Seven areas to watch when evaluating risk—and how to keep your goals on track while you’re doing it.
How Community Banks Can Navigate Today's Risk Landscape
September 01, 2026 / By Elizabeth Judd
Seven areas to watch when evaluating risk—and how to keep your goals on track while you’re doing it.
If community bankers have a superpower, it’s assessing and addressing the risks their customers face. Strong community bank risk management starts with that instinct.
While understanding interest-rate, credit-quality and BSA/AML risk is standard fare, it gets trickier when risks suddenly change because of the rise of a new technology (generative AI, say) or heightened threats from abroad.
Scott Anchin, senior vice president of strategic initiatives and policy for ICBA, describes assessing risk as “a balancing act where a good deal of weighing is always involved.” That’s because community bankers need to address gathering storms without becoming so paralyzed that they miss out on whatever upside exists, too.
“Looking at risk is a good thing, but risk shouldn’t necessarily stop you,” says Anchin. “Risk is an opportunity to evaluate how best to manage [potential problems] while keeping in mind your forward-looking goals.”
Here are some key areas for evaluating risk.
Community bank data security: from cyber vulnerabilities to third parties
A wave of software vulnerabilities might soon come to light due to advancements in AI models, such as Anthropic’s Mythos, according to Anjelica Dortch, vice president of operational risk and cybersecurity policy for ICBA.
In fact, these vulnerabilities are already showing up. More than three-quarters (76%) of banking executives reported an increase in the number of cybersecurity attacks on their banks in the past year, according to KPMG’s 2026 Banking Technology Survey. As for the greatest emerging cybersecurity threats, KPMG identified AI-introduced vulnerabilities in code as the top concern at 63%.
Given the evolving AI environment, Dortch urges bankers to work closely with their vendors to identify potential weaknesses early and keep customers informed. For example, if a vulnerability is identified and the vendor assumes responsibility for fixing the issues, the community bank must communicate to customers that the system remains secure even when they’re offline for repair.
Dortch points out that more frequently occurring “system offline for updates” banners could erode consumer confidence, so this communication is critical.
She also encourages community bank leaders to map out in-depth plans for managing cyber threats.
“If an employee has to wake up an executive at 2 a.m. to get a decision, you’re already behind,” she says. “There should be a decision matrix in place, so the IT team doesn’t need to call someone in the middle of the night.”
Cybersecurity risk is an important part of vendor due diligence, a complicated issue that community bankers are increasingly adept at managing.
On this note, Andrew Pyles, president and CEO of $500 million-asset Eclipse Bank in Louisville, Kentucky, warns that monitoring third-party risk is necessary but no longer sufficient.
“Now we’re looking at fourth-party risk, too,” he says. “You need to ask: Who are your vendors’ vendors?”
Watch out for the resurgence in check fraud
Not all fraud is new. Recently, there’s been a massive rise in check fraud, with annual losses totaling around $21 billion, according to ICBA. In addition, in a 2025 annual fraud survey conducted by the Conference of State Bank Supervisors, check fraud ranked second in terms of absolute dollar losses, surpassed only by credit/debit card fraud.
“Technology makes it extremely easy for fraudsters to alter a check or create a brand-new check out of whole cloth based only on account information,” says Scott Anchin, senior vice president of strategic initiatives and policy for ICBA.
Educating all bank personnel, from tellers to back-office analysts, is key to managing check-fraud risk, says Anchin. He emphasizes the importance of studying fraudulent checks that went undetected to spotlight “lessons learned.”
He also is keen on newer, consortium-based technology tools that amass data from a broad swath of participating banks so new wrinkles on check fraud can be identified early.
Shadow AI and other AI risks
One of the thorniest challenges faced by Marion Community Bank in Marion, Alabama, is the rise of deepfakes, which is when criminals pose as bank regulators or employees to obtain funds or personally identifiable information (PII), says Angela Holifield, COO of the $350 million-asset community bank.
Holifield notes that the rise of deepfakes is fueled by the rapid spread of generative AI.
No question, AI is rewriting the dynamics of risks that community bankers have wrestled with for years—from making fraudulent documents look convincing to refining social-engineering tactics that dupe customers.
While AI is now front and center in many risk calculations, Dortch highlights two overlooked AI risks.
First, there’s “the shadow AI problem,” which is when employees use AI solutions that have not been fully vetted by a bank’s internal IT team. Breaches can arise when an AI solution has lax data security terms and conditions, which risks customer information being uploaded and used to train a model or shared with third parties.
