HomeFrameworksFinancial ServicesFFIEC

Framework  Financial Services

FFIEC

The Federal Financial Institutions Examination Council is the interagency body (Federal Reserve, FDIC, NCUA, OCC, CFPB, plus a state liaison committee) that writes uniform examination guidance for U.S. depository institutions.

Its IT Examination Handbook, a set of booklets covering information security, business continuity management, architecture and operations, development and acquisition, outsourcing, and related topics, is what bank and credit union examiners use when they review an institution's technology and cyber risk. The FFIEC is not a standard you certify to; it is the examiner's playbook.

The booklets expect an institution to have a board-approved information security program, a written risk assessment, business continuity and incident response plans, third-party risk management policies, and evidence that management reports to the board.

The Information Security booklet also ties into the GLBA 501(b) Interagency Guidelines, which require a written customer information security program. The FFIEC's separate Cybersecurity Assessment Tool has been retired (verify the current status with your regulator), and many institutions now map to NIST CSF or CRI Profile instead.

AI-compiled
Share
Sponsored
FFIEC
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with FFIEC
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Federally insured banks, thrifts, and credit unions, their holding companies, and technology service providers examined under the Bank Service Company Act. Applicability is by charter and examination jurisdiction, not by size.

What the assessor asks to see

Examiners ask for the board-approved information security program and GLBA 501(b) program, the IT and cyber risk assessment, the IT audit universe and most recent audit reports, business continuity and disaster recovery plans with test results, the incident response plan and incident log, third-party risk management policy with due diligence files for critical vendors, access management and change management records, patch and vulnerability management reports, and board and IT steering committee minutes.

Assessors

Who assesses FFIEC

Federal and state bank and credit union examiners (OCC, FDIC, Federal Reserve, NCUA, state banking departments) using the handbook's examination procedures. Independent internal or external audits are expected but are not a certification. Examiners derive authority from their agencies.

No firm has claimed a FFIEC assessor listing yet. Claim yours →

Consultants

Who helps with FFIEC

IT audit and cyber consulting firms, virtual CISO providers for community banks, and core-processor partner programs. A typical engagement is an annual IT risk assessment and GLBA program review mapped to the handbook booklets, with a board report, ahead of the next safety and soundness or IT examination.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a FFIEC consultant listing yet. Claim yours →

Software

Tools for FFIEC

Tools that name this framework in their own material.

No firm has claimed a FFIEC tool listing yet. Claim yours →

Related reading

  1. FFIEC to Sunset Cybersecurity Assessment Tool in 2025Reports the retirement of the CAT and the standards regulators pointed institutions towards in its place.ABA Banking Journal
  2. FFIEC Cybersecurity Assessment Tool Sunset: What's Next?Explains what the CAT did for a bank's governance reporting and how to choose a replacement assessment approach examiners will accept.Rehmann

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for FFIEC

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with FFIEC

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.