<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>The Risk Practitioner&apos;s Journal</title><description>Practical insights on AI risk, compliance, and risk management for financial services professionals.</description><link>https://risktemplate.com/</link><item><title>FinCEN Renewed the Minnesota GTO. Banks Have Four Days to Restart $3,000 International Transfer Reporting.</title><link>https://risktemplate.com/blog/2026-08-07-fincen-minnesota-gto-international-transfer-reporting/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-07-fincen-minnesota-gto-international-transfer-reporting/</guid><description>The FinCEN Minnesota GTO starts August 11. Banks and money transmitters need complete data and monthly reporting for covered $3,000 transfers.</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate></item><item><title>FINRA Is Still Barring Brokers Over Text Messages. Here&apos;s What the Off-Channel Enforcement Split Means for Your Records Program.</title><link>https://risktemplate.com/blog/2026-08-07-finra-off-channel-individual-accountability-enforcement-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-07-finra-off-channel-individual-accountability-enforcement-2026/</guid><description>The SEC ended its off-channel enforcement wave after 95 cases and $2.3 billion in penalties. FINRA didn&apos;t follow. While the SEC pivoted to fraud and fiduciary cases, FINRA fined BTIG $600,000 and started barring individuals from the industry. Here&apos;s what the divergence means for broker-dealer compliance programs.</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate></item><item><title>The OCC Called Them &apos;Available Funds.&apos; Veterans Paid the Origination Fees. What the Federal Savings Bank Consent Order Teaches About Marketing Review.</title><link>https://risktemplate.com/blog/2026-08-07-occ-federal-savings-bank-va-loan-deceptive-marketing-ftc-act-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-07-occ-federal-savings-bank-va-loan-deceptive-marketing-ftc-act-2026/</guid><description>The Federal Savings Bank of Chicago sent millions of mailers telling veterans they had &apos;available funds&apos; — when accessing those funds required taking out a new VA cash-out refinance loan. Employees told consumers interest rates would decrease on what were actually permanent fixed-rate mortgages. The April 2026 OCC consent order requires restitution, a corrective action plan, and quarterly progress reports.</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate></item><item><title>OFAC Targeted Iranian Crypto Exchanges and Shadow-Banking Networks. Your Controls Need More Than an SDN Name Match.</title><link>https://risktemplate.com/blog/2026-08-07-ofac-iran-crypto-exchanges-shadow-banking-sanctions-controls/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-07-ofac-iran-crypto-exchanges-shadow-banking-sanctions-controls/</guid><description>OFAC&apos;s August 7 Iran sanctions target crypto exchanges, exchange houses, wallets, and shell networks. Here is the control response for financial institutions.</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate></item><item><title>AML&apos;s Board Accountability Moment: What the 2026 Examination Standard Expects Beyond Transaction Monitoring</title><link>https://risktemplate.com/blog/2026-08-06-aml-board-accountability-bsa-exam-2026-fincen-nprm-governance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-06-aml-board-accountability-bsa-exam-2026-fincen-nprm-governance/</guid><description>FinCEN&apos;s April 2026 NPRM proposes formal board oversight as a required AML program component. OCC&apos;s revised exam procedures took effect February 2026. TD Bank&apos;s $3B penalty set the precedent. Here&apos;s what examiners now look for at the board level.</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Q2 2026: $931 Million in Penalties, One Theme — Firms That Had Controls and Didn&apos;t Use Them</title><link>https://risktemplate.com/blog/2026-08-06-q2-2026-enforcement-escalation-controls-failures-compliance-strategy/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-06-q2-2026-enforcement-escalation-controls-failures-compliance-strategy/</guid><description>Corlytics tracked 37 major penalties totaling $931M in Q2 2026. The pattern isn&apos;t missing frameworks — it&apos;s firms ignoring the ones they already have. Here&apos;s what that means for your escalation and issues management process.</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate></item><item><title>SEC’s New Financial Reporting and Accounting Unit: The ICFR Review to Start Now</title><link>https://risktemplate.com/blog/2026-08-06-sec-financial-reporting-accounting-unit-icfr-audit-committee/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-06-sec-financial-reporting-accounting-unit-icfr-audit-committee/</guid><description>The SEC Financial Reporting and Accounting Unit puts specialist scrutiny back on accounting fraud, ICFR, audit evidence, and auditor conduct.</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Delaware&apos;s Banking Law Overhaul Is Done. What the SB 16, SB 18, and SB 19 Package Means for Fintechs and Stablecoin Issuers</title><link>https://risktemplate.com/blog/2026-08-05-delaware-banking-modernization-money-transmitter-stablecoin-sb16-sb18-sb19-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-05-delaware-banking-modernization-money-transmitter-stablecoin-sb16-sb18-sb19-2026/</guid><description>Governor Matt Meyer signed three bills on July 6, 2026 — the most significant update to Delaware&apos;s financial regulatory framework in 40+ years. Here is what changed and what compliance teams need to do now.</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate></item><item><title>FDIC Supervisory Appeals Office Is Live: The 60-Day Bank Exam Window to Calendar Now</title><link>https://risktemplate.com/blog/2026-08-05-fdic-supervisory-appeals-office-60-day-bank-exam-window/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-05-fdic-supervisory-appeals-office-60-day-bank-exam-window/</guid><description>The FDIC supervisory appeals office is operational. Banks have 60 days to challenge eligible exam determinations—and the evidence clock starts early.</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate></item><item><title>X Money Picked a Sponsor Bank with an FDIC Consent Order. Read It Before Your Next BaaS Review.</title><link>https://risktemplate.com/blog/2026-08-05-x-money-cross-river-bank-baas-sponsor-enforcement-compliance-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-05-x-money-cross-river-bank-baas-sponsor-enforcement-compliance-2026/</guid><description>Cross River Bank is X Money&apos;s banking backbone. Its 2023 FDIC consent order for unsafe or unsound fair lending practices is the BaaS case study every compliance team needs to work through.</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Gotbit SEC Settlement: The Crypto Wash-Trading Controls That Matter Now</title><link>https://risktemplate.com/blog/2026-08-04-gotbit-sec-settlement-crypto-wash-trading-controls/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-04-gotbit-sec-settlement-crypto-wash-trading-controls/</guid><description>The Gotbit SEC settlement shows crypto market-manipulation risk is still live. Here are the wash-trading controls compliance teams should test.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate></item><item><title>NYDFS Drops the BNPL Rulebook: What the July 2026 Proposed Regulation Requires</title><link>https://risktemplate.com/blog/2026-08-04-new-york-bnpl-nydfs-proposed-regulation-licensing-compliance-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-04-new-york-bnpl-nydfs-proposed-regulation-licensing-compliance-2026/</guid><description>NYDFS published comprehensive BNPL licensing and consumer protection rules on July 15, 2026, implementing New York&apos;s Buy-Now-Pay-Later Act. Here is what every BNPL provider in New York needs to know before the comment deadline closes and the final rule takes effect.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate></item><item><title>The Fed Is Coming for Private Credit Exposure. Here&apos;s What Your Risk Program Needs.</title><link>https://risktemplate.com/blog/2026-08-04-private-credit-ndfi-bank-exposure-federal-reserve-supervisory-examination-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-04-private-credit-ndfi-bank-exposure-federal-reserve-supervisory-examination-2026/</guid><description>Federal Reserve examiners have named private credit and NDFI lending a top supervisory priority for 2026. Bank exposure to nonbank financial institutions sits at $1.4 trillion. Here is what your credit risk and counterparty risk programs need to look like before examiners ask.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate></item><item><title>46 State AGs Just Settled with Cash App for $45 Million. Here&apos;s What Your Fraud Disclosure, KYC Design, and Customer Support Look Like Under That Lens.</title><link>https://risktemplate.com/blog/2026-08-03-cash-app-block-46-state-ag-settlement-fraud-disclosure-kyc-fintech-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-03-cash-app-block-46-state-ag-settlement-fraud-disclosure-kyc-fintech-2026/</guid><description>On July 8, 2026, a bipartisan coalition of 46 state attorneys general announced a $45M settlement with Block Inc. over Cash App&apos;s fraud disclosure failures, identity verification gaps that enabled fraudsters, and the absence of any official customer support phone number. Combined with the January 2025 CFPB order, Block paid $220M in 18 months. Here&apos;s what that enforcement record means for your compliance program.</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Stablecoin Issuers Just Got a Customer Identification Mandate. The Comment Deadline Is August 21.</title><link>https://risktemplate.com/blog/2026-08-03-genius-act-stablecoin-cip-nprm-comment-deadline-august-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-03-genius-act-stablecoin-cip-nprm-comment-deadline-august-2026/</guid><description>On June 18, 2026, FinCEN and four federal banking agencies proposed the first-ever Customer Identification Program requirements for permitted payment stablecoin issuers under the GENIUS Act. The comment period closes August 21. Here&apos;s what the rule requires, where it matters most, and what stablecoin compliance programs need to build.</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate></item><item><title>NYDFS&apos;s First 2026 Cybersecurity Fine Wasn&apos;t About the MOVEit Hack. It Was About What Happened After.</title><link>https://risktemplate.com/blog/2026-08-03-nydfs-delta-dental-moveit-breach-notification-data-disposal-72-hour-rule/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-03-nydfs-delta-dental-moveit-breach-notification-data-disposal-72-hour-rule/</guid><description>On April 29, 2026, NYDFS issued a $2.25 million consent order against Delta Dental of New York—its first 2026 cybersecurity enforcement action. The underlying breach was a 2023 MOVEit zero-day. The violations were late notification, inadequate data disposal, and insufficient incident response plan detail. And the consent order bars insurance reimbursement. Here&apos;s what the enforcement record tells your program.</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Your Bank Partner Just Got an OCC Consent Order. What Happens to Your Fintech Program.</title><link>https://risktemplate.com/blog/2026-08-03-occ-baas-bank-partner-consent-order-fintech-tprm-program-risk-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-03-occ-baas-bank-partner-consent-order-fintech-tprm-program-risk-2026/</guid><description>In May 2026, the OCC made public a consent order against Community Federal Savings Bank for BSA/AML deficiencies tied to fintech-partner payment processing growth—wire, ACH, and cross-border volume the bank couldn&apos;t supervise. Fintechs whose programs run through enforcement-action banks face program pause, enhanced scrutiny, or termination. Here&apos;s what your TPRM program needs to monitor.</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate></item><item><title>UBS $125 Million AML Penalty: The Data Failures Behind the Repeat Violation</title><link>https://risktemplate.com/blog/2026-08-03-ubs-125-million-aml-penalty-transaction-monitoring-failures/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-03-ubs-125-million-aml-penalty-transaction-monitoring-failures/</guid><description>The UBS AML penalty exposes FX wire data gaps, weak CDD, and failed remediation. Here is what compliance teams should test now.</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Examiners Are Now Asking About Your Non-Work-Authorized Borrower Portfolio: What the July 2026 Interagency Guidance Requires</title><link>https://risktemplate.com/blog/2026-08-02-lending-non-work-authorized-individuals-credit-risk-ecoa-interagency-guidance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-02-lending-non-work-authorized-individuals-credit-risk-ecoa-interagency-guidance/</guid><description>On July 13, 2026, the OCC, FDIC, and NCUA issued interagency guidance telling financial institutions to apply safe-and-sound credit risk practices when lending to borrowers not legally authorized to work in the US. Here&apos;s what examiners will actually look for — and how to build a defensible program.</description><pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate></item><item><title>When Your Examiner Wants Your Penetration Test Results: The July 2026 Joint Statement on Protecting Your Most Sensitive Security Data</title><link>https://risktemplate.com/blog/2026-08-02-sensitive-exam-data-penetration-test-regulator-handling-joint-statement/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-02-sensitive-exam-data-penetration-test-regulator-handling-joint-statement/</guid><description>On July 16, 2026, the OCC, FDIC, and Federal Reserve issued a joint statement establishing coordinated protocols for how examiners handle your most sensitive security documentation — penetration test results, network diagrams, and IT control weaknesses. Here&apos;s what it means for your examination preparation.</description><pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate></item><item><title>72% of Banks Can&apos;t Shut Down a Malfunctioning AI Model. Examiners Are About to Find That Out.</title><link>https://risktemplate.com/blog/2026-08-01-ai-kill-switch-bank-exam-governance-vendor-risk/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-01-ai-kill-switch-bank-exam-governance-vendor-risk/</guid><description>A June 2026 survey found 72% of banks are unprepared to shut down a malfunctioning AI model or report an AI failure to regulators—the two most basic controls in any AI incident-response playbook. OCC and Fed examiners have made AI a permanent standing topic in every routine bank examination. Here&apos;s what kill switch documentation, vendor disentanglement testing, and data boundary enforcement look like when an examiner walks in.</description><pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate></item><item><title>The CFPB Gutted Federal Disparate Impact. Now AI-Driven Lenders Have a State Fair Lending Problem.</title><link>https://risktemplate.com/blog/2026-08-01-cfpb-reg-b-disparate-impact-removal-ai-lending-state-fair-lending-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-01-cfpb-reg-b-disparate-impact-removal-ai-lending-state-fair-lending-2026/</guid><description>The CFPB&apos;s Reg B final rule, effective July 21, 2026, removed the effects test from ECOA — but five states immediately reaffirmed their own disparate impact regimes, NYDFS issued an industry letter the same day, and CFPB Circular 2026-03 kept adverse action notice requirements fully in place for AI models. For any lender using algorithmic underwriting, this isn&apos;t deregulation. It&apos;s a compliance map with more moving parts.</description><pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate></item><item><title>CIRCIA&apos;s 72-Hour Reporting Clock Is Statutory, and It&apos;s Coming for Financial Institutions. What Your Incident Response Plan Is Missing.</title><link>https://risktemplate.com/blog/2026-08-01-circia-72-hour-cyber-incident-reporting-financial-institutions-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-01-circia-72-hour-cyber-incident-reporting-financial-institutions-2026/</guid><description>CISA&apos;s final rule implementing CIRCIA is expected by September 2026 — but the 72-hour cyber incident reporting clock and 24-hour ransomware payment deadline are written into the statute and won&apos;t change regardless of when the rule drops. Financial institutions already juggling five overlapping reporting regimes need to add CISA to the matrix now, not after enforcement starts.</description><pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate></item><item><title>The ECB Just Ran 110 Banks Through a Geopolitical Reverse Stress Test. Here&apos;s What US Banks&apos; BCPs Are Missing.</title><link>https://risktemplate.com/blog/2026-08-01-ecb-geopolitical-stress-test-2026-bcp-scenario-us-banks/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-08-01-ecb-geopolitical-stress-test-2026-bcp-scenario-us-banks/</guid><description>On July 31, 2026, the ECB published results of its thematic geopolitical risk reverse stress test covering 110 directly supervised euro area banks—and urged the sector to improve. The OCC&apos;s Spring 2026 Semiannual Risk Perspective added geopolitical risk as a prominent new concern for the first time. Most US bank business continuity programs are built for IT failures and natural disasters. They are not built for this class of scenario.</description><pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Bank Holding Company Source-of-Strength: What Fintechs Getting Bank Charters Haven&apos;t Accounted For</title><link>https://risktemplate.com/blog/2026-07-31-bank-holding-company-source-of-strength-fintech-subsidiaries/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-31-bank-holding-company-source-of-strength-fintech-subsidiaries/</guid><description>When a fintech gets a bank charter and forms a bank holding company, it inherits the source-of-strength obligation — a capital backstop requirement most fintech BHC playbooks don&apos;t address. The TS Banking Group July 2026 written agreement shows what happens when this surfaces at exam time.</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs</title><link>https://risktemplate.com/blog/2026-07-31-exodus-ofac-crypto-wallet-sanctions-compliance-program/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-31-exodus-ofac-crypto-wallet-sanctions-compliance-program/</guid><description>OFAC&apos;s December 2025 settlement with Exodus Movement — $3.1 million for 254 apparent violations of the Iranian Transactions and Sanctions Regulations — is the clearest statement yet that non-custodial crypto wallets are in scope for sanctions obligations. The finding that staff advised Iranian users to use VPNs is the detail that turns a compliance failure into an egregious one.</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Federal Reserve Regulation O Proposal: Rebuild the Control Logic, Not Just the Limits</title><link>https://risktemplate.com/blog/2026-07-31-federal-reserve-regulation-o-proposal-insider-lending-controls/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-31-federal-reserve-regulation-o-proposal-insider-lending-controls/</guid><description>The 2026 Regulation O proposal raises insider-lending thresholds and changes passive-fund treatment. Here is the bank control impact.</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Iuka State Bank Written Agreement: The Fed&apos;s 30-Day Credit Risk and BSA/AML Remediation List</title><link>https://risktemplate.com/blog/2026-07-31-iuka-state-bank-federal-reserve-written-agreement-credit-bsa-aml/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-31-iuka-state-bank-federal-reserve-written-agreement-credit-bsa-aml/</guid><description>The Iuka State Bank written agreement maps Fed findings to 30- and 60-day fixes across credit, capital, liquidity, and BSA/AML.</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate></item><item><title>OCC-FDIC CRA Proposal: The 2026 Changes Banks Need to Map Now</title><link>https://risktemplate.com/blog/2026-07-31-occ-fdic-cra-proposal-2026-community-bank-changes/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-31-occ-fdic-cra-proposal-2026-community-bank-changes/</guid><description>The OCC-FDIC CRA proposal changes bank thresholds, lending tests, grant eligibility, and reporting. Here is the control impact.</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate></item><item><title>DORA&apos;s 4-Hour Incident Reporting Clock: What US Banks with EU Operations Are Missing in Their Playbooks</title><link>https://risktemplate.com/blog/2026-07-30-dora-ict-incident-reporting-4-hour-clock-us-banks-eu-operations/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-30-dora-ict-incident-reporting-4-hour-clock-us-banks-eu-operations/</guid><description>DORA&apos;s ICT incident reporting timeline is the strictest in the world — 4 hours to initial notification, 72 hours to the intermediate report, one month to final. US banks with EU branches are subject to it and most have a gap between their US playbook and what Brussels actually requires.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Fourth-Party Risk: What the 2023 Interagency Guidance Actually Requires When Your Vendor&apos;s Vendor Is the Exposure</title><link>https://risktemplate.com/blog/2026-07-30-fourth-party-risk-subcontractor-concentration-cloud-banking-exam/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-30-fourth-party-risk-subcontractor-concentration-cloud-banking-exam/</guid><description>Regulators don&apos;t use the phrase &apos;fourth-party risk&apos; — they call it subcontractor risk, and the 2023 interagency guidance has specific requirements for it. Here&apos;s what examiners are looking for, what common MRAs look like, and how the CrowdStrike incident and UK Critical Third Party designations changed the calculus.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate></item><item><title>New Jersey&apos;s A5328 Is the Costliest Data Broker Law in the Country — and It&apos;s Already in Effect for Sensitive Data</title><link>https://risktemplate.com/blog/2026-07-30-new-jersey-data-broker-law-a5328-fintech-compliance-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-30-new-jersey-data-broker-law-a5328-fintech-compliance-2026/</guid><description>New Jersey signed A5328 on June 30, 2026, banning the sale of sensitive financial and personal data immediately and creating registration fees up to $1.5 million. GLBA covers some fintechs — but &apos;financial services&apos; doesn&apos;t automatically mean exempt. Here&apos;s the analysis every fintech and data aggregator needs to run now.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The Zelle Ruling and What Every P2P Payment Operator Has to Fix in Its Fraud Control Framework</title><link>https://risktemplate.com/blog/2026-07-30-zelle-ruling-authorized-push-payment-fraud-p2p-operator-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-30-zelle-ruling-authorized-push-payment-fraud-p2p-operator-compliance/</guid><description>A New York judge let the $1B+ Zelle fraud lawsuit proceed on July 21, 2026. The court found Early Warning Services prioritized speed-to-market over fraud controls it had already designed. If you operate a P2P payment product, this ruling is a blueprint of what state prosecutors will look for in your control gap.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate></item><item><title>California&apos;s DELETE Act: The August 1, 2026 DROP Deadline and the GLBA Exemption Test Every Fintech Needs to Pass</title><link>https://risktemplate.com/blog/2026-07-29-california-delete-act-drop-system-august-2026-fintech-data-broker-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-29-california-delete-act-drop-system-august-2026-fintech-data-broker-compliance/</guid><description>California&apos;s DELETE Act requires data brokers to process consumer deletion requests through the DROP system starting August 1, 2026. The penalty is $200 per request per day. Most GLBA-covered financial institutions are exempt — but many fintechs aren&apos;t sure which category they&apos;re in. Here&apos;s how to run the analysis.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The House CFPB Reform Discussion Draft: What the $21B Supervisory Threshold and Congressional Appropriations Proposal Mean for Your Compliance Program</title><link>https://risktemplate.com/blog/2026-07-29-cfpb-reform-discussion-draft-21b-threshold-compliance-program-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-29-cfpb-reform-discussion-draft-21b-threshold-compliance-program-2026/</guid><description>On July 24, 2026, the House Financial Services Committee published a 70-page CFPB restructuring draft. Here&apos;s what&apos;s in the five titles, what the $21B threshold change actually affects, and why the compliance programs that survive any version of this are built around legal obligations — not exam schedules.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>NYDFS Part 500 Class A Requirements: What the 2023 Amendments Added and Where 2026 Exams Are Finding Gaps</title><link>https://risktemplate.com/blog/2026-07-29-nydfs-part-500-class-a-requirements-2026-examination-gaps/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-29-nydfs-part-500-class-a-requirements-2026-examination-gaps/</guid><description>NYDFS&apos;s Second Amendment to Part 500 created a new Class A tier for larger covered entities. The final compliance deadline passed November 1, 2024 — and 2026 is the first full examination cycle with all amended requirements in scope. Here&apos;s what examiners are finding and what covered entities are still getting wrong.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The SEC&apos;s Four-Day Clock: How to Make a Cyber Incident Materiality Call Under Item 1.05</title><link>https://risktemplate.com/blog/2026-07-29-sec-8k-cybersecurity-materiality-four-day-clock-item-1-05/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-29-sec-8k-cybersecurity-materiality-four-day-clock-item-1-05/</guid><description>The four-day filing clock under SEC Item 1.05 starts at materiality determination — not discovery. Here&apos;s how companies structure that determination, what enforcement looks like two years in, and how to avoid the two failure modes that are generating penalties.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>EU AI Act August 2, 2026: What&apos;s Going Live, What Got Pushed to December 2027, and What US Fintechs Need to Do This Week</title><link>https://risktemplate.com/blog/2026-07-28-eu-ai-act-august-2026-transparency-obligations-high-risk-deferral/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-28-eu-ai-act-august-2026-transparency-obligations-high-risk-deferral/</guid><description>August 2, 2026 is five days away. The Digital Omnibus deferral is now final law. Here&apos;s what actually goes into effect on August 2 vs. what got moved to December 2027 — and the two-hour compliance check US fintechs should run now.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>FinCEN&apos;s Venezuela BSA Enforcement Relief: What Banks Must Document Before Relying on It</title><link>https://risktemplate.com/blog/2026-07-28-fincen-venezuela-bsa-enforcement-relief-policy/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-28-fincen-venezuela-bsa-enforcement-relief-policy/</guid><description>FinCEN Venezuela BSA enforcement relief runs through January 29, 2027, but only for eligible institutions making reasonable compliance efforts.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The First 90 Days as a New Compliance Officer: Inventory Before You Rewrite</title><link>https://risktemplate.com/blog/2026-07-28-first-90-days-new-compliance-officer-inventory-checklist/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-28-first-90-days-new-compliance-officer-inventory-checklist/</guid><description>A compliance checklist template for your first 90 days: inventory obligations, issues, complaints, commitments, controls, access, and evidence first.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Risk Appetite Breach Playbook: What Happens After a Limit Turns Red</title><link>https://risktemplate.com/blog/2026-07-28-risk-appetite-breach-playbook-escalation-remediation/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-28-risk-appetite-breach-playbook-escalation-remediation/</guid><description>A KRI turning red isn&apos;t the problem — not knowing what to do next is. Here&apos;s the documented breach response playbook: validation, escalation, remediation, and what the board needs to see.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>SEC&apos;s Simplify Asset Management Order: Four ETF Controls That Failed at Once</title><link>https://risktemplate.com/blog/2026-07-28-sec-simplify-asset-management-etf-compliance-order/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-28-sec-simplify-asset-management-etf-compliance-order/</guid><description>The SEC Simplify Asset Management order ties a $400,000 penalty to affiliate trades, VaR escalation, Form N-RN delays, and distribution notices.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Vendor Due Diligence After the Contract Is Signed: A 10-Day Recovery Plan</title><link>https://risktemplate.com/blog/2026-07-28-vendor-due-diligence-contract-already-signed-recovery-plan/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-28-vendor-due-diligence-contract-already-signed-recovery-plan/</guid><description>Use this vendor risk assessment checklist when Risk is brought in after signature: contain access, assess gaps, add conditions, and record exposure.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI Risk Assessment Questionnaire: Split the Questions Between the Business Owner, Technology Team, and Independent Reviewer</title><link>https://risktemplate.com/blog/2026-07-27-ai-risk-assessment-questionnaire-role-based-evidence/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-27-ai-risk-assessment-questionnaire-role-based-evidence/</guid><description>Build an AI risk assessment questionnaire with clear owners, evidence fields, and independent challenge instead of one unreliable respondent.</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Personnel Continuity Under FFIEC BCM: Succession Is Not a List of Phone Numbers</title><link>https://risktemplate.com/blog/2026-07-27-ffiec-business-continuity-personnel-succession-coverage/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-27-ffiec-business-continuity-personnel-succession-coverage/</guid><description>Build FFIEC business continuity management personnel coverage with tested backups, delegated authority, usable procedures, and recovery evidence.</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Issue Management Framework: Stop Closing Findings When the Action Is Done but the Risk Is Still Open</title><link>https://risktemplate.com/blog/2026-07-27-issue-management-framework-action-complete-risk-still-open/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-27-issue-management-framework-action-complete-risk-still-open/</guid><description>An issue management framework that separates action completion from closure through evidence, validation, recurrence checks, and risk acceptance.</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Operational Risk Framework Architecture: How RCSAs, KRIs, Loss Events, Issues, and Scenarios Fit Together</title><link>https://risktemplate.com/blog/2026-07-27-operational-risk-framework-components-rcsa-kri-loss-events-scenarios/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-27-operational-risk-framework-components-rcsa-kri-loss-events-scenarios/</guid><description>Five operational risk components — RCSA, KRIs, loss events, issues, and scenario analysis — only work when they feed each other. Here&apos;s the architecture and the artifact handoffs.</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate></item><item><title>RCSA Template in Excel: From Workshop Notes to Owner Sign-Off Without Losing the Challenge Record</title><link>https://risktemplate.com/blog/2026-07-27-rcsa-template-excel-workshop-notes-owner-sign-off-challenge-record/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-27-rcsa-template-excel-workshop-notes-owner-sign-off-challenge-record/</guid><description>The challenge record is what separates a defensible RCSA from a copy-paste exercise. Here&apos;s the Excel structure that carries workshop observations through second-line challenge to documented owner sign-off.</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Regulatory Change Implementation Record: Prove the Alert Became a Working Control</title><link>https://risktemplate.com/blog/2026-07-27-regulatory-change-implementation-record-evidence-working-control/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-27-regulatory-change-implementation-record-evidence-working-control/</guid><description>A regulatory change log tells you when the alert arrived. An implementation record proves the alert became a working control. Here&apos;s what the evidence chain needs to contain.</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Vendor Risk Questionnaire Review: Which Answers Require Challenge, Proof, or a Contract Condition</title><link>https://risktemplate.com/blog/2026-07-27-vendor-risk-questionnaire-review-evidence-contract-conditions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-27-vendor-risk-questionnaire-review-evidence-contract-conditions/</guid><description>Review a vendor risk questionnaire by turning each answer into proof, a compensating control, a contract condition, escalation, or rejection.</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AML Risk Assessment in Excel: Make Every Inherent-Risk Score Traceable to Source Data</title><link>https://risktemplate.com/blog/2026-07-26-aml-risk-assessment-excel-workbook-methodology-inherent-risk-traceable/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-26-aml-risk-assessment-excel-workbook-methodology-inherent-risk-traceable/</guid><description>A BSA/AML risk assessment that can&apos;t show its work fails the exam. Here&apos;s the Excel workbook structure that makes every inherent-risk score, control effectiveness rating, and residual score traceable to source data.</description><pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Business Continuity Workaround Strategies: Document the Manual Process Before the System Goes Down</title><link>https://risktemplate.com/blog/2026-07-26-business-continuity-workaround-strategies-manual-procedures-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-26-business-continuity-workaround-strategies-manual-procedures-financial-services/</guid><description>A BCP without documented manual workaround procedures isn&apos;t a continuity plan — it&apos;s a recovery plan. Here&apos;s the workaround template fields and critical-function structure FFIEC examiners expect to see.</description><pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Enterprise Risk Management After Approval: The Operating Cadence That Keeps ERM Alive</title><link>https://risktemplate.com/blog/2026-07-26-enterprise-risk-management-framework-operating-cadence/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-26-enterprise-risk-management-framework-operating-cadence/</guid><description>Run an enterprise risk management framework with a practical monthly, quarterly, and annual cadence, named owners, and decision evidence.</description><pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate></item><item><title>After the Incident: Turn Lessons Learned Into Control Changes That Stay Closed</title><link>https://risktemplate.com/blog/2026-07-26-incident-response-plan-lessons-learned-control-changes-effectiveness-closure/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-26-incident-response-plan-lessons-learned-control-changes-effectiveness-closure/</guid><description>Strengthen an incident response plan by converting lessons learned into owned control changes, effectiveness tests, and defensible closure evidence.</description><pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Policy Exception Management: Stop Temporary Waivers From Becoming the Real Policy</title><link>https://risktemplate.com/blog/2026-07-26-policy-exception-management-temporary-waiver-register/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-26-policy-exception-management-temporary-waiver-register/</guid><description>Add policy exception management to your policy management framework with approvals, compensating controls, expiry, and a waiver register.</description><pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Privacy Impact Assessment for Mixed GLBA and Non-GLBA Data: Scope the Data, Not the Entity</title><link>https://risktemplate.com/blog/2026-07-26-privacy-impact-assessment-mixed-glba-non-glba-data-scope/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-26-privacy-impact-assessment-mixed-glba-non-glba-data-scope/</guid><description>Use a data privacy impact assessment template to separate GLBA and non-GLBA processing by data flow, purpose, person, use, and state-law scope.</description><pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate></item><item><title>FFIEC BCM Section III.B Risk Assessment: Turn Threats Into Continuity Strategies</title><link>https://risktemplate.com/blog/2026-07-25-ffiec-bcm-section-iii-b-risk-assessment-continuity-strategies/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-25-ffiec-bcm-section-iii-b-risk-assessment-continuity-strategies/</guid><description>Build an FFIEC BCM Section III.B risk assessment that traces threats, controls, gaps, continuity strategies, tests, and remediation.</description><pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate></item><item><title>GRC Framework for a Small Risk Team: One Control Library, Five Workflows, No Enterprise Platform</title><link>https://risktemplate.com/blog/2026-07-25-grc-framework-small-risk-team-one-control-library/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-25-grc-framework-small-risk-team-one-control-library/</guid><description>A GRC program that runs on one control library, five traceable workflows, and a set of spreadsheets beats a half-implemented enterprise platform every time. Here&apos;s how to build it.</description><pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Incident Response Decision Log: Document Why a Notification Clock Did—or Did Not—Start</title><link>https://risktemplate.com/blog/2026-07-25-incident-response-decision-log-notification-clock-documentation/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-25-incident-response-decision-log-notification-clock-documentation/</guid><description>When a cyber event hits, every regulator wants the same thing: proof you made a good-faith materiality determination without unreasonable delay. Here&apos;s the decision log structure that creates that proof—whether the clock started or not.</description><pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Effective Challenge in Model Risk Management: Document the Disagreement</title><link>https://risktemplate.com/blog/2026-07-25-model-risk-management-effective-challenge-documentation-disagreement/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-25-model-risk-management-effective-challenge-documentation-disagreement/</guid><description>Model risk management effective challenge needs a decision trail. Build a challenge memo that preserves evidence, responses, conditions, and escalation.</description><pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate></item><item><title>NIST AI RMF Implementation: The Minimum Artifact Set for a Team That Cannot Build 200 Controls</title><link>https://risktemplate.com/blog/2026-07-25-nist-ai-rmf-implementation-minimum-artifact-set-small-team/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-25-nist-ai-rmf-implementation-minimum-artifact-set-small-team/</guid><description>What a small risk team actually needs to produce for NIST AI RMF and FS AI RMF compliance — 12 artifacts across GOVERN, MAP, MEASURE, and MANAGE that hold up to examiner scrutiny.</description><pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Third-Party Risk Management Lifecycle RACI: Fix the Handoffs Between Procurement, Security, Legal, Business Owners, and Risk</title><link>https://risktemplate.com/blog/2026-07-25-tprm-lifecycle-raci-procurement-security-legal-handoffs/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-25-tprm-lifecycle-raci-procurement-security-legal-handoffs/</guid><description>A TPRM lifecycle RACI that assigns clear ownership at each stage — planning, due diligence, contracting, onboarding, monitoring, and offboarding — so findings don&apos;t fall between functions.</description><pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI Governance Decision Log: The Missing Artifact Between Committee Meetings and Production Approval</title><link>https://risktemplate.com/blog/2026-07-24-ai-governance-decision-log-production-approval/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-24-ai-governance-decision-log-production-approval/</guid><description>An AI governance framework example for logging approval conditions, dissent, evidence, owners, and expiry dates before an AI use case goes live.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Compliance Monitoring Plan in Excel: Convert the Risk Assessment Into a Defensible Test Universe</title><link>https://risktemplate.com/blog/2026-07-24-compliance-monitoring-plan-excel-test-universe/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-24-compliance-monitoring-plan-excel-test-universe/</guid><description>Build a compliance monitoring plan template in Excel that traces risks and obligations to scope, evidence, exceptions, and remediation.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>FinCEN&apos;s Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now</title><link>https://risktemplate.com/blog/2026-07-24-fincen-student-aid-fraud-alert-transaction-monitoring/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-24-fincen-student-aid-fraud-alert-transaction-monitoring/</guid><description>FinCEN&apos;s student aid fraud alert gives banks nine red flags, a SAR keyword, and a clear transaction-monitoring task for ACH refunds.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Risk Assessment Template in Excel: Build the Evidence Trail, Not Just the Heat Map</title><link>https://risktemplate.com/blog/2026-07-24-risk-assessment-template-excel-evidence-trail/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-24-risk-assessment-template-excel-evidence-trail/</guid><description>Build a risk assessment template in Excel that preserves evidence, challenge, approvals, and score history—not just a polished heat map.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Vendor Due Diligence Without a SOC 2: What Evidence Can Actually Substitute</title><link>https://risktemplate.com/blog/2026-07-24-vendor-due-diligence-without-soc-2-evidence-substitutes/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-24-vendor-due-diligence-without-soc-2-evidence-substitutes/</guid><description>A vendor due diligence checklist for evaluating security evidence when a vendor has no SOC 2 report, with a risk-based substitution matrix.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Four Months Late: What the NYDFS Healthplex $2M Penalty Says About When the Notification Clock Actually Starts</title><link>https://risktemplate.com/blog/2026-07-23-healthplex-nydfs-breach-notification-delay-determination-vs-investigation/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-23-healthplex-nydfs-breach-notification-delay-determination-vs-investigation/</guid><description>NYDFS fined Healthplex $2 million in August 2025 for notifying 4+ months after a breach. The failure wasn&apos;t forensics — it was a misunderstanding of when the 72-hour clock starts. The same mistake trips up banks under the FDIC&apos;s 36-hour rule.</description><pubDate>Thu, 23 Jul 2026 14:30:00 GMT</pubDate></item><item><title>Three Vendors, One Existential Risk: What the OCC&apos;s Community Bank Core Provider RFI Actually Asked</title><link>https://risktemplate.com/blog/2026-07-23-occ-core-provider-concentration-risk-fiserv-fis-jack-henry-community-banks/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-23-occ-core-provider-concentration-risk-fiserv-fis-jack-henry-community-banks/</guid><description>The OCC published Bulletin 2025-39 asking community banks hard questions about their relationships with Fiserv, FIS, and Jack Henry. The questions reveal exactly what examiners are now checking — and what most TPRM programs haven&apos;t addressed.</description><pubDate>Thu, 23 Jul 2026 14:00:00 GMT</pubDate></item><item><title>Magnolia Diagnostics False Claims Act Settlement: Why Investors Paid Part of the $24 Million</title><link>https://risktemplate.com/blog/2026-07-23-magnolia-diagnostics-false-claims-act-investor-settlement/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-23-magnolia-diagnostics-false-claims-act-investor-settlement/</guid><description>The Magnolia Diagnostics False Claims Act settlement reached investors, requisition controls, and $24M in payments. Here is what to fix.</description><pubDate>Thu, 23 Jul 2026 12:00:00 GMT</pubDate></item><item><title>August 2 Is Ten Days Away: What the EU AI Act&apos;s High-Risk Deadline Actually Requires from Financial Services AI</title><link>https://risktemplate.com/blog/2026-07-23-eu-ai-act-high-risk-annex-iii-august-2-financial-services-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-23-eu-ai-act-high-risk-annex-iii-august-2-financial-services-compliance/</guid><description>The EU AI Act&apos;s Annex III high-risk AI obligations take effect August 2, 2026. Credit scoring models, creditworthiness assessment systems, and insurance risk pricing AI are all in scope. Here&apos;s what providers and deployers in financial services must have in place before the deadline—and what the Digital Omnibus deferred.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Your Reg E Program Wasn&apos;t Built for FedNow: The Error Resolution Timeline Trap in Instant Payments</title><link>https://risktemplate.com/blog/2026-07-23-reg-e-fednow-rtp-error-resolution-instant-payments-dispute-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-23-reg-e-fednow-rtp-error-resolution-instant-payments-dispute-compliance/</guid><description>Reg E&apos;s 10-business-day provisional credit requirement applies to FedNow and RTP consumer transactions—but instant payment irrevocability means the fraud money is gone before you finish the investigation. Here&apos;s what your error resolution procedures actually need to say for instant payments, and where most programs have a documented gap.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>FedNow&apos;s Network Intelligence API Launched in April 2026. Your Fraud Risk Program Probably Hasn&apos;t Caught Up.</title><link>https://risktemplate.com/blog/2026-07-22-fednow-network-intelligence-api-fraud-risk-controls-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-22-fednow-network-intelligence-api-fraud-risk-controls-2026/</guid><description>On April 28, 2026, the Federal Reserve made pre-payment network-level fraud intelligence available to every FedNow participant. The data — receiver account behavioral trends derived from system-wide FedNow activity — is available before a transaction is approved. Most institutions haven&apos;t updated their fraud policies, controls, or KRIs to account for what this changes.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate></item><item><title>FinCEN Extended 314(b) to Fraud: The Safe Harbor Most Financial Institutions Are Still Ignoring</title><link>https://risktemplate.com/blog/2026-07-22-fincen-314b-fraud-information-sharing-2026-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-22-fincen-314b-fraud-information-sharing-2026-guide/</guid><description>On June 12, 2026, FinCEN updated its Section 314(b) Fact Sheet to explicitly cover fraud — including pig butchering, romance scams, and mule account activity. Institutions can now share transaction records, device data, IP addresses, and video footage in real time with other registered participants. Here&apos;s what changed, what you can and can&apos;t share, and why most compliance teams are leaving this tool unused.