Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity NewswireTechnologies & SolutionsCybersecurity News

US bank regulators issue best practices to improve operational resilience

The Keys to the Treasury Kingdom
November 10, 2020

The Office of the Comptroller of the Currency, the Board of Governors of the Federal Reserve System, and the Federal Deposit Insurance Corporation (collectively, the agencies) issued an interagency paper titled “Sound Practices to Strengthen Operational Resilience.” The sound practices paper generally describes standards for operational resilience set forth in the agencies’ existing rules and guidance for domestic banking organizations that have average total consolidated assets greater than or equal to (1) $250 billion or (2) $100 billion and have $75 billion or more in average cross-jurisdictional activity, average weighted short-term wholesale funding, average nonbank assets, or average off-balance-sheet exposure.

Although operational resilience is important for all national banks and federal savings associations (collectively, banks), the sound practices paper is directed to the largest and most complex domestic banking organizations.

Highlights

The sound practices paper

  • outlines standards for operational resilience set forth in the agencies’ rules and guidance for domestic banking organizations that have average total consolidated assets greater than or equal to (1) $250 billion or (2) $100 billion and have $75 billion or more in average cross-jurisdictional activity, average weighted short-term wholesale funding, average nonbank assets, or average off-balance-sheet exposure.
  • promotes a principles-based approach for effective governance, robust scenario analysis, secure and resilient information systems, and thorough surveillance and reporting.
  • includes an appendix focused on sound practices for managing cyber risk.

Background

Over the last decade, the agencies have instituted various reforms aimed at enhancing the prudential framework and improving the financial resilience of domestic banking organizations and the financial system more broadly. These reforms – which included stronger capital and liquidity requirements as well as enhanced recovery and resolution mechanisms – reduce the likelihood and severity of a banking organization’s failure.

Notwithstanding these improvements to financial stability, banking organizations in recent years have experienced significant challenges from a wide range of disruptive events, including technology-based failures, cyber incidents, pandemics, and natural disasters. Such events, combined with a growing reliance on third-party service providers, expose banking organizations to a range of operational risks. These risks underscore the importance for banking organizations to strengthen their operational resilience, which the sound practices paper describes as the ability to deliver operations, including critical operations and core business lines, through a disruption from any hazard. These disruptions could include technology-based failures, cyber incidents, natural disasters, and third-party failures.

The agencies recognize that technological developments have provided banks with new tools, such as cloud-based computing resources, to strengthen their operational resilience. Nonetheless, the agencies view the risk of a significant operational disruption as material, and such a disruption could jeopardize gains in financial stability and resilience. While efforts to strengthen operational resilience may not prevent a disruption from occurring, a pragmatic, well-constructed approach to operational resilience can help minimize the adverse effects of an operational disruption and enhance a bank’s ability to withstand a disruption.

The sound practices paper brings together existing regulations, guidance, and common industry standards to provide a comprehensive approach that banks may use to strengthen and maintain their operational resilience. Effective governance grounds the sound practices paper. Robust operational risk and business continuity management anchor the sound practices, which are informed by rigorous scenario analyses and consider third-party risks. Secure and resilient information systems underpin the approach to operational resilience, which is supported by thorough surveillance and reporting. The sound practices paper does not revise the agencies’ existing regulations or guidance.

Given the significance and technical nature of cybersecurity risk, which constitutes one of the most important types of operational risk, appendix A of the sound practices paper provides a separate collection of sound practices for managing cyber risk. Appendix B of the sound practices paper provides a glossary of terms used in the paper.

The issuance of these sound practices would facilitate ongoing discourse with the public on operational resilience. In the coming months, the agencies intend to convene discussions with the public on further steps to improve operational resilience. Continued dialogue with the public will allow the agencies to further refine their approach to support the operational resilience of banking organizations. In these forthcoming discussions, the agencies will be particularly interested in discussing ways in which the largest and most complex banking organizations can improve the operational resilience of critical operations and core business lines of a banking organization’s material entities and how they and supervisors can measure operational resilience and banking organizations’ progress toward achieving it. Given that many of these banking organizations have extensive cross-border activities, the agencies will seek to minimize the potential for market fragmentation and to align best practices for operational resilience.1 The agencies may update the sound practices to reflect input from these discussions.

Applicability

Although operational resilience is important to all banking organizations, the sound practices described in the paper are directed to the largest and most complex domestic banking organizations. The paper describes sound practices drawn from existing regulations and guidance for individual national banks, state member banks, state nonmember banks, savings associations, U.S. bank holding companies, and savings and loan holding companies that have average total consolidated assets greater than or equal to (1) $250 billion or (2) $100 billion and have $75 billion or more in average cross-jurisdictional activity, average weighted short-term wholesale funding, average nonbank assets, or average off-balance-sheet exposure.2 The sound practices paper does not set forth any new regulations or guidance; rather, the paper brings together the existing regulations, guidance, and common industry standards in one place to assist in the development of comprehensive approaches to operational resilience.

The agencies acknowledge that operational resilience is important to banking organizations of all sizes and that any bank may find elements of the sound practices useful as it considers operational risk and resilience challenges. Because the sound practices emphasize critical operations of a banking organization’s material entities, which generally are characteristic of large banking organizations, the sound practices paper is not addressed to smaller banking organizations.

A key objective of the sound practices paper is promoting harmonization across international and domestic frameworks regarding operational resilience, and the agencies are aware of similar international efforts to improve operational resilience.

To view the paper, please visit https://www.occ.gov/news-issuances/news-releases/2020/nr-occ-2020-144a.pdf

KEYWORDS: bank security governance risk operational security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • healthcare-freepik1170x658v57.jpg

    4 best practices to improve healthcare cybersecurity

    See More
  • cybersecurity

    8 best practices to improve cybersecurity program performance

    See More
  • NIST Releases Cybersecurity Guide for Energy Sector to Improve Operational Technology

    See More
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing