Bank Officer Background Checks: What Federal Law Actually Requires
Industry Guides

Bank Officer Background Checks: What Federal Law Actually Requires

Discover how the bank officer background check helps maintain trust and security in FDIC-insured institutions across the United States.

Created by

Charm Paz, CHRP
Charm Paz, CHRP Recruiter & Editor

A bank officer background check exists because federal law requires it, not just because the role carries more risk. Section 19 of the Federal Deposit Insurance Act bars anyone convicted of dishonesty, breach of trust, or money laundering from serving at an FDIC-insured institution, and it puts an affirmative duty on the institution to screen for it.

Key Takeaways

  • Section 19 of the FDI Act (12 U.S.C. §1829) prohibits anyone convicted of dishonesty, breach of trust, or money laundering from serving as an officer, director, or institution-affiliated party at an FDIC-insured institution without prior written FDIC consent.
  • Credit unions operate under a near-identical statute: Section 205(d) of the Federal Credit Union Act (12 U.S.C. §1786(d)), enforced by the NCUA rather than the FDIC, with the two agencies required by statute to coordinate.
  • Section 19 places a “reasonable inquiry” duty directly on the institution: screening for covered offenses isn’t optional risk management, it’s how a bank demonstrates it met a statutory obligation.
  • A separate statute, Section 32 of the FDI Act (12 U.S.C. §1831i), requires troubled or newly chartered institutions to give regulators 30 to 90 days’ prior notice before adding a director or senior executive officer, with the regulator able to disapprove based on competence, experience, character, or integrity.
  • The Fair Hiring in Banking Act narrowed what counts as a disqualifying offense under Section 19 and its credit union counterpart, with implementing regulations effective in 2024.
  • These statutory requirements sit alongside, not in place of, standard FCRA disclosure, consent, and adverse action obligations.

What Section 19 Actually Bars

Section 19 of the Federal Deposit Insurance Act, codified at 12 U.S.C. §1829, exists to keep a specific category of conviction out of banking entirely, not to add extra scrutiny to an already-qualified candidate. Without the FDIC’s prior written consent, a person convicted of a criminal offense involving dishonesty, breach of trust, or money laundering, or who has agreed to a pretrial diversion program for such an offense, may not become or continue as an institution-affiliated party of an FDIC-insured institution, may not own or control one directly or indirectly, and may not otherwise participate, directly or indirectly, in the conduct of the institution’s affairs. The prohibition applies without exception unless the person has obtained that consent in advance.

The institution carries an obligation of its own, not just the individual. The FDIC’s Statement of Policy for Section 19 describes this as a “reasonable inquiry” duty, and at minimum, the FDIC expects an institution to require a written application that lists all prior convictions and program entries, to screen every candidate for an officer, director, or institution-affiliated role against Section 19’s covered-offense definition before the appointment takes effect, and to document that the inquiry actually happened rather than merely exist as a policy on paper. This is the specific legal hook that turns a criminal background check from a best practice into a documented compliance requirement.

It’s also broader than it first sounds. “Institution-affiliated party” isn’t limited to a bank’s own C-suite. It reaches directors, officers, and anyone else participating in the conduct of the institution’s affairs, which is why the screening duty attaches the moment someone is being considered for a board seat or officer title, not only when a background check happens to already be part of the hiring process.

Finding a covered offense doesn’t automatically end the process; it starts a different one. A person with a disqualifying conviction can seek the FDIC’s written consent through what the agency calls a consent application, submitted either by the individual or by the institution on their behalf, and the FDIC has approved a substantial share of these applications in recent years, particularly for older or minor offenses.

A small number of specific offenses carry a ten-year minimum ban before the FDIC can even consider a consent application, absent a court-approved motion. Confirming whether a specific conviction falls on this list is a real step, not a formality, since it determines whether a consent application can even be filed yet. These are enumerated by statute reference rather than described generally:

The landscape shifted recently. The Fair Hiring in Banking Act amended Section 19’s scope, and the FDIC’s implementing regulations took effect October 1, 2024. The changes narrowed what counts as a disqualifying “offense involving dishonesty”: simple possession of a controlled substance, and possession with intent to distribute, are now excluded from that category, reversing the FDIC’s earlier practice of treating most drug-related offenses as covered by default. The rule also expanded de minimis exceptions, reducing how often a consent application is needed at all for genuinely minor, dated offenses.

Credit Unions Operate Under a Parallel Statute

Everything above covers FDIC-insured banks, but GCheck’s financial services clients include credit unions too, and the rules there aren’t identical, they’re a close statutory mirror administered by a different agency.