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Your State Regulator Is About to Ask for Your AI Inventory: What the NAIC&apos;s 12-State Pilot Means for Insurance AI Governance</title><link>https://risktemplate.com/blog/2026-07-22-naic-ai-systems-evaluation-tool-12-state-pilot-insurer-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-22-naic-ai-systems-evaluation-tool-12-state-pilot-insurer-compliance/</guid><description>The NAIC&apos;s AI Systems Evaluation Tool is live in 12 states through September 2026, with full national adoption expected at the November NAIC Fall Meeting. Regulators are asking for four specific exhibits — AI inventory, governance framework, high-risk system detail, and data quality controls. If you&apos;re not in a pilot state yet, you have a narrow window to build these before they come for you.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate></item><item><title>United Texas Bank&apos;s OCC Consent Order at Charter Conversion: The BSA/AML Lesson for Crypto Banking</title><link>https://risktemplate.com/blog/2026-07-22-united-texas-bank-occ-bsa-aml-crypto-national-charter-consent-order/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-22-united-texas-bank-occ-bsa-aml-crypto-national-charter-consent-order/</guid><description>When United Texas Bank converted to a national charter in May 2026, it arrived at the OCC already carrying a Federal Reserve BSA/AML consent order from 2024. Two months later, the OCC issued its own Cease and Desist. Here&apos;s what that sequence tells compliance teams about what national bank standards actually require for crypto-focused BSA/AML programs.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate></item><item><title>BCP Testing That Actually Satisfies Examiners: What FFIEC Requires Beyond Your Annual Tabletop</title><link>https://risktemplate.com/blog/2026-07-21-bcp-testing-ffiec-examiner-expectations-2026-documentation-frequency/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-21-bcp-testing-ffiec-examiner-expectations-2026-documentation-frequency/</guid><description>An annual tabletop that never fails anything is not a BCP test — it&apos;s theater. Here&apos;s what the FFIEC Business Continuity Management booklet actually requires, how 2026 examiners evaluate test programs, and what documentation makes your tests defensible.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CFPB Deleted Disparate Impact from Reg B. Here&apos;s What Actually Changed for AI Lenders Today.</title><link>https://risktemplate.com/blog/2026-07-21-cfpb-reg-b-disparate-impact-removed-july-2026-ai-lending-what-changes/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-21-cfpb-reg-b-disparate-impact-removed-july-2026-ai-lending-what-changes/</guid><description>The CFPB&apos;s Reg B amendment removing the effects test takes effect July 21, 2026. AI lenders aren&apos;t off the hook — Fair Housing Act disparate impact, state fair lending laws, GSE contracts, and ECOA disparate treatment still apply. Here&apos;s the complete picture.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Why Fintechs Are Racing for Bank Charters in 2026 — And What It Means If You&apos;re Still Running on a Sponsor Bank</title><link>https://risktemplate.com/blog/2026-07-21-fintech-bank-charter-surge-2026-baas-sponsor-bank-risk-occ-applications/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-21-fintech-bank-charter-surge-2026-baas-sponsor-bank-risk-occ-applications/</guid><description>OCC received more de novo charter applications in 2025 than the previous four years combined. Mercury got conditional approval in April 2026. Here&apos;s what&apos;s driving the charter surge, what types of charters are in play, and how to assess your BaaS exposure if you&apos;re not on the charter path.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Fourth-Party Risk After Synapse: What OCC and FDIC Now Expect from Your Subcontractor Oversight Program</title><link>https://risktemplate.com/blog/2026-07-21-fourth-party-risk-synapse-occ-fdic-subcontractor-monitoring/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-21-fourth-party-risk-synapse-occ-fdic-subcontractor-monitoring/</guid><description>Synapse collapsed and 100,000+ customers lost access to $265M in deposits they thought were FDIC-insured. The cause wasn&apos;t fraud — it was middleware risk nobody was watching. Here&apos;s what OCC and FDIC now expect from your fourth-party and subcontractor oversight program.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The GENIUS Act Missed Its Own Deadline. Here&apos;s Your Stablecoin Compliance Playbook for the Six-Month Countdown to January 2027.</title><link>https://risktemplate.com/blog/2026-07-20-genius-act-deadline-missed-stablecoin-compliance-january-2027/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-20-genius-act-deadline-missed-stablecoin-compliance-january-2027/</guid><description>The July 18, 2026 statutory deadline for GENIUS Act implementing regulations came and went with zero final rules. The law still takes effect January 18, 2027. Here&apos;s what stablecoin issuers, custodians, and compliance teams should be building right now — using proposed rules as a working framework.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The $1M Yotta Fine Shows That &apos;FDIC-Insured&apos; Is a Compliance Claim, Not a Marketing Tagline</title><link>https://risktemplate.com/blog/2026-07-20-yotta-dfpi-fdic-insurance-marketing-compliance-fintech/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-20-yotta-dfpi-fdic-insurance-marketing-compliance-fintech/</guid><description>California&apos;s DFPI fined Yotta Technologies $1 million for telling 18,000 customers their deposits were FDIC-insured while moving their funds to an entity with no such coverage — even as the CEO&apos;s internal messages showed he knew it was happening. Here&apos;s what every fintech marketing and compliance team needs to take from this case.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Three Clocks, One Incident: How to Manage the Overlapping Cyber Notification Timelines Under OCC, NYDFS, and SEC Rules</title><link>https://risktemplate.com/blog/2026-07-19-cyber-incident-notification-timelines-occ-nydfs-sec-overlap-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-19-cyber-incident-notification-timelines-occ-nydfs-sec-overlap-financial-institutions/</guid><description>When a cyber incident hits, you&apos;re not managing one notification obligation — you&apos;re managing six, with different triggers, different recipients, and different clocks. The OCC&apos;s 36-hour rule, NYDFS&apos;s 72-hour requirement, the SEC&apos;s 4-business-day materiality window, GLBA customer notices, FinCEN SAR filing, and bank partner contractual obligations all run simultaneously. Here&apos;s how to track them without missing one.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Sign or Skip: The EU AI Act Transparency Code of Practice Decision Financial Services Firms Have Three Days to Make</title><link>https://risktemplate.com/blog/2026-07-19-eu-ai-act-transparency-code-of-practice-july-22-deadline-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-19-eu-ai-act-transparency-code-of-practice-july-22-deadline-financial-services/</guid><description>The EU Commission published the final Code of Practice on Transparency of AI-Generated Content on July 8, 2026, and the signatory deadline is July 22 at 18:00 CET. Signing gives you preferential regulatory positioning for Article 50 enforcement that begins August 2. Here&apos;s what financial services firms need to know before deciding.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The October 2025 AWS Outage Was a BCP Exam That Most Fintechs Didn&apos;t Know They Were Taking</title><link>https://risktemplate.com/blog/2026-07-18-cloud-concentration-risk-bcp-aws-outage-fintech-ffiec/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-18-cloud-concentration-risk-bcp-aws-outage-fintech-ffiec/</guid><description>A 15-hour AWS outage in October 2025 locked customers out of financial accounts and froze transactions across 1,000+ companies — and exposed how few fintechs had actually stress-tested their cloud concentration risk. Here&apos;s what the FFIEC BCM handbook requires, what the OCC&apos;s 2026 report found, and what your BCP needs to say about single-provider dependency.</description><pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The Fed Changed the Math on Self-Disclosure: What the Revised Supervisory Operating Principles Mean for Your Issues Program</title><link>https://risktemplate.com/blog/2026-07-18-federal-reserve-supervisory-operating-principles-self-disclosure-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-18-federal-reserve-supervisory-operating-principles-self-disclosure-compliance/</guid><description>On April 30, 2026, the Federal Reserve released a revised Statement of Supervisory Operating Principles with two policy changes that make self-identifying problems genuinely worthwhile. Self-disclosed deficiencies now get supervisory observation treatment instead of MRAs — if you start remediating promptly. Here&apos;s what that means and how to make your issues management program work for you in exams.</description><pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Oregon&apos;s Privacy Law Has a Feature No Other State Has — and Financial Services Companies Are Probably in Scope</title><link>https://risktemplate.com/blog/2026-07-18-oregon-consumer-privacy-act-glba-exemption-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-18-oregon-consumer-privacy-act-glba-exemption-financial-services/</guid><description>The Oregon Consumer Privacy Act&apos;s 30-day cure period ended January 1, 2026. The AG can now sue without notice. More importantly for financial services: the GLBA exemption is narrower than most assume, fintechs have significant exposure on non-NPI data, and Oregon requires something no other state does — a list of the specific named third parties that received consumer data.</description><pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The Flagstar Blueprint: What the SEC&apos;s $3.5M Fine Teaches Every Financial Institution About Cyber Incident Disclosure</title><link>https://risktemplate.com/blog/2026-07-18-sec-cybersecurity-disclosure-8k-flagstar-incident-response-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-18-sec-cybersecurity-disclosure-8k-flagstar-incident-response-financial-institutions/</guid><description>In December 2024, Flagstar Bancorp paid $3.5M to settle SEC charges that it made misleading statements about a 2021 cyberattack — including disclosures that said no customer data was compromised when the company already knew 1.5 million records had been stolen. Here&apos;s what the SEC&apos;s growing cyber enforcement record means for your incident response program.</description><pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CFPB&apos;s July 2026 Regulatory Agenda: Five Things Compliance Teams Need to Act On Before Year-End</title><link>https://risktemplate.com/blog/2026-07-17-cfpb-2026-regulatory-agenda-h2-compliance-calendar/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-17-cfpb-2026-regulatory-agenda-h2-compliance-calendar/</guid><description>On July 6, the CFPB released its semiannual regulatory agenda — payday NPRM, Section 1033 do-over, mortgage servicing overhaul, and a 64% cut to nonbank exams. Here&apos;s what each item actually means and what compliance teams need to do before December.</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Connecticut&apos;s CTDPA Just Got a Lot Bigger — And Fintechs May Not Know They&apos;re Covered</title><link>https://risktemplate.com/blog/2026-07-17-connecticut-ctdpa-2026-amendments-fintech-nonbank-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-17-connecticut-ctdpa-2026-amendments-fintech-nonbank-financial-services/</guid><description>Connecticut&apos;s CTDPA expanded on July 1, 2026 — lower thresholds, narrowed GLBA exemption, eliminated cure period, new profiling impact assessments. Here&apos;s what fintechs and nonbank lenders need to do now.</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate></item><item><title>3,383 Incidents Later: What DORA&apos;s First ICT Data Reveals About Your Operational Risk Program</title><link>https://risktemplate.com/blog/2026-07-17-dora-first-ict-incident-report-2025-third-party-operational-risk-lessons/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-17-dora-first-ict-incident-report-2025-third-party-operational-risk-lessons/</guid><description>The ESAs published their first DORA ICT incident report in June 2026 — 3,383 major incidents, nearly one-third from third-party failures, only 10% cyber-related. Here&apos;s what the data means for your operational risk program.</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate></item><item><title>What TPRM Examiners Are Actually Finding Three Years Into the Interagency Guidance</title><link>https://risktemplate.com/blog/2026-07-17-interagency-tprm-guidance-2026-exam-findings-occ-fdic/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-17-interagency-tprm-guidance-2026-exam-findings-occ-fdic/</guid><description>OCC Bulletin 2023-17 and FDIC FIL-29-2023 turned three in June. Third-party risk programs that looked solid at launch are showing cracks under examination — incomplete due diligence, weak ongoing monitoring, critical activity designations that don&apos;t hold up, and subcontractor gaps that no one mapped. Here&apos;s what&apos;s getting flagged and what to fix.</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate></item><item><title>FinCEN&apos;s AML/CFT Overhaul Is the Biggest BSA Change in Decades. Here&apos;s What Your Compliance Program Needs Before the Final Rule.</title><link>https://risktemplate.com/blog/2026-07-16-fincen-aml-cft-program-overhaul-2026-compliance-program/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-16-fincen-aml-cft-program-overhaul-2026-compliance-program/</guid><description>FinCEN&apos;s April 2026 NPRM would fundamentally reform AML/CFT program requirements for every financial institution — and the Federal Reserve just issued its own separate proposal. Here&apos;s what the effectiveness mandate, risk assessment overhaul, and &apos;significant or systemic&apos; enforcement standard mean for your compliance team.</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The GENIUS Act&apos;s July 18 Deadline Arrives With No Final Rules. Here&apos;s What Stablecoin Compliance Teams Need to Know.</title><link>https://risktemplate.com/blog/2026-07-16-genius-act-july-18-deadline-no-final-rules-stablecoin-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-16-genius-act-july-18-deadline-no-final-rules-stablecoin-2026/</guid><description>July 18, 2026 was the statutory deadline for seven federal agencies to finalize GENIUS Act stablecoin rules. Six agencies, eight proposed rules, zero finals — and no fallback mechanism in the statute. Here&apos;s what the regulatory void means for stablecoin issuers, custodians, and the compliance teams supporting them.</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate></item><item><title>NYDFS Part 500 in 2026: What 27 Consent Orders and $144M in Fines Tell You About Examiner Priorities</title><link>https://risktemplate.com/blog/2026-07-16-nydfs-part-500-2026-enforcement-consent-orders-exam-findings/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-16-nydfs-part-500-2026-enforcement-consent-orders-exam-findings/</guid><description>All Part 500 amended requirements are now in effect. NYDFS has 27 consent orders and $144M in fines under its belt. Here&apos;s what examiners are finding — and what to do before they show up at your door.</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI-Enhanced Fraud Is Now the OCC&apos;s Top Operational Risk Concern. Here&apos;s What That Means for Your Fraud Risk Program.</title><link>https://risktemplate.com/blog/2026-07-16-occ-spring-2026-fraud-risk-program-operational-risk-ai-enhanced/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-16-occ-spring-2026-fraud-risk-program-operational-risk-ai-enhanced/</guid><description>The OCC&apos;s Spring 2026 Risk Perspective named fraud the primary driver of operational losses. But having a fraud operations team isn&apos;t a fraud risk program — examiners want second-line oversight, documented loss events, and KRIs that signal emerging exposure.</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Cyber Insurance Claims for Financial Institutions: Why Claims Get Denied in 2026 — and What You Must Document Before You Need to File</title><link>https://risktemplate.com/blog/2026-07-15-cyber-insurance-claims-financial-institutions-documentation-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-15-cyber-insurance-claims-financial-institutions-documentation-2026/</guid><description>Claim denial rates have risen sharply as carriers shift from self-attestation to evidence-based verification. Here&apos;s what financial institutions must document before an incident — and why a denied claim still leaves you facing a regulatory examination.</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Fannie Mae LL-2026-04: What Mortgage Sellers and Servicers Must Build Before August 6 — and Why Freddie Mac&apos;s March 3 Deadline Already Exposed Gaps</title><link>https://risktemplate.com/blog/2026-07-15-fannie-mae-ll-2026-04-ai-governance-mortgage-sellers-servicers-august-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-15-fannie-mae-ll-2026-04-ai-governance-mortgage-sellers-servicers-august-2026/</guid><description>Fannie Mae&apos;s AI/ML governance framework (LL-2026-04) takes effect August 6, 2026. Freddie Mac&apos;s equivalent hit March 3. Both cover all AI in origination and servicing, including vendor tools. Here&apos;s what a compliant program actually looks like.</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate></item><item><title>OCC Bulletin 2026-29: What the New Loan Portfolio Management Handbook Means for Your Credit Risk Controls and Exam Prep</title><link>https://risktemplate.com/blog/2026-07-15-occ-bulletin-2026-29-lending-loan-portfolio-risk-management-examination/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-15-occ-bulletin-2026-29-lending-loan-portfolio-risk-management-examination/</guid><description>OCC Bulletin 2026-29, issued June 25, 2026, replaces the 1998 lending handbook and rewrites examiner expectations for loan portfolio risk management. Here&apos;s what changed, what examiners will now test, and how to update your RCSA before your next safety-and-soundness exam.</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate></item><item><title>SEC&apos;s &apos;Back to Basics&apos; Enforcement Pivot: What the 2026 Mid-Year Update Means for Investment Advisers and Broker-Dealers</title><link>https://risktemplate.com/blog/2026-07-15-sec-enforcement-2026-back-to-basics-fraud-focus-off-channel-investment-advisers/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-15-sec-enforcement-2026-back-to-basics-fraud-focus-off-channel-investment-advisers/</guid><description>The SEC has rescinded its no-deny settlement rule, backed away from off-channel enforcement, and refocused on fraud, fiduciary breaches, and direct investor harm. Here&apos;s how compliance programs need to adapt — and what FINRA is still doing.</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate></item><item><title>California&apos;s ADMT Rules Are Live: What Banks and Fintechs Get Wrong About the GLBA Exemption</title><link>https://risktemplate.com/blog/2026-07-14-california-admt-rules-glba-exemption-financial-services-cppa-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-14-california-admt-rules-glba-exemption-financial-services-cppa-2026/</guid><description>The CPPA finalized ADMT regulations effective January 1, 2026 — and California&apos;s GLBA exemption is narrower than you think. Here&apos;s what financial institutions and fintechs actually need to do about automated decision-making, opt-out rights, and risk assessments.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate></item><item><title>SEC Marketing Rule Compliance in 2026: The Deficiencies Examiners Are Finding — and What to Fix Before They Show Up</title><link>https://risktemplate.com/blog/2026-07-14-sec-marketing-rule-deficiencies-testimonials-endorsements-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-14-sec-marketing-rule-deficiencies-testimonials-endorsements-2026/</guid><description>The SEC&apos;s December 2025 risk alert on Marketing Rule deficiencies is a blueprint for your next exam. Here&apos;s what advisers are getting wrong on testimonials, endorsements, and third-party ratings — and the specific fixes to make before examiners arrive.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Shadow AI in Financial Services: What the First SEC Form 8-K, the GLBA Safeguards Rule, and OCC 2026-13 Mean for Your Undocumented AI Inventory</title><link>https://risktemplate.com/blog/2026-07-14-shadow-ai-financial-services-sec-8k-glba-safeguards-occ-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-14-shadow-ai-financial-services-sec-8k-glba-safeguards-occ-2026/</guid><description>On May 11, 2026, CB Financial Services filed the first SEC Form 8-K triggered by an employee&apos;s unauthorized use of an AI tool — not an external attack. Here&apos;s what the GLBA Safeguards Rule, OCC 2026-13, and three other frameworks say your institution is responsible for managing, even when you don&apos;t know the tools exist.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Trump&apos;s Fintech Executive Order: What the August and November 2026 Regulatory Deadlines Mean for Your Charter, Partnership, and Payment Strategy</title><link>https://risktemplate.com/blog/2026-07-14-trump-fintech-executive-order-august-november-2026-deadlines/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-14-trump-fintech-executive-order-august-november-2026-deadlines/</guid><description>The May 2026 executive order on fintech innovation set hard deadlines for every major federal financial regulator. The 90-day review window closes August 17. Here&apos;s what compliance teams at banks and fintechs need to track — and what won&apos;t change regardless of what regulators produce.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate></item><item><title>FDIC&apos;s Confidential Information Overhaul: What Banks and Their Fintech Partners Can Now Share Without Prior Approval</title><link>https://risktemplate.com/blog/2026-07-13-fdic-confidential-supervisory-information-rule-bank-fintech-data-sharing/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-13-fdic-confidential-supervisory-information-rule-bank-fintech-data-sharing/</guid><description>The FDIC&apos;s June 2026 proposed rule — the first major revision to its confidential information disclosure framework in approximately 30 years — would let banks share confidential supervisory information with fintech partners, auditors, and M&amp;A counterparties without needing prior FDIC authorization. Comments are due August 31. Here&apos;s what changes and what your contracts need to reflect.</description><pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate></item><item><title>FFIEC CAT Sunset: What Banks and Credit Unions Should Use Instead in 2026 — and What Examiners Now Expect</title><link>https://risktemplate.com/blog/2026-07-13-ffiec-cybersecurity-assessment-tool-retirement-replacement-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-13-ffiec-cybersecurity-assessment-tool-retirement-replacement-2026/</guid><description>The FFIEC Cybersecurity Assessment Tool retired August 31, 2025, with no mandated replacement. NIST CSF 2.0 has become the de facto industry choice, but the transition isn&apos;t just swapping one framework for another. Here&apos;s what changed, what examiners look for now, and the documentation gaps most institutions missed.</description><pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The OCC National Trust Bank Charter: What Circle&apos;s July 10 Approval and the GENIUS Act January 2027 Deadline Mean for Every Stablecoin Issuer Still on the Sidelines</title><link>https://risktemplate.com/blog/2026-07-13-occ-national-trust-bank-charter-stablecoin-issuer-genius-act-2027/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-13-occ-national-trust-bank-charter-stablecoin-issuer-genius-act-2027/</guid><description>Circle&apos;s final OCC approval on July 10, 2026 marks a turning point in crypto regulation. With the GENIUS Act&apos;s January 18, 2027 enforcement deadline approaching, stablecoin issuers that haven&apos;t started the charter application process are already behind. Here&apos;s what the charter actually requires — and what it doesn&apos;t.</description><pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Software Supply Chain Failure BCP Scenarios: What FFIEC Guidance and Post-CrowdStrike Expectations Require Financial Institutions to Test in 2026</title><link>https://risktemplate.com/blog/2026-07-13-software-supply-chain-bcp-testing-ffiec-crowdstrike-scenarios-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-13-software-supply-chain-bcp-testing-ffiec-crowdstrike-scenarios-2026/</guid><description>A year after CrowdStrike brought down 8.5 million Windows devices and cost the banking sector $1.149 billion, financial institution BCP programs are expected to test software supply chain failure scenarios explicitly. Here&apos;s what changed in FFIEC guidance, what examiners now look for, and how to build a scenario that holds up.</description><pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate></item><item><title>What the Reg B Change Didn&apos;t Touch: AI Credit Model Compliance After July 21</title><link>https://risktemplate.com/blog/2026-07-12-ai-credit-model-adverse-action-cfpb-requirements-july-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-12-ai-credit-model-adverse-action-cfpb-requirements-july-2026/</guid><description>CFPB&apos;s July 21 Reg B amendment removes disparate impact from ECOA—but three enforcement frameworks survived intact. Here&apos;s what AI credit model compliance actually looks like after the change, and where the real exam risk sits.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate></item><item><title>SEC 2026 Examination Priorities: What Investment Advisers, Broker-Dealers, and Compliance Teams Are Getting Tested On</title><link>https://risktemplate.com/blog/2026-07-12-sec-2026-examination-priorities-investment-advisers-broker-dealers/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-12-sec-2026-examination-priorities-investment-advisers-broker-dealers/</guid><description>The SEC Division of Examinations released its FY 2026 priorities on November 17, 2025. Here&apos;s what&apos;s new, what changed from 2025, and the specific controls investment advisers and broker-dealers need to document before examiners arrive.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate></item><item><title>After the CFPB Stepped Back: Who&apos;s Supervising Your Fintech in 2026 — and What They&apos;re Actually Looking For</title><link>https://risktemplate.com/blog/2026-07-12-state-ag-cfpb-enforcement-fintech-ewa-bnpl-compliance-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-12-state-ag-cfpb-enforcement-fintech-ewa-bnpl-compliance-2026/</guid><description>The CFPB&apos;s 2025 enforcement pullback didn&apos;t reduce regulatory risk for fintechs — it redistributed it. New York sued EWA providers. California expanded DFPI UDAAP authority. New Jersey issued a junk fees enforcement statement. Here&apos;s the new enforcement map and what your compliance program needs to address.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Vendor Exit Plans: What OCC 2023-17 Requires, What Examiners Actually Test, and Where Programs Keep Failing</title><link>https://risktemplate.com/blog/2026-07-12-vendor-exit-plan-occ-2023-17-tprm-critical-third-party/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-12-vendor-exit-plan-occ-2023-17-tprm-critical-third-party/</guid><description>OCC 2023-17&apos;s fifth lifecycle stage — termination — is where TPRM documentation is thin, testing is rare, and examination findings are accumulating. Here&apos;s what a defensible vendor exit plan actually contains and the five gaps that generate MRAs.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate></item><item><title>10 Days to July 21: The SPCP Changes Every For-Profit Lender Missed in the Reg B Overhaul</title><link>https://risktemplate.com/blog/2026-07-11-cfpb-reg-b-spcp-for-profit-lenders-july-21-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-11-cfpb-reg-b-spcp-for-profit-lenders-july-21-2026/</guid><description>While everyone was reading about disparate impact, a harder compliance problem was buried in the CFPB&apos;s Reg B overhaul: for-profit lenders can no longer use race, national origin, or sex as SPCP eligibility criteria. Here&apos;s the checklist before July 21.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Cloud Provider Concentration Risk: What OCC Examiners Now Expect When AWS, Azure, or GCP Is Critical Infrastructure</title><link>https://risktemplate.com/blog/2026-07-11-cloud-provider-concentration-risk-occ-tprm-examination-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-11-cloud-provider-concentration-risk-occ-tprm-examination-2026/</guid><description>Your bank relies on AWS, Azure, or GCP for critical operations. OCC examiners are asking hard questions about cloud dependency mapping, exit strategies, and concentration risk. Here&apos;s what they want to see—and where programs keep falling short.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate></item><item><title>OCC&apos;s $700 Billion Threshold Proposal: What Banks Between $50B and $700B Need to Do with Their Risk Governance Frameworks</title><link>https://risktemplate.com/blog/2026-07-11-occ-heightened-standards-700b-threshold-risk-governance-midsize-banks/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-11-occ-heightened-standards-700b-threshold-risk-governance-midsize-banks/</guid><description>The OCC&apos;s proposed rule would cut the number of banks subject to heightened standards from 38 to 8—releasing 30 mid-size banks from formal risk governance requirements. Here&apos;s what risk officers at those banks need to think through before dismantling anything.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Rhode Island RIDTPPA at Six Months: What the GLBA Exemption Actually Covers for Financial Services Firms</title><link>https://risktemplate.com/blog/2026-07-11-rhode-island-ridtppa-glba-exemption-financial-services-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-11-rhode-island-ridtppa-glba-exemption-financial-services-2026/</guid><description>Rhode Island&apos;s Data Transparency and Privacy Protection Act has been in effect since January 1, 2026. If you&apos;re a financial services firm relying on the GLBA exemption, here&apos;s what it covers, what it doesn&apos;t, and the no-cure-period enforcement risk you&apos;re carrying.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate></item><item><title>When One Cyber Incident Triggers Four Notification Clocks: Sequencing FFIEC, CIRCIA, SEC, and State Breach Law Obligations</title><link>https://risktemplate.com/blog/2026-07-10-cyber-incident-multi-regulator-notification-sequencing-ffiec-circia-sec/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-10-cyber-incident-multi-regulator-notification-sequencing-ffiec-circia-sec/</guid><description>A single cyber incident at a bank or fintech can simultaneously trigger the FFIEC 36-hour rule, CIRCIA&apos;s 72-hour CISA notification, the SEC&apos;s 4-business-day Form 8-K requirement, and state breach notification deadlines — each starting from a different legal trigger. Here&apos;s how to sequence them without missing one.</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate></item><item><title>EU AI Act Article 50 Is 23 Days Away: The Chatbot Disclosure, Deepfake Labeling, and AI Content Transparency Checklist for Financial Services</title><link>https://risktemplate.com/blog/2026-07-10-eu-ai-act-article-50-transparency-chatbot-disclosure-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-10-eu-ai-act-article-50-transparency-chatbot-disclosure-financial-services/</guid><description>EU AI Act Article 50 transparency obligations take effect August 2, 2026. Customer-facing chatbots must disclose AI status at first interaction. Deepfakes must be labeled. AI-generated public interest content must be flagged. Here&apos;s what financial services firms must do — and why the July 22 Code of Practice deadline still matters.</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Hurricane Season BCP Testing: What FFIEC Examiners Expect Financial Institutions to Document Before October</title><link>https://risktemplate.com/blog/2026-07-10-hurricane-season-bcp-testing-ffiec-financial-institutions-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-10-hurricane-season-bcp-testing-ffiec-financial-institutions-2026/</guid><description>Atlantic hurricane season peaks in August–October. Most financial institution BCP programs won&apos;t survive an FFIEC examination if they haven&apos;t run a geographic threat scenario this year. Here&apos;s what examiners look for, what documentation you need, and the exercise vs. test distinction that keeps programs from getting credit for work they actually did.</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate></item><item><title>MiCA&apos;s Transition Window Just Closed: What US Crypto Companies Still Serving EU Clients Must Do Now</title><link>https://risktemplate.com/blog/2026-07-10-mica-transition-deadline-us-crypto-companies-eu-casp-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-10-mica-transition-deadline-us-crypto-companies-eu-casp-compliance/</guid><description>The 18-month MiCA transitional period for crypto-asset service providers ended June 30, 2026. US exchanges and crypto firms that continue serving EU clients without authorization risk fines up to €5M or 3% of global turnover enforced simultaneously across 27 EU jurisdictions. Here&apos;s what changed, what the reverse solicitation exception actually allows, and the three paths forward.</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI-Powered BEC Stole $3 Billion in 2025: What Your Incident Response Playbook Is Missing</title><link>https://risktemplate.com/blog/2026-07-09-ai-bec-wire-fraud-incident-response-playbook-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-09-ai-bec-wire-fraud-incident-response-playbook-2026/</guid><description>The FBI&apos;s 2025 IC3 report logged $3.046 billion in BEC losses—86% via wire or ACH—with AI now generating the emails, cloning the voices, and running the deepfakes. Most financial institution IR playbooks were written before this threat existed. Here&apos;s the gap analysis and what to add before the next one hits.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Connecticut&apos;s CDPA Took Effect Last Tuesday: Financial Account Data Is Now Sensitive Data, the Threshold Dropped to 35,000, and There&apos;s No 60-Day Grace Period</title><link>https://risktemplate.com/blog/2026-07-09-connecticut-cdpa-july-2026-fintech-nonbank-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-09-connecticut-cdpa-july-2026-fintech-nonbank-compliance/</guid><description>Connecticut&apos;s expanded CDPA took effect July 1, 2026. It lowered the applicability threshold from 100,000 to 35,000 consumers, reclassified financial account information as sensitive data requiring consent before processing or sale, eliminated the guaranteed 60-day cure period, and stripped the entity-level GLBA exemption from fintechs and nonbank lenders. Here&apos;s what changed and what your program needs to address this week.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate></item><item><title>1,155 Violations and $1.2 Billion in Restitution: What the FDIC&apos;s Spring 2026 Supervisory Highlights Say About Where Your Program Gets Tested</title><link>https://risktemplate.com/blog/2026-07-09-fdic-spring-2026-consumer-compliance-supervisory-highlights/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-09-fdic-spring-2026-consumer-compliance-supervisory-highlights/</guid><description>The FDIC&apos;s Spring 2026 Consumer Compliance Supervisory Highlights documented 1,155 violations from 2025 exams — with TILA/Reg Z alone accounting for 462, flood insurance violations generating $150 million in orders, and formal enforcement actions requiring $1.2 billion in restitution. Here&apos;s how to use the FDIC&apos;s own findings as a self-assessment checklist before your next examination.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate></item><item><title>FinCEN&apos;s June 2026 Update Turns Section 314(b) Into a Real-Time Fraud-Fighting Tool</title><link>https://risktemplate.com/blog/2026-07-09-fincen-314b-fraud-information-sharing-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-09-fincen-314b-fraud-information-sharing-financial-institutions/</guid><description>FinCEN&apos;s June 12, 2026 guidance expanded the Section 314(b) safe harbor to explicitly cover fraud—wire fraud, bank fraud, mail fraud, computer fraud—without requiring an institution to connect the activity to money laundering first. Here&apos;s what changed, why it matters for BSA programs, and what enrollment and real-time sharing actually look like in practice.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate></item><item><title>KRI Library vs. Building Your KRIs From Scratch: An Honest Comparison</title><link>https://risktemplate.com/blog/2026-07-09-kri-library-vs-building-kris-from-scratch/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-09-kri-library-vs-building-kris-from-scratch/</guid><description>Buy a pre-built KRI library or derive key risk indicators internally? Real thresholds, real trade-offs, and where each approach actually wins.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Risk Register Template: Free Download vs. Paid vs. Building Your Own</title><link>https://risktemplate.com/blog/2026-07-09-risk-register-template-free-vs-paid-vs-build-your-own/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-09-risk-register-template-free-vs-paid-vs-build-your-own/</guid><description>Free risk register template, paid toolkit, or build from scratch? An honest three-way comparison — time to deploy, coverage, maintenance, and when each wins.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The Fed&apos;s Payment Account Proposal: What Fintechs and Digital Asset Firms Need to Know Before the July 27 Comment Deadline</title><link>https://risktemplate.com/blog/2026-07-08-federal-reserve-payment-account-fintech-access-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-08-federal-reserve-payment-account-fintech-access-2026/</guid><description>The Federal Reserve proposed a special-purpose Payment Account in May 2026, offering eligible fintechs direct access to Fedwire Funds and FedNow without a bank charter. The comment period closes July 27. Here&apos;s who qualifies, what compliance the Fed requires, and why your institution should care even if you&apos;re not applying yet.</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The Marquis Software Breach: What 80 Banks and Credit Unions Need to Learn About Vendor Concentration Risk</title><link>https://risktemplate.com/blog/2026-07-08-marquis-software-ransomware-breach-vendor-concentration-risk-banks/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-08-marquis-software-ransomware-breach-vendor-concentration-risk-banks/</guid><description>In August 2025, Akira ransomware hit Marquis Software Solutions through an unpatched SonicWall firewall. By the time breach notifications went out—over two months later—80 banks and credit unions had been exposed, 824,000 consumers&apos; data was compromised, and a ransom had reportedly been paid. Here&apos;s what your third-party risk program should take from it.</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate></item><item><title>What the OCC&apos;s CFSB Consent Order Says About BSA/AML Risk in Fintech Payment Partnerships</title><link>https://risktemplate.com/blog/2026-07-08-occ-cfsb-consent-order-bsa-aml-fintech-sponsor-bank-payment-processing/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-08-occ-cfsb-consent-order-bsa-aml-fintech-sponsor-bank-payment-processing/</guid><description>On May 21, 2026, the OCC released a consent order against Community Federal Savings Bank—sponsor bank for Wise and Crypto.com—for BSA/AML failures tied directly to rapid payment processing growth. The core problem wasn&apos;t the fintech partners. It was that alert tuning, CDD, and staffing never scaled with transaction volume. Here&apos;s the operational risk lesson for every institution growing through fintech relationships.</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate></item><item><title>OCC&apos;s 2026 Exam Rightsizing: What Community Banks Should Stop Doing—and What Still Gets You Written Up</title><link>https://risktemplate.com/blog/2026-07-08-occ-community-bank-exam-rightsizing-2026-bulletin-2025-24/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-08-occ-community-bank-exam-rightsizing-2026-bulletin-2025-24/</guid><description>Effective January 1, 2026, OCC Bulletin 2025-24 eliminated mandatory examination activities that aren&apos;t required by law for community banks. That means fair lending risk assessments and flood insurance transaction testing are no longer mandatory every exam cycle. Here&apos;s what actually changed, what didn&apos;t, and where compliance teams are misreading this shift.</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Agentic AI in Financial Services 2026: The Governance Framework Your Board Doesn&apos;t Know It Needs</title><link>https://risktemplate.com/blog/2026-07-07-agentic-ai-governance-framework-financial-services-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-07-agentic-ai-governance-framework-financial-services-2026/</guid><description>SR 26-2 carved agentic AI out of model risk scope in April 2026. That didn&apos;t make the risk disappear — it moved the governance burden entirely onto you. Here&apos;s what a functional agentic AI governance framework looks like and why you need one before your next exam.</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The 2026 CRE Loan Maturity Wall: How Community Banks Should Stress-Test Their Commercial Real Estate Portfolios Right Now</title><link>https://risktemplate.com/blog/2026-07-07-cre-loan-maturity-wall-2026-community-bank-stress-testing/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-07-cre-loan-maturity-wall-2026-community-bank-stress-testing/</guid><description>More than $1.5 trillion in commercial real estate loans mature in 2026. Roughly 31% of all U.S. banks are CRE-concentrated. Here&apos;s the stress-testing methodology community banks need — before examiners ask for it.</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI Foundation Model Concentration Risk: When Your Entire AI Stack Depends on Three Vendors</title><link>https://risktemplate.com/blog/2026-07-06-ai-foundation-model-concentration-risk-tprm-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-06-ai-foundation-model-concentration-risk-tprm-financial-institutions/</guid><description>The Cambridge Centre for Alternative Finance&apos;s 2026 report found 76% of financial institutions rely on OpenAI, 57% on Google, and 35% on Anthropic — while 63% build on external models rather than their own. Under OCC 2023-17 and DORA, that&apos;s not just an AI strategy question. It&apos;s a third-party concentration risk your TPRM program probably isn&apos;t mapped to address.</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Biometric Data in Financial Services: The BIPA Exemption Isn&apos;t as Broad as Your Vendors Think</title><link>https://risktemplate.com/blog/2026-07-06-biometric-data-financial-services-bipa-vendor-exemption-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-06-biometric-data-financial-services-bipa-vendor-exemption-compliance/</guid><description>Financial institutions have a GLBA-based exemption from Illinois&apos; Biometric Information Privacy Act — but courts are actively splitting on whether that exemption extends to your KYC and identity verification vendors. Two unsettled circuit questions, $100M+ in recent settlements, and what your vendor contracts need to say before the 7th Circuit decides.</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate></item><item><title>KYC in the Deepfake Era: Why Document + Selfie Verification Is Failing and What Actually Works</title><link>https://risktemplate.com/blog/2026-07-06-kyc-deepfake-document-fraud-identity-proofing-fincen-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-06-kyc-deepfake-document-fraud-identity-proofing-fincen-2026/</guid><description>FinCEN&apos;s November 2024 alert formally put financial institutions on notice that AI-generated deepfakes are bypassing KYC onboarding at scale. Here&apos;s what&apos;s failing in the document+selfie stack, what examiners expect, and which controls are working in 2026.</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate></item><item><title>SEC Cyber Disclosure Rule: What 2.5 Years of Form 8-K Filings Reveal About Your Response Program Gaps</title><link>https://risktemplate.com/blog/2026-07-06-sec-cyber-disclosure-rule-8k-item-105-materiality-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-06-sec-cyber-disclosure-rule-8k-item-105-materiality-2026/</guid><description>The SEC&apos;s 4-business-day cyber incident disclosure rule has 2.5 years of enforcement history. Here&apos;s what the filings and enforcement actions reveal about common materiality determination failures — and how to build a decision protocol that survives SEC scrutiny in 2026.</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate></item><item><title>GENIUS Act AML/CFT Compliance: Breaking Down the FinCEN and OFAC Rule That Drops July 18</title><link>https://risktemplate.com/blog/2026-07-05-genius-act-aml-compliance-stablecoin-issuer-fincen-ofac/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-05-genius-act-aml-compliance-stablecoin-issuer-fincen-ofac/</guid><description>The FinCEN/OFAC joint proposed rule for stablecoin issuers establishes a full BSA/AML compliance program requirement — SAR filing, CTR filing, CIP, CDD, and OFAC sanctions screening — with a technical wallet-blocking mandate that has no precedent in traditional financial services. Here&apos;s what Permitted Payment Stablecoin Issuers and their bank partners need to build.</description><pubDate>Sun, 05 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Power and Telecommunications Resilience: What the 2026 FFIEC BCM Booklet Requires You to Document and Test</title><link>https://risktemplate.com/blog/2026-07-05-power-telecom-resilience-bcp-ffiec-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-05-power-telecom-resilience-bcp-ffiec-2026/</guid><description>The 2026 FFIEC BCM Booklet elevated power and telecommunications resilience from a supporting concern to a standalone examination focus. Here&apos;s what examiners now look for in generator testing, telecom redundancy documentation, and alternate site utility independence.</description><pubDate>Sun, 05 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Breach Notification Letter Template: What the Law Requires, What Regulators Charge For, and Why Your Approval Process Fails Under Pressure</title><link>https://risktemplate.com/blog/2026-07-04-breach-notification-letter-template-customer-notice-requirements/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-04-breach-notification-letter-template-customer-notice-requirements/</guid><description>The content of a breach notification letter isn&apos;t optional — multiple regulatory frameworks specify exactly what must be in it, and enforcement actions from the FTC, SEC, and CFTC show how specific the mistakes regulators will charge you for. Here&apos;s what goes in the letter and how to build an approval process that holds up when the 30-day clock is running.</description><pubDate>Sat, 04 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Compliance Training Program Requirements: What OCC, FDIC, CFPB, and FINRA Examiners Actually Test</title><link>https://risktemplate.com/blog/2026-07-04-compliance-training-program-requirements-occ-fdic-cfpb-finra/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-04-compliance-training-program-requirements-occ-fdic-cfpb-finra/</guid><description>Most financial institutions have a training program. Fewer have one that survives examiner scrutiny. Here&apos;s what each regulator actually looks for — and the documentation gaps that turn a training calendar into an exam finding.</description><pubDate>Sat, 04 Jul 2026 00:00:00 GMT</pubDate></item><item><title>SR 26-2 for Community and Regional Banks: What the Proportionality Principle Actually Requires</title><link>https://risktemplate.com/blog/2026-07-04-sr-26-2-community-regional-bank-model-risk-proportionality/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-04-sr-26-2-community-regional-bank-model-risk-proportionality/</guid><description>SR 26-2 and OCC 2026-13 replaced SR 11-7 on April 17, 2026 — and the proportionality principle changes what model risk management looks like for banks under $100 billion. Here&apos;s what&apos;s actually required, what&apos;s still expected, and how to calibrate your program.