A Risk Assessment Is Not a Document. NYSDFS Just Said So.
On September 10, the New York State Department of Financial Services published guidance on how regulated entities should conduct and use risk assessments under Part 500. The first sentence of the guidance says: “This Guidance does not create new obligations.”
That’s technically accurate, and also a reason to read more carefully, not less.
What the guidance actually does is describe what DFS examiners are finding during examinations, and what those findings mean. The common gap list is, in effect, a preview of what a Part 500 examination looks like in practice. If any of those gaps describe your organization, the guidance hasn’t created a new obligation so much as named an existing one you may not have met.
What the Guidance is Actually About
Part 500 has required a risk assessment since the regulation’s original adoption. What it hasn’t done until now is spell out, in detail, what NYSDFS expects a risk assessment to be and to do.
The guidance covers five areas: governance and oversight, methodology, scope, documentation, and integration into the cybersecurity program. Each section describes what the regulation requires and what good looks like in practice.
The connecting thread across all five is a single point that NYSDFS makes explicit: a risk assessment is not a document you maintain. It’s a process that has to demonstrably drive your cybersecurity program. Control selection, compensating controls, risk acceptance decisions — NYSDFS expects regulated entities to be able to show how the risk assessment informed each of those. In examinations and interviews with regulated entity personnel, examiners are asking exactly that question: show us how the assessment shaped what you built.
What NYSDFS is Finding
The guidance includes a list of common gaps identified during DFS’s review of regulated entities. It’s specific enough to be useful.
Incomplete asset scope and visibility. Outdated or incomplete asset inventories, failure to track where nonpublic information resides or flows, and omitting critical systems, cloud environments, or third-party dependencies. A risk assessment can only identify risk in assets it knows about.
Weak or inconsistent methodologies. When the methodology isn’t defined or consistent, results can’t be compared across cycles or defended to an examiner. That includes a missing distinction between inherent and residual risk and controls evaluated differently from one review to the next.
Failure to account for evolving and interconnected risks. Emerging technologies (including AI), changes in the threat landscape, and concentration risk from shared infrastructure or service providers. DFS specifically calls out organizations that evaluate individual vendors as low risk but haven’t assessed what happens when multiple critical systems share the same provider.
Insufficient governance and risk treatment. This covers undocumented risk acceptance decisions, findings that never reach senior management or the board, and assessment results that don’t actually inform resource allocation. DFS wants to see how findings travel from assessment to action.
Failure to connect the risk assessment to the cybersecurity program. This is the gap DFS describes most directly: “policies, controls, and resource decisions that are not demonstrably based on the Covered Entity’s identified cyber risks.” If the risk assessment and the cybersecurity program are two separate exercises, that’s a problem examiners will surface.
The Annual Update and the ‘Material Change’ Trigger
Part 500 already required risk assessments to be reviewed at least annually and updated whenever a material change to the business or technology caused a material change to cybersecurity risk. The guidance clarifies what “material change” means in practice.
Mergers and acquisitions qualify, as do major system migrations and significant new outsourcing arrangements. NYSDFS specifically calls out adoption of AI as a material change. Active exploitation of critical software vulnerabilities may qualify, and so may geopolitical events that increase the likelihood of ideologically motivated attacks.
The practical implication for organizations that haven’t revisited their risk assessment since AI tools entered their environment: that’s likely a missed update. The guidance doesn’t say examiners will treat it as a violation, but it does say they’ll look for it.
What this Means for NYSDFS-Regulated Organizations
The guidance is addressed to all NYSDFS-regulated entities — banks, credit unions, insurance companies, mortgage companies, RIAs, and any other organization licensed or registered under New York’s Banking Law, Insurance Law, or Financial Services Law. That includes some nonprofits that hold DFS licenses, not just financial services firms in the traditional sense.
The guidance explicitly acknowledges that a risk assessment for a small organization will look different from one conducted by a large institution. What it doesn’t do is lower the standard — it acknowledges the difference in scale while holding the same goal: the assessment must be sufficient to inform the design of the cybersecurity program.
For any organization subject to Part 500, the most useful read of this guidance is as exam preparation. The five common gaps are the things NYSDFS is looking for. Organizations that can demonstrate a documented methodology, a current asset inventory, and a clear line from risk findings to control decisions are in a better position than those whose risk assessment is a Word document that was last updated before the pandemic.
If OrbitalFire is already working with you on cybersecurity, this guidance reflects work we carry forward together. Keeping your risk assessment current, connecting it to how your program is actually built, and updating it when your business or technology changes is the ongoing work, not a one-time project. We’ll make sure the picture reflects where you actually are.
How OrbitalFire Can Help
OrbitalFire works with NYSDFS-regulated organizations navigating Part 500 requirements, including organizations preparing for examinations or working to close gaps identified in prior reviews. If your risk assessment needs a refresh, or if you’re not sure whether it would hold up to the standard DFS described on September 10, we’d welcome the conversation. Reach Out and Connect With Us.
If you’d like a starting point for evaluating your broader cybersecurity posture, the Small Business Cybersecurity Readiness Checklist gives you a quick read on where you stand today.
Frequently Asked Questions
Q: What did NYSDFS release on September 10, 2026? A: NYSDFS issued an Industry Letter providing guidance on how to conduct and use risk assessments required by the NYSDFS Cybersecurity Regulation (Part 500). The guidance clarifies regulatory requirements and highlights best practices for designing, conducting, and updating risk assessments. It does not create new obligations.
Q: Who is required to have a risk assessment under NYSDFS Part 500? A: Any entity regulated by the New York State Department of Financial Services under the Banking Law, Insurance Law, or Financial Services Law — including banks, credit unions, insurance companies, mortgage companies, RIAs, and other licensed financial services entities — is required to maintain a cybersecurity program based on a risk assessment.
Q: How often must NYSDFS-regulated entities update their risk assessments? A: At least annually, and whenever a change in business or technology causes a material change to the entity’s cybersecurity risk. Material changes include major system migrations, mergers or acquisitions, significant outsourcing arrangements, adoption of emerging technologies like AI, or significant developments in the threat landscape.
Q: What are the most common risk assessment gaps NYSDFS finds during examinations? A: Based on its review and examination findings, NYSDFS has identified five common gaps: incomplete asset scope and visibility; weak or inconsistent methodologies; failure to account for evolving and interconnected risks; insufficient governance and risk treatment; and failure to connect the risk assessment to the actual cybersecurity program.
Q: What does NYSDFS mean when it says a risk assessment must “inform” the cybersecurity program? A: NYSDFS expects regulated entities to demonstrate how their risk assessment drove specific decisions — control selection, compensating controls, risk acceptance. It’s not enough to have a risk assessment document. Examiners will ask: show us how the assessment shaped what you built.



