These best practices support the view that the FDIC should establish and document a process for identifying procurements of Critical Functions. According to the Government Accountability Office (GAO), the use of a contractor poses a risk of fraud, waste, and abuse. One of the risk management processs four main elements is contract structuring and review. *NIST S.P. Board Reporting. Footnote: 22 According to the FDICs Enterprise Risk Management Standard Operating Procedure (May 2020), Inherent Risk is the exposure arising from a specific risk before any action has been taken to manage it beyond normal operations. In August 2017, a former FDIC senior executive expressed concern with the FDICs contractual relationship with and over-reliance on Blue Canopy. The OIG also concluded the FDIC needed a formal process for reviewing security control assessment reports to ensure that Blue Canopy performed sufficient security control testing. The Contracting Officer works with the Program Office throughout the acquisition process, and, based on the Program Offices nominations, appoints the Oversight Manager and Technical Monitor(s). Learn about the FDICs mission, leadership, As such, Blue Canopy should have had crisis readiness plans in place and should have tested those plans to ensure that it could continue to provide Critical Functions uninterrupted to the FDIC. We found that the FDIC did not have policies and procedures for identifying Critical Functions in its contracts, as recommended by the best practices in OMB Policy Letter 11-01 and embodied in industry standards. The system contains detailed information on contract actions over $3,000, since fiscal year 2004. When procuring Critical Functions, agencies considered (or, considered as a best practice) cost effectiveness analysis, which included analyzing the appropriate mix of Federal employees and contractors and rebalancing, as needed. The FDIC will consider each of the OIGs recommendations and further study the need for additional risk based controls for essential procurements. Agencies performed (or, considered as a best practice) periodic reviews of contractor and agency personnel performance, human capital planning, personnel training, risk management strategy, contract requirements, budget/cost justification, attribution of contractor vs. agency work, and over-reliance assessments. Recommendation 2: Identify Critical Functions during the procurement planning, award, and contract management phases of the acquisition process. However, the FDIC did not make the determination that Blue Canopy provided essential or critical services, even though the Agency dedicated more than 38 percent of its IT security budget to Blue Canopy services. Contract Planning. As noted above, the OIG identified best practices from OMB Guidance, the GAO, industry standards, and Federal agencies. Submit your announcement of an awarded contract for publication by sending a news release to: newsrelease@targetgov.com . According to the FDICs Financial Institution Letter titled Third-Party Risk Guidance for Managing Third-Party Risk (FIL-44-2008) (June 2008), the key to the effective use of a third party in any capacity is for management to appropriately assess, measure, monitor, and control the risks associated with a contractual relationship. All Awards Contracts Contract IDVs Grants Loans Direct Payments Other Financial Assistance Award Obligations $0 Over a 3-year period, from 2017 to 2019, the FDIC awarded nearly 4,000 contracts valued at more than $1.3 billion. Press Esc to cancel. The FDIC did not conduct periodic reviews of controls and processes for Critical Functions obtained from Blue Canopy during the contract management process, even though the Agency dedicated more than 38 percent of its Information Technology security budget to Blue Canopy services in 2019. Our methodology relied on identifying best practices from various reputable sources, including OMB Policy Letter 11-01, GAO reports, industry standards, and other Federal agencies, and comparing the FDICs acquisition process with these best practices. Over a 3-year period, from 2017 to 2019, the FDIC awarded nearly 4,000 contracts valued at more than $1.3 billion. - Program Office provides Statement of Work, and independent cost estimate. To report allegations of waste, fraud, abuse, or misconduct regarding FDIC programs, employees, contractors, or contracts, please contact us via our Hotline or call 1-800-964-FDIC. Management Response: Partially Concur. These services are critical to ensuring the security and protection of the FDICs Information Technology infrastructure and data. The contractor successfully performed all required tasks under both contracts, and received excellent and outstanding ratings in annual performance reviews, with the exception of one good rating on one contract