Federal banking agencies coordinate handling of ‘highly sensitive’ exam materials
On July 16, the Fed, the FDIC, and the OCC issued a joint statement establishing a coordinated approach for identifying and handling “highly sensitive information” during examinations of supervised banks. The statement provides that the agencies will rely on bank management to identify data and documents requested for an examination that management believes should be considered highly sensitive, allowing the agencies to evaluate whether additional protocols should apply to the review of that information. Examples of highly sensitive information may include technology and network diagrams and schematics, detailed penetration test results, technical details of specific information technology control weaknesses, and succession planning. For such information, the agencies said they will consider a range of options to minimize its collection and storage, including on-site review, direct digital review from the supervised bank’s own systems, and the use of redacted or summarized versions of documents.
The agencies committed to notifying affected banks of any material compromise of confidential supervisory information as soon as practicable and within no more than 72 hours after an agency has a reasonable basis to believe a compromise occurred and has determined which banks are affected, subject to applicable legal considerations. The statement further provides that banks with concerns about the sensitivity of requested information should raise those concerns with their examiners or primary agency contact, and that examiners will notify supervised banks of the specific processes through which they may escalate concerns to their primary federal regulator regarding examiner determinations on how to identify and handle highly sensitive information. The agencies said they will provide examiners with written guidance and training on the approach, and that examiners will notify supervised banks at the beginning of examination activities that bank management may identify information it considers highly sensitive.