Skip to main content

Takeaways from the OCC’s Cybersecurity and Financial System Resilience Report, June 2026

What the OCC’s latest Cybersecurity Report means for community financial institutions

Cybersecurity has entered a new phase for community banks. Artificial intelligence is giving threat actors new capabilities. Banks increasingly depend on interconnected third parties. Regulators expect institutions to identify and escalate significant incidents quickly. At the same time, emerging technologies are forcing financial institutions to consider risks that may not fully materialize for years.

The OCC’s June 2026 Cybersecurity and Financial System Resilience Report reinforces an important message for community financial institutions (CFIs): cybersecurity can no longer function primarily as an IT responsibility or periodic compliance exercise. It has become an operational resilience issue.

For community banks, that distinction matters. Most institutions cannot match the cybersecurity budgets or staffing levels of the nation’s largest banks, nor do regulators necessarily expect them to. They do, however, expect institutions to understand their risks, establish appropriate controls, manage critical dependencies, prepare for disruptions, and demonstrate that they can respond and recover when something goes wrong. Five developments deserve particular attention from community bank executives and boards in 2026.

1. AI has changed the economics of cybercrime

Community banks should no longer assume their size makes them less attractive to cybercriminals. Historically, attackers often had to devote significant time and resources to reconnaissance, vulnerability identification, social engineering, and attack development. That created an economic incentive to concentrate efforts on potentially lucrative targets. AI changes that calculation.

Threat actors can increasingly automate portions of the attack process, allowing them to identify vulnerabilities, develop convincing social engineering campaigns, and target organizations at greater scale.

As the OCC warns:

“The use of AI can enable automated reconnaissance, rapid vulnerability discovery and exploitation, targeted social engineering, and adaptive malware that can evade traditional security defenses.”

For community banks, the important issue is not whether a cybercriminal specifically selects your institution. Increasingly, they may not need to. Automated tools can search broadly for vulnerable systems, exposed credentials, misconfigurations, and other opportunities. A community bank can become a target simply because an exploitable weakness exists.

Adapting to the changes

Banks should evaluate their cybersecurity programs with this new reality in mind.

Traditional controls remain essential, but institutions should also ask whether those controls can respond to threats operating at greater speed and scale. Vulnerability management, multifactor authentication, access controls, endpoint protection, employee education, network monitoring, and timely patching become even more important when attackers can automate portions of the discovery and exploitation process.

The question is shifting from “Why would someone target us?” to “What would an automated attacker find if it looked?” That is a much more useful question for management and the board to ask.

2.The 36-hour clock makes preparation essential

When a significant cyber incident occurs, community banks may have very little time to determine their regulatory responsibilities.

Under the Computer-Security Incident Notification Rule, a banking organization must notify its primary federal regulator as soon as possible and no later than 36 hours after determining that a notification incident has occurred.

The key word is determining. Banks do not need to complete an investigation or understand every technical detail before the clock begins. Once the institution determines that an incident meets the notification threshold, the regulatory timeline applies. That makes internal escalation critical.

A bank that spends valuable hours determining who has authority to make decisions, locating regulatory contacts, debating notification thresholds, or waiting for complete forensic information can quickly lose much of its available response window.

Third-party incidents create another challenge. Bank service providers must notify affected banking organization customers as soon as possible when certain computer-security incidents cause, or are reasonably likely to cause, a material service disruption or degradation for four or more hours.

An incident response plan should work at 2:00 a.m. on a Sunday — not just look complete during an annual review.

Banks should clearly establish:

  • Who receives the first internal notification.
  • Who determines whether an event qualifies as a notification incident.
  • Who has authority to contact the regulator.
  • Who contacts customers, vendors, law enforcement, insurers, legal counsel, and other stakeholders when necessary.
  • Who assumes those responsibilities when primary personnel are unavailable.
  • Where current contact information, procedures, and notification templates reside.

Institutions should also test those decisions through tabletop exercises. The middle of a cyber incident is the wrong time to discover that your incident response plan depends on assumptions no one has tested.

3. Third-party risk has become cybersecurity risk

Community banks increasingly rely on third parties to provide technology and expertise they could not efficiently maintain internally.

That model creates tremendous value, but it also creates interconnected risk. Core processors, cloud providers, fintech platforms, managed service providers, payment systems, software vendors, telecommunications providers, and other partners can become part of the institution’s attack surface.

Cybercriminals recognize the opportunity. Compromising one widely used provider can potentially give an attacker access to, or disrupt services for, many institutions simultaneously. The OCC continues to emphasize effective management of these relationships, particularly when third parties support critical or higher-risk activities. As the report states:

“Effective risk management of third-party relationships — especially those that support higher-risk and critical activities — is important for safe and sound operations.”

Community banks should move beyond asking, “Did we complete our vendor due diligence?”

The more important questions are:

  • What happens to our bank if this vendor fails?
  • How quickly would we know?
  • What alternatives do we have?
  • How long could we operate without them?

That requires institutions to understand not only individual vendor risk but also operational dependency and concentration risk.

A strong third-party risk management program should identify which providers support critical activities, evaluate contractual protections, monitor changes in vendor risk, understand subcontractor dependencies when appropriate, establish escalation procedures, and develop realistic contingency plans.

Vendor management should not operate separately from business continuity, cybersecurity, and enterprise risk management. These disciplines increasingly describe different dimensions of the same risk.

4. Post-quantum risk belongs on the strategic technology agenda

Quantum computing may not represent an immediate operational threat for most community banks, but institutions should begin considering its long-term implications.

One concern is the “harvest now, decrypt later” approach. Threat actors can collect encrypted information today and retain it in anticipation that future quantum capabilities could eventually allow them to decrypt it. That creates an unusual cybersecurity problem: information protected adequately today may remain sensitive long enough for the technology protecting it to become obsolete.

For community banks, the appropriate response is not panic or an immediate overhaul of cryptographic systems. It is awareness and preparation.

Banks should begin discussing post-quantum readiness as part of long-term technology planning. An appropriate first step is understanding where cryptography exists throughout the institution.

Which systems protect sensitive information through encryption? Which vendors control those technologies? How long must the bank protect the underlying data? What plans do key technology providers have for adopting new cryptographic standards?

These questions can help institutions work toward crypto-agility, the ability to replace or update cryptographic technologies as standards evolve without requiring disruptive, last-minute system changes.

For most community banks, post-quantum readiness is not a 2026 implementation project. It is a 2026 planning conversation.

5. Digitalization requires risk management to keep pace

Community banks face a difficult balancing act. Customers increasingly expect convenient digital experiences.

Banks need technology to operate efficiently and compete effectively. New fintech relationships can provide capabilities that once required significant internal investment. But every new technology can also introduce new dependencies, data flows, access points, vendors, and operational risks.

The OCC’s focus on community bank digitalization reflects this tension. Its May 2025 Request for Information examined the challenges community banks face when adopting and implementing digital technologies.

The message should not discourage community banks from innovating. Instead, it should encourage institutions to make sure their governance and risk-management capabilities evolve alongside their technology. Digital strategy and risk strategy can no longer operate on separate tracks.

Before implementing significant new technology, management should understand:

  • What data the technology accesses and where that data resides.
  • Which third parties support the service.
  • How the bank will control and monitor access.
  • What happens if the technology becomes unavailable.
  • How the institution will exit or transition from the provider if necessary.
  • Whether existing cybersecurity, business continuity, compliance, and vendor-management programs adequately address the new risks.

