Breaking Regulatory Compliance
Nano Banc Failed at 0.82% Capital: The Enforcement Timeline Risk Teams Should Read
The Nano Banc failure followed years of governance orders and a missed 9.5% capital mandate. Here is the control breakdown and response checklist.
Table of Contents
TL;DR
- California closed Nano Banc on September 25 after its tangible shareholders’ equity fell to approximately $5.6 million—0.82% of assets—and the bank failed to satisfy a March capital order.
- The March order was not vague. It required a 9.5% tangible equity ratio within 120 days, an acceptable sale or merger, or a voluntary-liquidation plan, plus specific liquidity, credit, CECL, management, and reporting fixes.
- The FDIC transferred substantially all deposits to Sunwest Bank and preliminarily estimated a $114 million cost to the Deposit Insurance Fund. That figure is a resolution-cost estimate, not a penalty.
- The practitioner lesson is brutal: an enforcement tracker can be green while the institution is still failing. Boards need outcome metrics, hard decision dates, and an executable exit path—not just completed action items.
The Nano Banc failure is what happens when a regulatory remediation program becomes a reporting exercise while the balance sheet keeps deteriorating.
On September 25, 2026, California’s Department of Financial Protection and Innovation took possession of the Irvine bank and appointed the FDIC as receiver. The DFPI possession order puts the endpoint in one line: as of September 22, Nano Banc had roughly $5.644 million in tangible shareholders’ equity, equal to 0.82% of total assets, supporting approximately $685.2 million in liabilities.
This was not a surprise Friday-night closure. DFPI had been issuing orders over governance and management changes since 2021. The Federal Reserve entered a cease-and-desist order in 2022. In March 2026, California gave Nano Banc 120 days to restore capital, secure an acceptable merger or sale, or pursue voluntary liquidation. By September, none of those paths had been completed.
That sequence makes this more useful than another generic bank-failure recap. It is a case study in the gap between tracking remediation activity and proving that remediation changes the outcome.
Nano Banc failure: the numbers at closure
Two official snapshots use different reporting dates, so do not mix them.
| Measure | Amount | Measurement date and source |
|---|---|---|
| Total assets | $690.868 million | September 22 DFPI possession-order balance sheet |
| Total deposits | $626.777 million | September 22 DFPI possession-order balance sheet |
| Total liabilities | $685.207 million | September 22 DFPI possession-order balance sheet |
| Tangible shareholders’ equity | Approximately $5.644 million | September 22 DFPI finding |
| Tangible equity ratio | 0.82% | September 22 DFPI finding |
| Retained earnings | Negative $122 million | September 22 DFPI balance sheet |
| Assets reported to FDIC | $736 million | June 30 regulatory reporting date cited by FDIC |
| Deposits reported to FDIC | $686 million | June 30 regulatory reporting date cited by FDIC |
| Assets acquired by Sunwest | Approximately $476 million | FDIC preliminary transaction figure |
| Estimated Deposit Insurance Fund cost | Approximately $114 million | FDIC preliminary estimate |
The FDIC’s closure announcement says Sunwest Bank assumed substantially all deposits and acquired certain assets. The FDIC retained the remaining assets for disposition and warned that its $114 million loss estimate would change as those assets were sold.
The FDIC failed-bank page also confirms that substantially all deposit accounts—including uninsured deposits—transferred to Sunwest. Customers kept access to checks, cards, direct deposits, and online services. That smooth depositor handoff is resolution execution. It should not be confused with a healthy pre-failure control environment.
The warning chain started with governance
The cleanest way to read this case is chronologically.
| Date | Regulatory action | Control signal |
|---|---|---|
| February 24, 2021 | DFPI required 30 days’ advance notice before adding directors or executive officers | Regulator lacked confidence in governance changes occurring without review |
| December 15, 2021 | DFPI issued a cease-and-desist order after board and executive changes without required notice | Formal requirements did not prevent unauthorized governance action |
| January 18, 2022 | Federal Reserve issued a cease-and-desist order involving Nano Banc and its holding companies | State concerns had become a multi-regulator matter |
| November 12, 2024 | Fed prohibited two former directors; one received a $75,000 penalty | Individual conduct and prior-order compliance remained part of the history |
| March 20, 2025 | Fed terminated its 2022 institutional order | Termination of one order did not establish that every state-level or financial risk was resolved |
| March 6, 2026 | DFPI imposed capital, liquidity, credit, management, and reporting requirements | The problem had become a quantified recovery mandate |
| September 25, 2026 | DFPI took possession; FDIC became receiver | Capital and exit-path requirements were not achieved |
The 2021 DFPI cease-and-desist order says the bank changed directors and executive management without the required advance notice. The changes included removing six directors, placing two executives on leave, appointing five directors, and naming a chairman and CEO. DFPI ordered the bank to stop operating without a CEO and chief risk officer who had received the regulator’s non-objection.
