Skip to content
RiskTemplates · The Daily Brief Monday, August 3, 2026
Wire The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs JUL 30

Feature Operational Risk

When Your Examiner Wants Your Penetration Test Results: The July 2026 Joint Statement on Protecting Your Most Sensitive Security Data

On July 16, 2026, the OCC, FDIC, and Federal Reserve issued a joint statement establishing coordinated protocols for how examiners handle your most sensitive security documentation — penetration test results, network diagrams, and IT control weaknesses. Here's what it means for your examination preparation.

Table of Contents

TL;DR

  • On July 16, 2026, the OCC, FDIC, and Federal Reserve issued a joint statement establishing coordinated protocols for handling highly sensitive information during bank examinations — including penetration test results, network diagrams, and IT control weakness documentation
  • Banks are responsible for proactively flagging sensitive materials; examiners are now trained to offer on-site review rather than taking digital copies of flagged documents
  • Agencies committed to notifying affected banks within 72 hours if they have reason to believe confidential supervisory information was compromised
  • The statement resolved about half of what the industry asked for — the protocols exist, but external audit of agency data practices and stronger transmission controls are still outstanding

Your Penetration Test Results Are Now a Regulatory Coordination Problem

Picture the setup: your examiner requests your most recent third-party penetration test report and the full network topology diagram your security team uses for monitoring. Both are exactly what an attacker would want if they were trying to map your systems. Both are also exactly what an examiner needs to evaluate whether your cybersecurity controls are adequate.

This tension has existed as long as bank cybersecurity examinations have. What changed on July 16, 2026, is that the OCC, Federal Deposit Insurance Corporation, and Federal Reserve jointly acknowledged it in writing — and committed to specific protocols for managing it.

The joint statement on “Coordinated Federal Banking Agency Approach for the Handling of Highly Sensitive Information During Examinations” is not a sea change in examination authority. Examiners still have broad rights to review your systems, controls, and documentation. What changed is the process around the most sensitive category of that documentation — and the obligations the agencies are now taking on with respect to your data.

What “Highly Sensitive Information” Means Under the Statement

The agencies defined highly sensitive information through examples rather than a closed list. The specific categories called out in the statement:

  • Technology and network diagrams and schematics
  • Detailed penetration test results
  • Technical details of specific information technology control weaknesses
  • Succession planning

Banks should treat these as the floor, not the ceiling. The Bank Policy Institute and ABA had previously released best-practice guidance for sharing sensitive data with regulators; that guidance referenced additional categories including M&A proposals, cybersecurity remediation roadmaps with specific timelines, and detailed vulnerability scan outputs.

The unifying characteristic across all of these: they’re materials that would give an adversary meaningful operational advantage if they were exfiltrated. Your penetration test report, by design, contains a detailed map of vulnerabilities in your environment. Your network topology diagram shows every segment, every chokepoint, every connection. Your succession plan shows who makes decisions if your CEO or CISO is suddenly unavailable.

For institutions with mature cybersecurity programs, this list will map closely to your own crown-jewel document classification — the materials your security team already designates as restricted or confidential.

The Request-and-Flag Process

The statement places the burden of identification squarely on bank management. Regulators will rely on you to identify data and documents that should be considered highly sensitive — not the other way around.

This is a process design problem, not just a policy decision. In practice, it means your institution needs:

A pre-examination sensitive-document register. Before the examiner’s document request list arrives, you should know which materials in your environment would qualify for highly sensitive treatment. The register doesn’t need to list every document — it should identify document types, system categories, and ownership so the right people can respond quickly when a specific request comes in.

A designated flagging point of contact. When the examination data request comes in, someone needs authority to review each item against the highly sensitive definition and communicate with the examination team about handling alternatives. In many institutions this falls to the chief compliance officer, chief information security officer, or both working together.

A documented response protocol. Once a document is flagged, the institution needs a clear path: who communicates the flag to the examiner, what alternative review mechanism is proposed, who has authority to accept or escalate if the examiner pushes back.

The joint statement notes that examiners will evaluate whether additional protocols should apply to flagged materials. This is a negotiation framework, not a veto — but it gives banks standing to have the conversation before sensitive materials are transmitted.

