FULLTEXT DEL 4 AV 9

10-K – 2026-03-02 – d17859d10k.htm

Föregående del · Dokumentindex · Nästa del

14
(“FDIA”), established  
a plan  
in September  
2020 to  
restore the  
DIF reserve  
ratio to  
meet or  
exceed the  
statutory minimum  
of 1.35
percent within  
eight years. The  
increased assessment is  
intended to improve  
the likelihood that  
the DIF  
reserve ratio would  
reach
the required minimum by the statutory deadline  
of September 30, 2028.
As of December 31, 2025, BPPR and  
PB had a DIF average total asset  
less average tangible equity assessment base of
$69 billion.
On  
November 16,  
2023,  
the  
FDIC finalized  
a  
rule  
that  
imposes  
a special  
assessment to  
recover the  
costs to  
the  
DIF
resulting  
from  
the  
FDIC’s  
use,  
in  
March  
2023,  
of  
the systemic  
risk  
exception to  
the  
least-cost resolution  
test  
under the  
FDIA  
in
connection with the  
receiverships of Silicon  
Valley Bank  
and Signature Bank.  
The FDIC estimated  
in approving the  
rule that those
assessed losses total $16.3 billion. The rule provides  
that this loss estimate will be periodically adjusted,  
which will affect the amount
of  
the special  
assessment. Under  
the rule,  
the assessment  
base is  
the  
estimated uninsured  
deposits that  
an insured  
depository
institution reported in its Consolidated Reports of Condition and Income (“Call Report”) at December 31, 2022,  
excluding the first $5
billion  
in estimated  
uninsured deposits.  
For  
a holding  
company  
that  
has  
more than  
one  
insured depository  
institution subsidiary,
such as Popular,  
the $5 billion  
exclusion is allocated  
among the company’s  
insured depository institution subsidiaries  
in proportion
to each  
insured depository  
institution’s estimated  
uninsured deposits.  
The special  
assessments were  
to be  
collected at  
an annual
rate of approximately 13.4 basis points per  
year (3.36 basis points per quarter) over  
eight quarters,  
with the first assessment period
having begun  
January 1,  
2024. In  
June 2024,  
due to  
the increase  
in the  
estimate of  
losses, the  
FDIC announced that  
it projected
that the special  
assessment would be collected  
for an additional  
two quarters beyond the  
initial eight quarter collection  
period, at a
lower rate.  
In December  
2025, the  
FDIC reduced  
the rate  
at which  
the assessment  
is collected,  
with an  
invoice payment  
date of
March 30, 2026, from 3.36 basis points to  
2.97 basis points,  
and also reduced the collection period back  
to eight quarters.
Brokered Deposits
The FDIA  
and regulations  
adopted thereunder  
restrict the  
use of  
brokered deposits  
and the  
rate of  
interest payable  
on
deposits for institutions  
that are less  
than well capitalized.  
Popular does not  
believe the brokered  
deposits regulations have  
had or
will have a material effect on the funding or liquidity  
of BPPR and PB.
Capital Adequacy
Popular, PNA,  
BPPR and PB are  
each required to comply  
with applicable capital adequacy standards  
established by the
federal  
banking  
agencies  
(the  
“Capital  
Rules”),  
which  
implement  
the  
Basel  
III  
framework  
set  
forth  
by  
the  
Basel  
Committee  
on
Banking Supervision (the “Basel Committee”) as  
well as certain provisions of the Dodd-Frank  
Act.
Among other  
matters, the  
Capital Rules:  
(i) impose  
a capital  
measure called  
“Common Equity  
Tier  
1” (“CET1”)  
and the
related regulatory capital ratio of CET1 to risk-weighted assets; (ii) specify that Tier 1 capital consists of CET1 and “Additional Tier 1
capital” instruments meeting  
certain revised requirements;  
and (iii) mandate  
that most deductions/adjustments to  
regulatory capital
measures be made  
to CET1  
and not to  
the other components  
of capital.  
Under the Capital  
Rules, for most  
banking organizations,
including  
Popular,  
the  
most  
common  
form  
of  
Additional  
Tier  
1  
capital  
is  
non-cumulative  
perpetual preferred  
stock  
and  
the  
most
common form of Tier  
2 capital is subordinated notes and  
a portion of the  
allocation for loan and lease losses,  
in each case, subject
to the Capital Rules’ specific requirements.
Pursuant to the Capital Rules, the minimum  
capital ratios are:
4.5% CET1 to risk-weighted assets;
6.0% Tier 1 capital (that is, CET1 plus Additional Tier 1 capital) to risk-weighted  
assets;
8.0% Total capital (that is, Tier 1 capital plus Tier 2 capital) to risk-weighted assets; and
4% Tier 1 capital to average consolidated assets as reported  
on consolidated financial statements (known  
as the
“leverage ratio”).
The Capital Rules also impose  
a “capital conservation buffer,”  
composed entirely of CET1, on top  
of these minimum risk-
weighted  
asset  
ratios. The  
capital  
conservation  
buffer  
is  
designed  
to  
absorb  
losses  
during  
periods  
of  
economic stress.  
Banking
institutions  
with  
a  
ratio  
of  
CET1  
to  
risk-weighted  
assets  
above  
the  
minimum  
but  
below  
the  
capital  
conservation  
buffer  
will  
face
constraints on  
dividends, equity repurchases  
and compensation based  
on the  
amount of  
the shortfall and  
eligible retained  
income
(that is, four  
quarter trailing net income, net  
of distributions and tax effects  
not reflected in net  
income). Popular, BPPR  
and PB are
therefore required to maintain such additional capital  
conservation buffer of 2.5% of CET1,  
effectively resulting in minimum ratios of
(i) CET1  
to risk-weighted  
assets of  
at least  
7%, (ii)  
Tier  
1 capital  
to risk-weighted  
assets of  
at least  
8.5%, and  
(iii) Total  
capital to

15
risk-weighted assets of at least 10.5%.
Pursuant  
to  
the  
Capital  
Rules,  
the  
effects  
of  
certain  
accumulated other  
comprehensive income  
or  
loss  
(“AOCI”)  
items
included in stockholders’ equity  
(for example, marks-to-market of securities  
held in the available  
for sale portfolio) are  
not excluded
from  
regulatory  
capital  
ratios;  
however,  
banking  
organizations  
that  
are  
not  
subject  
to  
Categories  
I  
or  
II  
standards  
under  
the
framework for  
banking organizations  
with $100  
billion or  
more in  
assets, including  
Popular,  
BPPR and  
PB, may  
make a  
one-time
permanent election to continue to  
exclude these items. Popular,  
BPPR and PB have  
made this election in order  
to avoid significant
variations in  
the level  
of capital  
depending upon  
the impact  
of interest  
rate fluctuations  
on the  
fair value  
of their  
available for  
sale
securities portfolios.  
On July  
27, 2023,  
the federal  
banking regulators  
proposed revisions  
to the  
Capital Rules  
to implement  
the
Basel Committee’s 2017 standards, described  
below, and make  
other changes to the  
Capital Rules, including the ability  
of banking
organizations in Categories III and IV to elect not to recognize most elements of AOCI in regulatory capital. The proposal introduces
revised credit risk, equity risk, operational risk, credit valuation adjustment risk and market risk requirements, among other changes.
However, the  
revised capital requirements  
of the  
proposed rule would  
not apply  
to Popular,  
BPPR, or  
PB because  
they have  
less
than $100 billion in total consolidated assets and trading  
assets and liabilities below the threshold for market risk requirements. The
federal  
banking  
regulators have  
subsequently indicated  
that  
they  
expect to  
issue  
a  
revised  
proposal, the  
timing  
and contents  
of
which are uncertain.
The  
Capital  
Rules  
preclude certain  
hybrid  
securities, such  
as  
trust  
preferred  
securities, from  
inclusion  
in  
bank  
holding
companies’  
Tier  
1  
capital.  
Trust  
preferred  
securities  
not  
included  
in  
Popular’s  
Tier  
1  
capital  
may  
nonetheless  
be  
included  
as  
a
component of  
Tier 2 capital.  
Popular has  
not issued  
any trust  
preferred securities since  
May 19,  
2010. As  
of December  
31, 2025,
Popular has  
$193 million  
of trust  
preferred securities  
outstanding which  
no longer  
qualify for  
Tier  
1 capital  
treatment, but  
instead
qualify for Tier 2 capital treatment.
The Capital Rules also provide for a number of deductions  
from and adjustments to CET1.  
Banking organizations that are
not subject to Category  
I or II standards  
are subject to rules that  
provide for simplified capital requirements relating  
to the threshold
deductions  
for  
certain  
mortgage  
servicing  
assets,  
deferred  
tax  
assets,  
investments  
in  
the  
capital  
of  
unconsolidated  
financial
institutions and inclusion of minority interests  
in regulatory capital.
Failure  
to  
meet  
capital  
guidelines  
could  
subject  
Popular  
and  
its  
depository  
institution  
subsidiaries  
to  
a  
variety  
of
enforcement remedies, including the termination of deposit insurance by the FDIC  
and to certain restrictions on our business. Refer
to “Prompt Corrective Action” below for further  
discussion.
In  
December 2017,  
the Basel  
Committee published  
standards that  
it  
described as  
the finalization  
of the  
Basel III  
post-
crisis regulatory  
reforms. Among other  
things, these  
standards revise  
the Basel  
Committee’s standardized approach  
for credit  
risk
(including  
by  
recalibrating  
risk  
weights  
and  
introducing  
new  
capital  
requirements  
for  
certain  
“unconditionally  
cancellable
commitments,” such  
as  
unused credit  
card  
lines of  
credit) and  
provide  
a new  
standardized approach  
for operational  
risk capital.
Under the current U.S. capital rules, operational risk capital requirements and a capital floor apply only to Category I and Category II
banking organizations and not to Popular, BPPR and PB.
In 2020, federal bank regulators adopted a rule  
that allowed banking organizations to elect to delay  
temporarily the
estimated effects of adopting the Current Expected Credit  
Loss (“CECL”) model of ASU 2016-13 on regulatory  
capital until January
2022 and subsequently to phase in the effects through  
January 2025. The Corporation’s capital ratios  
at December 31, 2025 reflect
the full phased in impact from the adoption of CECL.
Refer to  
the Consolidated  
Financial Statements  
in this  
Form 10-K.,  
Note 20  
and Table  
10 of  
Management’s Discussion
and Analysis for the  
capital ratios of Popular,  
BPPR and PB  
under Basel III. Refer  
to the Consolidated Financial Statements  
in this
Form 10-K Note 2 for more information regarding  
CECL.  

Prompt Corrective Action
The  
FDIA  
requires,  
among  
other  
things,  
the  
federal  
banking  
agencies  
to  
take  
prompt  
corrective  
action  
in  
respect  
of
insured  
depository  
institutions  
that  
do  
not  
meet  
minimum  
capital  
requirements.  
The  
FDIA  
establishes  
five  
capital  
tiers:  
“well
capitalized,”  
“adequately  
capitalized,”  
“undercapitalized,”  
“significantly  
undercapitalized,”  
and  
“critically  
undercapitalized”.  
A
depository institution’s capital tier will depend upon how its  
capital levels compare with various relevant capital  
measures and certain
other factors.

16
An insured  
depository institution will  
be deemed  
to be  
(i) “well  
capitalized” if  
the institution  
has a  
total risk-based  
capital
ratio of 10.0% or greater, a CET1 capital ratio of 6.5%  
or greater, a Tier 1  
risk-based capital ratio of 8.0% or greater, and a leverage
ratio of 5.0% or  
greater, and is  
not subject to any order  
or written directive by  
any such regulatory authority to  
meet and maintain a
specific capital level for any capital  
measure; (ii) “adequately capitalized” if the institution  
has a total risk-based capital ratio  
of 8.0%
or greater, a  
CET1 capital ratio of 4.5%  
or greater, a  
Tier 1 risk-based capital  
ratio of 6.0% or greater,  
and a leverage ratio of  
4.0%
or greater  
and is  
not “well  
capitalized”; (iii)  
“undercapitalized” if  
the institution  
has a  
total risk-based  
capital ratio  
that is  
less than
8.0%, a CET1 capital  
ratio less than 4.5%,  
a Tier 1  
risk-based capital ratio of  
less than 6.0% or  
a leverage ratio of  
less than 4.0%;
(iv) “significantly  
undercapitalized” if  
the institution  
has a  
total risk-based  
capital ratio  
of less  
than 6.0%,  
a CET1  
capital ratio  
less
than 3%, a Tier  
1 risk-based capital ratio of less than 4.0% or  
a leverage ratio of less than 3.0%;  
and (v) “critically undercapitalized”
if  
the  
institution’s  
tangible  
equity  
is  
equal  
to  
or  
less  
than  
2.0%  
of  
average  
quarterly  
tangible  
assets.  
An  
institution  
may  
be
downgraded to, or deemed  
to be in, a  
capital category that is  
lower than indicated by  
its capital ratios if  
it is determined to  
be in an
unsafe  
or  
unsound  
condition  
or  
if  
it  
receives  
an  
unsatisfactory  
examination  
rating  
with  
respect  
to  
certain  
matters.  
An  
insured
depository institution’s capital category is determined solely for the purpose of applying prompt corrective action  
regulations, and the
capital category  
may not  
constitute an  
accurate representation  
of the  
institution’s overall  
financial condition  
or prospects  
for other
purposes.
The FDIA generally prohibits an insured depository institution from making any capital  
distribution (including payment of a
dividend) or  
paying any  
management fee to  
its holding  
company, if  
the depository  
institution would thereafter  
be undercapitalized.
Undercapitalized  
depository  
institutions  
are  
subject  
to  
restrictions  
on  
borrowing  
from  
the  
Federal  
Reserve  
System.  
In  
addition,
undercapitalized  
depository  
institutions  
are  
subject  
to  
growth  
limitations  
and  
are  
required  
to  
submit  
capital  
restoration  
plans.  
A
depository institution’s  
holding company must  
guarantee the capital  
restoration plan, up  
to an  
amount equal to  
the lesser  
of 5%  
of
the  
depository  
institution’s  
assets  
at  
the  
time  
it  
becomes  
undercapitalized  
or  
the  
amount  
of  
the  
capital  
deficiency,  
when  
the
institution fails to comply with the  
plan. The federal banking agencies may not  
accept a capital restoration plan without determining,
among other things,  
that the plan  
is based  
on realistic assumptions  
and is  
likely to succeed  
in restoring the  
depository institution’s
capital. If a depository institution fails to submit an  
acceptable plan, it is treated as if it is  
significantly undercapitalized.
Significantly  
undercapitalized  
depository  
institutions  
may  
be  
subject  
to  
a  
number  
of  
requirements  
and  
restrictions,
including orders to  
sell sufficient voting  
stock to become  
adequately capitalized, requirements to  
reduce total assets  
and cessation
of receipt  
of deposits  
from correspondent  
banks. Critically  
undercapitalized depository  
institutions are  
subject to  
appointment of  
a
receiver or conservator.
The capital-based prompt  
corrective action provisions  
of the FDIA  
apply to  
the FDIC-insured depository  
institutions such
as  
BPPR  
and  
PB,  
but  
they  
are  
not  
directly  
applicable  
to  
holding  
companies  
such  
as  
Popular  
and  
PNA,  
which  
control  
such
institutions. As of December 31, 2025,  
both BPPR and PB met the quantitative requirements  
for ‘well capitalized’ status.
Restrictions on Dividends and Repurchases
The  
principal  
sources  
of  
funding  
for  
Popular  
and  
PNA  
have  
included  
dividends  
received  
from  
their  
banking  
and  
non-
banking subsidiaries, asset sales  
and proceeds from  
the issuance of  
debt and equity.  
Various statutory  
provisions limit the amount
of  
dividends an  
insured depository  
institution may  
pay to  
its  
holding company  
without regulatory  
approval. A  
member bank  
must
obtain the approval of the  
Federal Reserve Board for any  
dividend, if the total of  
all dividends declared by the  
member bank during
the calendar year would exceed the total of its net income for that year,  
combined with its retained net income for the preceding two
years, after  
considering those  
years’ dividend  
activity,  
less any  
required transfers to  
surplus or  
to a  
fund for  
the retirement  
of any
preferred stock. During the year  
ended December 31, 2025, BPPR declared  
cash dividends of $575  
million, a portion of  
which was
used by Popular for the payments of the cash dividends on its  
outstanding common stock. At December 31, 2025, BPPR needed to
obtain prior approval of the Federal Reserve Board before declaring a dividend  
in excess of $191 million due to its  
retained income,
declared dividend activity and transfers to statutory reserves over the three years ended December 31, 2025. In addition, a member
bank may  
not declare  
or pay  
a dividend  
in an  
amount greater  
than its  
undivided profits  
as reported  
in its  
Report of  
Condition and
Income, unless the member bank has received the approval of  
the Federal Reserve Board. A member bank also may not permit  
any
portion of its permanent capital to  
be withdrawn unless the withdrawal has  
been approved by the Federal Reserve Board.  
Pursuant
to  
these  
requirements, PB  
may  
not  
declare  
or  
pay  
a  
dividend without  
the  
prior  
approval  
of  
the  
Federal  
Reserve  
Board  
and  
the
NYSDFS.
During the  
year ended  
December 31,  
2025, Popular  
received cash  
dividends of  
$23 million  
from Popular  
International
Bank, Inc. (“PIBI”) and $22 million from its other  
non-banking subsidiaries.
It is Federal Reserve Board policy that bank holding companies generally should pay dividends on common  
stock only out

17
of net  
income available to  
common shareholders  
over the past  
year and  
only if  
the prospective rate  
of earnings retention  
appears
consistent with the organization’s current and  
expected future capital needs, asset quality  
and overall financial condition. Moreover,
under Federal Reserve Board policy, a bank  
holding company should not maintain dividend levels that place undue pressure on the
capital of depository  
institution subsidiaries or that  
may undermine the bank  
holding company’s ability to  
be a source  
of strength to
its  
banking subsidiaries.  
Federal Reserve  
policy  
also  
provides that  
a  
bank  
holding company  
should  
inform  
the  
Federal  
Reserve
reasonably in advance of declaring or paying a dividend that  
exceeds earnings for the period for which the dividend is  
being paid or
that could result in a material adverse change  
to the bank holding company’s capital structure.  

The  
Federal Reserve  
Board  
also restricts  
the  
ability of  
banking  
organizations to  
conduct stock  
repurchases. In  
certain
circumstances, a banking organization’s repurchases  
of its common stock may  
be subject to a  
prior approval or notice requirement
under other regulations or policies of the Federal Reserve. Any redemption or  
repurchase of preferred stock or subordinated debt is
subject to the prior approval of the Federal Reserve.
Subject to compliance with certain conditions, distributions of U.S. sourced dividends to a corporation  
organized under the
laws  
of the  
Commonwealth of  
Puerto Rico  
are subject  
to  
a withholding  
tax  
of 10%  
instead of  
the 30%  
applied to  
other “foreign”
corporations. Accordingly, dividends from current or accumulated earnings and profits  
paid by PNA to Popular, Inc. sourced from the
U.S. operations of PB are subject to a 10% tax withholding.
A corporation organized under the laws of the Commonwealth of Puerto
Rico that is engaged in a U.S. trade or business is generally subject to a branch profits tax of 30% on its earnings and profits  
for the
taxable year that are “effectively connected” with  
such U.S. trade or business, adjusted as  
provided by U.S. federal income tax law.
Accordingly,  
to  
the extent  
BPPR’s  
U.S. operations  
generate effectively  
connected earnings  
and profits  
that  
are not  
reinvested in
such U.S. operations  
(and that are  
not otherwise adjusted  
as provided by  
U.S. federal income tax  
law), such effectively  
connected
earnings and profits will generally be subject  
to a branch profits tax of 30%.  

