Fewer Supervisory Findings Will Put More Weight on Bank Telemetry
Executive summary
The Office of the Comptroller of the Currency and Federal Deposit Insurance Corporation have narrowed the conditions under which examiners may label a bank practice “unsafe or unsound” or issue a Matter Requiring Attention. The joint final rule, published September 1 and effective November 2, is designed to focus boards, management teams and examiners on material financial risks rather than process, documentation and other nonfinancial weaknesses.
The mainstream case is straightforward. Formal findings consume management attention and can trigger expensive remediation. A clearer materiality threshold should reduce low-value work, make examinations more consistent and give banks room to exercise business judgment. The agencies expect fewer MRAs and enforcement actions, although they cannot quantify the benefit.
That interpretation misses an operational consequence. When fewer weaknesses become formal supervisory findings, the absence of an MRA becomes a weaker signal that a bank’s control environment is healthy. Emerging risks can remain as informal observations that do not have to reach the board and do not carry an expectation of corrective action. Banks and their fintech partners will need stronger internal telemetry, escalation rules and evidence linking process failures to plausible effects on capital, asset quality, earnings, liquidity and market risk.
The contrarian thesis is not that the rule eliminates supervision. Actual violations remain remediable, examiners can still issue observations, and materiality is tailored to each institution and even to individual products. It is that formal-signal scarcity raises the value of management-generated evidence. The rule may reduce supervisory noise; it also transfers more responsibility for detecting the risk before it becomes material.
Market context
MRAs sit between an examiner’s diagnosis and a bank’s operating agenda. They identify weaknesses serious enough to require management attention and remediation, frequently with board visibility. They can also generate substantial expense. In its impact analysis, the OCC cited hourly rates of $300 to $1,200 for top-tier consultants, $150 to $300 for lower-tier consultants and $250 to $550 for financial advisers used in response to MRAs or enforcement actions. Those figures describe vendor rates, not the full cost of remediation, which can include technology changes, data reconstruction, customer review and delayed product work.
The final rule creates the first regulatory definition used by these agencies for an unsafe or unsound practice. A practice, act or failure to act must be contrary to generally accepted standards of prudent operation and either be likely, if continued, to materially harm the institution’s financial condition, present a material risk of loss to the Deposit Insurance Fund, or have already caused material harm.
The MRA threshold is somewhat earlier-looking. Examiners may issue an MRA where an imprudent practice could reasonably be expected, under current or reasonably foreseeable conditions, to cause material financial harm or material DIF loss; where harm has already occurred; or where there is an actual violation of a banking or banking-related law or regulation. The agencies describe the new standard as narrower than prior practice while preserving the ability to identify risk before loss occurs.
The framework also creates two less forceful channels. A “supervisory observation” can identify a weakness that does not meet the MRA threshold, but it creates no requirement or supervisory expectation that the bank will correct it or present it to the board. An “other violation” remains subject to remediation, but the agencies generally cannot direct actions beyond remediation unless the law requires them.
The distinction is material for banks that distribute products through fintechs. The regulated institution remains responsible for the financial condition of the bank even when onboarding, transaction processing, customer service, fraud controls or data infrastructure sits partly with a partner. The rule does not lower the cost of an operational failure. It changes when an examiner can force the issue into a formal lane.
Exhibit 1: The new supervisory signal ladder
| Communication | Threshold in the final rule | Required response | Board signal |
|---|---|---|---|
| Unsafe or unsound practice | Imprudent conduct that is likely, if continued, to materially harm financial condition or create material DIF-loss risk; also includes material harm already caused | Enforcement or supervisory action may follow | High |
| Matter Requiring Attention | Imprudent conduct that could reasonably be expected under current or foreseeable conditions to cause material financial harm or material DIF-loss risk; material harm already caused; or an actual banking-law violation | Corrective action expected | Formal management and governance attention |
| Other violation | Actual banking or banking-related legal violation that does not lead to enforcement or an MRA | Remediation may be required; additional action only where law requires | Depends on the underlying violation and internal escalation |
| Supervisory observation | Weakness below the MRA threshold | No supervisory expectation of correction | No supervisory expectation that it reach the board |
Source: OCC/FDIC final rule, published September 1, 2026, effective November 2, 2026. Units: qualitative supervisory categories. Method: Blackrock Research mapping of the codified thresholds and required consequences. Limitation: institution-specific tailoring can lower the effective materiality threshold for riskier or more complex banks, business lines, products or services.
