A Risk-Based Approach to Changing Regulatory Priorities
Successful banks will use evolving supervisory priorities to align resources with material risk, improve operational effectiveness and strengthen short-term resilience.
Brought to you by Crowe LLP

Regulatory agencies are recalibrating their supervisory approaches, leading many banks to reevaluate their compliance and risk management initiatives. As they do, directors and executive teams must take care not to misinterpret the changing regulatory environment.
Evolving Supervisory Priorities
Today’s banking industry is seeing a noticeable shift in regulatory posture. To be clear, agencies are not stepping away from supervision, but they are refocusing their attention toward issues that they view as the most material threats to financial stability, safety and soundness, with less direct supervisory attention on matters viewed as ancillary concerns.
Recent examples include the Federal Deposit Insurance Corp. raising the asset thresholds for certain Federal Deposit Insurance Corp. Improvement Act (FDICIA) compliance requirements, the Office of the Comptroller of the Currency proposing an increase in the threshold for heightened safety and soundness standards for national banks from $50 billion to $700 billion, and the Federal Reserve issuing supervisory guidance that suggests examiners may rely more heavily on effective internal audit and compliance testing rather than duplicating that work themselves.
The common theme in these actions is not deregulation but reprioritization — coupled with a broader regulatory acknowledgment that not all risks carry equal systemic weight, particularly for midsize and community banks. Rather than emphasizing extensive process reviews, documentation exercises or duplicative testing, supervisors appear to be focusing on whether banks are effectively identifying and managing the risks that matter most.
The Impact on Banks’ Risk Management
The current changes in regulatory approach should not be interpreted as reduced accountability or an opportunity to relax risk management. If anything, directors need to exercise even greater judgment as regulators place more reliance on management, compliance functions and internal audit work to support supervisory conclusions.
This could create opportunities for banks to rethink how risk management resources are deployed and allocated. For example, many institutions have begun reassessing whether certain low-risk or duplicative activities can be streamlined, automated or integrated across functions. Others are moving more rapidly toward integrated assurance models, in which compliance and internal audit collaborate closely, reduce duplicative testing and focus on whether the compliance management system is well designed and whether ongoing monitoring is robust and reliable.
Other practical steps include refreshing risk assessments to reflect the new supervisory posture, rebalancing annual audit plans and reconsidering what should remain in the control environment by distinguishing between regulator-required activities and good governance practices.
Technology also plays an important role in this transition. Automation, continuous monitoring tools, integrated risk platforms and enhanced data analytics allow institutions to maintain or even strengthen oversight while reducing manual processes and unnecessary duplication.
Leading organizations are using this moment to rethink their broader operating model across all three lines of defense (line of business, compliance and risk management, and internal audit) and to proactively redesign processes to be more efficient, scalable and insight driven.
How Bank Boards Can Respond
As external scrutiny becomes more targeted, the bank’s own second- and third-line credibility becomes even more important. Toward this end, boards and audit committees should test management on various fronts, asking critical questions such as:
- Has management defined its view of material risk in light of the current supervisory posture?
- Which risk areas are likely to receive less direct supervisory testing, and how is management keeping those areas appropriately controlled?
- Are there areas where management is changing the bank’s risk management program because requirements have shifted? If so, what is the rationale?
- How is the second line adjusting its monitoring plan to reflect both supervisory priorities and the bank’s own risk profile? Does it have a robust framework or methodology and the necessary technical knowledge to effectively perform integrated testing of compliance and controls?
- If FDICIA or similar work is reduced, what assurance coverage is being removed and what, if anything, is replacing it?
- Has internal audit revised its annual plan to address any assurance gaps created by regulatory change?
- Where is the bank relying more on management monitoring or compliance testing, and how can the reliability of that work be confirmed?
- Are cost savings from reduced regulatory burden being tracked, measured and invested into technology, data capabilities or higher-value risk management initiatives?
Going Forward
Supervisory priorities can shift in response to changing economic conditions or emerging threats. In some cases, regulators have requested that banks adjust their audit or monitoring plans to address evolving concerns. Banks with strong governance frameworks and adaptable assurance functions will be better positioned to respond effectively.
Ultimately, a narrower supervisory lens does not justify a narrower governance lens. Successful institutions will view the evolving supervisory priorities not as permission to do less but as an opportunity to work smarter, aligning resources more closely with material risk, improving operational effectiveness and strengthening the institution’s long-term resilience.