Feature Regulatory Compliance
OCC-FDIC CRA Proposal: The 2026 Changes Banks Need to Map Now
The OCC-FDIC CRA proposal changes bank thresholds, lending tests, grant eligibility, and reporting. Here is the control impact.
Table of Contents
TL;DR
- The OCC and FDIC released a new CRA proposal on July 31, 2026 that keeps the familiar 1995-era framework but rewires what receives weight.
- Proposed thresholds move to under $1 billion for small banks, $1 billion to $10 billion for intermediate banks, and over $10 billion for large banks.
- Deposit services would drop out of the retail-services analysis, while large-bank community development grants could lose credit when recipient indirect costs exceed 15%.
- Do not redesign the program yet. Build a change-impact inventory now so the CRA Officer can show what would move, who owns it, and what evidence needs to change.
The new OCC-FDIC CRA proposal is not a cosmetic cleanup. It would change which banks carry the heaviest data burden, which products drive the lending test, which services count, and whether some community development grants receive CRA credit at all.
On July 31, the Office of the Comptroller of the Currency and Federal Deposit Insurance Corporation announced targeted amendments to their current Community Reinvestment Act rules. The agencies say the proposal would preserve much of the framework applied since 1995. That continuity matters, but it should not obscure the operational work hidden inside the changes.
A bank can keep the same CRA policy and still produce the wrong examination file if its product scope, grant due diligence, public file, or data logic no longer matches the rule.
What the 2026 OCC-FDIC CRA proposal would change
The shortest useful summary is this: lending moves closer to the center, community bank burden comes down, and community development grant documentation gets sharper.
The OCC’s Bulletin 2026-35 translates the proposal into changes compliance teams can map:
| Proposed change | Current operating assumption to challenge | Likely owner |
|---|---|---|
| Small-bank threshold rises from $412 million to $1 billion | Current test classification and exam preparation scope | CRA Officer / Regulatory Compliance |
| Intermediate category runs from $1 billion to $10 billion | Data collection and reporting built for a large-bank treatment | CRA Officer / Data Governance |
| Large bank means over $10 billion | Threshold monitoring and acquisition-growth planning | CFO / Regulatory Change Management |
| Retail lending review focuses on major product lines | Every retail lending line receives equivalent preparation effort | CRA Officer / Lending Compliance |
| Retail service analysis excludes deposit services | Deposit products and deposit delivery narratives support the services case | Retail Banking / CRA Officer |
| Large-bank grant recipients face a 15% indirect-cost ceiling | Grant eligibility relies mainly on mission and geography | Community Development / Legal |
| Agencies maintain illustrative lists and an activity-confirmation process | Qualification decisions rely on internal interpretation until the exam | CRA Officer / Legal |
| Public notice and public file can use more technology | Paper-first controls remain the official process | Compliance Operations / Web Owner |
These are proposed requirements. No one should shut off a report or rewrite a grant agreement based on a press release. The immediate task is impact analysis, not implementation theater.
The asset thresholds create a classification-control problem
The proposal creates three categories:
- Small bank: less than $1 billion in assets
- Intermediate bank: $1 billion through $10 billion
- Large bank: more than $10 billion
That would replace current thresholds cited by the OCC of $412 million for small banks and $1.65 billion for intermediate small banks. Banks at or near the proposed boundaries need more than a line in the regulatory change log. They need a classification control that connects finance data to compliance obligations.
A workable control looks like this:
- Finance supplies quarter-end total assets from the authoritative regulatory-reporting source.
- Regulatory Change Management compares the result to current and pending rule thresholds.
- The CRA Officer documents the applicable examination category and affected controls.
- Compliance Testing checks whether required data, files, and performance-test preparation match that category.
- M&A governance triggers a prospective CRA impact assessment before a transaction crosses a threshold.
The artifact should be a signed classification memo with the source balance, calculation date, applicable rule version, projected threshold crossings, and control changes. A spreadsheet cell that turns yellow is not enough if no one is accountable for the response.
