Item 1A. Risk Factors 12
Item 1B. Unresolved Staff Comments 25
Item 1C. Cybersecurity 25
Item 2. Properties 26
Item 3. Legal Proceedings 28
Item 4. Mine Safety Disclosures 28
Supplemental Item: Information about our Executive Officers 28
Item 6. [Reserved] 31
Item 7A. Quantitative and Qualitative Disclosures About Market Risk 44
Item 8. Financial Statements and Supplementary Data F-1
Item 9A. Controls and Procedures 45
Item 9B. Other Information 46
Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 46
PART III 47
Item 10. Directors, Executive Officers and Corporate Governance 47
Item 11. Executive Compensation 48
Item 14. Principal Accountant Fees and Services 48
Item 15. Exhibits and Financial Statement Schedules 49
Signatures 53
i
PART
I
Item
1. Business.
Certain
statements contained in this Annual Report on Form 10-K which are not statements of historical fact constitute forward-looking statements
within the meaning of the Private Securities Litigation Reform Act of 1995. See “Cautionary Statement Regarding Forward-Looking
Information” under Item 1A. Risk Factors on page 12 of this Annual Report on Form 10-K.
General
SB
Financial Group, Inc., an Ohio corporation (the “SB Financial”), is a financial holding company subject to regulation under
the Bank Holding Company Act of 1956, as amended, and to inspection, examination and supervision by the Board of Governors of the Federal
Reserve System (the “Federal Reserve Board” or the “FRB”). SB Financial was organized in 1983. The executive
offices of SB Financial are located at 401 Clinton Street, Defiance, Ohio 43512.
Through
its direct and indirect subsidiaries, SB Financial is engaged in a variety of financial activities, including commercial banking, trust
and wealth management services, and title insurance, as explained in more detail below.
As
used in this Annual Report on Form 10-K, the “Company” refers to SB Financial and its consolidated subsidiaries collectively,
except where the context indicates the reference relates solely to the registrant, SB Financial.
The
State Bank and Trust Company
The
State Bank and Trust Company (“State Bank”) is an Ohio state-chartered bank and wholly owned subsidiary of SB Financial.
State Bank offers a full range of commercial banking services, including checking accounts, savings accounts, money market accounts and
time certificates of deposit; automatic teller machines (“ATMs”); commercial, consumer, agricultural and residential mortgage
loans; personal and corporate trust services; commercial leasing; bank credit card services; safe deposit box rentals; internet banking;
private client group services; and other personalized banking services. The trust and financial services division of State Bank offers
various trust and financial services, including asset management services for individuals and corporate employee benefit plans, as well
as brokerage services through Cetera Investment Services, an unaffiliated company. State Bank presently operates 27 banking centers,
located within the Ohio counties of Allen, Defiance, Franklin, Fulton, Hancock, Henry, Lucas, Ottawa, Paulding, Williams and Wood, with
one banking center located in Allen County, Indiana and one located in Steuben County, Indiana. State Bank also presently operates four
loan production offices, located in Franklin, Lucas and Warren Counties, Ohio, and Hamilton County, Indiana. At December 31, 2025, State
Bank had 246 full-time equivalent employees.
SBFG
Title, LLC
SBFG
Title, LLC dba Peak Title Agency (“SBFG Title”) was formed as an Ohio limited liability company in January 2019 and purchased
all of the assets and real estate of an Ohio-based title agency effective March 15, 2019. SBFG Title is a wholly owned subsidiary of
SB Financial. SBFG Title provides title insurance and operates two locations within the Ohio Counties of Franklin and Williams. At December
31, 2025, SBFG Title had 8 full-time equivalent employees.
SBT
Insurance
SBT
Insurance, LLC (“SBI”) is an Ohio corporation and wholly owned subsidiary of State Bank. SBI is an insurance company that
engages in the sale of insurance products to retail and commercial customers of State Bank. At December 31, 2025, SBI had no employees.
1
SB
Captive
SB
Captive, Inc. (“SB Captive”) is a Nevada corporation and wholly owned subsidiary of SB Financial. SB Captive is a self-insurance
company that provides coverage to State Bank and SB Financial . The purpose of SB Captive is to mitigate insurance risk by participating
in a pool with other banks. At December 31, 2025, SB Captive had no employees.
Rurban
Statutory Trust II
Rurban
Statutory Trust II (“RST II”) is a trust that was organized in August 2005. In September 2005, RST II closed a pooled private
offering of 10,000 Capital Securities with a liquidation amount of $1,000 per security. The proceeds of the offering were loaned to the
Company in exchange for junior subordinated debentures with terms similar to the Capital Securities. The sole assets of RST II are the
junior subordinated debentures and the back-up obligations, which in the aggregate, constitute a full and unconditional guarantee by
the Company of the obligations of RST II under the Capital Securities.
Dissolved
Subsidiaries
In
December 2024, the Company completed the dissolution of four of its inactive subsidiaries: RFCBC, Inc., Rurbanc Data Services Inc., Rurban
Mortgage Company, and SBFG Mortgage, LLC.
