Skip to content

Evidence request lists

FFIEC Cybersecurity Assessment Tool (CAT)

Evidence request list. 49 controls, 49 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Cybersecurity Maturity - Cyber Incident Management and Resilience

FFIEC-CAT-CRI-1
Migration Path to CRI Profile

FFIEC announced CAT will sunset on 31 August 2025 with institutions transitioning to the CRI Profile v2.1 mapped to NIST CSF 2.0.

Artefacts an auditor will ask for
  • CAT to CRI Profile mapping workbook
  • Sunset transition project plan
  • Gap analysis against CRI diagnostic statements
  • Board update on transition
Where this commonly fails
  • No board awareness of CAT sunset
  • Mapping treats CRI as identical scoring
FFIEC-CAT-IM-1
Incident Management - Incident Resilience Planning and Strategy

Incident response plan, playbooks, and resilience strategy aligned to scenarios.

Artefacts an auditor will ask for
  • IR plan latest revision
  • Scenario playbooks ransomware, DDoS, wire fraud
  • BIA outputs
  • Crisis communications plan
Where this commonly fails
  • Plan not socialised to business
  • Wire fraud playbook missing
FFIEC-CAT-IM-2
Incident Management - Detection, Response, and Mitigation

Detection, triage, containment, and eradication procedures with defined RTOs and RPOs.

Artefacts an auditor will ask for
  • IR ticketing export sample
  • MTTD and MTTR metrics
  • Containment evidence per incident class
  • Post-incident review template
Where this commonly fails
  • MTTD measured only for SIEM-detected
  • Containment improvisation not captured
FFIEC-CAT-IM-3
Incident Management - Escalation and Reporting

Internal and external escalation including 36 hour computer security incident notification rule and customer notification.

Artefacts an auditor will ask for
  • 36 hour notification SOP
  • Primary federal regulator contact card
  • Sample notification template
  • Customer notification template
Where this commonly fails
  • 36 hour rule not tested in tabletop
  • Sub-servicer breach trigger unclear

Cybersecurity Maturity - Cyber Risk Management and Oversight

FFIEC-CAT-CRMO-1
Cyber Risk Management and Oversight - Governance

Board and senior management oversight of cybersecurity strategy, with documented roles, accountability, and reporting cadence.

Artefacts an auditor will ask for
  • Cyber governance charter
  • Board meeting minutes referencing cyber
  • CISO reporting line org chart
  • Cyber strategy approved document
Where this commonly fails
  • Board cyber expertise undocumented
  • Strategy not refreshed against threat changes
FFIEC-CAT-CRMO-2
Risk Management Program

Integrated cyber risk management program with risk appetite, risk assessments, and exception handling tied to ERM.

Artefacts an auditor will ask for
  • Cyber risk register with treatment plans
  • Risk appetite document
  • Risk acceptance log
  • Annual cyber risk assessment
Where this commonly fails
  • Risk appetite not quantitative
  • Risk register not linked to controls
FFIEC-CAT-CRMO-3
Resources and Training

Budget, staffing, and training to sustain cyber capabilities including role-based training for privileged users.

Artefacts an auditor will ask for
  • Cyber budget allocation by program
  • Role-based training matrix
  • Completion rates report
  • Phishing simulation results
Where this commonly fails
  • Privileged role training conflated with general awareness
  • Vendor staff excluded from awareness metrics
FFIEC-CAT-CRMO-4
Culture and Accountability

Embed cyber accountability across business lines with incentives, disciplinary measures, and culture surveys.

Artefacts an auditor will ask for
  • Cyber accountability policy
  • Performance review templates referencing cyber
  • Culture survey results
  • Disciplinary action log redacted
Where this commonly fails
  • Business line ownership of risks unclear
  • Survey only IT staff

Cybersecurity Maturity - Cybersecurity Controls

FFIEC-CAT-CC-1
Cybersecurity Controls - Preventive Controls Infrastructure Management

Network segmentation, secure configuration baselines, and change management to prevent compromise.

