Skip to content

FFIEC

What is FFIEC?

The Federal Financial Institutions Examination Council that prescribes uniform principles, standards, and report forms for the federal examination of financial institutions. FFIEC guidance covers cybersecurity, IT, and operational risk.

Compliance

Each of these is named in at least one of the same controls as ffiec. The number is how many controls name both.

What the standards actually require on ffiec

Requirements naming ffiec across 6 standards, quoted from the control text.

HKMA C-RAF crosswalk to international + sectoral cybersecurity frameworks. (a) NIST CYBERSECURITY FRAMEWORK (CSF) 2.0 - the 6 CSF functions (Govern + Identify + Protect + Detect + Respond + Recover) map directly to C-RAF 7 domains;

HKMA-CRAF-Crosswalk-NIST-CSF-ISO27001-FFIEC-CBEST-TIBER · HKMA C-RAF Crosswalk to NIST CSF, ISO 27001, FFIEC CAT, CBEST, TIBER-EU and Sectoral Frameworks

Disaster recovery procedures. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Operational Resilience.

FFIEC-12 · Disaster recovery procedures

FFIEC announced CAT will sunset on 31 August 2025 with institutions transitioning to the CRI Profile v2.1 mapped to NIST CSF 2.0.

FFIEC-CAT-CRI-1 · Migration Path to CRI Profile

FTC Safeguards Rule coordination with parallel regulators. BANKING AGENCIES (Interagency Guidelines per 12 CFR Parts 30 + 208 + 225 + 364 + 748): OCC + FRB + FDIC + NCUA issue equivalent safeguards regulations for federally-supervised banks + savings associati...

FTC-Safeguards-Coord-Banking-SEC-Higher-Ed · Coordination with Banking Agencies, SEC, Higher Education Safeguards and Insurance
HKMA TM-G-11 control

HKMA TM-G-1 coordination + 2024-2025 pipeline. COORDINATION WITH HKMA FRAMEWORKS: (a) HKMA SPM UMBRELLA (separately referenced) - TM-G-1 is one of 60+ SPM modules; SPM provides overall framework + supervisory expectations;

HKMA-TMG1-Coord-SPM-CRAF-Basel-FSB-2024-2025-Pipeline · TM-G-1 Coordination with HKMA SPM, C-RAF v2.0, Basel III, FSB, ISO 27001, NIST CSF and 2024-2025 Pipeline

Questions people ask about ffiec

What is FFIEC?
The Federal Financial Institutions Examination Council that prescribes uniform principles, standards, and report forms for the federal examination of financial institutions. FFIEC guidance covers cybersecurity, IT, and operational risk.
Why is FFIEC important for compliance?
FFIEC is a key concept in Compliance. Understanding ffiec helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address FFIEC?
FFIEC appears in the requirement text of Japan FSA Cybersecurity Guidelines for Financial Institutions, HKMA Cyber Resilience Assessment Framework (C-RAF), FFIEC IT Examination Handbook, FFIEC Cybersecurity Assessment Tool (CAT), FTC GLBA Safeguards Rule (16 CFR Part 314). Across these standards we have identified 34 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about FFIEC?
Explore our compliance framework pages to see how ffiec applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how FFIEC applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.