OCC Heightened Standards
Also known as: 12 CFR Part 30 Appendix D
Office of the Comptroller of the Currency's heightened risk governance standards applicable to large national banks above asset thresholds.
OCC Heightened Standards are the prudential governance standards codified in 12 CFR Part 30, Appendix D — the Office of the Comptroller of the Currency's final rule adopted September 2, 2014 (effective November 10, 2014) establishing minimum standards for risk governance frameworks at large national banks, federal savings associations, and federal branches and agencies of foreign banks with $50 billion or more in average total consolidated assets. The Standards arose from OCC post-financial-crisis supervisory experience and the broader regulatory response codified in Dodd-Frank, formalizing supervisory expectations that had previously been articulated through informal guidance. The Standards specify minimum requirements for: risk governance framework (three lines of defense structure, risk appetite statement, risk taxonomy, concentration limits); board responsibilities (active oversight, independent challenge, succession planning); independent risk-management function; and related governance practices. Compliance is enforced through OCC supervisory examinations with potential enforcement actions for non-compliance ranging from supervisory letters to consent orders and civil money penalties.
Core components
- Applicability: insured national banks, federal savings associations, and federal branches and agencies of foreign banks with $50 billion or more in average total consolidated assets (computed quarterly, four-quarter average)
- Risk Governance Framework requirement (Part I of Appendix D): three lines of defense structure (front-line units, independent risk management, internal audit)
- risk appetite statement establishing aggregate and risk-type-specific limits
- risk taxonomy covering all material risks
- concentration risk limits
- risk reporting framework
- Board Responsibilities (Part II): active oversight
- independent challenge of management
- competent membership
- majority of independent directors
- independent risk and audit committees
- succession planning
- Independent risk management function: led by a Chief Risk Officer or equivalent reporting to the CEO and to a board-level committee
- budget and resource independence
- Risk-related talent management: ensure competence in front-line units, independent risk management, and internal audit
- Front-line unit accountability: primary responsibility for managing risks within the unit's activities
- Internal audit independence and competence
- Compliance management framework integration
- Enforcement: OCC examination, supervisory letters, Matters Requiring Attention (MRAs), Matters Requiring Immediate Attention (MRIAs), enforcement actions (consent orders, civil money penalties)
Primary use case
Mandatory minimum governance standards for OCC-regulated banks ≥$50 billion (covers approximately 25-30 institutions including JPMorgan Chase, Bank of America, Wells Fargo, Citibank, US Bank, Truist, Capital One, TD Bank, MUFG, HSBC, BNY Mellon, State Street, Northern Trust, others); examination reference for OCC examiners during supervisory examinations of large banks; internal-governance design template for banks approaching the $50B threshold preparing for Heightened Standards application; reference framework cited by other US banking regulators (Federal Reserve large-bank guidance, FDIC SHELF framework) and international banking supervisors developing parallel governance expectations; academic and professional reference in bank governance, regulatory capital, and post-crisis financial-services regulation literature; input to broader OCC Risk Governance Framework (Comptroller's Handbook on Corporate and Risk Governance) applied to OCC-regulated banks below the Heightened Standards threshold.
Common criticisms
- The $50 billion threshold has been substantially debated — critics argued the threshold is mechanical rather than risk-based, with some smaller institutions presenting substantial risk and some larger institutions with simpler business models not requiring the full Heightened Standards framework
- the 2018 EGRRCPA (Economic Growth, Regulatory Relief, and Consumer Protection Act) raised the threshold for several Dodd-Frank requirements but did not change Heightened Standards applicability, producing regulatory-threshold-fragmentation across US banking supervision
- the three-lines-of-defense structure embedded in Heightened Standards has been substantially critiqued by post-2020 governance scholarship — the IIA's own 2020 Three Lines Model update moved away from 'defense' framing toward more flexible accountability model, while Heightened Standards remains anchored in the earlier framing
- documentation burden has been substantially documented as substantial — the requirement for risk taxonomy, risk appetite statement with aggregate and risk-type limits, three-lines accountability, and ongoing reporting infrastructure produces compliance costs that some banks have argued exceed risk-management benefits
- Wells Fargo cross-selling scandal (2016) and subsequent OCC enforcement actions against Wells Fargo, JPMorgan, others demonstrate that Heightened Standards compliance does not prevent governance failures — documentation can exist while substantive practice is weak, the longstanding 'paper compliance' critique applied here
- concentration limits and risk appetite statement requirements interact awkwardly with growth ambition, particularly during low-rate / high-growth periods when bank boards face pressure to expand limits
- international interoperability with home-country supervision frameworks for foreign branches and agencies subject to Heightened Standards produces duplicative obligation
- the Standards' interaction with Federal Reserve large-bank governance guidance (SR 21-3, SR 16-11) and FDIC guidance produces overlapping supervisory expectations that banks must reconcile
- examiner discretion in applying Standards to institutions of different business models produces inconsistent supervisory practice
- talent-management and CRO-independence requirements have been argued to operationalize bureaucratic structure without substantive cultural change.
Lineage
- Siblings
- OCC Risk Governance Framework, Three Lines Model, Basel III, COSO ERM
- Derived from
- Dodd-Frank Act