</description><pubDate>Sat, 04 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Vendor Financial Health Monitoring: The Early Warning Program OCC 2023-17 Expects for Critical Third Parties</title><link>https://risktemplate.com/blog/2026-07-04-vendor-financial-health-monitoring-critical-third-party-occ-2023-17/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-04-vendor-financial-health-monitoring-critical-third-party-occ-2023-17/</guid><description>OCC 2023-17&apos;s ongoing monitoring phase requires active financial health surveillance for critical third-party vendors — but most institutions treat it as an annual renewal checkbox. Here&apos;s what a defensible early warning program looks like, what warning signs to track, and what the Synapse collapse demonstrated about gaps in current practice.</description><pubDate>Sat, 04 Jul 2026 00:00:00 GMT</pubDate></item><item><title>15 Days Until the GENIUS Act Regulatory Deadline: What Stablecoin Issuers Need Before July 18</title><link>https://risktemplate.com/blog/2026-07-03-genius-act-implementing-regulations-july-18-stablecoin-compliance-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-03-genius-act-implementing-regulations-july-18-stablecoin-compliance-2026/</guid><description>Six federal agencies must finalize GENIUS Act implementing regulations by July 18, 2026. Here&apos;s what the OCC capital floor, FinCEN CIP rules, and the compliance timeline mean for stablecoin issuers right now.</description><pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Liquidity Risk KRIs Beyond LCR and NSFR: The 12 Early Warning Metrics That Give You Days, Not Hours</title><link>https://risktemplate.com/blog/2026-07-03-liquidity-risk-kri-metrics-beyond-lcr-nsfr-early-warning/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-03-liquidity-risk-kri-metrics-beyond-lcr-nsfr-early-warning/</guid><description>LCR and NSFR tell regulators you&apos;re compliant. Liquidity KRIs tell you when you&apos;re three days from a crisis. Here are the 12 metrics every risk manager should be tracking — and what SVB&apos;s 31 open MRAs reveal about what happens when early warning breaks down.</description><pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Minnesota&apos;s MCDPA Has Been Enforcing Since January — Your GLBA Exemption Doesn&apos;t Cover What You Think It Does</title><link>https://risktemplate.com/blog/2026-07-03-minnesota-mcdpa-glba-exemption-fintech-compliance-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-03-minnesota-mcdpa-glba-exemption-fintech-compliance-2026/</guid><description>Minnesota&apos;s Consumer Data Privacy Act uses a data-level GLBA exemption, not an entity-level one. Non-bank fintechs have been exposed since January 31, 2026 — with no notice-to-cure period and $7,500-per-violation penalties.</description><pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate></item><item><title>SR 26-2 and OCC 2026-13: What the New Model Risk Management Guidance Changes — and the GenAI Gap Your Program Needs to Close</title><link>https://risktemplate.com/blog/2026-07-03-sr-26-2-occ-2026-13-model-risk-management-genai-gap/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-03-sr-26-2-occ-2026-13-model-risk-management-genai-gap/</guid><description>The interagency guidance that replaced SR 11-7 on April 17, 2026 is voluntary and principles-based — and it explicitly excludes generative AI and agentic AI from scope. Here&apos;s what changed, what examiners will still test, and the gap your AI governance program needs to close before the AI-specific RFI lands.</description><pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Your BCP Activation Just Became a Regulatory Notification Trigger: What FCA/PRA PS26/2 Requires by March 2027</title><link>https://risktemplate.com/blog/2026-07-02-fca-pra-ps26-2-bcp-activation-regulatory-notification-march-2027/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-02-fca-pra-ps26-2-bcp-activation-regulatory-notification-march-2027/</guid><description>The FCA and PRA published PS26/2 in March 2026, establishing a new operational incident reporting regime that hardwires regulatory notification into BCP activation. Financial institutions with UK operations have until March 18, 2027 to comply. Here&apos;s what needs to change in your BCP.</description><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate></item><item><title>GENIUS Act Stablecoin Custody: The Due Diligence Framework Your TPRM Program Doesn&apos;t Cover Yet</title><link>https://risktemplate.com/blog/2026-07-02-genius-act-stablecoin-custodian-tprm-due-diligence-july-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-02-genius-act-stablecoin-custodian-tprm-due-diligence-july-2026/</guid><description>The GENIUS Act&apos;s July 18, 2026 rulemaking deadline is 16 days away. When final rules land, every bank acting as a stablecoin custodian — or relying on one — will face vendor oversight obligations your standard TPRM template wasn&apos;t built to address. Here&apos;s the framework.</description><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Colorado Replaced Its AI Law: SB 26-189 Targets Automated Decision-Making — What Financial Institutions Need Before January 1, 2027</title><link>https://risktemplate.com/blog/2026-07-01-colorado-sb-26-189-admt-financial-institutions-compliance-2027/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-01-colorado-sb-26-189-admt-financial-institutions-compliance-2027/</guid><description>Colorado&apos;s SB 24-205 was repealed and replaced by SB 26-189 before it ever took effect. The new law drops the high-risk AI framework for a consumer-focused ADMT regime — and eliminates the prudential regulator exemption banks were counting on.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate></item><item><title>EU AI Act August 2, 2026: Your 32-Day Compliance Checklist — What&apos;s Still Required After the Omnibus Deferral</title><link>https://risktemplate.com/blog/2026-07-01-eu-ai-act-august-2-2026-compliance-checklist-transparency-gpai/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-01-eu-ai-act-august-2-2026-compliance-checklist-transparency-gpai/</guid><description>The Digital Omnibus pushed Annex III high-risk AI to December 2027 — but August 2, 2026 still brings Article 50 transparency requirements and full GPAI enforcement powers. Here&apos;s your verified 32-day checklist.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate></item><item><title>FTC Health Breach Notification Rule: What Non-HIPAA Health Data Holders Must Report and When</title><link>https://risktemplate.com/blog/2026-07-01-ftc-health-breach-notification-rule-non-hipaa-health-apps-fintech/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-01-ftc-health-breach-notification-rule-non-hipaa-health-apps-fintech/</guid><description>The FTC&apos;s 2024 amendments to the Health Breach Notification Rule dramatically expanded coverage to health apps, wellness platforms, and connected devices — with enforcement actions totaling $9+ million. Here&apos;s what every fintech and non-HIPAA health data holder needs to know.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Supply Chain Cyber Incident Response for Financial Institutions: Lessons from Marquis, MOVEit, and CrowdStrike</title><link>https://risktemplate.com/blog/2026-07-01-supply-chain-cyber-incident-response-financial-institutions-third-party/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-07-01-supply-chain-cyber-incident-response-financial-institutions-third-party/</guid><description>Supply chain attacks are now the top global cyber threat. When Marquis Software ransomware hit 74+ banks and credit unions, those institutions owned the regulatory response even though their own systems were never touched. Here&apos;s the incident response playbook for incidents you didn&apos;t cause.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CIRCIA&apos;s 72-Hour Reporting Clock: What Financial Institutions Must Know Before the Final Rule Takes Effect</title><link>https://risktemplate.com/blog/2026-06-30-circia-72-hour-reporting-financial-institutions-compliance-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-30-circia-72-hour-reporting-financial-institutions-compliance-guide/</guid><description>CIRCIA adds a fourth federal reporting clock alongside FFIEC&apos;s 36-hour rule, the SEC&apos;s 4-day rule, and FTC Safeguards&apos; 30-day notification. Here&apos;s what financial services covered entities need to understand now — and the preparation steps that matter before the rule drops.</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate></item><item><title>GENIUS Act CIP Proposed Rule: Five Agencies Just Set the KYC Standard for Stablecoin Issuers — Comments Due August 21</title><link>https://risktemplate.com/blog/2026-06-30-genius-act-fincen-cip-rule-stablecoin-issuers/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-30-genius-act-fincen-cip-rule-stablecoin-issuers/</guid><description>On June 22, 2026, FinCEN and four banking regulators jointly proposed the first Customer Identification Program requirements for permitted payment stablecoin issuers. Here&apos;s what the rule requires, who it covers, and why the comment deadline matters.</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate></item><item><title>NYDFS Put Every Regulated Entity on Notice About Frontier AI Cyber Risk — Here&apos;s What the May 21 Guidance Requires</title><link>https://risktemplate.com/blog/2026-06-30-nydfs-frontier-ai-cybersecurity-guidance-may-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-30-nydfs-frontier-ai-cybersecurity-guidance-may-2026/</guid><description>On May 21, 2026, NYDFS issued two companion industry letters warning that frontier AI models will fundamentally change the speed and scale of cyberattacks against financial institutions. The guidance doesn&apos;t create new legal requirements, but it will be cited in exams. Here&apos;s what NYDFS expects and what to document.</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Regulatory Examination Readiness: The 60-Day Checklist for Banks, Credit Unions, and Fintechs</title><link>https://risktemplate.com/blog/2026-06-30-regulatory-examination-readiness-60-day-checklist-banks-fintechs/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-30-regulatory-examination-readiness-60-day-checklist-banks-fintechs/</guid><description>The notification letter arrives with 30–60 days&apos; notice. What happens in those weeks determines whether you walk out with a clean report or spend the next year managing MRAs. Here&apos;s the pre-examination preparation framework that actually reduces examination duration and findings count.</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CFPB Reg B Overhaul Takes Effect July 21: What the Disparate Impact Removal Actually Means for AI Credit Models</title><link>https://risktemplate.com/blog/2026-06-29-cfpb-reg-b-disparate-impact-removal-ai-credit-model-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-29-cfpb-reg-b-disparate-impact-removal-ai-credit-model-compliance/</guid><description>The CFPB&apos;s final rule removing disparate impact from Regulation B takes effect July 21, 2026. Here&apos;s what changed, what didn&apos;t, and what AI-driven lenders need to document before the deadline.</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Credit Risk KRIs for Fintech Lenders: DPD Buckets, Charge-Off Trends, and the Concentration Signals That Show Up in Exam Findings</title><link>https://risktemplate.com/blog/2026-06-29-credit-risk-kri-fintech-lenders-dpd-charge-off-concentration/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-29-credit-risk-kri-fintech-lenders-dpd-charge-off-concentration/</guid><description>Most fintech lenders track delinquency and charge-offs. Few connect them into a KRI framework that holds up under regulatory scrutiny. Here are the 7 credit risk metrics your risk function should be running — and the thresholds that trigger action.</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate></item><item><title>OCC&apos;s 2026 Supervisory Reset: What the Shift from Checklists to Risk-Based Judgment Means for Your Next Exam</title><link>https://risktemplate.com/blog/2026-06-29-occ-2026-supervisory-reset-risk-based-examination-community-banks/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-29-occ-2026-supervisory-reset-risk-based-examination-community-banks/</guid><description>The OCC eliminated mandatory exam activities for community banks, removed reputation risk from its toolkit, proposed narrowing MRA authority, and reorganized into bank-size-specific units. What changed, what it means for exam prep, and what examiners are still looking for in 2026.</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate></item><item><title>35% of FDIC Banks Got a TPRM Finding in 2024: What Examiners Keep Flagging and How to Fix It</title><link>https://risktemplate.com/blog/2026-06-29-tprm-fdic-examination-deficiencies-2024-interagency-guidance-gaps/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-29-tprm-fdic-examination-deficiencies-2024-interagency-guidance-gaps/</guid><description>The FDIC&apos;s 2024 Risk Review found that 35% of supervised institutions had at least one third-party risk management finding. Incomplete due diligence and inadequate ongoing monitoring are the top deficiencies. Here&apos;s what examiners are actually testing under the 2023 interagency guidance.</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate></item><item><title>AI Vendor Contract Provisions: The 7 Clauses Financial Institutions Are Missing From Their Model Agreements</title><link>https://risktemplate.com/blog/2026-06-28-ai-vendor-contract-provisions-financial-institutions-7-critical-clauses/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-28-ai-vendor-contract-provisions-financial-institutions-7-critical-clauses/</guid><description>Financial institutions using AI vendors are signing contracts that don&apos;t cover model changes, bias audits, or incident notification timelines. Here are the 7 clauses examiners expect to see—and most agreements still lack.</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Interest Rate Risk KRIs: 8 Metrics for Banks and Credit Unions Monitoring IRRBB</title><link>https://risktemplate.com/blog/2026-06-28-interest-rate-risk-kri-irrbb-metrics-banks-credit-unions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-28-interest-rate-risk-kri-irrbb-metrics-banks-credit-unions/</guid><description>SVB&apos;s collapse was a KRI failure before it was a capital failure. Here are the 8 interest rate risk in the banking book metrics your board should be seeing every quarter—and the thresholds that matter.</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Investment Adviser Compliance Programs in 2026: Why Technical Adequacy Is No Longer Enough Under SEC Rule 206(4)-7</title><link>https://risktemplate.com/blog/2026-06-28-rule-206-4-7-annual-compliance-review-investment-adviser-sec-examination/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-28-rule-206-4-7-annual-compliance-review-investment-adviser-sec-examination/</guid><description>The SEC&apos;s 2026 examination priorities put compliance program effectiveness at the center of investment adviser exams. Rule 206(4)-7 always required advisers to evaluate adequacy and effectiveness annually — but examiners are now testing that standard with specificity. Here&apos;s what a compliant annual review actually looks like.</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate></item><item><title>SEC&apos;s 2026 Division of Examinations Priorities: What Investment Advisers and Broker-Dealers Need to Fix Before Examiners Arrive</title><link>https://risktemplate.com/blog/2026-06-28-sec-2026-division-examinations-priorities-investment-advisers-broker-dealers/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-28-sec-2026-division-examinations-priorities-investment-advisers-broker-dealers/</guid><description>The SEC Division of Examinations published its 2026 examination priorities in November 2025. Here&apos;s the practitioner breakdown: fiduciary duty deficiencies, AI governance, Reg S-P incident response, Reg BI Form CRS, newly registered adviser targeting, and how the SEC&apos;s priorities overlap with FINRA&apos;s 2026 Oversight Report.</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate></item><item><title>AI Audit Trail in Financial Services: What to Log, How Long to Keep It, and What Examiners Test</title><link>https://risktemplate.com/blog/2026-06-27-ai-audit-trail-requirements-financial-services-logging-documentation/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-27-ai-audit-trail-requirements-financial-services-logging-documentation/</guid><description>OCC 2026-13, NIST AI RMF, the FS AI RMF, and EU AI Act Article 12 all require documentation for AI systems. Here&apos;s what a defensible AI audit trail contains, how long to retain it, and how agentic AI changes the calculus.</description><pubDate>Sat, 27 Jun 2026 00:00:00 GMT</pubDate></item><item><title>FINRA&apos;s 2026 Annual Regulatory Oversight Report: What Broker-Dealers and Investment Advisers Need to Fix Before Examiners Arrive</title><link>https://risktemplate.com/blog/2026-06-27-finra-2026-regulatory-oversight-report-broker-dealer-exam-prep/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-27-finra-2026-regulatory-oversight-report-broker-dealer-exam-prep/</guid><description>FINRA&apos;s nearly 90-page 2026 Annual Regulatory Oversight Report dropped in December 2025. Here&apos;s a practitioner&apos;s walkthrough of the top deficiencies — Reg BI, GenAI governance, new AML fraud typologies, cybersecurity, and third-party vendor management — and what your compliance program needs to address now.</description><pubDate>Sat, 27 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Vendor Change Notification in TPRM: How to Catch Material Changes Before They Become Operational Surprises</title><link>https://risktemplate.com/blog/2026-06-27-vendor-change-notification-tprm-material-changes/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-27-vendor-change-notification-tprm-material-changes/</guid><description>CrowdStrike&apos;s Channel File 291 update crashed 8.5 million Windows systems across financial services — and most affected institutions had no contractual right to advance notice. OCC 2023-17 and DORA both require change notification rights in vendor contracts. Here&apos;s what to require and how to operationalize it.</description><pubDate>Sat, 27 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Vendor Data Processing Agreements: The GDPR, CCPA, and State Privacy Provisions Most Financial Services Contracts Are Missing</title><link>https://risktemplate.com/blog/2026-06-27-vendor-data-processing-agreement-gdpr-ccpa-required-provisions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-27-vendor-data-processing-agreement-gdpr-ccpa-required-provisions/</guid><description>A data processing agreement isn&apos;t a checkbox — it&apos;s a legally required document with 8 mandatory provisions under GDPR Article 28 and overlapping requirements under CCPA, CPRA, and 20+ US state privacy laws. Here&apos;s what the clauses actually need to say, the sub-processor gap most contracts ignore, and the language DPAs routinely miss.</description><pubDate>Sat, 27 Jun 2026 00:00:00 GMT</pubDate></item><item><title>BCP Update Triggers: When FFIEC Requires You to Revise Your Business Continuity Plan Between Annual Reviews</title><link>https://risktemplate.com/blog/2026-06-26-bcp-update-triggers-mid-year-review-ffiec/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-26-bcp-update-triggers-mid-year-review-ffiec/</guid><description>Annual BCP review isn&apos;t enough. The FFIEC BCM Handbook and ISO 22301 both identify specific events that require mid-cycle plan updates. Here&apos;s the six-trigger framework that keeps your program defensible year-round.</description><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate></item><item><title>OCC 36-Hour Notification Rule: What Qualifies, How to File, and the Gaps Banks Keep Failing On</title><link>https://risktemplate.com/blog/2026-06-26-occ-36-hour-computer-security-incident-notification-rule/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-26-occ-36-hour-computer-security-incident-notification-rule/</guid><description>12 CFR Part 53 requires banking organizations to notify their primary federal regulator within 36 hours of a qualifying computer-security incident. Three years in, examiners are still finding the same gaps. Here&apos;s what to fix.</description><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate></item><item><title>RCSA for Fintechs: How to Build a Risk and Control Self-Assessment That Actually Holds Up in an Exam</title><link>https://risktemplate.com/blog/2026-06-26-rcsa-risk-control-self-assessment-fintech-occ-fdic-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-26-rcsa-risk-control-self-assessment-fintech-occ-fdic-2026/</guid><description>The OCC found that over half of large banks had weak operational risk and control frameworks in 2024. Outstanding supervisory findings are rising across all institution sizes. RCSA is where examiners are looking — here&apos;s how to build one that holds.</description><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Vendor Offboarding Compliance: The Exit Process Most Financial Institutions Get Wrong</title><link>https://risktemplate.com/blog/2026-06-26-vendor-offboarding-compliance-occ-exit-process/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-26-vendor-offboarding-compliance-occ-exit-process/</guid><description>Morgan Stanley&apos;s $60M OCC fine traces directly to a vendor decommissioning failure. The 2023 interagency guidance requires exit planning to start at onboarding. Here&apos;s the compliance checklist most TPRM programs are missing.</description><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate></item><item><title>BEC Incident Response for Financial Institutions: The 72-Hour Window That Changes Everything</title><link>https://risktemplate.com/blog/2026-06-25-bec-incident-response-financial-institutions-72-hour-window/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-25-bec-incident-response-financial-institutions-72-hour-window/</guid><description>Business Email Compromise caused $3.046 billion in losses in 2025. For financial institutions, the response playbook is different from ransomware — and the recovery window is measured in hours, not days. Here&apos;s what to do.</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate></item><item><title>FinCEN Delayed the Investment Adviser AML Rule to January 2028. Here&apos;s What Changes — and What Doesn&apos;t.</title><link>https://risktemplate.com/blog/2026-06-25-fincen-investment-adviser-aml-rule-delay-2028/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-25-fincen-investment-adviser-aml-rule-delay-2028/</guid><description>FinCEN published a final rule on December 31, 2025 postponing the investment adviser AML/CFT compliance deadline from January 2026 to January 2028. Here&apos;s what the delay actually says, why bank partners aren&apos;t waiting for FinCEN&apos;s timeline, and what to build in the next 18 months.</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate></item><item><title>ISO 42001 Is Not EU AI Act Compliance. But for Financial Services Firms, It&apos;s Worth Understanding What It Actually Is.</title><link>https://risktemplate.com/blog/2026-06-25-iso-42001-ai-management-system-certification-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-25-iso-42001-ai-management-system-certification-financial-services/</guid><description>ISO/IEC 42001:2023 is the international AI management system standard with direct structural alignment to EU AI Act Articles 9-17. Here&apos;s what certification means, what it doesn&apos;t substitute for, and why it&apos;s becoming a vendor selection differentiator in regulated financial services.</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate></item><item><title>State Privacy Law Enforcement in 2026: What Texas, California, and the New AG Consortium Mean for Financial Services</title><link>https://risktemplate.com/blog/2026-06-25-state-privacy-law-enforcement-2026-texas-california-ag-consortium/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-25-state-privacy-law-enforcement-2026-texas-california-ag-consortium/</guid><description>Texas filed the first-ever lawsuit under a state comprehensive privacy law in January 2025. California hit Disney with a $2.75 million CCPA fine in February 2026. Eight AGs now share enforcement intelligence through a formal consortium. The &apos;nobody is actually enforcing this&apos; assumption is over.</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Basel III Endgame&apos;s Operational Risk Capital Overhaul: What the Business Indicator Formula Means for Your Loss Data Program</title><link>https://risktemplate.com/blog/2026-06-24-basel-iii-endgame-operational-risk-capital-business-indicator-formula/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-24-basel-iii-endgame-operational-risk-capital-business-indicator-formula/</guid><description>The March 2026 Basel III endgame re-proposals replace the Advanced Measurement Approach with a standardized formula for all Category I-IV banks — subjecting Category III-IV institutions to operational risk capital requirements for the first time. Here&apos;s what op risk teams need to understand and track.</description><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The OCC and FDIC Reputation Risk Rule Is Now Effective: What Compliance Programs Must Change After June 9, 2026</title><link>https://risktemplate.com/blog/2026-06-24-occ-fdic-reputation-risk-final-rule-compliance-program-update/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-24-occ-fdic-reputation-risk-final-rule-compliance-program-update/</guid><description>The OCC and FDIC formally removed &apos;reputation risk&apos; from their supervisory frameworks on June 9, 2026. Here&apos;s what the final rule actually prohibits, what it doesn&apos;t change, and what compliance teams need to update now.</description><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate></item><item><title>BaaS Vendor Exit Planning After Synapse: What the FDIC Now Requires From Sponsor Banks and Their Fintech Partners</title><link>https://risktemplate.com/blog/2026-06-23-baas-vendor-exit-planning-synapse-fdic-sponsor-banks/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-23-baas-vendor-exit-planning-synapse-fdic-sponsor-banks/</guid><description>Synapse&apos;s 2024 bankruptcy froze $265M in customer funds and exposed a critical gap in BaaS vendor exit planning. Consent orders against Thread Bank, Evolve, and others — plus the FDIC&apos;s proposed recordkeeping rule — have now defined what &apos;adequate&apos; exit planning actually means.</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CFPB&apos;s New Enforcement Principles: What the Bilt Case Tells You About How the Bureau Intends to Police Consumer Finance</title><link>https://risktemplate.com/blog/2026-06-23-cfpb-new-enforcement-principles-2026-what-it-means-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-23-cfpb-new-enforcement-principles-2026-what-it-means-compliance/</guid><description>The CFPB published its new Enforcement Principles on June 22, 2026 — a four-pillar framework that explicitly narrows when the Bureau will pursue formal action. The Bilt case, resolved without penalties the same week, is the first real-world example of what those principles look like applied.</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The Deregulation Era Compliance Trap: Why a Lighter Federal Touch Makes Internal Controls More Important, Not Less</title><link>https://risktemplate.com/blog/2026-06-23-federal-deregulation-pivot-2026-compliance-program-maintenance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-23-federal-deregulation-pivot-2026-compliance-program-maintenance/</guid><description>Federal banking regulators have reduced exam frequency, softened model risk guidance, and repositioned enforcement as a last resort. The compliance trap is assuming that means you can do less. Here&apos;s what&apos;s actually happening to the risk landscape — and what compliance programs get wrong during deregulatory periods.</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Ransomware Response Compliance: The OFAC Sanctions Screen and FinCEN SAR Your IR Team Needs Before the Wire Goes Out</title><link>https://risktemplate.com/blog/2026-06-23-ransomware-ofac-sanctions-fincen-sar-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-23-ransomware-ofac-sanctions-fincen-sar-financial-institutions/</guid><description>OFAC can fine your organization for paying a sanctioned ransomware group even if you didn&apos;t know they were on the SDN list. With Evil Corp, Conti, and dozens of other groups designated, the sanctions analysis happens in the first hours of an incident — not after the payment.</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate></item><item><title>AI Chatbot Vendor Due Diligence: The Compliance Checklist Before Your Customer Service Bot Goes Live in a Regulated Environment</title><link>https://risktemplate.com/blog/2026-06-22-ai-chatbot-vendor-due-diligence-financial-services-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-22-ai-chatbot-vendor-due-diligence-financial-services-compliance/</guid><description>The CFPB has already flagged chatbot misinformation as a UDAAP risk. Colorado is eliminating the financial institution AI exemption in 2027. The EU AI Act&apos;s high-risk provisions are live. Before your AI chatbot vendor goes into production, here&apos;s the due diligence framework regulators expect you to have.</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate></item><item><title>AI-Powered Vishing at the Help Desk: The Authentication Controls NYDFS Is Now Requiring</title><link>https://risktemplate.com/blog/2026-06-22-ai-vishing-help-desk-authentication-controls-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-22-ai-vishing-help-desk-authentication-controls-financial-institutions/</guid><description>Vishing attacks surged 442% in H2 2024 and now dominate social engineering engagements. NYDFS issued its first vishing-specific advisory on February 6, 2026. Here&apos;s the authentication control framework — challenge protocols, identity verification procedures, and incident response steps — that regulators now expect to see.</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Maryland MODPA Is in Enforcement: The Sensitive Data Compliance Gap Fintechs Can&apos;t Cover With GLBA</title><link>https://risktemplate.com/blog/2026-06-22-maryland-modpa-sensitive-data-fintech-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-22-maryland-modpa-sensitive-data-fintech-compliance/</guid><description>Maryland&apos;s MODPA has been in enforcement since April 1, 2026 — and the GLBA entity-level exemption most fintechs assume protects them doesn&apos;t cover geolocation, biometrics, or marketing behavioral data. Here&apos;s where the gap is and what to do about it.</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Shadow AI in the 2026 Bank Exam: What Examiners Are Finding and the Inventory Problem Most Banks Haven&apos;t Solved</title><link>https://risktemplate.com/blog/2026-06-22-shadow-ai-bank-examination-2026-inventory-governance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-22-shadow-ai-bank-examination-2026-inventory-governance/</guid><description>Examiners at OCC, Fed, and FDIC have elevated AI governance to a permanent exam priority — and they&apos;re finding unauthorized AI tools embedded in workflows that no one inventoried. Here&apos;s the shadow AI problem, what the CB Financial 8-K tells you, and how to build an inventory your examiners will actually accept.</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Deepfake Voice Cloning Fraud: The Incident Response Playbook Financial Institutions Are Missing</title><link>https://risktemplate.com/blog/2026-06-21-deepfake-voice-cloning-fraud-incident-response-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-21-deepfake-voice-cloning-fraud-incident-response-financial-institutions/</guid><description>When a deepfake call beats your fraud controls and a wire goes out, you have hours — not days — to act. This playbook covers the challenge protocol before a wire clears, wire recall procedures, SAR filing for deepfake fraud, evidence preservation, and what FinCEN and the FBI expect you to have documented.</description><pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate></item><item><title>EU AI Act August 2, 2026: The Compliance Obligations That Didn&apos;t Get Deferred</title><link>https://risktemplate.com/blog/2026-06-21-eu-ai-act-august-2-2026-transparency-obligations-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-21-eu-ai-act-august-2-2026-transparency-obligations-financial-services/</guid><description>Six weeks before the EU AI Act&apos;s August 2 enforcement date, most financial services teams are focused on the wrong deadline. Annex III high-risk AI got a 16-month reprieve — but Article 50 transparency, GPAI enforcement, and a full penalty regime are still landing on schedule.</description><pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Cyber Insurance Requirements in 2026: The Evidence Underwriters Now Demand Before They Bind Coverage</title><link>https://risktemplate.com/blog/2026-06-20-cyber-insurance-requirements-2026-underwriter-controls-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-20-cyber-insurance-requirements-2026-underwriter-controls-financial-services/</guid><description>Cyber insurance underwriting shifted from questionnaire to evidence-based in 2024-2026. MFA is no longer enough to check a box — underwriters want screenshots, deployment reports, and restore test logs. For financial services firms, here&apos;s the full list of what carriers are requiring before they bind, and how to organize your evidence file.</description><pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate></item><item><title>NCUA 2026 Supervisory Priorities: What Credit Union Examiners Are Testing for AI, Lending, and BSA/AML Compliance</title><link>https://risktemplate.com/blog/2026-06-20-ncua-2026-supervisory-priorities-credit-union-exam-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-20-ncua-2026-supervisory-priorities-credit-union-exam-guide/</guid><description>The NCUA released its 2026 supervisory priorities in January — six focus areas that will define every credit union exam this year. Here&apos;s what examiners are specifically testing: loan quality metrics, AI governance documentation, BSA risk-based tailoring, third-party vendor oversight, and fraud controls for payment systems.</description><pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Basel III Endgame 2026: What the March Re-Proposal Means for Capital Planning at Regional and Community Banks</title><link>https://risktemplate.com/blog/2026-06-19-basel-iii-endgame-2026-capital-planning-regional-banks/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-19-basel-iii-endgame-2026-capital-planning-regional-banks/</guid><description>The March 2026 Basel III Endgame re-proposal just closed comments. Here&apos;s what capital planning teams at regional and community banks need to model before the final rules drop — and why AOCI is the provision that deserves immediate attention.</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate></item><item><title>FinCEN&apos;s CDD Exceptive Relief: What the February 2026 Order Changes About Beneficial Ownership Verification at Account Opening</title><link>https://risktemplate.com/blog/2026-06-19-fincen-cdd-exceptive-relief-beneficial-ownership-account-opening/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-19-fincen-cdd-exceptive-relief-beneficial-ownership-account-opening/</guid><description>FinCEN&apos;s February 2026 exceptive relief order eliminates the repeat beneficial ownership collection requirement under the CDD Rule. Here&apos;s exactly what changed, what didn&apos;t, and what BSA officers need to update now.</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate></item><item><title>H2 2026 Compliance Deadline Calendar: The 8 Dates Financial Services Teams Need to Track Before Year-End</title><link>https://risktemplate.com/blog/2026-06-19-h2-2026-compliance-deadline-calendar-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-19-h2-2026-compliance-deadline-calendar-financial-services/</guid><description>NACHA ACH Phase 2 just took effect. CFPB Reg B disparate impact changes hit July 21. EU AI Act transparency rules begin August 2. FFIEC CAMELS revision comments due August 17. Here&apos;s every material compliance deadline between now and December 2026 — and how to triage which ones need your attention first.</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Operational Resilience vs. Business Continuity: Why Your BCP Isn&apos;t Enough — and How to Close the Gap</title><link>https://risktemplate.com/blog/2026-06-19-operational-resilience-vs-business-continuity-us-bank-framework/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-19-operational-resilience-vs-business-continuity-us-bank-framework/</guid><description>Business continuity planning is about recovering from disruptions. Operational resilience is about ensuring you never exceed the maximum tolerable impact on critical services — before, during, and after disruptions. US regulators are converging on the operational resilience standard. Here&apos;s what it means for your program.</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate></item><item><title>AI Is Now a Standing Topic in Every U.S. Bank Exam: What the OCC and Fed&apos;s Oversight Questions Actually Cover</title><link>https://risktemplate.com/blog/2026-06-18-ai-now-every-bank-exam-occ-fed-examiner-questions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-18-ai-now-every-bank-exam-occ-fed-examiner-questions/</guid><description>The OCC and Federal Reserve have embedded AI oversight into every routine bank examination. Here&apos;s what examiners are asking about kill switches, data boundaries, and vendor AI chains — and what to have ready.</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate></item><item><title>California Burned $4.2M in CCPA Penalties in Six Weeks: What Disney, Ford, and PlayOn Mean for Your Fintech</title><link>https://risktemplate.com/blog/2026-06-18-ccpa-2026-enforcement-disney-ford-playon-fintech-opt-out-lessons/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-18-ccpa-2026-enforcement-disney-ford-playon-fintech-opt-out-lessons/</guid><description>The CPPA&apos;s first major enforcement wave of 2026 — Disney&apos;s $2.75M opt-out settlement, Ford&apos;s $375K friction finding, and PlayOn&apos;s $1.1M GPC failure — establishes a clear enforcement playbook. Here&apos;s what fintechs and financial services companies need to fix before auditors show up.</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Federal Reserve 2026 DFAST Stress Test: What the June 24 Results Mean for Your Capital Planning Program</title><link>https://risktemplate.com/blog/2026-06-18-dfast-2026-stress-test-results-internal-capital-planning/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-18-dfast-2026-stress-test-results-internal-capital-planning/</guid><description>The Federal Reserve releases 2026 bank stress test results on June 24 for 32 major lenders. The severely adverse scenario features 10% unemployment, a 40% CRE price decline, and a historically steep yield curve. Here&apos;s how to use the results in your internal capital planning program — and why they matter even if your institution isn&apos;t directly tested.</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Financial Data Transparency Act: What the June 2026 Joint Data Standards Final Rule Means for Banks and Fintechs</title><link>https://risktemplate.com/blog/2026-06-18-financial-data-transparency-act-joint-data-standards-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-18-financial-data-transparency-act-joint-data-standards-compliance/</guid><description>Nine federal agencies published the FDTA joint data standards final rule, effective October 1, 2026. No reporting requirements change yet — but the LEI is now the cross-agency entity identifier of record, and Phase 2 rulemakings that will change actual data submissions must be completed within two years. Here&apos;s what to track and do now.</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate></item><item><title>DORA Article 26 TLPT: Who Gets Designated for Threat-Led Penetration Testing in 2026 and How to Prepare Before Your NCA Calls</title><link>https://risktemplate.com/blog/2026-06-17-dora-article-26-tlpt-threat-led-penetration-testing-requirements-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-17-dora-article-26-tlpt-threat-led-penetration-testing-requirements-2026/</guid><description>DORA&apos;s advanced testing obligation under Article 26 is different from the ICT third-party risk requirements you&apos;ve been building for. 2026 is the year national competent authorities begin issuing TLPT designations. Here&apos;s who is in scope, what a TLPT engagement actually covers, and what to have ready before you receive the call.</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate></item><item><title>FDIC IT Examinations in 2026: What the End of URSIT and the New Single IT Rating Mean for Your Technology Risk Program</title><link>https://risktemplate.com/blog/2026-06-17-fdic-it-examination-2026-ursit-single-rating-technology-risk/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-17-fdic-it-examination-2026-ursit-single-rating-technology-risk/</guid><description>The FDIC is replacing the decades-old URSIT framework with a single IT rating organized around five focus areas: governance, cybersecurity, BCP, vendor management, and audit. Early 2026 examinations confirm the shift is already underway. Here&apos;s what community banks and their fintech partners need to prepare.</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate></item><item><title>FTC Safeguards Rule in 2026: The 9-Element Security Program Every Non-Bank Financial Institution Now Has to Prove It Has</title><link>https://risktemplate.com/blog/2026-06-17-ftc-safeguards-rule-9-elements-non-bank-financial-institution-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-17-ftc-safeguards-rule-9-elements-non-bank-financial-institution-2026/</guid><description>If you&apos;re a mortgage broker, payday lender, tax preparer, money transmitter, or collection agency — not a bank, not an SEC-registered adviser — the FTC Safeguards Rule is your data security regulation. Here&apos;s what the 9-element information security program actually requires, plus the breach notification obligation that became enforceable in May 2024.</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Regulation E and P2P Payment Scam Liability: What the $175M Cash App Consent Order Tells Banks About Their Investigation Process</title><link>https://risktemplate.com/blog/2026-06-17-regulation-e-p2p-payment-scam-liability-cash-app-investigation-standards/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-17-regulation-e-p2p-payment-scam-liability-cash-app-investigation-standards/</guid><description>The CFPB&apos;s $175M consent order against Block/Cash App wasn&apos;t about the fraud — it was about the investigation process. Here&apos;s what financial institutions must document, how the 10-business-day clock works, and where authorized P2P scam liability actually lives.</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate></item><item><title>OCC 2023-17 Vendor Contract Provisions: What Goes in Every Critical Vendor Agreement — and What Examiners Flag First</title><link>https://risktemplate.com/blog/2026-06-16-occ-2023-17-vendor-contract-provisions-critical-vendor-agreement/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-16-occ-2023-17-vendor-contract-provisions-critical-vendor-agreement/</guid><description>OCC Bulletin 2023-17 specifies exactly what should be in every critical vendor contract — from right-to-audit to subcontracting controls to exit planning. Here&apos;s the complete list, where most agreements fall short, and what to do when a large vendor won&apos;t accept the terms the guidance requires.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Amended Regulation S-P: The 30-Day Breach Notification Rule That Now Applies to Every Investment Adviser and Broker-Dealer</title><link>https://risktemplate.com/blog/2026-06-16-sec-regulation-sp-amendment-30-day-breach-notification-investment-advisers/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-16-sec-regulation-sp-amendment-30-day-breach-notification-investment-advisers/</guid><description>The SEC&apos;s 2024 amendment to Regulation S-P created a mandatory 30-day customer breach notification requirement for investment advisers, broker-dealers, and investment companies. Smaller entities just passed their June 3, 2026 compliance deadline. Here&apos;s what the rule actually requires — and the three operational gaps most firms haven&apos;t closed.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CFPB&apos;s 2026 Section 1071 Overhaul: Narrower Scope, a Single January 2028 Deadline, and What Small Business Lenders Must Do Now</title><link>https://risktemplate.com/blog/2026-06-15-cfpb-section-1071-2026-small-business-lending-data-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-15-cfpb-section-1071-2026-small-business-lending-data-compliance/</guid><description>The CFPB&apos;s May 2026 final rule dramatically narrows Section 1071 — raising the threshold to 1,000 originations, cutting the small business revenue cap to $1M, and replacing tiered compliance dates with a single January 1, 2028 deadline. Here&apos;s what changed and what every covered lender needs to do before data collection begins.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>EU AI Act in 2026: What Your Financial Supervisors Are Checking Before the December 2027 High-Risk Deadline</title><link>https://risktemplate.com/blog/2026-06-15-eu-ai-act-2026-supervisory-priorities-srep-digital-omnibus-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-15-eu-ai-act-2026-supervisory-priorities-srep-digital-omnibus-financial-services/</guid><description>The Digital Omnibus pushed the Annex III high-risk AI deadline to December 2027 — but the ECB, EBA, and ESMA are already probing AI governance through SREP cycles in 2026. Here&apos;s what financial institutions need to have ready now, and the Commission classification guidelines you can still comment on before July 23.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>FinCEN&apos;s AML/CFT Program Overhaul NPRM: What the April 2026 Proposed Rule Means for Your BSA Compliance Program</title><link>https://risktemplate.com/blog/2026-06-15-fincen-aml-cft-program-modernization-nprm-risk-based/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-15-fincen-aml-cft-program-modernization-nprm-risk-based/</guid><description>FinCEN&apos;s April 2026 NPRM would fundamentally restructure AML/CFT program requirements — adding a mandatory codified risk assessment, tying programs to National AML/CFT Priorities, and replacing the checkbox compliance standard with an effectiveness-based framework. Here&apos;s what BSA officers need to know before the final rule drops.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Third-Party Dependent BCP: What FFIEC BCM and OCC 2023-17 Require You to Verify About Vendor Continuity</title><link>https://risktemplate.com/blog/2026-06-15-third-party-dependent-bcp-ffiec-occ-2023-17-vendor-verification/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-15-third-party-dependent-bcp-ffiec-occ-2023-17-vendor-verification/</guid><description>Collecting a vendor&apos;s BCP and verifying it are not the same thing. FFIEC BCM and the 2023 interagency third-party guidance both require institutions to actively assess critical vendor resilience — and bank examiners know the difference. Here&apos;s what the verification standard actually requires.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>FCRA Adverse Action Notice Requirements: What Fintechs Using AI Credit Models Need to Get Right in 2026</title><link>https://risktemplate.com/blog/2026-06-14-fcra-adverse-action-notice-requirements-fintech-ai-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-14-fcra-adverse-action-notice-requirements-fintech-ai-2026/</guid><description>CFPB examiners found fintechs using AI credit models with 1,000+ variables failing to provide legally required adverse action notices. Here&apos;s what FCRA Section 615, ECOA Reg B, and the 2025 Supervisory Highlights require — and a 5-step compliance checklist.