Skip to content
RiskTemplates · The Daily Brief Wednesday, September 2, 2026
Wire Lugano Diamonds SEC Fraud Case: How $1B in Alleged Fake Revenue Beat the Control Stack SEP 1

Feature Operational Risk

The OCC's Spring 2026 Risk Perspective Named Three Operational Threats. Here's What Your Program Needs to Fix.

The OCC's Spring 2026 Semiannual Risk Perspective shifted focus from credit risk to operational resilience—flagging legacy technology, rising fraud, and sophisticated cyber threats as the top concerns. Here's what that means for your risk program.

By Rebecca Leung · August 31, 2026 ·
Table of Contents

TL;DR

  • The OCC’s Spring 2026 Semiannual Risk Perspective describes balance sheets as “strong” and credit risk as “manageable”—the focus has shifted to operational risk
  • Three specific threats: legacy technology and end-of-life infrastructure; rising fraud driven by sophisticated impersonation scams; and elevated cyber threats from criminal groups and foreign state-sponsored actors
  • The OCC frames operational resilience—not capital strength—as the key determinant of which institutions prove durable in the next stress cycle
  • For most risk programs, this is a gap: capital and credit KRIs are mature, but operational resilience metrics often lack meaningful thresholds

The OCC Semiannual Risk Perspective is one of the clearest public signals of where examiner attention is heading. Not because it reveals anything examiners don’t already know—they wrote it. But because it tells you which conversations will dominate your next exam cycle.

The Spring 2026 edition made something explicit that practitioners have been sensing for a while: the credit risk moment has passed. Bank earnings improved in 2025 supported by loan growth and declining funding costs. Balance sheets remain strong, with capital ratios and liquidity high by historical standards. Credit risk within the federal banking system is described as manageable.

What’s elevated now is operational risk. Specifically: three threats the OCC’s National Risk Committee identified as elevated and interconnected—legacy technology vulnerabilities, rising fraud, and sophisticated cyber threats. If those aren’t showing up on your risk dashboard with real KRIs and real thresholds, you’re measuring the previous exam cycle.


Why the Focus Shifted to Operational Risk

The Spring 2026 report introduces a framing that hasn’t appeared this explicitly in prior editions: operational resilience—not just capital strength—may determine which institutions prove durable in the next phase of banking stress.

That’s a significant statement. For decades, bank supervision organized itself around capital adequacy as the primary health metric. The question was whether an institution could absorb losses. The Spring 2026 framing introduces a parallel question: can the institution continue to deliver critical services through disruption?

Those questions require different answers—and different risk programs. A bank with strong capital ratios but brittle operational infrastructure has a vulnerability profile that traditional capital metrics don’t capture. An institution running core functions on end-of-life systems, with fraud monitoring that can’t keep pace with social engineering attacks, is exposed in ways that a Tier 1 capital ratio won’t reveal.

The OCC is signaling that examinations are increasingly testing for the latter.


Threat 1: Legacy Technology

The Spring 2026 report identifies outdated legacy systems and end-of-life infrastructure as material operational risk vulnerabilities. That phrasing—material—is examiner language. It’s the difference between a risk that’s logged and a risk that’s examined.

The tension the OCC is flagging: technology modernization is both necessary and itself a source of risk. Every major system migration or cloud conversion introduces operational, compliance, and cybersecurity exposure during the transition. Banks that defer modernization accumulate infrastructure risk. Banks that rush modernization accumulate implementation risk. Neither is a clean answer.

What examiners are now asking for isn’t just a current-state inventory of where legacy technology sits. It’s a roadmap—documented milestones, resource allocation, and risk mitigation controls for the transition period itself. Saying “we know the core system is end-of-life” is insufficient without a credible plan for what comes next and when.

For community banks and smaller fintechs, this often means the core banking platform that’s been in production for 15-20 years, running on vendor support that’s thinning out. The OCC’s concern isn’t abstract—it’s about the specific operational risk created when institutional knowledge of how a system works is concentrated in two people who are retirement-eligible, the vendor’s support roadmap ends in 36 months, and there’s no documented migration plan with assigned owners.

One thing to note from the Spring 2026 framing: the OCC is also watching the modernization projects themselves. New cloud infrastructure, API integrations, and digital channel builds introduce their own risks if not managed carefully. Banks that have completed modernization aren’t off the hook—they’re on to the next set of operational risk questions about how the new systems are controlled.