Artefacts an auditor will ask for
  • Hardening standards by platform
  • Configuration drift report
  • Segmentation review
  • Change management metrics
Where this commonly fails
  • Cloud baselines absent
  • OT and IT segmentation not enforced
FFIEC-CAT-CC-2
Cybersecurity Controls - Access and Data Management

Least privilege, MFA, identity governance, and data loss prevention across critical systems.

Artefacts an auditor will ask for
  • MFA enrollment report
  • Privileged access review
  • DLP policy and incident log
  • Joiner mover leaver evidence
Where this commonly fails
  • MFA gaps on legacy apps
  • DLP egress monitoring rules stale
FFIEC-CAT-CC-3
Cybersecurity Controls - Detective Controls

Logging, monitoring, anomaly detection, and EDR with documented coverage and tuning.

Artefacts an auditor will ask for
  • Log source inventory
  • Detection coverage matrix
  • EDR deployment report
  • Tuning change log
Where this commonly fails
  • Servers and containers underlogged
  • EDR exclusions undocumented
FFIEC-CAT-CC-4
Cybersecurity Controls - Corrective Controls Patch Management

Timely vulnerability remediation, patch management, and end-of-life replacement.

Artefacts an auditor will ask for
  • Vulnerability scan reports
  • Patch compliance dashboard
  • EOL inventory and replacement plan
  • Exception register
Where this commonly fails
  • KEV catalogue not prioritised
  • EOL systems carry-forward without compensating controls

Cybersecurity Maturity - External Dependency Management

FFIEC-CAT-EDM-1
External Dependency Management - Connections

Inventory and risk-rate all external connections including third party access and APIs.

Artefacts an auditor will ask for
  • External connection diagram
  • API register with auth model
  • Connection risk ratings
  • Decommission log
Where this commonly fails
  • API to fintech partners undocumented
  • VPN tunnels orphaned
FFIEC-CAT-EDM-2
External Dependency Management - Relationship Management

Due diligence, contracts, and ongoing monitoring of third parties with cyber requirements.

Artefacts an auditor will ask for
  • TPRM policy and tiering
  • Sample due diligence package
  • SOC 2 review log
  • Contract clauses for cyber, breach notification, audit
Where this commonly fails
  • Fourth parties not assessed
  • Breach notice SLAs missing in legacy contracts

Cybersecurity Maturity - Threat Intelligence

FFIEC-CAT-TI-1
Threat Intelligence - Intelligence and Information

Subscribe to and act on cyber threat intelligence from FS-ISAC, CISA, vendors, and peers with documented triage.

Artefacts an auditor will ask for
  • FS-ISAC membership confirmation
  • Threat intel platform export
  • Triage SOP
  • Indicator pushdown to SIEM evidence
Where this commonly fails
  • Intel consumed but not actioned
  • No measurement of mean time to deploy IOCs
FFIEC-CAT-TI-2
Threat Intelligence - Monitoring and Analyzing

Continuous monitoring, correlation, and analysis of threat data against institutional context.

Artefacts an auditor will ask for
  • SIEM use case catalogue
  • Threat hunting reports
  • Detection coverage map
  • Analyst playbooks
Where this commonly fails
  • Coverage gaps against ATT&CK not measured
  • Hunt program ad hoc
FFIEC-CAT-TI-3
Threat Intelligence - Information Sharing

Share threat indicators and incident learnings with sector partners and law enforcement.

Artefacts an auditor will ask for
  • Information sharing agreements
  • TLP marking policy
  • Submitted IOC log
  • FBI and Secret Service contact register
Where this commonly fails
  • TLP mishandled on outbound
  • No metrics on contributions

Domain 1: Cyber Risk Management and Oversight

CAT-D1-1
Governance

Board and senior management oversight of institution-wide cybersecurity strategy and direction

Artefacts an auditor will ask for
  • board charter
  • board cyber briefing pack
  • cyber risk committee minutes
  • governance policy
Where this commonly fails
  • board cyber expertise gap
  • infrequent reporting
  • no defined cadence
  • tone from top weak
CAT-D1-2
Risk management