Resources such as the Cybersecurity Supervision Work Program (CSW), Third-Party Risk Management: A Guide for Community Banks, and the OCC’s community bank digitalization resources can help institutions evaluate those questions.

The goal should not be to eliminate technology risk. That is impossible. The goal is to understand the risk well enough to make informed decisions about where and how the institution accepts it.

From cybersecurity compliance to operational resilience

The most important takeaway from the OCC’s cybersecurity report may not involve any individual technology or regulatory requirement. It is the broader shift in how banks should think about cybersecurity.

For years, institutions have devoted significant attention to preventing cyber incidents. Prevention remains critical, but prevention alone cannot define a mature cybersecurity program.

Banks must assume that systems can fail, vendors can experience outages, employees can make mistakes, credentials can become compromised, and sophisticated attackers may occasionally penetrate even strong defenses. The question then becomes: What happens next?

  • Can the institution identify the problem quickly?
  • Can management make decisions without unnecessary delay?
  • Can the bank maintain critical operations?
  • Does everyone understand their responsibilities?
  • Can the institution communicate effectively with regulators, customers, vendors, and other stakeholders?
  • Can it restore operations safely?
  • And after the incident, can the bank identify what went wrong and strengthen its controls?

Those questions define operational resilience.

What community bank leaders should do now

Community bank executives and boards do not need to respond to every emerging cyber threat by purchasing another technology solution. In many cases, the more valuable first step is determining whether the institution’s existing cybersecurity program works as intended. That means testing — not simply documenting — key capabilities.

At Young & Associates, we work with community financial institutions every day, and we understand the challenge: banks must respond to increasingly sophisticated risks without unlimited staff, budgets, or time.

The answer is not to build the cybersecurity program of a global bank. It is to build a program that appropriately reflects your institution’s size, complexity, technology environment, risk profile, and critical operations — and then verify that it works. When a cyber incident occurs, the strength of the program will not be measured by the policies sitting on a shelf. It will be measured by how effectively your institution responds.

Explore our suite of IT consulting services:


Source: OCC Cybersecurity and Financial System Resilience Report, 2026

Takeaways from the NCUA Deregulation Project

For years, credit union leaders have navigated the dense thicket of the 12 CFR, often grappling with a “compliance fatigue” that stifles innovation. Balancing operational growth against a rigid and complex regulatory framework has felt like a zero-sum game. However, the regulatory weight is beginning to lift.

Spurred by the catalyst of 
Executive Order 14192 (“Unleashing Prosperity Through Deregulation”), the National Credit Union Administration (NCUA) is currently executing a massive, multi-year “Deregulation Project.” Phase One (2025–2027) is focused on modernizing the agency’s framework by identifying rules that are obsolete, duplicative, or overly burdensome. For the strategic credit union leader, this represents a shift toward a more principles-based supervisory environment.

The end of the client-customer automatic bar

One of the most significant shifts involves proposed changes to 12 CFR 701 (Appendix B) regarding associational common bonds. Historically, the NCUA maintained an “automatic bar” against groups primarily based on a client-customer relationship. If joining an association required the purchase of a product or service, such as an insurance policy, the group was automatically disqualified from Field of Membership (FOM) eligibility.

The new proposal moves from an automatic bar to a process of further evaluation. The NCUA Board has determined that a product purchase requirement is no longer a hard no. Instead, the agency will evaluate if the client-customer relationship is merely incidental to the group’s broader activities. This shift to a holistic evaluation opens significant new doors for FOM expansion, allowing credit unions to partner with associations they previously would have ignored.

Flexing senior management compensation

In a competitive labor market, attracting and retaining high-level talent is vital for institutional resiliency. However, the NCUA’s historical blanket prohibition on loan-related compensation has been a major pain point, often suffering from varying interpretations and inconsistent enforcement across the NCUA’s different regions.

Proposed changes to 12 CFR 701.21(c)(8) seek to resolve this confusion. By adding a formal definition of “overall financial performance,” the rule would explicitly permit credit unions to offer incentives and bonuses to employees, including senior management, that incorporate lending metrics. As long as these metrics are part of a broader evaluation of the institution’s financial health, the NCUA now views this as a critical tool for recruitment rather than a hurdle.

Removing prescriptive training deadlines

Volunteer boards are the lifeblood of the credit union movement, but prescriptive mandates can deter community members from serving. Currently, 12 CFR 701.4(b)(3) mandates that every director attain a “working familiarity” with finance and accounting within six months of election or appointment.

The NCUA is now proposing to eliminate this rigid six-month deadline. While the agency continues to hold the core expectation that directors possess financial expertise, it admits the current rigid clock is “unduly burdensome” and can “undermine the ability of a credit union’s members to elect their board.” This is a clear win for community representation: the requirement for competence remains, but the arbitrary training clock is being dismantled.

Lifting the caps on third-party auto servicing

Effective September 8, 2026, a final rule will remove the restrictive caps previously found in 12 CFR 701.21(h). In the past, credit unions were capped at 50% of their net worth for indirect auto loans serviced by third parties, only reaching 100% after 30 months of experience with a specific servicer.

By removing these prescriptive limitations, the burden of risk management shifts from federal mandates to the board’s own risk tolerance. This allows institutions to manage liquidity and portfolio diversity based on their unique needs rather than a one-size-fits-all cap.


“With today’s announcement, we are moving forward on our commitment to removing regulations that are obsolete, burdensome, duplicative, or simply guidance that has no place in regulation. Our goal is to make it easier for credit unions to serve their members, meet compliance requirements, and stay innovative. These final rules and those that come after will give credit unions the flexibility to do just that.” — Chairman Kyle Hauptman

The guidance vs. regulation cleanup

A key pillar of this project is ensuring that non-binding guidelines are not misinterpreted as enforceable law. The NCUA is stripping several “Appendices” out of the Code of Federal Regulations and moving them into “Letters to Credit Unions.” This cleanup clarifies that guidance should be followed as best practice, but it is not independently enforceable.

Key areas moving out of the CFR into guidance include:

  • Safeguarding Member Information: Moving the standards for protecting the security of records (formerly 748 Appendix A).
  • Response Programs: Moving the guidance for responding to unauthorized access to member data (formerly 748 Appendix B).
  • Voting Guidelines: Moving the non-binding suggestions for obtaining fair votes during conversions (found in 12 CFR 708a).

Modernized catastrophic reporting

During a crisis, management should focus on stabilizing operations, not filling out forms. To reflect this, the NCUA is modernizing 12 CFR 748.1(b).

The reporting window for catastrophic acts is being increased from 5 business days to 15 calendar days. Furthermore, in a significant procedural shift, reports are now to be made directly to the NCUA rather than the Regional Director. This centralizes the reporting process and gives credit unions the necessary breathing room to manage emergency conditions before worrying about regulatory paperwork.

A new era of safety and soundness

The Deregulation Project represents a fundamental pivot in the NCUA’s philosophy. By categorizing rules as Obsolete, Duplicative, Overly Burdensome, or Guidance, the agency is attempting to prioritize relief that actually impacts daily operations.

