What Is FFIEC and Why It Matters

FFIEC guidance defines what regulators expect to see when they examine a bank, credit union, or financial institution - especially around cybersecurity, third-party risk, and technology governance.

If an examiner will ever sit across the table from you, FFIEC guidance is the script they are working from.

What It Is

The Federal Financial Institutions Examination Council (FFIEC) is a U.S. interagency body that establishes uniform principles, standards, and examination guidance for financial institutions. Congress created it in March 1979 to prescribe uniform principles, standards, and report forms for federal examinations (FFIEC).

The Council has six members: the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), the Office of the Comptroller of the Currency (OCC), the Consumer Financial Protection Bureau (CFPB), and the chair of the State Liaison Committee.

Two things FFIEC is not: it is not a law, and it does not itself examine or regulate financial institutions - its member agencies do. What FFIEC produces is the cybersecurity, risk management, and IT examination expectations those agencies apply, published largely through the FFIEC IT Examination Handbook.

Who It Applies To

FFIEC guidance applies wherever its member agencies examine.

Financial institutions:

  • Banks: national and state-chartered, through their federal and state examiners.
  • Credit unions: through the NCUA.
  • Savings associations and trust companies: through their chartering regulators.
  • Mortgage lenders and servicers: where supervised by a member agency.

Organizations supporting financial institutions:

  • Core banking system providers: the deepest technology dependency an institution has.
  • Fintech platforms and payment processors: in scope wherever they touch regulated systems or data.
  • Cloud and SaaS vendors: institutions must evidence oversight of them.
  • MSPs, IT providers, and managed security providers: your controls become part of your customer's exam file.
  • Third-party service providers with system or data access: due diligence, contracts, and monitoring all trace to you.

If your organization supports a regulated financial institution, expect to be evaluated through your customers' exams - due-diligence requests, contract requirements, and findings that land on your roadmap. Significant technology service providers can also be examined directly under the interagency Supervision of Technology Service Providers program (FFIEC IT Handbook).

What Information Is Regulated

FFIEC guidance focuses on information systems and sensitive data, including:

  • Customer financial data (NPI): the confidentiality core shared with GLBA.
  • Online banking platforms: the highest-exposure customer-facing systems.
  • Payment systems: where integrity failures become money movement.
  • Core banking infrastructure: the systems an institution cannot operate without.
  • Cloud environments: examined with the same rigor as on-premises systems.
  • Third-party connections: every integration is an inherited risk.
  • Business-critical IT systems: anything whose failure disrupts the institution.

From an IT perspective, FFIEC is about resilience, availability, security, and oversight - not just confidentiality.

Relation to Other Frameworks

FFIEC guidance works alongside the financial data regulations, and each layer has a distinct job.

GLBA establishes the requirement to protect customer information. The FTC Safeguards Rule defines minimum security expectations. FFIEC defines how regulators evaluate whether controls are effective.

In short: GLBA is the law. FFIEC is how regulators test compliance with it.

IT Requirements

FFIEC examinations are risk-based and evidence-driven. Examiners look for real controls, not policies alone.

Key expectation areas include:

Governance and oversight. Board and executive involvement in cybersecurity, defined roles and accountability, documented IT and security strategies, and regular risk reporting to leadership.

Risk management and risk assessments. Formal IT and cyber risk assessments, identification of inherent risk, evaluation of control maturity, and ongoing risk management processes - not annual paperwork.

Identity and access management. Strong access controls, least-privilege permissions, multi-factor authentication (MFA), secure remote access, and regular access reviews.

Cybersecurity controls. Endpoint and network security, email security, vulnerability management, patch and configuration management, and secure system architecture.

Monitoring, detection, and incident response. Logging and monitoring, threat detection capabilities, incident response plans, breach notification and escalation processes, and tabletop and response exercises.

Business continuity and resilience. Backup and disaster recovery, incident recovery planning, availability and resilience testing, and third-party dependency planning. Resilience is a first-class exam topic, not an appendix.

Third-party and vendor risk management. FFIEC places heavy emphasis on vendor due diligence, ongoing monitoring, contractual security requirements, and exit and contingency planning. Third-party risk is a major focus of examinations.

