About Churchill & Harriman
Founded in 1986, Churchill & Harriman (C&H) provides comprehensive risk management advisory services to many of the most distinguished and established financial services organizations across the globe. We proactively collaborate with the Shared Assessments Program, in the establishment and implementation of industry-wide risk assessment and management programs.
Our Financial Services Experience/Credentials:
Our C&H team of advisors have comprehensive executive-level experience in all aspects of enterprise risk management in the financial services industry. C&H consultants have relevant accreditations including CISSP, ISO 27001 Lead Auditor, CTPRP, CIPP, Professional Engineer, and others. C&H has deployed as many as 80 consultants simultaneously to achieve client project objectives. C&H has performed thousands of risk assessments around the world beginning in 1998. In addition, C&H is a charter member of Shared Assessments (SA) Program Steering Committee, External Advisory Board and Technical Development Committee. Additionally, we serve as the liaison between the Shared Assessments Program Steering Committee and the External Shared Assessments Program Advisory Board.
Our Services
We work closely with our financial services clients to help them move beyond mere compliance, by establishing enterprise risk management programs that proactively identify and mitigate risks.
Here are some of our service areas:
- C-level risk management advisory services
- Global onsite and remote third party risk assessments
- NIST Special Publication 800-53 assessments
- NIST Cybersecurity Framework conformance
- Vendor management program establishment and optimization
Compliance
Churchill & Harriman provides financial services industry enterprise risk management guidance and executes third party risk assessments according to the following laws, regulations, standards, and commercial practices:
- National Institute of Standards and Technology (NIST)
- NIST SP800-53 assessments
- NIST Cybersecurity Framework (CSF) assessments
- International Organization for Standardization (ISO)
- ISO 27001 pre-certification preparation and post-certification surveillance
- ISO 22301 business continuity management/disaster recovery planning
- ISO 22307 privacy impact assessments
- Federal Financial Institutions Examination Council (FFIEC)
- Sarbanes-Oxley Act (SOX)
- Shared Assessments Program – AUP, SIG
- Financial Services Authority (FSA)
- European Banking Authority (EBA)
- Australian Securities and Investments Commission (ASIC)
Our Clients/Results/Earned Distinctions
The following is a sample of financial services clients and results supported by C&H: