Supervisors are redirecting their resources to focus on the most significant threats to safety and soundness. Have you?

The Federal Reserves September 2026 Statement of Supervisory Operating Principles includes a line that caught my attention:

“Initially, we are going to focus on addressing the finding that for decades there has been a culture of excessive risk-aversion and indecision in Federal Reserve supervision on the most significant vulnerabilities of banking organizations, but not on their least significant vulnerabilities.”

There is a lot packed into that statement.

But from a Compliance program perspective, I think it should prompt organizations to take a fresh look at two things:

1. Your Compliance Risk Assessment

Does your methodology truly differentiate between material and less significant risks? Or, once something is identified as a regulatory requirement, does everything begin to get the same level of attention?

When assessing your control environment, are controls addressing procedural adherence given the same weight as controls designed to prevent fraud?

A strong risk assessment shouldn't simply catalog requirements and assign ratings. It should help leadership understand where failure could meaningfully impact safety and soundness.

If everything is a priority, nothing is a priority.

2. Your Monitoring and Testing Program

Now, does your Monitoring and Testing plan truly draw from the output of that risk assessment?

Are your most significant compliance risks receiving the greatest attention, strongest coverage, and most timely insight? Or are highly skilled Compliance professionals spending valuable time testing lower-risk processes and procedural requirements?

Look at your testing inventory. How much of it is focused on what the Federal Reserve might describe as the “least significant vulnerabilities”?

When it comes to managing risk, deciding what not to do is just as important as deciding what to do. Materiality doesn't mean ignoring requirements. It means being thoughtful about how you allocate finite resources against them.

And that distinction matters.

A Compliance program that treats every risk as equally important is not effective.

So, take a moment and reflect: Are you leveraging the Federal Reserves operating principles to improve your program and thoughtfully narrow your focus?

Risk-based supervision should be met with risk-based Compliance.

Next
Next

Community Bank LeadershIP: Is Your Risk Appetite Keeping Pace?