Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Regulatory Compliance

Exam Readiness KRIs: Evidence Gaps, Repeat Requests, and Aging Management Responses

Six key risk indicators for exam readiness that go beyond checklists — tracking evidence gap rates, repeat examiner requests, aging commitments, and validation completeness before the examiner asks.

Table of Contents

TL;DR

  • Exam readiness is not a pre-exam checklist problem — it’s a continuous KRI problem. Teams that scramble before an exam have already lost the argument.
  • The six exam readiness KRIs that matter: evidence gap rate, repeat request rate, aging management responses, unresolved commitment count, validation completeness rate, and document owner response time.
  • The OCC’s October 2025 MRA framework shift doesn’t reduce the tracking obligation — it extends it to cover supervisory observations that won’t generate formal commitment letters but will be revisited.
  • An examiner who gets a complete, timely, validated evidence package doesn’t need to write an MRA. An examiner who gets incomplete documentation, late responses, and commitments represented as closed without validation evidence absolutely does.

Examiners don’t fail institutions because compliance work didn’t happen. They fail institutions because the work can’t be proven.

The distinction matters more than most compliance programs are built to handle. You’ve got monitoring reviews scheduled and completed. You’ve got training records. You’ve got board-approved policies. But when the OCC or FDIC examiner sends a request list, three things happen that shouldn’t: some documents take three days to locate, some evidence is a year out of date, and some commitments from the prior exam are still marked “in progress” against a target date that passed in Q3.

The problem isn’t effort. It’s that nobody built a KRI for exam readiness.

What Exam Readiness KRIs Measure

Most teams approach exam readiness as a pre-exam event: they run through a checklist, verify documents exist, prepare staff talking points, and organize the evidence binder. That’s not wrong — it’s just twelve weeks too late.

Exam readiness KRIs turn the evidence question into a continuous measurement. They track whether your program can prove its work to an examiner at any point, not just after a request letter arrives. They also track whether prior exam findings were actually fixed — which is the question every examiner asks first.

The OCC’s Bank Supervision Process handbook specifies that examination data sources include past supervisory findings and conclusions, independent testing, and information available through ongoing monitoring processes. Examiners arrive with your prior-cycle record. They know what was requested. They know what was committed to. They’ll test whether it was addressed.

These are the six KRIs that tell you whether you’re ready before they do.


KRI 1: Evidence Gap Rate

What it measures: The percentage of examiner document requests that were not fulfilled on time or not fulfilled at all during an examination cycle.

Why it matters: Evidence gaps are the most direct signal of a documentation problem. A gap isn’t just a retrieval inconvenience — it tells an examiner that a monitoring activity, a policy review, or a control test may not have happened.

Track this by request category. A high gap rate on monitoring reports means your monitoring program isn’t producing exportable documentation. A high gap rate on board minutes means board-level oversight of risk topics isn’t being documented. A high gap rate on training records by business line means training isn’t tracked in a queryable system.

ThresholdCriteria
GreenGap rate <10% overall; no gaps in Critical/High-priority request categories
AmberGap rate 10–20%; or any gap in a Critical request category with a known retrieval cause
RedGap rate >20%; or any gap in a Critical category with no retrieval plan; or repeat gap in the same category as prior exam

Data source: Examiner request letter mapped to fulfilled vs. unfulfilled items. Track each request by category, date requested, date fulfilled, and reason for any delay or gap.


KRI 2: Repeat Request Rate

What it measures: The percentage of items on the current exam request list that were also requested in the prior exam cycle.

Why it matters: When an examiner asks for the same thing twice, they’re signaling that the prior-cycle gap wasn’t structurally addressed. Repeat requests mean the documentation problem persists — and the examiner now has evidence of recurrence.

A 10–15% repeat rate is typical across exam cycles — some requests are standard regardless of gaps. A rate above 20–25% means prior-cycle documentation failures weren’t structurally fixed; they were addressed as one-time retrieval problems rather than process gaps.

ThresholdCriteria
Green<15% overlap between current and prior exam request lists
Amber15–25% overlap; prior-cycle gap explanations documented and remediation confirmed
Red>25% overlap; or any repeat request in a category that generated a formal finding in the prior cycle

Data source: Archived prior exam request letters compared against the current request list. A cross-reference by request category is sufficient if you archived the prior list.

This KRI requires keeping prior exam request lists — not just findings letters. Most programs discard the request list after the exam closes. Don’t.


KRI 3: Aging Management Responses

What it measures: Average days from commitment made to target completion date; separately, the percentage of open commitments past their target date.

