Handling Highly Sensitive Information During Examinations: The Governance Questions Banks Should Consider

Bank audit committee reviewing a confidential document in a boardroom before a regulatory examination

The Federal Reserve, FDIC, and OCC now expect bank management to raise concerns about information that management believes should receive special handling during examinations. Boards should set governance parameters before those decisions are made under exam pressure.

Executive Summary

On July 16, 2026, the Fed, FDIC, and OCC issued a joint statement establishing a coordinated approach for handling highly sensitive information during examinations of supervised banks [1][2][3]. The technical elements have been well covered in the trade press: enhanced security procedures, a range of options to minimize the collection and storage of highly sensitive information on agency systems, and a commitment to notify affected banks of a potential or confirmed material data breach involving confidential supervisory information as soon as practicable and no later than 72 hours, subject to legal considerations [1][8]. The element that implicates the audit committee most directly has received less attention. It appears in a single sentence: bank management should raise concerns with the Examiner-in-Charge or primary agency contact when management believes requested data or documents should be treated as highly sensitive [1]. Although the statement does not assign a role to the board or audit committee, institutions may benefit from establishing governance parameters before these decisions arise during an examination. Those parameters should preserve the agencies’ access to information and internal audit’s unrestricted access under the institution’s charter [5][6][7].


Key Takeaways

  • The board should clarify management’s role. The statement governs how information is protected during exams, not whether examiners can access it. The sensitivity concern should be raised through an institutional framework. That judgment belongs in a governance framework, not in an ad hoc email during an exam [1][4].
  • Special handling may involve several options. The agencies may consider on-site review, direct digital review of the bank’s systems, redacted or summarized documents, and additional measures for transmission and access. These options are intended to minimize agency collection and storage while preserving the agencies’ ability to access information, conduct examinations, support conclusions, and maintain a historical record [1][4].
  • Unrestricted access is not a technicality. The Global Internal Audit Standards, effective January 9, 2025, and the IIA’s Three Lines Model require internal audit to have full, unrestricted access to records, personnel, and property. A framework built for examiner handling may influence internal practices if the board does not preserve internal audit’s unrestricted access in writing [5][6][7].
  • Boards should set the parameters upfront. The audit committee, not management alone, should own the framework that defines when management should raise a sensitivity concern, who approves the institution’s position before it is raised with examiners, and how disputes escalate. Left unsettled, those questions are answered under pressure and inconsistently [5][7].
  • The 72-hour breach notification commitment requires institutional readiness. The agencies have committed to notify affected banks of a potential or confirmed material compromise of confidential supervisory information as soon as practicable and no later than 72 hours after the impacted agency has a reasonable basis to believe a compromise occurred and determines which banks are affected, subject to applicable legal considerations. Institutions should establish documented channels for receiving and escalating that notice [1][3].

What the Statement Actually Says, and What It Does Not Change

The joint statement, issued by the Fed, FDIC, and OCC on July 16, 2026, outlines a coordinated approach for identifying and handling highly sensitive information during examinations, including at community banks [1][3][4]. The FDIC issued a parallel Financial Institution Letter, FIL-37-2026, and the OCC issued Bulletin 2026-32, both emphasizing that the statement does not establish new expectations and aims to protect sensitive supervisory data while preserving the agencies’ ability to examine [2][4]. The categories flagged as potentially highly sensitive are practical, not exotic: technology and network diagrams, detailed penetration test results, technical details of specific IT control weaknesses, and succession planning documents [1]. Every community and regional institution has files that fit.

For that information, examiners may review materials on-site rather than transferring them to agency systems, conduct direct digital review from the bank’s own systems, or accept redacted or summarized versions, along with added transmission and access controls [1]. After any of these methods, examiners may still determine that a copy is needed for the supervisory record, and, where legal requirements are met, redacted or summary documents may be accepted [1]. The agencies also commit to notify affected banks of potential or confirmed material data breaches involving confidential supervisory information as soon as practicable and no later than 72 hours after the impacted agency has a reasonable basis to believe a compromise occurred and determines which banks are affected, subject to legal considerations [1][3].

