MARKETS, CREDIT & POLICYAbout & methodology
c.The Credit CurrentDAILY INTELLIGENCEWhat matters in Credit
Back to newsfeed
Policy · Supervisory update

OCC updates cyber examination mapping without new procedures

The OCC’s September 21 cybersecurity bulletin updates the structure and references of its examiner work program to align with the evolving NIST framework. The agency explicitly says examination procedures are unchanged and no new regulatory expectations are created.

1 min read · estimatedAI-generated analysis · Methodology

Why it matters

Analysis: update control crosswalks and evidence ownership before treating the release as a new remediation mandate. The useful test is whether existing incident response, recovery and third-party evidence can be retrieved and explained under the revised mapping.

What remains uncertain

Banks are not required to use the OCC work program as their own assessment tool. A mapping change does not establish that a particular bank’s controls are sufficient.

Sources