Skip to main content

Author: admin

Takeaways from the OCC’s Cybersecurity and Financial System Resilience Report, June 2026

What the OCC’s latest Cybersecurity Report means for community financial institutions

Cybersecurity has entered a new phase for community banks. Artificial intelligence is giving threat actors new capabilities. Banks increasingly depend on interconnected third parties. Regulators expect institutions to identify and escalate significant incidents quickly. At the same time, emerging technologies are forcing financial institutions to consider risks that may not fully materialize for years.

The OCC’s June 2026 Cybersecurity and Financial System Resilience Report reinforces an important message for community financial institutions (CFIs): cybersecurity can no longer function primarily as an IT responsibility or periodic compliance exercise. It has become an operational resilience issue.

For community banks, that distinction matters. Most institutions cannot match the cybersecurity budgets or staffing levels of the nation’s largest banks, nor do regulators necessarily expect them to. They do, however, expect institutions to understand their risks, establish appropriate controls, manage critical dependencies, prepare for disruptions, and demonstrate that they can respond and recover when something goes wrong. Five developments deserve particular attention from community bank executives and boards in 2026.

1. AI has changed the economics of cybercrime

Community banks should no longer assume their size makes them less attractive to cybercriminals. Historically, attackers often had to devote significant time and resources to reconnaissance, vulnerability identification, social engineering, and attack development. That created an economic incentive to concentrate efforts on potentially lucrative targets. AI changes that calculation.

Threat actors can increasingly automate portions of the attack process, allowing them to identify vulnerabilities, develop convincing social engineering campaigns, and target organizations at greater scale.

As the OCC warns:

“The use of AI can enable automated reconnaissance, rapid vulnerability discovery and exploitation, targeted social engineering, and adaptive malware that can evade traditional security defenses.”

For community banks, the important issue is not whether a cybercriminal specifically selects your institution. Increasingly, they may not need to. Automated tools can search broadly for vulnerable systems, exposed credentials, misconfigurations, and other opportunities. A community bank can become a target simply because an exploitable weakness exists.

Adapting to the changes

Banks should evaluate their cybersecurity programs with this new reality in mind.

Traditional controls remain essential, but institutions should also ask whether those controls can respond to threats operating at greater speed and scale. Vulnerability management, multifactor authentication, access controls, endpoint protection, employee education, network monitoring, and timely patching become even more important when attackers can automate portions of the discovery and exploitation process.

The question is shifting from “Why would someone target us?” to “What would an automated attacker find if it looked?” That is a much more useful question for management and the board to ask.

2.The 36-hour clock makes preparation essential

When a significant cyber incident occurs, community banks may have very little time to determine their regulatory responsibilities.

Under the Computer-Security Incident Notification Rule, a banking organization must notify its primary federal regulator as soon as possible and no later than 36 hours after determining that a notification incident has occurred.

The key word is determining. Banks do not need to complete an investigation or understand every technical detail before the clock begins. Once the institution determines that an incident meets the notification threshold, the regulatory timeline applies. That makes internal escalation critical.

A bank that spends valuable hours determining who has authority to make decisions, locating regulatory contacts, debating notification thresholds, or waiting for complete forensic information can quickly lose much of its available response window.

Third-party incidents create another challenge. Bank service providers must notify affected banking organization customers as soon as possible when certain computer-security incidents cause, or are reasonably likely to cause, a material service disruption or degradation for four or more hours.

An incident response plan should work at 2:00 a.m. on a Sunday — not just look complete during an annual review.

Banks should clearly establish:

  • Who receives the first internal notification.
  • Who determines whether an event qualifies as a notification incident.
  • Who has authority to contact the regulator.
  • Who contacts customers, vendors, law enforcement, insurers, legal counsel, and other stakeholders when necessary.
  • Who assumes those responsibilities when primary personnel are unavailable.
  • Where current contact information, procedures, and notification templates reside.

Institutions should also test those decisions through tabletop exercises. The middle of a cyber incident is the wrong time to discover that your incident response plan depends on assumptions no one has tested.

3. Third-party risk has become cybersecurity risk

Community banks increasingly rely on third parties to provide technology and expertise they could not efficiently maintain internally.

That model creates tremendous value, but it also creates interconnected risk. Core processors, cloud providers, fintech platforms, managed service providers, payment systems, software vendors, telecommunications providers, and other partners can become part of the institution’s attack surface.

Cybercriminals recognize the opportunity. Compromising one widely used provider can potentially give an attacker access to, or disrupt services for, many institutions simultaneously. The OCC continues to emphasize effective management of these relationships, particularly when third parties support critical or higher-risk activities. As the report states:

“Effective risk management of third-party relationships — especially those that support higher-risk and critical activities — is important for safe and sound operations.”

Community banks should move beyond asking, “Did we complete our vendor due diligence?”

The more important questions are:

  • What happens to our bank if this vendor fails?
  • How quickly would we know?
  • What alternatives do we have?
  • How long could we operate without them?

That requires institutions to understand not only individual vendor risk but also operational dependency and concentration risk.

A strong third-party risk management program should identify which providers support critical activities, evaluate contractual protections, monitor changes in vendor risk, understand subcontractor dependencies when appropriate, establish escalation procedures, and develop realistic contingency plans.

Vendor management should not operate separately from business continuity, cybersecurity, and enterprise risk management. These disciplines increasingly describe different dimensions of the same risk.

4. Post-quantum risk belongs on the strategic technology agenda

Quantum computing may not represent an immediate operational threat for most community banks, but institutions should begin considering its long-term implications.

One concern is the “harvest now, decrypt later” approach. Threat actors can collect encrypted information today and retain it in anticipation that future quantum capabilities could eventually allow them to decrypt it. That creates an unusual cybersecurity problem: information protected adequately today may remain sensitive long enough for the technology protecting it to become obsolete.

For community banks, the appropriate response is not panic or an immediate overhaul of cryptographic systems. It is awareness and preparation.

Banks should begin discussing post-quantum readiness as part of long-term technology planning. An appropriate first step is understanding where cryptography exists throughout the institution.

Which systems protect sensitive information through encryption? Which vendors control those technologies? How long must the bank protect the underlying data? What plans do key technology providers have for adopting new cryptographic standards?

These questions can help institutions work toward crypto-agility, the ability to replace or update cryptographic technologies as standards evolve without requiring disruptive, last-minute system changes.

For most community banks, post-quantum readiness is not a 2026 implementation project. It is a 2026 planning conversation.

5. Digitalization requires risk management to keep pace

Community banks face a difficult balancing act. Customers increasingly expect convenient digital experiences.

Banks need technology to operate efficiently and compete effectively. New fintech relationships can provide capabilities that once required significant internal investment. But every new technology can also introduce new dependencies, data flows, access points, vendors, and operational risks.

The OCC’s focus on community bank digitalization reflects this tension. Its May 2025 Request for Information examined the challenges community banks face when adopting and implementing digital technologies.

The message should not discourage community banks from innovating. Instead, it should encourage institutions to make sure their governance and risk-management capabilities evolve alongside their technology. Digital strategy and risk strategy can no longer operate on separate tracks.

Before implementing significant new technology, management should understand:

  • What data the technology accesses and where that data resides.
  • Which third parties support the service.
  • How the bank will control and monitor access.
  • What happens if the technology becomes unavailable.
  • How the institution will exit or transition from the provider if necessary.
  • Whether existing cybersecurity, business continuity, compliance, and vendor-management programs adequately address the new risks.

Resources such as the Cybersecurity Supervision Work Program (CSW), Third-Party Risk Management: A Guide for Community Banks, and the OCC’s community bank digitalization resources can help institutions evaluate those questions.

The goal should not be to eliminate technology risk. That is impossible. The goal is to understand the risk well enough to make informed decisions about where and how the institution accepts it.

From cybersecurity compliance to operational resilience

The most important takeaway from the OCC’s cybersecurity report may not involve any individual technology or regulatory requirement. It is the broader shift in how banks should think about cybersecurity.

For years, institutions have devoted significant attention to preventing cyber incidents. Prevention remains critical, but prevention alone cannot define a mature cybersecurity program.

Banks must assume that systems can fail, vendors can experience outages, employees can make mistakes, credentials can become compromised, and sophisticated attackers may occasionally penetrate even strong defenses. The question then becomes: What happens next?

  • Can the institution identify the problem quickly?
  • Can management make decisions without unnecessary delay?
  • Can the bank maintain critical operations?
  • Does everyone understand their responsibilities?
  • Can the institution communicate effectively with regulators, customers, vendors, and other stakeholders?
  • Can it restore operations safely?
  • And after the incident, can the bank identify what went wrong and strengthen its controls?

Those questions define operational resilience.

