Skip to main content

Takeaways from the OCC’s Cybersecurity and Financial System Resilience Report, June 2026

What the OCC’s latest Cybersecurity Report means for community financial institutions

Cybersecurity has entered a new phase for community banks. Artificial intelligence is giving threat actors new capabilities. Banks increasingly depend on interconnected third parties. Regulators expect institutions to identify and escalate significant incidents quickly. At the same time, emerging technologies are forcing financial institutions to consider risks that may not fully materialize for years.

The OCC’s June 2026 Cybersecurity and Financial System Resilience Report reinforces an important message for community financial institutions (CFIs): cybersecurity can no longer function primarily as an IT responsibility or periodic compliance exercise. It has become an operational resilience issue.

For community banks, that distinction matters. Most institutions cannot match the cybersecurity budgets or staffing levels of the nation’s largest banks, nor do regulators necessarily expect them to. They do, however, expect institutions to understand their risks, establish appropriate controls, manage critical dependencies, prepare for disruptions, and demonstrate that they can respond and recover when something goes wrong. Five developments deserve particular attention from community bank executives and boards in 2026.

1. AI has changed the economics of cybercrime

Community banks should no longer assume their size makes them less attractive to cybercriminals. Historically, attackers often had to devote significant time and resources to reconnaissance, vulnerability identification, social engineering, and attack development. That created an economic incentive to concentrate efforts on potentially lucrative targets. AI changes that calculation.

Threat actors can increasingly automate portions of the attack process, allowing them to identify vulnerabilities, develop convincing social engineering campaigns, and target organizations at greater scale.

As the OCC warns:

“The use of AI can enable automated reconnaissance, rapid vulnerability discovery and exploitation, targeted social engineering, and adaptive malware that can evade traditional security defenses.”

For community banks, the important issue is not whether a cybercriminal specifically selects your institution. Increasingly, they may not need to. Automated tools can search broadly for vulnerable systems, exposed credentials, misconfigurations, and other opportunities. A community bank can become a target simply because an exploitable weakness exists.

Adapting to the changes

Banks should evaluate their cybersecurity programs with this new reality in mind.

Traditional controls remain essential, but institutions should also ask whether those controls can respond to threats operating at greater speed and scale. Vulnerability management, multifactor authentication, access controls, endpoint protection, employee education, network monitoring, and timely patching become even more important when attackers can automate portions of the discovery and exploitation process.

The question is shifting from “Why would someone target us?” to “What would an automated attacker find if it looked?” That is a much more useful question for management and the board to ask.

2.The 36-hour clock makes preparation essential

When a significant cyber incident occurs, community banks may have very little time to determine their regulatory responsibilities.

Under the Computer-Security Incident Notification Rule, a banking organization must notify its primary federal regulator as soon as possible and no later than 36 hours after determining that a notification incident has occurred.

The key word is determining. Banks do not need to complete an investigation or understand every technical detail before the clock begins. Once the institution determines that an incident meets the notification threshold, the regulatory timeline applies. That makes internal escalation critical.

A bank that spends valuable hours determining who has authority to make decisions, locating regulatory contacts, debating notification thresholds, or waiting for complete forensic information can quickly lose much of its available response window.

Third-party incidents create another challenge. Bank service providers must notify affected banking organization customers as soon as possible when certain computer-security incidents cause, or are reasonably likely to cause, a material service disruption or degradation for four or more hours.

An incident response plan should work at 2:00 a.m. on a Sunday — not just look complete during an annual review.

Banks should clearly establish:

  • Who receives the first internal notification.
  • Who determines whether an event qualifies as a notification incident.
  • Who has authority to contact the regulator.
  • Who contacts customers, vendors, law enforcement, insurers, legal counsel, and other stakeholders when necessary.
  • Who assumes those responsibilities when primary personnel are unavailable.
  • Where current contact information, procedures, and notification templates reside.

Institutions should also test those decisions through tabletop exercises. The middle of a cyber incident is the wrong time to discover that your incident response plan depends on assumptions no one has tested.

3. Third-party risk has become cybersecurity risk

Community banks increasingly rely on third parties to provide technology and expertise they could not efficiently maintain internally.

That model creates tremendous value, but it also creates interconnected risk. Core processors, cloud providers, fintech platforms, managed service providers, payment systems, software vendors, telecommunications providers, and other partners can become part of the institution’s attack surface.

Cybercriminals recognize the opportunity. Compromising one widely used provider can potentially give an attacker access to, or disrupt services for, many institutions simultaneously. The OCC continues to emphasize effective management of these relationships, particularly when third parties support critical or higher-risk activities. As the report states:

“Effective risk management of third-party relationships — especially those that support higher-risk and critical activities — is important for safe and sound operations.”

Community banks should move beyond asking, “Did we complete our vendor due diligence?”

The more important questions are:

  • What happens to our bank if this vendor fails?
  • How quickly would we know?
  • What alternatives do we have?
  • How long could we operate without them?

That requires institutions to understand not only individual vendor risk but also operational dependency and concentration risk.

A strong third-party risk management program should identify which providers support critical activities, evaluate contractual protections, monitor changes in vendor risk, understand subcontractor dependencies when appropriate, establish escalation procedures, and develop realistic contingency plans.

Vendor management should not operate separately from business continuity, cybersecurity, and enterprise risk management. These disciplines increasingly describe different dimensions of the same risk.

4. Post-quantum risk belongs on the strategic technology agenda

Quantum computing may not represent an immediate operational threat for most community banks, but institutions should begin considering its long-term implications.

One concern is the “harvest now, decrypt later” approach. Threat actors can collect encrypted information today and retain it in anticipation that future quantum capabilities could eventually allow them to decrypt it. That creates an unusual cybersecurity problem: information protected adequately today may remain sensitive long enough for the technology protecting it to become obsolete.

For community banks, the appropriate response is not panic or an immediate overhaul of cryptographic systems. It is awareness and preparation.

Banks should begin discussing post-quantum readiness as part of long-term technology planning. An appropriate first step is understanding where cryptography exists throughout the institution.

Which systems protect sensitive information through encryption? Which vendors control those technologies? How long must the bank protect the underlying data? What plans do key technology providers have for adopting new cryptographic standards?

These questions can help institutions work toward crypto-agility, the ability to replace or update cryptographic technologies as standards evolve without requiring disruptive, last-minute system changes.

For most community banks, post-quantum readiness is not a 2026 implementation project. It is a 2026 planning conversation.

5. Digitalization requires risk management to keep pace

Community banks face a difficult balancing act. Customers increasingly expect convenient digital experiences.

Banks need technology to operate efficiently and compete effectively. New fintech relationships can provide capabilities that once required significant internal investment. But every new technology can also introduce new dependencies, data flows, access points, vendors, and operational risks.

The OCC’s focus on community bank digitalization reflects this tension. Its May 2025 Request for Information examined the challenges community banks face when adopting and implementing digital technologies.

The message should not discourage community banks from innovating. Instead, it should encourage institutions to make sure their governance and risk-management capabilities evolve alongside their technology. Digital strategy and risk strategy can no longer operate on separate tracks.

Before implementing significant new technology, management should understand:

  • What data the technology accesses and where that data resides.
  • Which third parties support the service.
  • How the bank will control and monitor access.
  • What happens if the technology becomes unavailable.
  • How the institution will exit or transition from the provider if necessary.
  • Whether existing cybersecurity, business continuity, compliance, and vendor-management programs adequately address the new risks.

Resources such as the Cybersecurity Supervision Work Program (CSW), Third-Party Risk Management: A Guide for Community Banks, and the OCC’s community bank digitalization resources can help institutions evaluate those questions.

The goal should not be to eliminate technology risk. That is impossible. The goal is to understand the risk well enough to make informed decisions about where and how the institution accepts it.

From cybersecurity compliance to operational resilience

The most important takeaway from the OCC’s cybersecurity report may not involve any individual technology or regulatory requirement. It is the broader shift in how banks should think about cybersecurity.

