Regulatory Change Management Policy Template (FFIEC-Aligned)
In short
The FFIEC Consumer Compliance Rating System (81 FR 79473) makes change management one of four Board and Management Oversight factors, and no rule requires a written policy for it. The OCC's examination procedures do list adopted policies and procedures related to the change as evidence, so this 13-section template maps each clause to the exact supervisory wording.
A regulatory change management policy is the document that answers the change-management assessment factor of the FFIEC Uniform Interagency Consumer Compliance Rating System, one of four factors under Board and Management Oversight. The rating system was published at 81 FR 79473 on 14 November 2016 and has applied to examinations since 31 March 2017. No rule requires the policy itself. But when OCC examiners test the factor, the records they may review include "adopted policies and procedures related to the change," so a written policy is the practical proof. Below is the full 13-section template, ungated, plus a crosswalk that maps each section to the FFIEC and OCC language it answers.
The template is built around five questions that any regulatory change program has to answer for management: what changed, does it apply to us, what must we change, who is accountable and by when, and can we show how the decision was made and carried out? Each section of the policy answers one or more of them.
"Change management policy" is an ambiguous phrase, and adopting the wrong document for a consumer-compliance examination is worse than adopting none. In the FFIEC framework the phrase can mean IT change control (change types, testing, rollback plans, deployment approvals) or the compliance sense used here, and an institution that answers a consumer-compliance question with an IT change-control policy has documented that it misread the expectation. This template and its crosswalk sit in our trackers and templates library.
The FFIEC has two change management regimes, and they are easy to conflate
The confusion is structural, so clear it first. As of 30 September 2026:
- IT change management. Governed by the FFIEC IT Examination Handbook: the Information Security booklet (September 2016) and the Development, Acquisition, and Maintenance booklet, which replaced the April 2004 Development and Acquisition booklet. The Federal Reserve announced the new booklet in SR 24-6 on 29 August 2024 and the OCC in Bulletin 2024-26 on 5 September 2024. This regime is about testing, authorization, version control, rollback and audit trails for system changes.
- Consumer-compliance change management. Governed by the Consumer Compliance Rating System and, for national banks, the OCC Comptroller's Handbook, "Compliance Management Systems" (Version 1.0, June 2018). This regime is about how the institution detects and responds to new laws, regulations, guidance, products and market conditions.
If a template's section headings mention deployment windows and rollback procedures, it answers the first regime. This article is about the second, regulatory change management in the compliance sense. Your policy should name its sibling explicitly, as Section 1 below does, because an examiner who asks for your change management process should be handed the right one first.
Examiners test whether you respond "timely and satisfactorily to any variety of change"
The assessment factor, verbatim from the FFIEC guidance: examiners assess the "effectiveness of the institution's change management processes, including responding timely and satisfactorily to any variety of change, internal or external, to the institution." It applies to institutions supervised by the FFIEC member agencies, which are the Federal Reserve, the CFPB, the FDIC, the NCUA, the OCC and the State Liaison Committee, and the FDIC carries the same text in section II-13 of its Consumer Compliance Examination Manual. As of 30 September 2026 we found no later amendment to the rating system in the Federal Register.
Three details in the primary text shape the whole template.
The rating matrix rewards anticipation, not response. In the rating 1 column, management "anticipates and responds promptly to changes in applicable laws and regulations, market conditions and products and services offered by evaluating the change and implementing responses across impacted lines of business," conducts "due diligence in advance of product changes, considers the entire life cycle of a product or service in implementing change, and reviews the change after implementation to determine that actions taken have achieved planned results." In rating 2, management "responds timely and adequately," and evaluates product changes "before and after implementing the change." In rating 5, management "fails to monitor and respond." The gap between the top two descriptors is one verb and one habit: management anticipates the change, and it reviews the result afterwards. That is proactive monitoring, horizon scanning, written into examiner language, and it is why Section 5 of the template is the longest. One caveat the guidance itself insists on: "Specific numeric ratings will not be assigned to any of the 12 assessment factors." Nobody gets "a 2 in change management"; the descriptors inform the single composite rating.
