Financial Services IT Supervision
DETAIL

FFIEC Information Technology Examination Handbook (IT Handbook InfoBase)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

The FFIEC Information Technology Examination Handbook (IT Handbook) is the set of booklets that federal and state examiners use to evaluate technology risk management at financial institutions and their technology service providers. Published online as the IT Handbook InfoBase, it currently comprises ten booklets: Audit; Business Continuity Management; Development, Acquisition, and Maintenance; Information Security; Management; Architecture, Infrastructure, and Operations; Outsourcing Technology Services; Retail Payment Systems; Supervision of Technology Service Providers; and Wholesale Payment Systems. Each booklet pairs guidance with examination procedures and a downloadable work program.

The handbook is published by the Federal Financial Institutions Examination Council (FFIEC), the interagency body established by Congress in 1979 that comprises the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the National Credit Union Administration, the Office of the Comptroller of the Currency, and the Consumer Financial Protection Bureau, with state regulators represented through the State Liaison Committee. The FFIEC prescribes uniform principles and standards for the federal examination of financial institutions; the booklets are supervisory guidance rather than regulation, but examiners apply them to banks, savings associations, credit unions, and their service providers, and findings carry supervisory consequences.

Institutions implement the handbook by treating each booklet's expectations as the standard against which their IT governance, information security program, business continuity, third-party risk management, development practices, and payment operations will be examined. Compliance teams map booklet sections and examination procedures to internal policies and controls, gather the evidence examiners request, remediate gaps, and refresh the mapping when a booklet is revised; the most recent InfoBase update, in February 2026, removed references to reputational risk without adding requirements. The InfoBase also provides a glossary, cross-references to laws, regulations, and guidance, and an archive of superseded booklets.

Why it Matters

The FFIEC IT Handbook is the yardstick U.S. examiners use for technology risk, so aligning to it before an examination avoids findings, matters requiring attention, and enforcement actions.

Key benefits include:

  • Examination readiness

Institutions that map controls and evidence to the booklets' examination procedures answer examiner requests quickly and completely.

  • Consistent supervisory expectations

The same booklets are used by all federal banking agencies and many state regulators, so one program satisfies multiple examiners.

  • Complete coverage of IT risk

The ten booklets span governance, security, resilience, development, outsourcing, and payments rather than security alone.

  • Board and management accountability

The Management booklet sets clear expectations for board oversight, IT risk management structure, and reporting.

  • Third-party oversight

The Outsourcing Technology Services and Supervision of Technology Service Providers booklets define how institutions and examiners assess service providers.

How it Works

The handbook is organized as independent booklets, each with an introduction, guidance chapters, and appendices containing examination procedures, a glossary, and references to laws, regulations, and guidance. The Management booklet establishes IT governance and IT risk management (identification, measurement, mitigation, monitoring, and reporting); the Information Security booklet covers governance of the security program, risk identification, measurement, and mitigation, security operations, and program effectiveness through testing and assurance; the remaining booklets address audit, business continuity, development and acquisition, architecture and operations, outsourcing, payment systems, and the supervision of technology service providers.

Examiners use the booklets' examination procedures and work programs to scope and conduct IT examinations and to rate institutions under the Uniform Rating System for Information Technology. Institutions prepare by performing self-assessments against each relevant booklet, maintaining policies and standards that reflect the guidance, keeping asset inventories, risk assessments, testing results, vendor due diligence, incident and continuity exercise records, and board reporting current, and by tracking remediation of prior examination findings. Booklets are revised individually, so programs must monitor the InfoBase for updates.

Within SmartSuite, teams can operationalize the IT Handbook by loading each booklet's sections and examination procedures as requirements, mapping them to policies, controls, and evidence, assigning owners and review dates, and tracking examination requests, findings, and remediation in one workspace. Dashboards show readiness by booklet and give management and the board the reporting the handbook expects.

Key Elements

  • IT governance and management

Board oversight, IT management structure, enterprise architecture, and the IT risk management process defined in the Management booklet.

  • Information security program

Governance, risk identification and measurement, control implementation, security operations, and assurance testing set out in the Information Security booklet.

  • Business continuity management

Business impact analysis, resilience planning, testing, and exercises covered by the Business Continuity Management booklet.

  • Development, architecture, and operations

Controls over software development, procurement, change management, infrastructure design, and delivery of IT services.

  • Third-party and service provider oversight

Risk management of outsourced technology services and the agencies' supervisory program for technology service providers.

  • Payment systems

Risk identification and controls for retail and wholesale payment systems, including large-value transfers.

  • IT audit

Characteristics of an effective IT audit function and how examiners evaluate audit independence, coverage, and follow-up.

Framework Scope

The IT Handbook applies to institutions supervised by the FFIEC member agencies, including national and state banks, savings associations, credit unions, and holding companies, and to the technology service providers the agencies examine. It covers the full scope of information technology risk: governance, information security, business continuity, development and acquisition, architecture and operations, outsourcing, retail and wholesale payments, and IT audit. Institutions of every size are examined against it, with the depth of review scaled to complexity and risk profile.

Framework Objectives

The FFIEC IT Handbook is intended to help examiners and institutions achieve the following outcomes.

Give examiners uniform guidance and procedures for assessing IT risk management across all federally supervised institutions.

