Thursday, October 1, 2026

September 2026 OBA Legal Briefs

September 2026

The FFIEC’s Proposed Revisions to the CAMELS Rating System

For nearly thirty years, the Uniform Financial Institutions Rating System (UFIRS)—commonly known as the CAMELS rating system—has served as the ultimate report card for U.S. banks. As most of you already know, it grades institutions across six areas— Capital adequacy, Asset quality, Management, Earnings, Liquidity, and Sensitivity to market risk, culminating in a composite rating from 1 the gold standard) to 5 (on life support). But after decades of frustration over subjective grading, the FFIEC has finally proposed a massive, ground-up overhaul of the framework. Following extensive industry debate regarding supervisory subjectivity and examiner inconsistency, the Federal Financial Institutions Examination Council (FFIEC) issued a comprehensive proposal to overhaul the UFIRS framework. Following the close of the public comment window on August 17, 2026, the proposed revisions are currently pending final agency review and issuance.

  1. Rulemaking Status and Timeline
  • Proposal Publication: The FFIEC published the proposed revisions in the Federal Register to recalibrate supervisory practices across the Federal Reserve, OCC, FDIC, and NCUA.
  • Public Comment Period: The formal notice-and-comment period closed on August 17, 2026.
  • Current Status: The agencies are evaluating stakeholder submissions—spanning banking trade associations, legal analysts, and consumer protection organizations—prior to drafting the final supervisory framework.
  1. The Shift to “Material” Financial Risk

This proposal represents a fundamental shift in how examiners view risk. Bankers have argued for years that regulators need to stop obsessing over subjective, administrative processes and focus on what actually impacts a bank’s bottom line. This appears to be the core philosophy of the new system. In short, the FFIEC wants to hone in on the variables that actually keep the bank alive. The proposal tackles this through eight major changes:

  1. Removing the “special consideration” language that has historically elevated the Management component above the others.
  2. Rewriting the Management component to isolate actual material financial risks.
  3. Drawing a clear line on how specialty exams (IT, BSA, Trust) impact your core CAMELS score.
  4. Linking the Composite Rating definitions directly to financial performance and risk management.
  5. Cleaning up the risk management language in the non-management components (C, A, E, L, and S).
  6. Scrapping open-ended evaluation clauses to rein in regulatory overreach and ensure consistency between examiners.
  7. Standardizing the terminology across all five rating tiers so a “3” means the same thing everywhere.
  8. Bringing the framework out of the 1990s by updating it for modern accounting standards (like CECL) and dropping outdated risk categories.
  9. The “M” is No Longer a Wildcard

If you’ve ever sat through a frustrating exam exit meeting, you know the Management (“M”) component has always been the examiner’s trump card. Current guidelines explicitly tell examiners to give the “M” component “special consideration” when assigning the final composite rating. I have heard it said that a composite will never be a one if Management is a two, regardless of the other ratings. Under the new proposal, that language is entirely gone.

The FFIEC is finally acknowledging that elevating one component distorts the reality of a bank’s health. If your capital is strong, your assets are clean, and your earnings are solid, a subjective markdown on Management shouldn’t automatically tank your overall composite score unless those management weaknesses actually threaten the bank’s safety and soundness. This doesn’t mean your board is off the hook for forward-looking planning. The FFIEC kept language requiring the board and management to effectively plan for changing business conditions and new products. But by deleting the “special consideration” directive, regulators are turning the Management rating into an objective, standalone metric rather than a wild card that can dictate your whole exam.

  1. Stripping Subjective Criteria and Setting Objective Floors

To ensure examiners are grading structural health rather than check-the-box exercises, the FFIEC is tossing out several traditional evaluation factors that were too qualitative, subjective, or redundant. Say goodbye to being graded on:

  • Management depth and succession planning.
  • Responsiveness to recommendations from auditors and regulators.
  • Willingness to serve the legitimate banking needs of the community.
  • The overall performance of the institution and its risk profile.

By stripping these away, the focus shifts entirely to operational discipline.

Even better, the proposal establishes a hard floor: an examiner cannot give you a 3, 4, or 5 in Management based on minor process hiccups. To hit those restrictive tiers, your risk management weaknesses must create clear, quantifiable vulnerabilities:

  • Rating 3: Risk management practices are less than satisfactory and result in material financial risk. This also hits you if your reporting is unreliable, you fail to safeguard assets, or you are in significant noncompliance with the law.
  • Rating 4: Risk management is deficient, resulting in excessive material financial risk that requires immediate action to keep the bank sound.
  • Rating 5: Practices are critically deficient, and the resulting financial risks threaten the bank’s continued viability.
  1. Containing Fallout from Specialty Examinations

We all know the dread of a bad specialty exam (Consumer Compliance, BSA/AML, CRA, IT/Cybersecurity, Trust). Historically, it’s been a coin toss as to whether a ding on your IT exam would automatically contaminate your core CAMELS score.

