What FFIEC Actually Requires of a Community Bank, in Plain English

What FFIEC Actually Requires of a Community Bank, in Plain English
TL;DR
  • The FFIEC is not a regulator. It is the council that coordinates how the prudential regulators (FDIC, OCC, Federal Reserve, NCUA, CFPB) examine financial institutions. The FFIEC publishes the IT Examination Handbook and related guidance that examiners actually use.

  • The IT Examination Handbook does not tell a bank what tools to buy. It describes a program with documented capabilities, governance, and evidence. A community bank is FFIEC-compliant when it operates the program, documents what it operates, and produces evidence the regulator can review.

  • The CEO question is not whether the bank has read the handbook. It is whether the bank's leadership, board, and operating discipline match what the handbook describes a community bank should look like by the time the next exam arrives.

What Every Community Bank CEO Should Know Before the First FFIEC IT Exam

A community bank CEO who has lived through one FFIEC IT exam knows the experience. A small team of examiners arrives on site or remotely, requests documentation across a wide range of topics, interviews the bank's qualified individual and IT lead, reviews the bank's program against current guidance, and produces an exam report. The whole process spans weeks. The findings shape the bank's compliance posture for the next cycle.

A CEO who has not yet lived through one approaches it with a different posture. The questions tend to be specific. What is FFIEC actually going to ask for? How much of the IT decision-making does the regulator actually direct? What does the report look like, and what does a "finding" mean for the bank?

The article that follows is the plain-English version of what FFIEC requires, what the exam actually evaluates, and where the leadership team's attention matters most.

 

What the FFIEC Actually Is — And What It Isn't

The FFIEC, the Federal Financial Institutions Examination Council, is the coordinating body for the prudential regulators of U.S. financial institutions. The council itself does not directly examine banks. Each prudential regulator (FDIC for state non-member banks, OCC for national banks, Federal Reserve for state member banks and bank holding companies, NCUA for credit unions) conducts its own examinations. The FFIEC's role is to coordinate the examination approach, publish unified guidance, and maintain the IT Examination Handbook the examiners use.

What this means for a CEO is that the bank's primary regulator (whichever of the four applies) is the entity that conducts the exam and signs the report. The FFIEC handbook is the framework the examiner uses, but the exam itself is the regulator's. A bank should know its primary regulator's specific expectations alongside the FFIEC handbook, because the two interact at the level of practical examination.

The FFIEC is not the FTC, which enforces the Safeguards Rule for non-banking financial institutions. A bank is subject to the GLBA Safeguards provisions through its prudential regulator, not through the FTC. The frameworks overlap heavily, but the enforcement paths differ.

 

What the IT Examination Handbook Actually Requires From a Community Bank

The FFIEC IT Examination Handbook is published as a series of booklets, each covering a specific area of bank IT and information security. The booklets relevant to a community bank include Information Security, Management, Operations, Audit, Partner engagement Technology Services, Business Continuity Management, Wholesale Payment Systems, Retail Payment Systems, and others depending on the bank's lines of business.

What the handbook describes is not a list of tools or a list of certifications. It describes a program with three recognizable layers.

The first layer is governance. The bank's board and senior management are accountable for the IT program. The handbook expects the board to oversee IT risk through reporting, approval of major decisions, and review of the program's output. Board minutes that show informed discussion of IT risk, not just receipt of reports, are the evidence the regulator looks for.

The second layer is the program itself. The bank operates an information security program with named ownership (the qualified individual under GLBA Safeguards, or the equivalent role under prudential expectations), documented Risk Assessment, technical and administrative safeguards, vendor risk management, business continuity and disaster recovery, incident response, and training. Each component is documented, maintained, and producing evidence of operation.

The third layer is examination evidence. When the examiner asks for a document, a record, or a demonstration, the bank produces it within a defensible timeframe. The evidence matches what the program describes. The documentation is current, not last year's version. Banks that operate the program but cannot produce the evidence are functionally non-compliant, regardless of how strong the program actually is.

 

What Replaced the CAT — And Why It Matters for Your Self-Assessment

For several years the FFIEC published the Cybersecurity Assessment Tool, a structured self-assessment that mapped a bank's inherent risk profile against its cybersecurity maturity across five domains. The CAT was widely used by community banks as a benchmarking framework, and many banks built their internal documentation around it.

