Skip to content
Navanta logo - homepage
  • 877-778-7774
  • Support
    • Our Story
    • Our People
    • Join Our Team
    • View All Solutions
    • Core Banking
    • Managed IT
      • Bankers Private Cloud
      • Flex+
      • Cybersecurity
      • M365 Management
    • CRM
    • Advisory
      • Virtual CIO
      • Virtual ISO
      • Security Awareness Training
    • View All Resources
    • Blog Posts
    • In the News
    • Client Experiences
      • Core Banking
      • Cyber Attacks
      • Exams & Audits
      • Information Security
      • Managed IT
    • Events & Webinars
  • Brand FAQs
  • Contact
      • Our Story
      • Our People
      • Join Our Team
      • View All Solutions
      • Core Banking

        Keep community focus with a core that runs reliably.

      • Managed IT

        Simplify banking IT with one trusted partner.

      • CRM

        Know every customer. Grow every relationship

      • Advisory

        Navigate IT and risk with clarity and confidence.

      • Have something in mind?
        Bankers Private Cloud
      • Flex+
      • Cybersecurity
      • M365 Management
      • Virtual CIO
      • Virtual ISO
      • Security Awareness Training
      • View All Resources
      • Browse By Type
        Blog Posts
      • In the News
      • Client Experiences
      • Events & Webinars
      • Browse by Topic
        Core Banking
      • Cyber Attacks
      • Exams & Audits
      • Information Security
      • Managed IT
  • Brand FAQs
  • Contact
Blog Post

Enhance Risk Management with Key Takeaways from the FFIEC DA&M Booklet

CYBERATTACKS

Navigating the August 2024 update of the FFIEC Development, Acquisition, and Maintenance Booklet can indeed be daunting due to its comprehensive detail. The upgraded booklet, which updates the previous version from 2004, provides significantly more detail on how financial institutions can effectively manage risks during the development, acquisition, maintenance, and delivery of new initiatives.

This blog post provides a concise overview and essential insights to assist financial institutions (FIs) in understanding the guidance and improving their operational strategies. It is important to understand that this guidance applies to all FDIC-supervised institutions and their service providers. 

The updated booklet prominently highlights enhanced details on project and change management principles, while emphasizing the crucial importance of operational resilience. This combined focus aims to strengthen an institution's project planning and implementation processes for all projects, with particular emphasis on those that are highly critical. By prioritizing resilience, FIs can ensure continued operations and mitigate risks during times of change or disruption, safeguarding their stability and service reliability.

Here are two steps your FI can take to help manage these new expectations:

1. Review and update your written project management policies and procedures

Examiners will be looking for FIs to have an enterprise-wide, process-based approach to ensure that risks are assessed and managed in relation to the unique attributes of a new project or engagement. This expectation includes a focus on a customized approach to project management. Significant projects will require a more in-depth approach. To assist with understanding what makes a project unique, the booklet references examples to help illustrate differentiating perspectives.

2. Review and update your written third-party or vendor management due-diligence methodology and associated procedures

Standards for acquiring systems, components, or services have long been an important focus for FIs in mitigating risk. However, the industry’s expanded reliance on Third Party Service Providers (TSPs), including FinTechs, has resulted in the exposure of customer data and disruption of the delivery of products/services (E.g., 2023 MOVEit mass hack, 2024 CrowdStrike data breach).

The focus on TSPs also aligns with the FFIEC’s focus on operational resilience including the increased importance of:

  • Business continuity/incident response planning (resilience) for critical third-party relationships
  • A higher expectation for due diligence of foreign-based entities
  • An emphasis on supply chain considerations

The booklet's main goal is to emphasize the importance of management identifying, planning for, and addressing potential operational weaknesses with high-risk TSPs. This includes fintech organizations and foreign entities. These critical TSPs must have business continuity plans, incident response plans, and other documented operational resilience procedures. This will also assist in ensuring a successful business partnership while mitigating the risk of significant business service disruption and the exposure of NPI.

In summary, equipped with these strategies, your FI can bolster its operational resilience and effectively mitigate risks associated with project and change management, especially with significant or highly critical projects and high-risk TSPs. By adopting a proactive approach, your institution can significantly reduce the negative impact of crises on its operations.

By Navanta • March 29, 2026

Join our Email Newsletter

More in Cyberattacks

  • Pennies
    BLOG POST

    Industry Update: Preparing for Operational Changes Related to Pennies and Cash-Handling Practices

    VIEW DETAILS
  • BLOG POST

    Why We Chose to Partner with the Cyber Risk Institute (CRI)

    VIEW DETAILS
  • BLOG POST

    A Guide to Selecting the Right Replacement for the FFIEC CAT

    VIEW DETAILS
Navanta logo - homepage
  • Linkedin
  • Get to Know Us
    • Our Story
    • Our People
    • Join Our Team
  • Find Your Solution
    • Core Banking
    • Managed IT
    • CRM
    • Advisory
  • Explore Resources
    • Blog Posts
    • Client Experiences
    • Events & Webinars
  • Contact Us
    • 877-778-7774
    • [email protected]

  • 877-778-7774
  • Support
  • Privacy Policy
© 2026 Navanta

Client Login

  • MyBPC

    Previously MyBankonIT. Log in here to access your client portal for Bankers Private Cloud.

    Sign In

  • theSafeTM

    Sign in here to access your account information and resources in theSafe as usual.

    Sign In

  • Navanta CRM

    Previously Quest Analytics IQCRM. Continue to use these existing CRM links:

    Product Updates Technical Requirements CRM Email Support