Refer to  
Part II,  
Item 5,  
“Market for  
Registrant’s Common  
Equity,  
Related Stockholder  
Matters and  
Issuer Purchases  
of
Equity Securities” for further information on Popular’s  
distribution of dividends and repurchases of equity  
securities.
See  
“Puerto  
Rico  
Regulation”  
below  
for  
a  
description  
of  
certain  
restrictions  
on  
BPPR’s  
ability  
to  
pay  
dividends  
under
Puerto Rico law.
Interstate Branching
The Dodd-Frank  
Act amended  
the Riegle-Neal  
Interstate Banking  
and Branching  
Efficiency Act  
of 1994  
(the “Interstate
Banking  
Act”)  
to  
authorize  
national  
banks  
and  
state  
banks  
to  
branch  
interstate  
through
de  
novo
 
branches. For  
purposes  
of  
the
Interstate Banking Act, BPPR is treated as a state bank and is subject to the same restrictions on interstate branching as other state
banks.
Activities and Acquisitions
In general, the BHC Act limits the activities  
permissible for bank holding companies to the business of banking, managing
or controlling banks and such other activities as the Federal Reserve Board has determined to be so closely related to banking as to
be  
properly  
incidental  
thereto.  
A  
company  
that  
meets  
management  
and  
capital  
standards  
and  
whose  
subsidiary  
depository
institutions meet management,  
capital and  
Community Reinvestment Act  
(“CRA”) standards may  
elect to  
be treated  
as a  
financial
holding company  
and engage  
in a  
substantially broader  
range of  
nonbanking financial  
activities, including  
securities underwriting
and dealing, insurance underwriting and making  
merchant banking investments in nonfinancial  
companies.
In order for a bank holding company to elect to be treated as a financial  
holding company, (i) all of its depository institution
subsidiaries  
must  
be  
well capitalized  
(as described  
above)  
and  
well managed  
and  
(ii)  
it  
must  
file a  
declaration with  
the Federal
Reserve Board that it elects to be a “financial holding  
company.” As noted above, a bank  
holding company electing to be a financial
holding company must itself be and remain  
well capitalized and well managed. The Federal Reserve Board’s  
regulations applicable
to bank holding companies separately define  
“well capitalized” for bank holding companies,  
such as Popular,  
to require maintaining
a tier 1 capital  
ratio of at least  
6% and a total capital  
ratio of at least 10%.  
Popular and PNA have elected  
to be treated as  
financial
holding  
companies.  
A  
depository  
institution  
is  
deemed  
to  
be  
“well  
managed”  
if,  
at  
its  
most  
recent  
inspection,  
examination  
or
subsequent review  
by the  
appropriate federal banking  
agency (or  
the appropriate state  
banking agency), the  
depository institution
received  
at  
least  
a  
“satisfactory”  
composite  
rating  
and  
at  
least  
a  
“satisfactory”  
rating  
for  
the  
management  
component  
of  
the
composite  
rating.  
If,  
after  
becoming  
a  
financial  
holding  
company,  
the  
company  
fails  
to  
continue  
to  
meet  
any  
of  
the  
capital  
or
management requirements  
for financial  
holding company  
status, the  
company  
must  
enter into  
a confidential  
agreement with  
the
Federal  
Reserve  
Board  
to  
comply  
with  
all  
applicable capital  
and  
management  
requirements.  
If  
the  
company  
does  
not  
return  
to

18
compliance  
within  
180  
days,  
the  
Federal  
Reserve  
Board  
may  
extend  
the  
agreement  
or  
may  
order  
the  
company  
to  
divest  
its
subsidiary banks or the  
company may discontinue, or  
divest investments in companies  
engaged in, activities permissible only  
for a
bank holding company that has elected to be treated as a financial  
holding company. In addition, if a depository institution subsidiary
controlled by a financial holding company does not  
maintain a CRA rating of at least “satisfactory,” the financial holding company  
will
be subject to restrictions on certain new activities  
and acquisitions.
The Federal Reserve Board  
may in certain circumstances limit  
our ability to conduct  
activities and make acquisitions that
would otherwise be permissible for  
a financial holding company.  
Furthermore, a financial holding company must obtain  
prior written
approval from the Federal Reserve Board before acquiring a nonbank company with $10 billion or more in total consolidated assets.
In addition, we  
are required to  
obtain prior Federal  
Reserve Board approval  
before engaging in  
certain banking and  
other financial
activities both in the United States and abroad.
The “Volcker  
Rule” adopted  
as part  
of the  
Dodd-Frank Act  
restricts the  
ability of  
Popular and  
its subsidiaries,  
including
BPPR and PB as  
well as non-banking subsidiaries, to  
sponsor or invest in  
“covered funds,” including private funds,  
or to engage in
certain types  
of proprietary  
trading. Popular  
and its  
subsidiaries generally  
do not  
engage in  
the businesses  
subject to  
the Volcker
Rule; therefore, the Volcker Rule does not have a material effect on our  
operations.  

Anti-Money Laundering Initiative and the USA PATRIOT Act
A major focus of governmental policy relating to financial institutions in  
recent years has been aimed at combating money
laundering and  
terrorist financing.  
The USA  
PATRIOT  
Act of  
2001 (the  
“USA PATRIOT  
Act”) strengthened  
the ability  
of the  
U.S.
government to help prevent, detect and prosecute international money  
laundering and the financing of terrorism. Title  
III of the USA
PATRIOT  
Act imposed  
significant compliance  
and due  
diligence obligations,  
created new  
crimes and  
penalties and  
expanded the
extra-territorial jurisdiction of the United States. Failure of a financial institution to comply with the USA PATRIOT Act’s requirements
could have serious legal and reputational consequences  
for the institution.
The  
Anti-Money  
Laundering  
Act  
of  
2020  
(“AMLA”),  
which  
amended  
the  
Bank  
Secrecy  
Act  
(the  
“BSA”),  
is  
intended  
to
comprehensively  
reform  
and  
modernize  
U.S.  
anti-money  
laundering  
laws.  
Among  
other  
things,  
the  
AMLA  
codifies  
a  
risk-based
approach to anti-money laundering compliance for financial institutions; requires the U.S. Department of the Treasury to  
promulgate
priorities  
for  
anti-money  
laundering  
and  
countering  
the  
financing  
of  
terrorism  
policy;  
requires  
the  
development  
of  
standards  
for
testing technology and  
internal processes for BSA  
compliance; expands enforcement-  
and investigation-related authority,  
including
a  
significant  
expansion  
in  
the  
available  
sanctions  
for  
certain  
BSA  
violations;  
and  
expands  
BSA  
whistleblower  
incentives  
and
protections.  
Many  
of  
the  
statutory  
provisions  
in  
the  
AMLA  
require  
additional  
rulemakings,  
reports  
and  
other  
measures,  
and  
the
impact  
of  
the  
AMLA  
will  
depend on,  
among  
other  
things,  
rulemaking and  
implementation guidance.  
In  
June  
2021,  
the  
Financial
Crimes Enforcement Network, a bureau of  
the U.S. Department of the  
Treasury,  
issued the priorities for anti-money laundering  
and
countering the  
financing of  
terrorism policy  
required under AMLA.  
The priorities  
include: corruption, cybercrime,  
terrorist financing,
fraud, transnational crime, drug trafficking, human trafficking and  
proliferation financing.
Federal regulators  
regularly examine BSA/Anti-Money  
Laundering and sanctions  
compliance to  
enhance their  
adequacy
and effectiveness, and the frequency and extent of such examinations  
and related remedial actions have been  
increasing.
Community Reinvestment Act
The  
CRA  
requires  
banks  
to  
help  
serve  
the  
credit  
needs  
of  
their  
communities,  
including  
extending  
credit  
to  
low-  
and
moderate-income individuals  
and geographies.  
Should  
Popular  
or our  
bank  
subsidiaries  
fail  
to  
serve  
adequately  
the community,
potential penalties may include regulatory denials of applications to expand branches, relocate offices or branches, add subsidiaries
and affiliates, expand into new financial activities and merge  
with or purchase other financial institutions.  

Interchange Fees Regulation
The Federal Reserve Board  
has established standards for  
debit card interchange fees  
and prohibited network exclusivity
arrangements and routing restrictions. The  
maximum permissible interchange fee that  
an issuer may receive  
for an electronic debit
transaction is  
the sum  
of  
21 cents  
per transaction  
and 5  
basis points  
multiplied by  
the value  
of  
the transaction.  
Additionally,  
the
Federal Reserve  
Board allows  
for an  
upward adjustment  
of  
no more  
than 1  
cent  
to  
an issuer’s  
debit card  
interchange fee  
if the
issuer develops and implements policies and procedures  
reasonably designed to achieve certain fraud-prevention  
standards.
In  
October  
2023,  
the  
Federal  
Reserve  
Board  
proposed  
amendments  
to  
its  
rules  
on  
interchange  
fees.  
If  
adopted,  
the

19
proposed changes  
would establish  
a maximum  
permissible interchange  
fee of  
no more  
than 14.4  
cents per  
transaction plus  
four
basis  
points  
multiplied  
by  
the  
value  
of  
the  
transaction.  
The  
fraud  
prevention  
adjustment  
would  
be  
increased  
to  
1.3  
cents  
per
transaction. The proposed changes would also establish an automatic update of  
the interchange fee cap every other year based on
a survey of debit card issuers.
Consumer Financial Protection Act of 2010
The Consumer  
Financial Protection  
Bureau (the  
“CFPB”) supervises  
“covered persons”  
(broadly defined  
to include  
any
person offering or  
providing a consumer financial  
product or service and  
any affiliated service  
provider) for compliance with  
federal
consumer financial laws. The CFPB  
also has the broad power  
to prescribe rules applicable to  
a covered person or service  
provider
identifying  
as  
unlawful,  
unfair,  
deceptive,  
or  
abusive  
acts  
or  
practices  
in  
connection  
with  
any  
transaction  
with  
a  
consumer  
for  
a
consumer financial product or service, or the offering of  
a consumer financial product or service. We are subject to examination and
regulation by the CFPB. During 2025, the CFPB reduced its staff by over 80%. The  
reduction in force is the subject of litigation, and
the  
staffing  
cuts  
are  
currently  
stayed  
pending  
the  
federal  
circuit  
court’s  
en  
banc  
rehearing  
of  
the  
case.  
The  
impact  
of  
these
developments  
on  
banking  
organizations  
subject  
to  
CFPB  
regulation  
and  
supervision,  
including  
us,  
is  
uncertain.  
The  
Consumer
Financial Protection Act permits states to adopt consumer protection laws and standards that are more stringent than those adopted
at  
the federal  
level and,  
in certain  
circumstances, permits  
state attorneys  
general to  
enforce compliance  
with both  
the state  
and
federal laws and regulations. States and state attorneys general  
may increase regulatory, investigative and enforcement activity with
respect to consumer protection, in  
response to changes in regulation, supervision  
and enforcement of consumer protection laws  
by
federal regulators.
On October 22, 2024, the CFPB finalized a new rule to implement Section 1033 of the Consumer Financial Protection Act
that  
requires  
a  
provider  
of  
payment  
accounts  
or  
products,  
such  
as  
a  
bank,  
to  
make  
data  
available  
to  
consumers  
upon  
request
regarding the  
products or  
services they  
obtain from  
the provider.  
Any such  
data provider  
also has  
to make  
such data  
available to
third parties, with the consumer’s express authorization and  
through an interface that satisfies formatting, performance  
and security
standards,  
for  
the  
purpose  
of  
such  
third  
parties  
providing  
the  
consumer  
with  
financial  
products  
or  
services  
requested  
by  
the
consumer. Data required to be made available under the rule includes  
transaction information, account balance, account and routing
numbers,  
terms  
and  
conditions,  
upcoming  
bill  
information,  
and  
certain  
account  
verification  
data.  
The  
rule  
is  
intended  
to  
give
consumers  
control  
over  
their  
financial  
data,  
including  
with  
whom  
it  
is  
shared,  
and  
encourage  
competition  
in  
the  
provision  
of
consumer financial  
products or  
services. For  
banks with  
at least  
$10 billion  
and less  
than $250  
billion in  
total assets,  
compliance
with the rule’s requirements is required beginning on  
April 1, 2027. The rule is the subject of litigation,  
which is currently stayed while
the CFPB considers revisions to the rule.
Office of Foreign Assets Control Regulation
The  
U.S.  
Treasury  
Department  
Office  
of  
Foreign  
Assets  
Control  
(“OFAC”)  
administers  
economic  
sanctions  
that  
affect
transactions  
with  
designated  
foreign  
countries,  
nationals  
and  
others.  
The  
OFAC-administered  
sanctions  
targeting  
countries  
take
many  
different  
forms.  
Generally,  
however,  
they  
contain  
one  
or  
more  
of  
the  
following  
elements:  
(i)  
restrictions  
on  
trade  
with  
or
investment in a sanctioned country; and (ii) a blocking  
of assets in which the government of the  
sanctioned country or other specially
designated nationals have an interest, by prohibiting  
transfers of property subject to U.S. jurisdiction (including  
property in the United
States or the possession or control of U.S.  
persons outside of the United States). Blocked assets (e.g., property  
and bank deposits)
cannot  
be  
paid  
out,  
withdrawn, set  
off  
or  
transferred  
in  
any  
manner without  
a  
license  
from  
OFAC.  
Failure  
to  
comply  
with these
sanctions  
could  
have  
serious  
legal  
and  
reputational  
consequences,  
including  
denial  
by  
federal  
regulators  
of  
proposed  
merger,
acquisition, restructuring, or other expansionary activity.
Protection of Customer Personal Information and  
Cybersecurity
The privacy  
provisions of  
the Gramm-Leach-Bliley Act  
of 1999  
generally prohibit financial  
institutions, including  
us, from
disclosing nonpublic personal financial information of consumer customers to third  
parties for certain purposes (primarily marketing)
unless  
customers  
have  
the  
opportunity  
to  
opt  
out  
of  
the  
disclosure.  
The  
Fair  
Credit  
Reporting  
Act  
restricts  
information  
sharing
among affiliates for marketing purposes and governs  
the use and provision of information to consumer  
reporting agencies.
The federal banking regulators have also issued guidance and rules regarding cybersecurity that are intended to enhance
cyber risk management standards among financial institutions. A financial institution is expected to establish lines  
of defense and to
maintain risk management processes that are designed to address the risk posed by compromised customer credentials. A financial
institution’s  
management  
is  
expected  
to  
maintain  
sufficient  
business  
continuity  
planning  
processes  
for  
the  
rapid  
recovery,
resumption and maintenance of  
the institution’s operations  
after a cyber-attack involving  
destructive malware. A financial  
institution

20
is  
also  
expected  
to  
develop  
appropriate  
processes  
to  
enable  
recovery  
of  
data  
and  
business  
operations  
and  
address  
rebuilding
network capabilities and restoring data if the institution or its critical service  
providers fall victim to this type of cyber-attack. If we  
fail
to observe the  
regulatory guidance, we could  
be subject to various  
regulatory sanctions, including financial  
penalties. In November
2021, the U.S.  
federal bank regulatory agencies  
issued a final  
rule requiring banking organizations,  
including Popular,  
PNA, BPPR
and PB, to notify  
their primary federal banking regulator  
within 36 hours of determining  
that a “notification incident” has  
occurred. A
notification incident  
is a  
“computer-security incident” that  
has materially  
disrupted or degraded,  
or is  
reasonably likely to  
materially
disrupt or  
degrade, the  
banking organization’s  
ability to  
deliver services  
to a  
material portion  
of its  
customer base,  
jeopardize the
viability  
of  
key  
operations  
of  
the  
banking  
organization,  
or  
impact  
the  
stability  
of  
the  
financial  
sector.  
The  
final  
rule  
also  
requires
specific and immediate notifications by bank  
service providers that become aware of similar  
incidents.
State and foreign regulators  
have also been increasingly active  
in implementing privacy and cybersecurity  
standards and
regulations. Several states have adopted regulations requiring certain financial institutions to implement cybersecurity programs and
providing detailed requirements with respect to these  
programs, including data encryption requirements. In New York,  
the NYSDFS
requires  
financial  
institutions  
regulated  
by  
the  
NYSDFS,  
including  
PB,  
to,  
among  
other  
things,  
(i)  
establish  
and  
maintain  
a
cybersecurity program designed  
to enhance the  
confidentiality, integrity  
and availability of  
their information systems;  
(ii) implement
and maintain a written  
cyber security policy setting forth  
policies and procedures for the  
protection of their information systems  
and
nonpublic  
information;  
and  
(iii)  
designate  
a  
Chief  
Information  
Security  
Officer.
On  
November  
1,  
2023,  
the  
NYSDFS  
adopted
amendments to  
its  
cybersecurity regulations  
that  
represent  
a  
significant  
update  
to  
the  
regulation of  
cybersecurity practices.  
The
amendments  
generally  
fall  
within  
the  
following  
five  
categories:  
(i)  
increased  
mandatory  
controls  
associated  
with  
common  
attack
vectors,  
(ii)  
enhanced  
requirements  
for  
privileged  
accounts,  
(iii)  
enhanced  
notification  
obligations,  
(iv)  
expansion  
of  
cyber
governance practices and (v) additional cybersecurity  
requirements for larger companies.  

On  
July  
6,  
2023,  
the  
SEC  
adopted  
new  
rules  
that  
would  
require  
registrants,  
such  
as  
Popular,  
to  
(i)  
report  
material
cybersecurity incidents  
on Form  
8-K and,  
(ii) disclose  
in Annual  
Report on  
Form 10-K  
cybersecurity policies  
and procedures  
and
governance practices, including at the board and  
management levels.
Many states and foreign  
governments have also recently implemented or  
modified their data breach notification  
and data
privacy  
requirements. The  
California Consumer  
Privacy Act  
(“CCPA”)  
imposes privacy  
compliance obligations  
with regard  
to  
the
collection,  
use  
and  
disclosure of  
personal  
information of  
California residents,  
and the  
November 2020  
amendment to  
the  
CCPA
creates the California Privacy Protection Agency, a watchdog privacy agency, and further expands the scope of businesses covered
by the law  
and certain rights relating  
to personal information. The  
substantive obligations under the  
2020 amendment to the  
CCPA
became effective on January 1, 2023. In the European Union, the General Data Protection Regulation heightens privacy compliance
obligations and  
imposes strict  
standards for  
reporting data  
breaches. We  
continue to  
monitor these  
developments to  
comply with
applicable requirements.
See  
“Puerto  
Rico  
Regulation”  
below  
for  
a  
description  
of  
legislations  
and  
regulations  
on  
information  
privacy  
and
cybersecurity in Puerto Rico.
Climate-Related and ESG Developments
In recent years, certain lawmakers and regulators in and outside the United States have increased their focus on financial
institutions’  
and  
other  
companies’  
risk  
oversight,  
disclosures  
and  
practices  
in  
connection  
with  
climate  
change  
and  
other
environmental,  
social  
and  
governance (“ESG”)  
matters.  
For  
example,  
in  
2023,  
the  
NYSDFS  
issued  
guidance  
on  
climate-related
financial  
risk  
management  
applicable  
to  
NYSDFS-regulated  
banking  
and  
mortgage  
organizations,  
including  
PB.  
The  
guidance
addresses material  
financial  
risks related  
to  
climate change  
faced by  
these  
organizations in  
the context  
of  
risk assessment,  
risk
management,  
and  
risk  
appetite  
setting.  
In  
2023,  
California  
enacted  
climate-related  
disclosure  
laws  
requiring  
certain  
companies
doing business in  
California to make  
certain climate-related disclosures  
beginning in 2026,  
including but not  
limited to greenhouse
gas  
emissions data  
and climate-related  
risks. On  
the other  
hand, certain  
states  
have enacted,  
or have  
proposed to  
enact, “anti-
ESG”  
statutes,  
regulations  
or  
policies, including  
statutes  
that  
prohibit  
financial  
institutions from  
denying or  
canceling products  
or
services to  
a person,  
or otherwise discriminating  
against a  
person in making  
available products or  
services, on  
the basis  
of social
credit scores and certain other factors. Additionally, in August 2025, President Trump signed Executive Order 14331, “Guaranteeing
Fair Banking  
Access for  
All Americans,”  
which states  
that it  
is the  
policy of  
the United  
States that  
no American  
should be  
denied
access  
to  
financial  
services  
because  
of  
their  
constitutionally  
or  
statutorily  
protected  
beliefs,  
affiliations,  
or  
political  
views.  
The
Executive  
Order  
directs  
the  
Treasury  
Secretary  
and  
federal  
banking  
regulators  
to  
address  
politicized  
or  
unlawful  
debanking
activities.  

