Risk‑Based Framework for Strengthening Sensitive Data Sharing Between Supervised Institutions and Financial Regulators

0
5

Key Takeaways

  • U.S. prudential banking regulators (Federal Reserve, OCC, FDIC) issued an interagency statement urging a risk‑based approach to handling highly sensitive supervisory data.
  • Supervised institutions should identify any requested information they deem highly sensitive and retain control over its sharing.
  • Preferred sharing methods are firm‑controlled access (electronic via firm‑hosted applications, screen‑sharing, or on‑site review) rather than direct transfers that create additional copies.
  • When direct transfer is unavoidable, regulators must agree in writing on storage, access, retention, and disposal safeguards.
  • Protective measures—access restrictions, summarization, sampling, redaction, restricted file formats, and secure storage/disposal—should be applied based on data sensitivity.
  • Four data categories are highlighted: Strategy, Planning & Financial Data; Security, Resilience & Third‑Party Risk Management; Internal Business Data; and Legal, Regulatory & Compliance Data, each with especially sensitive sub‑types requiring extra safeguards.
  • The overarching goal is to reduce the attack surface, preserve institutional control, and strengthen collective cybersecurity resilience while fulfilling supervisory obligations.

Background and Evolving Supervisory Practices
Financial regulators have historically relied on on‑site manual inspections to obtain books and records from supervised institutions. As examinations become increasingly digital, the process now involves the electronic collection, retention, and transmission of large volumes of sensitive data. This shift introduces cybersecurity risks not only for the institutions but also for the regulators that hold data from multiple firms. Recognizing that the supervisory process itself should not create unnecessary exposure, the Federal Reserve, OCC, and FDIC issued an interagency statement advocating a coordinated, risk‑based approach to handling highly sensitive information during examinations. The statement emphasizes that institutions must identify any data they consider highly sensitive and retain authority over how that information is shared.


Purpose of the Risk‑Based Guidance
The document distills extensive feedback from financial institutions and industry stakeholders into clear, baseline expectations for securely sharing and managing sensitive supervisory data. It applies to a broad spectrum of supervisory interactions—including formal examinations, ad‑hoc requests, routine meetings, and ongoing monitoring—and is intended for U.S. federal financial regulators, state banking agencies, insurance regulators, their agents and contractors, and the institutions they supervise. By establishing consistent practices, the guidance aims to foster collaboration, preserve data security as a routine discussion topic, and adapt to an evolving threat landscape.


Methods for Sharing and Protecting Sensitive Information
Institutions regularly share four broad categories of sensitive data with regulators: Strategy, Planning & Financial Data; Security, Resilience & Third‑Party Risk Management; Internal Business Data; and Legal, Regulatory & Compliance Data. Three primary sharing methods are used:

  1. Direct Transfer – Uploading documents to regulator‑managed portals, sending encrypted emails, or providing hard copies. Even with encryption and strong access controls, this method creates additional copies, reduces institutional visibility, and expands the attack surface.
  2. Firm‑Controlled Access – Granting regulators persistent or temporary electronic view‑only access through firm‑hosted applications, conducting screen‑sharing sessions, or arranging on‑site reviews using institution‑controlled devices. These approaches limit data duplication and preserve the institution’s existing security protocols.
  3. Oral Discussion – Conveying information verbally without written documentation, which can reduce the need for data transfer but still requires protective handling of any meeting notes or follow‑up communications.

For especially sensitive information, institutions and regulators may agree to substitute less‑sensitive details or limit sharing to oral briefings only.


Protective Measures to Limit Exposure
When sharing data—whether via direct transfer or firm‑controlled access—institutions should consider one or more of the following safeguards:

  • Access Restrictions – Limit regulator audiences to examiners with a demonstrable need‑to‑know; track and control copying, downloading, printing, and sharing in firm‑hosted environments.
  • Summaries and Aggregation – Provide aggregated or summarized data instead of detailed records, reducing exposure to large or privileged datasets.
  • Samples and Excerpts – Share representative samples or excerpts rather than full datasets when the regulator’s request does not require comprehensive information.
  • Redactions – Remove personally identifiable information (PII), employee compensation, performance data, board evaluations, internal IP addresses, and any material protected by attorney‑client privilege or work‑product doctrine.
  • Restricted File Formats – Distribute information as screenshots or other non‑editable formats rather than native Word/Excel files, making data extraction more difficult.
  • Secure Storage, Retention, and Disposal – Prior to any direct transfer, agree in writing on where data will be stored, who will access applied protections, retention periods, and disposal methods (return to the institution or secure destruction). Document these agreements to ensure accountability.

These measures can be combined—for example, offering on‑site view‑only access to a full dataset while directly sharing only a summarized excerpt—to achieve optimal risk mitigation while satisfying supervisory needs.


Risk‑Based Sharing Best Practices Across Data Categories

Strategy, Planning & Financial Data – Regulators may request strategic objectives, succession plans, capital plans, material non‑public information, M&A details, financial statements, investment strategies, and revenue analyses. Institutions should provide firm‑controlled access via electronic applications, screen‑sharing, or on‑site review for most of this data. Pre‑deal M&A information and succession‑related details are exceptionally sensitive; they should be shared only orally or with added protections such as narrowed regulator audiences and summary formats until the information becomes public.

Security, Resilience & Third‑Party Risk Management – Requests often include network diagrams, configuration settings, security controls, testing methodologies, resilience/backup capabilities, vulnerability lists, incident‑management records, assessment results (penetration tests, red‑team outputs), and third‑party engagement reports. Because disclosure could enable malicious actors to compromise operations, firms should favor firm‑controlled access or on‑site review. Raw technical artifacts (configuration files, detailed network diagrams, IP addresses, data‑center locations) and vendor contract terms are especially sensitive and should be further protected via audience narrowing, summarization, and redaction; in many cases, they should not be shared externally at all.

Internal Business Data – This category covers board meeting materials, evaluations, product/service designs, intellectual property, detailed business reviews, trading/client‑account data, fraud‑monitoring materials, customer/investor/employee PII, employee compensation/performance data, and AI‑related governance, models, and validation records. Institutions should again encourage firm‑controlled access or on‑site review for most items. Customer and employee PII, individual compensation/performance data, and records of internal board/executive deliberations are exceptionally sensitive and warrant additional safeguards such as restricted regulator audiences, redaction, aggregation, or excerpting.

Legal, Regulatory & Compliance Data – Regulators may seek internal audit methodologies/results, AML/BSA suspicious activity filings and related modeling, non‑privileged investigation materials, and documents subject to attorney‑client privilege or work‑product doctrine. Firms should provide firm‑controlled access or on‑site review for most of these items. Given the privileged nature of attorney‑client and work‑product materials, regulators must respect that their examination authority does not override these protections; sharing should be avoided unless absolutely necessary, in which case protections such as audience narrowing, summarization, and redaction are required.


Conclusion
The supervisory process will continue to face sophisticated cyber threats from nation‑state actors, criminal syndicates, and other adversaries. By adopting the risk‑based practices outlined—prioritizing firm‑controlled access, minimizing data copies, applying tailored protective measures, and maintaining clear agreements on storage and disposal—regulators and supervised institutions can collectively reduce the attack surface of supervisory data. This collaborative approach preserves institutional control over the most sensitive information, strengthens the resilience of the financial system, and ensures that oversight remains effective without compromising cybersecurity. Implementing these standards will benefit customers, investors, regulators, and the institutions themselves by fostering a safer, more secure supervisory environment.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here