The latest banking compliance trends this quarter are showing that most major rules of the last two cycles are now in force, examiners have moved from drafting to validation, and AI has crossed from pilot into operational compliance infrastructure.
According to Moody’s 2026 risk and compliance research, more than half of compliance and risk professionals are now actively using or trialing AI, and agentic AI is moving rapidly from awareness to deployment in financial institutions.

In other news, GENIUS Act implementing regulations are on track for July 18, 2026, OCC Bulletin 2025-24 recalibrated the community-bank exam scope effective January 1, 2026, and the OCC has proposed lifting the asset threshold for its heightened standards for large banks from $50 billion to $700 billion.
For a CCO building the 2026 program calendar, the question is which seven trends will drive findings, which regulatory citation sits behind each, and which applies to which bank tier, all of which will be addressed in this article.
What is Structurally Different in Banking Compliance?
Rule-making defined the 2024–2025 cycle:
- The CFPB Personal Financial Data Rights Rule
- The GENIUS Act
- FinCEN’s AML modernisation track
- Interagency third-party risk management guidance
- OCC Bulletin 2025-24
- The OCC’s proposed threshold reset for heightened standards
In other words, 2026 is the validation year. The rules are written and examiners are testing whether banks can produce evidence that they took effect.
Three structural shifts define this posture:
- Rule-making has slowed while supervisory follow-through has accelerated
- Most compliance and risk professionals are using or trialing AI per Moody’s 2026 research, and model risk management documentation is now standard
- The line between community, regional, and large banks is being redrawn through OCC Bulletin 2025-24 and the OCC’s heightened-standards threshold proposal
The 7 Banking Compliance Trends Shaping Examiner Conversations
There are seven banking compliance trends that will surface in examiner conversations. The table below summarises which bank tier each trend hits hardest and what examiners are now asking for. Read on for further detail about each trend.
| Q2 Trend | Regulatory Anchor | Bank Tier Most Affected | Examiner Action |
|---|---|---|---|
| AI governance and agentic compliance | Interagency model risk guidance; OCC model risk focus | Regional and large banks | Request AI model inventory, validation logs, human-in-loop sign-offs |
| Perpetual KYC | FinCEN April 2026 proposed AML rule; FFIEC BSA/AML manual | All tiers; heaviest on regional banks | Test event-driven CDD triggers and screening cadence |
| GENIUS Act / stablecoin compliance | GENIUS Act, implementing regs expected by July 18, 2026 | Banks with payment, custody, or issuer relationships | Review reserve attestations, custody, issuer due diligence |
| CFPB Section 1033 data rights | CFPB Personal Financial Data Rights Rule (under reconsideration) | All tiers; consumer-facing impact | Data-portability readiness, third-party access governance |
| Threshold relief and exam recalibration | OCC $50B → $700B heightened-standards NPRM; OCC Bulletin 2025-24 | Community banks; regionals near $50B | Revised CAMELS focus, fewer horizontal reviews |
| Financial-crime outcomes evidence | AMLA 2020 effectiveness amendments; OFAC guidance | All tiers | SAR-quality testing, sanctions effectiveness reviews |
| Operational resilience and TPRM | Interagency TPRM guidance (2023); FFIEC IT Handbook; NCUA priorities | All tiers; credit unions especially | Concentration-risk reporting, vendor incident drill evidence |
1. AI governance and agentic compliance move from policy to operation
AI moved from compliance pilot to infrastructure in 2025, and 2026 is the year examiners treat it that way. According to Moody’s 2026 AI in risk and compliance research, 53 percent of risk and compliance professionals are now actively using or trialling AI, a steep climb from 30 percent in 2023.
Existing federal banking agency guidance on model risk management is the anchor, now applied to AI tools previously waved through as analytics utilities. Expect requests for the following:
- An AI model inventory
- Validation logs
- Human-in-the-loop sign-off points
2. Perpetual KYC replaces periodic refresh cycles
KYC trends in banking for 2026 turn on the move from periodic refresh cycles to event-driven, perpetual KYC. The case comes partly from Moody’s research showing a sizeable confidence gap on financial-crime effectiveness.
