What Your Bank Examiner Will Ask About Insurance

When an examiner asks whether a community bank's cyber insurance is adequate, most struggle to give a defensible answer. Regulators require your board to review coverage and document it. They don't tell you how to do it well.

Download the Examiner Checklist ↓

What's Inside the Checklist

Ten questions to test whether your cyber policy, fidelity bond and D&O work together when a wire fraud, a ransomware attack or a vendor outage hits. Working through them gives your board a documented basis for demonstrating informed oversight and preparedness.

01 · 2 questions

Board Governance

The board should be able to say what each policy covers, where the gaps are, and why the limits are the size they are. "Our broker recommended this" is not a review, and examiners are told to write up the review process itself.

02 · 4 questions

Policy Coverage

What fails is rarely the policy limit. It is the sublimit beneath it, or a trigger that never responds. Ransomware at your core banking vendor exposes both. And a security warranty your IT audit contradicts is a condition already broken.

03 · 4 questions

Policy Interactions

One wire fraud can land on two different bond agreements, and on most bonds one is 10x to 20x the other. If the attacker turns out to be sanctioned, all three policies can fail together. The worst gaps sit between policies, not inside them.

Common Questions

Does the FFIEC require community banks to have cyber insurance?

No. The FFIEC does not mandate cyber insurance or prescribe coverage amounts. The IT Examination Handbook treats it as one component of a sound information security program. What examiners expect is evidence that you evaluated whether your coverage fits your risk profile, and documented why. Carry none, and expect questions about how the residual risk is handled.

What do FDIC examiners ask about cyber insurance?

They ask "How do you know your cyber insurance is adequate?" Approving the premium is not an answer. They look for a limits rationale tied to real loss scenarios, security warranties that match your IT audit, and a board that can explain how the cyber policy, the bond and the D&O interact.

How should a community bank prepare for insurance questions during an examination?

Prepare by matching policy security warranties to your IT audit findings, creating a one-page board coverage summary, and mapping your three policies (cyber, bond, D&O) against likely incident scenarios. Document which policy responds to each scenario and where gaps exist.

Where These Requirements Come From

No single regulation tells you what coverage to carry. But these are what examiners cite when they ask.

FFIEC IT Examination Handbook — Information Security +
The primary source. The Information Security booklet identifies cyber insurance as a risk mitigation tool within the bank's information security program. Examiners use this framework to evaluate whether the bank has assessed its cyber risk exposure and whether insurance coverage aligns with that assessment. The handbook does not prescribe coverage amounts but expects documented rationale.
FDIC Risk Management Manual, Section 4.4 +
Examiners must comment in the Report of Examination on "lack of any significant coverage, board of director approval and review, or deficiencies in a bank's loss prevention program." This is the direct hook: examiners will note deficiencies in the board's review process itself, not just in coverage.
FFIEC IT Examination Handbook — Management (III.C.7) +
Insurance procedures "should include an annual program review by the board of directors." Management "should consider seeking the help of insurance consultants, attorneys, and other professionals, as necessary, to fully identify and measure the risk." This is where the expectation for independent analysis beyond the placing broker originates.
FFIEC Joint Statement on Cyber Insurance (2018) +
Boards should be engaged in insurance program reviews. Institutions should "review the scope of existing or proposed insurance coverage to identify gaps" and engage "outside advisors such as attorneys and brokers." The recommendation to engage advisors beyond the placing broker creates the practical expectation for independent review.

The checklist shows you which questions your board cannot answer. Answering them means reading your cyber policy, your bond and your D&O against each other, using your actual limits and exclusions. That is what the Risk Intelligence Report does.

Answer Them Before an Examiner Does

One report. Plain English. Before your next board review or examination.

Get in Touch