Feature Operational Risk
Congress Never Defined 'Unsafe or Unsound.' Regulators Just Did. What the OCC/FDIC Final Rule Means for Your Risk Program.
The OCC and FDIC finalized a rule on September 1, 2026 that — for the first time in US banking history — defines 'unsafe or unsound practice' in regulation. Effective November 2, it reshapes what kinds of operational failures trigger MRAs. Here's what your risk program needs to change.
Table of Contents
TL;DR
- On September 1, 2026, the OCC and FDIC finalized a rule that — for the first time — defines “unsafe or unsound practice” in regulation; effective November 2
- The new standard focuses on practices that create material financial risk to the institution, its customers, or the financial system; it excludes documentation and administrative deficiencies that don’t create financial exposure
- MRAs are now limited to matters relating to unsafe or unsound practices, material violations of law, or other significant supervisory concerns — not every policy gap or documentation deficiency
- Concurrently, the agencies removed “reputation risk” from interagency supervisory documents; it no longer has formal examination standing at the federal level
- For operational risk teams: the question your RCSA should answer isn’t “do we have a control?” — it’s “does the absence of this control create material financial risk?”
“Unsafe or unsound practice” appears in banking law hundreds of times. The Federal Deposit Insurance Act. The Bank Holding Company Act. The National Bank Act. Examination manuals. Consent orders. Formal agreements. Cease-and-desist orders. The phrase is the legal foundation for most of the enforcement authority US banking regulators exercise.
It had never been defined.
That changed September 1, 2026, when the OCC and FDIC finalized a rule codifying — for the first time in the history of federal banking regulation — what it actually means for a practice to be “unsafe or unsound.” The rule is effective November 2, 2026. What it does to operational risk programs is more significant than most teams have processed.
Why This Had Never Been Defined
The indefiniteness was deliberate, for decades. Regulators didn’t want to constrain their flexibility by committing to a specific definition. An undefined standard gave examiners latitude to cite whatever practices concerned them as “unsafe or unsound,” from inadequate capital buffers to missing policy language to practices associated with unfavorable news coverage.
Practitioners have been uncomfortable with that latitude for years. Critics argued that undefined “unsafe or unsound” standards allowed examiners to apply pressure on banks for reasons that weren’t squarely about financial risk — reputational concerns, policy preferences, documentation aesthetics. Banks navigating examinations often received MRAs for procedural deficiencies with no direct path to a financial loss scenario.
The rule changes that dynamic. Per OCC NR-IA-2026-71, the agencies are refocusing supervision on “material financial risks” and away from concerns involving “administrative, technical, or documenting deficiencies.” The parallel OCC news release described it as giving institutions “clarity about what federal banking regulators consider unsafe or unsound” while “reorienting” examination resources toward practices that create actual financial harm.
What the Definition Actually Says
The final rule codifies the standard in agency regulations. A practice constitutes an “unsafe or unsound practice” when it:
- Creates more than a minimal probability of loss or insolvency — actual financial exposure at the institution level, not hypothetical or speculative
- Could cause material financial harm to the institution, its customers, or the broader financial system
- Involves a material violation of law or regulation when that violation creates financial exposure
The exclusion is equally important: the definition explicitly excludes practices that present only “administrative, technical, or documenting deficiencies” when those deficiencies don’t create the financial exposure described above.
The MRA limitation follows from the definition. Going forward, MRAs may be issued for matters “relating to an unsafe or unsound practice, material violation of law or regulation, or other significant supervisory concern.” That last phrase — “significant supervisory concern” — preserves some discretion, but the context makes clear it’s intended to operate within the material financial risk framework, not as a backdoor to the old indefinite standard.
The Reputation Risk Elimination
Simultaneous with the OCC/FDIC final rule, all four federal banking agencies — OCC, FDIC, Federal Reserve, and NCUA — removed references to “reputation risk” from interagency supervisory documents and examination manuals.
