Four professionals analyze tangled network cables and cybersecurity data in an office with a shield emblem and courthouse view.

How Can a Community Bank Prepare for an FDIC or FFIEC IT Examination?

July 25, 2026

A Practical 90-Day IT Examination Readiness Plan for Community Banks

A community bank can prepare for an FDIC or FFIEC IT examination by completing five steps: organize the requested evidence, assess current risks, verify that security controls work, close high-priority gaps and prepare leadership to explain the bank’s decisions. For most 25–50 employee institutions, preparation should begin at least 90 days before the anticipated examination.

The goal is not to create perfect paperwork immediately before examiners arrive. The goal is to demonstrate that the bank has a repeatable technology risk-management program with clear ownership, effective controls, reliable testing and documented follow-through.

This guide provides a structured examination-readiness framework, a document checklist, common warning signs and a week-by-week preparation plan for community banks.

What Do IT Examiners Evaluate?

IT examinations are generally risk-focused. Examiners consider the size, complexity, services, technology, threat environment and third-party dependencies of the institution rather than expecting every bank to use the same products or processes.

Examiners commonly evaluate whether the bank:

  • Understands its material information-technology and cybersecurity risks
  • Maintains an effective information-security program
  • Assigns appropriate oversight to management and the board
  • Protects customer information and critical systems
  • Manages access to systems and data
  • Identifies and remediates vulnerabilities
  • Monitors for suspicious activity
  • Maintains resilient backups and recovery capabilities
  • Tests its incident-response and business-continuity plans
  • Conducts appropriate oversight of service providers
  • Tracks findings through verified completion

A bank should be prepared to explain not only which controls are in place, but also why those controls are appropriate for its risks and how it knows they are operating effectively.

The Five-Stage Examination Readiness Framework

Stage 1: Organize the Examination Evidence

Begin by creating one controlled location for examination materials. This may be a secure document-management platform, restricted file share or purpose-built compliance system.

Organize the evidence into clearly labeled folders such as:

  • Governance and board oversight
  • Policies and standards
  • Risk assessments
  • Asset and software inventories
  • Network and data-flow diagrams
  • Identity and access management
  • Cybersecurity monitoring
  • Vulnerability and patch management
  • Incident response
  • Business continuity and disaster recovery
  • Vendor and third-party management
  • Audit, penetration testing and remediation
  • Employee training
  • Open findings and corrective actions

Assign one person to coordinate document collection. That person does not need to create every item, but should know who owns it, whether it is current and where the final version is stored.

Use a Document-Control Standard

Each important document should show:

  • The document owner
  • The approval authority
  • The effective date
  • The most recent review date
  • The next scheduled review
  • The current version
  • A record of significant changes

Remove duplicate drafts and outdated copies from the examination package. Conflicting versions can create unnecessary confusion and make it difficult to demonstrate which process the bank actually follows.

Stage 2: Reassess the Bank’s Current Risks

The cybersecurity and technology risk assessments should reflect the institution’s current environment. Updating only the date on last year’s assessment is not sufficient if the bank has changed systems, vendors, locations or services.

Review whether the assessment addresses:

  • Core banking and digital banking systems
  • Online and mobile banking
  • Microsoft 365 and cloud services
  • Servers, workstations and network infrastructure
  • Remote-access systems
  • Privileged and administrative accounts
  • Payment and wire-transfer processes
  • Customer information and sensitive employee data
  • Third-party service providers
  • Backup and recovery dependencies
  • Cybercrime, ransomware and business email compromise
  • Concentration risk among critical vendors

Every material risk should connect to one or more safeguards. Every significant weakness should connect to a documented action, owner, target date or risk-acceptance decision.

Questions the Risk Assessment Should Answer

  1. Which systems and information are most critical?
  2. What threats could disrupt or compromise them?
  3. Which technical, administrative and physical controls reduce those risks?
  4. Where are the remaining control gaps?
  5. How severe is the remaining risk?
  6. Who is responsible for corrective action?
  7. When will the action be completed?
  8. Who approved any accepted residual risk?

Stage 3: Verify That Controls Work

Policies and screenshots do not prove that controls operate consistently. Before the examination, test representative controls and retain evidence of the results.

