← Back to Library
FCA EM 31.6

FCA Examination Manual 31.6 (2025)

Full Name:
Farm Credit Administration (FCA) Examination Manual
Acronym:
FCA EM 31.6
Type:
US Federal Standard
Organization:
Farm Credit Administration
Version:
2025
Year Published:
2025
Popularity:
Moderate

Overview of FCA Examination Manual 31.6 - Information Technology Risk Management

The Farm Credit Administration (FCA) Examination Manual Section 31.6, updated in 2025, provides comprehensive guidance for examining information technology risk management at Farm Credit System (FCS) institutions. This section of the FCA examination manual establishes supervisory expectations for IT governance, cybersecurity programs, business continuity planning, and technology risk management at agricultural lending cooperatives comprising the Farm Credit System. FCA examiners use Manual 31.6 to evaluate whether FCS institutions maintain adequate IT controls, protect borrower information, ensure operational resilience, and manage technology risks appropriately given their size, complexity, and risk profiles.

The 2025 update reflects evolving technology risks affecting agricultural financial institutions including ransomware targeting agricultural cooperatives, increased adoption of digital lending platforms, cloud computing migration, and cybersecurity threats exploiting agricultural sector supply chain vulnerabilities. Manual 31.6 emphasizes risk-based approaches recognizing that Farm Credit System institutions range from small associations with limited IT infrastructure to large System banks with sophisticated technology operations. Examination procedures scale requirements appropriately—smaller institutions face expectations for fundamental controls while larger institutions demonstrate advanced cybersecurity capabilities, robust business continuity, and enterprise risk management integration.

Scope of FCA Examination Manual 31.6

Manual Section 31.6 addresses IT risk management comprehensively across FCS institutions' technology environments. Examination areas include IT governance and strategic planning, cybersecurity programs and information security, business continuity and disaster recovery planning, change management and system development, vendor and third-party risk management, data management and privacy protection, and operational controls including access management, monitoring, and incident response.

The manual recognizes diverse technology profiles across FCS institutions. Small agricultural credit associations may operate with limited in-house IT capabilities, relying heavily on shared services from larger System entities or external service providers. Regional banks typically maintain internal IT teams and moderate cybersecurity capabilities. System-wide service organizations providing technology services to multiple FCS institutions face enhanced examination expectations given their critical role supporting multiple institutions. Examiners adjust evaluation intensity and expectations based on institution-specific characteristics rather than applying uniform standards.

Key Examination Areas in Manual 31.6

FCA examiners evaluate multiple dimensions of IT risk management when examining FCS institutions under Manual 31.6 guidance.

IT Governance and Strategic Planning

Examiners assess whether boards and management provide appropriate IT governance and oversight. Institutions should demonstrate board-level understanding of technology risks and strategic technology decisions, IT strategic plans aligned with business strategies and risk appetites, adequate budgets and resources for IT and cybersecurity, qualified IT leadership with appropriate authority and reporting lines, and regular management reporting on IT risks, incidents, and program effectiveness. Small institutions may have less formal governance structures, but boards must still demonstrate basic understanding of technology risks and resource allocation decisions.

Cybersecurity Programs and Information Security

Examiners evaluate cybersecurity program maturity including policies covering information security domains, technical controls protecting against common threats, vulnerability management and patching processes, access controls implementing least privilege and separation of duties, encryption protecting sensitive borrower data, security awareness training for all personnel, and incident detection and response capabilities. Institutions should demonstrate that cybersecurity programs are appropriate to their risk profiles—larger institutions with digital banking platforms face enhanced expectations compared to smaller institutions with limited technology footprints.

Business Continuity and Disaster Recovery

Operational resilience receives significant examination attention given agriculture's critical infrastructure designation. Examiners assess business continuity plans identifying critical business functions and recovery priorities, disaster recovery plans for IT systems supporting critical functions, backup procedures including offsite or cloud backups resistant to ransomware, testing of BCPs and DRPs at least annually with documented results, and recovery time objectives (RTOs) and recovery point objectives (RPOs) appropriate to business needs. Agricultural lending's seasonal nature requires institutions to consider timing of disruptions—recovery during planting or harvest seasons may require faster RTO s than off-season periods.

Third-Party Risk Management

FCS institutions extensively use technology service providers including core banking vendors, cloud providers, and shared services from other System entities. Examiners evaluate third-party risk management including comprehensive inventories of critical IT service providers, due diligence assessments before engaging providers, contracts specifying security requirements and incident notification, ongoing monitoring of provider security and financial viability, and business continuity planning for provider failures. Concentration risk receives particular scrutiny when institutions rely heavily on single providers for critical services.