What the statement does not do matters just as much. It does not restrict the agencies’ access to information or authorize a bank to withhold requested information from an examiner. The coordinated process is intended to minimize the collection and storage of highly sensitive information without interfering with the agencies’ ability to access information, conduct examinations, support conclusions, or maintain a historical record [1][2]. The statement also creates no right or benefit enforceable against the agencies [1]. It changes the methods for handling highly sensitive information during review, not the agencies’ authority to obtain and examine it.

The Governance Question the Statement Creates

Under the coordinated approach, the process begins when bank management believes certain requested information should be considered highly sensitive and raises that concern with the assigned Examiner-in-Charge or primary agency contact [1][2]. The agencies then evaluate whether additional protocols should be used. Although this is a procedural step, it creates a practical governance question: how will the institution make and escalate these judgments consistently without delaying or limiting examiner access? That question is best addressed before an examination begins.

Five questions arise immediately, and each deserves a written answer before the next exam cycle. Who has the authority to designate information as highly sensitive, and what evidence supports that designation? Can management narrow an information request from internal audit, external audit, or regulators, and under what standard? Should the audit committee approve any framework that reshapes how information is provided before it is used in front of an examiner? Are there categories that internal audit and regulators should review only on-site, and how is that documented in the charter and in exam correspondence? When a disagreement over access arises, how is it escalated, and who decides? None of these questions is addressed by the statement, and none should be answered for the first time during an exam.

One clean line matters here. The statement addresses how the agencies handle the sensitive information they review. The IIA principles govern how internal audit accesses information within the institution. These are two distinct questions, and boards should resist letting a protective framework built for regulators quietly become a limiting framework for their own third line.

The IIA Principle That Must Not Be Compromised

The IIA has been consistent for two decades. The internal audit charter, approved by the governing body and agreed to by management, must grant internal audit full and unrestricted access to all records, data, physical property, and personnel needed to fulfill its mandate [5][7]. The Global Internal Audit Standards carry that principle forward and treat any management-imposed limit on access as a potential impairment of independence that must be reported to the governing body [5]. The Three Lines Model reinforces this principle: the third line provides independent assurance to the board, and that assurance rests on the ability to test management’s assertions [6].

The practical risk is straightforward. An institution builds a categorization framework so management can respond confidently to an examiner’s request for penetration test results. Six months later, the same framework is quietly applied when internal audit requests the same file. Built for supervisory purposes, it now functions as an access filter for independent assurance. That is not a policy change; it is an unintended independence impairment the charter does not authorize and the audit committee never approved. The remedy is not to avoid categorization. It is to design it so the distinction between the how and the what is preserved in writing and to explicitly preserve internal audit’s unrestricted access, even when a special handling protocol applies [5].

Charter language and external audit engagement letters should be reviewed with that distinction in mind. When the institution establishes protective handling procedures for regulators, the charter should confirm that internal audit retains full and unrestricted access to the underlying information in its original form, subject to the confidentiality obligations it already has under the Standards [5]. Handling protocols are a legitimate response to real cybersecurity risk. They are not a legitimate basis for narrowing the assurance mandate.

What the Board Should Be Asking

The governing body’s role under the Three Lines Model is not to run the examination process. It is to set the framework within which management operates and to demand evidence that the framework works [6]. Five questions belong on the next audit committee agenda.

•  First, does the institution have a written framework that defines when management should raise a sensitivity concern under the joint statement, and has the audit committee approved it? A framework applied consistently across exams is defensible; an ad hoc one is not [1][5].

•  Second, does the internal audit charter explicitly ensure full and unrestricted access to records, personnel, and property, even when alternative handling protocols for regulators are in place? If not, update it at the next scheduled review [5][7].

•  Third, is there a documented escalation path when management and internal audit, or management and the Examiner-in-Charge, disagree on categorization or handling? It should escalate to the audit committee, not stop at the CRO or the General Counsel [5][6].

•  Fourth, is management prepared to receive the agencies’ 72-hour breach notification via a documented channel, and does the incident response playbook treat confidential supervisory information as a distinct category of protected data? The commitment is only useful if the receiving side can act on it [1][3][9].