Competition
The
Company experiences significant competition in attracting depositors and borrowers. Competition in lending activities comes principally
from other commercial banks in the lending areas of State Bank, and to a lesser extent, from savings associations, insurance companies,
governmental agencies, credit unions, securities brokerage firms, finance companies, financial technology companies (“fintechs”)
and pension funds. The primary factors in competing for loans are interest rates and overall banking services.
State
Bank’s competition for deposits comes from other commercial banks, savings associations, money market funds and credit unions as
well as from insurance companies, securities brokerage firms, and fintechs. The primary factors in competing for deposits are interest
rates paid on deposits and convenience of office location. State Bank operates in the highly competitive wealth management services field
and its competition consists primarily of other bank wealth management departments.
Supervision
and Regulation
The
following is a summary discussion of the significant statutes and regulations applicable to the Company. This discussion is qualified
in its entirety by reference to the full text of the statutes, regulations and policies that are described. Also, such statutes, regulations
and policies are continually under review by the U.S. Congress and state legislatures and federal and state regulatory agencies. A change
in statutes, regulations or regulatory policies applicable to the Company could have a material effect on our business.
Regulation
of Bank Holding Companies and Their Subsidiaries in General
SB
Financial is a financial holding company and, as such, is subject to regulation under the Bank Holding Company Act of 1956, as amended
(the “Bank Holding Company Act”). SB Financial is subject to the reporting requirements of, and examination and regulation
by, the FRB. The FRB has extensive enforcement authority over bank holding companies, including, without limitation, the ability to assess
civil money penalties, issue cease and desist or removal orders, and require that a bank holding company divest subsidiaries, including
its subsidiary banks. In general, the FRB may initiate enforcement actions for violations of laws and regulations and for unsafe or unsound
practices. A bank holding company and its subsidiaries are prohibited from engaging in certain tying arrangements in connection with
extensions of credit and/or the provision of other property or services to a customer by the bank holding company or its subsidiaries.
2
The
Bank Holding Company Act requires the prior approval of the FRB before a financial or bank holding company may acquire direct or indirect
ownership or control of more than 5 percent of the voting shares of any bank (unless the bank is already majority owned by the bank holding
company), acquire all or substantially all of the assets of another bank or another financial or bank holding company, or merge or consolidate
with any other bank holding company. Subject to certain exceptions, the Bank Holding Company Act also prohibits a financial or bank holding
company from acquiring 5 percent or more of the voting shares of any company that is not a bank and from engaging in any business other
than banking or managing or controlling banks. The primary exception to this prohibition allows a bank holding company to own shares
in any company the activities of which the FRB had determined, as of November 19, 1999, to be so closely related to banking as to be
a proper incident thereto.
In
April 2020, the FRB adopted a final rule to revise its regulations related to determinations of whether a company has the ability to
exercise a controlling influence over another company for purposes of the Bank Holding Company Act. The final rule expands and codifies
the presumptions for use in such determinations. By codifying the presumptions, the final rule provides greater transparency on the types
of relationships that the FRB generally views as supporting a facts-and-circumstances determination that one company controls another
company. The FRB’s final rule applies to questions of control under the Bank Holding Company Act but does not extend to the Change
in Bank Control Act.
As
a result of the Gramm-Leach-Bliley Act of 1999, also known as the Financial Services Modernization Act of 1999, which amended the Bank
Holding Company Act, bank holding companies that are financial holding companies may engage in any activity, or acquire and retain the
shares of a company engaged in any activity, that is either (1) financial in nature or incidental to such financial activity (as determined
by the FRB in consultation with the Secretary of the Treasury), or (2) complementary to a financial activity, and that does not pose
a substantial risk to the safety and soundness of depository institutions or the financial system generally. Activities that are financial
in nature include securities underwriting dealing and market-making, insurance underwriting and agency, and merchant banking activities.
On January 2, 2019, SB Financial elected, and received approval from the FRB, to become a financial holding company.
Various
requirements and restrictions under the laws of the United States and the State of Ohio affect the operations of State Bank, including
requirements to maintain reserves against deposits, restrictions on the nature and amount of loans that may be made and the interest
that may be charged thereon, restrictions relating to investments and other activities, limitations on credit exposure to correspondent
banks, limitations on activities based on capital and surplus, limitations on payment of dividends, and limitations on branching.
Various
consumer laws and regulations also affect the operations of State Bank. The Dodd-Frank Wall Street Reform and Consumer Protection Act
of 2010 (the “Dodd-Frank Act”) established the Consumer Financial Protection Bureau (the “CFPB”), which regulates
consumer financial products and services and certain financial services providers. The CFPB is authorized to prevent unfair, deceptive
or abusive acts or practices and ensures consistent enforcement of laws so that consumers have access to fair, transparent and competitive
markets for consumer financial products and services. Since it was established, the CFPB has exercised extensively its rulemaking and
interpretative authority.
The
Federal Home Loan Banks ( “FHLBs”) provide credit to their members in the form of advances. As a member of the FHLB of Cincinnati,
State Bank must maintain certain minimum investments in the capital stock of the FHLB of Cincinnati. State Bank was in compliance with
these requirements at December 31, 2025.
