07/23/2026 | Press release | Distributed by Public on 07/23/2026 14:53
Financial regulators have long requested sensitive strategic, operational and cybersecurity-related information from supervised institutions to fulfill their supervisory responsibilities and statutory obligations. Historically, financial regulators conducted on-site manual inspections of supervised institutions' books and records. Today, this process is increasingly digital, presenting growing risks to the security of both the supervised institutions and the financial regulators that collect and hold data from multiple firms. While the ability to inspect the books and records of financial institutions is foundational to effective oversight, sharing sensitive information through direct file transfers, such as via regulator-managed portals or encrypted email, presents significant risks and should be reconsidered. It is critical to ensure that the supervisory process itself does not introduce unnecessary risks to supervised institutions or regulatory agencies themselves.
In response to these risks, the Federal Reserve, the Office of the Comptroller of the Currency and the Federal Deposit Insurance Corporation issued an interagency statement outlining a new coordinated approach for handling sensitive financial institution data during supervisory examinations.[1] That statement recognizes the sensitivity of certain categories of data and notes the agencies will consider a range of options to minimize collecting and storing this information. Under this new approach, supervised institutions are responsible for identifying for regulators any requested data or documents the institution considers highly sensitive.
The following document provides a set of risk-based practices to assist supervised institutions in identifying sensitive data that should be subject to alternate sharing methods to ensure that information is adequately protected in a threat environment where this information and the regulators that collect it are a target. Those alternate review methods include supervised institutions providing firm-controlled access to sensitive data either electronically via firm-hosted applications, by screen-sharing or physically via on-site review.
Supervised institutions go to great lengths to protect the end-to-end security of their sensitive data, carefully controlling who can access it, how it is transmitted and stored, when and how it is disposed of and when it cannot be shared in the first place. Institutions prioritize data minimization strategies in accordance with regulatory requirements and to limit their overall attack surface, as the existence of multiple copies of sensitive information increases the risk of exposure and misuse. Accordingly, when asked to share sensitive information externally, regardless of recipient, institutions consider how to minimize the information shared and what additional protective measures are needed. These measures are critical to maintaining institutions' long-term data security.
Supervised institutions and their regulators face a shared and growing threat from increasingly sophisticated cyber adversaries, including nation-state actors and organized criminal groups. Given the interconnected nature of the financial system, securing sensitive information held by supervised institutions and regulators alike is a mutual priority. Effective protection requires ongoing collaboration, shared responsibility and coordinated efforts to strengthen collective resilience against cyber threats.
When sensitive information is sent directly to regulators or indirectly via their agents or contractors, supervised institutions inevitably lose some degree of control over its security, management and retention. Even with robust transfer protocols in place, once sensitive data leaves an institution's environment, visibility into its handling and protection becomes limited. This limited visibility begins with the security of the transfer method itself, but extends to how the sensitive data is accessed, managed, copied, redistributed, safeguarded and ultimately disposed of on an external system.
After cybersecurity incidents discovered at the Office of the Comptroller of the Currency in February 2025 and the Department of the Treasury in December 2024, the U.S. prudential banking regulators worked with industry to update, standardize and strengthen pragmatic sharing practices for sensitive supervisory data. Among other things, these updated practices:
These improved data sharing practices will collectively reduce the cybersecurity risks associated with the collection, retention and transmission of sensitive supervisory information, benefiting customers, investors, financial regulators and supervised institutions alike.
The risk-based practices identified in this document reflect extensive feedback from financial institutions and other stakeholders collected through a survey and a series of industry discussions. They are designed to provide supervised institutions and their financial regulators with clear, consistent baseline expectations for securely sharing and managing sensitive data across a wide range of data categories.
These practices are intended to apply broadly to requests for information, including inquiries, examinations, ongoing monitoring submissions, routine meetings, ad hoc data requests and related correspondence. The intended audience includes U.S. federal financial regulators, state banking agencies and other industry-specific regulatory bodies such as insurance regulators, as well as the agents and contractors that regulators hire to collect information on their behalf and the institutions these regulators supervise.
These practices are intended to facilitate constructive collaboration as the threat landscape continues to evolve, ensuring that data security remains a shared priority and a routine topic of discussion.
