Skip to content

Compliance & frameworks

FFIEC

FFIEC IT Examination Handbook

The FFIEC IT Examination Handbook is the playbook federal and state banking examiners use to judge technology and security at financial institutions. It is not a certificate you earn — it is the standard your next exam is measured against, spanning information security, architecture and operations, business continuity, and third-party risk. For a bank, credit union, or fintech running core and customer-facing systems in the cloud, the handbook's expectations increasingly come down to how you configure and govern AWS, Azure, and Google Cloud — and where the shared-responsibility line falls between you and your provider.

Who it applies to

FFIEC guidance is issued jointly by its member agencies — the OCC, FDIC, Federal Reserve, NCUA, and CFPB, together with the State Liaison Committee. It is not a law you file against; it is the lens examiners apply to federally supervised banks and credit unions. Technology service providers that host or process on behalf of those institutions fall under the same expectations through the Bank Service Company Act and can be examined directly, so cloud-native vendors serving banks inherit the pressure even when they are not banks themselves.

Cloud control themes

What FFIEC asks of your cloud

  • Access management and authentication — least privilege, MFA, and identity governance over nonpublic customer information (Information Security booklet)
  • Change and configuration management — controlled infrastructure changes, patching, and secure baselines (Architecture, Infrastructure & Operations booklet)
  • Audit logging, monitoring, and incident response — the ability to detect, investigate, and reconstruct events across cloud accounts
  • Third-party and cloud shared-responsibility oversight — the 2020 interagency statement on security in a cloud computing environment
  • Business continuity and resilience — backup integrity, recovery, and availability of cloud-hosted systems (Business Continuity Management booklet)

Domain × framework

Which assessment domains produce FFIEC evidence

Assessment domainHow it maps
Identity & accessIAM findings evidence the Information Security booklet's access-management and authentication expectations — least privilege, MFA, and timely deprovisioning for anyone who can reach nonpublic customer information.
Data securityEncryption and storage-exposure findings support the handbook's data-protection expectations for nonpublic information at rest and in transit, and show where regulated data actually lives across accounts.
Network exposureBoundary, segmentation, and exposed-service findings map to the perimeter and network-controls expectations examiners probe under Information Security and Operations.
Logging & monitoringLog coverage, retention, and detection findings evidence the audit-logging and incident-response expectations examiners weigh most heavily after an event.
Configuration & postureBaseline-drift and change-control findings speak to secure configuration and patch management — and surface the shared-responsibility misconfigurations the 2020 cloud statement specifically flags.
Framework mappingEvery finding is tied back to the specific IT Examination Handbook booklet it touches, so the report speaks the same structure your examiner and your internal audit function already use.

What you get

A findings report organized the way examiners actually look at cloud — each gap tied to the relevant IT Examination Handbook booklet (Information Security, Architecture/Infrastructure/Operations, Business Continuity, Outsourcing Technology Services), ranked by real risk, with a remediation order your CISO can carry into an exam and your engineers can execute. Where the cloud shared-responsibility line matters, we make explicit which side of it each finding sits on, so nothing falls into the gap between you and your provider.

Most relevant to: FinTech

Questions

Is a health check the same as an FFIEC examination?

No. Examinations are conducted by your prudential regulator — the OCC, FDIC, Federal Reserve, or NCUA. This is readiness work: it finds and prioritizes the cloud-technical gaps an examiner would raise, so you walk into the exam knowing where you stand instead of finding out during it.

Do you still use the FFIEC Cybersecurity Assessment Tool (CAT)?

The FFIEC sunset the CAT in 2025 and now points institutions toward frameworks such as the NIST Cybersecurity Framework and CISA's guidance. We map cloud findings to the current IT Examination Handbook booklets and those successor references — not to a retired tool.

We're a technology service provider to banks, not a bank — does this apply to us?

Yes. Under the Bank Service Company Act, providers that host or process for supervised institutions can be examined directly, and your bank clients' examiners expect your cloud controls to hold up. The health check gives you evidence you can hand those clients before they ask for it.

Framework work in practice

Evidence rooms and compliance tables

Mapping is for auditors and operators — shown in the spaces where evidence is reviewed.

Take free readiness check