The OCC Narrowed What It Will Tell You, Not What You Owe

On May 19, the White House directed the Treasury and the federal banking agencies to more closely scrutinize which customers banks onboard and how money moves through their accounts. On August 27, the Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corp. (FDIC) told examiners to stop elevating most process and control weaknesses into formal supervisory findings.

Both actions remain in force. Neither mentions the other. That creates a consequential split. Banks’ customer due diligence expectations are expanding, particularly around identity, payroll, beneficial ownership and payment flows. At the same time, the mechanism that once moved many weaknesses from an examiner’s workpapers to a board agenda has narrowed. The underlying obligation has not disappeared, but the external prompt to address a weakness has become easier to miss.

What the Order Asks Banks to See

Executive Order 14406, signed May 19, directs the Treasury Secretary to propose changes to Bank Secrecy Act rules that strengthen risk-based customer due diligence. It also directs Treasury and the banking agencies to consider changes to Customer Identification Program requirements that account for risks associated with foreign consular identification cards.

The Financial Crimes Enforcement Network (FinCEN) moved quickly. On June 5, the bureau joined the OCC, FDIC and the National Credit Union Administration in a joint advisory setting out 18 red flags, built around identity theft and payroll fraud as the two mechanisms used to conceal unauthorized employment. The typologies the order names will be familiar to anyone who has run an AML program: nominee accounts, shell companies, funnel structures, off-the-books wage payments routed through unregistered money services businesses, peer-to-peer platforms, and sub-threshold deposits timed to payroll cycles.

Credit followed. On July 13, the OCC, FDIC and NCUA issued guidance on lending to people not legally authorized to work in the United States. Separately, the Consumer Financial Protection Bureau’s statement on ability to repay and immigration status, effective June 8, says creditors may need to consider immigration status when it materially affects a borrower’s expected income.

Taken together, these actions ask a common question from several directions: Who is this customer, and does the activity in the account make sense given the identity, employment and financial story attached to that customer?

What the Rule Takes Off the Table

Ten weeks after the advisory, the OCC and the FDIC raised the threshold for formally telling a bank it has failed to answer that question.

OCC Bulletin 2026-40 describes the agencies’ joint final rule that defines an “unsafe or unsound practice” and establishes a uniform standard for Matters Requiring Attention (MRA). Under the new standard, an examiner may now issue an MRA only for conduct contrary to generally accepted standards of prudent operation that has already caused material harm to the bank’s financial condition, or that could reasonably be expected to cause such harm or present a material risk of loss to the Deposit Insurance Fund, or for an actual violation of a banking law or regulation.

The agencies are explicit about the intent. Examiners and banks should “prioritize material financial risks over concerns related to policies, process, documentation and other nonfinancial risks.” Issues below that threshold become supervisory observations, and the rule says an observation does not create a requirement or supervisory expectation that it be presented to the board. Decisions about whether to implement enhancements remain with the bank.

Materiality is also tailored. As a bank’s size, complexity and risk profile rise, the threshold for supervisory concern falls. The same weakness in documentation or alert coverage may have a different supervisory significance at a $2 billion institution than at a $200 billion institution.

What an MRA Used to Do

An MRA was never just a formal finding. It was an escalation mechanism that carried an issue from the examiner’s file to the board agenda, from the board agenda to a remediation plan and from the remediation plan to a budget request. In practice, it often provided the institutional backing for a compliance team’s request for more people, better data, a monitoring upgrade or a cross-functional fix.

The sequence is familiar. A monitoring platform produces more alerts than the team can investigate. The financial-crime leader raises the staffing gap, only to lose to product priorities or a broader technology roadmap. The problem resurfaces. Eventually, an examiner puts the gap in writing. The board must respond, and funding becomes available.

Under the new standard, much of that sequence is less reliable. An alert backlog, stale model documentation, tuning that has not been revalidated since implementation, or a coverage gap between fraud and AML systems may all be treated as process concerns. If they do not meet the new materiality standard or amount to an actual legal violation, they are likely to be supervisory observations rather than MRAs.

An observation is advisory by design. The legal duties beneath those issues have not changed. Bank Secrecy Act obligations remain statutory obligations, and the new rule preserves MRAs for actual violations. A monitoring gap does not cease to be a monitoring gap because it is called an observation. It may simply not become a board-level supervisory matter until it contributes to a violation, an enforcement action or a regulatory decision, such as a denied charter application.

That is the dynamic I discussed last month: the OCC can press hard in private on issues it explains only sparingly in public. Charter denials are often one of the few moments when that reasoning becomes visible. Since August 27, a similar reticence may shape both routine supervision and licensing.

Where the Red Flags Actually Sit

The FinCEN advisory is difficult to operationalize precisely because its indicators cross system boundaries. Consider deposits below reporting thresholds that recur around a payroll cycle. A transaction-monitoring system can see dates and amounts. But detecting the full pattern may require the bank to connect those transactions to an employer, an expected wage cadence, the presence or absence of a payroll processor and the customer’s identity profile. Much of that context lives outside conventional AML rules, in onboarding data, identity resolution tools, device intelligence and third-party enrichment sources.

Funnel accounts and nominee structures present a similar problem. Individual accounts can look ordinary in isolation. Identifying the underlying structure requires visibility into relationships across accounts, devices, entities and transactions. That visibility often breaks down when identity, fraud and AML data sit in separate systems managed by separate teams.

Meanwhile, FinCEN has moved in the opposite direction on some beneficial ownership requirements. Its February order granting exceptive relief narrowed to cover institutions that must obtain and verify beneficial owner information at account opening, during risk-based ongoing review and when the institution has reason to doubt the information it holds.

Less frequently refreshed ownership data places greater weight on behavioral signals. In practical terms, banks need to be better at inferring relationships, intent and risk from activity that may be fragmented across their fraud, identity, payments and AML environments. That makes the connective work more important than it was in May. It also places it squarely in the category that the new rule is most likely to treat as a process issue. Architecture is a process concern — until it produces a violation.

An Examiner’s Silence Is Now a Weaker Signal

Before August 27, an examination that produced no MRAs generally suggested that an examiner had found no issue requiring formal correction. Now, it can also mean that the examiner found a weakness but lacked the authority to require remediation. Compliance teams should interpret that silence accordingly. The escalation work that examiners once performed more routinely may now need to happen inside the bank.

  • Escalate material control weaknesses directly to the board. A weakness that might have produced an MRA in June may still deserve board attention in September, regardless of what an examiner is now permitted to call it.
  • Document decisions not to remediate. The rule leaves more discretion with the institution. That also means the institution owns the contemporaneous record explaining why it accepted, deferred or rejected a recommended enhancement.
  • Treat cross-system visibility as a risk-control issue, not merely a technology project. The indicators in the June advisory depend on joining identity, employment, device, payment and transaction data. If those connections do not exist, a bank may fail to see a pattern until after it has become a legal, financial or reputational event.
  • Track the unfinished half of the executive order. The order gave Treasury 90 days to propose BSA amendments strengthening customer due diligence — a deadline that fell on August 17 without a published proposal. The 180-day deadline for Treasury and the banking agencies to consider changes to the Customer Identification Program regarding foreign consular identification cards falls on November 15.

The asymmetry is notable. The rule that narrows what examiners may formally require took effect 10 days after the Treasury missed its deadline to propose rules that could expand what banks must detect. The bar for compliance did not necessarily move this summer, but the warning system did. Until examiners are again free to elevate these issues more readily, a finding that a bank never receives may still be one it ultimately has to own.

Take the First Step Toward Transformative Fraud Prevention