Skip to content
RiskTemplates · The Daily Brief Sunday, July 26, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Operational Risk

FDIC IT Examinations in 2026: What the End of URSIT and the New Single IT Rating Mean for Your Technology Risk Program

The FDIC is replacing the decades-old URSIT framework with a single IT rating organized around five focus areas: governance, cybersecurity, BCP, vendor management, and audit. Early 2026 examinations confirm the shift is already underway. Here's what community banks and their fintech partners need to prepare.

By Rebecca Leung · June 16, 2026 ·
Table of Contents

TL;DR:

  • The FDIC is replacing the URSIT framework — in use since 1978 — with a single holistic IT rating organized around five focus areas: governance, cybersecurity, BCP, vendor management, and audit. Early 2026 examinations in the Mid-Atlantic confirm the shift is already underway.
  • OCC Bulletin 2025-24 (effective January 1, 2026) eliminated mandatory policy-based examination requirements in favor of risk-proportionate assessment — smaller institutions are no longer held to large-bank documentation standards, but policy documents alone no longer satisfy examiners either.
  • All four federal banking agencies are using NIST CSF 2.0 language in examination findings. You don’t need to formally adopt CSF 2.0, but understanding the vocabulary helps you interpret what examiners are asking.
  • The shift from component ratings to a single IT rating means cybersecurity weaknesses that were previously absorbed into a component score are now more directly visible in the overall rating.

Most financial institutions have had URSIT — the Uniform Rating System for Information Technology — as the framework for their last several IT examinations. Established in 1978 and updated in 1999, URSIT’s component-based rating approach was designed for an era when IT was a back-office function and the primary risks were mainframe availability and audit trail integrity.

The FDIC is moving on from that framework. Based on recent examination observations from the Mid-Atlantic region, FDIC examiners in 2026 are organizing IT assessments around five thematic areas — governance, cybersecurity, BCP, vendor management, and audit — and producing a single holistic IT rating rather than URSIT’s multiple component scores. If your most recent FDIC IT examination was structured around URSIT component ratings, your next examination may look materially different.

What Was URSIT — and Why It Needed to Change

URSIT evaluated IT risk using a set of component ratings that were combined into a composite score:

  • Audit: Was IT covered in the audit plan? Were findings tracked and remediated?
  • Management: Did IT management demonstrate adequate governance and risk awareness?
  • Development and Acquisition: Were system changes, software acquisition, and project management appropriately controlled?
  • Support and Delivery: Were IT operations, access controls, backups, and continuity managed effectively?

Each component received a 1–5 rating, and the components combined into a composite IT rating that fed into the broader CAMELS management component.

The problem with URSIT in 2026 is structural: cybersecurity is distributed across components rather than evaluated as a primary concern. Business continuity is a subset of Support and Delivery rather than a standalone domain. Vendor management — now a top regulatory priority following the interagency OCC 2023-17 guidance — received limited URSIT treatment. An institution with strong Documentation and Development scores but chronic patching failures could look better on URSIT than its actual risk profile warranted.

The FDIC’s shift to five named focus areas reflects the same evolution that produced the FFIEC’s operational resilience framework and NIST CSF 2.0’s “Govern” function addition: technology risk, cybersecurity, and operational resilience have converged in examiner expectations, and legacy frameworks built for simpler environments need to catch up.

The Five Focus Areas of the New FDIC IT Rating

1. Governance

The governance focus examines whether your board and senior management actually oversee IT risk — not just whether a policy document says they should.

What examiners are looking for:

  • Board-level IT risk reporting: Written reports to the board at least annually documenting the status of the technology risk program, material risks, and any significant events or changes
  • IT strategic plan: A documented plan aligning IT investments and capabilities to business objectives, reviewed and approved by management
  • IT risk appetite: Defined risk tolerances for technology-related exposures, with escalation triggers when thresholds are approached or breached
  • Management accountability: Clear organizational structure with named IT risk responsibilities and appropriate segregation of duties
  • Prior MRA resolution: Evidence that findings from prior IT examinations have been addressed with documented remediation

OCC Bulletin 2025-24 (effective January 1, 2026) eliminated mandatory policy-based examination requirements in favor of risk-proportionate assessment. Under this approach, examiners evaluate whether your governance structure produces effective risk management — not whether your policy document matches a prescribed format. For smaller community banks and fintechs, this is a practical relief from large-bank documentation standards. The tradeoff: a policy document that exists without evidence of board engagement doesn’t satisfy the governance assessment.