Financial institutions regularly share a variety of sensitive information with their regulators to support the supervisory process. Broadly, this information falls into four institution-identified categories: Strategy, Planning & Financial Data (e.g., strategic initiatives and transaction details), Security, Resilience & Third-Party Risk Management Data (e.g., cybersecurity controls and assessments and architecture and network diagrams), Internal Business Data (e.g., governance and employee information) and Legal, Regulatory & Compliance Data (e.g., privileged investigations and audit filings). Given the sensitivity and diversity of this information, regulators and institutions should use appropriate methods for sharing it and consistently apply protective measures tailored to each specific data type.
Institutions identified three primary methods for sharing sensitive data with regulators, as well as measures that can be deployed to further protect or control access to particularly sensitive types of information. These measures are previewed below before discussion of specific risk-based best practices.
Institutions emphasized that the method through which they deliver sensitive information to regulators has the greatest impact on their ability to control and ensure the continued security of this information. Sensitive data is currently shared through one of three methods:
Alternatively, for especially sensitive information, institutions and regulators may agree that alternative, less sensitive information satisfies the regulators' request.
When institutions share certain sensitive data with regulators either directly or through firm-controlled access pursuant to the regulator's request, there often remain significant concerns about the recipient audience, the format of the data, and incidental or especially sensitive information contained within files that should not be exposed.
To effectively and sufficiently mitigate these risks, supervised institutions and financial regulators should proactively consider deploying one or more of the following protective measures:
These measures can be used in combination with other methods, e.g., providing on-site, view-only access to a complete data set while directly sharing only a sample or aggregated data, to best mitigate risk while meeting supervisory aims.
The practices outlined below establish clear, consistent, risk-based standards to guide supervised institutions when designating for financial regulators what supervisory data contains sensitive information warranting heightened protection. They are intended to ensure that supervisory data sharing is secure, effective and aligned with contemporary cybersecurity requirements appropriate for the threat environment.
Institutions identified four major categories of sensitive data frequently requested by financial regulators:
Within each major category, institutions also identified especially sensitive data types that require additional methods of protection.
In accordance with the risk-based practices herein, financial regulators should enable and encourage supervised institutions to provide firm-controlled access to sensitive data across all four categories electronically via firm-hosted applications, by screen-sharing or physically via on-site review, while allowing institutions flexibility to implement additional protections for especially sensitive data on a case-by-case basis.
If a financial regulator receives sensitive data from a supervised institution directly (e.g., via a regulator-hosted portal or an encrypted email), the financial regulator should be prepared to align with the supervised institution regarding how that data will be protected and ultimately disposed of, and who will access it, such as the methods described in Section II.
Financial regulators may request that supervised institutions share the following types of sensitive strategy, planning, and financial data: (i) strategic objectives and implementation plans, (ii) succession-related information, (iii) capital plans, (iv) material non-public information, (v) M&A and transaction information, (vi) financial statements, (vii) investment strategies and (viii) revenue analyses.
Institutions have been asked to share this information through direct transfer, uploading materials using either regulator-managed portals or encrypted or password-protected emails. However, some institutions place these materials in a firm-controlled electronic environment or offer on-site review only, and, for especially sensitive data types, some institutions offer oral briefings only or decline to provide certain files altogether.
Financial regulators should enable and encourage supervised institutions to provide firm-controlled access to most of these materials either electronically via firm-hosted applications or screen-sharing or physically via on-site review.
Pre-deal M&A information is exceptionally sensitive and should be shared through oral discussion only or with additional protective measures, such as narrowing regulator audiences and providing information in summary form until plans become public. Succession-related information is among the most sensitive data that a supervised institution holds. The cost to a firm from leaked succession-related information outweighs any examiner's need-to-know for purposes of assessing an institution's safety and soundness.
Financial regulators often request that supervised institutions share the following types of sensitive security, resilience and third-party risk management data: (i) technical information such as network diagrams and configuration settings for both the financial institution and its vendors, (ii) specific security controls, (iii) security testing methodologies, (iv) resilience and backup capabilities, (v) vulnerability lists and acknowledgments, (vi) incident-management information and disruptive-event records, (vii) results of security assessments such as penetration tests and red-team outputs and (viii) third-party engagement reports.
Information in this category is particularly sensitive because disclosure to a malicious third party could pose a material risk to firm operations. Institutions have been asked to share this information through direct transfer, uploading materials using either regulator-managed portals or encrypted or password-protected emails. However, some institutions place these materials in a firm-controlled electronic environment, offer on-site review only or choose not to share this information.
Once identified by supervised institutions, financial regulators should enable and encourage firm-controlled access to most of these materials either electronically via firm-hosted applications or screensharing or physically via on-site review and, wherever possible, enable and encourage supervised institutions to share security and resilience information through oral briefings only.
