FFIEC IT Examination Handbook
The FFIEC IT Examination Handbook is a set of guidelines and best practices issued by the Federal Financial Institutions Examination Council (FFIEC) for financial institutions and the examiners who oversee them. It is organized into topical booklets, such as Information Security and Management, that describe expectations for how institutions handle technology risk. It serves as reference and training material for field examiners and as guidance for the institutions they review.
The FFIEC IT Examination Handbook is the Information Technology examination guidance maintained by the Federal Financial Institutions Examination Council and delivered through the IT Examination Handbook InfoBase. It comprises multiple topical booklets, including the Information Security booklet and the Management booklet, each of which sets examiner expectations for specific IT and risk domains; individual booklets are periodically revised and rescind and replace prior versions (for example, the Management booklet updated in 2015 replaced the June 2004 version). Practitioners should note that the Handbook is examination guidance for supervised financial institutions rather than a payment-security standard, and it is separate and distinct from PCI DSS and the related PCI standards; specific booklet content, structure, and effective dates should be confirmed against the currently published version in the FFIEC InfoBase.
Why it matters
For supervised financial institutions in the United States, the FFIEC IT Examination Handbook defines the expectations that field examiners use to evaluate how an institution manages technology and information security risk. Because the Handbook shapes the examination process itself, its booklets effectively communicate what regulators consider sound practice across domains such as information security and IT management. Institutions that align their controls and governance to the relevant booklets are better positioned to demonstrate the maturity of their risk management during examination.
The Handbook is examination guidance for supervised financial institutions rather than a payment-security standard, and it is separate and distinct from PCI DSS and the related PCI standards. A payment processor, acquirer, or merchant risk team should not treat FFIEC alignment as a substitute for PCI DSS validation, nor assume PCI DSS compliance satisfies FFIEC examiner expectations. The two frameworks address overlapping but different concerns, and an institution subject to both must map its controls against each one independently.
Because individual booklets are periodically revised and rescind and replace prior versions, the specific expectations in force can change over time. Practitioners should confirm booklet content, structure, and effective dates against the currently published version in the FFIEC IT Examination Handbook InfoBase rather than relying on an older edition, since referencing a superseded booklet may misstate current examiner expectations.
Who it's relevant to
Inside FFIEC IT Handbook
Common questions
Answers to the questions practitioners most commonly ask about FFIEC IT Handbook.