OCC Heightened Standards (12 CFR Part 30, Appendix D)
The OCC Heightened Standards (12 CFR Part 30, Appendix D) set minimum requirements for the design, implementation, and ongoing operation of a risk governance framework for large insured national banks, federal savings associations, and insured federal branches with $50 billion or more in consolidated assets. The standards cover governance, risk management, internal controls, stress testing, capital planning, and supervisory reporting obligations.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Board of Directors
| Code | Title |
|---|---|
| OCCHS-6 | Board of Directors: Composition, Independence, Oversight, and Self-Assessment |
Independent Risk Management
| Code | Title |
|---|---|
| OCCHS-4 | Independent Risk Management: CRO, Charter, Authority, and Oversight |
Internal Audit
| Code | Title |
|---|---|
| OCCHS-5 | Internal Audit: Independence, Scope, Methodology, and Reporting |
Risk Appetite and Limits
| Code | Title |
|---|---|
| OCCHS-3 | Risk Appetite Statement, Risk Limits, Concentration Risk, and Limit Breach Protocols |
Risk Data, Talent, Compensation, Strategy
| Code | Title |
|---|---|
| OCCHS-7 | Risk Data Aggregation, Reporting, Talent, Compensation, and Strategic Planning |
Risk Governance Framework
| Code | Title |
|---|---|
| OCCHS-2 | Risk Governance Framework: Three Lines of Defense, Scope, and Charter |
Scope and Applicability
| Code | Title |
|---|---|
| OCCHS-1 | Scope, Applicability, and Definitions of Heightened Standards |
Third-Party Risk and Regulatory Integration
| Code | Title |
|---|---|
| OCCHS-8 | Third-Party Risk Within Heightened Standards and Integration with Broader Regulation |
Your Compliance Coverage
If you comply with OCC Heightened Standards (12 CFR Part 30, Appendix D), you already cover:
Protective Security Policy Framework (PSPF) Release 2024
38%
3 controls mapped
Compare →APRA CPS 234
38%
3 controls mapped
Compare →AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
38%
3 controls mapped
Compare →+ 123 more: ISO/IEC 38500:2024 - Governance of IT (38%), FFIEC IT Examination Handbook (38%)
See all 126 mapped frameworks ↓Maps to 126 other frameworks
Frequently Asked Questions
What is OCC Heightened Standards (12 CFR Part 30, Appendix D)?
OCC Heightened Standards (12 CFR Part 30, Appendix D) is a compliance framework from United States (OCC) with 8 domains and 8 controls. The OCC Heightened Standards (12 CFR Part 30, Appendix D) set minimum requirements for the design, implementation, and ongoing operation of a risk governance framework for large insured national banks, federal savings associations, and insured federal branches with $50 billion or more in consolidated assets. The standards cover governance, risk management, internal controls, stress testing, capital planning, and supervisory reporting obligations. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does OCC Heightened Standards (12 CFR Part 30, Appendix D) have?
OCC Heightened Standards (12 CFR Part 30, Appendix D) has 8 controls organised across 8 domains. The largest domains are Board of Directors (1 controls), Independent Risk Management (1 controls), Internal Audit (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does OCC Heightened Standards (12 CFR Part 30, Appendix D) map to?
OCC Heightened Standards (12 CFR Part 30, Appendix D) maps to 126 other compliance frameworks. The top mapping partners are Protective Security Policy Framework (PSPF) Release 2024 (38% coverage), APRA CPS 234 (38% coverage), AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence (38% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with OCC Heightened Standards (12 CFR Part 30, Appendix D) compliance?
Start your OCC Heightened Standards (12 CFR Part 30, Appendix D) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about OCC Heightened Standards (12 CFR Part 30, Appendix D) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 8 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required