Threat 2: Fraud

The OCC is specific about fraud in Spring 2026: it remains a primary driver of operational losses, and the threat is rising in sophistication.

The mechanism called out is impersonation scams facilitated by social media and text messages. This is distinct from traditional fraud patterns. Credential theft, account takeover via phishing, check kiting—those are technology attacks on systems. Impersonation scams are social engineering attacks on trust. A customer who genuinely believes they’re talking to their bank’s fraud department will hand over authentication credentials they’d never share with a stranger. That’s not a control failure in the traditional sense—it’s a failure of the trust relationship between the institution and its customers.

FinCEN has separately issued alerts on healthcare fraud schemes and money laundering networks, which the OCC cross-references in the Spring 2026 report. The practical implication for risk teams: fraud KRIs can’t only measure transaction-level anomalies. They need to capture customer-reported incidents, call center escalations that signal social engineering attempts, and account activity patterns that follow an impersonation event.

There’s a compliance angle here that often gets underweighted: fraud losses that fall on customers—not the institution—still create regulatory exposure. Inadequate fraud controls that leave customers unprotected can become Regulation E issues when the institution’s response is deficient, or UDAAP exposure when the institution’s claims about security don’t match what customers experience. The OCC is watching both the operational loss and the downstream compliance implications.


Threat 3: Cyber

The Spring 2026 report distinguishes two distinct cyber threat categories: sophisticated cybercriminal groups and foreign state-sponsored actors. Both are described as elevated.

Cybercriminal groups primarily operate through ransomware and business email compromise—attacks that are financially motivated and disruptive. State-sponsored actors represent a broader threat: espionage, data exfiltration, and in some scenarios, pre-positioned access for potential infrastructure disruption. The OCC’s concern about state-sponsored actors reflects a macro-level risk that goes beyond what most institution-level programs are designed to address.

The operational resilience framing ties directly into the cyber risk discussion. Examiners are no longer only asking whether your institution can prevent a cyber incident. They’re asking whether critical services would continue through one. That shift—from prevention to resilience—changes what “adequate” looks like.

For institutions with limited cybersecurity resources, the expectation isn’t proportionality with large-bank infrastructure. It’s proportionality with risk profile, combined with documented resilience planning for realistic scenarios. A business continuity plan that assumes systems come back online in four hours after a ransomware attack—without evidence that assumption has been tested—isn’t adequate resilience planning. Realistic scenarios include longer recovery timelines, partial system availability, and reliance on manual backup procedures.


What “Operational Resilience as a Survival Metric” Means for Your Examination

The practical translation: examiners are increasingly testing for the documentation of resilience, not just the assertion of it.

For capital adequacy, you produce your ratios and stress test results. For operational resilience, the examination is asking for:

  • A current-state map of critical business processes and their technology dependencies
  • Analysis of single points of failure in those processes
  • Recovery time and recovery point objectives that have been tested—not just written down
  • Third-party dependency mapping that shows what happens when a critical vendor fails (your vendor’s resilience matters to your resilience)
  • A technology modernization plan with a documented timeline for addressing identified vulnerabilities
  • KRIs that measure fraud, cyber events, and technology incidents with thresholds that actually trigger escalation

The last item is where most programs fall short. A risk register that lists “legacy technology risk” as an identified risk isn’t the same as a KRI that measures legacy system availability with an amber threshold at 98.5% and a red threshold at 95%, linked to an escalation procedure that goes to the CRO within 24 hours. The OCC is moving toward the latter.


Three Adjustments for Your Risk Program

Map your KRI library against the three flagged areas. If you don’t have KRIs tracking technology incident rates, legacy system availability and patch status, fraud loss ratios by channel, customer-reported impersonation incidents, and mean time to detect and respond to cyber events—you have coverage gaps in the exact areas the OCC’s National Risk Committee just documented. This doesn’t require dozens of new metrics. It requires ensuring that at least one KRI with a meaningful threshold covers each of the three priority areas.

For a deeper look at how the OCC’s examination expectations have evolved—including the new MRA materiality threshold and what the previous unsafe-or-unsound standard meant for operational risk findings—see the breakdown of the OCC and FDIC’s joint final rule defining “unsafe or unsound” practice.