What community bank leaders should do now

Community bank executives and boards do not need to respond to every emerging cyber threat by purchasing another technology solution. In many cases, the more valuable first step is determining whether the institution’s existing cybersecurity program works as intended. That means testing — not simply documenting — key capabilities.

At Young & Associates, we work with community financial institutions every day, and we understand the challenge: banks must respond to increasingly sophisticated risks without unlimited staff, budgets, or time.

The answer is not to build the cybersecurity program of a global bank. It is to build a program that appropriately reflects your institution’s size, complexity, technology environment, risk profile, and critical operations — and then verify that it works. When a cyber incident occurs, the strength of the program will not be measured by the policies sitting on a shelf. It will be measured by how effectively your institution responds.

Explore our suite of IT consulting services:


Source: OCC Cybersecurity and Financial System Resilience Report, 2026

Five human-smuggling indicators financial institutions should understand

The $4.9 billion financial footprint of human smuggling

The Financial Crimes Enforcement Network (FinCEN) has released a critical Financial Trend Analysis (FTA) examining Bank Secrecy Act (BSA) data from January 1, 2023 through December 31, 2025. This review period uncovered a massive $4.9 billion in suspicious activity linked to human smuggling — a sophisticated, multi-billion-dollar enterprise often controlled by Transnational Criminal Organizations (TCOs) like Mexico-based cartels. While total reports saw a 62% decline in 2025 (dropping from 29,266 in 2024 to 11,018 in 2025), the financial volume remains immense, highlighting the persistent role of the formal financial system in border security.

For Community Financial Institutions (CFIs), the most vital metric is the “Impact Gap.” While Money Services Businesses (MSBs) file 97% of all reports, Depository Institutions handle 61% of the total suspicious dollar value ($3 billion). Your institution must prioritize the analysis of these high-value flows: the average transaction amount for depository institutions is approximately $1.5 million, compared to the MSB average of just $7,961. This represents an 188x difference in risk-per-transaction, placing a disproportionate responsibility on CFIs to detect the high-value consolidation and exit points of smuggling networks.

Core metrics (2023–2025 review period)

  • Total BSA Reports Analyzed: 67,540
  • Total Suspicious Dollar Value: $4.9 Billion
  • Depository Institution Share of Value: $3 Billion (61% of total)
  • 2024 Report Volume: 29,266 (Peak year)
  • 2025 Report Volume: 11,018 (62% decline from peak)

Dismantling these networks begins with recognizing the specific behavioral patterns, or indicators, found in recent BSA data.

Indicator 1: Unverifiable relationships and originator-beneficiary mismatch

The lack of a logical or verifiable relationship between parties is the most prevalent red flag in human smuggling. Granular MSB data indicates that 57% of filings cited “no verifiable familial connection” as the primary reason for suspicion. CFIs should use this MSB-specific benchmark to calibrate their own monitoring; when U.S.-based customers send funds to unrelated third parties in high-risk jurisdictions, it frequently signifies a payment to a professional smuggler or the payment of a “piso“— a territorial tax collected by cartels for safe passage through controlled corridors.

The data reveals a specific pattern where U.S.-based foreign nationals use foreign-issued IDs to send money to friends or relatives. In approximately 7% of cases, customers explicitly admitted the funds were intended for smuggling. Compliance officers must scrutinize transactions where there is no clear familial or business nexus, particularly when the subject’s identification suggests a temporary presence in the United States.

Indicator 2: The proliferation of funnel accounts and aggregated P2P transfers

Human smuggling networks have strategically shifted toward using depository accounts as funnels to collect small-dollar payments from diverse sources. This typology bypasses traditional familial checks by using multiple, seemingly unrelated originators to fund a single beneficiary’s account.

A specific case study identifies a high-risk pattern: one account received small-dollar peer-to-peer (P2P) transfers from 30+ different senders between March and July 2023, totaling $68,000. The subject systematically transferred incoming funds to a separate savings account before executing the exit through structured cash withdrawals.

Warning Sign: Your institution must flag accounts with high-volume P2P activity that contradicts the customer’s stated occupation, followed by structured cash withdrawals at branch or ATM locations designed to stay below reporting thresholds.

Indicator 3: Strategic geographic deviations and migration route alignment

Smuggling activity follows international and domestic corridors that extend far beyond the Southwest border. “Geographic Deviation” occurs when account activity occurs far from a customer’s residence or in states like Minnesota and North Dakota. For Northern border CFIs, a specific tactical red flag involves the exchange of Canadian dollars for U.S. dollars, followed by P2P transfers to individuals previously linked to alien smuggling.

Strategic deviations also include international transit routes, such as the UAE-to-Nicaragua flight route, where Nicaragua serves as a disembarkation point for migrants continuing to the U.S. border by land.

High-risk jurisdictions for smuggling activity

Top U.S. States Top Latin American Countries Critical Cities
Texas (TX) Mexico Ciudad Juarez, MX
California (CA) Guatemala Villahermosa, MX
New York (NY) Honduras Tapachula, MX
Florida (FL) Colombia Monterrey, MX
New Jersey (NJ) Guatemala City, GTM
Houston, TX, USA

Indicator 4: Excessive cash activity and structuring in border jurisdictions

Cash is the primary medium for paying piso taxes and local facilitators. TCOs utilize structured withdrawals, keeping amounts just below reporting thresholds, at multiple ATM and branch locations along the U.S.-Mexico border to evade BSA oversight.

CFIs must be alert to high-volume cash activity in accounts belonging to individuals in non-cash-intensive industries. A striking example involves a “student” and a “produce company owner” in Arizona (Nogales and Phoenix) who made $195,000 in unusual cash deposits. These funds sourced debit card transactions for $30,000 in tactical equipment, including thermal binoculars and night vision attachments. The link between “Unusual Cash Deposit ➡ Debit Purchase ➡ Tactical Gear” is a direct indicator of logistical support for smuggling operations.

Indicator 5: Exploitation of travel agencies and “sham” operations

Smuggling networks exploit travel arrangements (flights, buses, hotels) for the “last mile” of the journey. CFIs are uniquely positioned to see the back-end of these operations, which often involve sham travel agencies or legitimate businesses acting as unwitting facilitators.

A recent case involved a Florida-based travel agency and chartered flights from the UAE to Nicaragua. CFIs should monitor for these three high-risk behaviors in travel agency accounts:

  1. Funding Anomalies: Excessive cash deposits at border ATMs (e.g., $150,000+) that serve as the primary source of funding.
  2. Lack of Operating Expenses: The total absence of traditional payroll activity or standard business overhead.
  3. Booking Discrepancies: Large-scale airline refunds or P2P transfers from individuals appearing to pay for “visa services” that fund bulk airline ticket purchases for unrelated groups.

Operationalizing intelligence for community financial institutions

Human smuggling is a multi-billion dollar enterprise that presents concentrated financial risks to the banking sector. While report volumes have declined, the “Impact Gap” confirms that depository institutions remain the primary vehicles for high-value illicit transfers. Your institution’s role in identifying these patterns is critical to dismantling the financial infrastructure of TCOs.

CFI compliance action checklist

  • Apply Key Technical Term: You must use the term “FIN-2023-HUMANSMUGGLING” in the narrative of all relevant BSA filings; this is the single most important technical requirement for law enforcement data aggregation.
  • Audit P2P Aggregation: Review accounts receiving frequent transfers from 30+ unrelated originators, particularly those with a consolidation-to-savings pattern.
  • Monitor Geographic Shifts: Flag activity in migration corridors (Southwest and Northern borders) that deviates from the customer’s residence, including Canadian currency exchanges.
  • Verify Business Profiles: Ensure cash-intensive activity aligns with stated occupations, specifically auditing travel agencies for the absence of payroll.
  • Logistical Screening: Review high-value debit purchases from tactical or thermal gear suppliers when sourced by unusual cash deposits.

BSA data remains the most valuable tool for law enforcement to follow the money and dismantle the networks profiting from human exploitation.

Strengthen your BSA/AML/CFT compliance program

Protect your institution from evolving financial crime risks with a strong, effective compliance program. Young & Associates provides experienced compliance consulting and advisory services to community financial institutions, including BSA/AML/CFT and OFAC reviews, AML model validation, and comprehensive compliance support.

Contact Young & Associates today to strengthen your BSA/AML compliance program and address emerging risks with confidence.


Source: Financial Crimes Enforcement Network (FinCEN), Human Smuggling: 2023–2025 Threat Pattern & Trend Information, Financial Trend Analysis, August 2026.

View the full FinCEN Financial Trend Analysis

Takeaways from the NCUA Deregulation Project

For years, credit union leaders have navigated the dense thicket of the 12 CFR, often grappling with a “compliance fatigue” that stifles innovation. Balancing operational growth against a rigid and complex regulatory framework has felt like a zero-sum game. However, the regulatory weight is beginning to lift.

