Skip to content
RiskTemplates · The Daily Brief Friday, July 31, 2026
Wire The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs JUL 30

Feature Regulatory Compliance

OCC-FDIC CRA Proposal: The 2026 Changes Banks Need to Map Now

The OCC-FDIC CRA proposal changes bank thresholds, lending tests, grant eligibility, and reporting. Here is the control impact.

By Rebecca Leung · July 30, 2026 ·
Table of Contents

TL;DR

  • The OCC and FDIC released a new CRA proposal on July 31, 2026 that keeps the familiar 1995-era framework but rewires what receives weight.
  • Proposed thresholds move to under $1 billion for small banks, $1 billion to $10 billion for intermediate banks, and over $10 billion for large banks.
  • Deposit services would drop out of the retail-services analysis, while large-bank community development grants could lose credit when recipient indirect costs exceed 15%.
  • Do not redesign the program yet. Build a change-impact inventory now so the CRA Officer can show what would move, who owns it, and what evidence needs to change.

The new OCC-FDIC CRA proposal is not a cosmetic cleanup. It would change which banks carry the heaviest data burden, which products drive the lending test, which services count, and whether some community development grants receive CRA credit at all.

On July 31, the Office of the Comptroller of the Currency and Federal Deposit Insurance Corporation announced targeted amendments to their current Community Reinvestment Act rules. The agencies say the proposal would preserve much of the framework applied since 1995. That continuity matters, but it should not obscure the operational work hidden inside the changes.

A bank can keep the same CRA policy and still produce the wrong examination file if its product scope, grant due diligence, public file, or data logic no longer matches the rule.

What the 2026 OCC-FDIC CRA proposal would change

The shortest useful summary is this: lending moves closer to the center, community bank burden comes down, and community development grant documentation gets sharper.

The OCC’s Bulletin 2026-35 translates the proposal into changes compliance teams can map:

Proposed changeCurrent operating assumption to challengeLikely owner
Small-bank threshold rises from $412 million to $1 billionCurrent test classification and exam preparation scopeCRA Officer / Regulatory Compliance
Intermediate category runs from $1 billion to $10 billionData collection and reporting built for a large-bank treatmentCRA Officer / Data Governance
Large bank means over $10 billionThreshold monitoring and acquisition-growth planningCFO / Regulatory Change Management
Retail lending review focuses on major product linesEvery retail lending line receives equivalent preparation effortCRA Officer / Lending Compliance
Retail service analysis excludes deposit servicesDeposit products and deposit delivery narratives support the services caseRetail Banking / CRA Officer
Large-bank grant recipients face a 15% indirect-cost ceilingGrant eligibility relies mainly on mission and geographyCommunity Development / Legal
Agencies maintain illustrative lists and an activity-confirmation processQualification decisions rely on internal interpretation until the examCRA Officer / Legal
Public notice and public file can use more technologyPaper-first controls remain the official processCompliance Operations / Web Owner

These are proposed requirements. No one should shut off a report or rewrite a grant agreement based on a press release. The immediate task is impact analysis, not implementation theater.

The asset thresholds create a classification-control problem

The proposal creates three categories:

  • Small bank: less than $1 billion in assets
  • Intermediate bank: $1 billion through $10 billion
  • Large bank: more than $10 billion

That would replace current thresholds cited by the OCC of $412 million for small banks and $1.65 billion for intermediate small banks. Banks at or near the proposed boundaries need more than a line in the regulatory change log. They need a classification control that connects finance data to compliance obligations.

A workable control looks like this:

  1. Finance supplies quarter-end total assets from the authoritative regulatory-reporting source.
  2. Regulatory Change Management compares the result to current and pending rule thresholds.
  3. The CRA Officer documents the applicable examination category and affected controls.
  4. Compliance Testing checks whether required data, files, and performance-test preparation match that category.
  5. M&A governance triggers a prospective CRA impact assessment before a transaction crosses a threshold.

The artifact should be a signed classification memo with the source balance, calculation date, applicable rule version, projected threshold crossings, and control changes. A spreadsheet cell that turns yellow is not enough if no one is accountable for the response.

