Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Compliance Strategy

The Deregulation Era Compliance Trap: Why a Lighter Federal Touch Makes Internal Controls More Important, Not Less

Federal banking regulators have reduced exam frequency, softened model risk guidance, and repositioned enforcement as a last resort. The compliance trap is assuming that means you can do less. Here's what's actually happening to the risk landscape — and what compliance programs get wrong during deregulatory periods.

Table of Contents

TL;DR

  • The FDIC reduced consumer compliance exam frequency for well-rated banks to a 5-6 year cycle with midcycle review; the OCC’s 2026 model risk guidance is explicitly non-enforceable
  • Lighter federal oversight does not reduce legal obligations — it increases the window for issues to compound undetected before an examination finds them
  • State AGs in New York, California, and Texas are expanding consumer financial enforcement as the federal footprint contracts
  • The compliance programs that fail during deregulatory periods are the ones that optimized for exam performance instead of building programs that run on their own

There’s a phrase that shows up in almost every deregulatory period in U.S. banking history: “the pendulum will swing back.” It’s usually said by compliance officers trying to explain why they’re maintaining controls that the current examination environment doesn’t require. It’s almost always right. And the compliance officers who ignored it are the ones who generated findings in the next supervisory cycle that took three years and a consent order to work through.

The 2026 federal deregulatory shift is real: reduced exam frequency, advisory-only model risk guidance, an enforcement bureau that has committed to resolving issues collaboratively before pursuing formal action. If you read that as a signal to thin out your compliance program, you’re making a mistake that has a historical record behind it. Here’s what the deregulatory environment actually means for compliance strategy.

What Has Actually Changed

Let’s be precise about what federal regulators have and haven’t done, because the distinction matters for calibrating your response.

FDIC exam frequency reduction (November 2025 FIL)

The FDIC issued supervisory guidance reducing consumer compliance examination frequency for well-rated community and regional banks. The new schedule:

  • Banks with $350M–$3B in assets rated 1 or 2: full consumer compliance exam approximately every 5 years, with a midcycle review in year 2 or 3
  • Banks under $350M in assets rated 1 or 2: approximately every 6 years with a midcycle review (66-78 month cycle)

Separately, the FDIC raised the threshold for continuous examination — the oversight model where examiners are essentially in residence — from $10B to $30B in assets.

What this changes: the frequency of formal examination. What it doesn’t change: the legal obligations those examinations assess. A fair lending violation that would have been found in year two of the old cycle will now be found in year four or five of the new cycle — and it will have compounded for longer.

OCC model risk guidance 2026-13

The OCC issued guidance on model risk management that includes an explicit disclaimer stating it “does not set forth enforceable standards or prescriptive requirements, and non-compliance will not result in supervisory criticism.”

That’s an unusual formulation for a supervisory guidance document. It means the guidance is advisory — the OCC is sharing views on sound practices, not establishing minimum expectations. The underlying model risk management obligations from SR 11-7 and SR 26-2 remain enforceable. Examiners assessing model risk programs will use those frameworks; they’re not obligated to follow the 2026-13 advisory guidance in their assessments.

CFPB enforcement principles (June 22, 2026)

The CFPB published its new Enforcement Principles, organizing the Bureau’s enforcement discretion around actual harm, due process, collaboration, and efficiency. The “collaboration” principle explicitly commits to working with institutions to resolve issues before pursuing formal action, and acknowledges that “not all situations require an adversarial process.”

What this changes: the enforcement sequence. An institution that discovers a compliance failure, remediates it proactively, and can document the remediation is significantly less likely to face a formal enforcement action under the current Bureau than under the previous one.

What it doesn’t change: UDAAP standards, fair lending obligations, or the legal framework for consumer financial protection. The substantive law hasn’t moved.

The Compounding Problem

When regulators examine less frequently, two things happen simultaneously.

First, issues take longer to surface. A fee calculation error that an examiner would have found in year two is now discoverable in year five. During those additional three years, the error is being applied to every eligible account, generating cumulative harm that grows with each passing month. When the issue surfaces — through an examination, a consumer complaint, or internal audit — the remediation scope is proportionally larger.

Second, internal attention drifts. This is the more insidious problem. Examination cycles create organizational accountability. Compliance testing gets done when an exam is scheduled. Policies get reviewed when a reviewer is coming. Issues management gets prioritized when someone needs to show a regulator that open findings are being tracked. When that external accountability disappears for five or six years, compliance program maintenance tends to slip toward lower-priority status.

The historical pattern is consistent: deregulatory periods are followed by enforcement cycles that focus heavily on exactly the controls that atrophied during the lighter-touch era. The compliance programs that avoid consent orders in the next cycle are the ones that maintained controls independent of examination pressure.

What State AGs Are Actually Doing

The federal deregulatory shift has a state counterpart that most compliance programs haven’t fully incorporated into their risk calendars.

