The Office of the Comptroller of the Currency’s (OCC’s) Semiannual Risk Perspective outlined the primary risks and emerging challenges affecting the federal banking system, evaluated trends across credit, market, operational, compliance, strategic, and liquidity risk areas, and identified significant vulnerabilities. The spring report, published in May 2026, primarily reflects data as of Dec. 31, 2025. The report highlighted resilient bank performance amid continued geopolitical uncertainty, evolving cyberthreats, increasing fraud activity, and accelerating adoption of AI technologies across the banking sector. Following is a summary of the report with a focus on key considerations for financial services organizations.
According to the OCC, bank earnings improved during 2025, supported by loan growth and declining funding costs, and first-quarter 2026 results indicated these trends have generally continued. Capital and liquidity remain strong by historical standards, supported by a resilient U.S. economy despite expectations for slower growth and higher inflation through the middle of 2026.
Key factors influencing the outlook included:
While the federal banking system remains in a sound financial position, the OCC emphasized cybersecurity, fraud, geopolitical developments, sanctions exposure, and operational resilience as key areas of ongoing risk.
In this report, the OCC emphasized disciplined risk management and operational resiliency as organizations navigate an increasingly dynamic environment. Despite favorable financial performance and balance sheet conditions, organizations should continue exercising prudent oversight in response to evolving cyberthreats, geopolitical uncertainty, and regulatory expectations. A forward-looking approach to risk management and responsible innovation will help support long-term stability.
Credit risk requires continued targeted oversight despite generally stable portfolio performance across the federal banking system. The OCC reported that credit risk remains manageable in aggregate, with past-due or nonaccrual loans and net charge-off ratios remaining below long-term averages for most loan portfolios.
Commercial real estate (CRE) refinance risk is an area that warrants continued monitoring as a substantial volume of loans originated in a lower-interest-rate environment matures and requires refinancing at prevailing rates. While some CRE sectors have shown signs of stabilization, performance continues to vary across property types.
The OCC also discussed emerging risks within private credit markets, and it made the following observations.
Key considerations: Organizations should continue maintaining disciplined portfolio monitoring practices while remaining attentive to emerging stress in CRE and private credit markets. A disciplined, risk-focused approach to credit administration can help identify deterioration early and preserve balance sheet resilience.
The OCC reported that net interest margins improved across the banking system during 2025, driven primarily by declining funding costs. Community banks, in particular, experienced stronger net interest margin improvements because of lower funding costs combined with favorable asset yields.
Additional positive trends noted in the report included:
Key considerations: Although declining funding costs and improving securities valuations have supported balance sheet performance, organizations should continue to maintain disciplined asset-liability management practices and closely monitor interest rate sensitivity, liquidity concentrations, and contingent funding capacity.
The OCC identified cybersecurity threats posed by foreign state-sponsored actors and sophisticated cybercriminal organizations targeting the financial sector as major risks. According to the report, ongoing geopolitical tensions could contribute to elevated malicious cyberattacks on financial services organizations and critical service providers. The spring 2026 report placed increased emphasis on the evolving role of AI in the cyberthreat landscape, as threat actors’ use of AI is amplifying the speed, scale, and sophistication of cyberattacks. Organizations are encouraged to strengthen threat detection and monitoring capabilities.
Key considerations: Financial services organizations should continue investing in operational resilience, cybersecurity governance, and technology risk management by evaluating foundational controls, including multifactor authentication, patch management, third-party oversight, and incident response preparedness.
Fraud is a significant cause of operational losses across the banking sector. Financial services organizations continue to face elevated levels and increasing sophistication of fraud and scam activity, including impersonation schemes facilitated through text messaging and social media platforms. The report noted recent Financial Crimes Enforcement Network (FinCEN) alerts highlighting evolving fraud typologies and the need for continued vigilance across financial services organizations.
Key considerations: The evolving fraud environment reinforces the need to view fraud as a distinct operational risk requiring sustained governance attention and cross-functional coordination. Organizations should evaluate the effectiveness of their fraud detection capabilities, payment controls, customer awareness initiatives, and third-party oversight practices as fraud schemes become increasingly adaptive and technologically sophisticated.