</description><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate></item><item><title>HIPAA OCR Enforcement in 2025-2026: What 21 Settlements Reveal About Where Examiners Are Actually Looking</title><link>https://risktemplate.com/blog/2026-06-14-hipaa-ocr-enforcement-2025-2026-settlement-patterns/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-14-hipaa-ocr-enforcement-2025-2026-settlement-patterns/</guid><description>OCR ended 2025 with 21 HIPAA settlements and civil monetary penalties — the second highest annual total ever — driven by two active enforcement initiatives. Here&apos;s what the Warby Parker $1.5M penalty, the Risk Analysis expansion, and the Right of Access trend mean for every covered entity and business associate.</description><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Instant Payments Fraud Controls: The Operational Risk Framework Financial Institutions Need for FedNow and RTP</title><link>https://risktemplate.com/blog/2026-06-14-instant-payments-fraud-controls-fednow-rtp-operational-risk/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-14-instant-payments-fraud-controls-fednow-rtp-operational-risk/</guid><description>FedNow and RTP are irrevocable, 24/7, and settling in seconds — and your fraud controls were built for ACH and wire. Here&apos;s the operational risk framework that bridges the gap before the fraud arrives.</description><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Synthetic Identity Fraud Bust-Out Response: How Financial Institutions Detect, Contain, and Report the Fraud Nobody Sees Coming</title><link>https://risktemplate.com/blog/2026-06-14-synthetic-identity-fraud-response-detection-bust-out-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-14-synthetic-identity-fraud-response-detection-bust-out-financial-institutions/</guid><description>Synthetic identity fraud is the defining fraud threat of 2026 — and your CIP wasn&apos;t built to catch it. Here&apos;s how financial institutions detect bust-out schemes, contain the exposure, and file the SARs that regulators expect.</description><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CAMELS Rating System: What Examiners Actually Test — and What the FFIEC&apos;s First Overhaul in 30 Years Changes for Your Exam Prep</title><link>https://risktemplate.com/blog/2026-06-13-camels-rating-system-ffiec-2026-revisions-exam-prep/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-13-camels-rating-system-ffiec-2026-revisions-exam-prep/</guid><description>The FFIEC proposed its first material CAMELS revision in 30 years in May 2026, with comments due August 17. Here&apos;s what each component measures, what moves composite ratings, and what the proposed changes mean before they take effect.</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Nth-Party Risk in TPRM: Mapping the Subcontracting Chain OCC 2023-17 Expects You to Understand</title><link>https://risktemplate.com/blog/2026-06-13-nth-party-risk-tprm-subcontracting-chain-occ-2023-17/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-13-nth-party-risk-tprm-subcontracting-chain-occ-2023-17/</guid><description>26% of financial institutions don&apos;t assess fourth-party risk at all. OCC 2023-17 made subcontracting oversight explicit. Here&apos;s how to map your vendor chain, what contract provisions you need, and what examiners expect to see.</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The Regulatory Exam Preparation Playbook: What to Have Ready Before an OCC, FDIC, or CFPB Team Walks In</title><link>https://risktemplate.com/blog/2026-06-13-regulatory-exam-preparation-playbook-occ-fdic-cfpb/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-13-regulatory-exam-preparation-playbook-occ-fdic-cfpb/</guid><description>The document request list arrives 2-4 weeks before examiners do. Here&apos;s how to manage the DRL, set up your exam response infrastructure, handle examiner interactions, and avoid the document production mistakes that create findings that didn&apos;t exist before the exam.</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Sensitive Data Under US State Privacy Laws: The GLBA Safe Harbor Fintechs Just Lost — and What to Do Now</title><link>https://risktemplate.com/blog/2026-06-13-sensitive-data-state-privacy-laws-glba-erosion-fintech-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-13-sensitive-data-state-privacy-laws-glba-erosion-fintech-2026/</guid><description>Montana and Connecticut just eliminated the GLBA entity-level exemption for non-depository financial institutions, effective October 2025 and July 2026. Here&apos;s what &apos;sensitive data&apos; means across 20+ state laws and what controls you actually need.</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Colorado SB 26-189 Implementation Roadmap: Building Your ADMT Compliance Program Before January 1, 2027</title><link>https://risktemplate.com/blog/2026-06-12-colorado-sb-26-189-admt-compliance-program-implementation/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-12-colorado-sb-26-189-admt-compliance-program-implementation/</guid><description>Colorado SB 26-189, signed May 14, 2026, eliminates the financial institution exemption from SB 24-205 and creates three deployer obligations for covered ADMT. Here is how to build the compliance program your institution needs before the January 1, 2027 effective date.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Communications Failure BCP: When Your Telecom, Email, and Collaboration Platforms Go Down Simultaneously</title><link>https://risktemplate.com/blog/2026-06-12-communications-failure-bcp-telecom-email-collaboration/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-12-communications-failure-bcp-telecom-email-collaboration/</guid><description>AT&amp;T&apos;s February 2024 outage lasted 11 hours and disrupted bank branches, fraud callbacks, and employee communications across the US. CrowdStrike&apos;s July 2024 update crashed the same Windows infrastructure that Microsoft Teams runs on. Most financial institution BCPs still treat communications as background infrastructure. Here&apos;s what your plan is missing.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate></item><item><title>How to Evaluate a Vendor&apos;s SOC 2 Report: The TPRM Practitioner&apos;s Guide to Reading What Actually Matters</title><link>https://risktemplate.com/blog/2026-06-12-how-to-evaluate-vendor-soc-2-report-tprm-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-12-how-to-evaluate-vendor-soc-2-report-tprm-guide/</guid><description>Most TPRM programs collect SOC 2 reports. Few actually review them. Here is how to read the five sections that determine whether a vendor&apos;s audit gives you assurance or just a PDF in your files.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Wire Transfer Fraud Incident Response: The First 48 Hours and the UCC 4A Liability Framework</title><link>https://risktemplate.com/blog/2026-06-12-wire-transfer-fraud-incident-response-ucc-4a-playbook/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-12-wire-transfer-fraud-incident-response-ucc-4a-playbook/</guid><description>Wire fraud via Fedwire, CHIPS, and SWIFT cost businesses $2.6 billion in 2025. Here&apos;s the step-by-step incident response playbook, what UCC Article 4A determines about who pays, and what the SDNY&apos;s January 2025 ruling changed for consumer wire fraud.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CRE Concentration Risk: How to Build the Policy Framework Your OCC or FDIC Examiner Will Actually Test</title><link>https://risktemplate.com/blog/2026-06-11-cre-concentration-risk-policy-framework-examiner/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-11-cre-concentration-risk-policy-framework-examiner/</guid><description>31% of US banks exceeded the CRE concentration threshold at year-end 2024. Here&apos;s how to build the credit policy limits, stress testing methodology, and documentation artifacts that show you&apos;ve made a deliberate, defensible risk decision — not just stumbled into concentration.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The FTC&apos;s March 2026 AI Policy Statement: What Financial Services AI Teams Need to Document Under Section 5</title><link>https://risktemplate.com/blog/2026-06-11-ftc-ai-policy-statement-financial-services-section-5/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-11-ftc-ai-policy-statement-financial-services-section-5/</guid><description>On March 7, 2026, the FTC issued its first comprehensive AI enforcement framework using Section 5 of the FTC Act — no new legislation required. Here&apos;s what the three-pillar framework means for financial services AI programs, and the four documentation gaps that create the most acute exposure.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate></item><item><title>NYDFS Part 500 Phase 3: The MFA and Asset Inventory Gaps Covered Entities Are Still Getting Wrong in 2026</title><link>https://risktemplate.com/blog/2026-06-11-nydfs-part-500-phase-3-mfa-asset-inventory-compliance-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-11-nydfs-part-500-phase-3-mfa-asset-inventory-compliance-2026/</guid><description>The November 2025 Phase 3 requirements under 23 NYCRR Part 500 are now in effect — and the April 2026 certification must reflect full compliance. Here&apos;s what most covered entities are still getting wrong on universal MFA, asset inventory, and third-party service provider oversight.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate></item><item><title>OCC and FDIC Drop Reputation Risk from Bank Supervision: What Your Compliance Program Must Do Now</title><link>https://risktemplate.com/blog/2026-06-11-occ-fdic-reputation-risk-rule-bank-compliance-program/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-11-occ-fdic-reputation-risk-rule-bank-compliance-program/</guid><description>The June 9, 2026 OCC/FDIC final rule prohibits regulators from citing reputation risk in examinations. Here&apos;s what changed, what the rule does and doesn&apos;t require, and the specific compliance program updates every bank and fintech needs to make.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Account Takeover Incident Response: The Reg E Liability Playbook Financial Institutions Can&apos;t Ignore</title><link>https://risktemplate.com/blog/2026-06-10-account-takeover-incident-response-playbook-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-10-account-takeover-incident-response-playbook-financial-institutions/</guid><description>ATO fraud hit $262 million in losses in 2025. The NY AG v. Citibank ruling changed the liability calculus. Here&apos;s the 72-hour incident response playbook and the Reg E obligations your policy needs to document.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate></item><item><title>FDIC 2026 Risk Review: The 5 Risk Areas That Will Drive Bank Exam Priorities for the Rest of the Year</title><link>https://risktemplate.com/blog/2026-06-10-fdic-2026-risk-review-bank-exam-priorities-cre-consumer-credit/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-10-fdic-2026-risk-review-bank-exam-priorities-cre-consumer-credit/</guid><description>The FDIC&apos;s 2026 Risk Review flags CRE concentrations, nonbank lending exposure, consumer credit delinquencies, and funding stability as the elevated-risk areas shaping supervisory priorities. Here&apos;s what compliance and risk teams at banks need to prepare for now.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Nacha ACH Fraud Monitoring Phase 2: The June 22 Compliance Deadline Every Financial Institution Is Treating as Optional (It Isn&apos;t)</title><link>https://risktemplate.com/blog/2026-06-10-nacha-ach-fraud-monitoring-phase-2-compliance-deadline-june-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-10-nacha-ach-fraud-monitoring-phase-2-compliance-deadline-june-2026/</guid><description>Nacha&apos;s Phase 2 ACH fraud monitoring rules take effect June 19, 2026, eliminating the volume threshold and covering every non-consumer originator, TPSP, third-party sender, and RDFI. Here&apos;s who&apos;s covered, what&apos;s required, and the documentation checklist before the deadline.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate></item><item><title>OCC Bulletin 2026-13: What Changed from SR 11-7 and the 7-Item Update Checklist for Your MRM Program</title><link>https://risktemplate.com/blog/2026-06-10-occ-bulletin-2026-13-model-risk-management-sr-11-7-what-changed/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-10-occ-bulletin-2026-13-model-risk-management-sr-11-7-what-changed/</guid><description>The federal banking agencies replaced SR 11-7 with OCC Bulletin 2026-13 and SR 26-02 in April 2026. Here&apos;s what changed in validation, independence, and community bank expectations — plus the GenAI exclusion that creates a compliance gap your MRM team can&apos;t afford to ignore.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate></item><item><title>FS AI RMF Gap Assessment: How to Score Your AI Program Against Treasury&apos;s 230 Control Objectives</title><link>https://risktemplate.com/blog/2026-06-09-fs-ai-rmf-gap-assessment-230-control-objectives/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-09-fs-ai-rmf-gap-assessment-230-control-objectives/</guid><description>Treasury&apos;s Financial Services AI Risk Management Framework gives financial institutions 230 control objectives across four maturity stages. Here&apos;s the gap assessment workflow your team should run before the next exam cycle.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate></item><item><title>GENIUS Act Stablecoin Compliance: The July 18 Deadline and What Every Issuer Still Needs to Build</title><link>https://risktemplate.com/blog/2026-06-09-genius-act-stablecoin-compliance-july-2026-deadline/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-09-genius-act-stablecoin-compliance-july-2026-deadline/</guid><description>Federal agencies must finalize GENIUS Act implementing regulations by July 18, 2026 — 39 days from today. FinCEN&apos;s AML comment period closes today. Here&apos;s the compliance checklist stablecoin issuers and their bank partners need to build before the deadline hits.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate></item><item><title>When Your Bank Partner Fails: The BCP Scenario Fintechs Keep Skipping Until It&apos;s Too Late</title><link>https://risktemplate.com/blog/2026-06-09-sponsor-bank-failure-fintech-bcp-operational-continuity/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-09-sponsor-bank-failure-fintech-bcp-operational-continuity/</guid><description>The Synapse bankruptcy froze $265 million in fintech customer funds. Most fintech BCPs don&apos;t mention the bank partner failing at all. Here&apos;s how to plan for the scenario most compliance teams assume will never happen.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Texas TDPSA for Banks and Fintechs: Where the GLBA Exemption Ends and Compliance Begins</title><link>https://risktemplate.com/blog/2026-06-09-texas-tdpsa-financial-services-glba-exemption-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-09-texas-tdpsa-financial-services-glba-exemption-compliance/</guid><description>Texas TDPSA took effect July 1, 2024, with no revenue threshold and no processing volume threshold. The GLBA entity-level exemption is more limited than most financial institutions assume — your marketing stack, website analytics, and pre-application data are likely covered. Here&apos;s what you still need to do.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CFPB Reg B Overhaul: Disparate Impact Is Out — What AI Credit Teams Must Know Before July 21, 2026</title><link>https://risktemplate.com/blog/2026-06-08-cfpb-reg-b-disparate-impact-eliminated-ai-credit-models-july-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-08-cfpb-reg-b-disparate-impact-eliminated-ai-credit-models-july-2026/</guid><description>The CFPB&apos;s April 2026 Regulation B final rule eliminates disparate impact from ECOA enforcement, effective July 21, 2026. But the debiasing trap, state fair lending laws, and Fair Housing Act obligations remain. Here&apos;s the five-item compliance checklist for AI credit teams.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate></item><item><title>California&apos;s New Privacy Compliance Requirements: What the CPPA Cybersecurity Audit, Risk Assessment, and ADMT Rules Mean for Financial Services Teams</title><link>https://risktemplate.com/blog/2026-06-08-cppa-cybersecurity-audit-admt-financial-services-compliance-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-08-cppa-cybersecurity-audit-admt-financial-services-compliance-2026/</guid><description>The CPPA&apos;s cybersecurity audit, privacy risk assessment, and ADMT regulations took effect January 1, 2026. A $1.35M record fine against Tractor Supply, a new Audits Division with independent examination authority, and an enforcement posture that no longer waits for consumer complaints — here&apos;s what financial institutions and fintechs with California customers must understand now.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate></item><item><title>DORA Article 28 in 2026: What US Financial Institutions with EU Operations Are Still Getting Wrong</title><link>https://risktemplate.com/blog/2026-06-08-dora-article-28-ict-third-party-risk-us-financial-institutions-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-08-dora-article-28-ict-third-party-risk-us-financial-institutions-2026/</guid><description>DORA&apos;s transition year is over. Q1 2026 Register of Information submissions are under NCA review, 19 Critical ICT Third-Party Providers have been designated, and active enforcement has begun. Here&apos;s what US financial institutions with EU branches and subsidiaries are still getting wrong — and what to fix before supervisory follow-up arrives.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The GenAI Model Risk Gap: What Banks Should Do While the OCC AI RFI Is Still Being Written</title><link>https://risktemplate.com/blog/2026-06-08-genai-model-risk-gap-occ-rfi-interim-governance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-08-genai-model-risk-gap-occ-rfi-interim-governance/</guid><description>OCC Bulletin 2026-13 explicitly excluded generative AI and agentic AI from model risk guidance scope. The AI-specific RFI hasn&apos;t landed yet. Here&apos;s the interim governance framework banks should be building now.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The BaaS Consent Order Playbook: What 10+ Enforcement Actions Reveal About TPRM Minimum Standards</title><link>https://risktemplate.com/blog/2026-06-07-baas-consent-order-tprm-minimum-standards-sponsor-bank/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-07-baas-consent-order-tprm-minimum-standards-sponsor-bank/</guid><description>From Cross River to Evolve, regulators have now issued consent orders against at least 10 BaaS-focused banks across three different agencies. The pattern is consistent enough to define TPRM minimum standards for any bank running a fintech partnership program — and what fintechs must build before their next sponsor bank due diligence review.</description><pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Biometric Privacy Compliance for Fintechs: What BIPA, Texas CUBI, and the KYC Vendor Gap Actually Require</title><link>https://risktemplate.com/blog/2026-06-07-biometric-privacy-compliance-fintech-bipa-texas-cubi/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-07-biometric-privacy-compliance-fintech-bipa-texas-cubi/</guid><description>Most financial institutions assume GLBA exempts them from BIPA. It doesn&apos;t cover your KYC vendors — and Texas is enforcing its biometric law with billion-dollar settlements. Here&apos;s what your compliance program actually needs.</description><pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Insider Threat Incident Response: The First 72 Hours for Financial Institutions</title><link>https://risktemplate.com/blog/2026-06-07-insider-threat-incident-response-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-07-insider-threat-incident-response-financial-institutions/</guid><description>Insider threats are the incident type where almost every instinct is wrong. A step-by-step framework for financial services — from the first alert through separation, SAR filing, and breach notification — without destroying the investigation or creating wrongful termination exposure.</description><pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Reputational Risk KRIs: What to Measure Now That Examiners No Longer Will</title><link>https://risktemplate.com/blog/2026-06-07-reputational-risk-kri-metrics-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-07-reputational-risk-kri-metrics-financial-institutions/</guid><description>The OCC and FDIC eliminated reputation risk as a standalone examination category effective June 9, 2026. Here are 8 KRIs to track reputational exposure independently — before it shows up in customer attrition, bank partner friction, or a media cycle that doesn&apos;t need an MRA to hurt.</description><pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CFPB Section 1033 Open Banking Rule: What Financial Institutions Need to Know While the Litigation Plays Out</title><link>https://risktemplate.com/blog/2026-06-06-cfpb-section-1033-open-banking-rule-compliance-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-06-cfpb-section-1033-open-banking-rule-compliance-financial-institutions/</guid><description>CFPB finalized its Section 1033 open banking rule in October 2024, requiring covered institutions to share consumer financial data via permissioned APIs. Then a federal court enjoined enforcement in October 2025. Here&apos;s what the rule requires, where the litigation stands, and why your compliance team should be building toward it anyway.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Credit Risk KRIs: Delinquency, Concentration, and CECL Metrics That Examiners Actually Check</title><link>https://risktemplate.com/blog/2026-06-06-credit-risk-kri-delinquency-concentration-cecl-examiner-metrics/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-06-credit-risk-kri-delinquency-concentration-cecl-examiner-metrics/</guid><description>Non-performing loan ratios, net charge-off rates, and CRE concentration limits don&apos;t just show up in credit reviews — they&apos;re the metrics bank examiners use to spot trouble before it becomes an enforcement action. Here&apos;s the full credit risk KRI framework with Green/Amber/Red thresholds.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Cybersecurity KRIs: 8 Metrics That Show Whether Your Security Program Is Actually Working</title><link>https://risktemplate.com/blog/2026-06-06-cybersecurity-kri-nydfs-part-500-ffiec-metrics/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-06-cybersecurity-kri-nydfs-part-500-ffiec-metrics/</guid><description>Compliance checkboxes tell you whether controls exist. Cybersecurity KRIs tell you whether they&apos;re functioning. Here are the 8 metrics NYDFS Part 500, the FFIEC IT Examination Handbook, and security-mature financial institutions actually track — with Green/Amber/Red thresholds and calibration guidance.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate></item><item><title>EU AI Act Compliance KRIs: 8 Metrics for the August 2, 2026 Deadline — Before Your Supervisor Asks</title><link>https://risktemplate.com/blog/2026-06-06-eu-ai-act-compliance-kri-high-risk-ai-program-metrics/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-06-eu-ai-act-compliance-kri-high-risk-ai-program-metrics/</guid><description>August 2, 2026 is the full enforcement date for EU AI Act high-risk system obligations. Banks, fintechs, and insurers using credit scoring, AML, or underwriting AI need more than a compliance checklist — they need KRIs that show whether the program is actually running. Here&apos;s the framework.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CIRCIA Final Rule: What Financial Institutions Need to Know About the New 72-Hour Mandatory Cyber Incident Reporting</title><link>https://risktemplate.com/blog/2026-06-05-circia-final-rule-financial-institutions-72-hour-incident-reporting/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-05-circia-final-rule-financial-institutions-72-hour-incident-reporting/</guid><description>CISA&apos;s CIRCIA final rule arrived in May 2026. Financial institutions in critical infrastructure sectors now face a 72-hour mandatory incident reporting requirement to CISA — layered on top of FFIEC 36-hour, SEC 4-day, and NYDFS Part 500 obligations. Here&apos;s what each one actually covers and how to build a coordinated response.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Colorado Rewrites Its AI Law: What SB 26-189 Means for Banks and Fintechs</title><link>https://risktemplate.com/blog/2026-06-05-colorado-sb-26-189-ai-law-financial-services-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-05-colorado-sb-26-189-ai-law-financial-services-compliance/</guid><description>Colorado&apos;s SB 26-189, signed May 14, 2026, replaces the original Colorado AI Act and eliminates the financial institution safe harbor. Here&apos;s what the new automated decision-making law requires before January 1, 2027.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate></item><item><title>BSA/AML KRIs: Transaction Monitoring False Positives, SAR Filing Rates, and the 10 Metrics Examiners Actually Check</title><link>https://risktemplate.com/blog/2026-06-04-bsa-aml-kri-transaction-monitoring-sar-filing-metrics/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-04-bsa-aml-kri-transaction-monitoring-sar-filing-metrics/</guid><description>Most BSA programs track activity. Few track program health. Here are the 10 BSA/AML KRIs that reveal whether your transaction monitoring, SAR filing, CDD, and independent testing pillars are working — including how to calibrate false positive rates, SAR conversion rates, and CDD completion metrics that hold up in examinations.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Business Continuity KRIs: Metrics That Show Whether Your BCP Is Actually Working</title><link>https://risktemplate.com/blog/2026-06-04-business-continuity-kri-bcp-testing-metrics/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-04-business-continuity-kri-bcp-testing-metrics/</guid><description>Annual BCP testing tells you if your plan can pass a drill. Business continuity KRIs tell you if it&apos;ll actually hold up. Here are eight metrics every practitioner should be tracking.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Data Privacy KRIs: What to Monitor for DSAR Backlogs, Consent Drift, and Breach Response Timing</title><link>https://risktemplate.com/blog/2026-06-04-data-privacy-kri-dsar-backlog-consent-breach-response/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-04-data-privacy-kri-dsar-backlog-consent-breach-response/</guid><description>Eight data privacy KRIs every compliance team should be tracking in 2026 — covering DSAR completion rates, consent opt-out effectiveness, breach notification timeliness, and vendor DPA coverage, with threshold guidance and escalation triggers.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Stress Testing KRIs: How to Turn Scenario Results Into Board-Level Triggers</title><link>https://risktemplate.com/blog/2026-06-04-stress-testing-kri-scenario-results-board-triggers/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-04-stress-testing-kri-scenario-results-board-triggers/</guid><description>Most stress test results never make it into ongoing KRI programs. Here&apos;s how to convert scenario outputs — deposit runoff assumptions, capital floor breaches, credit loss projections — into calibrated KRI thresholds that fire automatically when conditions approach the scenario&apos;s breaking points.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate></item><item><title>AI Governance Dashboard: What KRIs Belong in Committee Reporting</title><link>https://risktemplate.com/blog/2026-06-03-ai-governance-dashboard-committee-reporting-kris/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-03-ai-governance-dashboard-committee-reporting-kris/</guid><description>Engineering telemetry is not an AI governance dashboard. Here&apos;s how to separate what risk committees and boards need to see from what ML ops monitors — with a practical KRI set for each layer.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate></item><item><title>AI in Risk Management: What Financial Services Teams Can Automate Safely — and What They Still Own</title><link>https://risktemplate.com/blog/2026-06-03-ai-in-risk-management-financial-services-automate-safely-human-judgment/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-03-ai-in-risk-management-financial-services-automate-safely-human-judgment/</guid><description>Standard Chartered just announced 7,800 job cuts driven by AI. Here&apos;s the honest breakdown of which risk management tasks AI handles well, which need a human co-pilot, and which you should not automate at any price.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Cash Burn KRIs for Fintechs: Runway, Reserve Coverage, and Funding Dependency</title><link>https://risktemplate.com/blog/2026-06-03-cash-burn-kri-fintech-runway-reserve-coverage-funding-dependency/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-03-cash-burn-kri-fintech-runway-reserve-coverage-funding-dependency/</guid><description>Cash burn metrics are finance reporting. Cash burn KRIs are risk management. Here&apos;s how to build the six indicators that turn your runway and reserve data into early warnings your risk program can actually act on.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Contingency Funding Plan KRIs: Metrics That Should Trigger CFP Activation</title><link>https://risktemplate.com/blog/2026-06-03-contingency-funding-plan-kri-activation-triggers/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-03-contingency-funding-plan-kri-activation-triggers/</guid><description>Most CFPs have a trigger section. Most trigger sections are too vague to actually fire. Here&apos;s how to build contingency funding plan KRIs that activate the right tier at the right time — with evidence artifacts regulators will accept.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate></item><item><title>AI Incident KRIs: Output Errors, Customer Harm, Near Misses, and Remediation Aging</title><link>https://risktemplate.com/blog/2026-06-02-ai-incident-kri-output-errors-customer-harm-near-misses-remediation/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-02-ai-incident-kri-output-errors-customer-harm-near-misses-remediation/</guid><description>AI incidents don&apos;t announce themselves—they show up in complaint queues, credit disputes, and examiner findings. These KRIs measure what matters: error rates, customer harm, near misses, and how long your remediation pipeline is aging.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Compliance Calendar KRIs: How to Track Deadlines Before They Become Findings</title><link>https://risktemplate.com/blog/2026-06-02-compliance-calendar-kris-track-deadlines-before-findings/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-02-compliance-calendar-kris-track-deadlines-before-findings/</guid><description>Most compliance teams find out about missed deadlines when a regulator asks. These KRIs catch deadline risk before it shows up as an MRA—covering upcoming obligations, owner slippage, evidence completeness, and late filing history.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Deposit Concentration KRIs: Measuring Customer, Sector, and Platform Dependency</title><link>https://risktemplate.com/blog/2026-06-02-deposit-concentration-kris-customer-sector-platform-dependency/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-02-deposit-concentration-kris-customer-sector-platform-dependency/</guid><description>Generic deposit metrics don&apos;t catch concentration failures. Here&apos;s how to build deposit concentration KRIs that actually warn you — covering top depositor concentration, sector exposure, brokered deposits, and platform dependency.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Fair Lending and Bias KRIs for AI Models: Approval Rates, Override Rates, and Disparate Impact Signals</title><link>https://risktemplate.com/blog/2026-06-02-fair-lending-bias-kri-ai-models-approval-rates-disparate-impact/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-02-fair-lending-bias-kri-ai-models-approval-rates-disparate-impact/</guid><description>Periodic bias testing isn&apos;t monitoring — it&apos;s a snapshot. Here&apos;s how to build KRIs that track AI model fairness continuously: approval rate gaps, override patterns, adverse action drift, complaint signals, and validation exceptions.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate></item><item><title>If AI Writes the Memo, Who Owns the Risk? Accountability for AI-Generated Compliance Work</title><link>https://risktemplate.com/blog/2026-06-01-ai-accountability-compliance-who-owns-risk-ai-generated-work/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-01-ai-accountability-compliance-who-owns-risk-ai-generated-work/</guid><description>AI is generating risk assessments, SAR narratives, board memos, and regulatory change summaries. But &apos;human-in-the-loop&apos; without documented challenge is accountability theater. Here&apos;s what genuine ownership looks like — and what regulators are starting to require.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Early Warning Indicators vs KRIs: How Liquidity Teams Should Use Both</title><link>https://risktemplate.com/blog/2026-06-01-early-warning-indicators-vs-kri-liquidity-teams/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-01-early-warning-indicators-vs-kri-liquidity-teams/</guid><description>EWIs and KRIs are not the same thing — even when they measure the same metric. Here&apos;s how liquidity teams should design, separate, and connect them to CFP activation and board reporting.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Exam Readiness KRIs: Evidence Gaps, Repeat Requests, and Aging Management Responses</title><link>https://risktemplate.com/blog/2026-06-01-exam-readiness-kris-evidence-gaps-repeat-requests-aging/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-01-exam-readiness-kris-evidence-gaps-repeat-requests-aging/</guid><description>Six key risk indicators for exam readiness that go beyond checklists — tracking evidence gap rates, repeat examiner requests, aging commitments, and validation completeness before the examiner asks.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Internal Audit KRIs: Repeat Findings, Delayed Remediation, and Weak Validation</title><link>https://risktemplate.com/blog/2026-06-01-internal-audit-kris-repeat-findings-delayed-remediation-weak-validation/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-06-01-internal-audit-kris-repeat-findings-delayed-remediation-weak-validation/</guid><description>Seven key risk indicators for internal audit health — repeat finding rates, CAP aging, failed validation, closure evidence quality, issue recurrence, management response delays, and risk acceptance patterns for high and critical findings.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate></item><item><title>AI Vendor KRIs: Monitoring Model Drift, Output Errors, Complaints, and Contract Gaps</title><link>https://risktemplate.com/blog/2026-05-31-ai-vendor-kri-model-drift-output-errors-complaints/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-31-ai-vendor-kri-model-drift-output-errors-complaints/</guid><description>Six KRIs for monitoring AI vendor performance in your environment — model update detection, output error rate, complaint attribution, drift indicators, contract gap rate, and incident notification lag. Built around FS AI RMF and NIST AI RMF monitoring requirements.</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate></item><item><title>Generative AI KRIs: Hallucination Rates, Sensitive Data Exposure, and Escalation Failures</title><link>https://risktemplate.com/blog/2026-05-31-generative-ai-kri-hallucination-sensitive-data-escalation/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-31-generative-ai-kri-hallucination-sensitive-data-escalation/</guid><description>Six key risk indicators that show whether your GenAI deployment is failing in ways that are invisible until they reach a regulator — hallucination rates, sensitive data exposure events, prompt injection incidents, unsafe outputs, abstention failures, and human review bypasses.</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate></item><item><title>Policy Management KRIs: Overdue Reviews, Exception Volume, and Attestation Gaps</title><link>https://risktemplate.com/blog/2026-05-31-policy-management-kri-overdue-reviews-exceptions-attestation/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-31-policy-management-kri-overdue-reviews-exceptions-attestation/</guid><description>Five key risk indicators that show whether your policy management program is actually working — before your examiner finds the policies that haven&apos;t been meaningfully reviewed in three years.</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate></item><item><title>Process Risk KRIs: Backlogs, Manual Workarounds, SLA Breaches, and Error Rates</title><link>https://risktemplate.com/blog/2026-05-31-process-risk-kri-backlogs-workarounds-sla-breaches/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-31-process-risk-kri-backlogs-workarounds-sla-breaches/</guid><description>Six key risk indicators that catch operational process failures before they become loss events: backlog aging, manual workaround rate, SLA breach rate, error rate by process, rework volume, and handoff failure rate.</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate></item><item><title>AI Model Inventory KRIs: How to Spot Governance Drift Across Your AI Use Cases</title><link>https://risktemplate.com/blog/2026-05-30-ai-model-inventory-kri-governance-drift/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-30-ai-model-inventory-kri-governance-drift/</guid><description>AI governance programs fail when the inventory they&apos;re built on goes stale. Here are the KRIs that measure inventory completeness, ownership gaps, risk-tier accuracy, and validation aging — before an examiner finds the gaps for you.</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate></item><item><title>Control Testing KRIs: Exception Rates, Repeat Findings, and Failed Retesting</title><link>https://risktemplate.com/blog/2026-05-30-control-testing-kri-exception-rates-repeat-findings/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-30-control-testing-kri-exception-rates-repeat-findings/</guid><description>Six key risk indicators that show whether your control testing program is surfacing real risk or producing false greens — exception rates, repeat exception frequency, failed retesting, severity mix, owner response time, and overdue coverage.</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate></item><item><title>Issue Management KRIs: Aging, Reopen Rates, Missed Due Dates, and Weak CAPs</title><link>https://risktemplate.com/blog/2026-05-30-issue-management-kri-aging-reopen-rates-missed-due-dates/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-30-issue-management-kri-aging-reopen-rates-missed-due-dates/</guid><description>Six key risk indicators that show whether your issues program is actually fixing things — issue aging by severity, due date extension rate, reopen rate, repeat root cause frequency, CAP validation failure rate, and evidence completeness at closure.</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate></item><item><title>TPRM Dashboard KRIs: What to Show Management vs. the Board</title><link>https://risktemplate.com/blog/2026-05-30-tprm-dashboard-kri-management-vs-board-reporting/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-30-tprm-dashboard-kri-management-vs-board-reporting/</guid><description>Your TPRM program has two audiences with completely different information needs. Here&apos;s how to separate operational vendor risk metrics from board-level indicators — with sample KRIs, escalation thresholds, and a structure that survives examiner scrutiny.</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate></item><item><title>AI Risk KRIs: Metrics for Model Drift, Bias, Hallucination, Complaints, and Human Overrides</title><link>https://risktemplate.com/blog/2026-05-29-ai-risk-kri-model-drift-bias-hallucination-override/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-29-ai-risk-kri-model-drift-bias-hallucination-override/</guid><description>AI models fail gradually, not all at once. Here are the five KRI categories that catch model drift, bias signals, GenAI hallucination rates, human override patterns, and AI-specific complaint trends before an examiner does.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate></item><item><title>Training KRIs: Completion Rates Are Not Enough — What to Track Instead</title><link>https://risktemplate.com/blog/2026-05-29-compliance-training-kri-completion-rates-not-enough/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-29-compliance-training-kri-completion-rates-not-enough/</guid><description>A 97% training completion rate sounds impressive until your BSA examiner asks what roles made up the 3% who didn&apos;t complete it. Here are the five training KRIs that actually predict compliance risk.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate></item><item><title>Operational Loss KRIs: Tracking Loss Events, Near Misses, Recoveries, and Repeat Issues</title><link>https://risktemplate.com/blog/2026-05-29-operational-loss-kri-loss-events-near-miss-recovery/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-29-operational-loss-kri-loss-events-near-miss-recovery/</guid><description>How to turn your loss event database into a functioning early warning system — KRIs for frequency trends, near-miss conversion, recovery velocity, root cause recurrence, and severity distribution shifts that actually warn you before the next event.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate></item><item><title>Vendor Due Diligence KRIs: Missing Evidence, Overdue Reviews, and High-Risk Exceptions</title><link>https://risktemplate.com/blog/2026-05-29-vendor-due-diligence-kris-overdue-reviews-missing-evidence/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-29-vendor-due-diligence-kris-overdue-reviews-missing-evidence/</guid><description>Your TPRM program tracks vendor performance. These 6 KRIs track whether your due diligence process itself is working — review completion rates, evidence currency, exception handling, and the program health gaps examiners find most often.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate></item><item><title>AI Governance Policy Template: What to Include Before Employees Start Using ChatGPT and Other AI Tools</title><link>https://risktemplate.com/blog/2026-05-28-ai-governance-policy-template-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-28-ai-governance-policy-template-financial-services/</guid><description>A practitioner&apos;s guide to writing an AI governance policy for financial services: tool classification, prohibited data inputs, human review requirements, vendor-embedded AI, exception approvals, and enforcement sections that hold up to regulatory scrutiny.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>The Compliance Professional&apos;s AI Practice Plan: 10 Exercises to Build Fluency Before Your Job Changes</title><link>https://risktemplate.com/blog/2026-05-28-compliance-professional-ai-practice-plan-10-exercises/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-28-compliance-professional-ai-practice-plan-10-exercises/</guid><description>Standard Chartered is cutting 7,800 compliance and risk jobs by 2030. Fluency with AI isn&apos;t optional—it&apos;s the skill that determines whether you&apos;re the person directing AI or the one being replaced by it. Here are 10 exercises to build it.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>Fourth-Party Risk KRIs: Monitoring Concentration You Do Not Directly Control</title><link>https://risktemplate.com/blog/2026-05-28-fourth-party-risk-kris-monitoring-concentration/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-28-fourth-party-risk-kris-monitoring-concentration/</guid><description>You have no contract with fourth parties—but you inherit their failures. Here are the KRIs that surface cloud concentration, shared subcontractors, and upstream dependency risk before it becomes your incident.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>Operational Risk KRIs: 25 Metrics Every Risk Team Should Consider</title><link>https://risktemplate.com/blog/2026-05-28-operational-risk-kri-examples-25-metrics/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-28-operational-risk-kri-examples-25-metrics/</guid><description>A practitioner&apos;s guide to 25 operational risk KRIs grouped by loss events, incidents, process controls, issues management, people risk, customer impact, and vendor dependency — with thresholds, data sources, and escalation triggers.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>The AI Output Review Checklist for Risk and Compliance Teams</title><link>https://risktemplate.com/blog/2026-05-27-ai-output-review-checklist-risk-compliance-teams/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-27-ai-output-review-checklist-risk-compliance-teams/</guid><description>When an AI draft lands on your desk, what standard do you apply before signing off? The nine-point review checklist that separates defensible AI use from supervised negligence — covering source verification, scope accuracy, missing risk, customer harm, fairness, escalation triggers, and regulatory defensibility.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate></item><item><title>KRI Exceptions: How to Document, Escalate, and Close Red Indicators</title><link>https://risktemplate.com/blog/2026-05-27-kri-exceptions-document-escalate-close-red-indicators/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-27-kri-exceptions-document-escalate-close-red-indicators/</guid><description>A red KRI is a management obligation, not just a dashboard update. Here&apos;s the exception memo structure, escalation matrix, and validation evidence that makes your risk program defensible to examiners.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate></item><item><title>Regulatory Change KRIs: Missed Deadlines, Late Impact Assessments, and Policy Lag</title><link>https://risktemplate.com/blog/2026-05-27-regulatory-change-kris-missed-deadlines-policy-lag/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-27-regulatory-change-kris-missed-deadlines-policy-lag/</guid><description>Most compliance programs track regulatory changes but don&apos;t measure whether the process is actually working. Here are the seven KRIs that show whether your regulatory change management function is keeping pace — before the examiner finds the gap.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate></item><item><title>Third-Party Incident KRIs: When Vendor Outages Become Operational Resilience Issues</title><link>https://risktemplate.com/blog/2026-05-27-third-party-incident-kri-vendor-outage-operational-resilience/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-27-third-party-incident-kri-vendor-outage-operational-resilience/</guid><description>Vendor outages become your operational resilience problem when you can&apos;t detect them early, classify them correctly, or respond within your impact tolerances. Here are the KRIs that tell you which risk is real.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate></item><item><title>AI Governance Framework for Financial Services: A Practical Guide for Risk and Compliance Teams</title><link>https://risktemplate.com/blog/2026-05-26-ai-governance-framework-financial-services-risk-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-26-ai-governance-framework-financial-services-risk-compliance/</guid><description>An AI governance framework is not a policy document. It is an operating model. Here is what that operating model looks like for financial services teams navigating the FS AI RMF, SR 26-02, NIST AI RMF 1.1, and five regulatory deadlines hitting in 2026.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>Compliance KRIs: Metrics That Show Whether Your Program Is Actually Working</title><link>https://risktemplate.com/blog/2026-05-26-compliance-kris-metrics-program-health/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-26-compliance-kris-metrics-program-health/</guid><description>Most compliance dashboards report activity, not risk. Here&apos;s how to build compliance KRIs that show whether your program is actually functioning — across the four CMS pillars regulators test, with escalation triggers and board reporting guidance.