Feature Compliance Strategy
16 Days, 30 Days, 44 Days: The Q4 2026 Compliance Deadline Stack Every Financial Institution Needs to Clear
October 19, November 2, November 16: three separate compliance deadlines land in the next six weeks. One is a comment period for guidance that will define how examiners evaluate your vendor program. One is the effective date of the new MRA standard. One is the comment period for GENIUS Act implementing rules that will freeze your options if you miss it. Here's what each requires.
Table of Contents
TL;DR
- Three separate compliance deadlines land between October 19 and November 16, 2026: Treasury GENIUS Act NPRM comments, OCC/FDIC MRA standard effective date, and interagency TPRM proposed guidance comments
- November 2 is not a milestone — it’s an effective date. After that, OCC and FDIC examiners operate under a new legal definition of when formal supervisory action is authorized
- The TPRM comment window closes November 16; the final guidance will govern how every banking agency evaluates vendor programs for years, and most institutions haven’t started their comment
- January 18, 2027 is the GENIUS Act enforcement cliff; with OCC final rules not yet issued and compliance infrastructure not yet built, stablecoin-adjacent institutions have less runway than they realize
Six Weeks, Four Deadlines, No Slack
The October–November 2026 compliance calendar doesn’t give you much room to sequence. Three major regulatory deadlines land in the next 44 days. Each is distinct. Each requires a different response. And the cost of missing any of them ranges from lost influence over guidance that will govern your operations for years, to entering a formal examination cycle under a supervisory framework you haven’t adapted to.
Here’s the full stack:
| Date | Deadline | Stakes |
|---|---|---|
| October 19 | Treasury GENIUS Act NPRM comment deadline | Shapes reserve, custody, and AML requirements for stablecoin issuers and their bank partners |
| November 2 | OCC/FDIC “unsafe or unsound” final rule effective | New MRA standard in force; reputation risk gone as supervisory category |
| November 16 | Interagency TPRM proposed guidance comment deadline | Determines whether you have proportionality protections under the replacement framework |
| November 16 | FDIC bank merger proposed rule comment deadline | Affects state nonmember banks’ merger and acquisition strategic options |
| November (TBD) | OCC GENIUS Act final rules expected | Locks in stablecoin issuer requirements before January 18 enforcement date |
Let’s take each one.
October 19: Treasury GENIUS Act NPRM Comments Due
The GENIUS Act was signed in July 2025, giving the primary prudential regulators until mid-July 2026 to issue final implementing rules. That deadline passed without a final rule from any regulator. Treasury filled part of the gap with an NPRM published August 18, 2026, covering Treasury’s own implementing authority. Comments are due October 19.
If you issue payment stablecoins, custody them, process transactions denominated in them, or expect to do any of those things in the next 18 months, the NPRM matters. Treasury’s proposed framework covers reserve asset composition and management, redemption procedures and customer access rights, reporting requirements, and AML/BSA certification processes for payment stablecoin issuers and their qualifying custodian banks.
The OCC separately committed to final implementing rules by November 2026. What’s already clear from the March 2026 OCC NPRM is that the final rules will require permitted payment stablecoin issuers to maintain 1:1 reserves in high-quality liquid assets, implement real-time or near-real-time redemption procedures, and submit to OCC examination as a condition of authorization. The GENIUS Act final rules are converging quickly, and the comment window for influencing that framework at the Treasury level closes October 19.
What to do: Even if you’re not a stablecoin issuer today, if your institution banks stablecoin issuers, you should assess how the reserve custody and reporting requirements create compliance obligations for the custodian bank. If you are building stablecoin capabilities, you have 16 days to submit a comment — or accept the framework as written.
November 2: The New MRA Standard Is Live
On November 2, 2026, OCC and FDIC-supervised institutions enter a new supervisory environment. The OCC/FDIC final rule on ‘unsafe or unsound practice’ becomes effective. After that date:
- An MRA requires a finding that conduct creates a material financial risk — not just a policy gap or documentation deficiency
- Reputation risk is no longer a standalone supervisory category at the federal banking agencies
- The FDIC eliminates MRBAs and supervisory recommendations as categories; the MRA is the only formal supervisory communication category remaining
This is the most significant change to the MRA framework in decades, and it is legally effective — not aspirational. Examiners are bound by the new standard from the moment it takes effect.
