CashPro Service Organization Control (“SOC”) Reports Building Trust and Confidence in the CashPro Channels. We understand the importance you place on financial reporting integrity and information security. As the risk landscape continues to expand, the need for greater transparency on how we manage risk is a priority for us as your service provider.

CashPro SOC reports are available to provide visibility into the CashPro control environment and to give your organization continued confidence in using CashPro. In addition to visibility, SOC Reports deliver the following assurances and benefits -  Independent assessment by third party  Available via simple request and delivery process  Contains information often requested through  Free of charge RFPs and security questionnaires

Types of SOC Reports Each SOC Report is designed to evaluate specific CashPro Controls at points or for periods of time.  SOC 1 – attests to the integrity of CashPro controls and utilized by you and your auditors to evaluate the effect of the controls on your financial statements  SOC 2 – attests to the security of CashPro systems and information; also evaluates organization oversight in areas such as vendor and risk management SOC 1 and SOC 2 Reports are also classified as a Type 1 or Type 2 report.  Type 1 – evaluates design of controls as of a specific date  Type 2 – evaluates design and operating effectiveness of controls throughout a specified period Bridge Letters are available to supplement SOC 1 reports and confirm controls are still operating as reported. What’s Available for CashPro? Reports available include: CashPro Channel SOC Report Type Point / Period of Time CashPro Online and CashPro Mobile SOC 1, Type 2 12 month period from 10/1/18 – 9/30/19 SOC 2, Type 1 As of 5/31/19 CashPro Connect SOC 1, Type 2 6 month period from 4/1/19 – 9/30/19 SOC 2, Type 1 As of 5/31/19

Easy Request Process Timely Report Delivery Simply contact your treasury management team to SOC Report delivery through CashPro Assistant request a SOC Report and/or Bridge Letter. You will Document Center to provide reports in a timely manner. automatically receive both a SOC 1 and SOC 2 report for Your CashPro Primary Administrator can easily provision your applicable Channel(s) when your request is fulfilled. access if needed. Note: SOC reports are intended for CashPro users and their auditors (for Secure email delivery is an option for CashPro Connect SOC 1) and should not be shared or used by anyone other than these users not utilizing CashPro Online, or in other special parties. circumstances.

of America” and “BofA Securities” are the marketing names used by the Global Banking and Global Markets divisions of Corporation. Lending, other commercial banking activities, and trading in certain financial instruments are performed globally by banking affiliates of Bank of America Corporation, including Bank of America, N.A., Member FDIC. Trading in securities and financial instruments, and strategic advisory, and other activities, are performed globally by investment banking affiliates of Bank of America Corporation (“Investment Banking Affiliates”), including, in the United States, BofA Securities, Inc. and Lynch Professional Clearing Corp., both of which are registered broker-dealers and Members of SIPC, and, in other jurisdictions, by locally registered entities. BofA Securities, Inc. and Merrill Lynch Professional Clearing Corp. are registered as futures commission merchants with the CFTC and are members of the NFA. Investment products offered by Investment Banking Affiliates: Are Not FDIC Insured • May Lose Value • Are Not Bank Guaranteed. ©2020 Bank of America Corporation. All rights reserved. 2904270