Skip to main content

Author: admin

CRA strategic planning: How banks can reduce examination risk

By William J. Showalter, CRCM; senior consultant, Young & Associates

There was a lot of talk a few years ago about the regulatory agencies updating their rules for implementing the Community Reinvestment Act (CRA). The Office of the Comptroller of the Currency (OCC) even implemented revisions to its CRA rule. But the other agencies ended up not following suit and the OCC rescinded its amendments, going back to the previous regulation.

The last time the agencies did a major overhaul of their CRA rules was during the Bill Clinton Administration in the 1990s. So, it probably is due – banking and the communities it serves have changed significantly in the past 20 or so years – but that effort will take some time. For now, we have to make sure we are serving our communities to the best of our abilities and complying with the current CRA rules.

The 1990s era CRA rules are more performance focused and objective than the previous rules, but they are not objective. The rules and examination procedures do spell out what examiners will review. However, with many subjective terms and flexible standards, how examiners will review CRA performance is not stipulated. Examiner judgement is the guiding principle here. This leaves banks not knowing whether their performance is satisfactory until after an examination is completed.

In the latest developments, the OCC and Federal Deposit Insurance Corporation (FDIC) have just (mid-August 2026) issued proposed changes to their CRA rules to streamline them somewhat, but keeping largely to the 1995 model. The Federal Reserve can probably be expected to follow suit.

Banks cannot eliminate this risk of examiner criticism entirely, but steps can be taken to reduce it significantly. The key is good strategic planning.

Why manage CRA?

Many banks feel they are doing a pretty good job of meeting the credit (and other banking) needs of their local communities. So, why should they invest a lot of time and effort into managing their CRA climate and performance?

The answer is that good CRA performance is just good business. As with any other business function, smooth operation depends on good management. Directing the CRA function also allows banks to get through the CRA examination process more easily, and can prevent unexpected and unnecessary delays in future merger, branching, and other corporate applications.

Setting the stage

A bank can set, to some extent, the framework within which its performance will be judged. A formal way to do this is to choose the formal CRA strategic plan option, where the bank writes its own lending, investment, and service goals with input from its community. The bank’s supervisory agency reviews and approves the plan, and then examines the bank’s performance against the goals in the plan.

There is a less formal way to accomplish the same ends. A bank can formulate an internal CRA strategic plan, setting out objective standards against which its performance can be gauged. An important element of such a plan is to establish realistic goals based on local community factors (economic conditions, credit needs and demand, etc.) and the bank’s situation (size, financial condition, stability, etc.). One crucial component of such a scheme is internal monitoring and reporting of results on an ongoing basis.

An informal plan should be shared with examiners, assuming plan goals are being met, to give them the objective standards the bank wants used to measure its CRA performance. This allows the bank to control its destiny to a great extent by building the gauge for rating its performance, one that takes into account its own and its community’s unique situation.

Other advantages of an informal plan over a formal one are that it does not have to be negotiated with members of the public or formally approved by regulators, and it does not have to be made public.

Drafting a plan

A CRA plan should be drawn up to mesh with the bank’s existing planning structure and culture. It should build on the strengths the bank has identified in its performance and aim to shore up any weak areas.

The team assembled to draft the plan should be diverse and represent all areas of the bank that affect and touch on CRA performance. This brings the strengths and viewpoints of a variety of bank players into the process, and helps get wide “buy in” to the plan, an important element for its success.

The plan also must be tailored to fit the CRA environment within which the bank operates – the size and CRA type of the bank (small, intermediate small, large retail, limited purpose, wholesale), past CRA performance of the bank, characteristics of the bank (culture, business lines, etc.), and local community conditions (employment and income levels, economic needs, etc.). This process will guide the bank in deciding how to address its CRA responsibilities.

Elements of the CRA planning and management process include:

  • Setting clear, attainable goals for a “satisfactory” CRA rating, and more ambitious, stretch goals for an “outstanding”
  • Managing the information about the bank’s CRA performance (data revolving around the three key tests in the CRA examination scheme for large retail banks and thrifts – lending, investments, and services), including analysis of that data to get a picture of the bank’s ongoing performance
  • Establishing and nurturing relationships with active community partners, with a positive approach to work together for the betterment of the local community

Conclusion

Banks can control their CRA destiny. However, to do so, the entire process must be managed proactively – plans drawn up, goals set, information managed, and community partnerships nurtured. Dynamic, ongoing management of the entire CRA process, with appropriate accountability standards for all players, can lead to very positive results, not only for the banks involved but for their communities, as well.

Young & Associates: Your partner in change

Y&A is here to support financial institutions as they navigate the ever-evolving landscape of the financial industry. With our team’s extensive experience in strategic planning, we stand ready to assist you in successfully embracing, harnessing, and facilitating change.  Get in touch with us to learn how we can help.

GENIUS Act implementation status: What financial institutions need to know

By Bill Elliott, CRCM; director of compliance education, Young & Associates

The GENIUS Act was passed in 2025 and signed into law July 20, 2025. At the end of this article, we have prepared a summary of each regulator’s status regarding Where they are in their process to create implement regulations for this new law. The law itself states that the Act becomes effective January 18, 2027, regardless of the status of the presence of implementing regulations. We hope that the regulatory process is complete prior to the implementation date, as it will lead to confusion and probably additional efforts for both regulators and financial institutions.

Below is a general description of exactly what the rule actually requires.

Requirements for Issuing Payment Stablecoins (from Congress.gov)

“The act defines payment stablecoin as a digital asset issued for payment or settlement and redeemable at a predetermined fixed amount (e.g., $1). U.S. payment stablecoin issuers (unless falling under the act’s exceptions) must be approved by a state or federal regulator, as described below. Issuers are required to hold at least one dollar of permitted reserves for every one dollar of stablecoins issued. The GENIUS Act limits permitted reserves to coins and currency, deposits held at insured banks and credit unions, short-dated Treasury bills, repurchase agreements (“repos”) and reverse repos backed by Treasury bills, government money market funds, central bank reserves, and other similar government-issued assets approved by regulators.

Issuers may use reserve assets only for certain activities, including to redeem stablecoins and offer them as collateral in repos and reverse repos. The act requires federal and state regulators to issue tailored capital, liquidity, diversification, and risk management rules for federal and state stablecoin issuers, but it exempts stablecoin issuers from the regulatory capital standards applied to traditional banks.

Issuers are required to establish and disclose stablecoin redemption procedures and to issue periodic reports of outstanding stablecoins and reserve composition, which must be certified by executives and “examined” by registered public accounting firms. Those with more than $50 billion in stablecoins outstanding are required to submit audited annual financial statements. Issuers are prohibited from paying interest to stablecoin holders, but holders are not defined, and there is no restriction against exchanges paying interest to customers.”

Other regulations that face changes

In addition to the requirements above, the Bank Secrecy Act and the Financial Crimes Enforcement Network (FinCEN) must write tailored anti-money-laundering (AML) rules. The Act requires that FinCEN facilitate “novel methods … to detect illicit activity involving digital assets.”

The GENIUS Act will require any financial institution to certify that they have implemented appropriate AML and sanctions compliance programs.

Once completed, there likely will be additional responsibilities for your BSA staff. As part of the BSA process, it may require additional software or more upgrades to any current software you own.

The FinCEN proposal was issued in April 2026 and revolves mostly around Customer Identification issues. A Fact Sheet regarding the Notice of Proposed Rulemaking can be found at: https://www.fincen.gov/system/files/2026-04/FactSheet-PPSI-program-NPRM.pdf. OFAC will also need to be modified, but probably without major changes.

Issuing stablecoins

Stablecoins can be issued by several types of financial institutions, although non-banks will be restricted. Banks must apply to their relevant federal banking regulator. Applications must be evaluated based on whether the stablecoin issuers can meet the baseline requirements. The regulators must render a decision within 120 days, or the application will be deemed approved. Regulators must justify denials and permit applicants to appeal.

