Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Compliance Strategy

The Fed Changed the Math on Self-Disclosure: What the Revised Supervisory Operating Principles Mean for Your Issues Program

On April 30, 2026, the Federal Reserve released a revised Statement of Supervisory Operating Principles with two policy changes that make self-identifying problems genuinely worthwhile. Self-disclosed deficiencies now get supervisory observation treatment instead of MRAs — if you start remediating promptly. Here's what that means and how to make your issues management program work for you in exams.

Table of Contents

For years, the examination incentives ran in one direction: if examiners were going to find problems anyway, there wasn’t much upside to finding them first. Self-disclosure meant you’d still get an MRA. The examiner’s job was to validate remediation regardless. The only difference between self-identifying a gap and an examiner catching it was that the self-disclosure might get you to remediation a few months earlier.

The Federal Reserve’s revised Statement of Supervisory Operating Principles, released April 30, 2026, changes that math.

Not dramatically, and not unconditionally. But for the first time, there’s a formal policy mechanism where institutions that build real self-identification infrastructure get better examination outcomes than institutions that wait to be caught.

TL;DR

  • The Federal Reserve’s April 30, 2026 revised Statement of Supervisory Operating Principles contains two significant policy shifts for examination management
  • Self-identified deficiencies that are promptly remediated will presumptively get supervisory observation treatment instead of MRA classification
  • Examiners are now directed to ordinarily rely on internal audit validation for MRA closure, rather than independently re-testing
  • The OCC and FDIC ran a parallel but distinct reform: a joint NPRM proposing to limit MRAs to “material financial harm” scenarios — still pending as of mid-2026
  • Together, these shifts make internal self-identification and a credible audit function structurally worth building — for regulatory reasons, not just governance ones

What the Revised Principles Actually Changed

The Statement of Supervisory Operating Principles is an internal Fed policy document governing how supervisory staff conduct examinations and communicate findings. It’s not a rule; it’s an internal standard. But internal standards govern examiner behavior, and examiner behavior is what institutions experience.

The April 2026 revision contains two distinct policy changes that compliance programs need to understand — and they work differently.

Policy Change 1: Self-Identification Gets Better Treatment

The revised principles state that if a Board-supervised banking organization self-identifies a deficiency that would otherwise satisfy the standard for an MRA or MRIA based on a threat to safety and soundness, and promptly starts remediating that deficiency in a manner determined to be reasonable by supervisory staff, the deficiency will presumptively be treated as giving rise to a supervisory observation rather than an MRA or MRIA.

This creates a two-part trigger:

  1. The institution identifies the problem first (not the examiner)
  2. The institution starts remediation promptly and proceeds reasonably

Both conditions must be present. Self-identification without prompt remediation doesn’t get you the benefit. And the “presumptively” qualifier matters — it’s not a guarantee. Examiners retain discretion to treat the deficiency as an MRA if the self-identification wasn’t genuine or if remediation isn’t actually progressing.

But for institutions with real internal identification programs — issues management processes that catch control gaps, compliance failures, and operational weaknesses before the exam team arrives — this creates a structural advantage. Being first to find your problems now has a documented regulatory payoff.

Policy Change 2: Internal Audit Can Close MRAs

The second change addresses how already-cited MRAs get closed. The revised principles direct supervisory staff to “ordinarily rely on a banking organization’s internal audit validation to determine whether issues have been fully remediated.”

The carve-outs are important: examiners may independently validate when the internal audit function is ineffective, doesn’t exist, or hasn’t validated the remediation. But where those conditions don’t apply — where the internal audit function is credible and has done validation work — examiners are directed to accept that work rather than re-run their own testing.

The practical effect: institutions with strong, credible internal audit functions should see faster MRA closure. The sustainability-testing cycle — where examiners wait to confirm that remediations hold over time before formally closing findings — should be shorter when internal audit has already done that validation work.

This is different from Policy Change 1. Audit validation for MRA closure is about speed to closure for already-cited findings. Self-identification for supervisory observation treatment is about avoiding the MRA citation in the first place. They complement each other but address different parts of the examination lifecycle.


Why This Matters Now: The Broader Reform Context

The Fed’s revised principles don’t exist in isolation. They’re part of a broader shift in the supervisory posture that Governor Michelle Bowman has been articulating since taking her position. In her July 2026 speech on modernizing financial regulation and earlier at the Kansas City Future of Banking Conference in May, the themes are consistent: examination processes should be proportionate, findings should be tied to real risk, and the examination culture should support remediation rather than just cataloging deficiencies.

