Skip to content
RiskTemplates · The Daily Brief Sunday, September 27, 2026
Wire OFAC Just Codified Its Penalty Playbook. What 31 CFR Part 505 Means for Your Sanctions Compliance Program. SEP 26

Feature Operational Risk

Congress Never Defined 'Unsafe or Unsound.' Regulators Just Did. What the OCC/FDIC Final Rule Means for Your Risk Program.

The OCC and FDIC finalized a rule on September 1, 2026 that — for the first time in US banking history — defines 'unsafe or unsound practice' in regulation. Effective November 2, it reshapes what kinds of operational failures trigger MRAs. Here's what your risk program needs to change.

By Rebecca Leung · September 25, 2026 ·
Table of Contents

TL;DR

  • On September 1, 2026, the OCC and FDIC finalized a rule that — for the first time — defines “unsafe or unsound practice” in regulation; effective November 2
  • The new standard focuses on practices that create material financial risk to the institution, its customers, or the financial system; it excludes documentation and administrative deficiencies that don’t create financial exposure
  • MRAs are now limited to matters relating to unsafe or unsound practices, material violations of law, or other significant supervisory concerns — not every policy gap or documentation deficiency
  • Concurrently, the agencies removed “reputation risk” from interagency supervisory documents; it no longer has formal examination standing at the federal level
  • For operational risk teams: the question your RCSA should answer isn’t “do we have a control?” — it’s “does the absence of this control create material financial risk?”

“Unsafe or unsound practice” appears in banking law hundreds of times. The Federal Deposit Insurance Act. The Bank Holding Company Act. The National Bank Act. Examination manuals. Consent orders. Formal agreements. Cease-and-desist orders. The phrase is the legal foundation for most of the enforcement authority US banking regulators exercise.

It had never been defined.

That changed September 1, 2026, when the OCC and FDIC finalized a rule codifying — for the first time in the history of federal banking regulation — what it actually means for a practice to be “unsafe or unsound.” The rule is effective November 2, 2026. What it does to operational risk programs is more significant than most teams have processed.

Why This Had Never Been Defined

The indefiniteness was deliberate, for decades. Regulators didn’t want to constrain their flexibility by committing to a specific definition. An undefined standard gave examiners latitude to cite whatever practices concerned them as “unsafe or unsound,” from inadequate capital buffers to missing policy language to practices associated with unfavorable news coverage.

Practitioners have been uncomfortable with that latitude for years. Critics argued that undefined “unsafe or unsound” standards allowed examiners to apply pressure on banks for reasons that weren’t squarely about financial risk — reputational concerns, policy preferences, documentation aesthetics. Banks navigating examinations often received MRAs for procedural deficiencies with no direct path to a financial loss scenario.

The rule changes that dynamic. Per OCC NR-IA-2026-71, the agencies are refocusing supervision on “material financial risks” and away from concerns involving “administrative, technical, or documenting deficiencies.” The parallel OCC news release described it as giving institutions “clarity about what federal banking regulators consider unsafe or unsound” while “reorienting” examination resources toward practices that create actual financial harm.

What the Definition Actually Says

The final rule codifies the standard in agency regulations. A practice constitutes an “unsafe or unsound practice” when it:

  1. Creates more than a minimal probability of loss or insolvency — actual financial exposure at the institution level, not hypothetical or speculative
  2. Could cause material financial harm to the institution, its customers, or the broader financial system
  3. Involves a material violation of law or regulation when that violation creates financial exposure

The exclusion is equally important: the definition explicitly excludes practices that present only “administrative, technical, or documenting deficiencies” when those deficiencies don’t create the financial exposure described above.

The MRA limitation follows from the definition. Going forward, MRAs may be issued for matters “relating to an unsafe or unsound practice, material violation of law or regulation, or other significant supervisory concern.” That last phrase — “significant supervisory concern” — preserves some discretion, but the context makes clear it’s intended to operate within the material financial risk framework, not as a backdoor to the old indefinite standard.

The Reputation Risk Elimination

Simultaneous with the OCC/FDIC final rule, all four federal banking agencies — OCC, FDIC, Federal Reserve, and NCUA — removed references to “reputation risk” from interagency supervisory documents and examination manuals.

This is a categorical change. For the last decade, “reputation risk” functioned as a catch-all examination category that regulators applied to practices they wanted to discourage but couldn’t precisely ground in safety-and-soundness standards. Financial institutions received examination feedback about reputation risk associated with certain customer types, certain business lines, and certain legal activities. That feedback had real economic consequences — institutions exited markets and dropped customers partly in response to informal reputational pressure from supervisors.

