NYDFS Audit Resource
NYDFS cybersecurity audit preparation: what to expect and how to organize evidence.
A NYDFS cybersecurity audit is not just a request for policies. Examiners ask for narratives, numbered evidence, governance records, technical reports, meeting preparation, and proof that the Part 500 program operates in practice.
By Brian Edelman, Founder & CEO, FCI Cyber · Last updated: September 2026
The short version
Prepare for the audit as an evidence-production project.
Recent NYDFS cybersecurity examination requests and meeting agendas show a consistent pattern: the Department wants the current policy, the governance record, the technical proof, the remediation trail, and the people who can explain how the program works. A firm that waits until the request arrives will spend the exam period reconstructing evidence under deadline pressure.
This guide is not legal advice. It is a practical preparation guide for organizing cybersecurity evidence before a NYDFS request list or examiner meeting arrives.
Request list
Expect numbered evidence requests
DFS requests typically ask for electronic copies, brief narratives, item-number file labels, and explanations for anything marked not applicable.
Meetings
Expect operational interviews
IT management and support teams should be ready to discuss topology, patching, firewalls, monitoring, mobile devices, departures, BCDR, and remediation.
Evidence
Expect proof, not intent
Policies matter, but reports, screenshots, minutes, test results, contracts, logs, and remediation records are what make the response defensible.
What the request usually asks for
The evidence categories to assemble before NYDFS asks.
The exact request varies by entity and examination scope. The recurring categories below are the areas firms should keep current, indexed, and ready to explain.
| Audit area | Evidence to prepare |
|---|---|
| Applicability, Class A, exemptions, affiliates | Class A analysis if applicable, exemption support, affiliate/intercompany agreements, adopted-program documentation, and service-level agreements. |
| Policies and Part 500.3 program documents | Information security, data governance, asset inventory, access control, BCDR, systems operations, network monitoring, training, application security, physical security, privacy, vendor management, risk assessment, incident response, and vulnerability management policies. |
| Governance and oversight | Cybersecurity organization chart, CISO resume/job description, outsourced CISO agreement if applicable, backup CISO plan, board expertise evidence, committee charters, meeting minutes, annual CISO reports, plans, budgets, and risk appetite documentation. |
| Testing, vulnerabilities, and patching | Internal and external penetration testing reports, vulnerability scans, patch installation and aging reports, vulnerability-intake process, remediation prioritization, external testing agreements, and independent review evidence. |
| Audit trails, monitoring, and technical controls | Audit trail controls, log integrity and retention procedures, centralized logging, security-violation reports, failed-access reports, EDR/anti-malware reports, alert handling, and monitoring ownership. |
| Access privileges, MFA, and email authentication | Access policies, user and privileged access lists, remote access, MFA records, annual access-review reports, password standards, DMARC or email-authentication evidence, PAM/PIM details, and MFA exception approvals. |
| Risk assessment and change triggers | Current approved risk assessment, methodology, risk criteria, mitigation and acceptance decisions, board/senior-management summaries, update triggers, new products/services, and material IT/IS changes. |
| Gaps, remediation, MRAs/MRIAs, and prior findings | Self-assessments, control gap analyses, material-improvement schedules, remediation trackers, independent validation, and evidence of corrective action for previous findings or violations. |
| Third parties, vendors, cloud, and contractors | Vendor inventory, risk ratings, due diligence, contracts, critical-vendor reviews, board reporting, third-party risk assessments, cloud provider contracts, MFA/encryption controls, and TPRM tooling. |
| Assets, data disposal, encryption, training, IR, and BCDR | Asset inventory with owner/location/criticality/end-of-life status, secure disposal procedures, encryption standards and implementation evidence, training materials and attendance, incident response plans/playbooks, BIA, BCDR plans, tabletop/failover tests, backup restoration evidence, and unreported event lists. |
| IT audit and independent testing | IT audit org chart, auditor resumes/training, audit committee charter/minutes, internal audit charter/manual, IT audit risk assessment, audit universe, audit plan, audit reports, exception tracking, workpapers, and audit involvement in major technology changes. |
| IT management, development, and operations | Succession plans, management reports/dashboards, cyber insurance summary, GLBA monitoring reports, project/change management standards, custom software documentation, network diagrams, capacity reports, helpdesk reports, hardening standards, and system administrator responsibilities. |
Examiner meetings
What your IT and support teams should be ready to discuss.
Meeting agendas often test whether the written response matches operational reality. Prepare subject-matter owners who can explain the process and point to the evidence.
Network topology
How often diagrams are updated, what triggers updates, and whether diagrams include servers, clusters, internet connections, users, DNS/core services, DMZs, data stores, VLANs, wireless networks, cloud resources, service-provider VPNs, and remote access points.
