Financial institutions manage regulatory uncertainty by splitting a pending rule into the part that is settled enough to build now and the part that stays under monitoring, then recording the basis for each call so the choice holds at the next examination.
This article sets out how that condition differs from regulatory change, the four tests that sort the work, what is unresolved for US institutions going into Q4 2026, and how the sort is tracked in a compliance platform.

What Regulatory Uncertainty Means for a Supervised Institution
US banks and credit unions supervised by the OCC, FDIC, Federal Reserve or NCUA live with this condition, and its effects are most felt between $500M and $50B in assets, where compliance work is planned several quarters out.
Regulatory change management handles a rule that has already changed, while regulatory uncertainty is the condition before that point. It shows up as:
- A proposal out for comment
- A final rule whose compliance date is contested
- A rule enjoined or stayed in litigation
- A supervisory priority moving with no rule behind it
- An agency shedding examination capacity
Sorting a Pending Rule: Build Now or Defer and Monitor
Four tests sort any unsettled item onto one of two lists.
1. Direction test
Does the requirement point the same way under every plausible outcome? Data capture, record retention and customer identification usually do.
2. Reversibility test
Would the work be wasted if the rule lands differently? A reusable data field or a documented control survives most outcomes.
3. Lead-time test
Does the build take longer than the notice the institution would get? Anything needing a core system change, a vendor contract or a new data feed does.
4. Evidence test
Would an examiner ask what the institution did while the item was pending? A deferral needs a documented basis.
Each test produces a dated position, revisited on a set cadence of quarterly for most items and monthly for anything in active litigation, which builds the timestamped trail that makes a deferral defensible.
What Is Unresolved for US Financial Institutions in Q4 2026
Five items dominate bank compliance planning this quarter. Statuses follow the Federal Register, agency releases and court records as of September 2026.
| Unresolved item | Status, September 2026 | Build now | Hold and monitor |
|---|---|---|---|
| Basel III endgame capital | Interagency re-proposal 19 March 2026; comments closed 18 June 2026; no final rule | Capital data lineage, model documentation | Risk-weight calibration |
| Section 1071 small business lending | Final rule 1 May 2026; effective 30 June 2026; compliance 1 January 2028 | Data capture, counting originations to the 1,000 threshold | Privacy and publication terms |
| Section 1033 open banking | Enjoined in Forcht Bank v. CFPB, E.D. Kentucky, October 2025; new proposal at OIRA, August 2026 | Data-sharing inventory, authentication, third-party oversight | Interface specs, fees, compliance dates |
| FinCEN AML/CFT program rule | Proposed 7 April 2026; comments closed 9 June 2026; 12-month implementation proposed | Risk assessment quality, resourcing to higher risk | Program structure, testing, officer requirements |
| AI supervision | OCC Semiannual Risk Perspective, May 2026, signals guidance coming; interagency request for information planned | AI tools in the model inventory, under change control | Explainability and validation for generative models |
Evidence to Keep While a Rule Is Pending
A defensible file holds a dated position with the reasoning behind it, the version of the impact assessment that reasoning rests on, the named owner and review cadence, and the trigger that would reopen the decision. Those records belong in the regulatory change management framework that already tracks settled rules.
Supervisory capacity is thinner this quarter, which raises what the file has to carry at the next examination. The Federal Reserve is cutting its Board-level supervision and regulation headcount by about 30% by the end of 2026.
Tracking Unsettled Requirements in Predict360
Predict360‘s Regulatory Change Management module supports developing, assessing and monitoring an enterprise compliance framework as the regulatory environment changes, which is where a monitoring list and its review cadence sit.
Policy and Procedure Management holds the document versions a position rests on and Regulatory Examination and Findings Management stores what an examiner requests. The platform creates risk and regulatory relationships across those records.
Frequently Asked Questions
How is regulatory uncertainty different from regulatory change management?
Regulatory change management is the process an institution runs once a rule has changed, covering intelligence, impact assessment, implementation and testing against a known text and a known date.
Should a bank build to a proposed rule before it is final?
Partly. Build the elements that point the same way under every plausible outcome, typically data capture, record retention and customer identification, plus anything whose lead time exceeds the notice the institution would get. Hold the elements keyed to a contested threshold, format or calculation, and document why each one is on hold.
How do institutions track unsettled rules in real time?
Most pair a regulatory intelligence feed with a standing monitoring list held inside the compliance program, so every pending item carries an owner, a review cadence and a dated position.
The Predict360 Enterprise Risk Management Software ensures managers have complete visibility of enterprise risk on a single dashboard.
Request Demo- Cloud-Based
- Risk Repository
- Assess Risks
- Real-time Monitoring