Feature Compliance Strategy
The Fed Changed the Math on Self-Disclosure: What the Revised Supervisory Operating Principles Mean for Your Issues Program
On April 30, 2026, the Federal Reserve released a revised Statement of Supervisory Operating Principles with two policy changes that make self-identifying problems genuinely worthwhile. Self-disclosed deficiencies now get supervisory observation treatment instead of MRAs — if you start remediating promptly. Here's what that means and how to make your issues management program work for you in exams.
Table of Contents
For years, the examination incentives ran in one direction: if examiners were going to find problems anyway, there wasn’t much upside to finding them first. Self-disclosure meant you’d still get an MRA. The examiner’s job was to validate remediation regardless. The only difference between self-identifying a gap and an examiner catching it was that the self-disclosure might get you to remediation a few months earlier.
The Federal Reserve’s revised Statement of Supervisory Operating Principles, released April 30, 2026, changes that math.
Not dramatically, and not unconditionally. But for the first time, there’s a formal policy mechanism where institutions that build real self-identification infrastructure get better examination outcomes than institutions that wait to be caught.
TL;DR
- The Federal Reserve’s April 30, 2026 revised Statement of Supervisory Operating Principles contains two significant policy shifts for examination management
- Self-identified deficiencies that are promptly remediated will presumptively get supervisory observation treatment instead of MRA classification
- Examiners are now directed to ordinarily rely on internal audit validation for MRA closure, rather than independently re-testing
- The OCC and FDIC ran a parallel but distinct reform: a joint NPRM proposing to limit MRAs to “material financial harm” scenarios — still pending as of mid-2026
- Together, these shifts make internal self-identification and a credible audit function structurally worth building — for regulatory reasons, not just governance ones
What the Revised Principles Actually Changed
The Statement of Supervisory Operating Principles is an internal Fed policy document governing how supervisory staff conduct examinations and communicate findings. It’s not a rule; it’s an internal standard. But internal standards govern examiner behavior, and examiner behavior is what institutions experience.
The April 2026 revision contains two distinct policy changes that compliance programs need to understand — and they work differently.
Policy Change 1: Self-Identification Gets Better Treatment
The revised principles state that if a Board-supervised banking organization self-identifies a deficiency that would otherwise satisfy the standard for an MRA or MRIA based on a threat to safety and soundness, and promptly starts remediating that deficiency in a manner determined to be reasonable by supervisory staff, the deficiency will presumptively be treated as giving rise to a supervisory observation rather than an MRA or MRIA.
This creates a two-part trigger:
- The institution identifies the problem first (not the examiner)
- The institution starts remediation promptly and proceeds reasonably
Both conditions must be present. Self-identification without prompt remediation doesn’t get you the benefit. And the “presumptively” qualifier matters — it’s not a guarantee. Examiners retain discretion to treat the deficiency as an MRA if the self-identification wasn’t genuine or if remediation isn’t actually progressing.
But for institutions with real internal identification programs — issues management processes that catch control gaps, compliance failures, and operational weaknesses before the exam team arrives — this creates a structural advantage. Being first to find your problems now has a documented regulatory payoff.
Policy Change 2: Internal Audit Can Close MRAs
The second change addresses how already-cited MRAs get closed. The revised principles direct supervisory staff to “ordinarily rely on a banking organization’s internal audit validation to determine whether issues have been fully remediated.”
The carve-outs are important: examiners may independently validate when the internal audit function is ineffective, doesn’t exist, or hasn’t validated the remediation. But where those conditions don’t apply — where the internal audit function is credible and has done validation work — examiners are directed to accept that work rather than re-run their own testing.
The practical effect: institutions with strong, credible internal audit functions should see faster MRA closure. The sustainability-testing cycle — where examiners wait to confirm that remediations hold over time before formally closing findings — should be shorter when internal audit has already done that validation work.