Firewall and IDS/IPS monitoring
Who monitors firewalls and IDS/IPS, how event reports are reviewed, and how firewall rules are reviewed for ongoing business need.
Patch management
How patches are applied, whether automated systems identify and patch assets, whether patch reports are generated, and whether someone independently reviews patch status.
Joiner, mover, leaver controls
Whether departure and role-change checklists ensure accounts are disabled or modified when employees leave or responsibilities change.
Mobile and personal devices
What company-issued or personal devices can access or store, plus patching, monitoring, anti-malware, remote wipe, encryption, secure wireless, and VPN controls.
BCDR and remediation
Whether disaster recovery and business continuity tests include systems and personnel, use failovers/tabletops, and produce tracked remediation plans.
Acceptable use and clean desk
Whether acceptable use covers user-activity monitoring and whether clean desk controls address sensitive papers, mobile devices, end-of-day cleanup, and locked storage.
Planning, budget, insurance, and succession
How IT/IS planning and budgets address cybersecurity, how key-person succession works, and whether cyber insurance limits are tied to a risk assessment.
Preparation plan
How to prepare before the NYDFS request arrives.
The goal is to make the eventual response mechanical: current evidence, named owners, short narratives, and no scramble to reconstruct history.
Create folders that mirror likely request categories: governance, policies, risk assessment, testing, access, MFA, vendors, cloud, assets, monitoring, training, incident response, BCDR, audit, and remediation. Use item-number labels when responding to an actual DFS list.
DFS requests often ask for a brief written narrative explaining the documentation and process. The narrative should describe what the control is, who owns it, how often it is reviewed, which evidence proves it operates, and what exceptions or remediation exist.
Policies that overpromise create audit risk. Compare each Part 500 policy to the reports and controls that prove the policy is actually enforced. If the policy says a review happens annually, identify the minutes, report, ticket, screenshot, or signoff that proves it.
An audit response can fail in the meeting even if the document folder is strong. IT management, support, cybersecurity, compliance, vendor management, and internal audit owners should know which processes they own and where the evidence lives.
Common mistakes
Where firms get caught unprepared.
Submitting policies without proof
A policy answers what should happen. The audit asks whether it did happen and whether the firm can prove it.
Treating N/A as a checkbox
If something is not applicable, explain why. A blank or unsupported N/A can create more questions than a complete answer.
Letting evidence live with one person
Succession and backup ownership matter. The evidence process cannot depend on one CISO, IT manager, vendor, or spreadsheet owner.
Forgetting remediation history
Findings, MRAs, MRIAs, exceptions, and prior audit issues need tracked corrective action and independent validation where applicable.
Not preparing vendors and cloud records
DFS asks about service providers, contracts, due diligence, cloud use, MFA, encryption, and critical-vendor oversight.
Waiting for the meeting agenda
The operational questions are predictable. The firm should be ready to discuss them before the examiner schedules the meeting.
NYDFS audit FAQ
Common questions before a DFS cybersecurity audit.
What does NYDFS ask for in a cybersecurity audit?
NYDFS commonly asks for Part 500 policies, governance records, CISO reports, board and committee minutes, risk assessments, penetration testing and vulnerability evidence, patch reports, access and MFA records, third-party and cloud documentation, incident response and BCDR evidence, training records, and remediation tracking.
How should a firm prepare its NYDFS audit response?
Create a numbered evidence index that mirrors the request list, label every file by item number, include a short narrative for each item, explain any not-applicable responses, and assign owners for governance, IT, cybersecurity, vendor, incident response, and audit evidence.
What should a firm expect in NYDFS IT management meetings?
Firms should be ready to discuss IT succession planning, budgeting, acceptable use and monitoring, clean desk controls, cyber insurance, network topology, firewall rule reviews, IDS/IPS monitoring, patch management, employee departures, mobile devices, and disaster recovery and business continuity testing.
What is the biggest mistake firms make before a NYDFS cybersecurity audit?
The biggest mistake is treating the audit as a policy collection exercise. NYDFS requests operational proof: reports, screenshots, logs, meeting minutes, contracts, test results, remediation records, and evidence that controls are reviewed and maintained over time.
FCI helps financial-services firms enforce cybersecurity controls and produce the evidence that maps those controls to regulatory expectations. The FCI Portal centralizes endpoint status, user controls, monitoring records, remediation evidence, and compliance reporting so the audit response is assembled from an operating program, not rebuilt from scratch.
For NYDFS preparation, the practical question is simple: if DFS sent a request list today, could your firm produce the policy, the proof, the owner, the review date, and the remediation trail for each item?
Prepare before NYDFS asks.
Start with the readiness assessment, review the Part 500 requirements, or ask FCI to identify which audit evidence your firm can produce today and which items would require a scramble.