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>Critical Vendor KRIs: SLA Breaches, Incidents, Control Failures, and Concentration Risk</title><link>https://risktemplate.com/blog/2026-05-26-critical-vendor-kris-sla-breaches-incidents-control-failures-concentration-risk/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-26-critical-vendor-kris-sla-breaches-incidents-control-failures-concentration-risk/</guid><description>Critical vendors warrant a different level of KRI coverage than your Tier 2 and Tier 3 roster. Here&apos;s the board-level monitoring framework for SLA breach classification, incident patterns, control failures, and concentration exposure — with the escalation triggers regulators expect to see documented.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>KRI Data Quality: What to Do When the Metric Is Right but the Source Data Is Trash</title><link>https://risktemplate.com/blog/2026-05-26-kri-data-quality-source-data-risk-dashboard/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-26-kri-data-quality-source-data-risk-dashboard/</guid><description>Your KRI definition is solid. Your thresholds are calibrated. But if the source data feeding those metrics is stale, inconsistently extracted, or manually patched, your green dashboard is lying to you.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>AI Compliance Checklist: What Risk and Compliance Teams Should Review Before Employees Use AI</title><link>https://risktemplate.com/blog/2026-05-25-ai-compliance-checklist-employees-risk-compliance-teams/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-25-ai-compliance-checklist-employees-risk-compliance-teams/</guid><description>A practical AI compliance checklist for financial services employees—covering tool authorization, data restrictions, customer-impacting decisions, source verification, output retention, and escalation triggers.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate></item><item><title>How Many KRIs Is Too Many? Building a Dashboard That Does Not Become Metric Theater</title><link>https://risktemplate.com/blog/2026-05-25-how-many-kris-too-many-kri-dashboard-metric-theater/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-25-how-many-kris-too-many-kri-dashboard-metric-theater/</guid><description>More KRIs don&apos;t mean better risk visibility. Here&apos;s how to prune your dashboard, identify metric theater, and build a KRI program boards and examiners actually trust.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate></item><item><title>Partner Bank Liquidity KRIs: What Fintechs Should Monitor but Often Do Not</title><link>https://risktemplate.com/blog/2026-05-25-partner-bank-liquidity-kris-fintechs-monitor/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-25-partner-bank-liquidity-kris-fintechs-monitor/</guid><description>When your sponsor bank runs into trouble, you find out last. Here&apos;s what liquidity KRIs fintechs can actually track—before a Synapse-scale event freezes your customers&apos; funds.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate></item><item><title>What AI Can and Cannot Replace in Compliance Work</title><link>https://risktemplate.com/blog/2026-05-25-what-ai-can-cannot-replace-compliance-work/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-25-what-ai-can-cannot-replace-compliance-work/</guid><description>Standard Chartered is cutting 7,800 jobs—mostly in compliance and risk. HSBC is upskilling 200,000. Here&apos;s the task-level map of what AI actually automates vs. what human compliance professionals still own.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate></item><item><title>AI Compliance Training Plan: What Risk and Compliance Teams Need to Learn First</title><link>https://risktemplate.com/blog/2026-05-24-ai-compliance-training-plan-risk-compliance-teams/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-24-ai-compliance-training-plan-risk-compliance-teams/</guid><description>A practical 30/60/90-day AI compliance training roadmap for risk and compliance professionals—covering failure modes, safe prompting, regulatory frameworks, and role-specific applications.</description><pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate></item><item><title>AI Risk Assessment Template: Questions Every Compliance Team Should Ask Before Approving AI Use</title><link>https://risktemplate.com/blog/2026-05-24-ai-risk-assessment-template-questions-compliance-approval/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-24-ai-risk-assessment-template-questions-compliance-approval/</guid><description>Before any AI tool goes live, compliance needs answers to nine question categories — use case scope, customer impact, data sensitivity, explainability, vendor reliance, bias/fairness, monitoring, issue ownership, and evidence retained.</description><pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate></item><item><title>Incident KRIs: Volume, Severity, Time to Contain, Time to Resolve, and Root Cause Patterns</title><link>https://risktemplate.com/blog/2026-05-24-incident-kri-volume-severity-time-to-contain-resolve-root-cause/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-24-incident-kri-volume-severity-time-to-contain-resolve-root-cause/</guid><description>How to build an incident KRI dashboard that measures what regulators actually care about—response times, severity patterns, repeat incident rates, and root cause closure.</description><pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate></item><item><title>KRI Appetite Statements: How to Tie Metrics to Board-Approved Risk Appetite</title><link>https://risktemplate.com/blog/2026-05-24-kri-appetite-statements-board-approved-risk-appetite/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-24-kri-appetite-statements-board-approved-risk-appetite/</guid><description>Most KRI dashboards are designed without tracing thresholds back to the board-approved risk appetite statement. Here&apos;s how to close that gap — and why regulators will ask you to.</description><pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate></item><item><title>KRI Governance: Who Owns the Metric, Threshold, Escalation, and Remediation?</title><link>https://risktemplate.com/blog/2026-05-23-kri-governance-ownership-escalation-remediation/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-23-kri-governance-ownership-escalation-remediation/</guid><description>Most KRI programs have metrics but no real owners. When a KRI breaches amber, nothing happens because accountability was never built into the design. Here&apos;s the governance model — roles, RACI, threshold approval paths, and escalation chains — that makes a KRI program function under regulatory scrutiny.</description><pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate></item><item><title>Leading vs Lagging KRIs: Which Metrics Actually Warn You Early?</title><link>https://risktemplate.com/blog/2026-05-23-leading-vs-lagging-kri-early-warning-indicators/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-23-leading-vs-lagging-kri-early-warning-indicators/</guid><description>Most KRI dashboards are filled with lagging metrics that confirm what already went wrong. Here&apos;s how to tell the difference, why it matters to regulators, and how to convert common lagging KRIs into genuine early warning signals.</description><pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate></item><item><title>Business Email Compromise Incident Response: The First 48 Hours for Financial Institutions</title><link>https://risktemplate.com/blog/2026-05-22-business-email-compromise-incident-response-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-22-business-email-compromise-incident-response-financial-institutions/</guid><description>BEC caused $3.04 billion in losses in 2025. Recovery depends almost entirely on speed. Here&apos;s the hour-by-hour playbook: wire recall steps, IC3 reporting, Financial Fraud Kill Chain, SAR requirements, and how to close the loop.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate></item><item><title>California ADMT Regulations: What Fintechs Using AI for Credit, Fraud, and Customer Profiling Must Document Now</title><link>https://risktemplate.com/blog/2026-05-22-california-admt-regulations-fintech-ai-automated-decision-making/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-22-california-admt-regulations-fintech-ai-automated-decision-making/</guid><description>The CPPA&apos;s automated decision-making technology rules are live. Fintechs using AI for lending decisions, fraud detection, or customer scoring face new risk assessment, notice, and opt-out obligations starting in 2026 and 2027. Here&apos;s what compliance teams need to do.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate></item><item><title>FFIEC Business Continuity Management Booklet: What Examiners Actually Check (And What Changed in 2026)</title><link>https://risktemplate.com/blog/2026-05-22-ffiec-business-continuity-management-booklet-2026-update/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-22-ffiec-business-continuity-management-booklet-2026-update/</guid><description>In February 2026, the FFIEC removed &apos;reputation risk&apos; from the BCM booklet under Executive Order 14331. Here&apos;s what changed, what stayed, and a section-by-section breakdown of what examiners verify when they open Appendix A.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate></item><item><title>NYDFS Part 500 Enforcement in 2025-2026: What $25 Million in Fines Reveals About What Regulators Actually Check</title><link>https://risktemplate.com/blog/2026-05-22-nydfs-part-500-enforcement-2025-2026-cybersecurity-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-22-nydfs-part-500-enforcement-2025-2026-cybersecurity-compliance/</guid><description>NYDFS has issued more than $25 million in Part 500 cybersecurity fines since January 2025 — against PayPal, eight auto insurers, Healthplex, and Delta Dental. The violation patterns are consistent. Here&apos;s what every covered entity needs to fix before they&apos;re next.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate></item><item><title>AUP Ongoing Monitoring: What to Watch After You Approve a Higher-Risk Customer</title><link>https://risktemplate.com/blog/2026-05-21-aup-ongoing-monitoring-high-risk-customer-post-approval/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-21-aup-ongoing-monitoring-high-risk-customer-post-approval/</guid><description>Your AUP exception memo approved the customer. The compliance work isn&apos;t done — here&apos;s the behavioral monitoring framework, re-review triggers, and exit process that keeps the approval defensible over time.</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate></item><item><title>Fraud KRIs for Fintechs: Transaction Volume, Loss Rates, Alert Backlogs, and Threshold Drift</title><link>https://risktemplate.com/blog/2026-05-21-fraud-kri-examples-fintechs-threshold-drift/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-21-fraud-kri-examples-fintechs-threshold-drift/</guid><description>The fraud KRIs you set at launch become misleading when your transaction volume triples. Here&apos;s the full set of fraud metrics fintech risk teams need — and the calibration rules that keep them honest as the business scales.</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate></item><item><title>Liquidity KRIs for Fintech and Banking Teams: Early Warnings Before the Funding Problem Becomes Obvious</title><link>https://risktemplate.com/blog/2026-05-21-liquidity-kri-early-warning-indicators-fintech-banking/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-21-liquidity-kri-early-warning-indicators-fintech-banking/</guid><description>The metrics that matter for liquidity risk management — uninsured deposit concentration, deposit runoff rate, wholesale funding renewal, and six more — with CFP tier mapping and threshold guidance practitioners can actually use.</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate></item><item><title>Product Risk KRIs for Payments, Stablecoins, and BNPL: What to Monitor After Launch</title><link>https://risktemplate.com/blog/2026-05-21-product-risk-kri-payments-stablecoins-bnpl/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-21-product-risk-kri-payments-stablecoins-bnpl/</guid><description>Chargeback rates, reserve coverage ratios, early delinquency — the key risk indicators fintech product teams and risk functions need to monitor after launch across payments, BNPL, and stablecoin products.</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate></item><item><title>High-Risk Merchant Policy: How to Review the Transaction, Not Just the Industry</title><link>https://risktemplate.com/blog/2026-05-20-high-risk-merchant-policy-transaction-review-framework/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-20-high-risk-merchant-policy-transaction-review-framework/</guid><description>Merchant risk reviews that start and end with an industry code miss the actual risk. Here&apos;s the transaction-level framework that tells you whether a high-risk merchant is manageable — and what you need to document before approving or denying.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate></item><item><title>Operational Risk KRI Dashboard: What to Show the Board and What to Keep in Management Reporting</title><link>https://risktemplate.com/blog/2026-05-20-operational-risk-kri-dashboard-board-management-reporting/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-20-operational-risk-kri-dashboard-board-management-reporting/</guid><description>The board doesn&apos;t need your full KRI library — it needs risk movement, breach escalations, and appetite context. Here&apos;s exactly how to separate board-level reporting from management-level monitoring, with the regulatory framework and enforcement cases that make it non-negotiable.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate></item><item><title>Sales vs. Compliance in High-Risk Customer Reviews: How to Avoid Losing Good Deals for Bad Reasons</title><link>https://risktemplate.com/blog/2026-05-20-sales-vs-compliance-high-risk-customer-review/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-20-sales-vs-compliance-high-risk-customer-review/</guid><description>The tension between sales urgency and compliance diligence doesn&apos;t have to kill deals. Here&apos;s the escalation framework, SLA structure, and approval process that resolves high-risk customer decisions in days instead of weeks — and the enforcement record that shows what happens when sales wins for a decade.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate></item><item><title>Sponsor Bank RFI Volume as a KRI: Measuring Partner Scrutiny and Debanking Risk</title><link>https://risktemplate.com/blog/2026-05-20-sponsor-bank-rfi-volume-kri-debanking-risk/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-20-sponsor-bank-rfi-volume-kri-debanking-risk/</guid><description>Rising requests for information from your sponsor bank are one of the earliest signals that a partnership is under stress — and one of the least-tracked KRIs in fintech programs. Here&apos;s how to build the indicator properly and what the thresholds mean.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate></item><item><title>AUP Exception Memos: How to Document a High-Risk Customer Approval Without Creating a Mess</title><link>https://risktemplate.com/blog/2026-05-19-aup-exception-memo-high-risk-customer-approval-documentation/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-19-aup-exception-memo-high-risk-customer-approval-documentation/</guid><description>When you approve a restricted or borderline customer, the memo is not bureaucratic overhead — it&apos;s your defense against the next examiner, bank partner audit, or internal escalation. Here&apos;s the format that holds up under scrutiny.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate></item><item><title>Contingency Funding Plan Examples: What Good, Defensible CFP Language Actually Looks Like</title><link>https://risktemplate.com/blog/2026-05-19-contingency-funding-plan-examples-defensible-language/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-19-contingency-funding-plan-examples-defensible-language/</guid><description>Generic CFP language won&apos;t survive an examiner&apos;s follow-up questions. Here&apos;s how to replace vague placeholder text with specific, testable CFP language — with real examples for funding sources, triggers, testing protocols, and escalation owners.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate></item><item><title>KRI vs KPI: How to Tell Whether Your Metric Actually Measures Risk</title><link>https://risktemplate.com/blog/2026-05-19-kri-vs-kpi-how-to-tell-whether-metric-measures-risk/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-19-kri-vs-kpi-how-to-tell-whether-metric-measures-risk/</guid><description>Most risk dashboards are full of KPIs labeled as KRIs. Here&apos;s how to tell the difference — and how to convert an activity metric into a real key risk indicator that gives you an early warning before the risk becomes a problem.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate></item><item><title>Prohibited vs. Restricted Businesses: How Fintechs Should Decide What They Can Support</title><link>https://risktemplate.com/blog/2026-05-19-prohibited-vs-restricted-businesses-fintech-decision-framework/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-19-prohibited-vs-restricted-businesses-fintech-decision-framework/</guid><description>Industry labels alone don&apos;t tell you whether you can support a customer. Here&apos;s the transaction-level decision framework that separates &apos;never&apos; from &apos;not without a process&apos; — and what BaaS enforcement actions prove about getting this wrong.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate></item><item><title>Acceptable Use Policy Template for Fintechs: Prohibited, Restricted, and Enhanced-Review Customers</title><link>https://risktemplate.com/blog/2026-05-18-acceptable-use-policy-template-fintech-prohibited-restricted/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-18-acceptable-use-policy-template-fintech-prohibited-restricted/</guid><description>A structural template for fintech acceptable use policies — covering the seven sections every AUP needs, a three-tier decision table, an approval path for restricted customers, and monitoring triggers that hold up to sponsor bank and examiner scrutiny.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate></item><item><title>CFP Fund Flow Testing: The Liquidity Exercise Most Fintechs Skip Until a Regulator Asks</title><link>https://risktemplate.com/blog/2026-05-18-cfp-fund-flow-testing-fintechs-liquidity-exercise/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-18-cfp-fund-flow-testing-fintechs-liquidity-exercise/</guid><description>A fund-flow test proves your contingency funding plan actually works — not just on paper. Here&apos;s how fintechs should map payment rails, confirm collateral, walk approval chains, and document gaps before a regulator does it for them.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate></item><item><title>Key Risk Indicators Examples: 40 KRIs for Operational and Financial Risk Teams</title><link>https://risktemplate.com/blog/2026-05-18-key-risk-indicators-examples-operational-financial-risk/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-18-key-risk-indicators-examples-operational-financial-risk/</guid><description>40 ready-to-use KRI examples for operational and financial risk programs — each with risk measured, data source, owner, threshold idea, and escalation path.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate></item><item><title>Restricted Business Due Diligence: Questions to Ask Before You Approve Cannabis, Weapons, Adult, Gambling, or Crypto Customers</title><link>https://risktemplate.com/blog/2026-05-18-restricted-business-due-diligence-cannabis-weapons-gambling-crypto/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-18-restricted-business-due-diligence-cannabis-weapons-gambling-crypto/</guid><description>A practitioner&apos;s due diligence checklist for fintechs evaluating five high-risk business categories — the questions that determine whether a restricted customer is manageable or a liability.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate></item><item><title>Bank Partner Alignment for AUPs: When Your Sponsor Bank&apos;s Risk Appetite Overrides Yours</title><link>https://risktemplate.com/blog/2026-05-17-bank-partner-aup-alignment-sponsor-bank-risk-appetite/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-17-bank-partner-aup-alignment-sponsor-bank-risk-appetite/</guid><description>How to map your fintech AUP to your sponsor bank&apos;s prohibited and restricted business rules, when to pre-clear customers, how to document exceptions, and what rising RFI volume signals about bank partner discomfort.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate></item><item><title>Contingency Funding Plan Triggers: How to Set Liquidity Thresholds You Can Defend to Regulators</title><link>https://risktemplate.com/blog/2026-05-17-contingency-funding-plan-triggers-liquidity-thresholds/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-17-contingency-funding-plan-triggers-liquidity-thresholds/</guid><description>Vague CFP triggers don&apos;t survive examiner scrutiny. Here&apos;s how to design Green/Yellow/Red liquidity thresholds with specific metrics, documented rationale, and clear ownership — so your CFP activates before it&apos;s too late.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate></item><item><title>How to Build a KRI Task Force: Owners, Functional Leads, and Board Reporting That Actually Works</title><link>https://risktemplate.com/blog/2026-05-17-kri-task-force-owners-functional-leads-board-reporting/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-17-kri-task-force-owners-functional-leads-board-reporting/</guid><description>KRI programs fail when analysts assign ownership bottom-up. Here&apos;s how to build a top-down KRI task force with functional leads, board reporting rules, and accountability structures that examiners and audit committees actually accept.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate></item><item><title>Vendor Risk KRIs: Metrics That Show When a Third Party Is Becoming a Problem</title><link>https://risktemplate.com/blog/2026-05-17-vendor-risk-kri-metrics-third-party-warning-signals/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-17-vendor-risk-kri-metrics-third-party-warning-signals/</guid><description>The vendor KRIs that actually warn you before a third-party failure becomes your problem: SLA trends, SOC report exceptions, concentration exposure, financial distress signals, and fourth-party drift.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate></item><item><title>Contingency Funding Plan Evidence Binder: What to Keep Before the Examiner Asks</title><link>https://risktemplate.com/blog/2026-05-16-cfp-evidence-binder-exam-readiness-documentation/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-16-cfp-evidence-binder-exam-readiness-documentation/</guid><description>Examiners don&apos;t just read your CFP — they ask for evidence that it works. Here&apos;s the complete list of documentation, test records, and artifacts that belong in a CFP evidence binder, organized by funding source and review cycle.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate></item><item><title>Funding Sources Aren&apos;t Real Until Tested: How to Prove Your Contingency Funding Plan Works</title><link>https://risktemplate.com/blog/2026-05-16-cfp-funding-sources-testing-prove-contingency-plan-works/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-16-cfp-funding-sources-testing-prove-contingency-plan-works/</guid><description>Most CFPs list contingent funding sources without proving they&apos;re accessible. Here&apos;s how to run fund-flow tests, build an evidence file, and show regulators that your liquidity plan actually works when it needs to.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate></item><item><title>Who Should Own the Contingency Funding Plan? Treasury, Finance, Risk, and the Review-and-Challenge Model</title><link>https://risktemplate.com/blog/2026-05-16-cfp-ownership-treasury-finance-risk/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-16-cfp-ownership-treasury-finance-risk/</guid><description>Practical guide to CFP ownership: who drafts, who challenges, who approves. Three-lines-of-defense roles, board oversight, and what examiners expect after SR 10-6 and the 2023 addendum.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate></item><item><title>KRI Thresholds: How to Stop Your Dashboard From Creating False Greens and False Reds</title><link>https://risktemplate.com/blog/2026-05-16-kri-thresholds-false-greens-false-reds/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-16-kri-thresholds-false-greens-false-reds/</guid><description>Set KRI thresholds that actually warn before risk materializes. Calibration methods, the 60-day parallel run, and how to fix dashboards stuck in alert fatigue or perpetual green.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate></item><item><title>SEC&apos;s Final Judgment Against Black Hawk&apos;s Robert Newell: How a $37M Cannabis Fund Became a Ponzi Case Study</title><link>https://risktemplate.com/blog/2026-05-16-sec-newell-black-hawk-cannabis-fund-final-judgment/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-16-sec-newell-black-hawk-cannabis-fund-final-judgment/</guid><description>Robert Newell raised $37M for cannabis funds and used investor money to pay earlier investors. Here&apos;s the May 2026 SEC judgment and what private-fund advisers should learn from it.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate></item><item><title>Critical Vendor Exit Planning: How to Build a Wind-Down Strategy Before You Need One</title><link>https://risktemplate.com/blog/2026-05-15-critical-vendor-exit-planning-termination-wind-down-strategy/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-15-critical-vendor-exit-planning-termination-wind-down-strategy/</guid><description>A practitioner&apos;s guide to building vendor exit strategies that satisfy OCC, FDIC, and Federal Reserve examiners — with lessons from the Synapse collapse and the six components every exit plan must cover.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate></item><item><title>EU AI Act Digital Omnibus: What the December 2027 Deadline Deferral Means for Financial Services AI Teams</title><link>https://risktemplate.com/blog/2026-05-15-eu-ai-act-digital-omnibus-deadline-deferral-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-15-eu-ai-act-digital-omnibus-deadline-deferral-financial-services/</guid><description>The EU AI Act&apos;s Digital Omnibus deal, reached May 7, 2026, defers Annex III high-risk AI obligations from August 2, 2026 to December 2, 2027. Here&apos;s what changed, what didn&apos;t, and how financial services AI teams should use the extra 16 months.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate></item><item><title>FFIEC 36-Hour Incident Notification Rule: What Banking Organizations Must Report, When, and to Whom</title><link>https://risktemplate.com/blog/2026-05-15-ffiec-36-hour-computer-security-incident-notification-rule/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-15-ffiec-36-hour-computer-security-incident-notification-rule/</guid><description>A practitioner&apos;s guide to the federal banking agencies&apos; computer-security incident notification rule — what triggers the 36-hour clock, the two-tier framework for banks vs. bank service providers, and the gray areas that catch incident response teams off guard.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate></item><item><title>Fintech Acceptable Use Policy: How to Handle High-Risk Customers Without Killing Good Business</title><link>https://risktemplate.com/blog/2026-05-15-fintech-acceptable-use-policy-high-risk-customers/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-15-fintech-acceptable-use-policy-high-risk-customers/</guid><description>How to build a fintech acceptable use policy that evaluates high-risk customers by actual platform use, not blunt industry labels.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate></item><item><title>GLBA Regulation P Privacy Notices: What Financial Institutions Must Send, When, and the FAST Act Exception Explained</title><link>https://risktemplate.com/blog/2026-05-15-glba-regulation-p-privacy-notice-requirements-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-15-glba-regulation-p-privacy-notice-requirements-financial-institutions/</guid><description>A practitioner&apos;s guide to GLBA Regulation P: who must send privacy notices, what the initial and annual notice must include, when the FAST Act exception eliminates the annual requirement, and how opt-out rights actually work.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate></item><item><title>SEC Adani $18M Settlement: When Anti-Bribery Disclosures Become Securities Fraud</title><link>https://risktemplate.com/blog/2026-05-15-sec-adani-18-million-bribery-bond-disclosure-settlement/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-15-sec-adani-18-million-bribery-bond-disclosure-settlement/</guid><description>SEC settles Adani Green bond offering case for $18M, charging Gautam and Sagar Adani with materially false anti-bribery statements to US investors.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate></item><item><title>NYDFS Hits Delta Dental With $2.25M — The First 2026 Cyber Action Is About Notice and Retention, Not the Breach</title><link>https://risktemplate.com/blog/2026-05-14-nydfs-delta-dental-moveit-cyber-settlement/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-14-nydfs-delta-dental-moveit-cyber-settlement/</guid><description>NYDFS&apos;s first 2026 cybersecurity enforcement penalizes Delta Dental for a six-month notification delay and lengthened MOVEit retention settings — not for getting hit. What practitioners should pull from the consent order.</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate></item><item><title>Operational Risk Scenario Analysis: Building &apos;Severe But Plausible&apos; Scenarios That Satisfy Internal Audit and the OCC</title><link>https://risktemplate.com/blog/2026-05-14-operational-risk-scenario-analysis-methodology-best-practices/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-14-operational-risk-scenario-analysis-methodology-best-practices/</guid><description>A practitioner&apos;s guide to designing, facilitating, and defending operational risk scenario analysis — from workshop setup and expert elicitation to loss estimation and ICAAP integration.</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate></item><item><title>Privacy Impact Assessment Template: How to Run a DPIA or PIA That Satisfies GDPR, CPRA, and 20+ US State Privacy Laws</title><link>https://risktemplate.com/blog/2026-05-14-privacy-impact-assessment-template-dpia-gdpr-us-state/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-14-privacy-impact-assessment-template-dpia-gdpr-us-state/</guid><description>A practitioner&apos;s guide to designing, conducting, and documenting privacy impact assessments — covering GDPR Article 35 DPIA requirements, California CPRA risk assessments (effective January 2026), and state law PIA triggers across 20+ US jurisdictions.</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate></item><item><title>SEC and DOJ Charge 21 in BigLaw M&amp;A Insider Trading Ring — What the Document Management Trail Tells You</title><link>https://risktemplate.com/blog/2026-05-14-sec-doj-insider-trading-biglaw-attorneys-21-charged/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-14-sec-doj-insider-trading-biglaw-attorneys-21-charged/</guid><description>The SEC&apos;s May 6 complaint against 21 defendants tied to a decade-long Big Law M&amp;A insider trading scheme is a master class in supervision failure. Here is what compliance functions should pull from the document-access trail.</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate></item><item><title>Crisis Communication Plan: The BCP Component Most Financial Institutions Treat as an Afterthought</title><link>https://risktemplate.com/blog/2026-05-13-crisis-communication-plan-bcp-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-13-crisis-communication-plan-bcp-financial-institutions/</guid><description>Your BCP has 60 pages on recovery procedures and three paragraphs on communication. Here&apos;s what regulators actually test, the four audience streams every plan needs, and the pre-approved templates to build before the crisis hits.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate></item><item><title>EU AI Act Article 5 Prohibited AI Systems: The Compliance Checklist Financial Institutions Can&apos;t Ignore</title><link>https://risktemplate.com/blog/2026-05-13-eu-ai-act-article-5-prohibited-ai-systems-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-13-eu-ai-act-article-5-prohibited-ai-systems-financial-services/</guid><description>Article 5 prohibitions have been in force since February 2025 and the enforcement regime launched August 2025. Here&apos;s what financial institutions must audit, stop doing, and document — with the credit scoring carve-out explained.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate></item><item><title>HIPAA Security Rule Overhaul: The New Technical Safeguard Requirements Coming to Every Covered Entity and Business Associate</title><link>https://risktemplate.com/blog/2026-05-13-hipaa-security-rule-2025-final-rule-technical-safeguards/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-13-hipaa-security-rule-2025-final-rule-technical-safeguards/</guid><description>The biggest HIPAA Security Rule update since 2013 is arriving in 2026. Here&apos;s what the proposed final rule requires, what&apos;s actually changing, and how to run a gap assessment before the compliance deadline.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate></item><item><title>OCC Consent Orders: From Issuance to Termination — A Practitioner&apos;s Walkthrough</title><link>https://risktemplate.com/blog/2026-05-13-occ-consent-order-response-enforcement-anatomy/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-13-occ-consent-order-response-enforcement-anatomy/</guid><description>What an OCC consent order actually is, how it differs from a Formal Agreement, what the articles require, and what it takes to get out — with Wells Fargo as the documented case study.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate></item><item><title>SEC Charges Reign Financial and Berone Capital in $26M Prime Bank Scheme: The Due Diligence Failures Every Adviser Should Audit</title><link>https://risktemplate.com/blog/2026-05-13-sec-reign-financial-international-26-million-prime-bank-scheme/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-13-sec-reign-financial-international-26-million-prime-bank-scheme/</guid><description>SEC&apos;s $26M Reign Financial fraud case shows what happens when &apos;due diligence&apos; is just a Google search. Control gaps, red flags, and what advisers should fix this week.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate></item><item><title>DSAR Response Workflow: A Practitioner&apos;s Guide to Data Subject Access Requests Under CCPA, GDPR, and State Privacy Laws</title><link>https://risktemplate.com/blog/2026-05-12-dsar-response-workflow-ccpa-gdpr-state-privacy-laws/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-12-dsar-response-workflow-ccpa-gdpr-state-privacy-laws/</guid><description>DSARs aren&apos;t optional, and mishandling them now costs seven figures. Here&apos;s the complete workflow — intake, identity verification, data collection, legal review, and documented response — built for teams managing multi-law obligations.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate></item><item><title>Operational Loss Data Collection: Building a Loss Event Database That Satisfies Examiners and Feeds Your Risk Program</title><link>https://risktemplate.com/blog/2026-05-12-operational-loss-data-collection-loss-event-database/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-12-operational-loss-data-collection-loss-event-database/</guid><description>Most operational risk programs have an RCSA. Far fewer have a loss event database that&apos;s actually current, classified, and connected to risk monitoring. Here&apos;s how to build one that satisfies examiner expectations and makes the rest of your ORM program credible.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate></item><item><title>Ransomware Incident Response Playbook: The 24-Hour Checklist for Financial Institutions</title><link>https://risktemplate.com/blog/2026-05-12-ransomware-incident-response-playbook-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-12-ransomware-incident-response-playbook-financial-institutions/</guid><description>When ransomware hits your bank or fintech, the first 24 hours determine your regulatory exposure, recovery timeline, and whether your next call is to your CEO or your lawyer. Here&apos;s the phase-by-phase playbook.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate></item><item><title>Lessons from SVB &amp; Signature Bank: What Their Liquidity Failures Mean for Your CFP</title><link>https://risktemplate.com/blog/2026-05-12-svb-signature-bank-liquidity-failures-cfp-lessons/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-12-svb-signature-bank-liquidity-failures-cfp-lessons/</guid><description>Understand the critical lessons from the SVB and Signature Bank liquidity failures and how to strengthen your Contingency Funding Plan (CFP) to avoid similar pitfalls.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate></item><item><title>Vendor Breach Response: What to Do When a Critical Supplier Reports an Incident</title><link>https://risktemplate.com/blog/2026-05-12-vendor-breach-response-critical-supplier-incident/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-12-vendor-breach-response-critical-supplier-incident/</guid><description>When a vendor calls to report a breach, your incident response clock starts immediately. Here&apos;s the step-by-step playbook — triage, regulatory obligations, customer notification, and vendor accountability.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate></item><item><title>50 Essential Questions for Your Business Impact Analysis (BIA) Questionnaire</title><link>https://risktemplate.com/blog/2026-05-11-bia-questionnaire-template-50-questions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-11-bia-questionnaire-template-50-questions/</guid><description>Master your BIA with our comprehensive 50-question template, designed to identify critical business functions, RTOs, RPOs, and ensure robust business continuity planning. Download free template.</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate></item><item><title>BSA/AML Independent Testing: Building a Program That Passes the FFIEC Exam</title><link>https://risktemplate.com/blog/2026-05-11-bsa-aml-independent-testing-program-ffiec-requirements/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-11-bsa-aml-independent-testing-program-ffiec-requirements/</guid><description>The second pillar of a BSA/AML program — and one of the most cited in enforcement actions. Here&apos;s what the FFIEC exam manual actually requires, what examiners test, and how to build independent testing that holds up.</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate></item><item><title>EU AI Act High-Risk AI in Financial Services: What Banks and Fintechs Must Document by August 2, 2026</title><link>https://risktemplate.com/blog/2026-05-11-eu-ai-act-high-risk-ai-systems-financial-services-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-11-eu-ai-act-high-risk-ai-systems-financial-services-compliance/</guid><description>Annex III of the EU AI Act covers credit scoring, insurance pricing, and financial standing assessment. Here&apos;s what the seven compliance obligations actually require — and who they apply to.</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate></item><item><title>Parmar&apos;s $212M Constellation Healthcare Sentencing: Take-Private Fraud Lessons for Risk and Compliance</title><link>https://risktemplate.com/blog/2026-05-11-parmar-constellation-healthcare-212-million-securities-fraud-sentencing/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-11-parmar-constellation-healthcare-212-million-securities-fraud-sentencing/</guid><description>Former Constellation Healthcare CEO Parmjit Parmar got 5 years and $125M restitution for a $212M securities fraud built on fake subsidiaries. Here&apos;s what risk teams should rebuild this week.</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate></item><item><title>Compliance Calendar Template: Tracking Regulatory Deadlines, Filings, and Internal Reviews</title><link>https://risktemplate.com/blog/2026-05-10-compliance-calendar-template-regulatory-deadlines-filings/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-10-compliance-calendar-template-regulatory-deadlines-filings/</guid><description>How to build a compliance calendar that tracks every BSA, HMDA, Call Report, SAR, and exam deadline — with a 2026 reference template and the fields that survive an audit.</description><pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate></item><item><title>FFIEC IT Examination Handbook: A Practitioner&apos;s Walkthrough of What Examiners Actually Test</title><link>https://risktemplate.com/blog/2026-05-10-ffiec-it-examination-handbook-practitioner-walkthrough/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-10-ffiec-it-examination-handbook-practitioner-walkthrough/</guid><description>The FFIEC IT Handbook is 11 booklets and thousands of pages. Here&apos;s what examiners actually focus on, which booklets matter most for your institution, and how to prepare for each domain.</description><pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate></item><item><title>MRA Remediation Playbook: How to Respond When You Get a Matter Requiring Attention</title><link>https://risktemplate.com/blog/2026-05-10-mra-remediation-playbook-matter-requiring-attention/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-10-mra-remediation-playbook-matter-requiring-attention/</guid><description>How to respond to an OCC, FDIC, or Fed MRA — the 5 Cs format, 30-day board response, MRIA timelines, and what gets you out of the supervisory dog house.</description><pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate></item><item><title>OMB Cancels 2026 Civil Penalty Inflation Adjustment: What M-26-11 Means for Compliance</title><link>https://risktemplate.com/blog/2026-05-10-omb-m-26-11-civil-monetary-penalty-inflation-adjustment-cancelled-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-10-omb-m-26-11-civil-monetary-penalty-inflation-adjustment-cancelled-2026/</guid><description>OMB Memo M-26-11 freezes federal civil monetary penalties at 2025 levels for the first time since FCPIAA 2015. What it means for OFAC, SEC, OCC enforcement.</description><pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate></item><item><title>State Privacy Laws and the GLBA Safe Harbor: What Banks and Fintechs Can No Longer Assume</title><link>https://risktemplate.com/blog/2026-05-10-state-privacy-laws-glba-safe-harbor-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-10-state-privacy-laws-glba-safe-harbor-financial-institutions/</guid><description>Montana, Connecticut, Minnesota, California, and Oregon have narrowed or eliminated the GLBA entity-level exemption. If your financial institution assumes state privacy laws don&apos;t apply, you have a compliance gap.</description><pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate></item><item><title>Control Testing Techniques: Sampling, Walkthroughs, and Evidence Collection That Holds Up</title><link>https://risktemplate.com/blog/2026-05-09-control-testing-techniques-sampling-walkthroughs-evidence/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-09-control-testing-techniques-sampling-walkthroughs-evidence/</guid><description>A practitioner&apos;s guide to testing internal controls — statistical vs. nonstatistical sampling, how to run a walkthrough, what evidence examiners actually want, and where most testing programs fall short.</description><pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate></item><item><title>OCC Publishes List of Every Criminal Regulatory Offense It Enforces — What National Banks Should Do With It</title><link>https://risktemplate.com/blog/2026-05-09-occ-criminal-regulatory-offenses-report-eo-14294/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-09-occ-criminal-regulatory-offenses-report-eo-14294/</guid><description>OCC&apos;s May 8, 2026 report under Executive Order 14294 catalogs every criminal regulatory offense the OCC or DOJ can enforce, with mens rea standards. What compliance teams should do now.</description><pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate></item><item><title>Risk Scoring Techniques: Likelihood x Impact and the 4 Variations Examiners Push Back On</title><link>https://risktemplate.com/blog/2026-05-09-risk-scoring-techniques-likelihood-impact-examiner-pushback/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-09-risk-scoring-techniques-likelihood-impact-examiner-pushback/</guid><description>The L×I formula is nearly universal — but four common ways teams apply it turn defensible risk scores into examination findings. Here&apos;s what examiners flag and how to fix it.</description><pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate></item><item><title>Sanctions Screening Techniques: Tuning False Positives Without Missing Real OFAC Hits</title><link>https://risktemplate.com/blog/2026-05-09-sanctions-screening-techniques-ofac-false-positives/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-09-sanctions-screening-techniques-ofac-false-positives/</guid><description>How to calibrate your sanctions screening system to cut false positive volume, defend your match threshold to examiners, and document the tuning process OFAC expects.</description><pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate></item><item><title>Vendor Risk Questionnaire Template: The Questions That Actually Surface Third-Party Risk</title><link>https://risktemplate.com/blog/2026-05-09-vendor-risk-questionnaire-template-questions-that-surface-risk/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-09-vendor-risk-questionnaire-template-questions-that-surface-risk/</guid><description>Most vendor questionnaires produce clean checkboxes, not useful answers. Here are the specific questions — including AI vendor and fourth-party sections most templates miss — that reveal what&apos;s actually there.</description><pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate></item><item><title>Access Control Policy Template: Role-Based Access, Least Privilege, and Privileged User Reviews</title><link>https://risktemplate.com/blog/2026-05-08-access-control-policy-template-rbac-least-privilege/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-08-access-control-policy-template-rbac-least-privilege/</guid><description>Build a defensible access control policy covering RBAC, least privilege, privileged access management, and periodic user reviews. Includes the key sections examiners test under NIST 800-53 AC controls and the FFIEC IT Handbook.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate></item><item><title>Incident Triage Techniques: Severity Classification, Materiality, and the SEC 4-Day Clock</title><link>https://risktemplate.com/blog/2026-05-08-incident-triage-techniques-severity-materiality-sec-4-day-clock/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-08-incident-triage-techniques-severity-materiality-sec-4-day-clock/</guid><description>How to classify incident severity correctly, build a working materiality decision process for SEC 8-K purposes, and avoid the documentation failures that turned early Form 8-K filings into SEC comment letters.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate></item><item><title>OCC Spring 2026 Risk Perspective: What Risk Teams Need to Update Now</title><link>https://risktemplate.com/blog/2026-05-08-occ-semiannual-risk-perspective-spring-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-08-occ-semiannual-risk-perspective-spring-2026/</guid><description>OCC&apos;s Spring 2026 Semiannual Risk Perspective flags credit, cyber, AI, and sanctions risk. What examiners will ask and how to align your program.