Skip to content
Navanta logo - homepage
  • 877-778-7774
  • Support
    • Our Story
    • Our People
    • Join Our Team
    • View All Solutions
    • Core Banking
    • Managed IT
      • Bankers Private Cloud
      • Bankers Essentials
      • Cybersecurity
      • M365 Management
    • CRM
    • Advisory
      • Virtual CIO
      • Virtual ISO
      • Security Awareness Training
    • View All Resources
    • Articles
    • CEO Update
    • Client Spotlight
      • Core Banking
      • Cyber Attacks
      • Exams & Audits
      • Information Security
      • Managed IT
    • Navanta in the News
    • Upcoming Events
    • Recorded Webinars
  • Brand FAQs
  • Contact Us
      • Our Story
      • Our People
      • Join Our Team
      • View All Solutions
      • Core Banking

        Keep community focus with a core that runs reliably.

      • Managed IT

        Simplify banking IT with one trusted partner.

      • CRM

        Know every customer. Grow every relationship

      • Advisory

        Navigate IT and risk with clarity and confidence.

      • Have something in mind?
        Bankers Private Cloud
      • Bankers Essentials
      • Cybersecurity
      • M365 Management
      • Virtual CIO
      • Virtual ISO
      • Security Awareness Training
      • View All Resources
      • Browse By Type
        Articles
      • CEO Update
      • Client Spotlight
      • Navanta in the News
      • Upcoming Events
      • Recorded Webinars
      • Browse by Topic
        Core Banking
      • Cyber Attacks
      • Exams & Audits
      • Information Security
      • Managed IT
  • Brand FAQs
  • Contact Us
Articles

What Your Next Exam Is Quietly Going to Ask You About

  • ARTIFICIAL INTELLIGENCE (AI)
  • EXAMS & AUDITS
  • STRATEGIC PLANNING

We have been doing regulatory updates like this one for over a decade now, and every year there is a version of this same moment: something has been sitting in a Federal Register notice or a supervisory letter for months, nobody outside the compliance team has read it closely, and then it shows up as a question in an exam. Not a big dramatic finding. Just a question you were not quite ready for.

Four things are sitting in that spot right now. Here is what they mean for your institution, not just what they say.

A Mid-year Look at the Regulatory Shifts Shaping Community Banking

Prefer to hear this straight from Tom and Emily?

Watch the Webinar Replay

The AI risk that matters is not the AI

Nobody has written a rulebook for AI yet. What regulators are doing instead is pointing out rules you already know, third-party oversight, data protection, risk assessment, at whatever your staff are doing with AI, whether you have decided to have an AI program or not.

Start with the part you cannot see. Copilot is stitched into Word, Excel, and Outlook now, not bolted on, stitched in. Google defaults to an AI answer before you even finish typing. So the honest starting point is not “are our people using AI.” It is “we genuinely do not know everywhere they are, and neither do some of the vendors we buy from.” A policy that says do not use unapproved AI is worth having. It just will not catch much on its own, because it is an administrative control, and administrative controls are only as good as your ability to enforce them.

The sharper risk sits one layer down: what goes into the prompt. Nobody has to type your institution’s name for a prompt to be identifiable. Asset size, geography, a few operational details, and a model can often work out who you are without being told. If a loan officer or ops person is pasting anything that smells like nonpublic customer information into a chatbot to get a faster answer, that is a data leakage event whether the word “AI” ever shows up in your incident log.

So put something in writing, even if it is one paragraph added to your acceptable use policy. Auditors are not expecting you to have this solved. They are checking whether you have thought about it at all, and a bank that has said nothing looks very different from one that has said something, even something modest.
And do not let AI distract you from the plainer third-party question underneath it. Your core provider, your security vendor, the firm running your penetration tests, all of them are almost certainly using AI somewhere in how they operate. Ask how they validate their models and how they patch them. You may not get a satisfying answer yet. Ask anyway. That question, on the record, is the thing you will want to point to later.

One wrinkle worth knowing: the model risk management guidance that came out this spring explicitly says generative and agentic AI models are outside its scope. That is not regulators saying those models are off the hook. It is regulators admitting the guidance has not caught up yet. Explainability and validation still matter under your existing risk framework, especially anywhere AI touches a lending decision, where fair lending exposure does not wait for the paperwork to catch up.

Examiners have stopped accepting “we have DLP” as an answer

This one is not really a new rule. It is an old expectation of getting sharper teeth. Examiners and auditors are asking more specifically what is running in your environment, where your data moves, and whether tools like DLP were tuned on purpose or just switched on and left alone.

