Earlier quoted context omitted.
Man, it's like people think banks are special when it comes to IT. They're not! You have lots of extra regulations for sure but most of them are about retention of financial records . If a system isn't processing/storing financial records or "privileged" information nobody gives a damn. The "technology plan" is 99.5% about making or saving money. That remaining .5%? Yeah, that's compliance. Because that's all it cost…
If it's a computer in a bank and it touches risk, trading or treasury, it's fair game for the Fed auditor. So you tell me: what computer system of any import in a bank doesn't touch one of these three things?
They really don't care about systems that don't process financial information! They don't care about your dev or qa environments. They don't care about your DNS servers or your switches or much else for that matter.
Regulators are 100% laser-focused on financial information and transactions. They want to see ledgers and logs and they want to see evidence that your systems prevent tampering. That's it.
There's no financial regulators that actually audit IT stuff. We probably should have them but we don't. The closest is the FFIEC but they only publish non-binding guidelines.
If you think the PCI-DSS matters to banks you're mistaken. Every year we audit ourselves and put the results in a filing cabinet somewhere. We have no obligation to show it to anyone and no one would hold us accountable for failing to be PCI compliant anyway.