Feature Operational Risk
FDIC IT Examinations in 2026: What the End of URSIT and the New Single IT Rating Mean for Your Technology Risk Program
The FDIC is replacing the decades-old URSIT framework with a single IT rating organized around five focus areas: governance, cybersecurity, BCP, vendor management, and audit. Early 2026 examinations confirm the shift is already underway. Here's what community banks and their fintech partners need to prepare.
Table of Contents
TL;DR:
- The FDIC is replacing the URSIT framework — in use since 1978 — with a single holistic IT rating organized around five focus areas: governance, cybersecurity, BCP, vendor management, and audit. Early 2026 examinations in the Mid-Atlantic confirm the shift is already underway.
- OCC Bulletin 2025-24 (effective January 1, 2026) eliminated mandatory policy-based examination requirements in favor of risk-proportionate assessment — smaller institutions are no longer held to large-bank documentation standards, but policy documents alone no longer satisfy examiners either.
- All four federal banking agencies are using NIST CSF 2.0 language in examination findings. You don’t need to formally adopt CSF 2.0, but understanding the vocabulary helps you interpret what examiners are asking.
- The shift from component ratings to a single IT rating means cybersecurity weaknesses that were previously absorbed into a component score are now more directly visible in the overall rating.
Most financial institutions have had URSIT — the Uniform Rating System for Information Technology — as the framework for their last several IT examinations. Established in 1978 and updated in 1999, URSIT’s component-based rating approach was designed for an era when IT was a back-office function and the primary risks were mainframe availability and audit trail integrity.
The FDIC is moving on from that framework. Based on recent examination observations from the Mid-Atlantic region, FDIC examiners in 2026 are organizing IT assessments around five thematic areas — governance, cybersecurity, BCP, vendor management, and audit — and producing a single holistic IT rating rather than URSIT’s multiple component scores. If your most recent FDIC IT examination was structured around URSIT component ratings, your next examination may look materially different.
What Was URSIT — and Why It Needed to Change
URSIT evaluated IT risk using a set of component ratings that were combined into a composite score:
- Audit: Was IT covered in the audit plan? Were findings tracked and remediated?
- Management: Did IT management demonstrate adequate governance and risk awareness?
- Development and Acquisition: Were system changes, software acquisition, and project management appropriately controlled?
- Support and Delivery: Were IT operations, access controls, backups, and continuity managed effectively?
Each component received a 1–5 rating, and the components combined into a composite IT rating that fed into the broader CAMELS management component.
The problem with URSIT in 2026 is structural: cybersecurity is distributed across components rather than evaluated as a primary concern. Business continuity is a subset of Support and Delivery rather than a standalone domain. Vendor management — now a top regulatory priority following the interagency OCC 2023-17 guidance — received limited URSIT treatment. An institution with strong Documentation and Development scores but chronic patching failures could look better on URSIT than its actual risk profile warranted.
The FDIC’s shift to five named focus areas reflects the same evolution that produced the FFIEC’s operational resilience framework and NIST CSF 2.0’s “Govern” function addition: technology risk, cybersecurity, and operational resilience have converged in examiner expectations, and legacy frameworks built for simpler environments need to catch up.
The Five Focus Areas of the New FDIC IT Rating
1. Governance
The governance focus examines whether your board and senior management actually oversee IT risk — not just whether a policy document says they should.
What examiners are looking for:
- Board-level IT risk reporting: Written reports to the board at least annually documenting the status of the technology risk program, material risks, and any significant events or changes
- IT strategic plan: A documented plan aligning IT investments and capabilities to business objectives, reviewed and approved by management
- IT risk appetite: Defined risk tolerances for technology-related exposures, with escalation triggers when thresholds are approached or breached
- Management accountability: Clear organizational structure with named IT risk responsibilities and appropriate segregation of duties
- Prior MRA resolution: Evidence that findings from prior IT examinations have been addressed with documented remediation
OCC Bulletin 2025-24 (effective January 1, 2026) eliminated mandatory policy-based examination requirements in favor of risk-proportionate assessment. Under this approach, examiners evaluate whether your governance structure produces effective risk management — not whether your policy document matches a prescribed format. For smaller community banks and fintechs, this is a practical relief from large-bank documentation standards. The tradeoff: a policy document that exists without evidence of board engagement doesn’t satisfy the governance assessment.
2. Cybersecurity
Cybersecurity has always appeared in IT examinations, but the new single-rating approach elevates it to a primary named focus area rather than a distributed concern across URSIT components. Examiners across all four federal banking agencies are increasingly using NIST CSF 2.0 function categories — Govern, Identify, Protect, Detect, Respond, Recover — in examination findings and correspondence.