For years, institutions have devoted significant attention to preventing cyber incidents. Prevention remains critical, but prevention alone cannot define a mature cybersecurity program.

Banks must assume that systems can fail, vendors can experience outages, employees can make mistakes, credentials can become compromised, and sophisticated attackers may occasionally penetrate even strong defenses. The question then becomes: What happens next?

  • Can the institution identify the problem quickly?
  • Can management make decisions without unnecessary delay?
  • Can the bank maintain critical operations?
  • Does everyone understand their responsibilities?
  • Can the institution communicate effectively with regulators, customers, vendors, and other stakeholders?
  • Can it restore operations safely?
  • And after the incident, can the bank identify what went wrong and strengthen its controls?

Those questions define operational resilience.

What community bank leaders should do now

Community bank executives and boards do not need to respond to every emerging cyber threat by purchasing another technology solution. In many cases, the more valuable first step is determining whether the institution’s existing cybersecurity program works as intended. That means testing — not simply documenting — key capabilities.

At Young & Associates, we work with community financial institutions every day, and we understand the challenge: banks must respond to increasingly sophisticated risks without unlimited staff, budgets, or time.

The answer is not to build the cybersecurity program of a global bank. It is to build a program that appropriately reflects your institution’s size, complexity, technology environment, risk profile, and critical operations — and then verify that it works. When a cyber incident occurs, the strength of the program will not be measured by the policies sitting on a shelf. It will be measured by how effectively your institution responds.

Explore our suite of IT consulting services:


Source: OCC Cybersecurity and Financial System Resilience Report, 2026

Five human-smuggling indicators financial institutions should understand

The $4.9 billion financial footprint of human smuggling

The Financial Crimes Enforcement Network (FinCEN) has released a critical Financial Trend Analysis (FTA) examining Bank Secrecy Act (BSA) data from January 1, 2023 through December 31, 2025. This review period uncovered a massive $4.9 billion in suspicious activity linked to human smuggling — a sophisticated, multi-billion-dollar enterprise often controlled by Transnational Criminal Organizations (TCOs) like Mexico-based cartels. While total reports saw a 62% decline in 2025 (dropping from 29,266 in 2024 to 11,018 in 2025), the financial volume remains immense, highlighting the persistent role of the formal financial system in border security.

For Community Financial Institutions (CFIs), the most vital metric is the “Impact Gap.” While Money Services Businesses (MSBs) file 97% of all reports, Depository Institutions handle 61% of the total suspicious dollar value ($3 billion). Your institution must prioritize the analysis of these high-value flows: the average transaction amount for depository institutions is approximately $1.5 million, compared to the MSB average of just $7,961. This represents an 188x difference in risk-per-transaction, placing a disproportionate responsibility on CFIs to detect the high-value consolidation and exit points of smuggling networks.

Core metrics (2023–2025 review period)

  • Total BSA Reports Analyzed: 67,540
  • Total Suspicious Dollar Value: $4.9 Billion
  • Depository Institution Share of Value: $3 Billion (61% of total)
  • 2024 Report Volume: 29,266 (Peak year)
  • 2025 Report Volume: 11,018 (62% decline from peak)

Dismantling these networks begins with recognizing the specific behavioral patterns, or indicators, found in recent BSA data.

Indicator 1: Unverifiable relationships and originator-beneficiary mismatch

The lack of a logical or verifiable relationship between parties is the most prevalent red flag in human smuggling. Granular MSB data indicates that 57% of filings cited “no verifiable familial connection” as the primary reason for suspicion. CFIs should use this MSB-specific benchmark to calibrate their own monitoring; when U.S.-based customers send funds to unrelated third parties in high-risk jurisdictions, it frequently signifies a payment to a professional smuggler or the payment of a “piso“— a territorial tax collected by cartels for safe passage through controlled corridors.

The data reveals a specific pattern where U.S.-based foreign nationals use foreign-issued IDs to send money to friends or relatives. In approximately 7% of cases, customers explicitly admitted the funds were intended for smuggling. Compliance officers must scrutinize transactions where there is no clear familial or business nexus, particularly when the subject’s identification suggests a temporary presence in the United States.

Indicator 2: The proliferation of funnel accounts and aggregated P2P transfers

Human smuggling networks have strategically shifted toward using depository accounts as funnels to collect small-dollar payments from diverse sources. This typology bypasses traditional familial checks by using multiple, seemingly unrelated originators to fund a single beneficiary’s account.

A specific case study identifies a high-risk pattern: one account received small-dollar peer-to-peer (P2P) transfers from 30+ different senders between March and July 2023, totaling $68,000. The subject systematically transferred incoming funds to a separate savings account before executing the exit through structured cash withdrawals.

Warning Sign: Your institution must flag accounts with high-volume P2P activity that contradicts the customer’s stated occupation, followed by structured cash withdrawals at branch or ATM locations designed to stay below reporting thresholds.

Indicator 3: Strategic geographic deviations and migration route alignment

Smuggling activity follows international and domestic corridors that extend far beyond the Southwest border. “Geographic Deviation” occurs when account activity occurs far from a customer’s residence or in states like Minnesota and North Dakota. For Northern border CFIs, a specific tactical red flag involves the exchange of Canadian dollars for U.S. dollars, followed by P2P transfers to individuals previously linked to alien smuggling.

Strategic deviations also include international transit routes, such as the UAE-to-Nicaragua flight route, where Nicaragua serves as a disembarkation point for migrants continuing to the U.S. border by land.

High-risk jurisdictions for smuggling activity

Top U.S. States Top Latin American Countries Critical Cities
Texas (TX) Mexico Ciudad Juarez, MX
California (CA) Guatemala Villahermosa, MX
New York (NY) Honduras Tapachula, MX
Florida (FL) Colombia Monterrey, MX
New Jersey (NJ) Guatemala City, GTM
Houston, TX, USA

Indicator 4: Excessive cash activity and structuring in border jurisdictions

Cash is the primary medium for paying piso taxes and local facilitators. TCOs utilize structured withdrawals, keeping amounts just below reporting thresholds, at multiple ATM and branch locations along the U.S.-Mexico border to evade BSA oversight.

CFIs must be alert to high-volume cash activity in accounts belonging to individuals in non-cash-intensive industries. A striking example involves a “student” and a “produce company owner” in Arizona (Nogales and Phoenix) who made $195,000 in unusual cash deposits. These funds sourced debit card transactions for $30,000 in tactical equipment, including thermal binoculars and night vision attachments. The link between “Unusual Cash Deposit ➡ Debit Purchase ➡ Tactical Gear” is a direct indicator of logistical support for smuggling operations.

Indicator 5: Exploitation of travel agencies and “sham” operations

Smuggling networks exploit travel arrangements (flights, buses, hotels) for the “last mile” of the journey. CFIs are uniquely positioned to see the back-end of these operations, which often involve sham travel agencies or legitimate businesses acting as unwitting facilitators.

A recent case involved a Florida-based travel agency and chartered flights from the UAE to Nicaragua. CFIs should monitor for these three high-risk behaviors in travel agency accounts:

  1. Funding Anomalies: Excessive cash deposits at border ATMs (e.g., $150,000+) that serve as the primary source of funding.
  2. Lack of Operating Expenses: The total absence of traditional payroll activity or standard business overhead.
  3. Booking Discrepancies: Large-scale airline refunds or P2P transfers from individuals appearing to pay for “visa services” that fund bulk airline ticket purchases for unrelated groups.

Operationalizing intelligence for community financial institutions

Human smuggling is a multi-billion dollar enterprise that presents concentrated financial risks to the banking sector. While report volumes have declined, the “Impact Gap” confirms that depository institutions remain the primary vehicles for high-value illicit transfers. Your institution’s role in identifying these patterns is critical to dismantling the financial infrastructure of TCOs.

