The Analyst Note   Financial Services series  ·  piece 3 of 8  ·  Last updated July 2026

Mapping the FFIEC IT Handbook to a mid-market bank's vendor stack in 2026.

With the Cybersecurity Assessment Tool retired August 31, 2025, community and mid-market banks are back on the booklets themselves. Five booklets do most of the work — Management, Information Security, Outsourcing Technology Services, Business Continuity Management, and the Architecture, Infrastructure, and Operations booklet published August 2021. Here is how they map to the core, ancillary, and cloud vendors that actually sit in a mid-market bank.

14 min · Deep-dive · Financial Services series, piece 3 of 8

Questions this article answers

  • What happened when the FFIEC Cybersecurity Assessment Tool retired?
  • Which FFIEC booklets should a mid-market bank prioritize?
  • How does the AIO booklet change what examiners look at?
  • How do the core banking vendors map onto the booklets?
  • Where does the Outsourcing Technology Services booklet actually bite in a renewal?
  • What belongs in the FFIEC booklet mapping worksheet?
  • Where do FFIEC-driven mid-market engagements consistently fail?

The FFIEC Cybersecurity Assessment Tool was formally retired August 31, 2025 per the Council's August 2024 sunset notice. Examiners pointed institutions to CISA's Cybersecurity Performance Goals, the NIST Cybersecurity Framework 2.0, and the CRI Profile. None of those are examiner-authored. The framework of record for a mid-market bank or credit union — the document set the examiner actually walks in with — is still the FFIEC Information Technology Examination Handbook. In 2026, five booklets from that handbook cover almost every technology sourcing question an examiner will ask a mid-market institution. Reading them is not glamorous work. Not reading them is where MRAs come from.

The five booklets that carry the mid-market examination.

The FFIEC IT Handbook has thirteen booklets. Five carry the mid-market examination in 2026, in this order.

Architecture, Infrastructure, and Operations (AIO). Published August 2021. Consolidated the prior Operations, Development and Acquisition, and IT Audit booklets in part, and rebuilt the framework around cloud, microservices, containerization, DevOps, API-based architectures, and third-party integrations. This is where most 2025 examiner findings landed. Any question about hyperscaler use, container platforms (AKS, EKS, GKE, OpenShift), CI/CD pipelines, API gateways, and interconnections between the core and ancillary systems traces back to AIO.

Outsourcing Technology Services. Published 2004, still authoritative. Governs how the bank evaluates, contracts with, monitors, and exits a technology service provider. In 2026 practice, this booklet is what a QSA/examiner reaches for when reviewing a renewal against a core banking provider, a digital banking overlay, an API-based data aggregator, or a cloud provider. Note that the OCC issued separate Third-Party Risk Management guidance jointly with the Federal Reserve and FDIC in June 2023 (Interagency Guidance on Third-Party Relationships: Risk Management, replacing OCC Bulletin 2013-29 and equivalents). That interagency guidance operates alongside the FFIEC Outsourcing booklet, not in place of it.

Business Continuity Management. Published November 2019, replacing the prior Business Continuity Planning booklet. Broadened the scope from IT recovery to full enterprise-wide resilience, and emphasized third-party dependency, cloud-region strategy, and pandemic-adjacent testing. Every RTO/RPO conversation with a core, digital banking, or cloud provider maps to BCM.

Information Security. Published September 2016. The information security control framework proper — identity, access, encryption, monitoring, incident response. Overlaps with the GLBA Safeguards Rule and, for institutions with card programs, with PCI DSS 4.0.1 (covered in the piece on PCI DSS 4.0 in this series).

Management. Published November 2015. Covers IT governance, IT risk management, IT strategic planning, and board reporting. Where examiners look for evidence that IT decisions have management context, not just engineering context.

What retired with the CAT — and what did not.

The Cybersecurity Assessment Tool was a self-assessment instrument (declarative statements across five domains, maturity levels across each) that many community and mid-market banks used to structure their annual cybersecurity risk report to the board. Examiners frequently referenced CAT maturity ratings in Reports of Examination. With the August 31, 2025 sunset, the instrument itself is retired. The FFIEC's sunset notice explicitly directed institutions to consider CISA's Cybersecurity Performance Goals, the NIST Cybersecurity Framework 2.0 (released February 2024 with the new Govern function), and the Cyber Risk Institute's CRI Profile as alternatives. None of those replaced the CAT as an examiner-authored self-assessment. The practical 2026 posture at mid-market institutions has been to keep the CAT structure for one more cycle where the board relies on it, migrate to NIST CSF 2.0 or the CRI Profile on the next annual refresh, and treat the underlying booklets — particularly AIO and Information Security — as the actual examination framework.