That matters because governance was not a side issue. By March 2026, DFPI’s order required executive management acceptable to the commissioner, specifically including a CEO, chief credit officer, and CFO qualified to restore the bank to safe and sound condition. The board also had to give those executives written authority to implement the order.
A remediation program cannot outrun unstable decision rights. If the board, CEO, CFO, credit function, and risk function do not have clear and durable authority, every capital, liquidity, and credit action becomes slower and easier to contest.
The Federal Reserve’s history adds an important source-discipline point. The Fed terminated its 2022 institutional order in March 2025. That termination should not be read as a federal declaration that Nano Banc could not later fail. It means that particular action ended. Risk teams should never translate “one order terminated” into “the institution’s control environment is fixed” without testing the remaining risk indicators and regulatory commitments.
The March order was a recovery plan, not a policy refresh
DFPI’s March 6, 2026 order specified the required end states. Within 120 days, Nano Banc had to do one or more of the following:
- raise and maintain its tangible shareholders’ equity ratio at 9.5% or higher;
- enter a definitive agreement for an acceptable merger or sale; or
- provide an acceptable voluntary-liquidation plan.
The order then connected capital to the operating risks behind it.
Liquidity: Within 60 days, the bank had to revise stress-testing assumptions using data, peer benchmarks, and expert judgment; obtain board approval of the scenarios; reassess limits; and submit a contingency funding plan with quantitative and qualitative triggers tied to stress outputs and early-warning metrics.
Funding concentration: Within 90 days, management had to submit a plan to reduce deposit concentration and reliance on wholesale non-core deposits, with measurable goals and limits by deposit vertical.
Credit loss estimation: The bank had to assess its allowance-for-credit-loss methodology and CECL framework, then engage an independent third party to validate whether the methodology captured Nano Banc’s specific risk.
Commercial real estate and classified assets: The order required reduced concentrations, a timed plan for adversely classified assets, board-approved workout plans, defined upgrade and downgrade triggers, timely risk-rating migration, and consistent loss recognition.
Earnings: Quarterly reporting had to explain variances of 25% or more outside budget projections and show how the board and management would respond.
Those are not paperwork controls. They are linked outcome controls. Capital depends on timely loss recognition, viable earnings, funding stability, concentration management, and executives with authority to make difficult decisions.
DFPI’s September 26 public account says the bank had reported a net loss of roughly $75.3 million before the March order. By September 22, the possession order showed tangible equity at 0.82%, far below both the 9.5% order requirement and the 3% statutory threshold cited by the commissioner.
Where remediation governance breaks
The public orders do not disclose Nano Banc’s internal project plans, committee minutes, or issue tracker. It would be irresponsible to invent them. But the regulatory timeline supports four direct control tests every bank can run.
1. Task completion can hide outcome failure
A team can complete a policy revision, hold a board meeting, update a stress model, and hire a consultant while capital continues to fall. Those actions may all be necessary. None proves recovery.
For each regulatory article, track both:
- deliverable status: document submitted, policy approved, validation completed;
- outcome status: capital ratio, classified assets, deposit concentration, liquidity coverage, earnings variance, and unresolved exceptions.
The CRO should require an explicit explanation whenever deliverables are green but outcome metrics are red. That divergence is itself a high-severity issue.
2. The exit path needs its own critical path
“Raise capital, sell, merge, or liquidate” is not one action item. It is a set of strategic alternatives with different approvals, dependencies, diligence requirements, and failure points.
The board should maintain a decision table showing, for each path:
| Exit path | Evidence the path is real | Escalation trigger |
|---|---|---|
| Capital raise | Named investors, diligence stage, amount, closing conditions, regulatory status | Funding gap or closing date misses board-approved tolerance |
| Sale or merger | Executed engagement, bidders, data-room readiness, definitive-agreement milestones | No viable bidder or deadline threatens regulatory requirement |
| Voluntary liquidation | Board-approved plan, liquidity analysis, customer and creditor treatment, regulator acceptance | Capital or liquidity trajectory no longer supports another path |
A progress percentage is useless here. The board needs probability, deadline, blockers, and the date on which it will stop betting on one path and activate another.
3. Regulatory-order closure is not enterprise-risk closure
The Fed’s 2025 termination and DFPI’s 2026 action illustrate why order inventories must remain regulator- and scope-specific. Closing one action does not automatically close related governance, capital, credit, or liquidity risks.