The CFPB’s efficiency principle commits the Bureau to avoid duplicative enforcement when states are already pursuing the same conduct. That’s an invitation for state enforcement that doesn’t face federal overlap — and state AGs have moved into the space the Bureau has vacated.

New York DFS continues as one of the most active financial services regulators in the country. Its supervision of fintechs, payment processors, virtual currency businesses, and digital lending platforms hasn’t moderated. DFS has a unique enforcement mechanism — the BitLicense framework and expanded financial services licensing requirements — that creates compliance obligations independent of federal law.

California DFPI has expanded its coverage of embedded finance, earned wage access, and digital payment services. The Covered California consumer financial products list has grown to include categories that didn’t exist when the DFPI was established. State UDAAP enforcement authority under California law is broader than CFPB authority in some respects.

Texas AG consumer protection is structurally different — it operates through consumer protection statutes rather than a dedicated financial regulator — but the division has been pursuing financial services enforcement actions in areas that overlap with federal consumer financial protection authority.

For institutions with material consumer presence in any of these states, the enforcement exposure hasn’t shifted away from consumer financial protection — it’s shifted to venues that don’t have the CFPB’s due process commitments and don’t typically follow the same collaborative resolution approach the Bureau has adopted.

The CFPB’s new enforcement principles explain how the collaborative enforcement model works in practice — including what the Bilt case tells you about what “cooperation” actually requires.

The Specific Things That Atrophy First

Based on the pattern of compliance program degradation in prior deregulatory periods, four areas are most likely to show deterioration:

Issues management

Issues management is the canary in the coal mine. When exam pressure is off, open compliance findings tend to stay open. Remediation target dates get extended. Issues get downgraded in severity when nobody is looking. An examiner arriving after a five-year cycle who finds 40 open issues with average ages of 18 months has learned everything they need to know about how the compliance program actually functions.

A properly structured issues management system logs every compliance finding — internal audit, self-assessment, examination, risk monitoring — with a remediation owner, a target date, and a current status. It escalates overdue items automatically. It reports to the risk committee quarterly so there’s a governance trail showing the board knows what’s open. That system needs to run on its own schedule, not on an exam schedule.

Compliance testing cadence

Self-assessment and compliance testing programs tend to align their cycles to examination timing. When exams happen every two years, testing happens every two years. When exams stretch to five or six years, testing slips to three or four years. The practical result is that issues that would have been caught in year-two testing aren’t caught until year four, and by then the exposure has grown.

Annual compliance testing that runs on a calendar independent of examination scheduling is the minimum floor for maintaining program health. Higher-risk areas — fair lending, UDAAP-adjacent fee practices, complaint management — warrant semi-annual assessment.

Policy review and update cycles

Compliance policies get written, approved, and then quietly drift out of alignment with current regulatory guidance. Under a two-year exam cycle, the next exam creates a forcing function for policy review. Under a six-year cycle, a policy written in 2026 with embedded references to the regulatory environment of 2026 may still be in force in 2031, unchanged, as the environment has evolved around it.

A policy review calendar that operates on a 12-18 month review cycle for each major policy — independent of examination timing — is the infrastructure that prevents policy drift.

Training completion and content currency

BSA/AML training, fair lending training, UDAAP training — these tend to get prioritized when examiners are coming. When the exam cycle extends, completion rates often drift and content stays static. Both are visible to an examiner reviewing the program.

Training content that hasn’t been updated to reflect the 2026 regulatory environment is a flag. Training completion rates below 90% are a flag. The examiner who arrives in year five is specifically looking for evidence that the compliance program ran during the years when nobody was watching — and training records are one of the most accessible proxies for program activity.

The Issues Management Imperative

Of all the areas that atrophy during light-touch periods, issues management is the one that has the most direct relationship to enforcement outcomes.

The CFPB’s collaborative enforcement framework is predicated on one thing: the institution knowing about the problem and doing something about it. A bank that identified a fee error in its own compliance review, tracked it through issues management, and remediated it before examination gets a very different outcome than a bank that the examiner finds it in.

That self-discovery-and-fix outcome only happens if you have a working issues management system. “Working” means: findings get logged when they’re discovered, not when they’re convenient. Remediation owners are assigned. Closure requires evidence, not just declaration. Escalation paths to senior management and the risk committee are documented and used. Status is reported regularly regardless of whether an exam is scheduled.

An issues management system that runs on exam timing isn’t really an issues management system — it’s exam preparation. The distinction matters when regulators show up after a five-year absence and ask for the log of issues identified and resolved since the last examination.

The AI risk governance examination requests illustrate the same principle in a different regulatory context — examiners can distinguish between documentation that predates the exam and documentation assembled in response to it.

