Under Comptroller of the Currency Jonathan Gould, the OCC has spent the past several months systematically stripping away examination requirements that were never mandated by statute or regulation in the first place, while, at the same time, sounding a notably cautious tone about credit, technology and geopolitical risk in its own risk reporting. For community and regional national banks, 2026 examinations will likely feel different in scope and tone even as the underlying risk areas examiners care most about remain largely unchanged.9

Here is what the guidance points to.

1. The End of Policy-Mandated Exam Activities

The most consequential change took effect January 1, 2026, when the OCC eliminated a broad set of examination activities that had been required by internal OCC policy rather than by law. Under Bulletin 2025-24, examiners are no longer required to perform activities such as a fair lending risk assessment every supervisory cycle or flood insurance transaction testing every three cycles simply because policy called for it on a fixed schedule. Community Reinvestment Act (CRA) examination scheduling is now discretionary as well, tailored to a bank's size, risk profile and complexity rather than run on a fixed cadence.1,9

The OCC has been explicit about the philosophy behind the change: most community banks are well capitalised, well managed and engaged in low-risk activities, supporting the argument that examiners should not be required to perform activities "solely for the sake of completing procedures." Going forward, examiners will rely more heavily on quarterly off-site monitoring and bank-provided reports to track financial trends and flag emerging issues between on-site visits.

Other targeted relief announced alongside this shift includes:

  • Retail non-deposit investment products (RNDIP), community banks will now be examined against the shorter, less prescriptive Community Bank Supervision booklet rather than the lengthier RNDIP-specific booklet historically used for banks of all sizes
  • Model risk management, community banks will no longer face an annual model risk review by default; the OCC has clarified that model risk practices should be tailored to a bank's actual risk exposure and model use
  • Data collection, the OCC is reassessing tools such as the Money Laundering Risk System and Interest Rate Risk Survey to determine whether existing data requests can be trimmed or simplified

None of these changes a bank's underlying legal obligations, banks remain fully responsible for compliance with fair lending, flood insurance, BSA/AML and other requirements. What has changed is the OCC's own internal mandate to test for compliance with fixed frequency and scope regardless of risk.

2. A Genuinely Risk-Based BSA/AML Posture

Effective February 1, 2026, the OCC also updated its BSA/AML examination procedures for community banks to better reflect a risk-based approach, prioritising higher-risk areas of a bank's business rather than applying uniform scrutiny across the board. As part of the same announcement, the OCC discontinued its practice of annually collecting AML/CFT risk data from community banks through the Money Laundering Risk System, stating that the system was no longer necessary given the shift toward risk-based examination.

Compliance and risk teams should expect examiners to spend more time asking banks to demonstrate why their risk assessment supports a given level of AML testing, and less time working through a standardised checklist regardless of a bank's actual customer and transaction risk profile.

3. Cybersecurity Exams Are Narrower, But the Underlying Risk Is Not

The OCC has also updated the resources examiners use to scope bank information technology and cybersecurity examinations at community banks, aimed at narrowing and simplifying these reviews consistent with the broader risk-based push. That said, this is one area where "less examination burden" and "lower priority" are not the same thing. The OCC's own Spring 2026 Semiannual Risk Perspective flags cybersecurity as an elevated and growing risk, driven by sophisticated foreign state-sponsored actors and by AI tools that are increasing the speed and scale of attacks.5

Examiners are simplifying how they test for cyber and IT resilience at community banks, not deprioritising the risk itself, banks should expect a leaner exam process built around a more targeted set of questions about actual preparedness, rather than procedural completeness.

4. Credit Risk: Concentrated Into Manageable Pressure Points

The Spring 2026 Semiannual Risk Perspective describes credit risk across the federal banking system as manageable in aggregate, with past-due and nonaccrual ratios still below long-term averages, but it flags several areas warranting close monitoring:5

  • Commercial real estate, particularly office and to a lesser extent multifamily properties, where refinancing pressure continues even as net absorption for office space turned positive in late 2025
  • Private credit markets, an area of growing supervisory interest given banks' direct and indirect exposure to non-bank lenders and funds
  • Consumer credit among lower-score borrowers, where the OCC has observed modest increases in past-due loans even as overall retail loan performance at OCC-supervised banks remains comparatively stable

Notably, the OCC's updated approach draws an explicit distinction by institution size when assessing what counts as a "material" risk. A percentage decline in capital or liquidity that would be material for the largest banks will not necessarily be treated as material for a community bank.3 This tailoring principle, size matters when defining materiality, runs through both the exam-scope changes and the risk commentary.

5. Operational and Geopolitical Risk Get More Airtime

Community and regional banks should also expect examiners to probe operational resilience more than in past cycles. The OCC's spring reporting describes banks facing "elevated and interconnected" risks spanning commercial credit deterioration, technology disruption, cyber threats, fraud and interest rate and liquidity uncertainty, a framing that treats these risks as compounding rather than isolated.

Geopolitical tensions are cited as a factor that could disrupt energy markets and fuel inflation, with a compliance dimension as well. Elevated geopolitical tensions raise the risk of sanctions violations and strain BSA/AML systems, an area regulators including FinCEN have flagged given the use of money-laundering networks to move illicit funds through the US financial system.

6. Capital Relief: A Lower and More Flexible CBLR

On the capital side, the OCC finalised a rule (alongside the Fed and FDIC) lowering the community bank leverage ratio threshold from 9% to 8%, effective July 1, 2026, and extending the grace period for banks that temporarily fall out of compliance from two quarters to four. The OCC has noted that the vast majority of OCC-supervised banks under $10 billion in assets qualify for the CBLR framework, meaning this relief reaches a substantial share of the community banking population and gives more banks the option of a simpler, single-ratio measure of capital adequacy in place of full risk-based capital calculations.

7. Innovation Oversight Is Loosening

The OCC continues to signal openness to bank involvement in digital assets and stablecoins, issuing a notice of proposed rulemaking in February 2026 to establish a federal framework for payment stablecoins under the GENIUS Act and joining an interagency FAQ in March 2026 clarifying that tokenising a security does not generally change its regulatory capital treatment. For community and regional banks exploring these activities, the direction of travel is toward a defined regulatory perimeter rather than case-by-case improvisation, though banks pursuing this work should still expect close supervisory attention given the products' novelty.

What This Means for Community and Regional Banks in 2026

The OCC's approach this year has two layers that examination teams and boards should keep separate in their own minds:

  • Process relief is real, fixed-frequency, policy-driven testing, fair lending assessments, flood insurance transaction testing, annual model risk reviews, CRA exams on autopilot, standardised RNDIP procedures, is being replaced by discretion tied to a bank's actual risk profile. Banks that have historically absorbed exam burden disproportionate to their size and complexity should see meaningfully lighter-touch reviews in these areas
  • Substantive risk scrutiny is not going away, CRE concentration, private credit exposure, consumer credit performance among weaker-score borrowers, cybersecurity and AI-driven fraud, and BSA/AML effectiveness remain live priorities, arguably examined more purposefully now that examiners are not spread across mandatory procedural checklists

The practical takeaway for community and regional bank management teams is not to mistake a lighter exam process for a lighter risk bar. Examiners will ask fewer procedural questions but will expect sharper, risk-based answers on the areas that matter. A bank's own risk assessment increasingly has to do the work that a fixed OCC checklist used to do. Boards and risk committees that can clearly articulate why their institution's testing, monitoring and controls are appropriately scoped to their size and risk profile will be well positioned. For those banks relying on the old checklist as their risk framework, it may be a harder conversation with examiners going forward.