Federal regime supervision and enforcement

Any insured bank or nonbank issuer that opts for the federal regime or has more than $10 billion in issuance will be supervised by the regulator who evaluates their financial condition, risks to firm and financial system safety and soundness, and risk management systems. This will likely lengthen and complicate safety and soundness examination process. Additionally, there will be an increase in the reporting requirements outside of the safety and soundness examinations. This will mean extra efforts for your bank.

Regulators are authorized to stop a permitted issuer from issuing stablecoins or to issue other enforcement actions if necessary.

Other supervision and enforcement

In addition, depending upon your state regulators and perhaps law, state regulators will also be examining compliance with this Act. State regulators may cede their authority, but it is possible that state-chartered institutions will face additional state examinations as well.

Foreign Issuers

The GENIUS Act establishes requirements for the issuance of payment stablecoins by foreign issuers as well. That is beyond the scope of this article.

Other provisions

Other provisions address a number of topics, including stablecoin assets and reserve custodian issues. The law does permit banks to hold stablecoins and reserves in custody, use blockchains, and issue tokenized deposits.

Stablecoin holders receive priority over all other claims against the issuer in bankruptcy. This allows a bankruptcy court to issue automatic stays.

Payment stablecoins are not securities or commodities and are not federally insured.

The law prohibits those issuing stablecoin cannot represent stablecoin as being as beoing issued or guaranteed by the U.S. government.

Genius Act Chart

Conclusion

Each financial institution will need to consider whether to participate. It is likely that banks who have clients who do business outside the United States will be most interested. But participation will also come with additional costs and responsibilities. Financial institutions will need to evaluate their situation carefully before entering the world of stablecoin.

More on the GENIUS Act and stablecoin

Loan review trends: Credit risks and regulatory pressures to monitor

By David Reno, director of loan review & lending services, Young & Associates

Loan reviews provide institutions with an opportunity to evaluate their credit-granting processes, portfolio composition, and risk-management practices. Although each institution has a unique risk profile, recurring conditions across the lending environment can affect credit performance, staffing demands, and regulatory expectations. Our recent review experience highlights several trends institutions should monitor.

A risk-based approach to loan review

We do not approach loan reviews with a predetermined focus on hot topics. Each institution possesses a variety of risk elements that our diverse loan sample intends to cover. We look for consistent directionality in an institution’s credit-granting process and portfolio composition that aligns with its historical performance, staff expertise and knowledge, available resources, and geographic footprint.

An effective loan review is risk-based rather than one-size-fits-all. The review scope should reflect the institution’s size, complexity, loan types, concentrations, growth patterns, and overall risk profile. In addition to larger or higher-risk credits, a meaningful review may consider new loan products, loans approved as policy exceptions, rapidly growing portfolio segments, and credits with common repayment or collateral risks. This approach helps management assess not only individual credit quality, but also broader patterns that may affect portfolio performance.

Lending strategy and staffing pressures

Most institutions we review engage our services to maintain their established lending approach and strong portfolio performance. Those experiencing problems often have pursued geographically distant lending or launched a new-to-the-bank product that was poorly researched and scaled too quickly.

Finding and retaining qualified credit and lending staff challenges the entire industry. This shortage places added demands on experienced bank employees, who must more closely train and oversee junior staff. Similarly, experienced workout and collection professionals are scarce after more than ten years of favorable economic conditions. We see banks struggle to manage existing or emerging problem credits properly and promptly because of this lack of experience.

Credit risks to monitor

These conditions can compound one another, increasing the importance of timely monitoring, well-supported risk ratings, and proactive borrower communication. Our review experience also points to the following trends:

Non-owner-occupied commercial real estate (non-OOCRE) construction and renovation projects continue to face extended completion time frames because of labor and material shortages and delays. Inflation also contributes to cost overruns. If borrowers do not contribute additional equity, banks may need to increase loan amounts, changing the leverage and debt service coverage (DSC) dynamic.

Similarly, lease-up periods to stabilization for new multifamily construction and repositioned properties are extending. Borrowers may also need to offer unanticipated leasing discounts to increase occupancy.

Emerging credit risks and regulatory pressures

Student housing appears increasingly polarized. Properties near stable or growing institutions continue to perform well, while those in second- or third-tier college towns with declining student populations may experience lower occupancy and rents. Some of these properties are being considered for conversion to market-rate housing. Colleges also continue to develop on-campus housing that competes with investor-owned off-campus units.

Over the past year, we have observed a selective increase in regulatory scrutiny of institutions’ credit quality measurements. After an extended period of more hands-off regulatory oversight during and following the COVID-19 pandemic, certain Federal Deposit Insurance Corp. (FDIC) and Office of the Comptroller of the Currency (OCC) regions and field offices have become more aggressive. As a result, reports of examination (ROEs) may contain, at a minimum, credit and lending matters requiring attention. We expect some matters may escalate to a memorandum of understanding (MOU) or Consent Order after regional or Washington, D.C., offices review the ROE.

Examiner inexperience may contribute to this effect. Newer examination teams may lack the judgment developed through years of examinations and rely heavily on examiner-manual guidance. In some instances, new examiners may take an unnecessarily stringent approach as they seek to establish their reputations, posture for promotion, and attract the attention of supervisors.

Maintaining disciplined credit risk management

The conditions affecting credit quality vary by institution, market, and portfolio, but the need for disciplined credit risk management remains consistent. Institutions should monitor emerging weaknesses early, ensure staff have the experience and support needed to address them, and document actions taken to manage elevated risk. A focused loan review can help management identify developing concerns, assess whether risk ratings remain appropriate and take corrective action before issues become more difficult to resolve.

Stay ahead of loan review changes with Y&A

Young & Associates offers specialized lending and loan review services. For tailored solutions and expert support, contact us here.

UAD 3.6 appraisal report: What lenders need to know and how to prepare

By Casey Simpson; consultant and manager of appraisal review services, Young & Associates

The Uniform Appraisal Dataset (UAD) is the standardized industry dataset used to communicate appraisal property data electronically through the Uniform Collateral Data Portal (UCDP). The new UAD 3.6 is a redesigned Uniform Residential Appraisal Report (URAR) that is data driven and created to modernize the valuation industry.

This replaces UAD 2.6 and as part of this initiative, the Government Sponsored Enterprises (GSEs) are aligning to the latest version of the Mortgage Industry Standards Maintenance Organization (MISMO) Reference Model 3.6. Beginning November 2, 2026, all new appraisal reports submitted to UCDP for loans sold to Fannie Mae or Freddie Mac must use UAD 3.6. UAD 2.6 appraisal reporting has relied on static forms such as the 1004, 1073, 2055, 1025, and 1004D, which have been adapted to meet the changing industry requirements with property and market information dispersed throughout the report and in generalized addenda.

Appraisal orders will no longer specify a Form type. UAD 3.6 replaces the legacy forms for GSE appraisals for GSE appraisals with a single report. It will adapt based on property type, loan type, and scope of work, modernizing how appraisal data is packaged/delivered.

The new report is dynamic with sections turning “on” or “off” based on property characteristics accounting for all property and inspection types. This structure results in a more consistent reporting process and a machine-readable format.

Why is UAD 3.6 a better report?

UAD 3.6 enhances the collateral risk assessment with better data quality and consistency, greater transparency, improved analytics, and increased automation.

  • A Dynamic Reporting Structure: Instead of selecting a form based on the property type, the new structured report is flexible and will adapt to the appraisal data input, expanding or contracting based on the assignment, with only pertinent data for the subject included in the final report.
  • Structured Data Fields: UAD 3.6 is structured in a consistent data-driven format instead of long free-text narratives scattered throughout the report. Data is highly granular with the report containing more checkboxes and dropdowns enabling more consistent data entry, and consistent terminology. Each topic is grouped together with corresponding data, images, and commentary.
  • Expanded Property Details: Property details are more granular with approximately 150 new or modified data fields, including energy efficiency features, disaster mitigation improvements, smart home technology, high-speed internet availability, accessibility characteristics, as well as general property details down to ceiling height, room-level condition ratings and update status. UAD 3.6 captures accessory dwelling units (ADUs), manufactured homes, and other property features more consistently.
  • New Delivery Format: Appraisals will now be delivered as a ZIP package containing XML data, a human-readable PDF, and all supporting images.

