Feature Compliance Strategy
OCC's $700 Billion Threshold Proposal: What Banks Between $50B and $700B Need to Do with Their Risk Governance Frameworks
The OCC's proposed rule would cut the number of banks subject to heightened standards from 38 to 8—releasing 30 mid-size banks from formal risk governance requirements. Here's what risk officers at those banks need to think through before dismantling anything.
Table of Contents
In January 2026, the OCC proposed raising the threshold for its heightened standards guidelines from $50 billion to $700 billion in average total consolidated assets. If the rule finalizes as proposed, the number of banks formally subject to the guidelines drops from 38 to 8—releasing approximately 30 national banks and federal savings associations from a set of prescriptive risk governance requirements that have shaped their compliance programs since the post-2008 crisis era.
For risk officers at banks in the $50B–$700B range, that sounds like relief. It may well be. But between “the rule was proposed” and “we can scale back our governance framework” lies a set of decisions that, if made wrong, will produce MRAs instead of reduced compliance burden.
The comment period closed March 2, 2026. The proposal has not been finalized as of this writing. The practical questions for risk teams are: what changes, what doesn’t, and how do you navigate the period between a likely finalization and the current requirement state?
TL;DR
- The OCC’s proposed rule would raise the heightened standards threshold from $50B to $700B—releasing ~30 banks from formal risk governance requirements
- Affected banks would no longer be formally required to have three-lines-of-defense structures, board risk committees, or formal risk appetite statements under the heightened standards
- The OCC explicitly expects excluded banks to maintain “robust risk management programs”—and retains discretion to apply guidelines to complex institutions below $700B
- The practical move: map your current framework to its regulatory basis, document a rationalization plan, and don’t make structural changes before the rule is final
What the Heightened Standards Actually Require Today
The OCC’s heightened standards guidelines were created in the aftermath of the 2008 financial crisis to formalize governance expectations for large institutions whose size and complexity could create systemic risk. For covered banks, the guidelines require:
- A formal risk governance framework with documented objectives, risk tolerances, and defined ownership
- A three-lines-of-defense structure—with the second and third lines operationally independent of business units
- A board-level risk committee with independent directors and demonstrated risk management expertise
- A written risk appetite statement reviewed and approved by the board at least annually
- Compensation structures that incorporate risk management performance for senior staff
For risk teams at covered banks, these requirements have carried real costs: dedicated second-line functions, independent audit programs, board committee cadences, and risk appetite documentation that required executive and board sign-off. The compliance infrastructure around these requirements is substantial.
The proposal would remove the formal obligation to maintain that infrastructure for banks in the $50B–$700B range. The question is whether removing the obligation changes the underlying expectation.
What the Proposal Would and Wouldn’t Change
The amended definition of “covered bank” under the proposal would apply only to institutions with:
- $700 billion or more in average total consolidated assets
- Less than $700 billion but whose parent company controls at least one covered bank
- Less than $700 billion but where the OCC determines operations are highly complex or present a heightened risk
That third category is the important one. Banks with complex trust businesses, significant derivatives books, substantial fintech partnerships, or unusual liability structures should not assume automatic exclusion. The OCC retains authority to apply heightened standards to any bank it considers highly complex, regardless of asset size.
For a bank cleanly below $700B with a traditional lending and deposit model, the path to exclusion is clearer. For a bank with $150 billion in assets running a significant custody business and a substantial derivatives operation, the picture is less certain—and the right move is a documented analysis of whether the OCC would consider the institution’s operations “highly complex” before any governance changes are made.
What the Industry Comments Revealed
The comment period generated sharp disagreement on scope, though notably not on whether governance itself should be maintained.
The American Bankers Association urged the OCC to go further—rescinding the heightened standards guidelines entirely rather than simply raising the threshold. The ABA’s argument: these guidelines create duplicative requirements for banks already subject to safety and soundness examination, capital stress testing, and other supervisory frameworks that address the same governance risks.
The Bank Policy Institute and the Association of African American Owned Banks filed a joint comment generally supportive of the proposal while raising specific implementation questions.
ICBA urged adjustment for community banks, though heightened standards have never applied below $50B—so the community bank population isn’t directly affected by this specific change.
What every comment letter had in common: none argued that governance could or should be weakened. Even those supporting full rescission acknowledged that strong risk management practices remain necessary. The dispute is about whether formal prescriptive requirements—rather than examination expectations—are the right mechanism for mid-size banks.
The OCC Spring 2026 Risk Perspective Is Not Relaxing Expectations
This is the disconnect risk teams need to understand. The proposed rule relaxes formal governance requirements. The OCC’s supervisory posture on the underlying governance quality is not relaxing.
The Spring 2026 Semiannual Risk Perspective, released in May 2026, flagged elevated and interconnected risks for the banking sector: credit deterioration in commercial real estate and consumer portfolios, rising fraud driven by AI-enhanced attack techniques, cyber threats from state-sponsored actors, and interest rate uncertainty. The report noted explicitly that governance weaknesses facing these risks can be as destabilizing as credit losses themselves.
For banks in the $50B–$700B range, this creates a tension that needs active management. The formal requirement to maintain the heightened standards framework may be removed by a final rule. The examination expectation that the bank has a functioning risk governance program will not. The OCC will still assess governance quality during safety and soundness examinations, and governance deficiencies in the face of the risks identified in the Spring 2026 report will generate findings—regardless of whether heightened standards apply.
Banks that treat the threshold change as permission to hollow out governance programs will likely trade a formal framework for an MRA. That is not a favorable exchange.
A Framework for Deciding What to Keep
For risk officers, the useful question isn’t “what can we get rid of?” — it’s “which elements of our current framework have value beyond the regulatory checkbox?”
