Skip to content

Evidence request lists

OCC Heightened Standards (12 CFR Part 30, Appendix D)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Board of Directors

OCCHS-6
Board of Directors: Composition, Independence, Oversight, and Self-Assessment

Operate Board of Directors responsibilities per 12 CFR Part 30 Appendix D Section III. The Board must (a) require an effective Risk Governance Framework per Section III.A and oversee its design and implementation by management, (b) provide active oversight of management per Section III.B including review and approval of Risk Appetite Statement + Strategic Plan + significant policies + significant transactions + significant changes + acquisitions + significant compensation arrangements, (c) exercise independent judgment per Section III.C in fulfilling oversight responsibilities + with appropriate composition and information access to enable independent judgment, (d) include sufficient independent directors per Section III.D with documented independence criteria + independence assessments + with at least two members who are not officers or employees of the parent company or any subsidiary,

Artefacts an auditor will ask for
  • Board composition with independence assessment per Section III.D
  • training programme + completion records per director
  • annual self-assessment with action plans + closure tracking
  • committee charters + meeting cadence + reporting to full Board
Where this commonly fails
  • Board independence threshold not met or independence assessment perfunctory
  • training generic not banking + risk-specific
  • self-assessment template-driven without external facilitation or peer benchmarking

Independent Risk Management

OCCHS-4
Independent Risk Management: CRO, Charter, Authority, and Oversight

Operate Independent Risk Management per 12 CFR Part 30 Appendix D Section II.C.2. Independent Risk Management must (a) be a function or set of functions separate from the front line units with authority and independence to oversee the design and implementation of the covered banks risk management framework, (b) report to a Chief Risk Officer or equivalent who reports directly to the Chief Executive Officer + with unfettered access to the Board, (c) maintain a charter approved by the Board defining scope + authority + reporting + escalation + budget + staffing, (d) include functions for credit + market + operational + liquidity + interest rate + price + compliance + reputational + strategic risk oversight + with specialised expertise per risk category, (e) review and challenge front line unit risk-taking and risk management activities including new products + significant transactions + si

Artefacts an auditor will ask for
  • CRO appointment + qualifications + reporting line to CEO + unfettered Board access evidence
  • IRM charter Board-approved with scope + authority + reporting + escalation + budget + staffing
  • IRM review and challenge evidence on front line activities + new products + significant transactions
  • IRM reporting to executive + Board
Where this commonly fails
  • CRO reports to CFO or other officer producing independence challenges
  • IRM lacks budget or staffing to fulfil charter
  • IRM challenge of front line undocumented

Internal Audit

OCCHS-5
Internal Audit: Independence, Scope, Methodology, and Reporting

Operate Internal Audit per 12 CFR Part 30 Appendix D Section II.C.3. Internal Audit must (a) be a function independent of the front line units and Independent Risk Management with authority and independence to provide assurance to the Board on the design and operating effectiveness of the Risk Governance Framework + processes + controls, (b) report to a Chief Audit Executive (CAE) who reports directly to the Audit Committee of the Board + with unfettered access to the Board, (c) maintain a charter approved by the Audit Committee defining scope + authority + reporting + escalation + budget + staffing + methodology, (d) operate per professional standards (typically IIA International Professional Practices Framework + with augmentation for banking-specific guidance), (e) develop a risk-based audit plan covering all material risk categories + business lines + significant processes + with suf

Artefacts an auditor will ask for
  • CAE appointment + qualifications + reporting line to Audit Committee + unfettered Board access evidence
  • Audit Committee-approved charter + methodology
  • risk-based audit plan covering material risk categories + business lines + significant processes
  • audit execution evidence + workpapers + supervisory review + QA
  • audit reporting + finding ratings + remediation tracking through closure
Where this commonly fails
  • audit coverage gaps in cyber + IT + model risk + financial crime
  • CAE reporting line ambiguous
  • remediation tracking absent producing repeat findings

Risk Appetite and Limits

OCCHS-3
Risk Appetite Statement, Risk Limits, Concentration Risk, and Limit Breach Protocols

Maintain Risk Appetite Statement + Risk Limits + Concentration Risk Management + Limit Breach Protocols per 12 CFR Part 30 Appendix D Sections II.E + II.F + II.G + II.H + II.I + II.K. Risk Appetite Statement per Section II.E must (a) be a written statement of aggregate risk the covered bank is willing to accept in pursuit of strategic objectives + with qualitative and quantitative components, (b) cover all material risk categories per the Risk Governance Framework, (c) include forward-looking elements addressing the planning horizon and stress scenarios, (d) be approved by the Board + reviewed at least annually + revised after significant change. Risk Limits per Section II.F must (a) be quantitative and qualitative limits cascading from the Risk Appetite Statement to business unit + product + portfolio + risk category granular limits, (b) be approved by management and the Board as approp

Artefacts an auditor will ask for
  • Board-approved Risk Appetite Statement covering all material risk categories with quantitative + qualitative elements
  • cascade from RAS to business unit + product + portfolio limits with documented enforcement
  • concentration risk register + limits + monitoring + escalation
  • limit breach log + escalation evidence + remediation tracking
Where this commonly fails
  • RAS exists but no cascade to operational limits
  • concentration risk identified but not limited or monitored
  • limit breaches occur without documented escalation

Risk Data, Talent, Compensation, Strategy

OCCHS-7
Risk Data Aggregation, Reporting, Talent, Compensation, and Strategic Planning