for one rating period. SlVl&Ds@bQ*H9 fA2h4h1BC,0$h*@ 9 If so, whether the FDIC retained sufficient management oversight of Blue Canopy to maintain control of its mission and operations in accordance with best practices. Phase 3: Contract Management - Program Office and DOA Acquisition Services Branch perform periodic reviews of controls and processes and take corrective measures to address (or mitigate the potential risk of) instances of contractor overreliance for a Critical Function, as necessary. )% oYki|Wl{)9hg3(EV{Ih`f=aegasg`c$.hY+ R#@P-0to 1P$C@"WWG5mMsW>ne7#dMyrhkJY-~&tMWkZQG--+d7_#VZ {++Ojb~S+yKoBm#%G8@5p>Wwl)Ng=H]5~,SP"q,1sM/e,1@ vD2Hf3u,2G}H7[]f#[x2 Federal Agencies. Identify missing or insufficient controls in the BOAs and task orders for Managed Security Services Provider and Security and Privacy Professional Services, and implement appropriate corrective actions or compensating controls. conferences and events. As a result, we consider the remaining 12 recommendations to be unresolved at this time. Under the 10-year SITE III contract vehicle, contractors will vie for task orders to support DIA's evolving enterprise IT needs. The OIGs report, Security Configuration Management of the Windows Server Operating System (AUD-19-004) (January 2019), noted that the FDIC hired [Blue Canopy] to assess certain security controls, including configuration management controls, for which the FDIC had also assigned the firm duties related to design and/or execution. Contract Management: Program Office and DOA Acquisition Services Branch ider1tify the Critical 1Fm1ction within contract oversight documents and reports to the FDIC Board. Best Practices: 3. An Executive Agency is a Federal agency that is housed under the Executive Office of the President or one of the 15 Cabinet departments within the Executive Branch. The OIG notes in its report that the FDIC followed its normal contract policies and procedures for the two Blue Canopy contracts. Federal agencies have processes to identify, record, monitor, and report on procured Critical Functions. Institution Letters, Policy Table 2 illustrates the services performed by Blue Canopy that we identified as Critical Functions based on National Institute of Standards and Technology Special Publication 800-53, Revision 5 (NIST S.P. Federal government websites often end in .gov or .mil. In June 2014, the FDIC Board of Directors authorized senior management to contract for services in support of the information security and privacy program and to increase the prior contract ceiling. FDIC is also placing a greater focus on upfront acquisition planning to make sure contracts are properly structured and have meaningful service level agreements (SLAs), appropriate incentive/disincentive structures, and performance metrics. 3501 Fairfax Drive, Room VS-E-9068, Arlington, VA 22226. FDIC will consider and further study potential methodologies for assessing contractor overreliance, including how other agencies make such determinations. In addition, we determined that Blue Canopy performed Critical Functions at the FDIC, as defined by OMB Policy Letter 11-01 and best practices. Footnote: 31 According to FIL-44-2008, for reports, [t]he contract should specify the type and frequency of management information reports to be received from the third party. The Risk Inventory does not identify procured critical functions as a separate and distinct risk. As discussed in this report on Critical Functions, the procedures are not adequate to ensure that periodic reviews are performed to assess the contractor for over-reliance and to identify and implement corrective actions. FF The contract provides various support activities to the Privacy Program. Footnote: 24 Personally Identifiable Information is any information about an individual that can be used to distinguish or trace that individual's identity, or any other personal information that is linked or linkable to that individual. government site. FDIC Contract Portfolio Pricing Arrangements . DMI said it will bring digital transformation tools that usher in a new managed services model, focused on service delivery optimization. The FDIC has also recently implemented new acquisition initiatives to further improve vendor management, contract oversight, and to reduce the number of non-competitive awards. The Federal Deposit Insurance Corporation (FDIC) procures goods and services from contractors in support of its mission. o Perform a Cost Effectiveness Analysis. In addition, NASA considered internal capability when procuring a Critical Function, and CFPB ensured that Contract Officers had appropriate backgrounds, such as Information Technology expertise for procured Information Technology services. In 2019, these services comprised 38.3 percent ($16.2 million) of the OCISOs annual operating expenses ($42.3 