Banks approach regulatory examination preparation by keeping the records an examiner will request current as ordinary compliance work, so the weeks before fieldwork go on locating and reviewing evidence instead of creating it.
This article covers what an examination reaches and when preparation starts, what the request letter asks for and why, how the file stays current between examinations, and what examiners now ask about AI tooling.

What an Examination Covers and When Preparation Starts
Consumer compliance and safety-and-soundness examinations reach US banks and credit unions supervised by the OCC, FDIC, Federal Reserve or NCUA. Frequency follows asset size and prior rating.
Under the FDIC’s rule, a full-scope on-site examination happens at least once every 12 months, and institutions below $3 billion in total assets that are well capitalized, rated composite 1 or 2, rated 1 or 2 for management, free of formal enforcement proceedings and unchanged in control may qualify for an 18-month cycle.
The request letter arrives ahead of fieldwork, but the period under review runs back to the last examination, so the evidence an examiner wants was either created as the work happened or it does not exist.
Preparation is a separate discipline from two adjacent ones:
- The rating scales an examination produces
- Predicting which topics an examiner will prioritise.
What the Request Letter Asks for and Why
Exam readiness improves when a team reads the request letter by what each item is testing instead of as a document list. The categories and testing purposes below come from the FDIC compliance examination manual and equivalent supervisory guidance.
| Request category | What the examiner is testing | Where the evidence lives | Most common gap |
|---|---|---|---|
| Board and management oversight | Whether compliance has authority and reporting lines reaching the board | Board and committee minutes, compliance charter, reporting packs | Minutes that record approval but not the discussion behind it |
| Compliance management system | Whether the programme fits the institution’s actual risk profile | Policies, procedures, risk assessments, training records | A risk assessment dated more than a year back |
| Monitoring and testing | Whether the institution checks its own compliance and acts on findings | Compliance workpapers, scope, results, remediation tracking | Findings closed with no evidence the fix was verified |
| Consumer complaints | Whether complaints are captured, categorised and used as a risk signal | Complaint register, root cause analysis, trend reporting | Complaints resolved one by one and never analysed as a set |
| Prior findings | Whether previous matters requiring attention were corrected and stayed corrected | Remediation records, validation testing | Correction evidenced once, with no later check that it held |
Keeping the File Current Between Examinations
Regulatory examination management between cycles comes down to four habits:
- Every request category has a named owner
- Review runs on a cadence tied to the examination cycle
- Remediation is tracked to verified closure
- Evidence sits in one place
If a request category cannot be produced inside a week without three people searching their mailboxes, it is not current, whatever the compliance management system documentation says about it.
What Examiners Ask About AI Tooling
The OCC’s revised model risk management guidance, issued in April 2026, states that generative AI and agentic AI models are not within the scope of that guidance. Pointing an examiner at a model validation file therefore proves nothing about an AI compliance agent.
The governance record has to be built from the institution’s own controls. Four elements carry it:
- Which users can run which tools and who approved that access
- A log of what was run and against what data
- The human review step with the name of the reviewer
- Retention of outputs so a conclusion can be traced back to its inputs
A bank examiner is asking whether a compliance conclusion reached with AI assistance can be reconstructed and attributed months later.
Examination Management in Predict360
Predict360 carries Regulatory Examination and Findings Management, Internal Audit and Findings Management, and Compliance Monitoring and Testing as applications.
Ask Kaia records agent activity in an Agent Audit Log and controls access by user role through Agent Permission Management, and its agents run inside a guided launch window that captures the inputs used.
Frequently Asked Questions
How often are banks examined?
A full-scope on-site examination happens at least once every 12 months under the FDIC’s frequency rule. Institutions below $3 billion in total assets that are well capitalized, rated composite 1 or 2, rated 1 or 2 for management, subject to no formal enforcement proceedings and unchanged in control may qualify for an 18-month cycle.
What do examiners review first?
The compliance management system, because it frames everything else. Board oversight, the compliance programme, consumer complaint response and the compliance audit function together tell an examiner whether findings elsewhere are isolated incidents or symptoms of a programme that does not fit the institution’s risk.
Does model risk management guidance cover generative AI?
No. The OCC’s revised model risk management guidance, issued in April 2026, states that generative AI and agentic AI models are not within its scope, and the agencies have signalled a separate request for information on AI model risk. Governance evidence for AI compliance tooling has to come from access controls, audit logs and human review records.
The Predict360 Enterprise Risk Management Software ensures managers have complete visibility of enterprise risk on a single dashboard.
Request Demo- Cloud-Based
- Risk Repository
- Assess Risks
- Real-time Monitoring