The operational-resilience, BCDR, and crisis-handling obligations that most likely apply to large banks — by regulator, domain, and compliance status. Filter and search the full set below.
bank_large · 269 likely-applicable · 0 excluded by asset sizeHow this persona’s 269 applicable obligations distribute across cross-cutting themes. For the full lens (what each requires), run python3 -m regwatch.theme <theme> --persona bank_large.
| Theme | Obligations | of which proposed |
|---|---|---|
| Third-Party / Vendor Risk Management | 94 | 24 |
| Cybersecurity × Resilience | 95 | 15 |
| Incident Reporting & Notification | 117 | 10 |
| Resilience Testing & Exercises | 48 | 3 |
| ID | Country | Regulator | Domain | Size trigger | Obligation (with source quote) | Citation | Status | Suggested evidence to comply |
|---|---|---|---|---|---|---|---|---|
OBL-00731 | United States | FRB | business continuity | Establish a board-approved robust operational risk management framework that identifies and mitigates plausible sources of operational risk, ensures high security and reliability, and provides for rapid recovery of critical operations. “manage its operational risks by establishing a robust operational risk-management framework that is approved by its board of directors” | 12 CFR 234.3(a)(17) | final | Board-approved written operational risk management framework; documented risk-tolerance policy; evidence of board approval and periodic review. | |
OBL-00732 | United States | FRB | business continuity | Maintain a business continuity plan incorporating a secondary site with a distinct risk profile from the primary site. “business continuity plan that (1) incorporates the use of a secondary site at a location with a distinct risk profile from the primary site” | 12 CFR 234.3(a)(17)(vii) | final | Written BCP with documented secondary site; site risk profile analysis showing distinct risk profile; evidence of operational readiness of secondary site. | |
OBL-00733 | United States | FRB | business continuity | Maintain a BCP designed to enable critical systems to recover and resume operations no later than two hours following disruptive events. “is designed to enable critical systems to recover and resume operations no later than two hours following disruptive events” | 12 CFR 234.3(a)(17)(vii) | final | BCP with documented 2-hour RTO for critical systems; test results demonstrating achievement of 2-hour recovery target. | |
OBL-00734 | United States | FRB | business continuity | Maintain a BCP designed to enable completion of settlement by the end of the day of disruption, even in extreme circumstances. “is designed to enable it to complete settlement by the end of the day of the disruption, even in case of extreme circumstances” | 12 CFR 234.3(a)(17)(vii) | final | BCP with same-day settlement completion objective; scenario test results including extreme disruption scenarios confirming end-of-day settlement capability. | |
OBL-00735 | United States | FRB | business continuity | Test the business continuity plan at least annually. “is tested at least annually” | 12 CFR 234.3(a)(17)(vii) | final | Annual BCP test records including date, scope, participants, results, and identified gaps; evidence of participant involvement in testing. | |
OBL-00736 | United States | FRB | business continuity | Conduct tests of systems, policies, procedures, and controls in accordance with a documented testing framework that addresses at minimum scope, frequency, participation, interdependencies, and reporting. “conduct tests of its systems, policies, procedures, and controls in accordance with a documented testing framework” | 12 CFR 234.3(a)(17)(i)(A)(1) | final | Written testing framework document covering scope, frequency, participation, interdependencies, and reporting; test logs and results. | |
OBL-00737 | United States | FRB | business continuity | Ensure testing assesses whether systems, policies, procedures, or controls function as intended. “a designated FMU's testing assess whether its systems, policies, procedures, or controls function as intended” | 12 CFR 234.3(a)(17)(i)(A)(2) | final | Test plans with defined expected outcomes; test results comparing actual vs. intended performance; remediation records for gaps. | |
OBL-00738 | United States | FRB | business continuity | Conduct review of design, implementation, and testing of affected and similar systems, policies, procedures, and controls after any material operational incident. “conduct a review of the design, implementation, and testing of systems, policies, procedures, and controls after the designated FMU experienced any material operational incidents” | 12 CFR 234.3(a)(17)(i)(B) | final | Post-incident review reports documenting affected and similar systems reviewed; findings and remediation actions; governance sign-off. | |
OBL-00739 | United States | FRB | business continuity | Conduct review of affected and similar systems, policies, procedures, and controls when a change to the operating environment could significantly affect plausible sources or mitigants of operational risk. “review the design, implementation, and testing of systems, policies, procedures, and controls after significant changes to the environment in which it operates” | 12 CFR 234.3(a)(17)(i)(B) | final | Change management records identifying operational risk impact; post-change review reports; governance approval documentation. | |
OBL-00740 | United States | FRB | business continuity | Remediate deficiencies identified during tests and reviews as soon as possible, following established governance processes, including risk analysis, prioritization, and validation. “remediate, as soon as possible and following established governance processes, any deficiencies identified during tests and reviews” | 12 CFR 234.3(a)(17)(i)(C) | final | Deficiency tracking log; governance-approved remediation plans with target dates; evidence of completion or documented risk acceptance; validation records. | |
OBL-00741 | United States | FRB | business continuity | Establish a documented framework for incident management providing for prompt detection, analysis, and escalation of incidents; appropriate response procedures; and incorporation of lessons learned. “establish a documented framework for incident management that provides for the prompt detection, analysis, and escalation of an incident; appropriate procedures for addressing an incident; and incorporation of lessons learned following an incident” | 12 CFR 234.3(a)(17)(vi) | final | Written incident management framework document; evidence of lessons-learned reviews; escalation procedures; after-action reports. | |
OBL-00742 | United States | FRB | business continuity | Include within the incident management framework a plan for notification and communication of material operational incidents identifying entities to be notified, including non-participants that could be affected. “include a plan for notification and communication of material operational incidents. This plan, among other things, would need to identify the entities that would be notified of operational incidents, including non-participants” | 12 CFR 234.3(a)(17)(vi) | final | Written notification and communication plan listing all entity types to be notified; contact lists including non-participants and industry fora. | |
OBL-00743 | United States | FRB | business continuity | Immediately notify the Board when the designated FMU activates its business continuity plan or has a reasonable basis to conclude there is an actual or likely disruption or material degradation to critical operations, services, or ability to fulfill obligations on time. “notify the Board immediately when it activated its business continuity plan or had a reasonable basis to conclude that (1) there was an actual or likely disruption, or material degradation, to any of its critical operations or services” | 12 CFR 234.3(a)(17)(vi)(A)(1) | final | Incident notification log with timestamps; Board notification records; documented notification process aligned with Board-established process. | |
OBL-00744 | United States | FRB | business continuity | Immediately notify the Board when the designated FMU has a reasonable basis to conclude there is an unauthorized entry, or a vulnerability that could allow unauthorized entry, into its computer/network/electronic systems that affects or could affect critical operations or services. “unauthorized entry or a vulnerability that could allow unauthorized entry, into the designated FMU's computer, network, electronic, technical, automated, or similar systems that affects or has the potential to affect its critical operations or services” | 12 CFR 234.3(a)(17)(vi)(A)(2) | final | Cyber incident and vulnerability log; Board notification records with timestamps; evidence of reasonable-basis assessment criteria. | |
OBL-00745 | United States | FRB | business continuity | Notify the Board of incidents in accordance with the process established by the Board. [adjacent] “a designated FMU must notify the Board of incidents 'in accordance with the process established by the Board'” | 12 CFR 234.3(a)(17)(vi)(A) | final | Written notification procedure referencing Board-established process; evidence of communication with Board supervisory team to confirm contact details and methods. | |
OBL-00746 | United States | FRB | business continuity | Establish criteria and processes for timely communication and responsible disclosure of material operational incidents to participants or other relevant entities, including appropriate communication methods. “establish criteria and processes, including the appropriate methods of communication, to provide for timely communication and responsible disclosure of material operational incidents to its participants or other relevant entities” | 12 CFR 234.3(a)(17)(vi)(B) | final | Documented disclosure criteria; communication procedures; contact lists; sample notifications; records of participant communications during past incidents. | |
OBL-00747 | United States | FRB | business continuity | Immediately notify affected participants in the event of actual disruptions or material degradation to critical operations or services or to the ability to fulfill obligations on time. “notify affected participants immediately in the event of actual disruptions or material degradation to its critical operations or services or to its ability to fulfill its obligations on time” | 12 CFR 234.3(a)(17)(vi)(B)(1) | final | Participant notification logs with timestamps; incident records; evidence of identification of affected participants and immediate outreach. | |
OBL-00748 | United States | FRB | business continuity | Notify all participants and other relevant entities in a timely and responsible manner of all other material operational incidents that require immediate Board notification. “notify all participants and other relevant entities in a timely and responsible manner of all other material operational incidents that require immediate notification to the Board” | 12 CFR 234.3(a)(17)(vi)(B)(2) | final | All-participant notification records; disclosure timing log; documented responsible disclosure criteria; evidence of notifications to non-participant relevant entities. | |
OBL-00749 | United States | FRB | business continuity | Identify and mitigate plausible sources of operational risk (internal and external) through appropriate systems, policies, procedures, and controls that are reviewed, audited, and tested periodically and after major changes. “identify the plausible sources of operational risk, both internal and external, and mitigate their impact through the use of appropriate systems, policies, procedures, and controls that are reviewed, audited, and tested periodically and after major changes” | 12 CFR 234.3(a)(17)(i) | final | Operational risk register; audit reports; testing records; change management logs triggering post-change reviews. | |
OBL-00750 | United States | FRB | business continuity | Identify, monitor, and manage operational risks the designated FMU may pose to other FMUs and trade repositories. [adjacent] “identify, monitor, and manage the operational risks it may pose to other FMUs and trade repositories” | 12 CFR 234.3(a)(17) | final | Interdependency risk assessments; monitoring procedures for risks transmitted to connected FMUs and trade repositories; documented escalation procedures. | |
OBL-00751 | United States | FRB | business continuity | Ensure adequate, scalable capacity to handle increasing stress volumes. “have adequate, scalable capacity to handle increasing stress volumes” | 12 CFR 234.3(a)(17) | final | Capacity planning documentation; stress/volume test results; capacity monitoring reports; evidence of scalability mechanisms. | |
OBL-00752 | United States | FRB | business continuity | Address potential and evolving vulnerabilities and threats to operational risk, including supply chain and ransomware threats, through systems, policies, procedures, and controls. “address potential and evolving vulnerabilities and threats” | 12 CFR 234.3(a)(17) | final | Threat intelligence program documentation; vulnerability management policy; evidence of supply chain and ransomware scenario planning; updated risk assessments. | |
OBL-00885 | European Union | EU_ESA | business continuity | Establish and maintain a sound, comprehensive and well-documented ICT risk management framework as part of the overall risk management system. “Financial entities shall have in place a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system” | Art. 6(1) Regulation (EU) 2022/2554 | final | Board-approved ICT risk management framework document; annual review records; integration evidence within overall risk management system | |
OBL-00886 | European Union | EU_ESA | business continuity | Identify, classify and document all ICT-supported business functions, roles, dependencies, assets and information assets critical to operations. “Financial entities shall identify, classify and adequately document all ICT supported business functions, roles and responsibilities, the information assets and ICT assets supporting those functions” | Art. 8(1) Regulation (EU) 2022/2554 | final | Asset inventory and classification register; mapping of ICT assets to critical business functions; documented dependencies | |
OBL-00887 | European Union | EU_ESA | business continuity | Continuously monitor and manage all sources of ICT risk, including risks posed by third-party ICT service providers, and implement protection and prevention measures. “Financial entities shall continuously monitor and control the security and functioning of ICT systems and tools and shall minimise the impact of ICT risk” | Art. 9(1)-(2) Regulation (EU) 2022/2554 | final | Continuous monitoring logs; vulnerability management records; evidence of preventive controls; third-party risk monitoring reports | |
OBL-00888 | European Union | EU_ESA | business continuity | Implement ICT business continuity policy and plans to ensure continuity of critical or important functions through ICT disruptions. “As part of the ICT risk management framework referred to in Article 6(1), financial entities shall put in place a comprehensive ICT business continuity policy” | Art. 11(1) Regulation (EU) 2022/2554 | final | Board-approved ICT BCP document; list of critical functions covered; activation criteria; defined RTO/RPO; annual review records | |
OBL-00891 | European Union | EU_ESA | business continuity | Develop and implement crisis communication plans to ensure effective communication to staff, stakeholders and public during ICT-related crises. “Financial entities shall have in place crisis communication plans enabling a responsible disclosure of, at least, major ICT-related incidents or vulnerabilities to clients, counterparts and the public” | Art. 14(1) Regulation (EU) 2022/2554 | final | Documented crisis communication plan; defined roles and spokespersons; internal/external notification templates; activation records | |
OBL-00892 | European Union | EU_ESA | business continuity | Designate a crisis communication manager responsible for managing communications during ICT-related incidents. “Financial entities shall designate a person responsible for implementing the communication strategy for ICT-related incidents and fulfil the public and media function for that purpose” | Art. 14(2) Regulation (EU) 2022/2554 | final | Named crisis communication manager; role description; evidence of appointment; escalation pathway documentation | |
OBL-00893 | European Union | EU_ESA | business continuity | Establish and maintain an ICT-related incident management process to detect, manage and notify major ICT-related incidents, including classification criteria. “Financial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents” | Art. 17(1) Regulation (EU) 2022/2554 | final | Incident management process documentation; classification criteria; incident log; escalation procedures; evidence of regular review | |
OBL-00894 | European Union | EU_ESA | business continuity | Classify ICT incidents and cyber threats using prescribed criteria (clients affected, duration, data loss, criticality, economic impact) and report major incidents to competent authorities. “Financial entities shall classify ICT-related incidents and shall determine their impact based on the following criteria: the number of clients, counterparts or financial transactions affected” | Art. 18(1) Regulation (EU) 2022/2554 | final | Classification methodology aligned to RTS criteria; incident registers with classification evidence; major incident reports submitted to authorities | |
OBL-00895 | European Union | EU_ESA | business continuity | Submit initial, intermediate and final reports on major ICT-related incidents to the relevant competent authority within prescribed timeframes. “Financial entities shall submit: an initial notification; an intermediate report after the initial notification, as soon as the status of the original incident has changed significantly; a final report” | Art. 19(3) Regulation (EU) 2022/2554 | final | Templates for initial/intermediate/final reports; submission records with timestamps; evidence of authority acknowledgement | |
OBL-00896 | European Union | EU_ESA | business continuity | Perform a basic digital operational resilience testing programme annually, covering ICT tools, systems and processes supporting critical or important functions. “Financial entities shall establish, maintain and review a sound and comprehensive digital operational resilience testing programme as an integral part of the ICT risk management framework” | Art. 25(1) Regulation (EU) 2022/2554 | final | Annual resilience testing plan and results; coverage of critical/important functions; gap remediation records; sign-off by management | |
OBL-00897 | European Union | EU_ESA | business continuity | Conduct threat-led penetration testing (TLPT) at least every three years on critical or important live production systems. “Financial entities shall carry out at least every 3 years advanced testing by means of TLPT. Based on the risk profile of the financial entity and taking into account operational circumstances” | Art. 26(1) Regulation (EU) 2022/2554 | final | TLPT scope documentation; testers' credentials (TIBER or equivalent); test results and remediation plans; authority notification records | |
OBL-00898 | European Union | EU_ESA | business continuity | Adopt a strategy on ICT third-party risk, including a policy for use of ICT services supporting critical or important functions, and review it annually. “As part of their ICT risk management framework, financial entities shall adopt and regularly review a strategy on ICT third-party risk, taking into account the multi-vendor strategy” | Art. 28(1) Regulation (EU) 2022/2554 | final | Board-approved third-party ICT risk strategy; annual review records; multi-vendor strategy documentation; concentration risk assessment | |
OBL-00899 | European Union | EU_ESA | business continuity | Before entering into ICT third-party arrangements for critical or important functions, assess concentration risk and risks of ICT service provider failure or unavailability. “Prior to entering into a contractual arrangement on the use of ICT services, financial entities shall: identify and assess all relevant risks in relation to the ICT third-party service provider” | Art. 28(4) Regulation (EU) 2022/2554 | final | Pre-contract due diligence reports; concentration risk analysis; risk registers; sign-off documentation before contract execution | |
OBL-00900 | European Union | EU_ESA | business continuity | Maintain and update a register of all contractual arrangements with ICT third-party service providers and report it to competent authorities upon request. “Financial entities shall maintain and update at entity level, at sub-consolidated and at consolidated level, a register of information in relation to all contractual arrangements on the use of ICT services” | Art. 28(3) Regulation (EU) 2022/2554 | final | Centralised ICT third-party contract register; evidence of regular updates; submission records to competent authority | |
OBL-00901 | European Union | EU_ESA | business continuity | Ensure contractual arrangements with ICT third-party providers for critical/important functions include mandatory clauses on business continuity, availability, recovery and exit strategies. “Contractual arrangements on the use of ICT services shall include at minimum: the description of full service levels including updates and revisions thereof; the obligations of the ICT third-party service provider to provide assistance at no additional cost” | Art. 30(2) Regulation (EU) 2022/2554 | final | Contract clauses checklist aligned to Art. 30 requirements; contract review records; evidence of remediated legacy contracts | |
