Last verified: September 2026
What the FFIEC actually asks of your exercise program
The FFIEC's business continuity exercise and testing expectations, from the booklet and the examination work program — who they reach, why "should" is not "must", why there is no FFIEC interval, and what a tabletop can and cannot prove.
FFIEC
If you run business continuity at a US bank, credit union or the service provider behind one, you have probably been told the FFIEC requires you to test your plan, and that it wants it done annually.
Neither is quite what the guidance says. The FFIEC's expectations for exercises and tests are written for examiners, in the language of "should", and they set no interval of their own. That doesn't make them easy to set aside. An examiner assesses against them, but what gets assessed is whether your program is fit for your risk. That is harder to fake than a date on a calendar.
What follows is what the FFIEC's Business Continuity Management booklet and its examination work program actually say, with the parts that summaries most often get backwards. Everything here is sourced to the FFIEC's own text and to its member agencies, and cited in the footnotes.
Who this applies to
The Business Continuity Management booklet is part of the FFIEC IT Examination Handbook. It was issued in November 2019 and replaced the 2015 Business Continuity Planning booklet.³ ⁴
The FFIEC's members framed it around what examiners need to understand at "banks and other regulated entities, including depository financial institutions, nonbank financial institutions, bank holding companies, and third-party service providers."⁵ The member agencies each apply it to their own populations:
- The OCC applies it to its supervision of all national banks and federal savings associations, and adds that "Community banks should maintain effective business resilience and continuity commensurate with their operational complexities."³
- The FDIC applies it to all FDIC-supervised institutions, under a statement of applicability that expressly includes those under $1 billion in total assets.⁴
The sources set no asset threshold. The guidance scales instead. Expectations are proportionate to the institution's complexity and risk, and the booklet builds that into its cadence (see below).
Service providers are in the frame twice: as entities whose preparation examiners assess,⁵ and inside your scenarios, which "should include threats that could affect third-party service providers."¹
Requirements at a glance
| What the guidance expects | Where | Cadence | Addressed to |
|---|---|---|---|
| Provide for appropriate exercises and tests to verify that business continuity procedures support business continuity objectives | Booklet, Section VII (Action Summary)¹ | — | Board and senior management |
| Exercises and tests at appropriate intervals, when new risks are identified, or when significant changes affect the operating environment | Booklet, Section VII¹ | Risk-based. No FFIEC-set interval | The institution |
| Let the risk profile drive the frequency, objectives and documentation of the exercise schedule | Booklet, Section VII¹ | Set by the institution | The institution |
| Realistic, risk-based scenarios that simulate disruptions in business functions, including threats affecting third-party service providers | Booklet, VII.F¹ | — | Management |
| A mix of exercise types (full scale, limited scale, tabletop) and tests | Booklet, Section VII¹ | — | The institution |
| Examiner objective: whether the program is sufficient to let management assess the institution's ability to meet its continuity objectives | Work program, Appendix A² | At examination | Examiners |
| Examiner check: every function in the exercise and test universe covered within the institution's own established timeframes | Work program, Appendix A² | The institution's own. The FFIEC gives examples only | Examiners |
Sources: the FFIEC's Business Continuity Management booklet and examination work program.¹ ² As of September 2026.
Expectation, not mandate, and why the word matters
The booklet's section on exercises and tests opens with its Action Summary:
"The board and senior management should provide for appropriate exercises and tests to verify that business continuity procedures support business continuity objectives."¹
Three things in that sentence set the terms for everything after it.
The verb is "should." This is examination guidance, not a regulation. When the FDIC announced the 2019 revision, it said so plainly: "The changes do not impose new requirements on examined entities."⁴ The OCC described the booklet as providing "information for examiners to assess the adequacy of a bank's risk management related to the availability of critical financial products and services."³
It is addressed to the board and senior management. The expectation sits with governance, not with whoever happens to own the exercise calendar.
It says what exercises are for: to verify that business continuity procedures support business continuity objectives. That is the test every exercise in your program is measured against.
Parts of the section speak to the examiner directly, not to you: "Examiners should review for the following in exercise and testing plans:"¹ So the useful way to read the booklet is as the examiner's side of the table. It describes what will be looked at, not a form to be filled in.
"Should" is not a softer standard in practice. An expectation framed around the institution's own risk can't be closed by ticking a box. What an examiner looks for is a program visibly fit for that risk, and evidence that it runs.
