It’s exam time. You have prepared, gathered the requested information, and walked examiners through the details. Then they ask a question. Nothing big or dramatic, but one you were not ready for.
It happens all the time. Something significant in a Federal Register notice or supervisory letter slips by until it surfaces as an unexpected exam question. For more than a decade, we have hosted regulatory update sessions to help institutions avoid being caught off guard. Our goal is to help you stay aware of examiner scrutiny, risk management trends, and the issues most likely to show up in your next exam.
This year, four specific topics are sitting just beyond the radar of many compliance teams. Here is a rundown of these topics and what they mean for your institution.
A Mid-year Look at the Regulatory Shifts Shaping Community Banking
Prefer to hear this straight from Tom and Emily?
The AI risk that matters is not the AI
There is no formal “rulebook” for AI yet, but regulators are already evaluating it through frameworks you know well: third-party oversight, data protection, and risk assessments. They expect you to understand how to apply those frameworks to whatever your institution is doing with AI.
The biggest mistake is thinking your institution does not use AI. Microsoft Copilot is stitched into Word, Excel, and Outlook. Google defaults to AI-enhanced search before you even finish typing. AI tools are already part of everyday business processes. Telling an examiner you are not using AI suggests a blind spot in governance and oversight. A better approach is to acknowledge the presence of AI internally and in third-party solutions, even if you have not fully catalogued every instance.
Acceptable use policies matter. Employees need to understand and acknowledge what they should and should not do with the AI tools available in their workspace. But policies alone are not enough. Without technical controls to monitor and restrict activity, those guardrails can be difficult to enforce.
Another important piece of your information security program is acceptable use training. Employees should know how to sanitize prompt information so an AI model cannot piece together confidential details from context. Asset size, geography, and a few operational clues may be enough to identify your institution. If a loan officer or operations employee pastes anything that resembles nonpublic customer information into a chatbot for a faster answer, that is a data leakage event, whether the word “AI” ever shows up in your incident log.
Put something in writing, even if it is only one paragraph added to your acceptable use policy. Auditors and examiners are not expecting you to have this solved. They are checking whether you have thought about it and documented a first step. An institution that has said nothing looks very different from one that has taken even a modest action.
Employee use is one part of AI oversight, but much of the risk sits with third-party providers. Your core provider, security vendor, and penetration testing firm are almost certainly using AI somewhere in their operations. Ask how your vendors validate their AI models and how they patch them. You may not get a satisfying answer yet. Ask anyway. Having that question on record is what you will want to point to later.
One wrinkle worth knowing: the model risk management guidance that came out this spring explicitly says generative and agentic AI models are outside its scope. That does not mean regulators are letting those models off the hook. It means the guidance has not caught up yet. Explainability and validation still matter under your existing risk framework, especially when AI touches a lending decision, where fair lending exposure does not wait for the paperwork to catch up.
Examiners have stopped accepting “we have DLP” as an answer
Data Loss Prevention expectations are not new, but they are getting sharper. Examiners and auditors are past the checkbox phase. They want to know what is running in your environment, where your data moves, and whether you are treating DLP as a strategy to control risk.
If you are still using default vendor settings rather than configurations based on an actual risk assessment, then your DLP looks more like a checked box than a functioning control.
Monday morning task: Pull up your current software inventory and data flow diagrams. Do they reflect your current operations, or are they outdated? Shadow AI, meaning AI use that has not been officially approved, tends to thrive in the gap between what is documented and what is actually happening.
CAMELS is getting its first real rework in thirty years
The FFIEC as proposed significant changes to the Uniform Financial Institutions Rating System, with the comment period closing August 17, 2026. Even if you never plan to file a comment, this is worth reading closely because it changes how your next composite rating gets built.
In a nutshell, the proposal no longer gives special consideration to the Management component when determining the composite score. Regulators reviewed ratings data going back to 2000 and found that Management has been the single most influential factor in composite ratings, often relying on qualitative assessments.
The proposed shift reflects a broader regulatory move toward more quantitative measures of safety and soundness, especially material financial risk. But the qualitative side still matters. Weaknesses in management practices can still lead to risk-management problems that become material later, whether they are weighted differently in the exam or not.
The six components—Capital, Asset quality, Management, Earnings, Liquidity, and Sensitivity—are not going anywhere. What is changing is the weighting. The proposal places less emphasis on procedural precision and more emphasis on patterns that may threaten an institution’s financial condition.
This does not mean management stops mattering. It means a soft finding in an audit, on its own, may not carry the weight it used to. A genuine problem in how the institution is run will still show up, just measured differently. If your institution has been leaning on a strong management score to offset weaker numbers elsewhere, this is worth a direct conversation with your board before the rule is final, not after.
Stablecoins are now a bank supervision question, even if you have never touched one
Following the GENIUS Act of 2025, the OCC and the FDIC issued proposed rules related to stablecoins. The OCC’s version is broader, covering licensing, reserves, redemption, custody, and capital standards for payment stablecoin issuers under its authority. The FDIC’s proposal follows a similar shape for the institutions it supervises, with particular attention to how tokenized deposits are treated under deposit insurance.
It is tempting to file this under “not our problem” if you have no plans to issue a stablecoin. But that would miss the point. This can affect you for two reasons:
- Third-Party Risk: Your core provider or fintech partners may be closer to building stablecoin-related capabilities than you realize.
- Custody Services: If you provide any custody service that touches stablecoin reserves, the OCC’s proposal applies to you regardless of who issued the coin.
Put it on the vendor management radar now, even if today’s honest answer is “not yet.”
The bottom line: Show your work
These considerations are not really about the technology, the transaction, or even the rule itself. The common thread is whether you can show your work.
The exam question is shifting from, “Do you have a policy?” to “Does your policy reflect a clear understanding of your specific environment, and can you prove how you managed those risks?”
Closing these gaps now, while many of these rules are still very new or in the proposal stage, is the most effective way to ensure you aren’t blindsided at your next exam.
The Navanta Advisory Team is here to help you understand how these regulatory developments may affect your institution and what to prioritize before your next exam. Contact us.
Want the full mid-year regulatory picture?