OBL-00902 | European Union | EU_ESA | business continuity | Establish exit strategies for ICT third-party arrangements on critical or important functions to ensure continuity if a provider fails or is discontinued. “Financial entities shall, taking into account the specificities of the ICT services to be provided, have exit strategies in order to be able to terminate, without detriment to their regulated activities, the relevant contractual arrangements” | Art. 28(8) Regulation (EU) 2022/2554 | final | Documented exit strategies per critical provider; portability assessments; alternative provider lists; transition plan templates | |
OBL-00903 | European Union | EU_ESA | business continuity | Include in ICT contracts with providers of critical/important functions rights to audit, access data, and require participation in incident response and recovery activities. “Contractual arrangements for the provision of ICT services supporting critical or important functions shall include: full cooperation of the ICT third-party service provider with the competent authorities and the resolution authorities of the financial entity” | Art. 30(3) Regulation (EU) 2022/2554 | final | Contract audit-right and cooperation clauses; evidence of audit execution; incident response cooperation records from providers | |
OBL-00904 | European Union | EU_ESA | business continuity | Implement protection measures including data integrity, encryption and access controls to safeguard ICT assets and ensure resilience of ICT infrastructure. “Financial entities shall develop, document and implement a policy on ICT security giving formal mandate to protect confidentiality, integrity, and availability of data” | Art. 9(3) Regulation (EU) 2022/2554 | final | ICT security policy; encryption and access control standards; evidence of implementation; penetration test results; periodic review records | |
OBL-00905 | European Union | EU_ESA | business continuity | Maintain backup systems and data restore procedures tested regularly, with backup systems physically and logically separate from primary systems. “Financial entities shall put in place backup policies and procedures. Financial entities shall have backup systems that can be activated without undue delay” | Art. 12(1) Regulation (EU) 2022/2554 | final | Backup policy; evidence of physical/logical separation; restore test records and success metrics; RTO/RPO alignment documentation | |
OBL-00906 | European Union | EU_ESA | business continuity | Detect anomalous activity, identify potential single points of failure, and implement measures to address ICT concentration risk in own infrastructure. “Financial entities shall identify all sources of ICT risk and shall assess cyber threats and ICT vulnerabilities relevant to their ICT supported business functions, information assets and ICT assets” | Art. 8(4) Regulation (EU) 2022/2554 | final | ICT risk assessment reports; single point of failure analysis; concentration risk register; remediation plans with target dates | |
OBL-00907 | European Union | EU_ESA | business continuity | Ensure the management body defines, approves, oversees and is accountable for the ICT risk management framework and digital operational resilience strategy. “The management body of the financial entity shall define, approve, oversee and be accountable for the implementation of all arrangements related to the ICT risk management framework” | Art. 5(1) Regulation (EU) 2022/2554 | final | Board resolution approving ICT risk framework; board-level oversight records; assigned accountability documentation; training completion records | |
OBL-00908 | European Union | EU_ESA | business continuity | Conduct post-incident reviews after major ICT incidents to identify root causes and implement corrective actions to prevent recurrence. “After a major ICT-related incident, financial entities shall perform a post-incident review to determine the root causes of disruptions and identify improvements to be applied to the ICT operations” | Art. 17(6) Regulation (EU) 2022/2554 | final | Post-incident review reports with root-cause analysis; corrective action plans with owners and deadlines; evidence of implementation | |
OBL-00909 | European Union | EU_ESA | business continuity | Share cyber threat intelligence and information on ICT vulnerabilities and incidents with other financial entities under appropriate confidentiality arrangements. [adjacent] “Financial entities may exchange amongst themselves cyber threat information and intelligence, including indicators of compromise, tactics, techniques, and procedures, cyber alerts and configuration tools” | Art. 45(1) Regulation (EU) 2022/2554 | final | Information-sharing agreements; records of threat intelligence shared/received; confidentiality controls; participation in sector ISACs | |
OBL-00982 | Canada | CA_OSFI | business continuity | Establish and maintain an Enterprise Disaster Recovery Program (EDRP) to support ability to deliver technology services through disruption and operate within risk tolerance. “FRFIs should establish and maintain an Enterprise Disaster Recovery Program (EDRP) to support its ability to deliver technology services through disruption and operate within its risk tolerance.” | OSFI B-13, Section 2.9, Principle 12 | final | Board/Senior Management approved EDRP document; RTO/RPO definitions; accountability matrix; data backup/recovery policy; evidence of alignment with BCM program. | |
OBL-00984 | Canada | CA_OSFI | business continuity | Align the disaster recovery program with the business continuity management program. “FRFIs should align the disaster recovery program with its business continuity management program.” | OSFI B-13, Section 2.9.1 | final | Documentation cross-referencing EDRP and BCM program; shared dependency analysis; integrated test plans; governance records showing joint oversight. | |
OBL-00985 | Canada | CA_OSFI | business continuity | Manage key EDRP dependencies including data security/storage requirements, locations of backup sites, service provider locations relative to primary data centres, and other critical technology assets. “FRFIs should manage key dependencies required to support the EDRP, such as: Information security requirements for data security and storage (e.g., encryption); and, Location of technology asset centres, backup sites, service provider locations and proximity to primary data centres.” | OSFI B-13, Section 2.9.2 | final | Dependency register with geographic/proximity analysis; encryption standards for backup data; inventory of backup and recovery sites; third-party location mapping. | |
OBL-00986 | Canada | CA_OSFI | business continuity | Regularly perform scenario testing on disaster recovery capabilities against severe but plausible scenarios to validate recovery strategies and confirm ability to meet pre-defined requirements. “FRFIs should regularly validate and report on their disaster recovery strategies, plans and/or capabilities against severe but plausible scenarios...The FRFI's backup and recovery capabilities and processes to validate resiliency strategies, plans and actions, and confirm the organization's ability ” | OSFI B-13, Section 2.9.3, Principle 13 | final | DR test schedule; scenario descriptions; test results and gap analysis reports; evidence of senior management reporting on test outcomes. | |
OBL-00987 | Canada | CA_OSFI | business continuity | DR scenario testing must include critical third-party technologies and integration points with upstream/downstream dependencies, both on- and off-premises. “Critical third-party technologies and integration points with upstream and downstream dependencies, including both on- and off-premises technology.” | OSFI B-13, Section 2.9.3 | final | DR test scope documentation listing third-party systems tested; test results for third-party recovery; evidence of joint testing with critical service providers. | |
OBL-00988 | Canada | CA_OSFI | business continuity | DR scenarios must be forward-looking and consider new/emerging risks, material changes to business/technology, situations causing prolonged outage, and prior incident history. “These scenarios should be forward-looking and consider, where appropriate: New and emerging risks or threats; Material changes to business objectives or technologies; Situations that can lead to prolonged outage; and, Previous incident history and known technology complexities or weaknesses.” | OSFI B-13, Section 2.9.3 | final | Scenario library with documented rationale; threat intelligence inputs; post-incident review records used as scenario inputs; refresh log. | |
OBL-00989 | Canada | CA_OSFI | business continuity | Define standards and implement incident/problem management processes including governance structure for timely identification, escalation, system restoration/recovery, and root cause investigation. “FRFIs should define standards and implement processes for incident and problem management. Standards should provide an appropriate governance structure for timely identification and escalation of incidents, restoration and/or recovery of an affected system, and investigation and resolution of incide” | OSFI B-13, Section 2.7.1 | final | Incident management standard/policy; escalation matrix; restoration procedures; RCA process documentation; incident logs. | |
OBL-00990 | Canada | CA_OSFI | business continuity | Implement incident response procedures including internal/external communication with escalation/notification triggers, and establish and periodically test incident management processes with third parties. “Developing and implementing incident response procedures that mitigate the impacts of incidents, including internal and external communication actions that contain escalation and notification triggers and processes...Establishing and periodically testing incident management processes with third part” | OSFI B-13, Section 2.7.2 | final | Incident response playbooks; communication plans with notification thresholds; third-party incident management agreements; joint test records. | |
OBL-00991 | Canada | CA_OSFI | business continuity | Conduct periodic exercises and testing of incident management processes, playbooks, and response tools to validate and maintain their effectiveness. “Performing periodic testing and exercises using plausible scenarios in order to identify and remedy gaps in incident response actions and capabilities; Conducting periodic exercises and testing of incident management process, playbooks, and other response tools (e.g., coordination and communication)” | OSFI B-13, Section 2.7.2 | final | Exercise schedule and after-action reports; playbook review logs; gap remediation tracking; evidence of lessons-learned integration. | |
OBL-00992 | Canada | CA_OSFI | business continuity | Develop problem management processes for detection, categorization, investigation and resolution of incident causes, including post-incident reviews and root cause/impact diagnostics to improve incident management. “FRFIs should develop problem management processes that provide for the detection, categorization, investigation and resolution of suspected incident cause(s). Processes should include post-incident reviews, root cause and impact diagnostics and identification of trends or patterns in incidents.” | OSFI B-13, Section 2.7.3 | final | Problem management process documentation; post-incident review records; trend analysis reports; evidence of process improvements driven by findings. | |
OBL-00993 | Canada | CA_OSFI | business continuity | Design and implement technology architecture using Resilience-by-Design and Availability-by-Design principles, commensurate with business needs. “Using a risk-based approach, systems and associated infrastructure should be designed and implemented to achieve availability, scalability, security (Secure-by-Design) and resilience (Resilience-by-Design), commensurate with business needs.” | OSFI B-13, Section 2.1.2 | final | Architecture framework documentation; design standards referencing resilience/availability requirements; architecture review records; sign-off on new systems against resilience criteria. | |
OBL-00994 | Canada | CA_OSFI | business continuity | Maintain a current comprehensive asset inventory cataloguing technology assets throughout their lifecycle, including documented interdependencies between critical assets to assist in response to security and operational incidents. “Documented interdependencies between critical technology assets, where appropriate, to enable proper change and configuration management processes, and to assist in response to security and operational incidents, including cyber attacks.” | OSFI B-13, Section 2.2.2 | final | Asset inventory system with criticality classification; interdependency maps; process for keeping inventory current; evidence of use during incident response. | |
OBL-00995 | Canada | CA_OSFI | business continuity | Continuously monitor technology currency and proactively implement plans to mitigate risks from unpatched, outdated, or unsupported assets; replace/upgrade assets before maintenance ceases. “FRFIs should continuously monitor the currency of software and hardware assets...It should proactively implement plans to mitigate and manage risks stemming from unpatched, outdated or unsupported assets and replace or upgrade assets before maintenance ceases.” | OSFI B-13, Section 2.2.5 | final | Technology currency monitoring reports; end-of-life asset register; remediation/upgrade plans with timelines; evidence of executive oversight. | |
OBL-00996 | Canada | CA_OSFI | business continuity | Ensure changes to technology assets in production are documented, assessed, tested, approved, implemented and verified in a controlled manner, with defined emergency change controls. [adjacent] “FRFIs should ensure that changes to technology assets in the production environment are documented, assessed, tested, approved, implemented and verified in a controlled manner...The standard should also define emergency change and control requirements to ensure that such changes are implemented in a” | OSFI B-13, Section 2.5.1 | final | Change management policy/standard; change logs; emergency change procedures; post-implementation review records. | |
OBL-00997 | Canada | CA_OSFI | business continuity | Define technology service management standards with performance indicators/service targets and remediation processes to ensure technology services support business continuity. “FRFIs should establish technology service management standards with defined performance indicators and/or service targets that can be used to measure and monitor the delivery of technology services. Processes should also provide for remediation where targets are not being met.” | OSFI B-13, Section 2.8.1 | final | Service management standards; KPI/SLA dashboards; remediation tracking logs; management reporting on service performance. | |
OBL-00998 | Canada | CA_OSFI | business continuity | Define and continuously monitor performance and capacity requirements with thresholds on infrastructure utilisation to ensure technology supports current and future business needs. “FRFIs should define performance and capacity requirements with thresholds on infrastructure utilization. These requirements should be continuously monitored against defined thresholds to ensure technology performance and capacity support current and future business needs.” | OSFI B-13, Section 2.8.2 | final | Capacity management plan; utilisation threshold documentation; monitoring tool outputs; alerts and breach records; capacity planning reports. | |
OBL-00999 | Canada | CA_OSFI | business continuity | Establish cyber incident response capabilities (team, tools, playbooks) available on a continuous basis to rapidly respond, contain and recover from cyber security events materially impacting technology assets. “FRFIs should establish a cyber incident response team with tools and capabilities available on a continuous basis to rapidly respond, contain and recover from cyber security events and incidents that could materially impact the FRFI's technology assets, customers and other stakeholders.” | OSFI B-13, Section 3.4.4 | final | Cyber incident response team charter; on-call rosters; tooling inventory; playbooks; 24/7 availability evidence; test exercise records. | |
OBL-01000 | Canada | CA_OSFI | business continuity | Maintain cyber security incident management process and playbooks to enable timely and effective management of cyber security incidents. “FRFIs should maintain a cyber security incident management process and playbooks to enable timely and effective management of cyber security incidents.” | OSFI B-13, Section 3.4.3 | final | Current cyber incident management process documentation; scenario-specific playbooks; version control records; evidence of regular review and update. | |
OBL-01001 | Canada | CA_OSFI | business continuity | Align and integrate cyber security, technology, crisis management and communication protocols, including capabilities for timely escalation and stakeholder coordination during major cyber events. “FRFIs should ensure the alignment and integration between their cyber security, technology, crisis management and communication protocols. This should include capabilities to enable comprehensive and timely escalation and stakeholder coordination (internal and external) in response to a major cyber ” | OSFI B-13, Section 3.4.1 | final | Integrated cyber-crisis management framework; escalation matrix linking cyber, technology and crisis teams; communication protocols; joint exercise records. | |
OBL-01002 | Canada | CA_OSFI | business continuity | Conduct forensic investigation for incidents where technology assets may have been materially exposed; perform detailed post-incident assessment including RCA for high-severity incidents. “FRFIs should conduct a forensic investigation for incidents where technology assets may have been materially exposed. For high-severity incidents, the FRFI should conduct a detailed post-incident assessment of direct and indirect impacts...including a root cause analysis to identify remediation acti” | OSFI B-13, Section 3.4.5 | final | Forensic investigation reports; post-incident assessment reports; RCA documentation; remediation action plans; tracking of lessons learned. | |
OBL-01003 | Canada | CA_OSFI | business continuity | Maintain continuous security logging for technology assets and defence layers; implement minimum log retention periods; ensure logs support timely forensic investigation of cyber events. [adjacent] “FRFIs should ensure continuous security logging for technology assets and different layers of defence tools...FRFIs should implement minimum security log retention periods and maintain cyber security event logs to facilitate a thorough and unimpeded forensic investigation of cyber security events.” | OSFI B-13, Section 3.3.1 | final | Log management policy with defined retention periods; SIEM configuration; log completeness audit results; evidence that logs were available and usable in recent incidents. | |
OBL-01004 | Canada | CA_OSFI | business continuity | Proactively identify, defend, detect, respond and recover from cyber security threats and incidents to maintain confidentiality, integrity and availability of technology assets. “FRFIs should proactively identify, defend, detect, respond and recover from external and insider cyber security threats, events and incidents to maintain the confidentiality, integrity and availability of its technology assets.” | OSFI B-13, Section 3.0 | final | Cyber resilience framework documentation; threat assessment records; detection tool evidence; response/recovery playbooks; post-incident recovery evidence. | |
OBL-01005 | Canada | CA_OSFI | business continuity | Implement enhanced controls to rapidly contain cyber threats, defend critical technology assets, and remain resilient against cyber attacks, including designing application controls to limit cyber attack impact. “FRFIs should employ enhanced controls and functionality to rapidly contain cyber security threats, defend its critical technology assets and remain resilient against cyber attacks...Designing application controls to contain and limit the impact of a cyber attack.” | OSFI B-13, Section 3.2.3 | final | Critical asset register with associated enhanced controls; containment control documentation; security hardening baselines; control testing results. | |
OBL-01006 | Canada | CA_OSFI | business continuity | Establish technology and cyber risk management framework including risk appetite, tolerance levels, and processes for identifying, assessing, managing and reporting technology/cyber risks including emerging threats. [adjacent] “Technology and cyber risk appetite and measurement (e.g., limits, thresholds and tolerance levels)...Management of unique risks posed by emerging threats and technologies...Reporting to Senior Management on technology and cyber risk appetite measures, exposures and trends.” | OSFI B-13, Section 1.3.2 | final | Approved RMF with risk appetite statements; tolerance thresholds; risk reporting dashboards; emerging risk process documentation; board/senior management reporting records. | |
