Bank Regulators Set Coordinated Approach to Handling Sensitive Information Requested During Examinations
The Federal Reserve, the FDIC, and the OCC have committed to a coordinated approach to identifying, handling, and protecting highly sensitive information requested during bank examinations.
In a statement, the regulators said that bank management would take the first step in identifying which requested documents and data it considers highly sensitive. According to the regulators, a bank that flags information as highly sensitive should discuss with its examiners how to limit the information that the regulators collect and store. The regulators added that redacted or summary documents may be acceptable if examiners need to keep the information for the supervisory record and if legal requirements are satisfied.
Also, if there is a potential or confirmed material compromise of sensitive information the regulators are holding, they would be required to tell the affected bank within 72 hours. The clock would start once the impacted regulator has a reasonable basis to believe a material compromise occurred and determines which banks were affected.
Commentary
Regulators are wise to limit the amount of sensitive information that they hold, as the governmental entities are no less vulnerable to cyber breaches than are private entities. In fact, regulators may be more vulnerable, since they may be less concerned about being subject to enforcement actions, private suits, or loss of reputation. Indeed, one of the primary complaints that SEC Commissioner Hester Peirce advanced against the Consolidated Audit Trail is that it collected a massive amount of sensitive data in a single place.