The Regulatory Paradox: A Decade of Declining Enforcement Meets Expanded Exam Cycles
- Sepideh Rowland
- 10 minutes ago
- 6 min read
A False Sense of Security in Banking Compliance
For the past decade, federal banking regulators have initiated significantly fewer enforcement actions, creating an environment that might feel increasingly permissive. Yet even as enforcement activity has declined, regulatory agencies are fundamentally reshaping how they conduct examinations and assess bank performance. This apparent contradiction—fewer enforcement actions paired with structural changes to supervisory frameworks—presents a critical risk for banks that mistake reduced enforcement activity for relaxed compliance standards.
The reality is more nuanced. While enforcement may be down, the regulatory environment is not loosening. Instead, it is evolving into a more targeted, risk-focused model that could surface more issues for banks whose controls have lapsed.
The Enforcement Decline: A Decade-Long Trend
Enforcement Actions Have Fallen Sharply
Our Klarify data tells a striking story, revealing a sharp decline in formal federal enforcement actions for BSA/AML violations through 2026—marking a notable shift in the compliance enforcement landscape.Â
Peak to Trough: Enforcement actions surged to 40 in 2024, then dropped 77% to just 9 in 2025, with only 2 actions recorded year-to-date in 2026.

Agency Variations Tell Different Stories
Despite the sharp decline overall, the change in BSA/AML enforcement has not been uniform across regulators:
Federal Reserve: The Fed has experienced the sharpest decline, with no formal enforcement actions issued since 2024.
FDIC: The FDIC shows a steeper decline than the OCC, but significantly less pronounced than the Federal Reserve.
OCC: The OCC has remained relatively flat, increasing by approximately 4% overall, though this appears driven by a single spike year in 2024. The 2024 spike was largely short-lived; 2025 returned to the downward trajectory.

Smaller Banks Most Affected: The majority of historical enforcement actions with BSA/AML violations targeted banks with assets of <$100M and $100M-$1B, with mega-sized institutions ($10B+) accounting for a smaller proportion of cases.Â

