Skip to content
RiskTemplates · The Daily Brief Friday, August 21, 2026
Wire SEC's Tricolor Fraud Case: The Double-Pledging Controls Lenders Missed AUG 20

Feature Regulatory Compliance

CFP Activation and Override Decision Record: Trigger, Funding Choice, Approval, and Review Evidence

Your contingency funding plan's weakest link isn't the trigger framework—it's the decision record. Here's what examiners expect to see when your CFP gets pulled during a review, and how to document activation, non-activation, and overrides contemporaneously.

Table of Contents

Your contingency funding plan trigger framework is probably fine. The problem is what happens the moment a threshold actually gets hit.

Most institutions can point to a tiered trigger framework—green, yellow, amber, red, tied to specific metrics, with escalation paths defined. What they can’t produce is a contemporaneous record of the deliberation that followed when an early-warning indicator first crossed into yellow, or when a more serious threshold was breached and someone decided to activate a contingent funding source. Or, more commonly, when a threshold was hit and someone decided not to activate—and that decision was never written down.

That gap is what OCC Bulletin 2023-25 and the FDIC’s October 2023 guidance was pointing at. Not the trigger design. The documentation of what happened when triggers were met.


TL;DR

  • OCC Bulletin 2023-25 (October 2023) requires CFPs to articulate decision-making processes during stress events—not just trigger frameworks
  • SVB’s failure demonstrated that untested, undocumented CFPs become operationally unexecutable when stress materializes
  • The CFP activation decision record is the artifact that proves deliberate decision-making: trigger state, funding options evaluated, authority, rationale, and outcome
  • Overrides—when a trigger is met but activation is deferred—require documentation as much as activation itself
  • The record is built before a crisis, populated during it, and retained as a governance artifact afterward

What the 2023 Interagency Addendum Actually Required

Four months after SVB’s March 2023 failure, the OCC, Federal Reserve, FDIC, and NCUA issued OCC Bulletin 2023-25—an addendum to the 2010 Interagency Policy Statement on Funding and Liquidity Risk Management. The headline requirement wasn’t new: institutions should maintain, assess, and test contingency funding plans. What the addendum added was operational emphasis.

Three areas got specific attention:

Tested access to contingent funding sources. The addendum explicitly flagged situations where institutions had listed the Federal Reserve discount window as a contingent funding source without operationally testing their capacity to borrow. SVB had not tested discount window access in 2022. When it attempted to draw in March 2023, the operational arrangements weren’t in place to execute quickly. The addendum requires institutions to demonstrate they’ve actually confirmed access—not just listed the source.

Realistic stress scenarios. The addendum pushed institutions to model sudden, severe events—the kind of deposit run that SVB experienced over 48 hours—not just gradual stress scenarios that trigger warning systems with time to respond.

Roles, responsibilities, and decision-making processes. This is where the decision record requirement lives. A CFP must articulate who is responsible for monitoring triggers, who has authority to activate contingent funding sources, and what the decision-making process looks like when a threshold is breached. “The CRO and CFO will decide” is a role assignment. “Here is the record of how that decision was made and documented” is evidence of process.

The Documentation Gap Most CFPs Leave Open

Pull a typical CFP and you’ll find solid trigger framework design. Green/yellow/amber/red tiers. Specific metrics—wholesale funding ratio, deposit runoff rate, available liquidity buffer as percentage of stressed outflows—with defined thresholds. Escalation paths that reach the CRO, CFO, and board.

What you often won’t find:

  • A template for what gets written down when a trigger threshold is first breached
  • A record of the last time a trigger was actually hit and what happened
  • Documentation of funding options evaluated during a past stress event
  • An override record for any instance where a metric hit a threshold and management decided not to act

Examiners reviewing a CFP after a stress event—or as part of routine examination—are increasingly asking for the historical record. Not just “what does your trigger framework say” but “show me the last time an early-warning indicator hit amber, who was notified, what was discussed, and what was decided.” No record is a finding.

The Activation Decision Record: Fields and Format

The CFP activation decision record is a contemporaneous document created when a trigger threshold is breached. It has two versions: one for activation (you are executing a contingent funding response) and one for non-activation or override (a threshold was hit, you reviewed it, and you decided not to activate or to defer).

