Skip to content
Reference

Board Compliance Reporting: What Boards Receive and Why

The short version

Board compliance reporting is the periodic delivery of information about the state of an organization's compliance program to its board of directors or a board committee, so that the board can carry out its oversight duty. At a bank, the board approves the BSA/AML program (31 CFR 1020.210) and receives regular reports from the BSA officer on the status of compliance. A typical report covers program status, metrics and key risk indicators, findings and remediation, regulatory changes, and examination status, and the board's review is recorded in its minutes.

Board compliance reporting is the periodic delivery of information about an organization's compliance program to its board of directors, or to a committee the board designates, so that the board can oversee the program it is responsible for. The report is the main channel through which directors, who do not run the program, learn whether it is working. Its counterpart is the board minute: the written record that the board received the information, discussed it, and acted where action was needed.

The board's responsibility

Board oversight of compliance rests on regulation, supervisory guidance, and corporate law.

Supervisory guidance on board information

The Federal Reserve's Supervisory Guidance on Board of Directors' Effectiveness (SR 21-3, February 26, 2021) applies to domestic bank holding companies and savings and loan holding companies with $100 billion or more in total consolidated assets and to certain designated nonbank companies. It describes five attributes of an effective board, one of which is that the board directs senior management regarding the information the board needs. Its formal scope is limited to those firms.

For national banks and federal savings associations, the OCC's Director's Book: Role of Directors for National Banks and Federal Savings Associations (November 2020) describes directors' responsibilities and management's role. The companion Director's Reference Guide to Board Reports and Information (November 2020) states that sound board decisions depend on information that is timely, accurate, relevant, and complete, and gives examples of measures, questions, and warning signs across planning, operations, and risk management.

Contents of a compliance report

A compliance report to the board is normally organized around the following sections. The depth of each varies with the institution's size and risk.

SectionWhat it covers
Program statusWhether the program operates as approved; changes to policies, staffing, systems, or the risk assessment; items requiring board approval.
Metrics and key risk indicatorsMeasures of program activity and risk against thresholds, with trends over prior periods.
Findings and remediation statusOpen findings from examinations, independent testing, internal audit, and self-identification, with severity, owner, due date, and status, including items past due.
Regulatory changesNew or amended laws, rules, and guidance that affect the program, and the planned response.
Examination statusUpcoming or ongoing examinations, open supervisory matters, and progress on any enforcement action.
Required notificationsItems that must reach the board by rule, such as notice of SAR filings.

Management information and key risk indicators

Management information (MI) is the regular data that describes how a program operates. A key risk indicator (KRI) is a metric chosen because a change in it signals a change in risk, and it is reported against a threshold that triggers attention or escalation when breached. The Basel Committee's Principles for the Sound Management of Operational Risk (revised 2021) list key risk and performance indicators among the tools used to monitor operational risk, which the Basel Framework defines to include legal risk.

Common compliance KRIs include the following:

MI is most useful to a board when each metric is compared with a threshold and a prior period, when exceptions are explained rather than only counted, and when the report states what management is doing about each breach. A report that presents large volumes of undifferentiated data can obscure the items that require a decision; the OCC's reference guide and SR 21-3 both address the board's role in defining the information it needs.

Examiner packs

An examiner pack is the set of materials an institution assembles in response to an examination request. It is distinct from routine board reporting, but it draws heavily on board records. The FFIEC BSA/AML Examination Manual's Appendix H (Request Letter Items) asks for, among other things, the most recent written BSA/AML program approved by the board, with the date of approval noted in the minutes, and the results of independent tests performed since the prior examination, including management's responses and access to the workpapers. Examiners commonly review board and committee minutes and reports to assess whether the board received adequate information and exercised oversight. Consistency between what the board was told and what the program records show is therefore a practical test of reporting quality. Preparation practices are covered in the BSA/AML exam preparation article.

Who prepares and receives the report

The BSA officer or chief compliance officer prepares the compliance report, often with input from risk, legal, and internal audit. Many boards delegate detailed review to a risk, audit, or compliance committee, which reports to the full board. Internal audit and independent testers report their findings to the board or a committee directly, separately from management, so that the board receives an assessment of the program from a source independent of the people who run it. Reporting frequency is set by the board and by the institution's risk profile; quarterly reporting to a committee, with an annual review of the program by the full board, is a common arrangement.

Primary sources

Common questions

Is a bank board required to approve the BSA/AML program?
Yes. 31 CFR 1020.210 requires the anti-money laundering program to be approved by the board of directors or an equivalent governing body, and the FFIEC BSA/AML Examination Manual expects the approval to be noted in the board minutes.
What should a compliance report to the board include?
A typical report covers program status and changes, metrics and key risk indicators against thresholds, open findings and remediation status, relevant regulatory changes, examination status, and notifications required by rule, such as notice of SAR filings.
What is a key risk indicator in compliance reporting?
A key risk indicator is a metric selected because a change in it signals a change in risk, such as an aging alert backlog or overdue customer reviews. It is reported against a threshold that triggers escalation when breached.
Who does SR 21-3 apply to?
SR 21-3, the Federal Reserve's 2021 guidance on board effectiveness, applies to domestic bank holding companies and savings and loan holding companies with $100 billion or more in total consolidated assets and to certain designated nonbank financial companies.
What is an examiner pack?
An examiner pack is the set of documents an institution assembles in response to an examination request letter, such as the board-approved program, board and committee minutes and reports, the risk assessment, and independent testing results with access to workpapers.
About this library

This reference library is maintained by Rupture Labs. We perform BSA/AML independent testing and automated control testing against every record, with each requirement cited to its rule. Talk to a practitioner.