The OCC turned the factor into procedures with an evidence list. The examination objective in the handbook reads: "To determine whether the bank has a change management process that is commensurate with its size, complexity, and risk profile." Examiners determine whether management "monitors market conditions and regulatory developments" and "takes appropriate steps in advance of changes to prepare the bank to respond to changes once they occur," whether changes "are evaluated and responses are implemented across all affected lines of business," and whether systems and applications are included in change management "to re-test results when regulatory changes occur." They review "project management tracking records, applicable committee meeting minutes, adopted policies and procedures related to the change, and monitoring or audit reports for reviews conducted throughout and after the change." Sections 7, 10 and 11 of the template exist to produce each item on that list.
Third parties are inside the perimeter. The FFIEC guidance is direct: "the institution cannot outsource the responsibility for complying with laws and regulations or managing the risks associated with third-party relationships," and examiners evaluate third-party activities "as though the activities were performed by the institution itself." The OCC booklet says the same for consumer protection laws. A regulatory change management policy that stops at the institution's own systems fails the factor by omission, hence Section 8.
The volume data backs the examiners up. Implementing new regulations takes more than a year at 74% of firms, according to CUBE's Cost of Compliance Report 2025, a survey of more than 2,000 senior compliance, risk and legal leaders published on 4 November 2025. CUBE sells regulatory intelligence, so treat the survey as a vendor source.
The same expectation appears in UK, EU and US enforcement guidance
The FFIEC framework is US bank supervision, but the underlying expectation is not specific to it, which matters if your institution answers to more than one regulator:
- UK. FCA rule SYSC 6.1.1R requires a firm to "establish, implement and maintain adequate policies and procedures sufficient to ensure compliance of the firm" with its obligations under the regulatory system (FCA Handbook).
- EU banks. The EBA's internal governance guidelines say institutions "should set up a process to regularly assess changes in the law and regulations applicable to its activities" (EBA/GL/2021/05, paragraph 208), and paragraph 209 has the compliance function assess the possible impact of changes on the institution's activities and compliance framework (EBA).
- US, beyond bank supervision. The Department of Justice's Evaluation of Corporate Compliance Programs (September 2024) asks whether a risk assessment is "current and subject to periodic review," whether that review is based on "continuous access to operational data and information across functions," and whether it has "led to updates in policies, procedures, and controls" (DOJ).
None of these prescribes a template. Each one describes the same loop this policy documents: identify the change, decide what it means, update the controls, and be able to show it.
The policy template has 13 sections and no email gate
Model policy language is in block quotes: replace the bracketed values and adopt. Each section carries an Anchors line naming the primary-source language it satisfies, and Appendix A collects those anchors into one crosswalk.
Section 1: Purpose and regulatory basis
This policy establishes [Institution]'s process for identifying, assessing, implementing, and verifying responses to regulatory and related change affecting its compliance obligations. The process is designed to let management answer five questions for every change: what changed, whether it applies, what must be changed, who is accountable and by when, and how the decision and its implementation can be demonstrated. It is maintained consistent with the change-management assessment factor of the FFIEC Uniform Interagency Consumer Compliance Rating System (81 FR 79473) and the OCC Comptroller's Handbook, "Compliance Management Systems" (Version 1.0, June 2018), with formality commensurate with [Institution]'s size, complexity, and risk profile. This policy is distinct from [Institution]'s IT Change Management Policy, which governs changes to information systems.
Anchors: the CC Rating System factor, and the OCC's "commensurate with the bank's size, complexity, and risk profile." Note the deliberate word choice: "consistent with," not "as required by." The rating system is supervisory guidance, and a policy that overstates its own legal basis invites the question of what else it overstates.
