Feature Operational Risk
The OCC's Spring 2026 Risk Perspective Named Three Operational Threats. Here's What Your Program Needs to Fix.
The OCC's Spring 2026 Semiannual Risk Perspective shifted focus from credit risk to operational resilience—flagging legacy technology, rising fraud, and sophisticated cyber threats as the top concerns. Here's what that means for your risk program.
Table of Contents
TL;DR
- The OCC’s Spring 2026 Semiannual Risk Perspective describes balance sheets as “strong” and credit risk as “manageable”—the focus has shifted to operational risk
- Three specific threats: legacy technology and end-of-life infrastructure; rising fraud driven by sophisticated impersonation scams; and elevated cyber threats from criminal groups and foreign state-sponsored actors
- The OCC frames operational resilience—not capital strength—as the key determinant of which institutions prove durable in the next stress cycle
- For most risk programs, this is a gap: capital and credit KRIs are mature, but operational resilience metrics often lack meaningful thresholds
The OCC Semiannual Risk Perspective is one of the clearest public signals of where examiner attention is heading. Not because it reveals anything examiners don’t already know—they wrote it. But because it tells you which conversations will dominate your next exam cycle.
The Spring 2026 edition made something explicit that practitioners have been sensing for a while: the credit risk moment has passed. Bank earnings improved in 2025 supported by loan growth and declining funding costs. Balance sheets remain strong, with capital ratios and liquidity high by historical standards. Credit risk within the federal banking system is described as manageable.
What’s elevated now is operational risk. Specifically: three threats the OCC’s National Risk Committee identified as elevated and interconnected—legacy technology vulnerabilities, rising fraud, and sophisticated cyber threats. If those aren’t showing up on your risk dashboard with real KRIs and real thresholds, you’re measuring the previous exam cycle.
Why the Focus Shifted to Operational Risk
The Spring 2026 report introduces a framing that hasn’t appeared this explicitly in prior editions: operational resilience—not just capital strength—may determine which institutions prove durable in the next phase of banking stress.
That’s a significant statement. For decades, bank supervision organized itself around capital adequacy as the primary health metric. The question was whether an institution could absorb losses. The Spring 2026 framing introduces a parallel question: can the institution continue to deliver critical services through disruption?
Those questions require different answers—and different risk programs. A bank with strong capital ratios but brittle operational infrastructure has a vulnerability profile that traditional capital metrics don’t capture. An institution running core functions on end-of-life systems, with fraud monitoring that can’t keep pace with social engineering attacks, is exposed in ways that a Tier 1 capital ratio won’t reveal.
The OCC is signaling that examinations are increasingly testing for the latter.
Threat 1: Legacy Technology
The Spring 2026 report identifies outdated legacy systems and end-of-life infrastructure as material operational risk vulnerabilities. That phrasing—material—is examiner language. It’s the difference between a risk that’s logged and a risk that’s examined.
The tension the OCC is flagging: technology modernization is both necessary and itself a source of risk. Every major system migration or cloud conversion introduces operational, compliance, and cybersecurity exposure during the transition. Banks that defer modernization accumulate infrastructure risk. Banks that rush modernization accumulate implementation risk. Neither is a clean answer.
What examiners are now asking for isn’t just a current-state inventory of where legacy technology sits. It’s a roadmap—documented milestones, resource allocation, and risk mitigation controls for the transition period itself. Saying “we know the core system is end-of-life” is insufficient without a credible plan for what comes next and when.
For community banks and smaller fintechs, this often means the core banking platform that’s been in production for 15-20 years, running on vendor support that’s thinning out. The OCC’s concern isn’t abstract—it’s about the specific operational risk created when institutional knowledge of how a system works is concentrated in two people who are retirement-eligible, the vendor’s support roadmap ends in 36 months, and there’s no documented migration plan with assigned owners.
One thing to note from the Spring 2026 framing: the OCC is also watching the modernization projects themselves. New cloud infrastructure, API integrations, and digital channel builds introduce their own risks if not managed carefully. Banks that have completed modernization aren’t off the hook—they’re on to the next set of operational risk questions about how the new systems are controlled.
