the Banking Policy Institute The report recommends that financial institutions and their regulators reduce direct electronic transfers of sensitive financial and supervisory data, arguing that traditional practices such as uploading files to regulator-controlled portals or sending encrypted emails can create unnecessary cybersecurity risks.
In risk-based practices range Released on Thursday (July 23), the BPI called for greater reliance on systems that allow regulators to review sensitive information while financial institutions retain control of underlying data. Recommendations include company-hosted applications, screen sharing, on-site reviews, and for particularly sensitive information, oral briefings or summaries rather than full file transfers.
The framework comes after the discovery of cybersecurity incidents in Office of the Comptroller of the Currency In February 2025 and Ministry of Treasury in December 2024. These incidents helped prompt federal prudential regulators and financial institutions to reevaluate how sensitive supervisory information is shared.
BPI recommendations are based on a Joint statement This month from Federal Reserve, Federal Deposit Insurance Corporation The OCC created a coordinated approach to highly sensitive information during bank examinations. Under this approach, supervised institutions identify requested information that they consider to be highly sensitive, while regulatory bodies consider alternatives that minimize its collection and storage.
The main concern is that a direct transfer creates additional copies of sensitive information outside the financial institution’s security environment. Once transferred, an organization becomes less clear about who is accessing the information, whether it is copied or redistributed, how long it is retained, and how it is ultimately destroyed.
The BPI recommended reducing this exposure by limiting requests and submissions of informational materials to regulators’ responsibilities relating to safety and soundness, investor protection, market integrity or risk management. Where direct transfer remains necessary, institutions and regulators must agree in writing on storage locations, authorized users, security protections, retention periods, further sharing and eventual disposal.
Financial information received special attention. The framework identified strategic plans, capital plans, material non-public information, merger and acquisition data, financial statements, investment strategies and revenue analyzes as sensitive “strategy, planning and financial data”.
For most of this material, regulators must allow organizations to provide access through company-hosted applications, screen sharing or on-site review rather than requiring file transfer. Pre-deal M&A information provides stronger assurance because its disclosure may have market or competitive consequences. BPI recommended that this information be addressed through oral discussions or restricting regulators’ audiences and submitting summaries until the transaction becomes public.
The framework also proposes multi-layered protection that can reduce the amount of exposed data and ease of use. Organizations can provide aggregate information, summaries, samples, or excerpts rather than complete data sets; redact personal or commercially sensitive information; And use screenshots or other restricted formats instead of editable Word or Excel files. Access should be limited to examiners with a demonstrated need to know, with company-hosted systems controlling or tracking downloading, copying, printing and sharing.
These principles extend to trading and client account information, which BPI has classified as sensitive internal business data, along with personally identifiable information of clients and investors, fraud monitoring materials and AI-related models, data sources and validation records. Customer and employee PII must have additional protection through redaction, aggregation or excerpting and access to regulatory agencies is strictly limited.
Cybersecurity data underwrites some of the strongest constraints imposed by the framework. Network diagrams, configuration settings, vulnerabilities, penetration tests, and red teaming results can provide attackers with a road map to access financial institutions. BPI said the most sensitive technology information, including detailed network diagrams, IP addresses, control discussions and data center locations, should not be shared externally at all.
The recommendations also cover internal audit and anti-money laundering information Bank secrecy law Suspicious activity report materials, investigations, and privileged legal documents. Attorney-client privileges and work product materials generally should be withheld, BPI said, because the authority for regulatory scrutiny does not override privileges.
Overall, the framework seeks to transform supervisory data sharing from a model centered around file moving and copying to one based on controlled access and data minimization. The legitimate need for regulators to inspect institutions can be maintained while reducing the expanding attack surface created when highly sensitive financial data is copied to multiple external systems, BPI said.