To reduce this risk, Dortch recommends establishing a very clear acceptable-use policy. A strong AI policy, she says, informs employees which AI solutions have been vetted and provides mechanisms for getting additional new solutions reviewed for future acceptance. (Learn more about ICBA's resources for AI risk management.)
Another emerging risk comes from wearables, which are typically eyeglasses or sunglasses equipped with AI that record a user’s surroundings. Dortch points out that bank robbers could use footage captured on a wearable as reconnaissance for future burglaries.
Signage that prohibits all recording could help reduce this risk, especially in areas where vaults or safety deposit boxes are housed. Another strategy is educating tellers to recognize wearables (some models have dots indicating when a device is recording) and request that the devices be turned off during transactions.
Finally, as AI exacerbates existing risks while generating new ones, Dortch urges community bankers to look under the hood of their insurance policies. “If AI were used to [conduct] an attack [on your institution], would that be covered in your policy? Or is that a new loophole for insurers?” she asks. “Any policy written prior to 2025 probably doesn’t take into enough consideration risks associated with AI.”
Board and governance risks
“Cybersecurity issues are on our agenda for every board meeting,” says Eclipse’s Pyle. “It’s a standing agenda item for us.”
The effort bankers devote to educating directors about risk pays off in the quality of questions asked. “We have an astute board,” says Pyles, noting that four out of the nine members serve on the IT steering committee. “It’s not unusual for directors to ask us about the cybersecurity ramifications of a new product we’re considering.”
Miguel Rivera, assistant vice president and fraud manager at $3.3 billion-asset Ponce Bank N.A. in Bronx, New York, also prioritizes director education about fraud. In fact, he presents directors with a written report detailing all recent fraud cases at every quarterly meeting. In his communications, he emphasizes wins (times when, say, money wired to a fraudster is recovered), as well as losses.
“I let [directors] see the whole scope of the fight we’re waging,” says Rivera. “When they see that, you have their backing when you need it.”
Dortch notes that the cadence of board communications matters, with consistency being key.
“Someone from the IT team, the CISO or the CTO has to spend 15 minutes to half an hour regularly doing a deep dive with the board,” she says.
The risk of scams has not abated
Fighting fraud is a passion project for many community bankers, who witness up close the cataclysmic consequences that arise when customers fall prey.
According to Gay Dempsey, CEO of $230 million-asset Bank of Lincoln County in Fayetteville, Tennessee, “Romance scams are rampant with every bank we know.” She adds that working at a small bank can be an advantage. “Our tellers know our customers. They can tell what isn’t normal activity.”
That said, even when bank employees try to convince customers that they’re being scammed, success isn’t guaranteed. Dempsey recounts that one of her customers recently fell victim to a romance scam and could not be dissuaded from selling her house and converting the proceeds into bitcoin, which she gave to the fraudster.
Given the rise of AI, which can produce letter-perfect phishing emails and convincing replicas of bills of sale, fraud is becoming a larger problem with each passing month. Anchin notes that the problem is compounded by growing numbers of nation-state actors working for large organizations intent on defrauding Americans. To combat these overseas threats, Anchin urges community bankers to strengthen relationships with local law enforcement. (Read more on this topic.)
Another powerful arrow in a banker’s quiver is education. For example, Bank of Lincoln County has a checklist for tellers to use when they suspect a customer is being defrauded. Dempsey also makes fraud a focus of her morning “huddles,” 10-minute meetings held three times a week in which employees share experiences and raise concerns.
Of all the advice out there, she believes the simplest may be best: “We tell everyone involved, ‘Just take a breath. Pause before acting.’”
Education is also a key weapon against fraud at Ponce Bank. There, Rivera makes it a practice to speak to all new hires for 90 minutes, educating them on common or rising fraud strategies.
Asked about prevalent fraud schemes in late 2026, Rivera cites a rise in purported online auto dealerships that produce accurate-looking paperwork for the “sale” of cars that don’t exist. Illustrating the magnitude of the problem, he points to fraud-tracking blogger Frank McKenna, who estimates that fraudulent auto dealerships have resulted in $1.3 billion in losses.
For community bankers, safeguarding the assets of retail customers is a major concern, but so is nabbing the criminals running these rackets when they attempt to open small-business accounts. Rivera says the best defense is strong know-your-customer (KYC) practices, including Googling business addresses to make sure they’re not parks or empty lots.
