Examiner Readiness

What Your Bank Examiner Will Ask About Insurance

Regulators require your board to review insurance adequacy, and document it. They don't tell you how to do it well.
That's what the Risk Intelligence Report is for.

What Do Examiners Want to See?

Examiners evaluate your insurance program, including cyber, D&O, and fidelity bond. They look for evidence in four areas.

Checkpoint 1

Board-Level Coverage Review

The board should articulate what each policy covers and where the gaps are. "Our broker recommended this" is not a review.

Checkpoint 2

Limits Aligned to Risk

Examiners expect documented rationale for coverage limits across cyber, D&O, and bond — not just a declarations page.

Checkpoint 3

Security Warranty Compliance

Your carrier requires specific controls as conditions of coverage. If your IT environment doesn't match, the carrier can deny a claim.

Checkpoint 4

Policy Interactions

A ransomware attack, wire fraud loss, and board investigation touch multiple policies. Which one responds to which part?

Download the Examiner Checklist

Ten questions across board governance, policy coverage, and policy interactions to check whether you are in good shape.

Download the Checklist ↓

Where These Requirements Come From

No single regulation tells you what coverage to carry. But these are what examiners cite when they ask.

FDIC Risk Management Manual, Section 4.4 +
Examiners must comment in the Report of Examination on "lack of any significant coverage, board of director approval and review, or deficiencies in a bank's loss prevention program." This is the direct hook: examiners will note deficiencies in the board's review process itself, not just in coverage.
FFIEC IT Examination Handbook — Information Security +
The primary source. The Information Security booklet identifies cyber insurance as a risk mitigation tool within the bank's information security program. Examiners use this framework to evaluate whether the bank has assessed its cyber risk exposure and whether insurance coverage aligns with that assessment. The handbook does not prescribe coverage amounts but expects documented rationale.
FFIEC IT Examination Handbook — Management (III.C.7) +
Insurance procedures "should include an annual program review by the board of directors." Management "should consider seeking the help of insurance consultants, attorneys, and other professionals, as necessary, to fully identify and measure the risk." This is where the expectation for independent analysis beyond the placing broker originates.
FFIEC Joint Statement on Cyber Insurance (2018) +
Boards should be engaged in insurance program reviews. Institutions should "review the scope of existing or proposed insurance coverage to identify gaps" and engage "outside advisors such as attorneys and brokers." The recommendation to engage advisors beyond the placing broker creates the practical expectation for independent review.

Get a Head Start on Your Examiner's Questions

Get in Touch →