CBA - Consumer Bankers Association

07/24/2026 | Press release | Distributed by Public on 07/24/2026 10:02

For Examiner Eyes Only: The Safest Ways for Financial Institutions to Share Sensitive Information

press release

For Examiner Eyes Only: The Safest Ways for Financial Institutions to Share Sensitive Information

July 24, 2026
Weston Loyd

Washington, D.C. - Regulators require banks and other financial institutions to share certain sensitive information as part of the examination process. This information can include roadmaps to the institution's cybersecurity defenses, CEO succession plans and M&A proposals. Given the sensitivity of such data and the rise in sophisticated cyber threats, it's critical that financial firms can keep their information secure - including when examiners need to access it. Granular details of such data are often extraneous to the mandate of examiners, who are meant to focus on material risks to the bank, such as interest rate risk. A new joint paper by a coalition of financial trade associations[1]recommends best practices for sharing access to sensitive information in the supervisory process.

"These improved data sharing practices will collectively reduce the cybersecurity risks associated with the collection, retention and transmission of sensitive supervisory information, benefiting customers, investors, financial regulators and supervised institutions alike," the associations wrote in the paper.

Context

In the past, examiners would visit banks to inspect their records on-site, but now, the process is increasingly digital, which risks exposing the sensitive data to breaches. Cybersecurity incidents discovered at the Office of the Comptroller of the Currency in 2025 and the Treasury Department in 2024 respectively brought such threats to the forefront - after the breaches, the banking agencies worked with the industry to update, standardize and strengthen sharing practices for sensitive supervisory data.

Updated Procedures

The OCC, Federal Reserve and FDIC recently released guidance that updated procedures for handling sensitive bank data during the supervisory process. The updated protocols would:

  • Encourage consistency among secure data transfer methods and protections in line with risk-based best practices.
  • Increase reliance on information sharing via firm-controlled access, electronically or physically via on-site review.
  • Apply additional content and access control measures for particularly sensitive types of information.

Recommended Practices

The paper complements the interagency statement and suggests risk-based practices to safeguard the information that firms share with regulators:

  • Providing firm-controlled access to sensitive data either electronically via firm-hosted applications, by screen-sharing or physically via on-site review.
  • Narrowing the regulator audience by tracking and controlling access to certain examiners with a demonstrable need to know.
  • Creating summaries or aggregated data instead of transmitting detailed records, individually identifiable information or entire privileged documents.
  • Providing samples or excerpts instead of comprehensive data sets or documents to reduce unnecessary exposure.
  • Redacting sensitive details such as personally identifiable information (PII), employee compensation and performance data, board member evaluations, internal IP addresses and any material protected by the attorney-client privilege or the attorney work product doctrine.

[1] The groups co-authoring the paper are: the Bank Policy Institute, American Bankers Association, Consumer Bankers Association, Global Financial Markets Association, Independent Community Bankers of America, Institute of International Bankers, Investment Company Institute, Managed Funds Association and Securities Industry and Financial Markets Association.

CBA - Consumer Bankers Association published this content on July 24, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on July 24, 2026 at 16:02 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]