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate></item><item><title>Suspicious Activity Report (SAR) Template: Narrative Writing, Filing Triggers, and Common Mistakes</title><link>https://risktemplate.com/blog/2026-05-08-sar-template-narrative-writing-filing-triggers-mistakes/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-08-sar-template-narrative-writing-filing-triggers-mistakes/</guid><description>A practitioner&apos;s guide to SAR filing: thresholds by institution type, the 30/60-day clock, the five-W narrative framework, October 2025 FinCEN FAQ updates, and the 10 narrative mistakes that get your BSA program cited.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate></item><item><title>SEC v. Ortiz / DaveGlo: $18M Oil and Gas Sales, Undisclosed Comp, Unregistered Broker</title><link>https://risktemplate.com/blog/2026-05-08-sec-ortiz-daveglo-oil-gas-undisclosed-compensation-broker-registration/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-08-sec-ortiz-daveglo-oil-gas-undisclosed-compensation-broker-registration/</guid><description>SEC final judgment against David Ortiz and DaveGlo Investment Group for $18M unregistered oil and gas sales. Compliance lessons on broker registration and undisclosed compensation.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate></item><item><title>Vendor Due Diligence Techniques: What to Verify When the Questionnaire Comes Back</title><link>https://risktemplate.com/blog/2026-05-08-vendor-due-diligence-techniques-questionnaire-verification/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-08-vendor-due-diligence-techniques-questionnaire-verification/</guid><description>A completed vendor questionnaire is the starting point, not the finish line. Here&apos;s how to verify self-reported answers, what documents to request, what red flags look like, and how to document your work so it survives an OCC or FDIC exam.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate></item><item><title>AI Red Teaming Techniques: How to Stress-Test LLMs Before Deployment</title><link>https://risktemplate.com/blog/2026-05-07-ai-red-teaming-techniques-stress-test-llms-deployment/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-07-ai-red-teaming-techniques-stress-test-llms-deployment/</guid><description>A practitioner&apos;s playbook for AI red teaming in financial services. Covers the five attack categories regulators care about, how to structure an exercise, what scoring looks like, and how to document results for examiners.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>How to Build an Annual Compliance Risk Assessment: Methodology, Scoring, and What Regulators Look For</title><link>https://risktemplate.com/blog/2026-05-07-annual-compliance-risk-assessment-methodology-regulators/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-07-annual-compliance-risk-assessment-methodology-regulators/</guid><description>The compliance risk assessment is the foundation of every compliance management system that survives a regulatory exam. Here&apos;s the methodology regulators expect, the scoring model, and the gaps most often cited in exam findings.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Business Impact Analysis (BIA) Questionnaire Template: 50 Essential Questions</title><link>https://risktemplate.com/blog/2026-05-07-bia-questionnaire-template-50-questions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-07-bia-questionnaire-template-50-questions/</guid><description>Master business continuity with our BIA questionnaire template. Identify critical functions, assess impacts, and set recovery objectives with 50 essential questions.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Former Congressman Rivera Convicted: $50M PDVSA FARA Case Compliance Lessons</title><link>https://risktemplate.com/blog/2026-05-07-doj-rivera-nuhfer-fara-pdvsa-50-million-venezuela-conviction/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-07-doj-rivera-nuhfer-fara-pdvsa-50-million-venezuela-conviction/</guid><description>DOJ convicted ex-Rep. David Rivera and lobbyist Esther Nuhfer for a $50M unregistered Venezuela lobbying scheme. What it means for FARA, sanctions, and AML programs.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>GDPR Enforcement in 2026: The Biggest Fines, What&apos;s Being Targeted, and What US Companies Keep Getting Wrong</title><link>https://risktemplate.com/blog/2026-05-07-gdpr-enforcement-2026-fines-patterns-us-companies/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-07-gdpr-enforcement-2026-fines-patterns-us-companies/</guid><description>€7.1 billion in cumulative fines and enforcement is accelerating. Here are the top penalties, the patterns DPAs are pursuing, and the specific gaps that keep landing US multinationals in trouble.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>KYC Policy Template: A Fintech Practitioner&apos;s Guide to Customer Due Diligence</title><link>https://risktemplate.com/blog/2026-05-07-kyc-policy-template-customer-due-diligence-fintech/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-07-kyc-policy-template-customer-due-diligence-fintech/</guid><description>Build a defensible KYC policy covering all four pillars: CIP, risk rating, beneficial ownership, and ongoing monitoring. Includes the 2026 FinCEN exceptive relief update and lessons from Block&apos;s $80M and OKX&apos;s $504M enforcement actions.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Cybersecurity Policy Template: Building a Defensible Information Security Program</title><link>https://risktemplate.com/blog/2026-05-06-cybersecurity-policy-template/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-06-cybersecurity-policy-template/</guid><description>Build a cybersecurity policy that satisfies NYDFS Part 500, NIST CSF 2.0, FTC Safeguards, and FFIEC. Required elements, control mappings, and what examiners flag.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate></item><item><title>Disparate Impact Testing Techniques: Statistical Methods Examiners Actually Accept</title><link>https://risktemplate.com/blog/2026-05-06-disparate-impact-testing-techniques-statistical-methods/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-06-disparate-impact-testing-techniques-statistical-methods/</guid><description>The four statistical methods used in fair lending disparate impact testing — adverse impact ratio, regression analysis, Fisher&apos;s exact test, and BISG proxy methodology — and how to document them for exam readiness even after the federal regulatory shift.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate></item><item><title>$84M USPS Treasury Check Theft Ring Pleads Guilty: What Banks and BSA Teams Should Take From It</title><link>https://risktemplate.com/blog/2026-05-06-doj-postal-treasury-check-theft-84-million/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-06-doj-postal-treasury-check-theft-84-million/</guid><description>Four defendants pleaded guilty to stealing $84M in Treasury checks from a Philly USPS facility and reselling them on Telegram. Banks stopped 87%. Here&apos;s how.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate></item><item><title>OFAC Risk Assessment Template: Sanctions Exposure Scoring for Financial Institutions</title><link>https://risktemplate.com/blog/2026-05-06-ofac-risk-assessment-template/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-06-ofac-risk-assessment-template/</guid><description>Build a defensible OFAC risk assessment using Treasury&apos;s five-component framework. Risk factors, scoring methodology, and what examiners look for.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate></item><item><title>$450M Astor Impersonation Fraud: What the Sklarov SDNY Indictment Means for Lender Due Diligence</title><link>https://risktemplate.com/blog/2026-05-06-sklarov-astor-450-million-stock-loan-fraud-scheme/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-06-sklarov-astor-450-million-stock-loan-fraud-scheme/</guid><description>SDNY indicted Vladimir Sklarov for a $450M stock-backed loan scheme using a fake Astor family-linked lender. Here&apos;s the control gap every counterparty diligence team needs to fix.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate></item><item><title>Tabletop Exercise Facilitation Techniques: How to Run Drills That Actually Surface Gaps</title><link>https://risktemplate.com/blog/2026-05-06-tabletop-exercise-facilitation-techniques-bcp-gap-discovery/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-06-tabletop-exercise-facilitation-techniques-bcp-gap-discovery/</guid><description>The facilitation mechanics that separate tabletop exercises that find real gaps from ones that generate paperwork. Role structure, inject design, hot wash technique, and the common mistakes that turn a good scenario into a wasted afternoon.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate></item><item><title>AI Risk Assessment Template: Pre-Deployment Checklist for Financial Services</title><link>https://risktemplate.com/blog/2026-05-05-ai-risk-assessment-template-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-05-ai-risk-assessment-template-financial-services/</guid><description>A pre-deployment AI risk assessment for banks and fintechs — model inventory, tiering, scorecard, and the controls examiners ask about under SR 26-02 and FS AI RMF.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate></item><item><title>AML Risk Assessment Template: A Practitioner&apos;s Methodology for Banks and Fintechs</title><link>https://risktemplate.com/blog/2026-05-05-aml-risk-assessment-template-banks-fintechs/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-05-aml-risk-assessment-template-banks-fintechs/</guid><description>Build a defensible BSA/AML risk assessment using the FFIEC&apos;s inherent risk framework. Covers the four risk categories, scoring methodology, FinCEN&apos;s April 2026 NPRM requirements, and common exam deficiencies.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate></item><item><title>Data Classification Policy Template: How to Tier Data Without 200 Categories</title><link>https://risktemplate.com/blog/2026-05-05-data-classification-policy-template-tiers-defensible/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-05-data-classification-policy-template-tiers-defensible/</guid><description>Build a defensible data classification policy that maps to GLBA, CCPA, HIPAA, and PCI DSS. Includes the four-tier model, regulatory crosswalk, handling rules, and legal hold triggers.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate></item><item><title>Data Retention Policy Template: Schedules, Legal Hold Triggers, and Defensible Disposal</title><link>https://risktemplate.com/blog/2026-05-05-data-retention-policy-template-schedules-legal-hold-defensible-disposal/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-05-data-retention-policy-template-schedules-legal-hold-defensible-disposal/</guid><description>Build a data retention policy that survives a regulator&apos;s request and a litigator&apos;s subpoena. Retention schedules, legal hold workflows, and disposal proof.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate></item><item><title>Information Security Policy Template: A Fintech and Community Bank Walkthrough</title><link>https://risktemplate.com/blog/2026-05-05-information-security-policy-template-fintech-community-bank/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-05-information-security-policy-template-fintech-community-bank/</guid><description>Build an information security policy that satisfies the FTC Safeguards Rule, FFIEC expectations, and bank examiner scrutiny. Includes required elements, structure, and common gaps.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate></item><item><title>Liquidity Stress Testing Techniques: Modeling Run-Off, Wholesale Withdrawal, and Contingent Draws</title><link>https://risktemplate.com/blog/2026-05-05-liquidity-stress-testing-techniques-run-off-wholesale-withdrawal/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-05-liquidity-stress-testing-techniques-run-off-wholesale-withdrawal/</guid><description>Go beyond the scenario labels. How to build defensible run-off rate assumptions, model wholesale funding cliff risk, and quantify contingent draw exposure — with the specific techniques examiners challenge.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate></item><item><title>SR 11-7 Is Dead: What OCC Bulletin 2026-13 and Fed SR 26-2 Mean for Your Model Risk Program</title><link>https://risktemplate.com/blog/2026-05-05-occ-bulletin-2026-13-mrm-revised-guidance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-05-occ-bulletin-2026-13-mrm-revised-guidance/</guid><description>Banking regulators rescinded SR 11-7 and replaced it with principles-based MRM guidance. Here&apos;s what changed and what model risk teams need to do now.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate></item><item><title>SEC Settles With Musk for $1.5M Over 11-Day Twitter Disclosure Delay: What Compliance Officers Should Take Away</title><link>https://risktemplate.com/blog/2026-05-05-sec-elon-musk-twitter-13d-settlement-beneficial-ownership/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-05-sec-elon-musk-twitter-13d-settlement-beneficial-ownership/</guid><description>The SEC just closed the largest Section 13(d) penalty in agency history — $1.5M against the Elon Musk Revocable Trust for an 11-day delay disclosing a 5%+ stake in Twitter. Here&apos;s what every compliance officer monitoring the 5% threshold needs to know.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate></item><item><title>Compliance Monitoring and Testing: How to Build a Risk-Based Program That Survives an Exam</title><link>https://risktemplate.com/blog/2026-05-04-compliance-monitoring-testing-plan-risk-based/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-04-compliance-monitoring-testing-plan-risk-based/</guid><description>Examiners evaluate your compliance testing for substance, not form. A schedule that exists but produces no escalations is a red flag. Here&apos;s how to build a risk-based monitoring and testing program that actually holds up.</description><pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate></item><item><title>Customer Identification Program (CIP) Template: What Banks and Fintechs Must Document at Account Opening</title><link>https://risktemplate.com/blog/2026-05-04-customer-identification-program-cip-template-banks-fintechs/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-04-customer-identification-program-cip-template-banks-fintechs/</guid><description>Build a defensible CIP under 31 CFR 1020.220. Required data, verification methods, the 2025 TIN exemption, and lessons from the LPL Financial $18M fine.</description><pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate></item><item><title>Risk Matrix Template: 5x5 vs 3x3 vs Heat Map — Which to Use and How to Defend It</title><link>https://risktemplate.com/blog/2026-05-04-risk-matrix-template-5x5-vs-3x3-heat-map/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-04-risk-matrix-template-5x5-vs-3x3-heat-map/</guid><description>A risk matrix is only as good as the calibration behind it. Here&apos;s how to choose between 5x5 and 3x3, build defensible scoring criteria, and present the result in a way regulators and boards actually trust.</description><pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate></item><item><title>Risk Register Template: A Fintech Edition with 30+ Real Risk Examples and Scoring</title><link>https://risktemplate.com/blog/2026-05-04-risk-register-template-fintech-examples-scoring/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-04-risk-register-template-fintech-examples-scoring/</guid><description>Build a fintech risk register that survives examiner scrutiny. 30+ real risks across BaaS, fraud, vendor, AI, and compliance — with scoring, owners, and controls.</description><pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate></item><item><title>Cloud Concentration Risk: When Your AWS, Azure, or GCP Dependency Becomes a Regulatory Problem</title><link>https://risktemplate.com/blog/2026-05-03-cloud-concentration-risk-hyperscaler-regulatory-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-03-cloud-concentration-risk-hyperscaler-regulatory-compliance/</guid><description>DORA designated AWS, Microsoft, and Google Cloud as Critical ICT Third-Party Providers in November 2025 — the first formal regulatory oversight of hyperscalers in financial services. Here&apos;s how to assess, document, and manage cloud concentration risk before your next examination.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate></item><item><title>CBLR Drops to 8 Percent: What Community Banks Need to Update Before July 1</title><link>https://risktemplate.com/blog/2026-05-03-community-bank-leverage-ratio-final-rule-8-percent-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-03-community-bank-leverage-ratio-final-rule-8-percent-2026/</guid><description>Federal banking agencies finalized the 8% Community Bank Leverage Ratio with a 4-quarter grace period, effective July 1, 2026. Practitioner playbook for opt-in decisions and capital reporting.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate></item><item><title>EU AI Act GPAI Obligations: What Providers and Downstream Deployers Must Do in 2026</title><link>https://risktemplate.com/blog/2026-05-03-eu-ai-act-gpai-model-obligations-compliance-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-03-eu-ai-act-gpai-model-obligations-compliance-2026/</guid><description>EU AI Act GPAI model obligations went live August 2, 2025. Enforcement fines up to 3% of global turnover kick in August 2, 2026. Here&apos;s what every general-purpose AI provider must document, what systemic risk triggers, and what downstream deployers need from their vendors.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate></item><item><title>FTC Safeguards Rule: The 9-Element Compliance Checklist for Non-Bank Financial Institutions</title><link>https://risktemplate.com/blog/2026-05-03-ftc-safeguards-rule-compliance-nonbank-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-03-ftc-safeguards-rule-compliance-nonbank-financial-institutions/</guid><description>The FTC Safeguards Rule (16 CFR Part 314) applies to fintechs, mortgage brokers, auto dealers, tax preparers, and investment advisors — not just banks. Penalties reach $51,744 per violation per day. Here&apos;s what the 2021 and 2023 amendments require, what companies keep missing, and how to close the gaps.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate></item><item><title>GDPR Enforcement in 2025: €1 Billion in Fines, TikTok&apos;s €530M Penalty, and What US Companies Keep Getting Wrong</title><link>https://risktemplate.com/blog/2026-05-03-gdpr-enforcement-fines-2025-us-companies/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-03-gdpr-enforcement-fines-2025-us-companies/</guid><description>GDPR fines exceeded €1 billion in 2025 alone — eight of the ten biggest penalties hit US companies. TikTok&apos;s €530M fine, LinkedIn&apos;s €310M, and Google&apos;s third escalating penalty reveal a predictable enforcement pattern. Here&apos;s what practitioners need to fix before an inquiry lands.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate></item><item><title>SEC Charges Jay Lucas in $50M Private Equity Fraud: The Control Failures That Let It Run 12 Years</title><link>https://risktemplate.com/blog/2026-05-03-sec-jay-lucas-50m-private-equity-fraud-controls/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-03-sec-jay-lucas-50m-private-equity-fraud-controls/</guid><description>SEC charged Jay Lucas and Lucas Brand Equity with $50M fraud after 12 years of misappropriation. The control failures every PE adviser and CCO needs to fix.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate></item><item><title>CFP Testing Under the 2023 Interagency Addendum: What Regulators Expect</title><link>https://risktemplate.com/blog/2026-05-03-test-contingency-funding-plan-tabletop-exercises/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-03-test-contingency-funding-plan-tabletop-exercises/</guid><description>The 2023 Interagency Addendum specifically requires tested access to contingent funding sources. Here&apos;s how OCC, FDIC, NCUA, and Federal Reserve teams evaluate the testing record — with after-action review templates.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate></item><item><title>Fourth-Party Risk: When Your Vendor&apos;s Vendor Becomes Your Problem</title><link>https://risktemplate.com/blog/2026-05-02-fourth-party-risk-vendor-vendor-problem/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-02-fourth-party-risk-vendor-vendor-problem/</guid><description>Fourth-party risk is the gap most TPRM programs ignore — until a subcontractor takes down operations. Here&apos;s how to map, monitor, and contract for it.</description><pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate></item><item><title>Fourth-Party Risk in 2026: NYDFS, DORA, and the MOVEit/SolarWinds Lessons</title><link>https://risktemplate.com/blog/2026-05-02-fourth-party-risk-vendors-vendor-problem/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-02-fourth-party-risk-vendors-vendor-problem/</guid><description>Fourth-party risk took down thousands of organizations via MOVEit, SolarWinds, and CrowdStrike. NYDFS October 2025 and DORA Articles 28-29 now codify what banks have to manage downstream. Here&apos;s the practical program.</description><pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate></item><item><title>NIST Incident Response Framework: SP 800-61 Rev. 3 Explained</title><link>https://risktemplate.com/blog/2026-05-02-nist-incident-response-framework-sp-800-61-rev-3-explained/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-02-nist-incident-response-framework-sp-800-61-rev-3-explained/</guid><description>NIST SP 800-61 Rev. 3 was finalized April 3, 2025, withdrawing the 2012 Rev. 2 that most incident response programs were built on. Here&apos;s what changed, what the CSF 2.0 restructuring means for your IR program, and what you need to update.</description><pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate></item><item><title>OCC, Fed, and FDIC Just Replaced SR 11-7. Here&apos;s What Changed in the New Model Risk Management Guidance</title><link>https://risktemplate.com/blog/2026-05-02-occ-fed-fdic-revised-model-risk-management-guidance-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-02-occ-fed-fdic-revised-model-risk-management-guidance-2026/</guid><description>The 2026 interagency model risk management guidance retires SR 11-7 and OCC 2011-12. Principles-based, $30B threshold, AI carved out. What MRM teams need to do.</description><pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate></item><item><title>State Breach Notification Laws: 50-State Comparison and How to Track Deadlines</title><link>https://risktemplate.com/blog/2026-05-02-state-breach-notification-laws-50-state-comparison/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-02-state-breach-notification-laws-50-state-comparison/</guid><description>All 50 states have breach notification laws with varying deadlines, covered data types, and penalties. California just tightened its timeline to 30 days effective January 2026. Here&apos;s the practical guide to managing the patchwork.</description><pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate></item><item><title>Vendor Onboarding Process: The Compliance Steps Most Companies Skip</title><link>https://risktemplate.com/blog/2026-05-02-vendor-onboarding-process-compliance-steps-most-companies-skip/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-02-vendor-onboarding-process-compliance-steps-most-companies-skip/</guid><description>Most vendor onboarding programs are procurement checklists with compliance labels. Here are the eight steps that get skipped most often — and what the 2023 OCC/FDIC/Fed interagency guidance actually requires before you grant a vendor access.</description><pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate></item><item><title>Cyber Incident Response Playbook: From Detection to Lessons Learned</title><link>https://risktemplate.com/blog/2026-05-01-cyber-incident-response-playbook-detection-to-lessons-learned/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-01-cyber-incident-response-playbook-detection-to-lessons-learned/</guid><description>A step-by-step cyber incident response playbook covering all six phases: preparation, detection and analysis, containment, eradication, recovery, and post-incident review. Includes NIST SP 800-61 Rev. 3 alignment and CIRCIA reporting integration.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate></item><item><title>DOJ Busts $5M Bank Fraud &amp; Mail Theft Ring: Key Lessons for Financial Professionals</title><link>https://risktemplate.com/blog/2026-05-01-doj-bank-fraud-mail-theft-scheme-lessons/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-01-doj-bank-fraud-mail-theft-scheme-lessons/</guid><description>Learn critical lessons for financial institutions from the DOJ&apos;s recent $5 million bank fraud and mail theft indictment, focusing on insider threats and control gaps.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate></item><item><title>RCSA Methodology: Workshop Facilitation, Scoring, and the Pitfalls That Kill Most Programs</title><link>https://risktemplate.com/blog/2026-05-01-rcsa-methodology-workshop-facilitation-scoring-pitfalls/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-01-rcsa-methodology-workshop-facilitation-scoring-pitfalls/</guid><description>How to actually run a Risk and Control Self-Assessment — workshop prep, scoring matrices, inherent vs residual logic, and the seven pitfalls that turn RCSA into a check-the-box exercise.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate></item><item><title>SOC 2 vs ISO 27001: When to Pick Which (and When You Need Both)</title><link>https://risktemplate.com/blog/2026-05-01-soc-2-vs-iso-27001-when-to-pick-which/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-01-soc-2-vs-iso-27001-when-to-pick-which/</guid><description>SOC 2 or ISO 27001? The right answer depends on your market, timeline, and customer base — not on which framework sounds more rigorous. A practitioner&apos;s comparison of costs, timelines, control overlap, and when both are worth it.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate></item><item><title>The Three Lines of Defense Model: Roles, Responsibilities, and Where It Breaks</title><link>https://risktemplate.com/blog/2026-05-01-three-lines-of-defense-roles-responsibilities-where-it-breaks/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-01-three-lines-of-defense-roles-responsibilities-where-it-breaks/</guid><description>The Three Lines of Defense (now Three Lines Model) defines how risk ownership, oversight, and independent assurance divide across an organization. Here&apos;s what each line actually does, the 2020 IIA update, and the failure modes that cause the whole thing to collapse.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate></item><item><title>Vendor Risk Assessment Template: What to Ask Vendors Before You Sign</title><link>https://risktemplate.com/blog/2026-05-01-vendor-risk-assessment-template-questions-to-ask/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-01-vendor-risk-assessment-template-questions-to-ask/</guid><description>A practical vendor risk assessment template — the question domains, scoring approach, evidence to demand, and red flags that should kill a vendor before contract signature.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate></item><item><title>Vendor Risk Tiering: How to Classify Vendors by Criticality (Without 200 Categories)</title><link>https://risktemplate.com/blog/2026-05-01-vendor-risk-tiering-how-to-classify-vendors-by-criticality/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-05-01-vendor-risk-tiering-how-to-classify-vendors-by-criticality/</guid><description>A practical vendor risk tiering framework for compliance and risk teams: four scoring dimensions, four-tier model, and what each tier means for due diligence, monitoring, and examiner expectations under the 2023 OCC/FDIC/Fed interagency guidance.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate></item><item><title>Key Risk Indicators (KRIs): A Practitioner&apos;s Guide with 50+ Examples by Risk Domain</title><link>https://risktemplate.com/blog/2026-04-30-key-risk-indicators-kri-guide-50-examples-by-domain/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-30-key-risk-indicators-kri-guide-50-examples-by-domain/</guid><description>What KRIs actually are, how to design and threshold them, and 50+ ready-to-use examples across operational, credit, compliance, cyber, liquidity, third-party, and model risk domains.</description><pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate></item><item><title>SOC 2 Readiness Assessment: How to Run a Gap Analysis Before the Auditor Shows Up</title><link>https://risktemplate.com/blog/2026-04-30-soc-2-readiness-assessment-gap-analysis-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-30-soc-2-readiness-assessment-gap-analysis-guide/</guid><description>How to run a SOC 2 readiness gap analysis: the 4-phase process, most common findings, remediation priorities, and the 60–120 day timeline from gap to clean Type 1 report.</description><pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Risk Appetite Statement: How to Write One Your Board Will Actually Approve</title><link>https://risktemplate.com/blog/2026-04-29-risk-appetite-statement-how-to-write-board-approval/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-29-risk-appetite-statement-how-to-write-board-approval/</guid><description>How to write a risk appetite statement that survives board scrutiny: the three-tier structure, qualitative vs quantitative elements, and how to make it operational.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate></item><item><title>SOC 2 Compliance Checklist: The Controls Auditors Actually Test</title><link>https://risktemplate.com/blog/2026-04-29-soc-2-compliance-checklist-controls-auditors-test/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-29-soc-2-compliance-checklist-controls-auditors-test/</guid><description>SOC 2 compliance checklist mapped to all 9 Common Criteria: exact controls, evidence requirements, and the top audit exceptions that cause clean reports to go sideways.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate></item><item><title>How to Build an Enterprise Risk Management Framework from Scratch</title><link>https://risktemplate.com/blog/2026-04-28-how-to-build-enterprise-risk-management-framework-from-scratch/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-28-how-to-build-enterprise-risk-management-framework-from-scratch/</guid><description>Step-by-step guide to building an ERM framework: governance structure, risk appetite, risk taxonomy, RCSA, KRIs, and board reporting that actually works.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate></item><item><title>OCC Bulletin 2026-13: What the Agencies&apos; Model Risk Management Overhaul Actually Means for Your Program</title><link>https://risktemplate.com/blog/2026-04-28-occ-bulletin-2026-13-model-risk-management-guidance-update/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-28-occ-bulletin-2026-13-model-risk-management-guidance-update/</guid><description>OCC, Fed, and FDIC rescinded SR 11-7 and OCC 2011-12 on April 17, 2026. Here&apos;s what changed, what&apos;s gone, and what practitioners need to do now under OCC Bulletin 2026-13.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate></item><item><title>SOC 2 Type 1 vs Type 2: Which One Do You Actually Need?</title><link>https://risktemplate.com/blog/2026-04-28-soc-2-type-1-vs-type-2-which-one-do-you-actually-need/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-28-soc-2-type-1-vs-type-2-which-one-do-you-actually-need/</guid><description>SOC 2 Type 1 vs Type 2 explained: cost, timeline, what enterprise buyers actually accept, and when skipping straight to Type 2 is the right call.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate></item><item><title>COSO ERM Framework Explained: The 5 Components and 20 Principles</title><link>https://risktemplate.com/blog/2026-04-27-coso-erm-framework-5-components-20-principles/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-27-coso-erm-framework-5-components-20-principles/</guid><description>COSO ERM 2017 framework explained: 5 components, all 20 principles, and how to implement it in your organization without creating a shelf document.</description><pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Incident Response Plan Template: The 6 Phases (and What Most Templates Miss)</title><link>https://risktemplate.com/blog/2026-04-27-incident-response-plan-template-6-phases-what-templates-miss/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-27-incident-response-plan-template-6-phases-what-templates-miss/</guid><description>A practical guide to the 6-phase incident response lifecycle — Preparation through Lessons Learned — including what most IRP templates overlook: notification timelines, CIRCIA requirements, and NIST SP 800-61 Rev. 3.</description><pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate></item><item><title>SEC Bars &quot;Dr. Cash&quot; After $5M Ponzi Scheme — And What It Signals for Adviser Compliance in 2026</title><link>https://risktemplate.com/blog/2026-04-27-sec-terrence-chalk-dr-cash-ponzi-fraud/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-27-sec-terrence-chalk-dr-cash-ponzi-fraud/</guid><description>Terrence Chalk, aka Dr. Cash, ran a Ponzi scheme targeting retirees for three years before the SEC and FBI caught up. Here&apos;s what compliance teams need to know.</description><pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Vendor Risk Management: The Complete Process from Onboarding to Offboarding</title><link>https://risktemplate.com/blog/2026-04-27-vendor-risk-management-complete-process-onboarding-offboarding/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-27-vendor-risk-management-complete-process-onboarding-offboarding/</guid><description>The complete vendor risk management lifecycle explained: risk tiering, due diligence, contract controls, ongoing monitoring, and secure offboarding. Based on the 2023 OCC/FDIC/Fed interagency guidance.</description><pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate></item><item><title>What Is SOC 2 Compliance? A Practitioner&apos;s Guide for First-Timers</title><link>https://risktemplate.com/blog/2026-04-27-what-is-soc-2-compliance-practitioner-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-27-what-is-soc-2-compliance-practitioner-guide/</guid><description>SOC 2 compliance explained for practitioners: Trust Service Criteria, Type 1 vs Type 2, common audit findings, and how to get started.</description><pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate></item><item><title>DOJ Scam Center Strike Force Seizes $702M in Crypto: What Pig-Butchering Means for Your AML Program</title><link>https://risktemplate.com/blog/2026-04-26-doj-scam-center-strike-force-pig-butchering-702-million-aml-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-26-doj-scam-center-strike-force-pig-butchering-702-million-aml-compliance/</guid><description>The DOJ restrained $702M in crypto from pig-butchering scams and OFAC sanctioned 29 Cambodian entities including a bank. Here&apos;s what US compliance teams must do now.</description><pubDate>Sun, 26 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Building an EWI Framework: The M.E.R.I.T. Approach to Liquidity Risk Monitoring</title><link>https://risktemplate.com/blog/2026-04-26-early-warning-indicators-liquidity-stress-triggers/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-26-early-warning-indicators-liquidity-stress-triggers/</guid><description>A practical framework for designing Early Warning Indicators that actually trigger action — Measures, Escalation, Reporting, Integrated systems, and Thresholds. Aligned to BCBS, OCC, and Federal Reserve expectations.</description><pubDate>Sun, 26 Apr 2026 00:00:00 GMT</pubDate></item><item><title>GenAI Supply Chain Risk: Third-Party Model Dependencies and NIST AI 600-1 Controls</title><link>https://risktemplate.com/blog/2026-04-26-genai-supply-chain-risk-third-party-model-dependencies-nist-ai-600-1/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-26-genai-supply-chain-risk-third-party-model-dependencies-nist-ai-600-1/</guid><description>Most financial institutions using GenAI APIs don&apos;t fully own their AI supply chain. NIST AI 600-1 says that&apos;s your problem. Here&apos;s what you need to control.</description><pubDate>Sun, 26 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Developer vs. Deployer vs. Operator: Role-Specific Obligations Under NIST AI 600-1</title><link>https://risktemplate.com/blog/2026-04-26-nist-ai-600-1-developer-deployer-operator-roles-obligations/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-26-nist-ai-600-1-developer-deployer-operator-roles-obligations/</guid><description>NIST AI 600-1 assigns different GenAI risk obligations to developers, deployers, and operators. Here&apos;s what each role actually owns—and where the gaps live.</description><pubDate>Sun, 26 Apr 2026 00:00:00 GMT</pubDate></item><item><title>$14M BEC Extradition: How Credential Phishing Bypasses Your Controls — and What to Do About It</title><link>https://risktemplate.com/blog/2026-04-25-doj-bec-credential-phishing-travel-agency-extradition-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-25-doj-bec-credential-phishing-travel-agency-extradition-compliance/</guid><description>DOJ extradited an Ivorian national for a $14M BEC phishing scheme targeting travel agencies. Here&apos;s how the attack worked and the 5 controls that could have stopped it.</description><pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Generative AI Incident Disclosure and Content Provenance: NIST AI 600-1 Requirements</title><link>https://risktemplate.com/blog/2026-04-25-genai-incident-disclosure-content-provenance-nist-ai-600-1/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-25-genai-incident-disclosure-content-provenance-nist-ai-600-1/</guid><description>What NIST AI 600-1 requires when your GenAI system fails: incident disclosure obligations, after-action review requirements, and content provenance tracking.</description><pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate></item><item><title>The $50 Million Cookie Jar: SEC Charges PE Firm Founder Jay Lucas with Investment Adviser Fraud</title><link>https://risktemplate.com/blog/2026-04-25-jay-lucas-lucas-brand-equity-sec-private-equity-fraud/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-25-jay-lucas-lucas-brand-equity-sec-private-equity-fraud/</guid><description>SEC filed a civil complaint against Jay Lucas and Lucas Brand Equity LLC on April 24, 2026, alleging he raised $50M from investors and spent it on his wife&apos;s skincare company, alimony, and luxury expenses.</description><pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate></item><item><title>$5 Million Final Judgment: SEC&apos;s Forex Ponzi Case Against John Fernandez Shows How Unregistered Offerings Collapse</title><link>https://risktemplate.com/blog/2026-04-25-john-fernandez-avail-progression-forex-fraud-final-judgment/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-25-john-fernandez-avail-progression-forex-fraud-final-judgment/</guid><description>A federal court entered a $5 million final judgment against John Fernandez, Avail Progression LLC, and Elite Generators LLC for running unregistered forex Ponzi schemes targeting 100+ investors.</description><pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate></item><item><title>OCC Preempts Illinois Interchange Fee Law: What National Banks Need to Know Before July 1, 2026</title><link>https://risktemplate.com/blog/2026-04-25-occ-illinois-interchange-fee-prohibition-act-preemption-national-banks/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-25-occ-illinois-interchange-fee-prohibition-act-preemption-national-banks/</guid><description>The OCC issued two interim final actions preempting the Illinois Interchange Fee Prohibition Act. National banks and federal savings associations are not required to comply with the Illinois IFPA.</description><pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate></item><item><title>TEVV for Generative AI: Pre-Deployment Testing Requirements Under NIST AI 600-1</title><link>https://risktemplate.com/blog/2026-04-25-tevv-generative-ai-pre-deployment-testing-nist-ai-600-1/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-25-tevv-generative-ai-pre-deployment-testing-nist-ai-600-1/</guid><description>What NIST AI 600-1 requires before you deploy any GenAI system: the full TEVV testing protocol across all 12 risk categories, red-team requirements, and go/no-go gates.</description><pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate></item><item><title>FINRA Fines JPMorgan Securities $3.25M for Ignoring 10,000 Supervisory Alerts</title><link>https://risktemplate.com/blog/2026-04-24-finra-jpmorgan-securities-supervision-failure-rule-3110-10000-alerts/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-24-finra-jpmorgan-securities-supervision-failure-rule-3110-10000-alerts/</guid><description>FINRA&apos;s JPMorgan Securities action shows Rule 3110 compliance requires actual review — not just alert generation. Here&apos;s what compliance teams must fix now.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Confabulation and Hallucination Risk: What NIST AI 600-1 Says and How to Test for It</title><link>https://risktemplate.com/blog/2026-04-24-nist-ai-600-1-confabulation-hallucination-testing/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-24-nist-ai-600-1-confabulation-hallucination-testing/</guid><description>NIST AI 600-1 names confabulation as one of 12 GenAI risk categories. Here&apos;s what the framework actually requires — and how to build a testing program that satisfies it.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate></item><item><title>NIST AI RMF for Financial Services: Crosswalk to SR 26-02, OCC 2026-13, and FS AI RMF</title><link>https://risktemplate.com/blog/2026-04-24-nist-ai-rmf-sr-26-02-fs-ai-rmf-crosswalk-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-24-nist-ai-rmf-sr-26-02-fs-ai-rmf-crosswalk-financial-services/</guid><description>Three AI risk frameworks now apply to financial services. Here&apos;s how NIST AI RMF, SR 26-02, and the Treasury FS AI RMF fit together — and which one covers what.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Sripetch v. SEC: The Supreme Court Case That Could Reshape Every SEC Enforcement Settlement</title><link>https://risktemplate.com/blog/2026-04-24-sripetch-v-sec-supreme-court-disgorgement-enforcement/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-24-sripetch-v-sec-supreme-court-disgorgement-enforcement/</guid><description>SCOTUS heard oral argument April 20 in Sripetch v. SEC. The ruling will determine if the SEC must prove investor losses before seeking disgorgement — $6B+ per year at stake.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate></item><item><title>2026 Crypto Compliance Roadmap: Preparing for the GENIUS Act and CLARITY Act</title><link>https://risktemplate.com/blog/2026-04-23-2026-crypto-compliance-roadmap-genius-act-clarity-act/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-23-2026-crypto-compliance-roadmap-genius-act-clarity-act/</guid><description>Your compliance calendar for the two biggest US crypto laws: GENIUS Act deadlines, CLARITY Act status, California DFAL, and what to build before January 2027.</description><pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate></item><item><title>CFPB Finalizes ECOA Rule Eliminating Disparate Impact: What Your Fair Lending Program Must Do Now</title><link>https://risktemplate.com/blog/2026-04-23-cfpb-ecoa-disparate-impact-eliminated-regulation-b-fair-lending-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-23-cfpb-ecoa-disparate-impact-eliminated-regulation-b-fair-lending-compliance/</guid><description>CFPB&apos;s April 22 final rule removes disparate impact from Regulation B. Federal fair lending just changed permanently — but state exposure didn&apos;t. Here&apos;s what compliance teams need to act on before July 21.</description><pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate></item><item><title>The 7 Trustworthy AI Characteristics in NIST AI 100-1: What Compliance Teams Need to Know</title><link>https://risktemplate.com/blog/2026-04-23-nist-ai-100-1-seven-trustworthy-ai-characteristics-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-23-nist-ai-100-1-seven-trustworthy-ai-characteristics-compliance/</guid><description>NIST AI 100-1 defines seven trustworthiness characteristics that underpin the entire AI RMF. Here&apos;s what each one means, how they interact, the trade-offs NIST acknowledges, and how regulators are using them in exams.</description><pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate></item><item><title>NIST AI RMF MANAGE Function: How to Prioritize, Treat, and Monitor AI Risks in Production</title><link>https://risktemplate.com/blog/2026-04-23-nist-ai-rmf-manage-function-prioritize-treat-monitor-ai-risks/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-23-nist-ai-rmf-manage-function-prioritize-treat-monitor-ai-risks/</guid><description>The MANAGE function is where NIST AI RMF turns risk assessment into operational decisions. Learn what MG-1 through MG-4 require, how to structure risk treatment decisions, and what continuous AI risk monitoring looks like in practice.</description><pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate></item><item><title>NIST AI RMF MEASURE Function: TEVV, Bias Testing, and Metrics That Actually Matter</title><link>https://risktemplate.com/blog/2026-04-23-nist-ai-rmf-measure-function-tevv-bias-testing-metrics/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-23-nist-ai-rmf-measure-function-tevv-bias-testing-metrics/</guid><description>How to implement the NIST AI RMF MEASURE function: TEVV methodology, 13 trustworthy characteristic subcategories, bias testing, and financial services alignment.</description><pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate></item><item><title>NIST AI RMF MAP Function: How to Frame AI Risk Context Before You Build or Deploy</title><link>https://risktemplate.com/blog/2026-04-22-nist-ai-rmf-map-function-ai-risk-context-framing/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-22-nist-ai-rmf-map-function-ai-risk-context-framing/</guid><description>The MAP function is where NIST AI RMF risk management actually starts. Learn what MAP 1-5 require, how financial institutions implement them, and why most teams get this wrong.</description><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate></item><item><title>State Money Transmitter Licensing for Crypto: The Patchwork Compliance Challenge</title><link>https://risktemplate.com/blog/2026-04-22-state-money-transmitter-license-crypto-patchwork-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-22-state-money-transmitter-license-crypto-patchwork-compliance/</guid><description>49 states require money transmitter licenses for crypto businesses. OKX paid $505M for getting this wrong. Here&apos;s the state-by-state breakdown and how to build your licensing strategy.</description><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Voyager Pacific Capital&apos;s $25M Ponzi: What the SEC + DOJ Double Tap Means for Investment Advisers</title><link>https://risktemplate.com/blog/2026-04-22-voyager-pacific-capital-ponzi-fraud-sec-doj-compliance-lessons/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-22-voyager-pacific-capital-ponzi-fraud-sec-doj-compliance-lessons/</guid><description>The SEC charged Voyager Pacific Capital Management in a $25M real estate Ponzi that ran five years. Here&apos;s what compliance teams must fix before examiners ask.</description><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Agentic AI Governance: The Compliance Gap Nobody&apos;s Talking About</title><link>https://risktemplate.com/blog/2026-04-21-agentic-ai-governance-compliance-gap/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-21-agentic-ai-governance-compliance-gap/</guid><description>SR 11-7, Reg E, and UDAAP weren&apos;t built for AI that acts autonomously. Here&apos;s where your compliance program has a blind spot—and what to build before regulators close it.</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Stablecoin Compliance Under the GENIUS Act: Consumer Protection Requirements Explained</title><link>https://risktemplate.com/blog/2026-04-21-stablecoin-compliance-genius-act-consumer-protection/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-21-stablecoin-compliance-genius-act-consumer-protection/</guid><description>The GENIUS Act is law. Here&apos;s what permitted payment stablecoin issuers owe consumers—reserve requirements, redemption policies, fee disclosures, and bankruptcy protections.