Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Should We Scale Back Risk Controls Now That FDICIA Thresholds Are Rising?Regulatory Compliance
5 min readFor Risk Managers

Should We Scale Back Risk Controls Now That FDICIA Thresholds Are Rising?

Context: Questions from the Field

Since the FDIC proposed raising FDICIA thresholds in April 2025, risk managers at mid-sized banks have been grappling with what these changes mean for their operations. The proposed changes are significant: the internal control over financial reporting (ICOFR) threshold increases from $1 billion to $5 billion in assets, and audit committee independence rules shift from the $1-3 billion range to $5 billion.

While this appears to offer relief, it has created uncertainty about which controls to maintain, which to scale back, and how to justify ongoing investment in enterprise risk management when regulatory pressure eases.

These are not hypothetical questions. They're the real discussions happening as institutions plan for 2026.


Can We Stop Our Annual Control Assessments?

You can, but you shouldn't.

The FDIC's proposed rule removes the regulatory mandate for management's annual assessment of internal control over financial reporting if you're under $5 billion. It doesn't eliminate the risks those controls address.

Your board, external auditors, and depositors still expect transparency in managing financial reporting integrity. If you dismantle the control assessment process, you'll lose visibility into control gaps, discovering issues only when they cause problems.

A smarter approach is to streamline the process. Focus your annual review on high-risk areas like loan loss reserves, interest rate risk modeling, and vendor payment controls. Document what you test and why. You don't need to file it with regulators, but you'll want it when your audit committee asks how you're managing control effectiveness.


Can We Cut Our Risk Management Budget?

Only if you're comfortable flying blind.

Regulatory relief doesn't mean risk relief. Cyber threats, third-party failures, liquidity stress, and fraud attempts don't care about your asset size. Mid-sized banks are often targeted because attackers assume you have fewer resources than national banks but more assets than community banks.

Institutions that cut risk budgets in response to threshold changes often end up spending more later, either fixing preventable incidents or rebuilding programs when they grow past a threshold.

Instead, use the regulatory breathing room to invest strategically. Automate control testing to reduce labor. Build a risk register that informs decision-making. Implement monitoring for emerging risks like AI governance or climate-related credit exposure.

You're not spending to comply anymore. You're spending to compete.


Should We Wait Until We Hit $5B to Build Out ERM?

No. Waiting guarantees you'll be building under pressure.

If you're growing, whether through expansion or M&A, your risk complexity is already increasing. Waiting until you cross the $5 billion threshold means you'll be designing your ERM framework while managing the operational stress of being a larger institution.

Banks that mature their risk programs early report smoother regulatory exams, faster board reporting cycles, and fewer surprises during audits. They also find it easier to integrate acquisitions because they have standardized risk taxonomies and control frameworks in place.

Start with the fundamentals now: a centralized risk register, a control library mapped to your key processes, and automated workflows for policy attestation and incident tracking. These aren't heavy lifts if you phase them in over 12-18 months. They become heavy lifts if you try to implement them in six months while also preparing for your first ICOFR filing.


Do We Still Need Independent Audit Committee Members?

Tell them the rule changes the requirement, not the principle.

The proposed FDICIA changes raise the threshold for mandatory audit committee independence from the $1-3 billion range to $5 billion. But independence isn't just a compliance checkbox; it's a governance principle.

Independent audit committee members bring objectivity, challenge management assumptions, and reduce conflicts of interest when reviewing financial reporting or internal audit findings. Boards that maintain independence even when not required tend to have stronger oversight and catch issues earlier.

If your institution is under $5 billion and considering reducing independence, ask: what problem does that solve? If the answer is "it saves us the hassle of recruiting," that's not a risk-informed decision. If the answer is "we're a $1.2 billion community bank and true independence is hard to find in our market," consider other governance safeguards like rotating committee chairs or bringing in external advisors for complex reviews.


How Do We Justify Continued ERM Investment?

Frame it as strategic infrastructure, not regulatory overhead.

Executives pushing for cuts often see ERM as a cost center for satisfying examiners. Reframe the conversation around what ERM enables: better capital allocation, faster identification of profit-eroding risks, clearer insights into third-party exposures, and data-driven responses to board questions.

Bring specific examples. Show how your risk register flagged a vendor concentration issue before it became a business continuity problem. Demonstrate how automated control testing reduced the time your operations team spends on manual evidence collection. Quantify how integrated risk reporting cut board prep time by consolidating data from six different spreadsheets into one risk dashboard.

If you can't point to tangible value your ERM program delivers beyond compliance, that's a signal you need to redesign the program, not eliminate it. ERM that doesn't inform decisions is just expensive documentation.


What's the Biggest Mistake Banks Make When Thresholds Get Relaxed?

Assuming regulatory relief equals risk relief.

The 2008 financial crisis didn't exempt smaller banks. The 2023 regional bank failures included institutions under previous FDICIA thresholds. Operational losses from cyberattacks, fraud, and third-party failures don't check your asset size before they hit.

The biggest mistake is treating threshold changes as permission to deprioritize risk governance. The second-biggest mistake is maintaining your program exactly as-is without using the regulatory breathing room to modernize.

If you're no longer required to file annual ICOFR assessments, great. Use the time you would've spent on compliance paperwork to build continuous control monitoring. If you don't need audit committee independence filings, fine. Invest in audit committee education so they're asking better questions about emerging risks.

Regulatory minimums are floors, not ceilings. The banks that thrive are the ones that see floors as foundations to build on, not finish lines to stop at.


Where to Go for More

The FDIC's proposed rulemaking on adjusting Part 363 thresholds is available at fdic.gov/news/press-releases/2025/pr25036.html. The rule includes indexing provisions that will adjust thresholds for inflation going forward, so even if you're comfortably under the new limits today, track how indexing might affect you in future years.

For banks building or scaling ERM programs, focus on platforms that support phased implementation. You don't need to deploy everything at once. Start with a risk register and control library, add automated workflows as you mature, and integrate obligations and incidents when you're ready.

And remember: the goal isn't to comply harder. It's to see risks clearly, respond faster, and grow confidently.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like