How often: the booklet sets no interval
If you have been given a number here, it did not come from the booklet. The booklet makes cadence a function of risk:
"Exercises and tests should occur either at appropriate intervals, when new risks are identified, or when significant changes affect the entity's operating environment."¹
"The entity's risk profile should influence the frequency, objectives, and documentation of the overall exercise schedule."¹
There are three triggers (an appropriate interval, a new risk, a significant change), and no number. How often is appropriate is the institution's decision, driven by its own risk profile.
The examination work program checks that decision from the other side:
"Determine whether management covers all of the functions in the exercise and test universe according to its established timeframes (e.g., all processes are covered annually or every three years)."²
Read that step carefully, because the numbers in it are the ones most likely to be lifted out of context.
- The standard is the institution's own. Examiners check coverage against the timeframes management has established. The FFIEC does not set them.
- "Annually or every three years" are examples. They follow "e.g." They show what an institution's timeframe might look like. They are not an FFIEC standard, a floor, a ceiling, or a one-to-three-year band.
- It measures coverage, not frequency. The step asks whether every function in the exercise and test universe gets covered within the cycle. Covering all processes over three years is not "an exercise every three years."
A second step mirrors the booklet's triggers: "Verify that exercises and tests occur at appropriate intervals, or when significant changes affect the entity's operating environment."²
So the honest summary is this: examiners check that you cover every function in your exercise and test universe within the timeframes your institution has set, and that you exercise again when risks or your environment change. The FFIEC's work program offers covering all processes annually, or every three years, as examples. It does not give you a date.
What examiners check
The work program's objective for this area is a single sentence:
"Determine whether the exercise and testing program is sufficient to allow management to assess the entity's ability to meet its continuity objectives."²
Notice what it asks. In this objective the examiner is not asking whether the institution is resilient. The examiner is asking whether the program lets management find out. An exercise program is judged as a management instrument. It should produce something management can use to know whether continuity objectives will hold.
That has a practical consequence. An exercise that happened but left no usable record of what was decided, what broke and what changed afterwards gives management nothing to assess with, whatever it was called.
Scenarios: realistic, risk-based, and not only yours
VII.F is where "realistic" comes from, and the word is the booklet's own:
"Management should develop realistic exercise and test scenarios, based on risks, which simulate disruptions in business functions and help management determine the ability to meet both business requirements and customer expectations."¹
- Based on risks ties the scenario to your own risk assessment, not to a generic catalogue.
- Disruptions in business functions makes business functions the unit, not just systems.
- Business requirements and customer expectations is the measure. Technical recovery alone doesn't answer it.
- And the scenarios "should include threats that could affect third-party service providers."¹ Your provider's bad day belongs in your exercise.
What a tabletop is, and what it cannot prove
The booklet names three types of exercise, and tests separately: "Types of exercises (e.g., full scale, limited scale, or tabletop) and tests."¹ It defines the tabletop in its own words:
"A tabletop exercise (sometimes referred to as a walk-through) is a discussion during which personnel review their BCP-defined roles and discuss their responses during an adverse event simulation."¹
Then it draws the line:
"By themselves, tabletop exercises are likely insufficient to validate recovery capabilities, because they are limited to a discussion-based analysis of policies and procedures."¹
The FFIEC's examination work program carries the same caution into the examiner's checklist.²
That sentence is precise, and it is worth taking at its word. It does not say tabletops are inadequate. It says that by themselves they are likely insufficient for one specific job: validating recovery capabilities. The reason is structural. A discussion can establish that people know their roles and can reason through an adverse event. It cannot show that a system comes back, that a site fails over, or that a backup restores.
So a program meant to validate recovery should not rely on discussion alone. It needs the tests and the full- and limited-scale exercises the booklet names alongside the tabletop. A program built only of tabletops leaves that gap open, and the examiner's checklist carries the same caution.
The tabletop has its own job. It is where the people side of the plan gets exercised: roles, decisions, escalation, communication, and the reasoning behind each. The booklet defines it by exactly that. The mistake is asking a tabletop to do both jobs.
Doing the tabletop's job well
The booklet says what exercises are for: to verify that business continuity procedures support business continuity objectives.¹ The examiner's objective asks whether your program lets management assess its ability to meet them.² On the people side of the plan, the tabletop's side, both are answered by what an exercise reveals, not by the fact that it took place.
