On August 27, 2026, the Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC) jointly issued a final rule that, for the first time, gives the term “unsafe or unsound practice” a binding regulatory definition.1 With it came a uniform standard for Matters Requiring Attention (MRAs) and revised OCC examination manuals.2 The Federal Reserve did not join the rulemaking, but has adopted comparable standards through guidance. What that means for holding companies and state-chartered institutions is addressed below.3 The regulation takes effect November 2, 2026, and the revised OCC examination manuals took effect upon their issuance on August 27.

For boards, general counsel, and risk and compliance leaders, the headlines suggest clarity and potential relief. However, while the rule changes what federal bank examiners may require to bring enforcement, it does not change the standards of prudent risk management a bank is held to, the discretion examiners keep over ratings, or the exposure that sits with state supervisors, the holding company, and individual officers and directors. This client alert explains what changed and how to consider responding.

What Changed

The rule creates two standards and three tiers of supervisory communication:

TierStandardWhat it requires
Unsafe or unsound practiceContrary to generally accepted standards of prudent operation and (i) if continued, is likely to materially harm the bank’s financial condition or present a material risk of loss to the Deposit Insurance Fund, or (ii) has already materially harmed the bank’s financial condition4Formal enforcement, including cease-and-desist orders
Matter Requiring AttentionContrary to generally accepted standards of prudent operation and harm of the same kind could reasonably be expected under current or foreseeable conditions or has already occurred; or an actual violation of banking or banking-related law or regulation5Corrective action, examiner validation, and board reporting
Supervisory observationA weakness below the MRA standard6Informal feedback, with no action plan and no board reporting required

Financial institutions should be aware of three key points.

First, materiality is assessed on a financial basis. Harm is measured against capital, asset quality, earnings, liquidity, and market risk, and reputational concerns alone are not sufficient to support a finding. Non-financial risks still count when their consequences are financial: a serious cyber breach that produces litigation, restitution, or deposit flight could meet the test. However, materiality is not applied as a uniform standard under the final rule — rather, it is tailored to the institution. What constitutes material harm for a large, complex bank will not necessarily meet that threshold for a community bank.7

Second, this definition of unsafe or unsound practice is only applicable to a bank, not institution-affiliated parties. In a reversal of the originally proposed version of the rule, the new definition does not apply to individuals. For officers and directors, “unsafe or unsound” keeps its longstanding case law meaning — conduct contrary to prudent operation that creates an abnormal risk of loss to the bank — with no requirement that material financial harm be likely. A director’s or officer’s personal exposure did not narrow under the final rule.8

Third, an MRA can also be issued for any violation of banking or banking-related law, with no materiality test.9 Examiners may use that path for weaknesses they used to frame as risk-management concerns. Furthermore, by framing these as violations, rather than weaknesses, these determinations can carry civil money penalties. The agencies have said they intend, as a matter of supervisory discretion, to reserve that path for “substantive” violations: those that are patterned or systemic; have more than a minimal impact on the bank, its books and records, or its customers; require more than minimal restitution; or involve insider misconduct. An OCC proposal published September 1, with comments due October 1, would codify that position in a regulation.10

The OCC has revised its manuals to put these new standards into practice.11 Pursuant to these manual revisions, lookbacks — the historical file reviews that have dominated remediation budgets — would now be the exception. To mandate a lookback, examiners now need specified grounds and senior regulatory approval, must weigh cost against benefit, and, going forward, are expected in the ordinary course to let the bank do the review itself, as opposed to mandating an independent consultant. Reviews tied to suspicious-activity reporting will generally be capped at one year.12 This relief is specific to the OCC. The CFPB’s authority over larger banks is not affected,13 and FinCEN, the U.S. Department of Justice (DOJ), OFAC, and state authorities are not bound by the manual.14 A review scoped to the OCC’s one-year cap narrows what the OCC demands; it does not narrow the bank’s exposure to FinCEN, which has six years from a transaction to assess a civil penalty and two more to sue on it; to OFAC, which has a 10-year window to act; or to the DOJ, so a decision not to look further back should be documented and made with counsel.

