Fed's Own Cybersecurity Gaps Raise the Bar for Bank Vendor Due Diligence: Digital Asset Integration Teams Should Plan for Longer Approval Cycles

On Monday, the Federal Reserve's Office of Inspector General issued a management alert detailing an incident in which a departing employee potentially removed hundreds of documents containing classified FOMC information using an unencrypted USB device. The OIG reported that "the 2024 incident was not fully resolved and the removed information was not fully retrieved." Three months before retiring, the employee triggered 279 data loss prevention alerts, with 111 flagged as potentially involving sensitive FOMC classified information.
The OIG found that "each group's conflicting understanding of escalation and resolution responsibilities resulted in a general lack of clarity about how to proceed in addressing the incident," contributing to the matter remaining unresolved for over a year. A separate July 2026 OIG evaluation found that the Board's insider risk management activities "do not proactively or effectively identify and manage insider risks to its information and assets," noting the Board lacks a centralized program, consistent incident response procedures, and insider risk training requirements for all staff.
This matters beyond the Eccles Building. The Fed's own information security program was downgraded in the 2025 FISMA audit from level-4 maturity (managed and measurable) to level-3 (consistently implemented), leading the OIG to conclude it is "no longer effective." When the nation's central bank cannot maintain an effective security posture by its own watchdog's standards, the implications cascade through the supervisory expectations it sets for the institutions it regulates.
The timing is particularly acute for banks pursuing digital asset capabilities. The Board, FDIC, and OCC issued interagency guidance in 2023 establishing risk management principles for third-party relationships, guidance that "takes into account the level of risk, complexity, and size of the banking organization and the nature of the third-party relationship." Now, as of September 11, 2026, these same agencies have proposed updated interagency guidance on third-party risk management that could have "notable effects in the context of bank relationships with fintechs," given the considerable prior emphasis on risks arising from "banking as a service" and "embedded finance" arrangements.
For heads of digital assets or innovation teams at retail and commercial banks, this creates a compounding problem. You already face internal resistance when integrating third-party OTC desk or custody APIs, risk committees want penetration test results, SOC 2 Type II reports, incident response documentation, and evidence of continuous monitoring. The Fed's own security failures don't change the letter of existing guidance. But they change the atmosphere in which your CISO and compliance team interpret that guidance.
The dynamic is predictable. When a regulator's inspector general publicly flags that the regulator itself cannot coordinate incident response across divisions, cannot resolve security alerts for more than a year, and cannot prevent employees with documented histories of security violations from departing with classified information, internal gatekeepers gain leverage. The argument writes itself: if the Fed's own controls are insufficient, how can we approve a third-party integration without more extensive due diligence than the guidance technically requires?
Industry guidance for institutional custody already emphasizes asking vendors about their "security incident history" during due diligence, noting that "cybersecurity threats are especially dangerous in digital asset markets." Even major banks entering digital asset custody, such as Deutsche Bank's planned service, explicitly note that "client onboarding will be subject to the bank's criteria, due-diligence requirements and risk appetite." The question is not whether vendor security diligence is required, it is. The question is how much additional scrutiny becomes the de facto standard when the regulatory principal demonstrates its own deficiencies.
The Fed has stated it plans to implement processes and protocols to clarify roles and strengthen the escalation of alerts by the first quarter of 2027. That timeline is telling. It suggests the central bank itself needs more than a year to remediate the coordination gaps its watchdog identified. For banks evaluating API integrations for embedded trading desks today, the relevant question is what happens in the interim, and what precedent the remediation process sets for vendor oversight expectations going forward.
The OIG issued nine recommendations to develop a more robust insider risk management program at the Board. Senior Fed leaders responded that they "concur with the OIG's recommendations to strengthen the Board's governance of its information security program and enforcement of its controls." The acknowledgment is notable. It signals that the deficiencies are not contested, they are accepted as requiring structural remediation.
The practical effect for bank innovation teams is that vendor security posture shifts from a compliance checkbox to a potential roadblock. An OTC desk provider's SOC 2 report may satisfy the letter of third-party risk management guidance, but risk committees operating in a climate of heightened regulatory scrutiny will push for more: additional penetration testing, extended observation periods, contractual commitments on incident notification timelines, and possibly on-site security assessments. Each layer adds weeks or months to implementation.
This is not an argument against due diligence, rigorous vendor assessment is essential, particularly for digital asset infrastructure where private key management and API security carry existential risk. The point is that the regulatory climate moment created by the Fed's own security failures provides internal gatekeepers with additional justification to expand diligence requirements beyond current norms. For banks competing to ship embedded trading capabilities, the cost is measured in time-to-market while competitors with different internal risk cultures move faster.
The posture that emerges is one of calibrated patience. The regulatory signals are clear: security oversight at the highest levels of the financial system is under scrutiny, and expectations for supervised institutions will reflect that scrutiny. Innovation teams should budget for extended vendor approval cycles, engage CISOs and compliance teams early in product development, and treat security due diligence as a first-order constraint on roadmap timelines rather than a terminal approval step. The Fed's own difficulties resolving a year-old incident suggest the institutional appetite for security risk is contracting. Build accordingly.
References
[3] Interagency Guidance on Third-Party Relationships: Risk Management, 88 FR 37920, June 9, 2023