21
Incentive Compensation
The Federal Reserve Board reviews, as  
part of its regular,  
risk-focused examination process, the incentive compensation
arrangements of  
banking organizations, such  
as Popular,  
that are  
not “large,  
complex banking  
organizations.” Deficiencies will  
be
incorporated into  
the  
organization’s supervisory  
ratings, which  
can  
affect  
the  
organization’s ability  
to  
make  
acquisitions and  
take
other  
actions. Enforcement  
actions may  
be taken  
against  
a  
banking  
organization if  
its  
incentive compensation  
arrangements, or
related  
risk-management  
control  
or  
governance  
processes,  
pose  
a  
risk  
to  
the  
organization’s  
safety  
and  
soundness  
and  
the
organization is not taking prompt and effective measures  
to correct the deficiencies.
The  
Federal  
Reserve  
Board,  
OCC  
and  
FDIC  
have  
issued  
comprehensive  
final  
guidance  
on  
incentive  
compensation
policies intended to discourage excessive risk-taking in  
the incentive compensation policies of banking organizations  
in order to not
undermine  
the  
safety  
and  
soundness  
of  
such  
organizations.  
The  
guidance,  
which  
covers  
all  
employees  
that  
have  
the  
ability  
to
materially affect  
the risk  
profile of an  
organization, either individually  
or as  
part of  
a group,  
is based  
upon the key  
principles that  
a
banking organization’s incentive compensation arrangements should (i) provide incentives that do not encourage risk-taking beyond
the  
organization’s  
ability  
to  
effectively  
identify  
and  
manage  
risks,  
(ii)  
be  
compatible  
with  
effective  
internal  
controls  
and  
risk
management, and (iii)  
be supported by  
strong corporate governance,  
including active and  
effective oversight  
by the  
organization’s
board of directors.
The Dodd-Frank Act requires the U.S. financial regulators, including the Federal Reserve Board, the other federal banking
agencies  
and  
the  
SEC,  
to  
adopt  
rules  
prohibiting  
incentive-based  
payment  
arrangements that  
encourage  
inappropriate  
risks  
by
providing excessive  
compensation or  
that could  
lead to  
a material  
financial loss  
at specified  
regulated entities  
having at  
least $1
billion in total  
assets (including Popular,  
PNA, BPPR and  
PB). The U.S.  
financial regulators proposed revised  
rules in 2016,  
which
have not been finalized.
In October  
2022, the SEC  
adopted a final  
rule requiring securities  
exchanges to adopt  
rules mandating, in  
the case of  
a
restatement, the  
recovery or  
“clawback” of  
excess incentive-based  
compensation paid  
to current  
or former  
executive officers  
and
requiring listed  
issuers to  
disclose any  
recovery analysis where  
recovery is  
triggered by  
a restatement.  
The excess  
compensation
would be based  
on the amount  
the executive officer  
would have received  
had the incentive-based  
compensation been determined
using the restated  
financials. The Nasdaq  
Stock Market’s listing  
standards pursuant to the  
SEC’s rule became  
effective October 2,
2023. Popular’s clawback policy adopted in accordance  
with these listing standards is included as  
Exhibit 97.1.
Regulation of Broker-Dealers
Our subsidiary,  
PS, is a  
registered broker-dealer with the  
SEC and subject to  
regulation and examination by  
the SEC as
well  
as  
FINRA  
and  
other  
self-regulatory  
organizations.  
These  
regulations  
cover  
a  
broad  
range  
of  
issues,  
including  
capital
requirements;  
sales  
and  
trading  
practices;  
use  
of  
client  
funds  
and  
securities;  
the  
conduct  
of  
directors,  
officers  
and  
employees;
record-keeping and recording;  
supervisory procedures to  
prevent improper trading  
on material  
non-public information; qualification
and  
licensing  
of  
sales  
personnel;  
and  
limitations  
on  
the  
extension  
of  
credit  
in  
securities  
transactions.  
In  
addition  
to  
federal
registration, state securities  
commissions require the  
registration of certain  
broker-dealers. PS is  
registered with 35  
U.S. state and
territory securities commissions.
Regulation of Reinsurers, Insurance Producers and  
Agents
Popular’s subsidiaries that are engaged in  
insurance agency and producer activities are  
subject to regulatory supervision
by the Puerto  
Rico Office of  
the Commissioner of Insurance  
and to insurance laws  
and regulations requiring licensing  
of insurance
producers and  
agents. Popular’s  
reinsurance subsidiaries  
are subject  
to  
licensure and  
regulatory supervision  
by the  
Puerto Rico
Office of the Commissioner of Insurance and  
to insurance laws and regulations requiring, among  
other things, minimum capital and
solvency standards, financial reporting, restrictions on  
the amount of dividends payable, record  
keeping and examinations.
Puerto Rico Regulation
As  
a  
commercial  
bank  
organized  
under  
the  
laws  
of  
Puerto  
Rico,  
BPPR  
is  
subject  
to  
supervision,  
examination  
and
regulation by the Office of the Commissioner of Financial Institutions, pursuant to the Puerto Rico Banking Act of 1933, as amended
(the “Banking Law”).
Section 27 of the Banking Law requires that at least ten percent (10%) of BPPR’s annual retained earnings be transferred

22
annually to a statutory reserve fund. The  
apportionment must be done every year until the  
reserve fund is equal to the  
total of paid-
in capital on common and preferred stock. Under Regulation 9680 of the Puerto Rico Banking Law, dated July 22, 2025, Banks may
be exempted from  
the requirement to transfer  
such funds to  
the statutory reserve  
fund if they  
are well capitalized,  
have obtained a
rating of  
1 or  
2 in  
the last  
examination performed by  
the Office  
of the  
Commissioner or an  
applicable regulatory agency  
and have
accumulated at least 50% of the paid in  
capital for their common and preferred stock in  
their reserve fund.  

Section  
27  
of  
the  
Banking  
Law  
also  
provides that  
when  
the  
expenditures  
of  
a  
bank  
are  
greater  
than  
its  
receipts, the
excess of the  
former over the latter  
must be charged against  
the undistributed profits of  
the bank, and the  
balance, if any,  
must be
charged against the statutory reserve fund. If  
the statutory reserve fund is not sufficient to cover such balance  
in whole or in part, the
outstanding amount must be charged against the capital account and  
no dividend may be declared until capital has been restored to
its original amount and the statutory reserve fund to  
20% of the original capital.
Section 16 of the  
Banking Law requires every  
bank to maintain a  
legal reserve that, except  
as otherwise provided by  
the
Office of  
the Commissioner,  
may not be  
less than 20%  
of its  
demand liabilities, excluding  
government deposits (federal,  
state and
municipal) that  
are secured  
by collateral.  
If a  
bank is  
authorized to  
establish one  
or more  
bank branches  
in a  
state of  
the United
States or in a foreign country, where such branches are subject to the reserve requirements of that state  
or country, the Office of the
Commissioner  
may  
exempt  
said  
branch  
or  
branches  
from  
the  
reserve  
requirements  
of  
Section  
16.  
Pursuant  
to  
an  
order  
of  
the
Federal  
Reserve  
Board  
dated  
November  
24,  
1982,  
BPPR  
has  
been  
exempted  
from  
the  
reserve  
requirements  
of  
the  
Federal
Reserve  
System  
with  
respect  
to  
deposits  
payable  
in  
Puerto  
Rico.  
Accordingly,  
BPPR  
is  
subject  
to  
the  
reserve  
requirement
prescribed by Section 16 of the Banking Law. During 2025, BPPR was  
in compliance with the legal reserve requirement.
Section 17 of the Banking Law permits a bank to make loans to  
any one person, firm, partnership or corporation, up to an
aggregate  
amount  
of  
fifteen  
percent  
(15%)  
of  
the  
paid-in  
capital  
and  
reserve  
fund  
of  
the  
bank.  
In  
the  
case  
of  
loans  
which  
are
secured by collateral worth at  
least 25% more than the  
amount of the loan, the  
maximum aggregate amount of such secured  
loans
is increased to one  
third of the paid-in capital  
of the bank and  
its reserve fund. In no  
event may the total of  
unsecured and secured
loans to any one person, firm, partnership or corporation exceed an aggregate amount of  
33 1/3% of the paid-in capital and reserve
fund of the bank. If the institution is well capitalized and had been rated 1 or  
2 in the last examination performed by the Office of the
Commissioner or an applicable  
regulatory agency,  
its legal lending  
limit shall also  
include 15% of 100%  
of its undivided  
profits and
for loans  
secured by  
collateral worth  
at least  
25% more  
than the  
amount of  
the loan,  
the capital  
of the  
bank shall  
also include  
33
1/3% of 100% of  
its undivided profits. Institutions rated  
3 in their last  
regulatory examination may include this  
additional component
in their  
legal lending  
limit only  
with the  
previous authorization  
of the  
Office  
of the  
Commissioner.  
There are  
no restrictions  
under
Section  
17  
on  
the  
amount  
of  
loans  
that  
are  
wholly  
secured  
by  
bonds,  
securities  
and  
other  
evidence  
of  
indebtedness  
of  
the
Government of  
the United  
States or  
Puerto Rico,  
or by  
current debt  
bonds, not  
in default,  
of municipalities  
or instrumentalities  
of
Puerto Rico. As  
of December 31, 2025,  
the legal lending  
limit for BPPR  
under this provision  
was $723 million.  
During 2025, BPPR
was in compliance with the lending limit requirements  
of Section 17 of the Banking Law.
Section  
14  
of  
the  
Banking  
Law  
authorizes  
a  
bank  
to  
conduct  
certain  
financial  
and  
related  
activities,  
including  
finance
leasing  
of  
personal  
property  
and  
originating  
and  
servicing  
mortgage  
loans,  
directly  
or  
through  
subsidiaries.  
BPPR  
engages  
in
finance  
leasing  
and  
conducts  
the  
origination  
and  
servicing  
of  
mortgage  
loans  
through  
its  
Popular  
Auto  
and  
Popular  
Mortgage
divisions, respectively.
With  
respect to  
information privacy,  
Puerto  
Rico  
law  
requires businesses  
to  
implement information  
security  
controls to
protect consumers’  
personal information from  
breaches, as  
well as to  
provide notice of  
any breach to  
affected customers. In  
2024
Puerto  
Rico  
enacted the  
Cybersecurity Act  
of  
the  
Commonwealth of  
Puerto  
Rico,  
which  
establishes cybersecurity  
standards for
government entities  
and their  
contractors, including  
certain reporting  
and certification  
obligations. As  
a depositary  
of government
funds, BPPR  
could be  
considered a  
“contractor” under  
the statute;  
however,  
the Puerto  
Rico Innovation  
and Technology  
Service
has  
not  
yet  
adopted  
implementing  
regulation  
which  
we  
expect  
to  
address  
applicability  
and  
any  
exceptions  
to  
the  
statute’s
requirements.  
In addition,  
as noted  
above in  
“Regulation of  
Reinsurers, Insurance  
Producers and  
Agents,” Popular’s reinsurance
subsidiaries are subject to  
licensure and regulatory supervision  
by the Puerto Rico  
Office of the  
Commissioner of Insurance and  
to
insurance laws and regulations.
Available Information
We maintain an  
Internet website at www.popular.com.  
Via the “Investor  
Relations” link at our  
website, our annual reports
on  
Form 10-K,  
quarterly reports  
on  
Form 10-Q,  
current  
reports on  
Form 8-K  
and amendments  
to  
such  
reports filed  
or furnished

23
pursuant to Section 13(a) or  
15(d) of the Securities Exchange Act  
of 1934, as amended (the  
“Exchange Act”), are available, free  
of
charge, as  
soon as  
reasonably practicable  
after such  
forms are  
electronically filed  
with, or  
furnished to,  
the SEC.  
The SEC  
also
maintains an  
internet website at  
http://www.sec.gov that  
contains reports, proxy  
and information statements,  
and other information
regarding issuers that file electronically with the  
SEC. You may obtain copies of our filings on the SEC site.
We have  
adopted a  
written code  
of ethics  
that applies  
to all  
directors, officers  
and employees  
of Popular,  
including our
principal executive officer  
and senior financial  
officers, in accordance  
with Section 406  
of the Sarbanes-Oxley  
Act of 2002  
and the
rules  
of  
the  
SEC  
promulgated  
thereunder.  
Our  
Code  
of  
Ethics  
is  
available  
on  
our  
corporate  
website,  
www.popular.com,  
in  
the
section entitled “Corporate Governance.” In the event that we make changes to, or provide waivers from, the provisions of this Code
of Ethics that  
the SEC requires  
us to disclose,  
we intend to  
disclose these events  
on our corporate  
website in such  
section. In  
the
Corporate Governance  
section  
of our  
corporate  
website,  
we  
have also  
posted the  
charters  
for  
our Audit  
Committee, Talent  
and
Compensation  
Committee,  
Risk  
Management  
Committee,  
Corporate  
Governance  
and  
Nominating  
Committee  
and  
Technology
Committee, as well as our Corporate Governance Guidelines. In addition, information concerning  
purchases and sales of our equity
securities by our executive officers and directors is  
posted on our website.
All  
website  
addresses  
given  
in  
this  
document  
are  
for  
information  
only  
and  
are  
not  
intended  
to  
be  
active  
links  
or  
to
incorporate any website information into this Form  
10-K.
ITEM 1A. RISK FACTORS
We, like  
other financial institutions,  
face risks  
inherent to  
our business,  
financial condition, liquidity,  
results of  
operations
and  
capital  
position.  
These  
risks  
could  
cause  
our  
actual  
results  
to  
differ  
materially  
from  
our  
historical  
results  
or  
the  
results
contemplated by the forward-looking statements contained  
in this report.
The risks described in  
this report are not the  
only risks we face. Additional  
risks and uncertainties not currently  
known by
us  
or  
that  
we  
currently  
deem  
to  
be  
immaterial,  
or  
that  
are  
generally  
applicable  
to  
all  
financial  
institutions,  
may  
also  
materially
adversely affect our business, financial condition, liquidity, results of operations or capital  
position.
ECONOMIC AND MARKET RISKS
Weakness in  
the economy,  
particularly in  
Puerto Rico,  
where a  
significant portion  
of our  
business is  
concentrated, has  

adversely impacted us in the past and may adversely  
impact us in the future.
We have been, and will continue to be, impacted by global and local  
economic and market conditions, including weakness
in  
the  
economy,  
disruptions  
and  
volatility  
in  
the  
financial  
markets,  
inflation,  
monetary,  
trade  
and  
fiscal  
policies,  
public  
policy,
geopolitical conflicts, business and consumer sentiment  
and unemployment. A significant portion of  
our business is concentrated in
Puerto Rico, which accounted for 77% of our assets and 79%  
of our deposits as of December 31, 2025 and  
80% of our revenues for
the  
year  
ended  
December  
31,  
2025.  
As  
a  
result,  
our  
financial  
condition  
and  
results  
of  
operations  
are  
highly  
dependent  
on  
the
general  
trends  
of  
the  
Puerto  
Rico  
economy  
and  
other  
conditions  
affecting  
Puerto  
Rico  
consumers  
and  
businesses.  
The
concentration of  
our operations in  
Puerto Rico  
exposes us to  
greater risks than  
other banking companies  
with a  
wider geographic
base.
Puerto Rico  
has faced significant  
economic and fiscal  
challenges in the  
past, including a  
severe recession that  
began in
2007 and  
persisted for  
over a  
decade and  
an acute  
fiscal crisis  
that led  
the Puerto  
Rico government  
to file  
for a  
form  
of federal
bankruptcy protection  
in 2017.  
Puerto Rico’s  
fiscal and  
economic challenges  
have in  
the past  
adversely affected  
our customers,
resulting  
in  
higher  
delinquencies,  
charge-offs  
and  
increased  
losses  
for  
us.  
While  
Puerto  
Rico’s  
economy  
has  
been  
gradually
recovering  
and  
the  
Puerto  
Rico  
government  
emerged from  
bankruptcy  
in  
2022,  
Puerto  
Rico  
still  
faces  
significant  
economic  
and
fiscal challenges.  

Puerto Rico’s  
economy is  
closely tied  
to the  
U.S. economy,  
as well  
as  
highly reliant  
on U.S.  
public policy  
and funding
decisions. Puerto Rico  
has historically received  
significant federal support  
for a  
wide range of  
government programs and  
services,
including healthcare, education,  
infrastructure and social  
assistance programs. More  
recently, Puerto  
Rico has  
received significant
federal stimulus,  
disaster relief and  
reconstruction funding, which  
has served as  
a major  
driver of  
economic activity.  
Reductions in
federal  
funding  
to  
programs that  
have  
benefited the  
Puerto  
Rico  
economy  
or  
delays  
in  
disbursements could  
significantly impact
Puerto  
Rico’s  
economy  
and  
hinder  
reconstruction  
efforts,  
including  
the  
restoration  
and  
improvement  
of  
critical  
infrastructure.  
In
addition, given that Puerto Rico’s Medicaid program is  
funded through federal block grants, absent federal legislative action,  
annual

24
Medicaid funding for Puerto  
Rico is projected to  
drop significantly during the  
2027-2028 fiscal year,  
which would require the  
Puerto
Rico government  
to cover  
substantial program costs  
and potentially  
place significant  
strain on  
its finances.  
Beyond direct  
funding,
broader shifts in U.S. policy,  
such as changes to tax or trade policies, and  
shifts in policies of other governments in response, could
also adversely  
impact the  
Puerto Rico  
economy.  
A weakening  
of the  
Puerto Rico  
economy or  
other adverse  
economic conditions
affecting Puerto Rico consumers and businesses could result in decreased demand for our products or services, deterioration in the
credit  
quality  
of  
our  
customers,  
higher  
delinquencies,  
charge-offs  
or  
increased  
losses,  
all  
of  
which  
could  
adversely  
affect  
our
business, financial condition, liquidity, results of operations or capital position.
We are  
also exposed  
to risks  
related to  
the state  
of the  
local economies  
of the  
other markets  
in which  
we do  
business,
such as  
New York  
and Florida, as  
well as to  
the state of  
the global and  
U.S. economy and  
financial markets. Evolving  
geopolitical
tensions, the introduction  
or escalation of tariffs,  
inflationary pressures and other  
political or economic shifts  
may lead to  
increased
market volatility  
and disruption.  
These factors  
could, in  
turn, adversely  
impact our  
business, financial condition,  
liquidity,  
results of
operations or capital position.
Changes  
in  
interest  
rates  
and  
credit  
spreads  
can  
adversely  
impact  
our  
financial  
condition,  
including  
our  
investment
portfolio,  
since  
a  
significant  
portion  
of  
our  
business involves  
borrowing  
and  
lending  
money,  
and  
investing in  
financial
instruments.
Our business  
and financial  
performance are  
impacted by  
market interest  
rates and  
movements in  
those rates.  
Since a
high percentage of our assets and liabilities are interest bearing or otherwise sensitive in value to changes in interest rates, changes
in interest rates, in the shape of the yield curve or in spreads between different types of rates, have had and could in the future have
a material impact on our results  
of operations and the values of our  
assets and liabilities, including our investment portfolio.  
Interest
rates are  
highly sensitive  
to many  
factors over  
which we  
have no  
control and  
which we  
may not  
be able  
to anticipate  
adequately,
including general  
economic conditions  
and the  
monetary and  
tax policies  
of various  
governmental bodies,  
particularly the  
Federal
Reserve Board.  
Changes in  
these policies,  
including changes  
in interest  
rates, impact  
various aspects  
of our  
business, including
loan originations,  
the speed  
of prepayments,  
loan delinquencies,  
the value  
of our  
investments, the  
rates we  
receive on  
our loans
and investment  
securities, our  
ability to  
maintain and  
generate deposits  
and the  
rates we  
pay on  
our deposits  
and other  
funding
sources. The  
effects of  
these changes  
may be  
amplified if  
we are  
unable to  
effectively manage  
the sensitivity  
of our  
assets and
liabilities to market interest rate changes.  

The rapid  
rise in  
interest rates  
in 2022  
resulted in  
$2.5 billion  
in unrealized  
mark-to-market losses  
on available-for-sale
securities held  
in our  
investment securities  
portfolio. In  
October 2022,  
we transferred  
U.S. Treasury  
securities with  
a fair  
value of
$6.5 billion (par value of $7.4 billion), and with accumulated unrealized losses of  
$873 million, from our available-for-sale portfolio to
our  
held-to-maturity  
portfolio.  
While  
the  
size  
of  
our  
unrealized  
mark-to-market  
losses  
on  
available-for-sale  
securities  
had  
been
reduced  
to  
$0.9  
billion  
as  
of  
December 31,  
2025,  
if  
interest  
rates  
were  
to  
again  
rise  
rapidly  
or  
for  
a  
prolonged  
period,  
we  
may
accumulate  
significant  
additional  
mark-to-market  
losses  
on  
investment  
securities  
in  
our  
available-for-sale  
portfolio,  
which  
may
adversely affect our tangible capital and impact our  
ability to return capital to our stockholders.
For a discussion of the Corporation’s  
interest rate sensitivity, please refer  
to the “Risk Management” section of the MD&A
in this Form 10-K.
BUSINESS RISKS
Negative  
changes  
in  
the  
financial  
condition  
of  
our  
clients  
have  
adversely  
impacted  
us  
in  
the  
past  
and  
may  
adversely
impact us in the future.
 