What the Agencies Committed To

Once a document is flagged and the examiner agrees additional protocols apply, the statement describes several alternative review mechanisms:

On-site review. The primary alternative to digital transmission. The examiner reviews the material at your location rather than taking a copy. For penetration test reports and network diagrams, this is the cleanest solution — the document doesn’t leave your building, and you maintain chain-of-custody visibility.

Restricted transmission and storage. For materials that must be transmitted, agencies committed to restricting how they send and store the information. The statement doesn’t define the specific transmission security requirements, but the intent is that sensitive materials won’t travel through standard unprotected channels.

Examiner training. All three agencies committed to providing their examiners with written guidance and training on handling sensitive information. This is a process change at the agency level — examiners will be prepared for the flag-and-negotiate dynamic rather than treating all document requests as routine.

72-hour breach notification. The agencies committed to notify affected banks “as soon as practicable and within no more than 72 hours” after any agency has a “reasonable basis to believe” a compromise of confidential supervisory information has occurred. This is substantively the same trigger language used in CIRCIA’s cyber incident reporting obligations — “reasonably believes” is not “has confirmed,” which means the notification clock starts when the preliminary evidence points to a compromise, not when the investigation is complete.

What the Statement Didn’t Deliver

American Banker’s reporting characterized the outcome as regulators answering about half of what the banking industry asked for. The Bank Policy Institute had also raised the question of accountability mechanisms for agency data handling — specifically, whether banks would have any independent verification that their flagged materials were being handled as promised.

The statement doesn’t address:

External audit of agency data practices. Banks have no independent mechanism to verify that their sensitive materials are being handled according to the protocols. The commitment is the agencies’ own statement of intent, not a verifiable compliance obligation.

Specific transmission security standards. The statement says agencies will restrict transmission but doesn’t specify encryption standards, network security requirements, or device policies for examiners accessing sensitive materials remotely.

Consequences for non-compliance. There’s no enforcement mechanism for banks whose sensitive information is mishandled. The 72-hour breach notification creates transparency after the fact; it doesn’t create liability or compensation rights.

These gaps are worth tracking. The ABA and Bank Policy Institute are likely to continue pushing for stronger commitments in future rulemaking or guidance.

The 72-Hour Notification: Why It Matters

The commitment to notify banks within 72 hours of a suspected compromise of confidential supervisory information is meaningful precisely because it mirrors the same framework banks now use to report breaches to regulators.

If you’ve updated your incident response plan for CIRCIA’s 72-hour cyber incident reporting clock — which applies when your institution “reasonably believes” it’s experienced a covered cyber incident — you now have a parallel track where your regulator is making the same commitment back to you.

The practical implication: if the OCC, Fed, or FDIC believes they may have had a compromise of bank examination materials, your institution will receive notification within 72 hours of that determination. That’s your trigger for your own incident response protocol: assessing whether the compromised examination materials create downstream risk for your institution, determining whether your security team needs to treat any of the exposed information as potentially adversary-accessible, and deciding whether the exposure triggers any of your own notification obligations to your board or executive leadership.

Building This Into Your Examination Readiness Process

The most effective way to operationalize the joint statement isn’t to wait until the next examination and improvise. It’s to build the process into your standard examination preparation cycle.

A few concrete steps:

Create the sensitive-document inventory before the next examination cycle opens. Work with your CISO, CISO’s team, and compliance to create a standing list of document types that would qualify for highly sensitive treatment: penetration test reports, vulnerability scan outputs, network diagrams and schematics, IT control weakness documentation (including any open remediation timelines), succession planning documents, and any M&A-sensitive materials. Document the current custodians of these materials and who has authority to flag them during an examination.

Update the examination readiness checklist. The OCC’s 2026 examination rightsizing bulletin and the 60-day examination readiness framework both emphasize preparation before the examiner arrives. Add a sensitive-document identification step to that preparation — explicitly review which materials on the anticipated request list would qualify for highly sensitive treatment and prepare the flagging communication in advance.

Coordinate the CISO and compliance officer role. In most institutions, the CISO owns the penetration test results and network documentation; the CCO or compliance team owns the examination relationship. The joint statement creates a workflow that spans both functions. Whoever owns the examination coordinator role needs to have a pre-established communication channel with the CISO so the flagging decision can happen quickly when a document request comes in.

