On July 16, 2026, the Federal Deposit Insurance Corporation, the Federal Reserve Board, and the Office of the Comptroller of the Currency issued a joint statement describing a coordinated approach to handling highly sensitive information during regulatory examinations. Although the statement does not create new supervisory expectations, it recognizes that certain examination materials may pose a heightened risk if they are transferred, stored, or accessed outside the institution’s control environment. The joint statement seeks to reduce that exposure without limiting regulatory access. It also gives bank management an important role in identifying requested materials that may warrant additional safeguards.
What May Qualify as Highly Sensitive Information
Rather than creating a formal definition, the agencies provided examples of information that may carry additional sensitivity and heightened risk from disclosure, including detailed technology or network diagrams, penetration testing results, technical details about specific information technology control weaknesses, and succession planning materials.
These examples share a common feature: unauthorized access could reveal vulnerabilities, expose confidential strategies, or provide a roadmap to systems and controls. Financial Institutions should therefore evaluate sensitivity based on the nature and detail of the information, rather than relying on a document’s title or its existing internal data classification.
How The Examination Process May Change
Under the coordinated approach, management may identify data or documents requested for an examination that it believes should be treated as highly sensitive. Management should raise those concerns with the examiner-in-charge or the institution’s primary agency contact. Depending on the circumstances, regulators may consider alternative review methods such as reviewing materials on-site, reviewing information directly from the institution’s systems, accepting redacted or summarized documents, or using additional controls for transmission and access.
These options are intended to minimize unnecessary collection and storage by the agencies. They do not prevent examiners from obtaining information, conducting the examination, documenting conclusions, or maintaining an appropriate historical record.
A Practical Preparation Checklist
Although the statement does not impose new requirements, it creates an opportunity for institutions to strengthen their examination response process and make it more deliberate by:
- Identifying categories of information that may warrant heightened protection, with particular attention to cybersecurity, control vulnerabilities, strategic planning, and sensitive personnel information.
- Establish a process for reviewing examination requests and escalating concerns before potentially sensitive information is transmitted.
- Assign responsibility for communicating with the examiners when additional safeguards may be appropriate.
- Confirm that examination-response procedures address approved transmission methods, access restrictions, redaction, retention, and documentation of what was provided.
- Coordinate compliance, information security, legal, human resources, and executive stakeholders when a request crosses functional areas.
- Train employees who support examinations to recognize sensitive information and apply appropriate handling procedures throughout the examination process.
Incident Notification & Accountability
The agencies are also committed to notifying affected institutions of a potential or confirmed material compromise of confidential supervisory information as soon as practicable, and generally within 72 hours, when there is a reasonable basis to believe a compromise occurred and the affected institution has been identified. This commitment provides an important notification benchmark, but institutions should continue to maintain their own incident-response, escalation, and regulatory communication procedures.
The Takeaway for Financial Institutions
The joint statement reinforces a shared responsibility for protecting sensitive information during the examination process. Regulators retain full access to the records needed for effective supervision, while institutions have a clearer opportunity to identify materials that may require special handling. The most effective response is not to withhold information, but to recognize sensitive content early, communicate with examiners promptly, and agree on a secure review method that supports both supervisory access and sound information-security practices.
Institutions that prepare in advance will be better positioned to respond consistently when sensitive requests arise. A documented classification and escalation process can reduce uncertainty, avoid unnecessary transmission of high-risk information, and help examination teams work efficiently with regulators from the outset.
If you have any questions or are interested in learning more, we are here to help. Please do not hesitate to reach out to discuss your specific situation.
This material has been prepared for general, informational purposes only and is not intended to provide, and should not be relied on for, tax, legal or accounting advice. Should you require any such advice, please contact us directly. The information contained herein does not create, and your review or use of the information does not constitute, an accountant-client relationship.