Federal
Reserve System
The
FRB requires all depository institutions to maintain reserves at specified levels against their transaction accounts, primarily checking
accounts. In response to the COVID-19 pandemic, the FRB reduced reserve requirement ratios to 0 percent effective on March 26, 2020,
to support lending to households and businesses. The reserve requirement ratio remained at 0 percent as of December 31, 2025.
3
Economic
Growth, Regulatory Relief and Consumer Protection Act
The
Economic Growth, Regulatory Relief and Consumer Protection Act (the “Regulatory Relief Act”) repealed or modified certain provisions
of the Dodd-Frank Act and eased restrictions on all but the largest banks (those with consolidated assets in excess of $250 billion).
Bank holding companies with consolidated assets of less than $100 billion, including the Company, are no longer subject to enhanced prudential
standards. The Regulatory Relief Act also relieves bank holding companies and banks with consolidated assets of less than $100 billion,
including the Company, from certain record-keeping, reporting and disclosure requirements. Certain other regulatory requirements applied
only to banks with consolidated assets in excess of $50 billion and so did not apply to the Company even before the enactment of the
Regulatory Relief Act.
Restrictions
on Dividends
There
can be no assurance as to the amount of dividends which may be declared in future periods with respect to the common shares of the Company,
since such dividends are subject to the discretion of the Company’s Board of Directors, cash needs, and general business conditions,
dividends from the Company’s subsidiaries and applicable governmental regulations and policies.
The
ability of the Company to obtain funds for the payment of dividends and for other cash requirements is largely dependent on the amount
of dividends that may be declared by State Bank and the Company’s other subsidiaries. State Bank may not pay dividends to the Company
if, after paying such dividends, it would fail to meet the required minimum levels under the risk-based capital guidelines and the minimum
leverage ratio requirements. In addition, State Bank must obtain the approval of the FRB and the Ohio Division of Financial Institutions
(the “ODFI”) if a dividend in any year would cause the total dividends for that year to exceed the sum of the current year’s
net profits and the retained net profits for the preceding two years, less required transfers to surplus. At December 31, 2025, State
Bank had $12.1 million of excess earnings that would be available for dividends without approval of the FRB and the ODFI.
Payment
of dividends by State Bank may be restricted at any time at the discretion of the regulatory authorities, if they deem such dividends
to constitute an unsafe and/or unsound banking practice. Moreover, the FRB expects the Company to serve as a source of strength to its
subsidiary bank, which may require it to retain capital for further investment in the subsidiary, rather than for dividends to shareholders
of the Company.
The
Company’s ability to pay dividends on its shares is also conditioned upon the payment, on a current basis, of quarterly interest
payments on the subordinated debentures underlying the Company’s trust preferred securities. In addition, under the terms of the
Company’s fixed-to-floating rate subordinated debt, the Company’s ability to pay dividends on its shares is conditioned upon
the Company continuing to make required principal and interest payments, and not incurring an event of default, with respect to the subordinated
debt.
Transactions
with Affiliates and Insiders
The
Company and State Bank are separate and distinct legal entities. The FRB’s Regulation W and various other legal limitations restrict
State Bank from lending funds to, or engaging in other “covered transactions” with, the Company (or any other affiliate),
generally limiting such covered transactions with any one affiliate to 10 percent of State Bank’s capital and surplus and limiting
all such covered transactions with all affiliates to 20 percent of State Bank’s capital and surplus. Covered transactions, including
extensions of credit, sales of securities or assets and provision of services, also must be on terms and conditions consistent with safe
and sound banking practices, including credit standards, that are substantially the same or at least as favorable to State Bank as those
prevailing at the time for transactions with unaffiliated companies.
4
A
bank’s authority to extend credit to executive officers, directors and greater than 10 percent shareholders, as well as entities
such persons control, is subject to Sections 22(g) and 22(h) of the Federal Reserve Act and Regulation O promulgated thereunder by the
FRB. Among other things, these loans must be made on terms (including interest rates charged and collateral required) that are substantially
the same as those offered to unaffiliated individuals or be made as part of a benefit or compensation program and on terms widely available
to employees, and must not involve a greater than normal risk of repayment. In addition, the amount of loans a bank may make to these
persons is based, in part, on the bank’s capital position, and certain approval procedures must be followed in making loans which
exceed specified amounts.
Federally
insured banks are subject, with certain exceptions, to certain additional restrictions (including collateralization) on extensions of
credit to their parent holding companies or other affiliates, on investments in the stock or other securities of affiliates and on the
taking of such stock or securities as collateral from any borrower. In addition, such banks are prohibited from engaging in certain tying
arrangements in connection with any extension of credit or the providing of any property or service.
Regulatory
Capital
The
risk-based capital guidelines adopted by the federal banking agencies are based on the “International Convergence of Capital Measurement
and Capital Standard” (Basel I), published by the Basel Committee on Banking Supervision (the “Basel Committee”). In
July 2013, the United States banking regulators issued new capital rules applicable to smaller banking organizations which also implement
certain of the provisions of the Dodd-Frank Act (the “Basel III Capital Rules”).
The
Basel III Capital Rules include (a) a minimum common equity tier 1 capital ratio of 4.5%, (b) a minimum Tier 1 capital ratio of 6.0%,
(c) a minimum total capital ratio of 8.0%, and (d) a minimum leverage ratio of 4.0%.
