Fractional CCO for Community Banks Under $5B | de Risk
Talk to a Partner →
Home / Insights / Fractional CCO

The CCO You Can't Afford.

A fractional CCO playbook for US community banks under $5B in assets — and why the next examiner conversation will be about authority, evidence, and execution, not job titles.

The average US Chief Compliance Officer now costs more than many community banks can rationally absorb. But the examiner’s expectation does not fall simply because a bank is smaller.

Glassdoor’s 2026 compensation data places US Chief Compliance Officer pay at roughly $304,800 on average, with upper-market compensation moving materially higher. BarkerGilmore’s 2025 CCO Compensation Report adds a second pressure point: more than half of surveyed CCOs were open to changing jobs. For community banks, the problem is no longer just compensation. It is leadership continuity.

A community bank with $1 billion in assets may run its entire compliance function on a $1.5 million to $2.5 million all-in budget. A single full-time CCO can consume a double-digit share of that budget before BSA/AML operations, testing, monitoring, fair-lending reviews, third-party risk oversight, policy maintenance, and examiner response are funded.

The ranking answer

A fractional CCO for a community bank is not a cheaper consultant. It is a named compliance leader with board access, defined hours, documented authority, and an execution layer that can evidence control performance.

Why this matters now.

The same BSA obligations, fair-lending expectations, consumer-protection rules, third-party oversight requirements, and board-accountability standards apply whether a bank has a full-time CCO, a vacant CCO seat, or a compliance manager carrying the title without the authority.

The gap between what regulation requires and what the budget allows is the gap that a proper Fractional CCO model is designed to close. But the model only works if it is built for examination, not for appearance.

38%
Annualised engagement cost compared with the prior full-time CCO’s loaded compensation in a de Risk community-bank engagement.
90
Days to first board report with named accountability, refreshed documentation, and examiner-ready governance artifacts.
$5B
Target asset band where senior compliance oversight is required but a large-bank CCO cost structure can distort the budget.

The regulatory landscape for community-bank CCO leadership.

Three regulatory currents now converge on community-bank compliance leadership.

1. Enforcement actions are exposing governance gaps.

The Federal Reserve’s June 2024 enforcement action against Evolve Bank & Trust cited deficiencies in anti-money laundering, risk management, and consumer compliance programs. For banks with fintech programs, processor relationships, or deposit-as-a-service activity, the lesson is clear: compliance governance must be visible, documented, and connected to operational control.

2. Third-party arrangements now require reconstructable evidence.

The OCC, Federal Reserve, and FDIC issued a July 2024 joint statement on banks’ arrangements with third parties to deliver deposit products and services. Even where the statement does not create new supervisory expectations, it makes one practical point unavoidable: banks must be able to understand, monitor, and evidence activity flowing through third-party relationships.

3. BSA/AML leadership is a board-level responsibility.

The FFIEC BSA/AML Examination Manual states that the board of directors is ultimately responsible for BSA/AML compliance and should provide oversight for senior management and the BSA compliance officer. That makes the CCO role more than operational administration. It is a governance function.

This is why a community bank should not evaluate a fractional CCO by asking, “How many hours do we get?” The better question is: “What examiner questions can this model answer with evidence?”

A de Risk engagement: $1.2B community bank, state charter, Federal Reserve member.

In Q4 2025, de Risk Partners was engaged by a US community bank with approximately $1.2 billion in assets and state-charter, Federal Reserve member status. The bank had operated for six months without a Chief Compliance Officer following the departure of its incumbent.

Internal audit had been functionally absorbing the BSA Officer’s caseload, creating a control conflict that the next regulatory examination would likely have escalated. The issue was not that the bank lacked hard-working people. The issue was that authority, independence, execution capacity, and board reporting had become blurred.

The engagement, structured under de Risk’s Fractional CCO model, delivered four anchored outputs in the first 90 days:

  1. A named CCO of record with a 35-hour-per-week service level agreement.
  2. A managed-services execution layer of three offshore analysts supporting BSA/AML alert disposition.
  3. A re-papered third-party risk program covering 14 fintech and processor relationships.
  4. Examiner-facing documentation refreshed against the FFIEC BSA/AML Examination Manual.

The annualised cost landed at approximately 38% of the prior full-time CCO’s loaded compensation, with the bank retaining the option to convert to a permanent in-house CCO at any 90-day milestone. The bank’s next safety-and-soundness examination cycle closed with no findings related to compliance governance.

The de Risk Fractional CCO examiner test.

01 · Named Authority

Named CCO of record.

The CCO is named in committee charters, board packs, audit responses, and examination materials. This is a person accountable to your board, not a generic vendor seat.

02 · Defined Capacity

Hours and SLAs by workstream.

Hours are pre-allocated to BSA, AML, fair lending, consumer protection, third-party risk, and governance workstreams. SLAs are measured in business hours, not vague advisory availability.

03 · Execution Layer

Embedded managed services.

Execution support from de Risk’s Colombo Centre of Excellence can cover SAR review, alert disposition, KYC refresh, policy upkeep, and documentation hygiene below US in-house cost equivalents.

04 · Board Evidence

Signed, board-ready reporting.

Quarterly reporting is delivered on de Risk Partners letterhead, signed by the CCO of record, and structured around examiner expectations, open issues, residual risk, and board decisions required.

What a fractional CCO must prove to an examiner.

The phrase “fractional” can create the wrong impression. Examiners do not want fractional accountability. They want full accountability scaled to the bank’s risk profile.