million). bankers, analysts, and other stakeholders. Specific relevant items within the risk inventory currently include risks related to cybersecurity, privacy, protection of sensitive information, potential cyberattacks, management and oversight of contracts, adequacy of staffing, and succession planningwhich involves having a sufficient number of the right people with the right skills to meet mission responsibilities. FDIC Total Awards by Socio Economic Categories January 1 -December 31, 2020 $80 $90 $90.0 $70 $58.9 $60 $50.1$20 $30 $40 $50 $45.4 $10 $0 Percent of Total FDIC Awards: $4.5 $8.0 8(a) HubZone $10.8$4.1 Veteran OwnedServiceWomen OwnedSmallMinority OwnedMWOBDisabledDisadvantagedVeteran OwnedBusiness Corrective Action: Existing acquisition planning procedures require consideration and discussion of risks associated with all procurements. ERM provides transparency and accountability in business practices, reporting, and governance, which can improve stakeholder confidence in the agencys work. Reviewed the FDICs policy and procedures, including: o FDIC Acquisition Policy Manual (August 2008); o Acquisition Procedures, Guidance and Information (January 2020) document; and. In this case, the FDIC terminated the service providers contract because of the providers bankruptcy.32 As a result of the service providers failure, the FDIC compressed the procurement planning and solicitation and award processes, and Blue Canopy assumed the previous contract and began providing support services to the FDIC in May 2009 3 months after the companys failure.33 In addition to having limited time to find a replacement contractor, the companys distressed financial condition and ultimate bankruptcy could have impaired or compromised the quality of services provided over an extended period of time as the contractors senior management and employees focused on their companys financial turmoil at the expense of the services provided. Management should periodically evaluate the adherence to and effectiveness of its internal management controls and procedures to address the objectives and requirements of OMB Policy Letter 11-01. Footnote: 5 Contracts CORHQ-14-C-0769 and CORHQ-14-C-0778. Over a 4-year period (2015-2019), the FDICs OCISO spent between 35 percent to 44 percent of its operating expenses annually on Blue Canopy services. The Board authorized a 7 1/2-year term for Security Operations Center and Vulnerability Management Services and a 10-year term for security and privacy professional services. These periodic reviews should be focused on targeted controls or areas of performance (such as personnel performance or human capital planning), and/or performed more broadly (such as a contractor over-reliance assessment). Corrective Action: See response to Recommendation 12. As a result, the GAO recommended that DHS should (1) develop a risk-based approach for reviewing service requirements to ensure proposed service requirements are clearly defined and reviewed before planning how they are to be procured; (2) update the Inherently Governmental and Critical Functions Analysis to provide guidance for analyzing, documenting, and updating the federal workforce needed to perform or oversee service contracts requiring heightened management attention; and (3) [develop] guidance identifying oversight tasks or safeguards personnel can perform, when needed, to mitigate the risk associated with contracts containing closely associated with inherently governmental functions, special interest functions, or critical functions.. Fact Sheets, Key Contacts in Acquisition Services Branch, COVID-19 Safety Protocols for Contractor Employees Accessing FDIC Facilities, Information Technology Application Services (ITAS), Request for Proposal (RFP) for Mission-Driven Bank Funds Financial Advisory Services, Information for Prospective Outside Counsel, Frequently Asked Questions for Outside Counsel on the FDIC's Advanced Legal Information System (ALIS), List of Counsel Available (alpha by Firm Name), List of Counsel Available (alpha by State), Minority- and Women-Owned Law Firms on List of Counsel Available, Personnel Security Process for Candidates, List of Awards and Contractor Contact Information. 1.405(b). OIGs may also use evaluations to share best practices and approaches. 