Common
equity for the common equity tier 1 capital ratio generally includes common stock (plus related surplus), retained earnings, accumulated
other comprehensive income (unless an institution elects to exclude such income from regulatory capital), and limited amounts of minority
interests in the form of common stock, subject to applicable regulatory adjustments and deductions.
Tier
1 capital generally includes common equity as defined for the common equity tier 1 capital ratio, plus certain non-cumulative preferred
stock and related surplus, cumulative preferred stock and related surplus, trust preferred securities that have been grandfathered (but
which are not permitted going forward), and limited amounts of minority interests in the form of additional Tier 1 capital instruments,
less certain deductions.
Tier
2 capital, which can be included in the total capital ratio, generally consists of other preferred stock and subordinated debt meeting
certain conditions plus limited amounts of the allowance for credit losses (“ACL”), subject to specified eligibility criteria,
less applicable deductions.
The
deductions from common equity tier 1 capital include goodwill and other intangibles, certain deferred tax assets, mortgage-servicing
assets above certain levels, gains on sale in connection with a securitization, investments in a banking organization’s own capital
instruments and investments in the capital of unconsolidated financial institutions (above certain levels).
Under
the guidelines, capital is compared to the relative risk related to the balance sheet. To derive the risk included in the balance sheet,
one of several risk weights is applied to different balance sheet and off-balance sheet assets, primarily based on the relative credit
risk of the counterparty. The capital amounts and classification are also subject to qualitative judgments by the regulators about components,
risk weightings and other factors.
The
Basel III Capital Rules also place restrictions on the payment of capital distributions, including dividends, and certain
discretionary bonus payments to executive officers if the banking organization does not hold a capital conservation buffer of
greater than 2.5 percent composed of common equity tier 1 capital above its minimum risk-based capital requirements, or if its
eligible retained income is negative in that quarter and its capital conservation buffer ratio was less than 2.5 percent at the
beginning of the quarter.
5
In
December 2018, the federal banking agencies issued a final rule to address regulatory capital treatment of credit loss allowances under
the current expected credit loss (“CECL”) model (accounting standard). The rule revised the federal banking agencies’
regulatory capital rules to identify which credit loss allowances under the CECL model are eligible for inclusion in regulatory capital
and to provide banking organizations the option to phase in over three years the day-one adverse effects on regulatory capital that may
result from the adoption of the CECL model. Upon the Company’s adoption of CECL effective January 1, 2023, the Company recognized
a one-time cumulative effect adjustment (increase) to the ACL of $1.4 million and did not elect to utilize the three-year phase in. The
Company’s risk-based capital ratios remained in excess of “well-capitalized” levels after the impact of the one-time
cumulative effect adjustment.
At
December 31, 2025, State Bank was in compliance with all of the regulatory capital requirements to which it was subject. For State Bank’s
capital ratios, see Note 16 to the Consolidated Financial Statements under Item 8 of this Report on Form 10-K (the “Consolidated
Financial Statements”).
The
FRB has adopted regulations governing prompt corrective action to resolve the problems of capital deficient and otherwise troubled state-chartered
member banks. At each successively lower defined capital category, a bank is subject to more restrictive and numerous mandatory or discretionary
regulatory actions or limits, and the FRB has less flexibility in determining how to resolve the problems of the institution. In addition,
the FRB generally can downgrade a bank’s capital category, notwithstanding its capital level, if, after notice and opportunity
for hearings, the bank is deemed to be engaged in an unsafe or unsound practice, because it has not corrected deficiencies that resulted
in it receiving a less than satisfactory examination rating on matters other than capital or it is deemed to be in an unsafe or unsound
condition. State Bank’s capital at December 31, 2025, met the standards for the highest capital category, a “well-capitalized”
bank.
In
April 2015, the FRB issued a final rule which increased the size limitation for qualifying bank holding companies under the FRB’s
Small Bank Holding Company Policy Statement from $500 million to $1 billion of total consolidated assets. In August 2018, the FRB issued
an interim final rule, as required by the Regulatory Relief Act, to further increase size limitations under the Small Bank Holding Company
Policy Statement to $3 billion of total consolidated assets. The Company continues to qualify under the Small Bank Holding Company Policy
Statement for exemption from the FRB’s consolidated risk-based capital and leverage rules at the holding company level.
Federal
Deposit Insurance Corporation
The
Federal Deposit Insurance Corporation (the “FDIC”) is an independent federal agency, which insures the deposits of federally
insured banks and savings associations up to certain prescribed limits and safeguards the safety and soundness of financial institutions.
The general insurance limit is $250,000 per separately insured depositor. This insurance is backed by the full faith and credit of the
United States government.
As
insurer, the FDIC is authorized to conduct examinations of and to require reporting by insured institutions, including State Bank, to
prohibit any insured institution from engaging in any activity the FDIC determines to pose a threat to the Deposit Insurance Fund (the
“DIF”), and to take enforcement actions against insured institutions. The FDIC may terminate insurance of deposits of any
institution if the FDIC finds that the institution has engaged in unsafe and unsound practices, is in an unsafe or unsound condition
or has violated any applicable law, regulation, rule, order or condition imposed by the FDIC or other regulatory agency.