While this signals a move toward principles-based supervision, do not expect exams to be less rigorous. The focus remains squarely on safety and soundness, but with a renewed respect for the business judgment of credit union boards.

Note: Credit unions must continue to follow all existing regulations as they currently appear in the Code of Federal Regulations until the relevant Final Rules are officially effective. For help navigating regulatory compliance, learn more about Y&A’s compliance consulting services.

Y&A Credit Services launches asset-based lending field exam services

Y&A Credit Services, a full-service provider of outsourced underwriting services and credit analysis, announced the launch of its asset-based lending (ABL) field exam services. The service is designed to help financial institutions confidently manage asset-based lending relationships, strengthen risk management practices, and support portfolio growth with experienced, independent field exam expertise. 

“Asset-based lending can create valuable growth opportunities for community financial institutions, but it also requires a disciplined approach to collateral monitoring and risk management,” said Oliver Sutherin, principal of Y&A Credit Services. “Our ABL Field Exam Services are designed to give lenders greater visibility into collateral quality, borrower operations, and portfolio risk so they can make informed decisions with confidence. We strive to help institutions grow strategically while maintaining strong credit administration practices.” 

Each field exam may include: 

  • Verification and analysis of accounts receivable — aging schedules, eligibility testing, dilution trends, and concentration risk across the borrower’s customer base  
  • Inventory testing and valuation review — roll-forward analysis, eligibility criteria, obsolescence exposure, and physical verification against reported values  
  • Borrowing base validation — reconciliation of the calculated base to loan balances, confirming advance rates and eligible collateral are applied correctly  
  • Collateral monitoring assessments — UCC filing and lien priority review, insurance coverage confirmation, and ongoing collateral adequacy relative to outstanding advances  
  • Review of operational controls and reporting practices — evaluation of cash receipts handling, AP aging integrity, and the borrower’s internal reporting discipline 
  • Identification of risk trends, reporting inconsistencies, and exceptions — financial trend analysis, GL tie-out testing, and documented exceptions with recommended remediation  
  • Independent reporting for lending and credit administration teams — a structured exam summary covering scope, findings, and risk conclusions to support credit decisioning 

The new offering aligns with Y&A Credit Services’ broader mission of helping community financial institutions improve operational efficiency, overcome staffing challenges, and enhance credit risk management through outsourced expertise. With the addition of ABL field exam services, Y&A Credit Services now offers a comprehensive suite of commercial credit support services, including underwriting package reviews, annual underwriting reviews, financial statement spreading and analysis, and credit administration support. 

To support its ABL field examination services, Y&A Credit Services employs credit analysts who have earned Commercial Banking & Credit Analyst certifications from the Corporate Finance Institute® (CFI). Their training strengthens their expertise in financial modeling, loan security analysis, and industry analysis for ABL field examinations. 

ABL field exam services are available now. To learn more, visit Y&A Credit Services or call 1-800-525-9775. 

About Y&A Credit Services

Y&A Credit Services provides commercial underwriting and specialty credit services to financial institutions nationwide. Founded in 2022, Y&A Credit Services operates as an independent entity while delivering the same expertise, service, and integrity associated with Young & Associates. Both organizations help financial institutions navigate regulatory challenges and position themselves for growth. 

Learn more at Y&A Credit Services. 

Analyzing the OCC’s Spring 2026 Semiannual Risk Perspective for community bankers

The OCC’s Spring 2026 Semiannual Risk Perspective gives community financial institutions a strategic view of the most significant risks affecting the banking industry. Using the National Risk Committee’s latest findings, the report helps bank leaders evaluate institutional strength, identify emerging threats, and align risk management strategies with evolving federal regulatory expectations. This article examines the key insights and banking industry trends highlighted in the Spring 2026 report.

As the banking industry moves through the spring of 2026, U.S. financial institutions face a market defined by speed, volatility, and structural change. Strong earnings and high liquidity continue to support the system, but rising geopolitical tensions, AI-driven fraud, and mounting commercial real estate refinancing pressure are forcing banks to rethink traditional risk management strategies.

The banking system enters 2026 from a position of strength

The federal banking system enters 2026 from a position of strength, characterized by improved earnings, robust loan growth, and solid balance sheets. In 2025, bank performance was supported by a resilient U.S. economy and a decline in funding costs that drove revenue growth. Capital ratios and liquidity levels remain high by historical standards, with a system-wide liquid assets-to-total assets ratio of 31 percent — more than double the 15 percent recorded in 2008.

The 2026 macroeconomic outlook and structural headwinds

Despite these positive trends, the outlook for 2026 is tempered by significant uncertainties:
  • Geopolitical Risk: The conflict in the Middle East is a primary concern, with the potential to disrupt global energy flows (particularly through the Strait of Hormuz) and fuel inflation.
  • Credit Headwinds: While aggregate credit risk is manageable, specific segments — including commercial real estate (CRE), private credit markets, and consumer credit for lower-score borrowers — require ongoing monitoring.
  • Operational Threats: Cybersecurity remains an elevated risk, driven by sophisticated foreign state-sponsored actors and the emergence of advanced AI tools that enhance the speed and scale of attacks.
  • Regulatory Evolution: The OCC continues to implement the GENIUS Act regarding stablecoins and is working to tailor compliance requirements to reduce the burden on community banks while addressing increased sanctions and money laundering risks.

U.S. economy continues growing despite inflation risks

The U.S. economy grew by 2.1 percent in 2025, outperforming other advanced economies. This growth was driven by strong consumer spending and business investment, particularly in artificial intelligence.

Labor and inflation

  • Labor Market: Unemployment remained low at 4.3 percent as of March 2026. While payroll gains were strong in the first half of 2025, they reversed in the second half, leading to a characterized state of “employer caution” in early 2026. Wage growth eased to 3.4 percent by the end of 2025.
  • Inflation: Core inflation started 2026 at 3.1 percent, remaining above the Federal Reserve’s 2 percent target. Stickiness in service-sector inflation and high shelter costs persist.
  • Monetary Policy: After holding rates steady in early 2025, the Federal Reserve implemented three rate cuts in the second half of that year.

2026–2027 economic projections

According to the April 2026 Blue Chip consensus forecast, real GDP is expected to grow by 2.2 percent in 2026 and 2.0 percent in 2027. However, headline inflation is projected to peak at an annualized 5.1 percent in the second quarter of 2026 due to the Middle East conflict before falling in the second half of the year.

Significant economic risks

  • Strait of Hormuz: Sustained closure could drive higher energy costs, reducing consumer purchasing power and increasing business production expenses.
  • Interest Rate Expectations: Market participants have adjusted expectations downward; the April forecast anticipates only one rate cut in 2026, while financial market pricing suggests even that may not occur.

Bank performance analysis

Profitability for the federal banking system increased in 2025. Return on equity (ROE) exceeded 10 percent for both the total system (12.2 percent) and community banks (11 percent).

Financial trends (2024–2025)

Metric
System Total (2025)
System % Change
Community Banks (2025)
Community % Change
Net Interest Income
$493.9 Billion
+3.7%
$34.4 Billion
+12.2%
Noninterest Income
$249.6 Billion
+11.0%
$11.0 Billion
+7.1%
Net Income
$199.2 Billion
+8.8%
$12.5 Billion
+21.6%
Total Loan Balances
+6.0%
+5.0%
Net interest margins (NIM) improved across the board, particularly for community banks, which benefited from lower funding costs and more favorable asset yields compared to larger institutions. Larger banks saw a quicker downward repricing of their short-term commercial and industrial (C&I) loans.