"Realistic" is the booklet's word. VII.F asks for realistic, risk-based scenarios that simulate disruptions in business functions, including threats that could affect third-party service providers.¹ A scenario built on the disruptions your own risk assessment ranks highest exercises the procedures you would actually rely on.
An exercise that adapts to the room gives management more to assess. A scripted walk-through shows that people know their roles. One where the situation responds to what the crew decides shows where escalation stalls, where a decision has no owner, and where procedures and objectives part company. Realistic, adaptive exercises are one of the most direct ways to make the tabletop's job produce something management can use.
If you were pointed at the Cybersecurity Assessment Tool
If your program still cites the FFIEC's Cybersecurity Assessment Tool, it is citing a retired tool. **The FFIEC sunset it on 31 August 2025.**⁶ The FFIEC had described it as "a voluntary assessment tool," and it decided not to update it to reflect newer government resources.⁶
Where the guidance is deliberately open
Naming these is more useful than papering over them, because your examiner may read them differently than you do.
- "Appropriate" is not defined, in "appropriate exercises and tests" or in "appropriate intervals." That is proportionality by design. The judgement is yours to make, and to be able to explain.
- Whether your timeframes are appropriate is examiner-dependent. The work program checks that you keep to your own timeframes. How an examiner weighs whether those timeframes fit your risk profile is not written down.
- The mix of exercise types is your call. The booklet names full-scale, limited-scale and tabletop exercises and tests, and cautions against relying on tabletops alone to validate recovery. It does not prescribe a ratio.
- Scale is signalled, not tiered. The member agencies expect continuity commensurate with complexity and risk. This guide sets out no size tier, because the sources it relies on do not state one.
What Crewcible produces that maps to it
Crewcible is built for the exercise itself: designing it, running it, and capturing what came out of it. Crewcible exercises are discussion-based, and they do the tabletop's job. They are not a way to validate recovery capabilities. The booklet's caution applies to them as it applies to any tabletop. The testing and the full- and limited-scale exercises that validate recovery sit alongside them in your program.
Within that job, three outputs line up against what the guidance asks for.
The scenario. VII.F asks for realistic, risk-based scenarios that simulate disruptions in business functions. Global Library scenarios are built on narrated, escalating disruption. AI-suggested injects respond to what the crew actually decides, so the exercise follows the crew instead of a script. They are designed to support that expectation.
The record. The examiner's objective asks whether the program lets management assess its ability to meet continuity objectives. Crewcible captures decisions and reasoning per participant and per inject as the exercise runs. What management gets to assess from is a record, not a recollection written up a week later.
The improvement plan. After-action output comes out of the exercise rather than being reconstructed after it. That gives a revised plan a documented reason, and gives the next exercise something specific to check.
The facilitator decides what gets released and when, so the judgement stays with your people. AI enabled, human led.
Crewcible is built by experts who have supported crisis situations and exercises in the world's largest organizations.
For a ready-to-run financial-services starting point, see 48 Hours of Confidence: Anatomy of a Deposit Run in the Global Library. It puts executives, treasury, communications and the board through a deposit run moving at social-media speed. It exercises the decisions, which is what a tabletop is for.
Regulatory references current as of September 2026. This guide is scheduled for re-verification by March 2027.
¹ FFIEC IT Examination Handbook, Business Continuity Management booklet (November 2019), Section VII, "Exercises and Tests," including VII.F. Quoted passages are verbatim.
² FFIEC IT Examination Handbook, Business Continuity Management examination work program (Appendix A, Examination Procedures). The objective and the two procedure steps are quoted verbatim; the checklist's tabletop caution is summarised.
³ Office of the Comptroller of the Currency, Bulletin 2019-57, "FFIEC Information Technology Examination Handbook: Revised Business Continuity Management Booklet" (14 November 2019).
⁴ Federal Deposit Insurance Corporation, FIL-71-2019, "Updated FFIEC IT Examination Handbook – Business Continuity Management Booklet" (14 November 2019).
⁵ FFIEC joint press release on the revised booklet (14 November 2019), as republished by the NCUA.
⁶ FFIEC Cybersecurity Assessment Tool sunset statement (29 August 2024), as issued by the member agencies: OCC Bulletin 2024-25, Federal Reserve SR 24-7, and FDIC FIL-61-2024.