This is different from Policy Change 1. Audit validation for MRA closure is about speed to closure for already-cited findings. Self-identification for supervisory observation treatment is about avoiding the MRA citation in the first place. They complement each other but address different parts of the examination lifecycle.
Why This Matters Now: The Broader Reform Context
The Fed’s revised principles don’t exist in isolation. They’re part of a broader shift in the supervisory posture that Governor Michelle Bowman has been articulating since taking her position. In her July 2026 speech on modernizing financial regulation and earlier at the Kansas City Future of Banking Conference in May, the themes are consistent: examination processes should be proportionate, findings should be tied to real risk, and the examination culture should support remediation rather than just cataloging deficiencies.
The OCC and FDIC ran a parallel but structurally different reform. Their joint October 2025 NPRM — OCC Bulletin 2025-29, published in the Federal Register at FR 2025-19711 — proposed to formally define “unsafe or unsound practice” and limit formal MRA issuance to practices that cause or are likely to cause material financial harm, or that constitute actual violations of law.
The Fed took a different path: rather than proposing a formal rule change, it revised internal supervisory policy through the operating principles document. Institutions regulated by the Fed are working under the new internal policy now. Institutions regulated by the OCC or FDIC are working under the existing formal framework while the NPRM moves through the rulemaking process — with no guarantee of finalization on any particular timeline.
This matters for mixed-charter institutions and holding company structures. The legal entity that’s Fed-regulated has access to the self-disclosure benefit under the revised principles. The national bank or thrift subsidiary regulated by OCC operates under a different, still-in-progress reform process.
If you want to understand what examiners are actually finding across different risk domains right now — context that shapes how self-identification and remediation credibility are evaluated — our 2026 TPRM examination findings analysis covers what’s getting flagged and why documentation quality matters.
What Your Issues Management Program Needs to Actually Capture This
The self-disclosure benefit doesn’t kick in because you have a compliance program. It kicks in because your program actually finds problems first. That requires capabilities that many programs nominally have but don’t operationalize:
Continuous identification, not periodic audit. Internal audit cycles are quarterly or annual. The self-disclosure benefit requires that you identify a deficiency before the examiner does — which means the identification mechanism needs to run continuously, not on audit schedule. Control self-assessments, exception tracking, metric monitoring, and escalation protocols all need to be running between audit cycles to actually catch things first.
Escalation that moves fast enough to be “prompt.” The Fed’s policy requires “prompt” remediation start after self-identification. What counts as prompt isn’t defined precisely, but the spirit is clear: you can’t find a problem in January, sit on it through Q1 planning, and claim self-disclosure benefit when examiners arrive in June. Issues need to move through escalation to corrective action in a timeframe that’s defensible.
Documentation of the identification chain. When an examiner asks why this issue is showing as a supervisory observation rather than an MRA, the institution needs to show: when the issue was identified, who identified it, how it was escalated, when remediation started, and what the remediation status is. That documentation needs to exist before the exam, not be reconstructed after the question is asked.
A credible internal audit function. The MRA-closure benefit is conditioned on internal audit actually being effective. An audit function that routinely validates everything management says it fixed — without independent control testing — isn’t going to earn examiner reliance. Building credible audit validation means the function needs to do real testing, issue formal validation opinions, and maintain independence from the functions it’s validating.
If you’re using spreadsheets and email to track open issues, the documentation trail needed to support both exam preparation and audit validation is going to be incomplete. The specific evidence gaps — no timestamp on when an issue was identified, remediation status in someone’s head rather than a tracked record, audit validation captured as a verbal update — are exactly what examiners will look for when deciding whether supervisory observation or MRA treatment applies.
For a look at what the formal MRA response process looks like once an examiner does issue an MRA — and how to structure a response that supports timely closure — our MRA remediation playbook covers the response framework, timelines, and documentation expectations.
The Internal Audit Credibility Problem
The internal audit provision in the revised principles introduces a calibration challenge. Examiners will rely on internal audit “ordinarily” — but “ordinarily” is conditioned on the audit function being effective. Examiners retain authority to independently validate when they don’t trust the function.
