Feature Compliance Strategy
Federal Reserve Regulation O Proposal: Rebuild the Control Logic, Not Just the Limits
The 2026 Regulation O proposal raises insider-lending thresholds and changes passive-fund treatment. Here is the bank control impact.
Table of Contents
TL;DR
- The Federal Reserve issued a Regulation O proposal on July 31, 2026, calling it the first comprehensive update since 1979.
- Proposed thresholds generally rise fourfold: the $500,000 fixed board-approval ceiling becomes $2 million, while the $15,000 credit-card exception becomes $60,000.
- The proposal also tackles loans to portfolio companies connected to passive fund complexes, incorporates existing interpretations, and reorganizes the rule.
- This is not a “change six numbers in the core” project. Insider identity, related-interest logic, approvals, abstentions, public disclosure, and evidence all need end-to-end testing.
The Federal Reserve Regulation O proposal gives banks larger dollar thresholds. The dangerous implementation is to treat that as the whole story.
On July 31, 2026, the Federal Reserve requested comment on a broad modernization of Regulation O, the rule governing credit to executive officers, directors, principal shareholders, and related interests. The release says the rule has not been comprehensively updated since 1979.
The numbers are cleaner. The control environment is not.
A bank that updates its loan-system threshold but leaves stale insider records, broken relationship aggregation, weak director abstention evidence, or ambiguous passive-fund logic has implemented the easy 10% and missed the risky 90%.
The Regulation O proposal in one control table
The proposed Federal Register notice lists these dollar changes:
| Control point | Current amount | Proposed amount | System or process to inspect |
|---|---|---|---|
| Credit-card exception | $15,000 | $60,000 | Card platform and insider exception report |
| Overdraft under a credit plan | $5,000 | $20,000 | Deposit overdraft rules and linked-line setup |
| Inadvertent overdraft exception | $1,000 | $4,000 | Daily overdraft monitoring and cure workflow |
| Executive-officer “other purpose” exception | $100,000 | $400,000 | Commercial/consumer origination and approval routing |
| Fixed ceiling in prior board-approval test | $500,000 | $2 million | Relationship aggregation and board workflow |
| Related public-disclosure threshold | $500,000 | $2 million | Regulatory reporting and disclosure inventory |
The Board says it derived the proposed increases using changes in nominal gross domestic product from the fourth quarter of 1994 through the fourth quarter of 2025. It would also index thresholds going forward.
Governor Michael Barr supported publishing the proposal but asked whether nominal GDP or the consumer price index is the better index. That disagreement is not trivia. It means the indexing methodology is a live policy question, not an implementation fact.
Until a final rule becomes effective, the current limits stay in production.
Why a threshold update can create a control failure
Regulation O is relationship-driven. The correct result depends on who the borrower is, who controls the borrower, which other exposures aggregate with it, what type of credit is involved, and who approved it.
Consider a realistic hypothetical: a director owns a local construction company and personally has a home-equity line. The bank’s origination system recognizes the director’s personal customer record but does not connect the company because the ownership data lives in a separate commercial-lending file. Raising an approval threshold does nothing to fix the missing relationship. The system may route the transaction incorrectly at either the old or new amount.
A sound implementation sequence is:
- establish the complete insider population;
- map related interests and attribution rules;
- aggregate exposures across products and legal borrowers;
- apply the correct exception, limit, and approval logic;
- prevent interested-party participation;
- preserve evidence for monitoring and examination.
Teams often begin at step four because that is where the visible dollar amount sits. Examiners begin by asking how the bank knew the borrower was an insider or related interest in the first place.
The six tests your bank should run before changing a number
1. Can the bank prove who is an insider today?
The insider inventory should include executive officers, directors, principal shareholders, relevant affiliate insiders, and connected related interests. Each record needs an effective date, source, reviewer, and linkage to customer identifiers used by deposit, card, and loan systems.
Evidence should include:
- board and committee rosters;
- officer designation analysis;
- ownership and control records;
- annual conflict and related-interest questionnaires;
- midyear change notifications;
- customer master identifiers;
- review and certification history.
The annual questionnaire cannot be the only update mechanism. A new business interest acquired in March should not wait until next January to enter the monitoring population.
