Breaking Regulatory Compliance
Iuka State Bank Written Agreement: The Fed's 30-Day Credit Risk and BSA/AML Remediation List
The Iuka State Bank written agreement maps Fed findings to 30- and 60-day fixes across credit, capital, liquidity, and BSA/AML.
Table of Contents
TL;DR
- The Federal Reserve announced a written agreement with Iuka Bancshares and The Iuka State Bank on July 30, 2026, after an examination identified deficiencies across credit, capital, liquidity, internal controls, and BSA/AML.
- There is no announced fine. The consequence is a dense remediation program: multiple plans are due within 30 or 60 days, capital distributions and new debt require prior approval, and quarterly progress reporting is mandatory.
- The order is unusually useful for practitioners because it tells you what weak loan administration, board reporting, independent review, and BSA/AML testing look like when they become formal enforcement terms.
- Community-bank CROs, CCOs, lenders, finance teams, and boards should use the agreement as an exam-readiness checklist before similar gaps pile up into one enterprise-wide action.
A regulator does not need a nine-figure fine to make a bank’s next quarter miserable. The Iuka State Bank written agreement proves it.
On July 30, 2026, the Federal Reserve announced an enforcement action involving Iuka Bancshares, Inc. and The Iuka State Bank, both based in Salem, Illinois. The underlying written agreement, dated July 15, is a joint action involving the Federal Reserve Bank of St. Louis and the Illinois Department of Financial and Professional Regulation.
The agreement does not announce a civil money penalty. Instead, it converts examination deficiencies into a tightly sequenced operating plan. Credit administration, problem assets, allowance methodology, capital, liquidity, BSA/AML, board oversight, dividends, debt, and progress reporting all land on the same remediation calendar.
That is the real story. This is not one isolated control failure. It is what happens when weaknesses across several risk domains become connected in the exam report.
What triggered the Iuka State Bank written agreement?
The agreement says the bank’s May 27, 2026 report of examination identified deficiencies involving:
- internal controls;
- credit risk management;
- lending and credit administration;
- capital;
- liquidity and funds management; and
- compliance with the Bank Secrecy Act and other anti-money laundering requirements.
The public documents do not disclose the confidential exam ratings or every underlying examiner observation. That boundary matters. It would be irresponsible to guess at asset-quality figures, suspicious activity volumes, or individual control exceptions that the order does not publish.
What the agreement does disclose is detailed enough to reconstruct the control architecture regulators expect the bank to repair.
| Remediation area | Required deliverable | Deadline in the agreement | Named owner or decision-maker |
|---|---|---|---|
| Board oversight | Plan covering risk limits, policy exceptions, management adherence, and more granular reporting | 60 days | Bank board |
| Credit risk management | Concentration limits plus timely, accurate credit MIS | 30 days | Bank, subject to supervisor acceptance |
| Lending administration | Revised underwriting, collateral, exception tracking, nonaccrual, and watch-list procedures | 30 days | Lending and credit risk functions |
| Loan grading and review | Ongoing grading and an independent loan-review program | 30 days | Qualified staff independent of lending |
| Problem assets | Individual improvement plans for covered criticized or delinquent assets over $200,000 | 30 days | Management with board review |
| Allowance for credit losses | Revised methodology and an ongoing maintenance program | 30 days | Finance/credit with quarterly board review |
| Capital | Joint holding-company and bank capital plan | 60 days | Both boards and finance |
| Liquidity | Contingency funding plan with diversified sources and adverse scenarios | 60 days | Treasury/ALCO and board |
| BSA/AML | Internal-control and independent-testing enhancements | 60 days | BSA Officer, compliance, and independent testing |
| Progress reporting | Written status and results | 45 days after each quarter-end | Both boards |
The practical problem is obvious: these streams are interdependent. Finance cannot finalize a credible capital plan without reliable criticized-asset and allowance data. The board cannot establish risk limits without usable credit MIS. Internal audit cannot test remediation if owners have not defined evidence and completion criteria.
A spreadsheet with ten vague rows labeled “update policy” will collapse under this workload.
The credit requirements are really an evidence problem
The longest section of the agreement concerns credit. It requires documented analysis of repayment sources, financial statements, global cash flow, debt-service ability, and collateral value. It calls for collateral-perfection controls, compliant appraisals, a loan-document exception tracker, current borrower financial information, timely nonaccrual decisions, and prompt movement of deteriorating credits to a watch list.
