"It's not me who can't keep a secret. It's the people I tell that can't." Abraham Lincoln (1)


In recent years, new regulators, new rules, enhanced supervisory and enforcement authority, and intensive public scrutiny of the effectiveness of banking supervision have all amplified the longstanding tensions and ambiguities that emerge from the exchange of information critical to effective bank supervision, including "confidential supervisory information" ("CSI"). The dynamics of supervisory dialogue involve everything from routine examination matters to complex public enforcement investigations. The D.C. Circuit described the context from which CSI emerges as follows:
   Bank safety and soundness supervision is an iterative
   process of comment by the regulators and response by the
   bank. The success of the supervision therefore depends
   vitally upon the quality of communication between the
   regulated banking firm and the bank regulatory agency.
   This relationship is both extensive and informal. It is
   extensive in that bank examiners concern themselves
   with all manner of a bank's affairs: Not only the
   classification of assets and the review of financial
   transactions, but also the adequacy of security systems
   and of internal reporting requirements, and even the
   quality of managerial personnel are of concern to the
   examiners. (2)

As a policy matter, concerns about the treatment of CSI that emerge from this supervisory dialogue must be reconciled with legal privileges and the desirability of open government. These interrelated concerns can complicate the dialogue between a supervised institution and its supervisors. There are traps for the unwary for institutions that are insufficiently mindful of how CSI is shared and maintained, ranging from reputational damage and diminished competitive posture, to loss of legal privilege and even to civil or criminal sanction. The agencies have such elevated concerns about the improper use or disclosure of CSI that enforcement actions, civil penalties, and even criminal referrals will be used as a deterrent and punishment. Enforcement actions can serve as definitional guardrails in understanding the scope of permitted use of CSI, but many questions remain. (3)

For example, in 1997, Asahi Bank, Ltd., then one of Japan's largest banks, consented to an order issued by the Board of Governors of the Federal Reserve System ("Board") to pay a $5 million civil money penalty, in part, for the misuse of CSI by its New York branch employees, who allegedly accessed sealed boxes of documents stored by examiners at Asahi Bank's offices. No financial impropriety was alleged to have resulted from the improper access. In addition to its civil enforcement action, the Board referred the matter to the Justice Department. (4)

In 2012, the National Credit Union Administration ("NCUA") banned a credit union director from serving on any NCUA-insured credit union board, for having revealed the supervisory rating of a credit union led by a nominee for the NCUA's governing board. (5) In this case, the NCUA couched its enforcement action and prohibition order as pertaining to a breach of fiduciary duty by the director.

Most recently, a former Federal Reserve Bank of New York examiner and a Goldman Sachs banker each pled guilty to a misdemeanor charge of theft of government property and consented to an order banning each from banking. In this case, the banker wrongfully obtained approximately thirty-five documents containing CSI from his former subordinate at the Federal Reserve Bank of New York. The banker then used those documents for purposes of furthering his career interests at Goldman Sachs by sharing those documents within the company, including documents relating to examinations of a bank that Goldman Sachs was advising about a potential transaction. In this case, upon learning of these issues, Goldman Sachs fired the banker as well as a managing director with supervisory responsibility, and self-disclosed the misuse of CSI to its regulators. Despite these actions, Goldman Sachs paid a $50 million fine to the New York Department of Financial Services, agreed to a three-year abstention from any consulting arrangements that would require disclosure of CSI under New York law, and further agreed to pay a $36 million fine to the Board. The Board's Order asserted that the firm had inadequate policies, training, controls, and risk management oversight related to handling of CSI, and the Board required implementation of an enhanced compliance program pertaining to CSI. (6) Further, the Board also brought a civil enforcement action against the managing director also fired by Goldman Sachs, alleging violations of law as well as breach of fiduciary duty. (7)

Considering the examples above, there are clearly lessons to be learned. First, the agencies take improper disclosures of CSI seriously, and will bring civil actions and make criminal referrals in appropriate instances. Disclosure or use of CSI, except as expressly permitted by the appropriate agency, may be subject to criminal penalties. (8) Further, as seen in the Goldman Sachs Order (9) and other enforcement actions, the agencies expect banks to have appropriate compliance programs in place to ensure that CSI is not misused. However, despite the seriousness of these issues, the rules governing CSI are disparate and in some cases inconsistent, forcing some institutions to consider how to reconcile conflicting regulatory expectations.

