OCC Risk Governance Framework
Also known as: OCC Heightened Standards Risk Governance
Risk governance component of the OCC Heightened Standards specifying board, management, and three-lines requirements for large banks.
The OCC Risk Governance Framework refers to the comprehensive supervisory framework articulated by the Office of the Comptroller of the Currency for risk governance at OCC-regulated banks, embodied principally in the Comptroller's Handbook 'Corporate and Risk Governance' booklet (current version July 2019, updating prior January 2014 version) and the formal regulatory standards in 12 CFR Part 30 Appendix D (Heightened Standards) for banks ≥$50 billion. Where Heightened Standards is the specific binding regulation applicable to large banks, the broader OCC Risk Governance Framework includes supervisory expectations applied across all OCC-regulated national banks, federal savings associations, and federal branches of foreign banks (approximately 1,000 institutions, the substantial majority of which are below the $50B Heightened Standards threshold). Core elements include three-lines-of-defense governance structure, board oversight expectations, risk appetite framework, independent risk management, internal audit, compliance management, and integration with broader interagency banking-regulatory frameworks (Basel III capital, FFIEC IT examination, BSA/AML, fair-lending). The Framework is applied through OCC examinations and the Risk Assessment System (RAS).
Core components
- Three lines of defense governance structure: front-line units (first line, primary risk-taking and risk management)
- independent risk management (second line, oversight and challenge)
- internal audit (third line, independent assurance)
- Board responsibilities: strategic oversight, risk appetite approval, executive accountability, independent challenge, succession planning, board-committee structure
- Risk appetite framework: aggregate and risk-type-specific limits, integration with strategic planning and capital planning, ongoing monitoring
- Independent risk management function: Chief Risk Officer or equivalent, organizational independence, resource adequacy, board reporting
- Compliance management framework: integration with risk governance, BSA/AML compliance, fair-lending, consumer-protection compliance
- Internal audit framework: independence, competence, risk-based audit planning, board-audit-committee reporting
- Talent management: ensuring competence in risk-related roles, succession planning for key positions
- Integration with related supervisory frameworks: Heightened Standards (12 CFR Part 30 Appendix D for ≥$50B banks), Basel III capital, FFIEC IT examination, BSA/AML, fair-lending, consumer-protection
- Risk Assessment System (RAS): OCC's examination rating approach producing component ratings for capital, asset quality, management, earnings, liquidity, and sensitivity (CAMELS-like rating for OCC-regulated institutions)
- Examination cycle: regular OCC examinations with Matters Requiring Attention (MRAs), Matters Requiring Immediate Attention (MRIAs), and enforcement-action escalation as supervisory tools
Primary use case
Supervisory framework applied to all OCC-regulated national banks, federal savings associations, and federal branches and agencies of foreign banks (approximately 1,000 institutions); examination reference for OCC examiners during supervisory examinations; self-assessment reference for OCC-regulated banks designing or maturing risk-governance frameworks; community-bank reference: while Heightened Standards applies to ≥$50B banks, the broader Risk Governance Framework is applied to community and mid-size banks with proportionality to size and complexity; intellectual reference for parallel governance frameworks at other federal banking agencies (Federal Reserve, FDIC, NCUA) and at state banking regulators; input to interagency examination coordination through FFIEC and shared examination procedures; academic and professional reference in bank governance, post-2008-crisis regulatory-reform, and US financial-services supervision literature.
Common criticisms
- The Risk Governance Framework's relationship to Heightened Standards produces ongoing applicability questions — Heightened Standards is the specific binding regulation for ≥$50B banks, while the Comptroller's Handbook governance expectations apply to all OCC-regulated banks, with examiner discretion in applying framework elements proportionately to institution size and complexity producing variation in supervisory practice
- smaller community banks have argued the Framework's documentation and structural expectations are disproportionate to their actual risk profile, producing compliance burden inconsistent with regulatory-burden-reduction policy commitments
- the three-lines-of-defense structure embedded in OCC expectations follows the older IIA (Institute of Internal Auditors) model that the IIA itself updated in 2020 toward a more flexible Three Lines Model — OCC supervisory expectations have not formally adopted the updated framing, producing potential terminological and conceptual misalignment
- substantial governance failures at OCC-regulated banks (Wells Fargo cross-selling 2016, Wells Fargo broader compliance issues, JPMorgan London Whale 2012, Citigroup 2020 OCC consent order on data and risk management) demonstrate that framework compliance does not prevent governance failures — documentation can exist while substantive practice is weak
- the Risk Assessment System's examination rating produces consequential supervisory actions but the criteria for specific component ratings are not transparently specified, producing examiner-discretion variation
- integration with Federal Reserve large-bank supervision (SR letters), FDIC supervision (FILs), and CFPB consumer-protection supervision produces overlapping regulatory expectations that bank programs must reconcile
- international interoperability with Basel Committee corporate governance guidance (BCBS Corporate Governance Principles 2015), UK PRA SS5/16, EU EBA governance guidelines is conceptual rather than formal
- the Framework's evolution has been slower than industry and technology change — substantial bank-business-model evolution (digital banking, embedded finance, AI/ML deployment, cryptocurrency activities) requires supervisory framework adaptation that has been incremental
- the OCC's 2020 fintech-charter controversy and broader OCC engagement with novel bank business models has produced framework-applicability questions for non-traditional OCC-regulated entities.
Lineage
- Siblings
- OCC Heightened Standards, Three Lines Model, Basel III, COSO ERM, Sarbanes-Oxley