What to do before November 2:
Open MRA review: Every open MRA at an OCC or FDIC-supervised institution should be reviewed before November 2. The question for each item: was it issued because the practice created material financial risk, or because it created a documentation gap? Items in the second category may not meet the new standard and are worth discussing with your supervisory contact before the effective date. The OCC’s guidance accompanying the rule encouraged institutions to raise such questions proactively.
Program framing: When your exam contact asks about open items after November 2, frame responses around financial risk demonstrated or absent. “This finding was issued for our policy not containing a required appendix; the actual program was functioning and no financial loss occurred” is a different conversation than it was before the rule took effect.
RCSA recalibration: If your RCSA treats every control gap as equivalent regardless of financial impact, it will generate noise in an examination environment where material financial risk is now the threshold for formal action. Recalibrate residual risk ratings to distinguish between control gaps that create financial exposure and control gaps that create documentation exposure.
A caution: This rule narrows, not eliminates, MRA authority. Capital shortfalls, BSA program failures with documented suspicious activity gaps, and consumer compliance violations with actual customer harm all remain clearly in scope. The rule doesn’t protect institutions from their substantive compliance obligations — it limits the scope of supervisory action for matters that don’t create material harm.
November 16: Two Comment Deadlines, One Day
Interagency TPRM Proposed Guidance
The September 11, 2026 proposed interagency TPRM guidance would rescind and replace the June 2023 guidance that every banking agency has been using as the baseline for TPRM examination. The November 16 comment deadline is the only opportunity to influence the final framework before it becomes the examination standard for years.
What the proposal would change:
- The scope of heightened oversight: The current 2023 guidance applied the same general framework to all third-party relationships. The proposed guidance explicitly creates proportionality — lower-risk relationships receive less rigorous oversight; higher-risk relationships receive more. This sounds reasonable in theory but creates a practical risk: without clear criteria for what makes a relationship “higher risk,” the final guidance may produce inconsistent examination standards across institutions.
- The “magnitude of harm” standard: The proposed guidance introduces a harm-based framework for assessing how much oversight a vendor relationship requires — essentially asking what would happen if this vendor failed. This is similar in structure to the MRA materiality threshold in the OCC/FDIC rule and creates consistency across supervisory frameworks.
- Core provider concentration: The accompanying joint statement on core service providers from OCC, Federal Reserve, and FDIC specifically called out deconversion fees and integration lock-in as factors that create concentration risk. This is the banking agencies signaling that they will consider exit barriers when assessing TPRM program quality.
The vendor concentration risk post from October 1 covers what examiners are already asking about, separate from the proposed guidance. The comment period is your opportunity to say whether the proposed proportionality framework would work in practice — specifically whether the harm-based standard provides enough clarity for institutions to apply it consistently.
What to submit a comment on: If your TPRM program has been cited for deficiencies under the 2023 guidance that you believe reflected over-interpretation of the guidance’s scope, say so specifically. If the proposed proportionality framework lacks clear criteria that would let you confidently tier your relationships, identify the gap. If your core banking provider relationship creates examination exposure under the concentration language, comment on whether the proposed framework provides adequate clarity on what’s expected.
FDIC Bank Merger Proposed Rule
The September 17, 2026 FDIC proposed rule would overhaul the agency’s merger review framework for state nonmember banks — roughly 2,700 institutions. The proposal creates tiered processing timelines (from five-business-day de minimis processing to a 270-day maximum for complex deals) and introduces a 25% prior-notice requirement for rapid asset growth through acquisitions. The comment deadline is also November 16.
BaaS sponsor banks and fintechs with bank partnerships should pay particular attention to the 25% asset-growth prior-notice provision. If your fintech program has grown your bank partner’s balance sheet significantly, that growth trajectory intersects with this requirement in the next transaction — or in the transaction you’re planning to do next year.
November (TBD): OCC GENIUS Act Final Rules
OCC Comptroller Jonathan Gould committed to final GENIUS Act implementing rules by November 2026. As of October 3, those rules haven’t been issued. When they arrive, they will set the compliance framework for payment stablecoin issuers operating under OCC oversight — including reserve requirements, custody arrangements, redemption procedures, and examination frequency.
The January 18, 2027 enforcement date is a hard statutory deadline. The OCC’s November commitment is designed to provide at least two months of implementation runway. That’s tight for any institution building compliance infrastructure from scratch: implementing a real-time redemption capability, establishing qualifying custodian relationships, and building out AML/BSA certification processes typically takes six to twelve months, not two.
