Monthly Deposits – Issue #7
Welcome to the seventh issue of Monthly Deposits: MoFo’s Bank Regulatory Newsletter, which provides an overview of recent developments in U.S. bank regulation, including proposed rules, reforms, and other significant updates. In this newsletter, we cover some of the key developments from the past month that our team is monitoring.
Regulators Clarify: Banks May Discuss Suspicious Activity With Customers Without Compromising SAR Confidentiality
For an in-depth discussion of this topic, please see our full client alert.
On September 2, 2026, the Federal Reserve Board (FRB), the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), the Office of the Comptroller of the Currency (OCC), and the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) (collectively, the “Agencies”) issued a joint statement (the “Joint Statement”) clarifying how banks (and credit unions) can communicate with customers about suspicious or potentially fraudulent activity without violating the confidentiality rules that protect Suspicious Activity Reports (SARs) under the Bank Secrecy Act (BSA). The Joint Statement does not change any existing legal requirement or create new supervisory expectations, but it sends a clear signal that regulators want banks to be more forthcoming with customers, not less.
Key Takeaways:
- The core message of the Joint Statement is a familiar one, restated with new emphasis: the BSA prohibits disclosing a SAR or anything that would reveal the existence of a SAR, but it does not prohibit sharing the underlying facts, transactions, and documents on which a SAR is based.
- The Agencies offer a non-exhaustive list of communications that would not typically reveal the existence of a SAR, including requesting customer due diligence information; notifying a customer that an account restriction, delay, or closure may relate to suspected fraud; explaining that a deposit was rejected because of suspected check fraud; asking about the purpose of a transaction or source of funds; and providing fraud-awareness education, including on money mule schemes.
- Rather than treating SAR confidentiality as a reason for institutions to say as little as possible, the Agencies and FinCEN are encouraging banks to lean into the space that the law already gives them, whether that means sharing information with a foreign affiliate to fight illicit finance, or explaining to a customer why their account was frozen.
Agencies Issue FAQs on Acceptance of Verifiable Digital Credentials for Customer Identification Purposes
On September 8, 2026, the FRB, the FDIC, the NCUA, the OCC, and FinCEN (collectively, the “Agencies”) jointly issued answers to frequently asked questions (FAQs) on banks’ use of state-issued mobile driver’s licenses and other government-issued verifiable digital credentials (VDCs) to comply with the Customer Information Program (CIP) Rule. The FAQs do not change any existing legal requirement or create new supervisory expectations under the BSA, but they represent the first express confirmation that banks and credit unions may accept authenticated VDCs for CIP customer verification compliance purposes.
The FAQs provide a new definition of VDC, defined as a data structure that (i) contains information about an individual; (ii) is digitally signed by the issuing source of the information; (iii) is cryptographically bound to a device; and (iv) is protected by an activation factor, such as a PIN, password, or biometric identifier. Importantly, the FAQs confirm that a bank or credit union may consider accepting such a credential provided that the bank or credit union can meet the requirements of the CIP Rule, explicitly providing that an unexpired, government-issued VDC, such as a mobile driver’s license, would qualify as “government-issued identification” for CIP Rule compliance purposes. The Agencies remind banks and credit unions that if a government-issued VDC shows indications of fraud, the bank or credit union must consider those indications in determining whether it can form a reasonable belief that it knows the customer’s true identity. Finally, the FAQs clarify that VDCs that are maintained by a non-government third party may be used as non-documentary means to verify the identity of a customer, but that the bank or credit union is responsible for ensuring that the third party uses the same level of authentication as the bank or credit union itself would use.
Banking Agencies Issue Proposed Updated Third-Party Risk Management Guidance
For an in-depth discussion of this topic, please see our full client alert.
On September 11, 2026, the FRB, the FDIC, the OCC, and the NCUA (collectively, the “Agencies”) issued proposed interagency guidance (the “Proposed Guidance”) that would replace the Agencies’ 2023 guidance (the “2023 Guidance”) on third-party risk management. In a joint press release accompanying the Proposed Guidance, the Agencies stated that they would “move away from overly broad, process-driven approaches, make clear that there is no one-size-fits-all approach to third-party risk management, and encourage responsible innovation.” The Agencies plan on rescinding the 2023 Guidance when the Proposed Guidance is finalized. Comments on the Proposed Guidance are due by November 16, 2026.
