Regulatory compliance for financial services

Regulatory requirements are growing more complex as expectations rise. Wipfli helps financial services organizations improve compliance, mitigate risk and support operational effectiveness.

Get answers to your top compliance questions
Get answers to your top compliance questions

Subscribe to ComplianceHelp to send questions to Wipfli compliance advisors, gain access to quarterly webinars and more. 

How we help you

From new technologies to new generations of customers, financial services organizations are facing a variety of ways they can increase efficiency and grow. But as the industry changes, so do regulatory requirements and expectations.

Strengthen compliance audit and monitoring.

Mitigate fair lending risks.

Get comprehensive support for BSA/ AML.

Access compliance specialists and resources on demand.

Simplify your compliance

Resource-intensive processes and evolving regulatory priorities make compliance more challenging than ever. Let Wipfli’s regulatory risk and compliance team help with our risk-based solutions, real-world best practices and responsive support.

Explore our regulatory compliance services for the financial services industry

Insights and resources

  • Shot of two colleagues working on a laptop.

    ARTICLE

    CDD Rule: What financial institutions need to know

    The Financial Crimes Enforcement Network’s (FinCEN) recent actions regarding the Corporate Transparency Act (CTA) and Beneficial Ownership Information (BOI) reporting have created significant confusion within the financial services industry. Many institutions have asked whether FinCEN’s decision to eliminate BOI reporting requirements for U.S. companies means that they are no longer required to collect and verify beneficial ownership information at account opening. The short answer is no. While FinCEN has substantially narrowed the scope of the CTA’s BOI reporting regime, the agency has not eliminated financial institutions’ Customer Due Diligence (CDD) obligations under the Bank Secrecy Act (BSA). Financial institutions must continue to identify and verify beneficial owners of legal-entity customers in accordance with the CDD Rule unless FinCEN formally amends those requirements. The CTA reporting framework and the CDD Rule are related, but they are separate regulatory requirements. What changed under the CTA? On March 26, 2025, FinCEN issued an interim final rule that dramatically narrowed BOI reporting requirements under the CTA. The rule revised the definition of a “reporting company” so that only certain foreign entities registered to do business in the United States remain subject to BOI reporting obligations. Domestic entities and U.S. persons were exempted from reporting BOI to FinCEN. FinCEN’s final rule on BOI reporting under the Corporate Transparency Act (CTA) was issued on August 11, 2026, and became effective upon publication in the Federal Register on August 14, 2026. Under the final rule, domestic reporting companies remain exempt from BOI reporting. U.S. beneficial owners are exempt from providing BOI. FinCEN also announced that information relating to U.S. persons will be removed from the BOI database. Only certain foreign reporting companies formed under foreign law that are registered to do business in a U.S. state or tribal jurisdiction remain subject to CTA reporting obligations. These changes represent a significant scaling back of the CTA’s original reporting framework. However, they apply only to the requirement that companies report ownership information directly to FinCEN. They do not eliminate customer due diligence obligations imposed on financial institutions. The critical distinction for FIs: CTA reporting vs. CDD requirements One of the most common misconceptions is that the CTA and the CDD Rule are the same thing. They are not. The CTA created a reporting obligation requiring certain entities to submit BOI directly to FinCEN. By contrast, the CDD Rule requires covered financial institutions to identify and verify beneficial owners of legal-entity customers when accounts are opened and at certain triggering events. The information is collected and maintained by the financial institution as part of its BSA/AML program. The purpose is to help institutions understand who owns and controls their customers and to support risk-based monitoring and suspicious activity reporting. Although Congress envisioned that the BOI database could eventually reduce compliance burdens for financial institutions, FinCEN has not rescinded or replaced the CDD Rule. Accordingly, institutions remain subject to the existing beneficial ownership requirements contained in the BSA framework. How the February 2026 exceptive relief differs FinCEN’s February 13, 2026, Exceptive Relief Order, FIN-2026-R001, addressed the frequency with which financial institutions must identify and verify the beneficial owners of legal-entity customers. The order permits an institution to obtain and verify beneficial ownership information when the legal-entity customer first opens an account, rather than each time the same customer opens an additional account. Updated identification and verification remain necessary when the institution knows facts that reasonably call the reliability of previously obtained information into question or when required under its risk-based ongoing CDD procedures. This relief differs from the August 2026 CTA final rule. The exceptive relief modifies how financial institutions apply the CDD Rule, while the CTA final rule limits which companies and individuals must report BOI directly to FinCEN. Neither action eliminates a financial institution’s underlying obligation to identify and verify beneficial owners under the CDD Rule. As a result, examiners will continue to expect institutions to: Identify legal-entity customers Collect beneficial ownership information Verify the identity of beneficial owners Maintain appropriate records Conduct risk-based ongoing customer due diligence These obligations remain foundational components of an institution’s BSA/AML compliance program. How financial institutions should proceed The recent narrowing of the Corporate Transparency Act’s BOI reporting requirements is a significant regulatory development, but it should not be interpreted as eliminating beneficial ownership requirements for financial institutions. It does not eliminate the separate obligations imposed on institutions under the CDD Rule. Until FinCEN formally amends the CDD Rule, financial institutions should continue collecting and verifying beneficial ownership information at account opening for legal-entity customers and maintain risk-based procedures consistent with existing BSA/AML expectations. Institutions that incorrectly interpret CTA reporting relief as eliminating beneficial ownership requirements under the CDD Rule risk creating significant compliance gaps that could lead to examination findings and/or regulatory criticism. Read more How financial institutions can verify their CECL compliance Avoiding adjustable-rate mortgage loan compliance challenges What financial institutions should prioritize in a CRM

