Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Breaking Regulatory Compliance

The OCC's New Two-Tier Violation Framework: What 'Substantive vs. Technical' Means for Your Compliance Program

OCC Bulletin 2026-42, published September 1, proposes for the first time a formal distinction between 'substantive' and 'technical' violations of banking law — with MRAs limited to substantive violations only. Comment deadline is October 1.

By Rebecca Leung · September 5, 2026 ·
Table of Contents

TL;DR

  • On September 1, 2026, the OCC proposed a first-ever formal distinction between “substantive” and “technical” violations of banking law — with MRAs reserved exclusively for substantive violations
  • A violation is substantive if it meets one of five criteria: systemic pattern, more-than-minimal financial impact, bad books and records, consumer harm, or insider misconduct
  • Technical violations must be corrected but cannot generate MRAs or examiner-prescribed remediation
  • The comment deadline is October 1, 2026 — less than four weeks out
  • This NPRM runs parallel to, but is separate from, the OCC/FDIC final rule on unsafe/unsound practices (OCC Bulletin 2026-40)

Eight days after the OCC and FDIC finalized the first-ever statutory definition of “unsafe or unsound practice”, the OCC published a second piece of its supervisory reform package — this one aimed at a question the final rule didn’t answer.

The final rule addressed unsafe or unsound practices. But what about violations of actual laws and regulations? When an examiner finds a BSA violation, a fair lending gap, or an OFAC screening miss — does every one of those findings generate an MRA? Under the current framework, the answer is essentially yes, subject to examiner discretion. Under the proposed rule published in OCC Bulletin 2026-42 on September 1, the answer becomes: it depends on whether the violation is “substantive” or “technical.”

The comment deadline is October 1. That’s a short window for a proposed rule that will meaningfully change how examiners communicate legal violations to the banks they supervise.

What the NPRM Actually Proposes

OCC Bulletin 2026-42 proposes to amend the OCC’s regulatory framework for how it issues MRAs in response to violations of banking or banking-related laws and regulations. At the core is a simple binary: every violation the OCC identifies will be classified as either “substantive” or “technical.”

Substantive violations trigger MRAs. They get the full weight of the formal supervisory finding process — documented in examination reports, tracked for remediation, potentially escalated to enforcement action if not addressed.

Technical violations do not trigger MRAs. The OCC can require correction, but under the proposal, it cannot prescribe how the bank must correct the violation, and it cannot require remediation steps unrelated to the correction itself. The examiner documents the finding, but the bank retains meaningful discretion over how to respond.

This matters because MRAs carry mandatory corrective action requirements and appear in examination reports that bank partners, auditors, and counterparties can request. Technical violations, by contrast, would be a lower-pressure supervisory communication — more like the “supervisory observation” category created by the companion final rule for non-law-violation findings.

The Five-Category Substantive Test

The heart of the proposed rule is its definition of when a violation crosses from technical to substantive. The general standard is whether the violation’s “nature, duration, frequency, or severity could meaningfully impact the bank or its customers.” That’s broad — intentionally so. But the rule backs it up with five specific categories. A violation is substantive if any one of the following applies:

1. Systemic pattern. The violation reflects a pattern across multiple incidents or transactions, as opposed to a one-off error. A single SAR filing miss during a system outage looks different from a monitoring program that systematically fails to flag a category of transactions. Examiners have always distinguished these informally; the NPRM proposes to codify the distinction.

2. More-than-minimal financial effect. The violation had a material financial impact on the bank or its customers — losses, overcharges, missed payments, or economic harm that exceeded a de minimis threshold. The rule does not define “minimal” quantitatively, which is one area where commenters may want to push for more precision.

3. Inaccurate or unreliable books and records. The violation corrupted the bank’s financial records or reporting — CALL Report errors, ledger inaccuracies, regulatory filing misstatements. This is a bright line: if the violation touched the integrity of the institution’s books, it’s substantive.

4. Consumer harm or restitution required. The violation caused identifiable harm to consumers, requiring restitution or remediation payments. This includes fair lending violations resulting in adverse action on protected-class borrowers, fee overcharges requiring customer credits, or UDAAP-grounded conduct resulting in consumer losses.