Robustness of the cybersecurity risk management program and integration with enterprise risk management

Artefacts an auditor will ask for
  • risk management framework
  • risk register
  • risk appetite statement
  • treatment plans
Where this commonly fails
  • risk appetite undefined
  • register stale
  • treatment plans absent
  • no risk acceptance documentation
CAT-D1-3
Resources

Staffing, budgeting, and allocation of resources for information security and cybersecurity

Artefacts an auditor will ask for
  • security budget
  • headcount plan
  • tooling inventory
  • skills assessment
Where this commonly fails
  • chronic under investment
  • skills gaps
  • no capacity plan
  • tool sprawl
CAT-D1-4
Training and culture

Annual information security training, cybersecurity awareness programs, and security culture development

Artefacts an auditor will ask for
  • training plan
  • completion records
  • culture survey results
  • phishing test data
Where this commonly fails
  • below 100 percent completion
  • no role based content
  • culture metric absent
  • phishing remediation slow

Domain 2: Threat Intelligence and Collaboration

CAT-D2-1
Threat intelligence

Processes for uncovering, acquiring, and analyzing cybersecurity threat information

Artefacts an auditor will ask for
  • threat intel programme charter
  • feed inventory
  • intel briefs
  • FS-ISAC membership
Where this commonly fails
  • no formal programme
  • free feeds only
  • no actioning of intel
  • low FS-ISAC engagement
CAT-D2-2
Monitoring and analyzing

Monitoring threat intelligence sources and analyzing threat data for relevance to the institution

Artefacts an auditor will ask for
  • SIEM use cases
  • monitoring SOP
  • incident metrics
  • analyst playbooks
Where this commonly fails
  • use case coverage low
  • alert tuning weak
  • no 24x7 monitoring
  • playbooks outdated
CAT-D2-3
Information sharing

Sharing cybersecurity threat findings with stakeholders, peers, and information sharing organizations

Artefacts an auditor will ask for
  • FS-ISAC membership
  • intel sharing log
  • MOUs
  • industry forum participation
Where this commonly fails
  • one way consumption only
  • no anonymised sharing
  • MOUs absent
  • engagement low

Domain 3: Cybersecurity Controls

CAT-D3-1
Preventative controls

Maturity of preventative controls including access management, device security, and network security

Artefacts an auditor will ask for
  • firewall rules baseline
  • EDR deployment report
  • patching SLAs
  • secure config baselines
Where this commonly fails
  • patching SLA breaches
  • EDR coverage gaps
  • firewall rule sprawl
  • no baseline drift detection
CAT-D3-2
Detective controls

Maturity of detective controls including logging, monitoring, and anomaly detection capabilities

Artefacts an auditor will ask for
  • detection use cases
  • anomaly detection config
  • SOC dashboards
  • detection coverage map
Where this commonly fails
  • detection coverage gaps
  • weak anomaly tuning
  • no MITRE ATTACK mapping
  • logs siloed
CAT-D3-3
Corrective controls

Maturity of corrective controls including patch management, vulnerability remediation, and configuration management

Artefacts an auditor will ask for
  • containment playbooks
  • patch remediation tracker
  • IR runbooks
  • lessons learned reports
Where this commonly fails
  • remediation backlog
  • no automated containment
  • weak post incident review
  • lessons not implemented

Domain 4: External Dependency Management

CAT-D4-1
Connections

Managing and securing external connections that have access to enterprise information and technology assets

Artefacts an auditor will ask for
  • connection inventory
  • DMZ architecture
  • B2B gateway config
  • review of external connections
Where this commonly fails
  • connection inventory stale
  • unsanctioned connections
  • weak segmentation
  • no annual review
CAT-D4-2
Relationship management

Programs overseeing and managing third-party relationships including due diligence and ongoing monitoring

Artefacts an auditor will ask for
  • vendor inventory
  • lifecycle SOP
  • performance reviews
  • exit plans
Where this commonly fails
  • weak ongoing monitoring
  • no exit plans
  • concentration risk unmanaged
  • no performance reviews
CAT-D4-3
Third-party access controls