The proposal draws a much-needed boundary: findings from specialty reviews will only drag down your CAMELS ratings if they represent a material financial risk, severely impact your financial condition, or involve massive legal noncompliance. For example, if an IT exam uncovers a technical vulnerability that doesn’t actually jeopardize consumer data or your financial stability, your CAMELS score is safe. But if that vulnerability opens the bank up to catastrophic fraud or massive regulatory fines? Then it hits your CAMELS rating.

  1. The Standardized Composite Rating Matrix

The FFIEC proposal links composite classifications directly to financial performance and risk management efficacy:

Composite Tier Financial Performance Profile Risk Management Severity
Composite 1 Strong Financial Performance Minor Risk Management Weaknesses
Composite 2 Satisfactory Financial Performance Moderate Risk Management Weaknesses
Composite 3 Less than Satisfactory Performance Inadequate Practices Creating Material Financial Risk
Composite 4 Deficient Financial Performance Severe to Critically Deficient Risk Management
Composite 5 Critically Deficient Performance Viability-Threatening Risk Vulnerabilities

 

  1. Streamlining Risk Management Language & Eliminating Double-Counting

Along with overhauling the Management component, the FFIEC is taking aim at another massive headache for banks: the double-counting of risk management flaws.

Under the current framework, every single component (Capital, Asset Quality, Earnings, Liquidity, and Sensitivity to Market Risk) contains sweeping boilerplate language requiring examiners to evaluate management’s ability to “identify, measure, monitor, and control” risks. Because that language is so broad, examiners frequently take a single operational hiccup and penalize you for it across multiple ratings. The proposal strips out that generic catch-all language. Instead, it embeds specific, highly tailored risk management factors into each individual component.

Take Liquidity, for example:

  • The Old Way: Examiners were tasked with evaluating a vague list of items, including the general “capability of management to properly identify, measure, monitor, and control the institution’s liquidity position…”
  • The Proposed Way: That broad mandate is replaced with a sharp, concrete focus on “the effectiveness of funds management practices, including contingency funding plans and cash flow forecasting.”

By trading open-ended reviews for concrete operational requirements, the FFIEC is showing banks exactly what evidence they need to produce for each rating.

  1. The Operational Catch: Don’t Manage to the Test

While the industry is largely celebrating this shift toward objective, material financial factors, there is an operational catch that bank executives need to watch out for. Because the new framework focuses almost exclusively on factors that directly impact financial performance, there is a real temptation to deprioritize risk management practices that no longer directly drive your CAMELS score. If management views a specific internal control as a mere administrative chore that examiners no longer grade, they might be tempted to underfund or neglect it.

Don’t fall into that trap. Risk is rarely static. If you ignore a low-level control and it snowballs into a material issue, you could face sudden, catastrophic losses. By the time that weakness is big enough to trigger a downgrade under the new materiality threshold, the financial damage is already done. As the FFIEC notes, keeping material financial risks at bay requires continuous investment in your systems, whether an examiner has a specific checkbox for it or not.

  1. Guarding Against Regulatory Creep

If you’ve ever had an examiner invent an ad hoc requirement during an on-site review, you know exactly where it comes from. Historically, rogue expectations were made possible by a tiny phrase buried in the instructions for every CAMELS component: “rated based upon, but not limited to…”

Those four words—but not limited to—gave examiners the cover they needed to introduce unwritten rules.

The FFIEC is targeting this directly by stripping that clause out of every single component description. In its place, they are introducing a strict, overarching rule for the entire framework:

  • Exceptional Circumstances Only: Examiners can only introduce additional evaluation factors under truly exceptional circumstances or if business practices are evolving rapidly.
  • The Materiality Constraint: Any new factor introduced must be absolutely critical to assessing the bank’s financial condition, with an unyielding focus on material financial risk.
  • Mandatory Documentation: If examiners do add a factor, they are now formally required to thoroughly document and explain their rationale in the exam report.

This is a massive victory for regulatory predictability. It establishes a hard boundary that aims to keep exams standardized and focused.

  1. Structural Standardization and Vocabulary Modernization

Finally, the FFIEC is doing some much-needed housekeeping to align the framework with modern accounting standards and ensure examiners are speaking the same language.