OBL-01008 | European Union | EU_AI | artificial intelligence | Providers of high-risk AI systems must establish a quality management system ensuring the AI system meets robustness, accuracy and cybersecurity requirements throughout its lifecycle. [adjacent] “Providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation.” | Art. 17(1) | final | Written QMS documentation covering robustness/cybersecurity controls; audit trail; version control records | |
OBL-01009 | European Union | EU_AI | artificial intelligence | High-risk AI systems must be designed and developed to achieve appropriate levels of accuracy, robustness and cybersecurity, and to perform consistently in those respects throughout their lifecycle. [adjacent] “High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness and cybersecurity, and that they perform consistently in those respects throughout their lifecycle.” | Art. 15(1) | final | Technical documentation showing robustness/cybersecurity design measures; test results; lifecycle maintenance records | |
OBL-01010 | European Union | EU_AI | artificial intelligence | High-risk AI systems must be resilient against attempts by third parties to alter their use or performance through adversarial attacks exploiting system vulnerabilities. “High-risk AI systems shall be resilient as regards attempts by unauthorised third parties to alter their use, outputs or performance by exploiting the system vulnerabilities.” | Art. 15(3) | final | Adversarial testing reports; penetration test results; vulnerability management log; incident response procedures | |
OBL-01011 | European Union | EU_AI | artificial intelligence | High-risk AI systems must have technical redundancy solutions, including backup or fail-safe plans, to ensure continuity of operation when failures occur. “The technical robustness and safety measures shall include redundancy solutions, which may include backup or fail-safe plans.” | Art. 15(4) | final | Documented backup/fail-safe architecture; failover test results; continuity runbooks | |
OBL-01012 | European Union | EU_AI | artificial intelligence | Providers of high-risk AI systems must establish post-market monitoring systems to proactively collect and review data on system performance and safety after deployment. [adjacent] “Providers of high-risk AI systems shall establish and document a post-market monitoring system in a manner that is proportionate to the nature of the AI technologies and the risks of the high-risk AI system.” | Art. 72(1) | final | Post-market monitoring plan; performance dashboards; incident/anomaly logs; periodic review reports | |
OBL-01013 | European Union | EU_AI | artificial intelligence | Providers must report serious incidents involving high-risk AI systems to market surveillance authorities immediately and in any event within prescribed timeframes. [adjacent] “Providers of high-risk AI systems placed on the Union market shall report any serious incident to the market surveillance authorities of the Member States where that incident occurred.” | Art. 73(1) | final | Incident reporting procedure; incident log with timestamps; regulatory notification records within required timeframes | |
OBL-01014 | European Union | EU_AI | artificial intelligence | Providers of high-risk AI systems must immediately take corrective actions, including withdrawal or recall, when the system presents a risk, and inform distributors, deployers and authorities accordingly. [adjacent] “Providers of high-risk AI systems which consider or have reason to consider that a high-risk AI system that they have placed on the market or put into service is not in conformity with this Regulation shall immediately take the necessary corrective actions to bring that system into conformity.” | Art. 20(1) | final | Corrective action log; recall/withdrawal procedures; communications to deployers and authorities | |
OBL-01015 | European Union | EU_AI | artificial intelligence | High-risk AI systems must enable human oversight including the ability to override, interrupt or shut down the system to prevent or minimise risks. [adjacent] “High-risk AI systems shall be designed and developed in such a way to enable the persons to whom human oversight is assigned to be able to … intervene on the operation of the high-risk AI system or interrupt the system through a 'stop' button or a similar procedure.” | Art. 14(4)(e) | final | Technical design documentation showing stop/override functionality; human oversight procedures; operator training records | |
OBL-01016 | European Union | EU_AI | artificial intelligence | High-risk AI systems must automatically detect and flag failures, faults, or inconsistencies that may result in risks, and be able to operate in a safe state in the event of such failures. “High-risk AI systems shall be resilient as regards … errors, faults or inconsistencies that may occur within the system or the environment in which the system operates, in particular due to their interaction with natural persons or other systems.” | Art. 15(3) | final | Fault detection test records; safe-state design documentation; automated alerting configuration | |
OBL-01017 | European Union | EU_AI | artificial intelligence | Deployers of high-risk AI systems must monitor system operation on the basis of instructions of use and report to the provider any risks or incidents identified during use. [adjacent] “Deployers of high-risk AI systems shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers about serious incidents.” | Art. 26(5) | final | Operational monitoring logs; incident reports sent to providers; documented review cadence per instructions of use | |
OBL-01018 | European Union | EU_AI | artificial intelligence | Providers of general-purpose AI models with systemic risk must perform adversarial testing and red-teaming to identify and mitigate systemic risks including cybersecurity vulnerabilities. [adjacent] “Providers of general-purpose AI models with systemic risk shall … perform model evaluation in accordance with standardised protocols and tools … including adversarial testing of the model to identify and mitigate systemic risks.” | Art. 55(1)(a) | final | Red-team/adversarial test plans and results; risk mitigation records; model evaluation reports | |
OBL-01019 | European Union | EU_AI | artificial intelligence | Providers of general-purpose AI models with systemic risk must assess and mitigate systemic risks including risks to critical infrastructure and serious cyber threats. [adjacent] “Providers of general-purpose AI models with systemic risk shall … assess and mitigate possible systemic risks, including their sources, that may stem from the development, the placing on the market, or the use of general-purpose AI models with systemic risk.” | Art. 55(1)(b) | final | Systemic risk assessment report covering critical infrastructure and cyber threat scenarios; mitigation plan | |
OBL-01020 | European Union | EU_AI | artificial intelligence | Providers of general-purpose AI models with systemic risk must track, document and report serious incidents and possible corrective measures to the AI Office without undue delay. [adjacent] “Providers of general-purpose AI models with systemic risk shall … track, document and report, without undue delay, to the AI Office and, as applicable, to national competent authorities, relevant information about serious incidents and possible corrective measures.” | Art. 55(1)(c) | final | Incident tracking log; documented corrective measures; notification records to AI Office; timestamps of reports | |
OBL-01021 | European Union | EU_AI | artificial intelligence | Providers of general-purpose AI models with systemic risk must ensure adequate cybersecurity protection for the model and its physical infrastructure. [adjacent] “Providers of general-purpose AI models with systemic risk shall … ensure an adequate level of cybersecurity protection for the general-purpose AI model with systemic risk and the physical infrastructure of the model.” | Art. 55(1)(d) | final | Cybersecurity policy; infrastructure hardening records; penetration test results; access control documentation | |
OBL-01022 | European Union | EU_AI | artificial intelligence | Providers of high-risk AI systems must keep automatically generated logs for the period appropriate to the intended purpose, to enable incident investigation and monitoring. [adjacent] “High-risk AI systems shall technically allow for the automatic recording of events ('logs') over the lifetime of the system.” | Art. 12(1) | final | Log retention policy; automated logging configuration; sample logs demonstrating traceability of events | |
OBL-01023 | European Union | EU_AI | artificial intelligence | Providers must ensure high-risk AI systems have automatic logging capabilities that enable reconstruction of events over the period of the AI system's use to support post-incident investigation. “The logging capabilities shall ensure a level of traceability of the AI system's functioning throughout its lifetime that is appropriate to the intended purpose of the system.” | Art. 12(2) | final | Logging architecture documentation; evidence that logs capture sufficient events for incident reconstruction; retention schedule | |
OBL-01024 | European Union | EU_AI | artificial intelligence | Deployers of high-risk AI systems must retain logs automatically generated by the system for a minimum period as applicable, to support incident investigation and regulatory oversight. [adjacent] “Deployers of high-risk AI systems shall retain the logs automatically generated by that high-risk AI system to the extent such logs are under their control.” | Art. 26(6) | final | Log retention records; access controls on logs; documented retention periods; log inventory | |
OBL-01025 | European Union | EU_AI | artificial intelligence | Providers must include instructions for use with high-risk AI systems specifying the expected lifetime and maintenance/servicing measures required to ensure continued safe and accurate operation. [adjacent] “The instructions for use shall include … where relevant, a description of the maintenance and care measures … to ensure that the AI system continues to comply with the requirements set out in this Chapter.” | Art. 13(3)(b)(v) | final | Instructions for use document containing maintenance schedules and servicing requirements; evidence of provision to deployers | |
OBL-01029 | European Union | EU_AI | artificial intelligence | National competent authorities must conduct market surveillance of AI systems to detect, investigate and remedy non-conformities that present risks, including operational and cybersecurity risks. [adjacent] “Market surveillance authorities shall perform market surveillance of AI systems made available on the market, put into service or used in the Union in accordance with this Regulation.” | Art. 74(1) | final | Market surveillance programme documentation; investigation records; risk-based inspection plans; corrective action orders | |
OBL-01031 | European Union | EU_AI | artificial intelligence | Providers and deployers of AI systems used by critical infrastructure operators must ensure those systems meet all high-risk AI system requirements including robustness and continuity of safe operation. “High-risk AI systems referred to in Article 6(2) are the AI systems listed in any of the following areas: … 2. AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity.” | Annex III, point 2 | final | Classification assessment confirming critical infrastructure scope; conformity documentation; operational resilience test evidence | |
OBL-01032 | European Union | EU_AI | artificial intelligence | Providers of high-risk AI systems must systematically perform conformity assessments including evaluation of robustness and cybersecurity requirements before placing the system on the market or putting it into service. [adjacent] “For high-risk AI systems listed in Annex III, the conformity assessment shall be carried out by the provider … prior to placing it on the market or putting it into service.” | Art. 43(1) | final | Completed conformity assessment records; third-party audit reports where applicable; technical file cross-reference | |
OBL-01162 | United States (NY) | NYDFS | business continuity | Maintain a cybersecurity program that includes the ability to recover from Cybersecurity Events and restore normal operations and services. “recover from Cybersecurity Events and restore normal operations and services” | 23 NYCRR 500.2(b)(5) | final | Written cybersecurity program documentation showing recovery capabilities; incident response records demonstrating restoration of operations | |
OBL-01164 | United States (NY) | NYDFS | business continuity | Include systems availability concerns in the written cybersecurity policy. “systems operations and availability concerns” | 23 NYCRR 500.3(f) | final | Written cybersecurity policy containing systems availability section; review and approval records | |
OBL-01165 | United States (NY) | NYDFS | business continuity | Include incident response procedures in the written cybersecurity policy. “incident response” | 23 NYCRR 500.3(n) | final | Written cybersecurity policy with incident response section; board/Senior Officer approval documentation | |
OBL-01166 | United States (NY) | NYDFS | business continuity | Establish and maintain audit trail systems designed to reconstruct material financial transactions sufficient to support normal operations, retained for at least five years. [adjacent] “designed to reconstruct material financial transactions sufficient to support normal operations and obligations of the Covered Entity” | 23 NYCRR 500.6(a)(1), 500.6(b) | final | Audit trail system documentation; data retention policy; records proving 5-year retention; system architecture diagrams | |
OBL-01167 | United States (NY) | NYDFS | business continuity | Maintain audit trails designed to detect and respond to Cybersecurity Events that could materially harm normal operations, retained for at least three years. “audit trails designed to detect and respond to Cybersecurity Events that have a reasonable likelihood of materially harming any material part of the normal operations” | 23 NYCRR 500.6(a)(2), 500.6(b) | final | Audit log configurations; 3-year retention records; evidence of logs used in incident detection and response | |
OBL-01168 | United States (NY) | NYDFS | business continuity | Conduct a periodic Risk Assessment that considers availability and effectiveness of controls to protect Information Systems, updated as necessary to address changes in operations. “the availability and effectiveness of controls to protect Nonpublic Information and Information Systems” | 23 NYCRR 500.9(a) | final | Documented Risk Assessment reports; update history; written policies and procedures governing the assessment process | |
OBL-01169 | United States (NY) | NYDFS | business continuity | Ensure qualified cybersecurity personnel are sufficient to perform or oversee recovery from Cybersecurity Events (core cybersecurity function 500.2(b)(5)). “qualified cybersecurity personnel...sufficient to manage the Covered Entity's cybersecurity risks and to perform or oversee the performance of the core cybersecurity functions specified in section 500.2(b)(1)-(6)” | 23 NYCRR 500.10(a)(1) | final | Staffing records; roles and responsibilities documentation; training records; third-party service agreements if outsourced | |
OBL-01170 | United States (NY) | NYDFS | business continuity | Implement written policies and procedures governing Third Party Service Providers' cybersecurity practices, including periodic assessment based on risk they present. “periodic assessment of such Third Party Service Providers based on the risk they present and the continued adequacy of their cybersecurity practices” | 23 NYCRR 500.11(a)(4) | final | Written TPSP policy; periodic assessment records; risk-tiering documentation; vendor review schedule | |
OBL-01171 | United States (NY) | NYDFS | business continuity | Require Third Party Service Providers to provide notice to the Covered Entity upon any Cybersecurity Event directly impacting the Covered Entity's Information Systems or its Nonpublic Information. [adjacent] “notice to be provided to the Covered Entity in the event of a Cybersecurity Event directly impacting the Covered Entity's Information Systems or the Covered Entity's Nonpublic Information being held by the Third Party Service Provider” | 23 NYCRR 500.11(b)(3) | final | Vendor contracts with notification clauses; incident notification logs from TPSPs; due diligence checklists | |
OBL-01172 | United States (NY) | NYDFS | business continuity | Establish a written incident response plan designed to promptly respond to and recover from Cybersecurity Events affecting availability or continuing functionality of business operations. “written incident response plan designed to promptly respond to, and recover from, any Cybersecurity Event materially affecting...the continuing functionality of any aspect of the Covered Entity's business or operations” | 23 NYCRR 500.16(a) | final | Written IRP document; approval records; test/exercise results; post-incident review reports | |
OBL-01173 | United States (NY) | NYDFS | business continuity | Ensure the incident response plan defines clear roles, responsibilities, and decision-making authority for responding to and recovering from Cybersecurity Events. “the definition of clear roles, responsibilities and levels of decision-making authority” | 23 NYCRR 500.16(b)(3) | final | IRP with named roles and decision matrix; organizational charts; contact lists | |
OBL-01174 | United States (NY) | NYDFS | business continuity | Ensure the incident response plan addresses external and internal communications and information sharing during a Cybersecurity Event. “external and internal communications and information sharing” | 23 NYCRR 500.16(b)(4) | final | IRP communication protocols; stakeholder notification templates; media/regulator communication procedures | |
OBL-01175 | United States (NY) | NYDFS | business continuity | Ensure the incident response plan addresses identification and remediation of weaknesses in Information Systems and controls following a Cybersecurity Event. “identification of requirements for the remediation of any identified weaknesses in Information Systems and associated controls” | 23 NYCRR 500.16(b)(5) | final | Post-incident remediation tracking logs; vulnerability remediation reports; control improvement documentation | |
OBL-01176 | United States (NY) | NYDFS | business continuity | Ensure the incident response plan requires documentation and reporting regarding Cybersecurity Events and incident response activities. “documentation and reporting regarding Cybersecurity Events and related incident response activities” | 23 NYCRR 500.16(b)(6) | final | Incident log/register; after-action reports; regulatory notification records; internal reporting templates | |
OBL-01177 | United States (NY) | NYDFS | business continuity | Evaluate and revise the incident response plan as necessary following a Cybersecurity Event. “the evaluation and revision as necessary of the incident response plan following a Cybersecurity Event” | 23 NYCRR 500.16(b)(7) | final | Post-incident review records; IRP version history showing updates triggered by events; lessons-learned documentation | |
OBL-01178 | United States (NY) | NYDFS | business continuity | Notify the Superintendent within 72 hours of determining a Cybersecurity Event with reasonable likelihood of materially harming normal operations has occurred. “no event later than 72 hours from a determination that a Cybersecurity Event has occurred...Cybersecurity Events that have a reasonable likelihood of materially harming any material part of the normal operation(s) of the Covered Entity” | 23 NYCRR 500.17(a)(2) | final | Incident notification log with timestamps; DFS portal submission records; internal escalation procedure tied to 72h clock | |
OBL-01179 | United States (NY) | NYDFS | business continuity | Notify the Superintendent within 72 hours of determining a Cybersecurity Event requiring notice to any government body or regulatory/self-regulatory agency has occurred. [adjacent] “no event later than 72 hours from a determination that a Cybersecurity Event has occurred...Cybersecurity Events impacting the Covered Entity of which notice is required to be provided to any government body, self-regulatory agency or any other supervisory body” | 23 NYCRR 500.17(a)(1) | final | Multi-regulator notification log; mapping of events to notification triggers; DFS submission timestamps | |
OBL-01180 | United States (NY) | NYDFS | business continuity | Include in the cybersecurity program monitoring and testing—including penetration testing and vulnerability assessments—to assess program effectiveness, supporting detection and response to threats that could disrupt operations. [adjacent] “monitoring and testing, developed in accordance with the Covered Entity's Risk Assessment, designed to assess the effectiveness of the Covered Entity's cybersecurity program...annual Penetration Testing...bi-annual vulnerability assessments” | 23 NYCRR 500.5 | final | Annual pen test reports; bi-annual vulnerability scan results; Risk Assessment linking tests to identified risks | |
