Supervisory Guidance for Assessing Risk Management at Supervised Institutions with Total Consolidated Assets Less than $100 Billion

FederalAgency guidance

Ask Donna

How this section applies to your facts.

Federal Reserve SR/CA Letters › Supervisory Guidance for Assessing Risk Management at Supervised Institutions with Total Consolidated Assets Less than $100 Billion

This text was captured on Aug 14, 2026. It is a snapshot, not a live feed, so check the official code before relying on it.

Text

Page 1 of 3

BOARD OF GOVERNORS

OF THE

FEDERAL RESERVE SYSTEM

WASHINGTON, D.C. 20551

DIVISION OF BANKING

SUPERVISION AND REGULATION

SR 16-11

June 8, 2016

Revised February 17,

2021

Revision History: In February 2021, the attached guidance was revised to apply to the

supervision of Federal Reserve regulated institutions with total consolidated assets of less than

$100 billion, including state member banks, bank holding companies, and savings and loan

holding companies (including insurance and commercial savings and loan holding companies);

as well as foreign banking organizations with consolidated U.S. assets of less than $100 billion.

The guidance does not apply to intermediate holding companies of foreign banking organizations

established pursuant to the Federal Reserve’s Regulation YY with total consolidated assets of

$50 billion or more. These applicability modifications align with the Board’s tailoring rules. See

84 Fed. Reg. 59032 (November 1, 2019) for more information.

TO THE OFFICER IN CHARGE OF SUPERVISION

AT EACH FEDERAL RESERVE BANK

SUBJECT: Supervisory Guidance for Assessing Risk Management at Supervised

Institutions with Total Consolidated Assets Less than $100 Billion

Applicability: This supervisory guidance will be used by Federal Reserve examiners and

supervisory staff in assessing risk management at financial institutions supervised by the Federal

Reserve with total consolidated assets of less than $100 billion, except intermediate holding

companies of foreign banking organizations established pursuant to the Federal Reserve’s

Regulation Y with total consolidated assets of $50 billion or more

e will be used by Federal Reserve examiners and

supervisory staff in assessing risk management at financial institutions supervised by the Federal

Reserve with total consolidated assets of less than $100 billion, except intermediate holding

companies of foreign banking organizations established pursuant to the Federal Reserve’s

Regulation Y with total consolidated assets of $50 billion or more.

This letter sets forth an update to the Federal Reserve’s supervisory guidance for

assessing risk management at supervised institutions with less than $100 billion in total

consolidated assets.1 The attached guidance re-affirms the Federal Reserve’s long-standing

1 The risk management expectations outlined in the attached guidance are applicable to all supervised institutions

with total consolidated assets less than $100 billion, including state member banks, bank holding companies, and

savings and loan holding companies; and foreign banking organizations with consolidated U.S. assets of less than

$100 billion. This letter also applies to insurance and commercial savings and loan holding companies with total

consolidated assets less than $100 billion by providing core risk management guidance. This letter is not applicable

to intermediate holding companies of foreign banking organizations established pursuant to the Federal Reserve’s

Page 2 of 3

supervisory approach that emphasizes the importance of prudent risk management. The core risk

management principles outlined in the attached guidance reflect updates to, and partially

supersede, SR letter 95-51, “Rating the Adequacy of Risk Management and Internal Controls at

State Member Banks and Bank Holding Companies.”2 In addition to outlining core risk

categories and risk management principles, this updated guidance provides clarification on and

distinguishes supervisory expectations for the roles and responsibilities of the board of directors

and senior management for an institution’s risk management

the Adequacy of Risk Management and Internal Controls at

State Member Banks and Bank Holding Companies.”2 In addition to outlining core risk

categories and risk management principles, this updated guidance provides clarification on and

distinguishes supervisory expectations for the roles and responsibilities of the board of directors

and senior management for an institution’s risk management. The revisions also extend

applicability to savings and loan holding companies with less than $100 billion in total

consolidated assets and U.S. operations of foreign banking organizations with total consolidated

U.S. assets less than $100 billion, which were not previously subject to SR 95-51.