Controls governing third-party access to institutional systems and data

Artefacts an auditor will ask for
  • third party access policy
  • access requests log
  • JIT access tooling
  • session recording
Where this commonly fails
  • standing third party access
  • no session recording
  • no privilege separation
  • weak deprovisioning

Domain 5: Cyber Incident Management and Resilience

CAT-D5-1
Incident planning and strategy

Incident response planning including roles, responsibilities, communication plans, and escalation procedures

Artefacts an auditor will ask for
  • incident response plan
  • communications plan
  • stakeholder matrix
  • regulator contact list
Where this commonly fails
  • IR plan stale
  • no executive crisis plan
  • communications plan absent
  • tabletops infrequent
CAT-D5-2
Detection, response, and mitigation

Capabilities for detecting, responding to, and mitigating cyber incidents in a timely manner

Artefacts an auditor will ask for
  • detection coverage map
  • response runbooks
  • mitigation playbooks
  • tooling inventory
Where this commonly fails
  • MTTD high
  • MTTR high
  • playbooks untested
  • no automated response
CAT-D5-3
Escalation and reporting

Procedures for escalating cyber incidents to management and reporting to regulators and stakeholders

Artefacts an auditor will ask for
  • escalation matrix
  • regulator reporting SOP
  • executive briefing template
  • customer notification template
Where this commonly fails
  • unclear escalation thresholds
  • regulator reporting SLAs missed
  • no executive briefings
  • communications inconsistent
CAT-D5-4
Resilience planning and testing

Planning and testing to recover normal operations after a cybersecurity event including BCP and DR testing

Artefacts an auditor will ask for
  • BCP plan
  • DR test reports
  • resilience metrics
  • exercise scenarios
Where this commonly fails
  • BCP not tested
  • DR test scenarios narrow
  • resilience metrics absent
  • no scenario based exercises

Inherent Risk Profile

FFIEC-CAT-IRP-1
Inherent Risk Profile - Technologies and Connection Types

Catalogue technologies, connection types, and external service providers that drive inherent cyber risk to determine the institution's risk level (Least to Most).

Artefacts an auditor will ask for
  • IRP scoring workbook with technology counts
  • Network diagram showing external connections
  • Inventory of cloud services and SaaS
  • ISP and MPLS circuit list
  • Wireless access point register
Where this commonly fails
  • Shadow IT not captured
  • ISP redundancy unscored
  • Cloud connections undercounted
FFIEC-CAT-IRP-2
Inherent Risk Profile - Delivery Channels

Score inherent risk arising from online and mobile delivery channels including ATM operations and number of customers served.

Artefacts an auditor will ask for
  • Online banking user counts
  • Mobile banking enrollment report
  • ATM fleet inventory
  • Channel risk scoring sheet
Where this commonly fails
  • Mobile counts stale
  • ATM third-party operators excluded
FFIEC-CAT-IRP-3
Online or Mobile Products and Technology Services

Identify products and services offered through digital channels including wire transfers, P2P, merchant services, and trust services.

Artefacts an auditor will ask for
  • Product and service register
  • Wire transfer volume report
  • P2P transaction logs
  • Merchant card processing summary
Where this commonly fails
  • High-risk product overlap with risk appetite undocumented
  • Volumes not refreshed quarterly
FFIEC-CAT-IRP-4
Organizational Characteristics

Score risk from mergers, locations, employee counts, IT staff changes, and direct employee internet access.

Artefacts an auditor will ask for
  • Headcount trend
  • M&A timeline last 12 months
  • IT staff turnover report
  • Privileged user counts
Where this commonly fails
  • Contractor counts excluded
  • Post-merger integration risk unrated
FFIEC-CAT-IRP-5
External Threats

Quantify attempted attacks against the institution including phishing, DDoS, and reconnaissance traffic.

