The National Risk Committee (NRC) of the Office of the Comptroller of the Currency (OCC) monitors the condition of the U.S. federal banking system, identifies key risks facing banks, and highlights those risks that pose threats to the safety and soundness of banks and their compliance with applicable laws and regulations.
The latest edition of its guidance — the Fall 2021 Semiannual Risk Perspective – highlights four key risk areas including elevated operational risk and heightened compliance risk, and the risks associated with climate change.
The OCC has observed that “operational risk remains elevated as cyber attacks evolve, (and) become more sophisticated.” The OCC categorizes the main reasons for the ‘elevated’ status as the increase in ransomware attacks in the financial industry, known and unknown software vulnerabilities, expansion of remote financial services, and the increasing reliance on third-party providers for services such as cloud-based environments.
With the pandemic, the banking industry has experienced a lot of change. This includes the adoption of new technology to quickly respond to customer and organizational needs. Third parties stepped in to play a vital role in bridging the gap where banks and financial institutions often lacked the expertise or technology needed to introduce new products or services. This has resulted in an increase in onboarding of third-parties to take over or assist in such functions.
Taking this growth of third parties into account, the OCC notes that “Supply chain risk continues to increase and evolve as attacks target vulnerabilities in software systems commonly used by large numbers of OCC supervised banks,” and that “Threat actors are increasingly exploiting vulnerabilities in third-party hardware and software systems to conduct malicious cyber activities.”
To manage and mitigate cyber risks, the OCC recommends the following measures for banks and financial institutions:
Banks continue to face pandemic-related new and emerging compliance risks. The report calls out the heightened compliance risk as banks “adjust to regulatory changes and initiate efforts to serve customers in the final stages of assistance programs and initiatives related to the COVID-19 pandemic.”
With most of the assistance programs concluding, it has resulted in increased compliance responsibilities, high transaction volumes, as well as new types of fraud—all the while as banks continue to respond and operate in a changing operating environment.
The report further identifies other compliance hurdles including, “specific areas of challenge” such as ”responsibilities associated with underwriting and opening new accounts, monitoring customer activity, processing transactions, making loan modifications, servicing loans, communicating with customers, complying with consumer protection laws, and treating customers fairly.”
Other challenge areas noted by the OCC included meeting Bank Secrecy Act (BSA) and Office of Foreign Assets Control (OFAC) compliance obligations, as well as adapting to regulatory and policy actions by the Consumer Financial Protection Bureau (CFPB). The OCC also highlighted compliance risk being heightened by the rapid digitalization of banking processes and the emergence of digital assets.
To address the heightened compliance risk, the OCC proposes that banks take the following steps:
The impact of climate change on households, communities, businesses, and governments presents significant risk to banks and financial institutions. As per the report, “Banks are exposed to physical and transition risks presented by climate change, which may impact the safety and soundness of supervised institutions.”
This makes it important for banks and financial institutions to continually assess both physical risks such as hurricanes, wildfires, floods, heatwaves, sea level rise, etc., and transitional risk changes including those from government policy, technology, consumer/investor sentiment, etc.
MetricStream’s capabilities enable banks and financial institutions to implement the OCC’s recommendations. With real-time risk intelligence, AI-powered recommendations and insights, and years of proven domain expertise, MetricStream enables you to follow a robust operational risk management strategy and strengthen your compliance posture—empowering you make risk-aware decisions to ‘thrive on risk.’
See how MetricStream can help you stay current and compliant. Request a demo today.