FFIEC IT Examination Handbook: what your examiners actually use
The FFIEC IT Examination Handbook is the playbook examiners bring to every IT examination. Five booklets covering information security, authentication, business continuity, infrastructure, and third-party risk. If your institution is federally supervised, these are the expectations you will be measured against. BlackSheep maps every control so you are ready before they arrive.
$249/month · All frameworks included · No credit card to start
20
Controls
5
Booklets
NIST CSF
Assessment framework
Rolling
Updates
Five booklets that define IT examination expectations
The FFIEC IT Examination Handbook organizes IT risk management into five core booklets, each containing detailed examination procedures and expectations.
Information Security
Booklet 1 · 5 controls
- Information security program management
- Threat identification and risk assessment
- Security controls implementation
- Security monitoring and incident response
- Cybersecurity resilience and recovery
Authentication & Access
Booklet 2 · 4 controls
- Authentication program management
- Multi-factor and layered authentication
- Access rights administration and review
- Privileged access management
Business Continuity Management
Booklet 3 · 4 controls
- Business impact analysis and planning
- Resilience and recovery strategies
- Testing and exercises across scenarios
- Third-party continuity considerations
Architecture, Infrastructure & Operations
Booklet 4 · 4 controls
- IT architecture and governance
- Infrastructure management and cloud computing
- Operations and change management
- Data management and data governance
External Dependency Management
Booklet 5 · 3 controls
- Third-party risk management lifecycle
- Due diligence and contract management
- Ongoing monitoring and oversight
Does the FFIEC IT Handbook apply to your organization?
Banks
All federally supervised banks, savings associations, and bank holding companies examined by the OCC, FDIC, or Federal Reserve. IT examinations are conducted on a regular cycle and the handbook defines the scope of those examinations.
- National banks (OCC)
- State nonmember banks (FDIC)
- State member banks (Federal Reserve)
- Savings associations
- Bank holding companies
Credit Unions
Federally insured credit unions supervised by the NCUA. The FFIEC examination procedures apply to credit union IT examinations, with expectations scaled to institution size and complexity.
- Federal credit unions
- Federally insured state credit unions
- Corporate credit unions
- Credit union service organizations
Technology Service Providers
Significant technology service providers examined directly by the FFIEC under the Bank Service Company Act. Multi-agency examination teams evaluate TSP operations, security, and resilience using the handbook as their primary reference.
- Core banking processors
- Cloud service providers
- Payment network providers
- IT managed service providers
- Cybersecurity vendors
Common questions about FFIEC IT compliance
How do examiners assess cybersecurity maturity?
FFIEC examiners now use the NIST Cybersecurity Framework as the standard methodology for assessing institutional cybersecurity maturity, replacing the previously used FFIEC CAT tool which was sunset. The NIST CSF evaluates practices across six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. Institutions should establish Current and Target Profiles documenting their existing practices and desired maturity, and use the gap between them to prioritize improvements.
How do examiners use the IT Examination Handbook?
Examiners use the handbook as their primary reference during IT examinations. Each booklet contains detailed examination procedures with specific questions, evidence requests, and evaluation criteria. Examiners assess whether an institution's practices meet the expectations outlined in the relevant booklets, scaled to the institution's size, complexity, and risk profile. Examination findings are documented and can result in matters requiring attention, recommendations, or formal enforcement actions.
What is the relationship between the FFIEC Handbook and GLBA?
The GLBA Interagency Guidelines establish the legal requirement for financial institutions to maintain written information security programs. The FFIEC IT Examination Handbook provides the detailed procedures and expectations that examiners use to evaluate whether those programs are adequate. Think of GLBA as the legal mandate and the FFIEC Handbook as the examination playbook examiners use to verify compliance.
What are the FFIEC expectations for cloud computing?
The FFIEC addresses cloud computing primarily through the Architecture, Infrastructure, and Operations booklet and supplemental guidance. Institutions must perform thorough due diligence on cloud service providers, ensure contractual protections including audit rights, understand data location and sovereignty implications, verify that security controls meet or exceed on-premises standards, and plan for concentration risk and vendor lock-in.
How does the FFIEC examine technology service providers?
The FFIEC conducts direct, multi-agency examinations of significant technology service providers under the Bank Service Company Act. These examinations evaluate the TSP's operations, security posture, resilience capabilities, and risk management practices. Results are shared with supervised institutions through examination reports. Institutions are expected to review these reports, understand findings relevant to their operations, and ensure appropriate corrective actions are taken.
Related frameworks
GLBA Interagency Guidelines
The legal foundation requiring information security programs that FFIEC examiners evaluate.
NIST CSF 2.0
Voluntary cybersecurity framework frequently referenced in FFIEC guidance and examination procedures.
CIS Controls v8.1
Prioritized security controls that align with FFIEC examination expectations.
Know what examiners expect before they walk in
Track every FFIEC booklet requirement, prepare for NIST CSF-based assessments, and maintain examination-ready evidence across all domains. BlackSheep maps the full IT Examination Handbook so nothing catches you off guard.
$249/month. 30-day money-back guarantee.