Mapping the mid-market core, ancillary, and cloud stacks onto the booklets.

The mid-market band — banks between roughly $1B and $50B in assets, credit unions between roughly $500M and $10B — clusters onto a narrow set of technology vendors. The core banking pool is dominated by Fiserv (DNA, Premier, Signature), FIS (Horizon, IBS), and Jack Henry (SilverLake, CIF 20/20, Core Director) for banks; Symitar (a Jack Henry brand), Fiserv (DNA for credit unions), and Corelation KeyStone for credit unions. Second-tier and thrift-specific cores include CSI (NuPoint) and Finastra (Phoenix). Digital banking overlays include Q2, Alkami, Bottomline, Lumin Digital (a Constellation Software subsidiary), and NCR Voyix Digital First Banking. Payments and card processing include Fiserv (Optis, Card Services), FIS, Jack Henry, PSCU/Co-op (now Velera), and Corporate America Credit Union for cooperative processing. Fraud and compliance include Verafin (Nasdaq), NICE Actimize, Feedzai, Hawk AI, ThetaRay, and Alloy. Data aggregation and open banking include Plaid, MX, Finicity (Mastercard), Yodlee (Envestnet), and Akoya (bank-owned).

Each of these vendors implicates at least two booklets. A core banking renewal touches Outsourcing (contract, exit, monitoring), AIO (architecture, integration, cloud posture), BCM (RTO/RPO, region, tabletop), and Information Security (identity, encryption, monitoring). A digital banking overlay touches AIO more heavily (API integration to core, mobile app supply chain, browser controls) and Information Security more heavily (customer authentication, fraud). A data aggregator touches Outsourcing (the aggregator is a service provider, but so is the aggregator's downstream cloud), AIO (API architecture, token handling, screen-scraping legacy paths), and Information Security (customer credential handling). The examiner mental model does not treat these as separate procurement events. It treats them as one integrated stack, and the booklet mapping reflects that.

Buyer-side. Supplier-paid. Buyers pay zero. Compensation has zero weight in the Cardinal Index scoring inside the Cardinal Method. Specific commercial terms live only in the private Decision Memo a buyer signs, never on this page.

Where the Outsourcing booklet actually bites in a renewal.

The Outsourcing Technology Services booklet is 2004 vintage but every mid-market renewal in 2026 still runs into it. Three places bite consistently. First, the contract must explicitly cover audit rights, subcontractor notification and consent, breach notification, service-level thresholds tied to remedies (not just credits), and exit provisions with a defined data return format and destruction attestation. Second, concentration risk — a mid-market bank running Fiserv for core, Fiserv for card processing, and Fiserv for digital receives close examiner attention on single-provider dependency. Third, the interagency 2023 guidance introduced a lifecycle framing (planning, due diligence, contract negotiation, ongoing monitoring, termination) that examiners now walk explicitly. A renewal deck that skips due diligence documentation because “we already use them” will draw an examiner comment.

Run the FFIEC booklet mapping worksheet as a vendor management artifact, not a compliance one.

The lift-out artifact below belongs inside vendor management, reviewed at every renewal. It is not a compliance filing. It is the map an examiner will implicitly build in their head; making it explicit shortens the exam and surfaces gaps before they become findings.

The FFIEC booklet mapping worksheet

  1. Vendor and product. Vendor name, product name, product version if relevant (e.g., Jack Henry SilverLake vs. Core Director), and business owner inside the bank.
  2. Booklet applicability. Which of the five booklets — AIO, Outsourcing, BCM, Information Security, Management — apply to this vendor and why. Most will apply to two or three; the core will apply to all five.
  3. Work program mapping. Reference the specific work program items inside each booklet the vendor implicates. This is where an internal audit function or a QSA-adjacent consultant earns their fee.
  4. Attestation on file. SOC 2 Type II? SOC 1? PCI AoC (for card processors)? FFIEC-aligned control review from an outside firm? What is the coverage date and when does it refresh?
  5. Contract review date and next examiner touchpoint. When was the contract last substantively reviewed for FFIEC alignment? When is the next planned examiner IT engagement?
  6. Concentration risk exposure. How many other systems depend on this vendor? What is the exit plan if this vendor is unavailable or must be replaced? Which other vendors would need to be re-contracted?

What breaks: booklet-blind renewals, cloud posture drift, and the concentration-risk narrative.

