Skip to Main Content

Did you receive an Employee Retention Credit (ERC) that you now believe you were ineligible for? Since the ERC was announced, many ineligible claims have been filed, due to a variety of reasons, including companies working with ERC vendors that either did not understand the complexities or were not providing the due diligence necessary to ensure that the applications were complete and accurate.

The FDIC's Quarterly Banking Profile for first quarter 2026 reports the performance for the 3,852 community banks evaluated. Here are the key highlights: 

Note: Graphs are for all FDIC-insured institutions unless the graph indicates it is only for FDIC-insured community banks. 

Financial Performance 

  • Quarterly net income increased $302.7 million (3.9%) from the previous quarter to $8.1 billion, with 55.8% of community banks reporting an increase. 

  • Pretax return on assets increased to 1.42%, up 7 basis points quarter over quarter, increasing by 26 basis points year over year. 

  • Net interest margin decreased to 3.71%, down 6 basis points from the prior quarter; however, overall increased by 24 basis points year over year. 

Costs and Efficiency 

  • Noninterest expense decreased by $310 million (1.7%) from the previous quarter but has increased 6.4% year over year. 

  • Provision expense decreased by 34.4% quarter over quarter and 11.3% year over year, while asset quality indicators remained mixed.  

  • Efficiency ratio decreased to 61.87%, down 0.64% from the prior year first quarter, indicating increased cost control relative to revenue. 

Loan and Deposit Trends  

  • Loan and lease balances increased by $16.1 billion, or 0.8%, quarter over quarter and 5.4% year over year. Quarter-over-quarter growth was led by nonfarm nonresidential CRE loans, while year-over-year growth was led by nonfarm nonresidential CRE, 1–4 family residential real estate loans, and commercial and industrial loans. 

  • Domestic deposits rose 1.2% quarter over quarter and 4.6% year over year, with growth in both interest-bearing and noninterest-bearing accounts.

  • Nearly 58% of community banks reported loan growth, and about 69% reported deposit growth during the quarter. 

Asset Quality 

  • Past-due and nonaccrual loans (PDNA) increased 9 basis points to 1.44% from the previous quarter. 

  • Net charge-off ratio decreased 11 basis points from the prior quarter to 0.18%, continuing to be above the pre-pandemic average of 0.15%. 

  • Reserve coverage ratio continued to decline to 146.4%, as the allowance for credit losses decreased while noncurrent loan balances increased. 

Capital and Structural Stability 

  • Most capital ratios increased from the prior quarter. The tier 1 risk-based capital ratio for community banks that did not opt into the CBLR framework rose 13 basis points to 14.43%, while the average CBLR for banks using the framework remained relatively unchanged at 12.36%. The leverage capital ratio for all community banks increased 11 basis points to 11.15%. 

  • Unrealized losses on securities increased by $2.6 billion (8.9%) from the prior quarter to $32.2 billion in total.  

  • Community bank count declined by 59 during the quarter due to transitions, sales, mergers and acquisitions, and one community bank failure. 

Conclusion and Outlook 

The first quarter of 2026 reflected a modest increase in earnings performance for community banks. Quarterly net income increased $302.7 million (3.9%) from the prior quarter to $8.1 billion. Pretax return on assets improved by 7 basis points to 1.42%, marking a 26-basis-point increase from a year earlier. Net interest margin, however, edged down to 3.71%, declining 6 basis points from the previous quarter but remaining 24 basis points above the same period in 2025, suggesting that the benefits of higher asset yields may be stabilizing. 

Expense trends provided some relief during the quarter, supporting improved operating efficiency. Noninterest expenses declined by $310 million (1.7%) from the prior quarter, although they remain 6.4% higher year over year. Provision expenses fell significantly, decreasing 34.4% quarter over quarter and 11.3% year over year. As a result, the reserve coverage ratio continued to trend lower, falling to 146.4%, suggesting that reserve growth has not kept pace with rising levels of noncurrent loans. 

Balance sheet growth remained steady, with both lending and deposit activity continuing to expand. Loan and lease balances increased by $16.1 billion (0.8%) quarter over quarter and 5.4% year over year, driven primarily by growth in nonfarm nonresidential commercial real estate, 1–4 family residential mortgages, and commercial and industrial lending. Domestic deposits rose 1.2% during the quarter and 4.6% year over year, with gains in both interest-bearing and noninterest-bearing accounts. Growth was broadly distributed, as nearly 58% of community banks reported loan growth and approximately 69% reported deposit growth. 

Asset quality metrics presented a mixed picture. Past-due and nonaccrual loans increased 9 basis points to 1.44%; however, at the same time, the net charge-off ratio declined to 0.18%, down 11 basis points from the previous quarter but still above pre-pandemic levels of 0.15%. 

From a capital and structural standpoint, the sector remained sound. Regulatory capital ratios generally improved, with the tier 1 risk-based capital ratio for community banks that did not opt into the CBLR framework increasing to 14.43% and the leverage capital ratio for all community banks increasing to 11.15%. However, unrealized losses on securities grew by $2.6 billion (8.9%) during the quarter to $32.2 billion, reflecting some renewed pressure on securities valuations. 

Looking ahead, community banks enter the remainder of 2026 with improved earnings performance, better expense control, and steady balance sheet growth. However, evolving net interest margin dynamics, modest softening in certain asset quality indicators, and persistent unrealized securities losses may require continued vigilance. As economic conditions shift and consolidation trends persist, institutions will need to remain focused on disciplined credit management, efficient operations, and strategic growth. As the regulatory environment continues to evolve, BerryDunn's Federal Impacts page remains a valuable resource for timely updates that may affect your institution or its borrowers. We wish you continued success in 2026, and as always, your BerryDunn team is here to help.

Article
FDIC Issues its First Quarter 2026 Quarterly Banking Profile

Who this applies to: Owners, administrators, CEOs, COOs, CFOs, finance directors, directors of nursing, HR, and IT at nursing facilities.

The Centers for Medicare and Medicaid Services (CMS) has strict regulations for reporting direct care staffing and census information through the Payroll-Based Journal (PBJ) system, requiring nursing facilities to report this information quarterly. CMS publishes the data and uses it to determine star ratings on the staffing component of the Nursing Home Compare website. While star ratings are obviously important for your facility’s reputation and ability to attract new patients and residents, there are other reasons that you should ensure that the data you submit on your PBJ is accurate and complete. This article offers nine actionable steps you can take to prepare your nursing facility for the CMS Payroll-based Journal audit.

Why accurate PBJ data is important 

The data you provide can be accessed by other regulatory agencies, including state licensing agencies, and may be used for licensing and complaint investigation surveys, with any identified non-compliance resulting in citations, fines, or penalties. In 2026, the Office of Inspector General (OIG) started PBJ data audits as they relate to medical director hours reporting. Some state Medicaid agencies utilize PBJ data in a variety of ways, such as to validate paid nursing hours reported on Medicaid cost reports. Facilities need to be aware of a wide range of potential data uses and have comprehensive internal data review procedures to help ensure the public use file reflects accurate reporting and that the facility is prepared for an audit.

PBJ Data Specifications revisions 

A revised version of the PBJ Data Specifications (Version 4.10.0) is required as of April 2026.  Another recently announced change is that, effective August 17, 2026, the PBJ system will transition to the Internet Quality Improvement and Evaluation System (iQIES). This change impacts an organization’s access to the reporting platform because it requires an HCQIS Access Roles and Profile (HARP) login to access iQIES. Please note, similar to the Provider Statistical and Reimbursement (PS&R) report, providers have an option to request different levels of access to PBJ: 

Access level  Available actions Recommended for 
Provider Security Official (PSO) - required
  • Approve other user access requests
  • View, upload, edit, and submit PBJ data
  • Run PBJ reports
Senior leadership of the organization
PBJ Submitter (Provider or Vendor)
  • View, upload, edit, and submit PBJ data
  • Run PBJ reports
Primary PBJ submitter and back-up
Provider Administrator
  • Run PBJ reports
Facility administrator, director of nursing
PBJ Viewer View-only access with the ability to run PBJ reports HR, Finance, IT, Compliance, or consultants

According to CMS provider file data published June 1, 2026, about 4% of Skilled Nursing Facilities (SNFs) nationwide missed PBJ submission, submitted incorrect/unverifiable data, or failed a PBJ audit. 

