Feature Regulatory Compliance
FDIC Just Proposed Faster Bank Merger Reviews. Here's What Community Banks, Sponsor Banks, and Their Fintech Partners Need to Know.
The FDIC's September 17, 2026 proposed rule would cut bank merger review to as little as five business days for small deals and create a predictable 90-day track for standard transactions. Here's what state nonmember banks — and the fintechs that partner with them — need to understand before the 60-day comment window closes.
Table of Contents
TL;DR
- FDIC proposed to modernize bank merger review on September 17, 2026 — covering approximately 2,700 state nonmember banks
- New tracks range from five-business-day de minimis processing to a 270-day maximum for complex deals
- A 25% asset-growth prior-notice requirement applies to transactions with the same counterparty in a rolling 12-month window
- 60-day comment period; state nonmember banks, fintechs with bank partnerships, and BaaS programs should assess how the new framework changes strategic options
Bank mergers have been politically contested for years. The Biden administration’s 2023 merger policy made scrutiny more intensive and community bank M&A slower. The FDIC’s September 17, 2026 proposed rule marks the reversal: a risk-based, tiered processing framework designed to make mergers faster, more predictable, and calibrated to actual transaction risk rather than applying the same heavy-review process across all sizes and structures.
For the roughly 2,700 state nonmember banks under FDIC merger authority, this matters strategically. For the fintechs and BaaS programs that bank with those institutions, it matters operationally.
Why the Current Framework Is Being Reformed
The Bank Merger Act gives the FDIC authority to approve or deny mergers involving state nonmember banks. Under the current framework, that process has been criticized as slow, unpredictable, and inconsistently calibrated to the actual risk a given merger presents.
A community bank acquiring a tiny rural branch has historically faced many of the same procedural requirements as a large regional bank acquiring a direct competitor. The Biden administration’s 2023 Policy Statement on Bank Mergers added community reinvestment, financial stability, and competitive factors to the review calculus in ways that extended timelines and reduced predictability. The net effect was a slowdown in community bank consolidation at a moment when many small banks were under pressure from technology investments, staffing costs, and margin compression.
The FDIC’s proposed rule takes a different position: that merger review burden should match merger risk, not apply uniformly. FDIC Chairman Travis Hill, in his statement accompanying the proposal, framed it as reducing outdated provisions and creating a framework where review resources are concentrated on transactions that actually warrant intensive analysis.
The New Processing Tracks
The proposed rule establishes distinct processing categories based on transaction size and risk:
De Minimis Pipeline — as little as five business days. The fastest track covers acquisitions of extremely small targets or certain types of operating subsidiaries. For community banks making small, low-risk acquisitions — a tiny branch, a subsidiary that’s already operating as part of the bank’s business — the five-business-day window would make these transactions effectively administrative rather than strategic delays. This is a significant change: under the current framework, even small deals involve months-long review.
Prior Notice + Non-Objection — 30 days ordinarily, 90-day maximum. The proposal introduces a prior notice requirement for transactions that would increase a bank’s total assets by 25% or more over a rolling 12-month period when dealing with the same counterparty or its affiliates. The institution submits a notice; the FDIC issues non-objection, ordinarily within 30 days. This creates a structured early-warning mechanism for significant growth transactions without the full approval process.
Standard Review — 90 days, extensible to 180 days, 270-day maximum. Standard merger applications would carry a 90-day review period, extensible to 180 days for complex transactions and subject to a 270-day absolute maximum. For community banks, the 90-day timeline represents predictability — you know the outer bound before you structure the deal. Previously, extended review periods created strategic uncertainty that complicated transaction negotiations.
| Processing Track | Timeline | Scope |
|---|---|---|
| De Minimis | 5 business days | Very small targets; operating subsidiary acquisitions |
| Prior Notice | 30 days (max 90) | Transactions increasing assets 25%+ from same counterparty |
| Standard | 90 days (max 270) | All other Bank Merger Act applications |
What Changes for Community Banks
For community banks that are FDIC-supervised state nonmember banks, the proposed framework changes the strategic calculus for M&A in three ways.
Faster timelines for small deals. Community banks pursuing small acquisitions — a nearby independent bank, a branch book, a specialty subsidiary — would face a dramatically compressed process for the smallest transactions. Banks that have held off on low-complexity acquisitions because of review uncertainty have a clearer picture of what the process looks like.
Predictability for planning. The 90-day standard review window with a hard 270-day maximum gives deal teams a planning envelope. Under the prior framework, the lack of clear timelines made it difficult to structure financing, negotiate earnouts, or commit to integration timelines before regulatory approval was in hand. Defined ceilings reduce that uncertainty.
A clearer 25% growth threshold. The prior notice requirement for transactions that grow the bank by 25%+ with the same counterparty is new. Community banks considering a structured acquisition series — buying multiple related entities from the same seller — need to track whether the cumulative size increase crosses the threshold. The 30-day non-objection window is faster than a full approval process, but it adds a step that needs to be planned for.
The BaaS and Fintech Partnership Dimension
For banking-as-a-service programs and their fintech partners, bank M&A creates compliance complications that are easy to underestimate.