Section 2: Scope and the four change types
This policy applies to: (a) regulatory change: new or amended laws, regulations, official guidance, and material shifts in supervisory or enforcement posture; (b) product and service change: new, modified, or expanded products or services; (c) market-condition change; and (d) internal change: system conversions, staffing changes, reorganizations, and mergers or acquisitions.
Anchors: "any variety of change, internal or external" (CC Rating System), and OCC Bulletin 2017-43 for the new-products prong, which the OCC's page lists as still in effect with the 2025 reputation-risk edits. Watching for shifts in enforcement posture means treating a peer's enforcement action as a change signal.
Section 3: Definitions
| Term | Definition |
|---|---|
| Regulatory change | Any event in scope item (a), from proposal through mandatory compliance date |
| Legal status | The stage of a development: consultation, proposed rule, final rule, supervisory statement, enforcement action, or informal publication. Recorded for every item and never collapsed into "new rule" |
| Publication, effective, and mandatory compliance dates | Three distinct dates recorded separately for every change; deadlines key off the latter two, never off publication |
| Relevant | Concerns a jurisdiction, regulator, activity, risk, or topic inside [Institution]'s regulatory profile |
| Applicable | The legal conditions attach the requirement to a specific entity, activity, product, or situation of [Institution] |
| Applicability determination | The documented outcome, with written rationale: applicable, potentially applicable, not applicable, monitoring only, or legal review required |
| Action plan | The owned, deadlined set of implementation tasks for an applicable change |
Relevance and applicability are related but not the same, and the policy should keep them apart. A development is relevant when it falls inside the perimeter you monitor. It is applicable only when its conditions, thresholds, exclusions and transition rules reach one of your entities, products or activities. A relevant item that is not applicable still needs a recorded decision.
Section 4: Roles and responsibilities
Approval authority for this policy rests with [the Board]. Day-to-day administration is delegated to the Chief Compliance Officer, who may not further delegate applicability determinations rated High. Compliance oversees the process, challenges decisions and monitors completion; business-line owners are accountable for implementing changes in their areas; Legal interprets complex or contested requirements; Internal Audit provides independent assurance and does not own first-line or second-line decisions.
| Activity | Board | Compliance Committee | CCO | Legal | Business-line owner | IT and operations | Vendor manager | Internal Audit |
|---|---|---|---|---|---|---|---|---|
| Source monitoring and intake | I | I | A/R | C | C | |||
| Triage and applicability determination | I | A/R | C | C | C | C | ||
| Legal interpretation of contested requirements | I | A | R | C | ||||
| Impact assessment | I | A | C | R | C | C | ||
| Action-plan execution | I | C | C | A/R | R | R | ||
| Deadline changes and escalation | I | I | A | C | R | C | C | |
| Post-implementation review | A | R | C | C | C | C | ||
| Reporting to the Board | A | R | R | C | I | |||
| Independent assurance over the process | I | I | I | A/R |
Anchors: the factor sits under Board and Management Oversight, which examiners assess "as appropriate for their respective roles and responsibilities." The OCC handbook adds that "management should clearly outline roles and responsibilities so that monitoring by the various groups is complementary and not duplicative," which is why Internal Audit appears only as assurance.
Section 5: Identification and monitoring
Compliance maintains (i) an inventory of laws and regulations applicable to [Institution]'s activities, (ii) a regulatory profile covering legal entities and branches, jurisdictions, licenses and registrations, products and customer types, regulators, and material outsourced activities, and (iii) a named inventory of monitored sources, each with an assigned authority tier, monitoring frequency, and owner. Tier 1 sources (primary federal and state regulators, official journals, and legislative and rulemaking portals) are monitored [daily]; lower tiers at least [monthly]. Primary sources anchor every record. The profile and the source inventory are reviewed [quarterly] and whenever [Institution] enters a new product, market, or jurisdiction.