The proposal says banks with $10 billion or less would face fewer data collection, maintenance, and reporting requirements. That is meaningful relief. It is also where teams make mistakes: they hear “less reporting,” retire a process early, and later discover that the data still supports fair lending, HMDA, board reporting, or a state obligation.
For a disciplined way to manage that dependency, use the same implementation-record approach described in how to prove a regulatory change became a working control.
Major product lines become the examination-scope hinge
The proposal would evaluate retail lending through a bank’s major product lines. The notice identifies consumer, home mortgage, small business, and small farm loans as the relevant retail lending families and discusses two alternatives for selecting the major lines.
This is not permission to ignore smaller portfolios. It changes how the CRA evaluation may be scoped; it does not erase fair lending, consumer compliance, credit risk, or state-law obligations.
The CRA team should prepare a repeatable product-line determination file containing:
- loan count and dollar volume by retail product line;
- the source systems and reporting period used;
- treatment of acquired, sold, or discontinued portfolios;
- management’s rationale for lines treated as major;
- reconciliation to Call Report, HMDA, CRA, or internal lending data as applicable;
- a challenge record from Compliance or Internal Audit.
The practical mess appears when Finance defines products one way, Lending another, and CRA data another. “Small business” may be a marketing segment, a regulatory reporting category, and a general-ledger grouping with three different populations. Resolve that mapping before an examiner asks why the selected product lines do not reconcile.
Deposit-service narratives need a controlled exit review
The proposal would narrow the range of retail banking services considered to credit services, excluding deposit services, while continuing to consider the distribution and availability of retail banking facilities.
That means a bank should inventory every place deposit services currently appear in its CRA program:
- performance-context narratives;
- branch strategy and closure analyses;
- product committee materials;
- community needs assessments;
- CRA committee reporting;
- examination response libraries.
Do not delete those records. Tag them by legal purpose. A branch-access analysis may remain relevant even if a particular deposit product no longer earns the same CRA consideration. The bank may also need the evidence for fair banking, customer-impact, strategic, or state-law reasons.
This is a classic regulatory-change trap: one requirement narrows, but the underlying artifact serves four other controls. A proper retention decision is made by Legal, Records Management, and the control owner together.
The 15% grant rule turns nonprofit overhead into bank due diligence
The sharpest operational change is proposed for community development grants and donations.
The agencies would limit consideration to funds directly used for a plan, project, or initiative whose primary purpose is community development. For a large bank, the recipient’s indirect costs for administering the grant could not exceed 15%.
The full notice of proposed rulemaking gives a concrete example: a grant recipient reportedly used about 25% for internal expenses and the rest for direct services. Under the proposal, that grant would not qualify for a large bank because the indirect-cost share exceeded 15%.
That changes grant files. A mission statement and IRS determination letter will not establish compliance with the proposed test.
For each proposed community development grant, large banks should be able to produce:
| Evidence item | What it proves | Owner |
|---|---|---|
| Detailed project budget | Direct versus indirect use of proceeds | Community Development |
| Written indirect-cost definition | Consistent numerator and denominator | Finance / Legal |
| Recipient certification | Recipient accepts the use and cost conditions | Legal |
| Payment milestones | Funds follow project delivery rather than an unsupported lump sum | Community Development |
| Post-award expenditure report | Actual use remained within approved categories | Recipient + Bank Grant Owner |
| Exception and escalation record | Overruns are identified before CRA credit is claimed | CRA Officer |
The human problem is predictable. Community partners may use different overhead definitions, audited financial statements may not isolate one grant, and program teams may resist asking a trusted nonprofit for another certification. That is exactly why the definition, evidence standard, and escalation path need to be set before the first affected award.
Treat 15% as a proposed legal threshold, not a procurement score. The bank should not quietly convert it into a broader judgment that a nonprofit is efficient or inefficient.
The proposal could finally reduce qualification guesswork
The agencies propose a public, non-exhaustive illustrative list of qualifying community development activities and a process for confirming whether an activity qualifies. The notice describes uncertainty over CRA credit as a longstanding pain point and says the agencies intend to coordinate their lists, even though the rule would not require a single joint list.