The
FDIC assesses a quarterly deposit insurance premium on each insured institution based on risk characteristics of the insured
institution to the DIF, with institutions deemed less risky paying lower rates. Currently, assessments for institutions with less
than $10 billion of total assets are based on financial measures and supervisory ratings derived from statistical models that
estimate the probability of failure within three years. The FDIC may increase or decrease the range of assessments uniformly, except
that no adjustments can deviate more than two basis points from the base assessment without notice and comment rule making. The FDIC
may also impose special assessments in emergency situations, which fund the DIF. The FDIC has established 2 percent as the
Designated Reserve Ratio (“DRR”), which is the amount in the DIF as a percentage of all DIF insured deposits. In March
2016, the FDIC adopted final rules designed to meet the statutory minimum DRR of 1.35 percent.
6
Because
the DRR fell below the minimum DRR, the FDIC adopted a restoration plan requiring the restoration of the DRR to 1.35% within eight years
(September 30, 2028). The FDIC rules further changed the method of determining risk-based assessment rates for established banks with
less than $10 billion in assets to better ensure that banks taking on greater risks pay more for deposit insurance than banks that take
on less risk. The FDIC then adopted a final rule in October 2022 increasing the assessment rate from three basis points to five basis
points beginning with the first quarterly assessment period of 2023. As of December 31, 2025, the DRR was above the statutory minimum
of 1.35%.
The
FDIC is authorized to prohibit any insured institution from engaging in any activity that poses a serious threat to the insurance fund
and may initiate enforcement actions against a bank, after first giving the institution’s primary regulatory authority an opportunity
to take such action. The FDIC may also terminate the deposit insurance of any institution that has engaged in or is engaging in unsafe
or unsound practices, is in an unsafe or unsound condition to continue operations or has violated any applicable law, order or condition
imposed by the FDIC.
Community
Reinvestment Act
The
Community Reinvestment Act (the “CRA”) requires State Bank’s primary federal regulatory agency, the FRB, to assess
State Bank’s record in meeting the credit needs of the communities served by State Bank. The FRB assigns one of four ratings: outstanding,
satisfactory; needs to improve or substantial noncompliance. The rating assigned to a financial institution is considered in connection
with various applications submitted by the financial institution or its holding company to its banking regulators, including applications
to acquire another financial institution or to open or close a branch office. In addition, all subsidiary banks of a financial holding
company must maintain a satisfactory or outstanding rating in order for the financial holding company to avoid limitations on its activities.
State Bank received a satisfactory rating in its most recent CRA examination.
SEC
and NASDAQ Regulation
The
Company is subject to the jurisdiction of the Securities and Exchange Commission (the “SEC”) and certain state securities
authorities relating to the offering and sale of its securities. The Company is subject to the registration, reporting and other regulatory
requirements of the Securities Act of 1933, as amended (the “Securities Act”), and the Securities Exchange Act of 1934, as
amended (the “Exchange Act”), and the rules adopted by the SEC under those acts. The Company’s common shares are listed
on The NASDAQ Capital Market (“NASDAQ”) under the symbol “SBFG”. As a result, the Company is subject to NASDAQ
rules and regulations applicable to listed companies.
The
SEC has adopted rules and regulations governing, among other matters, corporate governance, auditing and accounting, executive compensation,
and enhanced and timely disclosure of corporate information. The SEC has also approved corporate governance rules promulgated by NASDAQ.
The Company has adopted and implemented a Code of Conduct and Ethics and a copy of that policy can be found on the Company’s website
at www.YourSBFinancial.com by first clicking “Corporate Overview” and then “Governance Documents”. The Company
has also adopted charters of the Audit Committee, the Compensation Committee and the Governance and Nominating Committee, which charters
are available on the Company’s website at www.YourSBFinancial.com by first clicking “Corporate Overview” and then “Governance
Documents”.
7
USA
Patriot Act and Anti-Money Laundering Act
The
Uniting and Strengthening of America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001 (the “Patriot
Act”) gives the United States government powers to address terrorist threats through enhanced domestic security measures, expanded
surveillance powers, increased information sharing and broadened anti-money laundering requirements. Title III of the Patriot Act encourages
information sharing among bank regulatory agencies and law enforcement bodies. Further, certain provisions of Title III impose affirmative
obligations on a broad range of financial institutions. Among other requirements, Title III and related regulations require regulated
financial institutions to establish a program specifying procedures for obtaining identifying information from customers seeking to open
new accounts and establish enhanced due diligence policies, procedures and controls designed to detect and report suspicious activity.
State Bank has established policies and procedures that State Bank believes comply with the requirements of the Patriot Act.
The
Anti-Money Laundering Act of 2020 (the “AMLA”), which amends the Bank Secrecy Act of 1970 (the “BSA”), was enacted
in January 2021. The AMLA is intended to be a comprehensive reform and modernization to U.S. bank secrecy and anti-money laundering laws.
Among other things, it codifies a risk-based approach to anti-money laundering compliance for financial institutions; requires the development
of standards for evaluating technology and internal processes for BSA compliance; expands enforcement-related and investigation-related
authority, including increasing available sanctions for certain BSA violations and instituting BSA whistleblower initiatives and protections.