OBL-01181 | United States (NY) | NYDFS | business continuity | Maintain a cybersecurity program designed to protect the availability of the Covered Entity's Information Systems. “maintain a cybersecurity program designed to protect the confidentiality, integrity and availability of the Covered Entity's Information Systems” | 23 NYCRR 500.2(a) | final | Written cybersecurity program documentation explicitly addressing availability; program review records | |
OBL-01182 | United States (NY) | NYDFS | business continuity | Include in the cybersecurity program the ability to detect and respond to Cybersecurity Events to mitigate negative effects on operations. “respond to identified or detected Cybersecurity Events to mitigate any negative effects” | 23 NYCRR 500.2(b)(4) | final | Cybersecurity program documentation covering response capabilities; SOC/detection tool evidence; response runbooks | |
OBL-01183 | United States (NY) | NYDFS | business continuity | Implement written TPSP policies that include minimum cybersecurity practices required of third parties, supporting resilience of systems accessible to or held by those providers. “minimum cybersecurity practices required to be met by such Third Party Service Providers in order for them to do business with the Covered Entity” | 23 NYCRR 500.11(a)(2) | final | Written TPSP policy with minimum standards; vendor onboarding checklists; contract clauses referencing standards | |
OBL-01184 | United States (NY) | NYDFS | business continuity | Make available to the Superintendent upon request all documentation relevant to the cybersecurity program, including BCDR and incident response components. [adjacent] “All documentation and information relevant to the Covered Entity's cybersecurity program shall be made available to the superintendent upon request” | 23 NYCRR 500.2(d) | final | Document repository of cybersecurity program materials; index of BCDR/IRP documents; retrieval procedure | |
OBL-01185 | United States (NY) | NYDFS | business continuity | Maintain records supporting the annual compliance certification for five years, including documentation of remedial efforts for identified areas requiring improvement. [adjacent] “maintain for examination by the Department all records, schedules and data supporting this certificate for a period of five years...document the identification and the remedial efforts planned and underway” | 23 NYCRR 500.17(b) | final | Five-year archive of compliance records; remediation tracking logs; annual certifications filed with DFS | |
OBL-01186 | United States (NY) | NYDFS | business continuity | Include vendor and Third Party Service Provider management in the written cybersecurity policy to address resilience risks from third-party dependencies. “vendor and Third Party Service Provider management” | 23 NYCRR 500.3(l) | final | Cybersecurity policy with TPSP management section; board/Senior Officer approval; vendor risk register | |
OBL-01189 | United States (NY) | NYDFS | crisis management | Maintain cybersecurity programs, policies, and procedures based on Risk Assessments that account for AI-related risks including deepfakes, threats from TPSPs' AI use, and AI vulnerabilities affecting availability of Information Systems. “Covered Entities should address AI-related risks in the following areas: the organization's own use of AI, the AI technologies utilized by TPSPs and vendors, and any potential vulnerabilities stemming from AI applications that could pose a risk to the confidentiality, integrity, and availability of ” | 23 NYCRR §§ 500.2 and 500.3 | proposed | Written cybersecurity program/policies referencing AI risks; current Risk Assessment documenting AI threat analysis; policy update log. | |
OBL-01190 | United States (NY) | NYDFS | crisis management | Update Risk Assessments at least annually and whenever a material change in business or technology affects cybersecurity risk, ensuring new AI-related risks are assessed and reflected in updated policies and procedures. [adjacent] “The Cybersecurity Regulation requires Risk Assessments to be updated at least annually and whenever a change in the business or technology causes a material change to a Covered Entity's cybersecurity risk to ensure new risks, including those posed by AI, are assessed.” | 23 NYCRR §§ 500.2, 500.3, and 500.9 | proposed | Dated Risk Assessment records showing annual refresh; change-triggered reassessment logs; documented policy updates following each assessment. | |
OBL-01191 | United States (NY) | NYDFS | crisis management | Maintain TPSP policies and procedures including due diligence guidelines addressing AI-related cybersecurity risks posed by third-party service providers, including how TPSPs protect against AI-enabled threats that could impact the Covered Entity. [adjacent] “One of the most important requirements for combatting AI-related risks is to maintain TPSP policies and procedures that include guidelines for conducting due diligence before a Covered Entity uses a TPSP that will access its Information Systems and/or NPI.” | 23 NYCRR § 500.11(a) | proposed | Written TPSP policy with AI-risk due diligence criteria; vendor assessment questionnaires addressing AI use; contractual provisions on AI security. | |
OBL-01192 | United States (NY) | NYDFS | crisis management | Require TPSPs to provide timely notification of any Cybersecurity Event that directly impacts the Covered Entity's Information Systems or NPI held by the TPSP, including AI-related threats. “Covered Entities should require TPSPs to provide timely notification of any Cybersecurity Event that directly impacts the Covered Entity's Information Systems or NPI held by the TPSP, including threats related to AI.” | 23 NYCRR § 500.11(a) | proposed | TPSP contracts containing incident notification clauses; incident notification tracking log; SLA documentation for notification timelines. | |
OBL-01193 | United States (NY) | NYDFS | crisis management | Maintain a monitoring process to promptly identify new security vulnerabilities in Information Systems (especially those holding NPI) to enable rapid remediation, including monitoring relevant to AI-enabled attacks. [adjacent] “Covered Entities must have a monitoring process in place that can identify new security vulnerabilities promptly so remediation can occur quickly.” | 23 NYCRR § 500.5(b) | proposed | Documented vulnerability monitoring program; scan frequency records; remediation tracking log; evidence of AI-related threat monitoring coverage. | |
OBL-01194 | United States (NY) | NYDFS | crisis management | Monitor Authorized User activity and email/web traffic to block malicious content and protect against installation of malicious code, including monitoring for unusual AI-related query behaviors that may indicate NPI exfiltration. [adjacent] “Covered Entities must monitor the activity of Authorized Users as well as email and web traffic to block malicious content and protect against the installation of malicious code on their Information Systems.” | 23 NYCRR §§ 500.5(b) and 500.14(a)(1)-(2) | proposed | User activity monitoring logs; email/web filtering configuration; policies on blocking NPI queries to public AI systems; monitoring alert records. | |
OBL-01195 | United States (NY) | NYDFS | crisis management | Implement MFA for all Authorized Users attempting to access Covered Entities' Information Systems or NPI, including customers, employees, contractors, and TPSPs, using factors resilient to AI-enabled deepfake attacks. [adjacent] “As of November 2025, the Cybersecurity Regulation will require MFA to be in place for all Authorized Users attempting to access Covered Entities' Information Systems or NPI, including customers, employees, contractors, and TPSPs.” | 23 NYCRR § 500.12 | proposed | MFA configuration records covering all user categories; Risk Assessment justifying authentication factor choices; evidence of deepfake-resistant factors where appropriate. | |
OBL-01196 | United States (NY) | NYDFS | crisis management | Implement access controls limiting each Authorized User's access privileges to only those necessary for their job functions, limiting elevated permissions, and periodically (at minimum annually) reviewing and removing unnecessary access privileges. [adjacent] “The controls must limit an Authorized User's access privileges to only those necessary for that Authorized User's job functions, and limit the number of Authorized Users with elevated permissions and access to NPI.” | 23 NYCRR § 500.7(a)(1),(2),(4),(5),(6) | proposed | Access control policy; annual access review records; privilege de-provisioning logs; terminated-user access removal evidence. | |
OBL-01198 | United States (NY) | NYDFS | crisis management | Maintain and update a data inventory of all Information Systems, with priority on AI-related systems critical to ongoing business operations, to support breach response and continuity. “Covered Entities should maintain and update data inventories as they are crucial for assessing potential risks and ensuring compliance with data protection regulations. Data inventories further help entities track NPI so that if there is a breach, they know what NPI may have been exposed.” | 23 NYCRR § 500.13(a) | proposed | Asset/data inventory records including AI systems; inventory update procedures; evidence of prioritization of AI-critical systems. | |
OBL-01199 | United States (NY) | NYDFS | crisis management | Identify all Information Systems that use or rely on AI (including AI-enabled products/services), maintain an inventory of such systems, and prioritize implementing mitigations for systems critical to ongoing business operations. [adjacent] “Entities should identify all Information Systems that use or rely on AI, including, if applicable, the Information Systems that maintain, or rely on, AI-enabled products and services... and prioritize implementing mitigations for those systems that are critical for ongoing business operations.” | 23 NYCRR § 500.13 | proposed | Documented AI systems inventory; criticality classification; mitigation priority matrix; evidence of remediation actions for critical AI systems. | |
OBL-01200 | United States (NY) | NYDFS | crisis management | Implement data governance procedures covering collection, storage, processing, and disposal of data, including controls to prevent threat actors from accessing data maintained for AI functioning. [adjacent] “Entities should implement data governance procedures that include data collection, storage, processing, and disposal. Moreover, if an entity uses AI or relies on a product that uses AI, controls should be in place to prevent threat actors from accessing the vast amounts of data maintained for the ac” | 23 NYCRR § 500.3(b) | proposed | Data governance policy; controls documentation for AI data stores; access controls evidence for AI training/inference datasets. | |
OBL-01201 | United States (NY) | NYDFS | crisis management | Provide at least annual cybersecurity awareness training for all personnel that includes social engineering (including deepfake attacks), procedures for responding to unusual requests, and AI-related threats. [adjacent] “Covered Entities must now provide at least annual cybersecurity awareness training that includes social engineering. Training on social engineering, including on deepfake attacks, can be effectively delivered through simulated phishing, and voice and video impersonation exercises.” | 23 NYCRR § 500.14(a)(3) | proposed | Annual training completion records for all staff; training content showing AI/deepfake/social engineering coverage; simulated exercise results. | |
OBL-01203 | United States (NY) | NYDFS | crisis management | Train relevant personnel on how to secure and defend AI systems from cybersecurity attacks and how to design/develop AI systems securely, where the entity deploys or relies on TPSP-deployed AI. [adjacent] “If deploying AI directly, or working with a TPSP that deploys AI, relevant personnel should be trained on how to secure and defend AI systems from cybersecurity attacks, and how to design and develop AI systems securely.” | 23 NYCRR § 500.14(a)(3) | proposed | Training records for AI developers/operators; curriculum documenting secure AI development content; evidence of role-based assignment. | |
OBL-01204 | United States (NY) | NYDFS | crisis management | Ensure the Senior Governing Body has sufficient understanding of AI-related cybersecurity risks, exercises oversight of cybersecurity risk management including AI risks, and regularly receives management reports on AI-related cybersecurity matters. [adjacent] “The Cybersecurity Regulation requires the Senior Governing Body to have sufficient understanding of cybersecurity-related matters (including AI-related risks), exercise oversight of cybersecurity risk management, and regularly receive and review management reports about cybersecurity matters (includ” | 23 NYCRR § 500.4(d) | proposed | Board/committee meeting minutes showing AI cybersecurity risk discussions; management reports submitted to Senior Governing Body; board training records on AI risk. | |
OBL-01206 | United States (NY) | NYDFS | crisis management | Conduct due diligence on TPSPs that will access Information Systems or NPI, specifically assessing AI-related threats facing those TPSPs and how TPSP compromise could impact the Covered Entity's continuity and security. “DFS strongly recommends Covered Entities consider, among other factors, the threats facing TPSPs from the use of AI and AI-enabled products and services; how those threats, if exploited, could impact the Covered Entity; and how the TPSPs protect themselves from such exploitation.” | 23 NYCRR § 500.11(a) | proposed | Completed vendor due diligence questionnaires with AI risk sections; risk ratings; documentation of TPSP AI security controls evaluated. | |
OBL-01207 | United Kingdom | UK_PRA | business continuity | Identify and document important business services (IBS) — those whose disruption could pose risk to safety and soundness, financial stability, or policyholder protection. “firms must identify their important business services...defined as the services a firm provides which, if disrupted, could pose a risk to a firm's safety and soundness or...the financial stability of the UK.” | Operational Resilience 2.1; SS1/21 §2.2 | final | Board-approved written list of IBS with documented rationale referencing safety/soundness, financial stability and policyholder protection criteria; reviewed annually. | |
OBL-01208 | United Kingdom | UK_PRA | business continuity | Set an impact tolerance (including a mandatory time-based metric) for each identified important business service. “firms to set an impact tolerance for each of their important business services...An impact tolerance must, in all cases, include a time-based metric to measure the tolerable level of disruption.” | Operational Resilience 2.2, 2.4; SS1/21 §3.1, §3.6 | final | Documented impact tolerances per IBS with time-based metric (and supplementary metrics where applicable); board approval evidenced in board minutes. | |
OBL-01209 | United Kingdom | UK_PRA | business continuity | Set impact tolerances at the point beyond which further disruption would pose a risk to safety and soundness, financial stability, or policyholder protection. “require firms to set their impact tolerances at the point at which any further disruption to the important business service would pose a risk to the firm's safety and soundness...policyholder protection...financial stability of the UK.” | Operational Resilience 2.3; SS1/21 §3.2 | final | Written rationale for each tolerance threshold referencing quantitative/qualitative indicators per SS1/21 §3.8. | |
OBL-01210 | United Kingdom | UK_PRA | business continuity | Ensure ability to deliver each IBS within its impact tolerance in severe but plausible scenarios by 31 March 2025. “firms to ensure they are able to deliver their important business services within impact tolerances in severe but plausible scenarios...no later than Monday 31 March 2025.” | Operational Resilience 2.5, 2.6; SS1/21 §4.1, §4.14 | final | Prioritised remediation plan showing milestones; evidence of plan execution; scenario test results confirming IBS delivery within tolerance by 31 March 2025. | |
OBL-01211 | United Kingdom | UK_PRA | business continuity | Develop and implement effective remediation plans for IBS that cannot remain within impact tolerances, with timing proportionate to disruption impact. “firms to develop and implement effective remediation plans for the important business services that would not be able to remain within their impact tolerance...speed at which vulnerabilities are remediated should be commensurate with the potential impact.” | SS1/21 §4.3, §4.15 | final | Written remediation plans per at-risk IBS with timelines; progress tracking records; evidence of senior management ownership. | |
OBL-01212 | United Kingdom | UK_PRA | business continuity | Map the people, processes, technology, facilities, and information resources required to deliver each IBS, including resources provided by third parties. “require firms to identify and document the necessary people, processes, technology, facilities, and information...required to deliver each of their important business services...irrespective of whether the resources are being provided wholly or in part by a third party.” | Operational Resilience 4.1; SS1/21 §5.1, §5.5 | final | Documented mapping artefacts per IBS showing all resource dependencies including third-party/intragroup; updated annually or on material change. | |
OBL-01213 | United Kingdom | UK_PRA | business continuity | Update IBS mapping at least annually, or sooner following a significant change. “The PRA expects firms to update their mapping annually at a minimum, or following significant change if sooner.” | SS1/21 §5.9 | final | Version-controlled mapping documents with dated review records; change-triggered update log. | |
OBL-01214 | United Kingdom | UK_PRA | business continuity | Regularly test ability to remain within impact tolerances using severe but plausible disruption scenarios, with testing focused on recovery and response. “require firms to test regularly their ability to remain within impact tolerances in severe but plausible disruption scenarios...The PRA expects firms to focus on recovery and response arrangements.” | Operational Resilience 5.1; SS1/21 §6.1 | final | Written testing plan; scenario test reports; evidence of increasing scenario severity over time; lessons-learned log. | |
OBL-01215 | United Kingdom | UK_PRA | business continuity | Develop a written testing plan specifying scenario types, frequency, IBS coverage, and availability/integrity testing, proportionate to potential disruption impact. “firms to develop a testing plan that details how they will gain assurance that they can remain within impact tolerances...nature and frequency of a firm's testing should be proportionate to the potential impact that disruption could cause.” | SS1/21 §6.6 | final | Documented testing plan covering scenario types, frequency, IBS prioritisation, availability/integrity scenarios; board or senior management approval. | |
OBL-01217 | United Kingdom | UK_PRA | business continuity | Ensure ability to remain within impact tolerances irrespective of third-party use; effectively manage third parties so they do not cause tolerance breaches. “firms to be able to remain within impact tolerances for important business services, irrespective of whether or not they use third parties in the delivery of these services...effectively manage their use of third parties to ensure they can meet the required standard.” | SS1/21 §4.5 | final | Third-party contracts with resilience obligations; third-party assurance reports; evidence that third-party SLAs align with impact tolerance requirements. | |
OBL-01218 | United Kingdom | UK_PRA | business continuity | Understand and manage sub-outsourcing dependencies that may threaten operational resilience and IBS delivery. “Firms should understand the reliance placed on sub-outsourcing arrangements and if these arrangements pose a threat to their operational resilience.” | SS1/21 §5.6 | final | Sub-outsourcing register; materiality assessment; evidence that primary service providers maintain oversight of sub-contractors' resilience capability. | |
OBL-01219 | United Kingdom | UK_PRA | business continuity | Include third-party failure/disruption scenarios (including supply chain) as severe but plausible scenarios in operational resilience testing. “one of the severe but plausible scenarios that firms may select for this testing could involve a failure or disruption at a third party, or their supply chain, based on previous incidents or near misses.” | SS1/21 §6.13 | final | Testing plans and reports that include at least one third-party/supply-chain failure scenario per material outsourced IBS. | |
OBL-01220 | United Kingdom | UK_PRA | business continuity | Require contractual agreements for material outsourcing to include obligations for both parties to implement and test business contingency plans aligned to impact tolerances. “contractual agreements for material outsourcing arrangements to include 'requirements for both parties to implement and test business contingency plans. For the firm, these should take account of firms' impact tolerances for important business services.'” | SS1/21 §6.13 | final | Material outsourcing contracts containing explicit BCP testing obligations; evidence of joint or coordinated testing with third parties. | |