The OCC and FDIC ran a parallel but structurally different reform. Their joint October 2025 NPRM — OCC Bulletin 2025-29, published in the Federal Register at FR 2025-19711 — proposed to formally define “unsafe or unsound practice” and limit formal MRA issuance to practices that cause or are likely to cause material financial harm, or that constitute actual violations of law.

The Fed took a different path: rather than proposing a formal rule change, it revised internal supervisory policy through the operating principles document. Institutions regulated by the Fed are working under the new internal policy now. Institutions regulated by the OCC or FDIC are working under the existing formal framework while the NPRM moves through the rulemaking process — with no guarantee of finalization on any particular timeline.

This matters for mixed-charter institutions and holding company structures. The legal entity that’s Fed-regulated has access to the self-disclosure benefit under the revised principles. The national bank or thrift subsidiary regulated by OCC operates under a different, still-in-progress reform process.

If you want to understand what examiners are actually finding across different risk domains right now — context that shapes how self-identification and remediation credibility are evaluated — our 2026 TPRM examination findings analysis covers what’s getting flagged and why documentation quality matters.


What Your Issues Management Program Needs to Actually Capture This

The self-disclosure benefit doesn’t kick in because you have a compliance program. It kicks in because your program actually finds problems first. That requires capabilities that many programs nominally have but don’t operationalize:

Continuous identification, not periodic audit. Internal audit cycles are quarterly or annual. The self-disclosure benefit requires that you identify a deficiency before the examiner does — which means the identification mechanism needs to run continuously, not on audit schedule. Control self-assessments, exception tracking, metric monitoring, and escalation protocols all need to be running between audit cycles to actually catch things first.

Escalation that moves fast enough to be “prompt.” The Fed’s policy requires “prompt” remediation start after self-identification. What counts as prompt isn’t defined precisely, but the spirit is clear: you can’t find a problem in January, sit on it through Q1 planning, and claim self-disclosure benefit when examiners arrive in June. Issues need to move through escalation to corrective action in a timeframe that’s defensible.

Documentation of the identification chain. When an examiner asks why this issue is showing as a supervisory observation rather than an MRA, the institution needs to show: when the issue was identified, who identified it, how it was escalated, when remediation started, and what the remediation status is. That documentation needs to exist before the exam, not be reconstructed after the question is asked.

A credible internal audit function. The MRA-closure benefit is conditioned on internal audit actually being effective. An audit function that routinely validates everything management says it fixed — without independent control testing — isn’t going to earn examiner reliance. Building credible audit validation means the function needs to do real testing, issue formal validation opinions, and maintain independence from the functions it’s validating.

If you’re using spreadsheets and email to track open issues, the documentation trail needed to support both exam preparation and audit validation is going to be incomplete. The specific evidence gaps — no timestamp on when an issue was identified, remediation status in someone’s head rather than a tracked record, audit validation captured as a verbal update — are exactly what examiners will look for when deciding whether supervisory observation or MRA treatment applies.

For a look at what the formal MRA response process looks like once an examiner does issue an MRA — and how to structure a response that supports timely closure — our MRA remediation playbook covers the response framework, timelines, and documentation expectations.


The Internal Audit Credibility Problem

The internal audit provision in the revised principles introduces a calibration challenge. Examiners will rely on internal audit “ordinarily” — but “ordinarily” is conditioned on the audit function being effective. Examiners retain authority to independently validate when they don’t trust the function.

For many midsize institutions, the answer to “is our internal audit credible with examiners?” often isn’t clear until an exam cycle reveals it. The signals are indirect:

  • Prior exam reports that cited internal audit methodology as a concern
  • CAMELS ratings where the management component reflects concern about oversight functions
  • Prior instances where examiners re-validated issues that internal audit had signed off on
  • Exam feedback that audit validation didn’t cover all relevant controls

If any of these signals are present, the audit-validation benefit is less available than the revised principles suggest on paper. And building credibility with examiners takes time — it accumulates through consistent performance over multiple exam cycles, not through a single well-documented validation effort.

Institutions that haven’t had their internal audit function assessed against examiner expectations recently may want to do that work before relying on the policy change.


What to Do Before Your Next Exam

ActionWhy It Matters
Audit your issues management process for identification gapsSelf-disclosure benefit requires you find it first — know what’s slipping through
Document the identification-to-escalation timeline for current open issuesExaminers will ask about timing when evaluating supervisory observation eligibility
Have internal audit validate remediation before the exam, not duringAudit validation needs to be completed and documented when examiners arrive
Assess whether your audit function is likely to be viewed as credibleIf there’s doubt, initiate a quality assessment before the exam cycle
Map which legal entities are Fed-regulated vs. OCC/FDIC-regulatedThe reformed policies apply differently — mixed structures need to know which applies where
Engage external audit resources for effectiveness assessment if neededIf the internal function has credibility questions, external validation may be worth the investment

So What?