Key financial risks

Credit risk

Credit quality remains satisfactory, with past-due and nonaccrual loan ratios below long-term averages. However, several sectors show emerging vulnerabilities:
  • CRE: Office properties still face high vacancy rates, though net absorption turned positive in late 2025. Refinancing risk is a major concern as loans originated in low-interest environments mature. Conversely, retail remains a “bright spot” with low vacancy rates.
  • Private Credit: While generally performing well, there are signs of weakening in some sectors. The use of “paid-in-kind” (PIK) mechanisms and debt restructurings may be masking underlying credit deterioration.
  • Consumer Credit: Delinquencies have increased among borrowers with lower credit scores, though supervised banks have manageable exposure to these higher-risk segments.

Market risk

Unrealized losses on securities portfolios fell in 2025 to their lowest levels since 2021. Uninsured deposits saw a modest increase as a share of total deposits, primarily at banks with over $500 billion in assets, though they remain in line with long-term averages.

Compliance and operational risks

Cybersecurity and artificial intelligence

The threat landscape is increasingly dominated by foreign state-sponsored actors and sophisticated criminal groups.
  • AI as a Threat: AI lowers the barrier to entry for cybercriminals, enabling automated reconnaissance, targeted social engineering, and adaptive malware that evades traditional defenses.
  • AI as a Defense: Banks are deploying AI tools to assist with threat monitoring and risk management. The OCC emphasizes that a sound understanding of these tools’ risks and benefits is essential for management.

Fraud risk

Fraud remains a primary driver of operational losses. Impersonation scams facilitated by social media and text messages are rising in sophistication. FinCEN has issued specific alerts regarding health care fraud schemes and money laundering networks.

Compliance and BSA/AML

Geopolitical tensions have strained compliance systems, increasing the risk of Bank Secrecy Act/anti-money laundering (BSA/AML) violations.
  • Supervisory Tailoring: The OCC is working to reduce the regulatory burden on community banks, recently clarifying examination procedures for low-risk institutions and discontinuing the Money Laundering Risk system data collection.
  • Regulatory Changes: A proposed rule is currently under consideration to amend requirements for risk-based AML and countering the financing of terrorism (CFT) programs.

Innovation and digital assets

Artificial intelligence implementation

Banks are adopting generative and agentic AI, primarily for productivity and customer experience tools.
  • Governance: The OCC advocates for “human-in-the-loop” accountability.
  • Challenges: Industry-wide challenges include a lack of explainability, data privacy, “data poisoning,” and validation difficulties.
  • Guidance: OCC Bulletin 2026-13 recently updated model risk management guidance, though generative AI models currently fall outside its specific scope. An interagency Request for Information (RFI) on bank use of AI is expected in the near future.

Digital assets and stablecoins

The regulatory landscape for digital assets is formalizing following the passage of the Guiding and Establishing National Innovation for U.S. Stablecoins (GENIUS) Act on July 18, 2025.
  • Stablecoins: The OCC issued a notice of proposed rulemaking in February 2026 to establish a federal regulatory framework for payment stablecoins.
  • Tokenization: Interagency FAQs released in March 2026 clarified that the technologies used to transact in a security do not generally change its regulatory capital treatment.

OCC’s Spring 2026 Semiannual Risk Perspective and outlook for the banking industry

The banking industry enters 2026 with strong capital levels, high liquidity, and improving profitability. However, regulators increasingly warn that the speed of emerging risks may challenge traditional oversight models. Commercial real estate refinancing pressure, private credit deterioration, AI-driven cyber threats, stablecoin regulation, and geopolitical instability are reshaping the banking landscape.

As financial institutions move deeper into 2026, banks that strengthen risk management, improve operational resilience, and adapt quickly to changing market conditions will likely remain best positioned for long-term stability and growth.

Can a 31% liquidity buffer outrun the 2026 refinancing cliff?

As we move through the spring of 2026, the American banking system resembles a fortress built on a fault line. On the ledger, the industry looks stronger than ever. Bank earnings surged throughout 2025 and pushed the system’s return on equity (ROE) to an impressive 12.2 percent. Community banks, which often absorb economic pressure first, still maintained a solid 11 percent ROE.

However, the most dangerous risks rarely wait for quarterly reporting cycles. Beneath the industry’s profitability, the National Risk Committee’s latest analysis highlights a financial landscape defined by “velocity”: AI-powered fraud evolves rapidly, geopolitical disruptions emerge suddenly, and the commercial real estate “maturity wall” advances steadily. Although the U.S. economy expanded by 2.1 percent in 2025, structural changes now outpace traditional risk management strategies. The latest regulatory data reveals six critical signals shaping the banking industry in 2026.

The 31 percent safety net

The NRC report’s most reassuring finding centers on the industry’s liquidity position. By the end of 2025, liquid assets accounted for 31 percent of total assets across the federal banking system. During the 2008 financial crisis, that same ratio stood at only 15 percent. This doubled buffer is the primary reason the system remains upright despite “higher-for-longer” interest rates and global instability.

Still, analysts cannot rely solely on aggregate figures. The NRC emphasized this point in its executive summary:

“Balance sheets remain strong, with capital ratios and liquidity high by historical standards. Earnings releases for the first quarter of 2026 indicate that these trends have generally persisted.”

The nuance? That 12.2 percent ROE is heavily skewed, driven primarily by the nation’s largest institutions. While the system-wide 31 percent liquidity buffer is a historical anomaly of strength, the underlying reality is a widening gap between the “too big to fail” giants and community banks, which hold a significantly higher concentration of long-term property loans now facing a brutal refinancing environment.

The private credit “performance mirage”

Although aggregate credit risk appears manageable, the NRC raised concerns about the expanding private credit market. As banks increase their exposure to private credit funds, they may unintentionally create what many analysts describe as a “performance mirage.”

The greatest risks sit within loan vintages originated during the low-interest-rate period of 2021 and 2022. Many of these loans still appear healthy on paper, but aggressive restructurings and paid-in-kind (PIK) arrangements often mask underlying weakness. Instead of requiring borrowers to make cash interest payments, lenders allow them to accumulate additional debt.

As a result, funds postpone defaults rather than resolve them. Investors should recognize that today’s stable yields may conceal deteriorating credit quality that could surface abruptly when these loans reach future refinancing deadlines.

The rise of agentic AI

The banking industry has moved past the “Generative AI” hype cycle. The industry now focuses on “Agentic AI,” which refers to autonomous systems capable of participating in material financial decisions such as credit underwriting and automated trading.

While banks maintain a “human-in-the-loop” model for accountability, this technology has intensified the cybersecurity arms race. AI has fundamentally lowered the barrier to entry for cybercriminals, enabling automated reconnaissance and “adaptive malware” that can evolve in real-time to evade traditional defenses.

This shift fundamentally changes the risk landscape. Traditional governance models, which often depend on quarterly reviews and slower oversight processes, struggle to keep pace with rapidly evolving AI-driven threats.

The CRE “maturity wall” and the sun belt chill

Commercial real estate (CRE) remains the banking system’s most visible weakness. The refinancing cliff has moved from theory to reality. Loans issued during the zero-interest-rate era now require refinancing at significantly higher rates, dramatically changing property economics.

