1. How New York Regulates Financial Institutions
Financial institutions in New York must satisfy both NYDFS requirements and federal standards, and the two frameworks do not always align. In several areas, New York imposes stricter obligations than federal law, and compliance with federal rules alone is not sufficient. For a broader overview of financial law, see our Banking and Finance practice page.
The Role of the Nydfs
The New York Department of Financial Services, established in 2011 under the New York Banking Law, supervises state-chartered banks, licensed lenders, mortgage servicers, and money transmitters. It conducts on-site examinations, issues and revokes licenses, and imposes civil money penalties. Institutions must report material changes in ownership or capital structure to the NYDFS before any transition takes effect.
State and Federal Authority under the Dual Banking System
State-chartered banks answer to the NYDFS, while nationally chartered banks fall under OCC supervision. Holding companies for both types remain subject to Federal Reserve oversight, and FDIC-member state banks face FDIC examination as well. Most institutions must satisfy both state and federal requirements at the same time.
2. Consumer Protection Laws Every Institution Must Follow
Federal consumer protection statutes apply across New York, but the state adds its own layer of requirements that often set a higher standard. Institutions should review both frameworks before finalizing any loan documentation or credit practice. Our Consumer Protection Compliance team advises on both.
TILA requires clear disclosure of the APR, total finance charges, and payment terms before a consumer transaction closes. New York General Business Law § 349 separately prohibits deceptive acts in consumer-oriented business transactions, enforceable by both the CFPB and the NYDFS. The FCRA requires lenders to issue adverse action notices when a credit report contributes to a denial and to investigate disputed information within statutory timeframes. ECOA prohibits discrimination in credit decisions based on race, national origin, sex, age, and marital status. New York's Human Rights Law extends those protections further, adding source of income and immigration status as protected classes.
3. Deposit Insurance and Customer Asset Protection
FDIC coverage protects depositors at member institutions up to $250,000 per depositor, per institution, per ownership category. Institutions must accurately represent their FDIC membership in all customer-facing materials.
| Ownership Category | Coverage Limit |
| Single accounts | $250,000 |
| Joint accounts (per co-owner) | $250,000 |
| IRA and retirement accounts | $250,000 |
| Revocable trust accounts (per beneficiary) | $250,000 |
4. Anti-Money Laundering and Know Your Customer Requirements
The Bank Secrecy Act requires institutions to maintain a written AML program, file Suspicious Activity Reports, and file Currency Transaction Reports for cash transactions over $10,000. New York adds a separate obligation under 3 NYCRR Part 116, which requires NYDFS-regulated institutions to maintain a transaction monitoring program calibrated to detect BSA and AML violations, with annual certification from a senior compliance officer. For guidance on structuring a certifiable program, visit our AML Compliance page.
Kyc Verification Standards
FinCEN's Customer Due Diligence Rule requires identity verification at account opening and identification of beneficial owners holding 25 percent or more of a legal entity. Enhanced due diligence applies to high-risk accounts, including those involving politically exposed persons or significant cross-border activity.
5. Data Security and Privacy Regulations
New York's cybersecurity and breach notification rules impose obligations that go beyond most federal baselines, and both have been updated in recent years. Institutions with New York operations should treat these state standards as the floor. Our Cybersecurity Compliance team handles both readiness assessments and post-incident response.
Nydfs Cybersecurity Regulation (23 Nycrr Part 500)
Substantially amended in November 2023 with phased compliance deadlines extending through 2026., this regulation requires covered institutions to appoint a CISO, maintain an annual written cybersecurity policy, implement multi-factor authentication for all privileged access, conduct annual penetration testing, and report cybersecurity incidents to the NYDFS within 72 hours. Larger institutions designated as Class A under the amended regulation also face independent cybersecurity audit requirements.
NY Shield Act
Effective March 2020, the SHIELD Act requires institutions to notify affected New York residents promptly after any breach of private information. It also imposes an ongoing obligation to maintain reasonable administrative, technical, and physical safeguards, independent of whether a breach has occurred.
6. Fair Lending and Mortgage Disclosure Standards
NYDFS examines credit portfolios for disparate impact and disparate treatment and uses HMDA data to identify lending patterns that raise fair lending concerns. New York mortgage servicers must also comply with RPAPL § 1304, which requires a 90-day pre-foreclosure notice before any foreclosure action is commenced on a one-to-four-family owner-occupied property.
7. Regulatory Examination and Enforcement
NYDFS conducts regular safety-and-soundness examinations using the CAMELS framework and runs targeted compliance reviews in areas such as AML, fair lending, and cybersecurity. Following an examination, institutions may receive informal guidance, supervisory findings or formal enforcement actions, or a formal consent order with defined remediation deadlines. Serious or repeated violations can result in civil money penalties under the New York Banking Law, license suspension, or criminal referral for willful BSA violations. Federal agencies may impose parallel penalties under their own authority.
8. Frequently Asked Questions
What institutions does the NYDFS regulate?
The NYDFS supervises state-chartered banks, trust companies, licensed lenders, mortgage servicers, check cashers, and money transmitters operating under New York law. Nationally chartered banks are supervised by the OCC, though NYDFS cybersecurity and consumer protection requirements still apply to their New York operations.
How does New York's cybersecurity rule differ from federal requirements?
23 NYCRR Part 500 requires a designated CISO, 72-hour incident reporting to NYDFS, annual penetration testing, and independent audits for Class A entities. Most federal guidelines do not impose these controls at the same level of specificity.
20 May, 2026

