4 unchanged sentences
Peoples’ information security policy and procedures are reviewed and assessed on an annual basis and as needed throughout the year by the Risk Committee of the Board.
−Removed: Peoples assesses itself against the Federal Financial Institutions Examination Council’s (“FFIEC”) Cybersecurity Assessment Tool (“CAT”) on a quarterly basis.
−Removed: Beginning in 2025, Peoples will assess itself using the Cyber Risk Institute Tool (“CRIT”) on at least an annual basis.
+Added: Peoples assesses itself using the Cyber Risk Institute Tool (“CRIT”) on at least an annual basis.
Additional assessment of Peoples’ cybersecurity capabilities is performed by consultants and regulators annually.
8 unchanged sentences
At least annually, the Risk Committee reviews and reassesses the adequacy of its charter and recommends any proposed changes to the full Board as necessary to reflect changes in regulatory requirements, authoritative guidance and evolving practices.
−Removed: On at least a quarterly basis, Peoples’ Chief Risk Officer provides a report to the Risk Committee regarding the overall risk condition of Peoples and whether it is within Peoples’ stated risk appetite.
−Removed: Peoples’ Chief Risk Officer (“CRO”) reports to the Risk Committee and the CEO and has primary responsibility for the design and implementation of the ERM Program.
−Removed: The ERM Program establishes Peoples’ risk appetite, monitors key risk and performance indicators, identifies key risks within the firm, designs and executes specific risk initiatives and monitors risk mitigation efforts and control processes.
+Added: On at least a quarterly basis, Peoples’ Chief Risk Officer (“CRO”) provides a report to the Risk Committee regarding the overall risk condition of Peoples and whether it is within Peoples’ stated risk appetite.
+Added: Peoples’ CRO reports to the Risk Committee and the CEO and has primary responsibility for the design and implementation of the ERM Program.
+Added: The ERM Program establishes Peoples’ risk appetite, monitors key risk and performance indicators, identifies key
+Added: risks within the firm, designs and executes specific risk initiatives and monitors risk mitigation efforts and control processes.
The CRO updates the Risk Committee quarterly on the overall risk condition of Peoples inclusive of any cybersecurity issues or threats.
18 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.