What Your Bank Examiner Will Ask About Insurance
When an examiner asks whether a community bank's cyber insurance is adequate, most struggle to give a defensible answer. Regulators require your board to review coverage and document it. They don't tell you how to do it well.
Download the Examiner Checklist ↓What's Inside the Checklist
Ten questions to test whether your cyber policy, fidelity bond and D&O work together when a wire fraud, a ransomware attack or a vendor outage hits. Working through them gives your board a documented basis for demonstrating informed oversight and preparedness.
Board Governance
The board should be able to say what each policy covers, where the gaps are, and why the limits are the size they are. "Our broker recommended this" is not a review, and examiners are told to write up the review process itself.
Policy Coverage
What fails is rarely the policy limit. It is the sublimit beneath it, or a trigger that never responds. Ransomware at your core banking vendor exposes both. And a security warranty your IT audit contradicts is a condition already broken.
Policy Interactions
One wire fraud can land on two different bond agreements, and on most bonds one is 10x to 20x the other. If the attacker turns out to be sanctioned, all three policies can fail together. The worst gaps sit between policies, not inside them.
Common Questions
Does the FFIEC require community banks to have cyber insurance?
No. The FFIEC does not mandate cyber insurance or prescribe coverage amounts. The IT Examination Handbook treats it as one component of a sound information security program. What examiners expect is evidence that you evaluated whether your coverage fits your risk profile, and documented why. Carry none, and expect questions about how the residual risk is handled.
What do FDIC examiners ask about cyber insurance?
They ask "How do you know your cyber insurance is adequate?" Approving the premium is not an answer. They look for a limits rationale tied to real loss scenarios, security warranties that match your IT audit, and a board that can explain how the cyber policy, the bond and the D&O interact.
How should a community bank prepare for insurance questions during an examination?
Prepare by matching policy security warranties to your IT audit findings, creating a one-page board coverage summary, and mapping your three policies (cyber, bond, D&O) against likely incident scenarios. Document which policy responds to each scenario and where gaps exist.
Where These Requirements Come From
No single regulation tells you what coverage to carry. But these are what examiners cite when they ask.
FFIEC IT Examination Handbook — Information Security +
FDIC Risk Management Manual, Section 4.4 +
FFIEC IT Examination Handbook — Management (III.C.7) +
FFIEC Joint Statement on Cyber Insurance (2018) +
The checklist shows you which questions your board cannot answer. Answering them means reading your cyber policy, your bond and your D&O against each other, using your actual limits and exclusions. That is what the Risk Intelligence Report does.
Answer Them Before an Examiner Does
One report. Plain English. Before your next board review or examination.
Get in Touch