The OCC noted that geopolitical tensions are elevating sanctions and money laundering risks, which increases pressure on compliance programs as well as potential exposure to sanctions and Bank Secrecy Act (BSA) and anti-money laundering (AML) violations. The report also covered FinCEN guidance regarding evolving money laundering typologies and emphasizes ongoing vigilance. The OCC further highlighted efforts to tailor supervision based on organizational risk profiles and operational complexity.
Recent initiatives include:
Key considerations: Compliance risk management requires adaptable governance supported by current policies, disciplined risk assessments, and clear escalation protocols. Organizations should maintain well-integrated compliance frameworks supported by:
The OCC acknowledged that banks of all sizes are exploring expanded use of AI technologies, including generative AI and agentic AI, to improve productivity, enhance customer experience, and support operational functions. The report noted that AI adoption might continue expanding into more significant business and financial decision-making processes over time. As AI use grows, organizations will encounter opportunities and challenges.
Potential benefits of AI use include:
Key governance considerations include:
Key considerations: AI governance increasingly requires a measured, multidisciplinary approach that balances innovation with operational resilience, regulatory compliance, and effective risk oversight. As AI capabilities become more embedded in financial services organizations and the wider industry, organizations should establish and maintain clear accountability, disciplined governance, and ongoing monitoring. Organizations also should understand where and how AI is used, including internally developed solutions and AI capabilities embedded within third-party products and services. Existing governance processes, AI risk assessments, and a defined AI risk appetite can help align AI adoption with business objectives and risk management.
The OCC continues to monitor digital and tokenized assets within the federal banking system. The report highlighted implementation of the Guiding and Establishing National Innovation for U.S. Stablecoins Act (GENIUS Act), which creates a federal regulatory framework for payment stablecoins and limits who may issue them in the U.S. The OCC also referenced interagency frequently asked question resources that clarify how tokenized securities generally receive the same regulatory capital treatment as traditional securities. As organizations pursue digital asset initiatives, the OCC reiterates the importance of sound governance, effective risk management, and compliance with applicable laws and regulations.
Key considerations: As stablecoins become more widely adopted and regulated, financial services organizations should assess their exposure and incorporate stablecoin-related risks into their governance and risk management frameworks.
The spring 2026 report continues a shift first seen in fall 2025, which is placing greater emphasis on operational resilience, AI governance, fraud risk, and cybersecurity than on liquidity stress and interest rate volatility. It also reflects the OCC’s growing recognition that emerging technologies and geopolitical developments are increasingly intertwined with enterprise risk management and long-term organizational stability.
Although not addressed directly in the spring 2026 report, the OCC’s recent final rule eliminating reputation risk from its supervisory framework reinforces this shift. By prohibiting supervisory criticism based solely on reputation risk, the rule signals a continued emphasis on measurable financial and operational risks and aligns regulatory oversight more closely with core safety and soundness principles.
The OCC is expanding its supervisory focus on emerging technologies and the operational, strategic, and governance considerations accompanying their adoption across the banking sector. Compared with prior reports, the spring 2026 report places greater emphasis on AI, digital assets, and technology-enabled operational risk.
Following are key areas of supervisory focus.
The OCC’s recent supervisory messaging reflects an increasingly integrated focus on operational resiliency, technology governance, and responsible innovation as core components of safety and soundness. While prior supervisory attention centered on liquidity pressures and balance sheet stabilization, current guidance emphasizes enterprisewide operational risk management and governance over emerging technologies. AI, cybersecurity, fraud risk, third-party oversight, and digital asset activities are increasingly viewed as interconnected supervisory issues.
Recent OCC issuances reinforce this direction: OCC Bulletin 2026-13 strengthens expectations for AI governance and model oversight; OCC Bulletin 2026-3 reinforces support for responsible financial innovation under the GENIUS Act; and OCC Bulletin 2026-10 emphasizes recovery planning, cyber preparedness, and operational governance. Collectively, these developments suggest that the OCC is moving toward a more integrated supervisory framework that evaluates innovation, resiliency, and operational governance together.
For risk managers and compliance leaders, these developments reinforce the importance of integrating emerging technologies into existing governance, risk management, and control frameworks rather than managing them as stand-alone initiatives.
Organizations should consider reassessing model governance, third-party oversight, operational resiliency, and cross-functional coordination and confirm that boards and senior management maintain effective oversight of AI-enabled processes, digital asset activities, and other technology-driven risks. Overall, the OCC continues to position innovation and operational resiliency as complementary supervisory objectives that support long-term organizational stability.