Skip to main content
Promotional banner for the pentest readiness checklist
Regulatory Relief Won't Protect You From RiskEnterprise Risk Management
5 min readFor Internal Auditors

Regulatory Relief Won't Protect You From Risk

The FDIC's proposal to raise Part 363 thresholds for the first time in 33 years has sparked relief among mid-sized banks. Fewer mandated audits and reduced audit committee requirements sound appealing after years of compliance pressure.

But relief can lead to complacency.

When regulators ease requirements, organizations often see it as permission to cut corners. The logic seems sound: if it's not required, why invest in it? This thinking confuses regulatory minimums with operational reality. Your risk environment hasn't changed just because a threshold did.

Let's clear up the myths that could cost your institution dearly.

Myth 1: Lower thresholds mean lower risk

Reality: The FDIC is raising the Part 363 applicability threshold from $500 million to $1 billion and the ICOFR threshold from $1 billion to $5 billion. These changes reflect inflation and consolidation trends, not a shift in the risk landscape.

Your cyber exposure didn't shrink. Third-party vendors didn't become more reliable. Liquidity gaps didn't close themselves. Climate-related financial risks didn't vanish. The proposal states it's indexing thresholds for inflation going forward, which tells you that the numbers were outdated, not that governance principles changed.

If you're a $750 million institution celebrating exemption from Part 363, remember that your board, customers, and counterparties still expect you to demonstrate control over financial reporting. The filing requirement disappeared; the operational need didn't.

Myth 2: You can scale up risk management when you need it

Reality: Building enterprise risk management under pressure is expensive and often ineffective.

Consider a regional bank approaching the new $5 billion ICOFR threshold. If you wait until you're at $4.8 billion to implement proper control documentation, you'll face a scramble: hiring external consultants at premium rates, retrofitting processes, and explaining to your board why you weren't prepared for predictable growth.

Scalable governance means deploying frameworks and platforms that can expand with your institution. Start with a risk universe that captures your top 15 operational risks. Build a control objective mapping structure that links activities to outcomes. Create a policy exception registry that tracks deviations from your standards. These foundational elements don't require massive investment, but they do require intentionality.

The banks that mature fastest are the ones that implement ERM principles before they're forced to. You're configuring workflows when you have time to think, not when auditors are waiting for deliverables.

Myth 3: Internal controls only matter for regulatory filings

Reality: Internal controls are your institution's immune system. They detect problems before they become material incidents.

ICOFR requirements under FDICIA exist because control failures in financial reporting can destroy institutions. But the discipline of documenting, testing, and remediating controls applies far beyond financial statements. Your loan origination process needs controls. Your vendor management program needs controls. Your incident response procedures need controls.

When the FDIC proposes raising the ICOFR threshold to $5 billion, it's not suggesting that $4 billion institutions don't need control rigor. It's acknowledging that formal management assertions and external attestations carry administrative costs that smaller institutions can redirect elsewhere. The question is: where are you redirecting that capacity? If the answer is "nowhere," you're missing the point.

Strong control environments reduce operational losses, catch errors before they become frauds, and give management reliable information for decisions. These benefits don't appear on a regulatory checklist, but they show up in your risk profile every quarter.

Myth 4: Audit committee independence rules are just bureaucracy

Reality: The proposed change raising audit committee independence requirements from the $1-3 billion range to $5 billion addresses a real burden: smaller institutions struggle to recruit fully independent directors with specialized financial expertise.

But independence requirements exist for a reason. Boards need members who can challenge management without conflicts of interest. If your institution falls below the new threshold and decides to relax independence standards, you're not eliminating the need for objective oversight. You're just removing the regulatory forcing function that ensured it happened.

Your audit committee should still include directors who understand financial reporting, risk management, and internal controls. They should still meet regularly with internal audit without management present. They should still have the authority and expertise to question control deficiencies. The FDIC isn't saying these practices are optional; it's saying you can structure them in ways that fit your size.

If you interpret regulatory relief as permission to weaken governance, you're setting yourself up for the kind of risk event that makes regulators reconsider relief programs.

Myth 5: ERM platforms are only for large, complex institutions

Reality: Enterprise risk management systems are scalable. You don't need to implement every module on day one.

Start with a single source of truth: integrate your risk universe, control objectives, regulatory obligations, and incident log in one platform. This gives you visibility across domains that are typically siloed. Your compliance team sees the same risk data as your operational risk function. Your board receives consistent reporting that links strategic decisions to risk appetite.

As you grow, you add capabilities: automated control testing workflows, vendor risk profiles with ongoing monitoring triggers, scenario analysis that feeds capital planning. The platform grows with you, which means you're never rebuilding from scratch.

Banks that deploy ERM early report faster maturity curves and fewer growing pains. They've already mapped their controls when ICOFR requirements kick in. They've already built remediation workflows when audit findings arrive. They've already established board-level risk reporting when regulators ask for it.

What to do instead

Treat regulatory relief as an opportunity to modernize, not retreat.

If you're under the new thresholds: Right-size your risk governance. You don't need the full ICOFR apparatus, but you do need documented controls over material processes. Build a risk universe that reflects your actual exposures. Implement a policy gap analysis cadence that catches drift before it becomes noncompliance.

If you're approaching $5 billion: Plan your control environment now. Map your key processes to COSO Internal Control-Integrated Framework components. Identify where you have manual workarounds that won't scale. Deploy an integrated risk management platform that can handle both current state and future requirements.

For all institutions: Stop treating risk management as a compliance exercise. It's a strategic capability that protects your institution from uncertainty, supports decision-making, and demonstrates to stakeholders that you're in control.

The FDIC's proposal will likely become final later this year. When it does, you'll have a choice: use the breathing room to strengthen your foundation, or assume that less regulation means less risk. Only one of those choices positions you for sustainable growth.

You can't manage what you can't see. Build the visibility now, while you have the time and space to do it right.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like