Federal Reserve watchdog calls for stronger measures on confidential information sharing

54 minutes ago 15

The Federal Reserve’s internal watchdog is pushing the central bank to shore up how it handles confidential supervisory information, warning that current safeguards aren’t robust enough to prevent sensitive data from reaching the wrong people. The target of concern: the 12 regional reserve bank boards, which are populated by private-sector bankers and business leaders who, by design, should never see that information.

The information firewall problem

Federal Reserve policy already explicitly prohibits Reserve Banks from sharing confidential supervisory information, known as CSI, with any member of their boards of directors. The rule exists for an obvious reason: those boards include Class A directors who are actual bankers, Class B directors representing business interests, and Class C directors drawn from the public. Giving any of them access to nonpublic supervisory data would create textbook conflicts of interest.

The OIG has been flagging related vulnerabilities across multiple reports. A June 2023 report zeroed in on Supervision Central, a technical platform used in bank examinations, and found that examiners had excessive access to sensitive personally identifiable information. That report recommended stronger access controls and more consistent purging of unnecessary documents from the system.

A February 2026 report went further, identifying excessive user access to CSI within another platform called OASIS. The OIG issued four specific recommendations to address those gaps. Then in July 2026, the watchdog delivered perhaps its most pointed critique yet: the Board’s insider risk management program was “insufficiently proactive,” lacking the enterprise-level processes necessary to manage the risk of internal information leaks.

Why regional bank boards are the pressure point

The structure of regional Federal Reserve banks is unusual by any institutional standard. Each of the 12 regional banks has a nine-member board of directors that blends public-interest appointees with representatives from the very banking industry the Fed supervises. This arrangement has been a feature of the Fed’s design since 1913, but it creates an inherent tension that demands rigorous information barriers.

The OIG has consistently emphasized what it calls a “need-to-know principle” for information management across Reserve Bank operations. In plain terms: people should only have access to data they genuinely need for their specific role, and the default setting should be no access rather than broad access.

Broader context for information security at the Fed

For the Fed specifically, the stakes are significant. Confidential supervisory information includes details about individual banks’ financial health, risk assessments, enforcement actions, and examination findings. Interagency actions taken in 2026 have addressed the management of highly sensitive data during bank examinations, signaling that the issue extends beyond the Fed’s internal operations to the broader regulatory ecosystem.

What comes next

The OIG’s recommendations collectively point toward a substantial overhaul of how the Fed manages information access. Tighter protocols for safeguarding highly sensitive data during banking examinations, better controls on who can access what within supervisory technology platforms, and a more proactive insider risk management program would all represent meaningful upgrades to the current system.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article