</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Continuous Monitoring for AI Models: Drift, Degradation, and Compliance Triggers</title><link>https://risktemplate.com/blog/2026-04-20-continuous-monitoring-ai-models-drift-degradation-compliance-triggers/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-20-continuous-monitoring-ai-models-drift-degradation-compliance-triggers/</guid><description>SR 11-7 ongoing monitoring for AI models — drift detection, PSI thresholds, re-validation triggers, and what OCC examiners check in 2026.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Crypto Complaint Handling: Preparing Your Platform for CFPB Scrutiny</title><link>https://risktemplate.com/blog/2026-04-20-crypto-complaint-handling-cfpb-scrutiny-platform-preparation/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-20-crypto-complaint-handling-cfpb-scrutiny-platform-preparation/</guid><description>CFPB pulled back, but state AGs and the GENIUS Act mean crypto platforms still need robust complaint handling. Here&apos;s what the Bitcoin Depot lawsuit revealed — and what your program needs.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>AI Model Validation Best Practices: Why Traditional Testing Breaks with Generative AI</title><link>https://risktemplate.com/blog/2026-04-19-ai-model-validation-best-practices-generative-ai/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-19-ai-model-validation-best-practices-generative-ai/</guid><description>Traditional SR 11-7 validation breaks with generative AI. Learn why deterministic testing fails for LLMs and what new validation approaches financial services firms actually need.</description><pubDate>Sun, 19 Apr 2026 00:00:00 GMT</pubDate></item><item><title>SEC&apos;s $16M Bitcoin Latinum Case: Why &apos;Insured&apos; Crypto Claims Are a Red Flag, Not a Safety Net</title><link>https://risktemplate.com/blog/2026-04-19-bitcoin-latinum-donald-basile-sec-saft-fraud-insured-crypto-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-19-bitcoin-latinum-donald-basile-sec-saft-fraud-insured-crypto-compliance/</guid><description>SEC charges Donald Basile with $16M SAFT fraud using fake &apos;insured&apos; crypto claims. What compliance teams need to know about SAFT red flags and crypto CDD.</description><pubDate>Sun, 19 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Ranking Contingent Funding Sources: FHLB, Discount Window &amp; Repo for Your CFP</title><link>https://risktemplate.com/blog/2026-04-19-contingent-funding-sources-ranking-framework/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-19-contingent-funding-sources-ranking-framework/</guid><description>A tiered ranking framework for the actual contingent funding sources in your CFP — speed, capacity, cost, and stigma. Documented to satisfy the 2023 Interagency Addendum&apos;s tested-access requirement.</description><pubDate>Sun, 19 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Hidden Wealth, Hidden Commissions: The SEC&apos;s $82M Radio Show Oil &amp; Gas Fraud and What It Exposes About OBA Oversight</title><link>https://risktemplate.com/blog/2026-04-19-sec-hidden-wealth-radio-oil-gas-fraud-outside-business-activity-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-19-sec-hidden-wealth-radio-oil-gas-fraud-outside-business-activity-compliance/</guid><description>Three &apos;advisers&apos; used radio shows and podcasts to sell $82M in unregistered oil &amp; gas securities — pocketing $5.7M without disclosing it. Here&apos;s the OBA and RIA compliance breakdown.</description><pubDate>Sun, 19 Apr 2026 00:00:00 GMT</pubDate></item><item><title>UDAAP in Crypto: Why State Attorneys General Are Your New Enforcement Risk</title><link>https://risktemplate.com/blog/2026-04-19-udaap-crypto-state-ag-enforcement-risk/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-19-udaap-crypto-state-ag-enforcement-risk/</guid><description>DOJ dismantled its crypto enforcement unit. State AGs filled the vacuum — with UDAP laws that don&apos;t require proof of harm. Here&apos;s what crypto compliance teams need to know.</description><pubDate>Sun, 19 Apr 2026 00:00:00 GMT</pubDate></item><item><title>AI Explainability Documentation: How to Show Your Work to Examiners</title><link>https://risktemplate.com/blog/2026-04-18-ai-explainability-documentation-show-work-examiners/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-18-ai-explainability-documentation-show-work-examiners/</guid><description>The model risk framework just changed. OCC 2026-13 is principles-based, GenAI is excluded, and CFPB still demands specific adverse action reasons. Here&apos;s what your explainability documentation package needs.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Building a Compliance Management System That Survives a CFPB Exam</title><link>https://risktemplate.com/blog/2026-04-18-building-compliance-management-system-cfpb-exam/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-18-building-compliance-management-system-cfpb-exam/</guid><description>The CFPB&apos;s Compliance Management Review evaluates four components — Board Oversight, Compliance Program, Consumer Complaint Response, and Compliance Audit. Here&apos;s how to build a CMS that functions every day, not just for exam prep.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Fintech Consumer Compliance Roadmap: TILA, GLBA, and State Licensing Requirements</title><link>https://risktemplate.com/blog/2026-04-18-fintech-consumer-compliance-roadmap-tila-glba-state-licensing/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-18-fintech-consumer-compliance-roadmap-tila-glba-state-licensing/</guid><description>Fintechs face a layered consumer compliance stack — TILA disclosures, GLBA Safeguards Rule, ECOA adverse action notices, and state-by-state money transmitter licensing. Here&apos;s how to sequence the build and what each layer actually requires.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate></item><item><title>CFP Liquidity Stress Testing: Designing Scenarios That Survive Examiner Review</title><link>https://risktemplate.com/blog/2026-04-18-liquidity-stress-testing-cfp-scenarios-methodology/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-18-liquidity-stress-testing-cfp-scenarios-methodology/</guid><description>Stress testing scenarios that examiners actually accept — idiosyncratic, market-wide, and combined shocks. How to defend your assumptions and integrate results back into your CFP.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate></item><item><title>OCC Bulletin 2011-12 and SR 11-7 Are Officially Rescinded — What Banks Need to Know</title><link>https://risktemplate.com/blog/2026-04-18-occ-bulletin-2011-12-sr-11-7-rescinded-new-model-risk-guidance-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-18-occ-bulletin-2011-12-sr-11-7-rescinded-new-model-risk-guidance-2026/</guid><description>The 15-year model risk framework is gone. OCC 2026-13 and SR 26-2 replace it with tailored, risk-based principles. What changed, what was dropped, and what to do now.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Operational Resilience vs. BIA: The Regulatory Shift from RTOs to Impact Tolerances</title><link>https://risktemplate.com/blog/2026-04-18-operational-resilience-bia-impact-tolerances-vs-rto/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-18-operational-resilience-bia-impact-tolerances-vs-rto/</guid><description>Traditional BIA produces RTOs. Operational resilience requires impact tolerances. They&apos;re different questions with different methodology — here&apos;s how to update your BIA process.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Scattered Spider Member Pleads Guilty: The SMS Phishing Playbook That Breached 130+ Companies</title><link>https://risktemplate.com/blog/2026-04-18-scattered-spider-tyler-buchanan-guilty-plea-sms-phishing-lessons/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-18-scattered-spider-tyler-buchanan-guilty-plea-sms-phishing-lessons/</guid><description>Tyler Buchanan&apos;s April 2026 guilty plea exposes Scattered Spider&apos;s exact attack chain. What every risk and compliance team needs to check after this conviction.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate></item><item><title>What Examiners Find in CFPs: A Component-by-Component Review Guide</title><link>https://risktemplate.com/blog/2026-04-17-contingency-funding-plan-template-components-exam/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-17-contingency-funding-plan-template-components-exam/</guid><description>Walk through each component of a Contingency Funding Plan from the examiner&apos;s perspective. What OCC, FDIC, and Federal Reserve teams actually flag — and how to fix gaps before the exam.</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate></item><item><title>NIST AI RMF GOVERN Function: Building AI Risk Culture, Accountability, and Inventory</title><link>https://risktemplate.com/blog/2026-04-17-nist-ai-rmf-govern-function-ai-risk-culture-accountability-inventory/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-17-nist-ai-rmf-govern-function-ai-risk-culture-accountability-inventory/</guid><description>The GOVERN function is the foundation of NIST AI RMF compliance. Learn what GV-1 through GV-6 actually require and how financial institutions are implementing AI accountability structures.</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate></item><item><title>OCC Nails Chicago Bank for Blasting Veterans with Fake VA Loan Offers</title><link>https://risktemplate.com/blog/2026-04-17-occ-federal-savings-bank-va-loan-deceptive-advertising-veterans-consent-order/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-17-occ-federal-savings-bank-va-loan-deceptive-advertising-veterans-consent-order/</guid><description>The Federal Savings Bank hit with OCC consent order after sending millions of deceptive mailers to veterans falsely claiming &apos;available funds.&apos; Here&apos;s what the UDAP failure means for your consumer compliance program.</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Reg E Is Coming to Crypto: Your Roadmap to EFTA Compliance</title><link>https://risktemplate.com/blog/2026-04-17-reg-e-efta-crypto-compliance-stablecoin-genius-act/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-17-reg-e-efta-crypto-compliance-stablecoin-genius-act/</guid><description>The CFPB tried to extend Reg E to crypto, then withdrew it. The GENIUS Act left a consumer protection gap. Now state AGs are filling the void. Here&apos;s what crypto and stablecoin platforms need to do.</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate></item><item><title>SEC Charges Milpitas Man with $43 Million Ponzi Scheme Targeting Indian American Investors via Telegram</title><link>https://risktemplate.com/blog/2026-04-17-sec-nambiar-spartan-trading-ponzi-telegram-indian-american-fraud/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-17-sec-nambiar-spartan-trading-ponzi-telegram-indian-american-fraud/</guid><description>SEC charges Sudheesh Nambiar with a $43M Ponzi scheme defrauding 400+ Indian American investors through fabricated statements and Telegram chatrooms.</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate></item><item><title>BNPL Compliance After the CFPB Rule Rescission: What You Still Owe Consumers</title><link>https://risktemplate.com/blog/2026-04-16-bnpl-compliance-cfpb-rule-rescission-consumer-obligations/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-16-bnpl-compliance-cfpb-rule-rescission-consumer-obligations/</guid><description>The CFPB rescinded its BNPL interpretive rule in May 2025 — but TILA, UDAP, state laws, and the New York BNPL Act still apply. Here&apos;s what compliance teams can&apos;t ignore.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate></item><item><title>FinCEN&apos;s New BSA Whistleblower Program Changes the Math on Internal Escalation — Especially for Compliance Officers</title><link>https://risktemplate.com/blog/2026-04-16-fincen-bsa-whistleblower-program-proposed-rule-compliance-implications/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-16-fincen-bsa-whistleblower-program-proposed-rule-compliance-implications/</guid><description>FinCEN&apos;s proposed BSA whistleblower rule offers 10-30% of penalties over $1M. Compliance professionals get a 120-day waiting period before they can report externally.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate></item><item><title>FinCEN and OFAC Just Put Stablecoin Issuers Under Bank-Level AML Rules — Here&apos;s What to Build Before January 2027</title><link>https://risktemplate.com/blog/2026-04-16-genius-act-stablecoin-aml-fincen-ofac-ppsi-proposed-rule/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-16-genius-act-stablecoin-aml-fincen-ofac-ppsi-proposed-rule/</guid><description>The GENIUS Act&apos;s AML proposed rule imposes SAR filing, CDD, and sanctions compliance on payment stablecoin issuers. Compliance teams have until January 2027.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Third-Party Dependencies in BIA: How Deep Should You Go?</title><link>https://risktemplate.com/blog/2026-04-16-third-party-dependencies-bia-how-deep/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-16-third-party-dependencies-bia-how-deep/</guid><description>When mapping third-party dependencies in your BIA, one tier isn&apos;t enough for critical functions. Here&apos;s how to scope the analysis — and where going deeper actually matters.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate></item><item><title>BIA for Fintech and SaaS: Mapping Cloud and API Dependencies</title><link>https://risktemplate.com/blog/2026-04-15-bia-fintech-saas-cloud-api-dependencies/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-15-bia-fintech-saas-cloud-api-dependencies/</guid><description>Most fintech BIAs skip the part that matters most: the cloud platforms and third-party APIs your entire business runs on. Here&apos;s how to map those dependencies correctly — and what your bank partners will ask about them.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Business Impact Analysis for Banks: FFIEC Requirements Explained</title><link>https://risktemplate.com/blog/2026-04-15-business-impact-analysis-banks-ffiec-requirements/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-15-business-impact-analysis-banks-ffiec-requirements/</guid><description>What the FFIEC BCM booklet actually requires in your BIA — critical function identification, interdependency analysis, recovery objectives, and what Appendix A examiners test at your next IT exam.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Fair Lending Compliance in 2026: State AG Enforcement Is Filling the Federal Void</title><link>https://risktemplate.com/blog/2026-04-15-fair-lending-compliance-2026-state-ag-enforcement/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-15-fair-lending-compliance-2026-state-ag-enforcement/</guid><description>The CFPB closed disparate impact investigations and federal examiners stopped looking. State AGs didn&apos;t. Here&apos;s what your fair lending program needs to do now.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate></item><item><title>NIST AI 600-1: The Generative AI Profile and Its 12 Risk Categories Explained</title><link>https://risktemplate.com/blog/2026-04-15-nist-ai-600-1-generative-ai-profile-12-risk-categories/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-15-nist-ai-600-1-generative-ai-profile-12-risk-categories/</guid><description>NIST AI 600-1 defines 12 GenAI-specific risk categories and 200+ controls. Here&apos;s what financial services teams need before examiners start asking.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Death Didn&apos;t Stop the SEC: Spartan Trading&apos;s Ponzi Scheme and What Investment Advisers Must Know</title><link>https://risktemplate.com/blog/2026-04-15-sec-spartan-trading-ponzi-estate-enforcement-investment-adviser/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-15-sec-spartan-trading-ponzi-estate-enforcement-investment-adviser/</guid><description>The SEC is still pursuing the Spartan Trading Company fraud case in 2026 — years after the principals died in a murder-suicide. Here&apos;s what investment advisers need to know.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate></item><item><title>AI and Fair Lending: UDAAP Risk in Algorithmic Decisioning</title><link>https://risktemplate.com/blog/2026-04-14-ai-fair-lending-udaap-risk-algorithmic-decisioning/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-14-ai-fair-lending-udaap-risk-algorithmic-decisioning/</guid><description>CFPB&apos;s UDAAP-as-discrimination gambit was vacated, but adverse action notice requirements still bite. Here&apos;s what AI lenders actually owe consumers in 2026.</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate></item><item><title>BIA Data Collection: Surveys vs. Interviews vs. Workshops</title><link>https://risktemplate.com/blog/2026-04-14-bia-data-collection-surveys-interviews-workshops/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-14-bia-data-collection-surveys-interviews-workshops/</guid><description>The method you choose for BIA data collection determines whether your RTOs reflect operational reality or wishful thinking. A practitioner&apos;s guide to surveys, interviews, and workshops — when each method works, where each fails, and how to combine them.</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate></item><item><title>DOJ&apos;s New National Fraud Enforcement Division: What Compliance Programs Need to Know Now</title><link>https://risktemplate.com/blog/2026-04-14-doj-national-fraud-enforcement-division-compliance-implications/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-14-doj-national-fraud-enforcement-division-compliance-implications/</guid><description>The DOJ&apos;s NFED consolidates healthcare fraud, tax, and market fraud units under one command. Here&apos;s what changes for compliance officers and risk managers.</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate></item><item><title>How to Present BIA Findings to the Board: Executive Summary and Business Case</title><link>https://risktemplate.com/blog/2026-04-14-how-to-present-bia-findings-to-the-board-executive-summary/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-14-how-to-present-bia-findings-to-the-board-executive-summary/</guid><description>A 47-page BIA full of RTOs and dependency tables won&apos;t get board buy-in for BCP investment. Here&apos;s how to translate BIA findings into an executive summary that drives decisions and satisfies FFIEC board reporting requirements.</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Third-Party AI Risk Questionnaire: Vendor Due Diligence Checklist and Evidence</title><link>https://risktemplate.com/blog/2026-04-14-third-party-ai-vendor-risk-assessment-due-diligence-questionnaire/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-14-third-party-ai-vendor-risk-assessment-due-diligence-questionnaire/</guid><description>A third-party AI vendor risk questionnaire for financial services: model documentation, data use, bias controls, monitoring, incident response, and evidence.</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate></item><item><title>CFPB Under the New Administration: What Changed and What Still Matters</title><link>https://risktemplate.com/blog/2026-04-13-cfpb-new-administration-changes-what-still-matters/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-13-cfpb-new-administration-changes-what-still-matters/</guid><description>The CFPB fired its director, dropped 40+ enforcement actions, and withdrew nearly 70 guidance documents. Here&apos;s what actually changed — and what compliance obligations remain regardless.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Common Regulatory Exam Findings on AI: Top Deficiencies and How to Fix Them</title><link>https://risktemplate.com/blog/2026-04-13-common-regulatory-exam-findings-ai-deficiencies-fixes/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-13-common-regulatory-exam-findings-ai-deficiencies-fixes/</guid><description>These are the AI governance deficiencies regulators are actually finding in exams — incomplete model inventories, missing validation records, unmanaged vendor AI — and what to do about each one.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Consumer Complaint Management Program: What the CFPB Exam Manual Requires</title><link>https://risktemplate.com/blog/2026-04-13-consumer-complaint-management-program-cfpb-exam-manual/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-13-consumer-complaint-management-program-cfpb-exam-manual/</guid><description>CFPB examiners don&apos;t just check whether you respond to complaints — they evaluate your entire complaint management infrastructure. Here&apos;s exactly what the exam manual requires and where programs typically fall short.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Identifying Critical Business Functions: A Practitioner&apos;s Scoring Framework</title><link>https://risktemplate.com/blog/2026-04-13-identifying-critical-business-functions-scoring-framework/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-13-identifying-critical-business-functions-scoring-framework/</guid><description>A step-by-step scoring methodology for identifying and tiering critical business functions in your BIA — with impact dimensions, scoring criteria, and real financial services examples.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Iran&apos;s $7.8B Crypto Economy Just Made Sanctions Compliance Harder for Everyone</title><link>https://risktemplate.com/blog/2026-04-13-iran-crypto-sanctions-risk-strait-of-hormuz/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-13-iran-crypto-sanctions-risk-strait-of-hormuz/</guid><description>Iran demanding crypto tolls at the Strait of Hormuz exposes massive sanctions risk for banks, shipping companies, and crypto exchanges. Here&apos;s what compliance teams need to do now.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Setting RTO and RPO: How to Quantify and Defend Your Recovery Objectives</title><link>https://risktemplate.com/blog/2026-04-13-setting-rto-rpo-quantify-defend-recovery-objectives/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-13-setting-rto-rpo-quantify-defend-recovery-objectives/</guid><description>How to derive RTO and RPO from real BIA data, set defensible numbers using the MTD hierarchy, and pass FFIEC examiner scrutiny on recovery objective methodology.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate></item><item><title>SR 11-7 for AI Systems: Applying Legacy Model Risk Guidance to LLMs</title><link>https://risktemplate.com/blog/2026-04-13-sr-11-7-ai-systems-applying-model-risk-guidance-llms/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-13-sr-11-7-ai-systems-applying-model-risk-guidance-llms/</guid><description>How to actually implement SR 11-7 for LLMs: model inventory, governance ownership, documentation standards, and validation scope for in-house and vendor AI.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate></item><item><title>AI Governance Program Checklist: What Regulators Actually Test</title><link>https://risktemplate.com/blog/2026-04-12-ai-governance-program-checklist-regulators-test/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-12-ai-governance-program-checklist-regulators-test/</guid><description>When examiners evaluate your AI governance program, they&apos;re checking specific items. Here&apos;s the complete checklist — mapped to SR 11-7, OCC guidance, and the GAO&apos;s 2025 findings.</description><pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate></item><item><title>UDAAP Risk Assessment: How to Evaluate Products Before the Examiner Does</title><link>https://risktemplate.com/blog/2026-04-12-udaap-risk-assessment-product-review-framework/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-12-udaap-risk-assessment-product-review-framework/</guid><description>UDAAP exam findings still happen even when the CFPB is pulling back. Here&apos;s how to conduct a real UDAAP product risk assessment across all three prongs.</description><pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate></item><item><title>CCPA and CPRA Enforcement in 2025: What the California Privacy Protection Agency Is Actually Going After</title><link>https://risktemplate.com/blog/2026-04-11-ccpa-cpra-enforcement-2025-cppa-california-privacy-actions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-11-ccpa-cpra-enforcement-2025-cppa-california-privacy-actions/</guid><description>The CPPA issued over $2.3 million in fines across multiple enforcement actions in 2025. Here&apos;s exactly what they found, what the common violation patterns are, and what compliance teams need to fix before they&apos;re next.</description><pubDate>Sat, 11 Apr 2026 00:00:00 GMT</pubDate></item><item><title>54 Months for $98M ERC Fraud: The DOJ Sentencing That Should Trigger Your Internal Audit</title><link>https://risktemplate.com/blog/2026-04-11-doj-erc-fraud-goode-mccoy-sentencing-compliance-lessons/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-11-doj-erc-fraud-goode-mccoy-sentencing-compliance-lessons/</guid><description>A Las Vegas business owner just got 54 months in prison for filing 1,227 fraudulent ERC returns. If your company claimed the credit, here&apos;s what to do now.</description><pubDate>Sat, 11 Apr 2026 00:00:00 GMT</pubDate></item><item><title>FinCEN Just Rewrote the AML Rulebook: What the 2026 BSA Program NPRM Means for Your Compliance Team</title><link>https://risktemplate.com/blog/2026-04-11-fincen-aml-cft-proposed-rule-bsa-program-reform/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-11-fincen-aml-cft-proposed-rule-bsa-program-reform/</guid><description>FinCEN&apos;s 2026 proposed rule fundamentally reforms BSA AML/CFT program requirements—shifting from paperwork to effectiveness. Here&apos;s what changes and what to do now.</description><pubDate>Sat, 11 Apr 2026 00:00:00 GMT</pubDate></item><item><title>How to Conduct a Business Impact Analysis: Step-by-Step Methodology</title><link>https://risktemplate.com/blog/2026-04-11-how-to-conduct-business-impact-analysis-step-by-step/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-11-how-to-conduct-business-impact-analysis-step-by-step/</guid><description>A practitioner&apos;s guide to running a business impact analysis that satisfies FFIEC examiners and ISO 22301 requirements—from scoping and data collection through RTO/RPO setting, dependency mapping, and board reporting.</description><pubDate>Sat, 11 Apr 2026 00:00:00 GMT</pubDate></item><item><title>LLM Model Risk Assessment: What MRM Teams Actually Need to Test</title><link>https://risktemplate.com/blog/2026-04-11-llm-model-risk-assessment-mrm-teams-testing/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-11-llm-model-risk-assessment-mrm-teams-testing/</guid><description>SR 11-7 wasn&apos;t written for language models. Here&apos;s what model risk management teams actually need to test for LLMs and generative AI—hallucination evaluation, red-teaming, adversarial testing, and continuous drift monitoring.</description><pubDate>Sat, 11 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Regulatory Change Management: How to Track New Rules, Update Policies, and Stay Ahead of Compliance Deadlines</title><link>https://risktemplate.com/blog/2026-04-11-regulatory-change-management-program-compliance-fintech/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-11-regulatory-change-management-program-compliance-fintech/</guid><description>92% of compliance professionals say their role has become harder, and 77% still track regulatory changes manually. Here&apos;s how to build a program that closes the gap between when rules take effect and when your policies reflect them.</description><pubDate>Sat, 11 Apr 2026 00:00:00 GMT</pubDate></item><item><title>AI and Business Continuity: How to Plan for AI System Failures and Model Risk</title><link>https://risktemplate.com/blog/2026-04-10-ai-business-continuity-plan-ai-system-failures-model-risk/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-10-ai-business-continuity-plan-ai-system-failures-model-risk/</guid><description>AI systems fail differently than traditional IT. Here&apos;s how to build AI failure scenarios into your BCP, set recovery objectives for models, and satisfy emerging regulatory requirements on AI resilience.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Annual BCP Testing Calendar: How to Schedule and Track Your Continuity Exercises</title><link>https://risktemplate.com/blog/2026-04-10-annual-bcp-testing-calendar-schedule-track-continuity-exercises/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-10-annual-bcp-testing-calendar-schedule-track-continuity-exercises/</guid><description>Build an annual BCP testing calendar that satisfies FFIEC, ISO 22301, and NCUA examiners. Covers exercise types, scheduling by function criticality, tracking, and how to handle mid-year changes.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate></item><item><title>How a National Insurance Broker&apos;s Street Marketer Program Became a $160M ACA Fraud Machine</title><link>https://risktemplate.com/blog/2026-04-10-doj-assuredpartners-apsf-aca-enrollment-fraud-160-million/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-10-doj-assuredpartners-apsf-aca-enrollment-fraud-160-million/</guid><description>DOJ&apos;s $160M resolution with AssuredPartners and APSF for ACA enrollment fraud shows exactly what happens when broker compliance programs ignore third-party marketer risk.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate></item><item><title>DORA Third-Party ICT Risk: Contracts, Concentration Risk, and the 19 Critical Providers You Now Answer To</title><link>https://risktemplate.com/blog/2026-04-10-dora-third-party-ict-risk-contracts-concentration-critical-providers/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-10-dora-third-party-ict-risk-contracts-concentration-critical-providers/</guid><description>DORA went live January 17, 2025. If your ICT vendor contracts haven&apos;t been updated, your Register of Information isn&apos;t filed, and you haven&apos;t mapped your concentration risk — here&apos;s exactly what needs to happen.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate></item><item><title>OCC and FDIC Just Banned Reputation Risk From Bank Supervision — Here&apos;s What It Means for Your Compliance Program</title><link>https://risktemplate.com/blog/2026-04-10-occ-fdic-reputation-risk-final-rule-bank-supervision/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-10-occ-fdic-reputation-risk-final-rule-bank-supervision/</guid><description>The OCC and FDIC finalized a rule prohibiting examiners from using &apos;reputation risk&apos; in supervision, effective June 9, 2026. What bank compliance teams need to update now.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate></item><item><title>SEC Cybersecurity Disclosure Rule: What&apos;s Material, How to File, and Lessons from Early Enforcement</title><link>https://risktemplate.com/blog/2026-04-10-sec-cybersecurity-disclosure-rule-8k-materiality-enforcement/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-10-sec-cybersecurity-disclosure-rule-8k-materiality-enforcement/</guid><description>Flagstar said it had &apos;no evidence of unauthorized access.&apos; The SEC disagreed. A practical breakdown of Form 8-K Item 1.05, how to build a defensible materiality determination process, and what early enforcement actions reveal about where companies are getting it wrong.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate></item><item><title>SEC FY2025 Enforcement Report: The Lowest Case Count in 20 Years—and What It Actually Means for Your Program</title><link>https://risktemplate.com/blog/2026-04-10-sec-fy2025-enforcement-report-priorities-shift/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-10-sec-fy2025-enforcement-report-priorities-shift/</guid><description>SEC filed just 456 enforcement actions in FY2025—fewest in two decades. Here&apos;s what compliance officers must know about the SEC&apos;s priorities shift.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Supply Chain Business Continuity: Lessons from COVID, Suez, and the Chip Shortage</title><link>https://risktemplate.com/blog/2026-04-10-supply-chain-business-continuity-lessons-covid-suez-chip-shortage/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-10-supply-chain-business-continuity-lessons-covid-suez-chip-shortage/</guid><description>Supply chain disruptions expose BCP gaps faster than almost any other event. COVID, the Suez blockage, and the chip shortage showed exactly where plans failed. Here&apos;s how to fix yours.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate></item><item><title>How to Write an After-Action Report for a BCP Exercise: Template and Examples</title><link>https://risktemplate.com/blog/2026-04-09-after-action-report-bcp-exercise-template/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-09-after-action-report-bcp-exercise-template/</guid><description>A practical after-action report template for BCP tabletop exercises. Covers the hot wash, finding format, corrective action tracking, and what FFIEC and ISO 22301 require.</description><pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Business Continuity Maturity Model: How to Measure and Improve Your Program</title><link>https://risktemplate.com/blog/2026-04-09-business-continuity-maturity-model-measure-improve-program/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-09-business-continuity-maturity-model-measure-improve-program/</guid><description>A practical guide to the Business Continuity Maturity Model (BCMM). Learn the 5 maturity levels, how to self-assess your program, and how to prioritize improvements.</description><pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Business Continuity for Remote and Hybrid Workforces: What Changed and What Didn&apos;t</title><link>https://risktemplate.com/blog/2026-04-09-business-continuity-remote-hybrid-workforce/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-09-business-continuity-remote-hybrid-workforce/</guid><description>COVID forced every BCP program to confront a reality most hadn&apos;t planned for: running critical operations with 80% of your team working from kitchen tables. Five years later, hybrid work is the permanent baseline — and most BCPs still haven&apos;t caught up.</description><pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Cyber Resilience and Business Continuity: Building a Unified Response Framework</title><link>https://risktemplate.com/blog/2026-04-09-cyber-resilience-business-continuity-unified-response-framework/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-09-cyber-resilience-business-continuity-unified-response-framework/</guid><description>Most organizations run cyber incident response and BCP as separate programs — and that gap showed up badly in Change Healthcare, MOVEit, and dozens of other major ransomware events. Here&apos;s how to build a unified framework that actually works.</description><pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate></item><item><title>10 Tabletop Exercise Scenarios for Business Continuity: Cyberattack, Pandemic, Cloud Outage, and More</title><link>https://risktemplate.com/blog/2026-04-08-10-tabletop-exercise-scenarios-business-continuity/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-08-10-tabletop-exercise-scenarios-business-continuity/</guid><description>Most business continuity plans fail not because they&apos;re wrong, but because they&apos;ve never been tested. Here are 10 tabletop exercise scenarios — with facilitator guidance — to stress-test your plan before a real incident does.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Business Continuity for Banks and Credit Unions: OCC and NCUA Examination Guide</title><link>https://risktemplate.com/blog/2026-04-08-business-continuity-banks-credit-unions-occ-ncua-examination/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-08-business-continuity-banks-credit-unions-occ-ncua-examination/</guid><description>OCC and NCUA examiners don&apos;t just check if you have a BCP — they test whether it actually works. Here&apos;s what national banks and credit unions need to meet regulatory expectations and avoid exam findings.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Business Continuity Plan for Small Business: A Practical Guide Without the Enterprise Complexity</title><link>https://risktemplate.com/blog/2026-04-08-business-continuity-plan-small-business-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-08-business-continuity-plan-small-business-guide/</guid><description>Small businesses don&apos;t need a 200-page BCP. Here&apos;s a minimum viable framework covering OSHA, SBA, and HIPAA requirements — built for teams of 1-50.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Business Continuity for SaaS Companies: Uptime SLAs, Incident Response, and Cloud DR</title><link>https://risktemplate.com/blog/2026-04-08-business-continuity-saas-companies-uptime-sla-cloud-dr/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-08-business-continuity-saas-companies-uptime-sla-cloud-dr/</guid><description>SaaS companies have two BC obligations: protecting their own operations and surviving as the vendor when their customers&apos; examiners come calling. Here&apos;s how to build a program that covers both.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate></item><item><title>How to Test Your Contingency Funding Plan: Tabletop Exercises &amp; Simulation Drills</title><link>https://risktemplate.com/blog/2026-04-08-how-to-test-contingency-funding-plan-tabletop-exercises/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-08-how-to-test-contingency-funding-plan-tabletop-exercises/</guid><description>SVB hadn&apos;t tested its discount window access since 2022. Learn how to design CFP tabletop exercises, stress scenarios, and simulation drills that satisfy OCC, FFIEC, and FINRA examiners.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Lessons from SVB &amp; Signature Bank: What Their Liquidity Failures Mean for Your CFP</title><link>https://risktemplate.com/blog/2026-04-08-svb-signature-bank-liquidity-failures-cfp-lessons/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-08-svb-signature-bank-liquidity-failures-cfp-lessons/</guid><description>SVB&apos;s own stress tests predicted its failure eight months early. Management changed the assumptions instead of fixing the balance sheet. Here&apos;s what the 2023 bank failures reveal about CFP design, testing, and governance — and what regulators now expect from every institution.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Business Continuity Plan for Healthcare: HIPAA, Patient Safety, and Regulatory Requirements</title><link>https://risktemplate.com/blog/2026-04-07-business-continuity-plan-healthcare-hipaa-patient-safety/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-07-business-continuity-plan-healthcare-hipaa-patient-safety/</guid><description>Healthcare BCP isn&apos;t just about uptime — it&apos;s about patient safety. Here&apos;s what HIPAA, CMS, and The Joint Commission actually require, and how to build a continuity plan that survives an OCR audit.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate></item><item><title>CFP Governance: Roles, Responsibilities &amp; Board Reporting</title><link>https://risktemplate.com/blog/2026-04-07-cfp-governance-roles-responsibilities-board-reporting/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-07-cfp-governance-roles-responsibilities-board-reporting/</guid><description>Most contingency funding plans fail in execution, not design. The reason is almost always governance — unclear ownership, no board-level accountability, and triggers that nobody has authority to pull. Here&apos;s how to build a CFP governance structure regulators can actually examine.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Early Warning Indicators for Liquidity Stress: What to Monitor &amp; How to Set Triggers</title><link>https://risktemplate.com/blog/2026-04-07-early-warning-indicators-liquidity-stress/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-07-early-warning-indicators-liquidity-stress/</guid><description>Build a practical EWI framework for liquidity stress monitoring. Covers the indicators regulators expect, how to set escalation thresholds, and the governance structure to act on signals before they become crises.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate></item><item><title>FinCEN&apos;s Record $80M BSA Fine Against Canaccord Genuity: Every Broker-Dealer&apos;s Wake-Up Call</title><link>https://risktemplate.com/blog/2026-04-07-fincen-canaccord-genuity-bsa-aml-record-penalty-broker-dealer/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-07-fincen-canaccord-genuity-bsa-aml-record-penalty-broker-dealer/</guid><description>FinCEN hit Canaccord Genuity with the largest-ever BSA penalty against a broker-dealer — $80M, coordinated with SEC and FINRA for $120M total. Here&apos;s what failed and what to fix now.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Identifying &amp; Prioritizing Contingent Funding Sources: A Practical Ranking Framework</title><link>https://risktemplate.com/blog/2026-04-07-identifying-prioritizing-contingent-funding-sources/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-07-identifying-prioritizing-contingent-funding-sources/</guid><description>Not all contingent funding sources are created equal. Here&apos;s how to rank your backup liquidity options by reliability, cost, and access speed — before you actually need them.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate></item><item><title>ISO 22301 Documentation Requirements: What You Actually Need to Maintain</title><link>https://risktemplate.com/blog/2026-04-07-iso-22301-documentation-requirements/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-07-iso-22301-documentation-requirements/</guid><description>ISO 22301:2019 mandates specific documented information across Clauses 4-10. Here&apos;s the complete list of required policies, procedures, and records — and what auditors actually check.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate></item><item><title>ISO 22301 Gap Analysis Template: Assess Your BCMS Maturity</title><link>https://risktemplate.com/blog/2026-04-07-iso-22301-gap-analysis-template-bcms-maturity/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-07-iso-22301-gap-analysis-template-bcms-maturity/</guid><description>ISO 22301 gap analysis maps where your BCMS falls short clause by clause. Use this template and scoring guide to assess maturity and prioritize before your certification audit.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Common CFP Exam Findings: Top Deficiencies Regulators Flag (And How to Fix Them)</title><link>https://risktemplate.com/blog/2026-04-06-common-cfp-exam-findings-deficiencies-regulators-flag/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-06-common-cfp-exam-findings-deficiencies-regulators-flag/</guid><description>The OCC, FDIC, and Fed repeatedly flag the same CFP deficiencies across examination cycles. Here&apos;s exactly what they find, why SVB is the case study, and what remediation actually looks like.</description><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate></item><item><title>How to Build a Contingency Funding Plan: A Step-by-Step Framework for Financial Institutions</title><link>https://risktemplate.com/blog/2026-04-06-how-to-build-contingency-funding-plan-framework/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-06-how-to-build-contingency-funding-plan-framework/</guid><description>Learn how to create a robust contingency funding plan (CFP) for your financial institution with our step-by-step framework, covering regulatory requirements and best practices for liquidity risk management.</description><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate></item><item><title>ISO 22301 Internal Audit Checklist: How to Prepare for Your BCMS Audit</title><link>https://risktemplate.com/blog/2026-04-06-iso-22301-internal-audit-checklist-bcms-audit/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-06-iso-22301-internal-audit-checklist-bcms-audit/</guid><description>ISO 22301 Clause 9.2 requires documented internal audits at planned intervals. Use this clause-by-clause checklist to find gaps before your external auditor does.</description><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Liquidity Stress Testing for Your CFP: Scenarios, Assumptions &amp; Methodology</title><link>https://risktemplate.com/blog/2026-04-06-liquidity-stress-testing-cfp-scenarios-assumptions-methodology/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-06-liquidity-stress-testing-cfp-scenarios-assumptions-methodology/</guid><description>Build a defensible CFP liquidity stress test: three required scenarios, assumption documentation, survival horizon metrics, and lessons from SVB&apos;s $18B 30-day deficit.</description><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate></item><item><title>OCC Kills Recovery Planning Requirements for Large Banks: What Risk Managers Need to Know</title><link>https://risktemplate.com/blog/2026-04-06-occ-rescinds-recovery-planning-guidelines-large-banks/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-06-occ-rescinds-recovery-planning-guidelines-large-banks/</guid><description>The OCC rescinded 12 CFR 30 Appendix E, eliminating mandatory recovery planning for $100B+ banks effective May 1, 2026. Here&apos;s what that means for your program.</description><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Operational Resilience vs Business Continuity: The Regulatory Shift You Need to Understand</title><link>https://risktemplate.com/blog/2026-04-06-operational-resilience-vs-business-continuity-regulatory-shift/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-06-operational-resilience-vs-business-continuity-regulatory-shift/</guid><description>Three major global regulatory frameworks — BCBS 2021, UK PS6/21, and EU DORA — have redefined business continuity into something practitioners barely recognize. Here&apos;s what changed and what it means for your program.</description><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate></item><item><title>BIA for IT Systems: How to Map Technology Dependencies to Business Functions</title><link>https://risktemplate.com/blog/2026-04-05-bia-it-systems-technology-dependency-mapping/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-05-bia-it-systems-technology-dependency-mapping/</guid><description>Most BIAs skip IT dependency mapping entirely — or treat it as an afterthought. Here&apos;s how to build the technology layer that makes your BIA actually useful for recovery planning.</description><pubDate>Sun, 05 Apr 2026 00:00:00 GMT</pubDate></item><item><title>How to Score and Prioritize a Business Impact Analysis: BIA Rating Methodology</title><link>https://risktemplate.com/blog/2026-04-05-bia-scoring-prioritization-methodology/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-05-bia-scoring-prioritization-methodology/</guid><description>A practical BIA scoring methodology for financial services. Score impact across 4 dimensions, assign criticality tiers, and set defensible RTO targets.</description><pubDate>Sun, 05 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Contingency Funding Plan Template: Key Components &amp; What Examiners Look For</title><link>https://risktemplate.com/blog/2026-04-05-contingency-funding-plan-template-key-components/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-05-contingency-funding-plan-template-key-components/</guid><description>A contingency funding plan that sits in a drawer fails the moment you need it. Here are the components OCC, Fed, and FDIC examiners actually check — and how to build a CFP that survives both a liquidity event and a regulatory exam.</description><pubDate>Sun, 05 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Contingency Funding Plan vs. Business Continuity Plan: What&apos;s the Difference?</title><link>https://risktemplate.com/blog/2026-04-05-contingency-funding-plan-vs-business-continuity-plan/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-05-contingency-funding-plan-vs-business-continuity-plan/</guid><description>CFP and BCP sound similar but serve completely different functions. Here&apos;s how to tell them apart, who owns each, and when both trigger at the same time.