Welcome to the seventh issue of Monthly Deposits: MoFo’s Bank Regulatory Newsletter, which provides an overview of recent developments in U.S. bank regulation, including proposed rules, reforms, and other significant updates. In this newsletter, we cover some of the key developments from the past month that our team is monitoring.
For an in-depth discussion of this topic, please see our full client alert.
On September 2, 2026, the Federal Reserve Board (FRB), the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), the Office of the Comptroller of the Currency (OCC), and the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) (collectively, the “Agencies”) issued a joint statement (the “Joint Statement”) clarifying how banks (and credit unions) can communicate with customers about suspicious or potentially fraudulent activity without violating the confidentiality rules that protect Suspicious Activity Reports (SARs) under the Bank Secrecy Act (BSA). The Joint Statement does not change any existing legal requirement or create new supervisory expectations, but it sends a clear signal that regulators want banks to be more forthcoming with customers, not less.
On September 8, 2026, the FRB, the FDIC, the NCUA, the OCC, and FinCEN (collectively, the “Agencies”) jointly issued answers to frequently asked questions (FAQs) on banks’ use of state-issued mobile driver’s licenses and other government-issued verifiable digital credentials (VDCs) to comply with the Customer Information Program (CIP) Rule. The FAQs do not change any existing legal requirement or create new supervisory expectations under the BSA, but they represent the first express confirmation that banks and credit unions may accept authenticated VDCs for CIP customer verification compliance purposes.
The FAQs provide a new definition of VDC, defined as a data structure that (i) contains information about an individual; (ii) is digitally signed by the issuing source of the information; (iii) is cryptographically bound to a device; and (iv) is protected by an activation factor, such as a PIN, password, or biometric identifier. Importantly, the FAQs confirm that a bank or credit union may consider accepting such a credential provided that the bank or credit union can meet the requirements of the CIP Rule, explicitly providing that an unexpired, government-issued VDC, such as a mobile driver’s license, would qualify as “government-issued identification” for CIP Rule compliance purposes. The Agencies remind banks and credit unions that if a government-issued VDC shows indications of fraud, the bank or credit union must consider those indications in determining whether it can form a reasonable belief that it knows the customer’s true identity. Finally, the FAQs clarify that VDCs that are maintained by a non-government third party may be used as non-documentary means to verify the identity of a customer, but that the bank or credit union is responsible for ensuring that the third party uses the same level of authentication as the bank or credit union itself would use.
For an in-depth discussion of this topic, please see our full client alert.
On September 11, 2026, the FRB, the FDIC, the OCC, and the NCUA (collectively, the “Agencies”) issued proposed interagency guidance (the “Proposed Guidance”) that would replace the Agencies’ 2023 guidance (the “2023 Guidance”) on third-party risk management. In a joint press release accompanying the Proposed Guidance, the Agencies stated that they would “move away from overly broad, process-driven approaches, make clear that there is no one-size-fits-all approach to third-party risk management, and encourage responsible innovation.” The Agencies plan on rescinding the 2023 Guidance when the Proposed Guidance is finalized. Comments on the Proposed Guidance are due by November 16, 2026.
If finalized as proposed, the Proposed Guidance would move from a process-driven approach in evaluating banks’ third-party partnerships to an approach focused on identifying and mitigating the risks with the highest likelihood and greatest potential impact. These developments suggest that fintechs and other complex technology providers will remain a significant area of supervisory interest even as the Agencies move toward a more flexible and risk-based third-party risk management framework.
On September 17, 2026, the FDIC Board of Directors approved a notice of proposed rulemaking (“Bank Merger NPR”) to modernize and reform the FDIC’s process for reviewing merger transactions under the Bank Merger Act (BMA). The Bank Merger NPR would standardize the required timelines under the BMA, providing for a written determination by the FDIC within 90 days for standard processing of bank merger filings from institutions with less than $50 billion in assets, and would modernize the bank merger framework to better align with the contemporary banking environment.
Specifically, the Bank Merger NPR would:
The FDIC’s Bank Merger NPR would continue the agency’s recent efforts to reduce regulatory burden and appropriately tailor regulations to the type, size, and complexity of the potential risks involved.
Comments on the Bank Merger NPR are due by November 23, 2026.
Also on September 17, 2026, the FDIC Board of Directors approved a notice of proposed rulemaking (NPR) to amend its regulations under the Federal Deposit Insurance Act (“FDI Act”) to promote parity between state banks and national banks. The NPR would provide that, if host state laws do not apply to a national bank, those laws would also not apply to an out-of-state state bank providing services in the host state, without regard to whether the state bank has a branch in the host state. Instead, the law of the state bank’s chartering state would apply.
The NPR arrives in the broader context of an ongoing preemption debate, spurred by the conflicting application of certain state laws regulating payments to national banks, which enjoy broad federal preemption of state laws, and state-chartered banks. While
Section 24(j) of the FDI Act places out-of-state state-chartered banks on comparable footing with out-of-state national banks when host-state laws apply to branches, it has been an open question whether this provision applies when an out-of-state state bank serves customers or merchants in a state where it has no physical branch. The NPR aims to clarify how this provision applies in a modern interstate banking environment by expressly providing that the parity provisions apply without regard to whether the state bank has a branch in the host state. However, the NPR would not apply to the interest rate provisions under Section 27 of the FDI Act, which governs the interest rates that state banks are permitted to charge on loans.
Comments on the NPR are due by November 23, 2026.