The risk environment for financial institutions isn't slowing down. If anything, Q3 2026 has made one thing clear: It's not just how your organization identifies emerging risks — it's how you respond to them.
Identifying risk means keeping your eyes open to insights from trusted industry partners, regulatory monitoring, software tools, internal discussions, and enforcement actions, which remain one of the clearest signals of where regulators are focused and what gaps they're finding in the field.
This update covers nine developments shaping the compliance and risk landscape right now:
- AI Governance
- AI in Third-Party Risk Management
- State Regulatory Fragmentation
- Consumer Complaints as Risk Intelligence
- Real-Time Payments and Fraud Risk
- Fair Lending in a Changing Regulatory Environment
- BSA/AML Enforcement
- Lending Risks
- Stablecoins
- Building a Compliance Program That Can Keep Up
Related: Watch the webinar for a full overview of Q3 emerging risks.
AI Governance: From Frameworks to Execution
Financial institutions (FIs) have more AI governance guidance than ever before, with several frameworks finalized in 2025 and 2026:
- NIST Artificial Intelligence Risk Management Framework (AI RMF)
- Financial Services AI Risk Management Framework (FS AI RMF)
- Freddie Mac AI governance requirements
- FS-ISAC sector risk advisory
- Revised interagency model risk management guidance (SR 11-7 replacement)
- State-level AI rules, including California, Massachusetts, and New York
For most FIs, execution of these frameworks is the problem. The Ncontracts 2026 TPRM Survey Report found that only 9% of organizations have identified and documented which vendors use AI.

Inventory Everything
You can't govern what you can't see. Governing AI risk means cataloging every AI tool in use, not just the ones your technology team deploys, but also AI embedded in vendor platforms, customer-facing tools, and back-office systems. Shadow AI is a major source of exposure. When employees use consumer-grade tools for work tasks without IT or compliance awareness, those tools bypass your procurement process, so they don't get vetted for data handling and won't show up in your model inventory unless something goes wrong.
Your AI inventory should capture what each tool does, what data feeds it, what decisions it influences, and who owns it. Risk tier each tool based on its potential impact on customers, credit decisions, or regulatory exposure, and apply governance controls proportionate to that tier.
Related: What is AI Auditing and Why Does It Matter?
Designate an AI Governance Owner
Someone needs to own AI risk at your organization. That means designating an AI governance officer or assigning explicit oversight responsibilities to an existing role. That person should stay current on emerging regulations, own the policy framework, and ensure training reaches staff, management, and the board.
The major frameworks consistently flag four risk categories: bias and fairness, transparency and explainability, data quality, and security and privacy. Your AI governance program should address all of them.
Related: AI Governance and Risk Management for Financial Institutions
Make Sure the Policy Covers What Employees Do
An AI policy that covers enterprise tools but not consumer-grade AI tools, such as ChatGPT and other large language models (LLMs), is incomplete. A policy should define acceptable use, prohibit inputting sensitive customer or institutional data into unapproved tools, and establish a review process for inputs and outputs. Training needs to reach the people making those decisions, not just sit in a policy document.
Related: Can Your AI Explain Itself? Black Box AI vs. Glass Box AI
AI in TPRM: What Due Diligence Looks Like Now
Most vendor due diligence questionnaires were built before AI became a standard feature in vendor products, so they don't ask the right questions about how AI is deployed, what data feeds it, or how outputs are validated. Contracts rarely define AI responsibilities explicitly enough to hold vendors accountable when something goes wrong.
AI-driven systems also create new single points of failure. If a vendor's AI-powered fraud detection or loan origination system (LOS) goes down, the impact on your operations and your customers is immediate. Your business continuity planning needs to anticipate these issues.
Here are three areas to address now if you haven’t already:
- Evaluate vendor AI governance. Ask vendors how they govern their AI systems, how outputs are validated, and how bias is monitored. If they can't answer, that's a finding.
- Update contracts. AI responsibilities need to be explicit: data standards, security requirements, monitoring obligations, and notification requirements when vendors make material changes to AI-driven features. Some FIs are adding AI-specific addendums to existing agreements to cover AI roles and responsibilities as an interim step.
- Extend ongoing monitoring. AI systems drift. Build AI-specific performance indicators into your vendor monitoring program, particularly for consumer-facing decisions. Confirm your business continuity plan accounts for AI-driven system outages.
Related: Using AI in Financial Services: Best Practices and Red Flags
State Regulatory Fragmentation: Compliance Follows Your Customers
Federal regulatory activity gets most of the attention, but state regulators are moving fast and, in many cases, setting a higher bar for compliance. The challenge is managing a patchwork of requirements across AI governance, cybersecurity, privacy, and consumer protection that varies by product, service, and where your customers are located.
California has finalized automated decision-making restrictions under the amended California Consumer Privacy Act (CCPA). Massachusetts has pursued AI-related disparate impact enforcement independently of federal posture. New York's 23 NYCRR Part 500 cybersecurity amendments establish mandatory board oversight and 72-hour vendor breach reporting. Requirements around elder financial exploitation vary further by state and aren't always aligned with federal guidance.
Build your compliance program to the highest standard you'll face in any jurisdiction where you operate or serve customers. Policies, training, and reporting structures should reflect location-specific requirements, not just federal minimums.