If you’re building stablecoin issuance capability or considering it, the practical question is what you’re building toward before the final rule is issued. Two principles from the March OCC NPRM and the July GENIUS Act itself have been consistent enough that they’re unlikely to change materially: 1:1 reserve requirements in high-quality liquid assets, and real-time or near-real-time redemption obligations. Building to those requirements now reduces your retrofit risk when the final rule lands.
How to Manage a Compressed Deadline Stack
When three distinct compliance deadlines fall within the same six-week window, the practical risk is that each one gets less attention than it deserves. The instinct is to triage — pick the one that feels most urgent and defer the others.
That instinct is wrong here, because each deadline has a different cost structure:
- October 19 is lost forever if you miss it. You can’t comment late on a closed NPRM.
- November 2 is a legal effective date, not an action item — you don’t need to “meet” it, but you need to have already acted. Reviewing open MRAs and recalibrating RCSA scoring needs to happen before it arrives.
- November 16 TPRM is like October 19 — close, and you’ve forfeited your only opportunity to shape guidance that will govern your examination for years.
For compliance teams with limited bandwidth, a practical sequence:
This week (October 3–10): Assign ownership of each deadline. Three different people or teams are likely responsible — the technology/cybersecurity team for OCC/FDIC MRA review, the TPRM/vendor team for the TPRM comment, and the payments/stablecoin team for the GENIUS Act comment. Don’t let them compete for the same bandwidth.
October 10–19: Draft and submit Treasury GENIUS Act comment. Even a short letter that identifies your institution’s relationship to the proposed framework and flags specific provisions you believe need clarification is better than silence.
October 19–November 2: Complete open MRA review and document conclusions. Run RCSA materiality recalibration. Prepare board-level summary of what changes on November 2.
November 2–16: Draft and submit TPRM comment letter. The draft should have been started earlier, but you have two weeks to finalize after the MRA deadline passes.
The compression of these deadlines isn’t coincidental. The September 2026 regulatory calendar was extraordinary in scope — the interagency TPRM guidance, the FDIC bank merger proposal, the OCC/FDIC MRA final rule, and the continuing GENIUS Act rulemaking all landed within the same six-week window. Most compliance teams are still absorbing what each development means individually.
The teams that will be best positioned going into 2027 are the ones that understand these aren’t separate developments — they’re a coordinated supervisory reset, and Q4 2026 is when the reset becomes operational.
Sources: Proposed interagency TPRM guidance — FDIC FIL-58-2026 | OCC/FDIC unsafe or unsound practice final rule — Consumer Finance Monitor | GENIUS Act OCC implementing rules — Sullivan & Cromwell | FDIC bank merger proposed rule — Skadden | GENIUS Act compliance timeline — Finance Magnates
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What are the three most pressing compliance deadlines in Q4 2026?
What changes on November 2, 2026 for OCC and FDIC-supervised banks?
Who needs to submit a comment on the TPRM proposed guidance by November 16?
Does the October 19 GENIUS Act comment deadline matter to non-stablecoin issuers?
What should compliance teams do with open MRAs before November 2, 2026?
When will GENIUS Act final rules actually take effect for stablecoin issuers?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Compliance Strategy
New York City's Click-to-Cancel Rule Is Now in Effect. What Financial Services Subscription Products Need to Show Before the First Enforcement Wave.
On October 1, 2026, New York City became the first US municipality to require click-to-cancel for subscription products. Civil penalties start at $525 per violation. For financial services companies with premium account tiers, advisory subscriptions, credit monitoring, and cash-advance membership models, this is a three-layer compliance obligation most haven't fully mapped.
Oct 2, 2026
Compliance Strategy
The New SEC Exam Handbook Turns Exam Readiness Into a Production-Control Test
The SEC Exam Handbook sets 24-hour record availability and 180/30/60-day milestones. Here is the evidence workflow CCOs should test.
Oct 1, 2026
Compliance Strategy
The SEC Just Charged 38 Entities for Using Form ADV as a Fraud Tool. Here's What Legitimate Advisers Need to Fix Now.
In August 2026, the SEC charged 38 entities with filing false Forms ADV to impersonate legitimate investment advisers. The scheme exploited IAPD directly. Here is what compliance teams at legitimate advisers need to audit in their own filings — and what due diligence now requires.
Sep 30, 2026