A significant portion of  
our business involves lending money,  
which exposes us to  
credit risk and  
risk of loss if  
borrowers
do  
not  
repay  
their  
loans,  
leases, credit  
cards  
or  
other  
credit  
obligations.  
The  
performance of  
these  
credit  
portfolios  
significantly
affects our  
financial condition  
and results  
of operations.  
We have  
in the  
past been  
adversely affected  
by negative  
changes in  
the
financial condition of our clients due to weakness in  
the Puerto Rico and U.S. economy. If the current economic environment were to
deteriorate, more customers may have difficulty in repaying their credit obligations, which may result in higher levels  
of credit losses
and reserves for credit losses.
We are exposed to  
increased credit risks and credit losses  
to the extent our clients are  
concentrated by industry segment
or type of client.
Our credit risk and credit  
losses can increase to the extent  
our loans are concentrated in borrowers engaged in  
the same
or similar  
activities or  
in borrowers  
who as  
a group  
may be  
uniquely or  
disproportionately affected  
by certain  
economic or  
market
conditions. We have significant  
exposure to borrowers in certain  
economic sectors, such as residential  
and commercial real estate,

25
hospitality and healthcare. Challenging economic or market conditions that affect  
the industries or types of clients to  
which we have
significant exposure  
could result  
in higher  
credit  
losses and  
adversely affect  
our business,  
financial condition,  
liquidity,  
results of
operations or capital position.
We also  
have direct  
lending and  
investment exposure  
to Puerto  
Rico government  
entities, which  
have faced  
significant
fiscal challenges.  
At December  
31, 2025,  
our exposure  
to the  
Puerto Rico  
government consisted  
of $391  
million in  
direct lending
exposure to Puerto  
Rico municipalities and  
$209 million in  
loans insured or  
securities issued by  
Puerto Rico governmental  
entities
but for  
which the  
principal source  
of repayment  
is non-governmental.  
We also  
have indirect  
lending exposure  
to the  
Puerto Rico
government in the  
form of loans  
to private borrowers  
who are service  
providers, lessors, suppliers  
or have other  
relationships with
the Puerto Rico government. While the overall fiscal situation  
of the Puerto Rico government has improved in recent years,  
including
as  
a  
result  
of  
the  
government  
and  
certain  
of  
its  
instrumentalities  
having  
restructured  
their  
debt  
obligations,  
some  
Puerto  
Rico
government entities, including certain municipalities, still face significant  
fiscal challenges. A deterioration in the fiscal situation of the
Puerto Rico government and  
its instrumentalities, and in  
particular the fiscal situation  
of the Puerto  
Rico municipalities to  
which we
have direct lending exposure,  
could result in higher  
credit losses and reserves  
for credit losses. For  
a discussion of risks  
related to
the Corporation’s credit  
exposure to the  
Puerto Rico and  
USVI governments, see  
the Geographic and  
Government Risk section  
in
the MD&A section of this Form 10-K.
Deterioration in the  
values of real  
properties securing our commercial, mortgage  
loan and construction portfolios  
have in
the past resulted, and may in the future result,  
in increased credit losses and harm our results  
of operations.
As of  
December 31,  
2025, 55%  
of  
our loan  
portfolio consisted  
of loans  
secured by  
real estate  
collateral (comprised  
of
29% in  
commercial loans,  
22% in  
residential mortgage  
loans and  
4%  
in construction  
loans). The  
value of  
the collateral  
securing
such loans is dependent upon economic conditions in the area in which the collateral is located. Weakness in the economy of some
of the markets we serve has in  
the past resulted in significant declines in the value  
of the real properties securing our loan portfolio,
leading to  
increased credit losses.  
If the  
value of  
the real  
estate properties securing  
our loan portfolio  
declines again in  
the future,
we  
may be  
required to  
increase our  
provisions for  
loan losses  
and allowance  
for loan  
losses. Any  
such  
increase could  
have an
adverse effect  
on our  
financial condition  
and results  
of operations.  
For more  
information on  
the credit  
quality of  
our construction,
commercial and mortgage portfolio, see the Credit  
Risk section of the MD&A included in this  
Form 10-K.
Defective and repurchased loans may harm our business  
and financial condition.
In  
connection  
with  
the  
sale  
and  
securitization  
of  
mortgage  
loans,  
we  
are  
required  
to  
make  
a  
variety  
of  
customary
representations  
and  
warranties regarding  
Popular  
and  
the  
loans  
being  
sold  
or  
securitized.  
Our  
obligations with  
respect to  
these
representations and warranties are generally outstanding for the  
life of the loan, and they  
relate to, among other things, compliance
with  
laws  
and  
regulations,  
underwriting  
standards,  
the  
accuracy  
of  
information  
in  
the  
loan  
documents  
and  
loan  
file  
and  
the
characteristics  
and  
enforceability of  
the  
loan.  
A  
loan  
that  
does  
not  
comply  
with  
the  
secondary  
market’s  
requirements  
may  
take
longer to  
sell, impact  
our ability  
to securitize  
the loans  
or pledge  
the loans  
as collateral  
for borrowings,  
or be  
unsalable or  
salable
only  
at  
a  
significant  
discount.  
Moreover,  
if  
any  
such  
loan  
is  
sold  
before  
we  
detect  
non-compliance,  
we  
may  
be  
obligated  
to
repurchase the loan and bear any associated loss directly,  
or we may be obligated to indemnify the purchaser against any loss.  
We
seek to  
minimize repurchases and  
losses from defective  
loans by correcting  
flaws, if possible,  
and selling or  
re-selling such loans.
However,  
if  
we  
were  
to  
suffer  
significant  
losses  
from  
defective  
and  
repurchased  
loans,  
our  
results  
of  
operations  
and  
financial
condition could be materially impacted.
If we are  
unable to maintain  
or grow our  
deposits, we may  
be subject to  
paying higher funding costs  
and our net  
interest
income may decrease.
 
We rely primarily on bank deposits as a low cost and  
stable source of funding for our lending and  
investment activities and
the operation of  
our business. Therefore, our  
funding costs are largely  
dependent on our ability  
to maintain and  
grow our deposits.
As  
our  
competitors  
have  
raised  
the  
interest  
rates  
they  
pay  
on  
deposits,  
our  
funding  
costs  
have  
increased,  
as  
we  
have  
had  
to
increase the  
rates we  
pay to  
our depositors  
to avoid  
losing deposits and  
to procure  
new ones.  
Rising interest  
rates have  
also led
customers to move their funds to other  
financial institutions or to alternative investments that pay higher interest  
rates.  
Additionally,
periods of market stress  
or lack of market or  
customer confidence in financial institutions may  
result in a loss of  
customer deposits,
especially to the  
extent those deposits are  
in excess of  
the FDIC-insured limit  
of $250,000. As of  
December 31, 2025, we  
had $14
billion of total deposits (other than collateralized public funds, which represent public deposit balances from  
governmental entities in
the  
U.S.  
and  
its  
territories,  
including  
Puerto  
Rico  
and  
the  
United  
States  
Virgin  
Islands,  
that  
are  
collateralized  
based  
on  
such
jurisdictions’ applicable  
collateral requirements)  
in excess  
of the  
FDIC-insured limit.  
If deposits  
decrease, we  
may need  
to rely  
on

26
more expensive sources of  
funding, which would  
negatively impact our interest  
rate margin and net  
interest income.  
In addition, a
reduction in our deposits would decrease our earning  
assets, which would also negatively affect our net interest  
income.
We have a significant amount of deposits from the Puerto  
Rico government, its instrumentalities and municipalities ($19.4
billion, or  
29% of our  
total deposits, as  
of December 31,  
2025), and the  
amount of these  
deposits may fluctuate  
depending on the
financial condition and liquidity of  
these entities, as well  
as on our ability  
to maintain these customer  
relationships. Under the terms
of BPPR’s deposit  
pricing agreement with the  
Puerto Rico government, most  
public fund deposit rates  
are market linked  
with a lag
minus a  
specified spread.  
Therefore, as  
market rates  
rise, we  
are required  
to sequentially  
increase the  
rates we  
pay our  
public
deposits. If the mix of our deposits shifts towards a higher proportion of higher-cost deposits for any reason, our funding costs would
increase and our net interest income would be expected  
to decrease.  

OPERATIONAL RISKS
We and  
our third-party  
providers have  
been, and  
expect in  
the future  
to continue  
to be,  
subject to  
cyber-attacks. Future
cyber-attacks could cause substantial harm and  
have an adverse effect on our business  
and results of operations.
Cybersecurity  
risks  
for  
large  
financial  
institutions  
such  
as  
Popular  
have  
increased  
significantly  
in  
recent  
years  
in  
part
because  
of  
the  
proliferation  
of  
new  
technologies,  
such  
as  
mobile  
banking,  
cloud  
hosting,  
artificial  
intelligence  
and  
the  
ability  
to
conduct instant financial transactions anywhere globally, as well as due to geopolitical conflicts and the increased sophistication and
activities  
of  
organized crime,  
hackers, terrorists,  
nation-states, hacktivists  
and  
other parties.  
Cybersecurity threats  
are constantly
evolving,  
especially  
given  
the  
advances  
in,  
and  
the  
rise  
of  
the  
use  
of,  
artificial  
intelligence  
and  
quantum  
computing,  
thereby
increasing the difficulty of preventing, detecting and  
successfully defending against them.
In  
the  
ordinary  
course  
of  
business,  
we  
rely  
on  
electronic  
communications  
and  
information  
systems  
to  
conduct  
our
operations  
and  
to  
transmit  
and  
store  
sensitive  
data.  
Notwithstanding  
our  
defensive  
measures  
and  
the  
significant  
resources  
we
devote to protecting the security of our systems, there  
is no assurance that all of our security measures  
will be effective at all times,
especially  
as  
the  
threats  
from  
cyber-attacks  
are  
continuous  
and  
severe.  
The  
risk  
of  
a  
security  
breach  
due  
to  
a  
cyber-attack  
is
expected to  
increase as  
we continue to  
expand our  
digital capabilities, mobile  
banking and other  
internet-based product offerings,
the use of the cloud for system development and  
hosting and internal use of internet-based  
products and applications.
We  
continue to  
detect and  
identify attacks  
that are  
becoming more  
sophisticated and  
increasing in  
volume, as  
well as
attackers  
that  
respond  
rapidly  
to  
changes  
in  
defensive  
countermeasures. The  
most  
significant  
cyber-attack  
risks  
that  
we  
or  
our
critical service providers may face include, but are not limited to, e-fraud,  
denial-of-service (DDoS), ransomware, computer intrusion
and  
the  
exploitation  
of  
software  
zero-day  
vulnerabilities  
that  
might  
result  
in  
disruption  
of  
services,  
in  
the  
exposure  
or  
loss  
of
customer or proprietary data, and significant financial loss. These types of cyber-attacks have in the past resulted and may continue
to result  
in the  
compromise of  
sensitive customer  
data, such  
as account  
numbers, credit  
cards and  
social security  
numbers, and
could present significant reputational, legal and regulatory  
costs to Popular if successful.  

Our  
customer-facing  
platforms  
are  
also  
routinely  
targeted  
by  
threat  
actors  
aiming  
to  
gain  
unauthorized  
access  
to  
our
clients’  
accounts.  
Although  
we  
have  
implemented  
defensive  
measures  
designed  
to  
protect  
against  
such  
attacks,  
there  
is  
no
assurance that these  
defensive measures will  
keep pace with  
threats that are  
continuous and growing  
in severity.  
For example, in
2022, certain customers were affected by brute force attacks on one of our platforms, which resulted in certain of our customers log-
in credentials  
and information  
being exposed,  
resulting in  
fraudulent transfers  
or withdrawals.  
Popular customers  
have also  
been
impacted by  
card skimming  
events in  
our ATM  
terminals. As  
a result,  
we have  
notified, and  
conducted additional  
remediation for,
customers identified as  
affected by  
these incidents. Cyber-security  
risks have also  
been exacerbated by  
the discovery of  
zero-day
vulnerabilities in  
widely distributed  
third party  
software, which  
have in  
the past  
affected and  
in the  
future could  
affect Popular’s  
or
any of its service provider’s systems, as  
further detailed below.
The  
increased  
use  
of  
remote  
access  
and  
third-party  
video  
conferencing  
solutions  
to  
enable  
work-from-home
arrangements for employees has  
also increased our exposure  
to cyber-attacks, including through  
the use of  
deep fakes and brand
impersonation.  
We  
expect  
the  
rise  
and  
use  
of  
artificial  
intelligence  
to  
exacerbate  
this  
risk.  
In  
addition,  
a  
third  
party  
could
misappropriate confidential information  
obtained by intercepting  
signals or communications  
from mobile  
devices used by  
Popular’s
customers or employees. Recent geopolitical conflicts have also exacerbated the risks related to supply-chain  
compromises and de-
stabilizing activities of nation-state sponsored actors.
A material compromise or circumvention of the security of our systems could  
have serious negative consequences for us,
including  
significant  
disruption  
of  
our  
operations  
and  
those  
of  
our  
clients,  
customers  
and  
counterparties,  
misappropriation  
of

27
confidential  
information  
of  
Popular  
or  
that  
of  
our  
clients,  
customers,  
counterparties  
or  
employees,  
or  
damage  
to  
computers  
or
systems used  
by us  
or by  
our clients,  
customers and  
counterparties, and  
could result  
in violations of  
applicable privacy  
and other
laws,  
financial  
loss  
to  
us  
or  
to  
our  
customers,  
increased  
regulatory  
scrutiny  
and  
enforcement  
actions,  
customer  
dissatisfaction,
significant litigation exposure and harm to our reputation, all of which could have a material adverse effect on us. Banking regulators
increasingly scrutinize third-party relationships supporting critical activities. If our regulators determine that our oversight,  
contractual
protections, or  
the performance  
and controls  
of our  
third-party providers  
(including critical  
providers) are  
inadequate, we  
could be
required  
to  
implement  
enhanced  
controls,  
conduct  
independent  
reviews,  
restrict  
or  
terminate  
relationships,  
or  
undertake  
costly
remediation or  
conversion activities,  
any of  
which could  
disrupt operations,  
increase expenses,  
or adversely  
affect our  
reputation
and results of operations.
The  
extent  
of  
a  
particular  
cyber-attack  
and  
the  
steps  
that  
we  
may  
need  
to  
take  
to  
investigate  
the  
attack  
may  
not  
be
immediately  
clear,  
and  
it  
may  
take  
a  
significant  
amount  
of  
time  
before  
such  
an  
investigation  
can  
be  
completed.  
While  
such  
an
investigation is ongoing, Popular may not necessarily know the full extent  
of the harm caused by the cyber-attack, and that  
damage
may continue to spread.  
These factors may inhibit  
our ability to provide  
rapid, full and reliable  
information about the cyber-attack to
our clients, customers, counterparties and regulators, as well as the public. Moreover, we may be required under SEC rules  
or bank
regulations to disclose information about a cybersecurity event before it has been resolved  
or fully investigated. Furthermore, it may
not be clear how best to contain and remediate the potential harm  
caused by the cyber-attack, and certain errors or actions could be
repeated or compounded before they are discovered  
and remediated. Cyber-attacks could also cause interruptions  
in our operations
and result in the incurrence of significant costs,  
including those related to forensic analysis  
and legal counsel.  

We also  
rely on  
third parties  
for the  
performance of  
a significant  
portion of  
our information  
technology functions and  
the
provision of information security,  
technology and business process services. As a result, a  
successful compromise or circumvention
of  
the security  
of  
the systems  
of these  
third-party service  
providers could  
have serious  
negative consequences  
for us,  
including
compromise  
of  
our  
systems,  
misappropriation of  
our  
confidential  
information  
or  
that  
of  
our  
clients,  
customers,  
counterparties  
or
employees, or  
other negative  
implications identified  
above with  
respect to  
a cyber-attack  
on our  
systems. The  
most important  
of
these  
third-party service  
providers for  
us  
is  
Evertec. As  
a result,  
we  
depend on  
Evertec to  
identify and  
remediate certain  
of  
our
cybersecurity vulnerabilities. Cyber-attacks at third-party service  
providers are also becoming increasingly common, and,  
as a result,
cybersecurity risks relating to our vendors, including Evertec have increased.  
Certain risks particular to Evertec and our dependence
on  
third  
parties  
are  
discussed  
under  
“We  
rely  
on  
other  
companies  
to  
provide  
key  
components  
of  
our  
business  
infrastructure,
including certain of our core financial transaction processing and  
information technology and security services, which exposes us to
a number  
of operational  
risks that  
could have  
a material  
adverse effect  
on us”  
in the  
Operational Risks  
section of  
Item 1A  
in this
Form 10-K. During 2023, personal information of Popular customers’ data was compromised in a data breach incident that impacted
MOVEit, the third-party file transfer platform used by one of our service  
providers. Popular notified, as required or otherwise deemed
appropriate,  
customers  
identified  
as  
affected  
by  
the  
incident.  
Furthermore,  
during  
2024,  
threat  
actors  
exploited  
a  
zero-day
vulnerability in  
the Fortinet  
enterprise management  
server software  
used by  
Evertec, which  
migrated to  
one of  
Popular's domain
controllers  
due  
to  
a shared  
network  
environment. While  
Evertec  
eventually determined  
that  
no  
BPPR  
customer  
information was
exfiltrated as a result of  
this incident, the event underscores  
the risks inherent in Popular’s dependency  
on Evertec. Although these
incidents did not  
have a material  
effect on  
Popular, including  
its business strategy,  
results of operations  
or financial condition,  
and
our  
third-party  
service  
providers  
agreed  
to  
cover  
external  
remediation  
costs  
associated  
therewith,  
a  
compromise  
of  
Popular
information  
or  
the  
personal  
information  
of  
our  
customers  
maintained  
by  
third  
party  
vendors  
could  
result  
in  
significant  
regulatory
consequences, reputational damage and financial  
loss to us. The  
success of our business  
depends in part on  
the continuing ability
of these  
(and other)  
third parties  
to perform  
these functions  
and services  
in a  
timely and  
satisfactory manner,  
which performance
could be disrupted or otherwise adversely affected  
due to failures or other information security events originating  
at the third parties
or  
at  
the  
third  
parties’  
suppliers  
or  
vendors  
(so-called  
“fourth  
party  
risk”).  
We  
may  
not  
be  
able  
to  
effectively  
directly  
monitor  
or
mitigate  
fourth-party  
risk,  
in  
particular  
as  
it  
relates  
to  
the  
use  
of  
common  
suppliers  
or  
vendors  
by  
the  
third  
parties  
that  
perform
functions and services for us.
 
As cyber  
threats continue  
to evolve,  
we also  
expect to  
expend significant  
additional resources  
to continue  
to modify  
or
enhance  
our  
layers  
of  
defense  
or  
to  
investigate  
and  
remediate  
additional  
information  
security  
vulnerabilities  
or  
incidents.  
The
obsolescence  
in  
our  
hardware  
or  
software  
limits  
our  
ability  
to  
mitigate  
vulnerabilities.  
System  
enhancements and  
updates  
also
create  
risks  
associated  
with  
implementing new  
systems  
and  
integrating  
them  
with  
existing  
ones,  
including  
risks  
associated  
with
supply chain compromises and the software development lifecycle of the systems used by us and our service providers. In  
addition,
addressing certain  
information security  
vulnerabilities, such  
as hardware-based  
vulnerabilities, may  
affect  
the performance  
of our
information  
technology  
systems.  
The  
ability  
of  
our  
hardware  
and  
software  
providers  
to  
deliver  
patches  
and  
updates  
to  
mitigate
vulnerabilities in a timely manner can introduce  
additional risks, particularly when a vulnerability is being actively  
exploited by threat

28
actors.  
Moreover,  
our  
efforts  
to  
timely  
mitigate  
vulnerabilities  
and  
manage  
such  
risks,  
given  
the  
rise  
in  
number  
and  
urgency  
of
required patches and third-party software, as well as  
the obsolescence in some of our hardware and  
software, may impact our day-
to-day operations, the availability of our systems and  
delay the deployment of technology enhancements  
and innovation.  

If Popular’s operational systems,  
or those of  
external parties on which  
Popular’s businesses depend, are  
unable to meet
the requirements of our businesses and operations or the standards of our regulators  
or other applicable data protection and privacy
laws, or if they fail, have other significant shortcomings or are impacted by cyber-attacks,  
Popular could be materially and adversely
affected.
We  
rely  
on  
other  
companies  
to  
provide  
key  
components  
of  
our  
business  
infrastructure,  
including  
certain  
of  
our  
core
financial  
transaction  
processing  
and  
information  
technology  
and  
security  
services,  
which  
exposes  
us  
to  
a  
number  
of
operational risks that could have a material  
adverse effect on us.
Third parties provide key components of our business operations, such  
as data processing, information security, recording
and monitoring transactions,  
online banking interfaces and  
services, Internet connections and  
network access. The most  
important
of  
these  
third-party service  
providers for  
us  
is  
Evertec  
due  
in  
large  
part  
to  
its  
role  
as  
a service  
provider to  
BPPR,  
our  
principal
banking subsidiary.  
We are dependent on Evertec for the provision of  
essential services to our business, including certain  
of BPPR’s
core financial  
transaction processing and  
information technology and  
security services. As  
a result,  
we are particularly  
exposed to
the operational risks of Evertec,  
including those related to its  
security architecture and potential breakdowns or  
failures of Evertec’s
systems or internal controls environment.  