Core Record Fields

Trigger State at Time of Review

FieldWhat to Capture
Date and time of reviewTimestamp when the trigger state was reviewed
Metric(s) in breachSpecific metric name(s), threshold value, actual value
Trigger tierYellow / Amber / Red (or your institution’s tier labels)
Trend directionIs the metric improving, stable, or deteriorating?
Time-since-first-breachFirst date this metric entered the breach range
Other metrics in watch stateAny additional metrics at or approaching threshold

Funding Options Evaluated

For each contingent funding source considered, document:

Funding SourceAvailable CapacityCost / Rate RangeTime to AccessExecution RiskIncluded in Response?
FHLB advances$[amount], [collateral pledged][rate range][1 day / 3 days / etc.][low/med/high]Y / N
Discount window$[estimated capacity], [collateral pledged]Fed funds + spread1 business dayRequires prior testingY / N
Brokered deposits$[estimated], [broker confirmed][current market]3–5 business daysRate volatilityY / N
Asset liquidation$[eligible securities], [haircut applied][estimated proceeds]Settlement T+1/T+2Market conditionsY / N
Other contingent lines$[available under agreement][per agreement][per agreement terms][counterparty status]Y / N

Decision and Authority

FieldWhat to Capture
DecisionActivate / Defer (override) / Continue monitoring
Selected funding responseWhich sources are being accessed and in what amounts
Total additional liquidity targeted$ amount
Decision authorityName, title, authority basis (per CFP governance section)
Secondary approverName, title (if required by CFP governance)
Board or committee notificationY / N — if Y, date and form of notification
Timestamp of decisionDate and time decision was made

The Override Record: When You Don’t Activate Despite Hitting a Trigger

This is the documentation gap that’s most commonly exploited as an exam finding. An institution hits an amber trigger. Management reviews it. They determine it’s transient—a single-day spike in deposit outflows that has since stabilized, a metric calculation artifact, a measurement timing issue. They decide not to activate a contingent funding source. Nothing gets written down.

Three months later, during an exam, an examiner pulls the trigger monitoring log and sees the amber breach. The institution can’t show a documented review or rationale. The finding is that the CFP governance framework wasn’t followed—even though management made a reasonable judgment call in real time.

The override record prevents this. It’s a short document: what metric breached, when, at what value, who reviewed it, what rationale led to non-activation, and when the metric will be reviewed again. It doesn’t need to be long. It needs to exist.

Override Record Minimum Fields:

  • Metric(s) in breach and values
  • Date and time of management review
  • Override rationale (specific, not generic—“metric has been stable for 48 hours and returned to yellow” is defensible; “management determined no action was necessary” is not)
  • Specific follow-up action (next monitoring date, metric that would trigger a reassessment)
  • Authority who reviewed and approved the override
  • Secondary reviewer if required

After-Action Review: Closing the Loop

Every CFP activation—and every significant override—should be followed by an after-action review. For activation, the review typically happens 30–60 days post-event. For overrides involving significant stress, run it when the stress event resolves.

The after-action review answers four questions:

  1. Did the trigger framework work? Did the right metrics detect the stress event at the right time, or did the institution find itself in amber/red without adequate warning?
  2. Were the contingent funding sources accessible as planned? Any friction in execution—delays in FHLB advance processing, discount window operational issues, brokered deposit market conditions—gets documented here.
  3. Was the decision record accurate and complete? Did the record as-written reflect what actually happened, and was it populated in real time or reconstructed afterward?
  4. What needs to change? Trigger threshold recalibration, funding source testing follow-ups, decision authority updates, CFP governance revisions.

Retain the after-action review as part of the CFP governance file. Examiners reviewing CFP effectiveness want to see that stress events—even small ones—generated a documented learning cycle.

What Examiners Will Ask For

When an examiner reviews your CFP, they’re not just looking at the document. They’re looking for evidence of a live governance process. The questions have shifted since 2023:

  • “Show me your trigger monitoring log for the past 12 months.”
  • “Has any metric breached a threshold in the past two years? What happened?”
  • “Walk me through the last time you tested discount window access. What’s the evidence?”
  • “Do you have any override records where a trigger was met but activation was deferred?”