Best practices for timely, accurate PBJ reporting 

1. Maintain and test access to the reporting portal(s) 

With turnover and planned and unplanned absences, we recommend that at least two staff members maintain logins and practice submitting reports. With the PBJ reporting transition to iQIES in August 2026 and April – June 2026 reports due by November 14, 2026, it is critical that facilities establish all required access (including back-up personnel) ahead of the reporting deadline. The iQIES Service Center is projecting an increase in the volume of calls and emails between July 2, 2026, and August 14, 2026, in preparation for this transition.  

2. Understand that less might be more  

PBJ reporting includes required and optional elements. The optional data may include worked hours for other service workers. Evaluate whether your organization should report optional data elements. If you opt to report this type of data, be sure that it is accurate and complete. 

3. Plan ahead and consider more frequent submissions 

Allow your team enough time for review after the quarter ends, but prior to the cut-off date. It is a requirement to file quarterly, but you may also submit data more frequently, such as after processing each pay period. This approach allows for more timely identification of employee classification issues or technical challenges. It also gets responsible staff into the habit of maintaining records on an ongoing basis, rather than as a quarterly event.  

4. Don't forget to verify your submission  

Do not skip the confirmations and available reports for review prior to the deadline. A frequent mistake we see in the industry is related to not reading acceptance/rejection reports carefully and assuming that the submission was accepted as submitted. Once the final data file is uploaded, SNF/NFs need to check their Final File Validation Report to verify that the data was submitted successfully. Please be aware that it may require up to 24 hours for the validation report to be available and allow for time to correct any errors and resubmissions, if needed. 

5. Make finding a needle in a haystack easier 

Carefully review and summarize data as described in the PBJ Report User Guide (CASPER Section 12 – Reports). We recommend obtaining all related reports (in CASPER, “D” at the end of the report number indicates detailed reports and “S” refers to summary reports). We recommend utilizing Excel data summarization tools to carefully review data. To help facilities with transition from CASPER to iQIES reporting, below is a list of available reports in both systems. 

Please note that users will only be allowed to run reports for the providers to which they have access with their iQIES role. The iQIES reports are expected to contain the same information as the CASPER reports, updated to have the iQIES formatting. CMS planned to migrate previous submissions for up to 10 years, which will allow users to run all reports except the Submitter Final Validation report for data submitted in QIES and iQIES (see notes in table below). 

CASPER Report Number and Title iQIES Report Description  Available download formats  Use for 
1700D - Employee Report  PBJ Employee Report  Lists the active and/or terminated employees associated with a facility during a specified period  PDF or CSV Verify all employees have a unique ID 

Notes: 

  1. All PBJ reports in iQIES can be located in Report Category/Report Type: Payroll-Based Journal/Staffing. 
  2. The use of the term Contractor was replaced with Contract throughout the report to match PBJ Specifications. 
1702D - Individual Daily Staffing Report PBJ Individual Daily Staffing Report Details facility staffing information during a specified period by Employee ID  PDF or CSV Use pivot table to summarize and review hours by employee or position / category and period (recommend daily, weekly, and monthly reports).
Note differences from CASPER report: The ‘Only Include Data Accepted Prior to the Deadline’ filter on the report criteria page is no longer applicable and will not be available in the iQIES report.
1702S - Staffing Summary Report  PBJ Staffing Summary Report  Summarizes staffing information by job title for a facility during a specified period. PDF or CSV Review summary of hours reported for the quarter to help ensure staff or contractor reports are submitted. Consider comparing this report to the prior quarter.
1703D - Job Title Report  PBJ Job Title Report  Details by work date the staffing hours submitted for select job title(s) during a specified period.  CSV/Excel Review hours by job title and classification. 
Note differences from CASPER report: The ‘Only Include Data Accepted Prior to the Deadline’ filter on the report criteria page is no longer applicable and will not be available in the iQIES report. The use of the term Contractor was replaced with Contract throughout the report to match PBJ Specifications.
1704S,1704D - Daily MDS Census Summary Report PBJ Daily MDS Census Summary Report Provides daily facility census counts for a specified period. Lists the IDs of the residents included in daily facility census counts for a specified period. PDF or CSV Use to reconcile to your internal total daily census.
1705D - PBJ Staffing Data Report PBJ Staffing Data Report

