The Office of the Comptroller of the Currency (OCC) today released enforcement actions for September 2026.
Why this matters
This is a standard OCC news release announcing two Orders of Prohibition against individual employees (former bankers) for criminal conduct (embezzlement and unauthorized account debits).
The Office of the Comptroller of the Currency (OCC), the Board of Governors of the Federal Reserve System (the Board) and the Federal Deposit Insurance Corporation (the FDIC, and collectively, the agencies) are issuing a statement to provide clarity on their risk-based supervision of certain services provided by core…
Why this matters
This is a joint statement from OCC, Federal Reserve, and FDIC providing clarity on supervisory approach to third-party core service providers used by community banking organizations.
The Office of the Comptroller of the Currency today continued to empower community banks and reduce their burden with a proposal to tailor third-party risk management to actual risk, and by providing greater clarity regarding supervision and enforcement of core service providers.
Why this matters
This is a policy proposal from the OCC (U.S. banking regulator) that introduces tailored third-party risk management guidance and clarifies supervision of core service providers for community banks.
The Office of the Comptroller of the Currency (OCC), jointly with the Financial Crimes Enforcement Network (FinCEN), the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, and the National Credit Union Administration, issued answers to frequently asked questions (FAQ) related…
Why this matters
This is a multi-agency FAQ bulletin providing authoritative clarification on how banks must treat state-issued mobile driver's licenses and other verifiable digital credentials under BSA/AML CIP requirements.
On September 2, 2026, the Office of the Comptroller of the Currency, the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Financial Crimes Enforcement Network (FinCEN), and the National Credit Union Administration issued a statement to clarify confidentiality…
Why this matters
This is a joint regulatory statement from OCC, Federal Reserve, FDIC, FinCEN, and NCUA that clarifies the scope and application of Bank Secrecy Act confidentiality requirements for SARs.
The Office of the Comptroller of the Currency (OCC) issued a notice of proposed rulemaking to refine the standard for the issuance of matters requiring attention (MRA) in response to violations of laws and regulations (12 CFR 4.92). The proposed rule would establish two categories of violations: "substantive…
AI Analysis
On August 27, 2026, the OCC proposed amending 12 CFR 4.92 to distinguish substantive violations from technical violations and to restrict violation-based MRAs to substantive violations. The proposal would raise the practical threshold for an MRA while preserving examiner authority to require correction of technical violations; independent commentary characterizes the broader supervisory direction as a shift toward material financial risk, legal violations, and more standardized supervisory communications.
Key dates
2026-08-27
The OCC issued Bulletin 2026-42 announcing the notice of proposed rulemaking.
Suggested considerations
Compliance teams may wish to inventory open and recently closed MRAs arising from alleged legal or regulatory violations and assess whether each matter would satisfy one or more of the proposed substantive-violation criteria.
Firms should consider strengthening documentation linking examination findings to duration, frequency, systemic characteristics, financial-condition effects, books-and-records impacts, customer harm, restitution, or insider misconduct.
Banks may wish to separate remediation plans for legal or regulatory violations from broader supervisory enhancements, because the proposal would limit examiner authority over technical violations to directing correction of the violation itself.
Compliance and examination-management teams should consider preparing comments or internal positions on the undefined terms more than minimal, systemic, pattern, and meaningfully impact, including how those terms should be applied to isolated but high-severity events.
Management may wish to review escalation thresholds so that technical-violation treatment does not result in under-escalation of recurring findings that could become systemic or satisfy the proposed substantive criteria.
Banks should monitor the Federal Register publication of the notice of proposed rulemaking and calculate the 30-day comment period from that publication date rather than from the OCC bulletin date.
Legal and regulatory-change teams may wish to assess this proposal alongside the OCC-FDIC final rule and related supervisory reforms concerning unsafe or unsound practices, MRAs, and material financial risk, while treating the proposal as nonfinal until adopted.
