The OCC and FDIC final rule on matters requiring attention lands in the Federal Register. What it changes for BSA, sanctions and AML examination findings.
Table of contents
The OCC and the FDIC have finalised a rule that limits when examiners may issue matters requiring attention, effective 2 November 2026. Published in the Federal Register on 1 September 2026, it defines "unsafe or unsound practice", ties prudential criticism to material financial harm, and both agencies say they will cite only substantive violations of law.
- The joint final rule was issued on 27 August 2026 and published on 1 September 2026 at 91 FR 56004. It takes effect on 2 November 2026.
- From that date a matter requiring attention (MRA) needs a prudential failing with reasonably expected material financial harm, or an actual violation of a banking or banking-related law.
- The agencies also state they will issue violation-based MRAs only for substantive violations, grouped into four categories, so an isolated Bank Secrecy Act slip may draw no citation at all.
- Anti-money laundering, counter-terrorist financing and sanctions rules stay expressly banking-related, and systemic BSA programme failings remain squarely substantive.
- OCC examiner policy already moved on 27 August, when the agency revised PPM 5310-3 and published its MRA manual, PPM 5400-11, for the first time.
What did the OCC and FDIC actually finalise?
Two US bank supervisors have written their examination vocabulary into regulation. The Office of the Comptroller of the Currency and the Federal Deposit Insurance Corporation issued a joint final rule on 27 August 2026 defining "unsafe or unsound practice" for section 8 of the Federal Deposit Insurance Act, and setting uniform standards for matters requiring attention.
Comptroller of the Currency Jonathan V. Gould said in the OCC announcement that the package tells examiners to "prioritize material financial risks and substantive violations of law". The same day the OCC revised its enforcement manual, PPM 5310-3, and released its MRA manual, PPM 5400-11, publicly for the first time. Examiner practice therefore shifted before the rule bites.
| Detail | Value |
|---|---|
| Agencies | OCC and FDIC (the Federal Reserve is not a party) |
| Instrument | Joint final rule, 12 CFR 4.92 (OCC) and 12 CFR 305.1 (FDIC) |
| Dockets | OCC-2026-0174, RIN 1557-AF35 and RIN 3064-AG16 |
| Issued | 27 August 2026 |
| Published | Federal Register, 1 September 2026, 91 FR 56004 |
| Effective | 2 November 2026 |
| Companion proposal | OCC-2026-0529, comments due 1 October 2026 |
Scope matters. The rule reaches national banks, federal savings associations and federal branches and agencies of foreign banks on the OCC side, and insured state nonmember banks, insured state licensed branches and insured state savings associations on the FDIC side. State member banks and holding companies supervised by the Federal Reserve sit outside it.
How does the new matters requiring attention standard work?
The rule builds a four-rung ladder. An unsafe or unsound practice must be contrary to generally accepted standards of prudent operation and, if continued, likely to materially harm the institution's financial condition or present a material risk of loss to the Deposit Insurance Fund. Matters requiring attention need only a reasonable expectation of that harm, or an actual legal violation.
Two lower rungs are new in regulation. A supervisory observation is an informal note on weaknesses in policies, practices, condition or operations, and the rule creates no expectation of board presentation or corrective action. An "other violation" is a real breach for which no MRA or enforcement action follows; the agencies may direct remediation and take any step another law compels.
| Rung | Test | What the bank must do |
|---|---|---|
| Unsafe or unsound practice | Imprudent and likely material financial harm | Respond to a formal or informal action, or to a finding in the examination report |
| Matters requiring attention | Imprudent and reasonably expected material harm, or an actual violation | Present to the board and remediate |
| Other violation | Actual violation, no MRA issued | Remediate; the FDIC may cite an uncorrected one as an MRA next examination |
| Supervisory observation | Weakness below the MRA threshold | Nothing required by the rule |
Both tests also reach harm already suffered, and the agencies say they will cite violations only where those violations are substantive. Harm itself is defined narrowly as losses or negative impacts to capital, asset quality, earnings, liquidity or sensitivity to market risk. The preamble goes further: "The standard would not include risks to the institution's reputation unrelated to financial condition."
Tailoring then cuts the other way for large firms. As capital structure, complexity, activities and asset size grow, the materiality threshold falls, the assessment gets more granular, and remediation expectations rise. Findings that would pass at a community bank can therefore escalate at a large or complex one.
What changes for your BSA and sanctions obligations?
Nothing here relaxes a substantive duty. The change is in the supervisory response to a gap, and it runs duty by duty. Anti-money laundering, counter-terrorist financing and sanctions rules, including the Office of Foreign Assets Control regulations, are expressly banking or banking-related, so they remain citable. What narrows is which violations earn a citation.
Start with programme pillars. Under 12 CFR 21.21 a failure to designate a day-to-day BSA compliance officer is, in the companion proposal's words, among the "Bank Secrecy Act (BSA) compliance program violations or pillar violations" that count as systemic. Systemic is the first of the four substantive categories, so pillar failures still draw matters requiring attention. Our Bank Secrecy Act explainer sets out those pillars.