CFI compliance action checklist

  • Apply Key Technical Term: You must use the term “FIN-2023-HUMANSMUGGLING” in the narrative of all relevant BSA filings; this is the single most important technical requirement for law enforcement data aggregation.
  • Audit P2P Aggregation: Review accounts receiving frequent transfers from 30+ unrelated originators, particularly those with a consolidation-to-savings pattern.
  • Monitor Geographic Shifts: Flag activity in migration corridors (Southwest and Northern borders) that deviates from the customer’s residence, including Canadian currency exchanges.
  • Verify Business Profiles: Ensure cash-intensive activity aligns with stated occupations, specifically auditing travel agencies for the absence of payroll.
  • Logistical Screening: Review high-value debit purchases from tactical or thermal gear suppliers when sourced by unusual cash deposits.

BSA data remains the most valuable tool for law enforcement to follow the money and dismantle the networks profiting from human exploitation.

Strengthen your BSA/AML/CFT compliance program

Protect your institution from evolving financial crime risks with a strong, effective compliance program. Young & Associates provides experienced compliance consulting and advisory services to community financial institutions, including BSA/AML/CFT and OFAC reviews, AML model validation, and comprehensive compliance support.

Contact Young & Associates today to strengthen your BSA/AML compliance program and address emerging risks with confidence.


Source: Financial Crimes Enforcement Network (FinCEN), Human Smuggling: 2023–2025 Threat Pattern & Trend Information, Financial Trend Analysis, August 2026.

View the full FinCEN Financial Trend Analysis

Takeaways from the NCUA Deregulation Project

For years, credit union leaders have navigated the dense thicket of the 12 CFR, often grappling with a “compliance fatigue” that stifles innovation. Balancing operational growth against a rigid and complex regulatory framework has felt like a zero-sum game. However, the regulatory weight is beginning to lift.

Spurred by the catalyst of 
Executive Order 14192 (“Unleashing Prosperity Through Deregulation”), the National Credit Union Administration (NCUA) is currently executing a massive, multi-year “Deregulation Project.” Phase One (2025–2027) is focused on modernizing the agency’s framework by identifying rules that are obsolete, duplicative, or overly burdensome. For the strategic credit union leader, this represents a shift toward a more principles-based supervisory environment.

The end of the client-customer automatic bar

One of the most significant shifts involves proposed changes to 12 CFR 701 (Appendix B) regarding associational common bonds. Historically, the NCUA maintained an “automatic bar” against groups primarily based on a client-customer relationship. If joining an association required the purchase of a product or service, such as an insurance policy, the group was automatically disqualified from Field of Membership (FOM) eligibility.

The new proposal moves from an automatic bar to a process of further evaluation. The NCUA Board has determined that a product purchase requirement is no longer a hard no. Instead, the agency will evaluate if the client-customer relationship is merely incidental to the group’s broader activities. This shift to a holistic evaluation opens significant new doors for FOM expansion, allowing credit unions to partner with associations they previously would have ignored.

Flexing senior management compensation

In a competitive labor market, attracting and retaining high-level talent is vital for institutional resiliency. However, the NCUA’s historical blanket prohibition on loan-related compensation has been a major pain point, often suffering from varying interpretations and inconsistent enforcement across the NCUA’s different regions.

Proposed changes to 12 CFR 701.21(c)(8) seek to resolve this confusion. By adding a formal definition of “overall financial performance,” the rule would explicitly permit credit unions to offer incentives and bonuses to employees, including senior management, that incorporate lending metrics. As long as these metrics are part of a broader evaluation of the institution’s financial health, the NCUA now views this as a critical tool for recruitment rather than a hurdle.

Removing prescriptive training deadlines

Volunteer boards are the lifeblood of the credit union movement, but prescriptive mandates can deter community members from serving. Currently, 12 CFR 701.4(b)(3) mandates that every director attain a “working familiarity” with finance and accounting within six months of election or appointment.

The NCUA is now proposing to eliminate this rigid six-month deadline. While the agency continues to hold the core expectation that directors possess financial expertise, it admits the current rigid clock is “unduly burdensome” and can “undermine the ability of a credit union’s members to elect their board.” This is a clear win for community representation: the requirement for competence remains, but the arbitrary training clock is being dismantled.

Lifting the caps on third-party auto servicing

Effective September 8, 2026, a final rule will remove the restrictive caps previously found in 12 CFR 701.21(h). In the past, credit unions were capped at 50% of their net worth for indirect auto loans serviced by third parties, only reaching 100% after 30 months of experience with a specific servicer.

By removing these prescriptive limitations, the burden of risk management shifts from federal mandates to the board’s own risk tolerance. This allows institutions to manage liquidity and portfolio diversity based on their unique needs rather than a one-size-fits-all cap.


“With today’s announcement, we are moving forward on our commitment to removing regulations that are obsolete, burdensome, duplicative, or simply guidance that has no place in regulation. Our goal is to make it easier for credit unions to serve their members, meet compliance requirements, and stay innovative. These final rules and those that come after will give credit unions the flexibility to do just that.” — Chairman Kyle Hauptman

The guidance vs. regulation cleanup

A key pillar of this project is ensuring that non-binding guidelines are not misinterpreted as enforceable law. The NCUA is stripping several “Appendices” out of the Code of Federal Regulations and moving them into “Letters to Credit Unions.” This cleanup clarifies that guidance should be followed as best practice, but it is not independently enforceable.

Key areas moving out of the CFR into guidance include:

  • Safeguarding Member Information: Moving the standards for protecting the security of records (formerly 748 Appendix A).
  • Response Programs: Moving the guidance for responding to unauthorized access to member data (formerly 748 Appendix B).
  • Voting Guidelines: Moving the non-binding suggestions for obtaining fair votes during conversions (found in 12 CFR 708a).

Modernized catastrophic reporting

During a crisis, management should focus on stabilizing operations, not filling out forms. To reflect this, the NCUA is modernizing 12 CFR 748.1(b).

The reporting window for catastrophic acts is being increased from 5 business days to 15 calendar days. Furthermore, in a significant procedural shift, reports are now to be made directly to the NCUA rather than the Regional Director. This centralizes the reporting process and gives credit unions the necessary breathing room to manage emergency conditions before worrying about regulatory paperwork.

A new era of safety and soundness

The Deregulation Project represents a fundamental pivot in the NCUA’s philosophy. By categorizing rules as Obsolete, Duplicative, Overly Burdensome, or Guidance, the agency is attempting to prioritize relief that actually impacts daily operations.

While this signals a move toward principles-based supervision, do not expect exams to be less rigorous. The focus remains squarely on safety and soundness, but with a renewed respect for the business judgment of credit union boards.

Note: Credit unions must continue to follow all existing regulations as they currently appear in the Code of Federal Regulations until the relevant Final Rules are officially effective. For help navigating regulatory compliance, learn more about Y&A’s compliance consulting services.

Y&A Credit Services launches asset-based lending field exam services

Y&A Credit Services, a full-service provider of outsourced underwriting services and credit analysis, announced the launch of its asset-based lending (ABL) field exam services. The service is designed to help financial institutions confidently manage asset-based lending relationships, strengthen risk management practices, and support portfolio growth with experienced, independent field exam expertise. 

“Asset-based lending can create valuable growth opportunities for community financial institutions, but it also requires a disciplined approach to collateral monitoring and risk management,” said Oliver Sutherin, principal of Y&A Credit Services. “Our ABL Field Exam Services are designed to give lenders greater visibility into collateral quality, borrower operations, and portfolio risk so they can make informed decisions with confidence. We strive to help institutions grow strategically while maintaining strong credit administration practices.” 

