Banking
OCC, FFIEC, and prudential regulation compliance
Banks operate under comprehensive regulatory oversight from multiple federal and state authorities. Thalorin provides unified compliance infrastructure for banking institutions, addressing OCC, FFIEC, Federal Reserve, and FDIC requirements through a single platform that reduces regulatory burden.
The most consequential change in bank cybersecurity assessment recently was a removal, not an addition. The FFIEC sunset the Cybersecurity Assessment Tool on 31 August 2025, retiring the maturity model that a generation of examiners and institutions had organised around. The agencies pointed to NIST CSF 2.0, the Cyber Risk Institute Profile, and the CIS Critical Security Controls as available alternatives, and pointedly endorsed none of them.
That leaves institutions choosing their own assessment framework while examiners still expect a coherent, defensible cyber risk posture. The CRI Profile has drawn the most adoption in banking because it is built on NIST CSF and maps to the specific regulatory expectations financial institutions already carry, which makes examiner conversations shorter.
Meanwhile the reporting clock is unforgiving. Under the computer-security incident notification rule, a banking organisation must notify its primary federal regulator within 36 hours of determining that a notification incident has occurred — a window that assumes you can distinguish a notification incident from ordinary noise quickly, which is an evidence problem before it is a legal one.
Third-party risk is the other persistent examination theme, governed by the 2023 Interagency Guidance on Third-Party Relationships. Thalorin holds the control state once and projects it into whichever assessment framework an institution has adopted, so a change of framework becomes a change of view rather than a fresh assessment programme.
Financial institutions operate under intense scrutiny
The CAT is gone and nothing replaced it
With the Cybersecurity Assessment Tool retired on 31 August 2025 and no successor endorsed, institutions must select a framework, justify the selection, and carry the mapping burden themselves.
A 36-hour notification clock
Notification to the primary federal regulator is required within 36 hours of determining a notification incident occurred. Making that determination confidently is what the window actually tests.
Multiple prudential regulators, one posture
OCC, Federal Reserve, FDIC, and state authorities examine overlapping ground with differing emphasis. Maintaining separate evidence per examiner multiplies work without improving the posture.
Third-party and fourth-party concentration
The 2023 interagency guidance raised expectations for the full lifecycle of third-party relationships, and examiners increasingly ask about concentration risk in critical service providers your vendors depend on.
How Thalorin helps
CRI Profile and NIST CSF 2.0 assessment
Assess against NIST CSF 2.0, the CRI Profile, or CIS Controls following the CAT sunset, holding one control state rather than re-assessing per framework.
OCC heightened standards
Track OCC heightened standards obligations for institutions in scope, with evidence bound to the controls they test.
Federal Reserve SR letter tracking
Carry Federal Reserve SR letter applicability and the supervisory findings that reference them.
FDIC examination preparation
Prepare FDIC examination artifacts from live control state rather than assembling them per examination cycle.
BSA/AML compliance integration
Integrate BSA/AML control evidence so financial crime and cybersecurity obligations share the artifacts they have in common.
Third-party risk management
Manage third-party risk against the 2023 interagency guidance lifecycle, including concentration in critical providers.
Banking: common questions
What replaced the FFIEC Cybersecurity Assessment Tool?
Formally, nothing. The FFIEC sunset the CAT on 31 August 2025 and identified NIST CSF 2.0, the Cyber Risk Institute Profile, and the CIS Critical Security Controls as resources institutions may leverage, without endorsing any as the preferred tool. In practice the CRI Profile has seen the strongest banking adoption because it is financial-sector specific and built on NIST CSF.
How quickly must a bank report a cyber incident?
Within 36 hours of determining that a notification incident has occurred, to the institution's primary federal regulator. The difficulty is rarely the notification itself — it is having enough signal to make the determination defensibly and early, which depends on detection and evidence capability rather than on legal process.
Do we have to adopt a specific framework now?
No, and that is the difficulty. Examiners expect a coherent, risk-based cybersecurity posture and will ask how you assess it, but no agency has mandated a particular successor to the CAT. The practical requirement is to choose deliberately, document why, and be able to show the assessment is genuinely performed rather than asserted.
How does GLBA relate to these requirements?
The Gramm-Leach-Bliley Act's Safeguards framework requires a written information security programme protecting customer information, and it sits underneath the prudential expectations rather than beside them. Most controls that satisfy a NIST CSF or CRI Profile assessment also serve GLBA obligations, which is why holding one control state and projecting it is more efficient than running parallel programmes.
What changed in third-party risk expectations?
The 2023 Interagency Guidance on Third-Party Relationships replaced separate agency guidance with a common lifecycle framing — planning, due diligence, contract negotiation, ongoing monitoring, and termination — applied proportionately to risk. Examiners now probe ongoing monitoring and concentration risk considerably harder than the older guidance prompted.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Banking.
See how one evidence artifact satisfies Banking requirements alongside every other framework you carry.