Raw technical artifacts such as configuration files are exceptionally sensitive data types that should be further protected by narrowing regulator audiences, providing summaries of materials, and redacting unnecessary sensitive information. Terms with technology vendors are also exceptionally sensitive because they could cause substantial competitive harm if revealed to another firm, and they should thus be handled with similar additional protections. Lastly, supervised institutions' most sensitive cybersecurity and technology data, including penetration test or red-team outputs, detailed network diagrams, IP addresses, control discussions and locations of data centers, should not be shared externally.
Financial regulators often request that supervised institutions share the following types of sensitive internal business data: (i) Board of Directors and senior governance body meeting materials, (ii) board assessment or evaluation materials, (iii) designs for emerging products, services and innovations, (iv) intellectual property, (v) detailed business reviews, (vi) trading data and information about client accounts, (vii) fraud monitoring-related materials, (viii) customer, investor and employee PII and other sensitive information, (ix) employee compensation and performance data and (x) AI-related information including governance materials, models, data sources and validation records.
Institutions have similarly been asked to share this information through direct transfer, uploading materials using either regulator-managed portals or encrypted or password-protected emails. However, some institutions place these materials in a firm-controlled electronic environment, offer on-site review only or decline to provide certain files altogether. Many institutions also report using redaction before transmission where PII, individual employee data or internal deliberation is involved.
Once identified by supervised institutions, financial regulators should enable and encourage firm-controlled access to most of these materials either electronically via firm-hosted applications or screensharing or physically via on-site review.
Customer and employee PII, individual employee compensation and performance information and records of internal board and executive deliberations are exceptionally sensitive data types that should be shared with additional protective measures, including narrowing regulator audiences and redacting, aggregating or excerpting PII and individually identifiable employee data.
Financial regulators often request supervised institutions share the following types of sensitive legal, regulatory, and compliance data: (i) internal audit methodologies and results, (ii) AML/BSA suspicious activity report filings and related modeling and tuning, (iii) non-privileged sensitive investigation materials and (iv) materials subject to the attorney-client privilege or the attorney work product doctrine.
Institutions have been asked to share this information through direct transfer, uploading materials using either regulator-managed portals or encrypted or password-protected emails. However, they sometimes restrict or refuse to transmit unredacted privileged documents or offer on-site review only.
Once identified by supervised institutions, financial regulators should enable and encourage firm-controlled access to most of these materials, either electronically via firm-hosted applications or screen-sharing, or physically via on-site review.
Given the extremely sensitive nature of legal data, regulators should also enable and encourage institutions to withhold any access to materials that are attorney-client privileged, subject to the attorney work product doctrine or otherwise contain legal advice because regulators' examination authority does not override attorney-client privilege.[2] When sharing is unavoidable, supervised institutions should be able to deploy additional protections to restrict regulator audiences, provide summaries of materials and redact unnecessary privileged information.
Financial regulators and supervised institutions will continue to face persistent threats from well-resourced and sophisticated cyber adversaries, including nation-state actors and affiliated criminal organizations. In this evolving threat landscape, supervised institutions and their financial regulators have a responsibility to ensure that sensitive data is shared only under conditions that reflect modern best practices for cybersecurity and incident response.
By reducing unnecessary data exposure and preserving firm-level discretion over the most sensitive materials, regulators can work in partnership with the industry to strengthen the resilience of the supervisory process itself. Implementing meaningful reforms will help reduce the risk to sensitive information and ensure that it is appropriately safeguarded, ultimately supporting stronger cybersecurity across the financial system.
[1] Fed. Reserve Bd., Fed. Dep. Ins. Corp., Off. Comptroller of the Currency, Statement regarding Coordinated Federal Banking Agency Approach for the Handling of Highly Sensitive Information During Examinations (Jul. 2026), https://www.federalreserve.gov/newsevents/pressreleases/files/bcreg20260716a1.pdf.
[2] See, e.g., Memorandum from Cleary Gottlieb Steen & Hamilton LLP, Covington & Burling LLP, Davis Polk & Wardwell LLP, Debevoise & Plimpton LLP, Simpson Thacher & Bartlett LLP, Sullivan & Cromwell LLP and Wilmer Cutler Pickering Hale and Dorr LLP, "Banking Regulators' Examination Authority Does Not Override Attorney-Client Privilege." (May 16, 2018).