FDIC and OCC Propose Substantive Updates to Treatment of Non-public Information, Impacting Banks and Fintechs

04 Sep 2026
Client Alert

On June 30, 2026, the Federal Deposit Insurance Corporation (FDIC) published a notice of proposed rulemaking (FDIC NPR) that would update, clarify, and supplement the FDIC’s regulations regarding disclosure of confidential information by the FDIC and other parties, facilitating disclosure in certain instances that would no longer require prior authorization by the FDIC. The FDIC also seeks to significantly simplify its requirements regarding discretionary disclosure of confidential information and disclosure of confidential information under the Freedom of Information Act (FOIA) and other means.

On August 5, 2026, the Office of the Comptroller of the Currency (OCC) published its notice of proposed rulemaking (OCC NPR) that would clarify the process for obtaining OCC approval to disclose non-public OCC information (“OCC information”), including “confidential supervisory information” (CSI). The OCC NPR would similarly allow for the disclosure of OCC information in certain circumstances without prior authorization by the OCC. The OCC NPR also seeks to update the OCC’s process for requesting nonexempt information under FOIA, including expedited processing requests.

Comments on both proposals are due October 5, 2026, after the FDIC published an extension on August 28, 2026. This client alert summarizes aspects of the agencies’ proposals that address the discretionary disclosure of confidential information.

Key Takeaways

n The agencies’ proposals are a welcome update to regulations and procedures that have often created significant friction and inefficiencies for the agencies, regulated institutions, fintech partners, outside advisors, and the general public.

  • If finalized in their current form, the agencies’ proposals would allow insured depository institutions (IDIs) to share confidential information, where necessary or appropriate for business purposes, with a broader category of parties. As described in the FDIC NPR, these parties would include fintech counterparties (i.e., “qualifying service providers”) that provide services used in connection with the provision of financial products or services to customers. IDIs could do so without prior agency approval, subject to certain conditions, such as entry into a qualifying confidentiality agreement.
  • While not identical, the proposals would significantly update the agencies’ policies on sharing of confidential information and expand the instances in which this information could be shared without preauthorization. Notably, only the OCC NPR would eliminate references indicating that referrals for criminal prosecution may be sought for the unauthorized disclosure of non-public information.
  • These proposals would bring the rules of the FDIC, the OCC, and the Federal Reserve Board (FRB) closer to a unified approach, but material differences would continue to exist among them, requiring regulated entities to consider the distinct approach of their primary federal regulator.

FDIC NPR

For the first time in 30 years, the FDIC proposes significant updates to the FDIC’s information-sharing and disclosure framework for IDIs. The FDIC NPR would amend the agency’s regulations at 12 CFR Part 309 and add a new Part 306 where certain regulations on service of process would be relocated. The FDIC’s current regulations would be reorganized into four subparts: (i) General; (ii) FOIA; (iii) Discretionary Disclosure of Confidential Information; and (iv) Disclosure of Confidential Information in Legal Proceedings in Which the FDIC Is Not a Party.

Disclosure of confidential information by the FDIC and other parties

The FDIC NPR would generally remove restrictions on the disclosure of confidential information that is more than 25 years old. It would also broaden the universe of parties with whom an IDI may share confidential information, where necessary or appropriate for business purposes, without prior FDIC approval, subject to certain conditions. The parties with whom an IDI could share confidential information (subject to a confidentiality agreement, described below) are as follows:

  1. IDI directors, officers, or employees;
  2. Affiliates of the IDI and the directors, officers, or employees of the IDI’s affiliates;
  3. An IDI’s external legal counsel, accountant, or auditor;
  4. Majority shareholders (in excess of 50 percent of IDI voting stock);
  5. Qualifying service providers;
    1. A “qualifying service provider” would mean an entity that (1) has a contractual relationship with the IDI, and (2) provides: (A) products or services to the institution that are used in connection with the provision of financial products or services to the IDI’s customers;[1] (B) advisory or consulting services related to the management or operations of the IDI; or (C) technological infrastructure to the IDI;
  6. Candidates for senior executive officer positions to whom an offer of employment has been made; and
  7. Potential merger counterparties (including their directors, officers, employees, affiliates, auditors, and legal counsel), with certain limitations.

Conditions for disclosure of confidential information by an IDI would require that, prior to or concurrently with any disclosure under categories 3–7 above, the IDI must enter into a qualifying confidentiality agreement with the intended recipient that is written and governed by state or federal law. Among other things, the confidentiality agreement would need to prohibit use of the information by the recipient for non-designated purposes and any onward disclosure. The confidentiality agreement would expressly provide that the FDIC is an intended third-party beneficiary of the agreement and is permitted to enforce its terms through a civil action.

Discretionary disclosure of confidential information that is exempt from disclosure under FOIA would need to meet the FDIC’s “good cause” standard. This standard would apply to decisions by the FDIC to disclose confidential information either on its own initiative or in response to a request. The standard would also apply to decisions by the FDIC to permit an IDI to disclose to a third party confidential information in the IDI’s possession, in those circumstances where such approval would continue to be required.

The good cause standard would be informed by FDIC consideration of eight non-exhaustive factors:

  1. Whether disclosure will serve a legitimate regulatory, supervisory, resolution, or law enforcement purpose;
  2. Whether there is another source for the confidential information;
  3. Whether disclosure of the confidential information is unduly burdensome or otherwise may adversely affect the FDIC;
  4. The scope and nature of the confidential information;
  5. The recipient’s intended use of the confidential information;
  6. Whether disclosure is lawful;
  7. Whether the confidential information includes privileged information or trade secrets; and
  8. Whether disclosure would present safety and soundness or financial stability risks.