Why It Matters

FFIEC findings carry consequences beyond the exam report: regulatory findings and remediation orders, increased scrutiny in future exams, operational restrictions, delays in growth initiatives, and damage to institutional credibility.

Examiner focus areas commonly include:

  • Incomplete risk assessments: inherent risk not identified, or controls never mapped to it.
  • Weak vendor oversight: due diligence done once at onboarding and never again.
  • Poor documentation: controls that ran but left no evidence.
  • Gaps between policy and reality: the policy says one thing; the systems do another.
  • Lack of executive involvement: cybersecurity treated as an IT topic instead of a board topic.

How It Fits Into Cyber Risk Management

FFIEC guidance reinforces a core principle: cybersecurity is an enterprise risk, not just an IT issue.

FFIEC expectations also align closely with the NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001, and SOC 2 - the same fundamentals under different labels.

Organizations that align FFIEC expectations with a broader GRC program gain better visibility into risk, stronger executive decision-making, improved audit and exam outcomes, and more resilient operations.

How We Help With FFIEC Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment maps your controls and documentation to the FFIEC IT Handbook expectation areas examiners actually test - before the exam does it for you.

How to Prepare

  1. 01Understand your inherent risk profile

    Assess your products and services, delivery channels, technology complexity, threat environment, and third-party dependencies. Inherent risk determines how deep the exam goes.

  2. 02Conduct formal IT and cyber risk assessments

    Document risks, existing controls, control maturity, residual risk, and remediation priorities. The assessment is the document examiners open first.

  3. 03Strengthen core security controls

    Focus on MFA and access management, endpoint, email, and network security, encryption, logging and monitoring, and incident response readiness.

  4. 04Improve vendor risk management

    Ensure vendors are assessed before onboarding, security requirements are documented in contracts, monitoring continues through the relationship, and exit plans exist.

  5. 05Align governance and documentation

    Examiners expect clear policies, evidence of execution, regular reporting to leadership, and continuous improvement. Evidence beats intention in every exam.

Frequently Asked Questions

Is FFIEC a regulator?

No. FFIEC is an interagency body - the Federal Reserve, FDIC, NCUA, OCC, CFPB, and the State Liaison Committee chair - that sets uniform examination standards. It does not itself examine or regulate institutions; its member agencies do, using FFIEC guidance as the yardstick.

Does FFIEC apply to my business if we are not a bank?

If you provide technology, cloud, IT, or security services to a regulated financial institution, FFIEC expectations reach you through your customer's exam - due diligence, contractual security requirements, and ongoing monitoring. Significant technology service providers can also be examined directly under the interagency supervision program.

What is the FFIEC IT Examination Handbook?

The handbook (ithandbook.ffiec.gov) is the published body of IT examination guidance - booklets covering security, business continuity, outsourcing, and more. It is the closest thing to a public answer key for what examiners will ask.

Is FFIEC compliance mandatory?

FFIEC guidance is not a statute, but for supervised institutions it is functionally mandatory: examiners test against it, and findings carry remediation orders and real supervisory consequences. Treating it as optional is how institutions end up with formal findings.

How does FFIEC relate to GLBA and the FTC Safeguards Rule?

GLBA is the law requiring customer information to be protected. The FTC Safeguards Rule defines minimum program expectations for FTC-regulated institutions. FFIEC defines how banking regulators evaluate whether controls are effective in the institutions they supervise. Same data, three layers, three different questions.

What do examiners actually look for?

Evidence. Governance with executive involvement, current risk assessments, working access controls and MFA, monitoring and incident response capability, tested business continuity, and vendor oversight with documentation at every step. A control without evidence is scored as a gap.

What does FFIEC exam preparation cost?

It depends on your inherent risk profile and how much of the documentation already exists. We publish no pricing because honest numbers require that context. Firm quote before any work begins. The conversation costs nothing.

Where do we start?

Start with the gap between your controls and the handbook. Our Cyber Risk & Compliance Gap Assessment maps your environment to the FFIEC expectation areas, identifies what an examiner would flag, and sequences the fixes before the exam calendar does.

Official source

Official source: FFIEC IT Examination Handbook InfoBase

Secondary source: Federal Financial Institutions Examination Council

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25