Services About Insights Schedule Consultation

On September 10, 2026, the New York Department of Financial Services published guidance on how to conduct and use the risk assessments required by its cybersecurity regulation. Both the letter and the accompanying press release state plainly that the guidance creates no new obligations. That’s accurate, and it’s the wrong takeaway. What the document actually does is show examiners’ hand: five categories of risk-assessment gaps DFS says it keeps finding, and an expectation that every Covered Entity can demonstrate how its assessment shaped its controls.

The letter goes to everything DFS regulates — banks and trust companies, insurance companies, money transmitters, virtual-currency businesses. If your firm operates under a BitLicense or a New York money-transmitter license, this is your document. The timing matters too: the amended Part 500 has been fully in effect since November 2025, so examiners are now checking assessments against the amended rulebook, with this guidance in their pocket.

What the guidance is — and isn’t

The obligations themselves live in Part 500, which has required a risk assessment “sufficient to inform the design of” the cybersecurity program for years. The new document is DFS telling regulated entities what that requirement means in practice. The letter says “This Guidance does not create new obligations.” The press release calls it a clarification of existing requirements plus best practices, and distills four factors worth building into any assessment: material technology change, third-party risk (think concentration on a shared cloud provider or MSP), emerging risk, and risk-informed controls.

What’s genuinely new is the specificity. The letter walks through what DFS expects an assessment to contain — governance and oversight, a defined and repeatable methodology, scope and coverage, documentation and traceability, integration into the program — and then does something regulators rarely do: it lists the gaps its own examiners keep finding. Acting Superintendent Kaitlin Asrow framed the intent in the press release:

“Risk assessments are the foundation of a strong cybersecurity program. As cybersecurity risks evolve and institutions’ risk profiles change, it is critical that their cybersecurity programs adapt, and this guidance outlines those expectations.”

The practical reading comes from Mondaq’s analysis (Mayer Brown): regulated entities “should expect this Guidance to inform NYDFS supervision and enforcement going forward.” No new rule — just a very public statement of what the people across the exam table will be checking.

The five gaps examiners keep finding

This is the part worth printing and pinning up. During examinations and investigations, DFS reviews risk assessments and information-security policies. Across those reviews and in interviews with entity personnel, the Department identified common gaps that, in its words, “have contributed to deficient cybersecurity programs.” The five categories, close to verbatim:

  1. Incomplete asset scope and visibility. Outdated or incomplete asset inventories; not knowing where nonpublic information resides or flows; omitting critical business processes, third-party service providers, cloud environments, or other external dependencies.
  2. Weak or inconsistent methodologies. Failing to consistently identify, analyze, prioritize, and document risks; failing to evaluate whether existing controls actually work; failing to distinguish inherent risk from residual risk.
  3. Failure to account for evolving and interconnected risks. Emerging technologies, changes in the threat landscape, interdependencies, concentration risk, single points of failure that could materially affect operations.
  4. Insufficient governance and risk treatment. No assigned ownership; undocumented risk-response decisions; assessment results that never reach enterprise governance; assessments that sit untouched while the business, technology, or threat environment moves.
  5. Failure to account for or inform the cybersecurity program. Policies, controls, and resource decisions that can’t be traced back to the risks the assessment identified.

Score your current assessment against that list honestly. Category 1 alone is where most first drafts die: the asset inventory is stale, nobody can say where the crown-jewel data actually flows, and the third-party dependencies in scope are the ones procurement knows about rather than the ones that would hurt. If three or more categories describe your shop, the assessment isn’t ready to be an exam exhibit — it’s a to-do list with a deadline.

AI adoption is now on the trigger list

Part 500 requires the assessment to be reviewed and updated at least annually — and whenever a change in the business or technology causes a material change to cyber risk. Most of this guidance’s urgency lives in that second clause. The letter’s examples of material change: “major system migrations, mergers or acquisitions, significant outsourcing arrangements, or significant developments in cybersecurity technologies (e.g., frontier AI models)” — citing § 500.9(a), with a footnote pointing straight to DFS’s May 21, 2026 advisory on heightened cybersecurity risks associated with frontier AI models.

