Michelle Beard
Partner, Risk Consulting
JP Shelly
Partner, Audit & Assurance
Stacia Vernon
Senior Manager, Risk Consulting

Regulatory agencies are recalibrating their supervisory approaches, leading many banks to reevaluate their compliance and risk management initiatives. As they do, directors and executive teams must take care not to misinterpret the changing regulatory environment.

Evolving Supervisory Priorities
Today’s banking industry is seeing a noticeable shift in regulatory posture. To be clear, agencies are not stepping away from supervision, but they are refocusing their attention toward issues that they view as the most material threats to financial stability, safety and soundness, with less direct supervisory attention on matters viewed as ancillary concerns.

Recent examples include the Federal Deposit Insurance Corp. raising the asset thresholds for certain Federal Deposit Insurance Corp. Improvement Act (FDICIA) compliance requirements, the Office of the Comptroller of the Currency proposing an increase in the threshold for heightened safety and soundness standards for national banks from $50 billion to $700 billion, and the Federal Reserve issuing supervisory guidance that suggests examiners may rely more heavily on effective internal audit and compliance testing rather than duplicating that work themselves.

The common theme in these actions is not deregulation but reprioritization — coupled with a broader regulatory acknowledgment that not all risks carry equal systemic weight, particularly for midsize and community banks. Rather than emphasizing extensive process reviews, documentation exercises or duplicative testing, supervisors appear to be focusing on whether banks are effectively identifying and managing the risks that matter most.

The Impact on Banks’ Risk Management
The current changes in regulatory approach should not be interpreted as reduced accountability or an opportunity to relax risk management. If anything, directors need to exercise even greater judgment as regulators place more reliance on management, compliance functions and internal audit work to support supervisory conclusions.

This could create opportunities for banks to rethink how risk management resources are deployed and allocated. For example, many institutions have begun reassessing whether certain low-risk or duplicative activities can be streamlined, automated or integrated across functions. Others are moving more rapidly toward integrated assurance models, in which compliance and internal audit collaborate closely, reduce duplicative testing and focus on whether the compliance management system is well designed and whether ongoing monitoring is robust and reliable.

Other practical steps include refreshing risk assessments to reflect the new supervisory posture, rebalancing annual audit plans and reconsidering what should remain in the control environment by distinguishing between regulator-required activities and good governance practices.

Technology also plays an important role in this transition. Automation, continuous monitoring tools, integrated risk platforms and enhanced data analytics allow institutions to maintain or even strengthen oversight while reducing manual processes and unnecessary duplication.

Leading organizations are using this moment to rethink their broader operating model across all three lines of defense (line of business, compliance and risk management, and internal audit) and to proactively redesign processes to be more efficient, scalable and insight driven.

How Bank Boards Can Respond
As external scrutiny becomes more targeted, the bank’s own second- and third-line credibility becomes even more important. Toward this end, boards and audit committees should test management on various fronts, asking critical questions such as:

  • Has management defined its view of material risk in light of the current supervisory posture?
  • Which risk areas are likely to receive less direct supervisory testing, and how is management keeping those areas appropriately controlled?
  • Are there areas where management is changing the bank’s risk management program because requirements have shifted? If so, what is the rationale?
  • How is the second line adjusting its monitoring plan to reflect both supervisory priorities and the bank’s own risk profile? Does it have a robust framework or methodology and the necessary technical knowledge to effectively perform integrated testing of compliance and controls?
  • If FDICIA or similar work is reduced, what assurance coverage is being removed and what, if anything, is replacing it?
  • Has internal audit revised its annual plan to address any assurance gaps created by regulatory change?
  • Where is the bank relying more on management monitoring or compliance testing, and how can the reliability of that work be confirmed?
  • Are cost savings from reduced regulatory burden being tracked, measured and invested into technology, data capabilities or higher-value risk management initiatives?

Going Forward
Supervisory priorities can shift in response to changing economic conditions or emerging threats. In some cases, regulators have requested that banks adjust their audit or monitoring plans to address evolving concerns. Banks with strong governance frameworks and adaptable assurance functions will be better positioned to respond effectively.

Ultimately, a narrower supervisory lens does not justify a narrower governance lens. Successful institutions will view the evolving supervisory priorities not as permission to do less but as an opportunity to work smarter, aligning resources more closely with material risk, improving operational effectiveness and strengthening the institution’s long-term resilience.

WRITTEN BY

Michelle Beard

Partner, Risk Consulting

Michelle is a partner at Crowe, where she serves internal audit clients and leads the firm’s 340B audit and consulting services. She also leads the Crowe Healthcare Exclusion Monitor solution, which helps eliminate much of the manual work involved in the screening, verifying, and reporting on individuals and entities excluded from participation in federal healthcare programs.

Michelle has over 19 years of public accounting experience providing audit and consulting services to public and private clients, with experience in risk-based internal audit; risk assessment; management, board, and audit committee reporting; fraud investigations; financial statement audit; SOX 404 compliance; and internal audit quality assessment reviews (QARs). 614-280-5247 | [email protected]

WRITTEN BY

JP Shelly

Partner, Audit & Assurance

JP Shelly is a partner in the audit group at Crowe. He specializes in financial statement audits, internal control attestations, and SEC financial reporting. JP has more than 14 years of experience providing audit services and interpreting regulatory and accounting policy for banks and other financial services companies. 202-509-8154 | [email protected]

WRITTEN BY

Stacia Vernon

Senior Manager, Risk Consulting

Stacia Vernon is a senior manager of risk consulting at Crowe LLP, focusing on internal audit. She has 10 years of experience providing risk-based operational consulting services and leading engagements for financial service organizations. Ms. Vernon is primarily responsible for end-to-end project management, including planning and managing internal audits, assessing the design and operating effectiveness of internal controls and reporting key findings and recommendations to key stakeholders including management, the audit committee and those charged with governance. 202-552-8051 | [email protected]