Each field exam may include: 

  • Verification and analysis of accounts receivable — aging schedules, eligibility testing, dilution trends, and concentration risk across the borrower’s customer base  
  • Inventory testing and valuation review — roll-forward analysis, eligibility criteria, obsolescence exposure, and physical verification against reported values  
  • Borrowing base validation — reconciliation of the calculated base to loan balances, confirming advance rates and eligible collateral are applied correctly  
  • Collateral monitoring assessments — UCC filing and lien priority review, insurance coverage confirmation, and ongoing collateral adequacy relative to outstanding advances  
  • Review of operational controls and reporting practices — evaluation of cash receipts handling, AP aging integrity, and the borrower’s internal reporting discipline 
  • Identification of risk trends, reporting inconsistencies, and exceptions — financial trend analysis, GL tie-out testing, and documented exceptions with recommended remediation  
  • Independent reporting for lending and credit administration teams — a structured exam summary covering scope, findings, and risk conclusions to support credit decisioning 

The new offering aligns with Y&A Credit Services’ broader mission of helping community financial institutions improve operational efficiency, overcome staffing challenges, and enhance credit risk management through outsourced expertise. With the addition of ABL field exam services, Y&A Credit Services now offers a comprehensive suite of commercial credit support services, including underwriting package reviews, annual underwriting reviews, financial statement spreading and analysis, and credit administration support. 

To support its ABL field examination services, Y&A Credit Services employs credit analysts who have earned Commercial Banking & Credit Analyst certifications from the Corporate Finance Institute® (CFI). Their training strengthens their expertise in financial modeling, loan security analysis, and industry analysis for ABL field examinations. 

ABL field exam services are available now. To learn more, visit Y&A Credit Services or call 1-800-525-9775. 

About Y&A Credit Services

Y&A Credit Services provides commercial underwriting and specialty credit services to financial institutions nationwide. Founded in 2022, Y&A Credit Services operates as an independent entity while delivering the same expertise, service, and integrity associated with Young & Associates. Both organizations help financial institutions navigate regulatory challenges and position themselves for growth. 

Learn more at Y&A Credit Services. 

Risk assessment is the BSA key

By William J. Showalter, CRCM; senior consultant, Young & Associates

Your bank has an opportunity to frame your next Bank Secrecy Act/Anti-Money Laundering/Countering the Financing of Terrorism (BSA/AML/CFT) examination – much as you do your Community Reinvestment Act (CRA) exam by preparing a summary of the “performance context” within which you operate.

The agencies state that a well-developed BSA/AML/CFT risk assessment assists the bank in identifying money laundering, terrorist financing, and other illicit financial activity risks and in developing appropriate internal controls – policies, procedures, and processes. Understanding its risk profile enables the bank to better apply appropriate risk management processes to the BSA/AML/CFT compliance program to mitigate and manage risk and comply with BSA regulatory requirements. The BSA/AML/CFT risk assessment process also enables the bank to better identify and mitigate any gaps in controls.

Risk-focused exam process

The interagency examination procedures provide that the extent of BSA/AML/CFT examination activities necessary to assess the bank generally depends on the bank’s risk profile and the quality of risk management processes to identify, measure, monitor, and control risks, as well as to report potential money laundering, terrorist financing, and other illicit financial activity. Given that banks vary in size, complexity, and organizational structure, the agencies acknowledge that each bank has a unique risk profile, and the scope of a BSA/AML/CFT examination varies by bank.

The first step in a BSA/AML/CFT examination is a scoping and planning process. At this preliminary stage of the activity, examiners analyze existing information about the bank – off-site monitoring information, previous examination reports and workpapers, BSA-reporting databases, other communications with the bank, and independent reviews or audits. Examiners also scrutinize request letter items completed by bank management and, perhaps most important in some ways, the bank’s BSA/AML/CFT risk assessment.

BSA examiners are charged to determine the BSA/AML/CFT risk profile of the bank as a part of the scoping and planning process. The preferred method for accomplishing this goal centers on a review of the bank’s risk assessment. While banks are not required to perform such an assessment, it is central to ensuring that a BSA/AML/CFT program is appropriate for the bank, given its product and customer mix, as well as location risk factors. The agencies consider that an effective risk assessment should be a composite of multiple factors, and depending on the circumstances, certain factors may be weighed more heavily than others.

The information contained in the BSA/AML/CFT risk assessment assists examiners in developing an understanding of the bank’s risk profile, risk-focusing the examination scope, and assessing the adequacy of the bank’s overall BSA/AML/CFT compliance program and its compliance with BSA regulatory requirements.

Examiners are directed to focus, when evaluating the bank’s BSA/AML/CFT risk assessment, on whether the bank has effective processes resulting in a well-developed risk assessment. They are not to take any single indicator as determinative of the existence of a lower- or higher-risk profile for the bank. Any assessment of risk factors is bank-specific, and a conclusion regarding the bank’s risk profile is to be based on a consideration of all pertinent information.

Examiners are to assess whether the bank has developed a BSA/AML/CFT risk assessment that identifies its money laundering, terrorist financing, and other illicit financial activity risks. Examiners are also to assess whether the bank has considered all its products, services, customers, and geographic locations in its assessment, and whether the bank analyzed the information relative to those risk categories.

If a bank has not prepared a BSA/AML/CFT risk assessment, or if its assessment is deemed inadequate, the examiner is directed to discuss this fact with management, as well as prepare their own risk assessment. The reason for this emphasis on a bank-prepared risk assessment is that the bank’s BSA/AML/CFT program should be tailored to the risks it faces, and the agencies see an assessment as an important tool to assist the bank in effectively managing BSA risks and critical in developing appropriate internal controls.

Using your risk assessment

An appropriate BSA risk assessment provides the bank with a foundation on which to build a successful compliance program addressing this area. This risk assessment is not a static document. You will have to monitor changes in the bank’s product offerings (e.g., virtual currency-related services), business environment, regulatory changes, bank personnel, and so forth – and make appropriate changes to policy and procedure – to ensure that the foundation remains strong under the bank’s BSA/AML/CFT compliance program.

The agencies expect that the bank will structure its BSA/AML/CFT compliance program to address its risk profile, based on the bank’s assessment of risks, as well as to comply with BSA regulatory requirements. Specifically, the bank should develop appropriate policies, procedures, and processes to monitor and control its money laundering, terrorist financing, and other illicit financial activity risks.

For example, the bank’s monitoring system to identify, research, and report suspicious activity should be risk-based to incorporate any necessary additional screening for higher-risk products, services, customers, and geographic locations as identified by the bank’s BSA/AML/CFT risk assessment.

Also, independent testing (audit) should review the bank’s BSA/AML/CFT risk assessment, including how it is used to develop the BSA/AML compliance program.

Banks that choose to implement a consolidated or partially consolidated BSA/AML/CFT compliance program should assess risk within business lines and across activities and legal entities.

Consolidating money laundering, terrorist financing, and other illicit financial activity risks for larger or more complex banking organizations may assist senior management and the board of directors in identifying, understanding, and appropriately mitigating risks within and across the banking organization.

To understand money laundering, terrorist financing, and other illicit financial activity risk exposures, the banking organization should communicate across all business lines, activities, and legal entities. Identifying a vulnerability in one aspect of the banking organization may indicate vulnerabilities elsewhere.

Conclusion

The importance of a BSA/AML/CFT risk assessment cannot be overstated. A bank-prepared assessment can establish the direction a bank’s BSA/AML/CFT program will take, as well as guiding BSA exams and other reviews/audits. Just as with a CRA performance context, preparing your own BSA/AML/CFT risk assessment can provide the roadmap to guide your compliance – and examiners’ evaluation of your program. And the agencies have given you a roadmap to guide your risk assessment – the BSA/AML/CFT examination procedures. Use it, if you have not already, before the examiners come for their next visit.

Why banks should invest in financial education for their lenders

By Ollie Sutherin, chief financial officer, Young & Associates

Ask a small business owner to name their loan officer, and you’ll usually get one of two answers: a name they remember fondly, or a shrug. The difference often comes down to what happened after the loan closed.

Too often, the relationship ends at funding. The borrower takes the money, and the loan officer goes quiet until another lending opportunity arises or the deal starts to sour. That pattern is so common in our industry that many bankers don’t even recognize it as a problem. But it is a problem, and it’s also a missed opportunity. The loan officer can be far more valuable than a point of contact for money. They can be a source of knowledge and a trusted reference for the small businesses they serve.

The knowledge gap nobody talks about

Community banks live and die by small-business lending, and small businesses are usually run by people who are exceptional at what they do. The contractor knows construction. The restaurateur knows food. The machine shop owner can tell you the tolerances on every part that leaves the floor. What they often do not know, and were never trained to know, are the nuances of bookkeeping, accounting, and tax treatment.

