Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Compliance Strategy

OCC's $700 Billion Threshold Proposal: What Banks Between $50B and $700B Need to Do with Their Risk Governance Frameworks

The OCC's proposed rule would cut the number of banks subject to heightened standards from 38 to 8—releasing 30 mid-size banks from formal risk governance requirements. Here's what risk officers at those banks need to think through before dismantling anything.

Table of Contents

In January 2026, the OCC proposed raising the threshold for its heightened standards guidelines from $50 billion to $700 billion in average total consolidated assets. If the rule finalizes as proposed, the number of banks formally subject to the guidelines drops from 38 to 8—releasing approximately 30 national banks and federal savings associations from a set of prescriptive risk governance requirements that have shaped their compliance programs since the post-2008 crisis era.

For risk officers at banks in the $50B–$700B range, that sounds like relief. It may well be. But between “the rule was proposed” and “we can scale back our governance framework” lies a set of decisions that, if made wrong, will produce MRAs instead of reduced compliance burden.

The comment period closed March 2, 2026. The proposal has not been finalized as of this writing. The practical questions for risk teams are: what changes, what doesn’t, and how do you navigate the period between a likely finalization and the current requirement state?

TL;DR

  • The OCC’s proposed rule would raise the heightened standards threshold from $50B to $700B—releasing ~30 banks from formal risk governance requirements
  • Affected banks would no longer be formally required to have three-lines-of-defense structures, board risk committees, or formal risk appetite statements under the heightened standards
  • The OCC explicitly expects excluded banks to maintain “robust risk management programs”—and retains discretion to apply guidelines to complex institutions below $700B
  • The practical move: map your current framework to its regulatory basis, document a rationalization plan, and don’t make structural changes before the rule is final

What the Heightened Standards Actually Require Today

The OCC’s heightened standards guidelines were created in the aftermath of the 2008 financial crisis to formalize governance expectations for large institutions whose size and complexity could create systemic risk. For covered banks, the guidelines require:

  • A formal risk governance framework with documented objectives, risk tolerances, and defined ownership
  • A three-lines-of-defense structure—with the second and third lines operationally independent of business units
  • A board-level risk committee with independent directors and demonstrated risk management expertise
  • A written risk appetite statement reviewed and approved by the board at least annually
  • Compensation structures that incorporate risk management performance for senior staff

For risk teams at covered banks, these requirements have carried real costs: dedicated second-line functions, independent audit programs, board committee cadences, and risk appetite documentation that required executive and board sign-off. The compliance infrastructure around these requirements is substantial.

The proposal would remove the formal obligation to maintain that infrastructure for banks in the $50B–$700B range. The question is whether removing the obligation changes the underlying expectation.

What the Proposal Would and Wouldn’t Change

The amended definition of “covered bank” under the proposal would apply only to institutions with:

  • $700 billion or more in average total consolidated assets
  • Less than $700 billion but whose parent company controls at least one covered bank
  • Less than $700 billion but where the OCC determines operations are highly complex or present a heightened risk

That third category is the important one. Banks with complex trust businesses, significant derivatives books, substantial fintech partnerships, or unusual liability structures should not assume automatic exclusion. The OCC retains authority to apply heightened standards to any bank it considers highly complex, regardless of asset size.

For a bank cleanly below $700B with a traditional lending and deposit model, the path to exclusion is clearer. For a bank with $150 billion in assets running a significant custody business and a substantial derivatives operation, the picture is less certain—and the right move is a documented analysis of whether the OCC would consider the institution’s operations “highly complex” before any governance changes are made.

What the Industry Comments Revealed

The comment period generated sharp disagreement on scope, though notably not on whether governance itself should be maintained.

The American Bankers Association urged the OCC to go further—rescinding the heightened standards guidelines entirely rather than simply raising the threshold. The ABA’s argument: these guidelines create duplicative requirements for banks already subject to safety and soundness examination, capital stress testing, and other supervisory frameworks that address the same governance risks.

The Bank Policy Institute and the Association of African American Owned Banks filed a joint comment generally supportive of the proposal while raising specific implementation questions.