Office
of Foreign Assets Control Regulation
The
U.S. Treasury Department’s Office of Foreign Assets Control (“OFAC”) administers and enforces economic and trade sanctions
against targeted foreign countries and regimes, under authority of various laws, including designated foreign countries, nationals and
others. OFAC publishes lists of specially designated targets and countries. State Bank is responsible for, among other things, blocking
accounts of, and transactions with, such targets and countries, prohibiting unlicensed trade and financial transactions with them and
reporting blocked transactions after their occurrence. Failure to comply with these sanctions could have serious financial, legal and
reputational consequences, including causing applicable bank regulatory authorities not to approve merger or acquisition transactions
when regulatory approval is required or to prohibit such transactions even if approval is not required. Regulatory authorities have imposed
cease and desist orders and civil money penalties against institutions found to be violating these obligations.
Executive
and Incentive Compensation
The
Dodd-Frank Act requires that the federal banking agencies, including the FRB and the FDIC, issue a rule related to incentive-based compensation.
No final rule implementing this provision of the Dodd-Frank Act has, as of the date of the filing of this Annual Report on Form 10-K,
been adopted. Although a final rule has not been issued, the Company has undertaken efforts to ensure that the Company’s incentive
compensation plans do not encourage inappropriate risks.
In
June 2010, the FRB, the Office of the Comptroller of the Currency (the “OCC”) and the FDIC issued comprehensive final guidance
on incentive compensation policies intended to ensure that the incentive compensation policies of banking organizations do not undermine
the safety and soundness of such organizations by encouraging excessive risk-taking. The guidance, which covers all employees that have
the ability to materially affect the risk profile of an organization, either individually or as part of a group, is based upon the key
principles that a banking organization’s incentive compensation arrangements should (i) provide incentives that do not encourage risk-taking
beyond the organization’s ability to effectively identify and manage risks, (ii) be compatible with effective internal controls and risk
management and (iii) be supported by strong corporate governance, including active and effective oversight by the organization’s board
of directors. These three principles are incorporated into the proposed joint compensation regulations under the Dodd-Frank Act, described
above.
The
FRB and the OCC review, as part of their respective regular, risk-focused examination process, the incentive compensation
arrangements of banking organizations, such as the Company and State Bank, that are not “large, complex banking
organizations.” These reviews are tailored to each organization based on the scope and complexity of the organization’s
activities and the prevalence of incentive compensation arrangements. Deficiencies will be incorporated into the organization’s
supervisory ratings, which can affect the organization’s ability to make acquisitions and take other actions. Enforcement actions
may be taken against a banking organization if its incentive compensation arrangements, or related risk-management control or
governance processes, pose a risk to the organization’s safety and soundness and the organization is not taking prompt and effective
measures to correct the deficiencies.
8
Public
company compensation committee members must meet heightened independence requirements and consider the independence of compensation consultants,
legal counsel and other advisors to the compensation committee. A compensation committee must have the authority to hire advisors and
to have the public company fund reasonable compensation of such advisors.
SEC
regulations require public companies to provide various disclosures about executive compensation in annual reports and proxy statements
and to present to their shareholders a non-binding vote on the approval of executive compensation.
Following
the adoption of additional listing requirements in 2023 to comply with the Dodd-Frank Act and rules adopted by the SEC in October 2022,
public companies are now required to adopt and implement “clawback” policies for incentive compensation payments and to disclose
the details of the procedures which allow recovery of incentive compensation that was paid on the basis of erroneous financial information
necessitating a restatement due to material noncompliance with financial reporting requirements. This clawback policy is intended to
apply to compensation paid within the three completed fiscal years immediately preceding the date the issuer is required to prepare a
restatement and would cover all executives who received incentive awards. The Company’s clawback policy adopted in accordance with
these listing standards is included as Exhibit 97 to this Annual Report on Form 10-K.
Consumer
Protection Laws and Regulations
Banks
are subject to regular examinations to ensure compliance with federal consumer protection statutes and regulations, including, but not
limited to, the following:
The
banking regulators also use their authority under the Federal Trade Commission Act to take supervisory or enforcement action with respect
to unfair or deceptive acts or practices by banks that may not necessarily fall within the scope of a specific banking or consumer finance
law.
Financial
Privacy Provisions
Federal
and state regulations limit the ability of banks and other financial institutions to disclose non-public information about consumers
to non-affiliated third parties. These limitations require disclosure of privacy policies to consumers and, in some circumstances, allow
consumers to prevent disclosure of certain personal information to a non-affiliated third party. These regulations affect how consumer
information is transmitted through diversified financial companies and conveyed to outside vendors.
9
State
Bank is also subject to regulatory guidelines establishing standards for safeguarding customer information. These guidelines describe
the federal bank regulatory agencies’ expectations for the creation, implementation and maintenance of an information security program,
which would include administrative, technical and physical safeguards appropriate to the size and complexity of the institution and the
nature and scope of its activities. The standards set forth in the guidelines are intended to ensure the security and confidentiality
of customer records and information, protect against any anticipated threats or hazards to the security or integrity of such records
and protect against unauthorized access to or use of such records or information that could result in substantial harm or inconvenience
to any customer.