A structured analysis by governance element:
| Element | Driven by Heightened Standards? | Driven by Other Requirements? | Recommended Approach |
|---|---|---|---|
| Risk appetite statement | Yes—explicitly required | OCC/Fed general expectations | Keep; right-size scope and depth |
| Board risk committee | Yes—required | Varies; may still apply | Keep; adjust mandate if warranted |
| Three lines of defense structure | Yes—formal requirements | General examination expectation | Rationalize; do not eliminate |
| Compensation risk tie-in | Yes—formal | Incentive compensation guidance still applies | Keep through other frameworks |
| Independent internal audit | Yes—component | Required for all OCC-supervised banks | Unaffected; keep |
| Written risk governance framework | Yes—formal requirement | Implicit in safety and soundness | Keep with updated regulatory basis |
The practical answer for most banks in this range: the governance structures driven by heightened standards are largely still expected by examiners on general safety and soundness grounds. What changes is the prescriptive template and formal compliance obligation—not the underlying expectation that these structures exist and function.
Three Things to Do Before the Rule Finalizes
1. Map your current framework to its regulatory driver.
Before any governance element can be modified, you need to know why it exists. Trace each major element of your risk governance framework—the board risk committee charter, the risk appetite statement, the three-lines-of-defense policy—to its regulatory basis. Is it there because of heightened standards? Because of OCC/Fed general examination guidance? Because of your state regulator? Because your own board decided it was best practice?
The answer determines what’s actually at stake when the threshold changes. An element with multiple regulatory drivers doesn’t simplify just because one driver goes away. An element that exists only because of heightened standards has more flexibility.
2. Document a rationalization plan.
For banks that will be excluded from heightened standards upon finalization, the prudent step now is to model what the governance framework should look like post-finalization—not to implement changes, but to have the analysis ready. Document what you’d keep unchanged, what you’d scale back, what new basis you’d anchor each element to, and how you’d explain the decisions in an examination.
That documentation demonstrates intentionality. A governance change made in silence after a final rule looks different than one supported by a board-approved rationalization analysis with explicit risk basis documentation. Examiners respond to deliberate governance decision-making very differently than to gaps they can’t explain.
3. Don’t move before the rule is final.
As of July 2026, this is still a proposed rule. Banks that have informally begun relaxing governance expectations based on the proposal are taking examination risk on a not-yet-final regulatory action. The OCC can and will examine against current requirements until a final rule takes effect. The right move is to prepare for the transition—not to execute it before there is a final rule with an effective date.
The Deregulatory Window and Its Limits
The heightened standards proposal is one piece of a broader deregulatory pattern that the OCC has pursued since early 2026—including the deregulatory pivot post for compliance programs, the OCC’s removal of reputation risk from examination criteria, and the OCC’s supervisory reset for community and regional bank examinations. The direction is consistent.
But there’s a pattern in how financial regulators handle deregulatory cycles that history consistently demonstrates: formal requirements relax; informal expectations often don’t. Banks that used the post-2018 regulatory relief cycle to reduce compliance investment found during the 2020–2023 enforcement wave that examination expectations had not followed the formal rule changes downward.
The heightened standards proposal creates real flexibility for banks in the affected range. Using that flexibility well means building a governance framework calibrated to actual risk—not one reduced to the minimum formal requirement. The three lines of defense structure, the board oversight function, and the risk appetite statement all provide genuine organizational value beyond compliance. Banks that recognize that now will design better programs. Banks that don’t will rebuild what they dismantled.
So What? The Practical Checklist
Before your next board risk committee meeting, risk officers at $50B–$700B banks should be able to answer:
- Do we understand the proposed rule? What the threshold change is, when comments closed, what the expected finalization timeline is
- Are we analyzing our complexity profile? Could the OCC argue our operations are “highly complex” even post-finalization?
- Have we mapped our governance framework to its regulatory drivers? Which elements are solely heightened-standards-driven vs. grounded in other requirements?
- Is there a documented rationalization plan for what changes upon finalization—board-reviewed before implementation?
- Are we waiting for the final rule before making structural governance changes?
The Enterprise Risk Management Framework includes templates for risk appetite statements, governance framework documentation, and three-lines-of-defense role definitions that can be anchored to either the heightened standards requirements or the underlying safety and soundness expectations they reflect—providing continuity through the transition regardless of how the final rule shakes out.
Sources:
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Enterprise Risk Management Framework (ERMF)
Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What are the OCC's heightened standards guidelines?
Which banks are affected by the OCC's proposed threshold change?
Does the proposal mean mid-size banks can eliminate their risk governance frameworks?
Is the OCC heightened standards threshold change finalized?
What should banks between $50B and $700B do now?
Can the OCC still apply heightened standards to banks below $700B?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Enterprise Risk Management Framework (ERMF)
Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.
◆ Keep reading
Related posts.
Compliance Strategy
GRC Framework for a Small Risk Team: One Control Library, Five Workflows, No Enterprise Platform
A GRC program that runs on one control library, five traceable workflows, and a set of spreadsheets beats a half-implemented enterprise platform every time. Here's how to build it.
Jul 24, 2026
Compliance Strategy
Compliance Monitoring Plan in Excel: Convert the Risk Assessment Into a Defensible Test Universe
Build a compliance monitoring plan template in Excel that traces risks and obligations to scope, evidence, exceptions, and remediation.
Jul 23, 2026
Compliance Strategy
Your Reg E Program Wasn't Built for FedNow: The Error Resolution Timeline Trap in Instant Payments
Reg E's 10-business-day provisional credit requirement applies to FedNow and RTP consumer transactions—but instant payment irrevocability means the fraud money is gone before you finish the investigation. Here's what your error resolution procedures actually need to say for instant payments, and where most programs have a documented gap.
Jul 22, 2026