FFIEC Information Technology Examination Handbook (IT Handbook InfoBase)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
The FFIEC Information Technology Examination Handbook (IT Handbook) is the set of booklets that federal and state examiners use to evaluate technology risk management at financial institutions and their technology service providers. Published online as the IT Handbook InfoBase, it currently comprises ten booklets: Audit; Business Continuity Management; Development, Acquisition, and Maintenance; Information Security; Management; Architecture, Infrastructure, and Operations; Outsourcing Technology Services; Retail Payment Systems; Supervision of Technology Service Providers; and Wholesale Payment Systems. Each booklet pairs guidance with examination procedures and a downloadable work program.
The handbook is published by the Federal Financial Institutions Examination Council (FFIEC), the interagency body established by Congress in 1979 that comprises the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the National Credit Union Administration, the Office of the Comptroller of the Currency, and the Consumer Financial Protection Bureau, with state regulators represented through the State Liaison Committee. The FFIEC prescribes uniform principles and standards for the federal examination of financial institutions; the booklets are supervisory guidance rather than regulation, but examiners apply them to banks, savings associations, credit unions, and their service providers, and findings carry supervisory consequences.
Institutions implement the handbook by treating each booklet's expectations as the standard against which their IT governance, information security program, business continuity, third-party risk management, development practices, and payment operations will be examined. Compliance teams map booklet sections and examination procedures to internal policies and controls, gather the evidence examiners request, remediate gaps, and refresh the mapping when a booklet is revised; the most recent InfoBase update, in February 2026, removed references to reputational risk without adding requirements. The InfoBase also provides a glossary, cross-references to laws, regulations, and guidance, and an archive of superseded booklets.
Why it Matters
The FFIEC IT Handbook is the yardstick U.S. examiners use for technology risk, so aligning to it before an examination avoids findings, matters requiring attention, and enforcement actions.
Key benefits include:
- Examination readiness
Institutions that map controls and evidence to the booklets' examination procedures answer examiner requests quickly and completely.
- Consistent supervisory expectations
The same booklets are used by all federal banking agencies and many state regulators, so one program satisfies multiple examiners.
- Complete coverage of IT risk
The ten booklets span governance, security, resilience, development, outsourcing, and payments rather than security alone.
- Board and management accountability
The Management booklet sets clear expectations for board oversight, IT risk management structure, and reporting.
- Third-party oversight
The Outsourcing Technology Services and Supervision of Technology Service Providers booklets define how institutions and examiners assess service providers.
How it Works
The handbook is organized as independent booklets, each with an introduction, guidance chapters, and appendices containing examination procedures, a glossary, and references to laws, regulations, and guidance. The Management booklet establishes IT governance and IT risk management (identification, measurement, mitigation, monitoring, and reporting); the Information Security booklet covers governance of the security program, risk identification, measurement, and mitigation, security operations, and program effectiveness through testing and assurance; the remaining booklets address audit, business continuity, development and acquisition, architecture and operations, outsourcing, payment systems, and the supervision of technology service providers.
Examiners use the booklets' examination procedures and work programs to scope and conduct IT examinations and to rate institutions under the Uniform Rating System for Information Technology. Institutions prepare by performing self-assessments against each relevant booklet, maintaining policies and standards that reflect the guidance, keeping asset inventories, risk assessments, testing results, vendor due diligence, incident and continuity exercise records, and board reporting current, and by tracking remediation of prior examination findings. Booklets are revised individually, so programs must monitor the InfoBase for updates.
Within SmartSuite, teams can operationalize the IT Handbook by loading each booklet's sections and examination procedures as requirements, mapping them to policies, controls, and evidence, assigning owners and review dates, and tracking examination requests, findings, and remediation in one workspace. Dashboards show readiness by booklet and give management and the board the reporting the handbook expects.
Key Elements
- IT governance and management
Board oversight, IT management structure, enterprise architecture, and the IT risk management process defined in the Management booklet.
- Information security program
Governance, risk identification and measurement, control implementation, security operations, and assurance testing set out in the Information Security booklet.
- Business continuity management
Business impact analysis, resilience planning, testing, and exercises covered by the Business Continuity Management booklet.
- Development, architecture, and operations
Controls over software development, procurement, change management, infrastructure design, and delivery of IT services.
- Third-party and service provider oversight
Risk management of outsourced technology services and the agencies' supervisory program for technology service providers.
- Payment systems
Risk identification and controls for retail and wholesale payment systems, including large-value transfers.
- IT audit
Characteristics of an effective IT audit function and how examiners evaluate audit independence, coverage, and follow-up.
Framework Scope
The IT Handbook applies to institutions supervised by the FFIEC member agencies, including national and state banks, savings associations, credit unions, and holding companies, and to the technology service providers the agencies examine. It covers the full scope of information technology risk: governance, information security, business continuity, development and acquisition, architecture and operations, outsourcing, retail and wholesale payments, and IT audit. Institutions of every size are examined against it, with the depth of review scaled to complexity and risk profile.
Framework Objectives
The FFIEC IT Handbook is intended to help examiners and institutions achieve the following outcomes.
Give examiners uniform guidance and procedures for assessing IT risk management across all federally supervised institutions.
Set clear expectations for board and senior management oversight of information technology.
Ensure institutions identify, measure, mitigate, and monitor technology and information security risk.
Promote resilience through business continuity planning, testing, and incident response.
Establish sound practices for developing, acquiring, operating, and outsourcing technology.
Protect the safety and soundness of payment systems and the security of customer information.
Framework in Context
The IT Handbook is the operational reference behind U.S. banking IT supervision: it implements the Interagency Guidelines Establishing Information Security Standards issued under the Gramm-Leach-Bliley Act, complements the FFIEC Cybersecurity Assessment Tool, the OCC's Cybersecurity Supervision Work Program, and the 2023 Interagency Guidance on Third-Party Relationships, and is cross-referenced by NYDFS 23 NYCRR 500, the NAIC Insurance Data Security Model Law, and FINRA cybersecurity guidance. Its Information Security and Management booklets align with NIST CSF 2.0, NIST SP 800-53, ISO/IEC 27001, and COBIT 2019, and institutions commonly reuse SOC 2 reports and PCI DSS assessments as evidence during examinations.
Common Framework Mappings
The FFIEC IT Handbook is commonly mapped to cybersecurity, control, and financial services frameworks so that institutions can present one control set to examiners, auditors, and customers.
Mapped frameworks include:
FFIEC CAT
GLBA Safeguards Rule (16 CFR Part 314)
OCC CSWP
NYDFS 23 NYCRR 500
NAIC MDL-668
FINRA Cybersecurity
NIST CSF 2.0
NIST 800-53 Rev. 5
ISO 27001:2022
COBIT 2019
CIS Controls v8.1
SOC 2
PCI DSS 4.0.1
SOX
MAS TRM 2021
Interagency Guidelines Establishing Information Security Standards
Interagency Guidance on Third-Party Relationships: Risk Management (2023)
NCUA Rules and Regulations Part 748
- ClassificationCategoryFinancial Services IT SupervisionDomainFinancial Services RegulationFramework FamilyOther
- Regulatory ContextTypeGuidanceLegal InstrumentGuidanceSectorFinancial SectorIndustryFinancial Services
- Region / PublisherRegionNorth AmericaRegion DetailUnited StatesPublisherFederal Financial Institutions Examination Council (FFIEC)
- VersioningVersionInfoBase; ten current booklets, revised individually (latest InfoBase update February 27, 2026)Effective DateFebruary 27, 2026 (latest InfoBase update; booklets dated individually)Issue DateAugust 29, 2024 (latest booklet revision: Development, Acquisition, and Maintenance)
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
The IT Handbook booklets and work programs are U.S. government publications available free from the FFIEC InfoBase; the platform links to the official booklets rather than reproducing them.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports FFIEC IT Handbook
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
For the FFIEC IT Handbook, SmartSuite maps each booklet's examination procedures to your policies, controls, and evidence, tracks examiner requests and findings, and produces the board reporting the Management booklet expects.
Booklet Requirements Library
Hold each booklet's sections and examination procedures as requirements linked to the policies and controls that satisfy them.
Control Owners and Review Cadence
Assign owners and schedule risk assessments, access reviews, testing, and policy approvals on the cycle examiners expect.
Examination Evidence and Audit Trail
Store evidence with links to requirements, timestamps, and approvers so examiner requests are answered from one record.
Testing, Findings, and Remediation
Track self-assessments, audit findings, examination findings, and remediation through verified closure.
Third-Party and Resilience Alignment
Connect service provider due diligence, contracts, and continuity exercises to the booklets that require them.
Board and Examiner Reporting
Report readiness by booklet, open findings, and risk posture to the board and to examiners.
Related frameworks

The FFIEC Cybersecurity Assessment Tool helps U.S. financial institutions assess cybersecurity preparedness and manage cyber risk.

The GLBA Safeguards Rule requires financial institutions to implement security programs to protect consumer financial information.

The OCC Cybersecurity Supervision Work Program guides examiners in assessing banks' cybersecurity risk management, controls, and incident response.

23 NYCRR 500 requires New York-regulated financial institutions to implement minimum cybersecurity controls protecting customer data and operational resilience.

NAIC MDL-668 establishes data security, risk management, and breach notification requirements for insurance companies and related entities.

FINRA Cybersecurity Guidance provides regulatory expectations for broker-dealers and firms to strengthen cybersecurity and protect client assets.
Frequently Asked Questions For FFIEC IT Handbook
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