2. Does aggregation work across products?
The proposal retains the underlying architecture of individual and aggregate lending restrictions. The notice explains that the general aggregate lending limit is 100% of unimpaired capital and unimpaired surplus, while individual lending-limit calculations and collateral rules continue to matter.
Test one insider relationship across:
- commercial loans;
- consumer loans;
- credit cards;
- deposit overdrafts;
- unused lines;
- derivatives or other covered credit exposures;
- related interests.
The expected evidence is a reconciliation showing every source system, matched customer identifier, exposure amount, exception, and total. If the result requires a compliance analyst to remember that “ABC Holdings” belongs to Director Smith, that is a person-dependent control, not reliable aggregation.
3. Are approvals tied to the whole relationship?
The proposed fixed board-approval ceiling rises from $500,000 to $2 million, but Regulation O’s approval test is not simply “anything below $2 million is fine.” The current framework also uses a percentage-of-capital component, and the proposal contains extensive conforming changes.
The workflow should calculate the applicable test from current capital data and aggregate exposure, not rely on a static dollar switch.
For each approval, preserve:
- amount before and after the transaction;
- capital and surplus source date;
- triggered threshold;
- credit terms and underwriting result;
- board materials;
- vote record;
- interested-party abstention;
- minutes or written consent.
A meeting minute that says “approved insider loan” without showing abstention and the relationship amount is thin evidence.
4. Do overdraft controls distinguish an exception from a pattern?
The proposal would move the inadvertent-overdraft exception from $1,000 to $4,000 and the credit-plan exception from $5,000 to $20,000.
That does not turn repeated overdrafts into “inadvertent” events. Monitoring should test amount, duration, recurrence, repayment, and whether the credit plan was documented in advance.
A useful exception report includes:
| Field | Control purpose |
|---|---|
| Insider and related account | Connects the event to the monitored population |
| Overdraft amount and start time | Tests the applicable exception |
| Cure date and source of funds | Shows timely correction |
| Prior events in 90 days | Detects a recurring pattern |
| Preexisting credit plan | Separates plan coverage from after-the-fact rationalization |
| Reviewer and disposition | Creates accountable evidence |
A higher threshold can reduce alerts. It should not eliminate recurrence monitoring.
5. Can disclosures be regenerated under both rule versions?
The proposal would raise the related public-disclosure threshold from $500,000 to $2 million. Banks should version the reporting logic rather than overwrite it.
The implementation file should show:
- the current-rule output for the last reporting period;
- a parallel proposed-rule output;
- the transactions that drop out and why;
- effective-date logic;
- retention of historical reports under the rule then in force;
- Legal and Regulatory Reporting sign-off.
This dual-run approach catches boundary errors before production changes and preserves the audit trail when someone later asks why a transaction appeared in one year’s disclosure but not the next.
6. Does the bank test terms, not only limits?
The Federal Reserve’s release says the proposal maintains safeguards against preferential treatment. A transaction can sit below every dollar threshold and still create risk if its pricing, collateral, maturity, exceptions, or underwriting differs improperly from comparable non-insider credit.
Compliance Testing should select a matched sample of insider and non-insider transactions and compare:
- rate and fees;
- collateral type and advance rate;
- debt-service and creditworthiness analysis;
- maturity and amortization;
- covenant exceptions;
- approval authority;
- past-due treatment.
Document the matching logic. “We reviewed five normal loans” is not persuasive if they came from different products, risk grades, or time periods.
Passive fund complexes are the proposal’s least spreadsheet-friendly issue
The proposal addresses a modern complication: passive investment fund complexes may own more than 10% of a class of a banking organization’s voting securities and become principal shareholders. Under current control presumptions, a bank’s loans to portfolio companies associated with that fund complex can be pulled into Regulation O analysis even where the economic relationship does not resemble classic insider self-dealing.
The Board proposes an exemption from a presumption of control for portfolio companies of fund complexes that meet specified criteria. It also asks how banks should treat corporate lending where passive asset managers hold equity in both the bank and borrowers.
This is not a blanket “BlackRock/Vanguard exception,” and banks should not implement it from a headline. Legal needs to map the final eligibility conditions, fund-complex structure, ownership data, control indicators, and documentation standard.