The Regulatory Evolution: Exams and Risk-Focused Supervision
Even as enforcement actions have declined, federal regulators have announced or implemented significant changes to their examination frameworks. These changes are not uniformly reducing scrutiny—they are reshaping it.
The OCC’s 2026 Community Bank Examination Pivot
Effective January 1, 2026, the OCC eliminated mandatory, policy-based examination requirements for community banks.(1) Rather than adhering to a fixed list of policies and procedures to examine, OCC examiners will now conduct examinations tailored to each bank’s specific activities, size, complexity, and risk profile.
This shift toward risk-focused examination means banks will no longer receive credit for generic compliance efforts. Examiners are expected to focus on material financial risks and the controls that protect against them. A bank that has maintained check-the-box compliance programs without a robust risk management infrastructure will be exposed.
Although this change officially applies only to banks with up to $30 billion in assets, we expect changes to ultimately trickle up to examinations of larger institutions.Â
The Federal Reserve’s Supervisory Enhancements
In November 2025 and again in April 2026, the Federal Reserve released information about supervisory enhancements designed to refocus examination efforts.(2) The new supervisory operating principles concentrate examiner resources on material financial risks that genuinely threaten the safety and soundness of institutions.
These enhancements are not deregulation, but are rather a reallocation of scrutiny away from procedural or documentation shortcomings and toward the highest-risk activities and controls.
The FDIC’s Modified Approach
The FDIC modified its examination approach in 2025, reducing the frequency of consumer compliance examinations for small banks.(3) While this sounds like a reduction in oversight, it reflects a broader strategy: focus on material risks rather than process-focused reviews.
The Paradox: Why Banks Should Be Wary
The combination of declining enforcement with evolving examination frameworks creates a dangerous paradox for many institutions.
The Temptation to Relax
When enforcement actions decline visibly, compliance officers, internal audit teams, and boards of directors may be tempted to reduce regulatory spending, deprioritize control enhancements, or scale back remediation efforts. The logic seems straightforward: fewer regulators are taking action, so the compliance burden should ease.
This reasoning is flawed.
The Materiality Test
Under the new risk-focused examination model, regulators are not asking, "Did you follow the policy?" They are asking, "Are your controls adequate for your actual risk?" A bank that has let its vendor management program atrophy, neglected to update its BSA/AML procedures for emerging typologies, or failed to adapt its cybersecurity controls to evolving threats will face regulatory findings—and potentially enforcement action—even if comparable banks are not being examined as frequently.
The revised exam cycles may extend to 18 months for certain banks, but an examination conducted once every 18 months using a material-risk framework is far more likely to identify genuine deficiencies than a more frequent examination focused on compliance.
The Compliance Debt Comes Due
Banks that have deferred remediation efforts or sidelined control improvements during the period of lighter enforcement may face a "compliance debt" that becomes immediately visible when examiners refocus their lens. A vendor that was not reassessed. A gap in AML training that went unaddressed. Resource constraints that were not addressed. These issues were always there; lighter enforcement simply provided a window to overlook them.
The Real Risk: Control Degradation in a Risk-Focused Environment
The greatest risk for banks is not the current enforcement level but the degradation of the control environment that leniency in enforcement may have enabled.
A decade of lighter enforcement can lead to:
Control fatigue, where compliance teams lose urgency around remediation.
Deferred system investments, where banks delay technology upgrades that reduce operational risk.
Talent loss, where experienced compliance staff, seeing fewer consequences, move to other industries.
False negatives in risk assessment, where banks rationalize continuing with inadequate controls because "no one has been penalized for this yet."
Significant, unplanned costs to remediate issues when enforcement activity does materialize.Â
In a risk-focused environment, a control that was adequate five years ago may be inadequate today. The risk landscape has changed: third-party service providers have proliferated, cyber threats have evolved, and consumer expectations around data protection have shifted. Regulators examining for material risks will assess controls against today's threat environment, not yesterday's.
When an examiner arrives with a material-risk focus, the absence of adequate controls becomes starkly apparent. Findings that were overlooked or deferred during a lighter enforcement period are unlikely to be missed in a focused examination. The subsequent enforcement action—if controls have deteriorated meaningfully—may be more significant than if the bank had maintained consistent effort throughout the lighter enforcement period.
What Banks Should Do Now
1. Conduct a Material Risk Assessment
Don't wait for examiners to tell you what matters. Conduct an honest assessment of your bank's material financial risks. What could actually threaten your safety and soundness? Build your control environment around those risks, not around a checklist of regulatory expectations.
2. Triage Your Compliance Investments
Not all controls are equal in a risk-focused environment. Prioritize investments that address material risks. Deprioritize (or eliminate) controls that provide minimal risk mitigation relative to their cost.
3. Close Remediation Backlogs
If your bank has accumulated a backlog of open audit and compliance findings, treat them with urgency. When risk-focused examiners arrive, outstanding findings will immediately signal an institution that has allowed its control environment to degrade.
4. Prepare for the New Exam Framework
Understand your regulatory agency's new examination approach. The OCC's shift to risk-focused exams for community banks is already in effect. The Federal Reserve's supervisory enhancements are live. The FDIC's modified compliance exam approach is in place. Ensure your control documentation and internal audit approach align with these frameworks, not legacy models.
5. Invest in Control Effectiveness Monitoring
In a material-risk environment, the strength of a control matters more than its existence. Build robust monitoring of control effectiveness, not just control existence. Ensure your board and audit committee see evidence of control performance, not just completion.
Conclusion: Enforcement Decline Does Not Mean Compliance Decline
The reduction in federal enforcement actions over the past decade is real and documented. But it is not an invitation to lower compliance standards. Instead, it reflects a regulatory shift toward more targeted, risk-focused oversight.
Banks that have allowed their control environments to atrophy during the lighter enforcement period face significant risk in this new model. When examiners arrive with a material-risk lens, the absence of robust controls will be immediately visible. The institutions that thrive in the new environment will be those that have maintained disciplined control environments focused on genuine risk, not those that have cut compliance costs in response to lighter enforcement.
The paradox of declining enforcement, paired with evolved examination frameworks, creates a critical moment for bank management and boards. The time to address control gaps is now—not after an examiner's material-risk assessment reveals what should have been obvious all along.
See OCC Bulletin 2025-24, Examinations: Frequency and Scope for Community Banks (Oct. 6, 2025), https://www.occ.gov/news-issuances/bulletins/2025/bulletin-2025-24.html.
See Mary Aiken & Julie Williams, Statement of Supervisory Operating Principles (Oct. 29, 2025), https://www.federalreserve.gov/newsevents/pressreleases/files/bcreg20251118a1.pdf; Randall D. Guynn & Julie Williams, Updated Statement of Supervisory Operating Principles (Apr. 21, 2026), https://www.federalreserve.gov/supervisionreg/files/statement-of-supervisory-operating-principles-20260430.pdf.
See FDIC Updates its Consumer Compliance Examination Schedule (Nov. 7, 2025), https://www.fdic.gov/news/financial-institution-letters/2025/fdic-updates-its-consumer-compliance-examination-schedule