Breaking Regulatory Compliance
The OCC and FDIC Just Defined 'Unsafe or Unsound' for the First Time. What the New MRA Standard Means for Your Bank.
On August 27, 2026, the OCC and FDIC finalized a joint rule defining 'unsafe or unsound practice' for the first time in 70 years — and overhauled how MRAs get issued. Here's what compliance teams at national banks and FDIC-supervised institutions need to understand.
Table of Contents
TL;DR
- On August 27, 2026, the OCC and FDIC issued a joint final rule that formally defines “unsafe or unsound practice” for the first time since section 8 of the Federal Deposit Insurance Act was enacted in 1950
- Under the new rule, examiners can only issue MRAs for practices that are contrary to generally accepted prudent standards AND pose material financial risk or constitute an actual legal violation
- “Supervisory observations” are now the documented vehicle for flagging weaknesses that don’t clear the MRA bar — lower pressure, but still tracked
- The rule applies only to OCC- and FDIC-supervised institutions; the Federal Reserve is not a party
The term has been in banking law since 1950. Nobody ever defined it.
“Unsafe or unsound practice” — the foundational basis for the OCC and FDIC’s enforcement authority under section 8 of the Federal Deposit Insurance Act — spent 76 years without a statutory definition. Examiners used it. Courts interpreted it. Banks and their counsel argued about its scope in enforcement proceedings. But as a formal regulatory definition, binding on examiners and agencies alike, it didn’t exist.
Until August 27, 2026.
The joint OCC/FDIC final rule issued that day doesn’t just fill a definitional gap. It rewrites the threshold for when an examiner can issue a Matter Requiring Attention — the formal supervisory citation that triggers mandatory corrective action and escalating oversight. For compliance teams at national banks, federal savings associations, state nonmember banks, and state savings associations, understanding what changed is now part of managing your regulatory exam posture.
The 70-Year Definitional Gap
The absence of a formal definition for “unsafe or unsound practice” wasn’t a regulatory accident. For decades, the banking agencies argued that flexibility was essential — that defining the term would allow banks to engineer around it, doing things that were technically outside the definition but still dangerous.
That argument has merit in some contexts. But in practice, the absence of a definition meant that the universe of things an examiner could call “unsafe or unsound” was effectively unbounded. MRAs were issued for policy gaps, documentation shortfalls, internal process weaknesses, and governance concerns that — in the examiner’s judgment — were problematic but didn’t necessarily pose material financial risk to the institution or the Deposit Insurance Fund.
The volume and scope of MRAs became a persistent compliance burden, particularly for community and midsize banks. An examiner who spotted a weakness in, say, the bank’s third-party vendor contract review process could issue an MRA even if the bank had no material vendor concentration, no material exposure to vendor failure, and no actual legal violation. The weakness was real; the material financial risk may not have been.
The October 2025 proposed rulemaking put a formal framework on the table. The August 2026 final rule codifies it.
The New Two-Part Definition
Under the joint final rule, “unsafe or unsound practice” means a practice, act, or failure to act that satisfies both of the following elements:
Element 1: Contrary to generally accepted standards of prudent operation. The practice must depart from what reasonable, prudent banking operators would do. This is a professional-standard test — not whether the bank made a mistake, but whether the bank’s conduct falls below the standard that the industry, regulators, and courts would recognize as reasonable. Violations of this prong alone are not sufficient for an MRA.
Element 2: Material financial risk or actual violation of law. The practice must also either:
- If continued, be likely to materially harm the financial condition of the bank, OR present a material risk of loss to the Deposit Insurance Fund; OR
- Constitute an actual violation of a banking or banking-related law or regulation.
Both elements must be present. A practice that departs from prudent standards but poses no material financial risk and doesn’t violate any law — a documentation gap, a process inefficiency, a governance concern without financial consequence — no longer meets the definition for MRA purposes.
The second prong is the significant change. Materiality now functions as an explicit gate.
What Changes for MRAs
The practical impact is that examiners must make a more explicit judgment call before issuing an MRA: does this weakness pose material financial risk to the bank or the DIF, or does it involve an actual legal violation?
This changes the landscape in several ways:
More MRAs will be process and legal violations, fewer will be documentation concerns. Under the prior framework, an examiner could issue an MRA for a bank’s failure to follow its own internal policy — even if that failure didn’t create material financial exposure. Under the new framework, that’s a supervisory observation unless the failure rises to the level of a legal violation or creates material financial risk.