This is a categorical change. For the last decade, “reputation risk” functioned as a catch-all examination category that regulators applied to practices they wanted to discourage but couldn’t precisely ground in safety-and-soundness standards. Financial institutions received examination feedback about reputation risk associated with certain customer types, certain business lines, and certain legal activities. That feedback had real economic consequences — institutions exited markets and dropped customers partly in response to informal reputational pressure from supervisors.
That mechanism is now formally removed. Reputation risk no longer has standing as a federal examination category. Risk management frameworks that maintain reputation risk as an internal risk category for board reporting purposes can keep it — it’s a useful discipline for understanding media and stakeholder exposure. But it can no longer form the basis for an examiner’s supervisory action.
What This Means for Operations Teams
The RCSA’s New Question
Your Risk and Control Self-Assessment is an examination artifact. It describes your control environment to the examiner, demonstrates that you’ve assessed your risks, and shows that your controls address material exposures.
Under the previous examination regime, an RCSA that mapped controls to every possible risk — including administrative and documentation risks — was a reasonable strategy. Examiners looked for completeness and often cited gaps regardless of financial impact.
The November 2 framework inverts the priority. An RCSA under the new standard should demonstrate clear thinking about which control failures create material financial exposure. The severity assessment in your RCSA should be able to answer, for every high-rated control gap: what is the specific financial loss scenario this gap creates? If the answer is “it creates a documentation deficiency that doesn’t directly lead to customer harm or financial loss,” that’s a lower severity item under the new standard.
This isn’t an argument for ignoring documentation. It’s an argument for honest calibration. An RCSA that treats every gap as equally severe produces examination noise — examiners can’t calibrate their attention when everything is red. An RCSA that demonstrates nuanced thinking about which gaps matter financially earns credibility with supervisors.
The MRA Posture Shift
For institutions managing open MRAs, the rule creates a practical opportunity. If you have outstanding MRAs related to documentation deficiencies, policy completeness, or procedural gaps that don’t have a clear path to a material financial loss scenario, those items warrant a fresh look with your supervisory team.
The OCC’s accompanying guidance explicitly encouraged institutions to work with their supervisory office on how open items should be assessed under the new framework. The November 2 effective date creates a natural review point.
This parallels what’s happening on the FDIC side. As covered last week, the FDIC rescinded its 2016 Statement on supervisory recommendations and MRBAs effective November 2, eliminating those informal categories entirely. Banks with open MRBAs and SRs need to get them re-designated before that date. The OCC/FDIC final rule operates in the same November 2 window.
What Still Gets MRAs
To be direct: the rule narrows, not eliminates, MRA exposure. Material financial risks still get examined. Capital adequacy shortfalls, BSA/AML program failures with documented lapses in suspicious activity identification, consumer compliance violations with actual customer harm, credit concentration exposures that exceed appetite — these remain in scope. The Silicon Valley Bank supervisory review findings catalogued a set of failures (rapid growth outpacing risk infrastructure, interest rate risk not reflected in internal limits, deferred supervisory escalation) that would absolutely meet the new “material financial risk” standard.
The change is at the margin. Examiners who previously cited institutions for:
- Policy manuals that lack specific required elements
- Risk assessments that don’t use the precisely prescribed format
- Committee charters that omit granular procedural descriptions
- Third-party oversight documentation that’s functionally complete but not formatted to examiner preference
…will now need to connect those gaps to a material financial risk scenario to make them MRA-worthy. That’s a real change for institutions that have historically received examination feedback in those categories.
Capital Implications
The OCC/FDIC rule doesn’t directly address capital treatment, but it intersects with the Basel III endgame reproposal in a practical way. The Basel III Endgame Reproposal reduced the operational risk capital floor for community and mid-size banks. Operational risk capital under the Standardized Approach is driven by a bank’s business indicator and historical loss experience — neither of which is affected by documentation MRAs.
The connection is governance: if your operational risk capital model is calibrated to your actual loss experience and your RCSA focuses on the risks that drive financial losses, both the capital model and the RCSA will converge on the same material risk picture. An RCSA built primarily to satisfy documentation-focused examiner preferences produces noise that inflates perceived operational risk without mapping to capital-relevant exposures.
