Summary
This is the second article in a three-part series. The first article examined what deregulation demands of institutions internally.
There’s no question that reduced federal friction creates real opportunities for financial institutions. The strategic challenge isn’t whether to pursue those opportunities but how, in what sequence, at what pace, and with what internal controls in place before committing time, money, and effort. Periods of deregulation tend to reward institutions that act early, but they also punish those that confuse permission with preparedness. Several key areas carry a genuine upside but also a specific trap for institutions that move without adequate planning.
The Office of the Comptroller of the Currency (OCC) has progressively been opening the door to digital asset activity by removing the supervisory non-objection requirement, permitting banks to hold digital assets, and authorizing crypto transactions. At the legislative level, the 2025 GENIUS Act created the first federal framework for payment stablecoin issuance. With banks no longer the sole beneficiaries of these changes, fintechs and crypto-native firms are operating on increasingly similar footing, which is reshaping competitive dynamics across payments, custody, and embedded finance.
The openings are real, but execution speed is where institutions get into trouble. Fintech partnerships, AI-driven underwriting, and real-time payment infrastructure are all moving faster than the legal and governance infrastructure can underpin them. A bank that signs a partnership agreement before resolving data governance, model risk, and vendor due diligence frameworks has simply shifted its risk exposure to the back office. This can cause issues that will only amplify with scale or the mere passage of time.
A more permissive approval environment has materially accelerated bank M&A activity. The operational complexity of merging core banking systems, loan origination platforms, and compliance data architectures is too often underestimated. Approving transactions without a defined integration risk assessment that includes system consolidation, timelines, and fallback plans is a governance failure.
The Consumer Financial Protection Bureau's withdrawal from active supervision of small-dollar lending has created opportunity for markets where compliance cost structures previously made such loans economically unfeasible. While the opportunity is real, it can be easily misread. New York, California, Pennsylvania, Massachusetts, and Connecticut have all expanded their consumer protection capacity in direct response to the federal pullback, with some hiring former CFPB officials and invoking Dodd-Frank's Section 1042 enforcement powers. The winners in this environment will be those that price state-level enforcement variability into product design and expansion decisions from the outset instead of attempting to retrofit controls after complaints, examinations, or enforcement actions surface.
In March, The Federal Reserve, OCC, and FDIC replaced 2023’s stringent large bank capital requirement proposal with a narrower framework and a modest decrease in overall capital requirements. But that just creates capacity, not strategy. The real decision facing institutions isn’t how much capital to free up but where to deploy it and under what assumptions. Discipline in capital deployment is what will separate institutions that build durable balance sheets from those that create the next stress event.
Shifts in enforcement posture elsewhere don’t extend to anti-money laundering regulations. FinCEN has been explicit that its AML approach isn’t becoming lighter but fundamentally different. Institutions that read the current environment as a signal to reduce AML investment are misreading it.
FinCEN has proposed modernizing the Bank Secrecy Act and implementing long-pending provisions of the Anti-Money Laundering Act of 2020. These reforms would shift the focus away from checklist-based technical compliance and toward measurable effectiveness and risk-based outcomes. The OCC, FDIC, and NCUA have proposed parallel alignment of bank-level BSA program rules with FinCEN's new framework.
FinCEN's customer due diligence exceptive relief order removes the requirement to re-identify and re-verify beneficial owners of existing legal entity customers at each new account opening. But less frequent re-verification increases the likelihood that ownership changes will go unnoticed, especially in complex or opaque structures. This can lead to exploitation by criminals, who can more easily hide control or ownership changes. And if banks start relying on risk-based updates only, they may end up applying more conservative thresholds.
While FinCEN has delayed implementation of its AML rule for registered investment advisers and exempt reporting advisers until 2028, the relaxed near-term compliance burden doesn’t mean that banks shouldn’t prepare. The direction of travel is clear: investment advisers are coming into the BSA framework. For banks with affiliated advisory operations or banking-as-a-service relationships with RIAs, the 2028 deadline should be treated as a planning horizon, not a signal that the obligation is off the table.
The final article of this series will explore how financial institutions can turn governance frameworks, technology architecture, and AI capabilities into durable competitive advantages.
Guidehouse is a global AI-led professional services firm delivering advisory, technology, and managed services to the commercial and government sectors. With an integrated business technology approach, Guidehouse drives efficiency and resilience in the healthcare, financial services, energy, infrastructure, and national security markets.