76%
of banking executives reported an increase in the number of cybersecurity attacks on their banks in the past year.
63%
of execs said AI-introduced vulnerabilities in code are their top concern among emerging threats.
Source: 2026 Banking Technology Survey, KPMG
Emerging payments risks
While community banks are adept at managing payment risk, third-party payment vendors, such as Toast, Square and PayPal, are spurring financial institutions to contemplate and address new scenarios, according to ICBA’s Kari Neckel, vice president of payments and technology policy.
For small-business customers to feel fairly treated, Neckel urges community bankers to educate customers fully about the fee side of various payment partnerships. She notes that payment providers charge swipe fees that far exceed what community banks collect under the Durbin Amendment.
Other problems might arise from “buy now, pay later” (BNPL) services. Neckel explains that while BNPL is popular with consumers, some large financial institutions have blocked it on credit cards because “it’s sometimes viewed as a paying-debt-with-debt situation.”
Not only can BNPL create problems for strapped consumers; banks also sometimes struggle to resolve disputes for BNPL transactions because additional parties (and rules) are involved. For this reason, Neckel advises community bankers to consider the latest payment scenarios and update their chargeback and dispute procedures accordingly.
Finally, she describes “friendly fraud,” or fraud that occurs when a consumer files a false Regulation E claim, as a growing problem. While Reg E is designed to protect consumers from identity theft and merchant errors, some consumers try to scam payment providers and banks by requesting reimbursement for purchases they made but later claim were unauthorized. According to the Atlanta Fed, friendly fraud recently skyrocketed 62% within a single year.
New sources of risk: Crypto and beyond
Crypto poses multiple risks to community banks, but one of the most concerning is that core deposits might swiftly be siphoned into this virtual (and largely unregulated) alternative currency.
“Community bankers think they have certain levels of stable deposits to lend from, but that money can flow out of the bank and online pretty easily,” says Ron Haynie, vice president of mortgage finance policy at ICBA.
He urges community bankers to keep abreast of deposit levels through software tools that monitor withdrawals. The risks are so great, he says, that when bankers gather, the risks of crypto draining deposits “is the number one concern I’m hearing.”
Amy Ledig, vice president and safety and soundness regulatory counsel for ICBA, points out that crypto is also positioned to remove cash from the traditional banking system through stablecoins. When the GENIUS Act of 2025 established a framework for stablecoins, a type of cryptocurrency pegged to real-world assets, the reserves were to be invested in treasuries rather than deposited at banks. Should crypto businesses offer interest on stablecoins, ICBA projects community banks stand to lose $1.3 trillion of their total $4.8 trillion in bank deposits. (Learn how you can advocate for community banks on this issue.)
“There are a lot of systemic risks that come from nonbanks entering the banking landscape and not being subject to the same supervision and regulation that helps keep community banks safe and low-risk,” says Ledig. She notes that when nonbanks and crypto providers begin competing for community bank deposits, “that money is no longer there to fuel local economic growth.”
Ledig urges community banks to devise liquidity plans for their institutions and to get active in advocacy work to protect core deposits.
“Research shows that community banks stay in ag lending and in small-business lending in good times and bad times, too,” she says. “Community bankers are trusted partners. No one else out there can replicate that.”
Risk conferences to add to your calendar
Education is one of a community banker’s best protections against emerging risks. Several upcoming conferences from ICBA can help get you and your team up to speed on the latest issues.
- Sept. 16–18. ICBA Fraud Conference—streamed live.
- Sept. 21–24. The annual Current Issues Certification Conference—Phoenix, Arizona (and Oct. 26–29 via livestream).
- Sept. 28–30. ICBA Enterprise Risk Management Institute—Bloomington, Minnesota.
Subscribe now
Sign up for the Independent Banker newsletter to receive twice-monthly emails about new issues and must-read content you might have missed.
Sponsored Content
Featured Webinars
Join ICBA Community
Interested in discussing this and other topics? Network with and learn from your peers with the app designed for community bankers.
Subscribe Today
Sign up for Independent Banker eNews to receive twice-monthly emails that alert you when a new issue drops and highlight must-read content you might have missed.
News Watch Today
Join the Conversation with ICBA Community
ICBA Community is an online platform led by community bankers to foster connections, collaborations, and discussions on industry news, best practices, and regulations, while promoting networking, mentorship, and member feedback to guide future initiatives.