What changed
The proposed rule would provide that the OCC may issue an MRA for a violation of a banking or banking-related law or regulation only when the violation is substantive. A violation would be substantive when its nature, duration, frequency, or severity could meaningfully impact the bank or its customers, and at least one of five criteria would need to be met: the violation is systemic or constitutes a pattern; it has had or could reasonably be expected to have a direct, clear, predictable, and more than minimal impact on the bank's financial condition; it has had or could reasonably be expected...
Compliance impact
The proposal is not currently binding, but it could materially change how OCC examination findings involving legal and regulatory violations are categorized, escalated, and remediated. It may reduce MRAs for genuinely minor violations while increasing the importance of evidence showing systemic conduct, recurring patterns, customer harm, financial impact, books-and-records effects, or insider misconduct; the OCC has not proposed eliminating the underlying obligation to comply with applicable law or correct violations.
The Office of the Comptroller of the Currency (OCC) today released two revised Policies and Procedures Manuals (PPM): PPM 5310-3, "Bank Enforcement Actions and Related Matters," and PPM 5400-11, "Matters Requiring Attention."
AI Analysis
On August 27, 2026, the OCC replaced its enforcement and MRA manuals with PPM 5310-3 and PPM 5400-11, aligning OCC supervision with the OCC-FDIC final rule defining unsafe or unsound practices and establishing a risk-based MRA framework. The update raises the practical threshold for MRAs and Section 8 enforcement by emphasizing material financial risk and substantive legal violations, while allowing examiners to communicate lower-level concerns as nonbinding supervisory observations.
Key dates
2026-08-27
OCC issued revised PPM 5310-3 and PPM 5400-11; PPM 5310-3 replaces the May 25, 2023 manual, PPM 5400-11 replaces the February 27, 2026 version, and OCC Bulletin 2023-16 is rescinded.
Suggested considerations
Compliance teams may wish to map open MRAs, enforcement orders, capital directives, and supervisory findings against the new material-harm, Deposit Insurance Fund risk, and substantive-violation thresholds.
Banks should consider reviewing issue-management taxonomies and governance procedures so that MRAs, other violations, and supervisory observations are recorded and escalated according to their distinct consequences.
Board and committee reporting processes may warrant review because supervisory observations do not automatically require board presentation or a corrective-action plan, whereas MRAs and enforcement actions remain subject to formal remediation and validation expectations.
Large and complex banks should consider reassessing whether deficiencies that might previously have produced a community-bank-level supervisory response could receive faster escalation under the revised tailoring framework.
Banks with existing enforcement actions may wish to assess whether their remediation evidence demonstrates substantial compliance with the essential requirements of each order and whether remaining issues are minor and isolated.
Capital management teams may wish to review procedures for the institution of and termination of individual minimum capital ratios under the revised enforcement manual.
Legal and regulatory change teams should monitor Federal Register publication of the joint OCC-FDIC final rule and calculate the actual effective date rather than relying on the bulletin date.
Internal audit and compliance functions may wish to preserve objective factual support for responses to MRAs and other supervisory communications, particularly where the bank believes an issue does not meet the new risk-based threshold.
What changed
Revised PPM 5310-3 replaces the May 25, 2023 version and structures the OCC enforcement framework around escalation, tailoring, and focus. The OCC generally intends to provide banks an opportunity to remediate deficiencies through supervision before initiating a Section 8 enforcement action, although it retains authority to act at any time when legally supportable and warranted.
Compliance impact
The update is likely to reduce the use of MRAs and Section 8 enforcement actions for isolated policy, process, documentation, or other nonfinancial weaknesses that do not meet the new material-risk or substantive-violation standards, but it does not eliminate supervisory discretion or escalation risk.
OCC Acts to Improve Transparency and Consistency to Bank Enforcement and Supervisory Standards OCC issues two revised policies and procedures manuals; proposes amendments to Violations of Laws and Regulations framework WASHINGTON-The Office of the Comptroller of the Currency (OCC) today announced additional actions to…
AI Analysis
On August 27, 2026, the OCC revised its enforcement-action and Matters Requiring Attention (MRA) policies and procedures manuals and publicly released PPM 5400-11 for the first time. The changes implement a risk-based supervisory framework centered on material financial risk and substantive legal violations, while a proposed rule would distinguish substantive violations from technical violations and limit MRAs for legal or regulatory violations primarily to the former.
