TL;DR: The 2026 examination landscape for community banks has shifted. The OCC's February 2026 Community Bank BSA/AML Examination Procedures tailor exam scope to institutional risk profile, and FinCEN's April 2026 proposed rule introduces an effectiveness-based standard that separates program design from program operation. Examiners are moving from "show us your policies" to "show us your outcomes." Community bank BSA officers who understand what examiners actually evaluate — risk assessment currency, transaction monitoring tuning rationale, SAR narrative quality, CDD documentation, and independent testing scope — can prepare programs that withstand scrutiny under both frameworks.
What Changed in 2026
Two regulatory developments in early 2026 redefined how BSA/AML examinations work at community banks. Neither reduces the core compliance obligations. Both change how examiners assess whether those obligations are met.
On February 1, 2026, the OCC's Community Bank BSA/AML Examination Procedures took effect. Issued under Bulletin 2025-37, these procedures supplement the FFIEC BSA/AML Examination Manual with standardized guidelines for tailoring examination scope and testing to a community bank's risk profile, past supervisory findings, and independent testing results. The procedures give examiners discretion to rely on satisfactory independent testing for specific examination conclusions, carry forward prior cycle conclusions on training and BSA officer pillars when risk profiles remain stable, and determine whether transaction testing should be performed or limited to analytical reviews. The OCC simultaneously ended its annual Money Laundering Risk System data collection from community banks, removing a reporting burden that fell exclusively on smaller institutions.
On April 7, 2026, FinCEN issued a proposed rule that would fundamentally restructure AML/CFT program requirements under the Bank Secrecy Act. The proposal introduces an effectiveness-based standard: programs would be measured by their ability to detect and deter illicit finance, not by the volume of documentation they produce. The OCC, FDIC, and NCUA issued a concurrent joint proposed rulemaking to align their supervisory frameworks with FinCEN's changes.
The FinCEN proposal establishes a two-pronged evaluation framework that distinguishes between program establishment and program maintenance. Establishment asks whether the community bank has designed a risk-based AML/CFT program incorporating the required pillars: internal policies, procedures, and controls (including risk assessment processes); independent testing; designation of a qualified compliance officer; and ongoing training. Maintenance asks whether the community bank implements that program "in all material respects." This distinction matters because it clarifies that isolated or immaterial shortcomings in an otherwise well-designed program do not warrant enforcement action. Only "significant or systemic" failures in maintenance would trigger supervisory consequences.
Together, these developments create a regulatory environment where community banks are examined against their actual risk profile rather than a one-size-fits-all standard. The examination question shifts from whether every procedural box is checked to whether the program produces defensible outcomes.
What Examiners Actually Evaluate

Understanding what examiners prioritize during a community bank BSA examination allows BSA officers to allocate preparation time where it matters most. Under both the OCC's tailored procedures and FinCEN's proposed effectiveness framework, five areas consistently drive examination outcomes.
Risk assessment currency
The risk assessment is the foundation of every examination. Examiners evaluate whether a community bank's BSA/AML risk assessment accurately reflects the institution's current products, services, customer base, and geographic footprint. Under FinCEN's proposed rule, risk assessment processes would become an explicit regulatory requirement embedded within the internal controls pillar — no longer just an implied best practice. The assessment must evaluate ML/TF risks across all business activities, incorporate FinCEN's AML/CFT priorities, and update "promptly" when the institution knows or has reason to know that its risk profile has significantly changed.
For community banks, "promptly" is the operative word. Examiners look for evidence that the risk assessment was updated when the institution launched a new product, entered a new geographic market, onboarded a new customer segment, or experienced a merger or acquisition. A risk assessment dated twelve months ago that does not reflect a new cannabis banking relationship or a recently added prepaid card program is a finding waiting to happen.
Transaction monitoring tuning rationale
Examiners do not simply verify that a community bank has transaction monitoring rules in place. They evaluate whether the rules are calibrated to the institution's specific risk profile and whether the community bank can document why each rule is set at its current threshold. This includes the initial rationale for rule parameters, the frequency and methodology of periodic reviews, evidence of above-the-line and below-the-line testing, and documented decisions to adjust or retain thresholds.
The tuning rationale is where many community banks encounter difficulty. An alert triage system generating 20,000 alerts per year with a 95% false positive rate raises an immediate question: has the institution evaluated whether its thresholds are producing meaningful results, or is it simply processing volume? SAR filings reached 2.6 million in fiscal year 2024, an 18.5% increase year-over-year. Examiners are attuned to whether monitoring systems are generating useful intelligence or contributing to a filing volume that obscures genuinely suspicious activity.
