Item 1. Business
ITEM 1 - BUSINESS
General
First Northern Community Bancorp (the “Company”) is a bank holding company registered under the Bank Holding Company Act of 1956, as amended (“BHCA”). Its legal headquarters and principal administrative
offices are located at 195 N. First Street, Dixon, CA 95620 and its telephone number is (707) 678-3041. The Company provides a full range of community banking services to individual and corporate customers throughout the California Counties of
Solano, Yolo, Placer, and Sacramento as well as portions of El Dorado County through its wholly-owned subsidiary bank, First Northern Bank of Dixon (“First Northern” or the “Bank”). The Company’s operating policy since inception has emphasized the
banking needs of individuals and small- to medium-sized businesses. In addition, the Bank owns 100% of the capital stock of Yolano Realty Corporation, a subsidiary created for the purpose of managing selected other real estate owned properties.
The Bank was established in 1910 under a California state charter as Northern Solano Bank, and opened for business on February 1st of that year. On January 2, 1912, the First National Bank of Dixon was
established under a federal charter, and until 1955, the two entities operated side by side under the same roof and with the same management. In an effort to increase efficiency of operation, reduce operating expense, and improve lending capacity,
the two banks were consolidated on April 8, 1955, with the First National Bank of Dixon as the surviving entity. On January 1, 1980, the Bank's federal charter was relinquished in favor of a California state charter, and the Bank's name was changed
to First Northern Bank of Dixon.
In April of 2000, the shareholders of First Northern approved a corporate reorganization, which provided for the creation of the bank holding company. This reorganization, effected May 19, 2000, enabled
the Company to better compete and grow in its competitive and rapidly changing marketplace.
On January 20, 2023, the Company completed the acquisition of three branches of Columbia State Bank, a Washington state-chartered commercial bank
(“Columbia”), and a wholly-owned subsidiary of Columbia Banking System, Inc., in the California towns of Colusa, Orland and Willows. This acquisition enabled the Company to extend its existing footprint. The aggregate deposits assumed totaled
approximately $116 million, and the aggregate principal balance of the loans acquired totaled approximately $4 million.
The Bank has fourteen full-service branches located in the cities of Auburn, Colusa, Davis, Dixon, Fairfield, Orland, Rancho Cordova, Roseville, Sacramento, Vacaville, West Sacramento, Winters, Willows
and Woodland. The Bank has one satellite banking office inside a retirement community in the city of Davis and a residential mortgage loan office in Davis. The Bank engages financial advisors, through Raymond James Financial Services, Inc., who offer
non-FDIC insured investment and brokerage services throughout the region from offices strategically located in West Sacramento, Davis and Auburn. The Bank’s operations center is located in Dixon and provides back-office support including information
services, central operations, and the central loan department. In 2019, the Bank opened an additional administrative office in Sacramento.
The Bank is in the commercial banking business and generates most of its revenue by providing a wide range of products and services to small- and medium-sized businesses and individuals, including
accepting demand, interest bearing transaction, savings, and time deposits, and making commercial, consumer, and real estate related loans. It also rents safe deposit boxes and provides other customary banking services.
First Northern offers a broad range of alternative investment products, fiduciary and other financial services through Raymond James Financial Services, Inc. First Northern also offers equipment
leasing, credit cards, merchant card processing, payroll services, and limited international banking services through third parties.
The Bank’s principal source of revenue is interest income. Interest income is primarily derived from interest and fees on loans and leases, interest on investments, and due from banks interest bearing
accounts. For the year ended December 31, 2024, these sources comprised approximately 70%, 19%, and 9%, respectively, of the Company’s interest income.
The Bank is a member of the Federal Deposit Insurance Corporation ("FDIC") and all deposit accounts are insured by the FDIC to the maximum amount permitted by law, currently $250,000 per depositor. Most
of the Bank's deposits are attracted from the market of northern and central Solano County, southern and central Yolo County and Placer County. The Bank’s deposits are not received from a single depositor or group of affiliated depositors, the loss
of any one which would have a materially adverse impact on the business of the Bank. A material portion of the Bank’s deposits are not concentrated within a single industry group of related industries.
5
Table of Contents
As of December 31, 2024, the Company had consolidated assets of approximately $1.89 billion, liabilities of approximately $1.72 billion and stockholders’ equity of approximately $176.3 million. The
Company and its subsidiaries employed 187 full-time-equivalent employees as of December 31, 2024. The Company and the Bank consider their relationship with their employees to be good and have not experienced any interruptions of operations due to
labor disagreements.
Available Information
The Company makes available free of charge on its website, www.thatsmybank.com , its Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments to
those reports, as soon as reasonably practicable after the Company electronically files such material with, or furnishes it to, the SEC. These filings are also accessible on the SEC’s website at www.sec.gov . The information found on the
Company’s website shall not be deemed incorporated by reference by any general statement incorporating by reference this report into any filing under the Securities Act of 1933 or under the Securities Exchange Act of 1934 and shall not otherwise be
deemed filed under such Acts.
The Effect of Government Policy on Banking
The earnings and growth of the Bank are affected not only by local market area factors and general economic conditions, but also by government monetary and fiscal policies. For example, the Board of
Governors of the Federal Reserve System (“FRB”) influences the supply of money through its open market operations in U.S. Government securities, adjustments to the discount rates applicable to borrowings by depository institutions and others and
establishment of reserve requirements against both member and non-member financial institutions’ deposits. Such actions significantly affect the overall growth and distribution of loans, investments, and deposits and also affect interest rates
charged on loans and paid on deposits. The nature and impact of future changes in economic conditions and governmental policies on the business and earnings of the Company cannot be predicted. Additionally, state and federal tax policies can impact
banking organizations.
Because of the extensive regulation of commercial banking activities in the United States, the business of the Company is particularly susceptible to being affected by the enactment of federal and state
legislation which may have the effect of increasing or decreasing the cost of doing business, modifying permissible activities or enhancing the competitive position of other financial institutions. Any change in applicable laws, regulations, or
policies may have a material adverse effect on the business, financial condition, or results of operations, or prospects of the Company.
