Fed’s OIG finds insider risk management program lacks proactive, centralized controls
On July 15, the Fed’s OIG issued a report, finding that the Federal Reserve Board’s insider risk management (IRM) activities do not proactively or effectively identify and manage risks to the agency’s information and assets, and are not consistent with leading practices for designing and operating such programs. The OIG also identified a maturity gap between the Board’s IRM activities and those of a peer federal financial regulatory agency it benchmarked against. The OIG determined that the Board lacks: (i) a process to identify its critical assets; (ii) a centralized IRM program to proactively manage risks at an enterprise level; (iii) procedures for timely sharing of pertinent information internally and with the Federal Reserve System; (iv) enterprise-level policies and procedures establishing consistent incident response and reporting practices; and (v) insider risk training requirements for all staff. The OIG said these weaknesses were further demonstrated by the Board’s handling of recent potential insider risk incidents, including instances in which insiders compromised sensitive information about the Board’s mission-related responsibilities, such as nonpublic Federal Open Market Committee (FOMC) interest-rate-setting information and deliberations, bank supervision stress-test information, and other proprietary economic analysis.
The OIG issued nine recommendations to develop a more robust program, including that the Board identify and assess its critical assets; establish a centralized hub with a senior official, dedicated budget, and cross-divisional membership to oversee enterprise risk activities; and establish information-sharing procedures between Board divisions and the centralized hub, as well as clear lines of reporting and collaboration with stakeholders. The OIG further recommended that the Board establish enterprisewide policies and procedures for responding to insider risks, including clear thresholds for referrals to the OIG and outside law enforcement, and require IRM training for all personnel annually. The Board concurred with all five findings and nine recommendations, and outlined plans to address them, with target dates ranging from the fourth quarter of 2026 to the fourth quarter of 2027.