Threat 2: Fraud
The OCC is specific about fraud in Spring 2026: it remains a primary driver of operational losses, and the threat is rising in sophistication.
The mechanism called out is impersonation scams facilitated by social media and text messages. This is distinct from traditional fraud patterns. Credential theft, account takeover via phishing, check kiting—those are technology attacks on systems. Impersonation scams are social engineering attacks on trust. A customer who genuinely believes they’re talking to their bank’s fraud department will hand over authentication credentials they’d never share with a stranger. That’s not a control failure in the traditional sense—it’s a failure of the trust relationship between the institution and its customers.
FinCEN has separately issued alerts on healthcare fraud schemes and money laundering networks, which the OCC cross-references in the Spring 2026 report. The practical implication for risk teams: fraud KRIs can’t only measure transaction-level anomalies. They need to capture customer-reported incidents, call center escalations that signal social engineering attempts, and account activity patterns that follow an impersonation event.
There’s a compliance angle here that often gets underweighted: fraud losses that fall on customers—not the institution—still create regulatory exposure. Inadequate fraud controls that leave customers unprotected can become Regulation E issues when the institution’s response is deficient, or UDAAP exposure when the institution’s claims about security don’t match what customers experience. The OCC is watching both the operational loss and the downstream compliance implications.
Threat 3: Cyber
The Spring 2026 report distinguishes two distinct cyber threat categories: sophisticated cybercriminal groups and foreign state-sponsored actors. Both are described as elevated.
Cybercriminal groups primarily operate through ransomware and business email compromise—attacks that are financially motivated and disruptive. State-sponsored actors represent a broader threat: espionage, data exfiltration, and in some scenarios, pre-positioned access for potential infrastructure disruption. The OCC’s concern about state-sponsored actors reflects a macro-level risk that goes beyond what most institution-level programs are designed to address.
The operational resilience framing ties directly into the cyber risk discussion. Examiners are no longer only asking whether your institution can prevent a cyber incident. They’re asking whether critical services would continue through one. That shift—from prevention to resilience—changes what “adequate” looks like.
For institutions with limited cybersecurity resources, the expectation isn’t proportionality with large-bank infrastructure. It’s proportionality with risk profile, combined with documented resilience planning for realistic scenarios. A business continuity plan that assumes systems come back online in four hours after a ransomware attack—without evidence that assumption has been tested—isn’t adequate resilience planning. Realistic scenarios include longer recovery timelines, partial system availability, and reliance on manual backup procedures.
What “Operational Resilience as a Survival Metric” Means for Your Examination
The practical translation: examiners are increasingly testing for the documentation of resilience, not just the assertion of it.
For capital adequacy, you produce your ratios and stress test results. For operational resilience, the examination is asking for:
- A current-state map of critical business processes and their technology dependencies
- Analysis of single points of failure in those processes
- Recovery time and recovery point objectives that have been tested—not just written down
- Third-party dependency mapping that shows what happens when a critical vendor fails (your vendor’s resilience matters to your resilience)
- A technology modernization plan with a documented timeline for addressing identified vulnerabilities
- KRIs that measure fraud, cyber events, and technology incidents with thresholds that actually trigger escalation
The last item is where most programs fall short. A risk register that lists “legacy technology risk” as an identified risk isn’t the same as a KRI that measures legacy system availability with an amber threshold at 98.5% and a red threshold at 95%, linked to an escalation procedure that goes to the CRO within 24 hours. The OCC is moving toward the latter.
Three Adjustments for Your Risk Program
Map your KRI library against the three flagged areas. If you don’t have KRIs tracking technology incident rates, legacy system availability and patch status, fraud loss ratios by channel, customer-reported impersonation incidents, and mean time to detect and respond to cyber events—you have coverage gaps in the exact areas the OCC’s National Risk Committee just documented. This doesn’t require dozens of new metrics. It requires ensuring that at least one KRI with a meaningful threshold covers each of the three priority areas.
