Feature Operational Risk
CRE Concentration Risk: How to Build the Policy Framework Your OCC or FDIC Examiner Will Actually Test
31% of US banks exceeded the CRE concentration threshold at year-end 2024. Here's how to build the credit policy limits, stress testing methodology, and documentation artifacts that show you've made a deliberate, defensible risk decision — not just stumbled into concentration.
Table of Contents
TL;DR:
- Approximately 1,374 banks (31% of all FDIC-insured institutions) exceeded the CRE concentration threshold at year-end 2024. Mid-sized banks have median CRE concentrations right at the 300% supervisory trigger.
- The 300% threshold isn’t a regulatory limit — it’s a supervisory signal. Being above it doesn’t mean you’re in trouble. Not having a defensible risk management program means you’re in trouble.
- A defensible CRE concentration risk policy requires six components: portfolio limits, sub-segment limits, an exception process, a stress testing methodology, remediation triggers, and board reporting.
- CRE past-due and nonaccrual rates ticked up to 1.45% in 2025. Office and retail sub-segments are under sustained pressure. Loan modification and extension practices that suppress reported delinquency are an active examiner focus.
The examiner knows your CRE ratio before they walk in the door. They pull it from Call Report data the same week they schedule the examination. What they don’t know yet — and what they’re coming to find out — is whether you made a deliberate, documented decision about what level of concentration risk you’re carrying and why.
That gap is where most CRE concentration risk management programs fall apart. The loan portfolio grew, the ratio crossed the supervisory threshold, and the credit policy still says something like “management will monitor CRE concentrations relative to capital and ensure they remain within acceptable levels.” That’s a monitoring commitment, not a risk management framework.
In 2026, with the FDIC’s 2026 Risk Review identifying CRE as one of five elevated supervisory priorities and mid-sized banks hovering right at the threshold, a vague concentration policy is a liability.
What the 300% Threshold Actually Triggers
The foundational document for CRE concentration risk management is the 2006 Interagency Guidance on Concentrations in Commercial Real Estate Lending — a joint OCC, Federal Reserve, and FDIC issuance that has governed examiner expectations for nearly two decades. The guidance establishes two distinct supervisory thresholds:
| Loan Category | Supervisory Threshold | What It Triggers |
|---|---|---|
| Construction & land development (ADC) | ADC loans ≥ 100% of Tier 1 Capital + ACL | Enhanced review of underwriting standards, portfolio monitoring, stress testing adequacy |
| Total CRE | CRE loans ≥ 300% of Tier 1 Capital + ACL AND portfolio growth ≥ 50% in prior 36 months | Full enhanced oversight: risk management program, capital adequacy, ACL methodology |
Neither number is a regulatory cap. A bank can exceed both and still receive a satisfactory safety and soundness rating — if its risk management infrastructure is sophisticated enough to justify the exposure. The question the examiner is answering is not “are you above 300%?” It’s “do you know why you’re there, and do you have the governance to manage it?”
As of year-end 2024, approximately 1,374 institutions exceeded the CRE threshold — about 31% of all FDIC-insured banks — with mid-sized institutions carrying median concentrations hovering around 300% of Tier 1 capital and reserves. The FDIC’s 2026 Risk Review notes the CRE past-due and nonaccrual (PDNA) rate reached 1.45% in 2025, with office and retail sub-segments under continued pressure from elevated vacancy rates and constrained refinancing conditions.
The December 2023 FDIC FIL-23-064 advisory reemphasized these expectations in light of the current credit environment, with specific attention to loan modification and extension practices. Modifications and extensions are a legitimate credit management tool — but when they’re used systematically to avoid reporting past-due status, they suppress the metrics that should be triggering management attention and reserve increases.
The Six Components of a Defensible CRE Concentration Policy
Most credit policies say something about CRE concentrations. The problem is that “something” is often one sentence: “Management will monitor CRE concentrations relative to capital and ensure they remain within acceptable levels.”
That’s not a risk management program. It’s a placeholder that tells an examiner the institution hasn’t thought carefully about what it will do when the ratio is too high.
