FFIEC (Federal Financial Institutions Examination Council)

The FFIEC is an interagency council, not a regulator. Its guidance does not carry the force of law, it sunset the Cybersecurity Assessment Tool in August 2025, and it has issued nothing on AI.

The FFIEC is the Federal Financial Institutions Examination Council, an interagency body that prescribes uniform principles, standards and report forms for the federal examination of financial institutions. It is not a regulator. In its own words, the Council "does not regulate financial institutions" — its members do, and they examine against guidance the Council publishes.

Who sits on it, and what it produces

Six voting members: the Federal Reserve Board, the FDIC, the NCUA, the OCC, the CFPB, and the chair of the State Liaison Committee, which represents state regulators. The common error is to describe it as five federal agencies — the State Liaison Committee chair votes, and the CFPB joined after Dodd-Frank.

Its most-cited output is the IT Examination Handbook, eleven booklets covering areas from information security to business continuity. Examiners work from these, which is why institutions treat them as de facto requirements even though they are not rules.

What force it carries

FFIEC guidance is examination guidance and does not have the force and effect of law. The member agencies said so formally: under the OCC's rule at 12 CFR part 4, subpart F, supervisory guidance does not create enforceable obligations, the agency does not take enforcement action based on guidance, and examiners will not criticize an institution for non-compliance with it.

Two qualifications keep that from being a license to ignore it. Guidelines issued under statutory authority — the GLBA information security standards, for instance — are a different instrument and do bind. And examiners may still cite guidance as illustrative of safe and sound practice, with the underlying safety-and-soundness authority doing the enforcing. Guidance is not enforceable as such; the conduct it describes still is. The same distinction separates SR 11-7 and SR 26-2 from an enforceable rule like FINRA Rule 3110.

Where AI sits, and where it does not

The FFIEC has issued no standalone guidance on AI, generative AI or agentic AI. The only AI material in the Handbook is a subsection of the Architecture, Infrastructure and Operations booklet published in June 2021 — which predates generative AI entirely and says nothing about autonomous agents.

The Council also sunset its Cybersecurity Assessment Tool on 31 August 2025, without issuing a replacement, pointing institutions instead to NIST CSF 2.0, CISA's Cybersecurity Performance Goals, the Cyber Risk Institute Profile and the CIS Critical Security Controls. So an institution examined on its AI controls today is examined against general IT and safety-and-soundness expectations, not against an AI framework — the same gap SR 26-2 created on the model risk side. What fills it is the institution's own record of what was permitted and what happened, which is the subject of examination readiness, tamper-evident audit logs and sample examination reports. The sector view is on the financial services page.

SR 11-7 and SR 26-2 · FINRA Rule 3110 · GLBA · NIST AI RMF · Full glossary

Verified against primary agency sources in September 2026. Supervisory guidance changes. If something here is out of date, tell us and we will correct it.

Put this in the path of your own agents.

Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.

Request a Demo Read the docs