{{item.title}}
{{item.text}}
{{item.text}}
Read "our take" on the latest developments and what they mean.
What happened? On August 27th, the OCC and FDIC issued a final rule defining “unsafe or unsound practice” and establishing standards for Matters Requiring Attention (MRAs), supervisory observations and violations that do not result in an MRA or enforcement action. On the same day, the OCC released:
The FDIC also released a statement describing how it will implement the final rule as well as updated versions of its risk management and compliance examination manuals but did not issue an additional proposal relating to violations of law.
What does the final rule do? The final rule largely retains the proposed standards for unsafe or unsound practices and MRAs, with several notable changes. Specifically, it:
What do the revised OCC manuals say? The revised manuals establish more specific procedures for the treatment and escalation of supervisory findings. Among other changes, they establish:
What would the OCC’s violations proposal do? The proposal would further limit when a violation of law or regulation may result in an MRA. Specifically, it would:
How is the FDIC implementing the final rule? The FDIC’s implementation statement provides additional detail on how the new framework will affect examinations and supervisory findings. Specifically, the FDIC will:
What’s next? The joint final rule will take effect November 2nd. Comments on the OCC’s violations proposal are due October 1st.
Codification should promote consistency, but it will not guarantee it
The final rule will cement the already sharp decline in new MRAs by placing a substantially higher bar for formal findings into regulation. Even if agency leadership changes, examination teams will remain bound by the new requirement to justify with “objective facts and sound reasoning” why a concern rises to the level of an MRA. Publication of the OCC’s previously internal MRA manual should further reinforce that shift by making examiner instructions more transparent and giving institutions a clearer basis for distinguishing supervisory requirements from examiner preferences. However, important terms such as “material harm,” “reasonably foreseeable” and “more than minimal” will continue to depend on examiner judgment. The OCC’s proposal also leaves consequential questions open, including the treatment of state-law violations, safety and soundness guidelines, and the ability of examiners to impact credit classifications and nonaccrual decisions. Consistent implementation will therefore depend on examiner training, internal review and how the agencies resolve questions that arise in practice. Even consistent implementation by the OCC and FDIC would not produce a single supervisory standard for firms also overseen by the Fed. Although the Fed has adopted a similar focus on material financial risk, it has not issued any formal rulemaking on the topic and continues to apply its own framework with different thresholds for findings. As such, firms with multiple regulators will need to account for differences among regulators while remaining consistent enough to support enterprise-wide risk decisions.
More flexibility means greater bank accountability. By tying formal supervisory findings and required remediation more closely to material risk, the new framework should give banks greater ability to focus resources on the issues most consequential to their financial condition, customers, and operations, rather than reflexively building remediation programs around process weaknesses or examiner-preferred practices. The distinction between substantive and technical violations would take that shift further at the OCC by reserving MRAs for violations that could meaningfully affect the institution or its customers and removing the OCC’s ability to direct how technical violations are corrected. That said, the underlying legal requirements and potential consequences of noncompliance remain relevant. For example, the OCC proposal notes that certain systemic BSA/AML program or pillar violations would remain substantive, and criminal and other sanctions remain available even where the OCC may limit its own response or required lookbacks (e.g., for identification of suspicious activity).
Similarly, while receiving fewer formal MRAs does not reduce the underlying risks, firms should be cognizant that decreased regulatory focus could make emerging concerns less visible or urgent to management and boards. Supervisory feedback that previously might have resulted in an MRA may instead be communicated through supervisory observations (or not at all), leaving to bank management all decisions around remediation, tracking, and reporting. Firms’ own materiality and escalation judgments, and related decisions around mitigation and remediation, will therefore carry greater weight, while MRA volume may diminish as a risk indicator.
What should firms do now? As the framework takes effect, institutions should consider:
What happened? On August 26th, Treasury Secretary Scott Bessent announced Operation Economic Outcast, a whole-of-government campaign targeting Iran’s financial infrastructure.
What does the campaign do? Three significant actions have taken place:
What's next? Comments on the Banque Misr UAE proposed rule are due by October 1st, 2026. Treasury indicated it has given foreign governments a defined timeline to shut down identified Iran related activity within their jurisdictions or face further action, suggesting additional sectoral designations and possibly further Section 311 actions are likely in the near term.
A coordinated campaign, not isolated action
The “Economic D-Day” campaign marks the broadest and most consequential sanctions measures against Iran to date, following an escalating series of sanctions that have taken place since the beginning of the current Administration. With OFAC significantly widening the net of entities that can be designated and FinCEN taking swift action 48 hours later, Treasury is sending a clear message that there are more designations and enforcement to come – and targets will include a broad set of worldwide actors, not just explicitly Iran-linked entities. Firms should consider the following moving forward:
What happened? On September 1st, the SEC proposed a broad package of amendments to the rules governing registered transfer agents, which are firms that maintain official records of who owns an issuer’s securities and help process changes in ownership and payments to investors.
What is the proposal intended to modernize? SEC Chair Paul Atkins explained that the rule – which was written when firms typically held paper share certificates – should be modernized to reflect the realities of electronic transfers, blockchain technology and tokenized securities.
What would the proposal do? The proposal would update rules intended to support accurate and timely securities processing and protect the securities and funds handled by transfer agents by addressing today’s electronic operating environment, including the use of electronic records and communications, distributed ledger technology and tokenized securities. It includes:
What's next? Comments on the proposal are due November 3rd.