A credit policy that an examiner can actually test against has six components:
1. Portfolio-Level Concentration Limits
Set overall CRE as a percentage of Tier 1 capital plus ACL, with a specific number your board has reviewed and approved. If the institution’s internal limit is 275% — below the 300% supervisory threshold — the policy says so. If the board has reviewed and approved a limit of 340% based on the institution’s capital position, diversification, and stress testing framework, the policy says that too — and documents the reasoning that supports it.
Vague policies let portfolios creep into concentration territory without triggering governance. Specific limits create the governance event that forces a management decision.
2. Sub-Segment Limits
Total CRE is only part of the story. Both the 2006 interagency guidance and the FDIC’s ongoing CRE supervisory focus make clear that examiners will look at the distribution within the portfolio. Institutions in markets with significant office vacancy that don’t have a separate office sub-segment limit will face the “did you know your office concentration was 190% of Tier 1 capital?” question from an examiner who already has the answer.
Sub-segment limits should cover at minimum: office, multifamily/residential income-producing, industrial/warehouse, retail, hotel/motel, and ADC. Sub-segment limits don’t all need to be the same — a bank with strong multifamily underwriting expertise and diverse geographic exposure in that segment can justify a higher multifamily limit than its office limit.
3. Exception Approval Process
When a loan would push a sub-segment above its limit, who approves it? What documentation is required for the exception? What’s the committee threshold for escalation above which the Chief Credit Officer or board committee must sign off?
If the answer is “it goes to credit committee with a memo explaining the concentration impact,” the policy says that, and the credit committee minutes document the approval and the concentration analysis.
4. Stress Testing Methodology
This is where most programs fall short. A stress test methodology isn’t a scenario. It’s a documented process: which portfolio segment is being stressed, what the stress assumptions are, how those assumptions were derived, who reviews the results, what the governance escalation looks like when loans breach stress thresholds, and how stress results feed into the ACL adequacy analysis.
FDIC examiners have consistently cited four findings in CRE stress testing reviews: insufficient portfolio segmentation, stress assumptions built on stale or internally inconsistent data, results that weren’t escalated to senior management or the board, and no documented link between stress findings and reserve methodology. All four are fixable with documentation discipline — none require rebuilding a stress model from scratch.
5. Remediation Triggers
What governance action is required when the CRE portfolio approaches 85% of the internal limit? What’s the mandatory reporting threshold to senior management? To the board? Policies with specific triggers force institutional responses before the ratio crosses the limit — instead of discovering at quarter-end Call Report time that the portfolio moved above a threshold nobody noticed.
6. Board Reporting Cadence
How frequently does the board see CRE concentration reporting? In what format? The OCC’s Concentrations of Credit Handbook (October 2020) expects board-level awareness of concentration risk and the management framework for managing it. A board that can’t describe the institution’s sub-segment limits — or when it last reviewed stress test results — is an examiner finding waiting to be written.
What “Adequate Stress Testing” Actually Means in 2026
The gap between what institutions call a CRE stress test and what examiners accept has widened since 2020. A defensible stress test demonstrates what happens to your portfolio under a “severe but plausible” scenario in terms of specific credit metrics, not just aggregate dollar losses.
For CRE in the current environment, that means:
Rate shock: What does a 2020-vintage CRE loan look like at 2026 interest rates if it hasn’t refinanced? Many CRE loans originated during the low-rate period used appraised values and debt service assumptions that simply don’t hold at current rates.
Vacancy stress: For office and retail sub-segments, what happens to debt coverage ratios at 15%, 20%, and 25% increases in vacancy from current levels? The answer should come with a specific DCR calculation by sub-segment, not a general “we expect stress would reduce valuations.”
Cap rate expansion: What does a 100–150 basis point cap rate expansion do to collateral values across the CRE portfolio relative to current appraised values? And how does that LTV shift compare to your lending standards?
Geographic concentration: If a meaningful portion of your CRE book is in a single metro market or property type, the stress test should model what a market-specific shock looks like for that sub-concentration.