Key cybersecurity areas examined:
- Information security program: Written, comprehensive, covering all required elements — not just a policy statement
- Vulnerability management: Regular scanning, a documented patching cadence, and evidence of timely remediation with exceptions tracked and managed
- Access controls: Least-privilege implementation, multi-factor authentication for privileged access and remote access, periodic review of access rights, and documented procedures for terminated user account removal
- Penetration testing: Annual penetration testing by a qualified, sufficiently independent party — internal scans alone are not sufficient
- Incident response: Written incident response plan with evidence of testing, and a clear escalation path to senior management for material events
- Patch management: Documented process with evidence of timely application and exceptions tracked to resolution
The Federal Reserve Board OIG’s May 2025 report on cybersecurity at community banks found that many community banks lack formal cybersecurity programs that adequately address these elements. That finding has informed examiner attention across all four agencies — if the Fed OIG is writing about it, every agency is asking about it.
3. Business Continuity Planning
BCP has always been an IT examination area. The new single-rating approach elevates it from a subset of Support and Delivery to a named focus area in its own right — reflecting the FFIEC Business Continuity Management booklet’s shift toward operational resilience and the heightened regulatory attention following the July 2024 CrowdStrike global IT outage, which exposed how technology concentration risk translates directly into operational disruption at scale.
What examiners test in the BCP area:
- BCP documentation: Current, comprehensive plans covering both business functions and the IT systems that support them — not just IT disaster recovery in isolation
- Recovery time and point objectives: Formally defined RTOs and RPOs for critical systems, achievable given your actual infrastructure, and documented with rationale
- BCP testing: Evidence of tested BCP — not just a completed plan on a shelf — including IT system recovery testing, not just tabletop exercises. Examiners are increasingly asking for test results, test scripts, and after-action documentation
- Vendor-dependent BCP: Evidence that you’ve verified your critical vendors’ BCP capabilities and documented what happens when a key vendor system is unavailable. See the third-party dependent BCP requirements for specifics on what OCC 2023-17 and the FFIEC BCM booklet require here
- Integration with incident response: BCP and incident response plans should reference each other consistently — an incident that triggers BCP activation should have a documented handoff process
BCP findings in IT examinations frequently arise not from absent documentation but from BCP that was last tested two or three years ago, doesn’t include cloud-hosted or SaaS systems in recovery scope, or hasn’t been updated to reflect current critical vendor dependencies.
4. Vendor Management
Vendor management in the new IT rating reflects the weight given to third-party risk in the interagency OCC 2023-17 guidance. What was previously distributed across URSIT’s acquisition and delivery components is now a named focus area with explicit examination criteria.
Examiners assess:
- Vendor inventory: Do you have a documented, current inventory of all technology vendors, what data they access, what systems they operate, and how critical they are to your operations?
- Risk tiering: Are vendors classified by criticality (Critical, High, Medium, Low) with due diligence frequency and depth calibrated accordingly?
- Contract terms: Do your critical vendor agreements include audit rights, security and incident response requirements, business continuity provisions, and subcontractor notification requirements? The OCC 2023-17 vendor contract provisions detail what examiners specifically look for in contract language
- Concentration risk: Have you documented and risk-assessed your meaningful dependencies on single cloud providers, core banking processors, or technology service providers? An undocumented concentration is an unassessed risk — and a common finding
- Ongoing monitoring: Is vendor performance and risk monitored through the relationship, not just at initial onboarding?
A persistent gap: vendor inventories that include SaaS tools and payment processors but miss fourth-party dependencies — the subprocessors of your core banking vendor, the cloud infrastructure underlying your SaaS providers. OCC 2023-17’s fourth-party visibility expectations apply whether or not your primary vendor contract is strong.
5. Audit
The audit focus area examines whether IT risks are covered in the internal audit plan with appropriate scope, frequency, and independence.
What examiners look for:
- IT coverage in the audit plan: Technology risk areas — cybersecurity controls, access management, BCP, vendor management, change management — are included in the audit plan with coverage frequency matching the risk profile of each area
- Audit independence: IT audit work is conducted or overseen by someone with appropriate independence from IT management — either through internal audit or external audit engagement
- Management responsiveness: Prior IT audit findings have defined remediation plans with owners and due dates, and closure is documented with evidence — not just asserted
- Third-party audit coverage: Critical vendors appear in the audit plan, either through direct vendor audit rights or through structured review of vendor-provided audit reports (SOC 2 Type 2 reports, penetration test results, cloud provider compliance certifications)
An audit program that issues findings without tracking them to closure — or where management’s response is to acknowledge without action — is a consistent MRA driver in IT examinations.
What the Rating Scale Change Means for CAMELS
The shift from URSIT’s component ratings to a single holistic IT rating doesn’t change the 1–5 rating scale used for the IT assessment itself. What changes is the signal each rating sends.
Under URSIT, an institution with strong Audit and Management component ratings but weak Support and Delivery scores could end up with a composite IT rating that partially masked the operational weaknesses. With a single rating organized around five named focus areas, cybersecurity weaknesses and BCP gaps are directly visible in the holistic rating — they can’t be averaged away.
An IT rating of 3 or worse contributes meaningfully to the Management (M) component of CAMELS, which is evaluated across all four federal banking agencies. For community banks targeting CAMELS composite ratings of 1 or 2, a deteriorating IT rating creates management rating pressure that flows through to the composite.
