FFIEC IT Examination Handbook
The living technology-supervision reference used by US financial institution examiners, with current booklets, work programs, laws, and guidance. It is supervisory guidance, not a certification; the separate FFIEC Cybersecurity Assessment Tool was retired in 2025.
Current booklets (living collection) · Federal Financial Institutions Examination Council
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
FFIEC IT Examination Handbook is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Metadata only; the living handbook is not normalized or released as a product module. Any future ingest must pin each booklet revision and must not present the retired CAT as current.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Architecture, infrastructure, and operations · Audit · Business continuity management · Development, acquisition, and maintenance · Information security · Management · Outsourcing technology services · Retail payment systems · Supervision of technology service providers · Wholesale payment systems
- Applies to
- banking · credit unions · financial services · technology service providers · US
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-28
03Version ledger
| Current booklets (living collection) | Current edition | date not published |
06Related frameworks
- APRA CPS 2302026 determination (effective 2026-07-01)
Also applies to banking · Australia's cross-industry prudential standard for operational risk, continuity of critical operations, and material service-provider risk at APRA-regulated entities. It is a binding supervisory standard, not a certification.
- SOC for CybersecurityAICPA cybersecurity risk management reporting framework
Also applies to financial services · AICPA's board- and enterprise-risk-oriented cybersecurity examination, distinct from SOC 2 — a description of an entity's cybersecurity risk-management program plus an opinion on its effectiveness, rather than a controls report for a specific service.
- Digital Operational Resilience ActRegulation (EU) 2022/2554
Also applies to financial services · The EU digital-operational-resilience rulebook for financial entities, covering ICT risk, incidents, testing, information sharing, and third-party risk, plus an oversight framework for ICT providers designated critical.
- GLBA Safeguards Rule16 CFR Part 314 (amended 2023)
Also applies to financial services · The FTC's mandatory security program for non-banking financial institutions — encryption, MFA, penetration testing, and breach reporting for events over 500 customers.