Operationally, the new UAD 3.6 offers an improved audit trail, better integration with technology, better Risk Management due to cleaner data, and more consistent appraisals. This will result in better collateral decisions, easier portfolio analysis, and stronger investor confidence. The report is no longer just a document – it is structured data that can be analyzed.

What can you expect, and how will this impact you?

  • Legacy forms may still be used for in-house portfolio valuation.
  • All secondary market transactions must adhere to the new UAD 3.6 standards.

The impact of UAD 3.6 extends far beyond the appraisal report itself. As we adapt to this new reporting framework, the initial rollout may bring temporary challenges and require significant operational adjustments. Organizations that prepare early—by educating employees, updating systems and processes, coordinating with vendors and partners, and testing new workflows—will be better positioned to navigate the transition and minimize disruption.

Expect:

More Data-Driven Appraisal Workflows: Expect significantly more information to be collected, analyzed, and delivered in a standardized, structured format.

Changes to Appraisal Review and Interpretation: Expect adjustments in how appraisal reports are reviewed and interpreted as users become familiar with the dynamic UAD 3.6 reporting format and the expanded data it contains.

Must-dos for UAD 3.6 readiness

Whether your organization manages the residential appraisal compliance process internally or relies on a vendor partner, these are essential steps for UAD 3.6 readiness:

  • Technology & software: Ensure systems are updated to support the new ZIP file delivery format and expanded data points required by the GSEs.
  • Staff training: Train underwriters, processors, appraisal review staff, and other relevant personnel to interpret the new dynamic report format and understand the significance of the required data and how it may affect the valuation and underwriting process.
  • Appraisal quality control: Update and enhance existing QC checklists to align with the new structured data format and incorporate checks for UAD 3.6 requirements, including applicable regulatory and investor compliance standards.
  • Workflow readiness: Identify, update, and implement new workflows and processes needed to support UAD 3.6 requirements.
  • Testing: Test systems, integrations, and workflows before mandatory implementation to identify and resolve potential issues before they affect production operations.

Key UAD 3.6 dates you should know

January 26, 2026, to November 1, 2026: Broad Production /Transition period. Lenders can choose to use UAD 3.6 reports.

November 2, 2026: Mandatory Use Date– All lenders must use UAD 3.6. Any new assignments headed to the GSEs must be on the new dataset. (Revisions are allowed for previously submitted UAD 2.6 appraisals)

May 3, 2027: Retirement – UAD 2.6 pipeline revision period ends.

Young & Associates is ready to be your strategic partner

The successful implementation of UAD 3.6 requires more than updated technology. It requires the right combination of expertise, technology, training, process, and partnership. Our Appraisal Review service can help your organization strengthen review processes, identify potential issues, improve data quality, and better manage collateral risk as the industry moves to the new UAD standard.

With Young & Associates Inc. by your side, your organization can approach the transition with greater confidence and be better positioned to minimize disruption, maintain compliance, and keep business moving. Let Young & Associates, Inc. help you turn UAD 3.6 from a compliance challenge into an opportunity to strengthen your appraisal review process, improve data quality, and better manage collateral risk.

Takeaways from the OCC’s Cybersecurity and Financial System Resilience Report, June 2026

What the OCC’s latest Cybersecurity Report means for community financial institutions

Cybersecurity has entered a new phase for community banks. Artificial intelligence is giving threat actors new capabilities. Banks increasingly depend on interconnected third parties. Regulators expect institutions to identify and escalate significant incidents quickly. At the same time, emerging technologies are forcing financial institutions to consider risks that may not fully materialize for years.

The OCC’s June 2026 Cybersecurity and Financial System Resilience Report reinforces an important message for community financial institutions (CFIs): cybersecurity can no longer function primarily as an IT responsibility or periodic compliance exercise. It has become an operational resilience issue.

For community banks, that distinction matters. Most institutions cannot match the cybersecurity budgets or staffing levels of the nation’s largest banks, nor do regulators necessarily expect them to. They do, however, expect institutions to understand their risks, establish appropriate controls, manage critical dependencies, prepare for disruptions, and demonstrate that they can respond and recover when something goes wrong. Five developments deserve particular attention from community bank executives and boards in 2026.

1. AI has changed the economics of cybercrime

Community banks should no longer assume their size makes them less attractive to cybercriminals. Historically, attackers often had to devote significant time and resources to reconnaissance, vulnerability identification, social engineering, and attack development. That created an economic incentive to concentrate efforts on potentially lucrative targets. AI changes that calculation.

Threat actors can increasingly automate portions of the attack process, allowing them to identify vulnerabilities, develop convincing social engineering campaigns, and target organizations at greater scale.

As the OCC warns:

“The use of AI can enable automated reconnaissance, rapid vulnerability discovery and exploitation, targeted social engineering, and adaptive malware that can evade traditional security defenses.”

For community banks, the important issue is not whether a cybercriminal specifically selects your institution. Increasingly, they may not need to. Automated tools can search broadly for vulnerable systems, exposed credentials, misconfigurations, and other opportunities. A community bank can become a target simply because an exploitable weakness exists.

Adapting to the changes

Banks should evaluate their cybersecurity programs with this new reality in mind.

Traditional controls remain essential, but institutions should also ask whether those controls can respond to threats operating at greater speed and scale. Vulnerability management, multifactor authentication, access controls, endpoint protection, employee education, network monitoring, and timely patching become even more important when attackers can automate portions of the discovery and exploitation process.

The question is shifting from “Why would someone target us?” to “What would an automated attacker find if it looked?” That is a much more useful question for management and the board to ask.

2.The 36-hour clock makes preparation essential

When a significant cyber incident occurs, community banks may have very little time to determine their regulatory responsibilities.

Under the Computer-Security Incident Notification Rule, a banking organization must notify its primary federal regulator as soon as possible and no later than 36 hours after determining that a notification incident has occurred.

The key word is determining. Banks do not need to complete an investigation or understand every technical detail before the clock begins. Once the institution determines that an incident meets the notification threshold, the regulatory timeline applies. That makes internal escalation critical.

A bank that spends valuable hours determining who has authority to make decisions, locating regulatory contacts, debating notification thresholds, or waiting for complete forensic information can quickly lose much of its available response window.

Third-party incidents create another challenge. Bank service providers must notify affected banking organization customers as soon as possible when certain computer-security incidents cause, or are reasonably likely to cause, a material service disruption or degradation for four or more hours.

An incident response plan should work at 2:00 a.m. on a Sunday — not just look complete during an annual review.

Banks should clearly establish:

  • Who receives the first internal notification.
  • Who determines whether an event qualifies as a notification incident.
  • Who has authority to contact the regulator.
  • Who contacts customers, vendors, law enforcement, insurers, legal counsel, and other stakeholders when necessary.
  • Who assumes those responsibilities when primary personnel are unavailable.
  • Where current contact information, procedures, and notification templates reside.

Institutions should also test those decisions through tabletop exercises. The middle of a cyber incident is the wrong time to discover that your incident response plan depends on assumptions no one has tested.

3. Third-party risk has become cybersecurity risk

Community banks increasingly rely on third parties to provide technology and expertise they could not efficiently maintain internally.

That model creates tremendous value, but it also creates interconnected risk. Core processors, cloud providers, fintech platforms, managed service providers, payment systems, software vendors, telecommunications providers, and other partners can become part of the institution’s attack surface.

Cybercriminals recognize the opportunity. Compromising one widely used provider can potentially give an attacker access to, or disrupt services for, many institutions simultaneously. The OCC continues to emphasize effective management of these relationships, particularly when third parties support critical or higher-risk activities. As the report states:

“Effective risk management of third-party relationships — especially those that support higher-risk and critical activities — is important for safe and sound operations.”

Community banks should move beyond asking, “Did we complete our vendor due diligence?”

The more important questions are:

  • What happens to our bank if this vendor fails?
  • How quickly would we know?
  • What alternatives do we have?
  • How long could we operate without them?

That requires institutions to understand not only individual vendor risk but also operational dependency and concentration risk.