Consistent with current practice, the Federal Reserve will continue to issue guidance that

specifically addresses supervisory expectations for the individual components of risk

management (such as internal audit or asset-liability management) or risk categories (such as

credit risk or liquidity risk). Federal Reserve examiners should exercise appropriate judgment in

applying the guidance to a particular institution, considering its unique characteristics and the

nature, scope, and complexity of its activities.

With regard to the assignment of supervisory ratings, the updated guidance does not

change the risk management rating requirements and ratings definitions from SR letter 95-51.

That ratings guidance has been retained in the Federal Reserve’s Commercial Bank Examination

Manual. For additional ratings guidance, refer to the Federal Reserve’s Bank Holding Company

Supervision Manual and the Examination Manual for U.S. Branches and Agencies of Foreign

Banking Organizations.3

Reserve Banks are asked to distribute this letter to the Federal Reserve-supervised

financial institutions in their districts, as well as to their supervisory and examination staff

ion

Manual. For additional ratings guidance, refer to the Federal Reserve’s Bank Holding Company

Supervision Manual and the Examination Manual for U.S. Branches and Agencies of Foreign

Banking Organizations.3

Reserve Banks are asked to distribute this letter to the Federal Reserve-supervised

financial institutions in their districts, as well as to their supervisory and examination staff.

Questions regarding the revised guidance should be addressed to Keith Coughlin, Manager,

Regional Banking Organizations, at (202) 452-2056; Anthony Cain, Manager, Community

Banking Organizations, at (202) 912-4377; Karen Caplan, Manager, Savings and Loan Holding

Companies, at (202) 452-2710; or Vaishali Sack, Manager, Supervisory Program Development

and Analysis, at (202) 452-5221. In addition, institutions may send questions via the Board’s

public website.4

Michael S. Gibson

Director

Regulation YY with total consolidated assets of $50 billion or more. Reserve Bank staff may further consult with

Board staff on appropriately tailoring this guidance for these institutions.

2 SR 95-51 remains applicable to state member banks and bank holding companies with $100 billion or more in total

assets until superseding guidance is issued for these institutions.

3 For savings and loan holding companies, see also SR letter 14-9, “Incorporation of Federal Reserve Policies into

the Savings and Loan Holding Company Supervision Program.”

4 See http://www.federalreserve.gov/apps/contactus/feedback.aspx.

to state member banks and bank holding companies with $100 billion or more in total

assets until superseding guidance is issued for these institutions.

3 For savings and loan holding companies, see also SR letter 14-9, “Incorporation of Federal Reserve Policies into

the Savings and Loan Holding Company Supervision Program.”

4 See http://www.federalreserve.gov/apps/contactus/feedback.aspx.

Page 3 of 3

Attachment

• Supervisory Guidance for Assessing Risk Management at Supervised Institutions with

Total Consolidated Assets Less than $100 Billion

Partially Supersedes

• SR letter 95-51, “Rating the Adequacy of Risk Management Processes and Internal

Controls at State Member Banks and Bank Holding Companies”

Cross-references to:

• SR letter 16-4, “Relying on the Work of the Regulators of the Subsidiary Insured

Depository Institution(s) of Bank Holding Companies and Savings and Loan Holding

Companies with Total Consolidated Assets of Less than $100 Billion”

• SR letter 14-9, “Incorporation of Federal Reserve Policies into the Savings and Loan

Holding Company Supervision Program”

• SR letter 13-8, “Extension of the Use of Indicative Ratings for Savings and Loan Holding

Companies”

• SR letter 13-1, “Supplemental Policy Statement on the Internal Audit Function and Its

Outsourcing”

• SR letter 12-17/CA 12-14, “Consolidated Supervision Framework for Large Financial

Institutions”

• SR letter 11-11, “Supervision of Savings and Loan Holding Companies (SLHCs)”

• SR letter 11-7, “Guidance on Model Risk Management”

• SR letter 03-5, “Amended Interagency Guidance on the Internal Audit Function and its

Outsourcing”

• Commercial Bank Examination Manual – Section A.5020.1, “Overall Conclusions

Regarding Condition of the Bank: Uniform Financial Institutions Rating System and the

Federal Reserve’s Risk Management Rating”

• Bank Holding Company Supervision Manual – Section 4070.0, “Bank Holding Company

Rating System”

• Examination Manual for U.S

Guidance on the Internal Audit Function and its

Outsourcing”