A CFP that’s never been triggered isn’t inherently problematic—many institutions manage their liquidity well enough that thresholds stay green. But a trigger monitoring log that shows a breach with no corresponding decision record or override documentation is a governance failure, not a liquidity one.

So What?

The 2023 interagency addendum didn’t change what a CFP needs to contain. It raised the bar on what it needs to demonstrate. Tested access, realistic scenarios, and documented decision-making processes. The activation and override decision record is the artifact that meets the documentation half of that standard.

Build the template before you need it. Wire it to your trigger monitoring log so that a threshold breach automatically generates a decision record that needs to be populated and signed off within a defined window—24 hours for amber, 4 hours for red. Store the completed records in your CFP evidence binder alongside the testing log and funding source confirmations. Run the after-action review within 60 days of any activation or significant override.

If your institution is working through the post-2023 CFP requirements and needs a full operational framework—trigger templates, funding source inventory, activation playbook, testing log, and governance structure—the Contingency Funding Plan — Banks kit includes the activation playbook with tier-specific action checklists and an evidence binder index built around what examiners actually pull.


Related reading:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is a CFP activation decision record?
A CFP activation decision record is a contemporaneous document that captures the full decision process when your contingency funding plan is triggered: which specific metrics crossed a threshold, what funding options were evaluated, the liquidity impact of each, who had authority to activate, what was decided and why, and any override rationale if a trigger was met but activation was deferred. It's the artifact that proves you ran a deliberate decision process—not just that a threshold was hit.
What does OCC Bulletin 2023-25 require for CFP activation documentation?
OCC Bulletin 2023-25 (the October 2023 Interagency Addendum on CFP Importance) requires institutions to have plans in place that articulate roles and responsibilities and describe decision-making processes during stress events. While it doesn't mandate a specific decision record format, the addendum's emphasis on operational readiness—tested access to contingent funding, defined escalation protocols, and demonstrated ability to execute—means examiners expect evidence that decisions were made deliberately and documented in real time, not reconstructed after the fact.
When should you document a CFP trigger that you didn't act on?
Always. An override—when a CFP trigger threshold is met but activation is deferred—requires documentation as much as activation itself. The record should capture: the trigger metric and its value at the time, the authority who reviewed the trigger state, the specific rationale for non-activation (e.g., the stress signal is transient, a specific funding source was confirmed available, management assessed the metric as a measurement artifact), and the date of next review. Undocumented overrides are a finding waiting to happen.
What funding options should a CFP activation record evaluate?
At minimum: FHLB advances (available capacity, pledged collateral, outstanding borrowings), Federal Reserve discount window (tested access, pledged collateral, estimated draw capacity), brokered deposits (broker relationships confirmed, rate range, estimated volume), other contingent lines, and asset liquidation (eligible securities, estimated proceeds after haircuts, settlement timeline). Each option should have an estimated draw amount, cost, timeline to access, and any execution risk noted. The record should show why the chosen option was selected over alternatives.
What does SVB's failure teach us about CFP activation documentation?
SVB's failure illustrated the consequences of an untested, undocumented CFP. GAO's preliminary review found that SVB had not conducted comprehensive testing of its contingent funding plan, including discount window access. In its final days, SVB attempted to access the discount window but lacked the operational arrangements to do so quickly. A well-documented CFP activation record—populated and tested before a stress event—can't prevent a run, but it can prevent the operational scramble that turns a manageable stress into an unexecutable response.
How is a CFP activation decision record different from a CFP trigger log?
A trigger log is a monitoring artifact: it records which metrics you track, their threshold values, and their current readings. A decision record is an activation artifact: it's created when a threshold is breached and documents the deliberation that followed. The trigger log tells you when a threshold was hit. The decision record tells you what you did about it, who decided, what options were considered, and why. Examiners who pull your CFP during a review want both—and the absence of a decision record for a past trigger event is a significant finding.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Contingency Funding Plan — Banks

Examiner-ready contingency funding plan for chartered banks built to the 2023 Interagency Addendum.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.