In recent years the FFIEC has shifted toward the broader IT Examination Handbook framework, with specific updates to handbook sections on information security, third-party relationships, and business continuity. The CAT remains available as a resource, but examiners increasingly evaluate banks against the current handbook framework directly. A community bank still using the CAT as its primary self-assessment should plan for the handbook framework to become the dominant lens going forward.

For a CEO, this means the bank's self-assessment posture needs to evolve with the regulator's framework. A bank that built its program around the CAT in 2018 and has not updated since is operating against an older lens than the examiner is likely to use.

 

What the Examiner Is Actually Looking for During the IT Exam

A community bank IT exam runs through a recognizable sequence. The examiner reviews the bank's most recent Risk Assessment and asks where it came from, who maintains it, and how it integrates with the bank's broader risk management. The examiner reviews the information security program documentation and asks for evidence the program operates. The examiner reviews vendor risk management, asking for the tiered inventory and a sample of due diligence records. The examiner reviews business continuity and DR testing, asking for the most recent test results and remediation. The examiner reviews incident response, asking what the bank did when its most recent incident occurred. And the examiner reviews board reporting, asking what the board has been told and what the board has decided.

What the examiner is evaluating across all of this is consistency. The program described in the documentation should match what the bank actually operates. The board reporting should match what the program produces. The Risk Assessment should match the systems and vendors the bank actually uses. Banks where the documentation describes one program and the operation reflects another produce findings.

The exam report itself includes findings (specific deficiencies cited), Matters Requiring Attention (findings the bank is required to address), and in serious cases enforcement actions or formal agreements that constrain the bank's operation until remediation is complete. Most community banks see findings; fewer see MRAs; very few see formal agreements. The escalation depends on severity and on whether the bank's response is credible.

 

The Six Things a CEO Should Be Able to Answer When the Examiner Asks

A community bank CEO does not need to read the entire IT Examination Handbook. The CEO needs to know, in operational terms, what the regulator expects to see and where the bank is likely to fall short.

The CEO should know what the bank's most recent Risk Assessment says about the bank's risk profile, who owns the assessment, and when it was last updated. The CEO should know what the bank's information security program documentation describes and whether the operation matches it. The CEO should know which vendors are tiered as critical and what oversight the bank applies to them. The CEO should know whether the bank has a current, tested business continuity and DR posture. The CEO should know what the bank's most recent incident response activity was, even if it was a near-miss. And the CEO should know what the board has been told, when, and what the board decided in response.

Those are the questions the regulator will ask the CEO directly during the exam. A CEO who can answer them clearly is operating the bank the FFIEC handbook describes. A CEO who cannot is operating a different bank than the one in the documentation.

 

Why "That's IT and Compliance's Job" Is a Governance Finding Waiting to Happen

A community bank CEO will hear, somewhere in the budget or operating discussion, this argument: FFIEC compliance is the IT and compliance functions' responsibility, the CEO's role is to approve their work, and direct executive engagement is unnecessary as long as those functions operate.

That is a false choice, and recent enforcement has made it expensive to keep believing in. The handbook explicitly names the CEO and senior management as accountable for the program. The exam evaluates governance, not just IT operations. CEOs who delegate FFIEC compliance entirely to IT and compliance produce banks where the program runs but where governance is not visible to the regulator. The findings that follow are not findings about IT. They are findings about governance.

The right framing is not whether the CEO needs to direct IT operations. It is whether the CEO is sized into the program's governance, is briefed on its operation, and is producing evidence of executive oversight that the regulator can examine. The first framing produces a delegated program. The second framing produces a defensible one.

 

Three Things Every CEO Should Have in Place Before the Next IT Exam

A community bank CEO should work through three things before the next IT exam. The first is a current-state benchmark of the bank's program against the FFIEC handbook framework, with the gaps named in plain language. The second is a one-page board briefing summary that the CEO can use in the next governance review, demonstrating the executive engagement the handbook expects. The third is a calendar discipline that ensures the program's outputs (Risk Assessment updates, vendor reviews, BCP tests, incident response exercises, board reporting) happen on a documented cadence rather than as fire drills.

