🔹 Challenge
When the OCC issued three high-impact MRAs to a global custody and asset servicing bank, the findings pointed to weak third-party controls, ineffective issue remediation, and inconsistent regulatory documentation across functions.
PGMP was engaged to design and execute a full-scope remediation program that would satisfy regulators, internal audit, and downstream legal review—while the custody business remained fully operational.
🔹 Our Role
- Stood up a dedicated remediation office with cross-functional oversight
- Built an OCC-aligned action plan with traceable corrective actions and testing criteria
- Rebuilt the RCSA (Risk & Control Self-Assessment) framework for third-party risk and issue management
- Created standard documentation templates and training for SMEs
- Provided weekly engagement support with regulators and internal audit
🔹 Outcomes
✅ All three MRAs were successfully remediated and closed within 4 months
✅ Internal audit accepted all documentation and test artifacts on first submission
✅ OCC examiners issued no follow-up findings post closure
✅ Control environment maturity improved across third-party and operations groups