Key dates
2026-08-27
OCC revised PPM 5310-3 and PPM 5400-11, issued Bulletin 2026-41, and published the proposed rulemaking notice concerning substantive and technical violations. The proposed rule's 30-day comment period begins only upon Federal Register publication.
Suggested considerations
Compliance teams may wish to map open and recently closed MRAs and enforcement actions against the revised material-financial-risk threshold and the stated tailoring factors of capital structure, complexity, activities, and asset size.
Banks should consider documenting objective facts, legal violations, financial-risk consequences, customer impact, duration, frequency, severity, and remediation status supporting the classification and closure of examination findings.
Large and complex banks may wish to reassess escalation risk because the OCC expressly permits enforcement action for practices that might not produce the same response at a community bank.
Banks should consider reviewing corrective-action plans to confirm that each action is directly tied to a specific deficiency and is proportionate to the risk, while preserving evidence of substantial compliance with existing orders.
Compliance teams may wish to distinguish substantive violations from potential technical violations in issue-management inventories, including systemic or repeated conduct, customer restitution, books-and-records impacts, financial-condition effects, and insider misconduct.
Banks should consider monitoring the Federal Register for publication of the proposed rule and calculating the 30-day comment period from that publication date; affected institutions may wish to submit comments on the proposed substantive-versus-technical framework.
Examiners may identify lower-level weaknesses as supervisory observations rather than MRAs; banks should consider maintaining internal governance and risk records for such observations without assuming that the OCC may require a board action plan or track remediation in the same manner as an MRA.
What changed
Revised PPM 5310-3, Bank Enforcement Action and Related Matters, replaces the May 25, 2023 version and emphasizes escalation, tailoring, and focused corrective action. The OCC generally expects to provide a bank an opportunity to remediate deficiencies through supervision before taking an enforcement action under section 8 of the Federal Deposit Insurance Act, although it retains authority to act at any time when legally supportable.
Compliance impact
The final policy changes reduce the likelihood that immaterial procedural, documentation, or nonfinancial weaknesses will independently generate an MRA or enforcement action, but they do not create a general safe harbor for legal violations or weak controls. Risk is likely to remain significant for large or complex banks, systemic or repeated violations, customer harm, inaccurate books and records, insider misconduct, and conduct that materially affects financial condition or the Deposit Insurance Fund.
The OCC and the FDIC issued a joint final rule to define the term "unsafe or unsound practice" for purposes of section 8 of the Federal Deposit Insurance Act and revise the supervisory framework for the issuance of matters requiring attention (MRA) and other supervisory communications.
AI Analysis
On August 27, 2026, the OCC and FDIC issued a joint final rule defining “unsafe or unsound practice” under section 8 of the Federal Deposit Insurance Act and establishing a uniform, narrower standard for Matters Requiring Attention (MRAs). Independent market commentary describes the rule as the first formal regulatory definition of the core supervisory concept and emphasizes its shift toward material financial risk, while creating a less coercive channel for lower-level supervisory concerns.
Key dates
2026-08-27
OCC and FDIC issued the joint final rule through OCC Bulletin 2026-40. The bulletin applies to all OCC-supervised banks; it does not state the Federal Register publication date, effective date, or a firm compliance deadline.
Suggested considerations
Firms should identify the final rule’s Federal Register publication and effective date, because the OCC bulletin itself does not state either date or a compliance deadline, and should monitor OCC and FDIC implementation guidance before relying on any transition treatment.
Compliance teams may wish to inventory open MRAs, supervisory recommendations, enforcement matters, and examination findings and map each item to the final rule’s material-financial-risk, DIF-risk, actual-violation, or already-caused-harm criteria.
Firms should consider separating board-level MRA remediation obligations from discretionary management responses to supervisory observations and documenting why a weakness is treated under one category rather than another.
Risk and compliance functions may wish to enhance evidence files supporting assessments of likelihood, materiality, current and reasonably foreseeable conditions, and impacts on capital, asset quality, earnings, liquidity, and market-risk sensitivity.
