Drive a Connected GRC Program for Improved Agility, Performance, and Resilience
Discover Connected GRC Solutions for Enterprise and Operational Resilience
Explore What Makes MetricStream the Right Choice for Our Customers
Discover How Our Collaborative Partnerships Drive Innovation and Success
Your Insight Hub for Simpler, Smarter, Connected GRC
Learn about our vision and mission

An independent U.S. federal regulatory agency, responsible for insuring deposits and protecting the safety and soundness of a credit union system spanning more than 6,500 institutions, wanted to establish a consistent and scalable process for regulatory exams and audits. That meant replacing a 25-year-old regulatory exam management tool with a modernized, efficient solution.
Using MetricStream’s Internal Audit Management, the agency streamlined and standardized regulatory exams, audit data collection, and reporting across thousands of financial institutions. Exams can now be conducted virtually to evaluate compliance.
What’s more, powerful reports and analytics provide comprehensive visibility into the risks and compliance gaps at financial institutions. This helps the agency act faster to build a safer and sounder financial system.
Building confidence in the financial system is a monumental task, especially when it involves assets worth over one trillion dollars spread across thousands of financial institutions. The agency regularly audits these institutions, so that any risks or compliance gaps that exist can be mitigated before they spiral into larger systemic issues.
However, a 25-year-old regulatory exam tool was slowing the agency down. Moreover, the financial institutions under the agency’s purview had developed their own audit frameworks and processes. This created inconsistencies that hampered the agency’s regulatory exam efforts.
It was time to overhaul the system, and establish a more standardized, efficient auditing process.
Companies on their GRC (governance, risk, and compliance) journey often tend to put the cart before the horse. They choose a GRC technology solution first, and then try to fit their business processes to it. However, the agency recognized that the better approach was to let the business drive the choice of technology. So, their first step was to outline their business requirements:
The next step was to look for a scalable GRC solution that would meet these objectives. The tool had to help minimize exam redundancies, enable the secure exchange of data, and strengthen risk identification. Analytics and 360-degree views of data were also essential.
MetricStream ticked all these boxes.
With MetricStream’s Internal Audit Management, the agency has replaced its legacy tool with a modern regulatory exam and risk identification solution that can adapt quickly to regulatory and industry changes.
The tool streamlines regulatory exams and audits, driving greater efficiency and consistency. Examiners can easily document their findings, issue reports to financial institutions, and follow up with them in a systematic manner.
With automation at every step, time spent on reviews and reporting has decreased by 25%, while time to resolve issues reduced by 30%. Annual exam planning and resourcing has also become faster and more cost-efficient.
Exams can now be conducted virtually, enabling the agency to save time and costs. Moreover, state supervisory authorities (SSAs) can seamlessly collaborate with the agency through MetricStream, reducing redundancies in exams.
As part of an exam or audit, financial institutions are required to submit various documents. With MetricStream, they can directly and securely upload these documents to the agency’s system instead of emailing them.
The agency, in turn, can distribute exam findings and reports to financial institutions via the solution and request additional documents as needed. In essence, they have a secure, quick way to communicate across the regulatory exam ecosystem.
By establishing a common risk and compliance taxonomy, the agency has simplified risk reporting and monitoring. A centralized GRC library makes it easy to understand the interconnections between risks, controls, issues, and other GRC elements.
Key metrics from each financial institution are rolled up and consolidated in a single source of truth. So, at any point, the agency has complete visibility into the risks and compliance issues of all the entities they regulate.
Powerful dashboards and visualization tools provide timely insights into compliance trends and potential risks. Advanced analytics go even deeper, showing how each program (e.g., loans and grants) is managed differently based on the type of financial institution or the region it’s in.
These insights have strengthened federal board reporting and decision-making.
Well-Planned Implementation and Adoption
The agency knew that purchasing the right solution alone wasn’t enough. The tool had to be implemented and adopted thoughtfully. To ensure success, the agency took the following steps:
A comprehensive risk analysis: Before implementing MetricStream, the agency enumerated all the risks of the project – including how to track, mitigate, and report those risks. For example, one of the biggest risks was a lack of user involvement. To counter it, the agency established an office of business innovation, staffed with experienced insiders who would champion the new solution and act as trusted advocates for change.
Another risk was inadequate executive support, which was mitigated by involving senior management from day one. They approved, funded, and endorsed the project.
Sound project governance: The agency set up clear lines of responsibility, accountability, and reporting for the project. Day-to-day decisions (e.g., solution configurations) were left to the project management team, enabling them to reach their targets on time. However, larger strategic decisions around costs, customizations, and integrations were escalated up a chain of command.
At regular intervals, the board and leadership team were updated about the project status. Meanwhile, an advisory group of business users kept the project going in the right direction by providing continuous feedback.
Streamlined change management: Since change management is often the most important yet hardest part of a project, the agency devoted significant time and resources to it. For starters, they involved all key stakeholders in the project – right from requirements gathering, to solution demos, procurement, pilots, and user acceptance testing. Many of these stakeholders went on to train the rest of the team on the solution.
Help desks were also set up to provide in-person, hands-on assistance to users adopting the new solution. User guides, quick reference documents, and other content helped ease the learning curve.
Safeguarding the assets of millions of customers is no easy task. But with MetricStream, the agency can identify and resolve potential risks and compliance issues faster, thereby improving the safety of the financial system. Regulatory exams and audits are more streamlined and consistent now. Risks are communicated better. And a carefully thought-out strategy for user adoption is helping teams get the most value from MetricStream.
Products
Subscribe for Latest Updates
Subscribe Now