Why it matters: An examiner who returns for a follow-up examination asks one question before anything else: what commitments did you make last cycle, and which ones are still open? If 30% of commitments are past their target dates, the exam starts badly.

The OCC’s October 2025 proposed rulemaking on MRA issuance includes specific attention to MRA closure, requiring agencies to validate that commitments have been fulfilled — not just represented as fulfilled. The proposed framework specifies that MRA closure verification, validation, and timing are all subject to examiner review. OCC Bulletin 2025-29 sets out the proposed framework, including that MRAs may only be issued for practices that could reasonably be expected to become unsafe or unsound, or actual law violations — a higher bar, but one that also means any MRA that does get issued is material by definition.

ThresholdCriteria
Green100% of commitments within 30 days of target have documented progress updates; <5% past target date
Amber5–15% of commitments past target date with documented extension rationale; or >25% within 30 days of target with no progress evidence
Red>15% past target date; or any commitment from more than 12 months ago still open without escalation; or board hasn’t reviewed commitment status in the prior quarter

Data source: Commitment register with target dates, actual completion dates, and evidence of completion. Review at senior management level monthly and board or risk committee level quarterly.

For the documentation structure examiners expect to find behind these commitments, the CFP evidence binder and exam readiness documentation guide covers the format in detail.


KRI 4: Unresolved Commitment Count

What it measures: The total number of examination and supervisory commitments from all prior cycles that remain open at the start of the current exam.

Why it matters: This KRI is most directly correlated with exam outcomes. An institution that enters an exam with zero open commitments from prior cycles signals a mature issues management program. One with fifteen open commitments from three prior cycles signals chronic remediation failure — before the current-cycle examination even begins.

The FDIC’s Consumer Compliance Examination Manual specifies that examiners assess whether previously identified weaknesses have been corrected before rating the current examination. Open commitments influence CAMELS ratings and MRA issuance based on prior-cycle performance, not just findings identified in the current visit.

ThresholdCriteria
Green0 open commitments from prior exam cycles; all closed commitments have validation evidence
Amber1–3 open commitments with documented plans and progress evidence
Red>3 open commitments; or any commitment open for more than 2 exam cycles; or any High/Critical commitment without a documented escalation path

Data source: Commitment register tagged by exam cycle of origin. Track separately from current-cycle issues so aging across cycles is visible.

One nuance from the OCC’s 2025–2026 supervisory reset: the shift toward focusing on material financial risks means some informal supervisory observations won’t generate formal commitment letters. Track those separately — they still create examiner expectations that will be tested at the next visit.


KRI 5: Validation Completeness Rate

What it measures: The percentage of commitments marked “closed” that have documented independent validation — vs. self-certification by the business line or first line only.

Why it matters: Examiners treat self-certified closures differently from validated closures. A management memo stating that a control was fixed is not the same as an independent second-line or internal audit test confirming the control is operating effectively. When examiners find that closures lack independent validation, they frequently reopen the finding.

The FDIC’s Risk Management Manual of Examination Policies addresses examiner expectations for closure evidence: management responses must demonstrate that remediation steps were taken and that recurrence is being monitored.

ThresholdCriteria
Green≥90% of closed commitments have independent validation documentation; validation conducted within 60 days of reported completion
Amber75–90% have independent validation; or average time from completion to validation >90 days
Red<75% have independent validation; or any High/Critical commitment closed via self-certification only; or validation tests that confirmed closure were later found to be insufficient

Data source: Commitment register showing close date, close method (self-cert vs. independent validation), validator role, and validation evidence type.

This is where most programs have their biggest exam readiness gap. The compliance KRIs and program health post covers the independent review CMS pillar that validation completeness feeds directly into — examiners test this pillar as part of every compliance management system assessment.


KRI 6: Document Owner Response Time

What it measures: The percentage of examiner requests — and internal evidence requests — where the delay was caused by inability to locate the document owner or the documentation itself.

Why it matters: When the person who built the monitoring framework left and their successor doesn’t know where anything is, it shows up as an evidence gap. But the cause — poor documentation ownership — needs to track separately because it requires a different fix.

High document-owner response time typically signals:

  • No formal document ownership registry with current assignments
  • Documentation living in individual email folders or personal drives
  • No naming convention or versioning for monitoring reports and testing results
  • Staff turnover without a documentation handoff process
ThresholdCriteria
Green<5% of requests delayed due to ownership or location issues; document ownership registry exists and is current
Amber5–15% of delays attributable to ownership or location; registry exists but not fully current
Red>15% of delays attributable to ownership or location; no formal registry; multiple critical documents with a single point-of-failure owner

Data source: Request fulfillment log with delay reason codes. Track reasons for delays explicitly: document not found, owner unavailable, document outdated, process not documented.

