Skip to Main Content
ICBA
  • Member Login
  • Member Login

ICBA, others issue best practices for sharing sensitive information


July 24, 2026 / By ICBA

ICBA and other groups published a new paper recommending best practices for safeguarding sensitive information in the supervisory process.

Background: Regulators require banks to share certain sensitive information as part of the examination process, including roadmaps for cybersecurity defenses, CEO succession plans, and merger and acquisition proposals. Given the sensitivity of such data and the rise in sophisticated cyber threats, financial institutions must work to keep their information secure, including when examiners need to access it.

Recent Action: The FDIC, Federal Reserve, and OCC last week announced they are instituting a coordinated approach for handling highly sensitive information during examinations of supervised banks.

Recommendations: In the joint paper, ICBA and the other groups suggested risk-based practices to safeguard the information that firms share with regulators:

  • Providing firm-controlled access to sensitive data electronically via firm-hosted applications, by screen sharing, or physically via on-site review.

  • Narrowing the regulator audience by tracking and controlling access to certain examiners with a demonstrable need to know.

  • Creating summaries or aggregated data instead of transmitting detailed records, individually identifiable information, or entire privileged documents.

  • Providing samples or excerpts instead of comprehensive data sets or documents to reduce unnecessary exposure.

  • Redacting sensitive details such as personally identifiable information, employee compensation and performance data, board member evaluations, internal IP addresses, and any material protected by the attorney-client privilege.

Join ICBA Community

Interested in discussing this and other topics? Network with and learn from your peers with the app designed for community bankers. 

Join the community Example Text