Year-end compliance work is mostly annual obligations that have been accruing quietly since January. Nothing on this list is difficult; the difficulty is that all of it lands in the same eight weeks, alongside the Call Report, the audit, and the budget.
The institutions that handle it well start in October and treat the list as a project with owners and dates rather than as a season.
Risk assessment refresh. Update for new products, new markets, changes in customer composition, acquisitions, and regulatory developments. Document the date, the methodology, and what changed since the prior version.
Independent testing. Confirm it was performed for the year, that its scope covered the program's pillars and included transaction testing, and that every finding has a remediation status. Unresolved prior findings are treated far more seriously than new ones.
Training completion. Verify that all appropriate personnel completed role-specific training, and that the board received its own training. Retain records of who, when, and on what content.
CTR exemption annual review. Every Phase I and Phase II designation requires confirmation of continued eligibility. An exemption not reviewed is an unsupported exemption, and every CTR not filed during that period becomes a potential violation.
Customer information refresh. Check the backlog of customers whose due diligence information exceeds the refresh interval, and report the aging.
314(a) and OFAC. Confirm responses were made on schedule and that screening is running against current lists.
HMDA LAR. Scrub through the year and prepare for submission, generally due March 1 — which means the work happens in January and February, not at year end, but the data quality is determined by what was captured all year.
Fair lending analysis. Run denial, approval, pricing, exception, and withdrawal rates by prohibited-basis group before the data becomes public. Follow outliers with comparative file review.
CRA. Confirm the public file is complete and current, the assessment area delineation still reflects the branch and lending footprint, and the community development inventory captured the year's loans, investments, and service hours.
Flood. Confirm determinations were made and documented, notices delivered, coverage maintained, and force placement performed where required. Check whether any map revisions moved properties into a special flood hazard area.
Loan review and risk ratings. Confirm ratings are current, criticized assets are properly graded, and the allowance calculation reflects them.
Adverse action notices. Sample for timeliness and for reasons that match the actual basis for denial and the HMDA denial reason reported.
Reg DD. Compare account disclosures to the current fee schedule line by line, and confirm the disclosed APY matches what the core system pays.
Maturity notices. Sample time accounts that matured during the year and confirm notices were sent on the required schedule.
Reg CC. Confirm the availability policy disclosure matches system configuration, and that exception holds during the year carried notices stating a permitted reason. Check whether the inflation-adjusted thresholds changed.
Escheatment. Identify dormant accounts and unclaimed items approaching the state's dormancy period, perform due diligence outreach, and calendar the reporting deadline for each state.
IRA required minimum distributions. Identify accountholders reaching the applicable age and notify them before year end, which is a service most institutions provide and a penalty most customers do not know about.
1099 and 1098 preparation. Interest, dividends, mortgage interest, acquisitions or abandonments, and cancellation of debt as applicable. Confirm name and TIN combinations to reduce mismatch notices, and solicit corrected certifications where prior notices were received.
Backup withholding. Confirm it was applied where required following B notices.
Call Report. Fourth-quarter preparation with the year-end complexities of the allowance, deferred taxes, and any accounting changes.
Annual board policy approvals. BSA/AML program, information security program, and whatever else the institution's policies require to be approved annually. Minute the approvals.
Information security. Confirm the annual report to the board was delivered, access reviews were performed, the incident response plan was tested, and vendor due diligence was refreshed for critical providers.
Business continuity. Confirm the plan was tested, including with critical third parties, and that findings were remediated.
Vendor management. Confirm critical vendor reviews were completed and current assurance reports obtained and read.
Regulatory change log. Confirm each development during the year has a documented applicability decision and, where applicable, evidence that the change was implemented and validated.
Complaint analysis. Compile the year's complaints by root cause, identify themes, and record what changed as a result.
Three practices separate institutions that finish calmly from those that do not.
Start in October. Most items require gathering rather than deciding, and the gathering can happen before the deadline pressure.
Assign a named owner and a date to each line, and track completion visibly. A checklist without owners is a list of things everyone assumes someone else is doing.
Distinguish what must be done by December 31 from what is merely annual. The risk assessment can be updated in November. The HMDA submission cannot happen before the year closes. Sorting the list by actual deadline rather than by category removes most of the artificial crunch.
Structured coverage of the underlying requirements is available across our bank compliance training, deposit compliance training, and BSA training catalogs.
A published checklist is a starting point and should not be adopted as an institution's actual year-end program, for three reasons worth stating plainly.
It is not tailored. The items above apply broadly, but an institution's obligations depend on its charter, size, products, states of operation, and regulator. A bank with no mortgage lending has no HMDA work; one operating in eight states has escheatment obligations this list treats as a single line. The institution's own compliance calendar, built from its own risk assessment and regulatory inventory, is the authoritative document.
