The OCC updated its BSA/AML examination procedures in March 2026 and published the revisions to the Bank Secrecy Act/Anti-Money Laundering Examination Manual. Examination manual updates do not get the same attention as final rules or regulatory guidance documents, but they matter significantly because they define what examiners actually look for during BSA/AML reviews. Understanding what changed in the procedures is often more practically useful than tracking rulemaking.
The March update made changes in several areas, but three stand out as likely to surface in the next examination cycle for national banks and federal savings associations: transaction monitoring calibration documentation, customer risk rating methodology review, and the treatment of negative news screening in enhanced due diligence.
Change 1: Transaction Monitoring Calibration Documentation
The OCC's examination procedures for transaction monitoring have always included a review of whether the institution's system is calibrated appropriately for its risk profile. What changed in the March update is the documentation specificity expected for that calibration process.
The revised procedures call for examiners to review documentation of the calibration rationale: why specific scenarios were tuned to specific thresholds, what data was used to support those thresholds, and when the calibration was last reviewed. This is a shift from examining whether calibration documentation exists to examining whether it demonstrates reasoned judgment tied to actual transaction data.
Many institutions maintain a calibration log that records when thresholds were changed and by how much. That record addresses the "what changed and when" question. The revised expectation adds the "why" question: what analysis supported the decision to set the threshold where it was set, and what would prompt the institution to revisit it?
For institutions running rule-based transaction monitoring systems, this means the calibration documentation should include a baseline behavioral analysis or peer comparison that justifies the threshold levels relative to the institution's customer base. For institutions running model-based monitoring, the model validation documentation typically covers this ground, but it needs to be retrievable in the context of an examination request, not just filed with model risk management.
A community bank running a transaction monitoring system for its commercial customer base should be able to point to documentation showing: the transaction volume and distribution for the customer segments the system monitors, the threshold levels set for each alert scenario, the rationale for those thresholds relative to that volume and distribution, and the date of the last calibration review. If any one of those four elements is missing, the documentation is incomplete under the revised examination standard.
Change 2: Customer Risk Rating Methodology Review
The revised procedures place renewed emphasis on the customer risk rating methodology itself, not just the results it produces. Examiners have always reviewed whether high-risk customers were subject to enhanced due diligence. The March update expands that review to include an evaluation of whether the methodology for assigning risk ratings is documented, reasonable, and consistently applied.
The specific additions to the examination procedures: examiners are now expected to ask for documentation of the factors used in the risk rating model or matrix, the weight given to each factor, and the evidence basis for those weights. They are also expected to sample the application of the methodology across a population of customer risk ratings to test whether the documented methodology is actually being applied consistently in practice.
This creates an alignment risk for institutions that have a written risk rating policy that describes one methodology, a risk rating tool that implements a somewhat different methodology, and front-line staff applying informal judgment on top of both. That kind of layered inconsistency has always been a BSA/AML weakness; the revised procedures make it more directly testable during examination.
We are not suggesting that customer risk rating methodologies need to be entirely algorithmic to satisfy the revised standard. Qualitative judgment is appropriate and expected in customer risk assessment. What the revised procedures demand is that the methodology, including the role of qualitative judgment, is documented, and that the documentation reflects actual practice rather than an idealized process that does not match what front-line staff do.
Periodic Review of Risk Ratings
The updated procedures also add more specificity around the periodic review of existing customer risk ratings. Previously, examination procedures noted that institutions should have a process for periodic risk rating review. The March update clarifies that the review process should be event-triggered in addition to periodic, meaning the institution should have documented triggers that would prompt a risk rating reassessment outside the standard review cycle. Changes in account activity patterns, new beneficial ownership information, and adverse news findings are examples of event triggers that the revised procedures specifically call out.
Change 3: Negative News Screening in Enhanced Due Diligence
The third area of change involves negative news screening as a component of enhanced due diligence for high-risk customers. The examination procedures have previously noted that EDD may include negative news searches. The March update strengthens that to indicate that for customers subject to EDD, negative news screening should be a documented component of the initial EDD review and of periodic EDD refresh cycles.
Two practical implications. First, institutions that conduct negative news searches informally, where an analyst googles a customer name and notes nothing notable before approving an account, now face a higher documentation expectation. The search methodology, the sources queried, the date of the search, and the conclusions drawn should be recorded in a retrievable format associated with the customer's EDD file.
Second, the periodic EDD refresh cycle should include a negative news search component, not just a review of account activity. The timing of the refresh cycle for high-risk customers is subject to institutional judgment, but the revised procedures indicate that examiners will review whether the refresh actually covered negative news sources and not just internal account metrics.
For institutions using third-party due diligence screening platforms, the screening run history and results should be retained in a way that links to the customer record. Platforms that provide batch screening but store results separately from the customer risk file create a documentation gap that is harder to close in examination.
What to Do Before Your Next BSA/AML Exam
These three changes point to the same underlying expectation: documented process that reflects actual practice, supported by retrievable evidence. The institutions that struggle in BSA/AML examinations are rarely the ones with weak programs; more commonly they have adequate programs that are poorly documented or inconsistently executed.
A practical pre-exam review against the March update should ask three questions. First, does your transaction monitoring calibration documentation address the rationale question, not just the history question? Second, does your customer risk rating methodology documentation describe how the methodology is actually being applied, including the role of qualitative judgment and the event triggers for reassessment? Third, does your EDD file population contain retrievable records of negative news searches, both at initial onboarding and at each periodic refresh?
If the answer to any of those is uncertain, the gap is worth addressing before examiners ask. Post-exam remediation of documentation gaps is significantly more disruptive than pre-exam remediation, and documentation weaknesses that surface in examination findings tend to cast a wider review net for the follow-up examination.
How We Track OCC Examination Procedure Updates
The OCC examination manual is a structured document, and changes to it are meaningful compliance inputs for any national bank or federal savings association. In Regloom, we treat examination manual updates as a specific source type with a higher baseline relevance score for BSA/AML controls, because examination procedure changes directly affect examination risk even when they do not change the underlying regulatory obligation.
When we processed the March update, we tagged the three areas described above and mapped them to the control categories in our obligation library covering transaction monitoring, customer risk rating, and EDD. For teams using Regloom, those three control categories received new change events with the obligation change type noted as "examination standard revision." That distinction allows compliance teams to prioritize their response correctly: this is not a new obligation requiring a new control, it is an existing obligation with tightened documentation expectations that likely requires a control evidence gap assessment.