Identifies areas of concern that may trigger follow-up during the survey, including:  

  • Failed to submit data for the quarter  
  • Excessively low weekend staffing  
  • One-star staffing rating  
  • No RN hours  
  • Failed to have licensed nursing coverage 24 hours/day  
PDF Review compliance and error triggers summary (triggered or not triggered, metric suppressed due to invalid data, new facility, special focus facility).
FFVR - PBJ On Demand Final File Validation Report PBJ On Demand Final File Validation Report Indicates whether the submitted file was accepted or rejected and details the warning and fatal errors applicable to the data or the data file structure submitted. PDF Use to confirm submission and acceptance.
Note differences from CASPER report: The 60-day waiting period for requesting the on-demand PBJ Final Validation Reports has been removed to account for new access in iQIES and the QIES system-generated Final Validation Reports being unavailable in the iQIES PBJ Final Validation folders.
PBJ System-generated Final Validation Report PBJ System Generated Final File Validation Report Indicates whether the submitted file was accepted or rejected and details the warning and fatal errors applicable to the data or the data file structure submitted. PDF Use to confirm submission and acceptance.

Notes:

  1. Differences from CASPER report: The system-generated Final Validation Reports in QIES (system used prior to August 2026) will not be migrated into iQIES. Users will be allowed to access CASPER to obtain these until they are automatically deleted based on the report's retention time period, if desired. Alternatively, users can generate the iQIES user-requested final validation reports for submissions performed in QIES if it is more convenient.
  2. The iQIES report now includes a CMS Certification Number (CCN), and error sections such as General, Staffing, Employee, or Employee Link have been delineated to make the report more intuitive for users.

iQIES users can schedule reports to run at their preferred frequency. Review these reports to help ensure the quarterly PBJ data reflects your records. Most of the detail reports (D) are available as a .csv file download, which is instrumental with the assistance of Excel templates to simplify and expedite your review. We recommend using pivot tables, data filtering, and conditional formatting rules to bring attention to potential errors, omissions, or high-risk audit areas, including:

  • Any days without at minimum eight RN hours
  • Exempt staff with >40 reported worked hours per week
  • Non-exempt (hourly) staff with more than 80 hours per week or >300 hours per month
  • High or low average total nurse (aides, LPNs, and RNs) staffing (less than two and more than five hours per patient day. Visit BerryDunn’s senior living self-service benchmarking portal for comparison to your peers
  • Changes in total average nurse staff hours per patient day by over 10% compared to the previous quarter(s)

6. Share the knowledge with PBJ reporting and management teams

Educate your PBJ reporting and management oversight team, discuss, and gain clarity on your internal record-keeping policies and procedures. Obtain the most recent manuals. We recommend electronic bookmarks to the CMS site rather than printed paper copies, as the guidance may change.

7. Trust but verify to help ensure compliance

While you may have complete trust in your team, nobody is immune to an occasional mistake or omission. Responsibility for PBJ compliance is with facility leadership. Review the reports carefully and make timely corrections.

8. Keep a close eye on the Nursing Home Compare website

Check the CMS nursing home compare information for your facility regularly to help ensure information is correct.

9. Don't panic: It is fixable!

If you have an unfavorable PBJ audit, there are actions you can take to remedy the situation and avoid it in the future. We suggest that your team:

  • Includes the PBJ program compliance review in your QAPI initiatives, which makes it a multi-departmental challenge to get back on track and prevent any future non-compliance
  • Engages your communications team in crafting a meaningful response to any potential community inquiries if you receive a one-star rating in staffing. Be prepared to describe the issue objectively and without blame, while outlining the steps the facility is taking to improve.
  • Takes an objective look at your systems. Consider an external consultant to help with identification of the process gap and ideas for sustainable remediation.

If you have any questions, please reach out to Olga Gross-Balzano or a member of BerryDunn’s Senior Living team of experts.

Article
Nine ways nursing facilities can prepare for a CMS PBJ audit

Research institutions are built for discovery. Decentralized teams, specialized tools, and flexible environments make innovation possible, but they also introduce complexity when it comes to cybersecurity.