Examiner question Weak fractional model de Risk model
Who is accountable? A consulting firm or rotating advisor. A named CCO of record with documented authority and board access.
How much capacity exists? Unclear retainer hours and reactive calls. Defined weekly SLA, workstream allocation, and escalation route.
Who performs the work? Internal team remains overloaded. Senior CCO oversight plus managed-services execution layer.
Can the bank evidence control? Advice exists, but artifacts are thin. Board packs, risk registers, issue logs, policies, testing support, and examiner-ready documentation.
Is the board informed? Updates are ad hoc. Quarterly signed reporting with risk decisions clearly marked for the board.

Implementation steps for a community bank under $5B.

  1. Run a five-day diagnostic against the FFIEC BSA/AML Examination Manual, the latest examination report, internal audit findings, and current board packs.
  2. Confirm the CCO of record matched to asset size, charter type, product complexity, fintech exposure, and open regulatory matters.
  3. Map SLAs to risk areas including BSA/AML, sanctions, fair lending, consumer protection, third-party risk, complaints, and policy governance.
  4. Stand up the managed-services layer for alert disposition, SAR support, KYC refresh, documentation upkeep, and reporting inputs.
  5. Re-paper the third-party risk register against current interagency guidance and the July 2024 joint statement on third-party deposit arrangements.
  6. Issue the first quarterly board report within 90 days with open issues, responsible owners, due dates, residual risk, and board decisions required.
  7. Create a 90-day conversion option if the bank later decides to recruit a permanent in-house CCO.

When a fractional CCO is the wrong answer.

A fractional CCO is not suitable for every institution. It is the wrong answer where a specific license, consent order, regulator expectation, or board resolution requires a full-time in-house officer. It is also the wrong answer where the bank’s issue is not leadership capacity but a broken control environment that first requires regulatory remediation.

In those situations, the right model may be a remediation PMO, managed compliance operations, or a permanent executive search process supported by interim coverage. The point is not to make fractional fit every problem. The point is to match authority, capacity, and cost to the risk profile.

Practical decision rule

If the bank’s board needs senior compliance judgement every week, but not a full-time executive every day, fractional is worth testing. If the regulator has already demanded a full-time officer, hire one.

How this connects to growth, AI, and managed compliance.

The CCO role is increasingly connected to growth strategy. Sponsor-bank relationships, banking-as-a-service programs, embedded finance, digital onboarding, and AI-driven monitoring can all fail if compliance is brought in after the product decision.

For banks expanding into fintech partnerships or modernizing compliance operations, the Fractional CCO model can be paired with Compliance Managed Services, Compliance Reinvented, and Enterprise AI governance support.

For non-US financial institutions entering the American market, the same leadership logic applies: the regulatory bar is high before the first customer is onboarded. That is where US Market Entry advisory becomes part of the compliance operating model, not a legal afterthought.

Compliance leadership should be visible.

A $1.2B community bank, six months without a CCO — back to examiner-ready governance in 90 days, without hiring a full-time executive.

The lesson: fractional only works when the model has named accountability, board-facing reporting, execution capacity, and examination-grade documentation.

That is the difference between buying advisory hours and building a compliance leadership function.

Ravi de Silva representing de Risk Partners at a fintech and compliance leadership event

Questions community-bank boards ask first.

Will examiners accept a fractional CCO?

Yes, where the CCO is a named individual with defined authority, documented hours, direct access to the board, and clear responsibility for the compliance program. Examiners are concerned with substance: independence, authority, reporting line, documentation, and evidence of oversight.

How does the economics actually work?

A fractional CCO engagement at a $1B community bank typically lands between 35% and 55% of the loaded cost of a full-time CCO at senior-market compensation. Savings come from defined leadership hours, offshore execution support, and reduced recruiting, benefits, equity, and turnover cost.

Who at de Risk Partners holds the CCO of record role?

The CCO of record is matched to the institution by asset size, charter type, regulator, examination history, product set, and risk profile. de Risk’s roster includes former examiners and senior compliance leaders from major global financial institutions.

Can a fractional CCO also support BSA/AML operations?

Yes. The senior CCO layer can be paired with a managed-services execution layer covering BSA/AML alert disposition, SAR support, KYC refresh, sanctions documentation, issue tracking, policy maintenance, and reporting inputs.

When should a community bank avoid a fractional CCO?

A bank should avoid the model where a regulator, consent order, license condition, or board mandate specifically requires a full-time in-house officer. It should also avoid weak vendor-style models where no individual is named, no SLA exists, and board reporting is informal.

What should we bring to a scoping call?

Bring the last examination report, the latest BSA/AML risk assessment, internal audit findings, third-party risk register, compliance committee pack, open issue log, and current organizational chart. de Risk can usually return a fixed-fee proposal within 72 hours after review.

Ravi de Silva in suit
About the Author

Ravi de Silva, Founder & CEO.

Ravi de Silva is the Founder & CEO of de Risk Partners and de Risk Suisse, advising regulated financial institutions, fintechs, digital asset businesses, and compliance teams on financial crime risk, regulatory remediation, AI governance, and compliance transformation.

His work focuses on helping boards and senior leadership teams build compliance operating models that are regulator-ready, commercially practical, and resilient under examination pressure.

Connect on LinkedIn

Need senior compliance leadership without the full-time price tag?

Book a 30-minute fractional CCO scoping call. Bring your last examination report. de Risk Partners will review the situation and return a fixed-fee proposal within 72 hours.