Those are not exotic expectations. The failure mode is usually operational: the policy says the right thing, but the credit file cannot prove it happened consistently.
For example, “monitor policy exceptions” is not a complete control. A defensible exception process needs:
- a unique exception ID tied to the loan and borrower relationship;
- the policy or documentation requirement missed;
- the accountable lender and independent reviewer;
- an approved cure date;
- evidence of escalation when the cure date is missed; and
- closure support showing the exception was actually resolved.
The agreement also demands independence. Loan grading must be performed by qualified staff, and the loan-review function must be independent of lending. Its reports must assess portfolio quality and grade accuracy, identify weaknesses in approval and monitoring, and reach the board in writing.
For a small bank, that separation can get messy fast. The senior lender may know the portfolio best, but cannot be the only person validating their own grades. If internal staffing cannot provide credible independence, the board needs a properly scoped external review—not a ceremonial annual sample with no follow-up mechanism.
The order specifically references the Federal Reserve’s Interagency Appraisal and Evaluation Guidelines, SR 10-16. That gives credit administration a concrete source document for revising appraisal standards rather than drafting from an exam-summary bullet.
Problem assets and the allowance must reconcile
The agreement sets an exact trigger for asset improvement plans: each loan, relationship, or other asset over $200,000 that is more than 90 days past due, appears on the problem-loan list, or was criticized in the examination requires a written plan. Future assets meeting those conditions trigger the same requirement. Quarterly updates must include carrying value, collateral changes, renewals and extensions, and past-due/nonaccrual reporting.
That is more than a workout log. It creates a traceability test across at least four artifacts:
| Artifact | Reconciliation question |
|---|---|
| Problem-loan list | Are all criticized and qualifying delinquent assets present? |
| Loan system | Do balances, status, and payment terms agree with the action plan? |
| Collateral file | Are valuations current and legally perfected? |
| Allowance workpapers | Does the loss estimate reflect the same risk grade and facts? |
If one file calls a relationship “watch,” another leaves it accruing, and the allowance memo uses stale collateral, the issue is not merely bad documentation. Management and the board are making decisions from conflicting versions of credit risk.
The allowance provisions reinforce that point. The bank must revise its methodology in line with the Federal Reserve’s Interagency Policy Statement on Allowances for Credit Losses, SR 20-12. The agreement names classified assets, concentration risk, past dues, nonperformers, loss experience, market conditions, and collateral values as relevant factors. It also requires quarterly board review with written support for the conclusions reached.
Banks reviewing their own process should start with one sample of criticized relationships and trace every number from the servicing system through the watch list, collateral support, allowance calculation, committee minutes, and board package. That one end-to-end test often exposes more than another policy rewrite.
The BSA/AML section is short—but specific
The BSA/AML provisions occupy far less space than the credit requirements, but they identify two high-value tests.
First, the bank must improve internal controls covering customer due diligence, beneficial ownership, and suspicious activity monitoring and reporting. Second, it must enhance independent testing so qualified parties independent of the BSA/AML compliance function perform comprehensive, timely reviews on a regular basis.
The phrase “comprehensive and timely” deserves attention. An audit can be independent and still be too narrow. If testing excludes data feeds, beneficial-owner records, alert disposition quality, SAR decision documentation, or prior-issue validation, a clean report may only prove that the scope was weak.
The BSA Officer should be able to hand internal audit or an external tester a population map showing:
- customer and beneficial-owner records by system;
- monitoring scenarios and the products or transaction types each covers;
- alert, case, and SAR populations with reconciliation totals;
- model or rule changes made during the review period;
- open findings with owners, due dates, and evidence; and
- prior findings selected for closure validation.
For a deeper operating checklist, see the site’s guide to BSA/AML independent testing that can survive an FFIEC exam.
Capital and liquidity turn this into a board-level action
The agreement restricts both Bancshares and the bank from paying dividends, repurchasing shares, making other capital distributions, or incurring or guaranteeing debt without prior written approval. Requests generally must arrive at least 30 days before the proposed transaction and include financial and funding support.
It also requires a capital plan addressing current and future needs, classified assets, concentrations, the allowance, growth, earnings, the risk profile, and contingency funding. Separately, the contingency funding plan must diversify funding sources, identify available liquidity, and include adverse scenarios.