At the same time, expectations are rising. Federal agencies and data-sharing partners increasingly require compliance with frameworks like NIST 800-171 and NIST 800-53, along with detailed System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms).

For many institutions, the challenge isn’t whether to comply. It’s how to do it without disrupting research.

The core challenge: Decentralization

Unlike traditional IT environments, research settings aren’t centralized. Labs, departments, and research teams often operate independently, using their own devices, systems, and workflows.

That flexibility is essential, but it can lead to:

  • Inconsistent security practices
  • Gaps in documentation
  • Added strain on IT and security teams
  • Increased risk during audits or reviews

Over time, even well-intentioned efforts can become fragmented.

Where institutions start to see friction

Most research institutions aren’t struggling because they lack security tools. The friction tends to show up in a few common ways:

  • Unclear ownership of security responsibilities across central IT, leadership, and research teams
  • SSPs and POA&Ms developed inconsistently across environments
  • Security controls that don’t fit the realities of research environments
  • Duplicated effort across labs and departments

These challenges are often operational, not technical.

A more practical path forward

Leading institutions are shifting their approach. Instead of trying to force uniform controls across every environment, they’re focusing on coordination, clarity, and scalability.

A few principles consistently make a difference:

Define roles clearly
Security works best when responsibilities are shared and understood across leadership, central IT, and local research teams. Clarity reduces duplication and keeps efforts aligned.

Standardize where it makes sense
Common controls—like identity management, logging, and training—can often be managed centrally and applied across environments. This reduces the burden on individual research teams.

Document with intent
SSPs and POA&Ms shouldn’t be treated as one-time compliance exercises. When used effectively, they become tools for tracking progress, managing risk, and improving consistency.

Adapt controls to the environment
Research environments will always have unique needs. The goal isn’t perfection; it’s demonstrating that risks are understood, documented, and actively managed.

From compliance burden to operational advantage

When cybersecurity is coordinated across the institution, it stops being a reactive exercise and starts supporting the research mission.

Institutions that take this approach often see:

  • More consistent and manageable compliance processes
  • Better visibility into risk across environments
  • Less duplication of effort between teams
  • Greater confidence from funders and partners

Most importantly, researchers can stay focused on their work—without navigating unnecessary barriers.

Go deeper: A practical roadmap for research cybersecurity

This overview highlights what’s possible, but implementing it takes a more structured approach.

In our ebook, Practical Strategies for Managing Cybersecurity in Research Environments, we break this down further, including:

  • How to define roles and responsibilities in distributed settings
  • Common areas where security controls create friction—and how to approach them
  • Frequent compliance gaps and ways to address them
  • Scalable strategies for managing security across multiple environments

If your institution is working to balance compliance requirements with the realities of research, the ebook provides a clear, practical next step.

Download the full ebook to learn how to strengthen your security posture while keeping research moving forward.

How BerryDunn can help

BerryDunn’s cybersecurity team brings deep industry expertise and recognized certifications to every engagement. We work closely with clients to bridge the gap between technical teams and leadership—delivering clear insights, tailored solutions, and lasting security improvements through transparent collaboration. Learn more about our cybersecurity team and services. 

Article
Securing research without slowing it down: A smarter approach to cybersecurity

Who this article applies to: CFOs, controllers, and internal audit professionals at financial institutions

Occupational fraud remains a persistent and costly risk for financial services organizations. In its 2026 Report to the Nations, the Association of Certified Fraud Examiners studied 2,402 fraud cases globally totaling more than $3.4 billion in losses across industries, including financial services. The report estimates that organizations lose about 5% of annual revenue to fraud, underscoring that no institution is immune. Equally important, many organizations never fully recover those losses, with over half of victims recovering nothing, highlighting the need for a proactive fraud risk management approach rather than post-event remediation.

Risk profile for banks and investment firms 

The report includes targeted insights for the banking and financial services sector: 

  • Median loss per case: $100,000 
  • Average loss per case: $1,535,000 
  • Median duration: 8 months  

These figures are consistent with overall global trends, but the financial sector’s exposure to high-value transactions, complex systems, and regulatory scrutiny increases both the potential impact and reputational risk associated with fraud events.