Larger, more complex banking institutions may have supervisory relationships or enforcement-related dialogue with the Board, the Office of the Comptroller of the Currency ("OCC"), the Federal Deposit Insurance Corporation ("FDIC"), the Consumer Financial Protection Bureau ("CFPB"), the Securities and Exchange Commission ("SEC"), the Commodity Futures Trading Commission ("CFTC"), the Department of Justice ("DOJ"), the Internal Revenue Service ("IRS"), state regulators and tax authorities, state attorneys general, foreign regulators, and others. In addition, banks have a choice of charter and of federal prudential supervisor, and the degree of clarity and permissiveness of the agency's rules pertaining to CSI may be a factor in regulatory arbitrage.

Further reflecting the importance of this issue, definitions and permissible uses of CSI have significance in other contexts beyond the scope of this article. For the distinct but related purposes of the federal Freedom of Information Act ("FOIA"), matters that are "contained in or related to examination, operating, or condition reports prepared by, on behalf of, or for the use of an agency responsible for the regulation or supervision of financial institutions" are exempt from disclosure to the public by the federal government. (10) The same policy underpins the common law "bank examiner privilege," which may be asserted by the agencies to shield disclosure of CSI as an evidentiary matter in the context of litigation. (11) Separately, CSI may contain communications subject to legal privilege, such that institutions must understand whether statutory protections pertaining to "selective waiver" preserve the privileged nature of those communications. (12)

Against this backdrop, this article examines the definitions of CSI and the treatment of confidential communications between banks (13) and their supervisors--the Board, the OCC, the FDIC, as well as with the CFPB--in the exercise of each agency's supervisory and enforcement powers. It proceeds in five parts. Part II discusses the agency definitions of CSI, both in an abstract sense and as the rules limit permitted use and disclosure. (14) Part III provides illustrative examples of the implications of the agencies' disparate rules. (15) Part IV posits whether market signals have eroded the veil of secrecy afforded to certain key elements of CSI. (16) Finally, Part V presents considerations for potential reform. (17) While many states have their own rules pertaining to CSI, further complicating the landscape, a complete analysis of those rules is beyond the scope of this article. Throughout, the article identifies some suggested opportunities for reform, and discusses some common practical concerns that arise from supervisory discourse. (18)


A. Definitions in the Abstract

CSI can generally be defined as information prepared for, by or on behalf of, or for the use of a bank's supervisors. At its core, this includes supervisory ratings, examination reports and supervisory letters, and the iterative back-and-forth that emerges as banks are subject to regulatory supervision. Beyond these axiomatic points, however, the Board, OCC, FDIC, and CFPB each have distinct definitions and requirements. In many cases, what constitutes CSI must be assessed under a "know it when you see it" standard, but the agencies have provided definitions in the abstract, varying between agencies:
Board   (1) Confidential supervisory information means:

        (i) Exempt information (19) consisting of reports of
        examination, inspection and visitation, confidential
        operating and condition reports, and any information
        derived from, related to, or contained in such reports;

        (ii) Information gathered by the Board in the course
        of any investigation, suspicious activity report, (20)
        cease-and-desist orders, civil money penalty enforcement
        orders, suspension, removal or prohibition orders, or other
        orders or actions under [enumerated laws pursuant to which
        the Board has supervisory or enforcement authority];

        (A) Such final orders, amendments, or modifications of final
        orders, or other actions or documents that are specifically
        required to be published or made available to the public
        pursuant to 12 U.S.C. 1818(u), (21) or other applicable law,
        including the record of litigated proceedings; and

        (B) The public section of Community Reinvestment Act
        examination reports...;


        (iii) Any documents prepared by, on behalf of, or for the
        use of the Board, a Federal Reserve Bank, a federal or
        state financial institutions supervisory agency, or a
        bank or bank holding company or other supervised
        financial institution.

