2 unchanged sentences
Risk Management and Strategy
−Removed: Our Board of Directors has delegated primary responsibility for oversight of cybersecurity risk management to the Audit, Finance & Risk Committee of the Board .
−Removed: The Committee receives quarterly reports from the Chief Information Security Officer (CISO) and Chief Risk Officer (CRO) , respectively, and reviews them with such officers.
−Removed: These reports are made available to all board members concurrently.
−Removed: The CRO’s report includes evaluation of the level of cybersecurity risks and strength of mitigating controls.
−Removed: All board members are invited to attend the portion of the Committee’s meetings for review of reports received on risk management from management (e.g., the CRO, CISO, Chief Compliance Officer).
+Added: Our Board of Directors has delegated primary responsibility for oversight of cybersecurity risk management to the Digital and Technology Committee of the Board .
+Added: The Committee receives quarterly reports from the Chief Information Security Officer (CISO) and the Chief Information Officer (CIO) , respectively, and reviews them with such officers.
+Added: These reports are made available to all board members.
+Added: In addition, our Chief Risk Officer (CRO) provides a quarterly report to the full Board that covers material risks to the organization and cybersecurity and other information security risks are among the organization’s material risks.
+Added: Such reports include management’s updates on the inherent risk level of cybersecurity and other information security risks and the strength of controls designed to mitigate those risks.
Our processes for assessing, identifying, and managing material risks from cybersecurity threats are based on examination guidance published by the Federal Financial Institution Examination Council (FFIEC), an interagency body established under the Financial Institutions Regulatory and Interest Rate Control Act of 1978.
7 unchanged sentences
Our Board and senior management oversee our processes for management of cybersecurity risks consistent with the foregoing standards.
−Removed: Such oversight includes regular reporting by management to the Board on the adequacy of such processes and potential material issues identified.
+Added: As noted above, s uch oversight includes regular reporting by management to the Board on the adequacy of such processes and potential material issues identified.
Before escalation to the Board, issues are generally identified and assessed through our risk governance structure established under our Enterprise Risk Management Program.
2 unchanged sentences
Management oversight is maintained through several committees that serve as forums for further assessment, remediation, and escalation.
−Removed: These management oversight committees include the Information Security Committee, co-chaired by the CISO and CRO, the Operational and Compliance Risk Committee, chaired by the CFO, vice chaired by the CISO and Chief Compliance Officer, the IT Steering Committee, chaired by the Chief Information Officer (CIO), the Enterprise Risk Management Committee, chaired by the CRO, the Data Governance Committee, chaired by the CIO, and the executive management committee known as the Strategic Deployment Committee, chaired by the CEO.
+Added: These management oversight committees include the Information Security Committee, co-chaired by the CISO and CRO, the Operational and Compliance Risk Committee, chaired by the Chief Operating Officer (COO) and vice chaired by the Chief Compliance Officer, the IT Steering Committee, chaired by the Chief Information Officer (CIO), the Enterprise Risk Management Committee, chaired by the CRO, the Data Governance Committee, chaired by the CIO, and the executive management committee known as the Strategic Deployment Committee, chaired by the Chief Executive Officer (CEO).
We regularly engage third-party assessors, consultants, and auditors to test and evaluate our controls for managing cybersecurity threats.
9 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.