FFIEC
What is FFIEC?
The Federal Financial Institutions Examination Council that prescribes uniform principles, standards, and report forms for the federal examination of financial institutions. FFIEC guidance covers cybersecurity, IT, and operational risk.
Terms that appear alongside ffiec
Each of these is named in at least one of the same controls as ffiec. The number is how many controls name both.
- cybersecurity 9 shared controls
- resilience 8 shared controls
- operational resilience 8 shared controls
- governance 7 shared controls
- incident management 7 shared controls
- information security 7 shared controls
- incident response 5 shared controls
- nist 5 shared controls
Frameworks that govern ffiec
What the standards actually require on ffiec
Requirements naming ffiec across 6 standards, quoted from the control text.
The FSA expects financial institutions to implement a comprehensive cybersecurity risk management framework + aligned with NIST CSF 2.0 + FFIEC IT Examination Handbook + ISO/IEC 27001 ISMS + integrated into Enterprise Risk Management (ERM).
JP-FSA-CYB-Risk-Management-NIST-CSF-FFIEC-Aligned-Identify-Protect-Detect-Respond-Recover-Govern-Plan-Do-Check-Act · Japan FSA Cybersecurity Risk Management Framework + NIST CSF 2.0 Aligned + FFIEC Crosswalk + Identify Protect Detect Respond Recover Govern + ISO 27001 ISMS + Plan-Do-Check-Act + Inherent vs Residual Risk + Risk Appetite + Cyber Risk in ERM →HKMA C-RAF crosswalk to international + sectoral cybersecurity frameworks. (a) NIST CYBERSECURITY FRAMEWORK (CSF) 2.0 - the 6 CSF functions (Govern + Identify + Protect + Detect + Respond + Recover) map directly to C-RAF 7 domains;
HKMA-CRAF-Crosswalk-NIST-CSF-ISO27001-FFIEC-CBEST-TIBER · HKMA C-RAF Crosswalk to NIST CSF, ISO 27001, FFIEC CAT, CBEST, TIBER-EU and Sectoral Frameworks →Disaster recovery procedures. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Operational Resilience.
FFIEC-12 · Disaster recovery procedures →FFIEC announced CAT will sunset on 31 August 2025 with institutions transitioning to the CRI Profile v2.1 mapped to NIST CSF 2.0.
FFIEC-CAT-CRI-1 · Migration Path to CRI Profile →FTC Safeguards Rule coordination with parallel regulators. BANKING AGENCIES (Interagency Guidelines per 12 CFR Parts 30 + 208 + 225 + 364 + 748): OCC + FRB + FDIC + NCUA issue equivalent safeguards regulations for federally-supervised banks + savings associati...
FTC-Safeguards-Coord-Banking-SEC-Higher-Ed · Coordination with Banking Agencies, SEC, Higher Education Safeguards and Insurance →HKMA TM-G-1 coordination + 2024-2025 pipeline. COORDINATION WITH HKMA FRAMEWORKS: (a) HKMA SPM UMBRELLA (separately referenced) - TM-G-1 is one of 60+ SPM modules; SPM provides overall framework + supervisory expectations;
HKMA-TMG1-Coord-SPM-CRAF-Basel-FSB-2024-2025-Pipeline · TM-G-1 Coordination with HKMA SPM, C-RAF v2.0, Basel III, FSB, ISO 27001, NIST CSF and 2024-2025 Pipeline →Questions people ask about ffiec
What is FFIEC?
Why is FFIEC important for compliance?
Which compliance frameworks address FFIEC?
Where can I learn more about FFIEC?
See how FFIEC applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.