CiberLATAMbywhalemate

OCC and FDIC narrow bank supervision

The final rule tightens the definition of unsafe or unsound practices and raises the MRA bar to material financial risk.

Whalemate Labs · AI-assisted researchPublished:3 min read

The OCC and FDIC issued a final rule that standardizes what counts as an unsafe or unsound practice in federal banking and raises the threshold for Matters Requiring Attention. The OCC also updated its procedures manual to align supervision with material financial risk and apply corrective measures more consistently.

The OCC and the FDIC have issued a final rule that sets a uniform definition of what counts as an unsafe or unsound practice in federal banking. The move shifts examiners' focus toward material financial risks and compliance with banking laws and related regulations. The OCC also updated its internal manual to align enforcement actions with that standard.

What changes with the new definition?

The rule says a practice falls into the unsafe or unsound category only if it departs from generally accepted standards of prudent operation and, if it continues, would likely cause material harm to the bank's financial condition or a material risk of loss to the Deposit Insurance Fund, or if it has already caused that harm. That gives examiners a clearer framework for deciding when a risk is no longer minor and becomes relevant to supervision.

The clarification also defines financial harm. According to industry materials and the regulatory framework itself, that includes negative effects on capital, asset quality, earnings, liquidity, or sensitivity to market risk. Supervisors now have a more precise threshold for separating operational problems from real threats to financial soundness.

How does the use of MRAs change?

The rule introduces an explicit materiality threshold for Matters Requiring Attention, so examiners may issue them only when the issue can reasonably be expected to cause material harm to the bank's financial condition, pose a material risk to the Deposit Insurance Fund, or amount to an actual violation of banking laws or regulations. The change limits formal observations to issues that reach that level.

At the same time, the OCC updated its Policy and Procedures Manual, known as PPM 5310-3, to align enforcement actions with three guiding principles, escalation, tailoring, and a focus on material financial risks. The agency said it wants more transparency and consistency in corrective measures.

How is the industry reading it?

Several industry analyses describe the rule as industry-friendly and say it raises the threshold for criticizing banks over process weaknesses, documentation gaps, or other nonfinancial risks that do not rise to material financial risk. In that vein, the Bank Policy Institute said the standard provides, for the first time, a clear definition of unsafe or unsound practice, improves the clarity and objectivity of supervision, and may help banking innovation and competition.

Other reporting says the new structure creates a separate channel for examiners to document less serious concerns without requiring formal corrective action. Those accounts say the design reduces supervisory reach over compliance and governance issues considered immaterial from a financial standpoint.

What parallel framework remains in place?

The FTC still enforces the Safeguards Rule under GLBA, which requires financial institutions to develop, implement, and maintain an information security program with administrative, technical, and physical safeguards to protect customer information. The agency's financial-sector page places that obligation within the federal U.S. framework for data protection and security for companies covered by GLBA.

That leaves two regulatory tracks operating at once, on one side federal bank supervision by the OCC and the FDIC, now more focused on material financial risks, and on the other, the FTC's requirements for customer information security at entities covered by GLBA.

Sources

View all