That mechanism is now formally removed. Reputation risk no longer has standing as a federal examination category. Risk management frameworks that maintain reputation risk as an internal risk category for board reporting purposes can keep it — it’s a useful discipline for understanding media and stakeholder exposure. But it can no longer form the basis for an examiner’s supervisory action.

What This Means for Operations Teams

The RCSA’s New Question

Your Risk and Control Self-Assessment is an examination artifact. It describes your control environment to the examiner, demonstrates that you’ve assessed your risks, and shows that your controls address material exposures.

Under the previous examination regime, an RCSA that mapped controls to every possible risk — including administrative and documentation risks — was a reasonable strategy. Examiners looked for completeness and often cited gaps regardless of financial impact.

The November 2 framework inverts the priority. An RCSA under the new standard should demonstrate clear thinking about which control failures create material financial exposure. The severity assessment in your RCSA should be able to answer, for every high-rated control gap: what is the specific financial loss scenario this gap creates? If the answer is “it creates a documentation deficiency that doesn’t directly lead to customer harm or financial loss,” that’s a lower severity item under the new standard.

This isn’t an argument for ignoring documentation. It’s an argument for honest calibration. An RCSA that treats every gap as equally severe produces examination noise — examiners can’t calibrate their attention when everything is red. An RCSA that demonstrates nuanced thinking about which gaps matter financially earns credibility with supervisors.

The MRA Posture Shift

For institutions managing open MRAs, the rule creates a practical opportunity. If you have outstanding MRAs related to documentation deficiencies, policy completeness, or procedural gaps that don’t have a clear path to a material financial loss scenario, those items warrant a fresh look with your supervisory team.

The OCC’s accompanying guidance explicitly encouraged institutions to work with their supervisory office on how open items should be assessed under the new framework. The November 2 effective date creates a natural review point.

This parallels what’s happening on the FDIC side. As covered last week, the FDIC rescinded its 2016 Statement on supervisory recommendations and MRBAs effective November 2, eliminating those informal categories entirely. Banks with open MRBAs and SRs need to get them re-designated before that date. The OCC/FDIC final rule operates in the same November 2 window.

What Still Gets MRAs

To be direct: the rule narrows, not eliminates, MRA exposure. Material financial risks still get examined. Capital adequacy shortfalls, BSA/AML program failures with documented lapses in suspicious activity identification, consumer compliance violations with actual customer harm, credit concentration exposures that exceed appetite — these remain in scope. The Silicon Valley Bank supervisory review findings catalogued a set of failures (rapid growth outpacing risk infrastructure, interest rate risk not reflected in internal limits, deferred supervisory escalation) that would absolutely meet the new “material financial risk” standard.

The change is at the margin. Examiners who previously cited institutions for:

  • Policy manuals that lack specific required elements
  • Risk assessments that don’t use the precisely prescribed format
  • Committee charters that omit granular procedural descriptions
  • Third-party oversight documentation that’s functionally complete but not formatted to examiner preference

…will now need to connect those gaps to a material financial risk scenario to make them MRA-worthy. That’s a real change for institutions that have historically received examination feedback in those categories.

Capital Implications

The OCC/FDIC rule doesn’t directly address capital treatment, but it intersects with the Basel III endgame reproposal in a practical way. The Basel III Endgame Reproposal reduced the operational risk capital floor for community and mid-size banks. Operational risk capital under the Standardized Approach is driven by a bank’s business indicator and historical loss experience — neither of which is affected by documentation MRAs.

The connection is governance: if your operational risk capital model is calibrated to your actual loss experience and your RCSA focuses on the risks that drive financial losses, both the capital model and the RCSA will converge on the same material risk picture. An RCSA built primarily to satisfy documentation-focused examiner preferences produces noise that inflates perceived operational risk without mapping to capital-relevant exposures.

What Changes — and What Doesn’t — in Practice

Before November 2, 2026After November 2, 2026
MRAs issued for documentation gaps without required financial impact linkMRAs require connection to material financial risk or material law violation
”Reputation risk” cited as standalone examination concernReputation risk removed from federal examination framework
”Unsafe or unsound” undefined — examiner discretion broadRegulatory definition: material financial harm standard
Policy deficiencies = MRA risk regardless of financial impactPolicy deficiencies only = MRA if they create material exposure
Risk programs optimized to show documentation completenessRisk programs should demonstrate control-to-loss scenario linkage

The second column is not an invitation to deprioritize governance. Sound documentation is still how you demonstrate to an examiner that you’re operating within the new framework. The change is that the documentation purpose shifts from “proving we have a policy” to “proving our controls prevent material financial harm.”

So What?

The OCC/FDIC final rule is the most significant change to the examination framework since the introduction of CAMELS ratings. It changes the fundamental question an examiner asks from “do you have this policy?” to “does your control environment prevent material financial losses?”