  • office setting

    ARTICLE

    How financial institutions can compete in today’s economy

    The financial services business climate is faster and more complex than ever. Today, traditional community financial institutions must compete for customers with not just each other, but fintech companies and new digital payment options, all while breaking through the noise of countless other demands on customers’ attention. How should an institution’s CEO adjust its growth strategy to succeed in this environment? Keep reading to find out, plus why doing so also requires a new approach to managing risk. How should community financial institutions adapt to compete in today’s attention economy? Winning customers’ attention, in today’s attention-starved environment, doesn’t mean creating a flashy ad campaign. Instead, it’s about meeting your customers (and potential customers) where they are by blending new technology, such as online account opening, with timeless community banking fundamentals. It’s this combination that helps your institution stand out from the plethora of large national banks, fintech companies and other digital payment alternatives competing for your customers’ business. Here are key actions CEOs can push to help drive growth and customer retention: 1. Win on customer experience Customer experience (CX) is what a customer experiences during their every interaction with your financial institution, including marketing, account opening, customer service and branch visits. CX is the single biggest strategic asset for community and regional financial institutions, because smaller institutions are better positioned than big banks and fintechs to build long-term, human relationships with customers that lead to organic growth. 2. Understand your customers better than ever To deliver that superior customer experience, you also have to understand what your customers want and need. To do this, do a deep dive into your customer data: Develop data-based personas, map your customer journeys, explore how you can provide more automated personalization and offer proactive services rather than waiting for your customers to come to you. 3. Use AI when it makes sense AI can help you analyze your data to learn about your customers more deeply. But you can also create customer-facing AI tools that provide instant answers to questions and personalized recommendations for products or services that fit a particular customer’s specific needs. Leaning into AI also helps give your employees more time to focus on the human aspects of their job, like customer relationships or complex problem-solving. However, you can’t just throw AI on top of ineffective processes or bad data and expect it to perform miracles — your foundation has to be solid before you add in AI . 4. Reduce friction wherever you can Friction kills CX. Nobody wants to wait for a slow app to load, navigate a clunky UI or struggle to set up a password for their new bank account. Reduce friction in your customer service experience wherever you can, as this is often an area where newer fintech companies will shine. Conducting a friction audit can help you accomplish this goal. During the audit, you’ll identify specific friction points within your customer experience and prioritize which ones to solve based on impact. 5. Offer a consistent omnichannel experience Whether a customer is stopping in the branch, opening a new account online, or calling your contact center to apply for a loan, they should feel like they are having a consistent, cohesive experience. This omnichannel approach is both a powerful branding exercise and an implicit promise that you will always come through for your customers. 6. Measure whether you’re delivering for your customers How quickly and smoothly can you deliver what your customers want? This is the essential metric you need to track, measure and seek to improve on, and someone in your C-suite should own it. 7. Earn (and keep) customer trust By taking the action steps above, you’ll also start earning meaningful customer trust. This is a long-term differentiator for community and regional financial institutions: The sense you’re looking out for your customers in a way that a fintech or a Wells Fargo never could. A frictionless omni-channel experience is also especially effective at building trust. While this might surprise you, how you manage risk and compliance also affects customer trust. And right now, the moment is ripe to change your approach to one that fits better with today’s business climate. Financial institutions should pivot to a risk-based approach to compliance and risk management Even as technology, markets and customer expectations are evolving faster than ever, regulatory agencies have pulled back on some of their traditional compliance oversight responsibilities . As a result, financial institutions have new flexibility to reallocate their compliance and risk management budgets from a compliance-based approach to a risk-based approach. Rather than approaching compliance as simply a box-checking exercise, a risk-based approach is more adaptive and better suited to navigating today’s risks and business realities. This strategy seeks to: Broadly assess your risks and compliance challenges. Identify risks as high, medium or low based on potential impact to your institution or customers. Prioritize mitigating risks that are higher impact so that you allocate your resources more effectively. Implement new or more effective controls to mitigate higher impact risks. Conduct ongoing monitoring and reassessment to ensure that your risk-management and compliance efforts continue to focus on where they’ll do the most good. A risk-based approach protects both your institution and your customer experience Risks are evolving as fast as the rest of the business environment is. By following a risk-based approach, your institution is able to constantly adapt as new risks emerge rather than getting locked into a compliance checklist that may no longer adequately reflect the latest risks in areas like cybersecurity or AI. Taking a risk-based approach is also a powerful tool to help protect your reputation with customers. Essentially, a risk-based approach goes hand in hand with your growth efforts by mitigating your risk of incidents that could hurt your customer experience (or draw attention to your institution for the wrong reasons rather than the right ones). Read more A short guide to vCISOs for financial institutions How should financial institutions respond to the federal compliance pullback? Minus a data strategy, financial institutions will fail at AI