How This Fits Into the 2026 Regulatory Exam Landscape
The FDIC IT examination shift sits in a larger 2026 pattern:
- OCC Bulletin 2025-24 (effective January 1, 2026): Eliminated mandatory policy-based requirements — examiners assess risk-proportionate controls, not policy document templates. This applies across OCC-supervised institutions and has influenced examiner expectations at FDIC and Federal Reserve as well.
- NIST CSF 2.0 (February 2024): The Govern function and supply chain risk guidance are now embedded in examiner language. See the FFIEC IT Examination Handbook walkthrough for how the handbook booklets connect to current examiner focus.
- OCC 2023-17: The interagency third-party risk management guidance sets the baseline for vendor management that the new IT rating’s vendor management focus area tests against. What was voluntary guidance in prior exams is now a named examination focus.
- FFIEC BCM Booklet: The operational resilience principles in the BCM booklet define BCP testing expectations that the BCP focus area tests against.
Preparation Checklist for the New IT Examination Approach
| Focus Area | Evidence Examiners Will Request |
|---|---|
| Governance | Most recent board IT risk report; IT strategic plan; IT risk appetite statement; prior IT MRA resolution documentation with closure evidence |
| Cybersecurity | Annual penetration test report and remediation follow-up; vulnerability assessment cadence and remediation evidence; MFA implementation documentation; written incident response plan and test record |
| BCP | Current BCP documentation covering IT systems; most recent BCP/DR test results including IT system recovery; RTO/RPO definitions; critical vendor BCP verification evidence |
| Vendor Management | Current vendor inventory with risk tiers; critical vendor due diligence files; contracts reviewed for OCC 2023-17 provisions; documented concentration risk assessment |
| Audit | Current IT audit plan; prior IT audit reports with management responses; open findings tracker with due dates, owners, and closure evidence |
So What?
If your IT examination was structured around URSIT component ratings, the questions your examiner asked and the documentation they requested were organized differently than what the single-rating approach surfaces. Examiners aren’t asking “do you have an IT policy?” — they’re asking “is your technology risk program producing effective outcomes in these five areas?”
For most community banks and their fintech partners, the gap between having a policy document and having operational evidence of effective controls is where exam findings come from. An annual penetration test that hasn’t been done. A BCP that hasn’t been tested since before the pandemic. A vendor inventory that lists 30 vendors but doesn’t capture the cloud concentration underlying all of them. A board IT report that exists as a template but hasn’t been updated since 2023.
The five focus areas give you a clear preparation framework before your next examination cycle. The Operational Risk Program bundle includes the RCSA template, KRI library, loss event tracking kit, and enterprise risk management framework — the operational risk program components that underpin strong IT risk governance and give examiners substantive evidence of first- and second-line risk ownership when they review your program.
Sources:
- FDIC IT Exam Changes in 2026: Observations from Recent Examinations (NETBankAudit)
- Federal Reserve Board OIG: Cybersecurity Oversight at Community Banks (May 2025)
- PwC: Banking on Resilience — FFIEC Operational Resilience Shift for Financial Service Examiners
- FFIEC IT Examination Handbook — Business Continuity Management Booklet
- FFIEC IT Examination Readiness for Financial Institutions (MyABT)
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Operational Risk Program
Build a complete ORM program: ERM framework, RCSA, loss monitoring, financial risk, KRIs, and the Contingency Funding Plan for chartered banks.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is URSIT and why is the FDIC replacing it?
When did the FDIC IT examination changes take effect?
What are the five focus areas of the new FDIC IT rating?
How does OCC Bulletin 2025-24 affect IT examination expectations for smaller institutions?
What is NIST CSF 2.0 and why does it appear in bank IT examination findings?
What evidence should community banks and fintechs prepare for the new IT examination areas?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Operational Risk Program
Build a complete ORM program: ERM framework, RCSA, loss monitoring, financial risk, KRIs, and the Contingency Funding Plan for chartered banks.
◆ Keep reading
Related posts.
Operational Risk
Enterprise Risk Management After Approval: The Operating Cadence That Keeps ERM Alive
Run an enterprise risk management framework with a practical monthly, quarterly, and annual cadence, named owners, and decision evidence.
Jul 25, 2026
Operational Risk
Risk Assessment Template in Excel: Build the Evidence Trail, Not Just the Heat Map
Build a risk assessment template in Excel that preserves evidence, challenge, approvals, and score history—not just a polished heat map.
Jul 23, 2026
Operational Risk
FedNow's Network Intelligence API Launched in April 2026. Your Fraud Risk Program Probably Hasn't Caught Up.
On April 28, 2026, the Federal Reserve made pre-payment network-level fraud intelligence available to every FedNow participant. The data — receiver account behavioral trends derived from system-wide FedNow activity — is available before a transaction is approved. Most institutions haven't updated their fraud policies, controls, or KRIs to account for what this changes.
Jul 21, 2026