OBL-01221 | United Kingdom | UK_PRA | business continuity | Develop communication strategies for internal and external stakeholders as part of operational disruption response planning, including escalation paths and decision-maker identification. “firms to develop communication strategies for both internal and external stakeholders as part of their planning for responding to operational disruptions...plans should include the escalation paths they would use to manage communications during an incident.” | SS1/21 §4.7 | final | Written communications plan per IBS covering escalation paths, key contact lists (regulators, suppliers, operational staff), and decision-maker identification. | |
OBL-01222 | United Kingdom | UK_PRA | business continuity | Review IBS list at least annually, or sooner on significant change, to determine whether additions or removals are required. “The PRA expects firms to review their important business services annually at a minimum, or sooner if a significant change occurs, and to determine whether any changes are required to their list of important business services.” | SS1/21 §2.10 | final | Annual review records with board/senior management sign-off; change log documenting trigger-based reviews. | |
OBL-01223 | United Kingdom | UK_PRA | business continuity | Board must approve and regularly review: IBS list, impact tolerances, and written self-assessment, including scenario analyses of ability to remain within tolerances. “a firm's board must approve and regularly review the firm's important business services, impact tolerances, and written self-assessment...boards must regularly review assessments...and the scenario analyses of its ability to remain within the impact tolerance.” | Operational Resilience 7; SS1/21 §7.1 | final | Board meeting minutes evidencing approval and review of IBS, tolerances, self-assessment and scenario results; board MI packs. | |
OBL-01224 | United Kingdom | UK_PRA | business continuity | Assign overall responsibility for implementing operational resilience policies to the Chief Operations SMF24 (where it exists) with reporting to the board. “the Chief Operations Senior Management Function (SMF) 24 should hold overall responsibility for implementing operational resilience policies and reporting to the board.” | SS1/21 §7.4 | final | SMF24 appointment documentation; SMCR responsibilities map attributing operational resilience to SMF24; board reporting records. | |
OBL-01225 | United Kingdom | UK_PRA | business continuity | Produce and maintain a written self-assessment documenting compliance with the Operational Resilience Parts, approved by the board. “require firms to document a self-assessment of their compliance with the Operational Resilience Part...Firms' boards are accountable for and should approve the information provided in these documents.” | Operational Resilience 6; SS1/21 §8.1 | final | Board-approved written self-assessment document; version history; board approval minute. | |
OBL-01226 | United Kingdom | UK_PRA | business continuity | Self-assessment must document IBS list with rationale, impact tolerances with rationale, mapping methodology, testing strategy and scenarios, lessons learned, identified vulnerabilities with remediation plans, and group-related risks. “list their important business services...specify the impact tolerances...detail their approach to mapping...describe their strategy for testing...identify any lessons learned...identify the vulnerabilities that threaten their ability...identify any additional risks...from elsewhere in their group.” | Operational Resilience 6; SS1/21 §8.3 | final | Self-assessment containing all enumerated sections; board approval minute; evidence of annual updates. | |
OBL-01227 | United Kingdom | UK_PRA | business continuity | Set recovery time objectives and recovery point objectives for resources underpinning IBS so that the IBS can be delivered within its impact tolerance. “requirements might include capacity specifications, recovery time objectives, and recovery point objectives. These requirements should be set to enable the firm to deliver the important business service within its impact tolerance.” | SS1/21 §3.14 | final | Documented RTO/RPO per resource/system supporting each IBS; evidence RTO/RPO align to and are tested against impact tolerances. | |
OBL-01228 | United Kingdom | UK_PRA | business continuity | CRR consolidation entities and insurers must identify important group business services and set impact tolerances at group level to capture risks from non-individually-regulated group members. “CRR consolidation entities...or an insurer...to identify a proportionate number of important group business services and respective impact tolerances at the level of the group.” | Operational Resilience 8.6–8.13; SS1/21 §9.1 | final | Group-level IBS list with impact tolerances; board approval at group level; group self-assessment including subsidiaries outside the UK. | |
OBL-01229 | United Kingdom | UK_PRA | business continuity | CRR consolidation entities must maintain regular dialogue with group members so CRR firms can account for additional risks to safety and soundness when assessing ability to remain within impact tolerances. [adjacent] “the CRR consolidation entity would have regular dialogue with other members of its group so the CRR firm (or CRR firms) can take account of any additional risks to their safety and soundness when assessing their ability to remain within impact tolerance.” | Operational Resilience 8.8; SS1/21 §9.4 | final | Records of regular group resilience dialogue (e.g. meeting minutes); group risk reporting mechanisms feeding into individual firm self-assessments. | |
OBL-01230 | United Kingdom | UK_PRA | business continuity | Manage risks from intragroup third-party arrangements with the same rigour as external third parties to ensure ability to remain within impact tolerances. “firms to manage risk and make appropriate arrangements to be able to remain within impact tolerance, whether using third parties that are other entities within their group or external providers.” | SS1/21 §4.6 | final | Intragroup SLAs/contracts with resilience obligations; assurance evidence (audits, test results) for intragroup providers equivalent to external third-party oversight. | |
OBL-01231 | United Kingdom | UK_PRA | business continuity | Have a prioritised plan in place by 31 March 2022 setting out how the firm will achieve full within-tolerance capability, with the plan already being executed by that date. “Firms are expected to have a prioritised plan which sets out how they will comply with the requirement to be able to remain within their impact tolerances within a reasonable time...firms must have started putting the plan into effect by Thursday 31 March 2022.” | SS1/21 §4.14 | final | Dated, board-approved prioritised remediation/implementation plan; evidence of programme initiation (e.g. project kick-off, resource allocation) by 31 March 2022. | |
OBL-01237 | Canada | CA_OSFI | business continuity | Identify critical operations and assess their ability to withstand disruptions; map all internal and external dependencies end to end, covering people, technology, processes, information, facilities, and third parties. “Critical operations should be identified and assessed for their ability to withstand disruptions... Once identified, critical operations should be mapped for internal and external dependencies.” | Guideline E-21, Section 3.1 | final | Written inventory of critical operations; dependency maps reviewed and updated regularly; documented financial-loss estimates for disruption scenarios. | |
OBL-01238 | Canada | CA_OSFI | business continuity | Establish tolerances for disruption for each critical operation, setting the maximum level of disruption the institution can withstand across a range of severe but plausible scenarios. “Tolerances for disruption should set out the maximum level of disruption a financial institution can withstand across a range of severe but plausible scenarios.” | Guideline E-21, Section 3.2 | final | Board/senior-management-approved tolerance statements per critical operation; documentation showing tolerances exceed risk appetite limits; periodic review records. | |
OBL-01239 | Canada | CA_OSFI | business continuity | Conduct regular scenario testing of critical operations against severe-but-plausible disruptions, using tabletop exercises, simulations, and live-systems testing, to assess whether operations can persist within tolerances for disruption. “Regular scenario testing improves understanding of when tolerances for disruption would be breached... a variety of testing methodologies should be used, including table-top exercises, simulations, and live-systems testing.” | Guideline E-21, Section 3.3 | final | Scenario testing schedule; test plans and results; gap analyses; board/senior-management reporting of results; iterative improvement records. | |
OBL-01240 | Canada | CA_OSFI | business continuity | Conduct business impact analyses to assess risks and potential impacts of disruptive events, identify the impact of disruptions, and establish maximum recovery objectives; review and update the analyses regularly. “A business impact analysis assesses the risks and potential impacts of a range of disruptive events on operations. It should identify and measure: The impact of disruptions. The maximum limits on recovery objectives before severe consequences or losses occur.” | Guideline E-21, Section 4.1.1 | final | Current BIA documentation with RTO/RPO thresholds; evidence of periodic review; linkage to BCP and scenario-testing programme. | |
OBL-01241 | Canada | CA_OSFI | business continuity | Develop business continuity plans (BCPs) covering response and recovery actions for a range of threats, including protocols for plan invocation, roles and responsibilities, backup personnel, staff safety, recovery targets, workarounds, and internal/external communication plans. “Business continuity plans set out the response and recovery actions for a range of potential threats... This should include: Establishing protocols for invoking the plan... Defining roles and responsibilities... Setting targets for recovery levels and times.” | Guideline E-21, Section 4.1.2 | final | Documented BCPs per critical operation/business unit; invocation protocols; communication templates; staff training records. | |
OBL-01242 | Canada | CA_OSFI | business continuity | Regularly test business continuity plans using scenarios that include long-duration and simultaneous disruptions involving critical third parties; address gaps identified and maintain contingency plans for critical third parties. “Business continuity plan tests should provide reasonable assurance that plans are effective... Tests should consider a range of severe but plausible circumstances, including scenarios with disruptions that: Are long in duration. Are simultaneous in nature. Involve critical third parties.” | Guideline E-21, Section 4.1.3 | final | BCP test schedule and results; after-action reports; gap-remediation tracking; evidence critical third parties demonstrated BCP robustness. | |
OBL-01244 | Canada | CA_OSFI | business continuity | Establish a crisis management plan with escalation protocols to senior management and the board, plan invocation criteria, internal and external communications protocols, and conduct regular testing and lessons-learned exercises. “A crisis management plan should be established that ensures effective, coordinated, and timely responses to potential crises... It should include: Protocols for escalation to senior management and the board. Criteria for invoking the plan. Internal and external communications protocols.” | Guideline E-21, Section 4.3 | final | Documented crisis management plan; escalation matrix; communications templates; test records; lessons-learned reports incorporated into plan updates. | |
OBL-01245 | Canada | CA_OSFI | business continuity | Maintain a senior-level crisis management team responsible for decision-making, coordination, and oversight of strategies to address crises affecting operations. “A crisis management team can help ensure effective communication, expedited recovery, and an effective response to the crisis.” | Guideline E-21, Section A5 (definition) and Section 4.3 | final | Terms of reference for crisis management team; membership list with seniority documented; records of activation and decision logs during incidents. | |
OBL-01246 | Canada | CA_OSFI | business continuity | Integrate business continuity risk management with operational resilience, evolving its focus from business processes to critical operations end to end, and including business impact analyses and tested BCPs. “Business continuity risk management is the process of planning for, and recovering from, disruptions to operations. It should be integrated with and strengthen operational resilience. Over time, its focus should evolve from business processes to critical operations end to end.” | Guideline E-21, Section 4.1 | final | Evidence of BCP integration with operational resilience programme; roadmap showing evolution toward end-to-end critical operations coverage. | |
OBL-01247 | Canada | CA_OSFI | business continuity | Provide staff with training on business continuity plans, including plan activation and management of operations during disruption. “Staff should be provided with training on business continuity plans, including their activation and how operations will be managed during disruption.” | Guideline E-21, Section 4.1.2 | final | Training completion records; training materials covering BCP activation; periodic refresher training schedule. | |
OBL-01248 | Canada | CA_OSFI | business continuity | Obtain sufficient information about critical third parties to assess their resilience, and coordinate with them to conduct broader resilience exercises where possible. “Where a third party is identified as critical, sufficient information should be obtained to assess its resilience... The financial institution should also coordinate with critical third parties, where possible, to conduct broader exercises.” | Guideline E-21, Sections 3.1 and 3.3 | final | Third-party resilience assessments; evidence of information gathered (e.g., audit reports, questionnaires); joint exercise records with critical third parties. | |
OBL-01249 | Canada | CA_OSFI | business continuity | Require critical third parties to demonstrate robustness in their own business continuity plans and testing, and maintain contingency plans for critical third-party failures. “Critical third parties should also demonstrate robustness in their own business continuity plans and testing. There should be processes to address gaps identified during testing, as well as contingency plans for critical third parties.” | Guideline E-21, Section 4.1.3 | final | Contractual BCP requirements for critical third parties; evidence of third-party BCP review/testing attestations; documented contingency/exit plans per critical third party. | |
OBL-01250 | Canada | CA_OSFI | business continuity | Implement a data risk management framework including a strategy and programme covering data governance, architecture, classification, integrity/availability controls, and processes for escalating and responding to data breaches and data-related incidents. [adjacent] “It should also comprise a specific data risk management framework that includes a data risk management strategy and program... Processes for escalating and responding to data breaches and other data-related incidents.” | Guideline E-21, Section 4.7 | final | Documented data risk management framework; data governance policy with roles; data architecture documentation; incident-response procedures for data breaches; training records. | |
OBL-01251 | Canada | CA_OSFI | business continuity | Ensure data supporting critical operations is accurate, complete, timely, secure, and protected, using methodologies that maintain integrity, adaptability, confidentiality, and availability throughout the data lifecycle. “Effective data risk management ensures that data is accurate, complete, timely, secure, and protected... Methodologies for ensuring the integrity, adaptability, confidentiality, and availability of data throughout its lifecycle.” | Guideline E-21, Section 4.7 | final | Data quality and availability metrics; documented lifecycle management controls; classification and protection policies; testing evidence for data availability under disruption scenarios. | |
OBL-01252 | Canada | CA_OSFI | business continuity | Embed effective technology and cyber risk management as a foundation of operational resilience, aligned with Guideline B-13, to prevent wide-scale operational disruption from technology failure, infiltration, or data loss. “A critical technology failure, infiltration, or loss of data can result in wide-scale disruption impacting operations. Sound technology and cyber risk management is fundamental to bolstering operational resilience.” | Guideline E-21, Section 4.5 | final | Technology and cyber risk management programme aligned with B-13; cyber incident response plans; resilience controls documentation; testing records. | |
OBL-01253 | Canada | CA_OSFI | business continuity | Manage third-party operational resilience risks (including disruption at a third party or loss/corruption of critical data) as part of operational resilience, aligned with Guideline B-10. “Threats to operational resilience can arise from critical third-party arrangements, including disruption at the third party or the loss or corruption of critical data. Accordingly, effective third-party risk management is an important contributor to operational resilience.” | Guideline E-21, Section 4.6 | final | Third-party risk register identifying critical arrangements; resilience due-diligence records; concentration risk analysis; B-10-aligned oversight documentation. | |
OBL-01254 | Canada | CA_OSFI | business continuity | Conduct scenario analysis at both business-unit and enterprise-wide levels using a range of severe but plausible scenarios; use results to inform operational resilience scenario testing. “Scenario analysis should be conducted using appropriate techniques at both the business unit and enterprise-wide levels and incorporate a range of severe but plausible scenarios... Scenario analysis results may be used to inform operational resilience scenario testing.” | Guideline E-21, Section 2.3.4 | final | Documented scenario analysis results; evidence of business-unit and enterprise-wide coverage; linkage records showing how results fed into Section 3.3 scenario testing. | |
OBL-01255 | Canada | CA_OSFI | business continuity | Ensure senior management and the board receive timely reports on operational resilience scenario testing results, including analysis of deficiencies, assessment of whether critical operations can be maintained within tolerances, and plans to address shortcomings. “Senior management and the board of directors should also receive the results of scenario analysis... and scenario testing... This should include: Analysis of deficiencies. An assessment of operational resilience, and whether critical operations can be maintained within established tolerances for dis” | Guideline E-21, Section 2.4.2 | final | Board and senior-management reporting templates; documented scenario testing reports presented to board; remediation tracking logs. | |
OBL-01256 | Canada | CA_OSFI | business continuity | Ensure breaches of tolerances for disruption are appropriately escalated to senior management and addressed in a timely and sustainable manner. “Ensuring breaches of tolerances for disruption are appropriately escalated and addressed.” | Guideline E-21, Section 1.1 | final | Escalation policy and procedures; log of tolerance breaches with escalation records; evidence of corrective actions taken and closed. | |
OBL-01257 | Canada | CA_OSFI | business continuity | Perform change management assessments for significant operational changes (new products, acquisitions, new tech systems, process changes), including deploying tested contingency plans if a change fails and testing changes before implementation. “Deploy tested contingency plans in the event a change fails. Test the change on systems and processes before introducing it.” | Guideline E-21, Section 4.4 | final | Change management policy; operational risk assessments for significant changes; tested contingency/rollback plans; pre-implementation test results; post-implementation effectiveness metrics. | |
OBL-01258 | Canada | CA_OSFI | business continuity | Conduct ongoing monitoring of adherence to tolerances for disruption and operational risk limits, using comprehensive metrics; ensure key risk indicators include escalation protocols when risk levels approach or exceed limits. “Ongoing monitoring should be conducted to help prepare for, and respond to, changes in operational risks. It should assess adherence to the operational risk appetite statement and operational risk limits, as well as tolerances for disruption.” | Guideline E-21, Sections 2.4.1 and 2.3.2 | final | KRI dashboard including tolerance-for-disruption metrics; documented escalation thresholds; monitoring reports; records of management actions taken when thresholds breached. | |