Anchors: the OCC's expectation that management has a "process to identify laws and regulations applicable to the bank's activities and stay abreast of evolving regulatory requirements," and the exam procedure testing whether management "takes appropriate steps in advance of changes." This section is where the rating matrix's "anticipates" is won or lost. Treat the regulatory profile as operational data rather than a spreadsheet built for one project: a new market, product, acquisition, regulator or distribution model changes what is relevant. The horizon scanning template is the operational companion, and how compliance teams track regulatory changes surveys source-inventory methods. For most banks the inventory now extends past the prudential regulators; state privacy regimes belong in it (see the US state privacy laws tracker). Official services can feed the source inventory directly: EUR-Lex, for example, offers predefined RSS feeds for legislation, case law, Commission proposals and Official Journal acts, and lets signed-in users create alerts for documents and procedures.
Section 6: Intake, triage, applicability, and impact assessment
Every item identified under Section 5 becomes a structured intake record showing the issuing authority and primary-source link; publication, effective, consultation, and response dates; jurisdiction; legal status; affected topics and activities; source text or precise citations; owner; and workflow status. Initial triage confirms that the source is authoritative, whether the item is new, amended, corrected, or duplicative, whether it falls inside the monitoring scope, whether an immediate deadline or escalation trigger exists, and whether specialist review is needed. A triage decision never erases the original item: the source, decision, reviewer, timestamp, and rationale are retained.
Every item receives a documented applicability determination within [10 business days] of identification, using the controlled outcomes in Section 3, with written rationale in every case. Where interpretation is uncertain, the uncertainty is recorded, the point requiring advice is identified, and a review date is set. Applicable changes receive an impact assessment rated [High / Medium / Low] that covers policies and procedures, products and customer journeys, contracts and disclosures, controls and monitoring, systems, data and records, training, third parties, existing regulatory commitments, and dependencies on other change programs. Priority is set from defined factors: legal status, effective date, customer or market impact, number of entities affected, implementation complexity, control weakness, and supervisory attention.
Anchors: the exam procedure's "changes are evaluated and responses are implemented across all affected lines of business." The out-of-scope rationale is the field most programs skip and the first thing a good examiner probes: a dismissal without reasoning is indistinguishable from a miss, and false certainty is more dangerous than a documented open question. The regulatory change impact assessment template is the full working document this section mandates.
Section 7: Implementation planning and escalation
Each applicable change receives an action plan recording: the obligation or obligations created; one accountable owner per obligation, who is a named person and never a department or shared mailbox; the deliverable; milestones; a deadline tied to the effective or mandatory compliance date; dependencies and contributing teams; required policy and procedure updates; system changes and associated re-testing; training updates; customer disclosures or notices with their required issuance dates; approval and validation requirements; and a closure test. Overdue actions, declined ownership, changed regulatory dates, blocked dependencies, unresolved interpretation, and residual risk above tolerance are escalated under Section 11. A deadline change preserves the original date and records who approved the change and why.
Anchors: exam procedures on implementation across affected lines and on "timely issuance of any required disclosures or account agreements." Obligations from action plans should land in one register, not in per-project spreadsheets. The obligations register template is the format, and an obligations register is what turns a plan into something auditable.
Section 8: Third-party and vendor changes
Where an affected product, service, or process is operated in whole or part by a third party, [Institution] remains responsible for compliance. The vendor manager obtains the provider's implementation plan for each applicable change, and Compliance validates the change as if it were performed in-house. Contracts require providers to notify [Institution] of changes affecting compliance obligations within [30 days] of identification.
Anchors: the FFIEC's "the institution cannot outsource the responsibility for complying with laws and regulations," and its instruction that third-party activities are evaluated "as though the activities were performed by the institution itself."
Section 9: Testing, post-implementation review, and closure
Every applicable change receives a post-implementation review within [90 days] of its effective date to determine that actions taken have achieved planned results. Automated systems affected by a regulatory change are re-tested before reliance is placed on their outputs, calculations, or disclosures. A change is closed only when the action owner confirms completion, evidence is attached, affected controls and documents are updated, ongoing monitoring is assigned, and, for changes rated High, someone other than the action owner has validated the result. Updating a policy alone does not close a change that also requires system configuration, revised customer communications, training, control testing, or third-party remediation.