1819(a). Analysis of National Institute of Standards and Technology Guidance, 6. Ultimately, the GAO concluded that without guidance for documenting and updating the planned Federal oversight personnel needed, and identifying oversight tasks, DHS cannot mitigate the risks associated with service contracts in need of heightened management attention. The Federal Deposit Insurance Corp. is looking for IT vendors to provideinfrastructure support services as part of a new multiple-award contract worth up to $487.5 million. According to the FDIC Financial Institution Letter, Third-Party Risk Guidance for Managing Third-Party Risk (FIL-44-2008) (June 2008), an effective risk management process should identify, in part, contractual requirements that would be critical to the ongoing assessment and control of specific identified risks. o Perform Periodic Reviews. Business Resumption and Contingency Plans.35 As part of the procurement risk assessment, or as a separate management oversight strategy, an agency should identify the contract structure and key contract provisions, such as the review and testing of business resumption and contingency plans. The GAO report, Human Capital: Additional Steps Needed to Help Determine the Right Size and Composition of DODs Total Workforce (GAO-13-470) (May 2013), found, in part, that DODs current policies did not fully reflect federal policy concerning the identification of Critical Functions. important initiatives, and more. However, it did not address how the Contracting Officer and Oversight Manager would assess the FDICs over-reliance on Blue Canopy or identify and implement corrective actions. Best Practices for Critical Functions by Source, 2. In October 2019, the FDIC changed its procurement strategy for the two contracts to two Basic Ordering Agreements (BOA)12 and included multiple service providers on the BOAs. The failure to establish or maintain a proper control environment jeopardizes the reasonable assurance that an entitys objectives will be achieved, and may affect the ability of an entity to maintain control of it mission and operations. important initiatives, and more. Following the FDICs study and actions in response to Recommendation 1, the CIOO will assess the need for additional periodic reviews of such contracts and whether additional enhancements are required beyond the controls already incorporated. : 10; Corrective Action: Taken or Planned - The FDIC plans to address this recommendation through the study and actions described in its response to Recommendation 1.; Expected Completion Date: March 31, 2022; Monetary Benefits: $0; Resolved-a - Yes or No: No; Open or Closed-b: Closed; Row 11: ; Rec. : 13; Corrective Action: Taken or Planned - The FDIC will consider additional reporting requirements related to contracts for essential functions or for services necessary during a business continuity event, including where such functions are performed by a single vendor, in conjunction with the study and actions described in response to Recommendation 1.; Expected Completion Date: March 31, 2022; Monetary Benefits: $0; Resolved-a - Yes or No: No; Open or Closed-b: Closed; 1. The Board of Directors must approve all contract actions over $20 million. DHS also lacked guidance on what these oversight tasks could entail. Since the FDIC relied on Blue Canopy to provide human capital (staffing) in key areas of information security and privacy, the FDIC needed to supervise and manage how Blue Canopy would continue to provide its services in the event that Blue Canopys human capital was impaired or negatively impacted by significant events. Appendix 1 Objectives, Scope, and Methodology, 1. The https:// ensures that you are connecting to Periodic Reviews of Controls and Processes. Determine when and how to assess for contractor over-reliance as part of the management oversight strategy. SlVl&!MDs@bQ*P fA24k42P %c : banking industry research, including quarterly banking Conduct a procurement risk assessment for Critical Functions during the procurement planning process, for each contract involving Critical Functions. Challenge, Quarterly Banking Profile for Fourth Quarter 2022, Quarterly Banking Profile for Third Quarter 2022, FDIC Releases 2021 National Survey of Unbanked and Underbanked Households, Financial Identify planned procurement of Critical Functions. As noted above, the OIG identified best practices from OMB Guidance, the GAO, industry standards, and several other Federal agencies. Some of the risks are associated with the underlying activity itself, similar to the risk faced by an institution directly conducting the activity. The oversight manager ensures that the contractor delivers the required goods or performs the work according to the contract and the delivery schedule, monitors the expenditure of funds, and approves invoices. The FDIC did not develop a management oversight strategy for Critical Functions obtained from Blue Canopy during the procurement planning process, as part of the procurement risk assessment. DODs policies and procedures predated the publication of this requirement, and consequently contained no reference to it. [Text box Prior OIG report. Recommendation 7: Revise the management oversight strategy for the procured Critical Functions performed under the BOAs for Managed Security Services Provider and Security and Privacy Professional