• Commercial Bank Examination Manual – Section A.5020.1, “Overall Conclusions

Regarding Condition of the Bank: Uniform Financial Institutions Rating System and the

Federal Reserve’s Risk Management Rating”

• Bank Holding Company Supervision Manual – Section 4070.0, “Bank Holding Company

Rating System”

• Examination Manual for U.S. Branches and Agencies of Foreign Banking Organizations

– Section 2003.1, “Rating System for U.S. Branches and Agencies of Foreign Banking

Organizations”

6/8/2016

Revised February 17, 2021

Page 1 of 9

Revision History: In February 2021, this guidance was revised to apply to the supervision of

Federal Reserve regulated institutions with total consolidated assets of less than $100 billion

including state member banks, bank holding companies, and savings and loan holding companies

(including insurance and commercial savings and loan holding companies); as well as foreign

banking organizations with consolidated U.S. assets of less than $100 billion. The guidance does

not apply to intermediate holding companies of foreign banking organizations established

pursuant to the Federal Reserve’s Regulation YY with total consolidated assets of $50 billion or

more. These applicability modifications align with the Board’s tailoring rules. See 84 Fed. Reg.

59032 (November 1, 2019) for more information.

Attachment

Supervisory Guidance for Assessing Risk Management at

Supervised Institutions with Total Consolidated Assets Less than $100 Billion1

OVERVIEW

Managing risks is fundamental to the business of banking. Accordingly, the Federal

Reserve places significant supervisory emphasis on an institution’s management of risk,

including its system of internal controls, when evaluating the overall effectiveness of an

institution’s risk management

ent at

Supervised Institutions with Total Consolidated Assets Less than $100 Billion1

OVERVIEW

Managing risks is fundamental to the business of banking. Accordingly, the Federal

Reserve places significant supervisory emphasis on an institution’s management of risk,

including its system of internal controls, when evaluating the overall effectiveness of an

institution’s risk management. An institution’s failure to establish a management structure that

adequately identifies, measures, monitors, and controls the risks of its activities has long been

considered unsafe-and-unsound conduct. Principles of sound management should apply to the

entire spectrum of risks facing an institution including, but not limited to, credit, market,

liquidity, operational, compliance, and legal risk:

• Credit risk arises from the potential that a borrower or counterparty will fail to

perform on an obligation.

• Market risk is the risk to a financial institution’s condition resulting from adverse

movements in market rates or prices, including, but not limited to, interest rates,

foreign exchange rates, commodity prices, or equity prices.

• Liquidity risk is the potential that a financial institution will be unable to meet its

obligations as they come due because of an inability to liquidate assets or obtain

adequate funding (referred to as “funding liquidity risk”) or that it cannot easily

unwind or offset specific exposures without significantly lowering market prices

1 Supervised institutions with total consolidated assets less than $100 billion including state member banks, bank

holding companies, and savings and loan holding companies (including insurance and commercial savings and loan

holding companies); and foreign banking organizations (FBOs) with consolidated U.S. assets of less than $100

billion

osures without significantly lowering market prices

1 Supervised institutions with total consolidated assets less than $100 billion including state member banks, bank

holding companies, and savings and loan holding companies (including insurance and commercial savings and loan

holding companies); and foreign banking organizations (FBOs) with consolidated U.S. assets of less than $100

billion. The guidance does not apply to intermediate holding companies of foreign banking organizations established

pursuant to the Federal Reserve’s Regulation YY with total consolidated assets of $50 billion or more.

6/8/2016

Revised February 17, 2021

Page 2 of 9

because of inadequate market depth or market disruptions (referred to as “market

liquidity risk”).

• Operational risk is the risk resulting from inadequate or failed internal processes,

people, and systems or from external events.2

• Compliance risk is the risk of regulatory sanctions, fines, penalties or losses resulting

from failure to comply with laws, rules, regulations, or other supervisory

requirements applicable to a financial institution.

• Legal risk is the potential that actions against the institution that result in

unenforceable contracts, lawsuits, legal sanctions, or adverse judgments can disrupt

or otherwise negatively affect the operations or condition of a financial institution.