Standardizing the Rating Tiers

To eliminate ambiguity, the proposal introduces unified boilerplate terms so that a score in one area carries the exact same weight as a score in another:

Rating Tier Financial Condition Descriptor Risk Management Practices (A, L, SMR)
1 Strong Effective
2 Satisfactory Adequate
3 Less than satisfactory Inadequate
4 Deficient Deficient
5 Critically deficient Specific descriptions removed

 

Updating Outdated Terminology

The FFIEC is also bringing the framework’s vocabulary into the current decade:

  • Transitioning to ACL: Outdated references to the Allowance for Loan and Lease Losses (ALLL) are finally being replaced with Allowance for Credit Losses (ACL), officially aligning CAMELS with CECL accounting standards.
  • Eliminating Reputation Risk: To match current policies held by the Fed, OCC, FDIC, and NCUA, all explicit references to “reputation risk” are being permanently purged from the framework.
  1. Industry Pushback: Fair Lending and Consumer Advocacy Concerns

While financial institutions and industry legal counsel have broadly supported the proposal for eliminating supervisory ambiguity, the changes have drawn significant opposition from public interest organizations, consumer advocates, and community development groups.

The NCRC Formal Critique

In formal comments submitted prior to the August 17, 2026 deadline, the National Community Reinvestment Coalition (NCRC) and allied groups raised major concerns:

  1. Decoupling Community Needs from Core Safety and Soundness: The NCRC strongly opposed stripping the requirement that bank leadership demonstrate a “willingness to serve the legitimate banking needs of the community.” Advocates argue that community reinvestment and fair credit delivery are intrinsic to a bank’s public charter and should remain an explicit pillar of executive leadership evaluations.
  2. Weakening CRA and Fair Lending Accountability: By requiring a finding of “material financial risk” or major statutory noncompliance before specialty reviews impact CAMELS scores, critics warn that discriminatory lending, redlining, or systemic Community Reinvestment Act (CRA) failures will be insulated from safety and soundness ratings unless they result in catastrophic monetary penalties.
  3. Masking Early-Stage Governance Failures: Removing qualitative assessments—including executive responsiveness to auditor recommendations and management depth—creates a lagging indicator of risk. Advocacy groups maintain that waiting for material balance-sheet damage to materialize before penalizing weak governance prevents early regulatory intervention, increasing long-term systemic risk.
  1. The Bottom Line

The FFIEC’s proposed revisions represent the most meaningful structural change to bank supervision we’ve seen in years. By cutting out the subjective fluff, closing the open-ended loopholes, and anchoring the entire rating system to material financial risk, this proposal offers a much more transparent and predictable exam environment. For well-run banks that maintain strong balance sheets and clear risk boundaries, this should reduce the overall compliance headache and shield you from unpredictable examiner whims. Just remember: the regulators are giving you more breathing room to run your bank, but they are placing the responsibility squarely on your shoulders to catch the risks before they hit the bottom line.

Banker FAQs

By Pauli Loeffler

Depositing check payable to an individual into an entity account.

  1. I would like some clarification if it is Ok to deposit a personal check into an LLC account.  I have read that it is not advisable but it is not against the law either.
  2. One reason a person registers a business as an LLC or a Corporation is to separate the assets and liabilities of the individual from the assets and liabilities of the legal entity and prevent the creditors of the individual attaching assets of the entity or creditors of the entity going after the assets of the individual.

What’s in the box… Accessing safe deposit box of deceased lessor.

  1. We have a situation at the bank that I wanted to get some advice on. We had a customer pass away last year. Since that time, we have not heard from the family. They came in this week, but no personal representative has been named as of yet. They are requesting access to the late customer’s safety deposit box, but do not have a key, which means we would have to break into the box. We have allowed access to the families in the past, to look for a will/insurance policies, but they have had keys. I guess my question is, if we are allowed to break into the box, how do protect the contents and/or handle custody of the contents, since they are not owners of the box and have not been named as personal representatives.
  2. This isn’t nearly as big a problem as you think it is under the Section 1308 of the Search Procedure on Death
  3. A lessor shall permit the person named in a court order, or if no order has been served upon the lessor, the spouse, a parent, an adult descendant, or a person named as an executor in a copy of a purported will produced by the person, to open and examine the contents of a safe deposit box leased by a decedent, or any documents delivered by a decedent for safekeeping, in the presence of an officer of the lessor. In addition, the lessor, if so requested by such person, shall deliver:
  4. Any writing purported to be a will of the decedent to the court having jurisdiction of the decedent’s estate according to his or her residence declared in such writing or may, at the option of the bank, be delivered to the person, so long as the bank retains a copy;
  5. Any writing purported to be a deed to a burial plot or to give burial instructions to the person making the request for a search;
  6. Any document purporting to be an insurance policy on the life of the decedent to the beneficiary named therein; and
  7. Any document purporting to be a trust agreement or Declaration of Trust wherein the decedent was the grantor, so long as the bank retains a copy.
  8. No other contents shall be removed pursuant to this subsection until an executor or administrator qualifies and makes claim to the contents, except where the safe deposit box was held by the decedent and his or her surviving spouse or any other person as joint tenants, in which case any part of the contents thereof may be removed by such surviving spouse or other surviving joint tenant.
  9. All contents of a safe deposit box shall be presumed to belong to the lessee(s) of the safe deposit box, and the lessor may rely on that assumption unless and until it receives a court order to the contrary.
  10. The lessor shall be under no duty to conduct an inventory of the contents of the safe deposit box.