SAR narrative quality
SAR narratives are one of the most visible outputs of a community bank's BSA program. Examiners review narratives for completeness, accuracy, and — critically — whether the narrative connects the observed activity to the basis for suspicion. A narrative that describes what happened without explaining why it is suspicious fails the basic test.
Under the effectiveness-based framework, SAR narrative quality takes on additional weight. FinCEN's proposed rule emphasizes that programs should generate information "highly useful" to law enforcement. Narratives that recite transaction details without contextualizing the activity — who the subject is, what their expected behavior looks like, and why the observed pattern deviates — do not meet that standard. Examiners evaluate whether narratives demonstrate that the analyst understood the customer relationship, identified the anomalous pattern, and articulated a coherent basis for the filing.
CDD and EDD documentation
Customer due diligence and enhanced due diligence documentation provides examiners with evidence that a community bank understands its customer base. Examiners evaluate whether CDD information is collected at onboarding, whether the institution has a process for refreshing CDD on an ongoing basis, and whether enhanced due diligence is applied to higher-risk customers as identified in the risk assessment.
The most common gap examiners find in community bank CDD programs is not the absence of a policy but the absence of evidence that the policy is followed. A CDD program that requires periodic refresh of beneficial ownership information but cannot produce evidence that refresh has occurred for high-risk customers will draw scrutiny. Under FinCEN's proposed rule, CDD becomes an explicit component of the internal controls pillar, reinforcing that documentation of due diligence activity — not just the existence of a policy — is what examiners evaluate.
Independent testing scope
The OCC's community bank procedures place particular emphasis on independent testing. Examiners assess whether testing covers all components of the BSA/AML compliance program, whether the testing methodology is appropriate for the institution's size and complexity, and whether findings from prior testing cycles have been addressed. The OCC's tailored procedures allow examiners to rely on satisfactory independent testing to support specific examination conclusions, which means the quality and scope of a community bank's independent testing program can directly influence the depth of the examination itself.
FinCEN's proposed rule clarifies that independent testing should focus on program effectiveness — whether the program achieves its stated objectives — rather than technical completeness. The proposal explicitly states that auditors should not substitute their subjective judgment for the institution's risk-based program decisions. For community banks, this means independent testing that evaluates whether monitoring rules detect the risks identified in the risk assessment, rather than testing that simply confirms rules exist.
Documentation Gaps That Trigger MRAs
Matters Requiring Attention (MRAs) and Matters Requiring Immediate Attention (MRIAs) are the formal mechanisms through which examiners communicate deficiencies. MRAs typically allow 90-180 days for remediation, while MRIAs demand interim controls within days and corrective action plans within 30-60 days. Understanding the documentation gaps that most frequently trigger these findings allows community bank BSA officers to address them before examiners arrive.
Risk assessment not updated for product changes
A community bank that added mobile deposit capture, introduced a new wire transfer product, or began serving marijuana-related businesses without updating its risk assessment has a gap that examiners will identify. The risk assessment must reflect the institution as it operates today, not as it operated when the assessment was last reviewed. Examiners cross-reference the risk assessment against the bank's current product offerings, customer types, and geographic presence. Any disconnect is a finding.
Transaction monitoring rules without tuning justification
Monitoring rules with thresholds set at implementation and never reviewed, or reviewed without documentation of the rationale for retaining current settings, generate MRAs. Examiners expect to see evidence that the institution periodically evaluates whether its rules are calibrated to its risk profile — including below-the-line testing to assess whether suspicious activity is passing through undetected. The absence of a tuning log, or a tuning log that consists of "no changes made" entries without supporting analysis, is insufficient.
SAR narratives that do not connect activity to suspicion
Narratives that describe transactions without articulating the basis for suspicion — or narratives that use boilerplate language across materially different filing scenarios — indicate a process gap. Examiners review SAR narratives as evidence of the quality of the institution's investigative process. A narrative that does not demonstrate the analyst reviewed CDD information, understood expected account activity, and identified specific deviations will be cited.
Missing CDD refresh evidence
A community bank with a policy requiring periodic CDD refresh on high-risk customers but no evidence that refresh has occurred is a common MRA trigger. The gap is not the policy; it is the absence of documentation showing the policy was executed. Examiners pull samples of high-risk customer files and look for evidence of ongoing due diligence activity — updated beneficial ownership information, refreshed source of funds documentation, and evidence that the customer's risk rating has been reviewed.
