Feature Regulatory Compliance
Federal Reserve Stress Test Overhaul: What Risk and Capital Teams Need to Change Now
The Federal Reserve stress test overhaul adds model transparency, two-year averaging, and new supervisory uses. Here is the control impact.
Table of Contents
TL;DR
- The Federal Reserve stress test overhaul is moving toward a Board decision in the coming weeks, according to Vice Chair for Supervision Michelle Bowman—not a distant 2027 project.
- Expected changes include granular model disclosures, public input on scenarios, a two-year average for stress capital buffer calculations, a balance-sheet freeze date, and two global market shocks.
- The bigger operational change is outside the capital formula: the Fed also wants targeted stress exercises to shape supervision of financial and nonfinancial risks.
- CROs, CFOs, model risk teams, and internal audit should build a change-control package now, but label every item previewed, proposed, or final so a speech does not quietly become policy in your documentation.
The Federal Reserve stress test overhaul just moved from proposal-tracking to implementation-readiness.
In a September 18 speech, Vice Chair for Supervision Michelle Bowman said the Board would consider final revisions to its stress testing framework “in the coming weeks.” She described a program with more model transparency, less year-to-year stress capital buffer volatility, two global market shock scenarios, and stress exercises that would influence supervision without directly setting capital.
That is a meaningful package. It is also not yet a final rule.
The distinction matters because policy teams have a bad habit of turning a senior official’s preview into a requirements memo, then spending months unwinding assumptions after the actual release lands. The right move is to prepare the operating machinery now—owners, data lineage, reproducibility, challenge records, and implementation gates—without pretending the Board has voted.
What the Federal Reserve stress test overhaul would change
Bowman’s speech connects several workstreams that have been moving separately. The Fed proposed two-year averaging in April 2025 and proposed broader model and scenario transparency in October 2025. In February 2026, the Board kept current stress-test-related capital requirements in place while it considered public feedback.
The September speech previews how those pieces may fit together.
| Previewed change | What Bowman described | Immediate control impact |
|---|---|---|
| Model transparency | Publication of equations, variables, coefficients, assumptions, limitations, decision rationale, alternatives, and planned 2027 model changes | Model Risk Management should create a formal intake, comparison, and challenge process for each disclosure |
| Scenario transparency | Expanded guides for macroeconomic variables and more detail on the global market shock and scenario construction | Scenario governance needs version control and documented decisions about which Fed assumptions are adopted, adapted, or rejected internally |
| Two-year SCB averaging | Use of the two most recent annual test results to reduce volatility | Capital Planning should reproduce the calculation and explain year-one/year-two contributions to management and the board |
| Later effective date | Shift of the annual SCB effective date from October 1 to January 1 | Finance, Treasury, and regulatory reporting calendars need a coordinated implementation date |
| Balance-sheet freeze date | A specified snapshot date before proposed scenarios are released | Data Governance must prove the population used for testing is complete, controlled, and reproducible as of the freeze date |
| Two global market shocks | Run two shocks on the same as-of date and use the larger loss in the SCB calculation | Trading and counterparty teams need dual-scenario lineage, comparison logic, and exception review |
| Revised noninterest-income model | A separate proposal for the 2027 test to better capture business diversity | Owners of wealth, investment banking, trading, and fee-income data need to validate segmentation and mapping |
| Supervisory stress exercises | Targeted tests for firm-specific financial and nonfinancial vulnerabilities, without direct capital effects | Enterprise Risk must connect scenario findings to issues, risk appetite, resilience plans, and supervisory response |
American Banker’s September 18 coverage highlights the two newest mechanics: the balance-sheet freeze and the use of two global market shocks. Those details matter because they change the evidence burden. A model output is not defensible if the bank cannot recreate the input population or explain why one shock—not the other—drove the binding result.
Transparency creates more work, not less
Model disclosure sounds like relief for banks that have criticized the test as opaque. It should make outcomes easier to analyze. It will also give examiners, internal audit, investors, and boards a sharper benchmark against which to challenge a bank’s own models.