For many midsize institutions, the answer to “is our internal audit credible with examiners?” often isn’t clear until an exam cycle reveals it. The signals are indirect:
- Prior exam reports that cited internal audit methodology as a concern
- CAMELS ratings where the management component reflects concern about oversight functions
- Prior instances where examiners re-validated issues that internal audit had signed off on
- Exam feedback that audit validation didn’t cover all relevant controls
If any of these signals are present, the audit-validation benefit is less available than the revised principles suggest on paper. And building credibility with examiners takes time — it accumulates through consistent performance over multiple exam cycles, not through a single well-documented validation effort.
Institutions that haven’t had their internal audit function assessed against examiner expectations recently may want to do that work before relying on the policy change.
What to Do Before Your Next Exam
| Action | Why It Matters |
|---|---|
| Audit your issues management process for identification gaps | Self-disclosure benefit requires you find it first — know what’s slipping through |
| Document the identification-to-escalation timeline for current open issues | Examiners will ask about timing when evaluating supervisory observation eligibility |
| Have internal audit validate remediation before the exam, not during | Audit validation needs to be completed and documented when examiners arrive |
| Assess whether your audit function is likely to be viewed as credible | If there’s doubt, initiate a quality assessment before the exam cycle |
| Map which legal entities are Fed-regulated vs. OCC/FDIC-regulated | The reformed policies apply differently — mixed structures need to know which applies where |
| Engage external audit resources for effectiveness assessment if needed | If the internal function has credibility questions, external validation may be worth the investment |
So What?
The Fed’s revised supervisory operating principles create a genuine policy incentive to build robust internal identification infrastructure. For the first time, there’s a formal mechanism where self-identifying problems produces a different examination outcome — not just better optics with the exam team, but a documented policy distinction between supervisory observation and MRA.
That benefit isn’t automatic. It requires prompt remediation, documented identification timelines, and a credible internal audit function that can validate closures. Institutions that have those capabilities in place are positioned to convert the policy change into real examination outcomes. Institutions that track issues in email chains and document remediation as “complete” without independent validation aren’t going to see the benefit.
The question isn’t whether the policy shift is meaningful — it is. The question is whether your issues management infrastructure is actually built to capture it.
If you’re formalizing your issues management program, the Issues Management Tracker gives you the structured tracking, escalation, and documentation framework to build the identification-to-remediation chain that the revised principles are designed to reward.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What changed in the Federal Reserve's April 2026 Statement of Supervisory Operating Principles?
What is the difference between a supervisory observation and an MRA?
How does the Federal Reserve's self-disclosure policy change examination incentives?
What is the OCC/FDIC NPRM on MRA reform and how does it relate to the Fed's supervisory principles?
How should an internal audit function be structured to take advantage of the Fed's new audit-validation policy?
What is a 'supervisory operating principles' document and how does it differ from formal regulatory guidance?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Compliance Strategy
GRC Framework for a Small Risk Team: One Control Library, Five Workflows, No Enterprise Platform
A GRC program that runs on one control library, five traceable workflows, and a set of spreadsheets beats a half-implemented enterprise platform every time. Here's how to build it.
Jul 24, 2026
Compliance Strategy
Compliance Monitoring Plan in Excel: Convert the Risk Assessment Into a Defensible Test Universe
Build a compliance monitoring plan template in Excel that traces risks and obligations to scope, evidence, exceptions, and remediation.
Jul 23, 2026
Compliance Strategy
Your Reg E Program Wasn't Built for FedNow: The Error Resolution Timeline Trap in Instant Payments
Reg E's 10-business-day provisional credit requirement applies to FedNow and RTP consumer transactions—but instant payment irrevocability means the fraud money is gone before you finish the investigation. Here's what your error resolution procedures actually need to say for instant payments, and where most programs have a documented gap.
Jul 22, 2026