        (2) Confidential supervisory information does not include
        documents prepared by a supervised financial institution
        for its own business purposes and that are in its
        possession. (22)

OCC     (b) Non-public OCC information:

        (1) Means information that the OCC is not required to
        release under the FOIA ... or that the OCC has not yet
        published or made available pursuant to [Section 1818(u)]
        and includes:

        (i) A record created or obtained:

        (A) By the OCC in connection with the OCC's performance
        of its responsibilities, such as a record concerning
        supervision, licensing, regulation, and examination of a
        national bank, a Federal savings association, a bank
        holding company, a savings and loan holding company,
        or an affiliate; or

        (B) By the OTS (23) in connection with the OTS's
        performance of its responsibilities, such as a record
        concerning supervision, licensing, regulation, and
        examination of a Federal savings association, a savings
        and loan holding company, or an affiliate;

        (ii) A record compiled by the OCC or the OTS in connection
        with either agency's enforcement responsibilities;

        (iii) A report of examination, supervisory correspondence,
        an investigatory file compiled by the OCC or OTS in
        connection with an investigation, and any internal
        agency memorandum, whether the information is in the
        possession of the OCC or some other individual or entity;

        (iv) Confidential OCC information obtained by a third party
        or otherwise incorporated in the records of a third party,
        including another government agency;

        (v) Testimony from, or an interview with, a current or
        former OCC employee, officer, or agent or a former OTS
        employee, officer, or agent concerning information acquired
        by that person in the course of his or her performance of
        official duties with the OCC or OTS or due to that person's
        official status at the OCC or OTS; and

        (vi) Confidential information relating to operating and
        no longer operating national banks, Federal savings
        associations, and savings and loan holding companies
        as well as their subsidiaries and their affiliates.

        (2) Is the property of the Comptroller. (24)

FDIC    [Confidential supervisory information includes:]

        Records that are contained in or related to examination,
        operating, or condition reports prepared by, on behalf of,
        or for the use of the FDIC or any agency responsible for
        the regulation or supervision of financial
        institutions. (25)

CFPB    (1) Confidential supervisory information means:

        (i) Reports of examination, inspection and visitation,
        non-public operating, condition, and compliance reports,
        and any information contained in, derived from, or related
        to such reports;

        (ii) Any documents, including reports of examination,
        prepared by, or on behalf of, or for the use of the CFPB
        or any other Federal, State, or foreign government agency
        in the exercise of supervisory authority over a financial
        institution, and any information derived from such

        (iii) Any communications between the CFPB and a
        supervised financial institution or a Federal, State, or
        foreign government agency related to the CFPB's supervision
        of the institution;

        (iv) any information provided to the CFPB by a financial
        institution to enable the CFPB to monitor for risks to
        consumers in the offering or provision of consumer
        financial products or services, or to assess whether
        an institution should be considered a covered person,
        as that term is defined by 12 U.S.C. 5481, or is subject
        to the CFPB's supervisory authority; and/or

        (v) Information that is exempt from disclosure pursuant
        to [Exemption 8].

        (2) Confidential supervisory information does not include
        documents prepared by a financial institution for its own
        business purposes and that the CFPB does not possess. (26)

As can be seen by the preceding definitions, there is a fundamental dissimilarity in the definition of what constitutes CSI among the agencies. There are a range of questions that emerge. What constitutes information "derived from" or "related to" an examination report? Is any information developed by a bank in response to an examination finding considered CSI? Is it the case that information may be CSI, but not also covered by Exemption 8 for FOIA purposes? Or, are these equivalent such that case law developing the coverage of Exemption 8 can inform what is to be treated as CSI? Should a banking group with many regulators adopt the most conservative definition? Which one is that? Should the bank synthesize the definitions to derive its own? What are the risks of that?

Should a bank whose primary federal supervisor is the FDIC look to the other agencies' definitions for greater certainty? Does the FDIC's definition relate to any supervisory dialogue outside of examination reports? Does it clearly include state examination materials, as the Board's rule does? What about information provided to the FDIC in the context of an applications process, such as for a merger or a new activity, which are not clearly examination, operating, or condition reports?