In May 2018, President Trump signed into law the Economic Growth, Regulatory Relief and Consumer Protection Act (the “EGRRCPA”) which amended various provisions of the Dodd-Frank Act as well as other federal banking
statutes, and generally authorized the FRB to tailor regulation to better reflect the character of the different banking firms that the FRB supervises. In August 2018, the FRB began implementing the EGRRCPA with several interim final rules which,
among other things, revised the FRB’s Small Bank Holding Company and Savings and Loan Holding Company Policy Statement (the “policy statement”) to raise the consolidated assets threshold from $1 billion to $3 billion, allowing the Company to qualify
under the policy statement. This policy statement applies to bank holding companies with pro forma consolidated assets of less than $3 billion that (i) are not engaged in significant nonbanking activities either directly or through a nonbank
subsidiary; (ii) do not conduct significant off-balance sheet activities (including securitization and asset management or administration) either directly or through a nonbank subsidiary; and (iii) do not have a material amount of debt or equity
securities outstanding (other than trust preferred securities) that are registered with the SEC. This policy statement permits qualifying bank holding companies, such as the Company, to operate with higher levels of debt, facilitating the ability of
community banks to issue debt and raise capital. Qualifying bank holding companies, such as the Company, also are permitted to be examined by a Federal banking agency every 18 months (as opposed to every 12 months) and are eligible to use shorter
call report forms. Whether and to what extent the EGRRCPA or new legislation will result in additional regulatory initiatives and policies, or modifications of existing regulations and policies, which may impact our business, cannot be predicted at
this time. See "Possible Future Legislation and Regulatory Initiatives" below for more information.
The new Trump Administration has indicated a desire to reduce the regulatory burden on U.S. companies, including financial institutions. See “Possible Future Legislation and Regulatory Initiatives” below for
additional information.
Supervision and Regulation of Bank Holding Companies
The Company is a bank holding company subject to the BHCA. The Company reports to, registers with, and is subject to regulation, supervision and examination by, the FRB. The FRB also has the authority
to examine the Company’s subsidiaries. The costs of any examination by the FRB are payable by the Company.
The FRB has significant supervisory, regulatory and enforcement authority over the Company and its affiliates. The FRB requires the Company to maintain certain levels of capital. See “Capital
Standards” below for more information. The FRB also has the authority
6
Table of Contents
to take enforcement action against any bank holding company that commits any unsafe or unsound practice, or violates certain laws, regulations, or conditions imposed in writing by the FRB. See “Prompt
Corrective Action and Other Enforcement Mechanisms” below for more information. Such enforcement powers include the power to assess civil money penalties against any bank holding company violating any provision of the BHCA or any regulation or order
of the FRB under the BHCA. Knowing violations of the BHCA or regulations or orders of the FRB can also result in criminal penalties for the bank holding company and any individuals participating in such conduct. Under long-standing FRB policy and
provisions of the Dodd-Frank Act, bank holding companies are required to act as a source of financial and managerial strength to their subsidiary banks, and to commit resources to support their subsidiary banks. This support may be required at times
when a bank holding company may not have the resources to provide such support, or may not be inclined to provide such support under the then-existing circumstances.
Under the BHCA, a company generally must obtain the prior approval of the FRB before it exercises a controlling influence over a bank, or acquires, directly or indirectly, more than 5% of the voting
shares or substantially all of the assets of any bank or bank holding company. Thus, the Company is required to obtain the prior approval of the FRB before it acquires, merges, or consolidates with any bank or bank holding company. Any company
seeking to acquire, merge, or consolidate with the Company also would be required to obtain the prior approval of the FRB.
The Company is generally prohibited under the BHCA from acquiring ownership or control of more than 5% of the voting shares of any company that is not a bank or bank holding company and from engaging
directly or indirectly in activities other than banking, managing banks, or providing services to affiliates of the holding company. However, a bank holding company, with the approval of the FRB, may engage, or acquire the voting shares of companies
engaged, in activities that the FRB has determined to be so closely related to banking or managing or controlling banks as to be a proper incident thereto. A bank holding company must demonstrate that the benefits to the public of the proposed
activity will outweigh the possible adverse effects associated with such activity.
The FRB generally prohibits a bank holding company from declaring or paying a cash dividend which would impose undue pressure on the capital of subsidiary banks or would be funded only through borrowing
or other arrangements that might adversely affect a bank holding company’s financial position. The FRB’s policy is that a bank holding company should not continue its existing rate of cash dividends on its common stock unless its net income is
sufficient to fully fund each dividend and its prospective rate of earnings retention appears consistent with its capital needs, asset quality, and overall financial condition. The Company is also subject to restrictions relating to the payment of
dividends under California corporate law. See “Restrictions on Dividends and Other Distributions” below for additional restrictions on the ability of the Company and the Bank to pay dividends.
Supervision and Regulation of the Bank
The Bank is subject to regulation, supervision and regular examination by the Financial Institutions Division of the California Department of Financial Protection and Innovation ("DFPI")
and the FDIC. The regulations of and laws administered by these agencies affect most aspects of the Bank’s business and prescribe permissible types of loans and investments, the amount of required reserves, requirements for branch offices, the
permissible scope of the Bank’s activities and various other requirements. While the Bank is not a member of the FRB, it is directly subject to certain regulations of the FRB dealing with such matters as check clearing activities, establishment of
banking reserves, Truth-in-Lending (“Regulation Z”), and Equal Credit Opportunity (“Regulation B”). The FDIC regularly conducts compliance examinations of insured depository institutions to determine whether the institution is meeting its
responsibility to comply with the requirements of consumer protection laws and regulations. The Bank is also subject to regulations of (although not direct supervision and examination by) the Consumer Financial
Protection Bureau (“CFPB”), which was created by the Dodd-Frank Act. Among the CFPB’s responsibilities are implementing and enforcing federal consumer financial protection laws, reviewing the business practices of financial services providers for
legal compliance, monitoring the marketplace for transparency on behalf of consumers and receiving complaints and questions from consumers about consumer financial products and services. The Dodd-Frank Act added prohibitions on unfair, deceptive or
abusive acts and practices to the scope of consumer protection regulations overseen and enforced by the CFPB.
