Skip to content
RiskTemplates · The Daily Brief Monday, September 21, 2026
Wire Nodus Bank CEO Sentenced: The Control Failures Behind a $24.9M Fraud and Sanctions Scheme SEP 20

Feature Regulatory Compliance

FDIC Just Proposed Faster Bank Merger Reviews. Here's What Community Banks, Sponsor Banks, and Their Fintech Partners Need to Know.

The FDIC's September 17, 2026 proposed rule would cut bank merger review to as little as five business days for small deals and create a predictable 90-day track for standard transactions. Here's what state nonmember banks — and the fintechs that partner with them — need to understand before the 60-day comment window closes.

By Rebecca Leung · September 21, 2026 ·
Table of Contents

TL;DR

  • FDIC proposed to modernize bank merger review on September 17, 2026 — covering approximately 2,700 state nonmember banks
  • New tracks range from five-business-day de minimis processing to a 270-day maximum for complex deals
  • A 25% asset-growth prior-notice requirement applies to transactions with the same counterparty in a rolling 12-month window
  • 60-day comment period; state nonmember banks, fintechs with bank partnerships, and BaaS programs should assess how the new framework changes strategic options

Bank mergers have been politically contested for years. The Biden administration’s 2023 merger policy made scrutiny more intensive and community bank M&A slower. The FDIC’s September 17, 2026 proposed rule marks the reversal: a risk-based, tiered processing framework designed to make mergers faster, more predictable, and calibrated to actual transaction risk rather than applying the same heavy-review process across all sizes and structures.

For the roughly 2,700 state nonmember banks under FDIC merger authority, this matters strategically. For the fintechs and BaaS programs that bank with those institutions, it matters operationally.

Why the Current Framework Is Being Reformed

The Bank Merger Act gives the FDIC authority to approve or deny mergers involving state nonmember banks. Under the current framework, that process has been criticized as slow, unpredictable, and inconsistently calibrated to the actual risk a given merger presents.

A community bank acquiring a tiny rural branch has historically faced many of the same procedural requirements as a large regional bank acquiring a direct competitor. The Biden administration’s 2023 Policy Statement on Bank Mergers added community reinvestment, financial stability, and competitive factors to the review calculus in ways that extended timelines and reduced predictability. The net effect was a slowdown in community bank consolidation at a moment when many small banks were under pressure from technology investments, staffing costs, and margin compression.

The FDIC’s proposed rule takes a different position: that merger review burden should match merger risk, not apply uniformly. FDIC Chairman Travis Hill, in his statement accompanying the proposal, framed it as reducing outdated provisions and creating a framework where review resources are concentrated on transactions that actually warrant intensive analysis.

The New Processing Tracks

The proposed rule establishes distinct processing categories based on transaction size and risk:

De Minimis Pipeline — as little as five business days. The fastest track covers acquisitions of extremely small targets or certain types of operating subsidiaries. For community banks making small, low-risk acquisitions — a tiny branch, a subsidiary that’s already operating as part of the bank’s business — the five-business-day window would make these transactions effectively administrative rather than strategic delays. This is a significant change: under the current framework, even small deals involve months-long review.

Prior Notice + Non-Objection — 30 days ordinarily, 90-day maximum. The proposal introduces a prior notice requirement for transactions that would increase a bank’s total assets by 25% or more over a rolling 12-month period when dealing with the same counterparty or its affiliates. The institution submits a notice; the FDIC issues non-objection, ordinarily within 30 days. This creates a structured early-warning mechanism for significant growth transactions without the full approval process.

Standard Review — 90 days, extensible to 180 days, 270-day maximum. Standard merger applications would carry a 90-day review period, extensible to 180 days for complex transactions and subject to a 270-day absolute maximum. For community banks, the 90-day timeline represents predictability — you know the outer bound before you structure the deal. Previously, extended review periods created strategic uncertainty that complicated transaction negotiations.

Processing TrackTimelineScope
De Minimis5 business daysVery small targets; operating subsidiary acquisitions
Prior Notice30 days (max 90)Transactions increasing assets 25%+ from same counterparty
Standard90 days (max 270)All other Bank Merger Act applications

What Changes for Community Banks

For community banks that are FDIC-supervised state nonmember banks, the proposed framework changes the strategic calculus for M&A in three ways.

Faster timelines for small deals. Community banks pursuing small acquisitions — a nearby independent bank, a branch book, a specialty subsidiary — would face a dramatically compressed process for the smallest transactions. Banks that have held off on low-complexity acquisitions because of review uncertainty have a clearer picture of what the process looks like.

Predictability for planning. The 90-day standard review window with a hard 270-day maximum gives deal teams a planning envelope. Under the prior framework, the lack of clear timelines made it difficult to structure financing, negotiate earnouts, or commit to integration timelines before regulatory approval was in hand. Defined ceilings reduce that uncertainty.

A clearer 25% growth threshold. The prior notice requirement for transactions that grow the bank by 25%+ with the same counterparty is new. Community banks considering a structured acquisition series — buying multiple related entities from the same seller — need to track whether the cumulative size increase crosses the threshold. The 30-day non-objection window is faster than a full approval process, but it adds a step that needs to be planned for.

The BaaS and Fintech Partnership Dimension

For banking-as-a-service programs and their fintech partners, bank M&A creates compliance complications that are easy to underestimate.

When a sponsor bank is acquired, the partnership agreement governing the fintech program doesn’t automatically transfer on identical terms. Change-of-control provisions, assignment rights, and consent requirements vary across agreements. Fintechs that haven’t read their partnership agreement’s M&A provisions recently should do so now — understanding what happens to the program in an acquisition is a due diligence question, not just a legal one.