Anchors: the rating matrix's strongest descriptor ("reviews the change after implementation to determine that actions taken have achieved planned results"), which this section quotes deliberately, and the OCC procedure to "re-test results when regulatory changes occur."
Section 10: Documentation and recordkeeping
For each change, the following records are retained for [X years]: the change-log entry (Appendix B); the original regulatory source and relevant provisions; the triage and applicability decisions with rationale; any legal or specialist advice; the impact assessment and approvals; the action plan and project tracking records; committee minutes recording review and approval; adopted policy, procedure, and control changes; training and communication evidence; testing or validation results; exceptions and risk acceptances; and the closure rationale.
Anchors: this list contains the OCC examiner evidence list, in the same structure. If Section 10 is maintained, exam preparation is a retrieval exercise, and nobody has to rebuild a decision months later from email and meeting notes.
Section 11: Board and committee reporting, cadence, and escalation
Compliance reports change-management activity to the Compliance Committee [monthly] and to the Board [quarterly]: new applicable changes, action-plan status, items overdue against regulatory deadlines, items awaiting applicability decisions, unresolved legal questions, and post-implementation review results. Escalation to the [Board risk committee] is immediate for: any High-rated change; any missed milestone on a regulatory deadline; any regulatory inquiry touching an in-flight change.
Set the operating cadence in the same section. A workable starting model:
| Cadence | What happens |
|---|---|
| Daily | Tier 1 source monitoring, intake, urgent triage, deadline alerts |
| Weekly | New material items, ownership, upcoming deadlines, blocked actions |
| Monthly | Portfolio trends, overdue work, high-impact assessments, residual risks; Compliance Committee report |
| Quarterly | Board report, control effectiveness, coverage review of the regulatory profile and source inventory |
| Annually | Regulatory profile, source universe, governance model, taxonomy, and methodology review |
Useful management information counts open items by materiality, actions approaching regulatory deadlines, overdue actions, items awaiting applicability decisions, unresolved legal questions, changes by jurisdiction and topic, and closure quality. Metrics should help management intervene: a large alert count with no relevance, ownership or timeliness context is not a control measure.
Anchors: Board and Management Oversight, meaning "oversight of and commitment to the institution's CMS." Committee minutes are on the OCC evidence list.
Section 12: Training
Training content affected by a regulatory change is updated before the change's mandatory compliance date and delivered to affected roles; completion records are retained as action-plan evidence.
Anchors: the Compliance Program factor on training, "the degree to which compliance training is current and tailored to risk and staff responsibilities."
Section 13: Policy administration
This policy is reviewed and re-approved by [the Board] at least annually and upon any material change to the regulatory expectations it references. Version history:
| Version | Date | Change | Approved by |
|---|---|---|---|
| 1.0 | [date] | Initial adoption |
Appendix A: the FFIEC crosswalk maps each section to the language examiners use
This is the table to hand an examiner or an internal auditor alongside the policy. Quotes are from the FFIEC CC Rating System guidance (November 2016) and the OCC Compliance Management Systems booklet (Version 1.0, June 2018), read on 30 September 2026.