These risks and the activities associated with them are addressed in greater detail in the

Federal Reserve’s supervision manuals and other guidance documents.3 In practice, an

institution’s business activities present various combinations, concentrations, and

interrelationships of these risks depending on the nature and scope of the particular activity. The

following discussion provides guidelines for the supervisory assessment of the overall

effectiveness of an institution’s risk management and its formal or informal systems for

identifying, measuring, monitoring, and controlling these risks

ities present various combinations, concentrations, and

interrelationships of these risks depending on the nature and scope of the particular activity. The

following discussion provides guidelines for the supervisory assessment of the overall

effectiveness of an institution’s risk management and its formal or informal systems for

identifying, measuring, monitoring, and controlling these risks.

ELEMENTS OF RISK MANAGEMENT

When evaluating the risk management at an institution as part of the evaluation of the

overall effectiveness of management, examiners should place primary consideration on findings

relating to the following elements of a sound risk management system:

• Board4 and senior management oversight

• Policies, procedures, and limits

• Risk monitoring and management information systems

• Internal controls

Each of these elements is described further below, along with a list of considerations

relevant to assessing each element. Examiners should recognize that the considerations specified

2 This definition conforms to the Basel committee’s definition of operational risk.

3 Refer to the Federal Reserve’s Commercial Bank Examination Manual, Bank Holding Company Supervision

Manual, Examination Manual for U.S. Branches and Agencies of Foreign Banking Organizations, and relevant

FFIEC Examination Manuals.

4 For the purpose of this guidance, for foreign banking organizations, “board of directors” refers to the equivalent

governing body of the U.S. operations of the FBO.

er to the Federal Reserve’s Commercial Bank Examination Manual, Bank Holding Company Supervision

Manual, Examination Manual for U.S. Branches and Agencies of Foreign Banking Organizations, and relevant

FFIEC Examination Manuals.

4 For the purpose of this guidance, for foreign banking organizations, “board of directors” refers to the equivalent

governing body of the U.S. operations of the FBO.

6/8/2016

Revised February 17, 2021

Page 3 of 9

in these guidelines are intended only to assist in the evaluation of risk management practices and

are not a checklist of requirements for each institution.

An institution’s risk management processes are expected to evolve in sophistication,

commensurate with the institution’s asset growth, complexity, and risk. At a larger or more

complex organization, the institution should have more sophisticated risk management processes

that address the full range of risks regardless of where the activity is conducted in the

organization. Moreover, while a holding company should be able to assess the major risks of the

consolidated organization, examiners should expect a parent company that centrally manages the

operations and functions of its subsidiary banks to have more comprehensive, detailed, and

developed risk management systems than a parent company that delegates the management of

risks to relatively autonomous subsidiaries.5

For a small community banking organization (CBO) engaged solely in traditional

banking activities and whose senior management is actively involved in the details of day-to-day

operations, relatively basic risk management systems may be adequate

detailed, and

developed risk management systems than a parent company that delegates the management of

risks to relatively autonomous subsidiaries.5

For a small community banking organization (CBO) engaged solely in traditional

banking activities and whose senior management is actively involved in the details of day-to-day

operations, relatively basic risk management systems may be adequate. In accordance with the

Interagency Guidelines Establishing Standards for Safety and Soundness, a CBO is expected, at

a minimum, to have internal controls, information systems, and internal audit that are appropriate

for the size of the institution and the nature, scope, and risk of its activities.6

The risk management processes of a regional banking organization (RBO) would

typically contain detailed guidelines that set specific prudent limits on the principal types of risks

relevant to a RBO’s consolidated activities.7 Furthermore, because of the diversity and the

geographic dispersion of their activities, these institutions will require relatively more

sophisticated information systems that provide management with timely information that

supports the management of risks. The information systems, in turn, should provide

management with information that present a consolidated and integrated view of risks that are

relevant to the duties and responsibilities of individual managers, senior management, and the

board of directors.8

5 If these subsidiaries are regulated by another federal banking agency, Federal Reserve examiners should rely to the

fullest extent possible on the conclusions drawn by relevant regulators regarding risk management. See also,

SR letter 16-4, “Relying on the Work of the Regulators of the Subsidiary Insured Depository Institution(s) of Bank

s, senior management, and the

board of directors.8

5 If these subsidiaries are regulated by another federal banking agency, Federal Reserve examiners should rely to the

fullest extent possible on the conclusions drawn by relevant regulators regarding risk management. See also,

SR letter 16-4, “Relying on the Work of the Regulators of the Subsidiary Insured Depository Institution(s) of Bank.