With regard to interagency communications, the CFPB makes it clear that interagency communications pertaining to the CFPB's supervision of an institution constitute CSI. The Board includes any documents prepared by, on behalf of, or for the use of the Board, a Federal Reserve Bank, a federal or state financial institutions supervisory agency, but does not--as the CFPB does--include any foreign government agency. (27) The OCC only includes any confidential OCC information obtained by another agency. The FDIC is silent on this issue.

When the Board and the CFPB exclude documents prepared by the bank for its own business purposes, the Board references documents that are in the bank's possession, but the CFPB references documents that are not in the CFPB's possession. If, for example, a large organization obtains a third party review of its compliance management system for business purposes, and the report is also provided to the Board and the CFPB upon supervisory request, is that information only CSI for so long as it is "possessed" by the agency? What does this mean in the context of shared databases of documents and information? Which agency's information is it?

In many ways, these and other questions and apparent inconsistencies in definitions may seem academic, but they take on real world meaning in the context of civil or criminal supervisory sanction for misuse of CSI.

B. Definitions Based Upon Usage and Context

While the agencies have each defined CSI differently in their rules, ambiguities about CSI also emerge in the context of determining how it is used, by whom, and for what purpose. Again, these ambiguities are brought into sharp focus by the threat of civil penalties and potentially criminal sanctions for unlawful use or disclosure. An understanding of the agency CSI rules, and how they are applied, is therefore a significant practical concern for each bank.

Likely reflective of the emerging ubiquity of electronic data, as well as instances of misuse of CSI, the federal prudential banking supervisors began to issue guidance in the late 1990s to better refine what constitutes CSI and how the agencies expect that information to be treated. (28) Agency guidance was later codified by the agencies in their regulations, but the agencies diverged in the degree to which they granted banks authority to divulge CSI.

In addition, the agencies issued the 2005 Interagency Advisory, (29) which predated the CFPB. This advisory was prompted specifically by agency concerns about insurers requesting or requiring banks to provide their CAMELS ratings in the context of underwriting directors and officers liability ("D&O") policies. The 2005 Interagency Advisory generally referenced existing agency rules regarding disclosure of CSI, emphasized the importance of those rules, and pointed to a range of public sources of information about banks, such as Call Reports and Thrift Financial Reports, Uniform Bank Performance Reports, SEC filings, rating agency reports, and public enforcement actions as alternatives to disclosure of CAMELS ratings or other CSI. (30)

Collectively, these efforts have established a number of fundamental principles in understanding CSI. First, CSI is the property of the agency, not the supervised institution, and the agency has the power to permit or deny its use or disclosure for any purpose. (31) Second, supervisory ratings, such as the CAMELS, RFI/C, or ROCA ratings, are sacrosanct, and exam reports are of equal rank. (32) Third, the agencies will respond collectively to issues of common import, such as the demands of insurers for CSI, in order to provide "cover" to banks under pressure to provide CSI to third parties.

However, rules pertaining to permitted disclosures of CSI vary in material ways among the agencies, and more recent rules from the CFPB have altered the landscape. Again, recent civil and criminal enforcement actions have brought into focus how and whether any institution can assure compliance with the agencies' divergent standards. Given the blurring of lines among the supervisory authority of the agencies, in particular for larger institutions, these distinctions may require them to accept the lowest common denominator, which may constrain the flexibility of the permitted business use of CSI in unnecessary and potentially costly ways.