Identity and Access Testing

  • Verify that terminated employees no longer have access
  • Review administrative and privileged accounts
  • Confirm multifactor authentication coverage
  • Identify inactive, shared and generic accounts
  • Review remote-access permissions
  • Confirm that access approvals are retained
  • Test whether access changes are completed promptly

Patch and Vulnerability Testing

  • Confirm the completeness of the asset inventory
  • Review current vulnerability-scan results
  • Identify unsupported systems
  • Locate overdue critical and high-risk vulnerabilities
  • Confirm that remediation was verified through rescanning
  • Document approved exceptions and compensating controls

Security Monitoring Testing

  • Confirm that critical endpoints, servers, identities and firewalls are monitored
  • Verify that every expected system is sending usable logs
  • Test the after-hours escalation process
  • Review recent alerts and response records
  • Confirm that security incidents are classified consistently
  • Measure how quickly critical events are investigated and escalated

911 IT’s cybersecurity services combine endpoint security, firewall management, threat monitoring, employee training and incident-response support to help organizations maintain layered protection.

Backup and Recovery Testing

  • Review failed and successful backup jobs
  • Confirm that critical systems are included
  • Test restoration of representative files and systems
  • Document actual recovery time
  • Confirm the age of the restored data
  • Verify that backups are protected from unauthorized deletion
  • Track problems discovered during testing

A completed backup does not prove that the institution can recover. A documented restoration test provides stronger evidence than a dashboard showing only successful backup jobs.

Learn how 911 IT supports operational resilience through business continuity and disaster-recovery services.

Incident-Response Testing

Conduct a tabletop exercise using a realistic scenario such as:

  • Ransomware affecting employee workstations
  • A compromised Microsoft 365 administrator
  • Business email compromise involving a wire request
  • A critical vendor becoming unavailable
  • Customer data being sent to an unauthorized recipient
  • A lost laptop containing sensitive information

The exercise should test technical response, executive decisions, legal and regulatory escalation, insurance requirements, customer communication and recovery procedures.

Document:

  • The participants
  • The scenario
  • The decisions made
  • Communication and escalation problems
  • Missing information or resources
  • Corrective actions
  • Owners and target completion dates

Stage 4: Close High-Priority Gaps

Do not attempt to hide unresolved weaknesses. A documented issue with an approved remediation plan is generally easier to defend than a known weakness that no one is managing.

Prioritize corrective work using four factors:

  1. Business impact: Could the weakness disrupt customer services or critical banking operations?
  2. Data sensitivity: Could it expose confidential customer, employee or financial information?
  3. Exploitability: Is the weakness internet-facing, actively exploited or easy to abuse?
  4. Control dependency: Would failure affect multiple systems or security layers?

Examples of High-Priority Gaps

  • Unsupported internet-facing systems
  • Missing multifactor authentication for remote or administrative access
  • Unprotected or untested backups
  • Critical vulnerabilities with no remediation plan
  • Former employees with active accounts
  • Security alerts that are not monitored after hours
  • An incident-response plan with outdated contacts
  • Critical vendors that have not been reviewed
  • Open audit findings with no owner or target date

Create a Corrective Action Register

Field Purpose
Finding Clearly states the control weakness
Risk Explains the operational, security or compliance impact
Priority Ranks the urgency of corrective action
Owner Identifies the person accountable for completion
Target date Establishes when remediation should be completed
Status Shows progress, delay or completion
Evidence Provides proof that the issue was corrected and verified

Do not close a finding merely because a ticket was submitted. Close it after the corrective action has been implemented, tested and supported by evidence.

Stage 5: Prepare Management and the Board

Examination readiness is not solely an IT department responsibility. Examiners may ask executives, department leaders and directors how the institution identifies risks, prioritizes investments and oversees significant providers.

Leadership should be prepared to explain:

  • The bank’s most significant technology and cybersecurity risks
  • How security priorities are selected
  • How often the board receives reporting
  • Which findings remain open
  • Why those findings have not yet been completed
  • How the bank verifies that vendors perform as expected
  • How incident-response and recovery capabilities are tested
  • How leadership evaluates the effectiveness of the information-security program

Prepare a One-Page Executive Summary

The summary should include:

  • The bank’s top five technology risks
  • Significant changes since the previous examination
  • Major security improvements completed
  • Recent testing and exercise results
  • Open high-priority findings
  • Upcoming projects and investments
  • Material third-party risks
  • Management’s 12-month technology roadmap

This summary should not replace detailed reports. It should help leadership communicate the program clearly and consistently.

