FFIEC guidance defines what regulators expect to see when they examine a bank, credit union, or financial institution - especially around cybersecurity, third-party risk, and technology governance.
If an examiner will ever sit across the table from you, FFIEC guidance is the script they are working from.
The Federal Financial Institutions Examination Council (FFIEC) is a U.S. interagency body that establishes uniform principles, standards, and examination guidance for financial institutions. Congress created it in March 1979 to prescribe uniform principles, standards, and report forms for federal examinations (FFIEC).
The Council has six members: the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), the Office of the Comptroller of the Currency (OCC), the Consumer Financial Protection Bureau (CFPB), and the chair of the State Liaison Committee.
Two things FFIEC is not: it is not a law, and it does not itself examine or regulate financial institutions - its member agencies do. What FFIEC produces is the cybersecurity, risk management, and IT examination expectations those agencies apply, published largely through the FFIEC IT Examination Handbook.
FFIEC guidance applies wherever its member agencies examine.
Financial institutions:
Organizations supporting financial institutions:
If your organization supports a regulated financial institution, expect to be evaluated through your customers' exams - due-diligence requests, contract requirements, and findings that land on your roadmap. Significant technology service providers can also be examined directly under the interagency Supervision of Technology Service Providers program (FFIEC IT Handbook).
FFIEC guidance focuses on information systems and sensitive data, including:
From an IT perspective, FFIEC is about resilience, availability, security, and oversight - not just confidentiality.
FFIEC guidance works alongside the financial data regulations, and each layer has a distinct job.
GLBA establishes the requirement to protect customer information. The FTC Safeguards Rule defines minimum security expectations. FFIEC defines how regulators evaluate whether controls are effective.
In short: GLBA is the law. FFIEC is how regulators test compliance with it.
FFIEC examinations are risk-based and evidence-driven. Examiners look for real controls, not policies alone.
Key expectation areas include:
Governance and oversight. Board and executive involvement in cybersecurity, defined roles and accountability, documented IT and security strategies, and regular risk reporting to leadership.
Risk management and risk assessments. Formal IT and cyber risk assessments, identification of inherent risk, evaluation of control maturity, and ongoing risk management processes - not annual paperwork.
Identity and access management. Strong access controls, least-privilege permissions, multi-factor authentication (MFA), secure remote access, and regular access reviews.
Cybersecurity controls. Endpoint and network security, email security, vulnerability management, patch and configuration management, and secure system architecture.
Monitoring, detection, and incident response. Logging and monitoring, threat detection capabilities, incident response plans, breach notification and escalation processes, and tabletop and response exercises.
Business continuity and resilience. Backup and disaster recovery, incident recovery planning, availability and resilience testing, and third-party dependency planning. Resilience is a first-class exam topic, not an appendix.
Third-party and vendor risk management. FFIEC places heavy emphasis on vendor due diligence, ongoing monitoring, contractual security requirements, and exit and contingency planning. Third-party risk is a major focus of examinations.
FFIEC findings carry consequences beyond the exam report: regulatory findings and remediation orders, increased scrutiny in future exams, operational restrictions, delays in growth initiatives, and damage to institutional credibility.
Examiner focus areas commonly include:
FFIEC guidance reinforces a core principle: cybersecurity is an enterprise risk, not just an IT issue.
FFIEC expectations also align closely with the NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001, and SOC 2 - the same fundamentals under different labels.
Organizations that align FFIEC expectations with a broader GRC program gain better visibility into risk, stronger executive decision-making, improved audit and exam outcomes, and more resilient operations.
Here is the truth: FFIEC compliance is about proving that you understand your risk and manage it responsibly.
Most required controls are not unique or exotic. They are fundamental cybersecurity and governance practices.
What matters is consistency, documentation, evidence, and executive awareness. Exams reward institutions that can show their work.
Our Cyber Risk & Compliance Gap Assessment helps organizations:
Our assessment maps your controls and documentation to the FFIEC IT Handbook expectation areas examiners actually test - before the exam does it for you.
Assess your products and services, delivery channels, technology complexity, threat environment, and third-party dependencies. Inherent risk determines how deep the exam goes.
Document risks, existing controls, control maturity, residual risk, and remediation priorities. The assessment is the document examiners open first.
Focus on MFA and access management, endpoint, email, and network security, encryption, logging and monitoring, and incident response readiness.
Ensure vendors are assessed before onboarding, security requirements are documented in contracts, monitoring continues through the relationship, and exit plans exist.
Examiners expect clear policies, evidence of execution, regular reporting to leadership, and continuous improvement. Evidence beats intention in every exam.
No. FFIEC is an interagency body - the Federal Reserve, FDIC, NCUA, OCC, CFPB, and the State Liaison Committee chair - that sets uniform examination standards. It does not itself examine or regulate institutions; its member agencies do, using FFIEC guidance as the yardstick.
If you provide technology, cloud, IT, or security services to a regulated financial institution, FFIEC expectations reach you through your customer's exam - due diligence, contractual security requirements, and ongoing monitoring. Significant technology service providers can also be examined directly under the interagency supervision program.
The handbook (ithandbook.ffiec.gov) is the published body of IT examination guidance - booklets covering security, business continuity, outsourcing, and more. It is the closest thing to a public answer key for what examiners will ask.
FFIEC guidance is not a statute, but for supervised institutions it is functionally mandatory: examiners test against it, and findings carry remediation orders and real supervisory consequences. Treating it as optional is how institutions end up with formal findings.
GLBA is the law requiring customer information to be protected. The FTC Safeguards Rule defines minimum program expectations for FTC-regulated institutions. FFIEC defines how banking regulators evaluate whether controls are effective in the institutions they supervise. Same data, three layers, three different questions.
Evidence. Governance with executive involvement, current risk assessments, working access controls and MFA, monitoring and incident response capability, tested business continuity, and vendor oversight with documentation at every step. A control without evidence is scored as a gap.
It depends on your inherent risk profile and how much of the documentation already exists. We publish no pricing because honest numbers require that context. Firm quote before any work begins. The conversation costs nothing.
Start with the gap between your controls and the handbook. Our Cyber Risk & Compliance Gap Assessment maps your environment to the FFIEC expectation areas, identifies what an examiner would flag, and sequences the fixes before the exam calendar does.
Official source: FFIEC IT Examination Handbook InfoBase
Secondary source: Federal Financial Institutions Examination Council
Source verified 2026-07-24
By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25