The Bank Policy Institute (BPI) has issued a compelling framework advocating for a significant shift in how financial institutions share sensitive data with regulators. The recommendations, released on July 23, 2025, urge a move away from direct electronic transfers, which can expose institutions to heightened cybersecurity threats. Instead, BPI proposes that regulators utilize controlled access systems that allow them to review sensitive information without the financial institutions relinquishing control over the data itself. This approach includes options such as firm-hosted applications, screen sharing, and on-site reviews, particularly for highly sensitive information that could impact market integrity or competitive positioning.

The impetus for this framework stems from recent cybersecurity breaches at the Office of the Comptroller of the Currency and the Treasury Department, which have prompted a reevaluation of data-sharing practices. BPI's recommendations align with a coordinated strategy from federal regulators aimed at minimizing the collection and storage of sensitive information during bank examinations. By limiting requests to only the information necessary for regulatory oversight, the framework seeks to reduce the risk associated with creating multiple copies of sensitive data outside a financial institution's secure environment.

Particularly noteworthy is the emphasis on safeguarding financial information deemed sensitive, such as strategic plans and merger-and-acquisition data. BPI suggests that regulators should allow financial institutions to provide access through controlled means rather than requiring full data transfers. This is especially critical for pre-deal M&A information, where market implications could arise from premature disclosures. The framework also recommends layered protections, including the use of aggregated data or summaries instead of complete datasets, thereby minimizing the risk of exposure.

Furthermore, the recommendations extend to internal audit information and anti-money laundering materials, underscoring the importance of maintaining attorney-client privilege in regulatory contexts. By advocating for a model focused on controlled access rather than duplication, BPI aims to preserve the regulatory oversight necessary for financial stability while simultaneously reducing the cybersecurity vulnerabilities that come with data sharing. This shift could have profound implications for how financial institutions in the Gulf region manage their regulatory relationships and safeguard sensitive information in an increasingly digital landscape.

Source: PYMNTS