  • The Cooling Sun Belt: After a massive supply wave between 2022 and 2024, rental rates in the Sun Belt and Mountain West are facing downward pressure.
  • The Resilient North: Surprisingly, the Northeast and Midwest are outperforming the cooling southern markets in both single-family and multifamily sectors.
  • The Retail Bright Spot: Retail properties have unexpectedly emerged as one of the strongest sectors. Low vacancy rates and limited new development have made retail investments more stable than office properties, which continue to face weak demand and elevated vacancies.

The GENIUS Act’s normalization of digital assets

The regulatory uncertainty surrounding digital assets effectively ended on July 18, 2025, when lawmakers signed the GENIUS (Guiding and Establishing National Innovation for U.S. Stablecoins) Act into law. This legislation formally normalized the digital dollar within the regulated financial system.

The OCC has already begun implementing a federal framework that restricts stablecoin issuance to authorized and regulated entities. Institutional investors received additional clarity on March 5, 2026, when interagency guidance confirmed that tokenization does not alter the regulatory capital treatment of securities.

This signal removes the “novelty” penalty for digital assets, paving the way for stablecoins and tokenized bonds to become standard features of the authorized financial system.

The Strait of Hormuz and the speed of global risk

Despite the domestic strength of the 31 percent liquidity buffer, the banking industry’s 2026 outlook is ultimately hostage to a narrow waterway 7,000 miles away. Analysts at Blue Chip have adopted a more defensive outlook, warning that a prolonged closure of the Strait of Hormuz could materially disrupt the global economy.

A disruption to oil and fertilizer shipments would likely trigger another major inflation spike. Blue Chip’s April forecast projects inflation could reach 5.1 percent during the second quarter under such a scenario. Rising inflation would likely eliminate any possibility of interest rate cuts in 2026 while simultaneously increasing pressure on both global trade and domestic refinancing markets.

As we look toward the second half of the year, the banking industry faces a defining challenge. The central issue no longer concerns the size of financial buffers alone, but the speed of institutional response. Banks must determine whether human-led governance systems can react quickly enough to manage the accelerating risks created by Agentic AI, geopolitical instability, and rapidly shifting financial markets.

The industry’s resilience remains real, but in 2026, the margin for error continues to shrink at an unprecedented pace.

AI technology in the workplace

AI GlassesBy Bill Elliott, CRCM; director of compliance education, Young & Associates

We have recently been made aware of new artificial intelligence (AI) technology that may create additional risk for banks. Apparently, a bank employee had a pair of glasses that doubled as an AI recording device. These glasses were worn to work and were capable of recording private conversations without anyone’s knowledge. It is unclear whether the glasses included video, but that of course is possible. This new technology is being used for a variety of purposes and is continuing to develop.

This is a compliance issue regarding privacy of customer information. If the glasses have a camera and, thus, can “see” and perhaps “record” computer screens of customer information and other bank information, there is potential for substantial increases in your risk under the privacy regulations.

There are also state and federal laws to take into consideration, depending on how the glasses are used. In any case, it is advisable to speak with your bank’s attorney on how to address and handle this new AI technology, as your current human resources (HR) and/or ethics policies likely do not address this issue.

We also recommend that you consider any other changes that may be necessary, as all institutions are going to be facing other manifestations of AI in the not too distant future.

This AI technology may not be in use at your bank yet. However, it is only a matter of time before it will be.

2026 Rescission Calendar – Free download now available

The right of rescission, governed by Regulation Z under the Truth in Lending Act (TILA), remains a cornerstone of consumer protection in the lending industry. For financial institutions, ensuring compliance with rescission rules is not only a regulatory requirement but also a reflection of their commitment to protecting borrowers’ rights. However, the intricacies of rescission — covering timing, disclosure requirements and exceptions — can make this area of compliance challenging for many lenders.

To support your institution in navigating these complexities, Young & Associates offers a free downloadable Rescission Reference Chart. The chart is designed to simplify compliance with rescission rules.

 

What is the 3 Day Right of Rescission?

The right of rescission provides consumers with the ability to cancel certain credit transactions that involve a lien on their principal dwelling. This cooling-off period, typically three business days, is intended to allow borrowers time to evaluate the terms of their transaction without pressure. While the concept is straightforward, compliance involves navigating strict rules related to timing, notification and disclosure.

Common challenges in rescission compliance

Despite its importance, rescission often presents challenges for financial institutions. Here are some common issues:

  1. Identifying covered transactions
    Not all transactions are subject to rescission. Determining whether a loan qualifies—such as refinances or home equity lines of credit—requires careful evaluation of loan terms and lien positions.
  2. Proper timing of the rescission period
    The rescission period must be calculated accurately, taking into account business days and excluding holidays. Miscalculations can result in compliance violations.
  3. Providing accurate and timely disclosures
    Borrowers must receive clear and complete rescission notices and required disclosures at the time of closing. Any inaccuracies can extend the rescission period or expose the lender to liability.
  4. Handling rescission notices
    If a borrower exercises their right to rescind, lenders must act swiftly to return funds and terminate the lien within 20 calendar days. Delays or errors in this process can lead to penalties.

How do you calculate a 3 day rescission period?

The rescission period typically begins the business day following the signing of loan documents and ends at midnight on the third business day.

How the calendar can help

Young & Associates’ Rescission Reference Chart is a comprehensive tool that simplifies the complexities of rescission compliance. This chart provides:

  • A clear breakdown of covered and exempt transactions.
  • Guidelines for accurately calculating the rescission period.
  • Tips for ensuring proper disclosure and handling rescission notices.

This chart offers a practical and easy-to-use resource to enhance your compliance program. It can assist in training new staff or refreshing your understanding of rescission rules.

Why rescission matters

Non-compliance with rescission rules can result in extended rescission periods, regulatory scrutiny or even legal action. Ensure your institution has a solid grasp of rescission requirements. Not only to avoid potential risks but also to reinforce your reputation as a trusted and reliable lender.

Download free today

Young & Associates is dedicated to helping financial institutions like yours maintain compliance while streamlining operations. Our Rescission Reference Chart is just one of the many tools we offer to support your success. Equip your team with the knowledge and tools they need to navigate rescission with confidence. With Y&A by your side, you can focus on serving your customers while staying compliant with ease.

OFAC extends record retention requirements

By Veronica Madsen; Consultant, Young & Associates

On March 21, 2025, the Department of the Treasury’s Office of Foreign Assets Control (OFAC) published its final rule to adopt the interim final rule extending certain recordkeeping requirements from five to 10 years. This extension is consistent with the statute of limitations for violations of certain sanctions administered by OFAC and became effective on the date of publication in the Federal Register.

The final rule also extended the period during which civil monetary penalties may accrue for late filing of reports required to be submitted to OFAC (e.g., blocked property and reject reports or reporting required under specific licenses), from five years to 10 years. The potential penalty amounts did not change.

The changes stemmed from the 21st Century Peace through Strength Act (Public Law 118-50), signed into law on April 24, 2024, which extended the statute of limitations for civil and criminal violations of the International Emergency Economic Powers Act (50 U.S.C. 1701), and the Trading with the Enemy Act (50 U.S.C. 4301), from five years to 10 years.

