A bank officer background check exists because federal law requires it, not just because the role carries more risk. Section 19 of the Federal Deposit Insurance Act bars anyone convicted of dishonesty, breach of trust, or money laundering from serving at an FDIC-insured institution, and it puts an affirmative duty on the institution to screen for it.
Key Takeaways
- Section 19 of the FDI Act (12 U.S.C. §1829) prohibits anyone convicted of dishonesty, breach of trust, or money laundering from serving as an officer, director, or institution-affiliated party at an FDIC-insured institution without prior written FDIC consent.
- Credit unions operate under a near-identical statute: Section 205(d) of the Federal Credit Union Act (12 U.S.C. §1786(d)), enforced by the NCUA rather than the FDIC, with the two agencies required by statute to coordinate.
- Section 19 places a “reasonable inquiry” duty directly on the institution: screening for covered offenses isn’t optional risk management, it’s how a bank demonstrates it met a statutory obligation.
- A separate statute, Section 32 of the FDI Act (12 U.S.C. §1831i), requires troubled or newly chartered institutions to give regulators 30 to 90 days’ prior notice before adding a director or senior executive officer, with the regulator able to disapprove based on competence, experience, character, or integrity.
- The Fair Hiring in Banking Act narrowed what counts as a disqualifying offense under Section 19 and its credit union counterpart, with implementing regulations effective in 2024.
- These statutory requirements sit alongside, not in place of, standard FCRA disclosure, consent, and adverse action obligations.
What Section 19 Actually Bars
Section 19 of the Federal Deposit Insurance Act, codified at 12 U.S.C. §1829, exists to keep a specific category of conviction out of banking entirely, not to add extra scrutiny to an already-qualified candidate. Without the FDIC’s prior written consent, a person convicted of a criminal offense involving dishonesty, breach of trust, or money laundering, or who has agreed to a pretrial diversion program for such an offense, may not become or continue as an institution-affiliated party of an FDIC-insured institution, may not own or control one directly or indirectly, and may not otherwise participate, directly or indirectly, in the conduct of the institution’s affairs. The prohibition applies without exception unless the person has obtained that consent in advance.
The institution carries an obligation of its own, not just the individual. The FDIC’s Statement of Policy for Section 19 describes this as a “reasonable inquiry” duty, and at minimum, the FDIC expects an institution to require a written application that lists all prior convictions and program entries, to screen every candidate for an officer, director, or institution-affiliated role against Section 19’s covered-offense definition before the appointment takes effect, and to document that the inquiry actually happened rather than merely exist as a policy on paper. This is the specific legal hook that turns a criminal background check from a best practice into a documented compliance requirement.
It’s also broader than it first sounds. “Institution-affiliated party” isn’t limited to a bank’s own C-suite. It reaches directors, officers, and anyone else participating in the conduct of the institution’s affairs, which is why the screening duty attaches the moment someone is being considered for a board seat or officer title, not only when a background check happens to already be part of the hiring process.
The FDIC Consent Process When a Covered Offense Turns Up
Finding a covered offense doesn’t automatically end the process; it starts a different one. A person with a disqualifying conviction can seek the FDIC’s written consent through what the agency calls a consent application, submitted either by the individual or by the institution on their behalf, and the FDIC has approved a substantial share of these applications in recent years, particularly for older or minor offenses.