| Policy section | CC Rating System language it answers | OCC exam-procedure hook | Evidence an examiner will ask for |
|---|---|---|---|
| 1. Purpose | The change-management assessment factor under Board and Management Oversight | Objective: process "commensurate with its size, complexity, and risk profile" | The adopted policy and approval minutes |
| 2. Scope | "any variety of change, internal or external" | Product due diligence per OCC Bulletin 2017-43 | Change log spanning all four change types |
| 4. Roles | Board and management assessed "as appropriate for their respective roles and responsibilities" | Review of policies and procedures and "discussions with management" | RACI, committee charters, delegation records |
| 5. Monitoring | Rating 1 descriptor: "anticipates and responds promptly" | "monitors market conditions and regulatory developments" and "takes appropriate steps in advance of changes" | Regulatory profile, source inventory, monitoring output, horizon-scan records |
| 6. Assessment | "evaluating the change" | "changes are evaluated and responses are implemented across all affected lines of business" | Applicability determinations, including out-of-scope rationale |
| 7. Implementation | "implementing responses across impacted lines of business" | "timely issuance of any required disclosures or account agreements" | Action plans, project management tracking records |
| 8. Third parties | "cannot outsource the responsibility for complying with laws and regulations"; activities evaluated "as though the activities were performed by the institution itself" | Booklet: the bank "cannot outsource the responsibility for complying with consumer protection-related laws and regulations" | Vendor notification clauses, validation records |
| 9. Post-implementation review | "reviews the change after implementation to determine that actions taken have achieved planned results" | "re-test results when regulatory changes occur" | Post-implementation review reports, system re-test evidence |
| 10. Recordkeeping | Evidence of an effective compliance management system | "project management tracking records, applicable committee meeting minutes, adopted policies and procedures related to the change, and monitoring or audit reports" | The retention schedule and sampled records |
| 11. Reporting | "oversight of and commitment to the institution's CMS" | Review of board and committee records | Board packs, committee minutes |
| 12. Training | "compliance training is current and tailored to risk and staff responsibilities" | Booklet: training "specifically tailored to employees' job functions" | Training completions, updated materials |
| 13. Administration | "policies and procedures are appropriate to the risk in the products, services, and activities of the institution" | Review of policies and procedures | Version history, approval records |
Appendix B: every change gets one log entry, shown here with a worked example
Section 10 presumes a regulatory change log. Keep one entry per change, with these fields (the change tracker spreadsheet implements the full register):
Change ID · Source, citation, and primary-source link · Issuing authority · Legal status · Date identified · Publication date · Effective and mandatory compliance dates · Applicability outcome and rationale · Impacted business lines · Risk rating · Owner · Action-plan status · Post-implementation review date · Board reporting date
Here is the template filled in for a real, small change that touches this very policy. The regulatory event is real; the institution and its dates are fictional.
| Field | Entry |
|---|---|
| Change ID | RC-2025-014 |
| Source and citation | OCC Bulletin 2025-4, "Bank Supervision: Removing References to Reputation Risk"; reputation-risk references removed from Comptroller's Handbook booklets, including "Compliance Management Systems," shown as strikethrough as of 20 March 2025 |
| Issuing authority and legal status | OCC; supervisory-guidance change |
| Date identified | 24 March 2025 (Tier 1 source sweep) |
| Publication date | 20 March 2025 |
| Effective and mandatory compliance dates | Immediate (supervisory-guidance change; no compliance deadline) |
| Applicability | Partial: no consumer-facing obligation changes, but our compliance risk-assessment taxonomy and this policy cite the CMS booklet, so references require review |
| Impacted business lines | Compliance only |
| Risk rating | Low |
| Owner | CCO |
| Action-plan status | Closed: citations reviewed; risk-taxonomy references to reputation risk retained as internal categories with a note that they no longer track OCC handbook language |
| Post-implementation review date | 15 June 2025 (confirmed that no examiner-facing document still cites the removed text) |
| Board reporting date | Q2 2025 compliance report, consent item |
Most changes are small guidance edits like this one, not CFPB rulemakings with 18-month runways, and their main risk is that nobody logs them. A factor whose verbatim text is "any variety of change" is tested on exactly these. A log with only headline rules in it reads as a process that only notices headlines. The example also has a sequel: on 10 April 2026 the OCC and FDIC published a final rule codifying the elimination of reputation risk from their supervisory programs (91 FR 18279, effective 9 June 2026). A working log gives that follow-on its own entry, linked to the first.