Key Takeaways:
- The Proposed Guidance signals a greater acceptance of bank-fintech partnerships and a focus on addressing material financial risks and violations of laws and regulations, in keeping with broader policy priorities.
- The Proposed Guidance retains a principles-based approach focused on tailoring risk management practices toward a bank’s size, complexity, risk profile, and the nature of its third-party relationships.
- Notwithstanding the flexibility that the Proposed Guidance would offer, banks would ultimately remain liable under the Proposed Guidance for the actions that their third-party service providers take when performing regulated banking activities. Fintechs should not anticipate any relaxation in scrutiny from their bank partners.
If finalized as proposed, the Proposed Guidance would move from a process-driven approach in evaluating banks’ third-party partnerships to an approach focused on identifying and mitigating the risks with the highest likelihood and greatest potential impact. These developments suggest that fintechs and other complex technology providers will remain a significant area of supervisory interest even as the Agencies move toward a more flexible and risk-based third-party risk management framework.
FDIC Approves Proposed Rule to Modernize Framework for Reviewing Bank Merger Transactions
On September 17, 2026, the FDIC Board of Directors approved a notice of proposed rulemaking (“Bank Merger NPR”) to modernize and reform the FDIC’s process for reviewing merger transactions under the Bank Merger Act (BMA). The Bank Merger NPR would standardize the required timelines under the BMA, providing for a written determination by the FDIC within 90 days for standard processing of bank merger filings from institutions with less than $50 billion in assets, and would modernize the bank merger framework to better align with the contemporary banking environment.
Specifically, the Bank Merger NPR would:
- Account for credit unions and centrally booked deposits in the competitive effects analysis;
- Establish a “deemed approval” letter filing process to grant approval for qualifying de minimis merger transactions within five business days of filing;
- Tailor merger filing requirements to reduce burden and processing times;
- Update the asset threshold for expedited processing to reflect that the amount of the total assets to be acquired cannot exceed 25%, up from 10%, of the acquiring institution’s total assets;
- Clarify the FDIC’s discretion to remove a filing from expedited processing;
- Require the FDIC to notify applicants within 21 days if an application filing is incomplete; and
- Reform the FDIC’s approach to evaluating the BMA’s statutory factors.
The FDIC’s Bank Merger NPR would continue the agency’s recent efforts to reduce regulatory burden and appropriately tailor regulations to the type, size, and complexity of the potential risks involved.
Comments on the Bank Merger NPR are due by November 23, 2026.
FDIC Approves Proposed Rule to Promote Parity Between State and National Banks
Also on September 17, 2026, the FDIC Board of Directors approved a notice of proposed rulemaking (NPR) to amend its regulations under the Federal Deposit Insurance Act (“FDI Act”) to promote parity between state banks and national banks. The NPR would provide that, if host state laws do not apply to a national bank, those laws would also not apply to an out-of-state state bank providing services in the host state, without regard to whether the state bank has a branch in the host state. Instead, the law of the state bank’s chartering state would apply.
The NPR arrives in the broader context of an ongoing preemption debate, spurred by the conflicting application of certain state laws regulating payments to national banks, which enjoy broad federal preemption of state laws, and state-chartered banks. While
Section 24(j) of the FDI Act places out-of-state state-chartered banks on comparable footing with out-of-state national banks when host-state laws apply to branches, it has been an open question whether this provision applies when an out-of-state state bank serves customers or merchants in a state where it has no physical branch. The NPR aims to clarify how this provision applies in a modern interstate banking environment by expressly providing that the parity provisions apply without regard to whether the state bank has a branch in the host state. However, the NPR would not apply to the interest rate provisions under Section 27 of the FDI Act, which governs the interest rates that state banks are permitted to charge on loans.
Comments on the NPR are due by November 23, 2026.