This isn’t a criticism of business owners. It’s simply the reality of how small businesses are built. The owner’s expertise is in their industry, not in debits and credits. Yet their ability to access capital depends almost entirely on how well their financial condition is documented and presented.

That is where the loan officer comes in. The loan officer sits at the bridge between business operations and financial condition. No one else in the borrower’s orbit occupies that position. The CPA sees the books once a year.

The bookkeeper, if there is one, may be a family member doing their best with QuickBooks on weekends. The loan officer, on the other hand, sees the financials in the context of what the business is actually trying to accomplish: growth, equipment, real estate, and working capital. With that vantage point comes not just an opportunity, but an obligation, to assist and educate.

A real-world example

Consider a borrower whose business is genuinely healthy: strong sales, good margins, loyal customers. But when their P&L comes across your desk, you notice they have expensed the principal portion of their loan payments. Their reported income is understated, their balance sheet does not tie, and now your credit department has to spend time untangling something that should have been clean from the start.

A loan officer with solid accounting fundamentals catches that immediately and, more importantly, can explain it to the borrower in plain terms: principal reduces a liability on the balance sheet; only the interest belongs on the income statement. That five-minute conversation does two things. It makes the borrower’s bookkeeping easier going forward, and it makes their true borrowing capacity clearer to the bank. Clearer financials mean faster underwriting, and faster underwriting helps businesses access capital sooner. Everybody wins.

But that conversation only happens if the loan officer knows enough accounting to have it.

The case for investing in training

This is where bank management comes in. Community banks should be making deliberate, ongoing investments in accounting and finance training for their loan officers. Not a one-time orientation, but real education that equips lenders to read, understand, and explain financial statements with confidence. The return on that investment shows up in at least three places.

  • First, better deals reach the credit department. A loan officer who truly understands financial condition knows when a deal is right and when it is not. Requests that should have been declined at the first meeting get declined at the first meeting, instead of consuming hours of analyst time before arriving at the same conclusion. Credit departments at community banks are stretched thin as it is. Lenders who can screen effectively at the point of contact take real strain off the back of the house.
  • Second, complex borrowers get represented accurately. As community banks compete for borrowers closer to the middle market, the financials get more complicated and the questions get harder. Deferred revenue, related-party transactions, owner add-backs, and percentage-of-completion accounting come up constantly with larger borrowers, and credit and loan committees will ask about them. A loan officer who can grasp the financial condition firsthand, ask the right questions of the borrower, and convey the answers clearly to committee is worth their weight in approvals. A loan officer who cannot becomes a relay station for confusion.
  • Third, smaller borrowers get the help they actually need. Many of them are not looking for a sales pitch. They’re looking for assistance, education, and good references. Often a borrower’s financial condition is fundamentally sound; it’s the presentation that’s broken. The lender who can fix that, or point the borrower to someone who can, earns a kind of loyalty that no rate sheet can buy.

Know the tools, share the preferences

Part of being a genuine resource is knowing the resources. Most people in banking can glance at a P&L and recognize which software produced it, and experienced lenders usually have preferences born from years of seeing what comes out clean and what comes out messy. Those preferences should not stay locked in anyone’s head. If a particular accounting platform consistently produces financials that are easy for the borrower to maintain and easy for credit to analyze, say so. Recommend it. Maintain a short list of reputable local bookkeepers and CPAs and hand it out freely.

This costs the bank nothing and makes everyone’s life easier, from the borrower keeping the books to the analyst spreading them.

The payoff

None of this is charity. A borrower who keeps clean books is a borrower whose loan requests move faster, whose covenants are easier to monitor, and whose problems surface earlier, while there is still time to work through them. A loan officer who is a trusted advisor rather than an occasional caller retains relationships through rate cycles and competitive pressure. And a bank known in its community as the place where lenders actually help you understand your business attracts the kind of word-of-mouth referrals that no marketing budget can replicate.

The math is simple. Invest in your loan officers’ financial education, and they will invest it right back into your borrowers. The credit department gets cleaner deals, management gets better profitability, and small businesses get the partner they have been missing. That is community banking at its best.

The “gateway” strategy: Turn a checking account into a long-term customer relationship

By Joseph Ciccolini, content marketing associate, Young & Associates

Marketing often takes a back seat at financial institutions. While many recognize its potential to drive new accounts and attract customers, institutions frequently underemphasize its role as a revenue-generating function. In many cases, the solution already exists but needs to be positioned more effectively: cross-selling, particularly through the “gateway” product that establishes a primary relationship.

For financial institutions, profitability is not just about volume growth but also depth in relationships. Checking accounts provide a natural starting point for building stronger customer engagement, increasing retention, and expanding cross-sell potential.

A 2025 Jack Henry Strategy Benchmark identified top priorities for bank and credit union CEOs, including improving efficiency, driving deposit and loan growth, acquiring new accountholders, and expanding solutions for small and medium-sized businesses. Checking account acquisition directly supports each of these priorities by establishing a primary customer relationship that enables deeper engagement, stronger retention, and increased opportunities for cross-selling.

Consumers typically define their primary financial institution as the one where they hold their primary checking account. That account serves as the gateway to cross-selling opportunities and deeper customer relationships. Primary financial institution relationships are remarkably stable, with customers staying with the bank for an average of eight to 10 years and using five to six products and services per household. Without it, customers are less likely to view the institution as their primary provider. Instead, the relationship resembles the financial equivalent of a secondary streaming service — used occasionally, but not the go-to.

What strategies can institutions use to encourage customers to open a checking account and become primary accountholders? One effective approach is a drip campaign.

Checking Account Stats

What are drip campaigns?

Drip campaigns are a form of email marketing that deliver targeted messages over time to encourage engagement and keep your institution top of mind with customers and prospects. By providing relevant, valuable information, these campaigns guide customers toward action through continuous communication. This approach helps institutions nurture leads and build strong, long-term relationships.

In this context, a drip campaign supports the goal of securing the “gateway” cross-sell in the form of a checking account. Once a customer opens a checking account, the likelihood of becoming a primary accountholder increases significantly, along with opportunities to expand the relationship.

Cross-selling differs from upselling by focusing on complementary products that enhance the customer relationship and increase overall value. The checking account serves as the entry point for this strategy. Once established, institutions can introduce additional products — such as debit cards or certificates of deposit — in a way that aligns with customer needs and behaviors.

Why drip campaigns can outperform cash incentives

Some institutions may already rely on cash incentives to encourage checking account acquisition. However, a 2025 ProSight industry outlook found that only 27 percent of consumers who recently switched institutions cited a cash incentive as the primary reason. Instead, institutions should identify customer needs, understand the challenges they can solve, and promote those solutions effectively.

Drip campaigns play a key role in this strategy by delivering relevant, timely messaging directly to customers. These campaigns help move prospects from consideration to conversion while setting the stage for meaningful interactions.

Gallup’s 2021 retail banking study found that high-quality conversations significantly improve sales conversion rates. When customers initiate the conversation, conversions are 1.6 times more likely compared with low-quality interactions. When employees initiate high-quality conversations, conversions are 4.2 times more likely. Drip campaigns can help prompt these conversations by engaging customers before direct interaction occurs.

Conclusion

Financial institutions should treat checking account acquisition as a critical step in attracting and retaining customers. According to the J.D. Power 2026 U.S. Retail Banking Satisfaction Study, key engagement metrics are beginning to decline as customers increasingly open accounts with multiple institutions. This shift creates a clear opportunity to attract new customers and strengthen relationships through effective cross-selling.

All of this can start with a checking account. Financial institutions should move beyond traditional go-to-market approaches and adopt a marketing-led strategy that prioritizes engagement, not just acquisition. By using tools like drip campaigns to convert and deepen relationships, institutions can turn checking accounts into a foundation for long-term growth and differentiation.