Findings
Finding 1
The rule reduces formal findings by design, but it does not reduce the underlying frequency of control weaknesses.
The agencies’ logic is resource allocation. Management and examiners should spend less time on policies, process and documentation that are not connected to material financial risk. In a well-run bank, that can improve the signal-to-noise ratio. A shorter list of consequential MRAs can command faster remediation and clearer accountability.
Yet a process weakness is often observable before its financial consequence is measurable. A partner’s reconciliation breaks may first appear as aged exceptions. A new fraud pattern may begin as a small rise in manual reviews. A model drift issue may show up in a segment that is immaterial to the whole bank. Under the new framework, the question is not simply whether the control failed. It is whether objective facts and sound reasoning connect that failure to material harm under reasonably foreseeable conditions.
That makes causal evidence a supervisory asset. Banks that can translate operational indicators into exposure, loss range, liquidity need or earnings sensitivity will be better able to prioritize remediation and to explain why a finding should or should not be formal. Banks that cannot make that translation may experience the worst combination: fewer external escalation signals and weak internal evidence.
The rule itself acknowledges this risk. The agencies say a narrowed MRA standard could delay identification of supervisory risks, raising resolution costs and, in extreme cases, contributing to failure. They judge that outcome unlikely because material risks remain in scope. That judgment is explicitly conditional on agency policy, oversight and management response. In other words, the rule’s success depends on how institutions behave after receiving more discretion.
Finding 2
Formal clarity will not produce numerical certainty.
The final rule requires examiners to use objective facts and sound reasoning and to share the basis for an unsafe-practice determination or MRA. That is valuable. It gives management a clearer record for remediation or appeal and should reduce findings based on unarticulated expectations.
But the agencies declined to require examiners to quantify probability or materiality. They concluded that a numerical burden would create false precision because forward loss estimates rely on subjective assumptions. The rule also uses different likelihood language: “likely” for unsafe or unsound practices and “could reasonably be expected” for MRAs. Those phrases create a hierarchy, not a calculator.
Materiality will move with context. The OCC’s summary says that as risks associated with capital structure, complexity, activities and asset size increase, the materiality threshold decreases, the assessment becomes more granular and remediation expectations increase. A control gap that is immaterial at the bank level can therefore be material within a fast-growing product or service.
For fintech partnerships, this undermines the temptation to define a universal MRA threshold. A fixed dollar-loss trigger can be too high for a concentrated program and too low for a diversified bank. The stronger design is a layered escalation model: absolute loss, loss relative to product revenue or capital allocation, customer count, velocity, recurrence, legal breach and the risk that a small defect can scale rapidly through automation.
Finding 3
The practical boundary will be what reaches the board.
The formal rule says a supervisory observation need not be presented to directors. That does not prevent management from escalating it. It removes the external expectation that it will do so. The distinction matters because boards allocate attention through a small number of recurring risk reports, committee agendas and remediation dashboards.
If every observation is promoted, the bank recreates the volume problem the rule is trying to solve. If none are promoted until they cross the MRA threshold, the board can learn about a pattern only after the exposure has grown. The operating answer is not a larger issue inventory. It is a conversion rule that identifies when observations become a portfolio signal.
Examples include repeated reconciliation defects across partners, several small fraud losses sharing the same control failure, customer complaints that indicate a legal violation, or a new product whose exception rate is rising faster than volume. Each event may be modest alone. Together they can show a practice that is becoming reasonably likely to affect earnings, liquidity or asset quality.