OFAC published an interim final rule on September 13, 2024, and requested public comment. Despite the concern financial institutions needed more time to acquire additional resources and storage capacity, and to adjust their current recordkeeping practices to conform to the new recordkeeping requirements, OFAC finalized the rule as written due to the length of time provided since the law was passed.

What records must be retained longer?

Under the Federal Financial Institutions Examination Council (FFIEC) BSA/AML Examination Manual, transactions subject to the extended record retention requirement relate to the full and accurate record of each rejected transaction, including all reports submitted to OFAC. For blocked property (including blocked transactions), records must be maintained for the period the property is blocked and for 10 years after the date the property is unblocked.

How should banks prepare for this OFAC change?

Because the rule became effective upon publication, banks that have not already prepared for this change should ensure their systems are updated to retain these documents longer; policies, procedures and the OFAC risk assessment are amended to reflect the new retention requirement and extended risk of penalties associated with late filings; prepare or amend training content; and prepare for potentially increased compliance costs.

Conclusion

Navigating this kind of regulatory shift can feel overwhelming, especially when it demands swift operational changes and long-term strategic planning. That’s where Young & Associates can help. Our compliance experts are ready to assist with updating your OFAC programs, reviewing risk assessments, and supporting your team in building a sustainable, compliant approach to record retention. Contact us today to ensure your institution is fully prepared for this new 10-year horizon.

Incorporating core competencies into performance reviews

A strategic approach for organizational success

By Clarissa Sinchak, PHR; director of HR, Young & Associates

It is widely known that performance reviews are key to how your organization can measure individual and, ultimately, company-wide growth and success. Performance reviews are not just about measuring what employees have accomplished throughout the year but are also created to identify opportunities to grow, develop and achieve their full potential through meaningful and intentional conversations with their managers. Additionally, they offer a chance to recognize achievements, identify areas for improvement, and set future goals and objectives. However, the real power of performance reviews is evident when core competencies are strategically aligned with your company’s goals. In doing so, it ensures that individual employee contributions are recognized and directly tied to the mission and vision of the organization, ultimately fostering a purpose-driven workforce.

What are core competencies?

In today’s competitive business world, organizations must possess specific strengths to separate themselves from the competition to guarantee long-term success. These strengths, also known as core competencies, establish the organization’s foundational knowledge, skills, defining products, services and capabilities that give a business an advantage over its competitors and ultimately drive its growth. These are behaviors and skills that employees in your company often either inherently possess or aim to develop over time to achieve their personal goals and perform well in their roles.

When leaders clearly define and communicate these strengths, they help ensure that all employees see a direct connection to the organization’s mission, which promotes more significant commitment and greater individual contributions. By aligning them with organizational goals, business leaders can ensure that employees prioritize the desired behaviors and work habits that contribute to them.

Some common examples of core competencies might include, but are not limited to:

  • Initiative
  • Decision-Making
  • Teamwork
  • Communication
  • Adaptability
  • Client Service
  • Technical Job Knowledge
  • Interpersonal Skills
  • Integrity

How to develop your organization’s core competencies

Developing core competencies within your organization requires deliberate thought, strategic alignment with the company’s long-term goals and a commitment to continuously improving. Business leaders should take a systematic approach when incorporating them into the performance review processes.

Defining the organization’s mission & goals

First, developing core competencies begins with understanding the organization’s purpose and aspirations, so business leaders should clearly define this in addition to their goals. Once they achieve this, leaders should openly communicate their strategy to employees to create buy-in and to build an overall understanding. A clearly articulated company vision is the basis for identifying the areas where the organization must excel. Leaders ensure transparency in communication by focusing the core competencies on capabilities that directly contribute to the company’s competitive positioning.

Identifying strengths & gaps in current capabilities

A second essential step in creating core competencies is identifying your company’s strengths and gaps. Leaders can evaluate and analyze current skills, resources, and processes by working with human resources to conduct an internal assessment. This analysis highlights areas of expertise within the organization and exposes any opportunities for improvement. Understanding your organization’s current state makes it easier to create development initiatives in the areas that guarantee the most significant value.

Fostering a culture of learning & development

A third key step in developing core competencies is promoting a workplace culture that prioritizes learning and development for employees at all levels of the organization. Investing in their growth is imperative because employees are fundamental to any company’s success. When leaders offer training programs, mentoring, and knowledge-sharing programs, employees build expertise in the company’s defined core competencies. Promoting open and ongoing communication, recognizing achievements, and encouraging accountability ensures employees work towards the same objectives.

Continuously evaluating & adapting competencies

Lastly, it is essential to note that core competencies require continuous modification and evaluation as your company’s goals progress over time. For example, the market might change, client expectations might evolve, and competitors undoubtedly will vary over time. Therefore, evaluating and monitoring your core competencies and considering these potential changes is critical. Continuously assessing the effectiveness of these core competencies within performance reviews while simultaneously benchmarking against your industry’s standards is essential to guarantee that they remain relevant and have a desired impact. This creates a consistent and ongoing framework for evaluating employee contributions, making reviews transparent and predictable while reinforcing the organization’s core values and priorities.

In summary, establishing core competencies within your organization is a significant undertaking that combines internal strategy and alignment while focusing on developing your employees to set them up for success. Companies that can build and maintain these core competencies position themselves to grow and thrive. By incorporating core competencies into performance reviews, companies will see an uptick in employee engagement and the desire to increase their productivity to enable the organization to propel forward.

2025 begins with a normal yield curve – but where is the risk?

By Michael Gerbick; president, Young & Associates

On Wednesday, Jan. 29, 2025, Jerome Powell and the Federal Open Market Committee (FOMC) decided to maintain the target range for the federal funds rate at 4.25 – 4.50 percent after three successive cuts totaling 100 bps in September, November and December. Heightened attention and focus continue on the yield curve, as the curve’s shift has been dramatic in recent years.

Yield curve over the years

The chart below shows the yield curve at five different points in time from Jan. 2022 to Tuesday, Feb. 18, 2025. The shape of the curve has gone from normal to inverted and now back to normal. Looking at a few different US Treasury Bond maturities over the last 14 months, you can see the one month yield has decreased over 120 bps and the 20 year has increased over 60 bps! Each rate curve shape and elevation imply different opportunities for your balance sheet. A more asset-sensitive and positive gap on a balance sheet may be more attractive for earnings in the short term and helpful when the Fed was raising rates in 2022 and 2023.  A more liability-sensitive and negative gap on a balance sheet may be more attractive for earnings in the short term as the Fed reduces rates. Your ALCO likely understands these shifts well and has managed these drastic movements and their impact on overall strategy.

The normal yield curve indicates improved expectations for economic growth in the years ahead. That said, there is also caution for inflation. When the Fed began rate reductions, there were discussions regarding more cuts totaling 100 bps by year end 2025. Then these ambitious views have shortened to perhaps two cuts of 25 bps each. The yield curve still stands above its level from several years ago, and the Fed Funds rate exceeds the previous cycle’s peak of 2.25–2.50 percent in 2018–2019. The consumer is savvier than they were at that time as well.

At the end of 2024, we spent time interviewing some of our community banker colleagues to gain a pulse on what they are talking internally about in their ALCO meetings concerning interest rate risk. As expected, there is relief to have a normal yield curve instead of managing the inverted one of recent years. Many reasons still create an overall sense of caution heading into 2025, with two key factors briefly discussed in the following sections.