Link every order article to the underlying enterprise issue, and keep that enterprise issue open until independent testing shows the risk outcome is controlled. The approach complements the escalation discipline in the new Silicon Valley Bank supervisory review: a known vulnerability needs a named decision-maker and deadline, not another status deck.
4. A trigger must force a decision
Nano Banc’s March order required contingency-funding triggers tied to stress tests and early-warning metrics. That design principle applies beyond liquidity. A trigger should identify:
- the metric and source system;
- the threshold and calibration basis;
- the accountable recipient;
- the maximum decision window;
- the allowed actions;
- the evidence retained; and
- the escalation when management does not act.
For a detailed implementation model, see Contingency Funding Plan KRIs: Metrics That Should Trigger CFP Activation. The useful distinction is simple: a red indicator that produces discussion is reporting; a red indicator that changes funding, growth, concentration, or recovery strategy is a control.
The 30-day response for banks under an order
Days 1–5 — Reconcile the obligations. The Chief Compliance Officer and General Counsel should map every order paragraph to one enterprise issue, one accountable executive, required evidence, outcome metric, and regulator submission. Internal Audit should identify obligations that exist in a regulatory tracker but not in the enterprise issue inventory.
Days 6–10 — Challenge the trajectory. The CFO, Treasurer, Chief Credit Officer, and CRO should compare current capital, liquidity, concentration, classified-asset, CECL, and earnings measures with both the regulatory end state and the deadline. Show the board the slope, not just the latest value.
Days 11–15 — Stress the recovery paths. Management should test whether capital-raise, sale, merger, and liquidation assumptions still hold under adverse deposit, credit-loss, and execution scenarios. Label assumptions, owners, evidence, and expiration dates.
Days 16–20 — Set decision gates. The board should approve dates when it will continue, switch, or abandon each strategic path. Document who can make an emergency decision between meetings. Link each gate to objective financial and execution triggers.
Days 21–25 — Test evidence independently. Internal Audit or an independent validation team should sample completed actions. Reperform calculations, inspect source data, verify board approvals, and test whether the control operates—not merely whether a document exists.
Days 26–30 — Report divergence. Produce one board view that places regulatory deliverables beside financial outcomes. Any green/red mismatch requires a corrective decision, named owner, and date. Reconcile board minutes, issue records, and regulator submissions so the institution cannot tell three different versions of the same remediation story.
If your team is still debating which finding owner owes which evidence, the Issues Management Tracker & Template gives regulatory articles, action plans, owners, deadlines, root cause, and independent closure checks one traceable home.
The point risk teams should carry forward
The Nano Banc failure is not a lesson to add more rows to an enforcement tracker. DFPI had already defined the outcomes: restore capital, secure a transaction, or execute an orderly exit while repairing liquidity, credit, earnings, and management weaknesses.
The practical test is whether the board can answer three questions without waiting for a new deck:
- Are the required financial outcomes improving fast enough to meet the order?
- Which strategic path is viable today, and what evidence supports that judgment?
- What metric or missed milestone forces a different decision—and who has authority to make it?
If the answers are unclear, the remediation program is measuring work. It is not controlling the result.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Why did Nano Banc fail in September 2026?
What happened to Nano Banc depositors?
How much will the Nano Banc failure cost the Deposit Insurance Fund?
What controls did the March 2026 Nano Banc order require?
What should risk teams learn from the Nano Banc failure?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
● Don't wait for your own enforcement action
Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Regulatory Compliance
OFAC Just Codified Its Penalty Playbook. What 31 CFR Part 505 Means for Your Sanctions Compliance Program.
On September 25, 2026, OFAC's new Sanctions Penalties Regulations (31 CFR Part 505) took effect — the first time OFAC has consolidated its civil and criminal penalty procedures into formal regulations. Here's what changed and what your compliance program needs to account for.
Sep 27, 2026
Regulatory Compliance
Federal Reserve Stablecoin Rules: The Capital Math and Application Binder Banks Need Now
Federal Reserve stablecoin rules propose capital, reserve, reporting, custody, and application standards under the GENIUS Act.
Sep 25, 2026
Regulatory Compliance
The 21st Century ROAD Act Just Doubled Your Exam Window. Here's Whether Your Bank Qualifies and What the Extra 6 Months Actually Means.
The OCC, Fed, and FDIC issued an interim final rule raising the 18-month exam cycle threshold from $3 billion to $6 billion total assets. 188 institutions are newly eligible. Here's the eligibility criteria, what the longer cycle actually changes, and how to use the runway strategically.
Sep 23, 2026