On July 16, 2026, the Federal Reserve Board, the Federal Deposit Insurance Corporation (“FDIC”) and the Office of the Comptroller of the Currency (“OCC”) issued a joint statement and press release announcing a new, coordinated approach to handling highly sensitive information during examinations of supervised banks (the “Joint Statement”).  This is a welcome step, as financial services institutions seek greater protection for sensitive data shared with regulators.

Alongside the Joint Statement, a coalition of banking trade associations, including the American Bankers Association, Bank Policy Institute, Institute of International Bankers, and Securities Industry and Financial Markets Association, published a companion risk-based practices framework designed to help banks identify information that warrants heightened protection and determine how that information may be shared more securely. Debevoise’s Data Strategy and Security group worked with the Bank Policy Institute and its members to initially develop the framework, including by conducting a member survey to better understand the information supervised institutions view as highly sensitive, the types of sensitive information that financial regulators request, how supervised institutions currently identify, share and protect that information, preferred alternatives, and the practical risks associated with a range of sharing methods.

The framework provides supervised institutions with a practical basis for evaluating supervisory information requests and seeking appropriately tailored, proportionate, and secure methods for sharing highly sensitive information with regulators, while continuing to support effective supervision.

Background

In the ordinary course of examinations, federal banking regulators regularly request that supervised institutions provide access to highly sensitive information, including detailed cybersecurity assessments and network diagrams, succession and transition plans, board and employee materials, and sensitive audit, compliance, and internal investigation records.

As examinations have become increasingly digital, highly sensitive data is often transferred to and stored on agency systems, creating additional security and confidentiality risks by placing copies of that data outside of the supervised institution’s direct control. The risks associated with that model were underscored in 2024 and 2025, when the U.S. Department of the Treasury and the OCC disclosed cybersecurity incidents, which prompted financial services trade associations to ask regulators to reconsider how sensitive information is collected and stored during examinations.

Newly Enhanced Security Procedures

The Joint Statement establishes a process for reducing the collection and storage of “highly sensitive” information on regulator systems while preserving examiners’ access to information needed for an examination.

Under the new approach, supervised institutions are responsible for identifying requested information they consider highly sensitive and raising any concerns with their examiner or primary regulatory contact. The agencies will then consider alternatives to taking custody of the information, including leveraging on-site review, conducting digital review directly from the bank’s systems, and accepting appropriately redacted or summarized versions of documents. If an examiner determines that information deemed highly sensitive by a bank must be obtained for the supervisory record, that determination is subject to approval through the examiner’s supervisory chain.

The agencies also committed to notify affected banks of a potential or confirmed material compromise of confidential supervisory information as soon as practicable and generally no later than 72 hours after discovery.

What Counts as “Highly Sensitive” Information?

The process laid out in the Joint Statement defers to supervised institutions to define “highly sensitive” information. However, it identifies four potential examples as guideposts: technology and network diagrams and schematics, detailed penetration-test results, technical details of specific information technology control weaknesses, and succession planning. The inclusion of succession planning alongside three cybersecurity-related examples signals that highly sensitive information is not limited to cybersecurity and technical materials.

The companion industry framework provides supervised institutions with a broader taxonomy covering strategic and financial information; security, resilience and third-party risk information; internal business information; and legal, regulatory and compliance information. It also identifies practical protections that supervised institutions can consider, including providing firm-controlled access to highly sensitive data, providing summaries or excerpts, redacting particularly sensitive details, and using access restrictions and restricted file formats.

Practical Next Steps

Supervised institutions should begin to assess the types of information requests that arise during examinations and whether they consider that information to be highly sensitive, drawing on both the agencies’ examples and the broader industry framework. Compliance, information security, legal, and regulatory relations teams should then determine the appropriate and preferred handling method for each category, such as on-site review, firm-controlled digital access, or redacted or oral summaries, and align to an internal process for promptly raising and escalating concerns about sensitive requests.

The federal banking agencies stated in their release that they plan to provide examiners with written guidance and training and will require examination teams to notify banks of their ability to identify highly sensitive information and the procedures for escalating disagreements.

***

To subscribe to the Data Blog, please click here.

The Debevoise STAAR (Suite of Tools for Assessing AI Risk) is a monthly subscription service that provides Debevoise clients with an online suite of tools to help them fast-track their AI adoption. Please contact us at STAARinfo@debevoise.com for more information.

The cover art for this blog post was generated by ChatGPT 5.6.

Author

Erez is a litigation partner and a member of the Debevoise Data Strategy & Security Group. His practice focuses on advising major businesses on a wide range of complex, high-impact cyber-incident response matters and on data-related regulatory requirements. Erez can be reached at eliebermann@debevoise.com

Author

Kendall Howell is counsel and a member of the firm's Data Strategy & Security and Banking Groups. His practice focuses on advising banks, broker-dealers, money services businesses, fintech companies and other financial institutions on artificial intelligence governance, BSA/AML and sanctions compliance, bank regulatory matters, risk management and regulatory enforcement. He can be reached at khowell@debevoise.com.

Author

Stephanie D. Thomas is an associate in the Litigation Department and a member of the firm’s Data Strategy & Security Group and the White Collar & Regulatory Defense Group. She can be reached at sdthomas@debevoise.com.

Author

Carl Lasker is an associate in the Litigation Department. He can be reached at calasker@debevoise.com.

Author

Caroline Moore is a law clerk in the Litigation Department. She can be reached at ccmoore@debevoise.com.