2. Cybersecurity

Cybersecurity has always appeared in IT examinations, but the new single-rating approach elevates it to a primary named focus area rather than a distributed concern across URSIT components. Examiners across all four federal banking agencies are increasingly using NIST CSF 2.0 function categories — Govern, Identify, Protect, Detect, Respond, Recover — in examination findings and correspondence.

Key cybersecurity areas examined:

  • Information security program: Written, comprehensive, covering all required elements — not just a policy statement
  • Vulnerability management: Regular scanning, a documented patching cadence, and evidence of timely remediation with exceptions tracked and managed
  • Access controls: Least-privilege implementation, multi-factor authentication for privileged access and remote access, periodic review of access rights, and documented procedures for terminated user account removal
  • Penetration testing: Annual penetration testing by a qualified, sufficiently independent party — internal scans alone are not sufficient
  • Incident response: Written incident response plan with evidence of testing, and a clear escalation path to senior management for material events
  • Patch management: Documented process with evidence of timely application and exceptions tracked to resolution

The Federal Reserve Board OIG’s May 2025 report on cybersecurity at community banks found that many community banks lack formal cybersecurity programs that adequately address these elements. That finding has informed examiner attention across all four agencies — if the Fed OIG is writing about it, every agency is asking about it.

3. Business Continuity Planning

BCP has always been an IT examination area. The new single-rating approach elevates it from a subset of Support and Delivery to a named focus area in its own right — reflecting the FFIEC Business Continuity Management booklet’s shift toward operational resilience and the heightened regulatory attention following the July 2024 CrowdStrike global IT outage, which exposed how technology concentration risk translates directly into operational disruption at scale.

What examiners test in the BCP area:

  • BCP documentation: Current, comprehensive plans covering both business functions and the IT systems that support them — not just IT disaster recovery in isolation
  • Recovery time and point objectives: Formally defined RTOs and RPOs for critical systems, achievable given your actual infrastructure, and documented with rationale
  • BCP testing: Evidence of tested BCP — not just a completed plan on a shelf — including IT system recovery testing, not just tabletop exercises. Examiners are increasingly asking for test results, test scripts, and after-action documentation
  • Vendor-dependent BCP: Evidence that you’ve verified your critical vendors’ BCP capabilities and documented what happens when a key vendor system is unavailable. See the third-party dependent BCP requirements for specifics on what OCC 2023-17 and the FFIEC BCM booklet require here
  • Integration with incident response: BCP and incident response plans should reference each other consistently — an incident that triggers BCP activation should have a documented handoff process

BCP findings in IT examinations frequently arise not from absent documentation but from BCP that was last tested two or three years ago, doesn’t include cloud-hosted or SaaS systems in recovery scope, or hasn’t been updated to reflect current critical vendor dependencies.

4. Vendor Management

Vendor management in the new IT rating reflects the weight given to third-party risk in the interagency OCC 2023-17 guidance. What was previously distributed across URSIT’s acquisition and delivery components is now a named focus area with explicit examination criteria.

Examiners assess:

  • Vendor inventory: Do you have a documented, current inventory of all technology vendors, what data they access, what systems they operate, and how critical they are to your operations?
  • Risk tiering: Are vendors classified by criticality (Critical, High, Medium, Low) with due diligence frequency and depth calibrated accordingly?
  • Contract terms: Do your critical vendor agreements include audit rights, security and incident response requirements, business continuity provisions, and subcontractor notification requirements? The OCC 2023-17 vendor contract provisions detail what examiners specifically look for in contract language
  • Concentration risk: Have you documented and risk-assessed your meaningful dependencies on single cloud providers, core banking processors, or technology service providers? An undocumented concentration is an unassessed risk — and a common finding
  • Ongoing monitoring: Is vendor performance and risk monitored through the relationship, not just at initial onboarding?