Over the  
course of our  
relationship with Evertec,  
we have experienced  
interruptions and delays  
in key  
services provided
by Evertec, as well as cyber events, as a result of system breakdowns, their exposure to zero-day vulnerabilities, misconfigurations,
human  
error,  
application  
obsolescence  
and  
dependency  
on  
shared  
infrastructure  
components  
and  
shared  
environments,  
which
have in certain cases also  
led to exposure of Popular information  
and BPPR customer information. In particular,  
the current level of
obsolescence in the hardware and  
software used by Evertec  
to service us exposes  
us to heightened operational and  
cybersecurity
risks, including system outages.  
Our ability to cure  
legacy obsolescence in the  
hardware and software we  
procure from Evertec, to
expand  
our  
oversight  
over  
security  
services  
being  
provided  
by  
Evertec,  
as  
well  
as  
to  
effect  
the  
segregation  
of  
our  
shared
infrastructure,  
is  
expected  
to  
be  
lengthy  
and  
complex,  
which  
exacerbates  
our  
exposure  
to  
resulting  
operational,  
including
cybersecurity,  
risks. See  
“The transition  
to new  
financial services  
technology providers,  
and the  
replacement of  
services currently
provided to us by Evertec, will be lengthy and  
complex” in the Operational Risks section of Item 1A  
in this Form 10-K below.  

While  
we  
select  
third-party vendors  
carefully  
and  
have  
increased our  
oversight  
of  
these  
relationships, our  
oversight is
constrained by  
the level  
of our  
ongoing visibility into  
our vendor’s systems  
and operations, and  
we do not  
have direct control  
over
their actions, assets  
or services. Any  
problems caused by  
these vendors, including  
those resulting from  
disruptions in the  
services
provided, vulnerabilities  
in or  
breaches of  
the vendor’s  
systems or  
environments, failure  
of the  
vendor to  
handle current  
or higher
volumes, failure of the vendor to provide services for any reason or  
poor performance of services, failure of the vendor to notify us  
of
a  
reportable  
event  
in  
a  
timely  
manner,  
or  
our  
vendors’  
misuse  
of  
artificial  
intelligence  
and  
other  
automatic  
decision  
making
technologies,  
could  
adversely  
affect  
our  
ability  
to  
deliver  
products  
and  
services  
to  
our  
customers  
and  
otherwise  
conduct  
our
business,  
disrupt  
our  
operations,  
result  
in  
potential  
liability  
to  
customers  
and  
counterparties,  
result  
in  
the  
imposition  
of  
fines,
penalties or judgments by our regulators, lead to exposure of our information or that of our customers or harm to our reputation, any
of which  
could materially  
and adversely  
affect us.  
The inability  
of our  
third-party service  
providers to  
timely address  
cybersecurity
threats may further exacerbate these  
risks. Financial or operational difficulties of  
a third-party vendor could also  
hurt our operations
if  
those  
difficulties  
interfere  
with the  
vendor’s ability  
to  
serve  
us.  
Replacing these  
third-party vendors,  
when possible,  
could  
also
create  
significant  
delay  
and  
expense.  
Accordingly,  
the  
use  
of  
third  
parties  
creates  
an  
unavoidable inherent  
risk  
to  
our  
business
operations.
The transition to new financial services technology providers, and the replacement of services currently provided to  
us by
Evertec, will be lengthy and complex.
Switching from one vendor of core financial transaction processing and related technology and security services to one or
more new  
vendors is  
a complex  
process that  
carries business  
and financial  
risks. The  
implementation cycle  
for such  
a transition
would be  
lengthy and require  
significant financial and  
management resources from  
BPPR and  
Popular. Such  
a transition can  
also
increase costs (including conversion costs), impede or disrupt business or technological initiatives, and expose us and our clients to
business disruption, as well as operational and cybersecurity risks. As  
we transition all or a portion of  
the existing services provided
by Evertec  
to new  
financial services  
technology providers,  
either (i)  
at the  
end of  
the term  
of the  
Second Amended  
and Restated
Master Services Agreement  
(the “MSA”) and  
related agreements or  
(ii) earlier upon  
the termination of  
any service for  
convenience

29
under the MSA, these transition risks could result in an adverse effect on our  
business, financial condition and results of operations.
Although Evertec  
has agreed  
to provide  
certain transition  
assistance to  
us in  
connection with  
the termination  
of the  
MSA, we  
are
ultimately dependent on their ability to provide those  
services in a responsive and competent manner, as well as their ability to retain
experienced personnel to  
provide the services. A  
successful transition will  
also depend on  
our ability to  
retain personnel who  
have
relevant experience  
and expertise.  
Furthermore, we  
may require  
transition assistance  
from Evertec  
beyond the  
term of  
the MSA,
potentially delaying and lengthening any transition  
process away from Evertec while increasing  
related costs and risks  
of disruption
to us and our clients.
 
Under the  
MSA, we  
are able  
to terminate  
services for  
convenience with  
180 days’  
prior notice.  
We expect  
to exercise
during the  
term of  
the MSA  
the right  
to terminate  
certain services  
for convenience  
and to  
transition such  
services to  
other service
providers prior to the expiration  
of the MSA, subject to  
complying with the revenue minimums contemplated in  
the MSA and certain
other conditions. In  
practice, in order  
to switch  
to a  
new provider for  
a particular service,  
we will have  
to commence procuring  
and
working on  
a transition  
process for  
such service  
significantly in  
advance of  
its termination  
and, in  
any case,  
much earlier  
than the
expiration date of the MSA, and such process may extend beyond the current term of the MSA. Furthermore, if we are unsuccessful
or  
decide  
not  
to  
complete  
the  
transition  
after  
expending significant  
funds  
and  
management resources,  
it  
could  
also  
result  
in  
an
adverse effect on our business, financial condition and  
results of operations.
Unforeseen or  
catastrophic events,  
including  
extreme weather  
events and  
other natural  
disasters, man-made  
disasters,
acts of violence or  
war, or the  
emergence of pandemics or epidemics, could  
cause a disruption in our  
operations or other
consequences that could have a material adverse  
effect on our financial condition and results  
of operations.
A  
significant  
portion  
of  
our  
operations  
are  
located  
in  
the  
Caribbean  
and  
Florida,  
a  
region  
susceptible  
to  
hurricanes,
earthquakes and other  
similar events. In  
2017, Puerto Rico,  
USVI and BVI  
were severely impacted  
by Hurricanes Irma  
and María,
which resulted in significant disruption to our operations and adversely affected  
our clients in these markets, and in 2022, Hurricane
Fiona impacted the  
southwest area of  
Puerto Rico,  
adversely affecting our  
customers in  
that region. Other  
types of  
unforeseen or
catastrophic events, including  
pandemics, epidemics, man-made  
disasters, or acts  
of violence or  
war, or  
the fear that  
such events
could occur  
in the  
future, could  
also adversely  
impact our  
operations and  
financial results.  
For example,  
in 2020,  
the COVID-19
pandemic  
severely  
impacted  
global  
health,  
financial  
markets,  
consumer  
spending  
and  
global  
economic  
conditions,  
and  
caused
significant disruption to businesses  
worldwide, including our business  
and those of  
our customers, service providers  
and suppliers.
Future unforeseen or catastrophic events, and actions taken by governmental authorities and other third parties in response to such
events, could  
adversely affect  
our operations,  
cause economic  
and market  
disruption, adversely  
impact the  
ability of  
borrowers to
timely repay  
their loans,  
or affect  
the value  
of any  
collateral held  
by us,  
any of  
which could  
have a  
material adverse  
effect on  
our
business, financial condition or results of operations. The frequency, severity and impact of future unforeseen or catastrophic events
is  
difficult  
to  
predict. While  
we maintain  
insurance against  
natural disasters  
and  
other unforeseen  
events, including  
coverage  
for
business interruption, the insurance may not be sufficient to cover all of the damage from any such event, and there is  
no insurance
against the  
disruption that  
a catastrophic  
event could  
produce to  
the markets  
that we  
serve and  
the potential  
negative impact  
to
economic activity.
Climate change could have a material adverse  
impact on our business operations and that  
of our clients and customers.
Our business and  
the activities and  
operations of our  
clients and customers  
may be disrupted  
by global climate  
change.
Potential physical risks  
from climate change  
include the increase  
in the  
frequency and severity  
of weather  
events, such as  
storms
and  
hurricanes,  
and  
long-term  
shifts  
in  
climate  
patterns, such  
as  
sustained  
higher  
and  
lower  
temperatures,  
sea  
level  
rise,  
heat
waves  
and  
droughts,  
among  
others.  
Our  
geographic  
concentration  
in  
localities,  
including  
Puerto  
Rico,  
the  
U.S.V.I.,  
B.V.I.  
and
Florida, particularly  
susceptible to  
risks arising  
from climate  
change, including  
severe hurricanes  
and sea  
level rise,  
heighten the
threat we  
face from  
climate change. Additionally,  
the impact  
of climate  
change in  
the markets  
that we  
operate and  
in other  
global
markets may  
have the  
effect of  
increasing the  
costs or  
reducing the  
availability of  
insurance needed  
for our  
business operations.
Climate change may also create transitional risks resulting from a shift to a low-carbon economy.  
These transition risks may include
changes in the legal and regulatory landscape, technology, consumer sentiment and preferences, and market demands that seek to
mitigate the  
effects  
of climate  
change. Changes  
in the  
legal  
and regulatory  
landscape may  
additionally increase  
our compliance
costs.  
These  
climate-driven  
changes  
could  
have  
a  
material  
adverse  
impact  
on  
asset  
values  
and  
on  
our  
business  
and  
financial
performance and those of our clients and customers.
LEGAL AND REGULATORY RISKS
Our  
businesses  
are  
highly  
regulated,  
and  
the  
laws  
and  
regulations  
that  
apply  
to  
us  
have  
a  
significant  
impact  
on  
our
business and operations.

30
We are subject to extensive and evolving  
regulation under U.S. federal, state and Puerto Rico laws that  
govern almost all
aspects of our operations and  
limit the businesses in which  
we may be engaged,  
including regulation, supervision and examination
by federal, state  
and foreign banking  
authorities. These laws  
and regulations have  
expanded significantly over an  
extended period
of  
time  
and  
are  
primarily  
intended  
for  
the  
protection  
of  
consumers,  
borrowers  
and  
depositors.  
Compliance  
with  
these  
laws  
and
regulations has resulted, and will continue  
to result, in significant costs. Additionally,  
the current federal administration is  
pursuing a
policy  
and  
regulatory  
agenda  
significantly  
different  
from  
that  
of  
the  
previous  
administration,  
including  
the  
reversal  
of  
rules
promulgated  
under  
the  
past  
administration  
and  
shifts  
in  
rulemaking,  
supervision,  
examination  
and  
enforcement  
priorities.  
The
implementation of that agenda is happening rapidly and is constantly  
evolving. The potential impact of any such changes cannot be
predicted.
Additional  
laws  
and  
regulations  
may  
be  
enacted  
or  
adopted  
in  
the  
future,  
and  
the  
application,  
interpretation  
or
enforcement  
of  
laws  
and  
regulations  
may  
in  
the  
future  
be  
changed  
(including  
through  
executive  
orders),  
in  
ways  
that  
could
significantly affect  
our powers,  
authority and  
operations and  
which could  
have a  
material adverse  
effect on  
our financial  
condition
and  
results  
of  
operations. In  
particular,  
we  
could  
be  
adversely impacted  
by  
changes  
in  
laws  
and  
regulations,  
or changes  
in  
the
application, interpretation  
or enforcement  
of laws  
and regulations,  
that proscribe  
or institute  
more stringent  
restrictions on  
certain
financial  
services  
activities, impose  
monetary fines  
or  
other  
penalties on  
institutions that  
fail  
to  
comply  
with  
applicable laws  
and
regulations, or impose new requirements.  
In addition, new laws or regulations could require significant system and process changes
that require  
systems upgrades  
and could  
limit our  
ability to  
meet adoption timeframes  
or pursue  
our innovation roadmap.  
If we  
do
not  
appropriately  
comply  
with  
current  
or  
future  
laws  
or  
regulations,  
adapt  
to  
the  
changing  
interpretation  
of  
existing  
laws  
or
regulations,  
or  
if  
we  
fail  
to  
meet  
supervisory  
expectations,  
we  
may  
be  
subject  
to  
fines,  
penalties  
or  
judgements,  
or  
to  
material
regulatory restrictions on  
our business, which could  
also materially and  
adversely affect our  
business,  
financial condition, liquidity,
results of operations or capital position.
Our participation  
(or lack  
of participation)  
in certain  
governmental programs,  
such as  
the Paycheck  
Protection Program
(“PPP”) enacted  
in response  
to the  
COVID-19 pandemic,  
also exposes  
us to  
increased legal  
and regulatory  
risks. We  
have also
been and could continue to  
be exposed to adverse  
action for the violation of  
applicable legal requirements or the improper  
conduct
of our employees in connection with such loans. For example, on January 24, 2023, Popular Bank consented to the imposition of an
order from  
the Federal  
Reserve Board  
requiring it  
to  
pay a  
$2.3 million  
civil money  
penalty to  
settle certain  
findings arising  
from
Popular Bank’s approval of six Payment Protection Program  
loans.
In addition,  
due to  
divergent policies  
and stakeholder  
viewpoints regarding  
climate and  
sustainability matters,  
we are  
at
increased risk of  
being subject to conflicting  
legal and regulatory requirements  
and stakeholder expectations regarding climate  
and
sustainability  
matters.  
For  
example,  
certain  
states  
have  
enacted  
or  
proposed  
laws  
addressing  
climate  
change  
and  
other
sustainability issues, including climate-related disclosure requirements. On the other hand, certain states have enacted  
or proposed
laws or regulations or  
taken other actions to  
prohibit the consideration of environmental  
and social factors in state  
investments and
contracting. In addition, in August 2025, President Trump signed Executive Order 14331, “Guaranteeing Fair Banking Access for All
Americans,” which  
states that  
it is  
the policy  
of the  
United States  
that no  
American should  
be denied  
access to  
financial services
because  
of  
their  
constitutionally  
or  
statutorily  
protected  
beliefs,  
affiliations,  
or  
political  
views.  
The  
Executive  
Order  
directs  
the
Treasury Secretary  
and federal  
banking regulators  
to address  
politicized or  
unlawful debanking  
activities. These,  
as well  
as other
laws,  
regulations,  
guidance  
and  
expectations,  
many  
of  
which  
may  
have  
broad  
and  
extraterritorial  
application,  
have  
in  
the  
past
subjected and may  
in the future  
subject us to  
additional requirements or  
different and conflicting  
requirements and expectations  
in
the various jurisdictions in which we operate, which  
could negatively affect our business and brand.
We  
are from  
time to  
time subject  
to information  
requests, investigations  
and other  
regulatory enforcement  
proceedings
from  
departments  
and  
agencies  
of  
the  
U.S.,  
Puerto  
Rico,  
New  
York  
and  
other  
state  
governments, including  
those  
that
investigate  
compliance  
with  
U.S.  
sanctions  
and  
consumer  
protection  
laws  
and  
regulations,  
which  
may  
expose  
us  
to
significant  
penalties  
and  
collateral  
consequences,  
and  
could  
result  
in  
higher  
compliance  
costs  
or  
restrictions  
on  
our
operations.
We  
from  
time-to-time  
self-report  
compliance  
matters  
to,  
or  
receive  
requests  
for  
information  
from,  
departments  
and
agencies  
of  
the  
U.S.,  
Puerto  
Rico,  
New  
York  
and  
other state  
governments, including  
with  
respect to  
compliance  
with consumer
protection laws and regulations. For example, BPPR  
has in the past received requests for  
information, such as subpoenas and civil
investigative demands from U.S. government regulators,  
including concerning add-ons on consumer products, real  
estate appraisals
and  
residential  
and  
construction  
loans  
in  
Puerto  
Rico.  
BPPR  
has  
also  
self-identified  
and  
reported  
to  
applicable  
regulators
compliance matters related to U.S. sanctions, as well  
as mortgage, credit reporting and other  
consumer lending practices.  

31
Incidents of this nature and investigations or examinations by governmental authorities have resulted in the past, and may
in the  
future result, in  
judgments, settlements, fines,  
enforcement actions, penalties  
or other sanctions  
adverse to the  
Corporation,
which could materially and adversely affect the Corporation’s business, financial  
condition, results of operations or capital position or
cause serious reputational harm. Any such settlements or orders  
that we enter into, or that regulatory authorities impose  
on us could
require enhancements to our  
procedures and controls and  
entail significant operational and  
compliance costs. Furthermore, issues
or delays in satisfying the requirements of a regulatory settlement or  
action on a timely basis could result in additional  
penalties and
enforcement actions, which could be significant. In connection with the resolution of regulatory proceedings, enforcement authorities
may seek admissions of wrongdoing and, in some cases, criminal pleas, which  
could lead to increased exposure to private litigation,
loss of clients or customers, and restrictions on offering certain products or  
services. In addition, responding to information-gathering
requests,  
investigations  
and  
other  
regulatory  
proceedings,  
regardless  
of  
the  
ultimate  
outcome  
of  
the  
matter,  
could  
be  
time-
consuming, expensive and divert management attention  
from our business.  

Financial services  
institutions such  
as Popular  
have been  
subject to  
heightened expectations  
and regulatory  
scrutiny in
recent years.  
Our regulators’  
oversight is  
not limited  
to banking  
and financial  
services laws  
but extends  
to other  
significant laws
such as those related to anti  
money laundering, anti-bribery and anti-corruption laws. Further,  
regulators in the performance of their
supervisory and enforcement  
duties, have significant  
discretion and power  
to prevent or  
remedy what they  
deem to be  
unsafe and
unsound  
practices  
or  
violations  
of  
laws  
by  
banks  
and  
bank  
holding  
companies.  
Therefore,  
the  
outcome  
of  
any  
investigative  
or
enforcement action, which may take years and be  
material to Popular, may be difficult to predict or estimate.  

Complying with economic and trade sanctions programs  
and anti-money laundering laws and regulations  
can increase our
operational and compliance costs. If  
we, and our subsidiaries, affiliates or  
third-party service providers, are found to  
have
failed to comply with applicable economic and trade sanctions programs and anti-money laundering laws  
and regulations,
we  
could  
be  
exposed  
to  
fines,  
sanctions  
and  
penalties,  
and  
other  
regulatory  
actions,  
as  
well  
as  
governmental
investigations.  

As  
a  
federally  
regulated  
financial  
institution,  
we  
must  
comply  
with  
regulations  
and  
economic  
and  
trade  
sanctions  
and
embargo  
programs  
administered by  
the  
Office  
of  
Foreign  
Assets  
Control  
(“OFAC”)  
of  
the  
U.S.  
Treasury,  
as  
well  
as  
anti-money
laundering laws and regulations, including those under  
the Bank Secrecy Act.
Economic and trade sanctions regulations and programs administered by OFAC prohibit U.S.-based entities from entering
into or facilitating  
unlicensed transactions with, for  
the benefit of,  
or in some  
cases involving the  
property and property interests  
of,
persons,  
governments or  
countries  
designated by  
the  
U.S.  
government under  
one  
or  
more  
sanctions  
regimes,  
and  
also  
prohibit
transactions  
that  
provide  
a  
benefit  
that  
is  
received in  
a  
country  
designated  
under  
one  
or  
more  
sanctions  
regimes.  
We  
are  
also
subject to  
a variety  
of reporting  
and other  
requirements under  
the Bank  
Secrecy Act,  
including the  
requirement to  
file suspicious
activity and currency  
transaction reports, that  
are designed to  
assist in  
the detection  
and prevention of  
money laundering, terrorist
financing  
and  
other  
criminal  
activities.  
In  
addition,  
as  
a  
financial  
institution  
we  
are  
required  
to,  
among  
other  
things,  
identify  
our
customers, adopt formal  
and comprehensive anti-money  
laundering programs, scrutinize  
or altogether prohibit  
certain transactions
of special concern, and be prepared to respond to inquiries from U.S.  
law enforcement agencies concerning our customers and  
their
transactions. Failure  
by the  
Corporation, its  
subsidiaries, affiliates  
or  
third-party service  
providers to  
comply with  
these  
laws  
and
regulations  
could  
have  
serious  
legal  
and  
reputational  
consequences  
for  
the  
Corporation,  
including  
the  
possibility  
of  
regulatory
enforcement  
or  
other  
legal  
action,  
including  
significant  
civil  
and  
criminal  
penalties.  
We  
also  
incur  
higher  
costs  
and  
face  
greater
compliance risks in  
structuring and operating  
our businesses to comply  
with these requirements. The  
markets in which  
we operate
heighten these costs and risks.
We have established risk-based policies and procedures and employed software designed to  
assist us and our personnel
in complying  
with these  
applicable laws  
and regulations.  
Even if  
the appropriate  
controls are  
in place,  
there can  
be no  
assurance
that  
our  
policies  
and  
procedures will  
prevent  
us  
from  
blocking  
and  
rejecting  
all  
applicable  
transactions  
of  
our  
customers  
or  
our
customers’ customers  
that may  
involve a  
sanctioned person,  
government or  
country.  
Any failure  
to detect  
and prevent  
any such
transaction  
could  
result  
in  
a  
violation  
of  
applicable  
laws  
and  
regulations  
and  
adversely  
affect  
our  
reputation,  
business,  
financial
condition and results of operations.
From time  
to time  
we have  
identified and  
voluntarily self-disclosed  
to OFAC  
transactions that  
were not  
timely identified,
blocked  
or  
rejected  
by  
our  
policies,  
controls  
and  
procedures  
for  
screening  
transactions  
that  
might  
violate  
the  
regulations  
and
economic and  
trade sanctions  
programs administered  
by OFAC.  
For example,  
during the  
second quarter  
of 2022,  
BPPR entered
into  
a  
settlement  
agreement  
with  
OFAC  
with  
respect  
to  
certain  
transactions  
processed  
on  
behalf  
of  
two  
employees  
of  
the
Government of Venezuela,  
in apparent violation of U.S. sanctions  
against Venezuela. Popular agreed  
to pay $256,000 to settle  
the
apparent  
violations,  
which  
had  
been  
self-disclosed  
to  
OFAC.  
There  
can  
be  
no  
assurances  
that  
any  
failure  
to  
comply  
with  
U.S.