Regulators write “e.g.” for a reason. Frontier AI is an illustration of the kind of development that should make you ask whether your last assessment still describes your company. The press release makes the adoption angle even more direct, listing “Emerging Risk” as a factor to weigh: “how adoption of AI or other emerging technologies changes the entity’s threat exposure, data risks, access controls, or third-party dependencies.”

There’s a series here worth noticing. October 2024: an industry letter on AI-related cyber risks. May 2026: an advisory telling CISOs to heighten controls around frontier models. September 2026: AI named inside the risk-assessment guidance itself. DFS is drawing a straight line from “AI is a cyber risk” to “your risk assessment has to say so.”

The honest nuance: the letter says these developments “may all constitute” material changes. It’s a judgment call, and the judgment is yours to make — and document. If you’ve deployed AI tooling since your last assessment and the assessment doesn’t mention it, that’s not a violation by itself. It’s a gap an examiner can now see clearly, because the regulator has said out loud what a material change looks like. Recording the decision either way is what turns the trigger clause from a liability into a defense.

Traceability is the exam currency

If the guidance has one operating theme, it’s that the assessment must connect to decisions. DFS expects records linking each identified risk to specific controls or compensating measures, documented justifications for accepted risks, and a mechanism — a risk register or comparable tracker — that records results, monitors remediation, and documents how residual risk changes over time. The letter also expects input from business units, operations, compliance, and legal with CISO participation, and results communicated upward: § 500.4(b)(3) requires the CISO to report material cybersecurity risks to the senior governing body, and § 500.4(d) puts oversight of the program on that body.

There’s a payoff beyond the exam, too. The letter notes that strong traceability makes audit and independent testing “more targeted and effective.”

The policy itself is rarely the difficult part. The harder problem is proving the control operates consistently — which risk led to which decision, who accepted the residual, when the compensating control was last tested. That’s the chain an examiner pulls on, and it’s the chain most firms can’t produce on request because nobody maintained it between assessments.

What to do before your next exam

Five moves, in the order I’d run them.

  1. Score the current assessment against the five categories. Two hours with the letter open next to your last assessment produces a gap memo. Where you can’t answer, you’ve found the work.
  2. Build the traceability chain for every accepted risk. Risk → control or compensating control → acceptance justification → named owner → date of last review. This is usually the heaviest lift for a mid-market team; plan in weeks, not days.
  3. Stand up or refresh the risk register. Residual risk over time, remediation status, emerging trends. A spreadsheet someone actually maintains beats a GRC platform nobody updates.
  4. Run the material-change review. Since the last assessment: system migrations, acquisitions, significant outsourcing changes, AI deployments. For each, record the decision — material or not — and who made it.
  5. Brief the senior governing body with the outputs. § 500.4(b)(3) reporting lands better when it draws on the assessment. The board doesn’t need another security dashboard. It needs to know which risks could materially affect the business and how the company decided to handle them.

The guidance is also explicit that assessments should be tailored — a small firm’s assessment “will often look very different” from one performed by a Class A company. Read that as permission to build something proportionate, not as an exemption. The bar is demonstrability, not headcount.

Demonstrability is a practice, not a document. A fractional CISO owns exactly this cadence — methodology, register, acceptance log, board reporting. If your next exam is on the calendar and any of the five categories above made you wince, get in touch before the exam notice arrives. Teams already staring at findings can start with our audit and exam response work, and if the AI trigger clause is the part that hit hardest, that sits at the intersection with our AI governance practice.

Need a second set of eyes before your SOC 2 audit?

NTD Consulting offers a free 30-minute readiness assessment. No pitch, no pressure — just direct feedback on where your program is likely to get pushed back.

Schedule a 30-Minute Consultation