ICBA urged adjustment for community banks, though heightened standards have never applied below $50B—so the community bank population isn’t directly affected by this specific change.

What every comment letter had in common: none argued that governance could or should be weakened. Even those supporting full rescission acknowledged that strong risk management practices remain necessary. The dispute is about whether formal prescriptive requirements—rather than examination expectations—are the right mechanism for mid-size banks.

The OCC Spring 2026 Risk Perspective Is Not Relaxing Expectations

This is the disconnect risk teams need to understand. The proposed rule relaxes formal governance requirements. The OCC’s supervisory posture on the underlying governance quality is not relaxing.

The Spring 2026 Semiannual Risk Perspective, released in May 2026, flagged elevated and interconnected risks for the banking sector: credit deterioration in commercial real estate and consumer portfolios, rising fraud driven by AI-enhanced attack techniques, cyber threats from state-sponsored actors, and interest rate uncertainty. The report noted explicitly that governance weaknesses facing these risks can be as destabilizing as credit losses themselves.

For banks in the $50B–$700B range, this creates a tension that needs active management. The formal requirement to maintain the heightened standards framework may be removed by a final rule. The examination expectation that the bank has a functioning risk governance program will not. The OCC will still assess governance quality during safety and soundness examinations, and governance deficiencies in the face of the risks identified in the Spring 2026 report will generate findings—regardless of whether heightened standards apply.

Banks that treat the threshold change as permission to hollow out governance programs will likely trade a formal framework for an MRA. That is not a favorable exchange.

A Framework for Deciding What to Keep

For risk officers, the useful question isn’t “what can we get rid of?” — it’s “which elements of our current framework have value beyond the regulatory checkbox?”

A structured analysis by governance element:

ElementDriven by Heightened Standards?Driven by Other Requirements?Recommended Approach
Risk appetite statementYes—explicitly requiredOCC/Fed general expectationsKeep; right-size scope and depth
Board risk committeeYes—requiredVaries; may still applyKeep; adjust mandate if warranted
Three lines of defense structureYes—formal requirementsGeneral examination expectationRationalize; do not eliminate
Compensation risk tie-inYes—formalIncentive compensation guidance still appliesKeep through other frameworks
Independent internal auditYes—componentRequired for all OCC-supervised banksUnaffected; keep
Written risk governance frameworkYes—formal requirementImplicit in safety and soundnessKeep with updated regulatory basis

The practical answer for most banks in this range: the governance structures driven by heightened standards are largely still expected by examiners on general safety and soundness grounds. What changes is the prescriptive template and formal compliance obligation—not the underlying expectation that these structures exist and function.

Three Things to Do Before the Rule Finalizes

1. Map your current framework to its regulatory driver.

Before any governance element can be modified, you need to know why it exists. Trace each major element of your risk governance framework—the board risk committee charter, the risk appetite statement, the three-lines-of-defense policy—to its regulatory basis. Is it there because of heightened standards? Because of OCC/Fed general examination guidance? Because of your state regulator? Because your own board decided it was best practice?

The answer determines what’s actually at stake when the threshold changes. An element with multiple regulatory drivers doesn’t simplify just because one driver goes away. An element that exists only because of heightened standards has more flexibility.

2. Document a rationalization plan.

For banks that will be excluded from heightened standards upon finalization, the prudent step now is to model what the governance framework should look like post-finalization—not to implement changes, but to have the analysis ready. Document what you’d keep unchanged, what you’d scale back, what new basis you’d anchor each element to, and how you’d explain the decisions in an examination.

That documentation demonstrates intentionality. A governance change made in silence after a final rule looks different than one supported by a board-approved rationalization analysis with explicit risk basis documentation. Examiners respond to deliberate governance decision-making very differently than to gaps they can’t explain.

3. Don’t move before the rule is final.

As of July 2026, this is still a proposed rule. Banks that have informally begun relaxing governance expectations based on the proposal are taking examination risk on a not-yet-final regulatory action. The OCC can and will examine against current requirements until a final rule takes effect. The right move is to prepare for the transition—not to execute it before there is a final rule with an effective date.