Brief the exam management team. The examiners you work with may or may not be aware of the new protocols — the statement commits to examiner training, but implementation takes time. Having your examination coordinator brief the lead examiner on your institution’s highly sensitive document process at the examination kickoff reduces the likelihood of a conflict later in the cycle.

So What?

The July 2026 joint statement is a process improvement, not a revolution. Examiners still have access to your most sensitive materials — but now there’s a recognized protocol for discussing how that access happens.

The meaningful shift is that banks now have standing to flag sensitive materials and request alternatives to digital transmission. Before this statement, an institution that objected to transmitting penetration test results had limited recourse. Now there’s a published framework that supports the negotiation.

For most institutions, operationalizing this means one main thing: building a sensitive-document identification process before the next examination cycle starts. That process doesn’t need to be complicated — a list of document types, a designated point of contact, and a clear escalation path if the examiner and bank can’t agree on handling. The hard part is making sure that process is in place before the document request arrives, not after.

Any examination findings or MRAs that come out of a cycle where sensitive materials were in play should be tracked carefully. The issues management system — and specifically the root cause analysis on any cybersecurity-related findings — should capture whether the finding stems from a control weakness that was shared with an examiner and what the exposure profile of that information is.


Related reading: Examining the 36-Hour and 72-Hour Cyber Reporting Clocks · NYDFS Part 500 Class A Requirements and 2026 Examination Gaps · OCC Community Bank Exam Rightsizing: What the 2026 Bulletin Changes

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What does the July 2026 joint statement actually require banks to do?
The statement establishes that bank management is responsible for proactively identifying data and documents requested during an examination that they believe should be treated as highly sensitive. This requires banks to develop an internal process for flagging materials before the examiner request comes in — not scrambling to object after the fact. Banks should designate a point person to evaluate each examination document request against a defined list of highly sensitive categories and submit requests for additional handling protocols through the new process.
What types of documents qualify as 'highly sensitive' under the joint statement?
The agencies specifically named four categories: technology and network diagrams and schematics; detailed penetration test results; technical details of specific information technology control weaknesses; and succession planning. The list isn't exhaustive — the statement's framing suggests regulators will evaluate any material the bank flags. Additional candidates include M&A strategy, CEO compensation structures, and cybersecurity roadmaps with specific remediation timelines. The key criterion is whether the document would provide a roadmap for exploiting your systems or organization if it fell into the wrong hands.
What exactly did the agencies promise if they compromise your sensitive examination data?
The joint statement commits to notifying affected banks 'as soon as practicable and within no more than 72 hours' after any of the three agencies has a 'reasonable basis to believe' a material compromise of confidential supervisory information has occurred. This mirrors the same 'reasonably believes' trigger used in cybersecurity incident reporting frameworks. Importantly, this is a notification commitment — not a liability or compensation commitment. The 72-hour window covers notification; remediation and any dispute about consequences are separate.
Does the joint statement resolve all the cybersecurity concerns banks had about sharing sensitive exam data?
No. American Banker's reporting characterized it as regulators 'answering half of banks' data-security asks.' The Bank Policy Institute and ABA had been pressing for more robust controls — including stronger restrictions on transmission, clearer rules on examiner device security, and independent audit of agency data handling practices. The joint statement commits to on-site review as an alternative to transmission and to examiner training, but it doesn't address auditing or accountability mechanisms for data handling practices within the agencies themselves.
How does this relate to the NYDFS Part 500 cybersecurity requirements for regulated institutions?
NYDFS Part 500 requires covered entities to maintain a cybersecurity program, including penetration testing and vulnerability assessment. Institutions that are both NYDFS-regulated and OCC/FDIC/Fed-regulated face the scenario where their Part 500 pen test results — required by state regulation — are then requested by their federal examiner. The July 2026 joint statement's protocols now apply to that exact scenario: the bank can flag the pen test results as highly sensitive and request on-site review rather than transmission to agency systems.
What should we do before the next examination cycle?
Three things: First, build an internal sensitive-document register — a list of materials that your institution would flag as highly sensitive, organized by document type and system. This lets you respond quickly when an examination data request comes in. Second, designate a point of contact who understands the new flagging process and can communicate with examiners about handling alternatives. Third, update your examination readiness checklist to include a sensitive-document review step at the start of every examination cycle, before the request list arrives.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.