Section 205(d) of the Federal Credit Union Act, codified at 12 U.S.C. §1786(d), prohibits the same categories of conviction from touching an insured credit union’s affairs, just under the NCUA Board’s consent authority instead of the FDIC’s.

Section 19 (banks)Section 205(d) (credit unions)
Covered offensesDishonesty, breach of trust, or money laundering, or an agreed pretrial diversion programSame three categories
Consent authorityFDICNCUA Board
Underlying purposeProtecting depositorsProtecting members
2024 policy updateFair Hiring in Banking Act implementing regulationsNCUA’s Interpretive Ruling and Policy Statement, mirroring the same changes

The two systems aren’t independent of each other. Federal law specifically requires the FDIC and NCUA to “consult and coordinate” on Section 19 and Section 205(d) implementation, and an individual denied consent by one agency for a given conviction generally can’t get a different answer from the other. A credit union building a compliant officer and director screening program should treat Section 205(d) as functionally equivalent to Section 19 for screening-design purposes, while confirming with counsel that any specific consent application goes to the correct agency.

Section 32: When a Director or Officer Change Needs Regulator Sign-Off

Who This Applies To

Section 32 of the FDI Act, 12 U.S.C. §1831i, is a separate mechanism from Section 19, and the two are easy to conflate. Section 32 requires an institution in “troubled condition,” meaning a composite rating of 4 or 5 under the Uniform Financial Institutions Rating System, subject to a formal enforcement action, or otherwise flagged by its regulator, or a newly chartered or converted institution, to give prior written notice before adding any board member or senior executive officer. FDIC- and Federal Reserve-supervised institutions get 30 days; OCC-regulated national banks get 90 days.

“Senior executive officer” has a specific regulatory definition, not a colloquial one. Named examples include:

A title change that moves someone into one of these roles can trigger the notice requirement even without a new hire.

What the Notice Must Show

The notice itself has to address the individual’s competence, experience, character, and integrity, and it must include fingerprints. The regulator can disapprove the appointment on that basis alone, issuing a written explanation, and the institution or individual has fifteen days to appeal. This is a genuine gatekeeping power: the appointment doesn’t go through on the institution’s say-so, it goes through on the regulator’s.

What Actually Triggers This Screening in Practice

The statutes describe legal categories; in practice, a handful of concrete situations are where a bank or credit union’s screening obligation actually gets tested. A new officer or director hire triggers the Section 19 or Section 205(d) reasonable inquiry outright, plus a Section 32 notice if the institution happens to be troubled or newly chartered. An internal promotion into an officer title carries the identical trigger, even though promotions often skip the fuller screening applied to external hires, since the trigger is the title itself, not how the person arrived at it. A board nomination carries the same obligation, and board candidates are frequently recruited through referral, with less formal vetting than an external executive search would apply.

Mergers and acquisitions create a version of this that’s easy to overlook: the acquiring institution inherits the screening duty for the combined leadership team, not just its own prior hires. A reinstatement after a prior denied consent isn’t a formality either, it requires a fresh consent application evaluated against the same statutory standard, and an earlier denial by either agency generally forecloses a different answer from the other.

These are ordinary lifecycle events, which is exactly why building the screening steps into standard HR and governance workflows, rather than a special process invoked only when someone remembers, is what keeps an institution from missing an obligation it didn’t realize applied. Confirming criminal history at the federal level is a starting point for the Section 19 inquiry, and employment verification confirms the professional history a Section 32 notice has to document.

How This Differs from Standard Employment Screening

The table below lines up standard employee screening against the statutory layers that apply to bank and credit union officers and directors.

Standard employee screeningSection 19 / Section 205(d)Section 32 (12 U.S.C. §1831i)
Who it applies toAny employeeOfficers, directors, and institution-affiliated parties at any insured bank or credit unionDirectors and senior executive officers, but only at troubled or newly chartered institutions
What triggers itThe hiring decision itselfA conviction or program entry for dishonesty, breach of trust, or money launderingAdding or changing a director or senior executive officer
Who decidesThe employerThe FDIC (banks) or NCUA Board (credit unions), through a consent applicationThe primary federal regulator (FDIC, Federal Reserve, or OCC)
What’s requiredFCRA disclosure, consent, adverse action processA documented reasonable inquiry into covered offenses30 to 90 days’ prior written notice, including fingerprints
Consequence of skipping itFCRA liability exposureStatutory violation exposing the institution and the individual to penaltiesRegulatory disapproval of the appointment
Relationship to state lawLayers on top of state screening lawsAdditive to state law, doesn’t preempt itAdditive to state law, doesn’t preempt it

An institution operating across multiple states needs both the federal and state layers accounted for, not just one.