For community banks running their first structured CRE stress test, the OCC’s and FDIC’s shared expectation is: a documented, reproducible methodology conducted at least annually. “Reproducible” is the word to focus on — examiners should be able to trace from assumptions to conclusions and understand exactly how you got there.
For a broader operational risk scenario methodology, our post on operational risk scenario analysis covers the “severe but plausible” framework and how to defend scenario assumptions in an exam context.
The Documentation Artifacts an Examiner Will Request
When reviewing CRE concentration risk management, an OCC or FDIC examiner will typically request the following:
- Credit policy, with concentration limits section (by portfolio level and sub-segment)
- Sub-segment CRE portfolio breakdown as a percentage of Tier 1 capital + ACL (current and prior four quarters)
- Most recent CRE stress test, including scenario assumptions documentation
- Board and senior management meeting minutes confirming stress test results were reviewed
- Loan modification and extension tracking for CRE credits
- The CRE section of the most recent ACL adequacy analysis
- Any internal audit or compliance review findings related to CRE risk management
Institutions that received a prior MRA on CRE concentration management should expect the follow-up examiner to ask specifically for remediation documentation: what policy language changed, what governance actions were taken, and what evidence demonstrates the changes are embedded in ongoing operations — not just written into a policy document that nobody follows.
The FDIC 2026 Risk Review exam priority analysis covers what examiners are asking about across all five elevated risk areas. For the ongoing monitoring side, the credit risk KRI post covers the specific metrics — CRE PDNA by sub-segment, loan maturity schedules, modification rates — that belong in board-level concentration reporting.
If your institution needs to build out the full KRI framework to support concentration monitoring, the KRI Library (132 Key Risk Indicators) includes pre-built credit risk KRIs with green/amber/red thresholds calibrated for financial institutions — including metrics specifically designed for CRE portfolio monitoring and examiner reporting.
So What?
If your institution is above 200% CRE-to-capital, this is not the year to carry a vague concentration policy into an examination. The FDIC 2026 Risk Review has put supervisors on notice that CRE is an elevated priority. Examiners at institutions at or above the 300% threshold will ask pointed questions about sub-segment composition, stress test assumptions, and board awareness.
The program upgrade required isn’t complex. Review your credit policy’s concentration section — does it state specific limits by sub-segment, or just commit to monitoring? Document your stress testing methodology at a level where a second examiner could reproduce it. Verify that board meeting minutes reflect CRE stress results in the last 12 months.
That’s not a program overhaul. It’s the documentation that transforms a concentration ratio from a number into a deliberate, reviewable risk decision.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is the 300% CRE concentration threshold and what does it actually trigger?
How many banks are currently at or above the 300% CRE concentration threshold?
What are the six components of a defensible CRE concentration risk policy?
What do examiners look for when reviewing CRE stress tests?
What is FDIC FIL-23-064 and what does it require?
What documentation artifacts will an examiner request when reviewing CRE concentration risk management?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Keep reading
Related posts.
Operational Risk
Risk Assessment Template in Excel: Build the Evidence Trail, Not Just the Heat Map
Build a risk assessment template in Excel that preserves evidence, challenge, approvals, and score history—not just a polished heat map.
Jul 23, 2026
Operational Risk
FedNow's Network Intelligence API Launched in April 2026. Your Fraud Risk Program Probably Hasn't Caught Up.
On April 28, 2026, the Federal Reserve made pre-payment network-level fraud intelligence available to every FedNow participant. The data — receiver account behavioral trends derived from system-wide FedNow activity — is available before a transaction is approved. Most institutions haven't updated their fraud policies, controls, or KRIs to account for what this changes.
Jul 21, 2026
Operational Risk
3,383 Incidents Later: What DORA's First ICT Data Reveals About Your Operational Risk Program
The ESAs published their first DORA ICT incident report in June 2026 — 3,383 major incidents, nearly one-third from third-party failures, only 10% cyber-related. Here's what the data means for your operational risk program.
Jul 16, 2026