What to Do With the Extended Runway

A six-year exam cycle isn’t a vacation — it’s a longer interval between external checkpoints during which your compliance program needs to demonstrate it was running. The institutions that come out of the next examination cycle with clean reports will be the ones that used the extended runway to build compliance infrastructure, not the ones that treated it as permission to coast.

Three specific structural moves:

Build an issues management system that runs independent of exam timing. If your current system requires an exam to be on the horizon to function, rebuild it. Every finding from internal audit, self-assessment, regulatory letter, or risk monitoring should go into the log. Every item should have a status and a next-action date. The log should report to the risk committee quarterly.

Run annual compliance testing on a calendar schedule. Decouple your testing program from your exam schedule. Fair lending, UDAAP risk areas, complaint management, and CRA compliance should be assessed at least annually. The documentation of that testing — what was tested, what was found, what was done about it — is the evidence that the compliance program was operating during the years between exams.

Expand your state AG monitoring. For any institution with material presence in New York, California, or Texas, build state enforcement monitoring into the compliance intelligence program. Track DFS enforcement actions, DFPI orders, and Texas AG consumer protection settlements the same way you track federal agency actions. The enforcement environment hasn’t moderated — it’s decentralized.

An Issues Management Tracker Template provides the logging structure, escalation workflows, and reporting format that make an issues management system functional for both internal oversight and external examination — including the field-level documentation that shows regulators the system was running before they arrived.

The Long Game

The pendulum does swing back. It always has. The compliance programs that have clean records through the next examination cycle — the one five or six years from now — will be the ones that maintained controls during the deregulatory period, not because they expected the pendulum to swing, but because they understood that compliance obligations exist independent of examination pressure.

State enforcement is already moving to fill the federal void. The AML program obligations haven’t changed. Fair lending liability is federal law, not exam policy. UDAAP standards are in the statute.

The regulatory environment in 2026 is a genuinely lighter-touch federal environment. It’s not a compliance holiday. Build the program that runs without an examiner watching — because it’s going to need to.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What has changed in federal bank exam frequency in 2026?
The FDIC issued FIL guidance in November 2025 reducing consumer compliance examination frequency for well-rated institutions. Banks between $350M and $3B in assets rated 1 or 2 now receive full consumer compliance exams approximately every five years with a midcycle review, versus more frequent cycles previously. Banks under $350M face roughly a six-year cycle with midcycle review. Separately, the FDIC raised the threshold for continuous examination from $10B to $30B in assets.
Does OCC's 2026 model risk guidance reduce compliance obligations?
The OCC issued guidance 2026-13 on model risk, which explicitly states it 'does not set forth enforceable standards or prescriptive requirements, and non-compliance will not result in supervisory criticism.' That means the guidance is advisory, not mandatory. However, the underlying model risk obligations from SR 11-7 and SR 26-2 remain enforceable. Banks that interpret the advisory framing as reducing model risk obligations are misreading the guidance.
What happens to compliance risk during deregulatory periods?
Reduced examination frequency doesn't reduce underlying legal obligations — it increases the consequences of non-compliance when violations are eventually discovered. Examination cycles of five to six years mean issues can compound for years before a regulator finds them. Additionally, deregulatory periods historically produce internal control atrophy: compliance resources get cut, testing cadences slow, and institutional attention drifts toward revenue-generating activities. The compliance programs that hold up are the ones that maintained controls independent of examination pressure.
Are state AGs actually increasing enforcement while federal regulators pull back?
Yes. New York DFS, California DFPI, and the Texas AG's consumer protection division have all expanded consumer financial enforcement activity in 2025 and 2026. The CFPB's new Enforcement Principles explicitly commit to deferring when states are already pursuing the same conduct, which reduces the risk of federal action crowding out state enforcement. For financial institutions with material consumer presence in New York, California, or Texas specifically, state enforcement exposure has likely increased even as federal enforcement has moderated.
What compliance program elements are most at risk during deregulatory periods?
The highest-risk areas for internal control atrophy during deregulatory periods are: issues management — findings pile up without resolution when there's no near-term exam pressure; compliance testing — self-assessment cadences slow when they're not tied to an impending exam; policy review cycles — policies drift out of date when there's no deadline forcing review; and training — completion rates fall when there's no immediate accountability. These are exactly the items an examiner looks for when assessing the health of a compliance program — and they tend to show degradation first.
How should compliance programs adjust their structure for a five-to-six year exam cycle?
Paradoxically, longer exam cycles require more rigorous internal compliance infrastructure, not less. You are now self-governing for longer without external checkpoints. The program adjustments that matter: a documented issues management system that tracks open findings through to closure regardless of exam timing; annual compliance testing that doesn't depend on exam scheduling; escalation protocols that surface material issues to the board or risk committee without waiting for an examiner to find them; and a clear record of the compliance program's health that predates any examination request.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.