Building a Compliant Officer and Director Screening Program

A program that satisfies both statutes, and holds up if a regulator ever asks how a specific hire was vetted, tends to share the same structural elements:

None of this is about disqualifying people by default. Section 19 explicitly gives the FDIC discretion to grant consent, and the Fair Hiring in Banking Act’s recent changes moved in the direction of fewer, not more, automatic exclusions. A candidate with an old, minor, or already-excluded offense isn’t necessarily out; the point of the process is documenting that the institution asked the right questions and made an informed decision, not applying a blanket bar.

The post-appointment layer is where continuous criminal monitoring becomes directly relevant rather than optional. A bank that only checks at the point of hire has no way of knowing whether a sitting officer or director picked up a disqualifying conviction two years into their tenure, and Section 19’s prohibition applies the moment that conviction becomes final, regardless of when the institution happens to find out about it. Section 19 and Section 205(d) are continuing obligations, not one-time checks, which is why a program built only for the hiring moment leaves a real gap open for the entire length of someone’s tenure.

Where This Overlaps with Executive Reputation Intelligence, and Where It Doesn’t

Section 19 and Section 32 are statutory floors specific to insured depository institutions; they don’t replace the broader due-diligence practices that apply to executives generally. A bank board weighing a C-suite appointment still benefits from the same kind of governance-level review covered in GCheck’s guide to executive reputation intelligence, news coverage, regulatory filings, and litigation history that a criminal-history check alone won’t surface. The difference is that for a bank, Section 19 and Section 32 aren’t optional additions to that process; they’re independent legal requirements that apply regardless of whether the institution also chooses to run a broader reputation review.

This is Protective Compliance in the most literal sense available in GCheck’s framework: the statutory duty exists specifically to protect depositors and the institution from the consequences of an unvetted appointment. It’s also where Transparent Compliance matters in a way that’s easy to overlook, the documentation a bank builds to satisfy Section 19’s reasonable inquiry standard and Section 32’s notice requirement is the same documentation that demonstrates, to a regulator asking after the fact, exactly what was checked and why a decision was made.

Frequently Asked Questions

Does Section 19 apply to credit unions too?

Not directly, credit unions operate under a separate but nearly identical statute, Section 205(d) of the Federal Credit Union Act (12 U.S.C. §1786(d)), enforced by the NCUA Board rather than the FDIC. The substantive standard, covered offenses, and consent-application process are functionally the same; only the agency and the specific statute differ.

Does Section 19 apply to every bank employee, or just officers and directors?

Section 19 applies to institution-affiliated parties, which includes officers and directors but extends further to anyone participating in the conduct of the institution’s affairs. It is not limited to a narrow C-suite definition, though the practical screening burden concentrates on officer, director, and other affiliated-party roles.

What happens if a candidate has a conviction that falls under Section 19?

A covered conviction doesn’t automatically end the process. The individual can seek the FDIC’s written consent through a consent application, and the FDIC has approved a substantial share of these applications, particularly for older or minor offenses, since the Fair Hiring in Banking Act’s changes took effect.

Does Section 32’s notice requirement apply to every bank?

No. It applies specifically to institutions in troubled condition, meaning a composite rating of 4 or 5, an active enforcement action, or a regulator flag, and to newly chartered or converted institutions. A well-capitalized, unflagged institution generally isn’t subject to Section 32’s prior-notice requirement for routine director or officer changes.

How is a bank officer background check different from a standard employment background check?

A standard check follows FCRA’s disclosure, consent, and adverse action sequence for any hire. A bank officer or director check adds two statutory layers on top of that: Section 19’s reasonable inquiry into dishonesty, breach of trust, or money laundering convictions, and, where applicable, Section 32’s regulatory notice and disapproval process.

Did the Fair Hiring in Banking Act change what counts as a disqualifying offense?

Yes. The FDIC’s regulations implementing the Act, effective October 1, 2024, excluded simple drug possession and possession with intent to distribute from the “offense involving dishonesty” category and expanded de minimis exceptions, reducing how often a formal consent application is needed for minor, dated offenses.

Sources cited

Charm Paz, CHRP
ABOUT THE CREATOR

Charm Paz, CHRP

Recruiter & Editor

Charm Paz is an HR professional at GCheck, specializing in background screening, fair hiring, and regulatory compliance. She holds FCRA Advanced certification from the Professional Background Screening Association (PBSA) and helps organizations navigate employment regulations with clarity and confidence.

With a background in Industrial and Organizational Psychology, she translates policy into practice to build ethical, compliant, human-centered hiring systems that strengthen decision-making over time.