Fraud types most relevant to financial institutions 

The report identifies three primary fraud categories: 

  • Asset misappropriation: 90% of cases; lower median loss 
  • Corruption: 45% of cases—includes conflicts of interest and kickbacks; moderate loss 
  • Financial statement fraud: 6% of cases; highest losses at $1 million median

Within financial services, asset misappropriation-related schemes are most prevalent. However, although financial statement fraud is less frequent, it presents the greatest dollar exposure. 

Fraud detection and why whistleblower programs matter 

Because fraud losses escalate over time, improving detection is one of the most effective ways to limit impact. Key insights include: 

  • 43% of fraud cases were detected through tips, over half of which came from employees. 
  • Email and web-based reporting channels are now more commonly used than hotlines. 

Institutions with strong whistleblower frameworks and accessible reporting channels are significantly better positioned to detect fraud early and minimize losses. The most effective frameworks are comprehensive, independent, and trusted by employees.

Higher roles, higher fraud exposure 

Fraud risk is closely tied to access and authority, requiring strong governance and oversight. Employees and managers commit most fraud, but executives cause the largest losses, with risk increasing alongside authority, tenure, and collusion.

Behavioral red flags 

Most perpetrators exhibit warning signs, such as financial pressure or unusual relationships. Behavioral monitoring can enhance fraud detection, particularly for high-risk roles. Always consider the components of the fraud triangle: incentive, opportunity, and rationalization. 

Internal control failure   

Approximately 70% of fraud cases involve control failures rather than absence of controls. For regulated institutions, this highlights the need for effective execution and monitoring of controls, not just design.  

Core controls include management review, data monitoring, and surprise audits. Fraud awareness training and regular reassessment of risk frameworks are also essential, as many organizations still respond to fraud reactively rather than proactively.

Aligning fraud risk management with strategic decision-making 

Fraud risk extends beyond operations to compliance, governance, and reputation. Organizations that emphasize active monitoring, strong controls, and a culture of accountability are best positioned to reduce losses and strengthen risk management. In our complimentary whitepaper on preventing financial institution fraud, we take a deeper look at how to successfully implement a strong anti-fraud plan. Commit to enhancing fraud prevention to build trust with your board, employees, customers, and the broader public—an investment that delivers strong value for any financial institution. 

Key takeaways

  • Recognize persistent fraud risk, with organizations losing an estimated 5% of annual revenue to fraud and many recovering none of those losses. 
  • Improve detection by strengthening whistleblower programs and digital reporting channels, especially for employees. 
  • Address high-impact fraud by focusing on asset misappropriation while monitoring high-cost financial statement fraud. 
  • Increase oversight of senior roles, where fraud risk and losses are greater. 
  • Check internal controls with monitoring, management review, and ongoing risk assessment. 

BerryDunn can help 

Our risk management team helps clients develop and implement effective risk management programs tailored to each organization’s size, risk level, and resources. Learn more about our team and services.

Article
Financial services fraud: Why proactive detection matters

Who this article applies to: Executives at financial institutions

Generative AI (GenAI) is rapidly moving from experimentation to operational reality across banking—powering loan analysis, automating reconciliations, summarizing regulatory updates, and supporting customer interactions. While the upside is clear, the risks are equally significant: hallucinated outputs, data leakage, model drift, and opaque decision-making can undermine financial reporting, compliance, and customer trust if not properly governed. 

The COSO framework—long the backbone of internal control over financial reporting (ICFR) for financial institutions—remains fully applicable. The difference is not whether banks need new frameworks, but how they apply existing control principles in a GenAI environment. 

This article highlights the most practical actions bank executives can take to implement GenAI with confidence, inspired by COSO’s recent Achieving Effective Internal Control over Generative AI white paper. We’ve distilled the white paper into our 10 biggest takeaways. 

1. Start with a capability-based view of AI (not tools) 

One of COSO’s most actionable insights is to shift focus from vendors or tools to what the AI actually does. GenAI capabilities fall into eight categories: ingestion, transformation, transaction processing, orchestration, judgment/forecasting, monitoring, knowledge retrieval, and human interaction.  

