NYDFS Does Not Want Your Annual PDF. It Wants the Decision Trail.

Table of Contents

The Department’s September 10 industry letter creates no new Part 500 duties. It does something more useful. It publishes the exam findings firms have been failing in private: incomplete inventories, leftover inherent-risk scores, and cybersecurity programs that cannot point back to the document that is supposed to justify them.

New York’s Department of Financial Services

Frontier AI Is Now a Material Change. So Is the Vendor Everyone Shares.

New York’s Department of Financial Services does not usually waste an industry letter on a pep talk. The September 10 guidance on risk assessments under 23 NYCRR Part 500 is not a pep talk. It is a map of what examiners have already been marking down, written in the voice of a supervisor who is tired of receiving a polished PDF that does not drive a single control decision.

The Department says the letter creates no new obligations. Read that sentence the way compliance people are trained to read it. The obligations were already in § 500.2 and § 500.9. What is new is the public inventory of failure modes. Incomplete asset scope. Weak methodology. No distinction between inherent and residual risk. No owner for the risk that was “accepted.” No update after a material change. A cybersecurity program that cannot demonstrate it was designed from the assessment it cites in the first paragraph of the policy.

If you are a bank, insurer, licensed lender, or anyone else living under a New York license, this letter is the grading rubric for the next exam cycle. Treat it that way.

What Part 500 already required, said without the brochure language

A Risk Assessment, as Part 500 defines it, is the process of identifying, estimating, and prioritizing cybersecurity risks to operations, assets, people, customers, other organizations, and critical infrastructure. It has to include threat and vulnerability analysis. It has to consider the controls you already have. It has to be sufficient to inform the design of the program that is supposed to protect the confidentiality, integrity, and availability of Information Systems and Nonpublic Information.

It has to be done under written policies that set three things: how you categorize risks, how you judge the CIA of systems and NPI against existing controls, and how identified risks get treated by the program. It has to be reviewed at least annually, and again whenever a business or technology change materially moves the risk. It has to be sized to the entity. A one-person shop and a Class A Company will not produce the same artifact. They are supposed to produce the same kind of decision: what to fix, what to compensate, what to accept, and why.

DFS now says out loud what “inform the design” means in an exam room. You should be able to walk an examiner from a line in the assessment to a control, a compensating control, or a documented acceptance. If you cannot, you do not have a risk-based program. You have a program and, separately, a risk assessment.

The five gaps examiners keep finding

The letter’s most useful page is the punch list of deficiencies DFS has already seen.

Incomplete asset scope and visibility. Outdated inventories. No map of where NPI lives or how it moves. Critical processes left out. Third-party service providers left out. Cloud left out. External dependencies left out. This is the original sin. You cannot assess what you have not listed. Part 500 already requires a current asset inventory under § 500.13(a). The guidance ties that inventory to the assessment as a foundational input, which is how it should have been read the first time. If the CMDB is a graveyard of laptops from 2019 and the SaaS roster lives in accounts payable, the assessment is fiction.

Weak or inconsistent methodology. Risks not identified the same way twice. Controls not evaluated for whether they actually work. Inherent and residual risk treated as synonyms. That last failure is how a firm scores “high” before controls, slaps MFA on the slide, and never records what is left. Residual risk is the only number a board can use. Inherent risk is the number a consultant uses to sell the next tool.

Failure to account for evolving and interconnected risks. Emerging technology. A changed threat landscape. Interdependencies. Concentration risk. Single points of failure. DFS is no longer willing to accept an assessment that treats each vendor and each platform as if it were alone on an island. Three “low” cloud findings can still be one franchise-killing outage if they sit on the same region of the same provider.

Insufficient governance and risk treatment. No owner. No documented response. Results that never reach enterprise governance. No refresh after the business actually changed. A risk without an owner is a risk you have already accepted, whether the register says so or not.

Failure to inform the program. Policies, controls, and budget that cannot be shown to come from the identified risks. This is the exam-ending finding. Everything else is a path to it.

The inverse picture, which DFS sketches as the mature program, is not mysterious. Dynamic. Data-driven. Fed into governance. Repeatable method. Scoped on purpose. Documented. Reviewed. That is the whole letter in eight words.

Governance is not a signature block

Part 500 already wants written cybersecurity policies approved at least annually by a Senior Officer or the Senior Governing Body. It wants a CISO, or a Senior Officer standing in, with real oversight of the assessment process. Exempt entities still need someone who knows enough about cyber risk to keep the file from becoming a vendor template.

The guidance pushes past the org chart. Business units, operations, compliance, and legal are supposed to be in the room. That is not inclusion theater. A CISO scoring ransomware without the payments team, or scoring a claims portal without operations, will miss the process failure that actually takes the firm down. Cross-functional input is how you stop the assessment from being an IT document that the business discovers during the incident.

Results go up. Section 500.4(b)(3) already requires the CISO to report material cybersecurity risks to the Senior Governing Body. The assessment is one of the ways you substantiate those risks. Section 500.4(d) already requires that body to confirm management put enough resources against the program. DFS is careful to say Part 500 does not require the board to vote the assessment itself into existence. Do not hide behind that sentence. If the board never sees the residual-risk list, it cannot do the resource job the regulation assigned it. Findings and recommendations exist to force a conversation about money, control selection, and acceptance. A deck that dies in the CISO’s folder is noncompliance wearing a governance label.

A method you can run twice

DFS will not pick your framework. It names the usual suspects — NIST CSF 2.0, the Cyber Risk Institute Profile, ISO 27005 — and then tells you to tailor whatever you picked to your actual business. That is the correct supervisory posture. It is also a warning. Copying a NIST worksheet and leaving the likelihood column on “medium” for every row is not alignment with a recognized framework. It is decorative compliance.