The control artifact should be a legal decision tree with:
- whether the fund complex is a principal shareholder;
- whether the borrower is a portfolio company;
- whether the proposed exemption’s criteria are met;
- whether another control relationship exists;
- the data source and as-of date for ownership;
- the legal approver and refresh trigger.
Ownership changes. Any exception dependent on a point-in-time position needs a refresh cadence and an event-driven update for material changes.
What the proposal does not let banks stop doing
The modernization language is broad, but the proposal does not erase the core protections. Banks still need controls designed to prevent preferential insider credit, calculate lending limits, obtain approvals, enforce abstentions, maintain records, and make required reports or disclosures.
It also incorporates statutory requirements and longstanding interpretations into the rule text. That can expose undocumented practices. A bank may be operating correctly because an experienced compliance officer knows a Federal Reserve interpretation; if the logic is absent from procedure and system requirements, the control will not survive turnover.
This is a good moment to compare the proposed text against:
- the Regulation O policy;
- insider-lending procedures;
- system business requirements;
- director and officer questionnaires;
- credit committee and board charters;
- monitoring and testing scripts;
- training materials;
- exception logs.
For the broader governance discipline, see how to build a regulatory change management program and how regulatory change KRIs catch policy lag and missed deadlines. Banks reviewing governance across a holding-company structure should also read the source-of-strength control implications for fintech subsidiaries.
A 30-day Regulation O evidence sprint
Week 1 — Compliance and Corporate Secretary: certify the insider population and reconcile it to board, officer, ownership, affiliate, and customer-master records.
Week 2 — Credit Risk and Technology: run cross-product aggregation for a sample that includes a director, executive officer, principal shareholder, and related interest. Log every manual bridge.
Week 3 — Legal and Regulatory Reporting: create a redline matrix covering all proposed threshold, definition, passive-fund, disclosure, and interpretation changes. Separate proposed text from current requirements.
Week 4 — Compliance Testing: dual-run current and proposed thresholds, test abstention evidence, sample overdrafts for recurrence, and compare insider terms with appropriately matched non-insider loans.
The final deliverable is not a slide saying “Reg O limits may increase.” It is a version-controlled impact assessment with source citations, affected controls, system requirements, test results, owners, dependencies, and go-live conditions.
The Board says comments are due 60 days after Federal Register publication. That gives banks a window to identify practical defects and submit evidence-based comments rather than generic support or opposition.
If your review exposes controls that exist only in people’s heads, use the RCSA Template to document the risk, control owner, evidence, test cadence, and remediation before a final rule forces the deadline.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
RCSA (Risk & Control Self-Assessment)
141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What would the Federal Reserve's 2026 Regulation O proposal change?
What is the proposed Regulation O board-approval threshold?
Would the Regulation O credit-card and overdraft thresholds increase?
Does the proposal remove Regulation O protections against preferential terms?
When are comments on the Regulation O proposal due?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
RCSA (Risk & Control Self-Assessment)
141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.
◆ Keep reading
Related posts.
Compliance Strategy
Bank Holding Company Source-of-Strength: What Fintechs Getting Bank Charters Haven't Accounted For
When a fintech gets a bank charter and forms a bank holding company, it inherits the source-of-strength obligation — a capital backstop requirement most fintech BHC playbooks don't address. The TS Banking Group July 2026 written agreement shows what happens when this surfaces at exam time.
Jul 30, 2026
Compliance Strategy
The House CFPB Reform Discussion Draft: What the $21B Supervisory Threshold and Congressional Appropriations Proposal Mean for Your Compliance Program
On July 24, 2026, the House Financial Services Committee published a 70-page CFPB restructuring draft. Here's what's in the five titles, what the $21B threshold change actually affects, and why the compliance programs that survive any version of this are built around legal obligations — not exam schedules.
Jul 28, 2026
Compliance Strategy
The First 90 Days as a New Compliance Officer: Inventory Before You Rewrite
A compliance checklist template for your first 90 days: inventory obligations, issues, complaints, commitments, controls, access, and evidence first.
Jul 27, 2026