The joint final rule narrows the basis for enforcement actions and MRAs to practices that pose material financial risk or constitute actual violations of law.
By Arthur S. Long, Parag Patel, Pia Naib, and Deric Behar
Key Points:
- The Final Rule formally defines the term “unsafe or unsound practice,” narrowing enforcement and supervisory attention to practices that are likely to materially harm an institution’s financial condition or present a material risk of loss to the Deposit Insurance Fund.
- The Final Rule establishes a uniform standard for “Matters Requiring Attention,” permitting the agencies to issue MRAs only for practices that could reasonably be expected to cause material financial harm or that constitute actual violations of banking or banking-related laws or regulations.
- The scope of the Final Rule was narrowed from the Proposal to apply only to supervised institutions, excluding institution-affiliated parties such as officers, directors, and other individuals, whose enforcement actions will continue under prior standards.
- The OCC separately proposed a rulemaking to codify a framework distinguishing between “substantive violations” and “technical violations” of laws and regulations for purposes of issuing MRAs.
On August 27, 2026, the Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC) (collectively, the agencies) issued a joint final rule (the Final Rule) that revises the supervisory framework for covered institutions by formally defining the term “unsafe or unsound practice” and establishing a uniform standard for “Matters Requiring Attention” (MRAs).
The Final Rule provides for tailoring of agency supervisory and enforcement actions “based on unsafe or unsound practices” and the issuance of MRAs “based on the risks associated with the institution’s capital structure, complexity, activities, asset size, and any other financial risk-related factor” that the agencies deem appropriate. This tailored approach seeks to ensure that supervisory and enforcement actions are effective, proportionate, and relevant to the specific circumstances of each institution, rather than a one-size-fits-all regulatory framework that can be overly burdensome for some banks and insufficient for others. It also allows agencies to focus their resources on managing areas of greatest financial risk, potentially resulting in “lower volumes of examination findings, particularly MRAs” and attendant compliance burdens for institutions.
The scope of the Final Rule was narrowed from the initial notice of proposed rulemaking (the Proposal),1 which would have encompassed the agencies’ supervisory and enforcement actions taken against both institutions and institution-affiliated parties (IAPs).2 The Final Rule is limited to institutions the agencies supervise, but does not limit enforcement authority generally (i.e., enforcement actions against IAPs continue under prior standards and procedures).
Unsafe or Unsound Practices
Prior to the Final Rule, there was no formal statutory or regulatory definition for what constituted an unsafe or unsound practice, which the agencies viewed as leading to a lack of consistency and clarity in enforcement and supervision.
The Final Rule seeks to remedy this by establishing a uniform definition for the term “unsafe or unsound practice” for purposes of supervisory activities and enforcement actions under section 8 of the Federal Deposit Insurance Act (12 U.S.C. § 1818) (FDI Act).
In line with the Proposal, an unsafe or unsound practice is defined as a practice, act, or failure to act, alone or together with other practices, acts, or failures to act, that:
- is contrary to generally accepted standards of prudent operation; and
- either:
- i. if continued, is likely to
- A. materially harm the financial condition of an institution; or
- B. present a material risk of loss to the Deposit Insurance Fund (DIF); or
- ii. materially harmed the financial condition of the institution.
As in the Proposal, “material” or “materially” are adopted in the Final Rule as the threshold for harm without a quantitative definition (such as dollar amounts, percentages, or bright-line tests). The agencies stated that “assessment of what qualifies as material harm to the financial condition of an institution relies on examiner judgment, based on objective facts and sound reasoning.”
The agencies also declined to adopt a defined time horizon for a result to be “likely” to occur, stating that “likely” is “more than speculative or merely possible” and that “[t]he appropriate time horizon would be a fact-specific determination based on multiple factors, including the certainty of projected conditions or harm and the magnitude of potential harm.”
However, in an elaboration on the Proposal, and to “prevent reputational or other non-financial impacts from being considered,” the Final Rule clarifies that “harm to financial condition” specifically “refers to financial losses or other negative impacts to an institution’s capital, asset quality, earnings, liquidity, or sensitivity to market risk.”3
Under the Final Rule, the agencies’ supervisory authority and enforcement authority are prospectively narrowed to reduce supervisory attention on “policies, process, documentation, and other nonfinancial risks.” However, the definition does not apply to the agencies’ rulemaking activities or authority.