32
sanctions and  
embargoes, or  
with anti-money  
laundering laws  
and regulations,  
will not  
result in  
material fines,  
sanctions or  
other
penalties being imposed on us.
Furthermore, if  
the policies,  
controls, and  
procedures of  
one of  
the Corporation’s  
third-party service  
providers, together
with our  
third-party oversight  
of such  
providers, do  
not prevent  
it from  
violating applicable  
laws and  
regulations in  
transactions in
which it engages, such violations could adversely affect its  
ability to provide services to us.  

We are  
subject to  
regulatory capital  
adequacy requirements, and  
if we  
fail to  
meet these  
requirements our  
business and
financial condition will be adversely affected.
Under regulatory capital adequacy requirements, and other  
regulatory requirements, Popular and our banking  
subsidiaries
must  
meet  
requirements  
that  
include  
quantitative  
measures  
of  
assets,  
liabilities  
and  
certain  
off-balance  
sheet  
items,  
subject  
to
qualitative  
judgments  
by  
regulators  
regarding  
components,  
risk  
weightings  
and  
other  
factors.  
If  
we  
fail  
to  
meet  
these  
minimum
capital  
requirements  
and  
other  
regulatory  
requirements,  
our  
business  
and  
financial  
condition  
will  
be  
materially  
and  
adversely
affected. If  
a financial  
holding company  
fails to  
maintain well-capitalized  
status under  
the regulatory  
framework, or  
is deemed  
not
well managed  
under regulatory  
exam procedures, or  
if it  
experiences certain  
regulatory violations, its  
status as  
a financial  
holding
company and its  
related eligibility for  
a streamlined review  
process for acquisition  
proposals, and its  
ability to offer  
certain financial
products, may be  
compromised and its  
financial condition and  
results of operations  
could be adversely  
affected. The failure  
of any
depository  
institution  
subsidiary  
of  
a  
financial  
holding  
company  
to  
maintain  
well-capitalized  
or  
well-managed  
status  
could  
have
similar consequences.  

See “Our businesses are  
highly regulated, and the  
laws and regulations that apply  
to us have a  
significant impact on our
business and operations” in the Legal and Regulatory  
Risks section of Item 1A in this Form 10-K.
Increases in FDIC insurance premiums may  
have a material adverse effect on our earnings.
Substantially  
all  
the  
deposits  
of  
BPPR  
and  
PB  
are  
subject  
to  
insurance  
up  
to  
applicable  
limits  
by  
the  
FDIC’s  
deposit
insurance fund  
(“DIF”) and, as  
a result, BPPR  
and PB  
are subject to  
FDIC deposit  
insurance assessments. On  
October 18, 2022,
the FDIC  
finalized a  
rule that  
increased initial  
base deposit  
insurance assessment  
rates by  
2 basis  
points, beginning  
with the  
first
quarterly assessment period of 2023. In addition, in November 2023, the FDIC finalized a rule that imposes a special assessment to
recover the costs to the DIF resulting from the FDIC’s  
use, in March 2023, of the systemic risk exception to  
the least-cost resolution
test  
under  
the  
FDIA  
in  
connection  
with  
the  
receiverships  
of  
Silicon  
Valley  
Bank  
and  
Signature  
Bank.  
The  
exact  
amount  
of  
this
assessment will be determined when the FDIC terminates  
the related receiverships considered in the final  
rule. Accordingly, the final
special assessment  
amount and collection  
period may change  
as the  
estimated cost  
is periodically adjusted  
or if  
the total  
amount
collected varies.  
For example,  
in December  
2025, the  
FDIC reduced  
the rate  
at which  
the assessment  
is collected  
for the  
eighth
quarter of the collection period, with an invoice  
payment date of March 30, 2026, due  
to its updated estimate of losses.
We  
are generally  
unable to  
control the  
amount of  
premiums or  
additional assessments  
that we  
are required  
to pay  
for
FDIC insurance. If there  
are additional bank or financial  
institution failures, our level of  
non-performing assets increases, or our  
risk
profile changes  
or our  
capital position  
is impaired,  
we may  
be required  
to pay  
even higher  
FDIC premiums.  
Any future  
additional
increases in  
FDIC premiums,  
assessment rates  
or special  
assessments may  
materially adversely  
affect our  
results of  
operations.
See the “Supervision  
and Regulation—FDIC Insurance” discussion  
in Item 1.  
Business of this  
Form 10-K for  
additional information
related to the FDIC’s deposit insurance assessments applicable  
to BPPR and PB.  

The resolution of pending litigation and regulatory proceedings, if unfavorable to us, could have material adverse financial
effects or cause us significant reputational  
harm, which, in turn, could seriously harm  
our business prospects.
We  
face  
legal  
risks  
in  
our  
businesses,  
and  
the  
volume  
of  
claims  
and  
amount  
of  
damages  
and  
penalties  
claimed  
in
litigation and regulatory proceedings against financial institutions  
remains high. We are involved  
in a number of litigation,  
arbitration
and regulatory proceedings  
in the  
ordinary course of  
our business. Substantial  
legal liability or  
significant regulatory action  
against
us could have material  
adverse financial effects or cause significant  
reputational harm to us or  
other adverse consequences, which
in turn could seriously harm our business prospects. For further information relating to our legal risk, see Note 23 - “Commitments &
Contingencies”, to the Consolidated Financial Statements  
in this Form 10-K.
LIQUIDITY RISKS
We  
are subject  
to liquidity  
risks arising  
from market  
events or  
disruptions and  
instances of  
low  
investor and  
depositor
confidence. Furthermore, actions by the rating agencies  
or decreases in our capital levels may have adverse  
effects on our
liquidity and business, including by raising the  
cost of our obligations or affecting our ability  
to borrow.  

33
We must  
maintain adequate liquidity  
and funding sources  
to support  
our operations, fund  
customer deposit withdrawals,
repay  
borrowings  
and  
debt,  
comply  
with  
our  
financial  
obligations,  
fund  
planned  
capital  
distributions  
and  
meet  
regulatory
requirements.  
The  
Corporation’s  
most  
significant  
source  
of  
funds  
are  
bank  
deposits,  
including  
customer  
deposits  
and  
brokered
deposits.  
In  
addition  
to  
deposits,  
sources  
of  
liquidity  
include  
secured  
borrowing  
arrangements,  
such  
as  
those  
with  
the  
Federal
Reserve Bank of  
New York  
and the Federal  
Home Loan Bank  
of New York  
(“FHLBNY”), unpledged securities from  
our investment
portfolio, the capital markets and proceeds from loan  
sales or securitizations.  

Popular’s  
liquidity  
and  
ability  
to  
fund  
and  
operate  
its  
business  
could  
be  
materially  
adversely  
affected  
by  
a  
variety  
of
conditions and  
factors, some  
of which  
are out  
of Popular’s control.  
For example,  
market events  
or disruptions,  
such as  
periods of
market stress and  
low investor confidence in  
financial institutions could result  
in deposit withdrawals, especially  
to the extent  
those
deposits are in  
excess of the  
FDIC-insured limit of  
$250,000. As of  
December 31, 2025,  
we had $14  
billion of total  
deposits (other
than collateralized  
public funds,  
which represent  
public deposit  
balances from  
governmental entities  
in the  
U.S. and  
its territories,
including Puerto Rico  
and the  
United States Virgin  
Islands, that are  
collateralized based on  
such jurisdictions’  
applicable collateral
requirements) in excess of  
the FDIC-insured limit. We  
may also suffer outflows  
of customer deposits due  
to competition from  
other
banks or  
alternative investments. In  
addition, in  
periods of  
stress, we  
may not  
be able  
to access  
existing funding sources,  
access
the capital markets or to sell or securitize loans or  
other assets, or to access such sources or to  
sell or securitize assets on favorable
terms.
In addition, actions  
by the rating agencies  
could raise the cost  
of our borrowings, since  
lower rated securities are  
usually
required by the  
market to pay  
higher rates than  
obligations of higher credit  
quality. Our  
credit ratings were  
reduced substantially in
2009 and, although one of  
the three major rating agencies upgraded our  
senior unsecured rating back to  
“investment grade” during
2021,  
the  
remaining  
two  
rating  
agencies  
have  
not  
upgraded  
their  
current  
“non-investment  
grade”  
rating.  
The  
market  
for  
non-
investment  
grade securities  
is  
much  
smaller  
and  
less  
liquid than  
for investment  
grade securities.  
If  
we  
were to  
attempt  
to  
issue
preferred stock  
or debt  
securities into  
the capital  
markets, it  
is possible  
that there  
would not  
be sufficient  
demand to  
complete a
transaction or  
that the  
cost could  
be substantially  
higher than  
for more  
highly rated  
securities. If  
Popular is  
unable to  
access the
capital markets on favorable terms, our liquidity  
may be adversely affected.
Changes in our ratings and capital levels could affect our  
relationships with some creditors and limit our  
access to funding.
For example,  
having negative  
tangible capital  
may impact  
our ability  
to  
access some  
sources of  
wholesale funding.  
The Federal
Housing Finance  
Agency restricts the  
FHLBNY from  
lending to  
members of  
the FHLBNY  
with negative  
tangible capital  
unless the
member’s primary banking regulator makes a written request to the  
FHLBNY to maintain access to borrowings. Both BPPR  
and PB
have secured borrowing facilities with the FHLBNY and  
could borrow up to $3.3 billion  
and $1.5 billion respectively as of  
December
31, 2025,  
of which  
$42.7 million  
and $0.8  
billion respectively  
were used.  
Losing access  
to the  
FHLBNY borrowing  
facilities could
adversely  
impact  
liquidity  
at  
the  
banking  
subsidiaries.  
Additionally,  
if  
BPPR  
or  
PB  
cease  
to  
be  
well-capitalized,  
the  
FDIA  
and
regulations  
adopted  
thereunder  
would  
restrict  
their  
ability  
to  
accept  
brokered  
deposits  
and  
limit  
the  
rate  
of  
interest  
payable  
on
deposits.
Our banking  
subsidiaries also  
have recourse  
obligations under certain  
agreements with  
third parties,  
including servicing
and custodial agreements, that include ratings covenants. Upon failure to maintain the required credit ratings,  
the third parties could
have  
the  
right  
to  
require  
us  
to  
engage  
a  
substitute  
fund  
custodian  
and  
increase  
collateral  
levels  
securing  
recourse  
obligations.
Collateral  
pledged by  
us  
to  
secure  
recourse  
obligations approximated  
$23.8 million  
on  
December 31,  
2025.  
While management
expects that we would be able to meet any additional  
collateral requirements if and when needed, the requirements  
to post collateral
under certain agreements or the loss of custodian  
funds could reduce our liquidity resources and  
impact our results of operations.  

As a bank holding company, we depend on dividends and distributions  
from our subsidiaries for liquidity.
As a bank holding company,  
we depend primarily on dividends from  
our banking and other operating subsidiaries  
to fund
our cash needs, including to capitalize our subsidiaries. Our banking subsidiaries, BPPR and PB, are limited by law in their ability to
make dividend  
payments and other  
distributions to  
us based  
on their earnings,  
dividend history,  
and capital  
position. Based on  
its
current financial condition,  
PB may  
not declare or  
pay a  
dividend without the  
prior approval of  
the Federal Reserve  
Board and  
the
NYSDFS. A  
failure by  
our banking subsidiaries  
to generate  
sufficient income  
and free  
cash flow to  
make dividend  
payments to  
us
may  
affect  
our  
ability to  
fund  
our cash  
needs, which  
could have  
a negative  
impact on  
our financial  
condition, liquidity,  
results  
of
operation or capital position. Such failure could also affect  
our ability to pay dividends to our stockholders and to  
repurchase shares
of our common stock. We have in the past suspended dividend payments  
on our common stock and preferred stock during times of
economic uncertainty,  
and there  
can be  
no assurance  
that we  
will be  
able to  
continue to  
declare dividends to  
our stockholders  
in
any future periods.  

34
An  
impact  
on  
the  
tangible  
capital  
levels  
of  
our  
operating  
subsidiaries,  
could  
also  
limit  
the  
amount  
of  
capital  
we  
may
upstream to the holding company. Tangible  
capital levels have in the past been, and may in the future be,  
adversely affected by the
impact of  
rapidly rising interest  
rates on investment  
securities in our  
available-for-sale portfolio. For  
a discussion of  
risks related to
changes in interest  
rates, see “Changes  
in interest rates  
and credit spreads  
can adversely impact  
our financial condition,  
including
our investment portfolio, since a significant portion of  
our business involves borrowing and lending money,  
and investing in financial
instruments” in Item 1A of this Form 10-K.
We also depend  
on dividends from our  
banking and other operating subsidiaries  
to pay debt service  
on outstanding debt
and to repay maturing debt. Our ability to  
declare such dividends would be subject to regulatory requirements and could  
require the
prior approval of the Federal Reserve Board.
STRATEGIC RISKS
Potential acquisitions of businesses or  
loan portfolios could increase some  
of the risks that  
we face, and may  
be delayed
or prohibited due to regulatory constraints.
To  
the extent  
permitted by  
our applicable  
regulators, we  
may pursue  
strategic acquisition  
opportunities. Acquiring  
other
businesses, however, involves various risks,  
including potential exposure to unknown or contingent liabilities of the  
target company,
exposure  
to  
potential  
asset  
quality  
issues  
of  
the  
target  
company,  
potential  
disruption  
to  
our  
business,  
the  
possible  
loss  
of  
key
employees and customers of  
the target company,  
and difficulty in  
estimating the value of  
the target company.  
If we pay  
a premium
over book or  
market value in  
connection with an  
acquisition, some dilution of  
our tangible book  
value and net  
income per common
share may occur.  
Furthermore, failure to  
realize the expected  
revenue increases, cost savings,  
increases in geographic  
or product
presence, or  
other projected  
benefits from an  
acquisition could have  
a material  
adverse effect  
on our  
business, financial condition
and results of operations.
Similarly,  
acquiring  
loan  
portfolios  
involves  
various  
risks.  
When  
acquiring  
loan  
portfolios,  
management  
makes
assumptions and  
judgments about  
the collectability  
of the  
loans, including  
the creditworthiness  
of borrowers  
and the  
value of  
the
real  
estate and  
other assets  
serving  
as collateral  
for the  
repayment of  
secured loans.  
In  
estimating the  
extent of  
the losses,  
we
analyze  
the  
loan  
portfolio  
based  
on  
historical  
loss  
experience,  
volume  
and  
classification  
of  
loans,  
volume  
and  
trends  
in
delinquencies  
and  
nonaccruals,  
local  
economic  
conditions,  
and  
other  
pertinent  
information.  
If  
our  
assumptions  
are  
incorrect,
however,  
our actual  
losses could  
be higher  
than estimated  
and increased  
loss reserves  
may be  
required, which  
would negatively
affect our results of operations.
Finally, certain  
acquisitions by financial institutions,  
including us, are  
subject to approval  
by a variety  
of federal and  
state
regulatory agencies.  
Regulatory approvals  
could be  
delayed, impeded,  
restrictively conditioned  
or denied.  
We may  
fail to  
pursue,
evaluate  
or  
complete  
strategic  
and  
competitively  
significant  
acquisition  
opportunities  
as  
a  
result  
of  
our  
inability,  
or  
perceived  
or
anticipated inability,  
to obtain regulatory  
approvals in a  
timely manner,  
under reasonable conditions or  
at all. Difficulties  
associated
with  
potential  
acquisitions  
that  
may  
result  
from  
these  
factors  
could  
have  
a  
material  
adverse  
effect  
on  
our  
business,  
financial
condition and results of operations.
We  
continue our  
broad-based multi-year,  
technological and  
business process  
transformation. The  
failure to  
achieve the
goals of the transformation project, the inability to maintain expenses related to our transformation program within current
estimates  
or  
delays  
in  
executing  
our  
plans  
may  
materially  
and  
adversely  
affect  
our  
business,  
competitive  
position,
financial condition, results of operations, or  
cause reputational harm.
The  
Corporation  
continues  
its  
broad-based  
multi-year,  
technological  
and  
business  
process  
transformation,  
which  
was
launched in  
2022. As  
part of  
this transformation,  
we are  
making significant  
investments in  
technology,  
talent and  
new digital  
and
data capabilities in order to provide our customers with more personalized and accessible services, increase employee  
performance
and satisfaction with more agile work processes,  
and generate sustainable profitable growth and  
value for our shareholders.  

We may not succeed in executing all projects or aspects of the transformation  
program, may abandon projects or aspects,
or fail to successfully launch new applications or achieve the intended  
functionality and operational benefits from these technological
initiatives, which could  
result in failed  
or partially successful  
implementations. In addition,  
we may fail  
to properly estimate  
costs of
the  
transformation  
program  
or  
may  
experience  
delays  
in  
executing  
our  
plans.  
Such  
failures  
or  
delays  
may  
in  
turn  
cause  
the
Corporation to  
incur costs  
exceeding our  
current  
estimates or  
disrupt our  
operations, including  
our technological  
services  
to  
our
customers,  
or  
fall  
short  
of  
our  
projected earnings  
or  
expense reduction  
targets  
driven  
by  
these  
efforts.  
To  
the  
extent that  
these
disruptions  
persist  
over  
time  
and/or recur,  
this  
could  
negatively  
impact  
our  
competitive  
position,  
require additional  
expenditures,

35
and/or harm our relationships with  
our customers and thus may  
materially adversely affect our  
business, financial condition, results
of operations, or cause reputational harm.
We face  
significant and  
increasing competition in  
the rapidly  
evolving financial services  
industry,  
and face  
challenges in
the adoption of new technologies such as  
artificial intelligence which may put us at a  
competitive disadvantage.
We  
operate  
in  
a  
highly competitive  
environment, in  
which  
we  
compete  
on  
the  
basis  
of  
a  
number of  
factors,  
including
customer service,  
quality and variety  
of products  
and services,  
price, interest rates  
on loans  
and deposits,  
innovation, technology,
ease of use, reputation, and transaction execution. While our main competition  
continues to come from other Puerto Rico banks and
financial institutions, we  
face increased competition  
from non-Puerto Rico  
institutions, as emerging  
technologies and the  
growth of
e-commerce  
have  
significantly  
reduced  
geographic  
barriers.  
These  
technologies  
have  
also  
made  
it  
easier  
for  
non-depositary
institutions to  
offer products  
and services  
that were  
traditionally considered  
banking products  
and allowed  
non-traditional financial
service providers  
and technology  
companies to  
provide electronic  
and internet-based  
financial solutions  
and services.  
In addition,
nonbank  
firms  
may  
have  
a  
competitive  
advantage  
over  
traditional  
banks  
and  
bank  
holding  
companies  
such  
as  
Popular  
due  
to
factors  
such  
as  
differences  
in  
regulation,  
funding  
models  
and  
tax  
treatment.  
We  
may  
also  
be  
unable  
to  
adopt  
or  
integrate  
new
technologies  
that  
could  
reduce  
expenses  
and  
simplify  
our  
operations,  
including  
artificial intelligence,  
automation  
and  
algorithmic
tools,  
at  
the  
pace  
of  
such  
competitors  
due  
to  
operational  
and  
compliance  
challenges  
and  
risks  
relating  
to  
data  
quality,  
internal
controls, privacy and consumer protection, among others.  
Our failure to successfully adopt and  
integrate these new technologies in
a  
timely  
and  
effective  
manner may  
impair our  
ability to  
compete effectively  
or to  
attract or  
retain business.  
Moreover,  
increased
competition could create pressure to lower prices, fees, commissions or  
credit standards on our products and services, which could
adversely affect our  
financial condition and results  
of operations. Increased competition could  
also create pressure to  
raise interest
rates  
on deposits  
or increase  
deposit attrition,  
which could  
negatively impact  
our business,  
financial condition,  
liquidity results  
of
operations or capital position.
If we are unable to  
meet constant technological changes and react quickly to  
meet new industry standards, including as a
result  
of our  
continued dependence  
on  
Evertec, we  
may  
be unable  
to enhance  
our  
current services  
and introduce  
new
products and  
services in  
a timely  
and cost-effective  
manner,  
placing us  
at a  
competitive disadvantage  
and significantly
affecting our business, financial condition, liquidity, results of operations  
or capital position.
To compete effectively,  
we need to constantly enhance and modify our products and services and introduce new products
and  
services  
to  
attract  
and  
retain  
clients  
or  
to  
match  
products  
and  
services  
offered  
by  
our  
competitors,  
including  
technology
companies  
and  
other  
nonbank firms  
that  
are  
engaged in  
providing similar  
products  
and services,
some  
of  
which are  
or  
may  
be
provided by Evertec  
itself.  
Our ability to  
compete effectively will  
depend in part  
on our  
ability to  
react quickly to  
meet new industry
standards  
and  
use  
new  
technology,  
such  
as  
artificial  
intelligence,  
to  
satisfy  
customer  
demands,  
as  
well  
as  
to  
create  
additional
efficiencies in our operations. Popular expects that it will continue to depend  
on Evertec’s technology services to operate and control
current products and services and to implement future products and services, making  
our success dependent on Evertec’s ability to
timely complete and introduce these enhancements and  
new products and services in a cost-effective  
manner.  