A persistent gap: vendor inventories that include SaaS tools and payment processors but miss fourth-party dependencies — the subprocessors of your core banking vendor, the cloud infrastructure underlying your SaaS providers. OCC 2023-17’s fourth-party visibility expectations apply whether or not your primary vendor contract is strong.

5. Audit

The audit focus area examines whether IT risks are covered in the internal audit plan with appropriate scope, frequency, and independence.

What examiners look for:

  • IT coverage in the audit plan: Technology risk areas — cybersecurity controls, access management, BCP, vendor management, change management — are included in the audit plan with coverage frequency matching the risk profile of each area
  • Audit independence: IT audit work is conducted or overseen by someone with appropriate independence from IT management — either through internal audit or external audit engagement
  • Management responsiveness: Prior IT audit findings have defined remediation plans with owners and due dates, and closure is documented with evidence — not just asserted
  • Third-party audit coverage: Critical vendors appear in the audit plan, either through direct vendor audit rights or through structured review of vendor-provided audit reports (SOC 2 Type 2 reports, penetration test results, cloud provider compliance certifications)

An audit program that issues findings without tracking them to closure — or where management’s response is to acknowledge without action — is a consistent MRA driver in IT examinations.

What the Rating Scale Change Means for CAMELS

The shift from URSIT’s component ratings to a single holistic IT rating doesn’t change the 1–5 rating scale used for the IT assessment itself. What changes is the signal each rating sends.

Under URSIT, an institution with strong Audit and Management component ratings but weak Support and Delivery scores could end up with a composite IT rating that partially masked the operational weaknesses. With a single rating organized around five named focus areas, cybersecurity weaknesses and BCP gaps are directly visible in the holistic rating — they can’t be averaged away.

An IT rating of 3 or worse contributes meaningfully to the Management (M) component of CAMELS, which is evaluated across all four federal banking agencies. For community banks targeting CAMELS composite ratings of 1 or 2, a deteriorating IT rating creates management rating pressure that flows through to the composite.

How This Fits Into the 2026 Regulatory Exam Landscape

The FDIC IT examination shift sits in a larger 2026 pattern:

  • OCC Bulletin 2025-24 (effective January 1, 2026): Eliminated mandatory policy-based requirements — examiners assess risk-proportionate controls, not policy document templates. This applies across OCC-supervised institutions and has influenced examiner expectations at FDIC and Federal Reserve as well.
  • NIST CSF 2.0 (February 2024): The Govern function and supply chain risk guidance are now embedded in examiner language. See the FFIEC IT Examination Handbook walkthrough for how the handbook booklets connect to current examiner focus.
  • OCC 2023-17: The interagency third-party risk management guidance sets the baseline for vendor management that the new IT rating’s vendor management focus area tests against. What was voluntary guidance in prior exams is now a named examination focus.
  • FFIEC BCM Booklet: The operational resilience principles in the BCM booklet define BCP testing expectations that the BCP focus area tests against.

Preparation Checklist for the New IT Examination Approach

Focus AreaEvidence Examiners Will Request
GovernanceMost recent board IT risk report; IT strategic plan; IT risk appetite statement; prior IT MRA resolution documentation with closure evidence
CybersecurityAnnual penetration test report and remediation follow-up; vulnerability assessment cadence and remediation evidence; MFA implementation documentation; written incident response plan and test record
BCPCurrent BCP documentation covering IT systems; most recent BCP/DR test results including IT system recovery; RTO/RPO definitions; critical vendor BCP verification evidence
Vendor ManagementCurrent vendor inventory with risk tiers; critical vendor due diligence files; contracts reviewed for OCC 2023-17 provisions; documented concentration risk assessment
AuditCurrent IT audit plan; prior IT audit reports with management responses; open findings tracker with due dates, owners, and closure evidence

So What?

If your IT examination was structured around URSIT component ratings, the questions your examiner asked and the documentation they requested were organized differently than what the single-rating approach surfaces. Examiners aren’t asking “do you have an IT policy?” — they’re asking “is your technology risk program producing effective outcomes in these five areas?”