Data Management and Privacy

Protection of borrower information is critical for agricultural cooperatives holding members' financial and operational data. Examiners assess data classification identifying sensitive information requiring protection, privacy programs addressing borrower information privacy rights and regulatory requirements, data retention policies aligned with business and regulatory needs, and secure data disposal ensuring permanent deletion when retention periods expire. Institutions sharing borrower data with agricultural technology (AgTech) partners face enhanced scrutiny of data sharing agreements and privacy protections.

Examination Ratings and Findings

FCA examiners issue findings when institutions fail to satisfy Manual 31.6 expectations. Finding severity ranges from matters requiring attention (MRAs) for moderate concerns to significant supervisory concerns for material weaknesses. Institutions must develop and execute corrective action plans addressing findings, with FCA monitoring remediation progress. Persistent or severe IT risk management weaknesses can affect institution's overall safety and soundness rating, impact capital requirements, and trigger enforcement actions including cease and desist orders in extreme cases.

Relationship to Other Financial Institution Frameworks

FCA examination approaches align with other financial regulatory frameworks including FFIEC IT Examination Handbook, NIST Cybersecurity Framework, and the Cyber Risk Institute Profile. FCS institutions can leverage implementations for FFIEC or CRI Profile to satisfy FCA examination expectations, as common controls address similar risks. Organizations should also reference GLBA privacy requirements and SOX controls for System banks with publicly traded debt.

Frequently Asked Questions

What is FCA Examination Manual Section 31.6?

FCA Examination Manual 31.6 provides FCA examiners with guidance for evaluating information technology risk management at Farm Credit System institutions. The manual establishes supervisory expectations for IT governance, cybersecurity, business continuity, vendor management, and operational controls. Examiners use Manual 31.6 during safety and soundness examinations to assess whether institutions adequately manage technology risks. Institutions should review Manual 31.6 to understand examination expectations and self-assess their IT risk management programs against examination criteria.

Which FCS institutions must comply with Manual 31.6?

All Farm Credit System institutions face IT risk management examination under Manual 31.6 including Farm Credit Banks, Agricultural Credit Associations, Federal Land Credit Associations, Production Credit Associations, and FCS service organizations. Expectations scale based on institution size and complexity—smaller associations with limited technology face baseline expectations, while larger banks and service organizations face comprehensive examination of advanced IT risk management capabilities. All institutions, regardless of size, must demonstrate appropriate board governance and fundamental cybersecurity controls.

How does Manual 31.6 relate to FFIEC IT Examination Handbook?

FCA Manual 31.6 aligns substantially with FFIEC IT Examination Handbook, as FCA is FFIEC member agency. Many examination procedures and expectations mirror FFIEC guidance, enabling FCS institutions to leverage FFIEC resources for implementation. However, Manual 31.6 includes Farm Credit System-specific considerations including cooperative governance structures, agricultural lending seasonality, and extensive use of System-wide shared services. Institutions satisfying FFIEC IT Handbook expectations generally satisfy FCA Manual 31.6 requirements, though FCA may emphasize specific areas based on System-specific risks.

What are common findings under Manual 31.6 examinations?

Common findings include inadequate board oversight and reporting on IT risks, insufficient cybersecurity policies or outdated policies not reflecting current operations, weak access controls including excessive privileged access and inadequate access reviews, lack of multi-factor authentication for remote access, inadequate patch management with delayed vulnerability remediation, insufficient business continuity testing or unrealistic recovery objectives, weak vendor risk management with inadequate due diligence or monitoring, and incomplete incident response plans or lack of incident response testing. Institutions can avoid findings by conducting honest self-assessments against Manual 31.6 and remediating gaps before examinations.

How can FCS institutions prepare for Manual 31.6 examinations?

Institutions prepare by reviewing Manual 31.6 guidance and conducting self-assessments against examination criteria, documenting IT governance including board minutes showing oversight and IT strategy approval, maintaining current IT policies, procedures, and system documentation, collecting evidence of control operation including access reviews, patch reports, backup tests, and security awareness training records, and addressing identified gaps before examinations. Institutions should maintain organized documentation readily available to examiners. Well-prepared institutions experience smoother examinations with fewer findings, while unprepared institutions face extensive findings requiring corrective actions. Engaging external IT auditors or consultants for pre-examination readiness assessments helps identify issues examiners will discover.