For the broader KRI exception management process — what to do when any of these metrics hit amber or red — the KRI exception escalation framework covers the escalation path and documentation requirements.


Building the Exam Readiness Dashboard

These six KRIs belong in a single dashboard that senior management reviews monthly and the board or risk committee reviews quarterly. The dashboard shouldn’t require an active examination to be useful — its function is to signal drift before the exam cycle opens.

KRICurrent PeriodPrior Exam CycleTrendStatus
Evidence gap rate
Repeat request rate
Aging commitments (% past target)
Unresolved commitments (count)
Validation completeness rate
Document owner response time

The “Prior Exam Cycle” column is what makes this dashboard useful. Most programs track current-period status without a baseline. The trend — improving, stable, deteriorating — is what management should be discussing, not the raw numbers.


The Pattern Behind Exam Failures

Most examination failures aren’t caused by programs that don’t do the work. They’re caused by programs that do the work but can’t prove it when asked — because evidence wasn’t organized, commitments weren’t tracked, and closures weren’t validated independently.

Bridgeforce’s exam readiness framework frames the core principle clearly: functions with recent findings should be automatically flagged as higher risk and prioritized for pre-exam review. That’s exactly what a KRI program provides — a continuous priority signal, not a one-time pre-exam assessment.


So What?

An examiner who receives a complete evidence package, timely responses, and documented independent validation on prior commitments has limited grounds for formal findings. An examiner who encounters incomplete documentation, late responses, and commitments closed via self-certification has everything needed for a material supervisory concern.

The difference isn’t whether you did the work. It’s whether you built the measurement infrastructure to prove you did it before the request letter arrived.

The Compliance Essentials bundle includes templates for tracking exam commitments, structuring the evidence documentation these KRIs measure, and organizing the validation trail that turns a represented-as-closed commitment into a verified-closed one. If you’re building this infrastructure now rather than the week before an exam, that’s the right starting point. Get the Compliance Essentials bundle.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is an exam readiness KRI?
An exam readiness KRI is a metric that measures whether your organization can demonstrate compliance to a regulator — not just whether compliance activities are occurring. The most useful exam readiness KRIs measure evidence quality, document accessibility, commitment follow-through, and whether previous examination findings have been remediated and validated. They function as a continuous signal of exam preparedness, not a one-time pre-exam checklist.
How do repeat examiner requests become a KRI?
A repeat request occurs when an examiner asks for something in the current exam that was also requested in the prior exam — the same document type, the same process evidence, the same data. When more than 20–25% of your current exam request list overlaps with your prior exam list, it signals that prior-cycle evidence gaps were not structurally addressed. Tracking this across exam cycles is more predictive than any pre-exam readiness checklist.
What's the difference between a commitment being 'closed' and being 'validated'?
A commitment is closed when management reports the action was taken. A commitment is validated when an independent reviewer — typically second-line or internal audit — confirms the root cause was addressed and the issue has not recurred. The gap between these two is where most exam preparation programs break down. Examiners verify closures by looking for validation evidence; management self-certifications without independent validation are treated as provisional closures at best.
How should evidence gap rates be measured?
The evidence gap rate is the number of examiner document requests that could not be fulfilled on time or at all, divided by total requests in the exam cycle. Track it by request category — policies, monitoring reports, testing results, board minutes — so you can identify which documentation area has the highest failure rate. A rate above 15% in any category is a strong signal of a structural documentation gap, not just a retrieval problem.
How do the OCC's 2025 MRA framework changes affect how institutions should track exam commitments?
The OCC's October 2025 proposed rulemaking on MRA issuance sets a higher bar for formal MRA issuance — but doesn't eliminate the tracking obligation. Examiners are directed to focus on material financial risks and issue supervisory observations for less material items. This means commitment tracking must span both formal MRAs and informal supervisory observations, which don't generate formal commitment letters but still represent examiner expectations that will be revisited at the next cycle.
What is document owner response time and why does it matter as a KRI?
Document owner response time tracks the percentage of examiner requests — and internal evidence requests — where the delay was caused by inability to locate the document owner or the documentation itself. High response time is often a sign of no formal document ownership registry, documentation living in personal drives, or staff turnover without an ownership handoff. It requires a different fix than an evidence gap driven by work that simply wasn't done.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Compliance Essentials

Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.