Banks should consider documenting how supervisory requirements and remediation plans are tailored to asset size, complexity, activities, capital structure, and other financial-risk factors, particularly where the institution has heightened systemic, concentration, liquidity, or operational complexity.
Legal and compliance teams may wish to distinguish actual violations of banking or banking-related laws and regulations from prudential weaknesses, because an actual violation can support an MRA without separately satisfying the prudent-operation and material-risk test.
Boards and senior management should consider reviewing governance procedures so that MRAs receive required escalation and tracking while supervisory observations are clearly identified as non-binding potential enhancements.
Firms should consider preparing a process for requesting and retaining the objective facts and reasoning underlying an MRA or unsafe-and-unsound-practice determination, as the rule requires examiners to share that basis.
What changed
An unsafe or unsound practice is now defined as a practice, act, or failure to act that is contrary to generally accepted standards of prudent operation and either is likely, if continued, to materially harm the bank’s financial condition or present a material risk of loss to the Deposit Insurance Fund, or has already materially harmed the bank’s financial condition. “Likely” requires more than a merely possible risk; relevant financial-condition effects include impacts on capital, asset quality, earnings, liquidity, and sensitivity to market risk.
Compliance impact
The rule may reduce the scope of MRAs and section 8 enforcement theories for nonfinancial, documentation, process, or reputation concerns that lack a material financial-risk or legal-violation nexus, but it does not eliminate supervisory scrutiny or remediation obligations. Higher-risk banks may face lower materiality thresholds, more granular harm assessments, and more demanding remediation expectations; actual violations remain independently capable of supporting an MRA.
The Office of the Comptroller of the Currency and the Federal Deposit Insurance Corporation (the agencies) today issued a final rule that continues their effort to focus examiners' and institutions' attention on material financial risks and compliance with banking and banking-related laws and regulations. The final…
AI Analysis
The OCC and FDIC issued a final rule on August 27, 2026, creating a uniform, risk-based definition of an “unsafe or unsound practice” under Section 8 of the Federal Deposit Insurance Act, 12 U.S.C. § 1818, and establishing standards for Matters Requiring Attention (MRAs) and supervisory observations. The rule raises the threshold for mandatory supervisory action toward material financial risks while preserving MRAs for actual violations of banking or banking-related laws and regulations.
Key dates
2026-08-27
OCC and FDIC issued the final rule and OCC published Bulletin 2026-40 describing its application to OCC-supervised banks.
Suggested considerations
Compliance teams may wish to map existing and anticipated MRAs, enforcement commitments, supervisory recommendations, and examination findings against the new material-financial-risk and actual-violation criteria.
Firms should consider separating board-level corrective-action items from nonbinding supervisory observations and documenting why each issue does or does not meet the MRA threshold.
Risk and compliance functions may wish to update issue-taxonomy and escalation procedures to assess impacts on capital, asset quality, earnings, liquidity, sensitivity to market risk, and the Deposit Insurance Fund.
Banks should consider retaining objective evidence and documented reasoning supporting materiality assessments, including institution-specific factors such as asset size, complexity, activities, and capital structure.
Management and boards may wish to review outstanding policies, process, and documentation findings to determine whether they remain mandatory remediation matters, are better treated as supervisory observations, or independently constitute violations of banking or banking-related law.
OCC-supervised banks should monitor the related examination guidance and assess whether planned lookbacks, independent-consultant requirements, or suspicious-activity review scopes are affected by the revised supervisory approach described in industry reporting.
Firms should track Federal Register publication and calculate the 60-day effective date once publication occurs; the August 27, 2026 announcement date is not itself the effective date.
What changed
An unsafe or unsound practice is now defined as a practice, act, or failure to act that is contrary to generally accepted standards of prudent operation and either, if continued, is likely to materially harm the bank’s financial condition or present a material risk of loss to the Deposit Insurance Fund, or has already materially harmed the bank’s financial condition. Relevant financial-condition impacts include capital, asset quality, earnings, liquidity, and sensitivity to market risk; reputation concerns unrelated to financial condition are excluded.