Many states and local jurisdictions have consumer protection laws analogous, and in addition, to those listed above. These federal, state and local laws regulate the manner in which financial institutions deal with
customers when taking deposits, making loans or conducting other types of transactions. Failure to comply with these laws and regulations could give rise to regulatory sanctions, customer rescission rights, action by state and local attorneys general
and civil or criminal liability. Failure to comply with consumer protection requirements may also result in our failure to obtain any required bank regulatory approval for merger or acquisition transactions we may wish to pursue or our prohibition
from engaging in such transactions even if approval is not required. See “Possible Future Legislation and Regulatory Initiatives” below for additional information about potential changes to the CFPB and consumer protection laws and enforcement.
The banking industry is also subject to significantly increased regulatory controls and processes regarding the Bank Secrecy Act and anti-money laundering laws. Over the past decade, a number of banks and bank
holding companies announced the imposition of regulatory sanctions, including regulatory agreements and cease and desist orders and, in some cases, fines and penalties, by the bank
7
Table of Contents
regulators due to failures to comply with the Bank Secrecy Act and other anti-money laundering legislation. In a number of these cases, the fines and penalties have been significant. Failure to comply
with these additional requirements may also adversely affect the Bank's ability to obtain regulatory approvals for future initiatives requiring regulatory approval, including acquisitions.
Under California law, the Bank is subject to various restrictions on, and requirements regarding, its operations and administration including the maintenance of branch offices and automated teller
machines, capital and reserve requirements, deposits and borrowings, and investment and lending activities.
California law permits a state-chartered bank to invest in the stock and securities of other corporations, subject to a state-chartered bank receiving either general authorization or, depending on the
amount of the proposed investment, specific authorization from the DFPI. Federal banking laws, however, impose limitations on the activities and equity investments of state-chartered, federally insured banks. The FDIC rules on investments prohibit
a state bank from acquiring an equity investment of a type, or in an amount, not permissible for a national bank. FDIC rules also prohibit a state bank from engaging as a principal in any activity that is not permissible for a national bank, unless
the bank is adequately capitalized and the FDIC approves the activity after determining that such activity does not pose a significant risk to the deposit insurance fund. The FDIC rules on activities generally permit subsidiaries of banks, without
prior specific FDIC authorization, to engage in those activities that have been approved by the FRB for bank holding companies because such activities are so closely related to banking to be a proper incident thereto. Other activities generally
require specific FDIC prior approval, and the FDIC may impose additional restrictions on such activities on a case-by-case basis in approving applications to engage in otherwise impermissible activities.
The USA Patriot Act
Title III of the United and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001 (“USA Patriot Act”) includes numerous provisions for fighting
international money laundering and blocking terrorism access to the U.S. financial system. The USA Patriot Act requires certain additional due diligence and record keeping practices, including, but not limited to, new customers, correspondent and
private banking accounts.
Part of the USA Patriot Act is the International Money Laundering Abatement and Financial Anti-Terrorism Act of 2001 (“IMLAFATA”). Among its provisions, IMLAFATA requires each financial institution to:
(i) establish an anti-money laundering program; (ii) establish appropriate anti-money laundering policies, procedures, and controls; (iii) appoint a Bank Secrecy Act officer responsible for day-to-day compliance; and (iv) conduct independent audits.
In addition, IMLAFATA contains a provision encouraging cooperation among financial institutions, regulatory authorities, and law enforcement authorities with respect to individuals, entities and organizations engaged in, or reasonably suspected of
engaging in, terrorist acts or money laundering activities. IMLAFATA expands the circumstances under which funds in a bank account may be forfeited and requires covered financial institutions to respond under certain circumstances to requests for
information from federal banking agencies within 120 hours. IMLAFATA also amends the BHCA and the federal Bank Merger Act to require the federal banking agencies to consider the effectiveness of a financial institution’s anti-money laundering
activities when reviewing an application under these Acts.
Pursuant to IMLAFATA, the Secretary of the Treasury, in consultation with the heads of other government agencies, has adopted measures applicable to banks, bank holding companies, and/or other financial
institutions. These measures include enhanced record keeping and reporting requirements for certain financial transactions that are of primary money laundering concern, due diligence requirements concerning the beneficial ownership of certain types
of accounts, and restrictions or prohibitions on certain types of accounts with foreign financial institutions.
Privacy Restrictions
The Gramm-Leach-Bliley Act (“GLBA”), which became law in 1999, in addition to the previous described changes in permissible non-banking activities permitted to banks, bank holding companies and
financial holding companies, also requires financial institutions in the U.S. to implement policies and procedures regarding the disclosure of nonpublic personal information about consumers to non-affiliated third parties. In general, the GLBA
requires explanations to consumers on policies and procedures regarding the disclosure of such nonpublic personal information, and, except as otherwise required by law, prohibits disclosing such information except as provided in the banks’ policies
and procedures and applicable law. These regulations also allow consumers to opt-out of the sharing of certain information between affiliates, and impose other requirements.
Certain state laws and regulations designed to protect the privacy and security of customer information also apply to us and our subsidiaries, including laws requiring notification to affected
individuals and regulators of data security breaches. For additional information, see “Information Security Breaches or Other Technological Difficulties Could Adversely Affect the Company” in Part I, Item 1A. “Risk Factors” in this Annual Report on
Form 10-K.
The Company believes that it complies with all provisions of GLBA and all implementing regulations, and that the Bank has
8
Table of Contents
developed appropriate policies and procedures to meet its responsibilities in connection with the privacy provisions of GLBA.
California and other state legislatures have adopted privacy laws, including laws prohibiting sharing of customer information without the customer’s prior permission. These laws may make it more difficult for the Company to share information with
its marketing partners, reduce the effectiveness of marketing programs, and increase the cost of marketing programs.