“We have DLP” used to close that conversation. It does not anymore. The next question is what it is tuned to catch, and whether that tuning reflects an actual risk assessment of your environment or the vendor’s default settings. If you cannot answer that, the control starts to look more like a checkbox than a control.
Worth a Monday morning task, not a project: pull up your current software inventory and data flow diagrams and ask honestly whether they describe what is running today, or what was running when someone last updated them. Shadow AI tends to surface exactly in that gap.

CAMELS is getting its first real rework in thirty years

The FFIEC has proposed the biggest changes to the Uniform Financial Institutions Rating System since 1996, and comments are open through August 17, 2026. Even if you never plan to file a comment, this is worth reading closely, because it changes how your next composite rating gets built.

Here is the headline. Right now, examiners give the Management component “special consideration” when rolling everything up into your composite score. The proposal would drop that. Regulators looked at ratings data going back to 2000 and found that Management had quietly become the single most influential factor in composite ratings, more than the underlying financial condition justified, and they want the rating to track material financial risk instead of leaning so hard on one component.

The six components are not going anywhere. Capital, asset quality, management, earnings, liquidity, and sensitivity to market risk, all still there. What moves is the weighting, less credit for clean policies and documentation, more attention on whether something threatens the institution’s financial condition.

This does not mean management stops mattering. It means a soft finding in an audit, on its own, may not carry the weight it used to. A genuine problem in how the place is run will still show up, just measured differently. If your institution has been leaning on a strong management score to offset weaker numbers elsewhere, this is worth a direct conversation with your board before the rule is final, not after.

Stablecoins are now a bank supervision question, even if you have never touched one

The GENIUS Act became law in July 2025. This year, both the OCC and the FDIC put out proposed rules to implement it. The OCC’s version is the broader of the two, covering licensing, reserves, redemption, custody, and capital standards for payment stablecoin issuers under its authority. The FDIC’s proposal follows a similar shape for the institutions it supervises, with particular attention to how tokenized deposits get treated under deposit insurance.

It is tempting to file this under “not our problem” if you have no plans to issue a stablecoin. Two reasons that is premature. If you provide any custody service that touches stablecoin reserves, the OCC’s proposal reaches you regardless of who issued the coin. And your core provider or a fintech partner may be closer to building this than you realize, which turns it into a third-party risk conversation before it ever becomes a product decision on your end. Put it on the vendor management radar now, even if the honest answer today is not yet.

The thread underneath all four

None of these are really about the technology, the transaction, or even the rule itself. Every one of them comes down to whether you can show your work: that you identified the risk, sized it to your institution, and can point to when and how you decided what to do about it.

The exam question is shifting from “do you have a policy” to can you “prove the policy reflects what is happening.” The comment periods are still open, and the guidance is still proposed, not final. That is exactly the window where closing the gap costs the least.

Want the full mid-year regulatory picture?

Watch the webinar replay
Navanta section divider
Sources: FFIEC; OCC; FDIC

By Compliance Guru • July 25, 2026

Join the Navanta Navigators Brief

Insights for community bankers navigating technology, security, and growth.

More in Artificial Intelligence (AI)

  • Pennies
    ARTICLES

    Industry Update: Preparing for Operational Changes Related to Pennies and Cash-Handling Practices

    Read the Post
  • ARTICLES

    Why We Chose to Partner with the Cyber Risk Institute (CRI)

    Read the Post
  • ARTICLES

    A Guide to Selecting the Right Replacement for the FFIEC CAT

    Read the Post
Navanta logo - homepage
  • Linkedin
  • Get to Know Us
    • Our Story
    • Our People
    • Join Our Team
  • Find Your Solution
    • Core Banking
    • Managed IT
    • CRM
    • Advisory
  • Explore Resources
    • Blog Posts
    • Client Experiences
    • Events & Webinars
  • Contact Us
    • 877-778-7774
    • [email protected]

  • 877-778-7774
  • Support
  • Privacy Policy
© 2026 Navanta
Contact Us

Client Login

  • MyBPC

    Previously MyBankonIT. Log in here to access your client portal for Bankers Private Cloud.

    Sign In

  • theSafeTM

    Sign in here to access your account information and resources in theSafe as usual.

    Sign In

  • Navanta CRM

    Previously Quest Analytics IQCRM. Continue to use these existing CRM links:

    Product Updates Technical Requirements CRM Email Support