Credit Union IT Risk Assessment Checklist Form
Use this checklist to assess your credit union's IT risk posture across systems, access, data protection, vendor dependencies, incident readiness, and control effectiveness.
Systems Inventory: Are all hardware and software assets inventoried and regularly updated?
*
Yes
No
Partially
User Access Controls: Which access controls are enforced for user accounts?
*
Role-based access
Multi-factor authentication
Periodic access reviews
None of the above
Data Protection: How is sensitive information stored and protected?
*
Encrypted at rest and in transit
Encrypted at rest only
Not encrypted
Vendor Risk Management: Are third-party vendors assessed for IT security risks?
*
Yes, annually
Yes, but not annually
No formal assessment
Incident Response: Is there a documented and tested incident response plan?
*
Yes, documented and tested
Documented, but not tested
No
Backup and Recovery: Rate your confidence in current backup and recovery processes.
*
1
2
3
4
5
Patch Management: How frequently are systems patched and updated?
*
Monthly or more often
Quarterly
Less frequently
Security Awareness Training: Which topics are included in staff training?
*
Phishing and social engineering
Data handling procedures
Incident reporting
None of the above
Control Effectiveness: Please rate the effectiveness of your IT controls overall.
*
Not effective
1
2
3
4
Highly effective
5
1 is Not effective, 5 is Highly effective
Continuous Improvement: What is your top IT risk improvement priority for the next year?
Submit Assessment
Should be Empty: