FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
    Filters
      Symbols
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      OCC Updates Cyber Audit Rules for Banks

      The Office of the Comptroller of the Currency (OCC) said in a bulletin released Monday (Sept. 21) that it updated the structure and references of the OCC Cybersecurity Supervision Work Program (CSW) used by examiners, without adding or changing any procedures.

      The changes to the CSW include updating the structure to align with the updated National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) categories and subcategories, addressing evolving risks and supporting risk-based bank information technology examinations, according to the bulletin.

      The bulletin maps to the Federal Financial Institutions Examination Council (FFIEC) Information Technology (IT) Examination Handbook and common cybersecurity frameworks, focuses on cybersecurity preparedness and supplements the OCC’s bank information technology examination procedures contained in the “Community Bank Supervision,” “Large Bank Supervision” and “Federal Branches and Agencies Supervision” booklets of the Comptroller’s Handbook and the FFIEC IT Examination Handbook booklets, the bulletin said.

      The bulletin rescinds OCC Bulletin 2023-22, “Cybersecurity: Cybersecurity Supervision Work Program,” which was issued on June 26, 2023, per the Monday bulletin.

      “The CSW does not establish new regulatory expectations, and banks are not expected to use this work program to assess cybersecurity preparedness,” OCC said in the bulletin. “The OCC continues to encourage, but does not require, the use of a standardized approach to assess and improve cybersecurity preparedness, and banks may choose from a variety of tools and frameworks available.”

      In an earlier, separate move, the OCC said in May that artificial intelligence is transforming the cyber threatlandscape and is one of several key issues facing banks.

      The OCC recommended that banks mitigate AI-enabled cyber risks by implementing more stringent security measures, including multifactor authentication and timely patch management; deploying AI to defend against threats; and understanding the potential benefits and risks of the increasingly advanced AI tools that are entering the market.

      PYMNTS reported in October 2025 that the OCC aims to focus oversight on material financial risks, including cyber and liquidity risks, rather than procedural issues. The report said that by tightening definitions rather than broadening them, the regulator may foster innovation by enabling banks to allocate resources toward measurable risks and collaborating on new solutions that strengthen resilience and transaction trust.


      Source: PYMNTS.com
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud