10.5.2026

Federal: AFC Response to FDIC CSI Rulemaking

Jennifer M. Jones
Deputy Executive Secretary
Federal Deposit Insurance Corporation
550 17th Street NW
Washington, DC 204291

Re: Response to Notice of Proposed Rulemaking on the Disclosure of Confidential Supervisory Information

Dear Ms. Jones,

On behalf of the American Fintech Council (AFC),  I submit this comment letter in response to the Federal Deposit Insurance Corporation’s (FDIC) Notice of Proposed Rulemaking regarding the disclosure of confidential supervisory information (CSI) by the FDIC and other parties, including insured depository institutions, their parent holding companies, and certain service providers (Proposed Rulemaking).  AFC appreciates the FDIC’s efforts to modernize its information disclosure regulations and to establish a framework that better accommodates contemporary banking relationships while preserving appropriate safeguards for CSI.

AFC is a standards-based organization and the largest and most diverse trade association representing financial technology companies and innovative banks. On behalf of more than 150 member companies and partners, AFC promotes a transparent, inclusive, and customer-centric financial system by supporting responsible innovation in financial services and encouraging sound public policy. AFC’s membership includes innovative banks, payments providers, technology companies, compliance providers, and other financial services firms that routinely operate within complex bank partnership and third-party risk management frameworks. These institutions possess direct experience with the practical consequences that supervisory information restrictions can have for due diligence, risk management, compliance, governance, and the formation and oversight of responsible bank fintech partnerships.

An effectively structured CSI framework should preserve the integrity of the supervisory process while recognizing that the safe and effective operation of modern banking organizations frequently requires information to collaboratively disseminate amongst a variety of stakeholders such as primary banking institutions, affiliates, professional advisers, and specialized service providers. The current framework, which in many circumstances requires an insured depository institution to obtain prior FDIC authorization before providing CSI to a third party, may impede ordinary business activity even where the recipient has a legitimate need for the information and is subject to robust confidentiality obligations. The Proposed Rulemaking takes an important step toward addressing that tension by providing greater latitude for appropriate disclosures and by bringing the FDIC’s framework into closer alignment with the practices of the other federal banking agencies.

The recommendations below are intended to further that objective and substantively advance the policy discussion. In particular, AFC encourages the FDIC to establish disclosure authorizations that encompass the full life cycle of responsible bank and service provider relationships, employ safeguards that are proportionate to the sensitivity and purpose of a disclosure, and permit appropriately structured aggregated analysis that can improve understanding of supervisory practices without compromising institution-specific confidential information.

I. AFC Supports Broadening Permissible Business Purpose Disclosures to Facilitate Effective Due Diligence, Risk Management, and Responsible Bank Partnerships

Modern financial institutions increasingly rely upon specialized third parties to perform technological, operational, compliance, payments, data, and other functions that are integral to the delivery of financial services. Effective risk management in this environment often depends upon the ability of banks and their prospective partners to exchange critical information necessary to understanding material supervisory concerns, evaluating operational capabilities, identifying remediation obligations, and determining whether a contemplated relationship can be structured consistently with applicable regulatory expectations.

As such, the final rule should therefore ensure that authorization to disclose CSI extends beyond relationships that have already been contractually consummated. Under the proposed definition, a "qualifying service provider" must have a contractual relationship with the insured depository institution. That limitation may unnecessarily constrain disclosure at precisely the stage when meaningful information exchange is most important. Interagency third-party risk management guidance often grapples intricately with planning and due diligence before a banking organization selects and enters into a relationship with a third party. A bank evaluating a particular technological entity, payments, compliance obligations, or another service provider may need information concerning supervisory findings or related matters to determine whether the contemplated arrangement presents risks that can be appropriately managed. Requiring the institution to execute a service contract before obtaining the benefit of the proposed disclosure authorization would invert the ordinary sequence of prudent third-party risk management.

Accordingly, the FDIC should consider expressly permitting an insured depository institution to disclose CSI to a prospective qualifying service provider where the institution reasonably determines that the disclosure is necessary or appropriate to conduct due diligence, assess or structure a potential relationship, evaluate risk, or determine the provider’s ability to satisfy the institution’s regulatory and operational requirements. This authorization should apply only where the prospective provider would fall within the substantive categories contained in the qualifying service provider definition if a contractual relationship were ultimately executed. It should also remain subject to an appropriate written confidentiality agreement and a need-to-know limitation. Such an approach would allow institutions to conduct informed diligence with tailored guardrails in a manner that does not engender unrestricted right of access to supervisory information.

The same principle should operate reciprocally for FDIC-examined service providers. A service provider that is subject to FDIC examination may possess CSI concerning its own operations that is materially relevant to an insured depository institution evaluating whether to enter into a partnership with that provider. Permitting disclosure only after the relationship has been established can place the prospective bank in the untenable position of having to make a risk decision without information that may bear directly on the provider’s operational resilience, compliance posture, remediation responsibilities, or ability to perform the contemplated services. The final rule should therefore permit an FDIC-examined service provider to disclose CSI concerning itself to an insured depository institution that is actively evaluating a prospective business relationship, provided that the information is reasonably related to the bank’s due diligence and the parties execute the required confidentiality protections before disclosure.

This reciprocal approach would reinforce, rather than diminish, prudent third-party risk management. A framework that permits relevant supervisory information to be considered during diligence would enable banks to identify risks before entering into a relationship, establish appropriate contractual controls, determine whether additional monitoring is warranted, and decline arrangements presenting risks outside the institution’s tolerance. Restricting disclosure until after the contractual relationship has commenced may produce an undesirable result by depriving decision makers of relevant information during the period when their ability to mitigate risk is greatest.

Furthermore, the FDIC should potentially construe the phrase "necessary or appropriate for business purposes" with sufficient breadth to encompass the legitimate functions through which regulated institutions manage their affairs. The final rule or accompanying guidance should make clear that qualifying purposes include third-party due diligence and monitoring, enterprise risk management, internal and external audit, legal and regulatory compliance, corporate governance, transaction evaluation, operational resilience, cybersecurity assessment, remediation planning, and other activities reasonably related to the safe and effective operation of the institution. Providing illustrative, nonexclusive examples would afford institutions greater certainty without transforming a flexible standard into an inflexible list.

Finally, the FDIC should seek substantial consistency with evolving approaches among the other prudential regulators, recognizing that each agency continues to refine its own framework for handling confidential supervisory information. As the other regulators actively reassess their own policies governing CSI, the FDIC should consider opportunities for alignment where supervisory objectives are comparable, while preserving appropriate flexibility for each agency to tailor its own information governance framework. Such an approach can help reduce unnecessary complexity for institutions operating across multiple supervisory regimes without constraining the ability of any agency to manage its own confidential information consistent with its statutory responsibilities.

II. AFC Supports Proportionate Confidentiality Safeguards That Protect Supervisory Information Without Recreating Unnecessary Administrative Burdens

The effectiveness of the final framework, in large part, will likely depend not only upon who may receive CSI, but also upon whether the conditions governing those disclosures are sufficiently clear and easily incorporated into ordinary business operations. The safeguards applicable to authorized disclosures should protect against misuse and unauthorized dissemination while avoiding procedural requirements that function as a substitute for the prior approval regime the FDIC is seeking to modernize.

A written confidentiality agreement provides an appropriate foundation for disclosures to external recipients. Such an agreement can establish the permissible purpose of the disclosure, restrict secondary use, prohibit unauthorized onward disclosure, and limit access to personnel who possess a legitimate business need. Those protections directly address the principal risks associated with providing sensitive supervisory information to a third party. The final rule should therefore preserve those core safeguards while allowing institutions to incorporate the required provisions into existing nondisclosure agreements, service agreements, due diligence agreements, or other contractual instruments. Requiring a separate stand-alone agreement solely for CSI would create additional documentation without necessarily improving protection of the underlying information.

The FDIC should also consider avoiding imposing a universal requirement that institutions create a separate disclosure log documenting the legal basis for every authorized disclosure. Banks and service providers already maintain extensive records relating to third-party relationships, contractual access controls, information security, governance, and regulatory compliance. An additional transaction-level recordkeeping regime could materially diminish the efficiency gains produced by eliminating prior FDIC approval, particularly for routine disclosures occurring within longstanding professional or service relationships.