The Community Bank Examination Document Checklist

Governance and Program Management

  • Information-security program
  • Technology and cybersecurity policies
  • Board approvals and meeting minutes
  • Organization chart and assigned responsibilities
  • Technology strategy and budget
  • Management and board reporting
  • Exceptions and risk-acceptance records

Risk and Asset Management

  • Current cybersecurity risk assessment
  • Technology risk assessment
  • Asset inventory
  • Software inventory
  • Data classification or information inventory
  • Network diagram
  • Data-flow diagrams
  • List of critical systems and services

Identity and Access

  • Current user list
  • Privileged account list
  • Access approval records
  • Recent access reviews
  • Terminated-user reports
  • Multifactor authentication coverage
  • Password and authentication standards
  • Remote-access procedures

Cybersecurity Operations

  • Endpoint-protection status
  • Firewall review records
  • Email-security reports
  • Security monitoring reports
  • Incident tickets and investigation records
  • Security awareness training results
  • Phishing simulation results
  • Cyber-insurance documentation

Vulnerability and Change Management

  • Vulnerability-scan reports
  • Penetration-test reports
  • Patch compliance reports
  • Remediation tracking
  • Unsupported-system inventory
  • Configuration standards
  • Change approvals and implementation records
  • Post-change validation records

Incident Response and Resilience

  • Incident-response plan
  • Incident contact list
  • Tabletop exercise results
  • Business-impact analysis
  • Business-continuity plan
  • Disaster-recovery plan
  • Backup status reports
  • Restoration-test results
  • Recovery time and recovery point objectives

Third-Party Management

  • Complete vendor inventory
  • Critical vendor classifications
  • Due-diligence reviews
  • Contracts and service-level agreements
  • Independent assurance reports
  • Business-continuity documentation
  • Incident-notification requirements
  • Subcontractor information
  • Performance reviews
  • Exit and transition plans

Audit and Remediation

  • Internal and external audit reports
  • Previous examination findings
  • Open corrective actions
  • Management responses
  • Completion evidence
  • Independent validation
  • Risk acceptances and extensions

A 90-Day Examination Preparation Timeline

Days 1–30: Collect, Assess and Prioritize

  • Appoint the examination-readiness coordinator
  • Collect the initial examination request materials
  • Review the previous report of examination
  • Update the technology and cybersecurity risk assessments
  • Confirm the asset, software and vendor inventories
  • Review all open findings
  • Identify missing or outdated policies
  • Prioritize material weaknesses

Days 31–60: Remediate and Test

  • Correct critical access and authentication gaps
  • Patch high-risk vulnerabilities
  • Remove unsupported or unauthorized systems
  • Test backup restoration
  • Conduct an incident-response tabletop exercise
  • Review critical vendor documentation
  • Test security escalation procedures
  • Update incomplete diagrams and inventories

Days 61–75: Validate the Evidence

  • Rescan remediated vulnerabilities
  • Verify closed access findings
  • Confirm that backup-test problems were corrected
  • Review log coverage and monitoring reports
  • Validate corrective action evidence
  • Remove draft and duplicate documents
  • Confirm that every request item has an owner

Days 76–90: Prepare Leadership and Finalize

  • Brief management and the board
  • Review the one-page executive summary
  • Practice answering likely examination questions
  • Confirm examination-day roles
  • Prepare a process for tracking additional requests
  • Review open findings and expected completion dates
  • Verify secure document-sharing procedures
  • Complete a final quality-control review

Common Examination Readiness Mistakes

Waiting Until the Request List Arrives

Important evidence should be produced throughout the year. Attempting to reconstruct access reviews, recovery tests and board oversight immediately before an examination creates unnecessary pressure and may reveal that required activities were never completed.

Providing Policies Without Operational Evidence

A policy may require quarterly access reviews, monthly patching or annual recovery testing. Examiners may also request proof that those activities occurred.

Closing Findings Without Verification

A completed work order is not always sufficient evidence. The bank should verify that the original weakness no longer exists.

Submitting Excessive Unorganized Material

More documents do not automatically demonstrate stronger controls. Submit the requested evidence in a clear structure and be prepared to provide additional information when needed.

Using Generic Vendor Reports

A vendor may provide a polished report that says the environment is “secure.” The bank still needs to understand what was tested, what was excluded, what was found and what corrective action remains.

Failing to Connect Technology With Business Risk

Leadership should be able to explain how a weakness could affect customers, critical services, financial operations or the bank’s reputation. Technical severity alone does not provide the full risk context.