For a deeper look at how the OCC’s examination expectations have evolved—including the new MRA materiality threshold and what the previous unsafe-or-unsound standard meant for operational risk findings—see the breakdown of the OCC and FDIC’s joint final rule defining “unsafe or unsound” practice.
Audit your operational resilience documentation for exam-readiness. The question isn’t whether you have a business continuity plan. It’s whether critical services would actually continue through a realistic disruption, with evidence of testing that supports that claim. Third-party dependency maps that stop at the tier-1 vendor aren’t sufficient—the OCC and FDIC BaaS enforcement record shows that vendor failures cascade in ways that institution-level BCP testing doesn’t always capture.
Document your technology roadmap before the exam asks for it. The Spring 2026 report’s legacy technology language will likely translate into a direct examination ask: show your technology modernization plan. If you’re running on end-of-life infrastructure, the question isn’t whether that generates a finding—it probably does. The question is whether you can demonstrate documented awareness of the risk, a timeline for remediation, and interim controls that manage exposure until the migration is complete. For how FINRA has handled supervisory failures in operational risk contexts, see the FINRA Reg BI enforcement analysis covering the 134-case wave and the supervisory program gaps driving findings.
So What?
The OCC Semiannual Risk Perspective isn’t a regulation. It doesn’t create new requirements. But it’s the clearest public signal of where examiner attention is focused—and the Spring 2026 edition has rotated that attention from credit risk to operational resilience in a way that has program-building implications.
If your risk program is organized around capital ratios, loan quality, and credit concentrations as its primary KRIs, you’re measuring the previous cycle’s priorities. The Spring 2026 report signals the current cycle is about operational resilience, legacy technology, fraud, and cyber. Those need to be on your dashboard with real thresholds—not just in your risk register as acknowledged risks with no measurement infrastructure behind them.
Banks that strengthen risk management, improve operational resilience, and adapt quickly to changing conditions will be best positioned for long-term stability. The examiners writing that sentence are also writing the examination questions.
For a library of 132 pre-built KRIs—including operational, cyber, fraud, vendor, compliance, and BSA/AML metrics with green/amber/red thresholds calibrated for financial services—the KRI Library includes a 23-page guide on setting meaningful escalation triggers and building a reporting cadence your risk committee can actually use.
Sources
- OCC Spring 2026 Semiannual Risk Perspective (full report)
- OCC News Release: Spring 2026 Semiannual Risk Perspective
- Crowe: Takeaways From the OCC’s Semiannual Risk Perspective
- Forbes: Beyond Bank Runs — The OCC Warns of a More Complex Financial Threat
- Young & Associates: Analyzing the OCC’s Spring 2026 Semiannual Risk Perspective for Community Bankers
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What are the key risk themes in the OCC's Spring 2026 Semiannual Risk Perspective?
How does the OCC's Spring 2026 report frame operational resilience?
What specific fraud threats did the OCC flag in Spring 2026?
What does the OCC say about legacy technology risk in Spring 2026?
How is the Spring 2026 risk perspective different from prior OCC reports?
What should compliance and risk teams do after reading the OCC's Spring 2026 risk perspective?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Keep reading
Related posts.
Operational Risk
FDIC Reciprocal Deposits Rule: The New $30 Billion Cap Is Not a Liquidity Free Pass
The FDIC reciprocal deposits rule raises the nonbrokered cap and expands agent-institution eligibility. Here is the treasury control plan.
Aug 29, 2026
Operational Risk
FINRA's Reg BI Enforcement Wave Is Here: 134 Cases, 72% Surge, and the Supervisory Failures Driving Them
FINRA brought 134 Regulation Best Interest enforcement actions in 2026, a 72% increase from 2025. Here's what the care obligation failures actually look like, how the Reid & Rudiger expulsion happened, and what broker-dealer supervisory programs need to fix before the next exam cycle.
Aug 29, 2026
Operational Risk
Tetra Tech’s $57M False Claims Settlement: When Control Evidence Is the Product
The Tetra Tech False Claims Act settlement turns on allegedly falsified soil data. Here is the evidence-integrity control plan.
Aug 25, 2026