Some  
of  
our  
competitors  
rely  
on  
financial  
services  
technology  
and  
outsourcing  
companies  
that  
are  
much  
larger  
than
Evertec, serve a  
greater number of  
clients than Evertec,  
and may have  
better technological capabilities and  
product offerings than
Evertec.  
Furthermore,  
financial  
services  
technology  
companies  
typically  
make  
capital  
investments  
to  
develop  
and  
modify  
their
product  
and  
service  
offerings  
to  
facilitate  
their  
customers’  
compliance  
with  
the  
extensive  
and  
evolving  
regulatory  
and  
industry
requirements, and,  
in most  
cases, such  
costs are  
borne by  
the technology  
provider.  
Because of  
our contractual  
relationship with
Evertec, and because Popular is the sole  
customer of certain of Evertec’s services  
and products,
including core bank processing of
BPPR, we have  
in the past borne  
the full cost  
of such developments and  
modifications and may be  
required to do so  
in the future,
subject to the terms of the MSA.
Moreover,  
the terms,  
speed, scalability,  
and functionality  
of certain  
of Evertec’s  
technology services  
are not  
competitive
when compared  
to offerings  
from its  
competitors. Evertec’s  
failure to  
sufficiently invest  
in and  
upscale its  
technology and  
services
infrastructure to  
meet the  
rapidly changing  
technology demands  
of our  
industry may  
result in  
our being  
unable to  
meet customer
expectations and  
attract or  
retain customers.  
Furthermore, Evertec’s  
strategy and  
investments may  
also be  
refocused away  
from
Popular towards other strategic  
initiatives,
potentially including initiatives that could  
have the effect  
of disintermediating us from  
our
customers  
or  
otherwise  
present  
a  
competitive  
risk.  
Any  
such  
impact  
could,  
in  
turn,  
reduce  
Popular’s  
revenues,  
place  
us  
at  
a
competitive disadvantage and significantly  
affect our business,  
financial condition, liquidity,  
results of operations  
or capital position.
While we  
have over time  
narrowed the scope  
of services which  
we are  
dependent on Evertec  
to obtain, in  
exchange for obtaining
releases  
in  
2022  
from  
exclusivity restrictions  
that  
limited  
our  
ability  
to  
engage  
other  
third-party  
providers  
of  
financial  
technology
services, we  
agreed to  
extensions of  
certain existing  
commercial agreements  
with Evertec  
and, as  
a result,  
have prolonged  
the

36
duration of  
our exposure to  
the risks  
presented by Evertec’s  
technological capabilities and  
its failures  
to enhance  
its products  
and
services  
and  
otherwise  
meet  
evolving  
demands.  
We  
may  
also  
be  
exposed  
to  
heightened  
business  
risks  
in  
connection  
with  
our
dependency on Evertec with  
respect to BPPR’s merchant  
acquiring business, which exclusivity runs  
until 2035, and with  
respect to
the ATH  
Network, which commitment  
runs until  
2030, in  
light of  
the pace  
of technology changes  
and competition in  
the payments
industry.
The ability to attract and retain qualified employees  
is critical to our success.
Our  
success  
depends,  
in  
large  
part,  
on  
our  
ability  
to  
attract  
and  
retain  
qualified  
employees.  
Competition  
for  
qualified
candidates,  
especially in  
the  
area of  
information technology,  
is  
intense  
and  
has  
increased  
recently as  
a  
result  
of  
a  
tighter  
labor
market.  
Increased  
competition  
may  
lead  
to  
difficulties  
in  
attracting  
or  
retaining  
qualified  
employees, which  
may,  
in  
turn,  
lead  
to
significant challenges in the execution of our business strategies  
and have an adverse effect on the quality of the service we provide
to  
the  
customers  
and  
communities  
we  
serve.  
Such  
challenges  
could  
adversely  
affect  
our  
business,  
operations  
and  
financial
condition. In addition, increased competition  
may lead to higher compensation  
packages and more flexible work  
arrangements. We
may also be required to hire employees outside of  
our market areas for certain positions that require specific expertise,  
which could
result in  
employment and tax  
compliance-related expenses, challenges  
and risks. In  
addition, flexible work  
arrangements, such as
remote or hybrid work  
models, have led to  
other workplace challenges, including fewer opportunities for  
face-to-face interactions or
to promote a cohesive corporate culture and heightened  
cybersecurity, information security and other operational risks.
Our  
ability  
to  
attract  
and  
retain  
qualified  
employees  
is  
also  
impacted  
by  
regulatory  
limitations  
on  
our  
compensation
practices, such as clawback requirements of incentive compensation, which may not affect other institutions with which we compete
for talent.  
The scope  
and content of  
regulators’ policies  
on executive compensation  
continue to  
develop and are  
likely to  
continue
evolving. Such policies and limitations on our compensation  
practices could adversely affect our ability to attract, retain and motivate
talented senior leaders in support of our long-term  
strategy.
OTHER RISKS
An impairment  
of our  
goodwill, deferred  
tax assets  
or amortizable  
intangible assets  
could adversely  
affect our  
financial
condition and results of operations.
As of December  
31, 2025, we  
had $790 million,  
$814 million and  
$188 million, respectively,  
of goodwill, net  
deferred tax
assets and amortizable intangible assets, including  
capitalized software costs, recorded on our balance  
sheet.
Under  
GAAP,  
goodwill  
is  
tested  
for  
impairment  
at  
least  
annually  
and  
amortizable  
intangible  
assets  
are  
tested  
for
impairment  
when  
events  
or  
changes  
in  
circumstances indicate  
the  
carrying value  
may  
not  
be  
recoverable. Factors  
that  
may  
be
considered a change in circumstances, indicating that the carrying value of the goodwill or amortizable intangible assets may not be
recoverable, include  
a decline in  
Popular’s stock price  
related to  
a deterioration in  
global or  
local economic conditions,  
declines in
our market capitalization, reduced future earnings estimates, and interest rate changes. The goodwill impairment evaluation process
requires  
us  
to  
make  
estimates  
and  
assumptions  
with  
regards  
to  
the  
fair  
value  
of  
our  
reporting  
units.  
Actual  
values  
may  
differ
significantly  
from  
these  
estimates.  
Such  
differences  
could  
result  
in  
future  
impairment  
of  
goodwill  
that  
would,  
in  
turn,  
negatively
impact our results of operations and the reporting  
unit where the goodwill is recorded.
The  
determination  
of  
whether  
a  
deferred  
tax  
asset  
is  
realizable  
is  
based  
on  
weighting  
all  
available  
evidence.  
The
realization  
of  
deferred  
tax  
assets, including  
carryforwards  
and  
deductible temporary  
differences,  
depends upon  
the  
existence  
of
sufficient taxable  
income of the  
same character during  
the carryback or  
carryforward period. The  
analysis considers all  
sources of
taxable income  
available to  
realize the  
deferred tax  
asset, including  
the future  
reversal of  
existing taxable  
temporary differences,
future taxable income  
exclusive of reversing temporary  
differences and carryforwards,  
taxable income in  
prior carryback years  
and
tax-planning strategies. Changes in these  
factors may affect  
the realizability of our  
deferred tax assets in  
our Puerto Rico and  
U.S.
operations.
If our  
goodwill, deferred  
tax assets  
or amortizable  
intangible assets  
become impaired,  
we may  
be required  
to record  
a
significant charge to earnings, which could adversely  
affect our financial condition and results of operations.
We could experience unexpected  
losses if the estimates  
or assumptions we use  
in preparing our financial  
statements are
incorrect or differ materially from actual results.  

In preparing  
our financial  
statements pursuant to  
U.S. GAAP,  
we are  
required to  
make estimates  
and assumptions  
that
are often based  
on subjective and  
complex judgments about  
matters that are  
inherently uncertain. For example,  
we use estimates
and assumptions to determine our allowance for credit losses, our  
liability for contingent litigation losses, and the fair value of certain

37
of our  
assets and  
liabilities, such  
as debt  
securities, loans  
held for  
sale, MSRs,  
intangible assets  
and deferred  
tax assets.  
If such
estimates  
or  
assumptions are  
incorrect  
or  
differ  
materially  
from  
actual  
results,  
we  
could  
experience  
unexpected  
losses  
or  
other
adverse impacts, some of which could be significant.
For further information on other risks faced by  
Popular please refer to the MD&A section of  
this Form 10-K.
ITEM 1B. UNRESOLVED STAFF COMMENTS
None.
Item 1C. Cybersecurity
The  
Corporation  
assesses,  
identifies  
and  
manages  
cybersecurity  
risk  
as  
part  
of  
the  
Corporation’s  
overall  
risk  
management
framework, alongside  
associated information  
security,  
anti-money laundering  
and counterterrorism,  
operational, fraud,  
regulatory,
legal and reputational risks, among others.  

The Corporation has established three management  
committees that oversee and monitor different aspects of  
cybersecurity risk.
●
 
The  
Enterprise Risk  
Management Committee  
(the “ERM  
Committee”), chaired  
by  
the Chief  
Risk Officer,  
oversees and
monitors  
the  
risks  
included  
in  
the  
Risk Appetite  
Statement  
(the  
“RAS”)  
of  
the  
Corporation’s  
Risk  
Management  
Policy,
including cybersecurity risks.  

●
 
The Information  
Technology and  
Cyber Risk  
Committee (“ITCRC”),  
chaired by  
the Chief  
Security  
Officer and  
the Chief
Information and  
Digital Strategy  
Officer, oversees  
and monitors  
information technology  
(“IT”), privacy  
and cybersecurity
risks, mitigating  
actions and  
controls, applicable  
regulatory developments, key  
risks metrics,  
and IT  
and cyber  
incidents
that may result in operational, compliance and reputational  
risks.
●
 
The  
Operational  
Risk  
Committee (“ORCO”),  
chaired  
by  
the  
Chief Risk  
Officer,  
oversees  
and  
monitors  
operational  
risk
management activities  
to ensure  
the development  
and consistent  
application of  
operational risk  
policies, processes  
and
procedures that  
measure, limit  
and manage  
the Corporation's  
operational risks  
while maintaining  
the effectiveness  
and
efficiency  
of  
the  
operating and  
business  
processes. As  
part  
of  
its  
responsibilities, ORCO  
oversees business  
continuity
matters, as well as operational losses stemming  
from any cybersecurity or fraud events.

The ITCRC and ORCO meet at least quarterly  
and report on cybersecurity and other matters  
to the ERM Committee.

The  
Board  
has  
established  
a  
Board-level  
Risk  
Management  
Committee  
(“RMC”),  
which  
is  
responsible  
for  
the  
oversight  
of  
the
Corporation’s overall risk framework, and assists the Board in the monitoring, review and approval of the policies that measure, limit
and manage the Corporation’s risks, including cybersecurity  
risk. The RMC holds periodic meetings in  
which management provides
an  
overview of  
Popular’s cybersecurity  
threat  
risk management  
and strategy  
processes,  
which includes  
summaries  
of  
escalated
incidents  
and  
incident  
remediation  
status.  
Our  
Chief  
Security  
Officer,  
Chief  
Information  
and  
Digital  
Strategy  
Officer,  
Chief
Information Security Officer  
(“CISO”), Chief Risk  
Officer and the  
Financial and Operational  
Risk Management Division  
(the “FORM
Division”)  
Manager  
generally  
participate  
in  
such  
meetings.  
The  
RMC  
is  
also  
responsible  
for  
(i)  
overseeing  
the  
development,
implementation  
and  
maintenance  
of  
the  
Corporation’s  
information  
security  
program  
(the  
“Information  
Security  
Program”);  
(ii)
approving the Corporation’s risk management program  
and any related policies and controls;  
(iii) overseeing the implementation by
the Corporation’s  
management of  
the Corporation’s  
risk management  
program and  
any related  
policies, procedures  
and controls;
(iv)  
overseeing the  
Corporation’s risk  
management with  
respect to  
emerging technologies,  
including artificial  
intelligence;  
and (v)
reviewing reports regarding selected topics such as  
cyber.
In addition, the  
Board also has  
a standing Technology  
Committee (the “TC”)  
that oversees the  
Corporation’s technology functions,
strategy, operations, investments and needs.  
The TC meets at least quarterly and  
our Chief Information and Digital Strategy Officer
and our Chief  
Security Officer  
generally participate in  
such meetings. The  
TC (i) oversees  
the development and  
implementation of
the Corporation’s technology  
strategy and initiatives,  
(ii) monitors the  
risks associated with  
critical technology vendor  
relationships,
including  
cyber  
risks,  
and  
(iii)  
reviews  
and  
receives  
reports  
from  
management  
and  
third  
parties  
regarding  
the  
Corporation’s
technology  
functions,  
operations,  
strategy  
and  
initiatives,  
as  
well  
as  
current  
and  
emerging  
technology  
trends  
and  
risks  
arising
therefrom.

The Board in turn also receives briefings on cybersecurity matters and risks, including an annual presentation from the Chief

38
Security  
Officer  
and  
the  
CISO  
on  
the  
Information  
Security  
Program.

In  
addition,  
as  
part  
of  
the  
Board’s  
director  
education  
plan,
members of the  
Board take, on  
an annual basis,  
a cybersecurity training that  
provides the Board with  
an overview of  
cybersecurity
principles and regulations that are relevant to our institution  
and the Board’s oversight function.

To identify, assess and manage risks from cybersecurity threats, the Corporation has established a three lines of defense
framework. The first line of defense is composed of business line management that identifies and manages the risks associated with
business activities, including cybersecurity risk. The second line of defense is made up of members of the Corporation’s Corporate
Risk Management Group and the Corporate Security and Operations Group (the “CSOG”) who, among other things, measure and
report on the Corporation’s risk activities. In such line of defense, the FORM Division, within the Corporate Risk Management
Group, is responsible for (i) establishing baseline metrics that measure, monitor, limit and manage the framework that identifies and
manages multiple and cross-enterprise risks, including cybersecurity risks; and (ii) articulating the RAS and supporting metrics,
including those related to operational risk, business continuity, disaster recovery and third-party management oversight processes.
Meanwhile, Popular’s Corporate Information Security and Privacy Division (the “CISP”), which is headed by the CISO and reports to
the CSOG, is responsible for the development of strategies, policies and programs to assess and mitigate cybersecurity and privacy
risks. Members of the CISP (including the CISO) and FORM Division report on and escalate cybersecurity, IT and privacy risks to
management committees, such as the ITCRC, ORCO and ERM Committees, and, if appropriate, to the RMC, TC, and the Board of
Directors, as required under relevant policies and procedures. Lastly, the third line of defense consists of the Corporate Auditing
Division, which independently provides assurance regarding the effectiveness of the risk framework and reports directly to the Audit
Committee of the Board.

Popular monitors various vectors of threats and utilizes open-source intelligence forums and communities such as the Financial
Services Information Sharing and Analysis Center and the Cybersecurity and Infrastructure Security Agency, among others, to
receive threat intelligence feeds which are reviewed by the CISP. As cybersecurity threats are identified, they are evaluated to
assess the level of exposure and the potential risk to Popular. The ITCRC and the ERM Committee discuss and track the threats
identified in internal assessments and scans or in third-party reports. Depending on the evolution and materiality of the threat, these
are escalated to the RMC as appropriate.

The CISP  
develops the Information  
Security Program, which  
considers and evaluates  
risks posed by  
cybersecurity threats, events
and  
activities  
impacting  
the  
industry  
and  
the  
Corporation.  
The  
Information  
Security  
Program  
outlines  
the  
Corporation’s  
overall
strategy and  
governance to  
protect the  
confidentiality,  
integrity and  
availability of  
information and  
prevent access  
by unauthorized
personnel, and is based on standards and controls set by the National Institute of Standards and Technology  
(“NIST”), including the
NIST’s Framework for  
Improving Critical Infrastructure  
Cybersecurity. Popular  
currently leverages the  
Cyber Assessment Tool  
(the
“CAT”), a tool based on NIST standards and controls developed by the Federal Financial Institutions  
Examination Council (“FFIEC”),
in order to measure the  
Corporation’s cybersecurity preparedness and maturity levels.  
The CAT  
assessment results are integrated
into the overall Information  
Security Program evaluation. In  
2025, we began the  
transition to the Cyber  
Risk Institute (“CRI”) Profile
2.0  
assessment  
framework,  
following  
the  
announcement  
by  
the  
FFIEC  
of  
the  
sunset  
of  
the  
CAT.  
The  
transition  
to  
the  
CRI
framework is  
expected to be  
completed in  
2026. The CRI  
Profile was  
produced through public-private  
collaboration and is  
a list  
of
assessment  
questions  
curated  
based  
on  
the  
intersection  
of  
global  
regulations  
and  
cyber  
standards,  
such  
as  
the  
International
Standards Organization (ISO) and the NIST.  

The CISP also  
manages the Incident  
Response Program (“IRP”)  
of the Corporation  
and is in  
charge of overseeing,  
assessing and
managing cyber  
incidents. The  
IRP outlines  
the measures  
Popular must  
take to  
prepare for,  
detect, respond  
to and  
recover from
cybersecurity  
incidents,  
which  
include  
processes  
to  
triage,  
assess  
severity  
for,  
escalate,  
contain,  
investigate  
and  
remediate
incidents, as well as to comply with potentially  
applicable legal obligations and mitigate brand  
and reputational damage.  

The Corporation also undertakes the below listed  
additional activities in its effort  
to maintain regulatory compliance, identify,  
assess
and manage its material risks from cybersecurity  
threats, and to protect against, detect and  
respond to cybersecurity incidents:  

●
 
Conduct  
tabletop  
exercises  
that  
simulate  
cybersecurity  
incidents  
to  
raise  
awareness  
and  
enhance  
Popular’s  
responsive
measures;
●
 
Assess how business  
and corporate strategies, new  
products, technology deployments, external  
events and the  
evolution of
threats impact  
the Corporation’s  
information security  
controls in  
order to  
determine if  
they require  
any additional  
resources,
technology or processes;
●
 
Discuss cybersecurity risks with law enforcement, peer  
groups, industry forums and trade associations;

39
●
 
Provide training  
to all  
Popular employees  
upon hiring  
and annually  
thereafter on  
cybersecurity and  
customer data  
handling
and use requirements;
●
 
Offer training and awareness campaigns to customers and employees  
based on their role;  

●
 
Conduct  
phishing  
simulations  
for  
employees,  
with  
escalation  
protocols  
for  
employees  
that  
fail  
such  
tests  
to  
enhance
awareness and responsiveness to such possible  
threats;
●
 
Offer learning and development opportunities to employees  
who handle and manage cybersecurity matters;
●
 
Carry cyber insurance to provide protection against  
potential losses arising from cybersecurity incidents;  
and
●
 
Monitor emerging  
legal and  
regulatory requirements  
and implement  
changes to  
our processes,  
policies and  
statements, as
necessary.

Popular engages third parties to assist in certain cybersecurity matters.
In particular, Popular uses the expertise of third parties to
perform specialized assessments to test its systems, such as periodic penetration testing, that provide insights into the effectiveness
of its controls. Popular also engages third parties to provide computer forensics and investigations services as needed to assess
and address actual or potential cybersecurity incidents. In addition, Popular hires third parties to provide the first level security
monitoring of Popular’s external and internal networks.
 

