Safety and soundness standards for insured depository institutions: internal controls, information systems and internal audit systems
In force since .
An AI sector rules rule binding private bodies.
- Criminal exposure
- No
- Instrument type
- an act of a legislature
- Obligation class
- Governance
- Audit expectation
- continuous
- Who audits it
- Internal independent
- Where the report goes
- Kept
As of .
What it requires
- It reaches you if you are an insured depository institution, the class of institution for which section 39 of the Federal Deposit Insurance Act requires each appropriate Federal banking agency to prescribe safety and soundness standards.
- An institution should have internal controls and information systems appropriate to the size of the institution and the nature, scope and risk of its activities, providing for clear lines of authority and responsibility for monitoring adherence to established policies, effective risk assessment, timely and accurate financial, operational and regulatory reports, adequate procedures to safeguard and manage assets, and compliance with applicable laws and regulations (Guidelines section II.A).
- An institution should have an internal audit system appropriate to its size and the nature and scope of its activities, providing for adequate monitoring of the system of internal controls through an internal audit function (or, where its size, complexity or scope of operations does not warrant a full scale internal audit function, a system of independent reviews of key internal controls), independence and objectivity, qualified persons, adequate testing and review of information systems, adequate documentation of tests and findings and any corrective actions, verification and review of management actions to address material weaknesses, and review by its audit committee or board of directors of the effectiveness of the internal audit systems (Guidelines section II.B).
Who enforces it
Enforcement body
The appropriate Federal banking agency for the institution: the Office of the Comptroller of the Currency, the Board of Governors of the Federal Reserve System or the Federal Deposit Insurance Corporation.
What this law does
Section 39 of the Federal Deposit Insurance Act requires each appropriate Federal banking agency to prescribe standards for all insured depository institutions relating to internal controls, information systems and internal audit systems. The agencies adopted the Interagency Guidelines Establishing Standards for Safety and Soundness in conjunction with a final rule published in the Federal Register in July 1995. That final rule took effect .
The Guidelines say an institution should have internal controls and information systems that are appropriate to the size of the institution and the nature, scope and risk of its activities. Those controls and systems should provide for effective risk assessment, timely and accurate reports, adequate procedures to safeguard and manage assets, and compliance with applicable laws and regulations.
The Guidelines also say an institution should have an internal audit system, appropriate to its size and the nature and scope of its activities, that provides for adequate monitoring of the system of internal controls through an internal audit function. If an agency determines that an institution fails to meet a standard established by guideline, the agency may require the institution to submit an acceptable plan to achieve compliance with the standard.
If the institution fails to submit an acceptable plan in time, or fails in any material respect to implement an accepted plan, the agency must by order require the institution to correct the deficiency. Until the deficiency is corrected, the agency may also restrict the growth of the institution's assets or require it to increase its ratio of tangible equity to assets.
Neither section 39 nor the Guidelines limits the authority of the agencies to address unsafe or unsound practices or violations of law.
Guidance on this law
How the bodies that enforce this law read it. Guidance binds nobody by itself, so LexLint never raises a finding from it; the duty is this law's.
- Interagency Supervisory Guidance on Model Risk Management (2011), the Federal Reserve Board, the Office of the Comptroller of the Currency and the Federal Deposit Insurance Corporation
- Interagency Supervisory Guidance on Model Risk Management (2026 revision), the Federal Reserve Board, the Office of the Comptroller of the Currency and the Federal Deposit Insurance Corporation
- OCC Bulletin 2025-26: Model Risk Management, Clarification for Community Banks, the Office of the Comptroller of the Currency
When LexLint raises it
When your app profile says your app provides financial services.