Skip to content
Capability/Financial Services

Banking

OCC, FFIEC, and prudential regulation compliance

01 / Overview

Banks operate under comprehensive regulatory oversight from multiple federal and state authorities. Thalorin provides unified compliance infrastructure for banking institutions, addressing OCC, FFIEC, Federal Reserve, and FDIC requirements through a single platform that reduces regulatory burden.

The most consequential change in bank cybersecurity assessment recently was a removal, not an addition. The FFIEC sunset the Cybersecurity Assessment Tool on 31 August 2025, retiring the maturity model that a generation of examiners and institutions had organised around. The agencies pointed to NIST CSF 2.0, the Cyber Risk Institute Profile, and the CIS Critical Security Controls as available alternatives, and pointedly endorsed none of them.

That leaves institutions choosing their own assessment framework while examiners still expect a coherent, defensible cyber risk posture. The CRI Profile has drawn the most adoption in banking because it is built on NIST CSF and maps to the specific regulatory expectations financial institutions already carry, which makes examiner conversations shorter.

Meanwhile the reporting clock is unforgiving. Under the computer-security incident notification rule, a banking organisation must notify its primary federal regulator within 36 hours of determining that a notification incident has occurred — a window that assumes you can distinguish a notification incident from ordinary noise quickly, which is an evidence problem before it is a legal one.

Third-party risk is the other persistent examination theme, governed by the 2023 Interagency Guidance on Third-Party Relationships. Thalorin holds the control state once and projects it into whichever assessment framework an institution has adopted, so a change of framework becomes a change of view rather than a fresh assessment programme.

02 / Challenges

Financial institutions operate under intense scrutiny

The CAT is gone and nothing replaced it

With the Cybersecurity Assessment Tool retired on 31 August 2025 and no successor endorsed, institutions must select a framework, justify the selection, and carry the mapping burden themselves.

A 36-hour notification clock

Notification to the primary federal regulator is required within 36 hours of determining a notification incident occurred. Making that determination confidently is what the window actually tests.

Multiple prudential regulators, one posture

OCC, Federal Reserve, FDIC, and state authorities examine overlapping ground with differing emphasis. Maintaining separate evidence per examiner multiplies work without improving the posture.

Third-party and fourth-party concentration

The 2023 interagency guidance raised expectations for the full lifecycle of third-party relationships, and examiners increasingly ask about concentration risk in critical service providers your vendors depend on.

03 / Capabilities

How Thalorin helps

FFIECOCCGLBA

CRI Profile and NIST CSF 2.0 assessment

Assess against NIST CSF 2.0, the CRI Profile, or CIS Controls following the CAT sunset, holding one control state rather than re-assessing per framework.

OCC heightened standards

Track OCC heightened standards obligations for institutions in scope, with evidence bound to the controls they test.

Federal Reserve SR letter tracking

Carry Federal Reserve SR letter applicability and the supervisory findings that reference them.

FDIC examination preparation

Prepare FDIC examination artifacts from live control state rather than assembling them per examination cycle.

BSA/AML compliance integration

Integrate BSA/AML control evidence so financial crime and cybersecurity obligations share the artifacts they have in common.

Third-party risk management

Manage third-party risk against the 2023 interagency guidance lifecycle, including concentration in critical providers.

Questions

Banking: common questions

What replaced the FFIEC Cybersecurity Assessment Tool?

Formally, nothing. The FFIEC sunset the CAT on 31 August 2025 and identified NIST CSF 2.0, the Cyber Risk Institute Profile, and the CIS Critical Security Controls as resources institutions may leverage, without endorsing any as the preferred tool. In practice the CRI Profile has seen the strongest banking adoption because it is financial-sector specific and built on NIST CSF.

How quickly must a bank report a cyber incident?

Within 36 hours of determining that a notification incident has occurred, to the institution's primary federal regulator. The difficulty is rarely the notification itself — it is having enough signal to make the determination defensibly and early, which depends on detection and evidence capability rather than on legal process.

Do we have to adopt a specific framework now?

No, and that is the difficulty. Examiners expect a coherent, risk-based cybersecurity posture and will ask how you assess it, but no agency has mandated a particular successor to the CAT. The practical requirement is to choose deliberately, document why, and be able to show the assessment is genuinely performed rather than asserted.

How does GLBA relate to these requirements?

The Gramm-Leach-Bliley Act's Safeguards framework requires a written information security programme protecting customer information, and it sits underneath the prudential expectations rather than beside them. Most controls that satisfy a NIST CSF or CRI Profile assessment also serve GLBA obligations, which is why holding one control state and projecting it is more efficient than running parallel programmes.

What changed in third-party risk expectations?

The 2023 Interagency Guidance on Third-Party Relationships replaced separate agency guidance with a common lifecycle framing — planning, due diligence, contract negotiation, ongoing monitoring, and termination — applied proportionately to risk. Examiners now probe ongoing monitoring and concentration risk considerably harder than the older guidance prompted.

Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.

05 / Get Started

Talk to us about Banking.

See how one evidence artifact satisfies Banking requirements alongside every other framework you carry.