Matters Requiring Attention
In line with the Proposal, the Final Rule also establishes uniform standards for when and how the agencies may communicate MRAs and non-binding supervisory observations as part of the examination process. It establishes that the agencies may only issue an MRA for a practice, act, or failure to act, alone or together with one or more other practices, acts, or failures to act, that:
- (i) is contrary to generally accepted standards of prudent operation; and
- (ii)(A) if continued, could reasonably be expected to, under current or reasonably foreseeable conditions,
- (1) materially harm the financial condition of the institution; or
- (2) present a material risk of loss to the DIF; or
- (B) has already caused material harm to the financial condition of the institution; or
- is an actual violation of a banking or banking-related law or regulation.
MRAs may only be issued for actual (not potential) violations of banking or banking-related laws. The agencies will also not issue an MRA solely to address minor deficiencies in policies, procedures, or internal controls unless they independently meet the MRA standard.
The Final Rule retains “banking or banking-related” in the standard, and the agencies provide a non-exhaustive interpretive framework of categories of laws or regulations that are properly classified as banking or banking-related. This includes prudential requirements (e.g., FDI Act, Regulation W); consumer protection laws applicable to bank products (e.g., Electronic Fund Transfer Act, Equal Credit Opportunity Act); and anti-money laundering, counter-terrorist financing, and sanctions laws. The agencies exclude “laws that are wholly unrelated to the business of banking” (e.g., zoning, environmental, etc.). Other laws may or may not be banking-related depending on the context (e.g., Internal Revenue Service (IRS) regulations for depositors may be relevant, but IRS regulations for employees may not).
Substantive Violations
The agencies introduce a “substantive violations” framework, whereby “examiners must review objective facts and apply sound reasoning to determine whether a violation is substantive” and therefore warrants an MRA. Such violations include:
- violations that demonstrate a pattern or are systemic;
- violations that have, or could reasonably be expected to have, “more than minimal adverse impact” on financial condition, books and records, or customers;
- violations that require, or could be reasonably expected to require, “more than minimal restitution to make recipients whole”; or
- violations that involve insider misconduct or self-dealing.
According to the agencies, the “more than minimal” threshold is lower than “material” but “excludes trivial or de minimis impacts or restitution.” The agencies also clarified that nonconformance with interagency guidelines (e.g., Safety and Soundness Guidelines) is not considered a violation of banking or banking-related law or regulation (see section below, Substantive Violations Versus Technical Violations).
Other Violations
The Final Rule adopts a category of “other violations,” defined as actual violations of banking or banking-related laws for which the agencies do not take an enforcement action or issue an MRA. The agencies, however, reserve the right to direct institutional remediation or to take other actions required by law.
Violations for which the agencies do not issue an MRA can also be considered in ratings determinations.
Supervisory Observations
The Proposal permitted examiners to provide supervisory observations (informal, non-binding suggestions) related to weaknesses in an institution’s policies, practices, condition, or operations, but which do not warrant an MRA. The Proposal’s preamble described limitations to supervisory observations (no action plans required, no tracking, no requirement to present to board, no escalation on the basis of non-adoption).
The Final Rule retains the concept of supervisory observations but codifies certain key limitations:
- The “unsafe or unsound practice” definition does not apply to supervisory observations.
- There is no requirement or supervisory expectation that observations be presented by an institution to its board or that the institution take any corrective action.
CAMELS Ratings Downgrades and MRAs
In addition to the various changes noted above, the Final Rule deviates from the Proposal in one other key way: The Proposal suggested that any downgrade to a less-than-satisfactory (3 or below) composite rating under the Uniform Financial Institutions Rating System (UFIRS, commonly referred to as the CAMELS rating system) would only occur when the institution receives an MRA or enforcement action. The agencies determined that this proposal was beyond the scope of the final rulemaking (i.e., the identification of unsafe or unsound practices and issuance of MRAs) and deferred taking any action on it.4
Implementation and Companion Actions
In connection with the Final Rule, both agencies issued companion guidance and took implementation actions that are effective immediately.