1. The Board's Rules

Below are key points of the Board's rules that guide a Board-supervised institution in determining whether and when disclosure of CSI is permitted. The Board explicitly permits a bank to provide CSI "to its directors, officers, and employees, and to its parent bank holding company or parent savings and loan holding company and its directors, officers, and employees." (33) The Board also permits a bank to provide CSI to any certified public accountant or legal counsel employed by the supervised financial institution, subject to certain conditions, including that these advisors may review CSI only on the premises of the supervised financial institution, and shall not make or retain any copies of such information, and may not make any further disclosure of the CSI except upon prior written approval of the Board's General Counsel, except as necessary to provide advice to the bank. (34) The Board's rules state further that "[n]o person obtaining access to confidential supervisory information pursuant to this section may make a personal copy of any such information; and no person may remove confidential supervisory information from the premises of the institution or agency in possession of such information except as permitted by specific language in this regulation or by the Board." (35)

As recently as 2013, largely reiterating the 2005 Interagency Advisory, the Board summarized and reinforced its warnings to community banks to ensure appropriate treatment of CSI, as follows:

OK to Disclose:

* Directors, officers, employees

* Parent company directors, officers, employees

* Certified public accountant (subject to limitations)

* Legal counsel (subject to limitations)

Check with Appropriate Agency:

* Insurers

* Creditors

* Shareholders

* Customers

* Rating agencies

* General public

* Potential acquirers (36)

The Board has required, since at least 1988, that certified public accountants and legal counsel may only access CSI "on the premises" of the supervised institution. (37) This means that, without specific permission, a Board-supervised institution may not reveal "matters requiring attention" or citations of legal violations for which the institution may require legal advice, unless the lawyer is on site at an office of the institution. While conceivably an outside lawyer may review electronic documents containing CSI, according to this rule, the lawyer may only do so at a computer that is "on the premises" of the supervised institution. The Board's pre-email and pre-Internet rule, while clearly intended to maintain custody and control of paper documents, does not reflect the modern reality of secure email, protected data rooms, and other mechanisms for sharing CSI with legal counsel or a CPA. (38) Because the Board's rule also restricts making or retaining "copies" of CSI--defined to include any information derived from exam reports--the Board could also sanction a bank, and its legal counsel or CPA, if memoranda or analyses of legal or accounting concerns include references to CSI, as broadly defined. Further, "copies" of that information would be made as a matter of course as files are shared (within the sanctioned relationship with counsel or the CPA). On their face, the Board's rules also would seem to prohibit a law firm from retaining records of privileged attorney-client discourse that contains CSI.

Moreover, this limitation is incongruent with the statutory requirement that an insured state member bank "shall transmit" a copy of its most recent examination report and any non-public enforcement action to its external auditor. (39) Further, the Board, along with the other prudential agencies, have long indicated, that banks "should provide [external auditors] with access to all examination reports and written communication between the institution and the agencies or state bank supervisor since the last external auditing activity." (40)

Similarly, the Board's rules do not permit disclosure of CSI to other advisors that are not legal counsel or public accountants. In recent years, a variety of consulting firms have evolved into key resources for banks addressing complex regulatory concerns and compliance matters. In some instances, these consulting firms are hired by legal counsel, establishing legal privilege protections for the work of the consultants. However, the Board's rule does not permit direct disclosure of CSI by a bank to its consultants, and prohibits disclosure of CSI by lawyers or CPAs to those consultants "without the prior written approval of the Board's General Counsel except as necessary to provide advice to the supervised financial institution, its parent bank holding company, or the officers, directors, and employees of such supervised financial institution and parent bank holding company."

The Board's rule permits disclosure of CSI by a bank to its parent holding company, but not to other affiliates. For example, information necessary to enable a holding company to develop an enterprise-wide view of the company's risks can include CSI. However, it is unclear whether the results of that risk analysis, increasingly expected of nearly every bank holding company by the Board as a supervisory matter, can be provided to the non-bank sister affiliates of the bank, unless the analysis is not derived from or related to CSI. Further, the Board's rules also would not permit CSI to be disclosed to insurers for important insurance coverage such as D&O policies, including to provide a notice of circumstances in order to preserve rights of claims against the policy.