FinCEN published its Notice of Proposed Rulemaking on April 7, 2026, with parallel proposed rules from the federal banking agencies. All of them aim to shift AML/CFT programs from a process-based to an effectiveness-based standard. Public comments on the FinCEN NPRM are due by June 9, 2026, with a proposed 12-month implementation period after finalisation.
3. GENIUS Act and stablecoin compliance go live by July 2026
GENIUS Act compliance is the new line item for any bank that issues, custodies, settles, or sponsors activity involving dollar-pegged stablecoins. The act, formally Guiding and Establishing National Innovation for U.S. Stablecoins, was signed into law on July 18, 2025 and directs federal financial regulators to issue implementing regulations within one year of enactment, i.e., by July 18, 2026.
The OCC issued a Notice of Proposed Rulemaking implementing the GENIUS Act on March 2, 2026, and Treasury, FinCEN, and OFAC have issued joint proposed rules covering AML/CFT and sanctions compliance for permitted stablecoin issuers.
McKinsey and other industry analyses suggest a meaningful share of card-based payment volume will migrate to account-to-account systems where stablecoins play a settlement role. Examiner action centres on three documents:
- The issuer due-diligence file
- The reserve attestation review
- The custody walkthrough
4. CFPB Personal Financial Data Rights Rule reshapes data sharing
Finalised under Dodd-Frank Section 1033 in October 2024, the CFPB Personal Financial Data Rights Rule formalised a consumer right to access and port financial data to authorised third parties. The rule is currently under reconsideration following an August 2025 Advance Notice of Proposed Rulemaking, and a federal court has enjoined the CFPB from enforcing it while the bureau revisits key provisions.
Examiner action covers:
- Data-portability readiness
- Third-party data-access governance
- The adequacy of consumer-facing disclosures
Smaller institutions that rely on a core processor will be expected to evidence the chain that produces the consumer’s data package.
5. Threshold relief redraws the community-vs-regional supervisory line
OCC Bulletin 2025-24, released October 6, 2025 and effective January 1, 2026, recalibrated examination procedures for community banks. The bulletin removed OCC-imposed mandatory examination activities not required by statute or regulation, replacing them with risk-based tailoring of each examination to the bank’s size, complexity, and risk profile.
Separately, the OCC approved on December 23, 2025 a Notice of Proposed Rulemaking that would raise the threshold for its heightened standards for large banks from $50 billion to $700 billion in average total consolidated assets. Per OCC analysis, the change would reduce the number of institutions subject to those standards.
Community banks below $10 billion will see a narrower exam scope but heightened focus on a shorter priority list. Regional banks between $50 billion and $700 billion operate under the old threshold this cycle while planning controls for a possible reset.
6. Financial crime compliance shifts from rule-following to outcomes evidence
Financial crime compliance in 2026 is being judged on outcomes. The Anti-Money Laundering Act of 2020’s effectiveness-based amendments, combined with FinCEN’s April 7, 2026 Notice of Proposed Rulemaking and parallel proposed rules from the federal banking agencies, have moved the supervisory bar from requiring filing to whether the sanctions screening produced the right decisions.
Examiner action includes SAR-quality reviews sampling filings for narrative quality and timing, and sanctions effectiveness testing that looks at false-positive and false-negative rates. Learn about how these patterns are surfacing in other regulatory enforcement trends in 2026.
7. Operational resilience and third-party risk fold into a single examiner lens
Operational resilience and third-party risk management are converging into a single supervisory line of inquiry. The interagency TPRM guidance issued in June 2023 by the OCC, Federal Reserve, and FDIC, FFIEC IT Examination Handbook updates, and the NCUA’s 2026 supervisory priorities push examiners toward the same questions:
- Where is concentration risk hiding?
- What evidence exists that vendor incident drills produce a recoverable institution?