Eight mistakes turn this policy into shelfware
- Adopting an IT change-control template. If your regulatory change management policy discusses rollback windows, you have documented the wrong regime. Keep both policies, cross-reference them, and hand the examiner the right one.
- Writing "as required by the FFIEC" into the purpose clause. The rating system is guidance, and the OCC's own standard is proportionality: "commensurate with the bank's size, complexity, and risk profile." Overstating the mandate creates a self-inflicted finding when your process does not match your policy's inflated claims.
- Targeting "a 1 in change management." No numeric rating is assigned to any of the 12 assessment factors, and the guidance says so explicitly. Write the rating-matrix language into your process (Sections 5 and 9 do), but never write factor-level score targets into policy.
- A source inventory or regulatory profile frozen at adoption. The OCC expects management to "stay abreast of evolving regulatory requirements." An inventory nobody has amended since the policy was approved is evidence against you, and more sources make more noise when the profile behind them is incomplete. Section 5's quarterly review with a named owner is the fix.
- No written rationale for dismissals. The applicability decisions you dismiss are the audit trail that proves monitoring works. Two dated sentences per dismissed change, with the reviewer named, and never delete them.
- Alerts that pile up without decisions. Teams collect updates but do not convert them into determinations. Set a decision deadline per item, name an accountable reviewer, and report aging in Section 11.
- Compliance owns every action. Business teams disengage and implementation stalls. Compliance is accountable for oversight; operating teams are accountable for change.
- Email as the system of record, and closure by self-attestation. Decisions, versions and evidence fragment across inboxes, and an owner marks work complete without validation. Keep one controlled record with history and linked artifacts, and require independent validation for higher-risk changes.
Judge software against this policy's operating model, not against the demo
Judge a tool against the operating model in the policy. Eight questions cover most of it:
- Can it monitor the authorities, jurisdictions and document types in your regulatory profile, with each item linked to an authoritative source?
- Can users tell a consultation from a final rule, guidance and an enforcement action?
- Can you configure your own scope and sources rather than accept a fixed feed?
- Does it support triage, applicability, impact, action, approval and closure with role-based workflows?
- Are the reviewer, rationale, timestamps and history kept for every decision, including dismissals?
- Are ownership, deadlines and escalation configurable, and can management report on decisions and actions rather than just publications?
- Can the decision history be exported in a form an examiner can read?
- Is there a human approval point at each material decision, and can automated outputs be reviewed after the fact?
A policy describes the process; it does not perform it
A policy is the examiner-facing description of a process; it does not perform the process. Sections 5, 6 and 10 are commitments to continuous work: monitor every source at its stated frequency, produce a dated rationale for every change including the dismissals, and keep the evidence retrievable. That work is what breaks first when a compliance team is busy, which is always. The CUBE finding that 74% of firms need more than a year to implement new regulations is what "responds timely" looks like when identification and triage eat the runway.
RegWatch, my company's product, works at this layer, and each of its objects answers a section of the policy. Section 5's source inventory is a Watchlist over tiered Sources, monitored on the schedule you set from daily to monthly. Each detected item is a Finding with its source URL, dates and a verbatim excerpt, so Section 6's applicability determination corresponds to triage: an accepted item carries a plain-language "Why this matters" tied to its source, and dismissing an alert requires a written reason. An accepted Alert converts to an Obligation with an owner and a deadline (Section 7), evidence attaches to it (Section 10), and decisions go to a tamper-evident, append-only audit log. The policy above works with a spreadsheet and a diligent analyst. What tooling changes is that "anticipates" stops depending on whether the analyst had a quiet week.
To put the policy to work, adopt the template with your bracket values filled, take the most recent regulatory change that reached your desk, and produce one complete Appendix B entry and one Section 6 rationale for it. If writing the out-of-scope rationale feels unfamiliar, that is the muscle this policy exists to build, and it is the line item examiners pull first.
This article is general information, not legal advice.
Questions
Is a regulatory change management policy required by the FFIEC?