These requirements tell directors exactly where “oversight” becomes measurable. The board package needs to connect credit deterioration to the allowance, earnings, capital ratios, and liquidity—not present five committee reports that never reconcile.
A useful board challenge question is: If our three largest criticized relationships migrated one grade and our least reliable funding source disappeared, which limits would breach first, and what action would management take? The bank’s answer should point to approved assumptions, named owners, usable funding sources, and decision deadlines.
A 30/60/90-day response model for banks using this as a self-check
The following is a practitioner starting point, not a requirement imposed on institutions other than Iuka.
Days 1–30: prove the populations are complete
The CRO should establish one remediation inventory with unique IDs for every gap. Credit should reconcile criticized assets, watch-list loans, delinquencies, nonaccruals, exceptions, and allowance inputs. The BSA Officer should reconcile customer, alert, case, SAR, and beneficial-owner populations. Internal audit should confirm independence and preserve the right to challenge scope.
Evidence due at this stage: reconciliations, data owners, exception reports, issue statements, root causes, and approved completion criteria.
Days 31–60: approve the operating controls
Credit Risk should document concentration limits and escalation triggers. Lending should implement exception aging and watch-list governance. Finance should connect the allowance, capital forecast, and liquidity stress assumptions. Compliance should map BSA/AML controls to testing procedures. The board should receive a single cross-domain dashboard rather than separate green status reports.
Evidence due: approved policies, committee minutes, test scripts, management information reports, training records, and implementation tickets.
Days 61–90: test whether the fixes work
Internal audit or another independent party should sample real transactions and loan files, retest data reconciliations, inspect aged exceptions, and challenge closure packages. The board should distinguish “document submitted” from “control operating effectively.” Any failed test returns to the issue inventory with a new owner and due date.
Evidence due: sample results, exception disposition, validation memos, reopened-issue records, and board challenge captured in minutes.
That workflow aligns with the broader MRA remediation playbook and the site’s guide to credit risk KRIs examiners can actually trace.
Five checks for Monday morning
- Pull one board package. Can a director see concentrations, criticized assets, exceptions, nonaccruals, allowance movement, capital, and liquidity in a connected story?
- Trace one criticized relationship. Do the grade, accrual status, collateral value, action plan, and allowance treatment agree everywhere?
- Inspect loan-review independence. Who selects the sample, changes grades, reports exceptions, and validates fixes? Document conflicts.
- Challenge BSA/AML test scope. Does the last review reconcile full populations and retest prior findings, or mostly confirm that policies exist?
- Audit the issue tracker. Does every item have a root cause, accountable owner, due date, evidence requirement, independent validator, and board escalation rule?
The Iuka action’s most useful lesson is not “community banks need stronger policies.” It is that credit, compliance, finance, treasury, audit, and board reporting must run from the same verified facts. When they do not, several ordinary weaknesses can become one extraordinary remediation burden.
If your exam findings are spread across emails and committee decks, the Issues Management Tracker & Template gives you one place to assign owners, evidence, validation, and escalation before the next progress report is due.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the Federal Reserve require from The Iuka State Bank?
Did the Federal Reserve fine Iuka State Bank?
When did the Iuka State Bank written agreement take effect?
What BSA/AML deficiencies does the Iuka agreement address?
What should another community bank review after this action?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
● Don't wait for your own enforcement action
Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Regulatory Compliance
The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs
OFAC's December 2025 settlement with Exodus Movement — $3.1 million for 254 apparent violations of the Iranian Transactions and Sanctions Regulations — is the clearest statement yet that non-custodial crypto wallets are in scope for sanctions obligations. The finding that staff advised Iranian users to use VPNs is the detail that turns a compliance failure into an egregious one.
Jul 30, 2026
Regulatory Compliance
OCC-FDIC CRA Proposal: The 2026 Changes Banks Need to Map Now
The OCC-FDIC CRA proposal changes bank thresholds, lending tests, grant eligibility, and reporting. Here is the control impact.
Jul 30, 2026
Regulatory Compliance
NYDFS Part 500 Class A Requirements: What the 2023 Amendments Added and Where 2026 Exams Are Finding Gaps
NYDFS's Second Amendment to Part 500 created a new Class A tier for larger covered entities. The final compliance deadline passed November 1, 2024 — and 2026 is the first full examination cycle with all amended requirements in scope. Here's what examiners are finding and what covered entities are still getting wrong.
Jul 28, 2026