MRAs going forward can also be validated and closed on a shorter timetable. An MRA can close once remediation is in place and validated, with no “sustainability” holding period, and an enforcement action can end at “substantial compliance.”15 For FDIC-supervised institutions, the rule also changes the FDIC’s longstanding examination practice. For examination reports issued after August 31, 2026, the FDIC will no longer use Matters Requiring Board Attention (MRBAs) or Supervisory Recommendations (SRs), the two categories through which it has historically communicated findings, and will use the single MRA category under the new rule.16

Considerations for Financial Institutions in Light of Regulatory Changes

Under the new standards, most findings will now be observations with no required action plan, no board reporting, and no formal examiner validation requirements. The issue-management frameworks built over the last decade may at first glance appear mismatched to the current state; however, banks, particularly large complex institutions, may determine that it is in their best interest to recalibrate these frameworks as opposed to making wholesale changes.17

Continue tracking observations. Banks may wish to continue tracking observations, even though it is not required. An observation cannot be escalated just because the bank did not act on it.18 However, examiners keep full discretion over CAMELS ratings, and the management rating in particular may be impacted by outstanding observations, whether a single observation or a group of observations considered collectively.19

Document the decision: remediate, tailor, or accept. Banks may also wish to assess each observation against the bank’s approved risk appetite, and under the new framework, three responses are available. Banks may remediate the matter as recommended by examiners; tailor the remediation, agreeing with the concern but implementing remediation suited to the bank, which the manuals expressly permit;20 or accept the risk, concluding, within the approved risk appetite, that no action is warranted. A record of why the bank chose its course is its best protection if a finding is revisited under a different standard.

Banks should continue to address sustainability. The OCC can no longer hold an MRA open to test whether a remediation endures. But repeat findings now must be labeled as such and invite escalation.21 Sustainability testing therefore remains a priority, whether it is completed by an independent compliance testing function or by internal audit, provided the function validating the remediation is not the one that implemented it.

Redesign board reporting around fiduciary oversight. The rule removes the requirement to present observations to the board. However, directors’ oversight duties under Delaware law, the OCC’s heightened standards for larger banks, and public-company disclosure controls all operate independent of supervisory requirements.22 A periodic summary of observation themes, the decisions taken, and the items the bank chose not to pursue keeps the board’s oversight record documented. Because such a summary may be discoverable, banks may wish to frame decisions as risk determinations against the approved risk appetite and to conduct any analysis of potential violations of law, and of the related legal exposure, under privilege.

Why the Governance Discipline Is Worth Keeping

Supervisory philosophy has historically shifted with agency leadership, and administrations change. The rule itself is durable: the agencies are bound by their own regulations, and undoing one typically requires notice and comment.23 The manuals, however, are not, and examiner practice will move faster than the Federal Register in either direction. A bank that stops tracking observations and faces a differently oriented examination team in the future will be reconstructing the intervening dialogue from institutional memory. A bank that keeps its documentation discipline will be in a better position during future exams, regardless of the administration and supervisory approach.

Two additional considerations strengthen the case for documentation discipline for many organizations. The Federal Reserve adopted similar standards to those in the new OCC/FDIC rule, but only by guidance, so holding company relief is the least durable aspect of the change in supervisory posture. The Federal Reserve also assesses a holding company’s risk management itself, and that assessment reflects how the organization tracks and resolves supervisory feedback. If the bank has a state supervisor, the state’s approach has not changed. That includes the New York Department of Financial Services (NYDFS), which supervises some of the largest U.S. banking organizations through their New York-chartered banks, as well as many foreign bank branches.24 State supervisors flagged this divergence in the rulemaking and asked the agencies to wait for the Federal Reserve prior to issuing a final rule. The agencies did not.25 Where a federal examiner would log an observation, a state examiner may write a formal finding on the same facts, and that finding informs the Federal Reserve’s holding company assessment. For New York-chartered institutions, the NYDFS record, not the narrowed federal one, will continue to define the examination approach.

Conclusion

The final rule narrows the range of conduct that regulators may require institutions to remediate. However, it does not explicitly alter the standards of prudent risk management to which institutions remain subject. Institutions may appropriately avail themselves of the relief the rule provides but should give attention to maintaining a record of how each supervisory concern was evaluated and resolved. The record is what will render the relief durable as supervisory approaches evolve over time.