A strong third-party risk management program should identify which providers support critical activities, evaluate contractual protections, monitor changes in vendor risk, understand subcontractor dependencies when appropriate, establish escalation procedures, and develop realistic contingency plans.

Vendor management should not operate separately from business continuity, cybersecurity, and enterprise risk management. These disciplines increasingly describe different dimensions of the same risk.

4. Post-quantum risk belongs on the strategic technology agenda

Quantum computing may not represent an immediate operational threat for most community banks, but institutions should begin considering its long-term implications.

One concern is the “harvest now, decrypt later” approach. Threat actors can collect encrypted information today and retain it in anticipation that future quantum capabilities could eventually allow them to decrypt it. That creates an unusual cybersecurity problem: information protected adequately today may remain sensitive long enough for the technology protecting it to become obsolete.

For community banks, the appropriate response is not panic or an immediate overhaul of cryptographic systems. It is awareness and preparation.

Banks should begin discussing post-quantum readiness as part of long-term technology planning. An appropriate first step is understanding where cryptography exists throughout the institution.

Which systems protect sensitive information through encryption? Which vendors control those technologies? How long must the bank protect the underlying data? What plans do key technology providers have for adopting new cryptographic standards?

These questions can help institutions work toward crypto-agility, the ability to replace or update cryptographic technologies as standards evolve without requiring disruptive, last-minute system changes.

For most community banks, post-quantum readiness is not a 2026 implementation project. It is a 2026 planning conversation.

5. Digitalization requires risk management to keep pace

Community banks face a difficult balancing act. Customers increasingly expect convenient digital experiences.

Banks need technology to operate efficiently and compete effectively. New fintech relationships can provide capabilities that once required significant internal investment. But every new technology can also introduce new dependencies, data flows, access points, vendors, and operational risks.

The OCC’s focus on community bank digitalization reflects this tension. Its May 2025 Request for Information examined the challenges community banks face when adopting and implementing digital technologies.

The message should not discourage community banks from innovating. Instead, it should encourage institutions to make sure their governance and risk-management capabilities evolve alongside their technology. Digital strategy and risk strategy can no longer operate on separate tracks.

Before implementing significant new technology, management should understand:

  • What data the technology accesses and where that data resides.
  • Which third parties support the service.
  • How the bank will control and monitor access.
  • What happens if the technology becomes unavailable.
  • How the institution will exit or transition from the provider if necessary.
  • Whether existing cybersecurity, business continuity, compliance, and vendor-management programs adequately address the new risks.

Resources such as the Cybersecurity Supervision Work Program (CSW), Third-Party Risk Management: A Guide for Community Banks, and the OCC’s community bank digitalization resources can help institutions evaluate those questions.

The goal should not be to eliminate technology risk. That is impossible. The goal is to understand the risk well enough to make informed decisions about where and how the institution accepts it.

From cybersecurity compliance to operational resilience

The most important takeaway from the OCC’s cybersecurity report may not involve any individual technology or regulatory requirement. It is the broader shift in how banks should think about cybersecurity.

For years, institutions have devoted significant attention to preventing cyber incidents. Prevention remains critical, but prevention alone cannot define a mature cybersecurity program.

Banks must assume that systems can fail, vendors can experience outages, employees can make mistakes, credentials can become compromised, and sophisticated attackers may occasionally penetrate even strong defenses. The question then becomes: What happens next?

  • Can the institution identify the problem quickly?
  • Can management make decisions without unnecessary delay?
  • Can the bank maintain critical operations?
  • Does everyone understand their responsibilities?
  • Can the institution communicate effectively with regulators, customers, vendors, and other stakeholders?
  • Can it restore operations safely?
  • And after the incident, can the bank identify what went wrong and strengthen its controls?

Those questions define operational resilience.

What community bank leaders should do now

Community bank executives and boards do not need to respond to every emerging cyber threat by purchasing another technology solution. In many cases, the more valuable first step is determining whether the institution’s existing cybersecurity program works as intended. That means testing — not simply documenting — key capabilities.

At Young & Associates, we work with community financial institutions every day, and we understand the challenge: banks must respond to increasingly sophisticated risks without unlimited staff, budgets, or time.

The answer is not to build the cybersecurity program of a global bank. It is to build a program that appropriately reflects your institution’s size, complexity, technology environment, risk profile, and critical operations — and then verify that it works. When a cyber incident occurs, the strength of the program will not be measured by the policies sitting on a shelf. It will be measured by how effectively your institution responds.

Explore our suite of IT consulting services:


Source: OCC Cybersecurity and Financial System Resilience Report, 2026

Five human-smuggling indicators financial institutions should understand

The $4.9 billion financial footprint of human smuggling

The Financial Crimes Enforcement Network (FinCEN) has released a critical Financial Trend Analysis (FTA) examining Bank Secrecy Act (BSA) data from January 1, 2023 through December 31, 2025. This review period uncovered a massive $4.9 billion in suspicious activity linked to human smuggling — a sophisticated, multi-billion-dollar enterprise often controlled by Transnational Criminal Organizations (TCOs) like Mexico-based cartels. While total reports saw a 62% decline in 2025 (dropping from 29,266 in 2024 to 11,018 in 2025), the financial volume remains immense, highlighting the persistent role of the formal financial system in border security.

For Community Financial Institutions (CFIs), the most vital metric is the “Impact Gap.” While Money Services Businesses (MSBs) file 97% of all reports, Depository Institutions handle 61% of the total suspicious dollar value ($3 billion). Your institution must prioritize the analysis of these high-value flows: the average transaction amount for depository institutions is approximately $1.5 million, compared to the MSB average of just $7,961. This represents an 188x difference in risk-per-transaction, placing a disproportionate responsibility on CFIs to detect the high-value consolidation and exit points of smuggling networks.

Core metrics (2023–2025 review period)

  • Total BSA Reports Analyzed: 67,540
  • Total Suspicious Dollar Value: $4.9 Billion
  • Depository Institution Share of Value: $3 Billion (61% of total)
  • 2024 Report Volume: 29,266 (Peak year)
  • 2025 Report Volume: 11,018 (62% decline from peak)

Dismantling these networks begins with recognizing the specific behavioral patterns, or indicators, found in recent BSA data.

Indicator 1: Unverifiable relationships and originator-beneficiary mismatch

The lack of a logical or verifiable relationship between parties is the most prevalent red flag in human smuggling. Granular MSB data indicates that 57% of filings cited “no verifiable familial connection” as the primary reason for suspicion. CFIs should use this MSB-specific benchmark to calibrate their own monitoring; when U.S.-based customers send funds to unrelated third parties in high-risk jurisdictions, it frequently signifies a payment to a professional smuggler or the payment of a “piso“— a territorial tax collected by cartels for safe passage through controlled corridors.

The data reveals a specific pattern where U.S.-based foreign nationals use foreign-issued IDs to send money to friends or relatives. In approximately 7% of cases, customers explicitly admitted the funds were intended for smuggling. Compliance officers must scrutinize transactions where there is no clear familial or business nexus, particularly when the subject’s identification suggests a temporary presence in the United States.

Indicator 2: The proliferation of funnel accounts and aggregated P2P transfers

Human smuggling networks have strategically shifted toward using depository accounts as funnels to collect small-dollar payments from diverse sources. This typology bypasses traditional familial checks by using multiple, seemingly unrelated originators to fund a single beneficiary’s account.

A specific case study identifies a high-risk pattern: one account received small-dollar peer-to-peer (P2P) transfers from 30+ different senders between March and July 2023, totaling $68,000. The subject systematically transferred incoming funds to a separate savings account before executing the exit through structured cash withdrawals.

Warning Sign: Your institution must flag accounts with high-volume P2P activity that contradicts the customer’s stated occupation, followed by structured cash withdrawals at branch or ATM locations designed to stay below reporting thresholds.

Indicator 3: Strategic geographic deviations and migration route alignment

Smuggling activity follows international and domestic corridors that extend far beyond the Southwest border. “Geographic Deviation” occurs when account activity occurs far from a customer’s residence or in states like Minnesota and North Dakota. For Northern border CFIs, a specific tactical red flag involves the exchange of Canadian dollars for U.S. dollars, followed by P2P transfers to individuals previously linked to alien smuggling.