In June 2018, the State of California enacted The California Consumer Privacy Act of 2018 (“CCPA”). This law became effective on January 1, 2020, and provides consumers with expansive rights and controls over their
personal information which is obtained by or shared with “covered businesses”, which includes the Bank and most other banking institutions subject to California law. The CCPA gives consumers the right to request
disclosure of information collected about them and whether that information has been sold or shared with others, the right to request deletion of personal information subject to certain exceptions, the right to opt out of the sale of the consumer’s
personal information and the right not to be discriminated against because of choices regarding the consumer’s personal information. The CCPA provides for certain monetary penalties and for its enforcement by the California Attorney General or
consumers whose rights under the law are not observed. It also provides for damages as well as injunctive or declaratory relief if there has been unauthorized access, theft or disclosure of personal information due to failure to implement
reasonable security procedures. The CCPA contains several exemptions, including a provision to the effect that the CCPA does not apply where the information is collected, processed, sold or disclosed pursuant to the GLBA if the GLBA is in conflict
with the CCPA.
In November 2020, California voters approved state-wide Proposition 24, also known as the California Privacy Rights and Enforcement Act of 2020 (the “CPREA") which expanded and amended certain provisions of the CCPA
and created the California Privacy Protection Agency to enforce privacy rights for Californians and impose fines for violations of such rights. The CPREA requires businesses to not share a consumer’s personal information upon the consumer’s request,
provides consumers with an opt-out option for having their sensitive personal information used or disclosed for advertising or marketing, to obtain permission for collecting data on certain minors, and to correct a consumer’s inaccurate information
upon the consumer’s request. It also removed the ability of businesses to remedy violations before being penalized for violations and increased the penalties for such violations.
These laws could adversely impact the business of the Bank by resulting in increased operating expenses as well as additional exposure to the risk of litigation by or on behalf of consumers.
Capital Standards
The FRB and the federal banking agencies have in place risk-based capital standards applicable to U.S. bank holding companies and banks. In July 2013, the FRB and the other U.S. federal banking agencies adopted final
rules making significant changes to the U.S. regulatory capital framework for U.S. banking organizations and to conform this framework to the guidelines published by the Basel Committee on Banking Supervision ("Basel Committee") known as the Basel
III Global Regulatory Framework for Capital and Liquidity. The Basel Committee is a committee of banking supervisory authorities from major countries in the global financial system which formulates broad supervisory standards and guidelines relating
to financial institutions for implementation on a country-by-country basis. These rules adopted by the FRB and the other federal banking agencies ("the U.S. Basel III Capital Rules") replaced the federal banking agencies’ general risk-based capital
rules, advanced approaches rule, market risk rule, and leverage rules, in accordance with certain transition provisions.
Banks, such as First Northern, became subject to these rules on January 1, 2015. The rules implemented higher minimum capital requirements, include a common equity Tier 1 capital requirement, and established criteria
that instruments must meet in order to be considered common equity Tier 1 capital, additional Tier 1 capital, or Tier 2 capital. The final rules provided for increased minimum capital ratios as follows: (a) a common equity Tier 1 capital ratio of
4.5%; (b) a Tier 1 capital ratio of 6%; (c) a total capital ratio of 8%; and (d) a Tier 1 leverage ratio to average consolidated assets of 4%. Under these rules, in order to avoid certain limitations on capital distributions, including dividend
payments and certain discretionary bonus payments to executive officers, a banking organization must hold a capital conservation buffer composed of common equity Tier 1 capital above its minimum risk-based capital requirements (equal to 2.5% of total
risk-weighted assets). The capital conservation buffer is designed to absorb losses during periods of economic stress. First Northern believes that it was in compliance with these requirements at December 31, 2024.
Pursuant to the EGRRCPA, the FRB adopted a final rule, effective August 31, 2018, amending the Small Bank Holding Company and Savings and Loan Holding Company Policy Statement (the “policy statement”) to increase the
consolidated assets threshold to qualify to utilize the provisions of the policy statement from $1 billion to $3 billion. Bank holding companies, such as the Company, are subject to capital adequacy requirements of the FRB; however, bank holding
companies which are subject to the policy statement are not subject to compliance with the regulatory capital requirements until they hold $3 billion or more in consolidated total assets. As a consequence, as of December 31, 2024, the Company was not
required to comply with the FRB’s regulatory capital requirements until such time that its consolidated total assets equal $3 billion or more or if the FRB determines that the Company is no longer deemed to be a small bank holding company. However,
if the Company had been subject to these regulatory capital requirements, it would have exceeded all regulatory requirements.
9
Table of Contents
In August of 2020, the federal banking agencies adopted the final version of the community bank leverage ratio framework rule (the “CBLR”), implementing two interim final rules adopted in April of 2020. The rule
provides an optional, simplified measure of capital adequacy. Under the optional CBLR framework, the CBLR was 8.5% through calendar year 2021 and 9% thereafter. The rule is applicable to all non-advanced approaches FDIC-supervised institutions with
less than $10 billion in total consolidated assets. Banks not electing the CBLR framework will continue to be subject to the generally applicable risk-based capital rule. At the present time, while we are a qualifying community banking
organization, the Company and the Bank do not intend to elect to use the CBLR framework.
The following table presents the capital ratios for the Bank as of December 31, 2024 (calculated in accordance with the Basel III capital rules):
The Bank
2024
Adequately Capitalized
Well
Capitalized
Capital
Ratio
Ratio*
Ratio
Tier 1 Leverage Capital (to Average Assets)
$
205,326
10.5
%
4.0
%
5.0
%
Common Equity Tier 1 Capital (to Risk-Weighted Assets)
205,326
16.4
%
4.5
%
6.5
%
Tier 1 Capital (to Risk-Weighted Assets)
205,326
16.4
%
6.0
%
8.0
%
Total Risk-Based Capital (to Risk-Weighted Assets)
220,977
17.7
%
8.0
%
10.0
%
* Ratio for regulatory requirement excludes the capital conservation buffer of 2.50%.
The federal banking agencies must take into consideration concentrations of credit risk and risks from non-traditional activities, as well as an institution’s ability to manage those risks, when
determining the adequacy of an institution’s capital. This evaluation will be made as a part of the institution’s regular safety and soundness examination. The federal banking agencies must also consider interest rate risk (when the interest rate
sensitivity of an institution’s assets does not match the sensitivity of its liabilities or its off-balance-sheet position) in evaluating a Bank’s capital adequacy.