Operate Risk Data Aggregation and Reporting + Talent Management + Compensation + Strategic Planning per 12 CFR Part 30 Appendix D Sections II.J + II.L + II.M + II.D. Risk Data Aggregation and Reporting per Section II.J must (a) provide the Board + senior management + Independent Risk Management with timely + accurate + comprehensive + consistent + relevant risk information across business lines + risk categories + with appropriate granularity, (b) align with BCBS 239 Principles for Effective Risk Data Aggregation and Risk Reporting as supervisory expectation for global systemically important banks, (c) integrate technology + data governance + data quality + reconciliation processes + capability to produce risk reports under stress conditions. Strategic Plan per Section II.D must (a) be a written multi-year strategy covering business objectives + risk objectives + capital + liquidity + ea

Artefacts an auditor will ask for
  • BCBS 239-aligned risk data aggregation programme with technology + data governance + data quality + reconciliation
  • ability to produce risk reports under stress conditions evidence
  • Board-approved multi-year Strategic Plan aligned to RAS
  • talent management with succession + leadership development + diversity
  • compensation framework with risk-aligned incentives + clawback + malus + Board oversight
Where this commonly fails
  • BCBS 239 progress stalled without continuing investment producing repeated supervisory findings
  • Strategic Plan not aligned to RAS producing risk decisions inconsistent with strategy
  • compensation includes excessive short-term risk-taking incentives

Risk Governance Framework

OCCHS-2
Risk Governance Framework: Three Lines of Defense, Scope, and Charter

Establish and maintain a Risk Governance Framework per 12 CFR Part 30 Appendix D Sections II.A and II.B. The Framework must (a) be a written articulation of the covered banks risk management framework with documented charter and approval by the Board, (b) cover comprehensively the risk areas of credit + interest rate + liquidity + price + operational + compliance + strategic + reputation risk + additional risks as warranted by the covered banks risk profile, (c) be tailored to the covered banks risk profile + size + complexity + nature of activities + scope of operations, (d) align with the three-lines-of-defense model per Section II.C: front line units (Section II.C.1) own and manage risk in their activities + independent risk management (Section II.C.2) provides oversight + internal audit (Section II.C.3) provides independent assurance, (e) be reviewed and approved by the Board at leas

Artefacts an auditor will ask for
  • written Risk Governance Framework with Board-approved charter
  • three-lines-of-defense responsibility matrix aligned to Section II.C.1/2/3
  • annual review and approval evidence with significant-change-triggered review
  • operational integration evidence (capital + new product + remediation prioritisation)
Where this commonly fails
  • Framework documentation disconnected from operational decisions
  • three lines of defense roles unclear in actual operations
  • annual review skipped or perfunctory

Scope and Applicability

OCCHS-1
Scope, Applicability, and Definitions of Heightened Standards

Determine scope and applicability of the OCC Heightened Standards per 12 CFR Part 30 Appendix D Section I and the OCC Heightened Standards for Large Banks final rule (effective November 2014 + revisions). The standards apply to (a) insured national banks + insured Federal savings associations + insured Federal branches of foreign banks with average total consolidated assets of USD 50 billion or more (a covered bank), (b) any insured national bank or Federal savings association the OCC notifies must comply, (c) banks below the 50 billion threshold may be voluntarily covered by their own decision or by OCC direction based on risk profile + complexity. Definitions in Section I.E apply throughout including covered bank + parent company + business line + front line unit + independent risk management + internal audit + risk + compliance risk + credit risk + interest rate risk + liquidity risk

Artefacts an auditor will ask for
  • covered bank status determination with documented threshold analysis
  • definitions inventory aligned to Section I.E
  • communication and phased implementation plan per Section IV
Where this commonly fails
  • sub-threshold bank adopts voluntarily without documenting scope producing ambiguous regulatory engagement
  • definitions inconsistent across policies

Third-Party Risk and Regulatory Integration

OCCHS-8
Third-Party Risk Within Heightened Standards and Integration with Broader Regulation

Operate third-party risk within Heightened Standards + integrate with broader bank regulation. Third-party risk per Heightened Standards must (a) integrate with OCC Bulletin 2013-29 Third-Party Risk Management + Interagency Guidance on Third-Party Relationships Risk Management (June 2023) jointly issued by OCC + Federal Reserve + FDIC, (b) cover all third-party relationships including critical relationships + cloud service providers + fintech partnerships + outsourcing arrangements + with risk-based diligence + contractual requirements + ongoing monitoring + termination management, (c) align with Risk Governance Framework + Risk Appetite Statement + Risk Limits + Internal Audit coverage. Integration with broader regulation must address (a) Federal Reserve SR 12-17 Consolidated Supervision Framework for Large Financial Institutions + SR 16-11 Supervisory Guidance for Assessing Risk Manage

Artefacts an auditor will ask for
  • third-party risk programme aligned to OCC 2013-29 + June 2023 Interagency Guidance with documented update
  • regulatory inventory + change monitoring + cross-regulator coordination via CCO
  • alignment evidence with Federal Reserve SR 12-17 + 16-11 + FDIC + CFPB + FinCEN + OFAC + state coordination
  • consumer financial law compliance evidence (HMDA + CRA + ECOA + FCRA + similar)
Where this commonly fails
  • third-party programme not updated to June 2023 Interagency Guidance
  • fintech partnerships handled outside third-party programme
  • regulatory inventory incomplete missing CFPB / FinCEN / OFAC
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the OCC Heightened Standards (12 CFR Part 30, Appendix D) framework page.