Why your “healthy” portfolio might be a time bomb

By Jerry Sutherin, CEO at Young & Associates

A community development financial institution (CDFI), a mission-driven lender that uses public and private capital to serve underserved communities, can appear healthy on the surface, with steady interest income and consistent growth. Because CDFIs often lend in distressed markets and to borrowers outside the traditional financial system, their portfolios carry unique and sometimes less visible risks. Interest income can mask a weakening foundation of documentation and systemic exposure. Financial history is filled with institutions that appeared stable until hidden vulnerabilities triggered catastrophic deterioration. The difference between sustainable CDFIs and those that fail is not luck. It is the rigor of their internal credit administration.

While front-end underwriting controls risk at origination, institutions must shift to active risk management once a loan is booked. This is where the loan review, an essential but frequently misunderstood strategic tool, serves as your early warning system. It identifies internal weaknesses and “invisible leaks” before they become irreversible financial losses.

Strategic oversight vs. detailed loan file review

In CDFI management, it is critical to distinguish between a high-level portfolio overview and a detailed loan-level audit. While a portfolio review assesses the “big picture,” focusing on geographic, borrower, or other risk concentrations, it cannot replace the granular insights of a loan review.

This assessment is anchored to a specific date, which establishes a clear snapshot of loan quality and ensures findings remain objective. A high-level trend analysis will miss the granular policy deviations that only an individual file examination can reveal.

An independent loan review performs the following functions:

  • Evaluates individual loans and repayment risk.
  • Verifies adherence to internal lending policies and procedures.
  • Identifies gaps in loan file documentation.
  • Communicates high-priority credit risk findings.
  • Recommends actionable improvements to policies and practices.
  • Validates the accuracy of internally assigned risk ratings.

The power of the independent eye

For a loan review to provide strategic value, it must be conducted with objectivity. This requires a strict “independent eye.” Individuals involved in the lending process, including members of the credit committee, should not participate in the review.

Familiarity creates blind spots. Lending staff may overlook a missing document or a policy breach because they “know” the borrower.

Independence also serves as a key control against internal fraud and theft — risks that directly affect a CDFI’s bottom line. Whether utilizing external consultants or internal staff outside the lending function, the goal is to provide the board of directors with objective, unfiltered data on loan quality.

Why paperwork errors are principal risks

CDFI managers often dismiss administrative lapses as routine paperwork. These are technical and legal failures that expose the institution to civil money penalties or the total loss of principal.

A high-priority finding often involves insurance documentation. There is a critical legal distinction between being listed as an “additional insured” versus a “mortgagee.” Missing this distinction means the CDFI is unprotected if the collateral is destroyed.

Other common deficiencies include:

  • Incorrect naming of the CDFI’s role on insurance certificates.
  • Missing documentation of physical inspections of the business or collateral.
  • Failure to implement post-closing follow-up to ensure receipt of all required loan documentation.
  • Having a robust internal exception tracking system where results can be easily conveyed to the board of directors.

These are not just errors— they signal systemic weakness. Additionally, all financial institutions must track the migration of risk ratings as they change. Risk rating changes of 10 percent or more during a loan review indicates systemic issues and warrants a closer review of the Bank’s Allowance for Credit Losses (ACL), their primary safety net.

Judgment and analytical failures: realism vs. optimism

Loan review also addresses lender optimism that can cloud internal analysis. Two common areas of analytical weakness include income projections and collateral valuation.

Income projections

Lenders often rely on projected net income rather than historical performance. While quality projections are useful during the analysis process, they need to be realistic, achievable and used alongside historical results to provide a comprehensive analysis of a company’s ability to satisfy its debt obligations. A rigorous loan review identifies this issue and prioritizes analysis based on future expectations and demonstrated results, a more reliable indicator of repayment capacity.

Collateral valuation

Many CDFIs rely on market value; however, a strategic loan review emphasizes liquidation value. Market value reflects ideal conditions, while liquidation value provides a more realistic assessment of recoverable collateral in the event of default. It clarifies what the institution can expect to recover if it must seize and sell an asset. Building a culture of sustainable credit risk management.

The final output of this process is a hierarchy of findings that allows a Board to prioritize its response:

  • High Priority: Policy violations that risk loss of principal or legal penalties.
  • Moderate Priority: Issues that deviate from the institution’s own internal practices.
  • Low Priority: Suggestions for adopting industry-wide best practices.

The Board should be actively involved in determining the scope and frequency of internal or external loan reviews. Regular reviews — annually for most, or semi-annually for larger, more complex financial institutions — are essential to catch systemic weaknesses before they become terminal. The scope should focus on the inherent risk of the portfolio as determined by the Board and the Bank’s adopted policy.

Addressing these issues early transforms risk management from a reactive chore into a proactive strategy for long-term impact. Institutions should evaluate whether their risk management framework serves as a true preventive control or simply responds to failures after losses occur.

Learn more about our loan review services here. 

Is your marketing engine a well-oiled machine? Or just a collection of shiny parts?

By Nicole Conrad, director of marketing, Young & Associates

In the current landscape of financial services, community bank marketing leaders are often distracted by the latest “shiny new toys.” From generative AI and complex CRM suites to automated social media engines, the promise of a technological silver bullet is everywhere. Yet, despite these investments, many community institutions still struggle to compete with national banks.

The success of AI tools and digital marketing depends on the strength of the strategy behind them. To compete effectively, you must focus on the fundamentals before layering on advanced technology. Technology can only accelerate the direction you are already headed; if your foundation is weak, technology can exacerbate existing issues and contribute to more severe organizational failures.

A high-performing marketing engine is not a collection of disconnected parts. It is a unified system built to achieve the only goal that matters: long-term, profitable customer loyalty.

Revisiting your institution’s marketing basics

Digital marketing and AI implementation depend on the strength of your underlying strategy. Investing in marketing software without a clear plan can waste capital and human resources. To diagnose the health of your marketing engine, you should audit your marketing foundation against three questions:

  • Who is our target? Have we identified the specific segments that view us as a primary partner, or are we casting a net so wide it catches nothing?
  • What is our value? Is our value proposition strong enough to overcome the inertia of switching, or are our products too complex for our own staff to explain?
  • Where is the trust? Are we deploying our message through channels the consumer actually engages with and trusts?

Without these answers, technology cannot bridge the gap between a bank and its customers. Marketing only generates ROI when the right message reaches the right person at the right time.

The right person: Humanizing your brand through buyer personas

Understanding your target audience requires stepping outside your role as a banker and seeing the experience from their perspective. Today’s consumer is not just looking for a transaction; they want to feel an authentic human connection and see their own identity reflected in the brands they choose.

This is where buyer personas come in. A buyer persona is a fictionalized version of your ideal account holders based on demographic data and qualitative research into their goals and concerns.

Buyer personas may include:

  • Demographics, such as age and gender, location, economic status, and marital or family status.
  • Qualitative drivers, such as goals, pain points, concerns, and desired outcomes.
  • Behavioral habits and preferences, such as media consumption, banking habits, and technical expectations.

Your buyer personas should evolve with consumer preferences and the digital landscape. When you know exactly who the customer is, you can stop the “shotgun approach” and meet them at the right time with a message that resonates. This allows you to tap into a “consciousness of kind” — that intrinsic understanding that your bank and its customers belong to the same community and share the same values.

For the community bank, humanizing the brand is a competitive advantage. National banks have three times as many customers per branch compared to the average community institution. This density forces them into cold, numbers-driven business models. You have the capacity to treat customers as people, and this is nonnegotiable in today’s market.

According to Salesforce’s State of the Connected Customer report, 84% of customers say being treated like a person, not a number, is very important to winning their business.

By deeply understanding who your customer is, you move from being a commodity to being a neighbor. Knowing the persona helps you predict the right time to connect, meeting the customer where they are in their decision-making journey. If you don’t know who you are talking to, don’t be surprised when no one listens.

The right time: Understanding the buyer’s journey

We are seeing a fundamental shift from outbound, interruptive marketing to inbound, helpful marketing. Inbound marketing focuses on being where the consumer is with the answers they need. The buyer’s journey supports this approach by nurturing the relationship, so the message evolves as the customer moves through each touchpoint.