A small number of specific offenses carry a ten-year minimum ban before the FDIC can even consider a consent application, absent a court-approved motion. Confirming whether a specific conviction falls on this list is a real step, not a formality, since it determines whether a consent application can even be filed yet. These are enumerated by statute reference rather than described generally:
- Bank bribery under 18 U.S.C. §215
- Theft or embezzlement by a bank officer or employee under 18 U.S.C. §656 or §657
- False bank entries and related fraud under 18 U.S.C. §§1005 through 1008
- False statements to influence a bank under 18 U.S.C. §1014
- Concealment of assets from a receiver under 18 U.S.C. §1032
- Bank fraud under 18 U.S.C. §1344
- Obstructing a bank examination under 18 U.S.C. §1517
- Money laundering under 18 U.S.C. §§1956 and 1957
- Mail or wire fraud under 18 U.S.C. §1341 or §1343, where the fraud affects a financial institution
The landscape shifted recently. The Fair Hiring in Banking Act amended Section 19’s scope, and the FDIC’s implementing regulations took effect October 1, 2024. The changes narrowed what counts as a disqualifying “offense involving dishonesty”: simple possession of a controlled substance, and possession with intent to distribute, are now excluded from that category, reversing the FDIC’s earlier practice of treating most drug-related offenses as covered by default. The rule also expanded de minimis exceptions, reducing how often a consent application is needed at all for genuinely minor, dated offenses.
Credit Unions Operate Under a Parallel Statute
Everything above covers FDIC-insured banks, but GCheck’s financial services clients include credit unions too, and the rules there aren’t identical, they’re a close statutory mirror administered by a different agency.
Section 205(d) of the Federal Credit Union Act, codified at 12 U.S.C. §1786(d), prohibits the same categories of conviction from touching an insured credit union’s affairs, just under the NCUA Board’s consent authority instead of the FDIC’s.
| Section 19 (banks) | Section 205(d) (credit unions) | |
| Covered offenses | Dishonesty, breach of trust, or money laundering, or an agreed pretrial diversion program | Same three categories |
| Consent authority | FDIC | NCUA Board |
| Underlying purpose | Protecting depositors | Protecting members |
| 2024 policy update | Fair Hiring in Banking Act implementing regulations | NCUA’s Interpretive Ruling and Policy Statement, mirroring the same changes |
The two systems aren’t independent of each other. Federal law specifically requires the FDIC and NCUA to “consult and coordinate” on Section 19 and Section 205(d) implementation, and an individual denied consent by one agency for a given conviction generally can’t get a different answer from the other. A credit union building a compliant officer and director screening program should treat Section 205(d) as functionally equivalent to Section 19 for screening-design purposes, while confirming with counsel that any specific consent application goes to the correct agency.
Section 32: When a Director or Officer Change Needs Regulator Sign-Off
Who This Applies To
Section 32 of the FDI Act, 12 U.S.C. §1831i, is a separate mechanism from Section 19, and the two are easy to conflate. Section 32 requires an institution in “troubled condition,” meaning a composite rating of 4 or 5 under the Uniform Financial Institutions Rating System, subject to a formal enforcement action, or otherwise flagged by its regulator, or a newly chartered or converted institution, to give prior written notice before adding any board member or senior executive officer. FDIC- and Federal Reserve-supervised institutions get 30 days; OCC-regulated national banks get 90 days.
“Senior executive officer” has a specific regulatory definition, not a colloquial one. Named examples include:
- President
- Chief executive officer
- Chief operating officer
- Chief financial officer
- Chief lending officer
- Chief investment officer
A title change that moves someone into one of these roles can trigger the notice requirement even without a new hire.
What the Notice Must Show
The notice itself has to address the individual’s competence, experience, character, and integrity, and it must include fingerprints. The regulator can disapprove the appointment on that basis alone, issuing a written explanation, and the institution or individual has fifteen days to appeal. This is a genuine gatekeeping power: the appointment doesn’t go through on the institution’s say-so, it goes through on the regulator’s.
What Actually Triggers This Screening in Practice
The statutes describe legal categories; in practice, a handful of concrete situations are where a bank or credit union’s screening obligation actually gets tested. A new officer or director hire triggers the Section 19 or Section 205(d) reasonable inquiry outright, plus a Section 32 notice if the institution happens to be troubled or newly chartered. An internal promotion into an officer title carries the identical trigger, even though promotions often skip the fuller screening applied to external hires, since the trigger is the title itself, not how the person arrived at it. A board nomination carries the same obligation, and board candidates are frequently recruited through referral, with less formal vetting than an external executive search would apply.