Spurred by the catalyst of 
Executive Order 14192 (“Unleashing Prosperity Through Deregulation”), the National Credit Union Administration (NCUA) is currently executing a massive, multi-year “Deregulation Project.” Phase One (2025–2027) is focused on modernizing the agency’s framework by identifying rules that are obsolete, duplicative, or overly burdensome. For the strategic credit union leader, this represents a shift toward a more principles-based supervisory environment.

The end of the client-customer automatic bar

One of the most significant shifts involves proposed changes to 12 CFR 701 (Appendix B) regarding associational common bonds. Historically, the NCUA maintained an “automatic bar” against groups primarily based on a client-customer relationship. If joining an association required the purchase of a product or service, such as an insurance policy, the group was automatically disqualified from Field of Membership (FOM) eligibility.

The new proposal moves from an automatic bar to a process of further evaluation. The NCUA Board has determined that a product purchase requirement is no longer a hard no. Instead, the agency will evaluate if the client-customer relationship is merely incidental to the group’s broader activities. This shift to a holistic evaluation opens significant new doors for FOM expansion, allowing credit unions to partner with associations they previously would have ignored.

Flexing senior management compensation

In a competitive labor market, attracting and retaining high-level talent is vital for institutional resiliency. However, the NCUA’s historical blanket prohibition on loan-related compensation has been a major pain point, often suffering from varying interpretations and inconsistent enforcement across the NCUA’s different regions.

Proposed changes to 12 CFR 701.21(c)(8) seek to resolve this confusion. By adding a formal definition of “overall financial performance,” the rule would explicitly permit credit unions to offer incentives and bonuses to employees, including senior management, that incorporate lending metrics. As long as these metrics are part of a broader evaluation of the institution’s financial health, the NCUA now views this as a critical tool for recruitment rather than a hurdle.

Removing prescriptive training deadlines

Volunteer boards are the lifeblood of the credit union movement, but prescriptive mandates can deter community members from serving. Currently, 12 CFR 701.4(b)(3) mandates that every director attain a “working familiarity” with finance and accounting within six months of election or appointment.

The NCUA is now proposing to eliminate this rigid six-month deadline. While the agency continues to hold the core expectation that directors possess financial expertise, it admits the current rigid clock is “unduly burdensome” and can “undermine the ability of a credit union’s members to elect their board.” This is a clear win for community representation: the requirement for competence remains, but the arbitrary training clock is being dismantled.

Lifting the caps on third-party auto servicing

Effective September 8, 2026, a final rule will remove the restrictive caps previously found in 12 CFR 701.21(h). In the past, credit unions were capped at 50% of their net worth for indirect auto loans serviced by third parties, only reaching 100% after 30 months of experience with a specific servicer.

By removing these prescriptive limitations, the burden of risk management shifts from federal mandates to the board’s own risk tolerance. This allows institutions to manage liquidity and portfolio diversity based on their unique needs rather than a one-size-fits-all cap.


“With today’s announcement, we are moving forward on our commitment to removing regulations that are obsolete, burdensome, duplicative, or simply guidance that has no place in regulation. Our goal is to make it easier for credit unions to serve their members, meet compliance requirements, and stay innovative. These final rules and those that come after will give credit unions the flexibility to do just that.” — Chairman Kyle Hauptman

The guidance vs. regulation cleanup

A key pillar of this project is ensuring that non-binding guidelines are not misinterpreted as enforceable law. The NCUA is stripping several “Appendices” out of the Code of Federal Regulations and moving them into “Letters to Credit Unions.” This cleanup clarifies that guidance should be followed as best practice, but it is not independently enforceable.

Key areas moving out of the CFR into guidance include:

  • Safeguarding Member Information: Moving the standards for protecting the security of records (formerly 748 Appendix A).
  • Response Programs: Moving the guidance for responding to unauthorized access to member data (formerly 748 Appendix B).
  • Voting Guidelines: Moving the non-binding suggestions for obtaining fair votes during conversions (found in 12 CFR 708a).

Modernized catastrophic reporting

During a crisis, management should focus on stabilizing operations, not filling out forms. To reflect this, the NCUA is modernizing 12 CFR 748.1(b).

The reporting window for catastrophic acts is being increased from 5 business days to 15 calendar days. Furthermore, in a significant procedural shift, reports are now to be made directly to the NCUA rather than the Regional Director. This centralizes the reporting process and gives credit unions the necessary breathing room to manage emergency conditions before worrying about regulatory paperwork.

A new era of safety and soundness

The Deregulation Project represents a fundamental pivot in the NCUA’s philosophy. By categorizing rules as Obsolete, Duplicative, Overly Burdensome, or Guidance, the agency is attempting to prioritize relief that actually impacts daily operations.

While this signals a move toward principles-based supervision, do not expect exams to be less rigorous. The focus remains squarely on safety and soundness, but with a renewed respect for the business judgment of credit union boards.

Note: Credit unions must continue to follow all existing regulations as they currently appear in the Code of Federal Regulations until the relevant Final Rules are officially effective. For help navigating regulatory compliance, learn more about Y&A’s compliance consulting services.

Y&A Credit Services launches asset-based lending field exam services

Y&A Credit Services, a full-service provider of outsourced underwriting services and credit analysis, announced the launch of its asset-based lending (ABL) field exam services. The service is designed to help financial institutions confidently manage asset-based lending relationships, strengthen risk management practices, and support portfolio growth with experienced, independent field exam expertise. 

“Asset-based lending can create valuable growth opportunities for community financial institutions, but it also requires a disciplined approach to collateral monitoring and risk management,” said Oliver Sutherin, principal of Y&A Credit Services. “Our ABL Field Exam Services are designed to give lenders greater visibility into collateral quality, borrower operations, and portfolio risk so they can make informed decisions with confidence. We strive to help institutions grow strategically while maintaining strong credit administration practices.” 

Each field exam may include: 

  • Verification and analysis of accounts receivable — aging schedules, eligibility testing, dilution trends, and concentration risk across the borrower’s customer base  
  • Inventory testing and valuation review — roll-forward analysis, eligibility criteria, obsolescence exposure, and physical verification against reported values  
  • Borrowing base validation — reconciliation of the calculated base to loan balances, confirming advance rates and eligible collateral are applied correctly  
  • Collateral monitoring assessments — UCC filing and lien priority review, insurance coverage confirmation, and ongoing collateral adequacy relative to outstanding advances  
  • Review of operational controls and reporting practices — evaluation of cash receipts handling, AP aging integrity, and the borrower’s internal reporting discipline 
  • Identification of risk trends, reporting inconsistencies, and exceptions — financial trend analysis, GL tie-out testing, and documented exceptions with recommended remediation  
  • Independent reporting for lending and credit administration teams — a structured exam summary covering scope, findings, and risk conclusions to support credit decisioning 

The new offering aligns with Y&A Credit Services’ broader mission of helping community financial institutions improve operational efficiency, overcome staffing challenges, and enhance credit risk management through outsourced expertise. With the addition of ABL field exam services, Y&A Credit Services now offers a comprehensive suite of commercial credit support services, including underwriting package reviews, annual underwriting reviews, financial statement spreading and analysis, and credit administration support. 

To support its ABL field examination services, Y&A Credit Services employs credit analysts who have earned Commercial Banking & Credit Analyst certifications from the Corporate Finance Institute® (CFI). Their training strengthens their expertise in financial modeling, loan security analysis, and industry analysis for ABL field examinations. 

ABL field exam services are available now. To learn more, visit Y&A Credit Services or call 1-800-525-9775. 

About Y&A Credit Services

Y&A Credit Services provides commercial underwriting and specialty credit services to financial institutions nationwide. Founded in 2022, Y&A Credit Services operates as an independent entity while delivering the same expertise, service, and integrity associated with Young & Associates. Both organizations help financial institutions navigate regulatory challenges and position themselves for growth. 

Learn more at Y&A Credit Services. 

Risk assessment is the BSA key

By William J. Showalter, CRCM; senior consultant, Young & Associates

Your bank has an opportunity to frame your next Bank Secrecy Act/Anti-Money Laundering/Countering the Financing of Terrorism (BSA/AML/CFT) examination – much as you do your Community Reinvestment Act (CRA) exam by preparing a summary of the “performance context” within which you operate.

The agencies state that a well-developed BSA/AML/CFT risk assessment assists the bank in identifying money laundering, terrorist financing, and other illicit financial activity risks and in developing appropriate internal controls – policies, procedures, and processes. Understanding its risk profile enables the bank to better apply appropriate risk management processes to the BSA/AML/CFT compliance program to mitigate and manage risk and comply with BSA regulatory requirements. The BSA/AML/CFT risk assessment process also enables the bank to better identify and mitigate any gaps in controls.

