In a risk-based practices framework released Thursday (July 23), BPI called for greater reliance on systems that allow regulators to review sensitive information while financial institutions retain control over the underlying data. The recommendations include firm-hosted applications, screen sharing, on-site reviews and, for particularly sensitive information, oral briefings or summaries rather than transfers of complete files.
The framework comes after cybersecurity incidents discovered at the Office of the Comptroller of the Currency in February 2025 and the Treasury Department in December 2024. These incidents helped prompt federal prudential regulators and financial institutions to reassess how sensitive supervisory information is exchanged.
BPI’s recommendations build on a joint statement this month from the Federal Reserve, Federal Deposit Insurance Corp. and the OCC establishing a coordinated approach to highly sensitive information during bank examinations. Under that approach, supervised institutions identify requested information they consider highly sensitive, while regulators consider alternatives that minimize collection and storage.
The central concern is that direct transfer creates additional copies of sensitive information outside a financial institution’s security environment. Once transferred, the institution has less visibility into who accesses the information, whether it is copied or redistributed, how long it is retained and how it is ultimately destroyed.
BPI recommended minimizing that exposure by limiting requests and submissions to information material to regulators’ responsibilities for safety and soundness, investor protection, market integrity or risk management. Where direct transfer remains necessary, institutions and regulators should agree in writing on storage locations, authorized users, security protections, retention periods, further sharing and eventual disposal.
Financial information received particular attention. The framework identified strategic plans, capital plans, material nonpublic information, merger-and-acquisition data, financial statements, investment strategies and revenue analyses as sensitive “Strategy, Planning & Financial Data.”
For most such material, regulators should permit institutions to provide access through firm-hosted applications, screen sharing or on-site review rather than requiring files to be transferred. Pre-deal M&A information warrants even stronger safeguards because disclosure could have market or competitive consequences. BPI recommended handling such information through oral discussions or restricting the regulator audience and providing summaries until the transaction becomes public.
The framework also proposed layered protections that can reduce the amount and usability of data exposed. Institutions could provide aggregated information, summaries, samples or excerpts instead of complete datasets; redact personally identifiable or commercially sensitive information; and use screenshots or other restricted formats instead of editable Word or Excel files. Access should be limited to examiners with a demonstrable need to know, with firm-hosted systems controlling or tracking downloading, copying, printing and sharing.
These principles extend to trading and client account information, which BPI classified as sensitive internal business data, along with customer and investor PII, fraud-monitoring materials and artificial intelligence-related models, data sources and validation records. Customer and employee PII should receive additional protection through redaction, aggregation or excerpts and tightly restricted regulator access.
Cybersecurity data warrants some of the framework’s strongest restrictions. Network diagrams, configuration settings, vulnerabilities, penetration tests and red-team results could provide attackers with a roadmap into financial institutions. BPI said the most sensitive technology information, including detailed network diagrams, IP addresses, control discussions and data center locations, should not be shared externally at all.
The recommendations also cover internal audit information, anti-money laundering and Bank Secrecy Act suspicious activity report materials, investigations and privileged legal documents. Attorney-client privileged and work-product materials generally should be withheld, BPI said, because regulatory examination authority does not override privilege.
Overall, the framework seeks to shift supervisory data sharing from a model centered on transmitting and duplicating files to one based on controlled access and data minimization. BPI said regulators’ legitimate need to inspect institutions can be preserved while reducing the expanding attack surface created when highly sensitive financial data is copied into multiple external systems.