Cybersecurity Policy Report, Trade groups issue risk-based framework for sharing sensitive supervisory data, (Jul 24, 2026)
Organizations Mentioned:American Bankers Association | Asia Securities Industry & Financial Markets Association | Bank Policy Institute | Consumer Bankers Association | Federal Deposit Insurance Corp. | Global Financial Markets Association | Independent Community Bankers of America | Institute of International Bankers | Managed Funds Association | Office of the Comptroller of the Currency | SIFMA | Securities Industry & Financial Markets Association
By Shashi Kant, BALLB, LLM
Banking and financial trade groups issued a framework recommending risk-based practices for supervised institutions to protect highly sensitive data shared with examiners.
A coalition of financial services trade associations, including the American Bankers Association and the Bank Policy Institute (BPI), published a framework of risk-based practices to help supervised institutions identify and safeguard highly sensitive data they share with financial regulators during the supervisory process. The paper complements the coordinated interagency approach that the Federal Reserve, the Office of the Comptroller of the Currency (OCC), and the Federal Deposit Insurance Corporation (FDIC) announced earlier in July for handling highly sensitive information during examinations (see Banking and Finance Law Daily, July 17, 2026).
Background. The associations noted that regulators have long inspected institutions' books and records, but that the increasingly digital nature of that process presents growing security risks for both institutions and the regulators that collect data from many firms. They argued that sharing sensitive information through direct file transfers, such as regulator-managed portals or encrypted email, carries significant risk and should be reconsidered, so that the supervisory process itself does not introduce unnecessary exposure. The groups pointed to cybersecurity incidents discovered at the OCC in February 2025 and the Department of the Treasury in December 2024 as prompting industry and regulators to update, standardize, and strengthen sharing practices. Among other aims, the updated practices seek to reduce the attack surface by limiting requested information to what is material to supervisory obligations, encourage consistency among secure transfer methods, increase reliance on firm-controlled access, apply additional controls for particularly sensitive information, and establish alignment on the protection, storage, sharing, and disposal of directly transferred data.
Methods for sharing sensitive data. The framework identifies three primary methods. Direct transfer (uploading to portals such as the Federal Reserve’s OASiS system), transmitting by email, or providing hard copies should use encryption, authentication, and access controls, but inherently creates additional copies and reduces institutional control. Firm-controlled access lets regulators view data through firm-hosted applications that record views and restrict copying and downloading, through screen-sharing, or through on-site review on firm-controlled devices, thereby limiting the number of copies. Oral discussion conveys certain information through briefings alone. The associations recommended that regulators enable and encourage firm-controlled access across all data categories, allowing institutions flexibility to add protections for especially sensitive data on a case-by-case basis.
Limiting content and controlling access. The framework describes measures that can be layered onto any sharing method: restricting access to examiners with a demonstrable need to know; providing summaries or aggregated data rather than detailed records; supplying samples or excerpts instead of complete data sets; redacting details such as personally identifiable information (PII), employee compensation and performance data, board evaluations, internal IP addresses, and privileged material; sharing information in restricted formats such as screenshots rather than editable native files like Word or Excel; and aligning in writing, before any direct transfer, on where data will be stored, who may access it, how long it will be retained, and how it will be disposed of.
Sensitive data categories. The paper organizes sensitive supervisory data into four institution-identified categories: strategy, planning, and financial data; security, resilience, and third-party risk management data; internal business data; and legal, regulatory, and compliance data. Within each, it flags especially sensitive types warranting heightened protection. The associations recommended, for example, that pre-deal merger-and-acquisition information be shared through oral discussion only or in summary form until plans become public, and that succession-related information not be provided at all, reasoning that the harm to a firm from a leak outweighs an examiner's need to know for safety-and-soundness purposes. They further recommended that the most sensitive cybersecurity and technology data (such as penetration-test and red-team outputs, detailed network diagrams, IP addresses, and data-center locations) not be shared externally, and that institutions be permitted to withhold attorney-client privileged materials and attorney work product, on the view that examination authority does not override the privilege.
The associations stressed the importance of keeping sensitive information secure even when examiners need to access it, observing that granular details are often extraneous to examiners' mandate to focus on material risks such as interest rate risk. The groups said the improved practices would collectively reduce the cybersecurity risks tied to collecting, retaining, and transmitting sensitive supervisory information, to the benefit of customers, investors, regulators, and institutions alike.
Companies: American Bankers Association; Asia Securities Industry & Financial Markets Association; Bank Policy Institute; Consumer Bankers Association; Global Financial Markets Association; Independent Community Bankers of America; Institute of International Bankers; Managed Funds Association; SIFMA
IndustryNews: BankingOperations CyberPrivacyFeed DataPrivacy DataSecurity IdentityTheft Privacy