Compliance impact
The rule is a material change to supervisory and enforcement standards because it is the first formal regulatory definition of “unsafe or unsound practice” and limits mandatory MRAs and corrective direction for matters that do not present material financial risk, except where an actual banking-law violation exists. It may reduce board-directed remediation for lower-risk process or documentation weaknesses, but does not eliminate legal compliance obligations, enforcement exposure for material harm, or remediation requirements for violations required by law.
The Office of the Comptroller of the Currency (OCC) today released enforcement actions for August 2026.
Why this matters
The content announces the termination of a formal agreement with First National Bank of Pasco dated September 2025, indicating the bank achieved compliance. This is a standard administrative closure notice with no new regulatory requirements, policy changes, or broad applicability.
On July 31, 2026, staffs of the Office of the Comptroller of the Currency (OCC), the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, and the National Credit Union Administration (collectively, the agencies), issued a statement of enforcement policy in support of U.S…
AI Analysis
On July 31, 2026, the OCC, Federal Reserve, FDIC, and NCUA issued a joint enforcement policy supporting humanitarian relief and financial stability efforts in Venezuela after major earthquakes. The policy matters because it creates a temporary enforcement safe harbor for eligible U.S. financial institutions that provide authorized financial services to persons or entities in Venezuela, reducing BSA-related supervisory risk during the relief period.
Key dates
2026-06-24
Venezuela experienced a pair of strong earthquakes off the northern coast west of Caracas, triggering the humanitarian crisis referenced by the agencies.
2026-07-27
FinCEN issued a substantively similar statement of enforcement policy regarding Venezuela-related financial services.
2026-07-31
The OCC, Federal Reserve, FDIC, and NCUA issued the joint enforcement policy.
2026-07-31
Start of the period during which authorized financial services to persons or entities in Venezuela are covered by the enforcement commitment.
2027-01-29 Deadline
End of the covered period for the joint enforcement commitment.
Suggested considerations
Compliance teams may wish to confirm whether current Venezuela-related activity falls within the scope of authorized financial services covered by the joint statement.
Institutions may wish to verify that their BSA compliance program remains current and that ongoing controls reflect reasonable efforts to comply during the relief period.
Firms may wish to check whether they have had any final FinCEN or OCC enforcement action involving BSA violations in the prior 24 months before relying on the policy.
Sanctions teams may wish to confirm continued compliance with all applicable OFAC-administered sanctions regulations and authorizations.
Institutions with Venezuela exposure may wish to document how they will evidence reliance on the policy and monitor the January 29, 2027 end date.
What changed
The agencies stated that eligible U.S. financial institutions that choose to provide authorized financial services to persons or entities in Venezuela will not be subject to supervisory action, including a citation for a violation of law, or enforcement action related to a Bank Secrecy Act requirement, for those services. The commitment is limited to authorized financial services provided from 2026-07-31 through 2027-01-29 and applies only to statutes or regulations specifically addressed in the joint statement.
Compliance impact
The immediate impact is moderate but targeted: institutions that qualify gain temporary relief from BSA-related supervisory and enforcement action for Venezuela-related authorized services. The agencies still expect compliance with applicable BSA requirements and OFAC sanctions, and the safe harbor is unavailable to institutions with recent final BSA enforcement actions or inadequate ongoing compliance efforts.
The Office of the Comptroller of the Currency (OCC) today released enforcement actions for July 2026.
Why this matters
This is a standard OCC monthly enforcement actions news release announcing specific enforcement orders (cease and desist against United Texas Bank for BSA/AML deficiencies, prohibition order against individual for theft) and terminations of prior agreements.
The OCC is highlighting the updated Section 314(b) Fact Sheet recently issued by the U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN). The updated guidance clarifies how financial institutions can share information with each other about suspected fraud under section 314(b) of the USA…
AI Analysis
The OCC issued Bulletin 2026-30 on 2026-07-09 to highlight FinCEN’s updated Section 314(b) Fact Sheet on voluntary information sharing. The update matters because it broadens and clarifies what participating financial institutions can share to detect suspected fraud and other illicit financial activity, while operating under the Section 314(b) safe harbor.