2. The OCC's Rules

Below are key points of the OCC's rules that guide an OCC-supervised institution in determining whether and when a disclosure of CSI is permitted. First, while impliedly permitted by the rule, there is no express provision permitting an OCC-supervised bank to disclose CSI to its holding company, in contrast with the Board's rules and the rules of the FDIC, described below. On the other hand, the OCC expressly permits disclosures "when necessary or appropriate for business purposes" to "a person or organization officially connected with the bank or Federal savings association as officer, director, employee, attorney, auditor, or independent auditor." (41) Further, the OCC permits disclosure of CSI to consultants, subject to a non-disclosure agreement meeting prescribed terms. There are no restrictions in the OCC's rules on making such disclosures only on the premises of the bank, or subject to limitations on retention of copies, as in the Board's rules.

3. The FDIC's Rules

The FDIC provides detailed rules for limited disclosure of its CSI pertaining to disclosure by the FDIC itself in its various capacities, but these rules provide only limited flexibility with regard to a bank's ability to share CSI with third parties without permission of the FDIC. (42) In general, the FDIC will provide directors, officers, employees, or agents of the regulated entity access to CSI in the performance of their official duties. However, the authorization provided by the FDIC's regulation does not extend, for example, to an officer of the bank providing CSI to any agent, such as a lawyer hired by the bank or its external auditor, if not authorized by the FDIC itself. Despite the FDIC's restriction, as noted above with regard to the Board's rules, federal statutes require that insured banks "shall transmit" copies of examination reports and other CSI to their external auditors, and this was reinforced by interagency policy. (43)

Unlike the other agencies, the FDIC has a highly prescriptive rule that permits disclosure of FDIC exam reports to the bank's parent holding company and its directors, officers, and employees. Requirements include that the parent must own 50% of the bank's voting stock, the bank board of directors must annually resolve, in a prescribed manner, to authorize the reproduction and furnishing of reports, and the minutes must record certain information pertaining to the disclosure. (44) As noted above, the Board's rules authorize disclosure, and the OCC only impliedly authorizes disclosure. Neither of these agencies have the same prescribed standards as the FDIC.

Notably, unlike other agencies, the FDIC does not provide for the disclosure of CSI by a bank to its lawyers, consultants, or service providers, without permission of the agency. The FDIC has been particularly sensitive in the context of its receivership role for troubled or failing banks. In 2012, the FDIC issued guidance stating that it is a breach of fiduciary duty, and a violation of FDIC regulations, for directors and officers, and their lawyers, to copy and remove CSI and other financial institution records in anticipation of litigation or an enforcement action against that director or officer in his or her personal capacity. (45)

4. The CFPB's Rules

As the newest agency on the block, the CFPB's current rules provide both the most clearly defined and the most permissive rules of those surveyed with regard to the permitted use and disclosure of CSI that belongs to the CFPB. (46) The CFPB provides the most definitional certainty and operational flexibility of any of the agencies with regard to use and disclosure of CSI. Affiliates, lawyers, contractors, consultants, and "service providers" are all permitted to obtain CSI as necessary to provide advice or services to the institution. Further, unlike any of the other agencies, the CFPB's rules explicitly permit disclosure to directors, officers, and employees of all affiliates "to the extent that the disclosure of such CSI is relevant to the performance of such individuals' assigned duties." (47) In turn, these affiliates may also disclose CSI to CPAs, lawyers, contractors, consultants, or service providers.

Instead of requiring prior permission in these instances, the CFPB permits disclosure unless otherwise directed by the agency, and imposes requirements on the recipients of the CSI. The recipient may not "utilize, make, or retain copies of, or disclose CSI for any purpose, except as is necessary to provide advice or services to the supervised financial institution or its affiliate." (48) This approach allows, for example, a bank to include restrictions on the use of CSI in the form of non-disclosure terms in services contracts, rather than having to seek prior approval of senior staff of the agency. These provisions perhaps reflect that modern banks need the services of third parties, often on an expedited basis, and that these institutions are part of larger organizations with consolidated operations and risk management needs.

While the CFPB's rules are notable for their clarity and utility, the CFPB has also proposed a controversial loosening of its rules with regard to sharing of CSI by the CFPB with non-supervisory agencies, such as state attorneys general. (49) This proposal received significant industry response, including concerns about the chilling effect that such disclosure would have on the confidential supervisory relationship and the potential waiver of legal privilege. (50) As of the close of 2017, the CFPB has not finalized its proposed rule.


