US Banking Regulators Are Raising the Bar for What Counts as a Compliance Failure
austin carrollUS banking regulators are changing how they supervise financial institutions, with greater emphasis on material financial risk, substantive legal violations and effective risk management.
The Office of the Comptroller of the Currency (OCC) and Federal Deposit Insurance Corporation (FDIC) have introduced new standards for identifying unsafe or unsound practices and issuing Matters Requiring Attention (MRAs). The Federal Reserve has also updated its supervisory principles.
The direction is clear: regulators are placing greater emphasis on issues that create meaningful financial or legal risk rather than treating every weakness as equally significant.
For compliance teams, however, this does not mean compliance requirements are becoming less important.
A New Standard For Bank Supervision
On August 27, 2026, the OCC and FDIC issued a joint final rule establishing a new definition of an "unsafe or unsound practice" and revising the framework for MRAs.
Under the rule, an unsafe or unsound practice generally involves conduct that has caused, or is likely to cause, material harm to a bank's financial condition or create a material risk of loss to the Deposit Insurance Fund.
An MRA may also be issued where a practice could reasonably be expected to cause material financial harm, has already caused material harm, or constitutes an actual violation of banking or banking-related law or regulation.
The result is a more risk-based approach to supervision, with greater attention directed toward problems that could materially affect a bank's financial condition, regulatory obligations or safe operation.
Fewer MRAs Do Not Mean Fewer Compliance Risks
The new framework narrows when certain issues qualify for an MRA, but regulators can still communicate other violations and supervisory observations where an issue does not meet the formal threshold.
That means fewer MRAs do not necessarily mean fewer regulatory concerns.
The OCC's revised enforcement procedures also generally give banks an opportunity to remediate deficiencies through the supervisory process before formal enforcement action under Section 8 of the Federal Deposit Insurance Act.
For compliance teams, effective remediation remains critical.
AML And CFT Remain Major Priorities
The narrower supervisory framework does not mean anti-money laundering (AML) and counter-terrorist financing (CFT) requirements are becoming less important.
Recent enforcement activity has highlighted deficiencies in AML/CFT programmes involving areas such as business expansion, foreign correspondent banking and virtual currency-related customers.
The key question is whether a bank's controls effectively address its actual risk profile.
As institutions expand into new products, customer segments, jurisdictions and delivery channels, their compliance programmes need to evolve with them.
This includes reviewing:
Customer due diligence
Transaction monitoring
Sanctions screening
Suspicious activity reporting
Customer risk ratings
Enhanced due diligence
Correspondent banking controls
Compliance testing
A policy that exists on paper is not enough. Regulators are increasingly concerned with whether controls work in practice.
Business Growth Can Change Compliance Risk
A control environment that works for a relatively simple banking business may not remain appropriate after expansion into payments, correspondent banking, digital assets or other higher-risk activities.
Recent enforcement actions highlighted by Reuters show how weaknesses can emerge as businesses and customer profiles change.
Compliance teams therefore need to identify when changes in products, customers, transaction volumes or markets require changes to controls.
The expectation is not simply that banks have compliance processes, but that those processes remain appropriate for the risks the institution actually faces.
Financial Risk Is Central To The New Approach
The new framework places greater emphasis on financial risks including capital, liquidity, asset quality, earnings and interest rate risk.
The OCC and FDIC specifically reference impacts involving capital, asset quality, earnings, liquidity and market risk when describing material harm to a bank's financial condition.
This reinforces the connection between financial and compliance risk.
A compliance weakness can create financial consequences through fines, remediation costs, restrictions on business activity, customer losses or operational disruption.
Compliance teams therefore need to understand how regulatory weaknesses could affect the wider financial position of the institution.
Technical Compliance Still Matters
The focus on materiality should not be interpreted as permission to ignore technical requirements.
Actual violations of banking laws can still support an MRA under the new OCC and FDIC framework.
The OCC has also proposed distinguishing between substantive and technical violations when determining whether an MRA should be issued. The aim is to focus supervisory attention on violations that could meaningfully affect a bank or its customers while retaining mechanisms for addressing less significant violations.
A technical weakness can still become significant when it is repeated, widespread or indicative of a broader control failure.
The Federal Reserve Is Taking A Similar Direction
The Federal Reserve has updated its supervisory operating principles to emphasize material financial risks that threaten the safety and soundness of banks and proportionate action to address those risks.
The direction is broadly similar across the federal banking agencies, although their approaches are not identical.
For banks supervised by multiple regulators, this could create differences in how materiality, regulatory significance and supervisory risk are interpreted.
What Compliance Teams Should Do Now
The changing framework creates several practical priorities for compliance leaders.
Test control effectiveness: Banks should be able to demonstrate that controls operate as designed and address relevant risks.
Reassess AML/CFT controls: Changes in customers, products, jurisdictions and transaction volumes should trigger reviews of AML/CFT controls.
Strengthen issue management: Compliance issues should be tracked from identification through remediation, with clear ownership and escalation.
Connect compliance and financial risk: Teams should understand where regulatory weaknesses could lead to financial losses, operational disruption or restrictions on business activity.
Take supervisory observations seriously: An issue does not need to become an MRA before it deserves attention. Informal regulatory feedback can provide an opportunity to address weaknesses early.
A Shift In Supervision, Not A Relaxation Of Compliance
US banking supervision is becoming more focused on materiality, financial risk, substantive violations and effective risk management.
But the underlying responsibility of banks has not changed.
AML/CFT obligations remain important. Banking law violations remain relevant. Financial weaknesses remain central to safety and soundness supervision. Regulatory observations can still expose weaknesses that need to be addressed.
For compliance teams, the practical lesson is straightforward: the focus is shifting from whether a process exists to whether the control environment effectively manages the risks that matter most.
Strong risk assessment, control testing, issue management and ongoing compliance monitoring will remain essential as regulators continue to apply the new standards.