Risk-focused exam process

The interagency examination procedures provide that the extent of BSA/AML/CFT examination activities necessary to assess the bank generally depends on the bank’s risk profile and the quality of risk management processes to identify, measure, monitor, and control risks, as well as to report potential money laundering, terrorist financing, and other illicit financial activity. Given that banks vary in size, complexity, and organizational structure, the agencies acknowledge that each bank has a unique risk profile, and the scope of a BSA/AML/CFT examination varies by bank.

The first step in a BSA/AML/CFT examination is a scoping and planning process. At this preliminary stage of the activity, examiners analyze existing information about the bank – off-site monitoring information, previous examination reports and workpapers, BSA-reporting databases, other communications with the bank, and independent reviews or audits. Examiners also scrutinize request letter items completed by bank management and, perhaps most important in some ways, the bank’s BSA/AML/CFT risk assessment.

BSA examiners are charged to determine the BSA/AML/CFT risk profile of the bank as a part of the scoping and planning process. The preferred method for accomplishing this goal centers on a review of the bank’s risk assessment. While banks are not required to perform such an assessment, it is central to ensuring that a BSA/AML/CFT program is appropriate for the bank, given its product and customer mix, as well as location risk factors. The agencies consider that an effective risk assessment should be a composite of multiple factors, and depending on the circumstances, certain factors may be weighed more heavily than others.

The information contained in the BSA/AML/CFT risk assessment assists examiners in developing an understanding of the bank’s risk profile, risk-focusing the examination scope, and assessing the adequacy of the bank’s overall BSA/AML/CFT compliance program and its compliance with BSA regulatory requirements.

Examiners are directed to focus, when evaluating the bank’s BSA/AML/CFT risk assessment, on whether the bank has effective processes resulting in a well-developed risk assessment. They are not to take any single indicator as determinative of the existence of a lower- or higher-risk profile for the bank. Any assessment of risk factors is bank-specific, and a conclusion regarding the bank’s risk profile is to be based on a consideration of all pertinent information.

Examiners are to assess whether the bank has developed a BSA/AML/CFT risk assessment that identifies its money laundering, terrorist financing, and other illicit financial activity risks. Examiners are also to assess whether the bank has considered all its products, services, customers, and geographic locations in its assessment, and whether the bank analyzed the information relative to those risk categories.

If a bank has not prepared a BSA/AML/CFT risk assessment, or if its assessment is deemed inadequate, the examiner is directed to discuss this fact with management, as well as prepare their own risk assessment. The reason for this emphasis on a bank-prepared risk assessment is that the bank’s BSA/AML/CFT program should be tailored to the risks it faces, and the agencies see an assessment as an important tool to assist the bank in effectively managing BSA risks and critical in developing appropriate internal controls.

Using your risk assessment

An appropriate BSA risk assessment provides the bank with a foundation on which to build a successful compliance program addressing this area. This risk assessment is not a static document. You will have to monitor changes in the bank’s product offerings (e.g., virtual currency-related services), business environment, regulatory changes, bank personnel, and so forth – and make appropriate changes to policy and procedure – to ensure that the foundation remains strong under the bank’s BSA/AML/CFT compliance program.

The agencies expect that the bank will structure its BSA/AML/CFT compliance program to address its risk profile, based on the bank’s assessment of risks, as well as to comply with BSA regulatory requirements. Specifically, the bank should develop appropriate policies, procedures, and processes to monitor and control its money laundering, terrorist financing, and other illicit financial activity risks.

For example, the bank’s monitoring system to identify, research, and report suspicious activity should be risk-based to incorporate any necessary additional screening for higher-risk products, services, customers, and geographic locations as identified by the bank’s BSA/AML/CFT risk assessment.

Also, independent testing (audit) should review the bank’s BSA/AML/CFT risk assessment, including how it is used to develop the BSA/AML compliance program.

Banks that choose to implement a consolidated or partially consolidated BSA/AML/CFT compliance program should assess risk within business lines and across activities and legal entities.

Consolidating money laundering, terrorist financing, and other illicit financial activity risks for larger or more complex banking organizations may assist senior management and the board of directors in identifying, understanding, and appropriately mitigating risks within and across the banking organization.

To understand money laundering, terrorist financing, and other illicit financial activity risk exposures, the banking organization should communicate across all business lines, activities, and legal entities. Identifying a vulnerability in one aspect of the banking organization may indicate vulnerabilities elsewhere.

Conclusion

The importance of a BSA/AML/CFT risk assessment cannot be overstated. A bank-prepared assessment can establish the direction a bank’s BSA/AML/CFT program will take, as well as guiding BSA exams and other reviews/audits. Just as with a CRA performance context, preparing your own BSA/AML/CFT risk assessment can provide the roadmap to guide your compliance – and examiners’ evaluation of your program. And the agencies have given you a roadmap to guide your risk assessment – the BSA/AML/CFT examination procedures. Use it, if you have not already, before the examiners come for their next visit.

Why banks should invest in financial education for their lenders

By Ollie Sutherin, chief financial officer, Young & Associates

Ask a small business owner to name their loan officer, and you’ll usually get one of two answers: a name they remember fondly, or a shrug. The difference often comes down to what happened after the loan closed.

Too often, the relationship ends at funding. The borrower takes the money, and the loan officer goes quiet until another lending opportunity arises or the deal starts to sour. That pattern is so common in our industry that many bankers don’t even recognize it as a problem. But it is a problem, and it’s also a missed opportunity. The loan officer can be far more valuable than a point of contact for money. They can be a source of knowledge and a trusted reference for the small businesses they serve.

The knowledge gap nobody talks about

Community banks live and die by small-business lending, and small businesses are usually run by people who are exceptional at what they do. The contractor knows construction. The restaurateur knows food. The machine shop owner can tell you the tolerances on every part that leaves the floor. What they often do not know, and were never trained to know, are the nuances of bookkeeping, accounting, and tax treatment.

This isn’t a criticism of business owners. It’s simply the reality of how small businesses are built. The owner’s expertise is in their industry, not in debits and credits. Yet their ability to access capital depends almost entirely on how well their financial condition is documented and presented.

That is where the loan officer comes in. The loan officer sits at the bridge between business operations and financial condition. No one else in the borrower’s orbit occupies that position. The CPA sees the books once a year.

The bookkeeper, if there is one, may be a family member doing their best with QuickBooks on weekends. The loan officer, on the other hand, sees the financials in the context of what the business is actually trying to accomplish: growth, equipment, real estate, and working capital. With that vantage point comes not just an opportunity, but an obligation, to assist and educate.

A real-world example

Consider a borrower whose business is genuinely healthy: strong sales, good margins, loyal customers. But when their P&L comes across your desk, you notice they have expensed the principal portion of their loan payments. Their reported income is understated, their balance sheet does not tie, and now your credit department has to spend time untangling something that should have been clean from the start.

A loan officer with solid accounting fundamentals catches that immediately and, more importantly, can explain it to the borrower in plain terms: principal reduces a liability on the balance sheet; only the interest belongs on the income statement. That five-minute conversation does two things. It makes the borrower’s bookkeeping easier going forward, and it makes their true borrowing capacity clearer to the bank. Clearer financials mean faster underwriting, and faster underwriting helps businesses access capital sooner. Everybody wins.

But that conversation only happens if the loan officer knows enough accounting to have it.

The case for investing in training

This is where bank management comes in. Community banks should be making deliberate, ongoing investments in accounting and finance training for their loan officers. Not a one-time orientation, but real education that equips lenders to read, understand, and explain financial statements with confidence. The return on that investment shows up in at least three places.

  • First, better deals reach the credit department. A loan officer who truly understands financial condition knows when a deal is right and when it is not. Requests that should have been declined at the first meeting get declined at the first meeting, instead of consuming hours of analyst time before arriving at the same conclusion. Credit departments at community banks are stretched thin as it is. Lenders who can screen effectively at the point of contact take real strain off the back of the house.
  • Second, complex borrowers get represented accurately. As community banks compete for borrowers closer to the middle market, the financials get more complicated and the questions get harder. Deferred revenue, related-party transactions, owner add-backs, and percentage-of-completion accounting come up constantly with larger borrowers, and credit and loan committees will ask about them. A loan officer who can grasp the financial condition firsthand, ask the right questions of the borrower, and convey the answers clearly to committee is worth their weight in approvals. A loan officer who cannot becomes a relay station for confusion.
  • Third, smaller borrowers get the help they actually need. Many of them are not looking for a sales pitch. They’re looking for assistance, education, and good references. Often a borrower’s financial condition is fundamentally sound; it’s the presentation that’s broken. The lender who can fix that, or point the borrower to someone who can, earns a kind of loyalty that no rate sheet can buy.