The proposal says banks with $10 billion or less would face fewer data collection, maintenance, and reporting requirements. That is meaningful relief. It is also where teams make mistakes: they hear “less reporting,” retire a process early, and later discover that the data still supports fair lending, HMDA, board reporting, or a state obligation.

For a disciplined way to manage that dependency, use the same implementation-record approach described in how to prove a regulatory change became a working control.

Major product lines become the examination-scope hinge

The proposal would evaluate retail lending through a bank’s major product lines. The notice identifies consumer, home mortgage, small business, and small farm loans as the relevant retail lending families and discusses two alternatives for selecting the major lines.

This is not permission to ignore smaller portfolios. It changes how the CRA evaluation may be scoped; it does not erase fair lending, consumer compliance, credit risk, or state-law obligations.

The CRA team should prepare a repeatable product-line determination file containing:

  • loan count and dollar volume by retail product line;
  • the source systems and reporting period used;
  • treatment of acquired, sold, or discontinued portfolios;
  • management’s rationale for lines treated as major;
  • reconciliation to Call Report, HMDA, CRA, or internal lending data as applicable;
  • a challenge record from Compliance or Internal Audit.

The practical mess appears when Finance defines products one way, Lending another, and CRA data another. “Small business” may be a marketing segment, a regulatory reporting category, and a general-ledger grouping with three different populations. Resolve that mapping before an examiner asks why the selected product lines do not reconcile.

Deposit-service narratives need a controlled exit review

The proposal would narrow the range of retail banking services considered to credit services, excluding deposit services, while continuing to consider the distribution and availability of retail banking facilities.

That means a bank should inventory every place deposit services currently appear in its CRA program:

  • performance-context narratives;
  • branch strategy and closure analyses;
  • product committee materials;
  • community needs assessments;
  • CRA committee reporting;
  • examination response libraries.

Do not delete those records. Tag them by legal purpose. A branch-access analysis may remain relevant even if a particular deposit product no longer earns the same CRA consideration. The bank may also need the evidence for fair banking, customer-impact, strategic, or state-law reasons.

This is a classic regulatory-change trap: one requirement narrows, but the underlying artifact serves four other controls. A proper retention decision is made by Legal, Records Management, and the control owner together.

The 15% grant rule turns nonprofit overhead into bank due diligence

The sharpest operational change is proposed for community development grants and donations.

The agencies would limit consideration to funds directly used for a plan, project, or initiative whose primary purpose is community development. For a large bank, the recipient’s indirect costs for administering the grant could not exceed 15%.

The full notice of proposed rulemaking gives a concrete example: a grant recipient reportedly used about 25% for internal expenses and the rest for direct services. Under the proposal, that grant would not qualify for a large bank because the indirect-cost share exceeded 15%.

That changes grant files. A mission statement and IRS determination letter will not establish compliance with the proposed test.

For each proposed community development grant, large banks should be able to produce:

Evidence itemWhat it provesOwner
Detailed project budgetDirect versus indirect use of proceedsCommunity Development
Written indirect-cost definitionConsistent numerator and denominatorFinance / Legal
Recipient certificationRecipient accepts the use and cost conditionsLegal
Payment milestonesFunds follow project delivery rather than an unsupported lump sumCommunity Development
Post-award expenditure reportActual use remained within approved categoriesRecipient + Bank Grant Owner
Exception and escalation recordOverruns are identified before CRA credit is claimedCRA Officer

The human problem is predictable. Community partners may use different overhead definitions, audited financial statements may not isolate one grant, and program teams may resist asking a trusted nonprofit for another certification. That is exactly why the definition, evidence standard, and escalation path need to be set before the first affected award.

Treat 15% as a proposed legal threshold, not a procurement score. The bank should not quietly convert it into a broader judgment that a nonprofit is efficient or inefficient.

The proposal could finally reduce qualification guesswork

The agencies propose a public, non-exhaustive illustrative list of qualifying community development activities and a process for confirming whether an activity qualifies. The notice describes uncertainty over CRA credit as a longstanding pain point and says the agencies intend to coordinate their lists, even though the rule would not require a single joint list.

