Feature Regulatory Compliance
CFP Activation and Override Decision Record: Trigger, Funding Choice, Approval, and Review Evidence
Your contingency funding plan's weakest link isn't the trigger framework—it's the decision record. Here's what examiners expect to see when your CFP gets pulled during a review, and how to document activation, non-activation, and overrides contemporaneously.
Table of Contents
Your contingency funding plan trigger framework is probably fine. The problem is what happens the moment a threshold actually gets hit.
Most institutions can point to a tiered trigger framework—green, yellow, amber, red, tied to specific metrics, with escalation paths defined. What they can’t produce is a contemporaneous record of the deliberation that followed when an early-warning indicator first crossed into yellow, or when a more serious threshold was breached and someone decided to activate a contingent funding source. Or, more commonly, when a threshold was hit and someone decided not to activate—and that decision was never written down.
That gap is what OCC Bulletin 2023-25 and the FDIC’s October 2023 guidance was pointing at. Not the trigger design. The documentation of what happened when triggers were met.
TL;DR
- OCC Bulletin 2023-25 (October 2023) requires CFPs to articulate decision-making processes during stress events—not just trigger frameworks
- SVB’s failure demonstrated that untested, undocumented CFPs become operationally unexecutable when stress materializes
- The CFP activation decision record is the artifact that proves deliberate decision-making: trigger state, funding options evaluated, authority, rationale, and outcome
- Overrides—when a trigger is met but activation is deferred—require documentation as much as activation itself
- The record is built before a crisis, populated during it, and retained as a governance artifact afterward
What the 2023 Interagency Addendum Actually Required
Four months after SVB’s March 2023 failure, the OCC, Federal Reserve, FDIC, and NCUA issued OCC Bulletin 2023-25—an addendum to the 2010 Interagency Policy Statement on Funding and Liquidity Risk Management. The headline requirement wasn’t new: institutions should maintain, assess, and test contingency funding plans. What the addendum added was operational emphasis.
Three areas got specific attention:
Tested access to contingent funding sources. The addendum explicitly flagged situations where institutions had listed the Federal Reserve discount window as a contingent funding source without operationally testing their capacity to borrow. SVB had not tested discount window access in 2022. When it attempted to draw in March 2023, the operational arrangements weren’t in place to execute quickly. The addendum requires institutions to demonstrate they’ve actually confirmed access—not just listed the source.
Realistic stress scenarios. The addendum pushed institutions to model sudden, severe events—the kind of deposit run that SVB experienced over 48 hours—not just gradual stress scenarios that trigger warning systems with time to respond.
Roles, responsibilities, and decision-making processes. This is where the decision record requirement lives. A CFP must articulate who is responsible for monitoring triggers, who has authority to activate contingent funding sources, and what the decision-making process looks like when a threshold is breached. “The CRO and CFO will decide” is a role assignment. “Here is the record of how that decision was made and documented” is evidence of process.
The Documentation Gap Most CFPs Leave Open
Pull a typical CFP and you’ll find solid trigger framework design. Green/yellow/amber/red tiers. Specific metrics—wholesale funding ratio, deposit runoff rate, available liquidity buffer as percentage of stressed outflows—with defined thresholds. Escalation paths that reach the CRO, CFO, and board.
What you often won’t find:
- A template for what gets written down when a trigger threshold is first breached
- A record of the last time a trigger was actually hit and what happened
- Documentation of funding options evaluated during a past stress event
- An override record for any instance where a metric hit a threshold and management decided not to act
Examiners reviewing a CFP after a stress event—or as part of routine examination—are increasingly asking for the historical record. Not just “what does your trigger framework say” but “show me the last time an early-warning indicator hit amber, who was notified, what was discussed, and what was decided.” No record is a finding.
The Activation Decision Record: Fields and Format
The CFP activation decision record is a contemporaneous document created when a trigger threshold is breached. It has two versions: one for activation (you are executing a contingent funding response) and one for non-activation or override (a threshold was hit, you reviewed it, and you decided not to activate or to defer).
Core Record Fields
Trigger State at Time of Review
| Field | What to Capture |
|---|---|
| Date and time of review | Timestamp when the trigger state was reviewed |
| Metric(s) in breach | Specific metric name(s), threshold value, actual value |
| Trigger tier | Yellow / Amber / Red (or your institution’s tier labels) |
| Trend direction | Is the metric improving, stable, or deteriorating? |
| Time-since-first-breach | First date this metric entered the breach range |
| Other metrics in watch state | Any additional metrics at or approaching threshold |
Funding Options Evaluated
For each contingent funding source considered, document:
| Funding Source | Available Capacity | Cost / Rate Range | Time to Access | Execution Risk | Included in Response? |
|---|---|---|---|---|---|
| FHLB advances | $[amount], [collateral pledged] | [rate range] | [1 day / 3 days / etc.] | [low/med/high] | Y / N |
| Discount window | $[estimated capacity], [collateral pledged] | Fed funds + spread | 1 business day | Requires prior testing | Y / N |
| Brokered deposits | $[estimated], [broker confirmed] | [current market] | 3–5 business days | Rate volatility | Y / N |
| Asset liquidation | $[eligible securities], [haircut applied] | [estimated proceeds] | Settlement T+1/T+2 | Market conditions | Y / N |
| Other contingent lines | $[available under agreement] | [per agreement] | [per agreement terms] | [counterparty status] | Y / N |
Decision and Authority
| Field | What to Capture |
|---|---|
| Decision | Activate / Defer (override) / Continue monitoring |
| Selected funding response | Which sources are being accessed and in what amounts |
| Total additional liquidity targeted | $ amount |
| Decision authority | Name, title, authority basis (per CFP governance section) |
| Secondary approver | Name, title (if required by CFP governance) |
| Board or committee notification | Y / N — if Y, date and form of notification |
| Timestamp of decision | Date and time decision was made |
The Override Record: When You Don’t Activate Despite Hitting a Trigger
This is the documentation gap that’s most commonly exploited as an exam finding. An institution hits an amber trigger. Management reviews it. They determine it’s transient—a single-day spike in deposit outflows that has since stabilized, a metric calculation artifact, a measurement timing issue. They decide not to activate a contingent funding source. Nothing gets written down.
