: Business professionals discussing risk management and regulatory compliance during a collaborative meeting.

OCC Semiannual Risk Perspective: Spring 2026 Takeaways 

Jacob M. Rivkin, Jonathan Browe, Elena Serra
9/1/2026

The OCC’s spring 2026 report highlighted how innovation, resilience, and risk management are converging for financial services organizations. 

The Office of the Comptroller of the Currency’s (OCC’s) Semiannual Risk Perspective outlined the primary risks and emerging challenges affecting the federal banking system, evaluated trends across credit, market, operational, compliance, strategic, and liquidity risk areas, and identified significant vulnerabilities. The spring report, published in May 2026, primarily reflects data as of Dec. 31, 2025. The report highlighted resilient bank performance amid continued geopolitical uncertainty, evolving cyberthreats, increasing fraud activity, and accelerating adoption of AI technologies across the banking sector. Following is a summary of the report with a focus on key considerations for financial services organizations.

Economy and banking industry overall health

According to the OCC, bank earnings improved during 2025, supported by loan growth and declining funding costs, and first-quarter 2026 results indicated these trends have generally continued. Capital and liquidity remain strong by historical standards, supported by a resilient U.S. economy despite expectations for slower growth and higher inflation through the middle of 2026.

Key factors influencing the outlook included:

  • Geopolitical tensions, particularly the conflict in the Middle East
  • Potential disruption involving the Strait of Hormuz
  • Elevated energy costs
  • Trade uncertainty and inflationary pressures

While the federal banking system remains in a sound financial position, the OCC emphasized cybersecurity, fraud, geopolitical developments, sanctions exposure, and operational resilience as key areas of ongoing risk.

In this report, the OCC emphasized disciplined risk management and operational resiliency as organizations navigate an increasingly dynamic environment. Despite favorable financial performance and balance sheet conditions, organizations should continue exercising prudent oversight in response to evolving cyberthreats, geopolitical uncertainty, and regulatory expectations. A forward-looking approach to risk management and responsible innovation will help support long-term stability.

Key risk themes and takeaways for risk managers

Credit risk

Credit risk requires continued targeted oversight despite generally stable portfolio performance across the federal banking system. The OCC reported that credit risk remains manageable in aggregate, with past-due or nonaccrual loans and net charge-off ratios remaining below long-term averages for most loan portfolios.

Commercial real estate (CRE) refinance risk is an area that warrants continued monitoring as a substantial volume of loans originated in a lower-interest-rate environment matures and requires refinancing at prevailing rates. While some CRE sectors have shown signs of stabilization, performance continues to vary across property types.

The OCC also discussed emerging risks within private credit markets, and it made the following observations.

  • Debt restructurings might mask underlying credit deterioration in certain portfolios.
  • Increased use of paid-in-kind mechanisms could obscure borrower stress.
  • Growing exposure to private credit funds warrants ongoing borrower monitoring and refinancing risk assessment.

Key considerations: Organizations should continue maintaining disciplined portfolio monitoring practices while remaining attentive to emerging stress in CRE and private credit markets. A disciplined, risk-focused approach to credit administration can help identify deterioration early and preserve balance sheet resilience.

Market and liquidity risk

The OCC reported that net interest margins improved across the banking system during 2025, driven primarily by declining funding costs. Community banks, in particular, experienced stronger net interest margin improvements because of lower funding costs combined with favorable asset yields.

Additional positive trends noted in the report included:

  • Declining unrealized losses on securities portfolios, reaching their lowest levels since 2021
  • Continued deposit growth during 2025
  • Modest increases in uninsured deposits among larger organizations that remain generally in line with long-term averages

Key considerations: Although declining funding costs and improving securities valuations have supported balance sheet performance, organizations should continue to maintain disciplined asset-liability management practices and closely monitor interest rate sensitivity, liquidity concentrations, and contingent funding capacity.