The buyer’s journey is the process a person goes through before they open an account or sign a loan. It typically consists of three core stages:

  • Awareness: The individual recognizes a financial problem or need.
  • Consideration: The individual researches various solutions and providers.
  • Decision: The individual selects a specific institution.

Mapping this journey is vital because banking is not an impulse purchase. Market data confirms that most banking shoppers begin their research two to three months before they switch institutions. This “invisible” phase is where banks may lose prospects by trying to close the sale too early.

To be successful, you must nurture them through various touchpoints, from helpful blog posts and social media tips to personalized emails and direct mail. The right message will change depending on where they are in this journey; you wouldn’t offer current car loan rates to someone who is just starting to save for their first vehicle.

The right message: Building your messaging matrix

Once you have your personas and their journeys mapped, you can build a strong messaging matrix. This combines your unique value propositions (UVPs) with the specific needs of each persona at each stage of the journey. The primary goal of a messaging matrix is to solve the difficult challenge of getting the right message to the right person at the right time.

Start with a basic messaging guide. Create a grid that crosses your personas with the stages of their journey. For each intersection, determine which UVP best solves that persona’s problem at that specific time.

Example: An “Awareness” message for a first-time homebuyer might focus on “Can I afford a house?” whereas a “Decision” message would focus on your specific loan application tips and competitive rates.

By mapping messages to specific audience needs, the bank provides content that is meaningful to the consumer’s current situation and avoids burdening people with irrelevant content.

Documented messaging provides staff and brand advocates with a custom-made set of points that capture the heart of the brand. This prevents the brand voice from becoming diluted or fragmented across different channels. This guide offers a straightforward approach to educating employees and reinforcing consistent marketing messaging throughout your organization, transforming your workforce into brand advocates.

A high-performing marketing engine is not a marketing task; it is a core organizational strategy. It requires executive buy-in, strong execution in the branches, and a marketing team that knows how to drive traffic to both digital and physical locations.

AI and digital tools have changed the speed of the race, but not the rules. These tools amplify what already exists: a strong strategy becomes stronger, and a fragmented strategy becomes weaker. If your foundation is built on the right message, the right person, and the right time, technology can help you take you to the finish line. If not, no amount of shiny parts will save you.

We would welcome a conversation to discuss your institution’s business and marketing strategy and be happy to help build out your strategy. Learn more about our strategic planning services here. 

The key to compliance success – accountability

By William J. Showalter, CRCM; senior consultant, Young & Associates

The financial industry recognizes compliance as a high-risk function. Failure to manage it effectively can result in high costs to an institution, as witnessed by many supervisory enforcement actions and fair lending settlements over the years.

Compliance management is an important element of an institution’s overall risk management efforts. It makes sense for line managers—those whose operations generate either compliance or noncompliance—to “own” compliance, just as they do all other elements of the institution’s overall risk. To make compliance management work effectively and efficiently, senior management must give line personnel the tools to succeed at compliance and hold them responsible for their results.

When senior management establishes accountability and all staff believe in it, and when the institution measures compliance performance in a meaningful way, the institution can achieve positive compliance results.

As with other aspects of compliance management, identifying and categorizing levels and types of compliance risks are critical to both efficient operations and effective outcomes in any system of enforcing accountability.

Noncompliance as risk

In recent years, the federal agencies have made a fundamental shift in the way they examine financial institutions for compliance within their overall examination process over a decade ago – to handling it with a risk-based methodology. Examiners design programs to focus attention on areas within financial institutions that may pose the most significant risks, including compliance.

The agencies work to promote a sound risk-management process at each regulated financial institution, one centered on the evaluation and management of risks. The agencies try to help financial institutions implement compliance programs that focus on anticipating, evaluating, managing, and communicating about key compliance risks.

“Compliance risk” means the risk to earnings or capital that arises when institutions violate or fail to conform with laws, rules, regulations, prescribed practices, or ethical standards.

The agencies’ examination procedures provide that compliance risk can damage an institution through any or all of the following consequences:

  • Regulatory or judicial fines and penalties
  • Payments of damages to aggrieved parties
  • Voiding of contracts
  • Diminished reputation
  • Reduced franchise value (due to monetary and reputation losses or penalties)
  • Diminished business opportunities
  • Lessened expansion potential (e.g., when fair lending or Community Reinvestment Act problems delay or disallow corporate changes, mergers, or acquisitions)

The supervisory agencies recognize that an important element in avoiding these risks and their resultant costs is an effective accountability system, where institution staff feel they own their pieces of the overall program.

Establishing accountability

A solid design must form the foundation of an effective accountability system. The system needs a few key elements to succeed: management commitment, appropriate training and communication for all staff, regular and independent performance testing, and consistent enforcement of responsibility.

  • Management commitment. Solid support from both the board of directors and senior management is vital to the success of any compliance (or other) management function. It should also be seen as in their best interests since the risks and penalties for noncompliance are tremendous, and the board and management are the ones ultimately responsible for the compliance (and other) performance of the institution. Management and the board need to understand the true importance of compliance – it is not a job to be relegated to one person, or a small group, and ignored by everyone else. “Everyone else” includes the ones who drive the institution’s compliance performance, and they must be given the tools to succeed at it and be held accountable for their results.
  • Training and communication. Training is the foundation for effective compliance, and effective accountability, since employees cannot be expected to comply with the plethora of laws and regulations that impact banking today if they have not been given appropriate instruction as to what is required of them. In structuring a compliance training program, the first step is a needs assessment – types of products and services offered, current level of staff knowledge, problems identified in audits and examinations, and so forth. The goal of the compliance training is to provide line officers and other staff with the information they need to produce positive compliance results in their particular area or job. It is not to be an exercise in information overload. Therefore, the person in charge of training (whether classroom, online, etc.) needs to scope out the proper laws and regulations to be covered, how to tie these rules in to the institution’s functions, what media and tools to use, and so forth. Communication of compliance information on a regular basis is an important complement to the “regular” training. It helps keep staff aware of changes in the compliance rules and expectations, as well as keeping compliance issues on their “radar screens.”
  • Testing. A good compliance internal review program – both periodic audits and ongoing monitoring – can serve several goals. These include giving an early warning of problems, providing a defense against litigation, and meeting regulatory expectations, in addition to furnishing measurements of department/area or individual performance.
  • Enforcement. Without consistent enforcement of accountability for compliance performance, all the other elements are pretty much for naught. If individual line managers and other personnel are “let off the hook” for poor compliance performance because, for example, of high loan production volume, then the system likely will fail.

Making it work

Human nature being what it is, there need to be incentives for good compliance performance and, perhaps more importantly, disincentives for poor results. If management does not hold all staff to the same standards, then any calls for strong results and performance will ring hollow. Employees who the institution continues to hold to proper standards will begin to resist, since management expects them to meet measures that others do not. Such a “program” is unfair and cannot succeed.

Institutions should factor compliance performance elements into job descriptions, performance evaluations, and incentive pay. It needs to be clear that line managers are ultimately responsible and accountable for compliance performance in their areas, and that compliance is an explicit part of everyone’s job.

If there are line managers who cannot or will not take responsibility for their own or their area’s compliance performance and, therefore, expose the institution to risk, the institution should send them packing and replace them with managers who are positive about compliance issues and willing to take on this important obligation.

Otherwise, the institution has to pay for expensive, redundant processes to check the work of that person(s) or area and fix their errors. Running such a “fix-it” shop is not the efficient route to take in managing compliance. When management establishes and enforces accountability, it can achieve the lowest-cost compliance — compliance embedded in normal operations rather than added on after the fact — with everyone working to get it right the first time.

Management can use an accountability matrix as a tool to run an accountability system. Institutions can customize the matrix to fit their specific situation, structure, and needs. The matrix helps management ensure that someone or some area takes responsibility for each compliance rule or issue that affects its lines of business. It should spell out the rules or issues, who is responsible for them, which areas they impact, and so forth.