In January 2014, the Basel Committee issued an updated version of its leverage ratio and disclosure guidance ("Basel III leverage ratio"), which were implemented beginning January 1, 2023. The Basel
Committee guidance continues to set a minimum Basel III leverage ratio of 3%. The Basel Committee, in December 2017, adopted further revisions to the Basel III capital standards ("Basel IV") which refined the definition of the leverage ratio
“exposure measures” (the Basel III term for non risk-weighted assets). On July 27, 2023, the federal banking agencies issued a proposed rule to implement the final components of the Basel III standards set by the Basel Committee on Banking
Supervision in 2017. The proposed rule, which would not apply to the Company and the Bank as proposed, would substantially revise the existing regulatory capital framework for institutions with $100 billion or more of assets.
The new Trump Administration may consider adjustments to these capital and liquidity rules. Whether and the extent to which these proposed rules, or modifications of existing regulations and policies, which may impact our business, will be enacted
and implemented is uncertain and cannot be predicted at this time.
Prompt Corrective Action and Other Enforcement Mechanisms
The Federal Deposit Insurance Corporation Improvement Act of 1991 (“FDICIA”) requires each federal banking agency to take prompt corrective action to resolve the problems of insured depository
institutions, including but not limited to those that fall below one or more prescribed minimum capital ratios. The law required each federal banking agency to promulgate regulations defining the following five categories in which an insured
depository institution will be placed, based on the level of its capital ratios: well capitalized, adequately capitalized, under-capitalized, significantly undercapitalized, and critically undercapitalized.
Under the prompt corrective action provisions of FDICIA, an insured depository institution generally will be classified in one of five capital categories ranging from "well capitalized" to "critically
under-capitalized."
An institution that, based upon its capital levels, is classified as “well capitalized,” “adequately capitalized” or “under-capitalized” may be treated as though it were in the next lower capital
category if the appropriate federal banking agency, after notice and opportunity for hearing, determines that an unsafe or unsound condition or an unsafe or unsound practice warrants such treatment. At each successive lower capital category, an
insured depository institution is subject to increased restrictions on its operations. Management believes that at December 31, 2024, the Company and the Bank exceeded the required ratios for classification as “well capitalized." Institutions that
are “under-capitalized” or lower are subject to certain mandatory supervisory corrective actions. Failure to meet regulatory capital guidelines can result in a bank being required to raise additional capital. An
10
Table of Contents
“under-capitalized” bank must develop a capital restoration plan and its parent holding company must generally guarantee compliance with the plan.
In addition to measures taken under the prompt corrective action provisions, commercial banking organizations may be subject to potential enforcement actions by the federal regulators for unsafe or
unsound practices in conducting their businesses or for violations of any law, rule, regulation or any condition imposed in writing by the agency or any written agreement with the agency. Enforcement actions may include the imposition of a
conservator or receiver, the issuance of a cease-and-desist order that can be judicially enforced, the termination of insurance of deposits (in the case of a depository institution), the imposition of civil money penalties, the issuance of directives
to increase capital, the issuance of formal and informal agreements, the issuance of removal and prohibition orders against institution-affiliated parties and the enforcement of such actions through injunctions or restraining orders based upon a
judicial determination that the agency would be harmed if such equitable relief was not granted. Additionally, a holding company’s inability to serve as a source of strength to its subsidiary banking organizations could serve as a further basis for
a regulatory action against the holding company.
Safety and Soundness Standards
FDICIA also implemented certain specific restrictions on transactions and required federal banking regulators to adopt overall safety and soundness standards for depository institutions related to
internal control, loan underwriting and documentation and asset growth. Among other things, FDICIA limits the interest rates paid on deposits by undercapitalized institutions, restricts the use of brokered deposits, limits the aggregate extensions
of credit by a depository institution to an executive officer, director, principal shareholder, or related interest, and reduces deposit insurance coverage for deposits offered by undercapitalized institutions for deposits by certain employee
benefits accounts.
The federal banking agencies may require an institution to submit to an acceptable compliance plan as well as have the flexibility to pursue other more appropriate or effective courses of action given
the specific circumstances and severity of an institution’s non-compliance with one or more standards.
Restrictions on Dividends and Other Distributions
The power of the board of directors of an insured depository institution to declare a cash dividend or other distribution with respect to capital is subject to statutory and regulatory restrictions
which limit the amount available for such distribution depending upon the earnings, financial condition and liquidity needs of the institution, as well as general business conditions. FDICIA prohibits insured depository institutions from paying
management fees to any controlling persons or, with certain limited exceptions, making capital distributions, including dividends, if, after such transaction, the institution would be undercapitalized.
The federal banking agencies also have authority to prohibit a depository institution from engaging in business practices, which are considered to be unsafe or unsound, possibly including payment of
dividends or other payments under certain circumstances even if such payments are not expressly prohibited by statute.
In addition to the restrictions imposed under federal law, banks chartered under California law generally may only pay cash dividends to the extent such payments do not exceed the lesser of retained
earnings of the bank’s net income for its last three fiscal years (less any distributions to shareholders during such period). In the event a bank desires to pay cash dividends in excess of such amount, the bank may pay a cash dividend with the
prior approval of the DFPI in an amount not exceeding the greatest of the bank’s retained earnings, the bank’s net income for its last fiscal year, or the bank’s net income for its current fiscal year.
Premiums for Deposit Insurance
The Bank is a member of the Deposit Insurance Fund (“DIF”) maintained by the FDIC. Through the DIF, the FDIC insures the deposits of the Bank up to prescribed limits for each depositor. To maintain
the DIF, member institutions are assessed an insurance premium based on their deposits and their institutional risk category. The FDIC determines an institution’s risk category by combining its supervisory ratings with its financial ratios and other
risk measures. The FDIC also has the authority to impose special assessments at any time it estimates that DIF reserves could fall to a level that would adversely affect public confidence.