Operational and cybersecurity risk

The OCC identified cybersecurity threats posed by foreign state-sponsored actors and sophisticated cybercriminal organizations targeting the financial sector as major risks. According to the report, ongoing geopolitical tensions could contribute to elevated malicious cyberattacks on financial services organizations and critical service providers. The spring 2026 report placed increased emphasis on the evolving role of AI in the cyberthreat landscape, as threat actors’ use of AI is amplifying the speed, scale, and sophistication of cyberattacks. Organizations are encouraged to strengthen threat detection and monitoring capabilities.

Key considerations: Financial services organizations should continue investing in operational resilience, cybersecurity governance, and technology risk management by evaluating foundational controls, including multifactor authentication, patch management, third-party oversight, and incident response preparedness.

Fraud risk

Fraud is a significant cause of operational losses across the banking sector. Financial services organizations continue to face elevated levels and increasing sophistication of fraud and scam activity, including impersonation schemes facilitated through text messaging and social media platforms. The report noted recent Financial Crimes Enforcement Network (FinCEN) alerts highlighting evolving fraud typologies and the need for continued vigilance across financial services organizations.

Key considerations: The evolving fraud environment reinforces the need to view fraud as a distinct operational risk requiring sustained governance attention and cross-functional coordination. Organizations should evaluate the effectiveness of their fraud detection capabilities, payment controls, customer awareness initiatives, and third-party oversight practices as fraud schemes become increasingly adaptive and technologically sophisticated.

Compliance risk

The OCC noted that geopolitical tensions are elevating sanctions and money laundering risks, which increases pressure on compliance programs as well as potential exposure to sanctions and Bank Secrecy Act (BSA) and anti-money laundering (AML) violations. The report also covered FinCEN guidance regarding evolving money laundering typologies and emphasizes ongoing vigilance. The OCC further highlighted efforts to tailor supervision based on organizational risk profiles and operational complexity.

Recent initiatives include:

  • Proposed amendments to AML and countering the financing of terrorism program requirements
  • Tailored BSA and AML examination procedures for community banks
  • Discontinuation of annual money laundering risk system data collection requirements
  • FinCEN relief intended to streamline customer due diligence obligations

Key considerations: Compliance risk management requires adaptable governance supported by current policies, disciplined risk assessments, and clear escalation protocols. Organizations should maintain well-integrated compliance frameworks supported by: 

  • Clear escalation protocols
  • Current policies and procedures
  • Disciplined risk assessment processes

Innovation and AI risk

The OCC acknowledged that banks of all sizes are exploring expanded use of AI technologies, including generative AI and agentic AI, to improve productivity, enhance customer experience, and support operational functions. The report noted that AI adoption might continue expanding into more significant business and financial decision-making processes over time. As AI use grows, organizations will encounter opportunities and challenges.

Potential benefits of AI use include:

  • Increased automation of core business activities
  • Enhanced operational efficiency
  • Improved customer experience

Key governance considerations include:

  • Explainability and model transparency
  • Data integrity and privacy
  • Cybersecurity risks
  • Effective model validation and oversight

Key considerations:  AI governance increasingly requires a measured, multidisciplinary approach that balances innovation with operational resilience, regulatory compliance, and effective risk oversight. As AI capabilities become more embedded in financial services organizations and the wider industry, organizations should establish and maintain clear accountability, disciplined governance, and ongoing monitoring. Organizations also should understand where and how AI is used, including internally developed solutions and AI capabilities embedded within third-party products and services. Existing governance processes, AI risk assessments, and a defined AI risk appetite can help align AI adoption with business objectives and risk management.

Digital asset risk

The OCC continues to monitor digital and tokenized assets within the federal banking system. The report highlighted implementation of the Guiding and Establishing National Innovation for U.S. Stablecoins Act (GENIUS Act), which creates a federal regulatory framework for payment stablecoins and limits who may issue them in the U.S. The OCC also referenced interagency frequently asked question resources that clarify how tokenized securities generally receive the same regulatory capital treatment as traditional securities. As organizations pursue digital asset initiatives, the OCC reiterates the importance of sound governance, effective risk management, and compliance with applicable laws and regulations.