Sanctions reporting behaves differently. The OCC says in that proposal that ongoing breaches of the reporting duties in 31 CFR part 501 could establish a pattern, which again is substantive, while a single late blocking report is neither systemic nor patterned. An isolated breach can still qualify under one of the other categories. For customer identification, customer due diligence, beneficial ownership collection and Suspicious Activity Report filing, the test becomes whether the breach is systemic, patterned, financially material, restitution-driven or insider-linked.
Everything below that line moves. Thin model documentation, a stale risk assessment, an unclear escalation path or an alert backlog are not violations of law. They now support matters requiring attention only where an examiner ties them to reasonably expected material financial harm, and otherwise become supervisory observations. Nonconformance with the Interagency Guidelines Establishing Standards for Safety and Soundness is likewise not a legal violation, though it can still reach an MRA through the prudential prong.
What is still uncertain about the new supervisory ladder?
The companion proposed rule would harden that policy into binding text, deeming a violation substantive where "its nature, duration, frequency, or severity could meaningfully impact the institution or its customers". It also regroups the four categories into five, and lets the OCC downgrade a substantive violation to a technical one.
That last power reintroduces the discretion the rule was meant to constrain. The agencies kept the words "banking or banking-related" in the final rule after commenters asked them to narrow the phrase, and Question 13 of the proposal now asks whether the OCC should remove it from 12 CFR 4.92(c). Deleting the limiter would widen the prong rather than narrow it, leaving substantive as the only filter, which is an odd loose end in a deregulatory package.
Escalation works differently from how it reads. The agencies rejected a request to escalate repeatedly ignored observations, stating "supervisory observations do not warrant escalation into an MRA" absent a change in the institution or its environment. What survives is quieter: information underlying observations can support assigned ratings, and for FDIC-supervised banks an unremediated other violation can be cited as an MRA at the next examination.
Two structural gaps remain. The Federal Reserve is not a party, so a state member bank and a national bank with the same transaction monitoring weakness may be treated differently, and the FDIC follow-up power has no OCC twin. The agencies also acknowledged that MRAs stay open long after remediation, then declined to fix closure timing in this rulemaking. The preamble also states that enforcement authority under section 8 is unaffected by this rulemaking, which the EagleBank BSA settlement illustrates in practice.
How does this sit alongside the other 2026 AML rulemakings?
The matters requiring attention rule is the third strand of a single supervisory redesign. In April 2026 FinCEN, the OCC, the FDIC and the NCUA proposed a risk-based AML program standard. In July 2026 the Federal Reserve followed with its own version, covered in our report on the risk-based AML program rule.
| Action | Status on 3 September 2026 | Key date |
|---|---|---|
| FinCEN and banking agency AML program proposals | Proposed | Comments closed 9 June 2026 |
| Federal Reserve AML program proposal | Proposed | Comments close 8 September 2026 |
| OCC and FDIC MRA final rule | Adopted and published | Effective 2 November 2026 |
| OCC violations proposal | Proposed | Comments due 1 October 2026 |
The two halves interlock awkwardly. The programme proposals push examiners toward judging whether an AML programme actually works, which is an effectiveness question. This rule then restricts how an effectiveness concern can be written up unless it is a legal violation or carries a financial harm nexus. Expect more findings to arrive as observations, and expect the burden of proving effectiveness to sit with the bank.
How should compliance teams respond?
Re-read every open finding against the new ladder before 2 November 2026. Sort each into an actual violation, a prudential weakness with a harm nexus, or a process gap, because the three now travel different routes. Read PPM 5400-11, since that is what your examiner will apply, and ask which rung a new finding sits on.
Then use the comment windows. The Federal Reserve programme proposal closes on 8 September 2026 and the OCC violations proposal on 1 October 2026, and the second will define "substantive violation" for your BSA programme. After that, close the evidence gap: if documentation no longer earns a citation, documentation alone no longer proves your programme works. An audit-ready compliance stack is the practical form of that.
Zyphe was built for that evidence problem. Our agents complete KYC, KYB and AML decisions without holding customer personal data, and each decision carries a documented rationale and an exportable audit trail you can hand to an examiner. If your findings are about proving effectiveness rather than storing documents, book a demo.
The bottom line
US bank supervisors have moved the line between a finding and a footnote, and written it into the Code of Federal Regulations rather than an examiner manual. For teams running KYC and AML the consequence is a different proof burden, not a lighter one. Process artefacts count for less, decision-level effectiveness counts for more, and the obligations did not move.
Cited sources
- Unsafe or Unsound Practices, Matters Requiring Attention, final rule, 91 FR 56004
- Violations of Laws or Regulations, OCC notice of proposed rulemaking, 91 FR 56074
- OCC and FDIC joint release: Agencies Issue Final Rule to Prioritize Material Financial Risks
- OCC release: Acts to Improve Transparency and Consistency to Bank Enforcement and Supervisory Standards
- OCC PPM 5400-11, Matters Requiring Attention
- OCC PPM 5310-3, Bank Enforcement Action and Related Matters
- OCC Bulletin 2026-40: Unsafe or Unsound Practices and Matters Requiring Attention
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.