Compliance teams may wish to review whether current Section 314(b) registration status is current and whether the institution has designated internal points of contact for information-sharing requests.
Firms may wish to assess whether existing BSA/AML and fraud-monitoring procedures explicitly cover the newly highlighted examples of shareable information, including cyber-related data and video surveillance footage.
Institutions may wish to confirm that information-sharing protocols limit disclosures to permissible Section 314(b) purposes and maintain security and confidentiality controls over information received from peers.
Banks may wish to refresh training for BSA, fraud, and investigations staff on when sharing is permissible, including the safe-harbor conditions and the scope of eligible counterparties.
Compliance teams may wish to verify that procedures for responding to requests and documenting reliance on Section 314(b) remain aligned with FinCEN’s updated fact sheet.
What changed
FinCEN’s updated Section 314(b) Fact Sheet clarifies that a participating financial institution may share information about suspected fraud, money laundering, terrorist financing, or other specified unlawful activities with any other financial institution eligible to participate in the Section 314(b) program.
Compliance impact
This is a supervisory guidance update rather than a new binding rule, but it has practical significance because it signals how regulators expect voluntary information sharing to support fraud and BSA/AML controls. The OCC emphasizes the safe harbor for eligible participants, so institutions that do not adapt their procedures may miss an opportunity to improve detection of money laundering, terrorist financing, and fraud.
The Office of the Comptroller of the Currency (OCC) is issuing a notice of proposed rulemaking to implement Bank Secrecy Act (BSA) and sanctions compliance standards applicable to OCC-supervised permitted payment stablecoin issuers (PPSI), as required by the Guiding and Establishing National Innovation for U.S…
AI Analysis
The OCC issued a notice of proposed rulemaking on June 22, 2026 to implement Bank Secrecy Act and sanctions compliance standards for OCC-supervised permitted payment stablecoin issuers under the GENIUS Act. The proposal matters because it would formalize AML/CFT and OFAC compliance expectations, create an OCC enforcement framework, and establish a consultation channel with FinCEN for significant actions.
Key dates
2026-06-22
OCC bulletin announcing the notice of proposed rulemaking was issued
2026-07-22 Deadline
Planned deadline for comments, if the Federal Register publication date aligns with the bulletin date and the OCC’s 30-day comment period is measured from publication
Suggested considerations
Compliance teams may wish to assess whether the entity falls within the OCC-supervised PPSI category or within the state-qualified issuer population covered by OCC authority under the GENIUS Act.
Firms may wish to review existing AML/CFT and sanctions controls against the BSA, FinCEN, and OFAC requirements referenced in the proposal, including reporting, monitoring, and risk assessment procedures.
Compliance teams may wish to map governance, escalation, and record-sharing workflows to the proposed OCC-FinCEN consultation framework, particularly for potential significant supervisory or enforcement matters.
Firms may wish to consider whether their current policies, procedures, and internal controls are sufficiently tailored to stablecoin-specific risks and whether additional board or senior management oversight would be needed.
Compliance teams may wish to evaluate whether they should submit comments during the 30-day Federal Register comment period if aspects of the proposed framework could affect operating models or compliance design.
What changed
The proposed rule would require OCC-supervised PPSIs to comply with the BSA, sections 4(a)(5) and 4(a)(6)(B) of the GENIUS Act, and applicable FinCEN and OFAC regulations, including AML/CFT program, sanctions program, and reporting requirements. It would also create a supervision and enforcement framework for PPSI AML/CFT programs, so the OCC can take AML/CFT supervisory and enforcement action against covered issuers.
The rule would establish a formal consultation process between the OCC and FinCEN when the OCC intends to initiate an AML/CFT enforcement action or a significant AML/CFT...
Compliance impact
The proposal signals a material increase in AML/CFT and sanctions compliance scrutiny for OCC-supervised stablecoin issuers, with explicit supervisory and enforcement consequences for program deficiencies. The OCC describes a framework that could support significant supervisory action or enforcement action, making program design, governance, and escalation controls more consequential for affected issuers.