The Deregulatory Window and Its Limits

The heightened standards proposal is one piece of a broader deregulatory pattern that the OCC has pursued since early 2026—including the deregulatory pivot post for compliance programs, the OCC’s removal of reputation risk from examination criteria, and the OCC’s supervisory reset for community and regional bank examinations. The direction is consistent.

But there’s a pattern in how financial regulators handle deregulatory cycles that history consistently demonstrates: formal requirements relax; informal expectations often don’t. Banks that used the post-2018 regulatory relief cycle to reduce compliance investment found during the 2020–2023 enforcement wave that examination expectations had not followed the formal rule changes downward.

The heightened standards proposal creates real flexibility for banks in the affected range. Using that flexibility well means building a governance framework calibrated to actual risk—not one reduced to the minimum formal requirement. The three lines of defense structure, the board oversight function, and the risk appetite statement all provide genuine organizational value beyond compliance. Banks that recognize that now will design better programs. Banks that don’t will rebuild what they dismantled.

So What? The Practical Checklist

Before your next board risk committee meeting, risk officers at $50B–$700B banks should be able to answer:

  1. Do we understand the proposed rule? What the threshold change is, when comments closed, what the expected finalization timeline is
  2. Are we analyzing our complexity profile? Could the OCC argue our operations are “highly complex” even post-finalization?
  3. Have we mapped our governance framework to its regulatory drivers? Which elements are solely heightened-standards-driven vs. grounded in other requirements?
  4. Is there a documented rationalization plan for what changes upon finalization—board-reviewed before implementation?
  5. Are we waiting for the final rule before making structural governance changes?

The Enterprise Risk Management Framework includes templates for risk appetite statements, governance framework documentation, and three-lines-of-defense role definitions that can be anchored to either the heightened standards requirements or the underlying safety and soundness expectations they reflect—providing continuity through the transition regardless of how the final rule shakes out.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What are the OCC's heightened standards guidelines?
The OCC heightened standards guidelines establish minimum requirements for risk governance frameworks and board oversight at large national banks and federal savings associations. They require formal risk governance frameworks, defined three-lines-of-defense roles, board risk committees, written risk appetite statements, and compensation structures tied to risk management. They were developed post-2008 financial crisis to address governance failures at systemically important institutions.
Which banks are affected by the OCC's proposed threshold change?
The proposal would raise the threshold from $50 billion to $700 billion in average total consolidated assets. Banks with between $50B and $700B that are currently covered would no longer be formally subject to the guidelines—approximately 30 institutions. Eight banks above $700B would remain covered. The OCC retains discretion to apply guidelines to excluded banks with complex operations.
Does the proposal mean mid-size banks can eliminate their risk governance frameworks?
No. The OCC explicitly stated it expects excluded institutions to maintain robust risk management programs. The change removes prescriptive heightened standards requirements—it does not eliminate examination expectations, safety and soundness standards, or the OCC's authority to apply guidelines to excluded banks it deems highly complex. Banks that hollow out governance programs based on this proposal may trade a formal framework for an MRA.
Is the OCC heightened standards threshold change finalized?
As of July 2026, the rule remains in proposed form. The comment period closed March 2, 2026. The proposal aligns with the current administration's regulatory direction and is widely expected to finalize, but has not been issued as a final rule as of this writing.
What should banks between $50B and $700B do now?
Banks should: map which elements of their current risk governance framework are driven by heightened standards versus other regulatory requirements or internal best practice; document what a rationalized post-finalization framework would look like; and avoid making structural changes before the rule is finalized. Moving faster than the rule creates examination risk on a not-yet-final proposal.
Can the OCC still apply heightened standards to banks below $700B?
Yes. The proposal retains OCC discretion to apply the guidelines to excluded banks if the OCC determines their operations are highly complex or otherwise present a heightened risk. Banks with complex trust businesses, significant derivatives exposure, substantial crypto activity, or unusual business lines should not assume automatic exclusion regardless of asset size.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Enterprise Risk Management Framework (ERMF)

Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.