Artefacts an auditor will ask for
  • Phishing attempts blocked report
  • DDoS mitigation summary
  • Threat intel digest
  • Attempted intrusion log
Where this commonly fails
  • Phishing metrics aggregated only annually
  • Attempted versus successful conflated

Inherent Risk Profile: Risk Categories

CAT-IRP-1
Technologies and connection types

Evaluates risk from third-party connections, unsecured external links, wireless networks, and hosting arrangements

Artefacts an auditor will ask for
  • technology inventory
  • connection types register
  • risk profile worksheet
  • annual reassessment
Where this commonly fails
  • inventory stale
  • shadow IT
  • risk profile not reassessed
  • scoring inconsistent
CAT-IRP-2
Delivery channels

Assesses risk from websites, mobile applications, ATMs, and other customer-facing channels

Artefacts an auditor will ask for
  • channel inventory
  • transaction volume metrics
  • channel risk assessment
  • fraud metrics
Where this commonly fails
  • new channels not assessed
  • fraud metrics weak
  • channel inventory outdated
  • no concentration analysis
CAT-IRP-3
Online/mobile products and technology services

Reviews payment and transaction service security challenges from online and mobile offerings

Artefacts an auditor will ask for
  • product inventory
  • mobile app security testing
  • online service risk assessments
  • feature rollout review
Where this commonly fails
  • mobile app testing infrequent
  • new features unassessed
  • API security gaps
  • third party SDKs unreviewed
CAT-IRP-4
Organizational characteristics

Examines staffing, access privileges, data center locations, employee count, and organizational structure

Artefacts an auditor will ask for
  • org profile worksheet
  • M&A integration plans
  • geographic footprint analysis
  • headcount trends
Where this commonly fails
  • M&A risk not integrated
  • geo expansion unassessed
  • merger inheritance untracked
  • outsourcing concentration
CAT-IRP-5
External threats

Analyzes attack frequency, types of threats, and the threat landscape facing the institution

Artefacts an auditor will ask for
  • threat landscape briefings
  • attack surface assessments
  • intel reports
  • annual threat review
Where this commonly fails
  • threat landscape stale
  • attack surface unmapped
  • no sector specific intel
  • no annual review

Maturity Levels

CAT-ML-1
Baseline

Minimum set of cybersecurity practices expected for all institutions regardless of size or risk profile

Artefacts an auditor will ask for
  • baseline declaration
  • control assessment
  • gap analysis
  • remediation plan
Where this commonly fails
  • below baseline declared
  • gap analysis missing
  • no remediation plan
  • baseline definition weak
CAT-ML-2
Evolving

Maturing cybersecurity practices beyond baseline with additional controls and risk management capabilities

Artefacts an auditor will ask for
  • maturity assessment
  • evolving control evidence
  • improvement plan
  • executive approval
Where this commonly fails
  • overstated maturity
  • no evidence of evolving controls
  • improvement plan absent
  • no peer benchmarking
CAT-ML-3
Intermediate

Detailed and formally documented cybersecurity processes validated on a regular basis

Artefacts an auditor will ask for
  • maturity assessment
  • intermediate control evidence
  • metrics dashboard
  • executive review
Where this commonly fails
  • control depth lacking
  • metrics absent
  • no executive review
  • self attestation unreliable
CAT-ML-4
Advanced

Integrated cybersecurity practices, real-time monitoring, and advanced threat detection capabilities

Artefacts an auditor will ask for
  • automation evidence
  • advanced control runbooks
  • KPI dashboards
  • external assessment
Where this commonly fails
  • automation absent
  • advanced controls unverified
  • metrics not trended
  • no external assurance
CAT-ML-5
Innovative

Cutting-edge cybersecurity practices, active contribution to industry knowledge, and continuous innovation

Artefacts an auditor will ask for
  • innovation roadmap
  • leading practice attestations
  • industry collaboration
  • research outputs
Where this commonly fails
  • self assessed as innovative without evidence
  • no industry contribution
  • no R and D
  • claims unsubstantiated
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the FFIEC Cybersecurity Assessment Tool (CAT) framework page.