Audit your operational resilience documentation for exam-readiness. The question isn’t whether you have a business continuity plan. It’s whether critical services would actually continue through a realistic disruption, with evidence of testing that supports that claim. Third-party dependency maps that stop at the tier-1 vendor aren’t sufficient—the OCC and FDIC BaaS enforcement record shows that vendor failures cascade in ways that institution-level BCP testing doesn’t always capture.

Document your technology roadmap before the exam asks for it. The Spring 2026 report’s legacy technology language will likely translate into a direct examination ask: show your technology modernization plan. If you’re running on end-of-life infrastructure, the question isn’t whether that generates a finding—it probably does. The question is whether you can demonstrate documented awareness of the risk, a timeline for remediation, and interim controls that manage exposure until the migration is complete. For how FINRA has handled supervisory failures in operational risk contexts, see the FINRA Reg BI enforcement analysis covering the 134-case wave and the supervisory program gaps driving findings.


So What?

The OCC Semiannual Risk Perspective isn’t a regulation. It doesn’t create new requirements. But it’s the clearest public signal of where examiner attention is focused—and the Spring 2026 edition has rotated that attention from credit risk to operational resilience in a way that has program-building implications.

If your risk program is organized around capital ratios, loan quality, and credit concentrations as its primary KRIs, you’re measuring the previous cycle’s priorities. The Spring 2026 report signals the current cycle is about operational resilience, legacy technology, fraud, and cyber. Those need to be on your dashboard with real thresholds—not just in your risk register as acknowledged risks with no measurement infrastructure behind them.

Banks that strengthen risk management, improve operational resilience, and adapt quickly to changing conditions will be best positioned for long-term stability. The examiners writing that sentence are also writing the examination questions.


For a library of 132 pre-built KRIs—including operational, cyber, fraud, vendor, compliance, and BSA/AML metrics with green/amber/red thresholds calibrated for financial services—the KRI Library includes a 23-page guide on setting meaningful escalation triggers and building a reporting cadence your risk committee can actually use.


Sources

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What are the key risk themes in the OCC's Spring 2026 Semiannual Risk Perspective?
The OCC identified four key risk themes: credit, market, operational, and compliance risk. On the operational side, the report specifically flagged legacy technology vulnerabilities, rising fraud and impersonation scams, and sophisticated cyber threats from criminal groups and foreign state-sponsored actors. Credit risk is described as manageable, with balance sheets strong—the emphasis has shifted toward operational resilience.
How does the OCC's Spring 2026 report frame operational resilience?
The Spring 2026 report frames operational resilience—not just capital strength—as the key determinant of long-term institutional durability. The OCC's position is that an institution's ability to deliver critical services through disruption, not merely to absorb losses, is what determines survival in the next phase of banking stress. That's a meaningful shift from prior capital-focused supervisory framing.
What specific fraud threats did the OCC flag in Spring 2026?
The OCC identified fraud as a primary driver of operational losses, with impersonation scams facilitated by social media and text messages rising in sophistication. FinCEN has separately issued alerts on healthcare fraud schemes and money laundering networks, which the report cross-references. The concern spans both customer-facing fraud and internal operational losses.
What does the OCC say about legacy technology risk in Spring 2026?
The OCC identified outdated legacy systems and end-of-life infrastructure as material operational risk vulnerabilities. Technology modernization is framed as both a risk mitigation necessity and a source of new operational, compliance, and cybersecurity risk during the transition itself. Examiners are increasingly asking about technology modernization roadmaps, not just current-state inventories.
How is the Spring 2026 risk perspective different from prior OCC reports?
Prior OCC risk perspectives focused heavily on credit and liquidity risk in the post-SVB environment. Spring 2026 shifts that: balance sheets are described as strong and credit risk as manageable. The new emphasis is operational risk—legacy technology, fraud, and cyber—and the report introduces the framing that operational resilience may now determine which institutions prove durable in the next stress cycle.
What should compliance and risk teams do after reading the OCC's Spring 2026 risk perspective?
Three immediate actions: (1) map your KRI library against the three flagged areas—legacy technology, fraud, and cyber—and verify you have amber/red thresholds that trigger real escalation; (2) test your operational resilience documentation against realistic disruption scenarios, not just tabletop exercises; and (3) document your technology modernization roadmap so examiners see a plan, not just a current-state problem.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

KRI Library (132 Key Risk Indicators)

132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.