  1. Unsafe or Unsound Practices, Matters Requiring Attention, 91 Fed. Reg. 56,004 (Sept. 1, 2026). The Final Rule is effective November 2, 2026; the manuals apply on issuance. Cease-and-desist authority for unsafe or unsound practices dates from the Financial Institutions Supervisory Act of 1966, 12 U.S.C. § 1818(b). ↩︎
  2. OCC Bulletin 2026-41PPM 5310-3, Bank Enforcement Actions and Related MattersPPM 5400-11, Matters Requiring Attention (published for the first time). ↩︎
  3.  Bd. of Governors of the Fed. Reserve Sys., Statement of Supervisory Operating Principles (rev. Apr. 2026) (MRAs and MRIAs confined to deficiencies presenting a “significant probability of significant harm;” SR 13-13 amended to reinstate nonbinding supervisory observations). The statement is guidance adopted outside notice-and-comment; the Board has not announced a rulemaking. ↩︎
  4. Final Rule, 91 Fed. Reg. at 56,021, 56,022 (to be codified at 12 C.F.R. §§ 4.92(b), 305.1(b) (an unsafe or unsound practice is “a practice, act, or failure to act, alone or together with one or more other practices, acts, or failures to act, that (1) is contrary to generally accepted standards of prudent operation; and (2)(i) if continued, is likely to (A) materially harm the financial condition of the institution; or (B) present a material risk of loss to the Deposit Insurance Fund; or (ii) materially harmed the financial condition of the institution”); OCC Bulletin 2026-40 (materiality measured against capital, asset quality, earnings, liquidity, and sensitivity to market risk). The agencies chose “likely,” over alternatives such as “reasonably foreseeable,” and quantitative thresholds, and confirmed they will not extrapolate from merely possible harms. The definition focuses on the financial materiality of consequences, not on the risk category (e.g., financial vs. non-financial risk). ↩︎
  5. Final Rule, 91 Fed. Reg. at 56,021, 56,022 (to be codified at 12 C.F.R. §§ 4.92(c), 305.1(c) (an MRA may issue for a practice, act, or failure to act alone or together with one or more other practices, acts, or failures to act that “(1)(i) is contrary to generally accepted standards of prudent operation; and (ii) (A) if continued, could reasonably be expected to, under current or reasonably foreseeable conditions, (1) materially harm the financial condition of the institution; or (2) present a material risk of loss to the Deposit Insurance Fund; or (B) materially harmed the financial condition of the institution; or (2) is an actual violation of a banking or banking-related law or regulation”). ↩︎
  6. Final Rule, 91 Fed. Reg. at 56,021, 56,022 (to be codified at 12 C.F.R. §§ 4.92(g), 305.1(g)). ↩︎
  7. Final Rule, 91 Fed. Reg. at 56,021, 56,022 (to be codified at 12 C.F.R. §§ 4.92(e), 305.1(e)). See also Final Rule, 91 Fed. Reg. at 56,015 (“as applied to the threshold for material harm, the agencies would not expect that a particular projected percentage decrease in capital or liquidity that rises to the level of materiality for the largest institutions would necessarily also be material for community banks. Similarly, while the agencies may consider increased classified assets in a particular business line as a result of the institution’s imprudent practices to warrant an MRA at the largest institutions, the agencies may consider a community bank’s asset quality less granularly and consider the overall asset portfolio at the institution level.”) ↩︎
  8. Final Rule, 91 Fed. Reg. at 56,007 & n.16 (institution-affiliated parties excluded; enforcement against individuals continues under prior standards and controlling appellate case law). The agencies were concerned that a uniform standard could leave individual misconduct at a large institution unaddressed. The standard applicable to individuals remains the formulation courts have applied since the Financial Institutions Supervisory Act of 1966: conduct “contrary to generally accepted standards of prudent operation, the possible consequences of which, if continued, would be abnormal risk of loss or damage to an institution.” See, e.g., Gulf Fed. Sav. & Loan Ass’n v. FHLBB, 651 F.2d 259, 264 (5th Cir. 1981); Seidman v. OTS, 37 F.3d 911, 926–32 (3d Cir. 1994). Removal and prohibition actions against individuals also require separate statutory showings of misconduct, effect, and culpability. 12 U.S.C. § 1818(e). See also FIL-53-2026 (“[e]nforcement actions against institution-affiliated parties are not impacted by part 305”). ↩︎
