Skip to content

Compliance

NY DFS Part 500

Cybersecurity oversight extended to AI systems, with incident evidence and access records examiners expect.

At a glance

Who this covers, and who enforces it

Entities regulated by the New York Department of Financial Services, including AI systems that touch covered nonpublic information or covered business processes.

NY DFS Part 500Framework
Instrument
23 NYCRR Part 500 — state regulation
Enforced by
New York Department of Financial Services
Timeline
Effective 2017; second amendment Nov 2023
Incident notice
72 hours
Annual duty
Compliance certification by a senior officer

Requirements

What it asks for

  • 1Risk assessment that covers AI use
  • 2Access controls and continuous monitoring
  • 3Incident response with 72-hour notification
  • 4Annual certification of compliance

Evidence mapping

What PRISM records against each requirement

Every plan records this evidence as your AI runs. Compliance Reports, which turn it into a reviewed, framework-mapped report, are delivered as a service, on request.

NY DFS Part 500
AI-aware risk assessment
Model Inventory and Synthetic Scenarios document AI-specific risk testing.
Access controls & monitoring
Guardrails and Projects & Team enforce and log access boundaries.
Incident response
Scores & Alerts flag anomalies in real time, feeding the 72-hour notification clock.
Annual certification
Export & Audit produces the evidence package a certifying officer reviews.

Primary source

Read the actual text

Everything on this page is drawn from New York DFS — Cybersecurity Resource Center (23 NYCRR Part 500). The capture is live, not a paraphrase — go straight to the source and check us.

dfs.ny.gov
Capture of New York DFS — Cybersecurity Resource Center (23 NYCRR Part 500)
Live capture, 24 Aug 2026Open the source ↗

Evidence, not certification

This page describes NY DFS Part 500’s publicly available requirements and how PRISM’s evidence layer supports them. It is not legal advice, and it does not constitute certification, regulatory approval, or a guarantee of compliance. NY DFS Part 500 compliance remains your organization’s responsibility, in consultation with qualified counsel.

Ask us about your framework

Tell us how NY DFS Part 500 applies to your systems and we'll show you the evidence path.