Federal Bank Regulators Tighten Security Rules For Sensitive Exam Data
By CU Today Staff —
WASHINGTON—Federal banking regulators have unveiled new procedures for handling highly sensitive information during bank examinations, allowing institutions to designate certain data and documents for enhanced security protections in an effort to reduce cybersecurity risks while preserving supervisory access.
In a joint statement, the Federal Reserve, Federal Deposit Insurance Corp. and Office of the Comptroller of the Currency said examiners will use a coordinated process to identify "highly sensitive" information and, where appropriate, review materials on-site instead of transferring them to agency systems. The agencies said the approach is intended to minimize the collection and storage of sensitive bank information without hindering the examination process.
The regulators also committed to notifying affected banks of any potential or confirmed material data breach involving confidential supervisory information as soon as practicable—and no later than 72 hours after discovery, unless legal restrictions apply. They said the new procedures are designed to protect institutions against unauthorized access resulting from cybersecurity vulnerabilities while ensuring regulators retain access to information needed to conduct examinations.
The guidance applies to examinations of supervised banks, including community institutions, and does not establish new supervisory expectations. Instead, it formalizes a coordinated framework for identifying highly sensitive information and applying enhanced handling procedures across the three federal banking agencies.
Originally reported by CU Today.