Booklet-blind renewals. A core renewal that treats FFIEC as a compliance-team artifact rather than a procurement input produces contracts that examiners will flag on audit rights, breach notification, subcontractor consent, and exit terms. The remediation is a joint procurement/compliance/legal review of the renewal draft against the Outsourcing booklet work program before signature, not after.

Cloud posture drift. The AIO booklet is explicit that the bank remains accountable for controls regardless of where the workload lives. A mid-market bank running its core on FIS-hosted infrastructure and its digital banking on Q2-hosted infrastructure (which in turn runs on AWS) has a set of shared-responsibility questions that examiners now ask directly. “It's in the cloud” is not an answer to a control question.

The concentration-risk narrative. Every mid-market bank has concentration risk. The examiner question is not “do you have it” but “can you narrate it, quantify it, and describe your exit posture.” A bank that can walk into the exam with a concentration-risk narrative — including the fact that switching cores is a 24-30 month project and that the board has accepted that dependency — is in a materially better posture than a bank that treats the question as adversarial.

What this means for procurement in 2026.

Five moves. First, retire the CAT dependency on the next annual cybersecurity report to the board, and pick a successor framework (NIST CSF 2.0 or CRI Profile) explicitly. Second, add the FFIEC booklet mapping worksheet to every vendor management file for material technology vendors — not just the core. Third, treat the AIO booklet as required reading for anyone signing a technology renewal in 2026; it is the booklet the exam is most likely to reference and the least likely to be familiar to procurement. Fourth, request the interagency 2023 third-party risk guidance be reflected in your vendor management program document if it isn't already. Fifth, if you're renewing a core, digital banking, or payments processing contract in the next 12 months, run the booklet mapping worksheet before the negotiation opens, not after — the leverage points are in the terms, and the terms are set at negotiation.

This is the third piece in the Financial Services Analyst Note series. The anchor is How mid-market financial services operators should source technology contracts in 2026. Every vendor named here is in The Cardinal Source's active supplier pool.

In short

  • The FFIEC Cybersecurity Assessment Tool was retired August 31, 2025. Alternatives (NIST CSF 2.0, CISA CPGs, CRI Profile) are self-assessments, not examiner frameworks. The framework of record remains the FFIEC IT Handbook booklets.
  • Five booklets carry the mid-market examination: Architecture, Infrastructure, and Operations (AIO, 2021); Outsourcing Technology Services (2004); Business Continuity Management (2019); Information Security (2016); Management (2015).
  • The AIO booklet is where most 2025 findings landed. It moved examiners from asking about the core in isolation to asking about the whole integrated stack, including ancillary vendors that touch the core through APIs.
  • The interagency 2023 Third-Party Risk Management guidance (jointly issued by the OCC, Federal Reserve, and FDIC) operates alongside the FFIEC Outsourcing booklet and introduced an explicit lifecycle framing examiners now walk.
  • Concentration risk is not the problem — inability to narrate concentration risk is. A mid-market bank that can quantify its concentration exposure and describe its exit posture is in a materially better exam position than one that treats the question as adversarial.
  • Run the FFIEC booklet mapping worksheet at every material vendor renewal, and treat it as a vendor management artifact — not a compliance one.

Sources

  • FFIEC, IT Examination Handbook InfoBase (booklet library). ithandbook.ffiec.gov
  • FFIEC, “Architecture, Infrastructure, and Operations” booklet (August 2021). ithandbook.ffiec.gov
  • FFIEC, “Sunset for the Cybersecurity Assessment Tool” notice (August 2024, effective August 31, 2025). ffiec.gov
  • OCC Bulletin 2023-17, “Third-Party Relationships: Interagency Guidance on Risk Management” (jointly with FRB and FDIC, June 6, 2023). occ.gov
  • NIST, Cybersecurity Framework 2.0 (February 26, 2024). nist.gov
  • CISA, Cybersecurity Performance Goals. cisa.gov
  • Cyber Risk Institute, CRI Profile. cyberriskinstitute.org

All linked sources were live at time of publish (July 2026). Verify before quoting in a procurement document.

Renewing a core or digital banking contract in 2026?

Run the Tier 1 benchmark.

Submit your core, digital banking, and ancillary contracts. We return a benchmark PDF in five business days showing where each vendor sits against the five FFIEC booklets, where concentration risk clusters, and which contract terms will draw an examiner comment. Free. No follow-up sales drip.

Run the Tier 1 benchmark →

Series  ·  Financial Services deep-dive · 8 pieces

Anchor: How mid-market financial services operators should source technology contracts in 2026. Coverage: Finance. Method: The Cardinal Method.