Cost of deposits

Community banks may not realize the full impact of the Fed’s rate reduction in their cost of deposits. Given the continued elevated competition for deposits and the more savvy consumer, community banks may find their deposit rate offering slower to adjust than the Fed’s rate movements and some may see their interest expense actually increase in 2025. There may also be migration to more longer term duration CDs. (movement from less than 6 months to 1 year or more). Yes, longer term CDs will keep the deposit costs higher than non-maturity but will create welcomed funding stability. Continued focus on the bank’s deposit makeup and shifts are necessary. Staggering the CD maturities will be critical for community banks to manage this new environment so as to maintain adequate liquidity levels as CDs mature and consumers make a choice to reinvest, migrate to shorter term or perhaps withdraw their funds.

Investments

Community banks made many investments with PPP funds and other excess liquidity in a low-rate environment back in 2021. The Fed raised rates 550 bps and many of those investments contributed to a significant amount of unrealized loss. The Fed cut rates 100 bps, and the yield curve no longer shows an inversion. Rates remain elevated, and community banks still hold a significant amount of investments on their balance sheets with unrealized losses. The chart below shows the fair value of investment portfolio expressed as a percent of the amortized cost of the investment portfolio over the last four years for commercial banks.

You can see all three asset sizes over the last four years have a similar trend line. Consider a bank having $100MM in their security portfolio, it is likely its portfolio is currently $7-$10MM underwater. This changes each day as these investments continue to reprice and mature over time.  As they do, bank management is faced with how best to serve its bank. Either by in reinvesting short-term or long-term within their investment portfolio or funding higher yielding loan growth opportunities. Each has liquidity and capital implications that must be considered.

Conclusion

Community banking is resilient. The conversations with community bankers reveal their drive to prepare and plans for managing risk in 2025 and beyond. ALCO and Boards of Directors should continue their sharp focus on managing interest rate risk.  If the deposit competition is fierce for your bank and interest expense in 2025 is expected to be elevated, then focus on what is within your bank’s control. On the asset side of the balance sheet, consider paying attention to the loan and investment portfolios and when they are repricing, what additional loan fee income can be generated, revisiting discussions and confirming the types of loans the bank is comfortable making.

When considering interest rate risk, confirm your bank’s risk profile and remember to stay within the board approved risk parameters. Your bank’s balance sheet may have experienced significant change away from a neutral risk position given the economic environment recently. If you have found your bank is outside the risk parameters, discuss strategies with your board that are designed to get the bank back within acceptable risk thresholds.  Always be clear with the board on expectations and inform them we may not be able to fix this overnight.  One banker said it best when providing advice for community bankers trying manage the interest rate risk of the bank, “Always manage the bank’s IRR to a better position, even if getting to that position takes years… don’t get ahead of your skis and try to do it all in one day.”

Thanks to community bankers that spent time discussing IRR and sharing insights in the interest of helping others.

If you’d like to hear more about our ALM services, reach out as we’d be happy to discuss and assist.

Compliance – 2025 & beyond

By Bill Elliott, CRCM; director of compliance education, Young & Associates

Over the last few years we have dealt with changes to regulation, followed by lawsuits, followed by resolution (in some cases).

The original intent of the CFPB was to have a governmental department that was independent of the rest of the federal government. The leader of the CFPB would not be a political appointment. For good or ill, that has changed due to decisions by the Supreme Court. As a result, this agency has become part of each administration and experiences changes in direction based on the results of elections.

Some of the discussion below includes other agencies, as they are part of the same trend.

CRA

Regulators published the new CRA rule, which was due for partial implementation last year. However, there is a lawsuit pending, challenging the regulation. That lawsuit still has not reached the resolution stage, and all federal regulators have said publicly that they are going to follow the old CRA regulation until resolution occurs.

The intent of the new CRA regulation was to try to take as much examiner judgment out of the rating system as possible, with the result of fairer reviews for banks. While an excellent goal, I am not sure that the pending regulation accomplishes this. In any event, all banks and regulators will follow the existing regulation until the court battles have concluded. The CFPB is not part of the new CRA rule, just the primary regulators, but this is part of the same trend.

Beneficial ownership

Congress passed the Corporate Transparency Act, requiring the federal government to collect beneficial ownership information. That process began in 2024, and required your smaller commercial customers to share a lot of information with the federal government.

The federal government said that compliance was actually going well. But late in 2024, once again in response to a lawsuit, everything ground to a halt. Your customers who have not yet complied may have to comply at some point in the future, and are welcome to comply now, but currently do not have to comply.

The lawsuit generally addresses whether Congress could pass a law such as this in the first place. We do not know where it will go from here, and because of the issue, we may have to wait for the Supreme Court to rule on it. Another example of the current environment.

1071

1071 (Regulation B, Subpart B)  is perhaps the regulation that will create the greatest problems for banks and their customers. Although many banks face implementation a year or more in the future, your customers will likely consider the current regulation invasive. Amongst other things, the regulation requires banks to ask small business owners their sexual preferences, orientations, etc. Many of your customers will consider this none of the government’s business. And this particular information is not required under the Dodd Frank Act.

While a small business owner could be discriminated because of their LGBTQ+ status, we would hope that that would not happen. This is a rule with good intentions, however, the approach in the regulation will create more difficulties for banks and their small commercial customers than we would like. We will see what happens with the change in administration and CFPB leadership.

Conclusion

There are other rules pending. For instance, privacy is becoming a bigger and bigger issue as we get more and more electronic. These sorts of regulations are probably going to be useful but we will have to wait and see how the final regulations read, and then maybe wait through lawsuits once again.

A regulatory environment that was less chaotic would be better for all of us, but that does not appear to be something that we can count on. Enjoy the ride.

In this ever-changing environment, having a knowledgeable compliance partner is essential. At Young & Associates, we specialize in helping financial institutions interpret, implement, and manage compliance requirements with confidence. Whether you need regulatory guidance, risk assessments, or compliance program reviews, our team is here to support you.

Reach out to Young & Associates today to discuss your compliance needs.

Checking your BSA program is more important than ever

By William J. Showalter, CRCM; senior consultant, Young & Associates

Over the past year, we have seen at least 27 Bank Secrecy Act (BSA) enforcement actions from an array of financial institution supervisory agencies.  Banks of all sizes continue to be hit with cease and desist (C&D) orders, formal agreements, consent orders, and even civil money penalties (CMP).  Five of these actions involved monetary penalties of some sort totaling nearly $4 billion – all but about $109 million coming from one case with four federal agency actions against one bank, and one $100,000 CMP imposed against an individual for BSA noncompliance.  These enforcement actions remind us that even community banks and thrifts must have thorough and well-managed BSA compliance programs.

The enforcement actions do not spell out specifics of what the agencies found at each institution, but they do give us important insights into what the regulators will expect during your next BSA compliance exam.

Community banks should evaluate their BSA compliance programs in light of the corrective actions that regulators require these institutions to take.

Another important issue that financial institution management should remember is that the USA PATRIOT Act made BSA compliance as important as Community Reinvestment Act (CRA) compliance in getting an application approved.  The act adds BSA as a factor for consideration in merger transactions. The agency must take into consideration “the effectiveness of any insured depository institution involved in the proposed merger transaction in combating money laundering activities.”  This means that banks and thrifts must have more than a written BSA program.  They must be able to demonstrate that the program works.