Know the tools, share the preferences

Part of being a genuine resource is knowing the resources. Most people in banking can glance at a P&L and recognize which software produced it, and experienced lenders usually have preferences born from years of seeing what comes out clean and what comes out messy. Those preferences should not stay locked in anyone’s head. If a particular accounting platform consistently produces financials that are easy for the borrower to maintain and easy for credit to analyze, say so. Recommend it. Maintain a short list of reputable local bookkeepers and CPAs and hand it out freely.

This costs the bank nothing and makes everyone’s life easier, from the borrower keeping the books to the analyst spreading them.

The payoff

None of this is charity. A borrower who keeps clean books is a borrower whose loan requests move faster, whose covenants are easier to monitor, and whose problems surface earlier, while there is still time to work through them. A loan officer who is a trusted advisor rather than an occasional caller retains relationships through rate cycles and competitive pressure. And a bank known in its community as the place where lenders actually help you understand your business attracts the kind of word-of-mouth referrals that no marketing budget can replicate.

The math is simple. Invest in your loan officers’ financial education, and they will invest it right back into your borrowers. The credit department gets cleaner deals, management gets better profitability, and small businesses get the partner they have been missing. That is community banking at its best.

The “gateway” strategy: Turn a checking account into a long-term customer relationship

By Joseph Ciccolini, content marketing associate, Young & Associates

Marketing often takes a back seat at financial institutions. While many recognize its potential to drive new accounts and attract customers, institutions frequently underemphasize its role as a revenue-generating function. In many cases, the solution already exists but needs to be positioned more effectively: cross-selling, particularly through the “gateway” product that establishes a primary relationship.

For financial institutions, profitability is not just about volume growth but also depth in relationships. Checking accounts provide a natural starting point for building stronger customer engagement, increasing retention, and expanding cross-sell potential.

A 2025 Jack Henry Strategy Benchmark identified top priorities for bank and credit union CEOs, including improving efficiency, driving deposit and loan growth, acquiring new accountholders, and expanding solutions for small and medium-sized businesses. Checking account acquisition directly supports each of these priorities by establishing a primary customer relationship that enables deeper engagement, stronger retention, and increased opportunities for cross-selling.

Consumers typically define their primary financial institution as the one where they hold their primary checking account. That account serves as the gateway to cross-selling opportunities and deeper customer relationships. Primary financial institution relationships are remarkably stable, with customers staying with the bank for an average of eight to 10 years and using five to six products and services per household. Without it, customers are less likely to view the institution as their primary provider. Instead, the relationship resembles the financial equivalent of a secondary streaming service — used occasionally, but not the go-to.

What strategies can institutions use to encourage customers to open a checking account and become primary accountholders? One effective approach is a drip campaign.

Checking Account Stats

What are drip campaigns?

Drip campaigns are a form of email marketing that deliver targeted messages over time to encourage engagement and keep your institution top of mind with customers and prospects. By providing relevant, valuable information, these campaigns guide customers toward action through continuous communication. This approach helps institutions nurture leads and build strong, long-term relationships.

In this context, a drip campaign supports the goal of securing the “gateway” cross-sell in the form of a checking account. Once a customer opens a checking account, the likelihood of becoming a primary accountholder increases significantly, along with opportunities to expand the relationship.

Cross-selling differs from upselling by focusing on complementary products that enhance the customer relationship and increase overall value. The checking account serves as the entry point for this strategy. Once established, institutions can introduce additional products — such as debit cards or certificates of deposit — in a way that aligns with customer needs and behaviors.

Why drip campaigns can outperform cash incentives

Some institutions may already rely on cash incentives to encourage checking account acquisition. However, a 2025 ProSight industry outlook found that only 27 percent of consumers who recently switched institutions cited a cash incentive as the primary reason. Instead, institutions should identify customer needs, understand the challenges they can solve, and promote those solutions effectively.

Drip campaigns play a key role in this strategy by delivering relevant, timely messaging directly to customers. These campaigns help move prospects from consideration to conversion while setting the stage for meaningful interactions.

Gallup’s 2021 retail banking study found that high-quality conversations significantly improve sales conversion rates. When customers initiate the conversation, conversions are 1.6 times more likely compared with low-quality interactions. When employees initiate high-quality conversations, conversions are 4.2 times more likely. Drip campaigns can help prompt these conversations by engaging customers before direct interaction occurs.

Conclusion

Financial institutions should treat checking account acquisition as a critical step in attracting and retaining customers. According to the J.D. Power 2026 U.S. Retail Banking Satisfaction Study, key engagement metrics are beginning to decline as customers increasingly open accounts with multiple institutions. This shift creates a clear opportunity to attract new customers and strengthen relationships through effective cross-selling.

All of this can start with a checking account. Financial institutions should move beyond traditional go-to-market approaches and adopt a marketing-led strategy that prioritizes engagement, not just acquisition. By using tools like drip campaigns to convert and deepen relationships, institutions can turn checking accounts into a foundation for long-term growth and differentiation.

Why your “healthy” portfolio might be a time bomb

By Jerry Sutherin, CEO at Young & Associates

A community development financial institution (CDFI), a mission-driven lender that uses public and private capital to serve underserved communities, can appear healthy on the surface, with steady interest income and consistent growth. Because CDFIs often lend in distressed markets and to borrowers outside the traditional financial system, their portfolios carry unique and sometimes less visible risks. Interest income can mask a weakening foundation of documentation and systemic exposure. Financial history is filled with institutions that appeared stable until hidden vulnerabilities triggered catastrophic deterioration. The difference between sustainable CDFIs and those that fail is not luck. It is the rigor of their internal credit administration.

While front-end underwriting controls risk at origination, institutions must shift to active risk management once a loan is booked. This is where the loan review, an essential but frequently misunderstood strategic tool, serves as your early warning system. It identifies internal weaknesses and “invisible leaks” before they become irreversible financial losses.

Strategic oversight vs. detailed loan file review

In CDFI management, it is critical to distinguish between a high-level portfolio overview and a detailed loan-level audit. While a portfolio review assesses the “big picture,” focusing on geographic, borrower, or other risk concentrations, it cannot replace the granular insights of a loan review.

This assessment is anchored to a specific date, which establishes a clear snapshot of loan quality and ensures findings remain objective. A high-level trend analysis will miss the granular policy deviations that only an individual file examination can reveal.

An independent loan review performs the following functions:

  • Evaluates individual loans and repayment risk.
  • Verifies adherence to internal lending policies and procedures.
  • Identifies gaps in loan file documentation.
  • Communicates high-priority credit risk findings.
  • Recommends actionable improvements to policies and practices.
  • Validates the accuracy of internally assigned risk ratings.

The power of the independent eye

For a loan review to provide strategic value, it must be conducted with objectivity. This requires a strict “independent eye.” Individuals involved in the lending process, including members of the credit committee, should not participate in the review.

Familiarity creates blind spots. Lending staff may overlook a missing document or a policy breach because they “know” the borrower.

Independence also serves as a key control against internal fraud and theft — risks that directly affect a CDFI’s bottom line. Whether utilizing external consultants or internal staff outside the lending function, the goal is to provide the board of directors with objective, unfiltered data on loan quality.

Why paperwork errors are principal risks

CDFI managers often dismiss administrative lapses as routine paperwork. These are technical and legal failures that expose the institution to civil money penalties or the total loss of principal.

A high-priority finding often involves insurance documentation. There is a critical legal distinction between being listed as an “additional insured” versus a “mortgagee.” Missing this distinction means the CDFI is unprotected if the collateral is destroyed.

Other common deficiencies include:

  • Incorrect naming of the CDFI’s role on insurance certificates.
  • Missing documentation of physical inspections of the business or collateral.
  • Failure to implement post-closing follow-up to ensure receipt of all required loan documentation.
  • Having a robust internal exception tracking system where results can be easily conveyed to the board of directors.

These are not just errors— they signal systemic weakness. Additionally, all financial institutions must track the migration of risk ratings as they change. Risk rating changes of 10 percent or more during a loan review indicates systemic issues and warrants a closer review of the Bank’s Allowance for Credit Losses (ACL), their primary safety net.

Judgment and analytical failures: realism vs. optimism

Loan review also addresses lender optimism that can cloud internal analysis. Two common areas of analytical weakness include income projections and collateral valuation.

Income projections

Lenders often rely on projected net income rather than historical performance. While quality projections are useful during the analysis process, they need to be realistic, achievable and used alongside historical results to provide a comprehensive analysis of a company’s ability to satisfy its debt obligations. A rigorous loan review identifies this issue and prioritizes analysis based on future expectations and demonstrated results, a more reliable indicator of repayment capacity.