Cybersecurity
In
March 2015, federal regulators issued two related statements regarding cybersecurity. One statement indicates that financial institutions
should design multiple layers of security controls to establish several lines of defense and to ensure that their risk management processes
also address the risk posed by compromised customer credentials, including security measures to reliably authenticate customers accessing
Internet-based services of the financial institution. The other statement indicates that a financial institution’s management is
expected to maintain sufficient business continuity planning processes to ensure the rapid recovery, resumption and maintenance of the
financial institution’s operations after a cyber-attack involving destructive malware. A financial institution is also expected
to develop appropriate processes to enable recovery of data and business operations and address rebuilding network capabilities and restoring
data if the financial institution or its critical service providers fall victim to this type of cyber-attack. If State Bank fails to
observe the regulatory guidance, it could be subject to various regulatory sanctions, including financial penalties.
In
November 2021, the OCC, the FRB and the FDIC issued a final rule, which became effective in May 2022, requiring banking organizations
that experience a computer-security incident to notify certain entities. A computer-security incident occurs when actual or potential
harm to the confidentiality, integrity, or availability of an information system or the information occurs, or there is a violation or
imminent threat of a violation to banking security policies and procedures. The affected bank must notify its respective federal regulator
of the computer-security incident as soon as possible and no later than 36 hours after the bank determines a computer-security incident
that rises to the level of a notification incident has occurred. These notifications are intended to promote early awareness of threats
to banking organizations and will help banks react to those threats before they manifest into larger incidents. This rule also requires
bank service providers to notify their bank organization customers of a computer-security incident that has caused, or is reasonably
likely to cause, a material service disruption or degradation for four or more hours.
Furthermore,
the Cyber Incident Reporting for Critical Infrastructure Act, enacted in March 2022, will require, once administrative rules are adopted,
certain covered entities, including those in the financial services industry, to report a covered cyber incident to the U.S. Department
of Homeland Security’s Cybersecurity & Infrastructure Security Agency (“CISA”) within 72 hours after a covered
entity reasonably believes an incident has occurred. Separate reporting to CISA will also be required within 24 hours if a ransom payment
is made as a result of a ransomware attack.
State
regulators have also been increasingly active in implementing privacy and cybersecurity standards and regulations. Recently, several
states have adopted regulations requiring certain financial institutions to implement cybersecurity programs and providing detailed requirements
with respect to these programs, including data encryption requirements. Many states have also recently implemented or modified their
data breach notification and data privacy requirements. The Company expects this trend of state-level activity in those areas to continue
and is continually monitoring developments in the states in which our customers are located.
On
July 26, 2023, the SEC adopted final rules that require public companies to promptly disclose material cybersecurity incidents in
Current Reports on Form 8-K and detailed information regarding their cybersecurity risk management, strategy, and governance on an
annual basis in their Annual Reports on Form 10-K. See ITEM 1C. CYBERSECURITY. Public companies are now required to report on Form
8-K any cybersecurity incident they determine to be material within four business days of making that determination. These SEC
rules, and related regulatory guidance, are in addition to notification and disclosure requirements under state and federal banking
laws and regulations.
10
In
the ordinary course of business, the Company relies on electronic communications and information systems to conduct its operations and
to store sensitive data. The Company employs an in-depth, layered, defensive approach that leverages people, processes and technology
to manage and maintain cybersecurity controls. The Company employs a variety of preventative and detective tools to monitor, block, and
provide alerts regarding suspicious activity, as well as to report on any suspected advanced persistent threats. The Company also regularly
invests in new products and technology to further enhance these tools and mechanisms. Notwithstanding the strength of the Company’s
defensive measures, the threat from cyber-attacks is severe, attacks are sophisticated and increasing in volume, and attackers respond
rapidly to changes in defensive measures. While to date, the Company has not detected a significant compromise, significant data loss
or any material financial losses related to cybersecurity attacks, the Company’s systems and those of its customers and third-party
service providers are under constant threat and it is possible that the Company could experience a significant event in the future. Risks
and exposures related to cybersecurity attacks are expected to remain high for the foreseeable future due to the rapidly evolving nature
and sophistication of these threats, as well as due to the expanding use of Internet banking, mobile banking and other technology-based
products and services by us and our customers.
Effect
of Environmental Regulation
Compliance
with federal, state and local provisions regulating the discharge of materials into the environment, or otherwise relating to the protection
of the environment, has not had a material effect upon the capital expenditures, earnings or competitive position of the Company. The
Company believes that the nature of its operations has little, if any, environmental impact. The Company, therefore, anticipates no material
capital expenditures for environmental control facilities for its current fiscal year or for the near future. The Company may be required
to make capital expenditures for environmental control facilities related to properties which they may acquire through foreclosure proceedings
in the future; however, the amount of such capital expenditures, if any, is not currently determinable.
Effects
of Government Monetary Policy
The
earnings of the Company are affected by general and local economic conditions and by the policies of various governmental regulatory
authorities. In particular, the FRB regulates money and credit conditions and interest rates to influence general economic conditions,
primarily through open market acquisitions or dispositions of United States Government securities, varying the discount rate on member
bank borrowings and setting reserve requirements against member and nonmember bank deposits. FRB monetary policies have had a significant
effect on the interest income and interest expense of commercial banks, including State Bank, and are expected to continue to do so in
the future.
