New York’s financial regulator is done leaving risk assessments to interpretation. On September 10, the Department of Financial Services issued new guidance spelling out exactly what a cybersecurity risk assessment has to cover before it can satisfy the state’s landmark cybersecurity regulation, first effective in 2017 and tightened again in November 2025. The regulation already required regulated entities to run annual risk assessments. What DFS added is the rubric: governance and oversight, methodology, scope, documentation, and how the assessment actually feeds back into the cybersecurity program it is supposed to inform.
That specificity is the point. “Risk assessments are the foundation of a strong cybersecurity program. As cybersecurity risks evolve and institutions’ risk profiles change, it is critical that their cybersecurity programs adapt, and this guidance outlines those expectations,” said Kaitlin Asrow, DFS Acting Superintendent, in the release. For a bank or fintech operating under the DFS regime, the guidance names four specific triggers that should force a fresh assessment: a material technology change, a merger or acquisition, the rollout of a new critical system, and dependence on a shared vendor, cloud provider, or platform across multiple business functions. That last trigger is squarely aimed at concentration risk, the exposure a firm carries when several critical functions quietly depend on the same third party.
The original insight here is not the guidance itself but its timing: DFS already showed this year, in its $50 million penalty against Swedbank, that it punishes concealment as harshly as the underlying violation. A documentation standard this explicit removes the ambiguity a firm could once lean on to argue an assessment was reasonable after the fact, and it arrives weeks after four federal agencies rewrote third-party risk rules for bank-fintech partnerships. Both moves push the same direction: less prescriptive checklist, more documented judgment a regulated entity has to be able to defend on demand.