That calls for a decision register:
- activity description and geography;
- community development purpose;
- relevant list example;
- agency confirmation, if requested;
- internal legal analysis;
- decision date and approver;
- examination outcome;
- reusable precedent tags.
Without that register, the same qualification question gets researched repeatedly, often with inconsistent answers. With it, the CRA Officer can show an examiner both the conclusion and the governance behind it.
The FDIC’s parallel release confirms this is a joint OCC-FDIC proposal. The Federal Reserve is not listed as a participating agency in the July 31 release, so Fed-supervised institutions should not assume their rule changes on the same timetable or in the same form.
A 30/60/90-day CRA proposal response
Days 1-30: establish the impact baseline
- Regulatory Change Management: log the proposal, source documents, affected legal entities, and comment deadline of 60 days after Federal Register publication.
- CRA Officer: classify each bank under current and proposed asset thresholds.
- Data Governance: inventory CRA reports that could be retired, reduced, or repurposed.
- Community Development: identify grants with indirect costs above, below, or unknown relative to 15%.
- Retail Lending: produce a first-pass major-product-line population and reconcile definitions.
Days 31-60: challenge the operating model
- Run a mock proposed-rule classification for the last completed examination period.
- Sample ten community development grants and calculate indirect cost using one documented method.
- Trace each major product line from source system to CRA analysis.
- Mark every deposit-services narrative with its remaining legal or business purpose.
- Escalate policy questions for a bank comment letter or trade-association response.
Days 61-90: prepare the implementation record
- Draft policy and procedure redlines without approving them prematurely.
- Assign final-rule decision points and dependencies.
- Build test scripts for asset classification, grant eligibility, and product-line selection.
- Create a board or CRA Committee memo distinguishing proposal facts, management assumptions, and open questions.
- Preserve the baseline so later reviewers can see why each change was made.
Banks should also review the broader mechanics in building a regulatory change management program and monitor whether delayed implementation shows up in regulatory change KRIs.
What to do Monday morning
Create one row for every affected control: asset classification, lending-scope selection, CRA data reporting, retail-services analysis, grant qualification, public-file maintenance, strategic-plan governance, and activity confirmation. Give each row an owner, current evidence, proposed change, dependency, and decision date.
That is the difference between “Compliance read the proposal” and a bank that can implement the final rule without losing its audit trail.
If the control inventory is the part you do not have, the RCSA Template provides a structured place to map risks, controls, evidence, owners, and testing before the proposal becomes an implementation scramble.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
RCSA (Risk & Control Self-Assessment)
141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What does the 2026 OCC-FDIC CRA proposal change?
Would banks under $10 billion have new CRA data reporting requirements?
Does the proposal eliminate deposit services from CRA evaluations?
What is the proposed 15 percent limit for community development grants?
When are comments on the CRA proposal due?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
RCSA (Risk & Control Self-Assessment)
141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.
◆ Keep reading
Related posts.
Regulatory Compliance
The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs
OFAC's December 2025 settlement with Exodus Movement — $3.1 million for 254 apparent violations of the Iranian Transactions and Sanctions Regulations — is the clearest statement yet that non-custodial crypto wallets are in scope for sanctions obligations. The finding that staff advised Iranian users to use VPNs is the detail that turns a compliance failure into an egregious one.
Jul 30, 2026
Regulatory Compliance
Iuka State Bank Written Agreement: The Fed's 30-Day Credit Risk and BSA/AML Remediation List
The Iuka State Bank written agreement maps Fed findings to 30- and 60-day fixes across credit, capital, liquidity, and BSA/AML.
Jul 30, 2026
Regulatory Compliance
NYDFS Part 500 Class A Requirements: What the 2023 Amendments Added and Where 2026 Exams Are Finding Gaps
NYDFS's Second Amendment to Part 500 created a new Class A tier for larger covered entities. The final compliance deadline passed November 1, 2024 — and 2026 is the first full examination cycle with all amended requirements in scope. Here's what examiners are finding and what covered entities are still getting wrong.
Jul 28, 2026