Allowing the MSP to Own the Entire Conversation

A managed service provider can explain technical controls and supply evidence, but bank leadership remains responsible for governance, oversight and risk decisions.

Questions Examiners May Ask

  • What are the bank’s most significant cybersecurity risks?
  • How has the risk profile changed since the last examination?
  • How does the board oversee information security?
  • Which critical vulnerabilities remain unresolved?
  • How does the bank determine patching priorities?
  • How are privileged accounts approved and reviewed?
  • Who monitors security events after normal business hours?
  • When was the most recent recovery test?
  • What problems were identified during that test?
  • How does the bank evaluate critical service providers?
  • When was the incident-response plan last tested?
  • Which previous examination or audit findings remain open?
  • How does management verify that corrective actions work?

How an MSP Can Support Examination Preparation

A qualified managed IT provider can help the bank:

  • Produce accurate asset and software inventories
  • Document the network and cloud environment
  • Provide patch and vulnerability reports
  • Supply security-monitoring evidence
  • Review identity and access controls
  • Test backups and document recovery results
  • Support incident-response exercises
  • Track technical remediation
  • Explain security architecture
  • Build a prioritized technology roadmap

The provider should not promise to “guarantee compliance” or make examination findings impossible. Its role is to help the institution implement effective controls, produce reliable evidence and correct identified technical gaps.

911 IT’s managed IT services include proactive monitoring, live 24/7 support, cybersecurity, network management and strategic technology planning. Banks with an internal technology resource can use co-managed IT services to add specialized expertise and after-hours coverage.

Financial-Industry Experience That Strengthens Readiness

Financial-industry clients consistently describe 911 IT as proactive, responsive and familiar with the security requirements involved in protecting confidential information.

One long-term financial client reported working with 911 IT for more than 20 years and emphasized that the help desk responds promptly, takes ownership of requests and ensures that issues are fully resolved before closing them.

Another financial-services client credited 911 IT with helping implement and maintain network protocols supporting strict IRS and PCI security requirements. The client valued having a dedicated team that understood the environment and could respond without requiring the organization to explain its systems from the beginning during each request.

A separate client reported that a security audit helped identify and correct security weaknesses, describing the resulting peace of mind and practical information as significantly more valuable than the cost of the assessment.

Learn more about 911 IT’s experience providing IT support for CPAs and financial firms.

Frequently Asked Questions

How far in advance should a community bank prepare for an IT examination?

A focused review should begin approximately 90 days before the expected examination. However, important activities such as access reviews, vulnerability management, vendor oversight and recovery testing should occur throughout the year.

What is the most important examination preparation document?

No single document is sufficient. The current risk assessment is particularly important because it should connect the bank’s assets and threats to its controls, residual risks and remediation priorities.

Should the bank fix every open issue before the examination?

Critical issues should be addressed promptly. When an issue cannot be completed before the examination, the bank should document the risk, interim controls, accountable owner, approved plan and realistic target date.

What should the bank do with an outdated policy?

Review and update it before submission. Confirm that the policy reflects actual practices and that the appropriate authority has approved the revised version.

How should the bank prepare its board?

Provide a concise summary of material risks, significant incidents, open findings, recovery-test results, major vendor concerns and planned investments. Directors should understand the issues well enough to ask informed questions.

Can an MSP attend examination meetings?

An MSP may help explain technical architecture, controls, reports and remediation work when appropriate. Bank management should remain actively involved and retain responsibility for governance and risk decisions.

What should happen after the examination?

Review every finding, assign an owner and target date, track progress and independently verify completed corrective actions. Management and the board should receive regular updates until material findings are closed.

Prepare Before the Examination Request Arrives

The strongest examination preparation program is part of everyday operations. When inventories, access reviews, security reports, recovery tests and corrective actions remain current throughout the year, the examination becomes a demonstration of the bank’s normal risk-management process rather than an emergency document-collection project.

911 IT provides local managed IT, cybersecurity, cloud and business-continuity support for organizations in Salt Lake City and throughout Utah. Our team combines live 24/7 assistance, local engineering resources, proactive security and strategic guidance under one accountable relationship.

Schedule a 10-minute discovery call to discuss your bank’s examination timeline, documentation gaps and highest-priority technical risks. You can also contact 911 IT to request an IT examination-readiness assessment.

This article provides general educational information and is not legal, regulatory or compliance advice. Financial institutions should consult their regulator, legal counsel and qualified compliance professionals regarding requirements that apply to their circumstances.