Examiner action centres on third-party concentration-risk reporting, including:
- A critical vendor inventory mapped to business functions with named single points of failure
- Incident drill evidence including documented scenarios and post-drill remediation tracking
What Bankers are Asking: The Ask Kaia 90-day Pulse Check
The seven trends above describe the regulatory calendar, but we have an insight to what other bankers are asking. Over a 90-day window in early 2026, the Ask Kaia AI compliance platform recorded thousands of questions from bankers at community and regional institutions.
The anonymised question stream, presented by 360factors Director Ken Proctor in the webinar What Bankers Are Really Asking Kaia: A 90-Day Compliance Pulse Check, surfaces the topics where formal regulatory guidance has not yet closed the gap to operational practice.
The highest-volume question topics in the pulse check, mapped to their regulatory anchor, are summarised below:
| Question topic | Regulatory anchor |
|---|---|
| BSA/AML and beneficial ownership reporting | Corporate Transparency Act; FinCEN BOI rule (revised March 2025) |
| Fair lending and Section 1071 small business data | CFPB 12 CFR 1002 subpart B; revised final rule May 1, 2026 |
| UDAAP and complaints management | CFPB UDAAP authority; prudential UDAP |
| Cybersecurity incident notification | 12 CFR Part 53 (36-hour rule) |
| Third-party and fintech partnership oversight | 2023 interagency TPRM guidance |
| AI and model governance | SR 11-7 model risk management |
| Regulatory change management | OCC, FDIC, FRB, CFPB, NCUA active rulemakings |
| HMDA and mortgage compliance | Regulation C; CFPB HMDA rule updates |
The overlap with the seven trends above is not coincidental, for example:
- The BSA/AML beneficial ownership questions reflect the FinCEN BOI rule revisions and perpetual KYC pressure
- The AI and model governance question cluster confirms that SR 11-7 is a live examiner conversation.
The pulse check also surfaces Section 1071 as a high-volume topic with questions concentrated on operational mechanics. That volume suggests institutions are in active data-infrastructure build-out rather than program design.
Frequently Asked Questions
What are the top banking compliance trends for 2026?
The seven trends most likely to drive examiner conversations in 2026 are:
- AI governance and agentic compliance
- Perpetual KYC
- GENIUS Act and stablecoin compliance
- The CFPB Personal Financial Data Rights Rule
- Threshold relief and supervisory recalibration
- Outcomes-based financial-crime compliance
- The convergence of operational resilience with third-party risk management
Each trend ties to a specific 2025–2026 regulatory anchor and is being tested through documented evidence requests.
What is the GENIUS Act for banks?
The GENIUS Act, formally Guiding and Establishing National Innovation for U.S. Stablecoins, is the federal framework signed into law on July 18, 2025 that sets reserve, redemption, custody, and disclosure standards for permitted dollar-pegged stablecoin issuers. Federal regulators are directed to issue implementing regulations by July 18, 2026, with the OCC and Treasury/FinCEN/OFAC already publishing proposed rules in early 2026.
Which 2026 compliance changes affect community banks most?
Community banks under $10 billion are most affected by OCC Bulletin 2025-24, which recalibrated examination scope effective January 1, 2026, and by the broader federal threshold-relief proposals such as the OCC’s heightened-standards $50B to $700B NPRM.
What is the CFPB Personal Financial Data Rights Rule?
The CFPB Personal Financial Data Rights Rule, finalised under Section 1033 of the Dodd-Frank Act in October 2024, formalises a consumer right to access financial data and direct it to authorised third parties. It creates implementation obligations covering machine-readable data delivery, authorisation and revocation workflows for third-party recipients, and consumer-facing disclosures.
Building a 2026 compliance program is about producing documented evidence that each trend is being managed in operation. Subscribe to our newsletter round-up to read about which violations are most likely to surface in supervisory letters this cycle.
Discover AI-powered technology that helps manage every aspect of risk and compliance, all in one platform.
Request Demo- Risk Prediction
- Regulatory Tracking
- Workflow Automation
- Integrated GRC