The FDIC and OCC recently finalized a rule designed to give banks clarity as to what constitutes "unsafe or unsound" banking practices and focus examiners on practices that are likely to materially harm an institution's financial condition.

  • For covered institutions, the final rule defines an unsafe or unsound practice as a practice, act, or failure to act that is contrary to generally accepted standards of prudent operation and that, if continued, is likely to materially harm the institution's financial condition or present a material risk of loss to the Deposit Insurance Fund—or that has already materially harmed the institution's financial condition.
  • The rule also permits examiners to issue an MRA (Matter Requiring Attention) under a lower, forward-looking standard: An MRA may address such imprudent conduct if, under current or reasonably foreseeable conditions, its continuation could reasonably be expected to materially harm the institution's financial condition or present a material risk of loss to the Deposit Insurance Fund, or if the conduct has already materially harmed the institution's financial condition.
  • Examiners may also issue an MRA for an actual violation of a banking or banking-related law or regulation.

At first blush, the rule appears to change examiners' focus away from meta-compliance and technical violations and toward the most serious risks facing banks. But banks as institutions, on the one hand, and the individuals that work at and for them, on the other, should note the separate standards involved.

Key Highlights

  • A generally positive development for banks as institutions. The OCC and FDIC finalized a joint rule that narrows the definition of "safety and soundness" to focus on material risks to banks and their customers. Supervisory priorities will shift toward this narrower definition.
  • The final rule does not apply to individuals. A bank employee or board member might still be held personally liable for a safety-and-soundness violation even if it is not material. Whether that actually happens is something to watch.
  • Compliance still matters. Banks and individuals can still be subject to supervisory or enforcement actions for violations of banking and related laws. Though the OCC proposed a rule to limit supervisory actions, it is not clear how much protection that will give banks or individuals.
  • Policies, procedures, and controls can still help. Banks—and individuals working at and for banks—should consider reviewing policies, procedures, and controls with an eye toward the human side of the examination process.

Safety and Soundness Background

A key concept of federal banking law is safety and soundness. Though the concept was undefined and malleable, the underlying idea is that federally insured banks should not set themselves up for failure.

The operative definition for decades was a statement made by John Horne, then Chairman of the Federal Home Loan Bank Board, during 1966 congressional hearings—later called "the authoritative definition" by the Fifth Circuit—which required only that the practice could produce "abnormal risk or loss," without any materiality threshold.

If a bank is found to have engaged in unsafe or unsound practices, it may be subject to an enforcement action. Employees, directors, and others that work for or with insured banks can also be subject to individual enforcement actions as "institution-affiliated parties" (IAPs). Prudential regulators examine banks to confirm consistency with this standard, and safety and soundness failures can also give rise to supervisory MRAs, which, though confidential and less serious than enforcement actions, may restrict growth and expansion plans. As previously covered, in recent years MRAs have multiplied, but in many cases, have never been resolved—they were often left open and unresolved for extended periods of time.

Critics have alleged that safety-and-soundness reviews have become increasingly solipsistic. Rather than focusing on material risks to the banking system, examiners appear to have focused more on the development of compliance management systems (CMS) and supporting technical and bureaucratic apparatuses than addressing systemic issues that could actually lead to bank failure.

  • These complaints became especially pronounced after the high-profile failures of several banks in March 2023 when regulators failed to raise—and manage—material red flags.
  • As early as 2017, the Bank Policy Institute (BPI) argued that examination had become focused on immaterial operational concerns like vendor management, committee composition, or documentation protocols and bore no demonstrated relationship to financial condition.
  • BPI also notably criticized the Federal Reserve for rating two-thirds of U.S. banking organizations as poorly managed while simultaneously acknowledging that the same institutions were well capitalized, highly liquid, and in strong financial condition.

The final rule's core provisions correspond closely to positions that industry has supported: a regulatory definition anchored in material financial harm, an MRA standard requiring a reasonable expectation of material harm, a mandate for objective facts and sound reasoning, the exclusion of reputational risk, and a tailoring framework calibrated to actual risk.

This policy change is not because of too many MRAs in general, but ineffective supervision more broadly. For instance, Michelle W. Bowman, the Federal Reserve Board's Vice Chair for Supervision, announced preliminary findings from an independent review of one of the 2023 bank failures and noted that "one significant factor contributing to supervisory inaction was a long-standing culture of risk aversion. Staff believed it was personally safer to take no action unless they were certain the action was exactly right." In addition, a lack of clarity regarding decision rights compounded this culture of risk aversion. The Federal Reserve Board has previously updated its Supervisory Operating Procedures to help address these concerns. The OCC and FDIC are broadly supportive of a general reorientation of supervision under the current Administration.