Three months later, during an exam, an examiner pulls the trigger monitoring log and sees the amber breach. The institution can’t show a documented review or rationale. The finding is that the CFP governance framework wasn’t followed—even though management made a reasonable judgment call in real time.
The override record prevents this. It’s a short document: what metric breached, when, at what value, who reviewed it, what rationale led to non-activation, and when the metric will be reviewed again. It doesn’t need to be long. It needs to exist.
Override Record Minimum Fields:
- Metric(s) in breach and values
- Date and time of management review
- Override rationale (specific, not generic—“metric has been stable for 48 hours and returned to yellow” is defensible; “management determined no action was necessary” is not)
- Specific follow-up action (next monitoring date, metric that would trigger a reassessment)
- Authority who reviewed and approved the override
- Secondary reviewer if required
After-Action Review: Closing the Loop
Every CFP activation—and every significant override—should be followed by an after-action review. For activation, the review typically happens 30–60 days post-event. For overrides involving significant stress, run it when the stress event resolves.
The after-action review answers four questions:
- Did the trigger framework work? Did the right metrics detect the stress event at the right time, or did the institution find itself in amber/red without adequate warning?
- Were the contingent funding sources accessible as planned? Any friction in execution—delays in FHLB advance processing, discount window operational issues, brokered deposit market conditions—gets documented here.
- Was the decision record accurate and complete? Did the record as-written reflect what actually happened, and was it populated in real time or reconstructed afterward?
- What needs to change? Trigger threshold recalibration, funding source testing follow-ups, decision authority updates, CFP governance revisions.
Retain the after-action review as part of the CFP governance file. Examiners reviewing CFP effectiveness want to see that stress events—even small ones—generated a documented learning cycle.
What Examiners Will Ask For
When an examiner reviews your CFP, they’re not just looking at the document. They’re looking for evidence of a live governance process. The questions have shifted since 2023:
- “Show me your trigger monitoring log for the past 12 months.”
- “Has any metric breached a threshold in the past two years? What happened?”
- “Walk me through the last time you tested discount window access. What’s the evidence?”
- “Do you have any override records where a trigger was met but activation was deferred?”
A CFP that’s never been triggered isn’t inherently problematic—many institutions manage their liquidity well enough that thresholds stay green. But a trigger monitoring log that shows a breach with no corresponding decision record or override documentation is a governance failure, not a liquidity one.
So What?
The 2023 interagency addendum didn’t change what a CFP needs to contain. It raised the bar on what it needs to demonstrate. Tested access, realistic scenarios, and documented decision-making processes. The activation and override decision record is the artifact that meets the documentation half of that standard.
Build the template before you need it. Wire it to your trigger monitoring log so that a threshold breach automatically generates a decision record that needs to be populated and signed off within a defined window—24 hours for amber, 4 hours for red. Store the completed records in your CFP evidence binder alongside the testing log and funding source confirmations. Run the after-action review within 60 days of any activation or significant override.
If your institution is working through the post-2023 CFP requirements and needs a full operational framework—trigger templates, funding source inventory, activation playbook, testing log, and governance structure—the Contingency Funding Plan — Banks kit includes the activation playbook with tier-specific action checklists and an evidence binder index built around what examiners actually pull.
Related reading:
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Contingency Funding Plan — Banks
Examiner-ready contingency funding plan for chartered banks built to the 2023 Interagency Addendum.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is a CFP activation decision record?
What does OCC Bulletin 2023-25 require for CFP activation documentation?
When should you document a CFP trigger that you didn't act on?
What funding options should a CFP activation record evaluate?
What does SVB's failure teach us about CFP activation documentation?
How is a CFP activation decision record different from a CFP trigger log?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Contingency Funding Plan — Banks
Examiner-ready contingency funding plan for chartered banks built to the 2023 Interagency Addendum.
◆ Keep reading
Related posts.
Regulatory Compliance
How to Test a Bank CIP: Sampling, Evidence, Exceptions, and Conclusions
Customer identification program testing that covers population completeness, CIP attributes, evidence, exceptions, and defensible workpaper conclusions.
Aug 21, 2026
Regulatory Compliance
SEC's Tricolor Fraud Case: The Double-Pledging Controls Lenders Missed
The SEC's Tricolor fraud case alleges $1.9B in ABS offerings and an $800M collateral hole. Here are the controls lenders should test now.
Aug 21, 2026
Regulatory Compliance
Transaction Monitoring Data Completeness Testing: Counts, Values, Rejects, and Alert Coverage
Build a transaction monitoring data completeness testing workpaper from source population through ingestion, rules, alerts, rejects, and repair.
Aug 18, 2026