•  Fifth, has internal audit tested the special handling framework itself? Access controls, exception logs, and prior categorization decisions should be auditable. If they are not, the framework is a policy document rather than a control [5][6].

The joint statement is a reasonable response to a real problem. The OCC’s own experience with unauthorized access to sensitive supervisory information is part of why the agencies are moving now, and the coordinated approach improves on the patchwork that preceded it [8]. It also places a practical identification step on supervised institutions. Those that treat that step as a governance opportunity and build the framework with the audit committee before the next exam window will handle the statement without incident. Those that leave the decision to the exam itself may find that their special handling framework has quietly narrowed the assurance the board relies on.

The agencies changed how sensitive information is handled. The board still owns the framework for determining when management raises a sensitivity concern, who approves the institution’s position internally, and how disputes are resolved. That framework should be in place now, not later.

About the Author

Celeste Burton is the Compliance Practice Director and Director of Credit Union Risk and Advisory at AuditOne, with over 30 years of banking experience spanning Internal Audit, Compliance, and Enterprise Risk at institutions including Bank of America, Countrywide, and American Express. A Certified Internal Auditor, she has built and tested governance and access frameworks that support the assurance posture outlined in this brief. She also advises community and regional financial institution boards on audit committee readiness, charter design, and examination management. She holds a dual degree in Accounting and Finance from UC Berkeley.

References

[1] Board of Governors of the Federal Reserve System, Federal Deposit Insurance Corporation, and Office of the Comptroller of the Currency. Statement Regarding Coordinated Federal Banking Agency Approach for the Handling of Highly Sensitive Information During Examinations. July 16, 2026. https://www.occ.gov/news-issuances/news-releases/2026/nr-ia-2026-60a.pdf

[2] Federal Deposit Insurance Corporation. Financial Institution Letter FIL-37-2026, Handling of Highly Sensitive Information During Examinations. July 16, 2026. https://www.fdic.gov/news/financial-institution-letters/2026/handling-highly-sensitive-information-during-examinations

[3] Board of Governors of the Federal Reserve System. Joint Press Release: Agencies Issue Joint Statement on Handling of Highly Sensitive Information During Bank Examinations. July 16, 2026. https://www.federalreserve.gov/newsevents/pressreleases/bcreg20260716a.htm

[4] Office of the Comptroller of the Currency. OCC Bulletin 2026-32, Examinations: Joint Statement on Identifying and Handling Highly Sensitive Information During Examinations. July 16, 2026. https://www.occ.gov/news-issuances/bulletins/2026/bulletin-2026-32.html

[5] The Institute of Internal Auditors. Global Internal Audit Standards, effective January 9, 2025. https://www.theiia.org/en/standards/

[6] The Institute of Internal Auditors. The IIA’s Three Lines Model: An Update of the Three Lines of Defense. July 2020. https://www.theiia.org/globalassets/documents/content/articles/gpi/2020/december/three-lines-model_english-final.pdf

[7] The Institute of Internal Auditors. Position Paper: The Internal Audit Charter, A Blueprint to Assurance Success. August 2019. https://www.theiia.org/globalassets/documents/resources/the-internal-audit-charter-a-blueprint-to-assurance-success-august-2019/pp-the-internal-audit-charter.pdf

[8] ABA Banking Journal. Banking Agencies Promise New Approach for Handling Sensitive Information. July 16, 2026. https://bankingjournal.aba.com/2026/07/banking-agencies-promise-new-approach-for-handling-sensitive-information/ [9] Federal Financial Institutions Examination Council. FFIEC Information Technology Examination Handbook, Information Security Booklet. https://ithandbook.ffiec.gov/it-booklets/information-security

Scroll to Top

We look forward to hearing from you.

Your Name(Required)
Your Email Address(Required)

How can AuditOne help? Are there certain Internal Audits or Risk Assessments you would like to know more information about?

Please let us know what's on your mind. Have a question for us? Ask away.
Consent(Required)