Materiality requires analysis, not just observation. An examiner who wants to issue an MRA for a weak control environment now needs to connect that weakness to potential financial harm — not just note that the control is weaker than it should be. That’s a different kind of analytical burden on the examination team, and it provides compliance counsel a clearer basis for discussion.
The legal violation prong means actual violations still generate MRAs. If a bank is violating the Bank Secrecy Act, the Community Reinvestment Act, consumer protection requirements, or any other banking law — that’s an actual violation, and the MRA standard is met regardless of materiality. The rule does not create a safe harbor for legal noncompliance.
The New “Supervisory Observation” Category
This is the mechanism that handles what falls below the MRA bar: the supervisory observation.
A supervisory observation is a formal examiner communication that identifies a weakness, gap, or concern that the examiner believes warrants management attention but does not rise to the level of an MRA under the new definition. It’s documented in examination findings. It’s communicated to management. But it doesn’t carry the mandatory corrective action requirements that an MRA triggers, and it doesn’t initiate the formal escalation path that can lead to enforcement action.
From a compliance program standpoint, this distinction matters:
- An MRA requires a formal management response with a committed remediation timeline, and it’s tracked by the examiner for progress on subsequent examinations. Failure to remediate an MRA adequately can lead to formal enforcement action.
- A supervisory observation creates an expectation that management will consider and address the concern. Not addressing it creates its own risk — examiners who see the same observation in the next examination cycle will question whether management is responsive — but it doesn’t carry the same mandatory corrective action framework.
Compliance teams need to update their exam management workflows to distinguish between these two communication types and treat them accordingly.
The Examiner Lookback Limit
Buried in the companion revised Policies and Procedures Manuals released the same day — OCC Bulletin 2026-41 — is a notable procedural change: a one-year lookback cap for SAR-related examination findings.
OCC examiners will now face a general one-year limit on lookback periods when examining a bank’s suspicious activity reporting. If the examination is reviewing whether the bank appropriately filed or declined to file SARs for transactions that occurred more than a year ago, the new procedures limit how far back they can look.
This matters because SAR reporting has historically been a significant source of MRAs, particularly for community banks with limited BSA/AML compliance infrastructure. Examiners sometimes surfaced SAR filing decisions from two or three years earlier, even after the bank had since improved its processes. The one-year cap limits that lookback.
The practical implication for compliance programs: document your SAR determinations contemporaneously, including your documented reasoning for non-filing decisions. The lookback limit narrows the window — but within that window, examiner scrutiny of your SAR decisions is still real.
The Broader Deregulatory Supervision Package
The August 2026 rule doesn’t stand alone. It’s the third significant move in a deregulatory supervision package that the OCC and FDIC have assembled this year:
April 2026 — Reputation risk eliminated. The OCC and FDIC finalized a rule prohibiting both agencies from taking adverse action against banks on the basis of reputation risk — defined as risks to public perception not clearly and directly related to the financial or operational condition of the institution. This rule also prohibited examiners from requiring or encouraging banks to close accounts based on political, social, or religious views, or lawful business activities perceived to present reputational concerns.
August 27, 2026 — MRA framework and enforcement PPMs revised simultaneously. Alongside the “unsafe or unsound” final rule, the OCC released revised Policies and Procedures Manuals governing both its bank enforcement actions (PPM 5310-3) and its MRA process (PPM 5400-11). These PPMs align the agencies’ internal procedures with the new statutory definitions — so examiners’ written guidance matches the legal standard.
The picture that emerges is a deliberate effort to raise the materiality floor on supervisory pressure, limit the scope of what examiners can call unsafe or unsound, and create formal distinctions between informal supervisory communication and binding corrective action requirements.
What Doesn’t Change
Several things remain unchanged that compliance teams should not misread as newly optional:
Legal violations still generate MRAs. If your BSA/AML program has genuine legal compliance failures — actual violations of statute or regulation — the new materiality gate doesn’t apply. The “actual violation” prong of the definition is met, and an MRA is appropriate.
Weak controls are still a problem even without MRAs. A supervisory observation about a weak control environment is a documented finding that management has seen. Controls that fail to prevent violations generate legal violations, which generate MRAs. The new framework doesn’t make weak controls safe — it creates a formal category for flagging them before they produce material harm.
The Federal Reserve is not part of this. Bank holding companies, financial holding companies, state member banks, and any institution supervised by the Federal Reserve System should not assume that the OCC/FDIC framework applies to them. CCO personal liability frameworks span regulators; the new MRA standard does not.
Examination priorities haven’t changed. The areas regulators care about — BSA/AML, CRA performance, fair lending, operational resilience — remain in scope. What’s changed is the threshold at which a weakness generates formal corrective action, not the scope of what examiners examine.
What Compliance Programs Need to Adapt
Three concrete adjustments for compliance teams at OCC- and FDIC-supervised institutions:
1. Update your issues management framework to reflect the MRA/supervisory observation distinction. Your existing issues tracker likely doesn’t distinguish between MRAs and other examination findings by the new materiality threshold. Build that distinction in now — so that when an examiner communicates a supervisory observation, your tracking, escalation, and remediation workflows treat it differently from an MRA.
2. Update your exam management process to understand what the examiner communicated and why. The new framework gives you analytical tools to engage with examiners on categorization — if an examiner characterizes something as an MRA, you should be able to ask whether it meets both prongs of the definition. That’s not obstruction; it’s the normal dialogue of examination management, and the new rule gives compliance counsel a clearer legal framework to work within.
3. Maintain the discipline of finding your own weaknesses before examiners do. The OCC/FDIC rule raises the formal bar for MRAs, but it doesn’t diminish the value of a strong RCSA and internal audit function that identifies control gaps. A supervisory observation that management anticipated and addressed before the examination shows a responsive risk management culture. A supervisory observation that surprises management shows the opposite — even if the formal consequences are limited.
This is the irony of the new framework: a higher MRA bar doesn’t make compliance programs less important. It makes proactive issue identification more important, because the formal enforcement mechanism now kicks in later in the weakness lifecycle, when harm is already materializing.
So What?
The OCC and FDIC created a formal definition for “unsafe or unsound” practice — and in doing so, they drew a cleaner line between what generates mandatory corrective action and what generates a documented observation. That line matters for how compliance programs prioritize remediation, how counsel engages with examiners, and how management reports to boards on examination results.
The caveat is that the line doesn’t make weak controls acceptable. Material financial risk often starts as a minor control gap that compounds over time. Supervisory observations left unaddressed have a way of becoming MRAs in the next examination cycle.
The new framework rewards compliance programs that find their own problems. The same discipline that generates early self-identification — regular RCSA updates, issues tracking, internal audit cadence — is exactly what you’d want to demonstrate to an examiner who’s now looking for material financial risk rather than process imperfection.
The enforcement floor went up. The standard for a well-run compliance program didn’t.
Tracking exam findings, MRAs, and supervisory observations across your program requires a system that captures source, severity, owner, and remediation timeline in one place. The Issues Management Tracker is built for exactly that — pre-formatted for regulatory exam findings, with an executive dashboard that shows your examiner what a managed, responsive compliance program looks like.
Sources:
- OCC Bulletin 2026-40: Unsafe or Unsound Practices and Matters Requiring Attention: Final Rule
- OCC Bulletin 2026-41: Revised Policies and Procedures Manuals for Bank Enforcement Actions and MRAs
- OCC and FDIC Finalize Narrower Bank Supervision Procedures — American Banker
- FDIC and OCC Formally Define Unsafe and Unsound Practices — ABA Banking Journal
- Federal Register: Unsafe or Unsound Practices, Matters Requiring Attention (NPRM, October 2025)
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is the new legal definition of 'unsafe or unsound practice' under the OCC/FDIC final rule?
How does the new MRA standard change what examiners can issue MRAs for?
What is a 'supervisory observation' under the new framework, and how is it different from an MRA?
Does the new rule apply to the Federal Reserve's bank examinations?
What is the new examiner lookback limit included in the revised procedures?
How should compliance programs respond to the new OCC/FDIC MRA framework?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
● Don't wait for your own enforcement action
Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Regulatory Compliance
FinCEN’s Banque Misr UAE Section 311 Rule: What U.S. Banks Need to Build Now
FinCEN’s Banque Misr UAE Section 311 proposal would require screening, correspondent notices, and documented controls at U.S. financial institutions.
Aug 28, 2026
Regulatory Compliance
SEC False Form ADV Cases: 38 Fake Advisers Turned a Public Filing Into a Trust Signal
The SEC sued 38 entities over false Form ADV filings. Here is how compliance teams should verify advisers when a public filing is not proof of approval.
Aug 28, 2026
Regulatory Compliance
The DOL Reverts to 1975: What the Retirement Security Rule Vacatur Means for Rollover Recommendations, PTE 2020-02, and Your Compliance Program
The DOL's 2024 Retirement Security Rule was vacated by the courts. The 1975 five-part test is back. Here's what that means for rollover recommendations, PTE 2020-02, and investment advice compliance programs that built controls around a rule that no longer exists.
Aug 27, 2026