Banks as Institutions Get Relief

The OCC and FDIC published a joint final rule codified at 12 CFR 4.92 and a new 12 CFR part 305, effective November 2, 2026, that for the first time defines "unsafe or unsound practice" in regulation. Under the final rule, a practice qualifies as unsafe or unsound only if it:

(1) is contrary to generally accepted standards of prudent operation and, if continued, is likely to materially harm the financial condition of the institution or present a material risk of loss to the Deposit Insurance Fund, or

(2) has already materially harmed the financial condition of the institution.

The rule specifies that material harm means negative impacts to an institution's capital, asset quality, earnings, liquidity, or sensitivity to market risk. Under this framework, process criticisms, policy disagreements, and reputational harm claims unconnected to financial condition do not meet the standard for enforcement action or supervisory criticism.

The final rule is consistent with a more general policy to pivot toward focusing on material financial risks. FDIC Chair Travis Hill explained that the rule "shifts ... attention toward underlying fundamental risks and away from banks' processes for managing those risks," and requires that the risk of material harm be "more than speculative or merely possible." Banks may still receive feedback from examiners, but it should be targeted and its use more focused. The idea is that the receipt of this information should allow banks to actually resolve these issues and move on.

Substantive prudential requirements are unchanged: Capital, complexity, asset size, liquidity, and concentration rules remain untouched.

Heightened Standards for MRAs and Examiner Accountability

The rule establishes a corresponding standard for MRAs. An MRA may be issued only where the criticized practice, if continued, "could reasonably be expected to under current or reasonably foreseeable conditions" materially harm the bank's financial condition or present a material risk of loss to the Deposit Insurance Fund. Weaknesses that do not meet this threshold may be communicated as informal "supervisory observations," which do not carry the board-notification expectations or remediation weight of an MRA. Practitioners should note, however, that the agencies expressly reserved the right to use the information underlying supervisory observations to support assigned CAMELS ratings classifying a bank's overall condition, a factor that compliance teams will need to keep in mind.

The rule further requires that examiners base their determinations on "objective facts and sound reasoning" and disclose that basis to the bank. Before issuing an MRA or characterizing conduct as unsafe or unsound, examiners must demonstrate a data-supported nexus between the criticized activity and a material financial harm. The agencies declined to require quantification or to codify any burden of proof, but institutions now will receive a written justification in the report of examination.

The agencies must also tailor their supervisory activities and enforcement actions based on the bank's capital structure, complexity, activities, and asset size. As institutional risk increases, the materiality threshold decreases, the harm assessment becomes more granular ("e.g., specific business lines, products, or services"), and remediation expectations increase. The inverse applies as risk falls. The result is that community banks receive a genuinely higher materiality bar assessed against the whole balance sheet. The agencies declined, however, to publish tiers based on asset size or complexity, an illustrative matrix, or any guidance on applying the tailoring standard, reasoning that such guidance "may have an inappropriate limiting effect on the application of examiner judgment." Tailoring is therefore mandatory but may prove largely unverifiable in application.

Bank Employees, Directors, and Others Are Still at Risk

Even if this rule is positive for banks as institutions, its impact on bank employees and others that work for or with them is far from clear. The final rule doesn't apply to IAPs—employees, agents, directors, officers, control persons like certain shareholders, and even attorneys and accountants in certain circumstances. So, an individual's (alleged) actions or failures that do not result in material risk of harm to the institution can still form the basis of a personal enforcement action for unsafe and unsound practices. The same goes for core third-party service providers; the prudential regulators also recently clarified that such third parties can also be the subject of enforcement inquiries. So, given the proliferation of bank-fintech partnerships and other recent trends, the fact that agents of banks may be found personally liable for safety and soundness violations is notable.

The prudential regulators' shift toward a focus on individuals was already on display prior to this guidance. At the OCC, the percentage of enforcement actions against individuals (as opposed to institutions) jumped from 70% to 89% under this Administration. The percentage of FDIC enforcement actions against individuals also inched up from 43% to 50%.