If the FDIC determines that some form of recordkeeping is necessary, the requirement should be principles-based and capable of being satisfied through records maintained in the ordinary course of business. For example, an institution should be permitted to demonstrate compliance through an executed confidentiality agreement, applicable access controls, due diligence records, board or management materials, engagement documentation, or other records sufficient to identify the recipient and legitimate business purpose. The rule should not require institutions to prepare a new legal memorandum or discrete written analysis each time information is disclosed.

On a similar note, the degree of protection should also correspond to the sensitivity of the information and the nature of the recipient. Not every item falling within the regulatory definition of CSI presents an identical risk if disclosed. Institution-specific supervisory findings, enforcement-sensitive materials, personally identifiable information, and information containing proprietary third-party data may warrant more restrictive access controls than information whose sensitivity has materially diminished with time or whose contents have already been substantially reflected in public information. A risk-based framework would allow institutions to apply enhanced controls, where justified, without imposing the most stringent possible safeguards to every authorized disclosure irrespective of context.

Nonetheless, the final rule should provide certainty concerning subsequent use cases and disclosure activities. Recipients should remain prohibited from using CSI for purposes unrelated to the basis on which initial access was provided, and future disclosure should remain limited absent subsequent authorization. The FDIC should expressly recognize, however, that ordinary internal use by employees, officers, directors, professional advisers, and contractors who are necessary to perform the authorized purpose does not constitute a prohibited further disclosure where those persons are bound by equivalent confidentiality restrictions. This clarification is particularly important for sophisticated technology and financial services organizations whose relevant legal, compliance, information security, and risk management functions may be distributed across affiliated entities or specialized personnel.

The FDIC should further ensure that contractual requirements do not unnecessarily displace existing mechanisms for protecting privileged or otherwise legally protected information. The Proposed Rulemaking recognizes that authorized disclosure is not intended, absent an express statement to the contrary, to waive or otherwise affect privileges or protections the FDIC may assert with respect to CSI.  As such, the final rule should bolster that principle and provide comparable clarity for regulated institutions to the extent permitted by applicable law. Clear nonwaiver treatment would facilitate appropriate information exchange by reducing uncertainty about whether compliance with the FDIC’s disclosure framework could be construed as waiving or otherwise affecting protections that are unrelated to the legitimate supervisory purpose of the disclosure.

These safeguards should collectively operate as a coherent framework rather than as overlapping layers of documentation. The principal question should remain whether the recipient has a legitimate reason to receive the information, whether access is confined to individuals who need it for that purpose, and whether enforceable protections prevent unauthorized use or dissemination. Focusing on those substantive outcomes would better protect supervisory information rather than imposing formalities whose principal effect is that of replicating the friction associated with prior agency approval.

III. AFC Supports Permitting Carefully Structured Aggregated Analysis to Improve Supervisory Transparency While Protecting Institution-Specific Information

Aggregated analysis of supervisory information can provide meaningful insight into regulatory practices without revealing the confidential affairs of individual institutions. Trade associations, law firms, consultants, research organizations, and other appropriately situated entities can identify recurring supervisory themes, implementation challenges, emerging risks, and areas of inconsistent interpretation that may be difficult to discern from the experience of a single institution. Permitting these analytical efforts to occur may ultimately improve both industry compliance and regulatory effectiveness by allowing institutions to understand broader supervisory expectations and devote resources to areas presenting recurring risk.

The final rule should therefore establish an express pathway through which insured depository institutions may provide appropriate CSI to qualified organizations for the purpose of producing aggregated analysis. Eligible recipients should include, but not be limited to, trade associations, law firms, accounting and consulting firms, and other organizations with a legitimate professional or research purpose and demonstrable capacity to safeguard the underlying information. Eligibility should turn on the recipient’s purpose, controls, and ability to preserve confidentiality rather than on organizational form alone.