Holding Companies and Savings and Loan Holding Companies with Total Consolidated Assets of Less than

$100 Billion.”

6 Refer to 12 CFR 208, Appendix D-1, the Interagency Guidelines Establishing Standards for Safety and Soundness.

7 As of the February 2021 revision to this guidance, the Federal Reserve generally considers an RBO to be a midsize

financial institution with total consolidated assets between $10 and $100 billion.

8 Additionally, the Federal Reserve’s Regulation YY includes specific and enhanced prudential standard

requirements regarding risk management for RBOs.

6/8/2016

Revised February 17, 2021

Page 4 of 9

Consistent with the principle of national treatment,9 the Federal Reserve has the same

supervisory goals and standards for the U.S. operations of FBOs as for domestic organizations of

similar size, scope, and complexity. Given the added element of foreign ownership, an FBO’s

risk management processes and control functions for the U.S. operations may be implemented

domestically or outside of the United States. In cases where these functions are performed

outside of the United States, the FBO’s oversight function, policies and procedures, and

information systems need to be sufficiently transparent to allow U.S. supervisors to assess their

adequacy. Additionally, the FBO’s U.S. senior management need to demonstrate and maintain a

thorough understanding of all relevant risks affecting the U.S. operations and the associated

management information systems, used to manage and monitor these risks within the U.S.

operations

cedures, and

information systems need to be sufficiently transparent to allow U.S. supervisors to assess their

adequacy. Additionally, the FBO’s U.S. senior management need to demonstrate and maintain a

thorough understanding of all relevant risks affecting the U.S. operations and the associated

management information systems, used to manage and monitor these risks within the U.S.

operations.

The information systems at a larger institution will naturally require frequent monitoring

and testing by independent control areas and by both internal and external auditors, to ensure the

integrity of the information used by the board of directors and senior management in overseeing

compliance with policies and limits. Therefore, an institution’s risk oversight function needs to

be sufficiently independent of the business lines to achieve an adequate separation of duties and

the avoidance of conflicts of interest.

Board and Senior Management Oversight

The board of directors has the responsibility for establishing the level of risk that the

institution should take. Accordingly, the board of directors should approve the institution’s

overall business strategies and significant policies, including those related to managing risks.

Further, the board of directors should also ensure that senior management is fully capable of

implementing the institution’s business strategies and risk limits. In evaluating senior

management, the board of directors should consider whether management is taking the steps

necessary to identify, measure, monitor, and control these risks.

The board of directors should collectively have a balance of skills, knowledge, and

experience to clearly understand the activities and risks to which the institution is exposed. The

board of directors should take steps to develop an appropriate understanding of the risks the

institution faces, through briefings from experts internal to their organization and potentially

from external experts

The board of directors should collectively have a balance of skills, knowledge, and

experience to clearly understand the activities and risks to which the institution is exposed. The

board of directors should take steps to develop an appropriate understanding of the risks the

institution faces, through briefings from experts internal to their organization and potentially

from external experts. The institution’s management information systems should provide the

board of directors with sufficient information to identify the size and significance of the risks.

Using this knowledge and information, the board of directors should provide clear guidance

regarding the level of exposures acceptable to the institution and oversee senior management’s

implementation of the procedures and controls necessary to comply with approved policies.

9 National treatment requires nondiscrimination between domestic and foreign firms, or treatment of foreign entities

that is no less favorable than that accorded to domestic enterprises in like circumstances. The International Banking

Act of 1978 generally gives foreign banks operating in the United States the same powers as domestic banking

organizations and subjects them to the same restrictions and obligations.

