Strengthening Sensitive Data Sharing Practices Between Supervised Institutions and Financial Regulators
Introduction
Financial regulators have long requested sensitive strategic, operational and cybersecurity-related information from supervised institutions to fulfill their supervisory responsibilities and statutory obligations. Historically, financial regulators conducted on-site manual inspections of supervised institutions’ books and records. Today, this process is increasingly digital, presenting growing risks to the security of both the supervised institutions and the financial regulators that collect and hold data from multiple firms. While the ability to inspect the books and records of financial institutions is foundational to effective oversight, sharing sensitive information through direct file transfers, such as via regulator-managed portals or encrypted email, presents significant risks and should be reconsidered. It is critical to ensure that the supervisory process itself does not introduce unnecessary risks to supervised institutions or regulatory agencies themselves.
In response to these risks, the Federal Reserve, the Office of the Comptroller of the Currency and the Federal Deposit Insurance Corporation issued an interagency statement outlining a new coordinated approach for handling sensitive financial institution data during supervisory examinations. 1 That statement recognizes the sensitivity of certain categories of data and notes the agencies will consider a range of options to minimize collecting and storing this information. Under this new approach, supervised institutions are responsible for identifying for regulators any requested data or documents the institution considers highly sensitive.
The following document provides a set of risk-based practices to assist supervised institutions in identifying sensitive data that should be subject to alternate sharing methods to ensure that information is adequately protected in a threat environment where this information and the regulators that collect it are a target. Those alternate review methods include supervised institutions providing firm-controlled access to sensitive data either electronically via firm-hosted applications, by screen-sharing or physically via on-site review.
Related Resource
For Examiner Eyes Only: The Safest Ways for Financial Institutions to Share Sensitive Information
- FED. RESERVE BD., FED. DEP. INS. CORP., OFF. COMPTROLLER OF THE CURRENCY, Statement regarding Coordinated Federal Banking Agency Approach for the Handling of Highly Sensitive Information During Examinations (Jul. 2026), https://www.federalreserve.gov/newsevents/pressreleases/files/bcreg20260716a1.pdf.