Exams go need-to-know on highly sensitive information

A July 16 joint statement lets banks flag their most sensitive materials for on-site or direct-access review instead of handing them over. It also commits the agencies to 72-hour notice if supervisory information is compromised.

Jul 16
Joint statement
3
Agencies · Fed, OCC, FDIC
Up: 72 hrs
Compromise notice window

On July 16 the Federal Reserve, OCC, and FDIC issued a joint statement on handling highly sensitive information during examinations (OCC Bulletin 2026-32 and FDIC FIL-37-2026). Security teams have argued the premise for years. Some documents are more dangerous in transit than they are informative in an exam file. Examples include network diagrams and schematics, detailed penetration-test results, technical details of specific IT control weaknesses, and succession plans.

The mechanics put the first move with the bank. Management identifies the requested materials it believes are highly sensitive, and the agencies then evaluate whether additional protocols should apply. Chief among them are alternative review methods, such as on-site examination or direct digital access through the bank’s own systems. These reduce the need to transfer sensitive data onto agency systems at all.

The 72-hour commitment

The statement also formalizes an obligation running in the other direction. If an agency has a reasonable basis to believe a material compromise of confidential supervisory information has occurred, it commits to notify affected banks as soon as practicable and within no more than 72 hours of determining which banks are affected, subject to applicable legal considerations. Exam material sitting on agency infrastructure is a real attack surface. The agencies are now on the clock to tell you if it leaks.

Your pen-test results are a map of your weakest points. The new statement recognizes that the safest place for that map is inside your own walls.
What this means for your bank
  • Build a standing “highly sensitive” inventory now that lists diagrams, pen-test reports, IT control details and succession plans. When the first-day letter arrives, identifying them becomes a lookup instead of a scramble.
  • Decide your preferred review method (on-site or direct digital access) for each document class, and be ready to propose it to your EIC.
  • Add agency-side CSI compromise to your incident-response playbook. Name who receives the 72-hour notice and what happens in the next 24 hours.
From Zovos AI

Zovos tags exam-request items against your sensitivity inventory automatically, so the highly-sensitive flag and the review method you want travel with every document request.