Why this matters for banks: 

  • Risk is different at each stage 
    • Data ingestion → data quality, personally identifiable information (PII) leakage 
    • Transaction automation → financial misstatement risk 
    • Forecasting → credit and liquidity risk 
  • Controls should be placed where risk originates, not generically across “AI” 

Practical takeaway: 

Inventory every AI use case and tag it by capability type. This becomes the foundation for: 

  • Risk assessments 
  • Control design 
  • Audit scoping

2. Treat GenAI outputs as “claims,” not facts 

GenAI is probabilistic and can be confidently wrong. For financial institutions, this is a critical mindset shift:

Practical controls: 

  • Require human validation for material outputs (e.g., financial reporting, credit memos) 
  • Implement: 
    • Confidence thresholds 
    • Source citation requirements 
    • Exception routing workflows 
  • Separate AI assistance from final decision authority 

Executive implication: 

If management or auditors are relying on AI outputs, those outputs must meet ICFR-level evidence standards (documentation of prompts, data sources, versioning, etc.). Furthermore, developing built-in confidence thresholds will help to identify those results that are potentially less accurate and thus need additional human validation. Those outputs that meet or exceed confidence thresholds may require less human intervention.

3. Build governance before scaling use cases 

A recurring risk is “shadow AI”—teams deploying tools outside formal governance. Thus, it is important to establish a formal governance structure and policies so employees know what acceptable use looks like at your institution. This should be the first step in any AI tool deployment and, if done with an institution-wide focus, can serve as the foundation for assessing and deploying any AI tool throughout the institution. 

Practical governance model: 

Establish a cross-functional AI governance committee: 

  • Risk and compliance 
  • IT/security 
  • Finance 
  • Business leadership 

Responsibilities: 

  • Approve high-risk use cases 
  • Set acceptable use policies 
  • Monitor incidents and Key Risk Indicators (KRI)

Key policy areas: 

  • Prohibited data (e.g., customer PII in public tools) 
  • High-risk use cases (e.g., lending decisions) 
  • Model and vendor approval standards 

In addition to the departments mentioned above, consider having individuals that will be using these tools daily on the committee. Furthermore, when identifying those individuals, try to find someone that is passionate about AI. These individuals will naturally keep the committee apprised of AI trends and, when it comes time to deploy AI tools, will be champions at your institution, driving change throughout the organization.

4. Define clear “reliance boundaries” upfront 

One of the most important—and often overlooked—steps in implementing GenAI is deciding where the bank will (and will not) rely on AI outputs. 

The COSO white paper introduces a critical concept: Reliance occurs when management depends on AI outputs as evidence supporting a control or decision. 

Why this matters for banks: 

Once you rely on AI outputs, you are effectively: 

  • Bringing the process into ICFR scope 
  • Triggering audit evidence requirements 
  • Increasing regulatory exposure 

Practical implementation: 

  • Classify each use case by reliance 
    • Non-reliance (low risk):  
      • AI drafts, summarizes, or assists 
      • Human fully re-performs or validates 
    • Reliance (high risk):  
      • AI outputs are used directly in decision-making or control execution. 
    • Align with key banking processes: 
      • Financial reporting → High likelihood of reliance 
      • Credit decisions → High likelihood of reliance 
      • Back-office productivity tools → Typically non-reliance 

Executive implication: 

Do not treat all GenAI use cases equally. Instead, draw a clear line between “assistive AI” and “decision-driving AI.” 

That single distinction will: 

  • Simplify governance 
  • Focus control investment 
  • Avoid unnecessary audit complexity 
  • Reduce regulatory risk 

5. Expand risk assessment to new AI-specific threats 

Traditional risk frameworks are not enough. GenAI introduces new risk categories: 

High-priority risks for banks: 

  • Hallucinations (incorrect but plausible outputs) 
  • Prompt injection attacks (malicious inputs manipulating models) 
  • Model drift (performance degradation over time) 
  • Third-party/vendor risk (limited visibility into models) 
  • Bias/fair lending implications  

Practical approach: 

  • Maintain a living risk register that is frequently reviewed and updated 
  • Include “What if?” scenario analysis: 
    • What if a vendor updates the model without notice? 
    • What if training data changes? 
  • Link risks to key reporting initiatives (e.g., accuracy thresholds, exception rates)

6. Elevate “configuration” to a controlled asset 

In GenAI, controls are not just around systems—but around: 

  • Prompts 
  • Retrieval data 
  • Model settings 

These are effectively new financial reporting control points. 

