Understanding FDICIA IT Requirements

How to bring your network and data into compliance with the Federal Deposit Insurance Corporation Improvement Act


In 1991 during the Savings and Loan Crisis, in an attempt to stabilize the industry, the Senate and House Banking Committee each introduced bills which resulted in the FDICIA. This act requires financial institutions to submit annual reports, which include management’s assertions regarding the effectiveness of internal controls (e.g., risk assessment, control environment, information and communication, control activities, and monitoring) around their financial reports. If the institution has assets over $1 billion, external auditors verify the managers’ assertions.

Who Needs to Comply

Public and private financial institutions must comply with FDICIA.

Under FDICIA, institutions with assets over $500 million require the following:

  • A statement regarding adequate internal controls and procedures for financial reporting
  • A description of management’s responsibility of the institution’s internal controls

Under FDICIA, Institutions with assets over $1 billion require the following:

In addition to the requirements above, management is required to assess and report on the effectiveness of internal controls and external auditors must examine and attest to management’s internal control assertions.

Key IT Requirements

Requirement Description Varonis Product/Feature
Requirement Description
MANAGEMENT RESPONSIBILITY FOR INTERNAL CONTROLS Each insured depository institution shall prepare— (A) a statement of the management's responsibilities for– establishing and maintaining an adequate internal control structure; (B) an assessment, as of the end of the institution's most recent fiscal year, of– the effectiveness of such internal control structure and procedures; (C) the institution's compliance with the laws and regulations relating to safety and soundness which are designated by the Corporation and the appropriate Federal banking agency; [Codified to 12 U.S.C. 1831m(b)] FDICIA requires that management is responsible for an adequate internal control (risk assessment, control environment, information and communication, control activities, and monitoring) structure, and an assessment by management of the effectiveness of the control structure, including computerized information system controls and security. This means the institution must have a clear understanding of where data is stored, who owns it, who is responsible for it (steward) and who is authorized to use it.FDICIA also requires that organizations be able to provide evidence that they are compliant. This requires an ongoing effort to document and measure compliance continuously.