  9. Final Rule, 91 Fed. Reg. at 56,021, 56,022 (to be codified at 12 C.F.R. §§ 4.92(c), 305.1(c); 12 U.S.C. § 1818(i)(2) (civil money penalties for violations of law or regulation). ↩︎
  10. Final Rule, 91 Fed. Reg. at 56,012-56,013 (“the agencies intend to exercise their supervisory discretion to issue MRAs for violations only in response to substantive violations”) listing the points noted above as the indicia for substantive violations; Violations of Laws or Regulations, 91 Fed. Reg. 56,074 (proposed Sept. 1, 2026) (comments due Oct. 1, 2026); FDIC Statement on the Implementation of Part 305, at 2, 4. The FDIC has not joined the proposed codification. ↩︎
  11. PPM 5310-3 § I, at 4 (escalation and tailoring); id. § IV, at 9 (corrective actions must not “elevate the bank’s process and procedure over substance”). ↩︎
  12. PPM 5400-11 § III.B, at 11. A lookback requires objective facts supporting substantial consumer harm, a systemic pattern, widespread fraud or books-and-records inaccuracies, or other exceptional circumstances, plus deputy comptroller approval; SAR-related lookbacks are limited to one year absent special circumstances; an independent consultant may be required only where examiners lack documented confidence in management, the bank concealed the concern, or exceptional circumstances exist. ↩︎
  13. 12 U.S.C. § 5515 (CFPB authority over insured depository institutions exceeding $10 billion in assets). ↩︎
  14. 31 U.S.C. § 5321(b)(1) (six-year period from the date of the transaction to assess a civil penalty); 31 U.S.C. § 5321(b)(2) (two-year period to commence an action to recover an assessed penalty, running from the later of assessment or a final criminal judgment on the same transaction); 31 U.S.C. § 5322 (criminal penalties); 50 U.S.C. §§1705(d)4315(d) (10-year limitations period for civil and criminal sanctions violations, as extended by the 21st Century Peace through Strength Act, Pub. L. No. 118-50, div. D, § 3111 (2024), applicable to violations not time-barred at enactment). ↩︎
  15. PPM 5400-11 § III.C, at 12 (examiners “must not delay closing an MRA to assess the sustainability of the corrective action”); PPM 5310-3 § VII, at 12 (substantial compliance); FDIC, Formal and Informal Enforcement Actions Manual (rev. Sept. 2025) (permitting termination of an order where the institution “has achieved at least substantial compliance with the order”). ↩︎
  16. See FDIC, FIL-53-2026, Implementation of the Final Rule on Unsafe or Unsound Practices; Matters Requiring Attention (Aug. 27, 2026), and the accompanying FDIC Statement on the Implementation of Part 305. ↩︎
  17. OCC Bulletin 2026-40 (as risk increases, the materiality threshold decreases and the assessment becomes more granular). ↩︎
  18. PPM 5400-11 § I.F, at 7. ↩︎
  19. “Well managed” status, which conditions financial holding company activities and expedited application processing, turns on the management and composite ratings of the depository institutions. 12 U.S.C. § 1843(l)(1)12 C.F.R. § 225.2(s)PPM 5400-11 § I.F, at 7 (“examiners can use the information underlying supervisory observations to support assigned ratings”); FDIC Statement on the Implementation of Part 305, at 4 (supervisory observations support “supervisory assessments and, potentially, supervisory ratings”). ↩︎
  20. PPM 5400-11 § III.A, at 8 (corrective actions state what must be done “at a minimum” without prescribing the method). ↩︎
  21. PPM 5400-11 § III.A, at 8–9 (repeat designation); PPM 5310-3 § I, at 4. ↩︎
  22. In re Caremark Int’l Inc. Derivative Litig., 698 A.2d 959 (Del. Ch. 1996); 12 C.F.R. pt. 30, app. D (heightened standards, unamended). ↩︎
  23. United States ex rel. Accardi v. Shaughnessy, 347 U.S. 260 (1954). ↩︎
  24. State-chartered banks are examined jointly or alternately with the Federal Reserve (member banks) or the FDIC (nonmember banks); state-licensed foreign bank branches are examined under the interagency FBO program, SR 00-14. Federal branches are OCC-supervised and within the rule, 12 U.S.C. § 3102. NYDFS has announced no change to findings practice or its enforcement posture. ↩︎
  25. Conference of State Bank Supervisors, Comment Letter (Dec. 29, 2025) (warning of an “inconsistent supervisory outcome” between state member and nonmember banks and urging delay until the Federal Reserve aligned). ↩︎
Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Cristina Diaz Cristina Diaz