Strategic deviations also include international transit routes, such as the UAE-to-Nicaragua flight route, where Nicaragua serves as a disembarkation point for migrants continuing to the U.S. border by land.

High-risk jurisdictions for smuggling activity

Top U.S. States Top Latin American Countries Critical Cities
Texas (TX) Mexico Ciudad Juarez, MX
California (CA) Guatemala Villahermosa, MX
New York (NY) Honduras Tapachula, MX
Florida (FL) Colombia Monterrey, MX
New Jersey (NJ) Guatemala City, GTM
Houston, TX, USA

Indicator 4: Excessive cash activity and structuring in border jurisdictions

Cash is the primary medium for paying piso taxes and local facilitators. TCOs utilize structured withdrawals, keeping amounts just below reporting thresholds, at multiple ATM and branch locations along the U.S.-Mexico border to evade BSA oversight.

CFIs must be alert to high-volume cash activity in accounts belonging to individuals in non-cash-intensive industries. A striking example involves a “student” and a “produce company owner” in Arizona (Nogales and Phoenix) who made $195,000 in unusual cash deposits. These funds sourced debit card transactions for $30,000 in tactical equipment, including thermal binoculars and night vision attachments. The link between “Unusual Cash Deposit ➡ Debit Purchase ➡ Tactical Gear” is a direct indicator of logistical support for smuggling operations.

Indicator 5: Exploitation of travel agencies and “sham” operations

Smuggling networks exploit travel arrangements (flights, buses, hotels) for the “last mile” of the journey. CFIs are uniquely positioned to see the back-end of these operations, which often involve sham travel agencies or legitimate businesses acting as unwitting facilitators.

A recent case involved a Florida-based travel agency and chartered flights from the UAE to Nicaragua. CFIs should monitor for these three high-risk behaviors in travel agency accounts:

  1. Funding Anomalies: Excessive cash deposits at border ATMs (e.g., $150,000+) that serve as the primary source of funding.
  2. Lack of Operating Expenses: The total absence of traditional payroll activity or standard business overhead.
  3. Booking Discrepancies: Large-scale airline refunds or P2P transfers from individuals appearing to pay for “visa services” that fund bulk airline ticket purchases for unrelated groups.

Operationalizing intelligence for community financial institutions

Human smuggling is a multi-billion dollar enterprise that presents concentrated financial risks to the banking sector. While report volumes have declined, the “Impact Gap” confirms that depository institutions remain the primary vehicles for high-value illicit transfers. Your institution’s role in identifying these patterns is critical to dismantling the financial infrastructure of TCOs.

CFI compliance action checklist

  • Apply Key Technical Term: You must use the term “FIN-2023-HUMANSMUGGLING” in the narrative of all relevant BSA filings; this is the single most important technical requirement for law enforcement data aggregation.
  • Audit P2P Aggregation: Review accounts receiving frequent transfers from 30+ unrelated originators, particularly those with a consolidation-to-savings pattern.
  • Monitor Geographic Shifts: Flag activity in migration corridors (Southwest and Northern borders) that deviates from the customer’s residence, including Canadian currency exchanges.
  • Verify Business Profiles: Ensure cash-intensive activity aligns with stated occupations, specifically auditing travel agencies for the absence of payroll.
  • Logistical Screening: Review high-value debit purchases from tactical or thermal gear suppliers when sourced by unusual cash deposits.

BSA data remains the most valuable tool for law enforcement to follow the money and dismantle the networks profiting from human exploitation.

Strengthen your BSA/AML/CFT compliance program

Protect your institution from evolving financial crime risks with a strong, effective compliance program. Young & Associates provides experienced compliance consulting and advisory services to community financial institutions, including BSA/AML/CFT and OFAC reviews, AML model validation, and comprehensive compliance support.

Contact Young & Associates today to strengthen your BSA/AML compliance program and address emerging risks with confidence.


Source: Financial Crimes Enforcement Network (FinCEN), Human Smuggling: 2023–2025 Threat Pattern & Trend Information, Financial Trend Analysis, August 2026.

View the full FinCEN Financial Trend Analysis

Takeaways from the NCUA Deregulation Project

For years, credit union leaders have navigated the dense thicket of the 12 CFR, often grappling with a “compliance fatigue” that stifles innovation. Balancing operational growth against a rigid and complex regulatory framework has felt like a zero-sum game. However, the regulatory weight is beginning to lift.

Spurred by the catalyst of 
Executive Order 14192 (“Unleashing Prosperity Through Deregulation”), the National Credit Union Administration (NCUA) is currently executing a massive, multi-year “Deregulation Project.” Phase One (2025–2027) is focused on modernizing the agency’s framework by identifying rules that are obsolete, duplicative, or overly burdensome. For the strategic credit union leader, this represents a shift toward a more principles-based supervisory environment.

The end of the client-customer automatic bar

One of the most significant shifts involves proposed changes to 12 CFR 701 (Appendix B) regarding associational common bonds. Historically, the NCUA maintained an “automatic bar” against groups primarily based on a client-customer relationship. If joining an association required the purchase of a product or service, such as an insurance policy, the group was automatically disqualified from Field of Membership (FOM) eligibility.

The new proposal moves from an automatic bar to a process of further evaluation. The NCUA Board has determined that a product purchase requirement is no longer a hard no. Instead, the agency will evaluate if the client-customer relationship is merely incidental to the group’s broader activities. This shift to a holistic evaluation opens significant new doors for FOM expansion, allowing credit unions to partner with associations they previously would have ignored.

Flexing senior management compensation

In a competitive labor market, attracting and retaining high-level talent is vital for institutional resiliency. However, the NCUA’s historical blanket prohibition on loan-related compensation has been a major pain point, often suffering from varying interpretations and inconsistent enforcement across the NCUA’s different regions.

Proposed changes to 12 CFR 701.21(c)(8) seek to resolve this confusion. By adding a formal definition of “overall financial performance,” the rule would explicitly permit credit unions to offer incentives and bonuses to employees, including senior management, that incorporate lending metrics. As long as these metrics are part of a broader evaluation of the institution’s financial health, the NCUA now views this as a critical tool for recruitment rather than a hurdle.

Removing prescriptive training deadlines

Volunteer boards are the lifeblood of the credit union movement, but prescriptive mandates can deter community members from serving. Currently, 12 CFR 701.4(b)(3) mandates that every director attain a “working familiarity” with finance and accounting within six months of election or appointment.

The NCUA is now proposing to eliminate this rigid six-month deadline. While the agency continues to hold the core expectation that directors possess financial expertise, it admits the current rigid clock is “unduly burdensome” and can “undermine the ability of a credit union’s members to elect their board.” This is a clear win for community representation: the requirement for competence remains, but the arbitrary training clock is being dismantled.

Lifting the caps on third-party auto servicing

Effective September 8, 2026, a final rule will remove the restrictive caps previously found in 12 CFR 701.21(h). In the past, credit unions were capped at 50% of their net worth for indirect auto loans serviced by third parties, only reaching 100% after 30 months of experience with a specific servicer.

By removing these prescriptive limitations, the burden of risk management shifts from federal mandates to the board’s own risk tolerance. This allows institutions to manage liquidity and portfolio diversity based on their unique needs rather than a one-size-fits-all cap.


“With today’s announcement, we are moving forward on our commitment to removing regulations that are obsolete, burdensome, duplicative, or simply guidance that has no place in regulation. Our goal is to make it easier for credit unions to serve their members, meet compliance requirements, and stay innovative. These final rules and those that come after will give credit unions the flexibility to do just that.” — Chairman Kyle Hauptman

The guidance vs. regulation cleanup

A key pillar of this project is ensuring that non-binding guidelines are not misinterpreted as enforceable law. The NCUA is stripping several “Appendices” out of the Code of Federal Regulations and moving them into “Letters to Credit Unions.” This cleanup clarifies that guidance should be followed as best practice, but it is not independently enforceable.