For most community banks and their fintech partners, the gap between having a policy document and having operational evidence of effective controls is where exam findings come from. An annual penetration test that hasn’t been done. A BCP that hasn’t been tested since before the pandemic. A vendor inventory that lists 30 vendors but doesn’t capture the cloud concentration underlying all of them. A board IT report that exists as a template but hasn’t been updated since 2023.

The five focus areas give you a clear preparation framework before your next examination cycle. The Operational Risk Program bundle includes the RCSA template, KRI library, loss event tracking kit, and enterprise risk management framework — the operational risk program components that underpin strong IT risk governance and give examiners substantive evidence of first- and second-line risk ownership when they review your program.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is URSIT and why is the FDIC replacing it?
URSIT — the Uniform Rating System for Information Technology — was established in 1978 and revised in 1999. It rates IT risk using four to six component categories (Audit, Management, Development and Acquisition, Support and Delivery) that are then combined into a composite IT rating. The FDIC is replacing URSIT because the component-based structure doesn't capture how integrated technology risk, cybersecurity, vendor management, and business continuity have become in modern financial institutions. The replacement approach uses a single holistic IT rating organized around five thematic areas: governance, cybersecurity, BCP, vendor management, and audit.
When did the FDIC IT examination changes take effect?
The shift was first documented in FDIC examinations in the Mid-Atlantic region in early 2026. NETBankAudit has observed FDIC examiners applying the single-rating approach rather than URSIT component ratings. No formal Federal Register update to URSIT has been published as of mid-2026, but institutions in any FDIC region should prepare for this approach — early examination results suggest it is not limited to one region.
What are the five focus areas of the new FDIC IT rating?
The five areas FDIC examiners are now organizing IT assessments around are: (1) Governance — board and management IT risk oversight, IT strategy, and IT risk appetite; (2) Cybersecurity — information security program, vulnerability management, access controls, and incident response; (3) Business Continuity Planning — BCP/DR documentation, testing, and recovery time and point objectives; (4) Vendor Management — due diligence, contract terms, concentration risk, and ongoing monitoring; and (5) Audit — IT audit scope, independence, and management's responsiveness to findings.
How does OCC Bulletin 2025-24 affect IT examination expectations for smaller institutions?
OCC Bulletin 2025-24, effective January 1, 2026, eliminated mandatory policy-based examination requirements in favor of a risk-proportionate model. This means examiners evaluate whether controls are appropriate to the institution's size, complexity, and risk profile — not whether they match a documentation template designed for large banks. For smaller community banks and fintechs, this is a practical relief: examiners are calibrating expectations to institutional risk rather than applying large-bank standards uniformly. The tradeoff is that pointing to a policy document alone is no longer sufficient evidence of compliance — examiners want to see that controls are actually working.
What is NIST CSF 2.0 and why does it appear in bank IT examination findings?
NIST Cybersecurity Framework 2.0 (published February 2024) expanded the original 2014 CSF with a new 'Govern' function and stronger guidance on third-party risk management and cybersecurity governance. All four federal banking agencies — OCC, FDIC, Federal Reserve, and NCUA — are increasingly using NIST CSF 2.0 function categories (Govern, Identify, Protect, Detect, Respond, Recover) in examination findings and correspondence. You don't have to formally adopt CSF 2.0, but understanding its vocabulary helps you interpret examiner feedback and structure your program in a way that maps clearly to current examiner expectations.
What evidence should community banks and fintechs prepare for the new IT examination areas?
For governance: most recent board IT risk report, IT strategic plan, IT risk appetite statement, and prior MRA resolution documentation. For cybersecurity: annual penetration test results, vulnerability assessment cadence, MFA implementation documentation, incident response plan and test record. For BCP: current BCP documentation, most recent test results including IT system recovery, RTO/RPO definitions, and vendor BCP verification. For vendor management: vendor inventory with risk tiers, critical vendor due diligence files, contracts with OCC 2023-17 provisions, and concentration risk assessment. For audit: current IT audit plan, prior audit reports with management responses, and open finding tracker.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Operational Risk Program

Build a complete ORM program: ERM framework, RCSA, loss monitoring, financial risk, KRIs, and the Contingency Funding Plan for chartered banks.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.