Once the Fed publishes equations, assumptions, limitations, and model-change rationales, “our internal approach is different” stops being an answer. The team will need to show:
- A documented comparison. Which Fed variables and relationships have internal analogues? Where does the bank use a different segmentation, horizon, or loss function?
- A reason for every difference. The rationale should point to portfolio composition, internal loss history, product design, or another evidenced factor—not preference.
- Independent challenge. Model Risk Management should record whether the difference is reasonable, conservative, and supported by validation results.
- A disposition. Adopt, adapt, monitor, or reject the Fed methodology, with a named owner and approval date.
- Board-ready translation. Directors need the capital and risk consequence of a methodological difference, not a 70-page coefficient comparison.
A practical artifact is a Fed-to-internal model delta register. Give each difference an ID; identify the affected portfolio, variable, assumption, owner, validation evidence, estimated capital sensitivity, decision, and next review date. That register should link to—not replace—the model inventory and model-change log.
This is where ownership gets messy. Finance may own the capital number, Model Risk may own independent validation, and the business may own the source data. The CRO should designate one accountable executive for the end-to-end reconciliation. Three contributing owners are not the same thing as one accountable owner.
Two-year averaging changes the questions the board should ask
Averaging two annual results may reduce volatility, but it can also make deterioration less visually obvious. A strong prior year can soften the apparent effect of a weak current year.
The board package therefore needs more than the averaged SCB result. It should show:
| Board view | Why it belongs in the package |
|---|---|
| Current-year standalone result | Prevents the average from obscuring fresh deterioration |
| Prior-year standalone result | Shows the second input and any restatements |
| Two-year average | Connects directly to the expected regulatory calculation |
| Driver bridge | Explains movement from portfolio, scenario, model, and data changes |
| Sensitivity range | Shows the result without averaging and under reasonable alternative assumptions |
| Management action triggers | Identifies what would cause capital conservation, balance-sheet changes, or risk reduction |
Do not create unsupported “safe” trigger levels just to complete the dashboard. A workable starting point is to calibrate escalation against the bank’s board-approved capital plan, internal buffers, recovery options, and the last several test cycles. Then back-test whether those triggers would have prompted action early enough under prior adverse outcomes.
The existing RiskTemplates breakdown of the 2026 DFAST results and internal capital planning provides the scenario side of that analysis. The new work is the governance bridge between individual annual results and the expected averaged regulatory result.
The supervisory use of stress testing may be the bigger change
The capital formula will get the headlines. The supervisory expansion deserves the CRO’s attention.
Bowman described future exercises aimed at firm-specific financial and nonfinancial vulnerabilities. The results would not directly change capital requirements. Instead, they would help supervisors understand exposures and resilience.
That creates a different kind of risk. A noncapital exercise can still produce supervisory questions, observations, remediation commitments, or pressure to improve controls. Banks should not treat “no direct capital impact” as “no consequence.”
A credible scenario package should connect five artifacts:
- Risk identification: the risk taxonomy entry and rationale for materiality;
- Scenario design: assumptions, transmission channels, severity, and limitations;
- Control response: preventive, detective, and recovery controls tested by the scenario;
- Decision protocol: named executives, escalation thresholds, and available management actions;
- Issue disposition: gaps logged with owners, dates, evidence requirements, and independent closure validation.
For nonfinancial risk, a realistic hypothetical might combine a critical cloud outage with delayed recovery of a high-volume payments service and a third-party data-integrity problem. The useful output is not a dramatic loss estimate alone. It is whether Operations can invoke the recovery plan, whether Finance can estimate exposure, whether Compliance can identify notification obligations, and whether the incident commander has authority to stop affected transactions.
The method in Stress Testing KRIs: How to Turn Scenario Results Into Board-Level Triggers is useful here: convert scenario breakpoints into monitored indicators and explicit actions. Label any example threshold as a starting point and calibrate it against internal history and risk appetite.