It goes stale. Thresholds adjust, rules change effective dates, and requirements are added. A checklist reused unchanged for three years will confidently omit whatever appeared in year two.
It does not capture commitments. Outstanding examination findings, audit recommendations, board directives, and remediation plans have their own deadlines, and those are frequently the items with the most consequence attached. They belong on the year-end list alongside the recurring requirements, and no published checklist knows about them.
The productive use of a list like this is as a comparison — read it against your own calendar and investigate anything present here and absent there. What you find is either a genuine gap or a documented reason the item does not apply, and both outcomes are worth the hour.
Some of the most valuable year-end work is not required annually at all. It is work that has no natural deadline, which is precisely why it never happens.
Reconcile the policy inventory to reality. Institutions accumulate policies, and some describe processes that changed years ago. Reading each policy against what the department actually does surfaces both compliance gaps and policies that should be retired. Examiners read the policy and then test against it, so a policy describing a control the institution abandoned is worse than no policy.
Test a restore, not a backup. Confirming that backup jobs completed is not the same as confirming the institution can recover. Attempting an actual restore of a critical system, and timing it, routinely reveals that recovery takes far longer than the business continuity plan assumes.
Review access for people who changed roles. Periodic access reviews typically confirm that current entitlements are approved. They rarely ask whether someone accumulated access across three internal moves that now breaks segregation of duties. That question requires looking at the person rather than the entitlement.
Read a sample of your own SAR narratives as an investigator would, with no system access. Institutions measure filing timeliness and almost never measure whether the narratives are usable.
Pull twenty charged-off loans and read them from origination forward. The warning signs are almost always visible in the original file, and reading them in hindsight is the cheapest underwriting training available.
Ask the front line what the institution does that makes no sense. The answers identify controls that are being worked around, which is more useful than any self-assessment.
None of these produce a document a regulator asks for. All of them find things the required annual reviews are structured to miss, which is why the institutions that do them have fewer surprises.
The most useful thing an institution can do with a year-end checklist is stop having one.
A compliance calendar spreads the same obligations across twelve months, assigns each to an owner, and records the authority requiring it. The items above do not all belong in December — the BSA risk assessment can be refreshed in September, exemption reviews can be staggered by designation date rather than clustered, vendor reviews can follow contract anniversaries, and policy approvals can be distributed across board meetings rather than presented as a stack at the December session, where they receive the attention a stack receives.
Building one takes a day and produces three benefits beyond the workload smoothing.
It makes ownership explicit. Every recurring obligation has a named person, and gaps become visible as items with no owner rather than as tasks nobody happened to do.
It survives turnover. The compliance officer who leaves takes the undocumented calendar with them. A written one is the difference between a successor who inherits a program and one who reconstructs it from examination findings.
It answers an examiner's question directly. Asked how the institution ensures recurring requirements are met, a dated calendar with owners and completion evidence is a complete answer. A description of diligence is not.
The practical construction: list every recurring obligation with its authority, frequency, owner, and due date; add outstanding examination and audit commitments with their agreed dates; distribute the load so no month carries more than it can absorb; and review it quarterly rather than annually, because that is when a missed item is still recoverable.
One last observation about why year-end feels harder than it is. Most of these obligations became annual because someone decided a year was a reasonable interval, not because December is when they matter. The clustering is an artifact of the calendar rather than a feature of the risk, and an institution that recognizes that can move most of the work to whenever its own year is quietest. The items genuinely tied to the year end — the fourth-quarter Call Report, tax information reporting, and anything measured on a calendar-year basis — are a much shorter list than the one above.
October. Most items involve gathering evidence rather than making decisions, and the gathering can be completed before deadline pressure arrives. Institutions that begin in December are performing the same work with less time to investigate anything that turns out to be a genuine problem rather than a documentation gap.
CTR exemption annual reviews, board BSA training, IRA required minimum distribution notifications, escheatment due diligence outreach, and confirming that account disclosures still match the current fee schedule. Each is straightforward and each is missed because no single person owns it.
The submission is generally due March 1, so the filing itself happens after year end. But the data quality is determined by what was captured throughout the year, which is why quarterly scrubbing is far more effective than a single January review of twelve months of records.
Approval of the BSA/AML program and the information security program at minimum, plus whatever else the institution's own policies specify. The board should also receive its BSA training and the annual information security report. Every approval should be minuted, because the minute is the evidence.
By actual deadline rather than by regulatory category, with a named owner and date for each line and visible completion tracking. Sorting by deadline reveals that much of the work does not have to happen in December, which removes most of the artificial crunch.
No. It is a comparison tool. An institution's real obligations depend on charter, size, products, states of operation, and regulator, and no published list captures outstanding examination findings, audit recommendations, or board directives — which are frequently the items with the most consequence. Read a list like this against your own calendar and investigate the differences.