What Changes — and What Doesn’t — in Practice
| Before November 2, 2026 | After November 2, 2026 |
|---|---|
| MRAs issued for documentation gaps without required financial impact link | MRAs require connection to material financial risk or material law violation |
| ”Reputation risk” cited as standalone examination concern | Reputation risk removed from federal examination framework |
| ”Unsafe or unsound” undefined — examiner discretion broad | Regulatory definition: material financial harm standard |
| Policy deficiencies = MRA risk regardless of financial impact | Policy deficiencies only = MRA if they create material exposure |
| Risk programs optimized to show documentation completeness | Risk programs should demonstrate control-to-loss scenario linkage |
The second column is not an invitation to deprioritize governance. Sound documentation is still how you demonstrate to an examiner that you’re operating within the new framework. The change is that the documentation purpose shifts from “proving we have a policy” to “proving our controls prevent material financial harm.”
So What?
The OCC/FDIC final rule is the most significant change to the examination framework since the introduction of CAMELS ratings. It changes the fundamental question an examiner asks from “do you have this policy?” to “does your control environment prevent material financial losses?”
For operational risk teams, that means:
- Reframe your RCSA to demonstrate financial impact linkage for high-severity findings — not just control presence
- Audit open MRAs before November 2 and identify which ones can be reclassified under the new standard
- Remove reputation risk as a standalone operational risk category in your formal risk inventory (retain it for board reporting where useful, but don’t tie control assessments to reputational exposure that has no financial impact pathway)
- Build financial loss scenarios into your risk assessment methodology — for each identified risk, the residual risk score should reflect the realistic financial impact of control failure, not the documentation gap
A well-designed RCSA that can answer “how does this control failure translate to financial loss?” is both better risk management and a stronger examination artifact under the new standard. The RCSA (Risk & Control Self-Assessment) provides a structured methodology for building that financial impact linkage into your assessment process from the start.
Sources: OCC NR-IA-2026-71: Agencies Issue Final Rule to Prioritize Material Financial Risks; Arnold & Porter: OCC and FDIC Overhaul Bank Supervision, MRAs, and Enforcement Framework; Morgan Lewis: OCC and FDIC Finalize New Bank Supervision Standards; Sullivan & Cromwell: OCC and FDIC Adopt Final Rule Defining Unsafe or Unsound Practice; FDIC: Agencies Remove References to Reputation Risk
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
RCSA (Risk & Control Self-Assessment)
141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the OCC/FDIC final rule actually change about the 'unsafe or unsound' standard?
Does this mean examiners can no longer issue MRAs for documentation and process deficiencies?
What is the effective date and what happens to existing MRAs?
Does the rule apply to credit unions or investment advisers?
How should operational risk teams reframe their RCSA and control testing in light of this rule?
Does this rule change anything about reputation risk?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
RCSA (Risk & Control Self-Assessment)
141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.
◆ Keep reading
Related posts.
Operational Risk
FTC Made Corpay's CEO Pay Personally. The $100 Million Unauthorized Fee Case Rewrites What 'Authorization' Means for Billing Controls.
On September 17, 2026, the FTC announced a $100 million settlement with Corpay (formerly FleetCor) and personally named CEO Ronald Clarke for charging unauthorized fees on commercial fuel cards. The injunction's 'clear and unavoidable' disclosure standard goes further than any prior FTC action. Here's what every compliance team with a recurring billing product needs to audit.
Sep 26, 2026
Operational Risk
Your FedNow Send Function Goes Live Next Quarter. Here's What Your Fraud Controls and Operational Risk Program Need Before the First Transaction.
With 1,700+ FedNow participants and $271 billion processed in Q1 2026, instant payments are production infrastructure. But irrevocable, 24/7 settlement with a seconds-long authorization window breaks fraud programs built for ACH. Here's what your operational risk program needs to say about instant payments before you enable send.
Sep 20, 2026
Operational Risk
New Silicon Valley Bank Review: The Seven Supervisory Failures Risk Teams Should Fix
The new Silicon Valley Bank review says supervisors saw risks but failed to act. Here is how banks can repair escalation and decision rights.
Sep 19, 2026