A 30-day readiness plan for capital and risk teams
Days 1–5: establish the rule-status ledger
Owner: Regulatory Change Management
Create one row for each expected change. Record the primary source, status, affected regulation or process, open interpretation questions, accountable executive, and next decision date. Use three status values only: previewed, proposed, and final.
Evidence: dated ledger, Legal review comments, and links to the underlying Fed material.
Days 6–10: run a model and data gap assessment
Owners: Model Risk Management and Data Governance
Inventory every stress-testing model, feeder system, manual adjustment, and end-user computing tool. Test whether the team can reproduce the input population as of a historical date. If a balance-sheet freeze were declared tomorrow, could the bank prove which records were included and which late adjustments were made?
Evidence: source-to-model lineage, reconciliation results, exception log, and approvals for manual overlays.
Days 11–15: dry-run two-year averaging
Owner: Capital Planning
Recalculate the SCB using the two most recent annual results, then bridge it to each standalone year. The point is not to predict the final requirement. It is to expose data-definition conflicts, restatement questions, and board-reporting gaps before the final rule creates a deadline.
Evidence: calculation workbook, independent review sign-off, and documented treatment of restatements.
Days 16–20: test dual market-shock governance
Owners: Market Risk and Counterparty Credit Risk
Run two internally approved global market shocks using the same controlled snapshot. Document scenario differences, loss attribution, the logic selecting the larger result, and any portfolios that behave unexpectedly.
Evidence: scenario specifications, run logs, loss bridge, and challenge minutes.
Days 21–25: build the supervisory-scenario workflow
Owner: Enterprise Risk
Select one material nonfinancial risk and walk it from risk identification through scenario result, management action, and issue creation. Do not start with the most complicated cyber scenario. Start with one where data and ownership are mature enough to test the workflow honestly.
Evidence: scenario memo, participant list, decision log, issue records, and after-action review.
Days 26–30: brief the board risk committee
Owners: CRO and CFO
Present what is known, what remains proposed, the bank’s readiness gaps, and which decisions wait for final Board action. Include the current-year result next to the two-year average so smoothing does not bury the signal.
Evidence: board materials, minutes, challenges raised, and assigned follow-ups.
The practical takeaway
The Federal Reserve stress test overhaul is not simply a new calculation. It is a governance test: can the bank reproduce its data, explain model differences, preserve current-year risk signals, and turn scenario findings into owned remediation?
Start with the delta register and historical data snapshot. Those artifacts are useful even if the final language changes.
For teams formalizing ownership, escalation, and board reporting across this work, the Enterprise Risk Management Framework provides the governance structure to assign the decisions and preserve the evidence.
◆ Related template
Enterprise Risk Management Framework (ERMF)
Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Has the Federal Reserve finalized the stress test overhaul?
How would two-year averaging change the stress capital buffer?
What would the Federal Reserve disclose about its stress test models?
Will stress tests be used for more than capital requirements?
What should banks do before the final Federal Reserve stress test rules are published?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Enterprise Risk Management Framework (ERMF)
Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.
◆ Keep reading
Related posts.
Regulatory Compliance
The SEC's Securities Lending Reporting Deadline Is Nine Days Away. Here's What Your Firm Still Needs to Build.
SEC Rule 10c-1a requires broker-dealers, agent lenders, and custodian banks to report securities lending transactions to FINRA SLATE by September 28, 2026. Here is what covered persons must have in place before the deadline.
Sep 19, 2026
Regulatory Compliance
FinCEN Just Said Mobile Driver's Licenses Are Valid for KYC. Your CIP Probably Doesn't Allow It Yet.
On September 8, 2026, FinCEN and the federal banking agencies issued FAQs clarifying that state-issued mobile driver's licenses and other verifiable digital credentials can satisfy CIP documentary identification requirements — with three specific conditions your program needs to meet first.
Sep 18, 2026
Regulatory Compliance
FINRA Rule 3290 Approved: Rebuild Your Outside Activities Program Before the Effective Date
FINRA Rule 3290 is approved. See what changes for outside activities, private securities transactions, supervision, records, and implementation.
Sep 17, 2026