Practical controls: 

  • Version control for prompts and configurations 
  • Formal approval workflows for changes 
  • Logging of: 
    • Inputs 
    • Outputs 
    • Model versions 

Executive implication: 

Treat GenAI configurations like core banking system configurations—subject to the same change management rigor. Specific to prompting, develop a prompt library with widely used prompts. Encourage employees to visit this prompt library prior to developing their own prompt. Establishing this protocol will assist in creating consistent outputs for similar tasks.

7. Design controls that scale with automation 

GenAI can amplify both efficiency and errors. 

Leading practices: 

  • Human-in-the-loop review for high-risk decisions 
  • Multi-model validation for critical outputs 
  • Automated monitoring for anomalies and drift 
  • Segregation of duties (separate model configuration from approval) 

Example

Auto-reconciliation: 

  • Auto-post only above validated confidence threshold. 
  • Route exceptions with full audit trail. 
  • Require approval for threshold changes. 

For instance, incoming invoices are routed through an AI tool that attempts to categorize and record the journal entry associated with the invoice. The tool has been trained that if it is not confident in the journal entry, it will suggest one, but it will not be posted until a manual review occurs. 

8. Strengthen data provenance and traceability 

Banks must be able to answer: 

  • Where did this output come from? 
  • What data was used? 
  • Which model generated it? 

Practical requirements: 

Capture and retain: 

  • Prompts and inputs 
  • Source data references 
  • Output versions 
  • Confidence scores  

Why this matters: 

  • Auditability 
  • Regulatory defensibility 
  • Root cause analysis

9. Monitor continuously—not periodically 

GenAI environments change rapidly (model updates, data shifts, usage patterns). As mentioned earlier, this is why it is important to maintain a living risk register. 

Practical monitoring strategy: 

Combine: 

  • Real-time dashboards (accuracy, exceptions, drift) 
  • Periodic deep reviews (model validation, bias testing) 

Key metrics: 

  • Accuracy / precision / recall 
  • Hallucination rate 
  • Data leakage incidents 
  • Forecast variance 

Action triggers: 

  • Retrain models 
  • Roll back changes 
  • Escalate to governance committees 

Example

Forecasting: 

An AI tool is used to forecast credit losses, which is then used as an input in a financial institution’s current expected credit loss model. This forecast is temporarily compared to actual results and, if forecast variances exceed a certain threshold for consecutive comparisons, the tool is retrained. 

10. Follow a simple, repeatable implementation roadmap 

COSO outlines a practical six-step cycle: 

  1. Establish governance 
  2. Inventory use cases 
  3. Assess risks 
  4. Design controls 
  5. Implement and train 
  6. Monitor and adapt  

Executive takeaway: 

This is not a one-time project—it is a continuous control cycle, similar to ICFR. 

Bottom line for bank executives 

GenAI is not simply a technology initiative—it is a control environment transformation. 

Banks that succeed will: 

  • Integrate GenAI into existing control frameworks. 
  • Treat AI outputs as risk-bearing assertions. 
  • Build governance before scaling. 
  • Design controls that evolve with the technology. 

Banks that do not succeed may be subject to: 

  • Financial reporting errors 
  • Regulatory findings 
  • Reputational damage 

Strong internal controls do more than reduce risk—they help institutions align GenAI initiatives to enterprise strategy, scale adoption responsibly, and improve value realization by making AI-enabled processes more reliable, repeatable, and trusted. 

Done well, GenAI becomes not just efficient—but auditable, reliable, and strategically differentiating. That matters at the enterprise level because strong controls give leadership the confidence to move beyond isolated pilots and embed AI into broader transformation priorities. In that way, governance and control disciplines are not barriers to innovation—they are enablers of sustainable adoption, measurable business impact, and long-term value realization.

BerryDunn can help 

If you have any questions about GenAI and internal controls at your bank, please reach out. Learn more about our team and services. 

Article
10 steps for bank execs to turn GenAI into a controlled advantage