Collateral valuation

Many CDFIs rely on market value; however, a strategic loan review emphasizes liquidation value. Market value reflects ideal conditions, while liquidation value provides a more realistic assessment of recoverable collateral in the event of default. It clarifies what the institution can expect to recover if it must seize and sell an asset. Building a culture of sustainable credit risk management.

The final output of this process is a hierarchy of findings that allows a Board to prioritize its response:

  • High Priority: Policy violations that risk loss of principal or legal penalties.
  • Moderate Priority: Issues that deviate from the institution’s own internal practices.
  • Low Priority: Suggestions for adopting industry-wide best practices.

The Board should be actively involved in determining the scope and frequency of internal or external loan reviews. Regular reviews — annually for most, or semi-annually for larger, more complex financial institutions — are essential to catch systemic weaknesses before they become terminal. The scope should focus on the inherent risk of the portfolio as determined by the Board and the Bank’s adopted policy.

Addressing these issues early transforms risk management from a reactive chore into a proactive strategy for long-term impact. Institutions should evaluate whether their risk management framework serves as a true preventive control or simply responds to failures after losses occur.

Learn more about our loan review services here. 

Is your marketing engine a well-oiled machine? Or just a collection of shiny parts?

By Nicole Conrad, director of marketing, Young & Associates

In the current landscape of financial services, community bank marketing leaders are often distracted by the latest “shiny new toys.” From generative AI and complex CRM suites to automated social media engines, the promise of a technological silver bullet is everywhere. Yet, despite these investments, many community institutions still struggle to compete with national banks.

The success of AI tools and digital marketing depends on the strength of the strategy behind them. To compete effectively, you must focus on the fundamentals before layering on advanced technology. Technology can only accelerate the direction you are already headed; if your foundation is weak, technology can exacerbate existing issues and contribute to more severe organizational failures.

A high-performing marketing engine is not a collection of disconnected parts. It is a unified system built to achieve the only goal that matters: long-term, profitable customer loyalty.

Revisiting your institution’s marketing basics

Digital marketing and AI implementation depend on the strength of your underlying strategy. Investing in marketing software without a clear plan can waste capital and human resources. To diagnose the health of your marketing engine, you should audit your marketing foundation against three questions:

  • Who is our target? Have we identified the specific segments that view us as a primary partner, or are we casting a net so wide it catches nothing?
  • What is our value? Is our value proposition strong enough to overcome the inertia of switching, or are our products too complex for our own staff to explain?
  • Where is the trust? Are we deploying our message through channels the consumer actually engages with and trusts?

Without these answers, technology cannot bridge the gap between a bank and its customers. Marketing only generates ROI when the right message reaches the right person at the right time.

The right person: Humanizing your brand through buyer personas

Understanding your target audience requires stepping outside your role as a banker and seeing the experience from their perspective. Today’s consumer is not just looking for a transaction; they want to feel an authentic human connection and see their own identity reflected in the brands they choose.

This is where buyer personas come in. A buyer persona is a fictionalized version of your ideal account holders based on demographic data and qualitative research into their goals and concerns.

Buyer personas may include:

  • Demographics, such as age and gender, location, economic status, and marital or family status.
  • Qualitative drivers, such as goals, pain points, concerns, and desired outcomes.
  • Behavioral habits and preferences, such as media consumption, banking habits, and technical expectations.

Your buyer personas should evolve with consumer preferences and the digital landscape. When you know exactly who the customer is, you can stop the “shotgun approach” and meet them at the right time with a message that resonates. This allows you to tap into a “consciousness of kind” — that intrinsic understanding that your bank and its customers belong to the same community and share the same values.

For the community bank, humanizing the brand is a competitive advantage. National banks have three times as many customers per branch compared to the average community institution. This density forces them into cold, numbers-driven business models. You have the capacity to treat customers as people, and this is nonnegotiable in today’s market.

According to Salesforce’s State of the Connected Customer report, 84% of customers say being treated like a person, not a number, is very important to winning their business.

By deeply understanding who your customer is, you move from being a commodity to being a neighbor. Knowing the persona helps you predict the right time to connect, meeting the customer where they are in their decision-making journey. If you don’t know who you are talking to, don’t be surprised when no one listens.

The right time: Understanding the buyer’s journey

We are seeing a fundamental shift from outbound, interruptive marketing to inbound, helpful marketing. Inbound marketing focuses on being where the consumer is with the answers they need. The buyer’s journey supports this approach by nurturing the relationship, so the message evolves as the customer moves through each touchpoint.

The buyer’s journey is the process a person goes through before they open an account or sign a loan. It typically consists of three core stages:

  • Awareness: The individual recognizes a financial problem or need.
  • Consideration: The individual researches various solutions and providers.
  • Decision: The individual selects a specific institution.

Mapping this journey is vital because banking is not an impulse purchase. Market data confirms that most banking shoppers begin their research two to three months before they switch institutions. This “invisible” phase is where banks may lose prospects by trying to close the sale too early.

To be successful, you must nurture them through various touchpoints, from helpful blog posts and social media tips to personalized emails and direct mail. The right message will change depending on where they are in this journey; you wouldn’t offer current car loan rates to someone who is just starting to save for their first vehicle.

The right message: Building your messaging matrix

Once you have your personas and their journeys mapped, you can build a strong messaging matrix. This combines your unique value propositions (UVPs) with the specific needs of each persona at each stage of the journey. The primary goal of a messaging matrix is to solve the difficult challenge of getting the right message to the right person at the right time.

Start with a basic messaging guide. Create a grid that crosses your personas with the stages of their journey. For each intersection, determine which UVP best solves that persona’s problem at that specific time.

Example: An “Awareness” message for a first-time homebuyer might focus on “Can I afford a house?” whereas a “Decision” message would focus on your specific loan application tips and competitive rates.

By mapping messages to specific audience needs, the bank provides content that is meaningful to the consumer’s current situation and avoids burdening people with irrelevant content.

Documented messaging provides staff and brand advocates with a custom-made set of points that capture the heart of the brand. This prevents the brand voice from becoming diluted or fragmented across different channels. This guide offers a straightforward approach to educating employees and reinforcing consistent marketing messaging throughout your organization, transforming your workforce into brand advocates.

A high-performing marketing engine is not a marketing task; it is a core organizational strategy. It requires executive buy-in, strong execution in the branches, and a marketing team that knows how to drive traffic to both digital and physical locations.

AI and digital tools have changed the speed of the race, but not the rules. These tools amplify what already exists: a strong strategy becomes stronger, and a fragmented strategy becomes weaker. If your foundation is built on the right message, the right person, and the right time, technology can help you take you to the finish line. If not, no amount of shiny parts will save you.

We would welcome a conversation to discuss your institution’s business and marketing strategy and be happy to help build out your strategy. Learn more about our strategic planning services here. 

Analyzing the OCC’s Spring 2026 Semiannual Risk Perspective for community bankers

The OCC’s Spring 2026 Semiannual Risk Perspective gives community financial institutions a strategic view of the most significant risks affecting the banking industry. Using the National Risk Committee’s latest findings, the report helps bank leaders evaluate institutional strength, identify emerging threats, and align risk management strategies with evolving federal regulatory expectations. This article examines the key insights and banking industry trends highlighted in the Spring 2026 report.

As the banking industry moves through the spring of 2026, U.S. financial institutions face a market defined by speed, volatility, and structural change. Strong earnings and high liquidity continue to support the system, but rising geopolitical tensions, AI-driven fraud, and mounting commercial real estate refinancing pressure are forcing banks to rethink traditional risk management strategies.

The banking system enters 2026 from a position of strength

The federal banking system enters 2026 from a position of strength, characterized by improved earnings, robust loan growth, and solid balance sheets. In 2025, bank performance was supported by a resilient U.S. economy and a decline in funding costs that drove revenue growth. Capital ratios and liquidity levels remain high by historical standards, with a system-wide liquid assets-to-total assets ratio of 31 percent — more than double the 15 percent recorded in 2008.

The 2026 macroeconomic outlook and structural headwinds

Despite these positive trends, the outlook for 2026 is tempered by significant uncertainties:
  • Geopolitical Risk: The conflict in the Middle East is a primary concern, with the potential to disrupt global energy flows (particularly through the Strait of Hormuz) and fuel inflation.
  • Credit Headwinds: While aggregate credit risk is manageable, specific segments — including commercial real estate (CRE), private credit markets, and consumer credit for lower-score borrowers — require ongoing monitoring.
  • Operational Threats: Cybersecurity remains an elevated risk, driven by sophisticated foreign state-sponsored actors and the emergence of advanced AI tools that enhance the speed and scale of attacks.
  • Regulatory Evolution: The OCC continues to implement the GENIUS Act regarding stablecoins and is working to tailor compliance requirements to reduce the burden on community banks while addressing increased sanctions and money laundering risks.