No rule mandates a standalone policy. Change management is one of the assessment factors in the FFIEC Consumer Compliance Rating System (81 FR 79473), and the OCC says the process should be commensurate with the bank's size, complexity and risk profile. OCC examination procedures do list adopted policies and procedures related to a change among the records examiners may review, so a written policy is the practical evidence.
What is change management under the FFIEC Consumer Compliance Rating System?
It is one of four assessment factors under Board and Management Oversight: the effectiveness of the institution's change management processes, including responding timely and satisfactorily to any variety of change, internal or external. The rating system has applied to examinations since 31 March 2017 across the FFIEC member agencies: the Federal Reserve, CFPB, FDIC, NCUA, OCC and the State Liaison Committee.
What do examiners actually look for in regulatory change management?
The OCC's procedures name the records: project management tracking records, applicable committee meeting minutes, adopted policies and procedures related to the change, and monitoring or audit reports for reviews conducted throughout and after the change. Examiners also test whether management takes appropriate steps in advance of changes, and whether automated systems are re-tested when regulatory changes occur.
What is the difference between a change management policy and a regulatory change management policy?
The FFIEC framework covers two separate things. IT change control, in the IT Examination Handbook, governs code, systems, testing and rollback. Consumer-compliance change management, in the Consumer Compliance Rating System, governs how an institution responds to new laws, regulations, products and market conditions. A template written for one will not satisfy an examiner asking about the other, so name both in your policy.
What separates a strong change management process from a merely satisfactory one?
In the rating matrix, the strongest descriptor says management anticipates and responds promptly to changes, conducts due diligence in advance of product changes, considers the entire life cycle, and reviews the change after implementation to confirm planned results. The next tier only responds timely and adequately. Anticipation is the difference. No numeric rating is assigned to the individual factor; the descriptors inform the composite rating.
Terms in this guide
Sources
- Uniform Interagency Consumer Compliance Rating System, 81 FR 79473 (Federal Register, 14 November 2016) accessed 30 Sep 2026
- FFIEC Guidance on the Uniform Interagency Consumer Compliance Rating System (Federal Reserve CA 16-8 attachment) accessed 30 Sep 2026
- FDIC FIL-75-2016: Final Guidance on the Uniform Interagency Consumer Compliance Rating System accessed 30 Sep 2026
- FDIC Consumer Compliance Examination Manual, section II-13 Consumer Compliance Ratings accessed 30 Sep 2026
- OCC Comptroller's Handbook, Compliance Management Systems (Version 1.0, June 2018, with the 20 March 2025 reputation-risk strikethrough) accessed 30 Sep 2026
- OCC Bulletin 2025-4: Bank Supervision, Removing References to Reputation Risk (20 March 2025) accessed 30 Sep 2026
- OCC Bulletin 2017-43: New, Modified, or Expanded Bank Products and Services, Risk Management Principles (20 October 2017) accessed 30 Sep 2026
- OCC Bulletin 2024-26: FFIEC IT Examination Handbook, new Development, Acquisition, and Maintenance booklet (5 September 2024) accessed 30 Sep 2026
- Federal Reserve SR 24-6: FFIEC IT Examination Handbook, Development, Acquisition, and Maintenance (29 August 2024) accessed 30 Sep 2026
- Prohibition on the Use of Reputation Risk by Regulators, 91 FR 18279 (OCC and FDIC final rule, 10 April 2026) accessed 30 Sep 2026
- CUBE: The Cost of Compliance Report 2025 (published 4 November 2025) accessed 30 Sep 2026
- FCA Handbook, SYSC 6.1 Compliance accessed 30 Sep 2026
- EBA Guidelines on internal governance under CRD (EBA/GL/2021/05) accessed 30 Sep 2026
- US Department of Justice, Evaluation of Corporate Compliance Programs (updated September 2024) accessed 30 Sep 2026
- EUR-Lex: predefined RSS feeds accessed 30 Sep 2026