Mergers and acquisitions create a version of this that’s easy to overlook: the acquiring institution inherits the screening duty for the combined leadership team, not just its own prior hires. A reinstatement after a prior denied consent isn’t a formality either, it requires a fresh consent application evaluated against the same statutory standard, and an earlier denial by either agency generally forecloses a different answer from the other.
These are ordinary lifecycle events, which is exactly why building the screening steps into standard HR and governance workflows, rather than a special process invoked only when someone remembers, is what keeps an institution from missing an obligation it didn’t realize applied. Confirming criminal history at the federal level is a starting point for the Section 19 inquiry, and employment verification confirms the professional history a Section 32 notice has to document.
How This Differs from Standard Employment Screening
The table below lines up standard employee screening against the statutory layers that apply to bank and credit union officers and directors.
| Standard employee screening | Section 19 / Section 205(d) | Section 32 (12 U.S.C. §1831i) | |
| Who it applies to | Any employee | Officers, directors, and institution-affiliated parties at any insured bank or credit union | Directors and senior executive officers, but only at troubled or newly chartered institutions |
| What triggers it | The hiring decision itself | A conviction or program entry for dishonesty, breach of trust, or money laundering | Adding or changing a director or senior executive officer |
| Who decides | The employer | The FDIC (banks) or NCUA Board (credit unions), through a consent application | The primary federal regulator (FDIC, Federal Reserve, or OCC) |
| What’s required | FCRA disclosure, consent, adverse action process | A documented reasonable inquiry into covered offenses | 30 to 90 days’ prior written notice, including fingerprints |
| Consequence of skipping it | FCRA liability exposure | Statutory violation exposing the institution and the individual to penalties | Regulatory disapproval of the appointment |
| Relationship to state law | Layers on top of state screening laws | Additive to state law, doesn’t preempt it | Additive to state law, doesn’t preempt it |
An institution operating across multiple states needs both the federal and state layers accounted for, not just one.
Building a Compliant Officer and Director Screening Program
A program that satisfies both statutes, and holds up if a regulator ever asks how a specific hire was vetted, tends to share the same structural elements:
- A written application disclosure requiring every candidate for an officer or director role to list all convictions and program entries, the FDIC’s minimum expectation under Section 19’s reasonable inquiry standard
- A documented criminal history review confirming whether any disclosed or discovered offense falls under Section 19’s covered-offense definition, including the enumerated ten-year-ban list
- Troubled-condition and role tracking that flags when an institution’s status or a role’s title triggers Section 32’s notice requirement
- Regulatory notice preparation that assembles competence, experience, character, and integrity documentation, plus fingerprints, before the 30- or 90-day filing window closes
- The standard FCRA sequence, disclosure, written authorization, a pre-adverse notice with a copy of the report, and a final adverse action notice, running alongside the statutory layers above rather than in place of them
None of this is about disqualifying people by default. Section 19 explicitly gives the FDIC discretion to grant consent, and the Fair Hiring in Banking Act’s recent changes moved in the direction of fewer, not more, automatic exclusions. A candidate with an old, minor, or already-excluded offense isn’t necessarily out; the point of the process is documenting that the institution asked the right questions and made an informed decision, not applying a blanket bar.
The post-appointment layer is where continuous criminal monitoring becomes directly relevant rather than optional. A bank that only checks at the point of hire has no way of knowing whether a sitting officer or director picked up a disqualifying conviction two years into their tenure, and Section 19’s prohibition applies the moment that conviction becomes final, regardless of when the institution happens to find out about it. Section 19 and Section 205(d) are continuing obligations, not one-time checks, which is why a program built only for the hiring moment leaves a real gap open for the entire length of someone’s tenure.