In September, 2020, the FDIC board of directors voted to adopt a restoration plan to restore the DIF reserve ratio to at least 1.35% within 8 years as required by the Dodd-Frank Act. This action was in response to the
reserve ratio dropping to 1.30% primarily due to the inflow of more than $1 trillion in estimated insured deposits in the first six month of 2020 resulting mainly from the pandemic, monetary policy actions, direct government assistance and an overall
reduction in business spending. On October 18, 2022, the FDIC adopted a final rule, applicable to all insured depository institutions to increase the initial base deposit insurance assessment rate schedules uniformly by two basis points consistent
with the Amended Restoration Plan approved by the FDIC on June 21, 2022. The FDIC indicated that it was taking this action in order to restore the DIF reserve ratio to the required statutory minimum of 1.35% by
11
Table of Contents
the statutory deadline of September 30, 2028. Under the final rule, the increase in rates began with the first quarterly assessment period of 2023 and will remain in effect unless and until the reserve ratio meets or
exceeds 2% in order to support growth in the DIF in progressing toward the FDIC’s long-term goal of a 2% reserve ratio. The increase in assessment rates will apply to the Bank and is projected to have an insignificant effect on the Company’s capital
levels and net income.
Deposit insurance assessments and assessment rates are subject to change by the FDIC and can be impacted by the overall economy and the stability of the banking industry as a whole. On November 16, 2023, the FDIC
issued a final rule to implement a special assessment to recover the loss to the DIF associated with protecting uninsured depositors following the closure of Silicon Valley Bank and Signature Bank. Under the final rule, the assessment base for an
insured depository institution was equal to the institution’s estimated uninsured deposits as of December 31, 2022, adjusted to exclude the first $5 billion in estimated uninsured deposits. Under the final rule, the FDIC will collect the special
assessment at an annual rate of 13.4 basis points beginning with the first quarterly assessment period of 2024 and continuing for an anticipated total of eight quarterly assessment periods. This special assessment did not apply to the Bank; however,
there can be no assurance that the FDIC will not impose special assessments on, or increase annual assessments payable by, the Bank in the future. The ultimate effect on our business of legislative, regulatory and economic developments on the DIF
cannot be predicted with certainty. Future increases in insurance premiums could have adverse effects on the operating expenses and results of operations of the Company. Management cannot predict what the FDIC insurance assessment rates will be in
the future.
Insurance of a bank’s deposits may be terminated by the FDIC upon a finding that the institution has engaged in unsafe or unsound practices, is in an unsafe or unsound condition to continue operations, or has violated
any applicable law, regulation, rule, order, or condition imposed by the FDIC or the Bank’s primary regulator. Management of the Company is not aware of any practice, condition or violation that might lead to termination of the Company’s deposit
insurance.
Community Reinvestment Act and Fair Lending
The Bank is subject to certain fair lending requirements and reporting obligations involving its home mortgage lending operations and is also subject to the Community Reinvestment Act (“CRA”). The CRA
generally requires the federal banking agencies to evaluate the record of a financial institution in meeting the credit needs of the Bank’s local communities, including low- and moderate-income neighborhoods. In addition to substantive penalties and
corrective measures that may be required for a violation of certain fair lending laws, the federal banking agencies may take compliance with such laws and CRA into account when reviewing other activities by the Bank, particularly applications
involving business expansion such as acquisitions or de novo branching.
On October 24, 2023, the federal banking agencies jointly issued a final rule to strengthen and modernize the existing CRA regulations. Under the final rule, the agencies will evaluate a
bank’s CRA performance based upon the varied activities that it conducts and the communities in which it operates. CRA evaluations and data collection requirements will be tailored based on bank size and type. Under the final rule, the Bank would
be considered an intermediate bank (with assets of at least $600 million and less than $2 billion) and therefore will be evaluated under a new retail lending test and will have the flexibility to remain under the existing CD test under the current
rule or opt into a new Community Development Financing Test. The final rule includes CRA assessment areas associated with mobile and online banking, and new metrics and benchmarks to assess retail lending performance. In addition, the final rule
emphasizes smaller loans and investments that can have a high impact and be more responsive to the needs of low- and moderate-income communities. The final rule exempts small and intermediate banks from new data requirements that apply to banks
with assets of at least $2 billion and limits certain new data collection and reporting requirements to large banks with assets greater than $10 billion. The final rule took effect on April 1, 2024; however, on March 21, 2024 the agencies
issued a supplemental final rule extending the applicability date for certain provisions. Specifically, the requirements for facility-based assessment areas and public file provisions, initially effective on April 1, 2024, were extended to January 1,
2026. This extension aligns these provisions with the compliance date for other aspects of the final rule. The supplemental final rule also clarifies that banks are not required to make changes to their public files until January 1, 2026, providing
institutions additional time to comply with the updated public notice requirements. These developments indicate ongoing legal and regulatory adjustments affecting the implementation timeline of the CRA final rule. The Bank continues to monitor and
stay informed on changes to ensure compliance with the evolving regulatory framework.
Cybersecurity
The federal banking regulators regularly issue new guidance and standards, and update existing guidance and standards, regarding cybersecurity intended to enhance cyber risk management among
financial institutions. Financial institutions are expected to comply with such guidance and standards and to accordingly develop appropriate security controls and risk management processes. If we fail to observe such regulatory guidance or
standards, we could be subject to various regulatory sanctions, including financial penalties. In 2023, the SEC issued a final rule that requires disclosure of material cybersecurity incidents, as well as cybersecurity risk management, strategy and
governance. Under this rule, banking organizations that are SEC registrants must generally disclose
12
Table of Contents
information about a material cybersecurity incident within four business days of determining it is material with periodic updates as to the status of the incident in subsequent filings as necessary.
Under a final rule adopted by federal banking agencies in 2021, banking organizations are required to notify their primary banking regulator within 36 hours of determining that a “computer-security incident” has materially disrupted or degraded, or
is reasonably likely to materially disrupt or degrade, the banking organization’s ability to carry out banking operations or deliver banking products and services to a material portion of its customer base, its businesses and operations that would
result in material loss, or its operations that would impact the stability of the United States. The federal banking agencies have also adopted guidelines for establishing information security standards and cybersecurity programs for implementing
safeguards under the supervision of the board of directors. These guidelines, along with related regulatory materials, increasingly focus on risk management and processes related to information technology and the use of third parties in the provision
of financial services. Moreover, recent cyberattacks against banks and other financial institutions that resulted in unauthorized access to confidential customer information have prompted the federal banking regulators to issue more extensive
guidance on cybersecurity risk management. Among other things, financial institutions are expected to design multiple layers of security controls to establish lines of defense and ensure that their risk management processes address the risks posed by
compromised customer credentials, including security measures to authenticate customers accessing internet-based services. A financial institution also should have a robust business continuity program to recover from a cyberattack and procedures for
monitoring the security of third-party service providers that may have access to nonpublic data at the institution.