How AI Audit Trails Change the Conversation
The shift from process-based to effectiveness-based evaluation changes what constitutes adequate documentation during an examination. Under the traditional model, examiners reviewed training records, procedure manuals, and analyst notes — artifacts that demonstrate the institution followed its processes. Under the effectiveness-based framework, the question becomes whether the institution can demonstrate why it made specific decisions about specific alerts, customers, and filings.
This is where AI-generated audit trails fundamentally change the examination conversation. Community banks in the $1 billion to $3 billion range can deploy AI-driven alert triage in four to eight months. When properly implemented, these systems produce structured documentation of every decision as a byproduct of the analysis itself — not as a separate step that analysts perform after the fact.
An AI-generated audit trail for a cleared alert typically includes: the data sources reviewed (transaction history, CDD profile, peer group analysis, watchlist screening results), the specific factors that contributed to the disposition, the confidence level of the assessment, and the reasoning chain connecting the evidence to the conclusion. This is fundamentally different from an analyst note that reads "reviewed activity, no suspicious patterns identified."
For examiners, structured audit trails provide something that traditional documentation cannot: traceability from the disposition back to the underlying evidence. An examiner reviewing an AI-generated audit trail can see exactly what data the system considered, how it weighted different risk factors, and why it reached its conclusion. This transparency shifts the examination dialogue from "did you follow the process" to "does the reasoning hold up" — which is precisely the conversation that the effectiveness-based framework is designed to encourage.
The practical implication for community bank BSA officers preparing for examinations: documented decision reasoning is becoming more valuable than documented process adherence. An institution that can produce a structured audit trail for every alert disposition occupies stronger examination ground than one that can produce a procedure manual and a stack of analyst worksheets.
Where Sphinx Fits
Sphinx deploys AI agents that work inside a community bank's existing compliance workflows — reviewing alerts, producing structured audit trails, and generating SAR-ready narratives with the documented reasoning that examiners now evaluate. Community banks using Sphinx have reduced alert review time by up to 99% while producing the kind of traceable, evidence-backed documentation that the OCC's tailored procedures and FinCEN's effectiveness-based framework reward. In a regulatory environment that measures program quality by outcomes rather than paperwork volume, Sphinx helps community banks demonstrate that their programs work.
Frequently Asked Questions
What are the OCC's new community bank BSA examination procedures?
The OCC's Community Bank BSA/AML Examination Procedures, effective February 1, 2026, supplement the FFIEC BSA/AML Examination Manual with guidelines for tailoring examination scope to a community bank's risk profile. The procedures give examiners discretion to rely on satisfactory independent testing, carry forward prior cycle conclusions on certain program pillars, and adjust the depth of transaction testing based on institutional risk. The OCC also ended its annual Money Laundering Risk System data collection from community banks.
How does FinCEN's effectiveness rule affect community bank BSA exams?
FinCEN's April 2026 proposed rule shifts the evaluation standard from process compliance to outcome effectiveness. Community bank BSA programs would be assessed on whether they actually detect and deter illicit finance — not on the volume of documentation they produce. The rule introduces a two-pronged framework separating program establishment (design) from maintenance (operation), and raises the enforcement threshold so that isolated or immaterial deficiencies in a well-designed program do not trigger supervisory action.
What documentation gaps most commonly trigger MRAs at community banks?
The most common MRA triggers at community banks include risk assessments that have not been updated to reflect new products or customer segments, transaction monitoring rules without documented tuning rationale, SAR narratives that describe transactions without connecting the activity to a basis for suspicion, and CDD programs that lack evidence of periodic refresh for high-risk customers. Each gap reflects a disconnect between the community bank's stated policies and its documented execution.
How do AI audit trails help community banks prepare for BSA exams?
AI audit trails produce structured, timestamped documentation of every alert disposition as a byproduct of the analysis — including the data reviewed, risk factors considered, confidence levels, and reasoning chains. This gives examiners traceability from the disposition back to the evidence, which aligns with the effectiveness-based framework's emphasis on demonstrating decision quality rather than process adherence. Community banks in the $1 billion to $3 billion range can deploy AI triage in four to eight months.
What is the difference between an MRA and an MRIA for community banks?
An MRA (Matter Requiring Attention) identifies a deficiency that requires corrective action, typically within 90-180 days. An MRIA (Matter Requiring Immediate Attention) identifies a deficiency that poses a more serious risk and requires interim controls within days, a corrective action plan within 30-60 days, and may trigger follow-up reviews before the next full examination cycle. An unresolved MRIA can escalate to a consent order or cease-and-desist action without waiting for the next scheduled examination.

.png)







