Skip to Main Content
ICBA
  • Member Login
  • Member Login
7/23/26

Strengthening Sensitive Data Sharing Practices Between Supervised Institutions and Financial Regulators – Risk-Based Practices Framework

Financial regulators have long requested sensitive strategic, operational, and cybersecurity-related information from supervised institutions to fulfill their supervisory responsibilities and statutory obligations. Historically, financial regulators conducted on-site manual inspections of supervised institutions’ books and records. 

Today, this process is increasingly digital, presenting growing risks to the security of both the supervised institutions and the financial regulators that collect and hold data from multiple firms. While the ability to inspect the books and records of financial institutions is foundational to effective oversight, sharing sensitive information through direct file transfers, such as via regulator-managed portals or encrypted email, present significant risks and should be reconsidered. 

It is critical to ensure that the supervisory process itself does not introduce unnecessary risks to supervised institutions or regulatory agencies themselves.

In response to these risks, the Federal Reserve, the Office of the Comptroller of the Currency, and the Federal Deposit Insurance Corporation issued an interagency statement outlining a new coordinated approach for handling sensitive financial institution data during supervisory examinations.

Download PDF Example Text