Key areas moving out of the CFR into guidance include:

  • Safeguarding Member Information: Moving the standards for protecting the security of records (formerly 748 Appendix A).
  • Response Programs: Moving the guidance for responding to unauthorized access to member data (formerly 748 Appendix B).
  • Voting Guidelines: Moving the non-binding suggestions for obtaining fair votes during conversions (found in 12 CFR 708a).

Modernized catastrophic reporting

During a crisis, management should focus on stabilizing operations, not filling out forms. To reflect this, the NCUA is modernizing 12 CFR 748.1(b).

The reporting window for catastrophic acts is being increased from 5 business days to 15 calendar days. Furthermore, in a significant procedural shift, reports are now to be made directly to the NCUA rather than the Regional Director. This centralizes the reporting process and gives credit unions the necessary breathing room to manage emergency conditions before worrying about regulatory paperwork.

A new era of safety and soundness

The Deregulation Project represents a fundamental pivot in the NCUA’s philosophy. By categorizing rules as Obsolete, Duplicative, Overly Burdensome, or Guidance, the agency is attempting to prioritize relief that actually impacts daily operations.

While this signals a move toward principles-based supervision, do not expect exams to be less rigorous. The focus remains squarely on safety and soundness, but with a renewed respect for the business judgment of credit union boards.

Note: Credit unions must continue to follow all existing regulations as they currently appear in the Code of Federal Regulations until the relevant Final Rules are officially effective. For help navigating regulatory compliance, learn more about Y&A’s compliance consulting services.

Y&A Credit Services launches asset-based lending field exam services

Y&A Credit Services, a full-service provider of outsourced underwriting services and credit analysis, announced the launch of its asset-based lending (ABL) field exam services. The service is designed to help financial institutions confidently manage asset-based lending relationships, strengthen risk management practices, and support portfolio growth with experienced, independent field exam expertise. 

“Asset-based lending can create valuable growth opportunities for community financial institutions, but it also requires a disciplined approach to collateral monitoring and risk management,” said Oliver Sutherin, principal of Y&A Credit Services. “Our ABL Field Exam Services are designed to give lenders greater visibility into collateral quality, borrower operations, and portfolio risk so they can make informed decisions with confidence. We strive to help institutions grow strategically while maintaining strong credit administration practices.” 

Each field exam may include: 

  • Verification and analysis of accounts receivable — aging schedules, eligibility testing, dilution trends, and concentration risk across the borrower’s customer base  
  • Inventory testing and valuation review — roll-forward analysis, eligibility criteria, obsolescence exposure, and physical verification against reported values  
  • Borrowing base validation — reconciliation of the calculated base to loan balances, confirming advance rates and eligible collateral are applied correctly  
  • Collateral monitoring assessments — UCC filing and lien priority review, insurance coverage confirmation, and ongoing collateral adequacy relative to outstanding advances  
  • Review of operational controls and reporting practices — evaluation of cash receipts handling, AP aging integrity, and the borrower’s internal reporting discipline 
  • Identification of risk trends, reporting inconsistencies, and exceptions — financial trend analysis, GL tie-out testing, and documented exceptions with recommended remediation  
  • Independent reporting for lending and credit administration teams — a structured exam summary covering scope, findings, and risk conclusions to support credit decisioning 

Comprehensive commercial credit support

The new offering aligns with Y&A Credit Services’ broader mission of helping community financial institutions improve operational efficiency, overcome staffing challenges, and enhance credit risk management through outsourced expertise. With the addition of ABL field exam services, Y&A Credit Services now offers a comprehensive suite of commercial credit support services, including underwriting package reviews, annual underwriting reviews, financial statement spreading and analysis, and credit administration support.

Specialized ABL field exam expertise

To support this expanded capability, Y&A Credit Services employs credit analysts who have earned the Commercial Banking & Credit Analyst (CBCA) certification from the Corporate Finance Institute® (CFI). This specialized training strengthens their ability to evaluate the collateral, borrowing-base, operational, and financial risks commonly encountered in asset-based lending field examinations, including financial modeling, loan security analysis, and industry analysis.

Our experienced credit professionals conduct field exams tailored to your institution’s credit policy, loan agreement, and risk profile. We provide clear, independent insights to help identify exceptions, validate collateral reporting, and support informed lending decisions.

ABL field exam services are available now. To learn more, visit Y&A Credit Services or call 1-800-525-9775. 

About Y&A Credit Services

Y&A Credit Services provides commercial underwriting and specialty credit services to financial institutions nationwide. Founded in 2022, Y&A Credit Services operates as an independent entity while delivering the same expertise, service, and integrity associated with Young & Associates. Both organizations help financial institutions navigate regulatory challenges and position themselves for growth. 

Learn more at Y&A Credit Services. 

Risk assessment is the BSA key

By William J. Showalter, CRCM; senior consultant, Young & Associates

Your bank has an opportunity to frame your next Bank Secrecy Act/Anti-Money Laundering/Countering the Financing of Terrorism (BSA/AML/CFT) examination – much as you do your Community Reinvestment Act (CRA) exam by preparing a summary of the “performance context” within which you operate.

The agencies state that a well-developed BSA/AML/CFT risk assessment assists the bank in identifying money laundering, terrorist financing, and other illicit financial activity risks and in developing appropriate internal controls – policies, procedures, and processes. Understanding its risk profile enables the bank to better apply appropriate risk management processes to the BSA/AML/CFT compliance program to mitigate and manage risk and comply with BSA regulatory requirements. The BSA/AML/CFT risk assessment process also enables the bank to better identify and mitigate any gaps in controls.

Risk-focused exam process

The interagency examination procedures provide that the extent of BSA/AML/CFT examination activities necessary to assess the bank generally depends on the bank’s risk profile and the quality of risk management processes to identify, measure, monitor, and control risks, as well as to report potential money laundering, terrorist financing, and other illicit financial activity. Given that banks vary in size, complexity, and organizational structure, the agencies acknowledge that each bank has a unique risk profile, and the scope of a BSA/AML/CFT examination varies by bank.

The first step in a BSA/AML/CFT examination is a scoping and planning process. At this preliminary stage of the activity, examiners analyze existing information about the bank – off-site monitoring information, previous examination reports and workpapers, BSA-reporting databases, other communications with the bank, and independent reviews or audits. Examiners also scrutinize request letter items completed by bank management and, perhaps most important in some ways, the bank’s BSA/AML/CFT risk assessment.

BSA examiners are charged to determine the BSA/AML/CFT risk profile of the bank as a part of the scoping and planning process. The preferred method for accomplishing this goal centers on a review of the bank’s risk assessment. While banks are not required to perform such an assessment, it is central to ensuring that a BSA/AML/CFT program is appropriate for the bank, given its product and customer mix, as well as location risk factors. The agencies consider that an effective risk assessment should be a composite of multiple factors, and depending on the circumstances, certain factors may be weighed more heavily than others.

The information contained in the BSA/AML/CFT risk assessment assists examiners in developing an understanding of the bank’s risk profile, risk-focusing the examination scope, and assessing the adequacy of the bank’s overall BSA/AML/CFT compliance program and its compliance with BSA regulatory requirements.

Examiners are directed to focus, when evaluating the bank’s BSA/AML/CFT risk assessment, on whether the bank has effective processes resulting in a well-developed risk assessment. They are not to take any single indicator as determinative of the existence of a lower- or higher-risk profile for the bank. Any assessment of risk factors is bank-specific, and a conclusion regarding the bank’s risk profile is to be based on a consideration of all pertinent information.

Examiners are to assess whether the bank has developed a BSA/AML/CFT risk assessment that identifies its money laundering, terrorist financing, and other illicit financial activity risks. Examiners are also to assess whether the bank has considered all its products, services, customers, and geographic locations in its assessment, and whether the bank analyzed the information relative to those risk categories.

If a bank has not prepared a BSA/AML/CFT risk assessment, or if its assessment is deemed inadequate, the examiner is directed to discuss this fact with management, as well as prepare their own risk assessment. The reason for this emphasis on a bank-prepared risk assessment is that the bank’s BSA/AML/CFT program should be tailored to the risks it faces, and the agencies see an assessment as an important tool to assist the bank in effectively managing BSA risks and critical in developing appropriate internal controls.