6/8/2016

Revised February 17, 2021

Page 5 of 9

Senior management is responsible for implementing strategies set by the board of

directors in a manner that controls risks and that complies with laws, rules, regulations, or other

supervisory requirements on both a long-term and day-to-day basis. Accordingly, senior

management should be fully involved in and possess sufficient knowledge of all activities to

ensure that appropriate policies, controls, and risk monitoring systems are in place and that

accountability and lines of authority are clearly delineated

ks and that complies with laws, rules, regulations, or other

supervisory requirements on both a long-term and day-to-day basis. Accordingly, senior

management should be fully involved in and possess sufficient knowledge of all activities to

ensure that appropriate policies, controls, and risk monitoring systems are in place and that

accountability and lines of authority are clearly delineated. Senior management is also

responsible for establishing and communicating a strong awareness of the need for effective risk

management, internal controls, and high ethical business practices. To fulfill these

responsibilities, senior management needs to have a thorough understanding of banking and

financial market activities and detailed knowledge of the institution’s activities, including the

internal controls that are necessary to limit the related risks.

In assessing the quality of the oversight provided by the board of directors and senior

management, examiners should consider the following:

• The board of directors has approved significant policies to establish risk tolerances

for the institution’s activities and periodically reviews risk exposure limits to align

with changes in the institution’s strategies, address new activities and products, and

react to changes in the industry and market conditions.

• Senior management has identified and has a clear understanding and working

knowledge of the risks inherent in the institution’s activities. Senior management

also remains informed about these risks as the institution’s business activities evolve

or expand and as changes and innovations occur in financial markets and risk

management practices.

• Senior management has identified and reviewed risks associated with engaging in

new activities or introducing new products to ensure that the necessary infrastructure

and internal controls are in place to manage the related risks

bout these risks as the institution’s business activities evolve

or expand and as changes and innovations occur in financial markets and risk

management practices.

• Senior management has identified and reviewed risks associated with engaging in

new activities or introducing new products to ensure that the necessary infrastructure

and internal controls are in place to manage the related risks.

• Senior management has ensured that the institution’s activities are managed and

staffed by personnel with the knowledge, experience, and expertise consistent with

the nature and scope of the institution’s activities and risks.

• All levels of senior management provide appropriate management of the day-to-day

activities of officers and employees, including oversight of senior officers or heads of

business lines.

• Senior management has established and maintains effective information systems to

identify, measure, monitor, and control the sources of risks to the institution.

Policies, Procedures, and Limits

6/8/2016

Revised February 17, 2021

Page 6 of 9

Although an institution’s board of directors approves an institution’s overall business

strategy and policy framework, senior management develops and implements the institution’s

risk management policies and procedures that address the types of risks arising from its

activities. Once the risks are properly identified, the institution’s policies and procedures should

provide guidance for the day-to-day implementation of business strategies, including limits

designed to prevent excessive and imprudent risks. An institution should have policies and

procedures that address its significant activities and risks with the appropriate level of detail to

address the type and complexity of the institution’s operations. A smaller, less complex

institution that has effective senior management directly involved in day-to-day operations

would generally not be expected to have policies as sophisticated as larger institutions

should have policies and

procedures that address its significant activities and risks with the appropriate level of detail to

address the type and complexity of the institution’s operations. A smaller, less complex

institution that has effective senior management directly involved in day-to-day operations

would generally not be expected to have policies as sophisticated as larger institutions. In a

larger institution, where senior managers rely on widely-dispersed staffs to implement strategies

for more varied and complex businesses, far more detailed policies and procedures would

generally be expected. In either case, senior management is expected to ensure that policies and

procedures address the institution’s material areas of risk and that policies and procedures are

modified when necessary to respond to significant changes in the institution’s activities or

business conditions.

The following guidelines should assist examiners in evaluating an institution’s policies,

procedures, and limits:

• The institution’s policies, procedures, and limits provide for adequate identification,

measurement, monitoring, and control of the risks posed by its significant risk-taking

activities.

• The policies, procedures, and limits are consistent with the institution’s stated

strategy and risk profile.

• The policies and procedures establish accountability and lines of authority across the

institution’s activities.

• The policies and procedures provide for the review and approval of new business

lines, products, and activities, as well as material modifications to existing activities,

services, and products, to ensure that the institution has the infrastructure necessary to

identify, measure, monitor, and control associated risks before engaging in a new or

modified business line, product, or activity

.

• The policies and procedures provide for the review and approval of new business

lines, products, and activities, as well as material modifications to existing activities,

services, and products, to ensure that the institution has the infrastructure necessary to

identify, measure, monitor, and control associated risks before engaging in a new or

modified business line, product, or activity.