A usable method starts with a structured hunt for threats and vulnerabilities that matter to this entity: threat intelligence, incident trends, vulnerability scans, penetration tests, audit findings, last year’s assessment. It estimates likelihood and impact with criteria you can apply next year without inventing a new scale. It looks outside the building and inside it. Malicious actors, misconfigurations, insider misuse, process failures, administrative-control gaps, human error, third-party failure, the flood that takes the generator. It prices more than a box-check. Loss of NPI. Money. Downtime. Legal and regulatory exposure. Reputation. Replacement cost.

Mature shops, DFS says, use the same risk language in vendor management, IT operations, and business continuity. Harmonized criteria are how a “high” in the vendor file means the same thing as a “high” in the BCP file. If those three processes speak different dialects, leadership is not governing risk. It is collecting dialects.

Review the method on a schedule. The threat changed. Your scoring sheet may need to change with it.

Scope is where most files die

Cover everything that can touch confidentiality, integrity, or availability: hardware, software, infrastructure, people, processes, and data, including NPI. Know where NPI sits, how it moves, who can reach it, and what is supposed to protect it. If the inventory cannot answer those four questions, stop writing the narrative and fix the inventory.

Emerging risk is no longer an appendix. The letter lists the examples examiners will now expect to see considered when they are real for you: adoption of artificial intelligence, quantum computing’s future effect on cryptography, software supply-chain attacks, evolving ransomware, geopolitical conflict that raises nation-state activity. DFS has already published a May 21 letter on heightened risk from frontier AI models. Citing that letter in a footnote and leaving AI out of the assessment is the kind of move that used to work. It will not work after this guidance.

Third parties get their own paragraph because they deserve it. Score providers by criticality of the service, sensitivity of the information they see, connectivity into your systems, and what happens to you if they go down. Cloud. Managed security. Software vendors. Payment processors. Affiliates. Anyone holding up a critical function. “We sent the questionnaire” is not an evaluation of those four factors.

Then concentration. This is the paragraph boards should read twice. A vendor that looks fine alone can be unacceptable in a cluster. Shared platforms, shared cloud regions, shared identity providers, shared MSSPs. Map the interdependency. Name the single points of failure. Ask what happens to the rest of the franchise if one of those shared pipes fails. Systemic cyber risk inside one firm is not a metaphor. It is three applications and a claims file sitting on the same tenant.

If you cannot trace it, you did not decide it

Documentation is not a courtesy to the examiner. It is how you prove a decision happened. Keep the method. Keep the inputs. Keep the rationale. Draw a line from each identified risk to the control or compensating control that is supposed to treat it. When management accepts a risk, write down why, and write down the residual. DFS wants to be able to judge whether that acceptance was reasonable. You should want the same thing before the incident makes the acceptance famous.

Identify the risk in writing before you score it. That sounds elementary because firms skip it. They jump to treatment language — “implement MFA,” “accept,” “transfer” — without a sentence that says what the risk is. You cannot monitor remediation of a blur. You cannot spot a pattern across years if last year’s blur was named differently.

Traceability is also how internal audit stops testing the entire universe. Map risks to controls, then let audit and independent testing chase the mapped controls. A targeted testing plan is not a gift to the auditors. It is how you learn whether the control you funded is configured and operating. Keep a register or an equivalent that shows assessment results, remediation status, and movement in residual risk. If the register is a spreadsheet last saved before the last cloud migration, you are already late for the “material change” duty.

The assessment is the program’s spine, not its appendix

§ 500.2 says the cybersecurity program is based on the Risk Assessment so the program can do the core functions. That is not a preamble. Update policies, procedures, controls, and testing plans from the results. If the assessment says concentration risk at the identity provider is unacceptable and the control budget still goes to a phishing poster, the program is not based on the assessment.

Update at least annually. Update sooner when a change in business or technology materially changes cyber risk. DFS gives the list you should have been using anyway: major system migrations, mergers and acquisitions, significant outsourcing, significant developments in cybersecurity technology — and it names frontier AI models in the text, with a citation to the May 21 industry letter. Changes in threat-actor capability. Adoption of emerging technology. Add the extras the Department flags as reasons to look again even when they may not, standing alone, rewrite the residual-risk table: active exploitation of a critical vulnerability, geopolitical events that raise ideologically motivated attacks. There is a companion letter on measures to consider in a heightened threat environment. Use it.

A continuous or regularly refreshed process beats a once-a-year offsite. The firms that treat the assessment as a living file will look adaptable in the next exam. The firms that treat it as an annual deliverable will look exactly as adaptable as their last table of contents.

What to do before the next examiner asks

Pull last year’s assessment and try the walk-through DFS is describing. Pick five residual risks. For each one, name the owner, the control or the acceptance memo, the last test of that control, and the date you last asked whether the risk had changed. If you cannot finish the sentence, you have the finding already. You just have not received it on letterhead.

Rebuild scope off a current inventory, including NPI flows, cloud, affiliates, and the vendors that can halt a product line. Put AI systems and training-data stores in the inventory if they exist. If you adopted a frontier model or a serious agentic workflow since the last assessment, you likely had a material change and did not update. Fix that before you explain it.

Harmonize scoring across vendor risk, IT operations, and continuity. Force one conversation at the Senior Governing Body that uses one set of words. Document every acceptance as if a referee will read it after an outage, because that is the audience.

This letter is not a new Part 500. It is DFS announcing that the old Part 500 will now be read like it meant what it said. Covered entities that already run a living, scoped, residual-risk process will file the letter and keep moving. Covered entities that have been buying an annual assessment to attach to the certification will spend the next quarter discovering they do not have a cybersecurity program. They have a binder. Binders do not survive the incident the assessment was supposed to rank.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.