Transfer agent controls will need to catch up with technology
Transfer agents have long been expected to maintain accurate ownership records and protect the securities and funds entrusted to them, but those responsibilities now depend heavily on technology. An unauthorized user, system outage, corrupted electronic record or failure at a critical service provider could interrupt transfers or compromise the integrity of securityholder records just as directly as a breakdown in traditional processing or custody controls. These risks will become increasingly important as transfer agents support securities represented through distributed ledger technology or other tokenized structures, where the technology used to record and transfer ownership may form part of the control environment itself. The proposal could therefore require transfer agents to take a more connected view of safeguarding, cybersecurity, operational resilience, electronic recordkeeping and third-party risk. To address these risks, transfer agents involved with tokenized securities will need to stand up private key management, blockchain architecture and smart contract capabilities.
Assurance coverage may need to expand alongside the control environment
Smaller transfer agents that could become newly subject to Rule 17Ad-13 may face the most significant readiness challenge because they would need to establish an independently testable control framework while implementing the proposal’s broader requirements. Although Rule 17Ad-13 itself would remain largely intact for transfer agents already subject to the rule, the anticipated expansion of the underlying control environment could affect both Rule 17Ad-13 testing and SOC 1 scope. Transfer agents and their auditors should consider the following:
Treasury announces the launch of the Quantum-Readiness Task Force. On August 24th, the Treasury department announced the launch of the Quantum-Readiness Task Force, which will develop guidelines to strengthen cryptographic protections for US sensitive data, critical infrastructure and the digital economy in accordance with Executive Order 14412.
FDIC publishes a reciprocal-deposit interim final rule. On August 27th, the FDIC issued a final rule that materially expands the reciprocal deposits that qualifying institutions may exclude from brokered-deposit treatment. A well-capitalized bank with a CAMELS 1, 2 or 3 can now qualify as an agent institution, and the previous general cap is replaced by a tiered cap reaching a maximum of $30 billion. Comments are due October 1st.
Agencies issue Joint Statement on Suspicious Activity Report Confidentiality Considerations. Issued September 2nd, the statement clarifies that the BSA and related regulations do not prohibit a bank from communicating with a customer about potentially fraudulent or other suspicious transactions involving the customer's account or notifying the customer that the bank intends to close the account for potentially fraudulent or suspicious activity, provided the communication does not reveal the existence of a SAR.
Seven agencies rescind the 2022 interagency Special Purpose Credit Program statement. On August 25th, the FDIC, NCUA, OCC, CFPB, HUD, DOJ and FHFA issued a notice of rescission that creditors should no longer rely on the February 2022 statement or related issuances and must instead apply current Equal Credit Opportunity Act (ECOA) requirements, Regulation B and, where applicable, the Fair Housing Act. The notice specifically points to CFPB’s April 2026 Regulation B amendments as making the earlier guidance obsolete.
SEC proposes rescission of pay-to-play rule. On September 3rd, the SEC issued a proposal to rescind Advisers Act Rule 206(4)-5, which prohibits investment advisers from providing compensated advisory services to a government client for two years after certain political contributions, along with related recordkeeping requirements. Other Advisers Act obligations, including the antifraud, fiduciary duty, compliance, and code of ethics rules, would remain in place.
SEC and CFTC further extend Form PF amendment compliance date. On August 31st, the SEC and CFTC published a joint final rule postponing compliance with 2024 amendments to Form PF from October 1st, 2026 to July 1st, 2027. The delay is intended to give the agencies additional time to consider an April 2026 proposal that would raise filing thresholds and modify or eliminate several expanded reporting requirements before firms incur implementation costs.
CFTC publishes SEF order-book proposal. On August 26th, the CFTC issued a proposal to eliminate the requirement that a swap execution facility maintain an order book for “permitted transactions” swaps not subject to mandatory trade execution. The proposal would not eliminate execution requirements for to “required transactions.”
CFTC finalizes amendments to its mandatory interest-rate-swap clearing requirements to complete benchmark transitions. On September 2nd, CFTC finalized a rule updating clearing requirements for derivatives to new successor benchmark rates for Canadian dollars and Mexican pesos. The rule becomes effective 30 days after Federal Register publication.
House Republicans unveil the Consumer Financial Protection Accountability and Reform Act of 2026. On September 1st, House republicans released a bill that would subject the CFPB to congressional appropriations; impose expanded cost-benefit and retrospective-review requirements; narrow UDAAP and nonbank supervision authority; raise the bank-supervision threshold from $10 billion to $30 billion; create new statutory frameworks for small-dollar lending and earned wage access; and limit certain enforcement, complaint-handling and market-monitoring practices.
California passes small business lending law. On August 20th, the California legislature passed Assembly Bill (AB) 2116, which would create a California licensing, reporting and UDAAP-style regulatory regime for providers and brokers of small-business commercial financing of $500,000 or less. Banks are generally exempt, but nonbank fintech, marketplace and commercial-financing partners may be subject to the new licensing requirements and restrictions. The bill will now need to be signed by the CA Governor to become law.
NYC issues FAQs on new debt collection law. On August 4th, the NYC Department of Consumer and Worker Protection published an FAQ on the implementation of amendments to its rules relating to debt collectors, known as the SHIELD Rule, which substantially expands the regulation of debt collection beyond the federal Fair Debt Collection Practices Act (FDCPA) and Regulation F.
{{item.text}}
{{item.text}}