For operational risk teams, that means:

  • Reframe your RCSA to demonstrate financial impact linkage for high-severity findings — not just control presence
  • Audit open MRAs before November 2 and identify which ones can be reclassified under the new standard
  • Remove reputation risk as a standalone operational risk category in your formal risk inventory (retain it for board reporting where useful, but don’t tie control assessments to reputational exposure that has no financial impact pathway)
  • Build financial loss scenarios into your risk assessment methodology — for each identified risk, the residual risk score should reflect the realistic financial impact of control failure, not the documentation gap

A well-designed RCSA that can answer “how does this control failure translate to financial loss?” is both better risk management and a stronger examination artifact under the new standard. The RCSA (Risk & Control Self-Assessment) provides a structured methodology for building that financial impact linkage into your assessment process from the start.


Sources: OCC NR-IA-2026-71: Agencies Issue Final Rule to Prioritize Material Financial Risks; Arnold & Porter: OCC and FDIC Overhaul Bank Supervision, MRAs, and Enforcement Framework; Morgan Lewis: OCC and FDIC Finalize New Bank Supervision Standards; Sullivan & Cromwell: OCC and FDIC Adopt Final Rule Defining Unsafe or Unsound Practice; FDIC: Agencies Remove References to Reputation Risk

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the OCC/FDIC final rule actually change about the 'unsafe or unsound' standard?
For the first time in US banking history, the rule establishes a regulatory definition of 'unsafe or unsound practice' — a term that appears hundreds of times in banking statutes but had never been defined. Under the final rule, a practice is unsafe or unsound when it creates more than a minimal probability of loss, insolvency, or other harm to an institution, or when it could cause material financial harm to the institution, its customers, or the broader financial system. The rule explicitly excludes 'administrative, technical, or documenting deficiencies' that do not pose a material financial risk. This is the key change: documentation gaps and policy deficiencies that don't translate to material financial risk are no longer the standard for formal supervisory action.
Does this mean examiners can no longer issue MRAs for documentation and process deficiencies?
Not exactly. The rule narrows when MRAs may be issued — they're now limited to matters that 'relate to an unsafe or unsound practice, material violation of law or regulation, or other significant supervisory concern.' The rule doesn't say MRAs can never address process issues; it says those process issues must rise to a level that creates material financial risk. An institution with a CAMELS-4 rated BSA program that's failing to file SARs has a material operational risk — that's still MRA territory. An institution with a policy that lacks a specific required element but is functionally sound and well-evidenced is a different case.
What is the effective date and what happens to existing MRAs?
The final rule is effective November 2, 2026. For existing MRAs, banks should expect examiners to apply the new standard prospectively — meaning open MRAs cited for documentation deficiencies rather than material financial risk may be assessed differently at the next examination cycle. The OCC issued accompanying guidance encouraging institutions to work with their supervisory team on transitioning open items under the new framework, particularly where MRAs were issued under the broader pre-November 2 standard. This mirrors the FDIC's parallel action on September 17 rescinding MRBAs and supervisory recommendations.
Does the rule apply to credit unions or investment advisers?
The OCC/FDIC final rule applies to OCC-supervised national banks and federal savings associations, and FDIC-supervised state non-member banks and state savings associations. It does not directly govern the Federal Reserve's supervision of state member banks or bank holding companies, though the Fed issued a parallel policy statement directionally consistent with the rule. NCUA and SEC are not parties to this rule. For credit unions, the NCUA has its own examination standards and hasn't published equivalent guidance. For investment advisers, the SEC's examination framework is separate.
How should operational risk teams reframe their RCSA and control testing in light of this rule?
The rule makes explicit what good operational risk programs already prioritize: the severity assessment in your RCSA should clearly distinguish between controls that prevent material financial loss and controls that produce documentation. A poorly designed RCSA that scores every control gap as 'High' regardless of financial impact will produce noise in your examination interaction — if everything is high risk, examiners can't calibrate their focus. After November 2, an RCSA that demonstrates clear thinking about which control failures create financial exposure vs. which create documentation gaps is a better exam artifact than one that treats both equally.
Does this rule change anything about reputation risk?
Yes — significantly. Concurrently with this rulemaking, the OCC, FDIC, Federal Reserve, and NCUA removed references to 'reputation risk' from interagency supervisory documents and examination manuals. Under the previous framework, examiners could flag practices as 'reputation risk' concerns — which critics argued led to chilling effects on legitimate banking activities. After November 2, 'reputation risk' as a standalone examination category is gone at the federal banking agencies. Risk management frameworks that have reputation risk as a separate risk category can retain it, but it no longer carries formal supervisory weight at the federal level.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

RCSA (Risk & Control Self-Assessment)

141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.