Cristina Diaz is a senior counsel in the firm’s Financial Services Group and is based in the New York office. With more than 20 years of banking law experience, Cristina brings a unique combination of in-house insight and private practice depth. She advises

Cristina Diaz is a senior counsel in the firm’s Financial Services Group and is based in the New York office. With more than 20 years of banking law experience, Cristina brings a unique combination of in-house insight and private practice depth. She advises foreign and domestic banks, fintechs, and digital assets businesses on bank regulation, compliance, and enforcement.

Cristina’s practice spans bank chartering and licensing, permissible activities, capital requirements, regulatory enforcement, M&A, and corporate governance. She advises clients navigating the intersection of traditional banking and emerging financial services, including digital assets companies seeking to acquire or establish national banks, and banks exploring partnerships with fintechs and digital assets firms. She regularly helps clients navigate complex relationships and remediation initiatives with state and federal financial regulators, including the Federal Reserve, OCC, FDIC, and the Utah Department of Financial Institutions.

Photo of Carlton Greene Carlton Greene

Carlton Greene is a partner in Crowell & Moring’s Washington, D.C. office and a member of the firm’s International Trade and White Collar & Regulatory Enforcement groups. He provides strategic advice to clients on U.S. economic sanctions, Bank Secrecy Act and anti-money laundering…

Carlton Greene is a partner in Crowell & Moring’s Washington, D.C. office and a member of the firm’s International Trade and White Collar & Regulatory Enforcement groups. He provides strategic advice to clients on U.S. economic sanctions, Bank Secrecy Act and anti-money laundering (AML) laws and regulations, export controls, and anti-corruption/anti-bribery laws and regulations. Carlton is the former chief counsel at FinCEN (the Financial Crimes Enforcement Network), the U.S. AML regulator responsible for administering the Bank Secrecy Act.

Photo of Anand Sithian Anand Sithian

For high-stakes internal and government investigations and complex regulatory and compliance matters, companies and individuals look to Anand to provide strategic advice and counseling, particularly on issues relating to the Bank Secrecy Act and Anti-Money Laundering (“BSA/AML”), economic sanctions, and digital assets. Anand

For high-stakes internal and government investigations and complex regulatory and compliance matters, companies and individuals look to Anand to provide strategic advice and counseling, particularly on issues relating to the Bank Secrecy Act and Anti-Money Laundering (“BSA/AML”), economic sanctions, and digital assets. Anand is resident in the firm’s New York office and a member of the firm’s International Trade, White Collar and Regulatory Enforcement, and Financial Services groups.

A former federal prosecutor, Anand leverages his government experience to guide clients through complex white-collar matters, including grand jury and regulatory investigations, enforcement proceedings, and internal investigations. Anand has deep experience in parallel criminal and civil investigations and proceedings, and often represents clients in defending against civil lawsuits related to government investigations.

Representing some of the world’s largest banks and technology companies, Anand has addressed a wide range of issues, including economic sanctions, BSA/AML; economic sanctions and national security; payments and cryptocurrency; securities laws; and cybersecurity enforcement. In the regulatory space, Anand prides himself on providing commercial and actionable advice, including in the developing areas of digital assets, FinTech, and payments.