Framework Financial Services
FFIEC
The Federal Financial Institutions Examination Council is the interagency body (Federal Reserve, FDIC, NCUA, OCC, CFPB, plus a state liaison committee) that writes uniform examination guidance for U.S. depository institutions.
Its IT Examination Handbook, a set of booklets covering information security, business continuity management, architecture and operations, development and acquisition, outsourcing, and related topics, is what bank and credit union examiners use when they review an institution's technology and cyber risk. The FFIEC is not a standard you certify to; it is the examiner's playbook.
The booklets expect an institution to have a board-approved information security program, a written risk assessment, business continuity and incident response plans, third-party risk management policies, and evidence that management reports to the board.
The Information Security booklet also ties into the GLBA 501(b) Interagency Guidelines, which require a written customer information security program. The FFIEC's separate Cybersecurity Assessment Tool has been retired (verify the current status with your regulator), and many institutions now map to NIST CSF or CRI Profile instead.
help
Who has to comply
Federally insured banks, thrifts, and credit unions, their holding companies, and technology service providers examined under the Bank Service Company Act. Applicability is by charter and examination jurisdiction, not by size.
What the assessor asks to see
Examiners ask for the board-approved information security program and GLBA 501(b) program, the IT and cyber risk assessment, the IT audit universe and most recent audit reports, business continuity and disaster recovery plans with test results, the incident response plan and incident log, third-party risk management policy with due diligence files for critical vendors, access management and change management records, patch and vulnerability management reports, and board and IT steering committee minutes.
Assessors
Who assesses FFIEC
Federal and state bank and credit union examiners (OCC, FDIC, Federal Reserve, NCUA, state banking departments) using the handbook's examination procedures. Independent internal or external audits are expected but are not a certification. Examiners derive authority from their agencies.
No firm has claimed a FFIEC assessor listing yet. Claim yours →
Consultants
Who helps with FFIEC
IT audit and cyber consulting firms, virtual CISO providers for community banks, and core-processor partner programs. A typical engagement is an annual IT risk assessment and GLBA program review mapped to the handbook booklets, with a board report, ahead of the next safety and soundness or IT examination.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a FFIEC consultant listing yet. Claim yours →
Software
Tools for FFIEC
Tools that name this framework in their own material.
No firm has claimed a FFIEC tool listing yet. Claim yours →
Related reading
- FFIEC to Sunset Cybersecurity Assessment Tool in 2025Reports the retirement of the CAT and the standards regulators pointed institutions towards in its place.ABA Banking Journal
- FFIEC Cybersecurity Assessment Tool Sunset: What's Next?Explains what the CAT did for a bank's governance reporting and how to choose a replacement assessment approach examiners will accept.Rehmann
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for FFIEC
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with FFIEC
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.