When a sponsor bank is acquired, the partnership agreement governing the fintech program doesn’t automatically transfer on identical terms. Change-of-control provisions, assignment rights, and consent requirements vary across agreements. Fintechs that haven’t read their partnership agreement’s M&A provisions recently should do so now — understanding what happens to the program in an acquisition is a due diligence question, not just a legal one.
Seven BaaS consent orders between 2022 and 2025 demonstrated that regulatory liability in bank-fintech programs follows the bank charter, not the partnership contract. When a bank with a fintech-driven compliance problem is acquired, the acquiring bank inherits the regulatory relationship. Examiners of the acquiring institution will ask about the inherited fintech programs, the compliance posture of each, and whether the acquiring bank conducted adequate due diligence before closing.
For fintechs, this means your bank partner’s acquisition is a trigger for your own internal risk assessment: does the acquiring institution’s risk appetite, compliance infrastructure, and operating model align with your program’s requirements? That assessment needs to be documented — your regulators and any future bank partners will want to see that you evaluated the change actively rather than treating it as a pass-through.
The 25% prior-notice growth threshold in the proposed rule is also worth monitoring for rapidly growing BaaS programs. If your bank partner’s balance sheet is growing significantly through fintech deposits and the bank enters into a transaction that, combined with prior fintech-related transactions, crosses the 25% threshold with the same counterparty, the prior notice process activates. Knowing that threshold exists — and monitoring whether your program’s growth trajectory would be material to it — is part of TPRM for fintech companies partnered with state nonmember banks.
The Broader Deregulatory Context
This proposed rule is one of several overlapping regulatory reforms under the current administration that affect FDIC-supervised community banks. The OCC and FDIC’s August 27 final rule defining “unsafe or unsound practice” for the first time in 70 years takes effect November 2, 2026, reshaping how MRAs and supervisory actions are issued. The combination of more predictable merger timelines and a higher threshold for enforcement action represents a significant shift in the operating environment for community banks.
That context matters for fintech partners evaluating bank relationships. A bank operating under the current enforcement environment — one that may face a new MRA standard effective November 2 — is a different counterparty than the same bank operating under the prior framework. Banks that were previously facing open enforcement actions may resolve them faster; banks that would have received MRAs under prior standards may not under the new materiality threshold.
Understanding your bank partner’s regulatory posture — their pending MRAs, their examination history, their risk profile — is more important in a shifting framework than in a stable one. OCC fintech charter denials in 2026 underscore that regulatory posture and AML program quality remain central to any bank’s ability to serve fintech partners at scale.
The Comment Deadline
The FDIC’s proposed rule carries a 60-day comment period. State nonmember banks, trade associations representing community banks, and fintech companies with bank partnerships should review the proposal’s specific provisions on the 25% prior notice threshold, the de minimis pipeline criteria, and the standard review timeline. If the current thresholds don’t match the risk calibration your institution operates under, the comment period is the structured mechanism for raising that.
So What?
The FDIC’s proposed merger reform is straightforwardly a deregulatory signal for community bank M&A. For banks that have held off on strategic acquisitions because of regulatory uncertainty, the new framework offers more predictability and faster processing for low-risk transactions.
For fintech compliance teams, the more immediate question is what this means for your existing bank partner. A faster, more predictable merger framework means community banks under M&A pressure — margin compression, technology investment requirements, geographic concentration — are more likely to pursue strategic transactions. Your bank partner may be an acquirer or a target. Either scenario creates program review obligations on your side.
Track the 25% prior notice threshold as you monitor your bank partner’s balance sheet trajectory. Review your partnership agreement’s change-of-control provisions before any M&A rumor becomes relevant. Document your evaluation of any material change to your bank partner’s structure — your own examiners will ask whether you monitored it.
The comment period closes 60 days after publication. The effective date of any final rule will follow. The strategic implications for community bank M&A and BaaS programs are already worth evaluating now.
Sources:
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Enterprise Risk Management Framework (ERMF)
Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the FDIC propose on September 17, 2026?
Which banks does the FDIC's merger authority cover?
What is the 25% prior notice requirement?
What does the de minimis processing track cover?
When is the comment deadline?
What should fintech compliance teams do when their bank partner is acquired?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Enterprise Risk Management Framework (ERMF)
Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.
◆ Keep reading
Related posts.
Regulatory Compliance
Nodus Bank CEO Sentenced: The Control Failures Behind a $24.9M Fraud and Sanctions Scheme
The Nodus Bank fraud mixed insider self-dealing with sanctions evasion. Here are the controls bank boards and compliance teams should test now.
Sep 21, 2026
Regulatory Compliance
Vitol Trader Sentenced in FCPA Bribery Scheme: The Payment Controls That Failed
The Vitol bribery scheme used sham invoices, shell companies, and alias email. Here is how compliance teams should test anti-bribery payment controls.
Sep 21, 2026
Regulatory Compliance
The BSA's Biggest Overhaul in Decades Just Cleared Its Last Comment Deadline. Here's What the FinCEN Program Reform NPRM Actually Changes.
FinCEN's April 2026 NPRM to fundamentally reform AML/CFT programs — combined with the Federal Reserve's companion rulemaking, whose comment period just closed September 8 — is the most significant BSA update since the PATRIOT Act. Here's what effectiveness-based evaluation means for your compliance program.
Sep 20, 2026