That calls for a decision register:

  • activity description and geography;
  • community development purpose;
  • relevant list example;
  • agency confirmation, if requested;
  • internal legal analysis;
  • decision date and approver;
  • examination outcome;
  • reusable precedent tags.

Without that register, the same qualification question gets researched repeatedly, often with inconsistent answers. With it, the CRA Officer can show an examiner both the conclusion and the governance behind it.

The FDIC’s parallel release confirms this is a joint OCC-FDIC proposal. The Federal Reserve is not listed as a participating agency in the July 31 release, so Fed-supervised institutions should not assume their rule changes on the same timetable or in the same form.

A 30/60/90-day CRA proposal response

Days 1-30: establish the impact baseline

  • Regulatory Change Management: log the proposal, source documents, affected legal entities, and comment deadline of 60 days after Federal Register publication.
  • CRA Officer: classify each bank under current and proposed asset thresholds.
  • Data Governance: inventory CRA reports that could be retired, reduced, or repurposed.
  • Community Development: identify grants with indirect costs above, below, or unknown relative to 15%.
  • Retail Lending: produce a first-pass major-product-line population and reconcile definitions.

Days 31-60: challenge the operating model

  • Run a mock proposed-rule classification for the last completed examination period.
  • Sample ten community development grants and calculate indirect cost using one documented method.
  • Trace each major product line from source system to CRA analysis.
  • Mark every deposit-services narrative with its remaining legal or business purpose.
  • Escalate policy questions for a bank comment letter or trade-association response.

Days 61-90: prepare the implementation record

  • Draft policy and procedure redlines without approving them prematurely.
  • Assign final-rule decision points and dependencies.
  • Build test scripts for asset classification, grant eligibility, and product-line selection.
  • Create a board or CRA Committee memo distinguishing proposal facts, management assumptions, and open questions.
  • Preserve the baseline so later reviewers can see why each change was made.

Banks should also review the broader mechanics in building a regulatory change management program and monitor whether delayed implementation shows up in regulatory change KRIs.

What to do Monday morning

Create one row for every affected control: asset classification, lending-scope selection, CRA data reporting, retail-services analysis, grant qualification, public-file maintenance, strategic-plan governance, and activity confirmation. Give each row an owner, current evidence, proposed change, dependency, and decision date.

That is the difference between “Compliance read the proposal” and a bank that can implement the final rule without losing its audit trail.

If the control inventory is the part you do not have, the RCSA Template provides a structured place to map risks, controls, evidence, owners, and testing before the proposal becomes an implementation scramble.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What does the 2026 OCC-FDIC CRA proposal change?
The proposal would refocus CRA evaluations on lending and credit services, raise the small-bank threshold to $1 billion and the intermediate-bank ceiling to $10 billion, limit large-bank grant credit where indirect costs exceed 15 percent, and clarify qualifying community development activities. It is a proposal, not a final rule.
Would banks under $10 billion have new CRA data reporting requirements?
The proposal generally moves in the opposite direction. Banks with $10 billion or less would be classified as small or intermediate banks and would face fewer data collection, maintenance, and reporting requirements than large banks. Compliance teams should confirm the final rule before changing current processes.
Does the proposal eliminate deposit services from CRA evaluations?
The proposal would narrow the retail banking services considered to credit services and the distribution and availability of retail banking facilities, excluding deposit services from the range of services evaluated. Banks should inventory which current CRA narratives depend on deposit-service activity.
What is the proposed 15 percent limit for community development grants?
For banks over $10 billion, a community development grant or donation would need to go to a recipient whose indirect costs for administering it do not exceed 15 percent. The proposal also requires the funds to be directly used for a plan, project, or initiative with community development as a primary purpose.
When are comments on the CRA proposal due?
The OCC and FDIC state that comments are due 60 days after the proposal is published in the Federal Register. Banks should use the Federal Register publication, once posted, to calculate the actual deadline.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

RCSA (Risk & Control Self-Assessment)

141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.