The bank will retain a copy of any will or trust agreement.

Those who can request access to the box include the spouse, parent, adult child, grandchild or great grandchild may request access to the box to search for the documents set out in A. If there is a surviving spouse or surviving joint tenants on the box, they may take whatever they like from the box.

While the statute is silent with regard to charging for breaking into the box, I think the bank is free to charge it’s usual fee for re-keying in the event joint tenants or surviving spouse don’t have a key.

Minor as joint owner of account.

  1. I am reaching out for guidance on how we should handle deposit accounts with POD designations or named beneficiaries when the listed beneficiary is a minor at the time the account owner passes away.

 

Based on our preliminary research, it appears that funds cannot be released directly to a minor beneficiary and may need to be paid to a guardian or custodian. However, in the situations we are seeing, we do not have paperwork in place that names a guardian or custodian for the minor at the time of the designation. It appears this may require a court-appointed guardian, but we would appreciate your confirmation and direction.

 

We are currently working on a process change so that minor beneficiaries will no longer be permitted going forward. In the meantime, we do have some existing accounts with minor beneficiaries listed. We recently had a situation where an account owner passed away and there were three beneficiaries, one of whom was a minor. We have also had another similar situation within the past month where a minor came in to claim funds as the named beneficiary.

 

Could you please advise us on the appropriate process for handling these claims? Specifically, we would like guidance on the following:

 

  1. Whether funds payable to a minor POD beneficiary must be released only to a court-appointed guardian or whether there are other permissible options.
  2. What documentation we should require before releasing funds when the beneficiary is a minor.
  3. What language our staff should use when explaining next steps to customers or family members if/when this situation arises so that we are clear, compassionate, and legally accurate.
  4. Whether the same rules and recommended procedures apply to our Texas branches, or whether Texas law requires a different process, documentation, or customer communication.

 

Our goal is to reduce confusion and avoid creating additional burden for families after a loss, while also ensuring we follow the proper legal requirements before releasing funds.

 

  1. If a minor is named as a pay on death beneficiary, a lot depends on the amount of the funds involved not only as POD on a deposit account but from other sources such as an insurance beneficiary. The greater the amount, the more likely formal legal action will be required,

On the other hand, if the funds payable to the minor are minimal, the account owner might simply name a custodian for the minor as well as a successor custodian just in case the custodian dies or becomes incapacitated. If you do that, upon proof of death of the account owner, the custodian can control the funds until the minor reaches the age of 18 but no later than age 21. This will generally solve the problem UNLESS there is a large amount involved or the minor is extremely young. The Oklahoma Banking Code also permits opening an account with the minor as sole owner under Banking Code Section 903.1 https://www.oscn.net/applications/oscn/DeliverDocument.asp?CiteID=76932 The statute allows A parent or legal guardian of a minor to deny the minor’s authority to control, transfer, draft on, or make withdrawals from the minor’s deposit account by notifying the bank or credit union in writing. On receipt of the notice by the bank or credit union, the minor may not control, transfer, draft on, or make withdrawals from the account during minority except with the joinder of a parent or legal guardian of the minor.

 

If the bank chooses to offer minor as sole owner accounts, it will need a photo ID for the minor. If the minor is in middle school or in high school, the bank could use the school ID together with a birth certificate to open the account.

 

I am not licensed to practice law in Texas so I cannot give you any advice in regard to your Texas branches.

 

Garnishment of deceased customer’s account.

  1. We have a garnishment in place on one of our customers who passed away over the weekend. This Garnishment was received earlier in August and a hold was placed on the account upon receipt of the garnishment. The customer promptly filed for an exemption because they receive SSA funds, and the hearing was set for this coming Wednesday 09/02/2026. Now that the customer has passed, should I continue to wait on the hearing and the judge’s ruling? Or how should I proceed?

I reached out to the plaintiff’s attorney, and they informed me that they intend to follow through with the hearing set for Wednesday. They have also asked that I complete and send in my answer so they will have a copy of it for the hearing.

 

  1. My gut reaction is REALLY? I don’t know the amount of the judgment against your deceased customer, but funeral expenses and expenses of the last illness would have to be paid before their claim.