OCC and FDIC tighten bank supervision
The OCC and FDIC raised the bar for unsafe or unsound findings and standardized the MRA threshold.
In August 2026, the OCC and FDIC issued a joint final rule that raises the evidentiary bar for bank supervisors to label a practice unsafe or unsound and take enforcement action. The new standard ties those findings to material financial risks or legal violations, and it also sets a uniform standard for Matters Requiring Attention (MRA).
In August 2026, the OCC and FDIC issued a joint final rule that raises the evidentiary bar for bank supervisors to label a practice unsafe or unsound and take enforcement action. The new standard ties those findings to material financial risks or legal violations, and it also sets a uniform standard for Matters Requiring Attention (MRA).
What changed in bank supervision?
The final rule is designed to steer examiner findings toward material financial risks and violations of banking laws and regulations. The OCC said the change reduces the weight of objections focused on policies, processes, documentation, and other nonfinancial risks.
That shift was spelled out in OCC bulletin 2026-40, titled Unsafe or Unsound Practices and Matters Requiring Attention: Final. The document applies to national banks, federal savings associations, their subsidiaries, and also to branches or agencies of foreign banks operating in the United States.
The OCC also confirmed that it retains enforcement authority over national banks, federal savings associations and their subsidiaries, as well as branches and federal agencies of foreign banks operating in the country. Combined with the new evidentiary standard, that scope leaves less room for disputes based only on procedural shortcomings.
How does this fit with cybersecurity and resilience?
The regulatory change arrives as the FDIC and the FFIEC framework have been setting more specific expectations for IT controls, cybersecurity, and incident response. A 2025 FDIC resilience report described examination programs that include the Computer-Security Incident Notification Rule and alignment with the NIST Cybersecurity Framework.
According to the analytical summary cited, that same report says FDIC IT and cybersecurity exams now treat AI-enabled social engineering and identity fraud as active threats. It also reinforces expectations for multifactor authentication and identity verification at supervised banks.
The FFIEC compliance guidance also says U.S. financial institutions must align IT, cybersecurity, and risk management controls with the standards federal regulators use in exams. That includes corporate governance, risk assessments, information security programs, access controls, third-party oversight, incident response, business continuity, and monitoring.
The technical requirements listed in that guidance include multifactor authentication, least-privilege access control, encryption, data classification, backup and restoration testing, log monitoring, vulnerability scanning, and tested incident response plans. In an analysis of the U.S. framework, Armour Cybersecurity adds that the FFIEC model and NYDFS Part 500 also require a written program, risk assessments, a CISO, periodic penetration tests, and vulnerability assessments.
What does this mean for foreign banks and correspondent accounts?
For foreign banks with operations in the United States, the new supervision standard overlaps with existing due diligence and risk control obligations. U.S. correspondent account rules require specific risk-based and, when needed, enhanced programs, with policies, procedures, and controls to detect and report known or suspected money laundering in accounts maintained in the United States for foreign financial institutions.
The OCC also keeps the ability to act against branches and federal agencies of foreign banks in the country. In practice, the higher threshold for calling a practice unsafe or unsound may make supervisor discussions more demanding when a finding involves financial risk or regulatory violations, not just process weaknesses.
The publication also lands in a broader regulatory environment in which the Commerce Department can assess, in ICTS transactions, whether a provider has headquarters or operations in foreign countries and which laws apply in its jurisdiction. For groups with subsidiaries, vendors, or correspondent accounts in the region, that mix of requirements can raise the level of documentation, internal control, and traceability they will need to show U.S. supervisors.
Sources
- Agencies Issue Final Rule to Prioritize Material Financial Risks and Enhance Consistency and Transparency in Supervision and Enforcementocc.gov· Office of the Comptroller of the Currency (OCC)
- Bank Cybersecurity Regulations: OSFI, FFIEC, and NYDFSarmourcyber.io· Armour Cybersecurity
- FDIC 2025 Report on Cybersecurity and Resilience: 2025 Report on Cybersecurity and Resilience — What It Says, Who It Applies Tobankingnewsai.com· FDIC / BankingNewsAI (resumen)
- Top Bank Watchdogs Adopt Plan to Narrow Oversight ...bloomberg.com· BloombergUnverified URL
- Due diligence programs for correspondent accounts for foreign financial institutionsgovregs.com· GovRegs
- Subpart B—Review of ICTS Transactionsgovregs.com· GovRegs
- Unsafe or Unsound Practices and Matters Requiring Attention: Finalocc.gov· Office of the Comptroller of the Currency (OCC)
- OCC and FDIC finalize narrower bank supervision proceduresamericanbanker.com· American Banker
- US bank regulators finalize rules defining 'unsafe' bank practicesreuters.com· ReutersUnverified URL
- Enforcement Actionsocc.gov· Office of the Comptroller of the Currency (OCC)
- Reg Wrap: US raises threshold for bank supervision and enforcementthebanker.com· The Banker
- FFIEC Compliance: An IT and Cybersecurity Guide for Financial ...cmitsolutions.com· CMIT Solutions