5. Insider misconduct or self-dealing. The violation involved an officer, director, or employee acting in their own interest at the bank’s or customers’ expense. This is the classic supervisory bright line — any time misconduct or self-dealing is involved, the finding is substantive by definition.

If a violation doesn’t meet any of the five criteria, it’s technical. The examiner can require correction but cannot escalate it to MRA status.

What This Changes for BSA/AML and OFAC Programs

The banking law areas where these categories will matter most are BSA/AML and OFAC — precisely the areas where compliance teams often face examination findings that look serious in isolation but represent discrete, correctable gaps rather than systemic program failures.

Under the current framework, an examiner who identifies a CTR filing error or an OFAC hit that was resolved but not escalated through the right internal channels can issue an MRA based largely on their judgment. Under the proposed rule, they would need to assess whether the violation meets one of the five categories before doing so.

An isolated CTR error with no pattern, no customer harm, and no books/records impact would likely be a technical violation — correctable without an MRA. A monitoring program that missed a category of high-risk transactions for six months, producing dozens of unfiled SARs, would almost certainly be substantive under the systemic pattern and potentially the consumer harm categories.

This distinction is already embedded in how sophisticated compliance teams evaluate their own programs. The NPRM proposes to make it the formal examiner standard — and that’s a significant shift from the consent order anatomy we’ve mapped before.

What “Technical Violation” Actually Means for Your Operations

One of the most practically important aspects of the proposed rule is what happens after a technical violation is identified. The OCC can require the bank to correct it. But the rule explicitly limits the examiner’s authority in two ways:

First, the examiner cannot prescribe how the bank corrects the violation. If a system error caused a handful of incorrect CALL Report fields, the examiner can require correction — but cannot mandate a specific technology change, a vendor replacement, or a management restructuring as the remedy.

Second, the examiner cannot impose remediation steps unrelated to correction of the violation. This is a meaningful constraint. Under the current informal framework, an examiner who finds a technical error sometimes uses it as an entry point to require broader compliance program enhancements that go beyond what the specific violation required. The proposed rule would prohibit that: the remediation must be proportionate to the actual violation.

For compliance teams, this means that documenting your own analysis of violation severity — before the examination communication — will become more important. If your internal assessment characterizes a finding as technical and the examiner disagrees, having a documented rationale will matter.

The OCC Also Proposed to Limit Its Own BSA Lookback

One detail buried in the broader reform package that connects directly to the violations framework: the OCC’s revised Policies and Procedures Manual (OCC Bulletin 2026-41, also published September 1) includes a new limit on examiner lookback periods for suspicious activity reporting. For SAR-related findings, examiners generally face a one-year lookback cap.

This matters for the substantive/technical analysis because the “systemic pattern” category depends partly on duration. A BSA monitoring gap that persisted for 18 months looks different under a framework that caps examiner review at 12 months. Compliance programs should maintain contemporaneous records of SAR decisions — including documented decisions not to file — specifically because examiner review of past decisions remains meaningful within the lookback window.

Why the Comment Deadline Matters

The October 1 comment deadline is unusually short for an NPRM with this scope. Four weeks from Federal Register publication to comment close is compressed, and it’s worth asking why.

The OCC has signaled that the violations framework is intended to accompany the final rule that took effect August 27. Finalizing this rule quickly — by Q1 2027 — would complete the supervisory reform package the OCC has been building since 2025. Industry associations, law firms, and compliance trade groups should be preparing comments now.

For individual institutions, the more useful response is internal: use the comment period as a forcing function to audit your issues management program against the five-category substantive test. Where do your open BSA, OFAC, fair lending, and consumer compliance findings fall on that spectrum? What would the examiner classify as substantive versus technical? If you can’t answer that question confidently, your issues log needs to be retooled.

So What Does This Mean for Your Compliance Program?

The OCC’s proposed violation framework is part of a consistent pattern: the agency is moving from a check-the-box, documentation-driven supervision model toward a risk-based model focused on material findings. The final rule defined “unsafe or unsound” for the first time in 70 years. This NPRM proposes to apply the same materiality logic to legal violations.

For compliance programs built around the assumption that any identified violation generates an MRA, the framework requires recalibration. You still need to find, document, and remediate every violation — technical or substantive. What changes is the supervisory weight each finding carries, and the examiner’s authority to prescribe your remedy.