Popular’s Third Party Risk Management Policy outlines the management of risks associated with  
the Corporation’s use of third-party
service  
providers,  
and  
the  
CSOG  
assesses  
the  
impact  
and  
level  
of  
cybersecurity  
and  
privacy  
risk  
of  
such  
providers.  
Popular
performs due diligence on  
third parties and monitors third  
parties that have access to  
its systems, data or facilities  
that house such
systems or data on a  
periodic basis, and based on due  
diligence results, determines how often vendor assessments are  
performed
on such third party.  
Popular also conducts periodic application and vendor assessments for third-party providers  
and their products.
Furthermore, Popular requires third parties that have  
access to its systems, data or facilities that house  
such systems or data to take
a training on cybersecurity at least annually.
For a  
description of how  
identified cybersecurity threats  
may affect Popular’s  
business strategy or  
results, see under  
the headings
“We  
and  
our third-party  
providers have  
been, and  
expect in  
the future  
to continue  
to  
be, subject  
to  
cyber-attacks. Future  
cyber-
attacks could cause substantial harm and have  
an adverse effect on our business  
and results of operations.” and “We  
rely on other
companies to  
provide key components  
of our  
business infrastructure, including  
certain of  
our core financial  
transaction processing
and information  
technology and  
security services,  
which exposes  
us to  
a number  
of  
operational risks  
that could  
have a  
material
adverse  
effect  
on  
us.”,  
included  
as  
part  
of  
our  
risk  
factor  
disclosures  
in  
Item  
1A  
in  
this  
Form  
10-K,  
which  
disclosures  
are
incorporated by reference herein.
To date, previous cybersecurity incidents have not materially affected our results of operations or
financial condition.

The CSOG  
operates under the  
direction of the  
Chief Security  
Officer.  
The Chief  
Security Officer  
has over  
37 years  
of experience,
including over 13 years of  
professional experience in information technology and cybersecurity matters such  
as the oversight of the
Information  
Security  
Program  
and  
the  
design  
and  
execution  
of  
the  
information  
security  
audit  
plan  
of  
the  
Corporation.

 
She  
is  
a
Certified Public Accountant and also holds a Juris Doctor degree and FINRA administered  
Series 7 and Series 27 certifications. She
holds the title  
of Executive Vice  
President and Chief Security  
Officer and has been  
in her role  
since 2018. Prior to  
that, she served
as Senior  
Vice President  
and General  
Auditor of  
the Corporation  
from November  
2012 to  
April 2018.  
Before 2012,  
she served  
in
various risk  
related functions of  
the Corporation and  
as the Chief  
Operating Officer  
and Chief Financial  
Officer of  
Popular’s broker
dealer business.

The  
CISO  
has  
over  
30  
years  
of  
work  
experience.  
She  
holds  
the  
title  
of  
Senior  
Vice  
President  
and  
Corporate  
Chief  
Information
Security  
Officer and  
assumed this  
role in  
January 2026.  
Prior to  
this role,  
since 2022,  
she  
served as  
Senior Vice  
President and
Financial  
and  
Operational  
Risk  
Management  
Division  
Manager,  
with  
oversight  
of  
the  
enterprise  
and  
operational  
risks  
of  
the
Corporation. Before 2022, she held  
positions for 18 years as  
Operational and IT Risk Director,  
Head of ERM and Operational  
Risk,
and Chief  
Information Security  
Officer for  
other financial  
institutions. She  
holds a  
BBA with  
majors in  
Accounting and  
Information
Systems, and a Master of Science in Information  
Technology Management.

 

The Corporate Risk  
Management Group operates under  
the direction of  
the Chief Risk  
Officer. The  
Chief Risk Officer  
has over 32
years of work experience.

 
He holds the title of Executive Vice President and  
Chief Risk Officer and has been in  
his role since 2011.
Prior to  
joining the  
Corporation, he served  
for 17  
years as  
Chief Financial  
Officer,  
Head of  
Retail Bank  
and Mortgage  
Operations,
Head of Commercial and Construction Mortgage and  
Head of Interest Rate Risk, among  
other positions, for other banks.  
He holds
a BS with a major in Computer Engineering  
and an MBA with majors in Finance and  
Accounting.

 
 
 
 
 
 
 
 
 
 
 
 
40
The FORM Division Manager has over 30 years of work experience. She holds the title of Senior Vice President and FORM Division
Manager and has been in  
her role since January 2026.  
Prior to this role, since  
2018, she held the position  
of Senior Vice President
and  
Division  
Manager  
of  
the  
Corporate  
Risk  
Reviews  
Division  
reporting  
directly  
to  
the  
RMC.  
She  
has  
leadership  
experience  
in
treasury  
management,  
investment  
strategy  
and  
enterprise  
risk  
oversight.  
She  
holds  
a  
BSBA  
with  
majors  
in  
Finance  
and
International Business and an MBA with concentrations  
in Finance and Management.

ITEM 2. PROPERTIES
As of December 31, 2025, BPPR operated 162 branches, of which 67 were owned and 95 were leased premises, and PB
operated 39 branches  
of which 3  
were owned and  
36 were on  
leased premises. Also,  
the Corporation had  
582 ATMs  
operating in
Puerto Rico, 27 in the Virgin Islands  
and 97 in the U.S. Mainland. The principal properties owned by Popular  
for banking operations
and other services  
are described below.  
Our management believes that  
each of our  
facilities is well  
maintained and suitable  
for its
purpose.
Puerto Rico
Popular Center, the twenty-story Popular and BPPR headquarters building, located  
at 209 Muñoz Rivera Avenue, Hato Rey,  
Puerto
Rico.  

Popular Center North Building, a three-story building, on  
the same block as Popular Center.  

Popular Street Building, a parking and office building located  
at Ponce de León Avenue and Popular Street, Hato  
Rey, Puerto Rico.  

Cupey Center  
Complex,  
one building, three-stories  
high, two  
buildings, two-stories high  
each, and  
two buildings three-stories  
high
each located in Cupey, Río Piedras, Puerto Rico.  

Old San Juan Building, a twelve-story structure located  
in Old San Juan, Puerto Rico.  

Guaynabo Corporate Office Park Building, a two-story building  
located in Guaynabo, Puerto Rico.  

Altamira Building,  
a nine-story office building located in Guaynabo,  
Puerto Rico.  

El Señorial Center, a four-story office building and a two-story branch building  
located in Río Piedras, Puerto Rico.  

Ponce de León 167 Building, a five-story office building  
located in Hato Rey, Puerto Rico.
Muñoz Rivera 200, a ten-story building located  
in Hato Rey, Puerto Rico.
U.S. & British Virgin Islands
BPPR Virgin Islands Center, a three-story building located in St. Thomas,  
U.S. Virgin Islands.  

Popular Center -Tortola,  
a four-story building located in Tortola, British Virgin Islands.

41
ITEM 3. LEGAL PROCEEDINGS
For a discussion  
of Legal proceedings,  
see Note 23,  
“Commitments and Contingencies”, to  
the Consolidated Financial Statements
in this Form 10-K.
ITEM 4. MINE SAFETY DISCLOSURE
Not applicable.
PART II
ITEM  
5.  
MARKET  
FOR  
REGISTRANT’S  
COMMON  
EQUITY,  
RELATED  
STOCKHOLDER  
MATTERS  
AND  
ISSUER
PURCHASES OF EQUITY SECURITIES
Common Stock
Popular’s Common Stock is traded on  
the Nasdaq Global Select Market under the symbol “BPOP”.  

During 2025, the Corporation declared cash dividends in the  
total amount of $2.90 per common share outstanding,  
for an
aggregate amount of $196.2 million. The Common Stock ranks junior to all series of  
Preferred Stock as to dividend rights and rights
on liquidation,  
dissolution or  
winding up  
of Popular.  
Our ability  
to declare  
or pay  
dividends on,  
or purchase,  
redeem or  
otherwise
acquire, the Common  
Stock is subject  
to certain restrictions  
in the event  
that Popular fails  
to pay or  
set aside full  
dividends on the
Preferred Stock for the latest dividend period.
During the year ended  
December 31, 2025, the Corporation  
repurchased 4,660,124 shares of common stock  
for $501.5
million,  
at  
an  
average  
price  
of  
$107.61  
per  
common  
share,  
and  
during  
the  
year  
ended  
December  
31,  
2024,  
the  
Corporation
repurchased 2,256,420 shares of common stock for  
$217.3 million, at an average price of  
$96.32 per common share. At December
31, 2025, $281.2 million remained on our active common stock repurchase authorization. The Corporation’s planned common stock
repurchases  
may  
be  
executed  
in  
open  
market  
transactions,  
privately  
negotiated transactions,  
block  
trades  
or  
any  
other  
manner
determined  
by  
the  
Corporation.  
The  
timing,  
quantity  
and  
price  
of  
such  
repurchases  
will  
be  
subject  
to  
various  
factors,  
including
market  
conditions,  
the  
Corporation’s  
capital  
position  
and  
financial  
performance,  
the  
capital  
impact  
of  
strategic  
initiatives  
and
regulatory and  
tax considerations.  
The common  
stock repurchase  
program does  
not require  
the Corporation  
to acquire  
a specific
dollar amount or number of shares and may be  
modified, suspended or terminated at any time  
without prior notice.
Additional information concerning legal or  
regulatory restrictions on the payment  
of dividends by Popular,  
BPPR and PB
is contained under the caption “Regulation and Supervision”  
in Item 1 herein.
As  
of  
February  
26,  
2026,  
Popular  
had  
5,721  
stockholders  
of  
record  
of  
the  
Common  
Stock,  
not  
including  
beneficial
owners whose shares  
are held in  
record names  
of brokers  
or other  
nominees. The last  
sales price  
for the  
Common Stock  
on that
date was $142.51 per share.
Preferred Stock
Popular has 30,000,000 shares of  
authorized Preferred Stock that may  
be issued in one  
or more series, and the  
shares
of each series  
shall have such  
rights and preferences as  
shall be fixed  
by the Board  
of Directors when authorizing  
the issuance of
that particular series. Popular’s Preferred Stock  
issued and outstanding at December 31, 2025  
consisted of:
●
 
885,726 shares of 6.375% non-cumulative monthly income Preferred Stock, Series A, no par value, liquidation preference
value of $25 per share.
All series of  
Preferred Stock are pari  
passu. Dividends on each  
series of Preferred Stock  
are payable if declared  
by our
Board  
of  
Directors.  
Our  
ability  
to  
declare  
and  
pay  
dividends  
on  
the  
Preferred  
Stock  
is  
dependent  
on  
certain  
Federal  
regulatory

 
 
 
 
 
 
 
 
 
 
 
 
 
 
42
considerations,  
including  
the  
guidelines  
of  
the  
Federal  
Reserve  
Board  
regarding  
capital  
adequacy  
and  
dividends.  
The  
Board  
of
Directors is not obligated to declare dividends and  
dividends do not accumulate in the event  
they are not paid.
Monthly  
dividends  
on  
the  
Preferred  
Stock  
amounted  
to  
a  
total  
of  
$1.4  
million  
for  
the  
year  
2025.  
There  
can  
be  
no
assurance that any dividends will be declared on  
the Preferred Stock in any future periods.
Dividend Reinvestment and Stock Purchase Plan
Popular  
offers  
a  
dividend reinvestment  
and stock  
purchase plan  
(the “Plan”)  
for  
our shareholders  
that  
allows them  
to
reinvest their dividends in shares of the Common Stock at a  
5% discount from the average market price at the time of the  
issuance.
Under the  
Plan, shareholders  
may  
also purchase  
shares of  
Common Stock  
at  
prevailing market  
prices by  
making  
optional cash
payments.
Equity Based Plans
On May  
12, 2020, the  
stockholders of  
the Corporation  
approved the Popular,  
Inc. 2020  
Omnibus Incentive Plan,  
which
permits the  
Corporation to issue  
several types of  
stock-based compensation to  
employees and directors  
of the Corporation  
and/or
any of its subsidiaries (the “2020 Incentive Plan”). The 2020 Incentive Plan replaced the Popular, Inc. 2004 Omnibus Incentive Plan,
which was in  
effect prior to  
the adoption of the  
2020 Incentive Plan.  
As of December 31,  
2025, the maximum number of  
shares of
common stock remaining available for future issuance under this plan was 2,599,105. For information about  
the securities remaining
available for issuance under our equity-based plans,  
refer to Part III, Item 12.
Purchases of Equity Securities
The following table sets forth the details of purchases of Common Stock by the Corporation during the quarter ended December 31,
2025:
Issuer Purchases of Equity Securities
Not in thousands
Period
Total Number of
Shares Purchased [1]
Average Price Paid
per Share
Total Number of  
Shares
Purchased as Part of Publicly
Announced Plans or Programs [2]
Maximum Dollar Value
of Shares that May Yet
be Purchased Under the
Plans or Programs [2]
October 1 – October 31
232,575
$120.97
232,539
$400,794,897
November 1 – November 30
496,688
113.84
496,688
344,252,709
December 1 – December 31
523,147
120.78
523,076
281,075,956
Total December 31, 2025
1,252,410
$118.06
1,252,303
$281,075,956
[1] Includes 36 and 71 shares of the Corporation's  
common stock acquired by the Corporation during  
October and December 2025,
respectively, in connection with the satisfaction of tax withholding obligations on  
vested awards of restricted stock or restricted stock
units granted to directors and certain employees  
under the Corporation’s Omnibus Incentive Plan. The  
acquired shares of common
stock were added back to treasury stock.  

[2] As part of its capital plan, in July 2025, the  
Corporation announced plans to repurchase up  
to $500 million in common stock, in
addition to the $500 million in common stock  
repurchase program announced in July 2024.  
As of December 31, 2025, the Corporation
had repurchased 6,916,544 shares of common stock  
for $718.8 million at an average price of  
$103.92 per share, as part of the 2024
and 2025 common stock repurchase programs.
Equity Compensation Plans
For information about our equity compensation plans,  
refer to Part III, Item 12.
Stock Performance Graph (1)

 
 
 
 
 
 
 
 
 

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

 

 
 
 
 
 
 
 

 
 
 
 
43
The graph  
below compares  
the cumulative  
total stockholder  
return during  
the measurement  
period with  
the cumulative
total return, assuming reinvestment of dividends, of  
the Nasdaq Bank Index and the Nasdaq Composite  
Index.
The  
cumulative  
total  
stockholder  
return  
was  
obtained  
by  
dividing  
(i)  
the  
cumulative  
amount  
of  
dividends  
per  
share,
assuming dividend reinvestment since the measurement point, December 31, 2020, plus (ii) the change  
in the per share price since
the measurement date, by the share price at  
the measurement date.
Comparison of Five-Year Cumulative Total Return (TSR)
Assumes all dividends were reinvested
Base Year:  
December 31, 2020 = $100
(1) Unless Popular specifically states otherwise, this Stock Performance Graph shall not be deemed to be incorporated by
reference  
and  
shall  
not  
constitute  
soliciting  
material  
or  
otherwise  
be  
considered  
filed  
under  
the  
Securities  
Act  
of  
1933  
or  
the
Securities Exchange Act of 1934.
ITEM 6. [RESERVED]
ITEM 7. MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION  
AND RESULTS OF OPERATIONS
The information required by this item is included in  
this Form 10-K, commencing on page 54.
ITEM 7A. QUANTITATIVE AND QUALITATIVE  
DISCLOSURES ABOUT MARKET RISK
The information regarding the  
market risk of our  
investments appears under the caption  
“Risk Management”, on page  
79
within Management’s Discussion and Analysis of Financial  
Condition and Results of Operations in this  
Form 10-K.
ITEM 8. FINANCIAL STATEMENTS AND SUPPLEMENTARY DATA

 
44
The information required by this item appears under the caption “Statistical Summaries” on pages 104 to 106 of this Form
10-K.
ITEM 9. CHANGES IN AND DISAGREEMENTS WITH  
ACCOUNTANTS ON ACCOUNTING AND FINANCIAL DISCLOSURE
Not Applicable.
ITEM 9A. CONTROLS AND PROCEDURES
Disclosure Controls and Procedures
Our  
management,  
with  
the  
participation  
of  
our  
Chief  
Executive  
Officer  
and  
Chief  
Financial  
Officer,  
has  
evaluated  
the
effectiveness  
of  
our  
disclosure  
controls  
and  
procedures  
(as  
such  
term  
is  
defined  
in  
Rules  
13a-15(e)  
and  
15d-15(e)  
under  
the
Exchange Act) as  
of the end  
of the period covered  
by this report.  
Based on such  
evaluation, our Chief Executive  
Officer and Chief
Financial  
Officer  
have  
concluded  
that,  
as  
of  
the  
end  
of  
such  
period,  
our  
disclosure  
controls  
and  
procedures  
are  
effective  
in
recording, processing, summarizing and  
reporting, on a timely  
basis, information required to  
be disclosed by Popular  
in the reports
that  
we  
file  
or  
submit  
under  
the  
Exchange  
Act  
and  
such  
information  
is  
accumulated  
and  
communicated  
to  
management,  
as
appropriate, to allow timely decisions regarding required  
disclosures.
Assessment on Internal Control over Financial  
Reporting
Information relating to our assessment on  
internal control over financial reporting is presented under the  
captions “Report
of  
Management  
on  
Internal  
Control  
Over  
Financial  
Reporting”  
and  
“Report  
of  
Independent  
Registered  
Public  
Accounting  
Firm”
located on pages 107 and 108 of this Form 10-K.
Changes in Internal Control over Financial Reporting
There have  
been no  
changes in  
our internal  
control over  
financial reporting  
(as such  
term is  
defined in  
Rules 13a-15(f)
and 15d-15(f) under the Exchange Act) that occurred during the quarter ended December 31, 2025, that have materially affected, or
are reasonably likely to materially affect, our internal control  
over financial reporting.
ITEM 9B. OTHER INFORMATION
Rule 10b5-1 Trading Plans or Other Preplanned Trading Arrangements
Certain  
of  
our  
officers  
or  
directors  
have  
made  
and  
may  
from  
time  
to  
time  
make  
elections  
to
participate in
,  
and  
are
participating in, our dividend  
reinvestment and purchase plan, the  
Company stock fund associated with  
our 401(k) plans and/or  
the
Company stock fund associated with  
our non-qualified deferred compensation plans and have  
shares withheld to cover withholding
taxes upon the vesting  
of equity awards, which may  
be designed to satisfy the  
affirmative defense conditions of Rule  
10b5-1 under
the Exchange Act or may constitute non-Rule 10b5–1
trading arrangements
 
(as defined in Item 408(c) of Regulation S-K).
ITEM 9C. DISCLOSURE REGARDING FOREIGN  
JURISDICTIONS THAT PREVENT INSPECTIONS
Not applicable.
PART III
ITEM 10. DIRECTORS, EXECUTIVE OFFICERS AND CORPORATE GOVERNANCE

 
 
 
 
 
45
The  
information  
contained  
under  
the  
captions  
“Security  
Ownership  
of  
Certain  
Beneficial  
Owners  
and  
Management”,
“Delinquent Section  
16(a) Reports”,  
“Corporate Governance”, “Nominees  
for Election  
as Directors”  
and “Executive  
Officers” in  
the
Proxy Statement  
are incorporated herein  
by reference.  
Information about our  
Code of  
Ethics, which  
applies to  
our senior  
financial
officers, is included in “Business — Available Information” in Part I  
of this Form 10-K.
ITEM 11. EXECUTIVE COMPENSATION
The  
information  
in  
the  
Proxy  
Statement  
under  
the  
caption  
“Executive  
and  
Director  
Compensation,”  
including  
the
“Compensation  
Discussion  
and  
Analysis,”  
the  
“2025  
Executive  
Compensation  
Tables  
and  
Compensation  
Information”  
and  
the
“Compensation  
of  
Non-Employee  
Directors,”  
and  
under  
the  
caption  
“Committees  
of  
the  
Board  
–  
Talent  
and  
Compensation
Committee – Talent and Compensation Committee Interlocks and Insider Participation” is  
incorporated herein by reference.
ITEM  
12.  
SECURITY  
OWNERSHIP  
OF  
CERTAIN  
BENEFICIAL  
OWNERS  
AND  
MANAGEMENT  
AND  
RELATED
STOCKHOLDERS MATTERS
The information under the captions “Principal Shareholders” and “Shares Beneficially  
Owned by Directors,  
Nominees and
Executive Officers” in the Proxy Statement is incorporated herein  
by reference.
The following tables sets forth information as  
of December 31, 2025 regarding securities remaining available for issuance
to directors and eligible employees under our  
equity-based compensation plans.
Plan Category
Plan
Number of Securities
Remaining Available  

for Future Issuance