OBL-01259 | Canada | CA_OSFI | business continuity | Capture and analyse operational risk event data (actual, potential, and near-misses) to determine root causes, contributing risk categories, and corrective measures; use findings to strengthen resilience controls. “Operational risk event data exceeding established limits should be captured to assess: What the root cause of the operational risk event is... What corrective measures ought to be taken to address deficiencies or control failures.” | Guideline E-21, Section 2.3.3 | final | Operational risk event database including near-misses; root-cause analysis records; corrective action logs; trend reporting to senior management. | |
OBL-01260 | Canada | CA_OSFI | business continuity | Ensure independent risk and compliance functions oversee and challenge resilience activities, including escalation channels for significant issues, and that internal audit provides independent assurance on operational risk management controls and systems. “The independent risk and compliance functions oversee and challenge the risk and resilience activities... Internal audit or a similar function should provide independent assurance to senior management and the board of directors that operational risk management controls, policies and procedures, and ” | Guideline E-21, Sections 1.3 and 1.4 | final | Internal audit plan covering ORM and resilience; audit reports; issue-tracking logs; documented escalation channels; second-line challenge records. | |
OBL-01261 | Canada | CA_OSFI | business continuity | Conduct lessons-learned exercises following a crisis and incorporate findings into the crisis management plan; share the plan with relevant business units and impacted external parties. “Lessons-learned exercises should be undertaken following a crisis and incorporated into the plan. The crisis management plan should be regularly tested and shared with the relevant business units in the financial institution and any impacted external parties, as appropriate.” | Guideline E-21, Section 4.3 | final | Post-crisis lessons-learned reports; evidence of plan updates; distribution records showing plan shared with business units and external parties; test schedules and results. | |
OBL-01262 | United States | OCC | crisis management | Banking organizations must notify their primary Federal regulator of any computer-security incident that rises to the level of a notification incident as soon as possible and no later than 36 hours after determining the incident occurred. “a banking organization must notify its primary Federal regulator of any computer-security incident that rises to the level of a notification incident as soon as possible and no later than 36 hours after the banking organization determines that a notification incident has occurred.” | 12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.A | final | Written incident response procedure with 36-hour notification SLA; incident log with timestamps of determination and notification; sample notifications to primary Federal regulator; after-action reports. | |
OBL-01263 | United States | OCC | crisis management | Bank service providers must notify at least one bank-designated point of contact at each affected banking organization customer as soon as possible when the bank service provider determines it has experienced a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, c “the final rule requires a bank service provider to notify at least one bank-designated point of contact at each affected banking organization customer as soon as possible when the bank service provider determines it has experienced a computer-security incident that has caused, or is reasonably likel” | 12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.A | final | Notification procedures referencing bank-designated contacts; incident logs with determination timestamps; evidence of as-soon-as-possible notifications to banking organization customers; service agreements identifying points of contact. | |
OBL-01264 | United States | OCC | crisis management | Banking organizations must have sufficient understanding of their lines of business to determine which business lines, upon failure, would result in a material loss of revenue, profit, or franchise value, in order to identify notification incidents. [adjacent] “all banking organizations must have a sufficient understanding of their lines of business to be able to determine which business lines would, upon failure, result in a material loss of revenue, profit, or franchise value to the banking organization, so that they can meet their notification obligatio” | 12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.B.iv | final | Documented inventory of core business lines with materiality assessments; board or senior management approval; mapping of business lines to notification incident thresholds. | |
OBL-01266 | United States | OCC | crisis management | Banking organizations must apply a 'reasonably likely' materiality standard when determining whether a computer-security incident constitutes a notification incident requiring regulator notification, covering incidents that have materially disrupted or degraded or are reasonably likely to do so. “a banking organization will be required to notify its primary Federal regulator when it has suffered a computer-security incident that has a reasonable likelihood of materially disrupting or degrading the banking organization or its operations.” | 12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.B.iv | final | Written decision criteria/playbook defining 'reasonably likely' threshold; documented incident classification rationale; training records for staff making notification determinations. | |
OBL-01267 | United States | OCC | crisis management | Banking organizations must evaluate whether a material loss of revenue, profit, or franchise value resulting from a computer-security incident is material on an enterprise-wide basis when assessing notification incident status under the second prong of the definition. “a banking organization should evaluate whether the loss is material to the organization as a whole.” | 12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.B.iv | final | Enterprise-wide materiality assessment methodology; documented incident evaluations referencing enterprise-level impact; internal policies on materiality thresholds. | |
OBL-01268 | United States | OCC | crisis management | Bank service providers must ensure their notification to banking organization customers is directed to a bank-designated point of contact rather than an arbitrary individual, requiring coordination with banking organization customers to establish and maintain those contact designations. “requiring that notice be provided to a bank-designated point of contact, rather than to at least two individuals at each banking organization customer.” | 12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.A and III.D.iii | final | Maintained and current list of bank-designated notification contacts per customer; contractual or operational records reflecting designated contacts; notification test records. | |
OBL-01269 | United States | OCC | crisis management | Banking organizations and bank service providers must determine whether a computer-security incident has occurred based on a determination standard (not a subjective good-faith belief), requiring documented incident assessment processes. “the agencies are replacing the 'good faith belief' standard with a banking organization's determination. The agencies agree with commenters who criticized the proposed 'believes in good faith' standard as too subjective and imprecise.” | 12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.B.iv | final | Documented incident determination procedures; records of each determination with supporting evidence; audit trail showing when determination was made and by whom. | |
OBL-01270 | United States | OCC | crisis management | Banking organizations must be capable of identifying computer-security incidents that materially disrupt or degrade (or are reasonably likely to do so) their ability to carry out banking operations or deliver products/services to a material portion of their customer base in the ordinary course of business. “Ability to carry out banking operations, activities, or processes, or deliver banking products and services to a material portion of its customer base, in the ordinary course of business.” | 12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.B.iv | final | Incident classification framework with defined thresholds for customer-base impact; customer access monitoring tools; documented escalation procedures for customer-facing service disruptions. | |
OBL-01271 | United States | OCC | crisis management | Banking organizations must be capable of identifying notification incidents that impact operations whose failure or discontinuance would pose a threat to the financial stability of the United States (the third prong of the notification incident definition). “operations, including associated services, functions and support, as applicable, the failure or discontinuance of which would pose a threat to the financial stability of the United States.” | 12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.B.iv | final | Documented identification of systemically important operations; impact analysis; linkage to resolution plan critical operations where applicable; board-approved classification. | |
OBL-01272 | United States | OCC | crisis management | Banking organizations that provide sector-critical services and currently notify their primary Federal regulator of computer-security incidents on a same-day basis are encouraged to continue doing so (supervisory expectation). “the agencies would encourage those banking organizations providing sector-critical services that currently notify their primary Federal regulator of these types of incidents on a same-day basis to continue to do so.” | 12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.A (footnote 19) | final | Incident response policy documenting same-day notification expectation for sector-critical service providers; notification logs demonstrating same-day practice. | |
OBL-01273 | United States | OCC | crisis management | Bank service providers must have procedures to determine when a computer-security incident has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, covered services to banking organization customers for four or more hours, triggering the notification obligation. “when the bank service provider determines it has experienced a computer-security incident that has caused, or is reasonably likely to cause, a material service disruption or degradation for four or more hours.” | 12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.D.ii | final | Documented incident response procedures with four-hour service degradation trigger; service monitoring and duration-tracking tools; incident classification logs; sample notifications. | |
OBL-01274 | United States | OCC | crisis management | Banking organizations must assess whether a computer-security incident at a bank service provider has or is reasonably likely to have a material impact on the banking organization, potentially triggering the banking organization's own notification requirement to its regulator. “prompt notification will allow the banking organization to assess whether the incident has or is reasonably likely to have a material impact on the banking organization and thus trigger the banking organization's own notification requirement.” | 12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule, Introduction and Section III.D.i | final | Third-party incident intake and assessment procedure; documented escalation criteria; records of assessments following receipt of bank service provider notifications. | |
OBL-01275 | United States | OCC | crisis management | Banking organizations and bank service providers must ensure that contracts with bank service providers address notification provisions consistent with the final rule, so that banking organizations receive prompt notification of computer-security incidents affecting covered services. “while the agencies agree that incident notification is generally addressed by contract, we believe that this issue is important enough to warrant an independent regulatory requirement that ensures consistency and enforceability, without the necessity of revising contractual provisions.” | 12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.D.iv | final | Contract inventory with review of notification provisions; updated contract templates meeting final rule standards; evidence of renegotiation or addenda for non-compliant contracts. | |
OBL-01276 | United States | OCC | crisis management | Banking organizations must identify and monitor their critical dependence on bank service providers for essential services and ensure operational resilience by receiving timely notification of computer-security incidents at those providers that could disrupt covered services. “banking organizations have become increasingly reliant on third parties to provide essential services. Such third parties may also experience computer-security incidents that could disrupt or degrade the provision of services to their banking organization customers.” | 12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.D.i | final | Inventory of critical bank service providers and covered services; third-party risk monitoring program; documented escalation procedures upon receipt of service provider incident notifications. | |
OBL-01564 | United States | OCC | crisis management | Notify the appropriate OCC supervisory office as soon as possible and no later than 36 hours after determining that a notification incident has occurred. “The OCC must receive this notification from the banking organization as soon as possible and no later than 36 hours after the banking organization determines that a notification incident has occurred.” | 12 CFR 53.3 | final | Incident log documenting time of determination and time of OCC notification; records of email/telephone contact with OCC supervisory office; written incident notification records. | |
OBL-01565 | United States | OCC | crisis management | Notify the OCC via email, telephone, or other OCC-prescribed methods upon occurrence of a notification incident. “A banking organization must notify the appropriate OCC supervisory office, or OCC-designated point of contact, about a notification incident through email, telephone, or other similar methods that the OCC may prescribe.” | 12 CFR 53.3 | final | Documented communication channel procedures for OCC notification; records of actual notifications sent; contact directory for OCC supervisory office. | |
OBL-01566 | United States | OCC | crisis management | Monitor for and determine when a computer-security incident constitutes a 'notification incident' — i.e., one that has materially disrupted or is reasonably likely to materially disrupt banking operations, business lines, or critical operations. “Notification incident is a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, a banking organization's— (i) Ability to carry out banking operations...in the ordinary course of business...” | 12 CFR 53.2(b)(7) | final | Documented criteria/thresholds for classifying incidents as notification incidents; incident triage records; escalation decision logs. | |
OBL-01567 | United States | OCC | crisis management | Bank service providers must notify at least one bank-designated point of contact at each affected banking organization customer as soon as possible when a computer-security incident has materially disrupted or degraded covered services for four or more hours. “A bank service provider is required to notify at least one bank-designated point of contact at each affected banking organization customer as soon as possible when the bank service provider determines that it has experienced a computer-security incident that has materially disrupted or degraded, or ” | 12 CFR 53.4(a) | final | Notification records to banking organization contacts; incident logs with timestamps; contractual or operational records of bank-designated contact information. | |
OBL-01568 | United States | OCC | crisis management | Bank service providers must notify the CEO and CIO (or comparable individuals) of the banking organization customer when no bank-designated point of contact has been previously provided. “If the banking organization customer has not previously provided a bank-designated point of contact, such notification shall be made to the Chief Executive Officer and Chief Information Officer of the banking organization customer, or two individuals of comparable responsibilities, through any reaso” | 12 CFR 53.4(a)(2) | final | Fallback contact directory including CEO/CIO details; notification logs; records demonstrating reasonable means of contact attempted. | |
OBL-01569 | United States | OCC | crisis management | Banking organizations must provide bank service providers with a designated point of contact (email, phone, or other contact) to receive incident notifications. “A bank-designated point of contact is an email address, phone number, or any other contact(s), previously provided to the bank service provider by the banking organization customer.” | 12 CFR 53.4(a)(1) | final | Records of designated contact information communicated to each bank service provider; contract provisions or vendor management records confirming contact details on file. | |
OBL-01570 | United States | OCC | business continuity | Maintain a complete inventory of all third-party relationships and periodically conduct risk assessments for each to determine whether risks have changed and update risk management practices accordingly. [adjacent] “Maintaining a complete inventory of its third-party relationships and periodically conducting risk assessments for each third-party relationship supports a banking organization's determination of whether risks have changed over time” | Interagency TPRM Guidance 2023, Section B (Risk Management) | proposed | Third-party inventory log; dated risk assessment records per relationship; documented updates to risk management practices when risks change | |
OBL-01571 | United States | OCC | business continuity | Apply more comprehensive and rigorous oversight and management to third-party relationships that support higher-risk or critical activities, including those that could cause significant operational disruption. “banking organizations engage in more comprehensive and rigorous oversight and management of third-party relationships that support higher-risk activities, including critical activities.” | Interagency TPRM Guidance 2023, Section B (Risk Management) | proposed | Risk-tiering methodology; documented critical-activity designations; enhanced monitoring plans and controls for critical-activity third parties | |
OBL-01572 | United States | OCC | business continuity | During planning, identify and assess risks associated with a contemplated third-party relationship—including operational risks—before entering the relationship, with board approval for critical activities. [adjacent] “effective planning allows a banking organization to evaluate and consider how to manage risks before entering into a third-party relationship... when critical activities are involved, plans may be presented to and approved by a banking organization's board of directors” | Interagency TPRM Guidance 2023, Section C.1 (Planning) | proposed | Pre-engagement risk assessment documents; board/committee approval records for critical-activity arrangements; documented risk appetite alignment | |
OBL-01574 | United States | OCC | business continuity | During due diligence, assess a third party's incident response and management capabilities, including how it handles and reports security or operational incidents. “incident response and management, including the third party's ability to respond to and recover from incidents that could disrupt operations” | Interagency TPRM Guidance 2023, Section C.2 (Due Diligence and Third-Party Selection) | proposed | Due diligence records evidencing review of third-party incident response plans; historical incident logs requested and reviewed; findings documented | |
OBL-01575 | United States | OCC | business continuity | During due diligence, assess a third party's information security program, including controls protecting the confidentiality, integrity, and availability of systems and data critical to the banking organization's operations. “information security, including the third party's information security program and its ability to protect the banking organization's systems, data, and customers” | Interagency TPRM Guidance 2023, Section C.2 (Due Diligence and Third-Party Selection) | proposed | Due diligence records with infosec review; SOC 2/ISO 27001 reports or equivalents reviewed; penetration test summaries; risk rating documented | |
OBL-01576 | United States | OCC | business continuity | During due diligence, evaluate a third party's operational resilience, including its ability to withstand and recover from disruptions to the services it provides. “operational resilience, including the third party's ability to withstand and recover from disruptions” | Interagency TPRM Guidance 2023, Section C.2 (Due Diligence and Third-Party Selection) | proposed | Due diligence file documenting resilience assessment; review of third-party RTO/RPO metrics; evidence of testing; risk-acceptance sign-off if gaps identified | |