Using your risk assessment

An appropriate BSA risk assessment provides the bank with a foundation on which to build a successful compliance program addressing this area. This risk assessment is not a static document. You will have to monitor changes in the bank’s product offerings (e.g., virtual currency-related services), business environment, regulatory changes, bank personnel, and so forth – and make appropriate changes to policy and procedure – to ensure that the foundation remains strong under the bank’s BSA/AML/CFT compliance program.

The agencies expect that the bank will structure its BSA/AML/CFT compliance program to address its risk profile, based on the bank’s assessment of risks, as well as to comply with BSA regulatory requirements. Specifically, the bank should develop appropriate policies, procedures, and processes to monitor and control its money laundering, terrorist financing, and other illicit financial activity risks.

For example, the bank’s monitoring system to identify, research, and report suspicious activity should be risk-based to incorporate any necessary additional screening for higher-risk products, services, customers, and geographic locations as identified by the bank’s BSA/AML/CFT risk assessment.

Also, independent testing (audit) should review the bank’s BSA/AML/CFT risk assessment, including how it is used to develop the BSA/AML compliance program.

Banks that choose to implement a consolidated or partially consolidated BSA/AML/CFT compliance program should assess risk within business lines and across activities and legal entities.

Consolidating money laundering, terrorist financing, and other illicit financial activity risks for larger or more complex banking organizations may assist senior management and the board of directors in identifying, understanding, and appropriately mitigating risks within and across the banking organization.

To understand money laundering, terrorist financing, and other illicit financial activity risk exposures, the banking organization should communicate across all business lines, activities, and legal entities. Identifying a vulnerability in one aspect of the banking organization may indicate vulnerabilities elsewhere.

Conclusion

The importance of a BSA/AML/CFT risk assessment cannot be overstated. A bank-prepared assessment can establish the direction a bank’s BSA/AML/CFT program will take, as well as guiding BSA exams and other reviews/audits. Just as with a CRA performance context, preparing your own BSA/AML/CFT risk assessment can provide the roadmap to guide your compliance – and examiners’ evaluation of your program. And the agencies have given you a roadmap to guide your risk assessment – the BSA/AML/CFT examination procedures. Use it, if you have not already, before the examiners come for their next visit.

Why banks should invest in financial education for their lenders

By Ollie Sutherin, chief financial officer, Young & Associates

Ask a small business owner to name their loan officer, and you’ll usually get one of two answers: a name they remember fondly, or a shrug. The difference often comes down to what happened after the loan closed.

Too often, the relationship ends at funding. The borrower takes the money, and the loan officer goes quiet until another lending opportunity arises or the deal starts to sour. That pattern is so common in our industry that many bankers don’t even recognize it as a problem. But it is a problem, and it’s also a missed opportunity. The loan officer can be far more valuable than a point of contact for money. They can be a source of knowledge and a trusted reference for the small businesses they serve.

The knowledge gap nobody talks about

Community banks live and die by small-business lending, and small businesses are usually run by people who are exceptional at what they do. The contractor knows construction. The restaurateur knows food. The machine shop owner can tell you the tolerances on every part that leaves the floor. What they often do not know, and were never trained to know, are the nuances of bookkeeping, accounting, and tax treatment.

This isn’t a criticism of business owners. It’s simply the reality of how small businesses are built. The owner’s expertise is in their industry, not in debits and credits. Yet their ability to access capital depends almost entirely on how well their financial condition is documented and presented.

That is where the loan officer comes in. The loan officer sits at the bridge between business operations and financial condition. No one else in the borrower’s orbit occupies that position. The CPA sees the books once a year.

The bookkeeper, if there is one, may be a family member doing their best with QuickBooks on weekends. The loan officer, on the other hand, sees the financials in the context of what the business is actually trying to accomplish: growth, equipment, real estate, and working capital. With that vantage point comes not just an opportunity, but an obligation, to assist and educate.

A real-world example

Consider a borrower whose business is genuinely healthy: strong sales, good margins, loyal customers. But when their P&L comes across your desk, you notice they have expensed the principal portion of their loan payments. Their reported income is understated, their balance sheet does not tie, and now your credit department has to spend time untangling something that should have been clean from the start.

A loan officer with solid accounting fundamentals catches that immediately and, more importantly, can explain it to the borrower in plain terms: principal reduces a liability on the balance sheet; only the interest belongs on the income statement. That five-minute conversation does two things. It makes the borrower’s bookkeeping easier going forward, and it makes their true borrowing capacity clearer to the bank. Clearer financials mean faster underwriting, and faster underwriting helps businesses access capital sooner. Everybody wins.

But that conversation only happens if the loan officer knows enough accounting to have it.

The case for investing in training

This is where bank management comes in. Community banks should be making deliberate, ongoing investments in accounting and finance training for their loan officers. Not a one-time orientation, but real education that equips lenders to read, understand, and explain financial statements with confidence. The return on that investment shows up in at least three places.

  • First, better deals reach the credit department. A loan officer who truly understands financial condition knows when a deal is right and when it is not. Requests that should have been declined at the first meeting get declined at the first meeting, instead of consuming hours of analyst time before arriving at the same conclusion. Credit departments at community banks are stretched thin as it is. Lenders who can screen effectively at the point of contact take real strain off the back of the house.
  • Second, complex borrowers get represented accurately. As community banks compete for borrowers closer to the middle market, the financials get more complicated and the questions get harder. Deferred revenue, related-party transactions, owner add-backs, and percentage-of-completion accounting come up constantly with larger borrowers, and credit and loan committees will ask about them. A loan officer who can grasp the financial condition firsthand, ask the right questions of the borrower, and convey the answers clearly to committee is worth their weight in approvals. A loan officer who cannot becomes a relay station for confusion.
  • Third, smaller borrowers get the help they actually need. Many of them are not looking for a sales pitch. They’re looking for assistance, education, and good references. Often a borrower’s financial condition is fundamentally sound; it’s the presentation that’s broken. The lender who can fix that, or point the borrower to someone who can, earns a kind of loyalty that no rate sheet can buy.

Know the tools, share the preferences

Part of being a genuine resource is knowing the resources. Most people in banking can glance at a P&L and recognize which software produced it, and experienced lenders usually have preferences born from years of seeing what comes out clean and what comes out messy. Those preferences should not stay locked in anyone’s head. If a particular accounting platform consistently produces financials that are easy for the borrower to maintain and easy for credit to analyze, say so. Recommend it. Maintain a short list of reputable local bookkeepers and CPAs and hand it out freely.

This costs the bank nothing and makes everyone’s life easier, from the borrower keeping the books to the analyst spreading them.

The payoff

None of this is charity. A borrower who keeps clean books is a borrower whose loan requests move faster, whose covenants are easier to monitor, and whose problems surface earlier, while there is still time to work through them. A loan officer who is a trusted advisor rather than an occasional caller retains relationships through rate cycles and competitive pressure. And a bank known in its community as the place where lenders actually help you understand your business attracts the kind of word-of-mouth referrals that no marketing budget can replicate.

The math is simple. Invest in your loan officers’ financial education, and they will invest it right back into your borrowers. The credit department gets cleaner deals, management gets better profitability, and small businesses get the partner they have been missing. That is community banking at its best.

The “gateway” strategy: Turn a checking account into a long-term customer relationship

By Joseph Ciccolini, content marketing associate, Young & Associates

Marketing often takes a back seat at financial institutions. While many recognize its potential to drive new accounts and attract customers, institutions frequently underemphasize its role as a revenue-generating function. In many cases, the solution already exists but needs to be positioned more effectively: cross-selling, particularly through the “gateway” product that establishes a primary relationship.

For financial institutions, profitability is not just about volume growth but also depth in relationships. Checking accounts provide a natural starting point for building stronger customer engagement, increasing retention, and expanding cross-sell potential.