OCC NPR

The OCC NPR would revise the agency’s regulations at 12 CFR Part 4 Subparts B and C regarding the availability of OCC information under FOIA and the release of OCC information. Currently, the OCC permits supervised entities to disclose OCC information only with OCC prior approval (subject to certain exceptions). In its proposal, the OCC states that the current categorization of non-public information in a “one-size-fits-all approach” fails to consider the context of the disclosure and limits government accountability.

Disclosure of CSI by the OCC and other parties

The OCC NPR would allow for disclosures to improve the efficiency of the supervisory process, without prior approval, to certain entities, including some that overlap with the FDIC NPR:

  • Affiliates;
  • Service providers;
    • The OCC proposal would define “service provider” as an unaffiliated person hired by or partnered with a supervised entity to perform specific, specialized functions for or on behalf of the entity related to the supervised entity’s operations or provision of services;
      • While this represents a broadened definition of the term “service provider” for the OCC, the definition would not include customers or financial counterparties, and, therefore, it is unclear whether the definition would include fintechs;
  • Senior executive officers;
    • Disclosures would only be permitted to incoming officers, rather than candidates as under the FDIC NPR;
  • Counterparties in business combinations; and
  • Certain consultants and attorneys of such counterparties.

One notable difference from the FDIC NPR is that the OCC NPR would also allow for disclosure to not-for-profit entities, such as trade organizations. The OCC indicates that this inclusion might allow for greater advocacy efforts, academic research, and new analyses and insights into the banking sector.

The OCC NPR would establish tailored safeguards around these exceptions, such as the required use of confidentiality agreements and other data-sharing safeguards, including that the recipient be incorporated in the U.S., have a business need for the information (such as assisting the supervised entity with remediating supervisory concerns or fulfilling supervisory expectations), and have a formal agreement with or be under a written contact to provide services to the supervised entity. The confidentiality agreement requirements would largely mirror those of the FDIC NPR, requiring a prohibition on the use of the information by the recipient for non-designated purposes and any onward disclosure and expressly providing that the OCC is an intended third-party beneficiary of the agreement and is permitted to enforce its terms through a civil action. In addition, the OCC NPR would require that the OCC receive notice of any violations of the agreement.

The OCC NPR would also eliminate references indicating that referrals for criminal prosecution may be sought for the unauthorized disclosure of non-public OCC information under 18 U.S.C. § 641. Notably, the FDIC NPR does not include similar language.

New Category of CSI

The OCC proposes a two-tiered framework for OCC information, establishing a new subcategory of OCC information for CSI and maintaining a category of other non-public OCC information. CSI would be defined to include:

  • Records concerning supervision, licensing, regulation, enforcement, and examination of a supervised entity;
  • Reports of examination, supervisory correspondence, investigatory files, and any internal agency memorandum; and
  • Statements or testimony concerning supervisory activities.

The OCC NPR states that information created or collected by a supervised entity for its own business purposes does not qualify as CSI simply because it is shared with the OCC.

Under the new framework, CSI could be disclosed without prior OCC approval in certain scenarios, while other non-public OCC information would follow the traditional approval process for disclosure. The OCC said it believes this would help to ensure more nuance than a “one-size-fits-all approach” to categorizing OCC information.

In addition, the OCC NPR would make several changes to the agency’s FOIA rules, including:

  • Providing for the permitted release of CSI that is at least 25 years old;
  • Providing for expedited processing for FOIA requests; and
  • Establishing procedures for a requestor to appeal a denial of an expedited processing or fee waiver request.

Our Thoughts

The agencies’ proposals represent a significant shift in the treatment and disclosure of confidential information. The treatment and sharing of confidential supervisory information have historically been a significant friction point in bank-fintech arrangements, at times impeding effective risk management and compliance coordination between banks and their fintech partners. The proposals would reduce the information asymmetry between banks and their fintech partners, potentially allowing for the sharing of critical supervisory findings, risk assessments, or compliance deficiencies without prior agency approval and encouraging robust, well-coordinated operational compliance and risk management programs.

If the proposals are finalized in their current form, the agencies would play less of an active gatekeeper role, allowing for routine disclosures to be handled without their prior approval. This should allow for smoother day-to-day business operations for regulated entities and meaningfully reduce administrative costs.

Minor differences in the agencies’ proposed approaches would still leave a slightly fractured regulatory landscape. Ideally, the FDIC, the OCC, and the FRB would adopt a uniform, interagency framework for handling and disclosing CSI with conforming definitions of the term “service provider” and interagency adoption of the term “confidential supervisory information.”

In sum, these proposals would represent a major shift toward greater transparency and a freer flow of information, allowing regulated entities to share confidential information under a broader threshold of preauthorized disclosures and reducing the administrative burden by no longer requiring agency approval for routine disclosures of CSI to covered third parties.


[1] The FDIC NPR specifically provides that this definition “would include third party ‘fintech’ companies that provide services used in connection with the provision of financial products or services to customers.” Disclosure of Information, 91 Fed. Reg. 39,726, 39,731 (proposed June 30, 2026).

We are Morrison Foerster — a global firm of exceptional credentials. Our clients include some of the largest financial institutions, investment banks, and Fortune 100, technology, and life sciences companies. Our lawyers are committed to achieving innovative and business-minded results for our clients, while preserving the differences that make us stronger.

Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Prior results do not guarantee a similar outcome.