Services to ensure that the strategy aligns with best practices. The official also stated that, in conjunction with the IGCE, the CIOO conducted an analysis to determine whether the FDICs costs associated with Information Security and Privacy support services were in line with other Federal agencies. OMB Policy Letter 11-01 requires agencies to identify and ensure that they retain control over Critical Functions that are core to the agencys mission, but may be contracted out to the private sector. Signature Bank, New York, NY, and Silicon Valley Bank, Santa Clara, CA, FDIC National Survey of Unbanked and Underbanked Households, Quarterly Banking 3. In addition, GSA, NASA, USDA, DOE, OCC, NCUA, and CFPB have procedures to oversee the contractors performance and their own personnels oversight of a contractor. As a result, the FDIC also did not implement heightened contract monitoring activities for Critical Functions as stated in OMBs Policy Letter 11-01, and best practices identified and used by other government agencies. The interactive forecast dashboard statistically predicts when contracts will be signed. The FDIC relies on the results of security control assessments to identify security weaknesses and inform key risk management decisions. Within this report, the OIG recommended that the FDIC [e]stablish requirements to ensure the independence of security control assessors. -]. The GAO report, DHS Service Contracts: Increased Oversight Needed to Reduce the Risk Associated with Contractors Performing Certain Functions (GAO-20-417) (May 2020), found, in part, that DHS did not consistently plan for the level of Federal oversight needed for certain contracts because there was no guidance on how to document and update the number of Federal personnel needed to conduct oversight. The FDICs procedures do not separately designate certain contracts as related to critical functions., FDIC Consideration of the OMB Policy Letter and Certain OIG-Identified Practices, The FDIC takes seriously its responsibility to maintain control of its operations and to ensure that it has sufficient and knowledgeable federal staff to oversee contractors, particularly those performing services essential to the FDICs mission. The FDIC develops detailed board cases for individual procurements exceeding $20 million that discuss procurement costs, benefits, alternatives considered, management oversight strategy, and other information. Federal Contract Awards > 100.0k 75D30118C02507 Definitive Contract $4.2m / $27.7m Updated Apr 29 2023 Federal Agency CDC Pittsburgh (HHS - CDC) Child Awarded Vendor Idoneous Educational Services, Inc. - VRLMHESN3KP5 Major Defense Program Not listed Award Date Sep 01 2018 Completion Date Aug 31 2020 Set Aside 8 (a) Sole Source NAICS Category 561110 The FDIC will also complete an annual performance review of MSSP and SPPS contractors. We also reviewed documentation and interviewed employees familiar with Blue Canopys work to determine if the FDIC maintained control of its mission and operations. In particular, the official stated that the IGCE included a comparison of the costs to conduct the planned activities internally against the cost for a vendor(s) to perform those same activities. The FDIC annually captures the risks it faces through its Enterprise Risk Management Risk Inventory. hdQK0iAl,H+rFy=Tf^;R6xyua:p@vbfN #iF^B3\xMVewU~~;!#GLCUj'7oN7~ 1!Gb^zB4XdiMVndwx` Xn In addition, OMB Policy Letter 11-01 established a definition for a Critical Function as "a function that is necessary to the agency being able to effectively perform and maintain control of its mission and operations. The OIG previously reported on the FDICs implementation of Enterprise Risk Management and concluded that improvements will help ensure that risks across the FDIC are considered, for example, as part of operations support and program management. In addition, the GSA and OCC report on procurement actions through the Federal Procurement Data System-Next Generation (FPDS-NG),* which includes those designated as Critical Functions. Best Practices: 4. Additional information on contract and contractor performance is provided in quarterly reports to the FDIC Board. No. endstream endobj 515 0 obj <>stream documentation of laws and regulations, information on Contractors provide a multitude of staff with highly specialized technical skills and knowledge in current industry best practices and regulations. The services provided under this contract included intrusion monitoring; incident investigation; event escalation; reporting; vulnerability research, analysis, and response; incident detection; incident response; and after-hours support. The FDIC took prompt action to address security control testing sufficiency before OIG issued the January 2019 audit report. Figure 2: Best Practices for Identifying Planned