U.S. economy continues growing despite inflation risks

The U.S. economy grew by 2.1 percent in 2025, outperforming other advanced economies. This growth was driven by strong consumer spending and business investment, particularly in artificial intelligence.

Labor and inflation

  • Labor Market: Unemployment remained low at 4.3 percent as of March 2026. While payroll gains were strong in the first half of 2025, they reversed in the second half, leading to a characterized state of “employer caution” in early 2026. Wage growth eased to 3.4 percent by the end of 2025.
  • Inflation: Core inflation started 2026 at 3.1 percent, remaining above the Federal Reserve’s 2 percent target. Stickiness in service-sector inflation and high shelter costs persist.
  • Monetary Policy: After holding rates steady in early 2025, the Federal Reserve implemented three rate cuts in the second half of that year.

2026–2027 economic projections

According to the April 2026 Blue Chip consensus forecast, real GDP is expected to grow by 2.2 percent in 2026 and 2.0 percent in 2027. However, headline inflation is projected to peak at an annualized 5.1 percent in the second quarter of 2026 due to the Middle East conflict before falling in the second half of the year.

Significant economic risks

  • Strait of Hormuz: Sustained closure could drive higher energy costs, reducing consumer purchasing power and increasing business production expenses.
  • Interest Rate Expectations: Market participants have adjusted expectations downward; the April forecast anticipates only one rate cut in 2026, while financial market pricing suggests even that may not occur.

Bank performance analysis

Profitability for the federal banking system increased in 2025. Return on equity (ROE) exceeded 10 percent for both the total system (12.2 percent) and community banks (11 percent).

Financial trends (2024–2025)

Metric
System Total (2025)
System % Change
Community Banks (2025)
Community % Change
Net Interest Income
$493.9 Billion
+3.7%
$34.4 Billion
+12.2%
Noninterest Income
$249.6 Billion
+11.0%
$11.0 Billion
+7.1%
Net Income
$199.2 Billion
+8.8%
$12.5 Billion
+21.6%
Total Loan Balances
+6.0%
+5.0%
Net interest margins (NIM) improved across the board, particularly for community banks, which benefited from lower funding costs and more favorable asset yields compared to larger institutions. Larger banks saw a quicker downward repricing of their short-term commercial and industrial (C&I) loans.

Key financial risks

Credit risk

Credit quality remains satisfactory, with past-due and nonaccrual loan ratios below long-term averages. However, several sectors show emerging vulnerabilities:
  • CRE: Office properties still face high vacancy rates, though net absorption turned positive in late 2025. Refinancing risk is a major concern as loans originated in low-interest environments mature. Conversely, retail remains a “bright spot” with low vacancy rates.
  • Private Credit: While generally performing well, there are signs of weakening in some sectors. The use of “paid-in-kind” (PIK) mechanisms and debt restructurings may be masking underlying credit deterioration.
  • Consumer Credit: Delinquencies have increased among borrowers with lower credit scores, though supervised banks have manageable exposure to these higher-risk segments.

Market risk

Unrealized losses on securities portfolios fell in 2025 to their lowest levels since 2021. Uninsured deposits saw a modest increase as a share of total deposits, primarily at banks with over $500 billion in assets, though they remain in line with long-term averages.

Compliance and operational risks

Cybersecurity and artificial intelligence

The threat landscape is increasingly dominated by foreign state-sponsored actors and sophisticated criminal groups.
  • AI as a Threat: AI lowers the barrier to entry for cybercriminals, enabling automated reconnaissance, targeted social engineering, and adaptive malware that evades traditional defenses.
  • AI as a Defense: Banks are deploying AI tools to assist with threat monitoring and risk management. The OCC emphasizes that a sound understanding of these tools’ risks and benefits is essential for management.

Fraud risk

Fraud remains a primary driver of operational losses. Impersonation scams facilitated by social media and text messages are rising in sophistication. FinCEN has issued specific alerts regarding health care fraud schemes and money laundering networks.

Compliance and BSA/AML

Geopolitical tensions have strained compliance systems, increasing the risk of Bank Secrecy Act/anti-money laundering (BSA/AML) violations.
  • Supervisory Tailoring: The OCC is working to reduce the regulatory burden on community banks, recently clarifying examination procedures for low-risk institutions and discontinuing the Money Laundering Risk system data collection.
  • Regulatory Changes: A proposed rule is currently under consideration to amend requirements for risk-based AML and countering the financing of terrorism (CFT) programs.

Innovation and digital assets

Artificial intelligence implementation

Banks are adopting generative and agentic AI, primarily for productivity and customer experience tools.
  • Governance: The OCC advocates for “human-in-the-loop” accountability.
  • Challenges: Industry-wide challenges include a lack of explainability, data privacy, “data poisoning,” and validation difficulties.
  • Guidance: OCC Bulletin 2026-13 recently updated model risk management guidance, though generative AI models currently fall outside its specific scope. An interagency Request for Information (RFI) on bank use of AI is expected in the near future.

Digital assets and stablecoins

The regulatory landscape for digital assets is formalizing following the passage of the Guiding and Establishing National Innovation for U.S. Stablecoins (GENIUS) Act on July 18, 2025.
  • Stablecoins: The OCC issued a notice of proposed rulemaking in February 2026 to establish a federal regulatory framework for payment stablecoins.
  • Tokenization: Interagency FAQs released in March 2026 clarified that the technologies used to transact in a security do not generally change its regulatory capital treatment.

OCC’s Spring 2026 Semiannual Risk Perspective and outlook for the banking industry

The banking industry enters 2026 with strong capital levels, high liquidity, and improving profitability. However, regulators increasingly warn that the speed of emerging risks may challenge traditional oversight models. Commercial real estate refinancing pressure, private credit deterioration, AI-driven cyber threats, stablecoin regulation, and geopolitical instability are reshaping the banking landscape.

As financial institutions move deeper into 2026, banks that strengthen risk management, improve operational resilience, and adapt quickly to changing market conditions will likely remain best positioned for long-term stability and growth.

Can a 31% liquidity buffer outrun the 2026 refinancing cliff?

As we move through the spring of 2026, the American banking system resembles a fortress built on a fault line. On the ledger, the industry looks stronger than ever. Bank earnings surged throughout 2025 and pushed the system’s return on equity (ROE) to an impressive 12.2 percent. Community banks, which often absorb economic pressure first, still maintained a solid 11 percent ROE.

However, the most dangerous risks rarely wait for quarterly reporting cycles. Beneath the industry’s profitability, the National Risk Committee’s latest analysis highlights a financial landscape defined by “velocity”: AI-powered fraud evolves rapidly, geopolitical disruptions emerge suddenly, and the commercial real estate “maturity wall” advances steadily. Although the U.S. economy expanded by 2.1 percent in 2025, structural changes now outpace traditional risk management strategies. The latest regulatory data reveals six critical signals shaping the banking industry in 2026.

The 31 percent safety net

The NRC report’s most reassuring finding centers on the industry’s liquidity position. By the end of 2025, liquid assets accounted for 31 percent of total assets across the federal banking system. During the 2008 financial crisis, that same ratio stood at only 15 percent. This doubled buffer is the primary reason the system remains upright despite “higher-for-longer” interest rates and global instability.

Still, analysts cannot rely solely on aggregate figures. The NRC emphasized this point in its executive summary:

“Balance sheets remain strong, with capital ratios and liquidity high by historical standards. Earnings releases for the first quarter of 2026 indicate that these trends have generally persisted.”

The nuance? That 12.2 percent ROE is heavily skewed, driven primarily by the nation’s largest institutions. While the system-wide 31 percent liquidity buffer is a historical anomaly of strength, the underlying reality is a widening gap between the “too big to fail” giants and community banks, which hold a significantly higher concentration of long-term property loans now facing a brutal refinancing environment.

The private credit “performance mirage”

Although aggregate credit risk appears manageable, the NRC raised concerns about the expanding private credit market. As banks increase their exposure to private credit funds, they may unintentionally create what many analysts describe as a “performance mirage.”

The greatest risks sit within loan vintages originated during the low-interest-rate period of 2021 and 2022. Many of these loans still appear healthy on paper, but aggressive restructurings and paid-in-kind (PIK) arrangements often mask underlying weakness. Instead of requiring borrowers to make cash interest payments, lenders allow them to accumulate additional debt.

As a result, funds postpone defaults rather than resolve them. Investors should recognize that today’s stable yields may conceal deteriorating credit quality that could surface abruptly when these loans reach future refinancing deadlines.

The rise of agentic AI

The banking industry has moved past the “Generative AI” hype cycle. The industry now focuses on “Agentic AI,” which refers to autonomous systems capable of participating in material financial decisions such as credit underwriting and automated trading.