When this discipline is in place, the next FFIEC exam is recognizably calmer than their last one. The conversation moves from "what are you doing about cyber risk" to "let's review the program's most recent reports," and the gap between the two framings is the difference between an exam that becomes a corrective-action plan and an exam that becomes a routine confirmation.

 

Know the Framework Before the Examiner Tests You on It

A community bank CEO reading the FFIEC IT Examination Handbook for the first time encounters a document that describes a program rather than a checklist. The bank that operates the program, documents what it operates, and demonstrates governance over what it documents will defend the next exam on its own terms. The bank that operates parts of the program, documents some of what it operates, and treats governance as a delegation will face the exam on the regulator's terms.

If your bank has not produced a current-state benchmark against the FFIEC framework in the last twelve months, that is the conversation worth having with your Tech-Operations partner before the next exam cycle.

Five Nines Technology Group is a Tech-Operations partner for community banks and credit unions. Translating regulatory frameworks into operating discipline at community bank scale is where our team focuses.

Frequently asked questions

Does the FFIEC examine my bank directly?

No. Your primary prudential regulator (FDIC, OCC, Federal Reserve, or NCUA for credit unions) conducts the exam. The FFIEC publishes the framework and coordinates approach across regulators.

How often does an IT exam happen?

For most community banks, a full IT exam happens on a multi-year cycle, with interim reviews in between. The exact cadence depends on the bank's size, risk profile, and prior findings. Banks with material findings see more frequent exams.

What is a "finding" versus an "MRA" versus an "enforcement action"?

A finding is a deficiency the examiner cites in the report. An MRA (Matter Requiring Attention) is a specific finding the bank is required to address with a documented response. An enforcement action is a formal regulatory measure (such as a Memorandum of Understanding, Written Agreement, or Consent Order) that constrains the bank's operation until remediation is complete. Most community banks see findings; the escalation tracks severity.

Can the bank's external IT auditor predict what FFIEC will find?

A competent IT auditor with bank-specific expertise can identify many of the gaps an exam would find. Banks that commission pre-exam readiness assessments through a Tech-Operations partner experienced in the framework typically benefit, since the assessment surfaces issues the bank can fix before the exam rather than after.

Does the FFIEC handbook apply differently to credit unions under NCUA?

NCUA has its own examination framework, but it increasingly aligns with the FFIEC handbook on IT and information security. Credit unions should be familiar with both NCUA-specific guidance and the FFIEC handbook, with their primary regulator's specific expectations driving the operational program.

What is the most common reason community banks see findings?

Documentation gaps. The bank's program operates, but the documentation does not match what the program does, or is out of date, or does not exist for specific functions the rule requires. Findings cite the documentation gap, not the operational substance.

How does the bank's strategic plan interact with FFIEC expectations?

The handbook expects IT and information security to integrate with the bank's broader strategic plan. A bank whose strategic plan does not address IT and cyber risk produces inconsistency the examiner notices. A bank whose plan addresses these explicitly demonstrates the executive engagement the framework expects.

Related Blog Posts

The 10 Most Common GLBA Safeguards Rule Violations FDIC Examiners Are Citing in 2026

The 10 Most Common GLBA Safeguards Rule Violations FDIC Examiners Are Citing in 2026

What This Year's Exam Findings Have in Common The pattern is not subtle. The regulators are not citing novel technical failures. They are citing the...

Read More
What Good Looks Like: A Tech-Operations Partner Relationship for a Community Bank (The CFO Contract View)

What Good Looks Like: A Tech-Operations Partner Relationship for a Community Bank (The CFO Contract View)

Why the Tech-Operations Partner Contract Is a Governance Instrument, Not a Procurement Signature A community bank CFO walking into a Tech-Operations...

Read More
Why Community Banks Keep Failing the Same FFIEC IT Exam Findings Year After Year

Why Community Banks Keep Failing the Same FFIEC IT Exam Findings Year After Year

Why the Same Findings Keep Appearing Every Exam Cycle A community bank CEO walking into the next FFIEC IT exam often sees a familiar list of likely...

Read More