Skip to main content
Framework library
Framework module · ffiec-it-examination-handbook

FFIEC IT Examination Handbook

The living technology-supervision reference used by US financial institution examiners, with current booklets, work programs, laws, and guidance. It is supervisory guidance, not a certification; the separate FFIEC Cybersecurity Assessment Tool was retired in 2025.

Current booklets (living collection) · Federal Financial Institutions Examination Council

Standing today
Directory entry

00Answer

from the registry record
What is FFIEC IT Examination Handbook?
The living technology-supervision reference used by US financial institution examiners, with current booklets, work programs, laws, and guidance. It is supervisory guidance, not a certification; the separate FFIEC Cybersecurity Assessment Tool was retired in 2025.
Who does FFIEC IT Examination Handbook apply to?
FFIEC IT Examination Handbook applies to banking, credit unions, financial services, technology service providers, US, per Federal Financial Institutions Examination Council.
What is the current version of FFIEC IT Examination Handbook?
The current edition is Current booklets (living collection), issued by Federal Financial Institutions Examination Council. Source: https://ithandbook.ffiec.gov/.
What does an assessment under FFIEC IT Examination Handbook require?
No control catalog has been ingested for FFIEC IT Examination Handbook yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

FFIEC IT Examination Handbook is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Metadata only; the living handbook is not normalized or released as a product module. Any future ingest must pin each booklet revision and must not present the retired CAT as current.

02Registry record

checked 2026-08-28
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Architecture, infrastructure, and operations · Audit · Business continuity management · Development, acquisition, and maintenance · Information security · Management · Outsourcing technology services · Retail payment systems · Supervision of technology service providers · Wholesale payment systems
Applies to
banking · credit unions · financial services · technology service providers · US
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-28

03Version ledger

1 edition
Current booklets (living collection)Current editiondate not published

06Related frameworks

scored from registry facts
  1. APRA CPS 2302026 determination (effective 2026-07-01)

    Also applies to banking · Australia's cross-industry prudential standard for operational risk, continuity of critical operations, and material service-provider risk at APRA-regulated entities. It is a binding supervisory standard, not a certification.

  2. SOC for CybersecurityAICPA cybersecurity risk management reporting framework

    Also applies to financial services · AICPA's board- and enterprise-risk-oriented cybersecurity examination, distinct from SOC 2 — a description of an entity's cybersecurity risk-management program plus an opinion on its effectiveness, rather than a controls report for a specific service.

  3. Digital Operational Resilience ActRegulation (EU) 2022/2554

    Also applies to financial services · The EU digital-operational-resilience rulebook for financial entities, covering ICT risk, incidents, testing, information sharing, and third-party risk, plus an oversight framework for ICT providers designated critical.

  4. GLBA Safeguards Rule16 CFR Part 314 (amended 2023)

    Also applies to financial services · The FTC's mandatory security program for non-banking financial institutions — encryption, MFA, penetration testing, and breach reporting for events over 500 customers.

FFIEC IT Examination Handbook | ControlFrame