Where This Overlaps with Executive Reputation Intelligence, and Where It Doesn’t
Section 19 and Section 32 are statutory floors specific to insured depository institutions; they don’t replace the broader due-diligence practices that apply to executives generally. A bank board weighing a C-suite appointment still benefits from the same kind of governance-level review covered in GCheck’s guide to executive reputation intelligence, news coverage, regulatory filings, and litigation history that a criminal-history check alone won’t surface. The difference is that for a bank, Section 19 and Section 32 aren’t optional additions to that process; they’re independent legal requirements that apply regardless of whether the institution also chooses to run a broader reputation review.
This is Protective Compliance in the most literal sense available in GCheck’s framework: the statutory duty exists specifically to protect depositors and the institution from the consequences of an unvetted appointment. It’s also where Transparent Compliance matters in a way that’s easy to overlook, the documentation a bank builds to satisfy Section 19’s reasonable inquiry standard and Section 32’s notice requirement is the same documentation that demonstrates, to a regulator asking after the fact, exactly what was checked and why a decision was made.
Frequently Asked Questions
Does Section 19 apply to credit unions too?
Not directly, credit unions operate under a separate but nearly identical statute, Section 205(d) of the Federal Credit Union Act (12 U.S.C. §1786(d)), enforced by the NCUA Board rather than the FDIC. The substantive standard, covered offenses, and consent-application process are functionally the same; only the agency and the specific statute differ.
Does Section 19 apply to every bank employee, or just officers and directors?
Section 19 applies to institution-affiliated parties, which includes officers and directors but extends further to anyone participating in the conduct of the institution’s affairs. It is not limited to a narrow C-suite definition, though the practical screening burden concentrates on officer, director, and other affiliated-party roles.
What happens if a candidate has a conviction that falls under Section 19?
A covered conviction doesn’t automatically end the process. The individual can seek the FDIC’s written consent through a consent application, and the FDIC has approved a substantial share of these applications, particularly for older or minor offenses, since the Fair Hiring in Banking Act’s changes took effect.
Does Section 32’s notice requirement apply to every bank?
No. It applies specifically to institutions in troubled condition, meaning a composite rating of 4 or 5, an active enforcement action, or a regulator flag, and to newly chartered or converted institutions. A well-capitalized, unflagged institution generally isn’t subject to Section 32’s prior-notice requirement for routine director or officer changes.
How is a bank officer background check different from a standard employment background check?
A standard check follows FCRA’s disclosure, consent, and adverse action sequence for any hire. A bank officer or director check adds two statutory layers on top of that: Section 19’s reasonable inquiry into dishonesty, breach of trust, or money laundering convictions, and, where applicable, Section 32’s regulatory notice and disapproval process.
Did the Fair Hiring in Banking Act change what counts as a disqualifying offense?
Yes. The FDIC’s regulations implementing the Act, effective October 1, 2024, excluded simple drug possession and possession with intent to distribute from the “offense involving dishonesty” category and expanded de minimis exceptions, reducing how often a formal consent application is needed for minor, dated offenses.
Sources cited
- Federal Deposit Insurance Act §19, 12 U.S.C. §1829
- FDIC Statement of Policy for Section 19 of the FDI Act
- 12 CFR Part 303, Subpart L (FDIC Section 19 consent application regulations, effective October 1, 2024, implementing the Fair Hiring in Banking Act)
- Federal Credit Union Act §205(d), 12 U.S.C. §1786(d)
- NCUA Interpretive Ruling and Policy Statement 19-1 (Section 205(d) covered offenses and de minimis exceptions)
- Federal Deposit Insurance Act §32, 12 U.S.C. §1831i
- 12 CFR Part 303, Subpart F (FDIC Section 32 implementing regulations)
- 12 CFR §5.51 (OCC notice requirement for national banks and federal savings associations)
Charm Paz, CHRP
Recruiter & Editor
Charm Paz is an HR professional at GCheck, specializing in background screening, fair hiring, and regulatory compliance. She holds from the Professional Background Screening Association (PBSA) and helps organizations navigate employment regulations with clarity and confidence.
With a background in Industrial and Organizational Psychology, she translates policy into practice to build ethical, compliant, human-centered hiring systems that strengthen decision-making over time.