While banks maintain a “human-in-the-loop” model for accountability, this technology has intensified the cybersecurity arms race. AI has fundamentally lowered the barrier to entry for cybercriminals, enabling automated reconnaissance and “adaptive malware” that can evolve in real-time to evade traditional defenses.

This shift fundamentally changes the risk landscape. Traditional governance models, which often depend on quarterly reviews and slower oversight processes, struggle to keep pace with rapidly evolving AI-driven threats.

The CRE “maturity wall” and the sun belt chill

Commercial real estate (CRE) remains the banking system’s most visible weakness. The refinancing cliff has moved from theory to reality. Loans issued during the zero-interest-rate era now require refinancing at significantly higher rates, dramatically changing property economics.

  • The Cooling Sun Belt: After a massive supply wave between 2022 and 2024, rental rates in the Sun Belt and Mountain West are facing downward pressure.
  • The Resilient North: Surprisingly, the Northeast and Midwest are outperforming the cooling southern markets in both single-family and multifamily sectors.
  • The Retail Bright Spot: Retail properties have unexpectedly emerged as one of the strongest sectors. Low vacancy rates and limited new development have made retail investments more stable than office properties, which continue to face weak demand and elevated vacancies.

The GENIUS Act’s normalization of digital assets

The regulatory uncertainty surrounding digital assets effectively ended on July 18, 2025, when lawmakers signed the GENIUS (Guiding and Establishing National Innovation for U.S. Stablecoins) Act into law. This legislation formally normalized the digital dollar within the regulated financial system.

The OCC has already begun implementing a federal framework that restricts stablecoin issuance to authorized and regulated entities. Institutional investors received additional clarity on March 5, 2026, when interagency guidance confirmed that tokenization does not alter the regulatory capital treatment of securities.

This signal removes the “novelty” penalty for digital assets, paving the way for stablecoins and tokenized bonds to become standard features of the authorized financial system.

The Strait of Hormuz and the speed of global risk

Despite the domestic strength of the 31 percent liquidity buffer, the banking industry’s 2026 outlook is ultimately hostage to a narrow waterway 7,000 miles away. Analysts at Blue Chip have adopted a more defensive outlook, warning that a prolonged closure of the Strait of Hormuz could materially disrupt the global economy.

A disruption to oil and fertilizer shipments would likely trigger another major inflation spike. Blue Chip’s April forecast projects inflation could reach 5.1 percent during the second quarter under such a scenario. Rising inflation would likely eliminate any possibility of interest rate cuts in 2026 while simultaneously increasing pressure on both global trade and domestic refinancing markets.

As we look toward the second half of the year, the banking industry faces a defining challenge. The central issue no longer concerns the size of financial buffers alone, but the speed of institutional response. Banks must determine whether human-led governance systems can react quickly enough to manage the accelerating risks created by Agentic AI, geopolitical instability, and rapidly shifting financial markets.

The industry’s resilience remains real, but in 2026, the margin for error continues to shrink at an unprecedented pace.

The key to compliance success – accountability

By William J. Showalter, CRCM; senior consultant, Young & Associates

The financial industry recognizes compliance as a high-risk function. Failure to manage it effectively can result in high costs to an institution, as witnessed by many supervisory enforcement actions and fair lending settlements over the years.

Compliance management is an important element of an institution’s overall risk management efforts. It makes sense for line managers—those whose operations generate either compliance or noncompliance—to “own” compliance, just as they do all other elements of the institution’s overall risk. To make compliance management work effectively and efficiently, senior management must give line personnel the tools to succeed at compliance and hold them responsible for their results.

When senior management establishes accountability and all staff believe in it, and when the institution measures compliance performance in a meaningful way, the institution can achieve positive compliance results.

As with other aspects of compliance management, identifying and categorizing levels and types of compliance risks are critical to both efficient operations and effective outcomes in any system of enforcing accountability.

Noncompliance as risk

In recent years, the federal agencies have made a fundamental shift in the way they examine financial institutions for compliance within their overall examination process over a decade ago – to handling it with a risk-based methodology. Examiners design programs to focus attention on areas within financial institutions that may pose the most significant risks, including compliance.

The agencies work to promote a sound risk-management process at each regulated financial institution, one centered on the evaluation and management of risks. The agencies try to help financial institutions implement compliance programs that focus on anticipating, evaluating, managing, and communicating about key compliance risks.

“Compliance risk” means the risk to earnings or capital that arises when institutions violate or fail to conform with laws, rules, regulations, prescribed practices, or ethical standards.

The agencies’ examination procedures provide that compliance risk can damage an institution through any or all of the following consequences:

  • Regulatory or judicial fines and penalties
  • Payments of damages to aggrieved parties
  • Voiding of contracts
  • Diminished reputation
  • Reduced franchise value (due to monetary and reputation losses or penalties)
  • Diminished business opportunities
  • Lessened expansion potential (e.g., when fair lending or Community Reinvestment Act problems delay or disallow corporate changes, mergers, or acquisitions)

The supervisory agencies recognize that an important element in avoiding these risks and their resultant costs is an effective accountability system, where institution staff feel they own their pieces of the overall program.

Establishing accountability

A solid design must form the foundation of an effective accountability system. The system needs a few key elements to succeed: management commitment, appropriate training and communication for all staff, regular and independent performance testing, and consistent enforcement of responsibility.

  • Management commitment. Solid support from both the board of directors and senior management is vital to the success of any compliance (or other) management function. It should also be seen as in their best interests since the risks and penalties for noncompliance are tremendous, and the board and management are the ones ultimately responsible for the compliance (and other) performance of the institution. Management and the board need to understand the true importance of compliance – it is not a job to be relegated to one person, or a small group, and ignored by everyone else. “Everyone else” includes the ones who drive the institution’s compliance performance, and they must be given the tools to succeed at it and be held accountable for their results.
  • Training and communication. Training is the foundation for effective compliance, and effective accountability, since employees cannot be expected to comply with the plethora of laws and regulations that impact banking today if they have not been given appropriate instruction as to what is required of them. In structuring a compliance training program, the first step is a needs assessment – types of products and services offered, current level of staff knowledge, problems identified in audits and examinations, and so forth. The goal of the compliance training is to provide line officers and other staff with the information they need to produce positive compliance results in their particular area or job. It is not to be an exercise in information overload. Therefore, the person in charge of training (whether classroom, online, etc.) needs to scope out the proper laws and regulations to be covered, how to tie these rules in to the institution’s functions, what media and tools to use, and so forth. Communication of compliance information on a regular basis is an important complement to the “regular” training. It helps keep staff aware of changes in the compliance rules and expectations, as well as keeping compliance issues on their “radar screens.”
  • Testing. A good compliance internal review program – both periodic audits and ongoing monitoring – can serve several goals. These include giving an early warning of problems, providing a defense against litigation, and meeting regulatory expectations, in addition to furnishing measurements of department/area or individual performance.
  • Enforcement. Without consistent enforcement of accountability for compliance performance, all the other elements are pretty much for naught. If individual line managers and other personnel are “let off the hook” for poor compliance performance because, for example, of high loan production volume, then the system likely will fail.

Making it work

Human nature being what it is, there need to be incentives for good compliance performance and, perhaps more importantly, disincentives for poor results. If management does not hold all staff to the same standards, then any calls for strong results and performance will ring hollow. Employees who the institution continues to hold to proper standards will begin to resist, since management expects them to meet measures that others do not. Such a “program” is unfair and cannot succeed.

Institutions should factor compliance performance elements into job descriptions, performance evaluations, and incentive pay. It needs to be clear that line managers are ultimately responsible and accountable for compliance performance in their areas, and that compliance is an explicit part of everyone’s job.

If there are line managers who cannot or will not take responsibility for their own or their area’s compliance performance and, therefore, expose the institution to risk, the institution should send them packing and replace them with managers who are positive about compliance issues and willing to take on this important obligation.

Otherwise, the institution has to pay for expensive, redundant processes to check the work of that person(s) or area and fix their errors. Running such a “fix-it” shop is not the efficient route to take in managing compliance. When management establishes and enforces accountability, it can achieve the lowest-cost compliance — compliance embedded in normal operations rather than added on after the fact — with everyone working to get it right the first time.

Management can use an accountability matrix as a tool to run an accountability system. Institutions can customize the matrix to fit their specific situation, structure, and needs. The matrix helps management ensure that someone or some area takes responsibility for each compliance rule or issue that affects its lines of business. It should spell out the rules or issues, who is responsible for them, which areas they impact, and so forth.

Conclusion

Accountability for compliance performance – good or bad – is essential for an institution’s success in effectively managing its compliance function. Properly structured and enforced, a strong accountability program helps ensure cost-effective positive compliance results.

Connect with a Consultant

Contact us to learn more about our consulting services and how we can add value to your financial institution

Ask a Question