Key considerations: As stablecoins become more widely adopted and regulated, financial services organizations should assess their exposure and incorporate stablecoin-related risks into their governance and risk management frameworks.

Themes across OCC supervision

The spring 2026 report continues a shift first seen in fall 2025, which is placing greater emphasis on operational resilience, AI governance, fraud risk, and cybersecurity than on liquidity stress and interest rate volatility. It also reflects the OCC’s growing recognition that emerging technologies and geopolitical developments are increasingly intertwined with enterprise risk management and long-term organizational stability.

Although not addressed directly in the spring 2026 report, the OCC’s recent final rule eliminating reputation risk from its supervisory framework reinforces this shift. By prohibiting supervisory criticism based solely on reputation risk, the rule signals a continued emphasis on measurable financial and operational risks and aligns regulatory oversight more closely with core safety and soundness principles.

Focus on emerging technologies

The OCC is expanding its supervisory focus on emerging technologies and the operational, strategic, and governance considerations accompanying their adoption across the banking sector. Compared with prior reports, the spring 2026 report places greater emphasis on AI, digital assets, and technology-enabled operational risk.

Following are key areas of supervisory focus.

  • AI is a transformative operational capability. In the spring report, the OCC highlighted the growing adoption of generative and agentic AI to improve operational efficiency, customer experience, and business processes and acknowledged increasing use in material financial and operational decision-making.
  • Governance and risk management expectations continue evolving alongside AI adoption. While many AI risks align with traditional model risk management principles, the OCC noted additional governance challenges related to explainability, data integrity, cybersecurity, privacy, and model validation.
  • Digital asset activity remains subject to heightened regulatory attention. The report highlighted implementation of the GENIUS Act and recent interagency guidance on tokenized securities, reinforcing the need for sound governance, effective risk management, and compliance with safe and sound banking practices.
  • Responsible innovation should be a supervisory priority. The OCC continues to support technological innovation, and in this report it emphasized operational resilience, regulatory compliance, and prudent risk management while reinforcing that innovation and strong risk governance must evolve together.

Resilience through governance

The OCC’s recent supervisory messaging reflects an increasingly integrated focus on operational resiliency, technology governance, and responsible innovation as core components of safety and soundness. While prior supervisory attention centered on liquidity pressures and balance sheet stabilization, current guidance emphasizes enterprisewide operational risk management and governance over emerging technologies. AI, cybersecurity, fraud risk, third-party oversight, and digital asset activities are increasingly viewed as interconnected supervisory issues.

Recent OCC issuances reinforce this direction: OCC Bulletin 2026-13 strengthens expectations for AI governance and model oversight; OCC Bulletin 2026-3 reinforces support for responsible financial innovation under the GENIUS Act; and OCC Bulletin 2026-10 emphasizes recovery planning, cyber preparedness, and operational governance. Collectively, these developments suggest that the OCC is moving toward a more integrated supervisory framework that evaluates innovation, resiliency, and operational governance together.

What’s next?

For risk managers and compliance leaders, these developments reinforce the importance of integrating emerging technologies into existing governance, risk management, and control frameworks rather than managing them as stand-alone initiatives.

Organizations should consider reassessing model governance, third-party oversight, operational resiliency, and cross-functional coordination and confirm that boards and senior management maintain effective oversight of AI-enabled processes, digital asset activities, and other technology-driven risks. Overall, the OCC continues to position innovation and operational resiliency as complementary supervisory objectives that support long-term organizational stability.

Risk and compliance consulting
Crowe can help you create and execute a successful risk management strategy for your business.

Contact us


Crowe helps financial services organizations align risk management, compliance, and innovation strategies with evolving OCC expectations through tailored consulting, governance, and technology solutions.
Image - Jacob Rivkin at Crowe.
Jacob M. Rivkin
Principal, Consulting
Jonathan Browe
Jonathan Browe
Risk Consulting
Serra-Elena
Elena Serra
Regulatory Compliance and Financial Crime Consultant

Related insights