OBL-01578 | United States | OCC | business continuity | Include in contracts provisions for incident notification, requiring the third party to promptly notify the banking organization of disruptions or incidents affecting the services provided. “incident notification, requiring the third party to promptly notify the banking organization of any incidents that may affect the third party's ability to provide the contracted services” | Interagency TPRM Guidance 2023, Section C.3 (Contract Negotiation) | proposed | Contract clauses mandating incident notification with defined timeframes; incident notification log; records of notifications received and actions taken | |
OBL-01579 | United States | OCC | business continuity | Include in contracts provisions that define service-level agreements (SLAs) for recovery time and availability, ensuring services can be restored within acceptable timeframes following a disruption. “performance standards and service level agreements, including measurable standards for performance and consequences for failure to meet the standards” | Interagency TPRM Guidance 2023, Section C.3 (Contract Negotiation) | proposed | Contracts with defined SLAs including uptime/availability and recovery metrics; SLA monitoring reports; records of breach remediation | |
OBL-01580 | United States | OCC | business continuity | Include in contracts provisions granting the banking organization rights to audit the third party's controls, including those related to business continuity and information security. “audit and examination rights, including the right to conduct audits and examinations of the third party and its subcontractors” | Interagency TPRM Guidance 2023, Section C.3 (Contract Negotiation) | proposed | Contract audit-rights clauses; records of audits conducted or review of third-party audit reports; findings and remediation tracking | |
OBL-01581 | United States | OCC | business continuity | Include in contracts provisions for orderly termination and business continuity, ensuring the banking organization can transition services or wind down the relationship without disruption to operations. “default and termination rights, including the ability of the banking organization to terminate the contract and transition the activities to another third party or in-house” | Interagency TPRM Guidance 2023, Section C.3 (Contract Negotiation) | proposed | Contract termination-transition clauses; documented exit/transition plans for critical activities; evidence of contingency vendor identification | |
OBL-01582 | United States | OCC | business continuity | During ongoing monitoring, monitor a third party's business continuity and disaster recovery capabilities, including reviewing BCP/DR test results on a periodic basis. “ongoing monitoring should include reviewing the third party's business continuity and disaster recovery capabilities, including test results” | Interagency TPRM Guidance 2023, Section C.4 (Ongoing Monitoring) | proposed | Periodic monitoring records with BCP/DR review; third-party test results on file; escalation log where deficiencies identified | |
OBL-01583 | United States | OCC | business continuity | During ongoing monitoring, monitor a third party's information security and incident response capabilities and track incidents that could affect the banking organization's operations. “information security, including monitoring changes to the third party's security controls and any security incidents that may affect the banking organization” | Interagency TPRM Guidance 2023, Section C.4 (Ongoing Monitoring) | proposed | Monitoring reports tracking security incidents; change-control notifications from third parties; incident log with banking organization response actions | |
OBL-01584 | United States | OCC | business continuity | During ongoing monitoring, assess changes in third-party concentration risk, including reliance on a single third party for critical services and potential impacts on operational continuity. “concentration risk, including assessing the banking organization's reliance on a single third party for critical activities and the potential impact on the banking organization's operations” | Interagency TPRM Guidance 2023, Section C.4 (Ongoing Monitoring) | proposed | Concentration risk assessments; list of single-source critical services; documented contingency plans or alternative provider identification | |
OBL-01585 | United States | OCC | business continuity | Develop and maintain contingency plans for terminating a critical third-party relationship, ensuring the banking organization can continue operations if the third party fails or the relationship must be ended. “maintaining contingency plans for terminating the relationship, including identifying and transitioning to alternative third parties or moving the activities in-house” | Interagency TPRM Guidance 2023, Section C.5 (Termination) | proposed | Documented termination/contingency plans per critical third party; alternative provider shortlists; tested transition procedures; board or senior management sign-off | |
OBL-01586 | United States | OCC | business continuity | Evaluate a third party's use of subcontractors to determine whether subcontracting arrangements may heighten operational or resilience risks to the banking organization, and apply mitigating controls as appropriate. “assessing whether a third party's use of subcontractors may heighten or raise additional risk to the banking organization and applying mitigating factors, as appropriate” | Interagency TPRM Guidance 2023, Section F (Subcontractors discussion / Section C.2) | proposed | Subcontractor risk assessment records; contract provisions requiring third party to manage subcontractor resilience; evidence of review of subcontractor BCP/DR | |
OBL-01587 | United States | OCC | business continuity | Ensure third-party contracts include provisions requiring subcontractors to adhere to the same operational resilience and security standards as the primary third party. “require the third party to bind its subcontractors to any obligations and standards of the third party” | Interagency TPRM Guidance 2023, Section C.3 (Contract Negotiation) / Subcontractors | proposed | Contract flow-down clauses binding subcontractors to resilience/security standards; evidence of third-party subcontractor oversight program review | |
OBL-01588 | United States | OCC | business continuity | Conduct independent reviews of third-party risk management processes, including effectiveness of controls related to operational resilience and business continuity for critical third-party relationships. “independent reviews of the banking organization's third-party risk management processes and controls, including those related to critical activities” | Interagency TPRM Guidance 2023, Section D.2 (Independent Reviews) | proposed | Independent audit/review reports covering TPRM resilience controls; findings and remediation tracking; frequency aligned to risk level | |
OBL-01589 | United States | OCC | business continuity | Establish board and senior management oversight of third-party risk management, including approval of policies addressing operational resilience risks from third-party relationships. “the board has ultimate oversight responsibility to ensure that the banking organization operates in a safe and sound manner... senior management implements the board-approved policies” | Interagency TPRM Guidance 2023, Section D.1 (Oversight and Accountability) | proposed | Board-approved TPRM policy including resilience provisions; board meeting minutes evidencing oversight; senior management accountability documentation | |
OBL-01590 | United States | OCC | business continuity | Maintain documentation and reporting sufficient to demonstrate effective management of operational resilience risks across the third-party relationship life cycle, for review by examiners. “documentation and reporting sufficient to support the banking organization's third-party risk management processes and to facilitate examination by the agencies” | Interagency TPRM Guidance 2023, Section D.3 (Documentation and Reporting) | proposed | Repository of TPRM records: risk assessments, due diligence files, contracts, monitoring reports, BCP/DR reviews, incident logs, independent review findings | |
OBL-01591 | United States | OCC | business continuity | When a banking organization cannot obtain adequate information to assess a third party's resilience capabilities, take steps to mitigate the resulting risk or determine whether residual risk is within the organization's risk appetite. “banking organizations should consider taking steps to mitigate the risks or, if the risks cannot be mitigated, to determine whether the residual risks are acceptable” | Interagency TPRM Guidance 2023, Section C.2 (Due Diligence) / Section II.E.1 | proposed | Documented risk-acceptance decisions; evidence of risk mitigation measures implemented; escalation to senior management or board where risk exceeds appetite | |
OBL-01592 | United States | OCC | business continuity | Assess concentration risk arising from reliance on a limited number of third-party providers in highly concentrated industries (e.g., cloud computing) and consider alternative arrangements to mitigate operational continuity risk. “asked for additional flexibility for banking organizations to manage relationships with third parties in relatively concentrated industries, mentioning cloud computing as an example” | Interagency TPRM Guidance 2023, Section II.D / Section C.4 (Ongoing Monitoring) | proposed | Concentration risk analysis per service category; documented alternative provider assessments; board or management reporting on concentration risk | |
OBL-01593 | United States | OCC | business continuity | Ensure that use of collaborative due diligence arrangements or third-party assessment utilities does not abrogate the banking organization's own responsibility to assess and manage operational resilience risks of critical third parties. “use of any collaborative efforts does not abrogate the responsibility of banking organizations to manage third-party relationships in a safe and sound manner... evaluate the conclusions from such collaborative efforts based on the banking organization's own specific circumstances” | Interagency TPRM Guidance 2023, Section II.E.1 (Due Diligence / Collaborative Arrangements) | proposed | Records of independent evaluation of shared due diligence outputs; supplemental assessments where shared results are insufficient for resilience review | |
OBL-01594 | United States | OCC | business continuity | Involve staff with requisite technical expertise—including technology, risk, and compliance specialists—at each stage of the third-party relationship life cycle to effectively assess and manage operational resilience risks. “It is important to involve staff with the requisite knowledge and skills in each stage of the risk management life cycle... experts across disciplines, such as compliance, risk, or technology, as well as legal counsel” | Interagency TPRM Guidance 2023, Section C (Third-Party Relationship Life Cycle) | proposed | Evidence of cross-functional TPRM team involvement; documented roles and responsibilities; records of specialist engagement for high-risk relationships | |
OBL-01625 | United States (CA) | CA_PRIVACY | cybersecurity | Establish and maintain a cybersecurity program consisting of policies, procedures, and practices that protect personal information from unauthorized access, destruction, use, modification, or disclosure, and protect against loss of availability of personal information. [adjacent] “"Cybersecurity program" means the policies, procedures, and practices that protect personal information from unauthorized access, destruction, use, modification, or disclosure; and protect against unauthorized activity resulting in the loss of availability of personal information.” | § 7001(k) | final | Written cybersecurity program documentation covering all enumerated protections; policies and procedures manual; evidence of implementation and periodic review. | |
OBL-01627 | United States (CA) | CA_PRIVACY | cybersecurity | Create a cybersecurity audit report documenting the required information for each completed annual cybersecurity audit. [adjacent] “"Cybersecurity audit report" means the document that every business must create as part of its cybersecurity audit. The cybersecurity audit report includes the information set forth in section 7123, subsection (e).” | § 7001(l) | final | Completed cybersecurity audit report containing all elements specified in § 7123(e); version history showing annual updates. | |
OBL-01629 | United States (CA) | CA_PRIVACY | cybersecurity | Conduct penetration testing of information systems by authorizing attempted circumvention or defeat of security features to identify vulnerabilities that could compromise availability or security of personal information. [adjacent] “"Penetration testing" means testing the security of an information system by attempting to circumvent or defeat its security features by authorizing attempted penetration of the information system.” | § 7001(bb) | final | Penetration testing authorization letters; test reports with findings and remediation tracking; schedule showing periodic conduct of testing. | |
OBL-01630 | United States (CA) | CA_PRIVACY | cybersecurity | Manage and control privileged accounts to prevent unauthorized configuration changes or unauthorized access that could affect availability and security of personal information. [adjacent] “"Privileged account" means any authorized user account or service account that can be used to perform functions that other user accounts are not authorized to perform, including but not limited to the ability to add, change, or remove other accounts, or make configuration changes to an information s” | § 7001(hh) | final | Privileged account inventory; access control policy; periodic access reviews/recertification records; audit logs for privileged account activity. | |
OBL-01631 | United States (CA) | CA_PRIVACY | cybersecurity | Scope the business's information system (including third-party-owned resources used for processing personal information) within the cybersecurity program and audit, addressing risks to all such resources. [adjacent] “"Information system" means the resources (e.g., network, hardware, and software) organized for the processing of personal information or that can provide access to personal information. The business's information system includes the resources organized for the business's processing of personal infor” | § 7001(t) | final | Asset inventory including third-party-hosted resources; contractual evidence of security requirements imposed on third-party providers; audit scope documentation. | |
OBL-01725 | United States | OCC | business continuity | Implement a comprehensive written information security program with administrative, technical, and physical safeguards appropriate to the institution's size, complexity, and activities. [adjacent] “Each national bank or Federal savings association shall implement a comprehensive written information security program that includes administrative, technical, and physical safeguards appropriate to the size and complexity” | 12 CFR 30 Appendix B, Section II.A | final | Board-approved written information security program document; evidence of annual review and updates; program scope documentation covering all business lines. | |
OBL-01726 | United States | OCC | business continuity | Board of directors must approve the written information security program and oversee its development, implementation, and maintenance, including assigning specific responsibility. [adjacent] “The board of directors or an appropriate committee of the board of each national bank or Federal savings association shall: 1. Approve the national bank's or Federal savings association's written information security program; and 2. Oversee the development, implementation, and maintenance” | 12 CFR 30 Appendix B, Section III.A | final | Board or committee meeting minutes approving ISP; documented assignment of implementation responsibility; board reporting records. | |
OBL-01727 | United States | OCC | business continuity | Identify reasonably foreseeable internal and external threats that could result in unauthorized disclosure, misuse, alteration, or destruction of customer information or customer information systems. [adjacent] “Identify reasonably foreseeable internal and external threats that could result in unauthorized disclosure, misuse, alteration, or destruction of customer information or customer information systems.” | 12 CFR 30 Appendix B, Section III.B.1 | final | Documented threat identification and risk assessment reports; inventory of customer information systems; records of threat analysis reviews. | |
OBL-01728 | United States | OCC | business continuity | Assess the likelihood and potential damage of identified threats, taking into consideration the sensitivity of customer information. “Assess the likelihood and potential damage of these threats, taking into consideration the sensitivity of customer information.” | 12 CFR 30 Appendix B, Section III.B.2 | final | Risk assessment documentation with likelihood and impact ratings; sensitivity classification of customer information; risk register or equivalent artifact. | |
OBL-01729 | United States | OCC | business continuity | Design information security program controls commensurate with information sensitivity and the complexity and scope of the institution's activities, including monitoring for attacks and intrusions into customer information systems. [adjacent] “Monitoring systems and procedures to detect actual and attempted attacks on or intrusions into customer information systems;” | 12 CFR 30 Appendix B, Section III.C.1.f | final | Documented monitoring controls (IDS/IPS, SIEM logs); evidence of real-time or near-real-time alerting capability; records of detected intrusion attempts and responses. | |
OBL-01730 | United States | OCC | business continuity | Implement response programs specifying actions to be taken when unauthorized access to customer information systems is suspected or detected, including reports to regulatory and law enforcement agencies. “Response programs that specify actions to be taken when the national bank or Federal savings association suspects or detects that unauthorized individuals have gained access to customer information systems, including appropriate reports to regulatory and law enforcement agencies;” | 12 CFR 30 Appendix B, Section III.C.1.g | final | Written incident response plan; documented escalation and notification procedures; records of prior regulatory/law enforcement notifications. | |
OBL-01731 | United States | OCC | business continuity | Implement measures to protect customer information against destruction, loss, or damage due to environmental hazards such as fire, water damage, or technological failures. “Measures to protect against destruction, loss, or damage of customer information due to potential environmental hazards, such as fire and water damage or technological failures.” | 12 CFR 30 Appendix B, Section III.C.1.h | final | Business continuity/disaster recovery plan addressing environmental hazards; data backup policies; evidence of offsite backups; environmental controls documentation. | |
OBL-01732 | United States | OCC | business continuity | Regularly test key controls, systems, and procedures of the information security program, with tests conducted or reviewed by independent third parties or independent staff. [adjacent] “Regularly test the key controls, systems and procedures of the information security program. The frequency and nature of such tests should be determined by the national bank's or Federal savings association's risk assessment. Tests should be conducted or reviewed by independent third parties or staf” | 12 CFR 30 Appendix B, Section III.C.3 | final | Risk-based testing schedule; penetration test and vulnerability assessment reports; evidence of independent reviewer involvement; tracking of remediation actions. | |
OBL-01733 | United States | OCC | business continuity | Exercise appropriate due diligence in selecting service providers that handle customer information. [adjacent] “Exercise appropriate due diligence in selecting its service providers;” | 12 CFR 30 Appendix B, Section III.D.1 | final | Third-party due diligence records; pre-contract security assessments; vendor risk scoring documentation. | |
OBL-01734 | United States | OCC | business continuity | Require service providers by contract to implement appropriate security measures meeting the objectives of the Information Security Guidelines. [adjacent] “Require its service providers by contract to implement appropriate measures designed to meet the objectives of these Guidelines;” | 12 CFR 30 Appendix B, Section III.D.2 | final | Service provider contracts with security requirements clauses; contract review checklist; inventory of covered service providers. | |
OBL-01735 | United States | OCC | business continuity | Monitor service providers, where indicated by risk assessment, to confirm they have satisfied their contractual security obligations, including reviewing audits, test summaries, or equivalent evaluations. “Where indicated by the national bank's or Federal savings association's risk assessment, monitor its service providers to confirm that they have satisfied their obligations as required by section D.2. As part of this monitoring, a national bank or Federal savings association should review audits, su” | 12 CFR 30 Appendix B, Section III.D.3 | final | Third-party monitoring program; SOC 2 reports or equivalent; records of annual or periodic reviews; escalation logs for deficiencies. | |