Three things your compliance function should do before October 1:

1. Map your open issues against the five categories. Go through every open compliance finding and ask: which of the five criteria would this meet? If the answer is “none,” it’s probably a technical violation under the proposed rule. That’s useful information for your risk committee and your examiner relationship.

2. Review your issues management escalation criteria. If your current escalation framework treats every legal violation as an MRA-equivalent, you need to update it. The proposed rule does not eliminate the compliance obligation — it changes the examiner communication and remediation authority. Your internal escalation should track the proposed standard so that it’s defensible if an examiner challenges your characterization.

3. Consider commenting. If the five-category list creates ambiguity for your regulatory footprint — particularly around BSA/AML pattern violations, OFAC screening errors, or fair lending disparities — the comment period is your opportunity to shape the final rule. Comments that offer specific, operationally grounded scenarios are far more useful than general objections.

The Issues Management Tracker is built to track this kind of nuanced severity categorization — with severity tiers, root cause classification, and escalation tracking across source types. If you’re rebuilding your issues log in anticipation of the new framework, it gives you a pre-built structure to start from.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is OCC Bulletin 2026-42 and how does it differ from the final rule published the same day?
OCC Bulletin 2026-42 is a notice of proposed rulemaking — still in comment period — that proposes to formally define 'substantive' and 'technical' violations of laws and regulations, and limit MRAs to substantive violations only. The companion final rule (OCC Bulletin 2026-40) is already effective and addresses 'unsafe or unsound practices.' These are parallel tracks of the same supervisory reform initiative: the final rule defines the unsafe/unsound standard; the NPRM proposes a separate framework for legal violations.
What makes a violation 'substantive' under the proposed rule?
A violation is substantive if its nature, duration, frequency, or severity could meaningfully impact the bank or its customers. The proposed rule backs that general standard with five concrete categories: (1) systemic violations showing a pattern across multiple incidents or transactions, (2) violations that have more than a minimal financial effect on the bank or its customers, (3) violations that result in inaccurate or unreliable books and records, (4) violations that caused consumer harm or require restitution, and (5) violations that involved insider misconduct or self-dealing. A violation meeting any one of the five is substantive.
What is a 'technical violation' and what happens when an examiner finds one?
A technical violation is a violation that does not meet the substantive standard — it doesn't show a pattern, doesn't have material financial effects, doesn't corrupt your records, didn't harm consumers, and doesn't involve misconduct. Under the proposal, the OCC can require the bank to correct a technical violation but cannot prescribe how the bank must do so and cannot impose remediation steps unrelated to the actual correction. No MRA is issued. It's still documented, but the supervisory weight is significantly lower than a formal MRA.
Does this proposal apply to the FDIC and Federal Reserve?
No. OCC Bulletin 2026-42 is an OCC-only proposed rulemaking. The FDIC published a companion final rule on the unsafe/unsound standard (alongside the OCC), but has not issued a parallel proposed rule on the violations framework. The Federal Reserve is not part of either initiative. If you have Federal Reserve-supervised entities — state member banks, bank holding companies, financial holding companies — the OCC's substantive/technical framework does not apply to them.
When is the comment deadline and how should compliance teams approach it?
Comments are due on or before October 1, 2026 — four weeks from the September 1 Federal Register publication. Compliance teams and their legal counsel should consider commenting if the proposed definition of 'substantive' violation is ambiguous for common examination scenarios, if the five-category list creates uncertainty for specific regulatory areas (BSA, fair lending, OFAC), or if the carve-out for non-banking-related laws needs clarification for multi-regulatory environments. Smaller institutions with limited examiner relationships often benefit most from clear standards — so the comment period matters to community banks and BaaS sponsor banks alike.
How should my issues management program adapt in anticipation of this rule?
Start by tagging your open issues and historical findings against the proposed five-category substantive standard. Items that would clearly be 'technical' under the proposal still need to be remediated — but they represent a different risk profile than MRA-level findings. Your issues log should distinguish between items your examiner would characterize as substantive versus technical, so that risk committee reporting reflects the difference. If the rule is finalized, you'll also want your exam management process to document your own view of violation severity before the examiner communicates theirs.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

● Don't wait for your own enforcement action

Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.