BPI data sharing safeguards target regulator file transfers
BPI urged banks and regulators to curb direct transfers of sensitive files after recent cybersecurity incidents at federal agencies.
By Rafael Ortiz · Fintech Correspondent
· 3 min read
The Bank Policy Institute is calling for banks and federal supervisors to reduce direct electronic movement of sensitive financial and supervisory files, citing cybersecurity risks from duplicating data outside a firm’s systems. The BPI data sharing safeguards, set out in a framework released July 23, would affect how regulators review materials during examinations, including financial plans, client records, cyber information and privileged documents.
BPI said common methods such as encrypted email and regulator-run upload portals can leave banks with less control over access, copying, retention and destruction once information leaves their environment. The group argued that supervisors can still examine institutions while relying more often on controlled access, narrower requests and alternatives to full file transfers.
The framework follows cybersecurity incidents identified at the Office of the Comptroller of the Currency in February 2025 and at the Treasury Department in December 2024. According to BPI, those events contributed to a reassessment by prudential regulators and financial institutions of how sensitive supervisory information is exchanged.
What are BPI data sharing safeguards?
BPI’s proposed safeguards are practices meant to limit when sensitive information is transferred to regulators and to reduce the usefulness of any data that must be shared. The framework favors firm-hosted applications, screen sharing, on-site reviews, summaries, samples, redactions and oral briefings, depending on the sensitivity of the material.
The recommendations build on a joint statement this month from the Federal Reserve, the Federal Deposit Insurance Corp. and the OCC. That statement established a coordinated process for highly sensitive information in bank examinations, with supervised institutions identifying materials they consider highly sensitive and regulators considering approaches that limit collection and storage.
BPI said direct transfers should be limited to information material to regulatory responsibilities, including safety and soundness, investor protection, market integrity and risk management. When transfers are necessary, the group recommended written agreements covering where the data will be stored, who may access it, what security controls apply, how long it will be retained, whether it can be shared further and how it will be disposed of.
The framework gives particular attention to strategy, planning and financial data. BPI identified strategic plans, capital plans, material nonpublic information, merger-and-acquisition materials, financial statements, investment strategies and revenue analyses as sensitive categories.
For most of those materials, BPI said regulators should review information through bank-controlled tools, screen sharing or in-person inspection rather than require file submissions. The group said pre-announcement M&A information merits stronger limits because disclosure could affect markets or competition, and it recommended oral discussions, smaller regulator audiences or summaries until a transaction is public.
BPI also proposed layered controls for trading records, client account information, customer and investor personally identifiable information, fraud-monitoring materials, and artificial intelligence models, data sources and validation records. Those controls include aggregation, excerpts, redaction and restrictions that prevent or track downloading, copying, printing and onward sharing.
Cybersecurity data received some of the strongest proposed limits. BPI said network diagrams, configuration settings, vulnerabilities, penetration-test findings and red-team results could help attackers understand a bank’s systems. The framework said the most sensitive technology details, including detailed network diagrams, IP addresses, control discussions and data center locations, should not be shared outside the institution.
The framework also covers internal audit records, anti-money laundering and Bank Secrecy Act suspicious activity report materials, investigations and privileged legal documents. BPI said attorney-client privileged and work-product materials generally should be withheld, arguing that examination authority does not override legal privilege.
This story draws on original reporting from PYMNTS.