Changeflow GovPing Banking & Finance FFIEC IT Handbook - Architecture, Infrastructur...
Routine Guidance Amended Final

FFIEC IT Handbook - Architecture, Infrastructure, and Operations Booklet Updated

Favicon for ithandbook.ffiec.gov FFIEC IT Examination Handbook Updates
Detected March 20th, 2026
Email

Summary

The Federal Financial Institutions Examination Council (FFIEC) has updated its IT Examination Handbook with a revised 'Architecture, Infrastructure, and Operations' booklet. This update provides guidance on enterprise-wide approaches to technology design, IT infrastructure implementation, and service delivery for financial institutions.

What changed

The FFIEC has updated the 'Architecture, Infrastructure, and Operations' booklet within its IT Examination Handbook. This guidance focuses on enterprise-wide, process-oriented approaches to technology design, IT infrastructure components, and the delivery of services and value to customers within financial institutions. The update includes revised content across various sections, including governance, board and senior management responsibilities, IT management roles, and policies and procedures.

Financial institutions should review the updated booklet to ensure their IT architecture, infrastructure, and operations align with the latest guidance. While this is an update to existing guidance and not a new regulation, adherence is expected as part of prudent IT risk management and examination processes. Compliance officers should familiarize themselves with the revised content, particularly regarding strategic planning, enterprise risk management, and specific roles like Chief Architect and Chief Data Officer.

What to do next

  1. Review the updated FFIEC IT Handbook 'Architecture, Infrastructure, and Operations' booklet.
  2. Assess current IT architecture, infrastructure, and operations against the revised guidance.
  3. Update internal policies and procedures as necessary to align with FFIEC recommendations.

Source document (simplified)

Architecture, Infrastructure, and Operations

The "Architecture, Infrastructure, and Operations" booklet is one in a series of booklets that compose the Federal Financial Institutions Examination Council (FFIEC) Information Technology Examination Handbook (IT Handbook). This booklet focuses on enterprise-wide, process-oriented approaches that relate to the design of technology within the overall business structure, implementation of IT infrastructure components, and delivery of services and value for customers.

Go to Introduction Download Booklet Download IT WorkProgram

Booklet Contents
- Introduction
- I Architecture, Infrastructure, and Operations
- II Architecture, Infrastructure, and Operations Governance
- II.A Board and Senior Management Responsibilities
- II.A.1 Strategic Planning
- II.A.2 Enterprise Risk Management
- II.B Other Roles and Responsibilities
- II.B.1 IT Management Responsibilities
- II.B.1(a) Chief Architect
- II.B.1(b) Chief Data Officer
- II.B.1(c) IT Operations Management
- II.B.2 IT Operations Personnel Responsibilities
- II.C Policies, Standards, and Procedures
- II.D Internal Audit, Independent Reviews, and Certification Processes
- II.E Communication
- II.F Board and Senior Management Reporting
- III Common AIO Risk Management Topics
- III.A Data Governance and Data Management
- III.A.1 Data Identification and Classification
- III.A.2 Database Management
- III.A.2(a) Database Security
- III.A.3 Non-Production Environments
- III.A.4 Data Analytics
- III.B IT Asset Management
- III.B.1 Technology Asset Inventory
- III.B.1(a) Hardware Inventory
- III.B.1(b) Software Inventory
- III.B.2 IT Asset End-of-Life
- III.B.3 Shadow IT
- III.C IT and Business Environment Representations
- III.C.1 Network Diagrams
- III.C.2 Data Flow Diagrams
- III.C.3 Business Process Diagrams and Narratives
- III.D Managing Change in AIO
- III.D.1 Change Management
- III.D.2 Transitioning From Strategic Change Management to Day-to-Day Operations
- III.E Oversight of Third-Party Service Providers
- III.F Resilience
- III.G Remote Access
- III.H Personally Owned Devices
- III.I File Exchange
- IV Architecture
- IV.A Architecture Plan
- IV.B Design Objectives
- IV.C IT Architecture Design
- IV.D Enterprise Architecture
- V Infrastructure
- V.A Hardware
- V.B Network and Telecommunications
- V.B.1 Network
- V.B.2 Telecommunications
- V.B.2(a) Voice Communications
- V.B.2(b) Data Communications
- V.C Software
- V.C.1 Internally and Externally Developed Software
- V.C.2 Software Types
- V.C.2(a) Open Source Software
- V.C.2(b) Mainframe Security Software
- V.C.2(c) Application Programming Interfaces
- V.C.3 Software Hosting
- V.D Environmental Controls
- V.D.1 Heating, Ventilation, and Air Conditioning
- V.D.2 Smoke and Fire
- V.D.3 Water
- V.D.4 Power
- V.E Physical Access Controls
- VI Operations
- VI.A Operational Controls
- VI.A.1 Operating Centers
- VI.A.2 Authorization Boundary
- VI.A.3 Identity and Access Management
- VI.A.4 Personnel Controls
- VI.B IT Operational Processes
- VI.B.1 Maintenance
- VI.B.2 Configuration Management
- VI.B.3 Vulnerability and Patch Management
- VI.B.3(a) Vulnerability Management
- VI.B.3(b) Patch Management
- VI.B.4 Backup and Replication Processes
- VI.B.5 Scheduling
- VI.B.6 Capacity Management
- VI.B.7 Log Management
- VI.B.8 Disposal of Data and Media
- VI.C Service and Support Processes
- VI.C.1 Service Management
- VI.C.2 Operational Support
- VI.C.3 IT Support
- VI.C.4 Event, Incident, and Problem Management
- VI.D Ongoing Monitoring and Evaluation Processes
- VI.D.1 Monitoring and Reporting
- VI.D.2 IT and Operations Key Performance Indicators
- VI.D.3 Control Self-Assessments
- VI.D.4 Continuous Improvement
- VII Evolving Technologies
- VII.A Cloud Computing
- VII.A.1 Essential Characteristics
- VII.A.2 Cloud Service Models
- VII.A.3 Cloud Deployment Models
- VII.A.4 Shared Responsibilities
- VII.A.5 Risk Considerations for Cloud Computing
- VII.A.5(a) Access Control Considerations
- VII.B Zero Trust Architecture
- VII.C Microservices
- VII.D Artificial Intelligence and Machine Learning
- VII.E Internet of Things
- Appendix A: Examination Procedures
- Appendix B: Glossary
- Appendix C: Abbreviations
- Appendix D: References

Named provisions

Architecture, Infrastructure, and Operations Architecture, Infrastructure, and Operations Governance Board and Senior Management Responsibilities IT Management Responsibilities Policies, Standards, and Procedures

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
FFIEC
Instrument
Guidance
Legal weight
Non-binding
Stage
Final
Change scope
Minor

Who this affects

Applies to
Banks Financial advisers Insurers
Industry sector
5221 Commercial Banking 5223 Credit Unions 5241 Insurance
Activity scope
IT Governance IT Operations Enterprise Risk Management
Geographic scope
United States US

Taxonomy

Primary area
Financial Services
Operational domain
IT Operations
Compliance frameworks
NIST CSF
Topics
IT Governance Risk Management

Get Banking & Finance alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when FFIEC IT Examination Handbook Updates publishes new changes.

Free. Unsubscribe anytime.