In considering the landscape above, there are a range of practical issues that arise with regard to the definition and use of CSI. A list of those issues includes, but is not limited to, the following:

* When can a bank reveal CSI of one agency to another agency? For example, if an on-site examiner demands to see the responses of the bank to supervisory "matters requiring attention" issued by another agency.

* In a joint exam by state and federal prudential supervisors, which agency's rules govern the treatment of CSI?

* In an examination of a third-party service provider by the FFIEC under its authority pursuant to the Bank Service Company Act, which agency's definitions and rules govern?

* How should a bank track, label, and maintain CSI? Is this a risk governance issue, a legal issue, an information security issue? Should the bank maintain labels, or header/footer legends, to identify CSI? What should those legends say? How should CSI information be maintained when it may also be subject to legal privilege, to private non-disclosure agreements, or to FOIA exemptions? Should institutions establish compliance programs that ensure they meet the standards emerging from the Goldman Sachs Order? (51)

* What should a bank do when it receives unsolicited CSI from a third party? For example, what if an applicant for a job at the bank references work history that included remediation of non-public supervisory concerns at another bank?

* If the bank has entered into a non-disclosure agreement with a third party, the agencies have asserted that such agreements should not impede supervisory access to such information. (52) Further, the Board has asserted that "identification of information requested by, or provided to, supervisory staff--including the fact that an examination has taken or will take place--is related to an examination and falls within the definition of confidential supervisory information." (53) In this case, the bank must ensure that non-disclosure agreements expressly permit access by their supervisors to confidential information shared by third parties. This access can create friction in negotiations.

* For publicly traded institutions, tensions may be created between restrictions on disclosure of CSI and securities law disclosure requirements. Many publicly traded banks feel obliged by the securities laws to pre-emptively disclose the impact of their regulatory status in securities filings. While the bank cannot reveal its CAMELS composite, RFI/C, compliance or other ratings, it may feel compelled by the securities laws to describe the effect of any memorandum of understanding or other non-public enforcement order on matters important to shareholders, such as limitations on dividends or debt. Surprisingly, the agencies have not issued any clarifying guidance on this issue, despite its impact on a wide range of firms.

* In the context of any bank merger or acquisition, appropriate diligence naturally includes a review of the regulatory status of the partner, its compliance and risk management systems, and other areas not immediately apparent from a review of the financial statements. (54) The acquirer or resulting bank wants to be sure it is not assuming a set of problems that can undermine the value of the deal. The target wants some assurance that the acquirer can complete the transaction as it requires regulatory approval. While there is substantial information publicly available, and even though deal diligence is always pursued pursuant to non-disclosure agreements, where CSI is so broadly defined to include information "derived from or related to" examination materials there is a delicate dance required to ensure that appropriate diligence can be accomplished. (55)


While the agencies have expressed substantial interest in maintaining the secrecy of a bank's ratings, justifying an entire regime of protection for CSI, increasingly the regulatory status of an institution can be deduced from its behavior and by public regulatory sanctions. Some may argue that the composite CAMELS or compliance ratings of a bank are an open secret. Banks with a "4" or "5" composite CAMELS rating typically face a public enforcement action. The market also can often deduce when banks have a composite CAMELS rating of "3" or a subjective management rating of "3," as these institutions will typically have to stay on the sidelines for any "expansionary" activity, including not only mergers and acquisitions, but also any branching activity. The Board has made this policy explicit, and the OCC and FDIC have typically followed the same approach. (56)

While other factors, such as open investigations of consumer compliance concerns, may constrain expansionary activity, even for satisfactorily-rated institutions, the effect is the same, in that confidential supervisory discussions may be revealed by their known market impact on the supervised institution. Once filed and publicly noticed, withdrawals of applications or licensing matters are also publicly known, and provide market signals on an institution's supervisory status. In other words, the agencies use the blunt lever of enforcement actions, forced withdrawals or slowed processes for expansionary proposals, and other tools to drive banks to act upon supervisory concerns. As a result, in some instances the agencies themselves are revealing significant information about an institution's supervisory status, while simultaneously constraining the bank's ability to address with clarity, in a public manner, its efforts to address those concerns, as that information may be considered CSI.


