry regulations.

  • The 21st Century ROAD to Housing Act became the biggest piece of financial institution (FI) legislation in years this month, easing supervisory burden on exam cycles and board meetings while adding new formal requirements around appraisal disputes. AML enforcement and rulemaking sent a clear signal: a compliance program that exists on paper doesn't hold up against what's happening inside an account. A $79 million forfeiture case and a $9.7 million BSA/AML settlement both delivered that lesson this month, and the Federal Reserve issued its own AML proposal on top of it. Want a deeper dive into the latest headlines? Watch the August Reg Update podcast. For additional resources and regulatory analyses, check Ncomply .
  • An outage recovery, regulators' growing appetite for vendor answers, and a vendor script quietly rerouting cryptocurrency. Here's what's happening this month in third-party risk management news.
  • In a dynamic risk and regulatory landscape, internal audit is more critical—and more complex—than ever. Financial institutions must rely on both audits and compliance reviews to identify risk, reveal process gaps, and ensure adherence to compliance standards . While these two functions share common goals, there are key differences in their approach, scope, and purpose. An audit is a formal, independent examination of a process, report, or system's effectiveness and accuracy. A compliance review is a check performed by a financial institution's own compliance department to confirm that staff are following internal policies and regulatory requirements.
  • Your third-party relationships carry real risk, and when one fails, the impact rarely stops at a single point — it ripples across operations, compliance, and your reputation. Vendor risk assessments are how you get ahead of it. This guide covers what they are, what they examine, and how to conduct them effectively.
  • Vendor breaches, regulatory shifts, and the governance gaps in between. Here's what happened this month in third-party risk management news.
  • You know what the Community Reinvestment Act is, but are you prepared for your next exam?
  • Risk management and compliance never stand still — neither do we. With Ncontracts’ Knowledge as a Service (KaaS) approach, you always have the latest content and regulatory insights at your fingertips.
  • The Securities and Exchange Commission's (SEC) fiscal year ends September 30. That deadline has a way of accelerating activity, including the issuance of sweep letters.
  • TruStage, a third-party financial services provider, shut down its network after a cybersecurity incident, and credit unions across the industry are now working through what that means for their members. Here's what's known so far and what it means for credit unions caught in the middle. Take this moment to better understand how your financial institution (FI) can strengthen its own business resiliency and incident response plans if a critical vendor ever goes dark. Related: Business Continuity Planning and Disaster Recovery: The Differences