A 2025 Jack Henry Strategy Benchmark identified top priorities for bank and credit union CEOs, including improving efficiency, driving deposit and loan growth, acquiring new accountholders, and expanding solutions for small and medium-sized businesses. Checking account acquisition directly supports each of these priorities by establishing a primary customer relationship that enables deeper engagement, stronger retention, and increased opportunities for cross-selling.

Consumers typically define their primary financial institution as the one where they hold their primary checking account. That account serves as the gateway to cross-selling opportunities and deeper customer relationships. Primary financial institution relationships are remarkably stable, with customers staying with the bank for an average of eight to 10 years and using five to six products and services per household. Without it, customers are less likely to view the institution as their primary provider. Instead, the relationship resembles the financial equivalent of a secondary streaming service — used occasionally, but not the go-to.

What strategies can institutions use to encourage customers to open a checking account and become primary accountholders? One effective approach is a drip campaign.

Checking Account Stats

What are drip campaigns?

Drip campaigns are a form of email marketing that deliver targeted messages over time to encourage engagement and keep your institution top of mind with customers and prospects. By providing relevant, valuable information, these campaigns guide customers toward action through continuous communication. This approach helps institutions nurture leads and build strong, long-term relationships.

In this context, a drip campaign supports the goal of securing the “gateway” cross-sell in the form of a checking account. Once a customer opens a checking account, the likelihood of becoming a primary accountholder increases significantly, along with opportunities to expand the relationship.

Cross-selling differs from upselling by focusing on complementary products that enhance the customer relationship and increase overall value. The checking account serves as the entry point for this strategy. Once established, institutions can introduce additional products — such as debit cards or certificates of deposit — in a way that aligns with customer needs and behaviors.

Why drip campaigns can outperform cash incentives

Some institutions may already rely on cash incentives to encourage checking account acquisition. However, a 2025 ProSight industry outlook found that only 27 percent of consumers who recently switched institutions cited a cash incentive as the primary reason. Instead, institutions should identify customer needs, understand the challenges they can solve, and promote those solutions effectively.

Drip campaigns play a key role in this strategy by delivering relevant, timely messaging directly to customers. These campaigns help move prospects from consideration to conversion while setting the stage for meaningful interactions.

Gallup’s 2021 retail banking study found that high-quality conversations significantly improve sales conversion rates. When customers initiate the conversation, conversions are 1.6 times more likely compared with low-quality interactions. When employees initiate high-quality conversations, conversions are 4.2 times more likely. Drip campaigns can help prompt these conversations by engaging customers before direct interaction occurs.

Conclusion

Financial institutions should treat checking account acquisition as a critical step in attracting and retaining customers. According to the J.D. Power 2026 U.S. Retail Banking Satisfaction Study, key engagement metrics are beginning to decline as customers increasingly open accounts with multiple institutions. This shift creates a clear opportunity to attract new customers and strengthen relationships through effective cross-selling.

All of this can start with a checking account. Financial institutions should move beyond traditional go-to-market approaches and adopt a marketing-led strategy that prioritizes engagement, not just acquisition. By using tools like drip campaigns to convert and deepen relationships, institutions can turn checking accounts into a foundation for long-term growth and differentiation.

Why your “healthy” portfolio might be a time bomb

By Jerry Sutherin, CEO at Young & Associates

A community development financial institution (CDFI), a mission-driven lender that uses public and private capital to serve underserved communities, can appear healthy on the surface, with steady interest income and consistent growth. Because CDFIs often lend in distressed markets and to borrowers outside the traditional financial system, their portfolios carry unique and sometimes less visible risks. Interest income can mask a weakening foundation of documentation and systemic exposure. Financial history is filled with institutions that appeared stable until hidden vulnerabilities triggered catastrophic deterioration. The difference between sustainable CDFIs and those that fail is not luck. It is the rigor of their internal credit administration.

While front-end underwriting controls risk at origination, institutions must shift to active risk management once a loan is booked. This is where the loan review, an essential but frequently misunderstood strategic tool, serves as your early warning system. It identifies internal weaknesses and “invisible leaks” before they become irreversible financial losses.

Strategic oversight vs. detailed loan file review

In CDFI management, it is critical to distinguish between a high-level portfolio overview and a detailed loan-level audit. While a portfolio review assesses the “big picture,” focusing on geographic, borrower, or other risk concentrations, it cannot replace the granular insights of a loan review.

This assessment is anchored to a specific date, which establishes a clear snapshot of loan quality and ensures findings remain objective. A high-level trend analysis will miss the granular policy deviations that only an individual file examination can reveal.

An independent loan review performs the following functions:

  • Evaluates individual loans and repayment risk.
  • Verifies adherence to internal lending policies and procedures.
  • Identifies gaps in loan file documentation.
  • Communicates high-priority credit risk findings.
  • Recommends actionable improvements to policies and practices.
  • Validates the accuracy of internally assigned risk ratings.

The power of the independent eye

For a loan review to provide strategic value, it must be conducted with objectivity. This requires a strict “independent eye.” Individuals involved in the lending process, including members of the credit committee, should not participate in the review.

Familiarity creates blind spots. Lending staff may overlook a missing document or a policy breach because they “know” the borrower.

Independence also serves as a key control against internal fraud and theft — risks that directly affect a CDFI’s bottom line. Whether utilizing external consultants or internal staff outside the lending function, the goal is to provide the board of directors with objective, unfiltered data on loan quality.

Why paperwork errors are principal risks

CDFI managers often dismiss administrative lapses as routine paperwork. These are technical and legal failures that expose the institution to civil money penalties or the total loss of principal.

A high-priority finding often involves insurance documentation. There is a critical legal distinction between being listed as an “additional insured” versus a “mortgagee.” Missing this distinction means the CDFI is unprotected if the collateral is destroyed.

Other common deficiencies include:

  • Incorrect naming of the CDFI’s role on insurance certificates.
  • Missing documentation of physical inspections of the business or collateral.
  • Failure to implement post-closing follow-up to ensure receipt of all required loan documentation.
  • Having a robust internal exception tracking system where results can be easily conveyed to the board of directors.

These are not just errors— they signal systemic weakness. Additionally, all financial institutions must track the migration of risk ratings as they change. Risk rating changes of 10 percent or more during a loan review indicates systemic issues and warrants a closer review of the Bank’s Allowance for Credit Losses (ACL), their primary safety net.

Judgment and analytical failures: realism vs. optimism

Loan review also addresses lender optimism that can cloud internal analysis. Two common areas of analytical weakness include income projections and collateral valuation.

Income projections

Lenders often rely on projected net income rather than historical performance. While quality projections are useful during the analysis process, they need to be realistic, achievable and used alongside historical results to provide a comprehensive analysis of a company’s ability to satisfy its debt obligations. A rigorous loan review identifies this issue and prioritizes analysis based on future expectations and demonstrated results, a more reliable indicator of repayment capacity.

Collateral valuation

Many CDFIs rely on market value; however, a strategic loan review emphasizes liquidation value. Market value reflects ideal conditions, while liquidation value provides a more realistic assessment of recoverable collateral in the event of default. It clarifies what the institution can expect to recover if it must seize and sell an asset. Building a culture of sustainable credit risk management.

The final output of this process is a hierarchy of findings that allows a Board to prioritize its response:

  • High Priority: Policy violations that risk loss of principal or legal penalties.
  • Moderate Priority: Issues that deviate from the institution’s own internal practices.
  • Low Priority: Suggestions for adopting industry-wide best practices.

The Board should be actively involved in determining the scope and frequency of internal or external loan reviews. Regular reviews — annually for most, or semi-annually for larger, more complex financial institutions — are essential to catch systemic weaknesses before they become terminal. The scope should focus on the inherent risk of the portfolio as determined by the Board and the Bank’s adopted policy.

Addressing these issues early transforms risk management from a reactive chore into a proactive strategy for long-term impact. Institutions should evaluate whether their risk management framework serves as a true preventive control or simply responds to failures after losses occur.

Learn more about our loan review services here. 

Connect with a Consultant

Contact us to learn more about our consulting services and how we can add value to your financial institution

Ask a Question