Law report No. GLW-5443 · filed October 10, 2026
Regulation & EnforcementReported case
NYDFS Sets New Expectations for Part 500 Risk Assessments
NYDFS has signaled closer examiner scrutiny of cybersecurity risk assessments under 23 NYCRR Part 500, according to a recent Lexology analysis. The guidance targets documentation depth, third-party coverage, and board oversight.
By Amara Osei3 min read638 words
Holding
- 23 NYCRR Part 500 took effect in 2017 and was comprehensively amended in November 2023
- Section 500.9 requires periodic, documented risk assessments of information systems and nonpublic information
- NYDFS supervises more than 3,000 institutions under Part 500
- Most 2023 amendments became enforceable between 2024 and 2025
- Expectations summarized in a Lexology analysis circulated to the legal community
The New York Department of Financial Services has signaled closer examiner scrutiny of risk assessments carried out under 23 NYCRR Part 500, according to a recent Lexology analysis circulated to financial-services practitioners. The guidance carries weight for the more than 3,000 institutions the Department supervises, including banks, insurers, mortgage servicers, and money-services businesses.
Part 500 took effect in 2017 and underwent comprehensive amendments in November 2023. The amended rule expanded the universe of covered entities, tightened governance duties, and added prescriptive requirements for risk assessment, access privileges, and incident response. Most provisions became enforceable between 2024 and 2025.
What Part 500 already requires
Section 500.9 anchors the assessment obligation. It directs each covered entity to:
- Conduct a periodic risk assessment of its information systems and the nonpublic information those systems hold.
- Evaluate risks to confidentiality, integrity, and availability of that information.
- Document the assessment results, including identified risks and mitigation plans.
- Update the assessment when material changes occur.
The 2023 amendments layered additional requirements onto this baseline, including coverage of third-party and supply-chain risk and clearer documentation expectations.
Where examiners now look harder
Lexology's analysis points to four areas where expectations have tightened under recent examination cycles:
- Documentation depth. Assessments should map identified risks to specific business functions, systems, and data flows rather than to broad categories.
- Third-party coverage. Vendor, service-provider, and fourth-party relationships must be evaluated, including concentration risk.
- Governance trail. Boards and senior officers must demonstrate that they reviewed the assessment, understood residual risk, and decided on risk acceptance.
- Update triggers. Material changes in technology, operations, or the threat landscape should drive interim updates, with documentation of the trigger and the response.
The Department has not issued a single consolidated FAQ setting out each of these points. Lexology's piece synthesizes them from the regulatory text, prior supervisory letters, and recent examination activity.
Why this matters now
NYDFS has long used a combination of guidance letters, examination findings, and enforcement actions to clarify what "periodic" and "effective" mean under Section 500.9. The 2023 amendments codify much of the practice the Department had been pressing through examinations.
Examiners now routinely ask for evidence that the assessment reviewed privileged-access management, data-loss prevention, vendor concentration, and ransomware-recovery scenarios. An otherwise sound assessment can fail an examination if its records do not show who performed it, when, on what inputs, and what changed as a result.
Practical consequences for practitioners
Counsel advising covered entities should treat the Lexology analysis as a working checklist, not official rule text. Practical steps include:
- Map current risk-assessment methodology against Section 500.9 and the November 2023 amendments.
- Confirm board and senior officer engagement is documented in meeting minutes.
- Expand vendor and supply-chain coverage to include concentration risk.
- Tie assessment updates to defined change-management triggers.
- Prepare a written summary suitable for board review and examiner production.
- Route the assessment through counsel where elements touch privileged work product.
Common gaps include thin treatment of vendor risk, generic mitigation language, and limited board reporting. Each is a likely examination finding under the new expectations.
The wider signal
NYDFS remains the most prescriptive cybersecurity regulator in U.S. financial services. Its enforcement docket has shaped the tone for examinations by the OCC, FDIC, and the prudential regulators' joint guidance on third-party risk management. A move toward tighter scrutiny of risk assessments, if echoed in the Department's own communications, would tell the industry that the floor under Section 500.9 has risen.
Covered entities and their counsel should read the Lexology analysis in full, map its points to current practice, and verify any operational change against the latest NYDFS publications. The Department's website remains the authoritative source for guidance letters, enforcement actions, and the current text of Part 500.
via GN Lexology (Source)
More from Amara Osei
Show full bio
Senior reporter covering industry trends and analytics at Global Law Wire.
186 articles