DiGi Advisory
All insights

Regulatory Commentary

Your Policy Library Points at Documents That Moved: A Test of Whether It Was Ever Maintained

By Thomas DiGiovanni, Partner and Founder

September 1, 20266 min read

Guidance was reissued under its original number, a federal directive the industry had borrowed was revoked, and the handbook definition of risk changed through one line on a webpage. None of it required an institution to act, which is why none of it surfaces until someone asks where a requirement came from.

On June 2, 2026, the Office of the Comptroller of the Currency (OCC), the Federal Deposit Insurance Corporation (FDIC), and the Federal Reserve reissued 15 interagency guidance documents with every reference to reputation risk removed. The guidance kept the numbers of the bulletins that first transmitted it. The Interagency Statement on Elder Financial Exploitation is still OCC Bulletin 2024-34. Only the transmittal is new, OCC Bulletin 2026-23, and the agencies asked institutions to do nothing.

On its own, a small problem. In aggregate, not small at all. This year has been an unusually heavy one for supersession, and most of it arrived the same way: quietly, without a request, and without disturbing the reference anyone would use to find it.

The reissue kept the number

The list runs across consumer protection, credit, and technology. Among the 15 are Interagency Guidance on Risk Management of Remote Deposit Capture (OCC Bulletin 2009-4), the Joint Statement on Cyber Attacks Involving Extortion (2015-40), and Sound Practices to Strengthen Operational Resilience (2020-94). Sound Practices was written for the largest and most complex banking organizations, and Bulletin 2026-23 disposes of the scope question in one line: the reissued documents apply to community banks to the same extent the original issuances did. Precise, and exactly the kind of sentence nobody in a policy library goes back to check.

The remote deposit capture entry carries its own lesson. The OCC's list flags Bulletin 2009-4 as rescinded, because the OCC withdrew the transmittal in October 2021 and moved the guidance into the Comptroller's Handbook. An institution citing 2009-4 in a deposit operations policy points at a rescinded transmittal of superseded text, and has done so for nearly five years. More is coming, because the agencies expect to remove any further references to reputation risk as their review continues.

Most institutions can produce a policy register naming every governing document by number. Far fewer can show when each of those citations was last compared against what the document currently says. Citation currency belongs in the policy as an attribute, with a named owner and an as-of date, kept separate from the content review. A policy can be reviewed on schedule, approved by the right committee, and still assert a requirement its source removed.

The revocation moved the clock

On June 10, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive (BOD) 26-04, Prioritizing Security Updates Based on Risk, which supersedes and revokes both BOD 19-02 and BOD 22-01. BOD 22-01 was the Known Exploited Vulnerabilities (KEV) catalog directive. It bound federal civilian executive branch agencies and never bound a bank or a credit union. It became the industry benchmark regardless, and vulnerability management standards across financial services adopted its model close to verbatim: remediate KEV catalog entries by the CISA-assigned due date.

BOD 26-04 replaced fixed due dates with risk tiering across four variables: public exposure, KEV listing, whether an adversary can automate exploitation, and whether exploitation yields partial or total control. KEV listing went from trigger to one input of four. The exposure for a supervised institution is not non-compliance with a directive nobody was subject to. It is an internal standard describing its remediation clock by reference to a mechanism no longer in operation, in a control area where the Federal Financial Institutions Examination Council (FFIEC) already expects documented, risk-based prioritization.

The remedy is to reconcile the standard's clock to its actual source. Where the institution chose the KEV due-date model on its own judgment, the standard should say so. Where a federal directive set it, the directive is gone and the rationale needs rewriting. The institutions handling this well are not the ones with the largest budgets. They are the ones who can explain why the clock reads what it reads.

The definition changed and no bulletin carried it

In February 2026, the FFIEC updated the Information Technology Examination Handbook to remove references to reputational risk, consistent with Executive Order 14331 of August 7, 2025. The handbook had defined risk as the potential for events to have an adverse effect on a financial institution's earnings, capital, or reputation. It now stops at earnings or capital, and reputation no longer appears among the risk categories listed for regulatory purposes. The announcement was one line on the FFIEC's What's New page. No OCC bulletin carried it, no FDIC letter, no Federal Reserve supervisory letter, so it never reached the channels most institutions actually monitor.

This is the handbook-wide definition of risk, and institutions lifted it verbatim for a defensible reason: it was the examiner's own. It appears word for word across policy libraries, which now define risk in terms the source has abandoned. The Cybersecurity Assessment Tool is the better-behaved companion case, sunset on August 31, 2025 with a year of notice and with alternatives named including the National Institute of Standards and Technology Cybersecurity Framework 2.0, and a year on, assessment methodologies still cite it by name.

Anything lifted from an external document, whether a definition, a control taxonomy, or a maturity scale, should carry the source and the as-of date beside it. The recheck then becomes mechanical rather than archaeological.

What a policy library actually claims

Not every change lands the same way. On August 25, 2026, seven agencies rescinded the Interagency Statement on Special Purpose Credit Programs under the Equal Credit Opportunity Act and Regulation B. The Federal Reserve signed the original and did not join that notice. It withdrew its own Consumer Affairs letter, CA 22-2, separately on August 21, four days earlier and through a different channel, surfacing as a banner added to the top of an existing letter page. Same guidance, same outcome, two channels, one of them watched. A register worth keeping notes which agency's version of a joint issuance governs the institution, not only the subject matter.

Credit unions have their own version arriving. Eleven National Credit Union Administration final rules take effect on September 8, 2026, and four of them rescind Interpretive Ruling and Policy Statements 06-1, 08-2, 10-1, and 11-02. Charter and field-of-membership policies cite those numbers by name.

A policy library is a set of claims. Each one asserts what the institution is required to do and where the requirement came from. The first half gets reviewed on a cycle, approved, and evidenced. Everyone assumes the second half holds still. This year it did not. The agencies rewrote guidance in place, revoked a directive the industry had borrowed, changed a definition through a channel nobody monitors, and unwound a joint statement in two pieces four days apart.

None of it obligated an institution to act, which is exactly why none of it surfaces until someone asks where a requirement came from and the honest answer is a document nobody has opened since it changed. The question is not whether the policies were reviewed. It is whether anyone confirmed the documents still say what the policies claim. Name the source. Name the date it was taken. Name who checks it. Name how many were checked this year.

Questions this raises

How often should policy citations be checked against their sources?

There is no supervisory cadence prescribed for this, which is part of why it goes undone. What the 2026 changes argue for is decoupling it from the content review cycle. An annual policy review confirms the content still describes how the institution operates, and says nothing about whether the cited source still reads the way it did when it was cited. A workable approach is a fixed annual sweep of the register, plus an out-of-cycle check on any document whose issuing agency has announced a review in progress. The agencies stated in June 2026 that they were continuing to review interagency documents and expected to remove further references to reputation risk, which is advance notice that the affected citations will move again.

Who should own citation currency if the policy already has a content owner?

The content owner is the wrong default, because the skill and the trigger are both different. A business owner knows whether the policy still reflects how the institution operates. Knowing that OCC Bulletin 2009-4 was withdrawn in October 2021 and its guidance folded into the Comptroller's Handbook requires someone watching issuance channels rather than operations. The split that works is to leave the content owner accountable for what the policy says, and to name a single role, usually in the second line of defense, accountable for confirming that every citation in the register still points at live text and for recording the date each was last checked.


Back to all insights

A 30-minute triage call to find the fastest path.

Start a Conversation