Such authorization should distinguish clearly between access to source information and dissemination of an analytical product. An organization conducting the analysis may need access to institution-level information in order to identify patterns accurately, but any external publication or broader circulation should be limited to information that has been aggregated and deidentified so that the identity, condition, supervisory rating, or confidential circumstances of a particular institution cannot reasonably be determined. The FDIC should consider permitting these recipients to employ appropriate aggregation, suppression, and deidentification techniques based upon the nature of the information rather than prescribing a single methodology that may prove unsuitable across different datasets.

At a minimum, public-facing analyses derived from CSI should satisfy several principles. They should contain a sufficiently broad cohort to prevent reasonable identification of individual institutions, omit or combine categories where small sample sizes or distinctive characteristics create a material reidentification risk, avoid institution-specific quotations or descriptions unless independently public, and refrain from presenting competitively sensitive information in a manner that facilitates coordination among market participants. Organizations should also maintain reasonable procedures for reviewing analytical outputs before publication to verify that underlying confidential information has not been inadvertently exposed. The framework should not, however, require the FDIC to review and preapprove each resulting report. Such a requirement would substantially diminish the value of creating an aggregation authorization and could cause the same administrative delays that the Proposed Rulemaking seeks to reduce. Instead, the FDIC should establish objective conditions under which a qualified recipient may publish aggregated findings without prior approval. The agency could retain authority to examine compliance with those conditions and to take appropriate action when a recipient fails to protect confidential information.

Importantly, aggregated analysis should be permitted to address supervisory practices and trends, not merely statistical characteristics of institutions. Responsible aggregation can provide useful information concerning recurring examination themes, areas in which institutions encounter inconsistent interpretations, common remediation expectations, and supervisory issues affecting emerging technologies or bank partnership models. Such information can enhance compliance by allowing regulated entities to identify potential concerns proactively rather than waiting for those concerns to arise in an individual examination. The ability to identify broader supervisory trends may be particularly valuable for innovative and community banks. Smaller institutions frequently have fewer internal resources with which to benchmark supervisory expectations and may have less visibility into how similar issues are being treated across the industry. Appropriately anonymized analysis can reduce that information asymmetry and support more effective risk management without compromising the confidentiality of individual supervisory relationships.

Such a crafted framework may similarly benefit the FDIC. Aggregated information can illuminate circumstances in which regulated institutions interpret supervisory expectations differently, identify areas where additional guidance may be warranted, and reveal recurring operational challenges that could be addressed more efficiently through agency-wide clarification. Increased visibility into systemic patterns can therefore strengthen the supervisory process while preserving the confidentiality necessary for candid communication between examiners and regulated institutions.

For these reasons, AFC recommends that the FDIC establish a clear authorization for qualified organizations to receive confidential information for aggregated analytical purposes, subject to enforceable confidentiality obligations, purpose limitations, reasonable deidentification controls, and restrictions on the disclosure of institution-specific information. A framework constructed around these principles would provide greater transparency into supervisory practices without compromising the integrity of confidential supervisory information or exposing individual institutions to inappropriate disclosure.

* * *

AFC appreciates the FDIC’s efforts to modernize a regulatory framework that has remained largely unchanged for decades and better align its information disclosure requirements with contemporary banking operations. As such, AFC respectfully encourages the FDIC to adopt a final rule that permits appropriately bounded information sharing for prospective and existing third-party relationships, avoids recordkeeping and contractual requirements with the potential to exacerbate the burdens of the current approval process, and establishes a workable pathway for responsible aggregated analysis of supervisory information. These measures would reduce unnecessary administrative friction, strengthen risk management and regulatory clarity, and facilitate informed decision making without compromising safety, soundness, or the confidentiality and integrity of the supervisory process.

AFC welcomes continued engagement with the Federal Deposit Insurance Corporation and stands ready to serve as a resource as the agency considers next steps in this rulemaking.

Sincerely,

Ian P. Moloney
Chief Policy Officer
American Fintech Council

‍

About the American Fintech Council: The mission of the American Fintech Council is to promote an innovative, responsible, inclusive, customer-centric financial system. You can learn more at www.fintechcouncil.org.