While policy-and-procedure-style supervisory criticisms may wane, institutional policies, procedures, and adequate controls nevertheless may help individuals avoid personal liability. And because institutions are still liable for material safety and soundness violations (but perhaps with less warning from examiners) institutions should be incentivized to get these basics right to avoid larger issues.

Technical Violations of Banking-Related Laws May Still Result in Enforcement Actions

The rule, moreover, concerns only safety and soundness—not the myriad other laws that banks are subject to. Under the Federal Deposit Insurance Act (FDI Act), insured banks and IAPs can be subject to an enforcement action for any predicate violation of law or safety and soundness violation. And under the new rule, MRAs can still be issued for violations of banking-related laws.

Unfortunately, banking-related laws can be as simultaneously prescriptive and vague as the previously unarticulated safety-and-soundness standard. For example, Regulation E contains multiple document-retention requirements, one of which includes a meta-requirement to develop adequate document-retention procedures (along with other adequate policies and procedures). For banks, violations of these rules probably would not constitute a safety-and-soundness risk under the new final rule. But they are still violations of federal law and thus might give rise to MRAs or a personal or institutional enforcement action under both the final rule and the FDI Act. (A bank's risk of exposure in an enforcement action from these regulators for a violation of consumer financial protection law depends on jurisdictional issues.)

To be sure, the OCC simultaneously unveiled a proposed rulemaking to further distinguish between "substantive" and "technical" violations of laws and regulations. But this does not provide as much cover as it initially suggests. The proposal concerns only the issuance of MRAs addressing supposed "technical" violations of law—not full-blown enforcement actions. So the proposal, if implemented, may have the perverse effect of funneling less severe violations into a more dramatic remedial tool.

And even then, the examples of "substantive" violations of law that can give rise to an MRA are sufficiently broad to cover all manner of seemingly technical misconduct. For example, "systemic" violations or those that "demonstrate a pattern" are considered substantive. Are meta-CMS issues—the exact type of policy-and-procedure issues this rulemaking was designed to target—"systemic," if based in regulatory text? If an insured bank inadvertently violates multiple provisions of one regulation, is that a "pattern"?

Similarly, a bank can be hit with an MRA if its violation of the law "had or reasonably [is] expected to have a more than minimal impact on the accuracy of the institution's books and records." The example the OCC provides—having to materially revise Call Reports—is certainly substantive. But, again, the language could be read to encompass paperwork requirements that the rule purportedly was designed to exclude.

Examiners Are Still Here and Will Be Here in the Future

Under the prior framework, examination staff had considerable latitude to characterize bank conduct as deficient on grounds ranging from credit-quality concerns to disagreements over committee structure, vendor management, documentation practices, or reputational risk. MRAs became the principal vehicle for communicating these criticisms, although there was no uniform regulatory standard that governed when one could be issued.

Even if these rules demonstrate a move toward more permissive bank regulation, they are being implemented by the same examiners from the former supervisory regime—and these same examiners will be on the front lines of any pendulum swing in the future.

Under the current supervisory and enforcement framework, IAPs including individuals appear to be even more at risk because of the very same dynamics that precipitated this rulemaking in the first place. Industry critics believed that bank examinations had become too focused on the examination process itself as opposed to material risks to insured banks. Examiners, in other words, developed expertise in identifying meta-policy-and-procedure errors. Now, these examiners have only one avenue to pursue that area of expertise: individual actions against IAPs.

Future Administrations may roll back this guidance and expect institutions to be able to quickly bring themselves into compliance with a broader supervisory framework. And, even if the current rules stay in place, many of the rules are sufficiently malleable to accommodate a more enforcement-minded regime, particularly against IAPs.

Our Take

Enforcement relief for banks is a positive development because it anchors agency actions in material harm rather than speculative issue-spotting that the regulator has little incentive to resolve. But individuals appear to face different enforcement risks and should not confuse the bank's interests with their own.

Deprioritizing CMS compliance is not recommended, even if banks do not receive pointed feedback about it. CMS compliance ultimately helps protect the bank and individuals. With less intermediate feedback, banks should be prepared for dichotomous results: silence or (eventual) public enforcement actions. We caution that political shifts may result in a more enforcement-oriented regime, and look-back periods could well exceed four-year presidential terms.

+++

Max Bonici, Jonathan Engel, and Steve Gannon are partners, and Sam Taxy and Paige Knight are associates in DWT's Washington, D.C., office. For questions or more insights, please reach out to the authors or another member of our financial services team. To stay informed, sign up for our alerts.