Risk Monitoring and Management Information Systems

Institutions of all sizes are expected to have risk monitoring and management information

systems in place that provide the board of directors and senior management with timely

information and a clear understanding of the institution’s business activities and risk exposures.

The sophistication of risk monitoring and management information systems should be

commensurate with the complexity and diversity of the institution’s operations. Accordingly, a

smaller and less complex institution may require less frequent management and board reports to

6/8/2016

Revised February 17, 2021

Page 7 of 9

support risk monitoring activities. For example, these reports may include, daily or weekly

balance sheets and income statements, a watch list for potentially troubled loans, a report on past

due loans, an interest rate risk report, and similar items. In contrast, a larger, more complex

institution would be expected to have much more comprehensive reporting and monitoring

systems, which includes more frequent reporting to board and senior management, tighter

monitoring of high-risk activities, and the ability to aggregate risks on a fully consolidated basis

across all business lines, legal entities, and activities.

In assessing an institution’s measurement and monitoring of risk and its management

reports and information systems, examiners should consider whether these conditions exist:

• The institution’s risk monitoring practices and reports address all of its material risks

nd the ability to aggregate risks on a fully consolidated basis

across all business lines, legal entities, and activities.

In assessing an institution’s measurement and monitoring of risk and its management

reports and information systems, examiners should consider whether these conditions exist:

• The institution’s risk monitoring practices and reports address all of its material risks.

• Key assumptions, data sources, models, and procedures used in measuring and

monitoring risks are appropriate and adequately documented and tested for reliability

on an on-going basis.10

• Reports and other forms of communication address the complexity and range of an

institution’s activities, monitor key exposures and compliance with established limits

and strategy, and as appropriate, compare actual versus expected performance.

• Reports to the board of directors and senior management are accurate, and provide

timely and sufficient information to identify any adverse trends and to evaluate the

level of risks faced by the institution.

Internal Controls

An effective internal control structure is critical to the safe and sound operation of an

institution. Effective internal controls promote reliable financial and regulatory reporting,

safeguard assets, and help to ensure compliance with relevant laws, rules, regulations,

supervisory requirements, and institutional policies. Therefore, an institution’s senior

management is responsible for establishing and maintaining an effective system of controls,

including the enforcement of official lines of authority and the appropriate segregation of duties.

Adequate segregation of duties is a fundamental and essential element of a sound risk

management and internal control system. Failure to implement and maintain an adequate

segregation of duties can constitute an unsafe-and-unsound practice and possibly lead to serious

losses or otherwise compromise the integrity of the institution’s internal controls

the appropriate segregation of duties.

Adequate segregation of duties is a fundamental and essential element of a sound risk

management and internal control system. Failure to implement and maintain an adequate

segregation of duties can constitute an unsafe-and-unsound practice and possibly lead to serious

losses or otherwise compromise the integrity of the institution’s internal controls. Serious lapses

or deficiencies in internal controls, including inadequate segregation of duties, may warrant

supervisory action, including formal enforcement action.

10 See also SR letter 11-7, “Guidance on Model Risk Management.”

6/8/2016

Revised February 17, 2021

Page 8 of 9

Internal controls should be tested by an independent party who reports either directly to

the institution’s board of directors or its designated committee, which is typically the audit

committee.11 However, small CBOs whose size and complexity do not warrant a full scale

internal audit function may rely on regular reviews of essential internal controls conducted by

other institution personnel. Given the importance of appropriate internal controls to institutions

of all sizes and risk profiles, the results of audits or reviews, whether conducted by an internal

auditor or by other personnel, should be adequately documented, as should management’s

responses to the findings. In addition, communication channels should allow for adverse or

sensitive findings to be reported directly to the board of directors or to the relevant board

committee.

In evaluating internal controls, examiners should consider whether these conditions are

met:

• The system of internal controls is appropriate to the type and level of risks posed by

the nature and scope of the institution’s activities.

• The institution’s organizational structure establishes clear lines of authority and

responsibility for risk management and for monitoring adherence to policies,

procedures, and limits

rols, examiners should consider whether these conditions are

met:

• The system of internal controls is appropriate to the type and level of risks posed by

the nature and scope of the institution’s activities.