The Fed’s revised supervisory operating principles create a genuine policy incentive to build robust internal identification infrastructure. For the first time, there’s a formal mechanism where self-identifying problems produces a different examination outcome — not just better optics with the exam team, but a documented policy distinction between supervisory observation and MRA.

That benefit isn’t automatic. It requires prompt remediation, documented identification timelines, and a credible internal audit function that can validate closures. Institutions that have those capabilities in place are positioned to convert the policy change into real examination outcomes. Institutions that track issues in email chains and document remediation as “complete” without independent validation aren’t going to see the benefit.

The question isn’t whether the policy shift is meaningful — it is. The question is whether your issues management infrastructure is actually built to capture it.

If you’re formalizing your issues management program, the Issues Management Tracker gives you the structured tracking, escalation, and documentation framework to build the identification-to-remediation chain that the revised principles are designed to reward.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What changed in the Federal Reserve's April 2026 Statement of Supervisory Operating Principles?
The Federal Reserve's revised Statement of Supervisory Operating Principles, released April 30, 2026, made two significant policy changes. First, it established that self-identified deficiencies that would otherwise qualify for MRA treatment will be presumptively treated as supervisory observations rather than MRAs, provided the institution promptly begins remediation in a manner that examiners determine is reasonable. Second, it directed examiners to ordinarily rely on a banking organization's internal audit validation to determine whether cited issues have been fully remediated, rather than requiring independent examiner re-testing unless the internal audit function is ineffective or hasn't validated the remediation.
What is the difference between a supervisory observation and an MRA?
A Matter Requiring Attention (MRA) is a formal supervisory communication that requires a written response, board-level reporting, and documented corrective action that examiners track and verify. Supervisory observations are lower-severity findings that institutions are expected to address but that don't carry the same formal tracking, board reporting, and sustainability-testing requirements. An MRA that goes unresolved can escalate to a Matters Requiring Immediate Attention (MRIA) and eventually to enforcement action. Supervisory observations that remain unaddressed over time can become MRAs. The distinction matters significantly for examination ratings, board agendas, and management bandwidth.
How does the Federal Reserve's self-disclosure policy change examination incentives?
Prior to the April 2026 revision, institutions faced a difficult calculation: self-identifying a problem might produce the same MRA as an examiner finding it, offering little benefit for disclosure. The revised principles change that calculation — if your institution identifies a gap, starts remediating promptly, and remediation is progressing reasonably when examiners arrive, the issue should be treated as a supervisory observation rather than an MRA. This creates a genuine incentive to build rigorous internal identification processes: finding problems first is now structurally better than being caught by examiners.
What is the OCC/FDIC NPRM on MRA reform and how does it relate to the Fed's supervisory principles?
In October 2025, the OCC and FDIC issued a joint NPRM (OCC Bulletin 2025-29, FR 2025-19711) proposing to define 'unsafe or unsound practice' and revise the framework for issuing MRAs and other supervisory communications. The proposal would limit formal MRA issuance to practices that cause or are likely to cause material financial harm or that constitute actual violations of law. This is a proposed rule — still pending — that would change the OCC and FDIC MRA framework, while the Federal Reserve ran its own internal process through the revised supervisory operating principles. Institutions regulated by the Fed face different rules than those regulated solely by the OCC or FDIC.
How should an internal audit function be structured to take advantage of the Fed's new audit-validation policy?
The Federal Reserve's revised principles allow examiners to ordinarily rely on internal audit validation for MRA closure — but only if the internal audit function is effective and has validated the remediation. An ineffective audit function doesn't get this benefit; examiners will independently validate instead. To take advantage of the policy, internal audit needs to: (1) have sufficient independence from management and the issues being validated, (2) document validation work with evidence of control testing, not just management attestation, (3) issue formal validation opinions on cited issues before the exam, and (4) maintain a track record of findings that supervisors view as reliable. Internal audit functions that routinely validate everything management says they've fixed are unlikely to earn examiner trust.
What is a 'supervisory operating principles' document and how does it differ from formal regulatory guidance?
The Federal Reserve's Statement of Supervisory Operating Principles is an internal policy document that governs how Fed supervisory staff conduct examinations, issue findings, and communicate with supervised institutions. It is not a rule published in the Federal Register and does not have the force of law. It establishes the internal standards examiners are expected to follow. Unlike formal supervisory guidance letters (SRs) or regulations, it can be revised without notice-and-comment rulemaking. Its significance is that it changes examiner behavior in ways institutions experience directly during examinations — even though the document itself is an internal policy, its effects are real.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.