Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • K-12 Cybersecurity Legislation Offered in House, Senate
    • Bipartisan House Bill Targets Data-Scraping ‘Stealth Bots’
    • Cyber Defense Agencies Warn About Russian Cyber Espionage Group
    • Foreign Cyber Criminals Face New U.S. Visa Restrictions
    • GPS Resiliency Bill Included in House-Passed NDAA
    • Injunction Upheld to Block Texas’ Restrictions on Targeted Ads to Kids
    • TikTok, Apple Face Privacy Fines in South Korea
    • Trade groups issue risk-based framework for sharing sensitive supervisory data
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, Trade groups issue risk-based framework for sharing sensitive supervisory data, (Jul 24, 2026)

    Organizations Mentioned:American Bankers Association | Asia Securities Industry & Financial Markets Association | Bank Policy Institute | Consumer Bankers Association | Federal Deposit Insurance Corp. | Global Financial Markets Association | Independent Community Bankers of America | Institute of International Bankers | Managed Funds Association | Office of the Comptroller of the Currency | SIFMA | Securities Industry & Financial Markets Association

    By Shashi Kant, BALLB, LLM

    Banking and financial trade groups issued a framework recommending risk-based practices for supervised institutions to protect highly sensitive data shared with examiners.

    A coalition of financial services trade associations, including the American Ba ...

    By Shashi Kant, BALLB, LLM

    Banking and financial trade groups issued a framework recommending risk-based practices for supervised institutions to protect highly sensitive data shared with examiners.

    A coalition of financial services trade associations, including the American Bankers Association and the Bank Policy Institute (BPI), published a framework of risk-based practices to help supervised institutions identify and safeguard highly sensitive data they share with financial regulators during the supervisory process. The paper complements the coordinated interagency approach that the Federal Reserve, the Office of the Comptroller of the Currency (OCC), and the Federal Deposit Insurance Corporation (FDIC) announced earlier in July for handling highly sensitive information during examinations (see Banking and Finance Law Daily, July 17, 2026).

    Background. The associations noted that regulators have long inspected institutions' books and records, but that the increasingly digital nature of that process presents growing security risks for both institutions and the regulators that collect data from many firms. They argued that sharing sensitive information through direct file transfers, such as regulator-managed portals or encrypted email, carries significant risk and should be reconsidered, so that the supervisory process itself does not introduce unnecessary exposure. The groups pointed to cybersecurity incidents discovered at the OCC in February 2025 and the Department of the Treasury in December 2024 as prompting industry and regulators to update, standardize, and strengthen sharing practices. Among other aims, the updated practices seek to reduce the attack surface by limiting requested information to what is material to supervisory obligations, encourage consistency among secure transfer methods, increase reliance on firm-controlled access, apply additional controls for particularly sensitive information, and establish alignment on the protection, storage, sharing, and disposal of directly transferred data.

    Methods for sharing sensitive data. The framework identifies three primary methods. Direct transfer (uploading to portals such as the Federal Reserve’s OASiS system), transmitting by email, or providing hard copies should use encryption, authentication, and access controls, but inherently creates additional copies and reduces institutional control. Firm-controlled access lets regulators view data through firm-hosted applications that record views and restrict copying and downloading, through screen-sharing, or through on-site review on firm-controlled devices, thereby limiting the number of copies. Oral discussion conveys certain information through briefings alone. The associations recommended that regulators enable and encourage firm-controlled access across all data categories, allowing institutions flexibility to add protections for especially sensitive data on a case-by-case basis.

    Limiting content and controlling access. The framework describes measures that can be layered onto any sharing method: restricting access to examiners with a demonstrable need to know; providing summaries or aggregated data rather than detailed records; supplying samples or excerpts instead of complete data sets; redacting details such as personally identifiable information (PII), employee compensation and performance data, board evaluations, internal IP addresses, and privileged material; sharing information in restricted formats such as screenshots rather than editable native files like Word or Excel; and aligning in writing, before any direct transfer, on where data will be stored, who may access it, how long it will be retained, and how it will be disposed of.

    Sensitive data categories. The paper organizes sensitive supervisory data into four institution-identified categories: strategy, planning, and financial data; security, resilience, and third-party risk management data; internal business data; and legal, regulatory, and compliance data. Within each, it flags especially sensitive types warranting heightened protection. The associations recommended, for example, that pre-deal merger-and-acquisition information be shared through oral discussion only or in summary form until plans become public, and that succession-related information not be provided at all, reasoning that the harm to a firm from a leak outweighs an examiner's need to know for safety-and-soundness purposes. They further recommended that the most sensitive cybersecurity and technology data (such as penetration-test and red-team outputs, detailed network diagrams, IP addresses, and data-center locations) not be shared externally, and that institutions be permitted to withhold attorney-client privileged materials and attorney work product, on the view that examination authority does not override the privilege.

    The associations stressed the importance of keeping sensitive information secure even when examiners need to access it, observing that granular details are often extraneous to examiners' mandate to focus on material risks such as interest rate risk. The groups said the improved practices would collectively reduce the cybersecurity risks tied to collecting, retaining, and transmitting sensitive supervisory information, to the benefit of customers, investors, regulators, and institutions alike.

    Companies: American Bankers Association; Asia Securities Industry & Financial Markets Association; Bank Policy Institute; Consumer Bankers Association; Global Financial Markets Association; Independent Community Bankers of America; Institute of International Bankers; Managed Funds Association; SIFMA

    IndustryNews: BankingOperations CyberPrivacyFeed DataPrivacy DataSecurity IdentityTheft Privacy

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use