Welcome to the sixth issue of Monthly Deposits: MoFo’s Bank Regulatory Newsletter, which provides an overview of recent developments in U.S. bank regulation, including proposed rules, reforms, and other significant updates. Here we cover some of the key developments from the past month that our team is monitoring.
For an in-depth discussion of these proposals, please see our full client alert.
On June 30, 2026, the Federal Deposit Insurance Corporation (FDIC) published a notice of proposed rulemaking (FDIC NPR) that would update, clarify, and supplement the regulations regarding disclosure of non-public information—what is often referred to as confidential supervisory information. In certain instances, disclosure would no longer require prior authorization by the FDIC. On August 5, 2026, the Office of the Comptroller of the Currency (OCC) published its own notice of proposed rulemaking (OCC NPR) that would clarify the process for obtaining OCC approval to disclose non-public information, including the creation of a new subcategory of non-public OCC information expressly identified as “confidential supervisory information.” This new OCC subcategory includes: (i) records concerning supervision, licensing, regulation, enforcement, and examination of a supervised entity; (ii) reports of examination, supervisory correspondence, investigatory files, and any internal agency memorandum; and (iii) statements or testimony concerning supervisory activities. The OCC NPR would similarly allow for the disclosure of non-public information, including confidential supervisory information, without prior authorization by the OCC in certain circumstances. Comments on both proposals are due October 5, 2026, following the FDIC’s publication of an extension on August 28, 2026.
For an in-depth discussion of this topic, please see our full client alert.
On August 10, 2026, the FDIC announced a new two-phase process to review applications for deposit insurance for all applications received after August 15, 2026. According to the FDIC, the two-phase process is intended to encourage new bank formation, accelerate the speed of the review process, and improve the efficiency of the application process.
The FDIC’s new process could significantly accelerate deposit insurance approvals, consistent with a recently enacted law directing the federal banking agencies to streamline de novo applications. Definitive timelines and the two-step process will provide organizers with more clarity before committing to activities such as hiring employees or raising capital.
The June issue of Monthly Deposits highlighted the Federal Financial Institutions Examination Council’s (FFIEC) proposed revisions to the Uniform Financial Institutions Rating System, commonly referred to as the CAMELS rating system. On August 24, 2026, the California Department of Financial Protection and Innovation (DFPI) announced that it had filed a comment letter in opposition to the proposed revisions.
The CAMELS rating system is used by the FFIEC’s member agencies to evaluate the safety and soundness of financial institutions, including state charted banks that are examined by both federal and state supervisors. The DFPI, which examines California state banks, warned that the proposed revisions would weaken critical bank supervision, potentially endangering the economic outlook of consumers and small businesses in the state.
In particular, DFPI took issue with the proposed shift in the focus of the CAMELS framework, which it views as deprioritizing bank management and supervision in favor of present-day financial metrics. In DFPI’s view, such a shift would undermine regulators’ ability to detect and address emerging problems in the financial system, potentially paving the way for unexpected bank crises, including bank failures. DFPI dealt firsthand with such failures during the 2023 bank failure crisis and expressed its preference for the current system. According to DFPI’s comment letter, the current “CAMELS ratings have adequately focused on forward-looking supervision allowing bank management to identify and address risks preemptively.” While DFPI’s preferred approach to bank supervision may not hold weight with the current administration, it likely indicates the direction federal banking regulators might take under a potential new administration.
On August 27, 2026, the OCC and the FDIC issued a joint final rule establishing new standards for identifying unsafe or unsound practices and issuing “matters requiring attention” (MRAs). The final rule is intended to focus supervisory and enforcement resources on material financial risks rather than nonfinancial risks or deficiencies involving policies, processes, documentation, or other issues that do not present material concerns. The final rule will take effect on November 2, 2026.
Under the final rule, an “unsafe or unsound practice” is defined as a practice, act, or failure to act that is contrary to generally accepted standards of prudent operation and, if continued, is likely to materially harm an institution’s financial condition or present a material risk of loss to the FDIC’s Deposit Insurance Fund, or that has already materially harmed the institution’s financial condition. The definition of “harm to financial condition” is expressly limited to financial losses or other negative impacts to capital, asset quality, earnings, liquidity, or sensitivity to market risk.
The final rule also provides that an MRA may be issued where an imprudent practice, if continued, could reasonably be expected under current or reasonably foreseeable conditions to materially harm the institution’s financial condition or present a material risk of loss to the FDIC’s Deposit Insurance Fund. An MRA may also be issued for actual violations of banking or banking-related laws or regulations under the final rule. The agencies emphasized that this standard permits MRAs to address significant risks before they rise to the level of an unsafe or unsound practice, while speculative concerns regarding future harm are insufficient to warrant an MRA.
With respect to violations of law, the agencies stated that they intend to exercise their supervisory discretion to issue MRAs only for “substantive” violations, including: (i) systemic or patterned violations; (ii) violations having a more-than-minimal impact on financial condition or books and records; (iii) violations requiring more-than-minimal restitution or adversely affecting customers; and (iv) insider misconduct or self-dealing. The rule also distinguishes MRAs from less formal supervisory communications, such as “supervisory observations,” which may identify weaknesses that do not satisfy the MRA standard, but do not require corrective action, and “other violations,” which are violations of banking or banking-related law that do not result in an MRA or enforcement.
On August 27, 2026, immediately following the joint OCC and FDIC final rule establishing standards for unsafe or unsound practices, MRAs, and other supervisory communications, the OCC announced a series of actions intended to focus its bank supervision and enforcement on material financial risks and significant violations of law. The actions include revised Policies and Procedures Manuals (PPMs) governing bank enforcement actions and MRAs, as well as a proposed rule that would establish separate categories for “substantive” and “technical” violations of law.
PPM on Bank Enforcement Actions
Under the revised framework, the OCC will generally provide banks an opportunity to remediate deficiencies through the supervisory process before escalating the matter to an enforcement action, while retaining the ability to take immediate enforcement action where circumstances warrant. The OCC will also tailor enforcement actions based on a bank’s capital structure, complexity, activities, asset size, and other financial risk-related factors, with heightened expectations for larger and more complex institutions. Notably, the revised PPM also provides that the OCC generally will terminate an enforcement action once a bank has achieved “substantial compliance,” even if minor or isolated remediation requirements remain outstanding.
PPM on MRAs
The PPM on MRAs generally limits the issuance of MRAs to those practices that (i) present a reasonably foreseeable risk of material harm to a bank’s financial condition or material risk of loss to the FDIC’s Deposit Insurance Fund; (ii) have already caused such material harm; or (iii) constitute substantive violations of banking or banking-related laws. Less significant violations may still be communicated to bank personnel, but examiners generally will not prescribe the manner of correction, require a corrective action plan, or track remediation. Similarly, supervisory observations that do not rise to the level of an MRA will not require corrective action or an action plan.
Proposed Rule on New Categories for Violations of Law
Finally, the OCC proposes to codify its approach to violations by distinguishing between “substantive violations,” which could support an MRA, and “technical violations,” which would be addressed through less formal supervisory mechanisms. The definition of “substantive violation” would generally mirror that of the joint OCC and FDIC final rule discussed above, while a “technical violation” would be a violation where the nature, duration, frequency, and severity of the violation could not meaningfully impact the institution and its customers. Taken together, the new definitions would generally place a limit on the OCC’s ability to issue MRAs for less significant legal violations. Comments on the proposed rule are due by October 1, 2026.