OBL-01736 | United States | OCC | business continuity | Monitor, evaluate, and adjust the information security program in light of changes in technology, information sensitivity, internal/external threats, and changing business arrangements such as outsourcing. [adjacent] “Each national bank or Federal savings association shall monitor, evaluate, and adjust, as appropriate, the information security program in light of any relevant changes in technology, the sensitivity of its customer information, internal or external threats to information, and the national bank's or” | 12 CFR 30 Appendix B, Section III.E | final | Program change log; records of periodic program reviews triggered by technology or business changes; documented update approvals. | |
OBL-01737 | United States | OCC | business continuity | Report to the board or appropriate committee at least annually on the overall status of the information security program, including risk assessment, control decisions, service provider arrangements, test results, security breaches, and program recommendations. [adjacent] “Each national bank or Federal savings association shall report to its board or an appropriate committee of the board at least annually. This report should describe the overall status of the information security program...risk assessment; risk management and control decisions; service provider arrang” | 12 CFR 30 Appendix B, Section III.F | final | Annual board/committee ISP report; meeting minutes evidencing presentation and receipt; documentation of breach summaries and remediation actions. | |
OBL-01738 | United States | OCC | business continuity | Develop and implement a risk-based response program to address incidents of unauthorized access to customer information in customer information systems, including systems maintained by service providers. [adjacent] “every financial institution should also develop and implement a risk-based response program to address incidents of unauthorized access to customer information in customer information systems that occur nonetheless. A response program should be a key part of an institution's information security pro” | 12 CFR 30 Appendix B, Supplement A, Section II | final | Written incident response program; documented risk-based procedures; evidence of testing and tabletop exercises; coverage of service provider-hosted systems. | |
OBL-01739 | United States | OCC | business continuity | Response program must include procedures to assess the nature and scope of an incident and identify which customer information systems and types of customer information have been accessed or misused. “Assessing the nature and scope of an incident, and identifying what customer information systems and types of customer information have been accessed or misused;” | 12 CFR 30 Appendix B, Supplement A, Section II.A.1.a | final | Incident response playbook with scope-assessment procedures; incident investigation records; data classification inventory supporting impact analysis. | |
OBL-01740 | United States | OCC | business continuity | Notify the primary Federal regulator as soon as possible when the institution becomes aware of an incident involving unauthorized access to or use of sensitive customer information. [adjacent] “Notifying its primary Federal regulator as soon as possible when the institution becomes aware of an incident involving unauthorized access to or use of sensitive customer information, as defined below;” | 12 CFR 30 Appendix B, Supplement A, Section II.A.1.b | final | Regulatory notification log; documented escalation triggers; records of prior notifications; time-stamped communications to OCC. | |
OBL-01742 | United States | OCC | business continuity | Take appropriate steps to contain and control an incident to prevent further unauthorized access, including monitoring, freezing, or closing affected accounts while preserving records and evidence. “Taking appropriate steps to contain and control the incident to prevent further unauthorized access to or use of customer information, for example, by monitoring, freezing, or closing affected accounts, while preserving records and other evidence;” | 12 CFR 30 Appendix B, Supplement A, Section II.A.1.d | final | Containment procedures in incident response plan; documented containment actions in post-incident reports; evidence preservation policy. | |
OBL-01744 | United States | OCC | business continuity | Require service providers by contract to notify the institution as soon as possible of any incident of unauthorized access to the institution's customer information to enable expeditious implementation of the institution's response program. “an institution's contract with its service provider should require the service provider to take appropriate actions to address incidents of unauthorized access to the financial institution's customer information, including notification to the institution as soon as possible of any such incident, to ” | 12 CFR 30 Appendix B, Supplement A, Section II | final | Service provider contracts with incident notification clauses; contract inventory; sample notification SLAs; records of provider incident reports received. | |
OBL-01745 | United States | OCC | business continuity | Retain responsibility for notifying customers and the regulator when an unauthorized access incident involves customer information in service provider systems, even if the institution contracts the notification function to the service provider. [adjacent] “Where an incident of unauthorized access to customer information involves customer information systems maintained by an institution's service providers, it is the responsibility of the financial institution to notify the institution's customers and regulator. However, an institution may authorize or” | 12 CFR 30 Appendix B, Supplement A, Section II.A.2 | final | Documented accountability framework for service provider incidents; oversight procedures for delegated notification; contract clauses for provider-led notification. | |
OBL-01746 | United States | OCC | business continuity | Train staff to implement the institution's information security program. [adjacent] “Train staff to implement the national bank's or Federal savings association's information security program.” | 12 CFR 30 Appendix B, Section III.C.2 | final | Training program documentation; completion records showing staff trained on ISP; curriculum covering incident response and security procedures. | |
OBL-01747 | United States | OCC | business continuity | Assess the sufficiency of existing policies, procedures, customer information systems, and other arrangements in place to control identified risks. “Assess the sufficiency of policies, procedures, customer information systems, and other arrangements in place to control risks.” | 12 CFR 30 Appendix B, Section III.B.3 | final | Gap analysis documentation; control effectiveness assessments; risk assessment reports referencing current control inventory. | |
OBL-01749 | United States | OCC | business continuity | Ensure trained personnel and reasonable policies and procedures are in place to respond appropriately to customer inquiries and requests for assistance following notification of a security incident. “The institution should, therefore, ensure that it has reasonable policies and procedures in place, including trained personnel, to respond appropriately to customer inquiries and requests for assistance.” | 12 CFR 30 Appendix B, Supplement A, Section III.B.1 (footnote 14) | final | Call center procedures for incident response; staff training records; escalation scripts; capacity planning records for post-incident customer contact surges. | |
OBL-01750 | United States | FDIC | cybersecurity | Implement a comprehensive written information security program with administrative, technical, and physical safeguards appropriate to the institution's size, complexity, and activities. [adjacent] “Each insured depository institution shall implement a comprehensive written information security program that includes administrative, technical, and physical safeguards appropriate to the size and complexity of the institution” | 12 CFR 364 App. B, II.A | final | Board-approved written information security program document; evidence of tailoring to institution size/complexity; coordinated policy set across all business lines. | |
OBL-01751 | United States | FDIC | cybersecurity | Design the information security program to protect against anticipated threats or hazards to the security or integrity of customer information and against technological failures. “Protect against any anticipated threats or hazards to the security or integrity of such information” | 12 CFR 364 App. B, II.B.2 | final | Threat and hazard register; risk assessment documentation mapping identified threats to program controls. | |
OBL-01752 | United States | FDIC | cybersecurity | Identify reasonably foreseeable internal and external threats that could result in unauthorized disclosure, misuse, alteration, or destruction of customer information or customer information systems. [adjacent] “Identify reasonably foreseeable internal and external threats that could result in unauthorized disclosure, misuse, alteration, or destruction of customer information or customer information systems.” | 12 CFR 364 App. B, III.B.1 | final | Written risk assessment report identifying internal and external threats; documented methodology; date-stamped assessments. | |
OBL-01753 | United States | FDIC | cybersecurity | Assess the likelihood and potential damage of identified threats, taking into consideration the sensitivity of customer information. “Assess the likelihood and potential damage of these threats, taking into consideration the sensitivity of customer information.” | 12 CFR 364 App. B, III.B.2 | final | Risk assessment with likelihood and impact ratings per threat; sensitivity classification of customer data categories. | |
OBL-01754 | United States | FDIC | cybersecurity | Implement response programs specifying actions to be taken when unauthorized access to customer information systems is suspected or detected, including reports to regulatory and law enforcement agencies. “Response programs that specify actions to be taken when the institution suspects or detects that unauthorized individuals have gained access to customer information systems, including appropriate reports to regulatory and law enforcement agencies” | 12 CFR 364 App. B, III.C.1.g | final | Written incident response plan with defined triggers, escalation procedures, and regulatory/law enforcement notification steps; test records. | |
OBL-01755 | United States | FDIC | cybersecurity | Implement measures to protect against destruction, loss, or damage of customer information due to environmental hazards such as fire, water damage, or technological failures. “Measures to protect against destruction, loss, or damage of customer information due to potential environmental hazards, such as fire and water damage or technological failures.” | 12 CFR 364 App. B, III.C.1.h | final | Business continuity/disaster recovery plan addressing environmental hazards; backup and data recovery procedures; facility protection controls documentation. | |
OBL-01756 | United States | FDIC | cybersecurity | Regularly test key controls, systems, and procedures of the information security program, with frequency determined by risk assessment, conducted or reviewed by independent parties. [adjacent] “Regularly test the key controls, systems and procedures of the information security program. The frequency and nature of such tests should be determined by the institution's risk assessment. Tests should be conducted or reviewed by independent third parties or staff independent” | 12 CFR 364 App. B, III.C.3 | final | Testing schedule aligned to risk assessment; test results reports; evidence of independent reviewer; remediation tracking logs. | |
OBL-01757 | United States | FDIC | cybersecurity | Monitor, evaluate, and adjust the information security program in light of changes in technology, threats, customer information sensitivity, and changing business arrangements. [adjacent] “Each institution shall monitor, evaluate, and adjust, as appropriate, the information security program in light of any relevant changes in technology, the sensitivity of its customer information, internal or external threats to information, and the institution's own changing business arrangements” | 12 CFR 364 App. B, III.E | final | Program change log; periodic review reports; documented triggers for program updates (e.g., post-merger, new technology deployments). | |
OBL-01758 | United States | FDIC | cybersecurity | Implement monitoring systems and procedures to detect actual and attempted attacks on or intrusions into customer information systems. [adjacent] “Monitoring systems and procedures to detect actual and attempted attacks on or intrusions into customer information systems” | 12 CFR 364 App. B, III.C.1.f | final | SIEM/IDS/IPS deployment records; monitoring policy; alert and incident logs demonstrating continuous detection capability. | |
OBL-01759 | United States | FDIC | cybersecurity | Exercise appropriate due diligence in selecting service providers that access customer information. [adjacent] “Exercise appropriate due diligence in selecting its service providers” | 12 CFR 364 App. B, III.D.1 | final | Vendor due diligence questionnaires; pre-contract security assessments; vendor risk scoring documentation. | |
OBL-01760 | United States | FDIC | cybersecurity | Require service providers by contract to implement appropriate measures designed to meet the information security objectives of the Guidelines. “Require its service providers by contract to implement appropriate measures designed to meet the objectives of these Guidelines” | 12 CFR 364 App. B, III.D.2 | final | Executed contracts with service providers containing security requirements clauses; contract review checklist confirming compliance with Guidelines objectives. | |
OBL-01761 | United States | FDIC | cybersecurity | Where indicated by risk assessment, monitor service providers to confirm they have satisfied contractual security obligations, including reviewing audits, test summaries, or equivalent evaluations. “Where indicated by the institution's risk assessment, monitor its service providers to confirm that they have satisfied their obligations...an institution should review audits, summaries of test results, or other equivalent evaluations of its service providers.” | 12 CFR 364 App. B, III.D.3 | final | Ongoing vendor monitoring reports; SOC 2 or equivalent reports from service providers; tracking log of review dates and findings. | |
OBL-01762 | United States | FDIC | cybersecurity | Report to the board or board committee at least annually on the status of the information security program, including risk assessment, risk management decisions, service provider arrangements, testing results, and security breaches. [adjacent] “Each institution shall report to its board or an appropriate committee of the board at least annually...addressing issues such as: Risk assessment; risk management and control decisions; service provider arrangements; results of testing; security breaches or violations” | 12 CFR 364 App. B, III.F | final | Annual board/committee information security report with required content; board meeting minutes evidencing receipt and discussion. | |
OBL-01763 | United States | FDIC | cybersecurity | Develop and implement a risk-based response program to address incidents of unauthorized access to customer information in customer information systems, including those maintained by service providers. “every financial institution should also develop and implement a risk-based response program to address incidents of unauthorized access to customer information in customer information systems that occur nonetheless.” | 12 CFR 364 App. B, Supplement A, II (opening paragraph) | final | Written incident response program document; evidence of risk-based scoping; coverage of service provider-hosted systems. | |
OBL-01764 | United States | FDIC | cybersecurity | Include in the response program procedures to assess the nature and scope of an incident and identify which customer information systems and types of customer information have been accessed or misused. “Assessing the nature and scope of an incident, and identifying what customer information systems and types of customer information have been accessed or misused” | 12 CFR 364 App. B, Supplement A, II.A.1.a | final | Incident response playbook with scope assessment procedures; post-incident reports documenting scope determination. | |
OBL-01765 | United States | FDIC | cybersecurity | Notify the primary Federal regulator as soon as possible when the institution becomes aware of an incident involving unauthorized access to or use of sensitive customer information. [adjacent] “Notifying its primary Federal regulator as soon as possible when the institution becomes aware of an incident involving unauthorized access to or use of sensitive customer information” | 12 CFR 364 App. B, Supplement A, II.A.1.b | final | Regulatory notification procedures in incident response plan; log of notifications made to FDIC; defined escalation triggers. | |
OBL-01767 | United States | FDIC | cybersecurity | Take appropriate steps to contain and control an incident to prevent further unauthorized access to customer information, while preserving records and evidence. “Taking appropriate steps to contain and control the incident to prevent further unauthorized access to or use of customer information, for example, by monitoring, freezing, or closing affected accounts, while preserving records and other evidence” | 12 CFR 364 App. B, Supplement A, II.A.1.d | final | Containment procedures in incident response plan; evidence preservation policy; post-incident containment action records. | |
OBL-01768 | United States | FDIC | cybersecurity | Require service providers by contract to notify the institution as soon as possible of unauthorized access incidents to the institution's customer information, enabling the institution to implement its response program. “an institution's contract with its service provider should require the service provider to take appropriate actions to address incidents of unauthorized access to the financial institution's customer information, including notification to the institution as soon as possible of any such incident” | 12 CFR 364 App. B, Supplement A, II (opening paragraph) | final | Service provider contracts with mandatory incident notification clauses; SLA specifying notification timing; incident notification log. | |
OBL-01771 | United States | FDIC | cybersecurity | Ensure the board of directors approves the written information security program and oversees its development, implementation, and maintenance, including assigning specific implementation responsibility. [adjacent] “The board of directors or an appropriate committee of the board of each insured depository institution shall: 1. Approve the institution's written information security program; and 2. Oversee the development, implementation, and maintenance of the institution's information security program, includin” | 12 CFR 364 App. B, III.A | final | Board resolution approving program; board committee charter; written delegation of implementation responsibility; board review minutes. | |
OBL-01772 | United States | FDIC | cybersecurity | Train staff to implement the institution's information security program. [adjacent] “Train staff to implement the institution's information security program.” | 12 CFR 364 App. B, III.C.2 | final | Training program records; completion logs; curriculum covering security program requirements; role-specific training for incident response personnel. | |
OBL-01773 | United States | FDIC | cybersecurity | Assess the sufficiency of existing policies, procedures, customer information systems, and other arrangements in place to control identified risks. “Assess the sufficiency of policies, procedures, customer information systems, and other arrangements in place to control risks.” | 12 CFR 364 App. B, III.B.3 | final | Gap analysis or control sufficiency assessment documented in risk assessment; control inventory mapped to identified risks; remediation tracking. | |
OBL-01774 | United States | FDIC | cybersecurity | Where a service provider maintains systems involved in an unauthorized access incident, the financial institution remains responsible for customer and regulator notification, though it may authorize the service provider to notify on its behalf. [adjacent] “Where an incident of unauthorized access to customer information involves customer information systems maintained by an institution's service providers, it is the responsibility of the financial institution to notify the institution's customers and regulator.” | 12 CFR 364 App. B, Supplement A, II.A.2 | final | Incident response plan addressing service provider incidents; contract clauses on delegated notification; records of institution oversight of service provider notifications. |
Knowing which rules bind you is step one. WSquare Advisory builds the operating capability behind compliance — the continuity, third-party, and recovery disciplines these regimes expect. If that's your challenge, let's talk.
Start with an Operating Survey · $5,000 →