Human
Capital Resources
Our
employees are vital to our success in the financial services industry. As a human-capital intensive business, the long-term success of
our company depends on our people. Our goal is to ensure that we have the right talent, in the right place, at the right time. We do
that through our commitment to attracting, developing and retaining our employees.
We
strive to attract individuals who are people-focused and share our values. We have a comprehensive program dedicated to selecting new
talent and enhancing the skills of our employees. In our recruiting efforts, we strive to have a diverse group of candidates to consider
for our roles.
We
have designed a compensation structure that we believe is attractive to our current and prospective employees. We also offer our employees
the opportunity to participate in a variety of professional and leadership development programs. Our programs include a variety of industry,
product, technical, professional, business development, leadership and regulatory topics. These programs are available online and in-person.
In addition, we encourage all employees to be involved in the communities we serve through various volunteer activities.
11
We
seek to retain our employees by using their feedback to create and continually enhance programs that support their needs. We use company-wide
surveys to solicit feedback from our employees. We have a formal annual goal setting and performance review process for our employees.
We promote a values-based culture, an important factor in retaining our employees. Our training, to share and communicate our culture
to all employees, plays an important part in this process. We are committed to having a diverse workforce, and an inclusive work environment
is a natural extension of our culture. We are committed to ensuring that all our employees feel welcomed, valued, respected and heard
so that they can fully contribute their unique talents for the benefit of our customers, their careers, our company and our communities.
We
monitor and evaluate various turnover and attrition metrics throughout our organization. Our annualized voluntary turnover is relatively
low, as is the case for turnover of our top performers, a record which we attribute to our strong values-based culture, commitment to
career development, and attractive compensation and benefit programs.
At
December 31, 2025, the Company employed approximately 254 full-time equivalent employees to whom a variety of benefits are provided.
Management considers its relationship with its employees to be good.
Item 1A. Risk Factors.
Cautionary
Statement Regarding Forward-Looking Information
Certain
statements contained in this Annual Report on Form 10-K, and in other statements that we make from time to time in filings by the Company
with the SEC, in press releases, and in oral and written statements made by or with the approval of the Company which are not statements
of historical fact constitute forward-looking statements within the meaning of Section 27A of the Securities Act, Section 21E of the
Exchange Act, and the Private Securities Litigation Reform Act of 1995. Examples of forward-looking statements include: (a) projections
of income or expense, earnings per share, the payment or non-payment of dividends, capital structure and other financial items; (b) statements
of plans and objectives of the Company or our Board of Directors or management, including those relating to products and services; (c)
statements of future economic performance; (d) statements of future customer attraction or retention; and (e) statements of assumptions
underlying these statements. Forward-looking statements reflect our expectations, estimates or projections concerning future results
or events. These statements are generally identified by the use of forward-looking words or phrases such as “anticipates”,
“believes”, “estimates”, “expects”, “intends”, “may”, “plans”,
“projects”, “should”, “will allow”, “will continue”, “will likely result”,
“will remain”, “would be”, or similar expressions.
The
Private Securities Litigation Reform Act of 1995 (the “Reform Act”) provides a “safe harbor” for forward-looking
statements to encourage companies to provide prospective information so long as those statements are identified as forward-looking and
are accompanied by meaningful cautionary statements identifying important factors that could cause actual results to differ materially
from those discussed in the forward-looking statements. We desire to take advantage of the “safe harbor” provisions of the
Reform Act.
Forward-looking
statements involve risks and uncertainties. Actual results may differ materially from those predicted by the forward-looking statements
because of various factors and possible events, including those factors discussed in the Risk Factors below. There is also the risk that
the Company’s management or Board of Directors incorrectly analyzes these risks and forces, or that the strategies the Company
develops to address them are unsuccessful.
Forward-looking
statements speak only as of that date on which they are made. Except as may be required by law, the Company undertakes no obligation
to update any forward-looking statement to reflect events or circumstances after the date on which the statement is made. All forward-looking
statements attributable to the Company or any person acting on our behalf are qualified in their entirety by the following cautionary
statements.
12
Risk
Factors
The
following sets forth certain risk factors that we believe are relevant to the Company and its business. These risk factors are not presented
in any particular order and do not constitute all of the risks that may affect our business. Additional risks that are not presently
known or that we currently deem to be immaterial could also have a material adverse impact on our business, financial condition, or results
of operations.
Economic,
Market and Political Risks:
Changes
in economic and political conditions could adversely affect our earnings through declines in deposits, loan demand, the ability of our
customers to repay loans and the value of collateral securing our loans.
Our
success depends to a large extent upon local and national economic conditions, as well as governmental fiscal and monetary policies.
Conditions such as inflation, recession, unemployment, changes in interest rates, fiscal and monetary policy, an increasing federal government
budget deficit, the failure of the federal government to raise the federal debt ceiling and/or possible future U.S. government shutdowns
over budget disagreements, slowing gross domestic product, potential or imposed tariffs, a U.S. withdrawal from or significant renegotiation
of trade agreements and other changes in the relationship of the U.S. and U.S. global partners, trade wars, and other factors beyond