Set clear expectations for board and senior management oversight of information technology.

Ensure institutions identify, measure, mitigate, and monitor technology and information security risk.

Promote resilience through business continuity planning, testing, and incident response.

Establish sound practices for developing, acquiring, operating, and outsourcing technology.

Protect the safety and soundness of payment systems and the security of customer information.

Framework in Context

The IT Handbook is the operational reference behind U.S. banking IT supervision: it implements the Interagency Guidelines Establishing Information Security Standards issued under the Gramm-Leach-Bliley Act, complements the FFIEC Cybersecurity Assessment Tool, the OCC's Cybersecurity Supervision Work Program, and the 2023 Interagency Guidance on Third-Party Relationships, and is cross-referenced by NYDFS 23 NYCRR 500, the NAIC Insurance Data Security Model Law, and FINRA cybersecurity guidance. Its Information Security and Management booklets align with NIST CSF 2.0, NIST SP 800-53, ISO/IEC 27001, and COBIT 2019, and institutions commonly reuse SOC 2 reports and PCI DSS assessments as evidence during examinations.

Common Framework Mappings

The FFIEC IT Handbook is commonly mapped to cybersecurity, control, and financial services frameworks so that institutions can present one control set to examiners, auditors, and customers.

Mapped frameworks include:

FFIEC CAT

GLBA Safeguards Rule (16 CFR Part 314)

OCC CSWP

NYDFS 23 NYCRR 500

NAIC MDL-668

FINRA Cybersecurity

NIST CSF 2.0

NIST 800-53 Rev. 5

ISO 27001:2022

COBIT 2019

CIS Controls v8.1

SOC 2

PCI DSS 4.0.1

SOX

MAS TRM 2021

Interagency Guidelines Establishing Information Security Standards

Interagency Guidance on Third-Party Relationships: Risk Management (2023)

NCUA Rules and Regulations Part 748

At a Glance
FFIEC Information Technology Examination Handbook (IT Handbook InfoBase)
  • Classification
    Category
    Financial Services IT Supervision
    Domain
    Financial Services Regulation
    Framework Family
    Other
  • Regulatory Context
    Type
    Guidance
    Legal Instrument
    Guidance
    Sector
    Financial Sector
    Industry
    Financial Services
  • Region / Publisher
    Region
    North America
    Region Detail
    United States
    Publisher
    Federal Financial Institutions Examination Council (FFIEC)
  • Versioning
    Version
    InfoBase; ten current booklets, revised individually (latest InfoBase update February 27, 2026)
    Effective Date
    February 27, 2026 (latest InfoBase update; booklets dated individually)
    Issue Date
    August 29, 2024 (latest booklet revision: Development, Acquisition, and Maintenance)
  • Adoption
    Adoption Model
    Regulatory Compliance
    Implementation Complexity
    High
  • Official Reference
License Information

License included / downloadable: Yes

The IT Handbook booklets and work programs are U.S. government publications available free from the FFIEC InfoBase; the platform links to the official booklets rather than reproducing them.

Framework text is licensed by its publisher and is included only where stated above.

SMARTSUITE

How SmartSuite Supports FFIEC IT Handbook

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

For the FFIEC IT Handbook, SmartSuite maps each booklet's examination procedures to your policies, controls, and evidence, tracks examiner requests and findings, and produces the board reporting the Management booklet expects.

Booklet Requirements Library

Hold each booklet's sections and examination procedures as requirements linked to the policies and controls that satisfy them.

Control Owners and Review Cadence

Assign owners and schedule risk assessments, access reviews, testing, and policy approvals on the cycle examiners expect.

Examination Evidence and Audit Trail

Store evidence with links to requirements, timestamps, and approvers so examiner requests are answered from one record.

Testing, Findings, and Remediation

Track self-assessments, audit findings, examination findings, and remediation through verified closure.

Third-Party and Resilience Alignment

Connect service provider due diligence, contracts, and continuity exercises to the booklets that require them.

Board and Examiner Reporting

Report readiness by booklet, open findings, and risk posture to the board and to examiners.

Related frameworks

FFIEC CAT

The FFIEC Cybersecurity Assessment Tool helps U.S. financial institutions assess cybersecurity preparedness and manage cyber risk.

GLBA Safeguards Rule (16 CFR Part 314)

The GLBA Safeguards Rule requires financial institutions to implement security programs to protect consumer financial information.

OCC CSWP

The OCC Cybersecurity Supervision Work Program guides examiners in assessing banks' cybersecurity risk management, controls, and incident response.

NYDFS 23 NYCRR 500

23 NYCRR 500 requires New York-regulated financial institutions to implement minimum cybersecurity controls protecting customer data and operational resilience.

NAIC MDL-668

NAIC MDL-668 establishes data security, risk management, and breach notification requirements for insurance companies and related entities.

FINRA Cybersecurity

FINRA Cybersecurity Guidance provides regulatory expectations for broker-dealers and firms to strengthen cybersecurity and protect client assets.

NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

COBIT 2019

COBIT 2019 is a governance framework that helps organizations govern and manage IT to meet business goals, risks, and compliance.

ONBOARDING FAQS

Frequently Asked Questions For FFIEC IT Handbook

No items found.

Operationalize FFIEC IT Handbook with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.