  • Smiling faces

    ARTICLE

    Participation loans: protect your position

    Participation loans for financial institutions offer a way to generate commercial lending income without creating a new borrower relationship from scratch. But acting as the participant in these loans comes with risks. Financial institution CEOs and CLOs need to be sure safeguards are in place to avoid ending up on the wrong side of a regulatory exam and to reduce the risk of losing money on a participant loan. Keep reading to learn about three actions participants should take to protect themselves. What is a participation loan? Financial institutions operate under legal lending limits that cap how much they can lend to any single borrower. Many also maintain internal lending limits that sit below the legal threshold. When a commercial borrower needs more money than one institution can lend, or more than it is comfortable lending due to other risks such as collateral concentrations, the initial institution can bring in another institution to share the loan. This is a participation loan. The originator of the loan is the lead. The institution brought on board to carry the remaining portion of the loan is the participant. In some cases, there may be more than one participant. The lead manages the borrower relationship and services the debt. The participant purchases a percentage of the loan and receives a proportionate share of payments and absorbs a proportionate share of any loss. If your institution owns 50% of the participation, 50% of the payments come to you. And if there’s a loss, you will absorb 50% of that as well. These arrangements allow financial institutions to deploy capital for commercial lending without having to establish new relationships with borrowers. But there are risks the participants need to be aware of. Participation lending is available only for commercial loans, not for consumer lending or residential mortgages. These are business loans to commercial borrowers that can be complex. Three things every participant institution must do If your financial institution is considering being a participant in a loan, here are three actions that will help mitigate the risks of losing money and of regulatory violations: 1. Conduct an independent credit evaluation When you agree to be a participant, the lead institution sends you their underwriting file, which should include financial statements, borrower background, collateral analysis and its risk conclusions. That information is a good starting point, but you need to do your own evaluation. Independent credit evaluation for loan participation means applying your institution’s established credit policies to the borrower, as if they had approached you directly for a loan. You can’t simply review the lead’s package and mark it as approved. That’s not an independent evaluation. Regulators have become increasingly direct on this point. Institutions that can’t show their own analysis that’s independent of the lead’s underwriting are creating meaningful examination exposure. Be prepared to answer these questions: What did your credit analysis independently conclude? How did you apply your own underwriting criteria? Where’s your work? Simply put, if the participation opportunity doesn’t meet your standards for a loan someone applied for at your institution, you should pass. 2. Negotiate a clear participation agreement The participation agreement is the contract that establishes the roles and responsibilities for the lead and participant institutions. Treating it as a formality is a mistake. Dedicate time to negotiating terms that protect your interests. Don’t make the mistake of assuming the lead’s standard form covers everything you need. A well-structured agreement for a participation loan should define: The lead institution’s responsibilities for obtaining updated borrower information. Specific timelines for delivering that information to the participant. How loan payments are received and remitted, including any netting arrangements. Interest income based on ownership percentage. How problem credits are managed and who makes decisions. Actions the lead can take unilaterally vs. those requiring participant consent. The absence of clear terms can leave participant financial institutions without the information they need to properly monitor the loan and with no contractual leverage to demand it. Negotiate the agreement before you sign it, not after something goes wrong. 3. Keep your books current As the participant, ongoing monitoring of the loan is your responsibility. You can’t just forget about it and assume the lead will tell you if something changes. Each year, participants should complete a formal internal evaluation that includes reviewing current borrower information, updating the risk rating and assessing whether the borrower remains capable of servicing the debt. The evaluation must be based on current data. The lead institution needs to provide you with updated information. Your agreement should define when that information is due, and you should hold the lead on it. Don’t assume that because the lead hasn’t raised a concern, there aren’t any. You must do your own analysis. When doing your annual review, the key information to gather, assess and document includes: Current financial statements or business tax returns for operating companies. Rent rolls, lease schedules and operating statements for non-owner-occupied commercial real estate. Evidence of consistent cash flow sufficient to service debt over at least the next 12 months. Any material changes to the borrower’s business, ownership or collateral position. Read more How financial institutions can verify their CECL compliance Avoiding adjustable-rate mortgage loan compliance challenges Regulation E error resolution misconceptions and common errors

Perspective changes everything.

Receive timely industry developments, regulatory changes and other news impacting your success.

Reach out to our team

From fair lending and BSA/AML compliance to compliance audits and monitoring, our professionals are ready to help.