Seven BaaS consent orders between 2022 and 2025 demonstrated that regulatory liability in bank-fintech programs follows the bank charter, not the partnership contract. When a bank with a fintech-driven compliance problem is acquired, the acquiring bank inherits the regulatory relationship. Examiners of the acquiring institution will ask about the inherited fintech programs, the compliance posture of each, and whether the acquiring bank conducted adequate due diligence before closing.

For fintechs, this means your bank partner’s acquisition is a trigger for your own internal risk assessment: does the acquiring institution’s risk appetite, compliance infrastructure, and operating model align with your program’s requirements? That assessment needs to be documented — your regulators and any future bank partners will want to see that you evaluated the change actively rather than treating it as a pass-through.

The 25% prior-notice growth threshold in the proposed rule is also worth monitoring for rapidly growing BaaS programs. If your bank partner’s balance sheet is growing significantly through fintech deposits and the bank enters into a transaction that, combined with prior fintech-related transactions, crosses the 25% threshold with the same counterparty, the prior notice process activates. Knowing that threshold exists — and monitoring whether your program’s growth trajectory would be material to it — is part of TPRM for fintech companies partnered with state nonmember banks.

The Broader Deregulatory Context

This proposed rule is one of several overlapping regulatory reforms under the current administration that affect FDIC-supervised community banks. The OCC and FDIC’s August 27 final rule defining “unsafe or unsound practice” for the first time in 70 years takes effect November 2, 2026, reshaping how MRAs and supervisory actions are issued. The combination of more predictable merger timelines and a higher threshold for enforcement action represents a significant shift in the operating environment for community banks.

That context matters for fintech partners evaluating bank relationships. A bank operating under the current enforcement environment — one that may face a new MRA standard effective November 2 — is a different counterparty than the same bank operating under the prior framework. Banks that were previously facing open enforcement actions may resolve them faster; banks that would have received MRAs under prior standards may not under the new materiality threshold.

Understanding your bank partner’s regulatory posture — their pending MRAs, their examination history, their risk profile — is more important in a shifting framework than in a stable one. OCC fintech charter denials in 2026 underscore that regulatory posture and AML program quality remain central to any bank’s ability to serve fintech partners at scale.

The Comment Deadline

The FDIC’s proposed rule carries a 60-day comment period. State nonmember banks, trade associations representing community banks, and fintech companies with bank partnerships should review the proposal’s specific provisions on the 25% prior notice threshold, the de minimis pipeline criteria, and the standard review timeline. If the current thresholds don’t match the risk calibration your institution operates under, the comment period is the structured mechanism for raising that.

So What?

The FDIC’s proposed merger reform is straightforwardly a deregulatory signal for community bank M&A. For banks that have held off on strategic acquisitions because of regulatory uncertainty, the new framework offers more predictability and faster processing for low-risk transactions.

For fintech compliance teams, the more immediate question is what this means for your existing bank partner. A faster, more predictable merger framework means community banks under M&A pressure — margin compression, technology investment requirements, geographic concentration — are more likely to pursue strategic transactions. Your bank partner may be an acquirer or a target. Either scenario creates program review obligations on your side.

Track the 25% prior notice threshold as you monitor your bank partner’s balance sheet trajectory. Review your partnership agreement’s change-of-control provisions before any M&A rumor becomes relevant. Document your evaluation of any material change to your bank partner’s structure — your own examiners will ask whether you monitored it.

The comment period closes 60 days after publication. The effective date of any final rule will follow. The strategic implications for community bank M&A and BaaS programs are already worth evaluating now.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the FDIC propose on September 17, 2026?
The FDIC board approved a proposed rule to modernize and reform the agency's framework for reviewing merger transactions subject to FDIC approval under the Bank Merger Act. The proposal creates risk-based processing tracks ranging from five business days for de minimis transactions to a 270-day maximum for complex deals, replacing the current framework that critics said was slow, opaque, and inconsistently applied.
Which banks does the FDIC's merger authority cover?
The FDIC's Bank Merger Act authority covers state nonmember banks — state-chartered banks that are not members of the Federal Reserve System. That accounts for approximately 2,700 of the country's roughly 4,500 FDIC-insured banks and savings associations. National banks and state member banks have separate merger review processes through the OCC and Federal Reserve, respectively.
What is the 25% prior notice requirement?
The proposed rule would require FDIC-supervised institutions to submit a prior notice and receive FDIC non-objection before completing any transaction — or series of transactions with the same counterparty or its affiliates — that would increase the institution's total assets by 25% or more over a rolling 12-month period. The non-objection would ordinarily be processed within 30 days, with a 90-day maximum.
What does the de minimis processing track cover?
The de minimis pipeline would apply to acquisitions of extremely small targets (below a defined asset threshold) or certain types of operating subsidiaries. These transactions would receive a decision in as little as five business days, providing community banks with a dramatically faster path for small, low-risk acquisitions.
When is the comment deadline?
The proposed rule carries a 60-day comment period, running from the date of Federal Register publication. The FDIC invited feedback on the risk-based tailoring framework, the processing timeline categories, and the prior notice threshold for growth transactions.
What should fintech compliance teams do when their bank partner is acquired?
Immediately review your partnership agreement for change-of-control provisions, assignment rights, and notification requirements. Verify whether the acquiring institution has existing fintech programs and how those were structured. Assess whether the combined institution's compliance posture and risk appetite are compatible with your program — and document that assessment for your own examiners, who may ask about your monitoring of material third-party changes.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Enterprise Risk Management Framework (ERMF)

Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.