The FDIC issued Financial Institution Letter FIL-53-2026, summarizing its supervisory and enforcement approach for implementing the Final Rule as Part 305 of the FDIC’s rules and regulations. As part of this implementation, the FDIC is ending the use of the terms “Matters Requiring Board Attention” (MRBAs) and “Supervisory Recommendations” (SRs) for examination reports issued after August 31, 2026, replacing them with MRAs in conformance with Part 305. The FDIC also issued revisions to its Risk Management Manual of Examination Policies and Consumer Compliance Examination Manual, including updated chapters on basic examination concepts, violations of laws and regulations, report of examination instructions, and examination planning. The FDIC noted that broader revisions to both manuals are planned for next year.
The OCC simultaneously revised two policies and procedures manuals (PPMs). The revised PPM 5310-3, “Bank Enforcement Actions and Related Matters,” emphasizes material financial risks and highlights the OCC’s three guiding principles for enforcement actions: “escalation, tailoring, and focus on the actions essential to correcting specific deficiencies.” The OCC also released PPM 5400-11, “Matters Requiring Attention,” establishing guidance and procedures for examiners to issue MRAs, including the handling of violations of law or regulation.
Substantive Violations Versus Technical Violations
The OCC separately issued a notice of proposed rulemaking (“Matters Requiring Attention for Violations of Laws and Regulations”) to codify its supervisory framework for the issuance of MRAs in response to violations of laws or regulations and to “establish a legally binding limit on the OCC’s ability to issue an MRA in response to a violation of a law or regulation.”
Going farther than the Final Rule, where substantive violations are discussed but not codified, the proposed rule would establish two categories of violations applicable to OCC-supervised institutions:
- Substantive violation: A violation of a law or regulation is substantive if its nature, duration, frequency, or severity could meaningfully impact the institution or its customers. Substantive violations of a law or regulation must:
- be systemic, or constitute a pattern of violations;
- have, or reasonably be expected to have, a direct, clear, predictable, and more than minimal impact on the institution’s financial condition;
- have, or reasonably be expected to have, a more than minimal impact on the accuracy of the institution’s books and records;
- require more than minimal restitution or reasonably be expected to have a more than minimal adverse impact on customers; or
- involve insider misconduct or self-dealing.
- Technical violation: A violation that does not meet any of the five criteria above and for which the OCC does not take an enforcement action or issue an MRA.
For technical violations, the OCC would be able to direct an institution to correct the violation but could not prescribe how the institution must do so or require remediation steps unrelated to the violation. The OCC would generally not track whether an institution has corrected a technical violation, and the institution would not be required to report back. If one or more technical violations later met any of the criteria of a substantive violation, the OCC could then issue an MRA.
Comments on the OCC’s proposed rule are due 30 days after publication in the Federal Register.
Conclusion
FDIC Acting Chairman Travis Hill said in a statement that the Final Rule shifts the agencies’ attention away from mere process and “towards underlying fundamental risks” while “impos[ing] a materiality threshold for evaluating those potential risks.”5
Chairman Hill also noted that the FDIC “has completed a ‘lookback’ review of all outstanding [supervisory criticisms] to assess which meet the MRA standard under the final rule and which should be closed out.” He stated that “a large majority of outstanding supervisory criticisms do not meet the standard under the final rule and thus will be (or in some cases already have been) closed out.” The ones that do meet the new standard, however, will be converted into MRAs. “The result,” he asserted, “will be more attention and focus by banks and examiners on issues truly relevant to safety and soundness.”
By defining the term “unsafe or unsound practice” and establishing uniform standards for MRAs, the Final Rule aims to reduce regulatory ambiguity for both examiners and supervised institutions, and to ensure that supervisory actions are based on tangible and data-driven criteria rather than subjective or non-financial concerns.
In addition, the distinction between substantive and technical violations in the OCC’s proposed rule is intended to focus the OCC’s supervisory attention on violations with the highest likelihood of potential harm to an institution or its customers.
Recent Comments