Conclusion

Accountability for compliance performance – good or bad – is essential for an institution’s success in effectively managing its compliance function. Properly structured and enforced, a strong accountability program helps ensure cost-effective positive compliance results.

The CFPB and other compliance trends

By Bill Elliott, CRCM; director of compliance education, Young & Associates

The White House announced in April 2025 that its goal was to reduce the number of employees in the CFPB by about 88 percent, to 207 positions, but that decision was blocked by the courts. The decision also resulted in a lawsuit brought by the CFPB employee’s union, but since the “One Big Beautiful Bill Act” cut the CFPB funding by about half, even if the union prevails, it is unlikely that all employees will return to work.

During the first year of the Trump administration, the CFPB removed approximately 70 pronouncements. Many of those were out of date, archaic, and no longer useful. But some of them were protections that were proposed and finalized during the latter days of the Biden administration. However, they were never actually enforced.

Overdraft fees

One form of relief that consumers lost was a limit on overdraft fees. This has been an ongoing discussion for many years. Between those that believe it was unfair that lower income individuals paid the majority of the overdraft fees vs. others who believe that the culprit is financial mismanagement by consumers. The Biden CFPB finalized the overdraft regulation in 2024 but Congress overturned the regulation last year. This effectively eliminated this discussion for now.

Credit cards

The CFPB also tried to cap the amount of money consumers pay to credit card companies for late charges. The proposed limit for many would have been $10. The regulation was blocked by a federal court last year. The CFPB, under the control of the Trump administration, decided not to fight the matter in court.

Stack of paper complaintsLawsuits

The CFPB also withdrew several lawsuits.

We will mention two examples.

  1. The CFPB sued Capital One in January 2025 for $2 billion. They alleged that Capital One has misrepresented the interest rate paid on its savings accounts to customers. That lawsuit was dismissed.
  2. The CFPB also sued Early Warning Systems, the company that runs the money transfer service Zelle, in December 2024 for $870 million alleging that the EWS and the banks that operate Zelle were negligent in protecting consumers from fraud and scams. That lawsuit was also dismissed last year.

Complaints

There has also been a slowdown in the number of complaints resolved by the CFPB. The CFPB runs its own consumer complaint database, where a consumer can allege wrongdoing by their bank or financial services company and the CFPB will act as intermediary between the consumer and financial company to resolve the complaint. Under the Biden CFPB, roughly half of all consumer complaints were resolved with relief for the consumer, while under the Trump CFPB, that figure has dwindled to less than 5 percent, largely due to the staffing issues discussed above.

Compliance examinations

Following the CFPB lead, the prudential regulators (OCC, Federal Reserve, and FDIC) have all indicated (with some differences) that they are going to be changing the methods for compliance examinations. Future examinations will likely be more risk focused.

Since the regulators are going to be more targeted in their approach, they are essentially relying on banks to police other areas of compliance themselves. The examiner will likely spend more time reviewing your compliance program, and especially your compliance audit program, to assure it is functioning appropriately.

Banks must adjust accordingly, and compliance audit will (at least for some banks) need to be improved. Whether your compliance auditor/reviewer is internal or external, you need to assure that you do not get so relaxed that when the regulators do appear, you pay the price of not being properly prepared.

Time between examinations

The time in between examinations is also likely to increase. For the regulators, this will allow them to review banks using fewer examiners.

While that appears to be a “win” for banks, banks need to be careful. For instance, should you receive a “needs to improve” or “substantial noncompliance” CRA rating, you may have to live with the negative consequences of that rating for longer periods of time.

Conclusion

As you’re reviewing your compliance program, assure that all necessary pieces are in place, including compliance review/audit. It is unlikely that there will be many new regulations in the next few years. This should allow bank to ensure that they are in full compliance with the regulations that exist.

The importance of floor plan audits for lending institutions

By Wendy Dancer; consultant, Young & Associates

Auditing your institution’s Floor Plan borrowers can seem like a tedious and time-consuming task. Workload is already heavy, weather is bad and frankly, who has the time to go out and touch hundreds of cars, motorcycles and boats? Your borrower is doing fine… until they are not.

As an example of a cautionary tale, I was personally involved in a Floor Plan audit that “seemed off”. The used car lot dealer was paying off vehicles on the line as expected, when it was discovered that the subject automobiles were still physically on the lot. Then mysteriously, the same autos would get added back to the line a month later. Long story short, the dealer had taken out a 2nd floor plan line with a private finance company. Vehicles were not getting sold; rather, the Floor Plan lines were being treated as a shell game to hide business decline.

This was the red flag that tipped us off on much larger business issues, which sadly ended in the dealership closure and a work-out loan situation for our institution. Below is an overview of why skipping Floor Plan audits is not in your institution’s best interest and a way to avoid the above scenario.

What are floor plan audits?

A Floor Plan audit is a physical verification of financed inventory. Auditors confirm that units pledged as collateral exist, are located where reported, and match lender records in terms of serial numbers, condition, and status (new, used, sold, or in transit). These audits may also include reviews of sales documentation, titles, and payoff activity.

Risk mitigation and collateral protection

Floor Plan lending is essentially asset-based lending. If inventory disappears, is sold out of trust, or is inaccurately reported, the lender’s collateral position is immediately compromised.

Regular audits help:

• Detect missing, sold-out-of-trust, or misrepresented units early
• Verify that financed inventory aligns with borrowing base reports
• Reduce the likelihood of large, undiscovered losses

Early detection is critical. Identifying discrepancies after weeks or months can significantly increase loss severity.

Fraud detection and deterrence

Floor Plan audits act as both a detection mechanism and a deterrent. The knowledge that audits are conducted regularly discourages intentional misreporting, double flooring, or concealment of sales proceeds. Auditors can uncover red flags such as altered VINs, falsified documentation, or repeated delays in payoff—often before fraud escalates.

Portfolio monitoring and credit quality

Audits provide lenders with real-time insight into dealer operations and financial health. Patterns observed during audits—such as chronic shortages, poor recordkeeping, or inventory aging—can signal deeper issues like cash flow stress or operational weakness.

This information allows lenders to:

  • Adjust credit limits or terms proactively
  • Increase monitoring on higher-risk accounts
  • Make informed renewal or exit decisions

In this way, Floor Plan audits serve as an early warning system rather than just a compliance exercise.

Regulatory and policy compliance

Many lending institutions are subject to internal policies, investor requirements, and regulatory expectations related to collateral verification and risk management.

Consistent Floor Plan audits help demonstrate:

  • Sound underwriting and ongoing credit administration
  • Adherence to internal risk management standards
  • Responsible stewardship of depositor or investor funds

Well-documented audits also provide defensible support in the event of disputes, charge-offs, or regulatory reviews.

Strengthening dealer relationships

While audits are often viewed as intrusive, when handled professionally they can strengthen lender-dealer relationships. Clear expectations, consistent audit schedules, and transparent communication help reinforce accountability on both sides. Audits can also surface operational inefficiencies at the dealer level, creating opportunities for corrective action before problems become critical.

Adapting to a changing lending environment

As floorplan portfolios grow more complex—with multi-location dealers, mixed inventory types, and rapid turnover—audits remain one of the few ways to independently validate data. Hybrid and technology-assisted audits now allow lenders to balance thorough oversight with efficiency, making regular verification more practical than ever.

Conclusion

Floor Plan audits are not merely a back-office function. They are a cornerstone of prudent Floor Plan lending. By verifying collateral, deterring fraud, monitoring credit quality, and supporting compliance, audits protect both lenders and their dealer partners. In an environment where inventory values are high and margins can shift quickly, consistent and well-executed floorplan audits are essential to sustainable, profitable lending.


Consistent, independent audits are key to protecting collateral and ensuring sound portfolio management. Young & Associates provides lending process review services to help institutions strengthen oversight and maintain credit confidence. Additionally, Y&A Credit Services provides ABL field exams that give lenders a clear, objective view of collateral strength.

Connect with a Consultant

Contact us to learn more about our consulting services and how we can add value to your financial institution

Ask a Question