• The institution’s organizational structure establishes clear lines of authority and

responsibility for risk management and for monitoring adherence to policies,

procedures, and limits.

• Internal audit or other control functions, such as loan review and compliance, provide

for independence and objectivity.

• The official organizational structures reflect actual operating practices and

management responsibilities and authority over a particular business line or activity.

• Financial, operational, risk management, and regulatory reports are reliable, accurate,

and timely; and wherever applicable, material exceptions are noted and promptly

investigated or remediated.

• Policies and procedures for control functions support compliance with applicable

laws, rules, regulations, or other supervisory requirements.

• Internal controls and information systems are adequately tested and reviewed; the

coverage, procedures, findings, and responses to audits, regulatory examinations, and

other review tests are adequately documented; identified material weaknesses are

given appropriate and timely, high-level attention; and management’s actions to

address material weaknesses are objectively verified and reviewed.

11 Given the importance of the internal audit function, several additional policy statements have been issued. For

comprehensive guidance on internal audit, see SR letter 03-5, “Amended Interagency Guidance on the Internal

Audit Function and its Outsourcing” and for institutions with more than $10 billion in assets, see SR letter 13-1/

CA letter 13-1, “Supplemental Policy Statement on the Internal Audit Function and Its Outsourcing.”

it function, several additional policy statements have been issued. For

comprehensive guidance on internal audit, see SR letter 03-5, “Amended Interagency Guidance on the Internal

Audit Function and its Outsourcing” and for institutions with more than $10 billion in assets, see SR letter 13-1/

CA letter 13-1, “Supplemental Policy Statement on the Internal Audit Function and Its Outsourcing.”

6/8/2016

Revised February 17, 2021

Page 9 of 9

• The institution’s board of directors, or audit committee, and senior management are

responsible for developing and implementing an effective system of internal controls

and that the internal controls are operating effectively.

Conclusions

Examiners are expected to assess risk management for an institution and assign formal

ratings of “risk management” as described in the Commercial Bank Examination Manual for

state member banks, the Bank Holding Company Manual for holding companies, and the

Examination Manual for U.S. Branches and Agencies of Foreign Banking Organizations.12 In

reports of examination or inspection, and in transmittal letters to the boards of directors of state

member banks, holding companies,13 and to the FBO officer of the U.S. operations, examination

staff should specifically reference the types and nature of corrective actions that need to be taken

by an institution to address noted risk management and internal control deficiencies. Where

appropriate, the Federal Reserve will advise an institution that supervisory action will be

initiated, if the institution fails to timely remediate risk management weaknesses when such

failures create the potential for serious losses or if material deficiencies or situations threaten its

safety and soundness. Such supervisory actions may include formal enforcement actions against

the institution, or its responsible officers and directors, or both, and would require the immediate

implementation of all necessary corrective measures

mediate risk management weaknesses when such

failures create the potential for serious losses or if material deficiencies or situations threaten its

safety and soundness. Such supervisory actions may include formal enforcement actions against

the institution, or its responsible officers and directors, or both, and would require the immediate

implementation of all necessary corrective measures.

If bank or holding company subsidiaries are regulated by another federal banking agency,

Federal Reserve examiners should rely to the fullest extent possible on the conclusions drawn by

relevant regulators regarding risk management. See also, SR letter 16-4, “Relying on the Work

of the Regulators of the Subsidiary Insured Depository Institution(s) of Bank Holding

Companies and Savings and Loan Holding Companies with Total Consolidated Assets of Less

than $100 Billion.”

12 Refer to section 1000.1 of the Commercial Bank Examination Manual; section 1062.0 of the Bank Holding

Company Supervision Manual; and section 2003.1 of the Examination Manual for U.S. Branches and Agencies of

Foreign Banking Organizations. For savings and loan holding companies, see also SR letter 14-9, “Incorporation of

Federal Reserve Policies into the Savings and Loan Holding Company Supervision Program.”

13 This letter applies to insurance and commercial savings and loan holding companies with total consolidated assets

less than $100 billion by providing core risk management guidance. Reserve Bank staff may further consult with

Board staff on appropriately tailoring this guidance for these institutions.

This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.

A word about cookies

We need a few to keep you signed in and the library working. The rest help us see which pages people use and where they get stuck. They stay off unless you say yes.