and Procured Critical Functions. Similarly, the Board meeting minutes did not identify the procured services as Critical Functions. As a result, the GAO recommended, in part, that DOD should revise existing workforce policies and procedures to address the determination of the appropriate workforce mix. In particular, the Federal Deposit Insurance Act authorizes the FDIC [t]o make contracts, [t]o appoint such officers and employees to define their duties, and [t]o prescribe, by its Board of Directors, bylaws regulating the manner in which its general business may be conducted.. In addition, routine reviews ensure that both contractor and agency staff know their roles and responsibilities in the event of an unexpected incident, and validate the planned response. For such matters, the analysis should be considered integral to the banks overall strategic planning, and should thus be performed by senior management and reviewed by the board or an appropriate committee.. Browse our extensive research tools and reports. 514 0 obj <>stream Such heightened contract monitoring activities would include: (1) performing a procurement risk assessment, (2) establishing a management oversight strategy, (3) conducting periodic reviews, and (4) providing formal reports to the Board on an individual and aggregate basis. Footnote: 8 The Contracting Officer is responsible for ensuring the performance of all actions necessary for efficient and effective contracting, ensuring compliance with the terms of contracts, and protecting the interests of the FDIC in all of its contractual relationships. The FIL clearly explains that the guidance should not be considered as a set of required procedures. The FDIC disagrees with any suggestion that the agencys existing comprehensive, risk-based procurement framework does not meet the third-party risk management principles outlined in the FIL. %PDF-1.6 % Specifically, the FDIC calculated that it would cost the FDIC an additional $2.55 million to procure the services ($26,387,825 versus $23,834,747).29 However, the FDIC did not include this information in the Board Case Package, nor was it discussed with the Board as demonstrated by the corresponding Board minutes. FDIC Actions Taken to Address Prior OIG Concerns Regarding Blue Canopy Contracts. One of the risk management processs four main elements is oversight. NASA, USDA, and CFPB performed, or considered it a best practice to perform, strategic human capital planning. However, to meet its fiduciary responsibility to the taxpayers, the agency must have sufficient internal capability to control its mission and operations Sufficient internal capability(i) generally requires that an agency have an adequate number of positions filled by Federal employees with appropriate training, experience, and expertise to understand the agencys requirements, formulate alternatives, take other appropriate actions to properly manage and be accountable for the work product, and continue critical operations with in-house resources, another contractor, or a combination of the two, in the event of contractor default; and (ii) further requires that an agency have the ability and internal expertise to oversee and manage any contractors used to support the Federal workforce Determinations concerning what constitutes sufficient internal capability must be made on a case-by-case basis taking into account, among other things the: (i) agencys mission; (ii) complexity of the function and the need for specialized skill; (iii) current strength of the agencys in-house expertise; (iv) current size and capability of the agencys acquisition workforce; and (v) effect of contractor default on mission performance. As part of acquisition planning, agencies shall confirm that for the Critical Functions to be procured, the agency has sufficient internal capability to control its mission and operations. The .gov means its official. As recommended in OMB Policy Letter 11-01, the APM details pre- and post-award responsibilities to avoid contracts for inherently governmental functions.6 The APM emphasizes the importance of being fully aware of contract terms, contractor performance, and contract administration to ensure that appropriate FDIC control is preserved. In this section, we show which sub-agencies of Federal Deposit Insurance Corporation (FDIC) have issued awards through different types of contracts or financial assistance and how much each sub-agency has obligated (promised to spend). The Risk Inventory includes an assessment of impact and likelihood, and risks are prioritized and summarized into one of four risk levels: critical, significant, moderate, and low.
Shooting On Hollywood Blvd Today,
Can You Record Bt Sport On Sky Q,
Manchester Gangland Families,
Is Kirsten Gillibrand Up For Reelection In 2022,
Killeshandra Lakes Fishing,
Articles F