Among the goals for regulatory reform should be the reconciliation of the disparate treatment of CSI by and among the agencies, to modernize rules, and to provide greater clarity to banks and others on the definitions and permissible usage of CSI. (57) Interagency collaboration to rectify this lack of clarity should be in the interest of the agencies themselves. Doing so would provide better clarity and transparency to all interested parties and remove unnecessary concerns that can impede the free-flow of information between regulators and regulated institutions necessary to both effective supervision and to the operations of the supervised bank. Unless required by Congress or as necessary given the unique powers or authority of the agency, rules governing the treatment of CSI should be as consistent as possible. To further the goal of confidentiality and candor to enable agencies to effectively supervise banks, the treatment of CSI should not be more or less stringent depending upon the choice of primary federal regulator. In addition, the treatment of CSI by the CFPB should be consistent with the treatment of such information by the prudential regulators, again except to the extent that the unique role and powers of the CFPB or the prudential agency dictate otherwise. Moreover, standards of interpretation of treatment of CSI should not be left to "agency policy" that is not set forth in law and regulation, or at a minimum set forth in interagency regulatory guidance.

The U.S. Government Accountability Office ("GAO") issued a study in 2016 ("GAO Report" or "Report") that found that "fragmentation and overlap have created inefficiencies in regulatory processes, inconsistencies in how regulators oversee similar types of institutions, and differences in the levels of protection afforded to consumers." (58) The Report encourages efforts by Congress to rectify these concerns. However, as the GAO Report points out, given the complex, overlapping, and fragmented nature of the U.S. regulatory system, reconciliation of competing interests among the agencies may require a mandate from Congress as an impetus to force the agencies to take action. The GAO Report also describes how legal constraints affect interagency sharing of confidential information to achieve the systemic risk monitoring and analysis goals set by the Dodd-Frank Act, which created the Office of Financial Regulation and the Financial Stability Oversight Council to achieve those goals. In other words, inconsistent standards for definitions and treatment of CSI not only impact supervised institutions, but also disrupt the government's ability to achieve its systemic oversight goals in a collaborative manner. (59)

Some have recommended an open dialogue among regulators, the regulated, and industry professionals, such as lawyers, consultants, and accountants, to facilitate a more consistent understanding of the definition and use of CSI. (60) These commentators also recommend reforms including: (1) having the prudential bank regulators adopt the CFPB's standard for sharing CSI with lawyers and other advisors as a practical step; (2) providing a common and streamlined approach to obtaining approvals for routine disclosures; and (3) taking into account the role of attorney-client privilege as an overlapping protection and justification for permitted disclosures. (61)

Moreover, in 1979, Congress established the Federal Financial Institutions Examinations Council ("FFIEC") "to prescribe uniform principles and standards for the Federal examination of financial institutions ... and make recommendations to promote uniformity in the supervision of these financial institutions." (62) From the FFIEC came the CAMELS rating system, schools for examiner training across agencies, and other interagency efforts. It seems that the FFIEC could also be an appropriate entity to reconcile disparate and in some cases outmoded approaches to the definition and treatment of CSI, which is so important to effective bank supervision.

In summary, the banking agencies have elevated the importance of the treatment of CSI by emphasizing concerns in enforcement actions and by issuing guidance and rules, but have not provided consistent and coherent definitions and guidance across the industry. Reform of these rules would remove unnecessary uncertainty and friction, and help foster the transparent and candid dialogue critical to effective bank supervision.

Clifford S. Stanford, Cliff Stanford is a Partner with Alston & Bird, where he chairs the firm's bank regulatory practice. Mr. Stanford was formerly an official with the Federal Reserve Bank of Atlanta. Mr. Stanford thanks students Roy G. Dixon, III, John H. Hykes, Joanne Wu, and Richard W. Gittings, and Professor Lissa L. Broome for their assistance in preparing this article.