State regulators have also been increasingly active in implementing privacy and cybersecurity standards and regulations. Recently, several states have adopted regulations requiring certain financial institutions to
implement cybersecurity programs and many states, including Texas, have also recently implemented or modified their data breach notification, information security and data privacy requirements. We expect this trend of state-level activity in those
areas to continue and are continually monitoring developments in the states in which our customers are located.
Risks and exposures related to cybersecurity attacks, including litigation and enforcement risks, are expected to be elevated for the foreseeable future due to the rapidly evolving nature and sophistication of these
threats, as well as due to the expanding use of Internet banking, mobile banking and other technology-based products and services by us and our customers.
See Item 1A. “Risk Factors” for a further discussion of risks related to cybersecurity and Item 1C. “Cybersecurity” for a further discussion of risk management strategies and governance processes related to
cybersecurity.
Certain CFPB Rules
The Consumer Financial Protection Bureau ("CFPB") has adopted an Ability-to-Repay rule that all newly originated residential mortgages must meet. The Ability-to-Repay rule establishes guidelines that
the lender must follow when reviewing an applicant’s income, obligations, assets, liabilities, and credit history and requires that the lender make a reasonable and good faith determination of an applicant’s ability to repay the loan according to its
terms. Lenders will be presumed to have met the Ability-to-Repay rule by originating loans that meet the criteria for “Qualified Mortgages”, which are set forth in detail in the rule. The mortgage loans originated by the Bank with the intent to sell
them to Freddie Mac meet the Qualified Mortgage criteria.
The CFPB has also adopted a rule on simplified and improved mortgage loan disclosures, otherwise known as Know Before You Owe. The rule provides that mortgage borrowers receive a loan estimate three
business days after application and a closing disclosure three days before closing. These forms replace disclosure forms previously provided to borrowers under other provisions of federal law. The rule provides for limitations on application fees
and increases in closing costs.
Any new or modified regulatory requirements promulgated by the CFPB could have an adverse impact on our residential mortgage lending business as the industry adapts to the additional regulations. Our
business strategy, product offerings and profitability may change as the market adjusts to any additional or modified regulations and as these requirements are interpreted by the regulators and courts. See "Possible Future Legislation and Regulatory
Initiatives" below for more information about potential changes to the CFPB and consumer protection laws and enforcement.
Conservatorship and Receivership of Insured Depository Institutions
If any insured depository institution becomes insolvent and the FDIC is appointed its conservator or receiver, the FDIC may, under federal law, disaffirm or repudiate any contract to which such
institution is a party, if the FDIC determines that performance of the contract would be burdensome, and that disaffirmance or repudiation of the contract would promote the orderly administration of the institution’s affairs. Such disaffirmance or
repudiation would result in a claim by its holder against the receivership or conservatorship. The amount paid upon such claim would depend upon, among other factors, the amount of receivership assets available for the payment of such claim and its
priority relative to the priority of others. In addition, the FDIC as conservator or receiver may enforce most contracts entered into by the institution notwithstanding any provision providing for termination, default,
13
Table of Contents
acceleration, or exercise of rights upon or solely by reason of insolvency of the institution, appointment of a conservator or receiver for the institution, or exercise of rights or powers by a
conservator or receiver for the institution. The FDIC as conservator or receiver also may transfer any asset or liability of the institution without obtaining any approval or consent of the institution’s shareholders or creditors.
The Dodd-Frank Act
The Dodd-Frank Act, enacted in 2010, has resulted in sweeping changes to the U.S. financial system and financial institutions, including us. Many of the law’s provisions have been implemented by rules
and regulations of the federal banking agencies. The law contains many provisions which have particular relevance to our business, including provisions that have resulted in adjustments to our FDIC deposit insurance premiums and that resulted in
increased capital and liquidity requirements, increased supervision, increased regulatory and compliance risks and costs and other operational costs and expenses, reduced fee-based revenues and restrictions on some aspects of our operations, and
increased interest expense on our demand deposits. In May 2018, then President Trump signed into law the EGRRCPA, which amended various provisions of the Dodd-Frank Act as well as other federal banking statutes. See “The Effect of Government Policy
on Banking” above for additional information.
The environment in which financial institutions continue to operate since the U.S. financial crisis, including legislative and regulatory changes affecting capital, liquidity, supervision, permissible
activities, corporate governance and compensation, and changes in fiscal policy may have long-term effects on the business model and profitability of financial institutions that cannot now be foreseen.
Overdraft and Interchange Fees
The FRB's Regulation E imposes restrictions on banks’ abilities to charge overdraft services and fees. The rule prohibits financial institutions from charging fees for paying overdrafts on ATM and
one-time debit card transactions, unless a consumer consents, or opts in, to the overdraft service for those types of transactions. The Dodd-Frank Act, through a provision known as the Durbin Amendment, required the FRB to establish standards for
interchange fees that are “reasonable and proportional” to the cost of processing debit card transactions and imposes other requirements on card networks. Under the rule, the maximum permissible interchange fee that a bank may receive is the sum of
$0.21 per transaction and five basis points multiplied by the value of the transaction, with an additional upward adjustment of no more than $0.01 per transaction if a bank develops and implements policies and procedures reasonably designed to
achieve fraud-prevention standards set by regulation. This regulation has resulted in decreased revenues and increased compliance costs for the banking industry and the Bank, and there can be no assurance that alternative sources of revenues can be
implemented to offset the impact of these developments.
Possible Future Legislation and Regulatory Initiatives
The economic and political environment of the past several years has led to a number of proposed legislative, governmental and regulatory initiatives, at both the federal and state levels, certain of
which are described above, that may significantly impact our industry. These and other initiatives could significantly change the competitive and operating environment in which we and our subsidiaries operate. We cannot predict whether these or any
other proposals will be enacted or the ultimate impact of any such initiatives on our operations, competitive situation, financial condition or results of operations.