Related: How to Keep Up with State Regulations
Consumer Complaints as Risk Intelligence
Consumer complaint data tells you where your compliance program is breaking down before an examiner does. The FDIC's 2025 data showed a 21% increase in complaints year over year, with third-party providers involved in nearly 6,356 cases, a 48% jump from the prior year. That data directly informs examination scoping.
The FIs best positioned going into examinations aren't just tracking volume. They're mapping complaints against products, channels, and regions to identify patterns. Findings feed into risk assessments. Complaint trends drive policy updates before they surface as examination findings.
If your complaint management program is still operating as a customer service function rather than a compliance intelligence tool, that's worth fixing before your next examination.
Related: What is Complaint Management and How Does It Work?
Real-Time Payments and Fraud Risk
Real-time payments have created a real-time fraud problem. Business email compromise, payroll attacks, account takeover, and social engineering schemes are all exploiting faster payment rails. The window to detect and stop fraud is measured in seconds, not hours.
The Nacha Automated Clearing House (ACH) fraud monitoring rules that took effect in 2026 (Phase 2 started June 22, 2026) require financial organizations to move from reactive to proactive fraud monitoring, establishing risk-based processes to identify ACH entries initiated through fraud. This includes false pretenses cases where the account holder authorizes the payment but was deceived into doing so.
Transaction monitoring and behavioral analytics are the first line of defense, and employee training and customer education are the second. When AI-powered vendor tools are involved in fraud detection decisions, your organization owns the outcome regardless of where the failure started.
Related: How to Create Dynamic BSA/AML/CFT Risk Assessments
Fair Lending in a Changing Regulatory Environment
Federal fair lending enforcement has shifted, but fair lending obligations haven't. The Regulation B final rule eliminated disparate impact liability under the Equal Credit Opportunity Act (ECOA), and the mortgage executive order signals further deregulatory movement. Neither changes what good compliance looks like.
Fair lending compliance is like a seat belt. You don't wear it because you expect to crash. You wear it because the consequences of not wearing it when something goes wrong are severe.
The risk of inaction runs in multiple directions. The Fair Housing Act still carries disparate impact liability, and state regulators in Massachusetts, California, New York, and New Jersey are actively enforcing fair lending requirements independent of federal posture. Private litigation is accelerating. The 21st Century ROAD to Housing Act and new immigration status underwriting guidance added fresh complexity in August 2026.
The practical standard hasn't changed. Monitor outcomes, pricing, underwriting, and complaints. Test regularly, report to the board, and train staff. When in doubt, do what's best for your customers and your community. That's a compliance program that holds up regardless of which direction the regulatory environment shifts next.
Related: Mortgage Industry Update 2026 Webinar
Other Emerging Risks Worth Watching
Three additional risk areas are worth keeping on your radar heading into Q4.
BSA/AML Enforcement
Bank Secrecy Act and anti-money laundering compliance have been a consistent enforcement focus over the past three months, with different regulators each taking action. August 2026 brought two significant enforcement actions that illustrate the pattern: a $79 million forfeiture case tied to inadequate customer due diligence and a $9.7 million settlement where insider influence overrode a bank's own compliance team.
Related: August 2026 Regulatory Update: 21st Century ROAD to Housing Act & More
Lending Risks
The Federal Reserve's June 2026 Supervision and Regulation Report flagged credit stress worth monitoring across several areas. Private credit delinquency data looks manageable for now, but high-profile defaults have prompted banks to revisit collateral management practices. Consumer delinquencies in credit cards and auto loans are trending up. Agricultural lending faces pressure from higher production costs, and CRE delinquency remains elevated, particularly for office and multifamily concentrations. The OCC also recently updated its Lending and Loan Portfolio Risk Management booklet. If any of these areas represent concentration risk for your FI, now is a good time to review your risk assessments.
Stablecoins
The GENIUS Act, signed into law in July 2025, established the first federal regulatory framework for payment stablecoins, but regulators are still working through the rulemaking process. The OCC has proposed implementing rules, and the FDIC has proposed new reporting forms requiring regular disclosure.
For most community banks, direct exposure is limited for now. The regulatory infrastructure is being built regardless of whether your FI participates, and that's worth tracking heading into 2027.
Building a Compliance Program That Can Keep Up
AI shows up in nearly every risk area covered in this update. That's not a coincidence. It's a clear signal of where the compliance environment is heading and why the organizations that build AI governance into their programs now, rather than waiting for prescriptive rules, will be better positioned when those rules arrive.
But AI governance is only one part of the equation. The deeper thread is speed. Regulations are changing faster than most compliance programs were built to absorb. The organizations that navigate this environment well aren't just the ones with the strongest programs — they're the ones with the most agile ones. That's effective change management.
Regardless of which risks are most pressing for your organization, this eight-step framework will help you move from awareness to action consistently:
- Change identification. Know where your regulatory intelligence is coming from and how quickly it reaches the right people.
- Impact analysis. Assess what the change requires of your organization and who needs to know.
- Identify responsible parties. Assign clear ownership before the work starts.
- Create action plans. Document what needs to change and what's missing to get there.
- Update risk assessments. Every significant regulatory change should trigger a review.
- Communicate and train. Changes don't stick without deliberate communication to the people affected.
- Test. Verify the change was implemented correctly before closing it out.
- Monitor post-implementation. Confirm the change is working as intended and flag unintended consequences.
If this update made you think about gaps in your compliance program, the next challenge is often making the case for the tools to address them. Download the free guide to getting buy-in for compliance software.

