Skip to main content
Should You Scale Back Risk Controls Just Because You Can?Enterprise Risk Management
5 min readFor Risk Managers

Should You Scale Back Risk Controls Just Because You Can?

The FDIC's proposed threshold changes under the Federal Deposit Insurance Corporation Improvement Act (FDICIA) will exempt hundreds of banks from mandatory internal control assessments and audit committee independence requirements. The Part 363 applicability threshold is rising from $500 million to $1 billion, and the internal control assessment threshold is increasing from $1 billion to $5 billion.

For risk managers, this presents a choice: interpret regulatory relief as permission to reduce investment in risk governance, or use the opportunity to build a more resilient framework. This checklist guides you through the critical decisions you'll face as these thresholds take effect in April 2025.

Prerequisites

Before working through this checklist, confirm:

  • Your institution's current total asset position and three-year growth trajectory
  • Which FDICIA thresholds currently apply to your organization
  • Your board's documented risk appetite and tolerance statements
  • Existing control frameworks and their maturity level (ad hoc, defined, managed, or optimized)

Compliance and Strategic Risk Checklist

1. Determine Your Threshold Status Under the Proposed Rule

Review your institution's total assets against the new thresholds: $1 billion for Part 363 applicability and $5 billion for internal control assessments over financial reporting (ICOFR).

Good looks like: A documented analysis showing your current position, projected position in 12, 24, and 36 months, and which requirements will apply at each stage. Your CFO and Chief Risk Officer have reviewed and signed off on this assessment.

2. Assess Whether Regulatory Relief Equals Operational Safety

Just because ICOFR filing requirements may no longer apply doesn't mean your control environment is adequate for your actual risk profile. Evaluate cyber threats, third-party vendor concentrations, liquidity risks, and operational vulnerabilities independent of compliance mandates.

Good looks like: A board-level discussion document that separates "what we must do" from "what we should do," with risk-based justification for each control you maintain or implement regardless of regulatory status.

3. Document Your Rationale for Any Control Reductions

If you're planning to scale back controls or assessments because you're under the new thresholds, create a formal record explaining why those controls are no longer necessary for your risk profile.

Good looks like: A risk committee memo that explains each proposed reduction, the residual risk you're accepting, and the monitoring mechanisms you'll use to detect if that decision needs to be reversed. Include board approval.

4. Map Your Current Controls to Business Objectives, Not Just Regulations

Review your existing control framework and identify which controls exist solely for FDICIA compliance versus which ones support strategic objectives, protect against known vulnerabilities, or satisfy stakeholder expectations.

Good looks like: A control inventory showing purpose, owner, frequency, and business rationale for each control. Controls marked "compliance only" should trigger a separate risk assessment before removal.

5. Evaluate Stakeholder Expectations Beyond Regulatory Minimums

Your regulators may have eased requirements, but your board, investors, customers, and examiners still expect robust governance. Survey or interview key stakeholders about their risk oversight expectations.

Good looks like: Documented feedback from your audit committee chair, largest investors, and primary regulator about their expectations for control rigor, regardless of formal thresholds. Use this to set your internal baseline.

6. Implement Scalable ERM Infrastructure Before You Need It

If you're approaching the $5 billion ICOFR threshold, deploying an enterprise risk management platform now prevents the scramble that comes with last-minute compliance buildout. Even if you're well below thresholds, a centralized risk register and control library streamline operations.

Good looks like: A single platform that houses your risk register, control library, compliance obligations, and incident log. You can generate board reports in under an hour, and new risks are logged within 24 hours of identification.

7. Build Control Testing into Business-as-Usual Operations

Whether or not you're required to file ICOFR assessments, periodic control testing identifies weaknesses before they become losses. Automate testing workflows where possible and assign clear ownership.

Good looks like: A testing calendar with assigned owners, completion rates above 95%, and documented remediation plans for any control failures. Your audit committee receives a quarterly dashboard showing testing coverage and findings.

8. Create a Threshold Trigger Plan for Growth Scenarios

If your institution is growing, you'll eventually hit the new thresholds. Map out what needs to be in place six months before you reach $1 billion or $5 billion in assets.

Good looks like: A project plan showing required hires, system implementations, policy updates, and board training needed to meet ICOFR or Part 363 requirements. Your plan includes budget estimates and lead times for vendor selection.

9. Link Risk Data to Strategic Planning Processes

ERM isn't just a compliance exercise; it's strategic intelligence. Ensure your risk register informs capital allocation, M&A due diligence, product launches, and market expansion decisions.

Good looks like: Your strategic planning committee reviews a risk heat map before approving new initiatives. You can demonstrate at least one strategic decision in the past year that was modified based on risk assessment findings.

10. Establish Clear Escalation Paths for Emerging Risks

Cyber incidents, third-party failures, and liquidity pressures don't wait for quarterly board meetings. Define when and how emerging risks get escalated to senior management and the board.

Good looks like: A documented escalation matrix showing risk severity thresholds, notification timelines, and decision authority. You've tested this process at least once in the past 12 months through a tabletop exercise.

Common Mistakes

Treating regulatory relief as a signal to reduce investment. The FDIC is adjusting thresholds to reflect inflation and consolidation, not because risks have diminished. Banks that interpret relief as permission to cut corners often face operational failures that cost far more than the controls they eliminated.

Waiting until you're at threshold to build capacity. If you're at $4 billion in assets and growing, you don't have time to implement an ERM platform, hire staff, and train your board once you hit $5 billion. Start 18 months early.

Confusing control documentation with control effectiveness. Just because you're no longer filing ICOFR doesn't mean your controls work. Test them. Weak controls create losses regardless of whether you report them to regulators.

Ignoring stakeholder expectations. Your regulator may have eased requirements, but your board, investors, and customers haven't. Governance gaps damage reputation and invite scrutiny even when you're technically compliant.

Next Steps

Review this checklist with your Chief Risk Officer and CFO within 30 days. Assign ownership for each item and set completion deadlines. Schedule a board-level discussion on your institution's risk governance philosophy: are you managing to regulatory minimums or to your actual risk profile?

If you're under the new thresholds, use the compliance breathing room to modernize your risk infrastructure. If you're approaching them, start building capacity now. Either way, the question isn't what you can stop doing, it's what you should start doing to ensure resilience as your institution grows.

You Might Also Like