AGP Picks
View all

Continuum GRC says OCC cyber update makes control mapping a readiness priority

Sep. 30, 2026
By AI, Created 18:09 UTC, Sep 30, 2026, AGP -

Continuum GRC is urging banks to tighten cybersecurity evidence mapping after the OCC updated its Cybersecurity Supervision Work Program on Sept. 21, 2026. The firm says the change adds no new procedures, but it raises the stakes for examiner-ready crosswalks, accountable ownership and evidence that holds across frameworks.

Why it matters: - The OCC’s updated Cybersecurity Supervision Work Program raises the bar for how banks organize and prove cybersecurity controls, even without adding new requirements. - Banks that can trace controls, ownership and evidence across frameworks will be better positioned for examiner questions and risk-based supervision. - Community banks face particular pressure to show preparedness in a way that matches size, complexity and risk profile without building a duplicative compliance process.

What happened: - Continuum GRC said banks should review how cybersecurity evidence maps to the current National Institute of Standards and Technology Cybersecurity Framework after the OCC’s Sept. 21, 2026, update to its Cybersecurity Supervision Work Program. - OCC Bulletin 2026-48 updated the work program’s structure and references to align with evolving NIST CSF categories and subcategories. - The OCC said it added no new procedures, changed no procedures and created no new regulatory expectations. - The agency also said banks are not expected to use the examiner work program as their own preparedness assessment. - The OCC continues to allow institutions to choose among standardized tools and frameworks.

The details: - The work program is used in risk-based supervision and maps to the FFIEC Information Technology Examination Handbook, OCC supervisory materials and common cybersecurity frameworks. - Its structure spans the NIST CSF functions Govern, Identify, Protect, Detect, Respond and Recover. - That structure gives examiners a practical way to follow governance, implementation and evidence across a cyber program. - A Sept. 29 speech by Federal Reserve Vice Chair for Supervision Michelle Bowman highlighted cyber risks facing community banks. - Bowman pointed to ransomware, business email compromise, vendor data breaches and AI-enabled attacks. - Bowman also emphasized board and senior-management risk ownership, employee training and periodic incident-response testing. - Continuum GRC said banks should validate, not just refresh, their crosswalks. - The firm said each mapped control should identify an accountable owner, the authoritative policy or procedure, the systems and third parties in scope, the evidence proving operation and the most recent test or remediation decision. - When one artifact supports several frameworks, Continuum GRC said organizations should preserve the source evidence and document the mapping logic rather than maintain disconnected copies that can drift.

Between the lines: - The OCC’s update appears procedural on paper, but the structure still shapes what examiners look for and how banks demonstrate control effectiveness. - The message from regulators is shifting toward traceability, governance discipline and evidence quality, not just policy inventory. - For community banks, a scalable evidence model can reduce duplication while making supervisory reviews faster and clearer. - Michael Peters, founder and CEO of Continuum GRC, said a framework crosswalk is only useful when it leads to living evidence. - Peters said banks should be able to move from an examiner’s question to the responsible owner, the control as designed, proof that it operated and any open remediation without rebuilding the story for every review.

What's next: - Banks are likely to review control mappings, ownership assignments and evidence repositories against the updated NIST CSF structure. - Institutions will also need to show how their cybersecurity program aligns with their risk decisions, control performance, exceptions and corrective actions. - Supervisory teams may use the updated work program as a sharper lens for examiner readiness across governance and operational testing. - Continuum GRC is positioning its platform as a tool for automating evidence collection, continuous control monitoring and cross-framework compliance.

The bottom line: - The OCC did not change the rules, but it reinforced how banks need to prove cybersecurity readiness: with mapped controls, accountable owners and evidence that is current, traceable and exam-ready.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

Today in Banking

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Today in Banking

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.