BSA compliance programs

All insured banks and thrifts must develop, administer, and maintain a program that assures and monitors compliance with the BSA and its implementing regulations, including recordkeeping and reporting requirements. Such a program can help protect a bank against possible criminal and civil penalties and asset forfeitures.

At a minimum, the board of directors must approve a bank’s written internal compliance program and note the approval in the board meeting minutes.

The program must include at least the following elements:

  • A system of internal controls to assure ongoing compliance
  • Independent testing of compliance
  • Daily coordination and monitoring of compliance by a designated person
  • Training for appropriate personnel
  • Risk-based customer due diligence/beneficial ownership procedures

Internal controls for the BSA

Senior management is responsible for assuring an effective system of internal controls for the BSA, including suspicious activity reporting, and must demonstrate its commitment to compliance by:

  • Establishing a comprehensive program and set of controls, including account opening, monitoring, and currency reporting procedures
  • Requiring that senior management be kept informed of compliance efforts, audit reports, identified compliance deficiencies, and corrective action taken – to assure ongoing compliance
  • Making BSA compliance a condition of employment
  • Incorporating compliance with the BSA and its implementing regulations into job descriptions and performance evaluations of bank personnel

Independent testing of compliance

The bank’s internal or external auditors should be able to:

  • Attest to the overall integrity and effectiveness of management systems and controls, and BSA technical compliance
  • Test transactions in all areas of the bank with emphasis on high-risk areas, products, and services to assure the bank is following prescribed regulations
  • Assess employees’ knowledge of regulations and procedures
  • Assess adequacy, accuracy, and completeness of training programs
  • Assess adequacy of the bank’s process for identifying suspicious activity

Internal review or audit findings should be incorporated after each assessment into a board and senior management report and reviewed promptly.  Appropriate follow up should be assured.

Regulators increasingly expect the BSA audit or testing program to also include these elements:

  • Confirmation of the integrity and accuracy of management information reports used in the AML compliance program
  • Overall integrity and effectiveness of the program
  • Evaluation of management’s efforts to resolve violations deficiencies
  • Evaluation of the effectiveness of the suspicious activity monitoring systems
  • Review of the BSA risk assess­ment for reasonableness given the bank’s risk profile

BSA compliance officer

A bank or thrift must designate a qualified bank employee as its BSA compliance officer, who has day-to-day responsibility for managing all aspects of the BSA compliance program and compliance with all BSA regulations.  The BSA compliance officer may delegate certain BSA compliance duties to other employees, but not compliance responsibility.

The bank’s board of directors and senior management must assure that the BSA compliance officer has sufficient authority and resources – time, funding, staffing – to administer effectively a comprehensive BSA compliance program.  And, the BSA officer must have a direct reporting channel to the board of directors.

Board of directors

The board must ensure that it exercises supervision and direction of the BSA/AML program.  This involves making sure that the institution develops sound BSA/AML policies, procedures, and processes that are approved by the board and implemented by management.  The board also has to ensure that the bank maintains a designated BSA officer with qualifications commensurate with the bank’s situation.  As noted above, the BSA officer must report directly to the board and be vested with sufficient authority, time, and resources.  The board must provide for an adequate independent testing of BSA/AML compliance.  The board should bear in mind that it has the ultimate responsibility for the institution’s BSA compliance.

Training

Financial institutions must ensure that appropriate bank personnel are trained in all aspects of the regulatory requirements of the BSA and the bank’s internal BSA compliance and anti-money laundering (AML) policies and procedures.

An effective training program includes provisions to assure that all bank personnel, including senior management, who have contact with customers (whether in person or by phone), who see customer transaction activity, or who handle cash in any way, receive appropriate training.  Board members also need to receive regular BSA/AML training, though at a much higher level with less detail than institution line employees.

The training needs to be ongoing and incorporate current developments and changes to the BSA, AML laws, and agency regulations.  Banks should address new and different money laundering schemes involving customers and financial institutions. The program should also include examples of money laundering schemes and cases, tailor them to the audience, and explain how the audience can detect or resolve such activities.

Another focus of the training should be on the consequences of an employee’s failure to comply with established policy and procedures (e.g., fines or termination).  These programs also should provide personnel with guidance and direction in terms of bank policies and available resources.

Beneficial ownership procedures

The beneficial ownership rule contains three core requirements:

  • Identifying and verifying the identity of the beneficial owners of companies opening accounts
  • Understanding the nature and purpose of customer relationships to develop customer risk profiles, and
  • Conducting ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information

A beneficial owner is an individual who owns more than 25 percent of the equity interest in a company or is the single individual who exercises control.  Also subject to these requirements is the one person who has control of each legal entity customer.

Beyond the basics

BSA enforcement actions continue to raise the bar for all financial institutions. BSA compliance programs must meet additional standards to be considered adequate to address the ever‑evolving challenges that arise over time.

  • Customer due diligence (CDD). Verifying a customer’s name, address, date of birth and identification number will satisfy the basic BSA customer identification requirements.  However, these four pieces of information will not be enough to help an institution deter­mine a customer’s typical account activity.  The recent C&D orders make clear that regulators expect community bank managers to use information collected as part of the institution’s CDD process to predict the type, dollar amount, and volume of transactions that a customer is likely to conduct.  This expectation goes beyond the new beneficial ownership rule to extend CDD expectations to the broader customer base. Regulators directed several institutions subject to the recent round of enforcement actions to develop specific procedures to describe how the institution will conduct customer due diligence. As computer and software technology has improved, regulators have come to expect small and large banks to gather and review information about the normal range of a customer’s banking activities.  They view the CDD processes and analysis as providing the framework that enables institutions to comply with suspicious activity reporting requirements.
  • Account & transaction monitoring. A number of institutions that received the most recent orders did not have adequate, or any, procedures for detecting and reporting suspi­cious activities. The enforcement actions make clear that community banks must specify in writing how the institu­tion will analyze and use customer information to detect suspicious activities.  As this area gets more complex, it becomes more difficult to try to maintain an adequate suspicious activity monitoring regimen without some form of automated monitoring.

Conclusion

The costs of being subject to an enforce­ment action go beyond extra regulatory scrutiny in subsequent examinations.  Institutions under the latest round of actions must report the enforcement action in communications with their shareholders and spend significant sums of money to hire outside consultants to train employees, audit the revised BSA programs and backfile required reports.  They also must submit planned actions to the regulators involved for prior approval, as well as report regularly (usually quarterly) on their progress in remediating the deficiencies that led to their particular enforcement action.

An interagency BSA enforcement policy statement clarifies that regulators will not issue formal enforcement actions for minor BSA infractions.  These enforcement actions are levied against financial institutions – including community banks – with significant breakdowns in their BSA compliance systems. The consent and other orders show that regulators expect all banks to have very specific procedures for collecting customer information, predicting customer account activity, utilizing transaction monitoring reports, and training and managing employees with BSA-related responsibilities.

Be sure that you are not an object lesson for your banking fellows.  If we can help, contact us today.

Connect with a Consultant

Contact us to learn more about our consulting services and how we can add value to your financial institution

Ask a Question