</description><pubDate>Sun, 05 Apr 2026 00:00:00 GMT</pubDate></item><item><title>FINRA&apos;s Proposed Rule 4610: What Broker-Dealers Need to Know About Liquidity Risk Management</title><link>https://risktemplate.com/blog/2026-04-05-finra-proposed-rule-4610-broker-dealer-liquidity-risk-management/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-05-finra-proposed-rule-4610-broker-dealer-liquidity-risk-management/</guid><description>FINRA&apos;s proposed Rule 4610 would impose liquidity risk management requirements on about 125 broker-dealers. Here&apos;s what the rule covers, the controversial &apos;rebuttable presumption&apos; conditions, and what firms should be doing now.</description><pubDate>Sun, 05 Apr 2026 00:00:00 GMT</pubDate></item><item><title>How Often Should You Update Your BIA? A Maintenance and Review Schedule</title><link>https://risktemplate.com/blog/2026-04-05-how-often-update-bia-maintenance-review-schedule/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-05-how-often-update-bia-maintenance-review-schedule/</guid><description>Your BIA isn&apos;t a one-time project. Learn FFIEC and ISO 22301 requirements for BIA review frequency, which triggers mandate an update, and how to build a defensible maintenance schedule.</description><pubDate>Sun, 05 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Long Island Investment Adviser Pleads Guilty to $160 Million Fraud: What Compliance Teams Should Learn</title><link>https://risktemplate.com/blog/2026-04-04-ag-morgan-vincent-camarda-160-million-investment-adviser-fraud/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-04-ag-morgan-vincent-camarda-160-million-investment-adviser-fraud/</guid><description>Vincent Camarda of A.G. Morgan Financial Advisors pleaded guilty to $160M investment fraud. Here&apos;s what went wrong and the compliance red flags every firm should watch for.</description><pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate></item><item><title>AI in Consequential Decision-Making: Where Regulators Draw the Compliance Line</title><link>https://risktemplate.com/blog/2026-04-04-ai-consequential-decision-making-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-04-ai-consequential-decision-making-compliance/</guid><description>How state and federal regulators define consequential AI decisions — and what compliance teams must do before January 2027 to avoid enforcement.</description><pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate></item><item><title>AI and Consumer Data Rights: Where CCPA, State Privacy Laws, and AI Decisions Collide</title><link>https://risktemplate.com/blog/2026-04-04-ai-consumer-data-rights-privacy-laws/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-04-ai-consumer-data-rights-privacy-laws/</guid><description>How consumer data rights like deletion, opt-out, and access apply when businesses use AI for automated decisions — mapped across CCPA, Colorado, Virginia, and 17 other state laws.</description><pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate></item><item><title>AI Model Validation: Testing Techniques That Actually Work for ML and LLM Models</title><link>https://risktemplate.com/blog/2026-04-04-ai-model-validation-testing-techniques-ml-llm/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-04-ai-model-validation-testing-techniques-ml-llm/</guid><description>A practitioner&apos;s guide to ai model validation techniques that satisfy OCC SR 11-7, FFIEC, and CFPB requirements for ML and LLM models in financial services.</description><pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate></item><item><title>BIA vs Risk Assessment: What&apos;s the Difference and When to Use Each</title><link>https://risktemplate.com/blog/2026-04-04-bia-vs-risk-assessment-difference-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-04-bia-vs-risk-assessment-difference-guide/</guid><description>Business impact analysis vs risk assessment — learn the key differences, when to use each, and how to integrate both into your BCM program.</description><pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Who Needs a Contingency Funding Plan? FINRA, OCC &amp; Interagency Requirements Explained</title><link>https://risktemplate.com/blog/2026-04-04-contingency-funding-plan-regulatory-requirements-finra-occ/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-04-contingency-funding-plan-regulatory-requirements-finra-occ/</guid><description>Contingency funding plan requirements vary by regulator, but most banks and larger credit unions need a CFP now. Here’s what OCC, Fed, FDIC, NCUA, and FINRA expect.</description><pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate></item><item><title>AI Training Data Governance: Managing Data Quality, Consent, and Provenance</title><link>https://risktemplate.com/blog/2026-04-03-ai-training-data-governance-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-03-ai-training-data-governance-compliance/</guid><description>How to build an AI training data governance program that covers data quality, consent, provenance tracking, and regulatory compliance for financial services.</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate></item><item><title>DOJ Hits Atlanta Urology Practice With $14 Million False Claims Act Settlement — What Compliance Teams Should Learn</title><link>https://risktemplate.com/blog/2026-04-03-doj-advanced-urology-14-million-false-claims-act-settlement/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-03-doj-advanced-urology-14-million-false-claims-act-settlement/</guid><description>Advanced Urology and Dr. Jitesh Patel will pay $14M to settle DOJ allegations of fraudulent billing and unnecessary procedures. Key compliance takeaways inside.</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Illinois AI Video Interview Act: What Employers and HR Tech Vendors Must Know</title><link>https://risktemplate.com/blog/2026-04-03-illinois-ai-video-interview-act-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-03-illinois-ai-video-interview-act-compliance/</guid><description>Using HireVue or AI screening in Illinois? HB 3773 just expanded your obligations. A federal court ruled BIPA and AIVICA apply simultaneously — here&apos;s what that means for your consent flow, notice requirements, and litigation exposure.</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate></item><item><title>NYC Local Law 144 Explained: AI Bias Audit Requirements for Employers and Vendors</title><link>https://risktemplate.com/blog/2026-04-03-nyc-local-law-144-ai-bias-audit-requirements/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-03-nyc-local-law-144-ai-bias-audit-requirements/</guid><description>NYC Local Law 144 requires annual bias audits for AI hiring tools. Learn AEDT requirements, penalties, audit process, and what the Comptroller&apos;s enforcement review means for 2026.</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate></item><item><title>PII in AI Systems: How to Handle Personal Data When Using LLMs</title><link>https://risktemplate.com/blog/2026-04-03-pii-handling-ai-llm-systems-compliance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-03-pii-handling-ai-llm-systems-compliance/</guid><description>Practical guide to detecting, protecting, and managing PII in LLM systems — covering GLBA, CCPA, de-identification, and vendor contract requirements.</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate></item><item><title>A.G. Morgan Financial Advisors Fraud: Vincent Camarda Pleads Guilty to $160M Investment Adviser Scheme</title><link>https://risktemplate.com/blog/2026-04-03-sec-camarda-mcarthur-ag-morgan-160m-fraud/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-03-sec-camarda-mcarthur-ag-morgan-160m-fraud/</guid><description>Vincent Camarda of A.G. Morgan Financial Advisors pleads guilty to defrauding 400+ clients of $160M. What compliance professionals need to know about this investment adviser fraud case.</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate></item><item><title>State AI Laws Tracker 2026: Every US AI Regulation You Need to Know</title><link>https://risktemplate.com/blog/2026-04-03-state-ai-laws-tracker-2026-us-regulations/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-03-state-ai-laws-tracker-2026-us-regulations/</guid><description>45 states have introduced 1,561 AI bills in 2026 — already surpassing 2024&apos;s full-year total. Colorado, Texas, and California are the three to watch. Every enacted state AI law, organized by what your compliance team actually needs to do.</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate></item><item><title>What Is a Contingency Funding Plan? A Plain-Language Guide for Risk &amp; Compliance Teams</title><link>https://risktemplate.com/blog/2026-04-03-what-is-a-contingency-funding-plan-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-03-what-is-a-contingency-funding-plan-guide/</guid><description>A contingency funding plan (CFP) maps how your institution survives a liquidity crisis. Learn what a CFP is, who needs one, key components, and regulatory requirements.</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate></item><item><title>AI Kill Switch: When, Why, and How to Shut Down a Model in Production</title><link>https://risktemplate.com/blog/2026-04-02-ai-model-kill-switch-shutdown-controls/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-02-ai-model-kill-switch-shutdown-controls/</guid><description>Your AI model is making bad decisions in production. Do you have a documented shutdown plan? Most banks don&apos;t. Here&apos;s the kill switch framework examiners expect — decision criteria, authority matrix, fallback ops, and what the EU AI Act requires.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate></item><item><title>AI Model Monitoring Template: Drift Detection, Thresholds, KRIs, and Evidence</title><link>https://risktemplate.com/blog/2026-04-02-ai-model-monitoring-drift-detection-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-02-ai-model-monitoring-drift-detection-guide/</guid><description>How to structure AI model monitoring: drift detection, performance thresholds, fairness checks, KRIs, alert owners, and governance evidence.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate></item><item><title>AI Operational Resilience: Making Sure AI Systems Don&apos;t Break the Business</title><link>https://risktemplate.com/blog/2026-04-02-ai-operational-resilience-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-02-ai-operational-resilience-financial-services/</guid><description>How to build AI operational resilience for financial services — dependency mapping, vendor concentration risk, BCP planning, and tabletop exercises for AI failures.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Deepfake Detection and Controls for Financial Services: A Risk Manager&apos;s Guide</title><link>https://risktemplate.com/blog/2026-04-02-deepfake-detection-controls-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-02-deepfake-detection-controls-financial-services/</guid><description>How financial institutions can detect and defend against deepfake fraud — from voice cloning scams to KYC bypass attacks. Practical controls, FinCEN red flags, and detection tech.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate></item><item><title>SEC Obtains Judgments Against P/E Capital and CEO Eliseo Prisno for $2.4 Million in Unauthorized Client Fees</title><link>https://risktemplate.com/blog/2026-04-02-sec-pe-capital-prisno-unauthorized-fees-fiduciary-fraud/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-02-sec-pe-capital-prisno-unauthorized-fees-fiduciary-fraud/</guid><description>The SEC settled with Chicago-based P/E Capital and CEO Eliseo Prisno for charging 200+ clients $2.4M in undisclosed fees — including hijacking client login credentials to approve charges.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Algorithmic Fairness Audits: A Step-by-Step Compliance Guide for 2026</title><link>https://risktemplate.com/blog/2026-04-01-algorithmic-fairness-audit-compliance-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-01-algorithmic-fairness-audit-compliance-guide/</guid><description>NYC LL 144 already requires annual bias audits — and a 2025 Comptroller report found most companies aren&apos;t complying. Colorado SB 205 hits January 2027. Here&apos;s the full audit lifecycle: scoping, testing methods, remediation, and documentation.</description><pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Disparate Impact Testing for AI Lending Models: Compliance Checklist and Evidence</title><link>https://risktemplate.com/blog/2026-04-01-disparate-impact-testing-ai-lending-models/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-01-disparate-impact-testing-ai-lending-models/</guid><description>How to document disparate impact testing for AI lending models: data, metrics, controls, adverse action review, and compliance evidence.</description><pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate></item><item><title>AI Model Risk Management Checklist: OCC Expectations, Inventory, Validation, and Monitoring</title><link>https://risktemplate.com/blog/2026-04-01-occ-model-risk-management-ai-bulletin-2011-12/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-01-occ-model-risk-management-ai-bulletin-2011-12/</guid><description>A practical AI model risk management checklist for financial services: model inventory, validation evidence, monitoring, governance, and vendor AI controls.</description><pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Prompt Injection Attacks: What Compliance Teams Need to Know Right Now</title><link>https://risktemplate.com/blog/2026-04-01-prompt-injection-risk-compliance-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-01-prompt-injection-risk-compliance-financial-services/</guid><description>OWASP ranks prompt injection #1 on their LLM Top 10. Gartner predicts 50%+ of successful AI attacks will use it through 2029. If your firm deploys any LLM, here are the four controls you need before the first incident — not after.</description><pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate></item><item><title>SEC Charges Jon Fullenkamp and Scott Sand in $2.6 Million Penny Stock Fraud Scheme</title><link>https://risktemplate.com/blog/2026-04-01-sec-charges-fullenkamp-sand-penny-stock-fraud/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-01-sec-charges-fullenkamp-sand-penny-stock-fraud/</guid><description>The SEC filed fraud charges against Jon Fullenkamp and Scott Sand for misappropriating millions through sham agreements and fraudulent preferred share issuances at two penny stock companies.</description><pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Agentic Payment Risk: Why Your Fraud Controls Are Already Obsolete</title><link>https://risktemplate.com/blog/2026-04-01-threat-modeling-agentic-payments-risk-framework/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-04-01-threat-modeling-agentic-payments-risk-framework/</guid><description>AI agents can now initiate payments autonomously. Your existing fraud controls were built for humans. Here&apos;s the threat model and control framework fintechs need now.</description><pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate></item><item><title>AI Model Risk Tiering: How to Classify AI Models by Risk Level</title><link>https://risktemplate.com/blog/2026-03-31-ai-model-risk-tiering-classification-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-31-ai-model-risk-tiering-classification-guide/</guid><description>Build an AI model risk tiering methodology that accounts for autonomy, explainability, and data sensitivity. Includes a decision-tree framework and tier-specific oversight requirements.</description><pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Business Impact Analysis Questionnaire Template: 50 Questions to Ask</title><link>https://risktemplate.com/blog/2026-03-31-bia-questionnaire-template-50-questions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-31-bia-questionnaire-template-50-questions/</guid><description>A complete business impact analysis questionnaire template with 50 questions across 10 categories. Based on FFIEC, NIST SP 800-34, and ISO 22301 guidance.</description><pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate></item><item><title>ISO 22301 Certification: Cost, Timeline, and Step-by-Step Roadmap for 2026</title><link>https://risktemplate.com/blog/2026-03-31-iso-22301-certification-cost-timeline-roadmap/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-31-iso-22301-certification-cost-timeline-roadmap/</guid><description>ISO 22301 certification costs $15K-$60K+ depending on org size. Get realistic timelines, a month-by-month implementation roadmap, and tips to avoid common pitfalls.</description><pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate></item><item><title>ISO 22301 vs ISO 27001: Which Standard Do You Actually Need?</title><link>https://risktemplate.com/blog/2026-03-31-iso-22301-vs-iso-27001-comparison-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-31-iso-22301-vs-iso-27001-comparison-guide/</guid><description>ISO 22301 vs ISO 27001 compared side-by-side: scope, controls, certification process, and whether you need one, both, or neither.</description><pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate></item><item><title>SEC Obtains Final Judgments Against Titanium Capital and Henry Abdo for $5.3 Million Ponzi Scheme</title><link>https://risktemplate.com/blog/2026-03-31-sec-titanium-capital-henry-abdo-ponzi-scheme-fraud/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-31-sec-titanium-capital-henry-abdo-ponzi-scheme-fraud/</guid><description>The SEC secured final judgments against Titanium Capital LLC and founder Henry Abdo for a Ponzi scheme that defrauded 162 investors of $5.3 million. Here&apos;s what happened and what compliance teams should learn.</description><pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate></item><item><title>AI Explainability: What Financial Regulators Expect and How to Deliver It</title><link>https://risktemplate.com/blog/2026-03-30-ai-explainability-requirements-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-30-ai-explainability-requirements-financial-services/</guid><description>How to meet AI explainability requirements from the OCC, Fed, CFPB, and EU AI Act — with practical techniques for every model type.</description><pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate></item><item><title>AI Impact Assessments: What They Are, Who Needs Them, and How to Conduct One</title><link>https://risktemplate.com/blog/2026-03-30-ai-impact-assessment-guide-template/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-30-ai-impact-assessment-guide-template/</guid><description>AI impact assessments are now required under Colorado SB 205 and the EU AI Act. Learn who needs one, what to include, and how to build the process.</description><pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate></item><item><title>AI Model Documentation: What Examiners Actually Want to See in 2026</title><link>https://risktemplate.com/blog/2026-03-30-ai-model-documentation-requirements-examiners/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-30-ai-model-documentation-requirements-examiners/</guid><description>Map SR 11-7 and OCC 2011-12 documentation requirements to AI and ML models. Section-by-section template for model cards, training data provenance, and examiner-ready documentation.</description><pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate></item><item><title>SEC Obtains Final Judgment Against Former Wells Fargo Advisor Kenneth Welsh for $3 Million Client Theft Scheme</title><link>https://risktemplate.com/blog/2026-03-30-sec-kenneth-welsh-wells-fargo-advisor-fraud/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-30-sec-kenneth-welsh-wells-fargo-advisor-fraud/</guid><description>The SEC secured a final judgment against Kenneth Welsh, a former Wells Fargo advisor who misappropriated $2.86M+ from clients over five years through 137 fraudulent transactions.</description><pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Agentic AI Risk Management: How to Govern Autonomous AI Systems Before They Govern You</title><link>https://risktemplate.com/blog/2026-03-29-agentic-ai-risk-management-governance/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-29-agentic-ai-risk-management-governance/</guid><description>Practical governance framework for agentic AI systems. Covers new risk categories, permission models, audit trails, and the human-on-the-loop debate for financial services.</description><pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate></item><item><title>College Student Stole $7M from Investors. The SEC&apos;s Case Against Krish Kumar Has Lessons for Every Investment Adviser.</title><link>https://risktemplate.com/blog/2026-03-29-sec-krish-kumar-investment-fraud-lessons/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-29-sec-krish-kumar-investment-fraud-lessons/</guid><description>SEC charged Tulsa college student Krish Kumar with misappropriating nearly $7M from two investment funds. Here&apos;s what compliance officers at investment advisers need to know.</description><pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate></item><item><title>AI Bias Testing for Fair Lending: Methodologies Every Risk Team Needs</title><link>https://risktemplate.com/blog/2026-03-28-ai-bias-testing-methodologies-fair-lending/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-28-ai-bias-testing-methodologies-fair-lending/</guid><description>Learn the essential AI bias testing methodologies for fair lending compliance—disparate impact analysis, counterfactual fairness, calibration testing, and more—before your next exam.</description><pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate></item><item><title>AI Data Leakage Prevention: A Practitioner&apos;s Guide to Protecting Sensitive Data in LLM Systems</title><link>https://risktemplate.com/blog/2026-03-28-ai-data-leakage-prevention-llm-sensitive-data/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-28-ai-data-leakage-prevention-llm-sensitive-data/</guid><description>Learn how to prevent AI data leakage from LLMs in financial services. Covers the 5 leakage vectors, OWASP LLM top risks, NIST controls, and a 90-day implementation roadmap.</description><pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Generative AI Acceptable Use Policy Template: What to Include and Why It Matters</title><link>https://risktemplate.com/blog/2026-03-28-generative-ai-acceptable-use-policy-template/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-28-generative-ai-acceptable-use-policy-template/</guid><description>Your employees are already using ChatGPT — do you have a policy? Build an AI acceptable use policy with data classification rules, prohibited uses, and tool approval workflows.</description><pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate></item><item><title>SEC Closes 7-Year Case Against Commonwealth Financial Network with $5M Penalty — Here&apos;s What Compliance Teams Should Know</title><link>https://risktemplate.com/blog/2026-03-28-sec-commonwealth-financial-network-revenue-sharing-conflicts/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-28-sec-commonwealth-financial-network-revenue-sharing-conflicts/</guid><description>The SEC&apos;s final consent judgment against Commonwealth Financial Network for undisclosed revenue-sharing conflicts offers a critical compliance lesson: fiduciary duty means disclosing who pays you, fully.</description><pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate></item><item><title>AI Incident Response Plan: Building a Playbook for Model Failures and AI Gone Wrong</title><link>https://risktemplate.com/blog/2026-03-27-ai-incident-response-plan-model-failure-playbook/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-27-ai-incident-response-plan-model-failure-playbook/</guid><description>How to build an AI incident response plan that covers model failures, hallucinations, bias events, and drift — with severity tiers, escalation paths, and containment controls.</description><pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate></item><item><title>AI Model Inventory Template: Fields Examiners Ask For First</title><link>https://risktemplate.com/blog/2026-03-27-ai-model-inventory-management-regulatory-exam/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-27-ai-model-inventory-management-regulatory-exam/</guid><description>Build an AI model inventory with ownership, use case, data, decision role, risk tier, vendor source, controls, monitoring, and review evidence.</description><pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate></item><item><title>LLM Hallucination Risk in Financial Services: How to Detect, Measure, and Mitigate</title><link>https://risktemplate.com/blog/2026-03-27-llm-hallucination-risk-management-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-27-llm-hallucination-risk-management-financial-services/</guid><description>How to detect, measure, and mitigate LLM hallucination risk in financial services — with real controls, metrics, and a regulatory-ready framework.</description><pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate></item><item><title>SEC Hits $284 Million Municipal Bond Fraud: How Fabricated Revenue Projections Burned Investors</title><link>https://risktemplate.com/blog/2026-03-27-sec-284-million-municipal-bond-fraud/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-27-sec-284-million-municipal-bond-fraud/</guid><description>The SEC charged four individuals with fabricating documents to defraud investors in a $284 million municipal bond offering for a Mesa, Arizona sports complex. Here&apos;s what went wrong and what compliance teams can learn.</description><pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Business Continuity for Financial Services: Meeting OCC, FDIC, and Fed Resilience Expectations</title><link>https://risktemplate.com/blog/2026-03-26-business-continuity-financial-services-regulatory-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-26-business-continuity-financial-services-regulatory-guide/</guid><description>How financial institutions should build business continuity programs that satisfy OCC, FDIC, and Fed operational resilience expectations — with real enforcement examples and implementation guidance.</description><pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Colorado AI Act (SB 205) Compliance Guide: What Every Business Must Do Before January 2027</title><link>https://risktemplate.com/blog/2026-03-26-colorado-ai-act-sb-205-compliance-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-26-colorado-ai-act-sb-205-compliance-guide/</guid><description>Colorado SB 205 takes effect January 1, 2027. Learn who&apos;s covered, what counts as a high-risk AI system, required impact assessments, consumer notices, and your compliance checklist.</description><pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate></item><item><title>ISO 22301 Business Continuity: Requirements, Implementation, and How It Maps to Your BCP</title><link>https://risktemplate.com/blog/2026-03-26-iso-22301-business-continuity-requirements-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-26-iso-22301-business-continuity-requirements-guide/</guid><description>Your auditor wants ISO 22301 alignment? Here&apos;s exactly what each clause requires, how it maps to FFIEC, and whether certification is actually worth the cost.</description><pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate></item><item><title>NIST AI RMF 1.1: What&apos;s Changing and What It Means for Your AI Risk Program</title><link>https://risktemplate.com/blog/2026-03-26-nist-ai-rmf-1-1-changes-update-2026/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-26-nist-ai-rmf-1-1-changes-update-2026/</guid><description>The NIST AI RMF is in active revision as of 2026. Here&apos;s what&apos;s changing, what&apos;s staying stable, and what your AI risk program should do right now.</description><pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate></item><item><title>SEC Closes 7-Year Case Against Investment Adviser Who Hid $14 Million in Fees</title><link>https://risktemplate.com/blog/2026-03-26-sec-stuart-frost-investment-adviser-fiduciary-fraud/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-26-sec-stuart-frost-investment-adviser-fiduciary-fraud/</guid><description>The SEC obtained a final judgment against Stuart Frost for extracting $14M in undisclosed incubator fees from VC fund investors. Key lessons for investment adviser compliance programs in 2026.</description><pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Shadow AI: How to Find and Govern Unauthorized AI Use in Your Organization</title><link>https://risktemplate.com/blog/2026-03-26-shadow-ai-governance-detection-controls/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-26-shadow-ai-governance-detection-controls/</guid><description>Shadow AI is spreading through financial services whether you know it or not. Here&apos;s how to detect it, assess the risk, and build a governance framework that actually works.</description><pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate></item><item><title>SR 11-7 in the Age of AI: What Model Risk Management Teams Must Change Now</title><link>https://risktemplate.com/blog/2026-03-26-sr-11-7-ai-model-risk-management-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-26-sr-11-7-ai-model-risk-management-guide/</guid><description>SR 11-7 was written for spreadsheet models, not LLMs. Here&apos;s how each pillar of the framework must adapt for AI/ML — and where traditional MRM breaks down completely.</description><pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Crisis Communication Plan Template: What to Say (and When) During a Business Disruption</title><link>https://risktemplate.com/blog/2026-03-25-crisis-communication-plan-template-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-25-crisis-communication-plan-template-guide/</guid><description>Build a crisis communication plan that covers customers, regulators, employees, and partners — with pre-drafted templates, escalation timelines, and real-world lessons.</description><pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate></item><item><title>SEC Closes $50 Million Ozy Media Fraud Case: What Compliance Teams Must Learn</title><link>https://risktemplate.com/blog/2026-03-25-sec-ozy-media-investor-fraud-enforcement/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-25-sec-ozy-media-investor-fraud-enforcement/</guid><description>SEC closes $50M Ozy Media fraud case — revenue inflated 100%, a YouTube exec impersonated on an investor call. What compliance teams must learn from this textbook failure.</description><pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Tabletop Exercise Template: How to Run a 90-Minute BCP Exercise That Finds Real Gaps</title><link>https://risktemplate.com/blog/2026-03-25-tabletop-exercise-template-business-continuity/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-25-tabletop-exercise-template-business-continuity/</guid><description>Step-by-step tabletop exercise template with facilitator guide, scenario injects, and 3 ready-to-use scenarios for business continuity testing.</description><pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Third-Party Business Continuity: How to Assess and Monitor Vendor Resilience</title><link>https://risktemplate.com/blog/2026-03-25-third-party-business-continuity-vendor-resilience/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-25-third-party-business-continuity-vendor-resilience/</guid><description>Learn how to assess vendor business continuity plans, monitor third-party resilience, and meet FFIEC requirements for vendor BCP oversight.</description><pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Business Continuity Plan Template: The Complete Guide to Building a BCP That Actually Works</title><link>https://risktemplate.com/blog/2026-03-24-business-continuity-plan-template-complete-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-24-business-continuity-plan-template-complete-guide/</guid><description>Free business continuity plan template with the 8 sections every BCP needs. Step-by-step guide for financial services teams building or rebuilding their BCP.</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Business Continuity Testing Template: Tabletop Exercise Checklist and Evidence</title><link>https://risktemplate.com/blog/2026-03-24-business-continuity-testing-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-24-business-continuity-testing-guide/</guid><description>How to test your BCP with tabletop exercises: scenarios, participant roles, evidence, after-action reports, and remediation tracking.</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Business Continuity vs. Disaster Recovery: What&apos;s the Difference and Why You Need Both</title><link>https://risktemplate.com/blog/2026-03-24-business-continuity-vs-disaster-recovery-difference/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-24-business-continuity-vs-disaster-recovery-difference/</guid><description>Business continuity vs disaster recovery explained — what each covers, where they overlap, and why treating DR as your whole continuity program is a regulatory red flag.</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Business Impact Analysis Template: BIA Fields, RTO/RPO, Scoring, and Examples</title><link>https://risktemplate.com/blog/2026-03-24-business-impact-analysis-template-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-24-business-impact-analysis-template-guide/</guid><description>How to build a business impact analysis template with critical functions, impact ratings, RTO/RPO, dependencies, owners, and recovery evidence.</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Disaster Recovery Plan Template: How to Build a DRP That Gets You Back Online Fast</title><link>https://risktemplate.com/blog/2026-03-24-disaster-recovery-plan-template-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-24-disaster-recovery-plan-template-guide/</guid><description>Step-by-step disaster recovery plan template with recovery tiers, DR strategies, and testing schedules. Build a DRP aligned to your BIA and RTO/RPO targets.</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate></item><item><title>FFIEC Business Continuity Plan Requirements: BCM Checklist and Evidence Guide</title><link>https://risktemplate.com/blog/2026-03-24-ffiec-business-continuity-management-requirements/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-24-ffiec-business-continuity-management-requirements/</guid><description>FFIEC business continuity requirements translated into BCP template fields, BIA evidence, tabletop tests, and examiner-ready documentation.</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate></item><item><title>RTO vs. RPO: How to Set Recovery Objectives That Actually Protect Your Business</title><link>https://risktemplate.com/blog/2026-03-24-rto-vs-rpo-recovery-objectives-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-24-rto-vs-rpo-recovery-objectives-guide/</guid><description>RTO vs RPO explained with practical guidance on setting recovery objectives, tiering critical functions, and avoiding the mistakes that turn outages into disasters.</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate></item><item><title>$284 Million in Forged Documents: The Legacy Cares Municipal Bond Fraud and What It Means for Compliance Teams</title><link>https://risktemplate.com/blog/2026-03-24-sec-legacy-cares-284-million-municipal-bond-fraud/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-24-sec-legacy-cares-284-million-municipal-bond-fraud/</guid><description>The SEC&apos;s Legacy Cares case is a textbook municipal bond fraud—fabricated contracts, forged signatures, and a near-total investor wipeout. Here&apos;s what compliance practitioners need to know.</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate></item><item><title>AI Ethics Framework vs. AI Governance Framework: What&apos;s the Difference?</title><link>https://risktemplate.com/blog/2026-03-23-ai-ethics-vs-governance-framework-differences/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-23-ai-ethics-vs-governance-framework-differences/</guid><description>AI ethics and AI governance are not the same thing. Learn how ethics, governance, and model governance layer together — and why you need all three.</description><pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate></item><item><title>How to Build an AI Governance Committee: Roles, Charter, and Meeting Cadence</title><link>https://risktemplate.com/blog/2026-03-23-ai-governance-committee-roles-charter-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-23-ai-governance-committee-roles-charter-guide/</guid><description>Build an effective AI governance committee with the right roles, a defensible charter, and a meeting cadence that actually works. Practical guide for financial services.</description><pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate></item><item><title>AI Oversight: Who Owns AI Risk in Your Organization?</title><link>https://risktemplate.com/blog/2026-03-23-ai-oversight-who-owns-ai-risk/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-23-ai-oversight-who-owns-ai-risk/</guid><description>AI risk ownership is broken at most firms. Learn how to apply three lines of defense, assign accountability, and stop the &apos;everyone owns it&apos; trap.</description><pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Enterprise AI Governance: Scaling Oversight Across Business Units</title><link>https://risktemplate.com/blog/2026-03-23-enterprise-ai-governance-scaling-oversight/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-23-enterprise-ai-governance-scaling-oversight/</guid><description>Scale AI governance across a large organization without killing innovation. Federated vs. centralized models, shadow AI controls, model inventories, and board reporting.</description><pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate></item><item><title>$284 Million in Fake Documents: The Legacy Cares Municipal Bond Fraud and What Compliance Teams Must Learn</title><link>https://risktemplate.com/blog/2026-03-23-legacy-cares-municipal-bond-fraud-sec-enforcement/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-23-legacy-cares-municipal-bond-fraud-sec-enforcement/</guid><description>The SEC&apos;s Legacy Cares case shows how fabricated revenue documents collapsed a $284M municipal bond deal. Here&apos;s what compliance and risk teams need to know.</description><pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate></item><item><title>AI Compliance Framework: From Policy to Audit-Ready Documentation</title><link>https://risktemplate.com/blog/2026-03-22-ai-compliance-framework-audit-ready-documentation/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-22-ai-compliance-framework-audit-ready-documentation/</guid><description>Build an AI compliance framework that survives regulatory exams. Model inventories, risk assessments, testing evidence, and documentation that proves you&apos;re compliant.</description><pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate></item><item><title>AI Governance Policy Template: What to Include and How to Customize It</title><link>https://risktemplate.com/blog/2026-03-22-ai-governance-policy-template-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-22-ai-governance-policy-template-guide/</guid><description>Build an AI governance policy that actually works. Covers scope, risk classification, approval workflows, monitoring, and exceptions — with section-by-section guidance.</description><pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate></item><item><title>AI Regulation Compliance in 2026: What&apos;s Required and What&apos;s Coming</title><link>https://risktemplate.com/blog/2026-03-22-ai-regulation-compliance-2026-requirements/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-22-ai-regulation-compliance-2026-requirements/</guid><description>Navigate the 2026 AI regulatory landscape — EU AI Act deadlines, state laws in Colorado, Illinois, and Texas, SEC enforcement priorities, and what compliance teams should do now.</description><pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate></item><item><title>NIST AI RMF vs. EU AI Act: Compliance Mapping for Financial Services</title><link>https://risktemplate.com/blog/2026-03-22-nist-ai-rmf-vs-eu-ai-act-compliance-mapping/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-22-nist-ai-rmf-vs-eu-ai-act-compliance-mapping/</guid><description>Map the NIST AI Risk Management Framework against EU AI Act requirements. Build one AI governance program that satisfies both — with a practical crosswalk for financial services teams.</description><pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate></item><item><title>AI Governance Best Practices: Lessons From Regulated Industries</title><link>https://risktemplate.com/blog/2026-03-21-ai-governance-best-practices-regulated-industries/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-21-ai-governance-best-practices-regulated-industries/</guid><description>Tactical AI governance best practices from financial services, healthcare, and insurance. Model inventories, tiered oversight, cross-functional committees, and documentation that survives exams.</description><pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate></item><item><title>AI Risk Management Framework: A Practical Approach for Financial Institutions</title><link>https://risktemplate.com/blog/2026-03-21-ai-risk-management-framework-financial-institutions/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-21-ai-risk-management-framework-financial-institutions/</guid><description>Build an AI risk management framework that identifies, assesses, and mitigates real AI risks. Includes risk taxonomy, tiering model, and 90-day roadmap.</description><pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Responsible AI Framework: Moving Beyond Principles to Practice</title><link>https://risktemplate.com/blog/2026-03-21-responsible-ai-framework-principles-to-practice/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-21-responsible-ai-framework-principles-to-practice/</guid><description>Build a responsible AI framework that turns fairness, transparency, and accountability principles into operational controls. Includes bias testing, impact assessments, and 120-day roadmap.</description><pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate></item><item><title>SEC Closes $26M Ponzi Case Against Bin Hao and Qidian LLC — What It Teaches Compliance Teams About Affinity Fraud</title><link>https://risktemplate.com/blog/2026-03-21-sec-bin-hao-qidian-ponzi-chinese-american-fraud/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-21-sec-bin-hao-qidian-ponzi-chinese-american-fraud/</guid><description>The SEC obtained a final judgment against Bin Hao and Qidian LLC for a Ponzi scheme that targeted Chinese-American investors. Here&apos;s what compliance teams need to know about affinity fraud detection and controls.</description><pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate></item><item><title>The Complete AI Governance Framework: Building Accountability Into Your AI Program</title><link>https://risktemplate.com/blog/2026-03-20-ai-governance-framework-complete-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-20-ai-governance-framework-complete-guide/</guid><description>Build an AI governance framework that actually works. 8 core components, maturity model, and 90-day implementation roadmap for risk practitioners.</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Business Continuity Plan Template for Financial Services: BIA, RTO/RPO, and Test Evidence</title><link>https://risktemplate.com/blog/2026-03-20-business-continuity-plan-template-financial-services/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-20-business-continuity-plan-template-financial-services/</guid><description>A financial services BCP template guide covering BIA, RTO/RPO, dependency mapping, communication roles, tabletop testing, and examiner evidence.</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate></item><item><title>NIST AI Risk Management Framework: The Complete Implementation Guide</title><link>https://risktemplate.com/blog/2026-03-20-nist-ai-rmf-implementation-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-20-nist-ai-rmf-implementation-guide/</guid><description>A practical guide to implementing the NIST AI RMF across Govern, Map, Measure, and Manage — with actionable steps for financial services teams.</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate></item><item><title>OneMain Financial Lawsuit: 13 State AGs Sue Over Loan Packing and Junk Fees — What Compliance Teams Must Learn Now</title><link>https://risktemplate.com/blog/2026-03-20-onemain-financial-13-ag-lawsuit-junk-fees-loan-packing/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-20-onemain-financial-13-ag-lawsuit-junk-fees-loan-packing/</guid><description>13 state AGs sued OneMain Financial for loan packing and junk fees on March 16, 2026. Here&apos;s what the case means for add-on product controls, fee disclosure, and state AG enforcement trends.</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate></item><item><title>How to Build an Operational Risk Management Framework From Scratch</title><link>https://risktemplate.com/blog/2026-03-20-operational-risk-management-framework-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-20-operational-risk-management-framework-guide/</guid><description>A practical guide to building an operational risk management framework — RCSA, KRIs, loss event tracking, and the ORM lifecycle for mid-size banks and fintechs.</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate></item><item><title>SEC Closes the Book on Ofer Abarbanel&apos;s $106 Million Mutual Fund Fraud — What Compliance Teams Should Learn</title><link>https://risktemplate.com/blog/2026-03-20-sec-ofer-abarbanel-106-million-mutual-fund-fraud/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-20-sec-ofer-abarbanel-106-million-mutual-fund-fraud/</guid><description>The SEC obtained a final consent judgment ordering $106.5M in disgorgement against Ofer Abarbanel for orchestrating a mutual fund fraud scheme. Here&apos;s what happened and why it matters for fund compliance.</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Congress Wants to Kill State Privacy Laws for Banks. Here&apos;s What the GLBA Overhaul Means for Your Compliance Program.</title><link>https://risktemplate.com/blog/2026-03-19-glba-overhaul-state-privacy-law-preemption/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-19-glba-overhaul-state-privacy-law-preemption/</guid><description>A new House bill would overhaul GLBA Title V and preempt state privacy laws for financial institutions. What practitioners need to know and do now.</description><pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Incident Response Plan Template: What Every Fintech Needs</title><link>https://risktemplate.com/blog/2026-03-19-incident-response-plan-template-fintech/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-19-incident-response-plan-template-fintech/</guid><description>Build a defensible incident response plan template for your fintech. Covers NIST phases, regulatory notification requirements, and what regulators actually check.</description><pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate></item><item><title>The Treasury&apos;s New AI Risk Framework Has 230 Control Objectives. Here&apos;s Where to Start.</title><link>https://risktemplate.com/blog/2026-03-19-treasury-fs-ai-rmf-230-controls/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-19-treasury-fs-ai-rmf-230-controls/</guid><description>The FS AI RMF gives financial institutions 230 AI control objectives. A practical guide to prioritizing what matters and building your implementation roadmap.</description><pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate></item><item><title>72% of Banks Don&apos;t Know Which Vendors Use AI. Here&apos;s How to Fix Your TPRM Program.</title><link>https://risktemplate.com/blog/2026-03-19-vendor-ai-risk-assessment-tprm/</link><guid isPermaLink="true">https://risktemplate.com/blog/2026-03-19-vendor-ai-risk-assessment-tprm/</guid><description>New survey data shows most financial institutions can&apos;t identify vendor AI use. A practical vendor AI risk assessment guide with due diligence questions and implementation roadmap.</description><pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate></item><item><title>How to Build an AI Risk Assessment Framework for Financial Services</title><link>https://risktemplate.com/blog/ai-risk-assessment-framework-guide/</link><guid isPermaLink="true">https://risktemplate.com/blog/ai-risk-assessment-framework-guide/</guid><description>A comprehensive guide to identifying, assessing, and mitigating AI risks in regulated financial institutions—from model governance to third-party AI vendor oversight.</description><pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate></item></channel></rss>