On January 20, 2025, President Donald J. Trump was sworn into office as the next President of the United States. The Trump Administration has indicated a desire to reduce the regulatory burden on U.S. companies,
including financial institutions. Further, in a recent statement, the Acting Chairman of the FDIC indicated that a matter of FDIC focus (among other things) will include conducting a “wholesale” review of the agency’s regulations, guidance and
manuals. President Trump is likely to appoint, or has already appointed, new acting leadership of bank regulatory agencies, including the CFPB, and, once appointed, this new agency leadership can rescind informal agency guidance, including advisory
opinions, interpretive rules and policy statements, creating opportunities for deregulation. On January 20, 2025, President Trump signed an executive order to pause all pending regulations. Sweeping in nature, the order applies to “all executive
departments and agencies” while directing them to “not propose or issue any rule in any manner, including by sending a rule to the Office of the Federal Register (the “OFR”), until a department or agency head appointed or designated by the President
after noon on January 20, 2025, reviews and approves the rule.” The order also states that agencies must “immediately withdraw any rules that have been sent to the OFR but not published in the Federal Register, so that they can be reviewed and
approved.” The executive order also states that agencies must “consider postponing for 60 days from the date of this memorandum the effective date for any rules that have been published in the Federal Register, or any rules that have been issued in
any manner but have not taken effect, for the purpose of reviewing any questions of fact, law, and policy that the rules may raise.” At this time, no details on potential or proposed reforms have been published, and we are uncertain whether the
intended deregulation will, in fact, occur, or have a significant impact on the Company.
In February 2025, the director of the CFPB was dismissed by the new Trump Administration and the new Director of the Office of Management and Budget was appointed as acting director of the CFPB. The new acting director
of the CFPB directed agency staff to
14
Table of Contents
stop virtually all work, including supervision activities and pending investigations, and announced that the CFPB would not be taking its next draw of federal funding. While the new Trump Administration appointee to
lead the CFPB and Administration policies could result in the rollback of rules implementing and enforcing consumer financial law and regulatory enforcement activities, there is an expectation of increased activity at the state level to enforce
consumer protection, data privacy, and banking regulations to address potential gaps in federal oversight. State regulation of financial products and potential enforcement actions could also adversely affect our business, financial condition or
results of operations. It cannot be predicted at this time what impact these changes will have on the CFPB and its regulatory responsibilities in the consumer protection area, or on the regulation and enforcement of consumer protection laws
generally.
In May 2024, several federal financial agencies (including the FDIC) adopted a notice of proposed rulemaking to address incentive-based compensation arrangements for financial institutions, re-proposing the regulatory
text previously proposed in June 2016 and seeking public comment on certain related matters. The 2024 proposed rule requires enhanced disclosure and reporting of compensation arrangements by covered institutions and prohibits incentive compensation
arrangements that involve inappropriate risks or could lead to material financial loss. The Federal Reserve and the SEC have not joined in issuing the 2024 proposed rule, which has not yet been published in the Federal Register or opened for formal
public comment. At this time, it cannot be predicted whether this proposed rule will be modified or implemented.
Following a bankruptcy filing by a financial services company known as Synapse, in October 2024, the FDIC approved a proposal which will require banks and their “fin-tech” partners holding certain custodial accounts to
maintain timely and accurate records to determine the actual consumers who own funds held in the pooled custodial accounts and the account balance attributable to each consumer so that the FDIC can meet insured deposit claims to beneficial owners
underlying the custody accounts upon the failure of the bank. At the present time, the Bank does not have any such “fin-tech” partners.
Competition
In the past, an independent bank’s principal competitors for deposits and loans have been other banks, savings and loan associations, and credit unions. Many of these competitors are large financial
institutions that have substantial capital, technology and marketing resources, which are well in excess of ours, although these larger institutions may be required to hold more regulatory capital and as a result, achieve lower returns on equity.
For agricultural loans, the Bank also competes with constituent entities with the Federal Farm Credit System. To a lesser extent, competition is also provided by thrift and loans, mortgage brokerage companies and insurance companies. Other
institutions, such as brokerage houses, mutual fund companies, credit card companies, and even retail establishments have offered new investment vehicles, which also compete with banks for deposit business. Additionally, technology has lowered
barriers to entry and made it possible for non-banks to offer products and services traditionally provided by banks, such as automatic transfer and payment systems. We also experience competition, especially for deposits, from internet-based banking
institutions and other financial companies, which do not always have a presence in our market footprint and have grown rapidly in recent years.
Non-traditional financial technology companies are less regulated and continue to expand their offerings of services traditionally provided by financial institutions. Further, the new Trump Administration is expected
to seek to promote innovation across financial services through a regulatory environment that is favorable to cryptocurrencies, digital assets, open banking initiatives and financial technology companies, which has the potential to further increase
competition within the banking industry.
Current federal law has made it easier for out-of-state banks to enter and compete in California. Competition in our principal markets has further intensified as a result of the Dodd-Frank Act which,
among other things, permitted out-of-state de novo branching by national banks, state banks and foreign banks from other states.
The business of banking in California remains highly competitive. Competition in our industry is likely to further intensify as a result of continued consolidation of financial services companies,
including consolidations of significance in our market area. In order to compete with major financial institutions and other competitors in its primary service areas, the Bank relies upon the experience of its executive and senior officers in
serving business clients, and upon its specialized services, local promotional activities and the personal contacts made by its officers, directors and employees.
For customers whose loan demand exceeds the Bank’s legal lending limit, the Bank may arrange for such loans on a participation basis with correspondent banks. In the past, the seasonal swings,
discussed below in “Management’s Discussion and Analysis of Financial Condition and Results of Operation – Liquidity”, have had some impact on the Bank’s liquidity. The management of investment maturities, sale of loan participations, federal fund
borrowings, qualification for funds under the Federal Reserve Bank’s seasonal credit program, and the ability to sell mortgages in the secondary market is intended to allow the Bank to satisfactorily manage its liquidity.
15
Table of Contents