The scope of the rule makes this an industry-wide operating question rather than a niche legal change.
Exhibit 2: Scale, expected benefit and measurement limits
| Measure | Final-rule evidence | What it means |
|---|---|---|
| OCC-supervised institutions affected | 986 | All OCC institutions move to the new framework |
| FDIC-supervised institutions potentially affected | 2,700 | The rule changes examination communication across a large bank population |
| FDIC-supervised institutions classified as small | 1,978 | Community-bank governance and vendor capacity are central to implementation |
| Estimated annual examinations of small FDIC institutions | 1,319–1,978 | The communication standard will be used repeatedly, not only in rare enforcement cases |
| Top-tier consultant rates cited by OCC | $300–$1,200 per hour | Fewer formal findings can release meaningful remediation budget |
| Quantified agency estimate of total benefit | Not available | The direction of savings is an agency expectation, not a measured outcome |
Source: OCC/FDIC final rule impact analysis. Institution counts are as of March 31, 2026 for FDIC data and July 29, 2026 for OCC data; consultant rates are examples cited in the rule. Units: institutions, examinations per year and dollars per hour. Method: direct transcription; no aggregation. Limitations: OCC and FDIC populations can involve different charters and supervision scopes and should not be summed as a unique-bank count without reconciliation. Rates exclude internal labor, technology, restitution and opportunity cost. The agencies state that they lack information to quantify potential benefits.
Implications for operators
Banks should redesign issue governance around evidence rather than labels. Every material product and partner needs leading indicators tied to financial consequences: unresolved exceptions, unauthorized transaction loss, false-decline cost, concentration, settlement exposure, complaint recurrence, access failures, model overrides and time to remediation. The dashboard should show both current loss and the mechanism by which a small failure could scale.
Boards should approve an escalation rule for supervisory observations and internally discovered weaknesses. Escalation should consider recurrence, common cause, growth rate, affected customers, legal status and exposure relative to the product, not only the bank. A quarterly summary should identify observations that remain below MRA materiality but are converging on the same control domain.
Fintech partnership teams should not market the rule as permission to relax diligence. Banks may have fewer examiner-driven process findings, which makes partner evidence more important during onboarding and monitoring. Contracts should preserve access to event-level data, audit rights, remediation milestones and the ability to pause volume when indicators deteriorate. A partner that reports only aggregate service levels cannot help the bank establish whether foreseeable material harm is developing.
Risk and finance teams should build a shared materiality model. The rule anchors harm in capital, asset quality, earnings, liquidity and sensitivity to market risk. Operational metrics should map to those outcomes through explicit assumptions. The purpose is not to manufacture false precision. It is to make the reasoning testable, versioned and reviewable.
Finally, management should track whether the new regime actually improves allocation. Useful measures include MRA count and closure time, consultant spend, aged observations, repeat findings, losses originating in previously informal observations, and the share of remediation capacity directed to top financial risks. A falling MRA count is not, by itself, evidence of safer banking or more efficient supervision.
Risks & open questions
The thesis would be wrong if fewer MRAs consistently shorten remediation queues without increasing losses, repeat observations or delayed escalations. It would also weaken if examiner observations remain highly visible to boards in practice despite the rule’s formal language, or if institutions already operate mature internal systems that make the external label largely irrelevant.
There is also an agency boundary. The Federal Reserve did not join this final rule and, as Reuters reported, had not issued its own equivalent proposal at the time of publication. Banking groups with multiple charters may therefore face different supervisory frameworks across entities. State supervisors can add another layer.
Legal durability is an open question. The rule formalizes a contested interpretation of supervisory authority, and critics argue that it could constrain early intervention. The agencies’ own impact analysis cannot quantify either the compliance savings or the probability of delayed risk identification. This is a policy experiment with observable outcomes, not a settled efficiency gain.
Three data points should decide the argument over the next two examination cycles: whether MRA volume falls; whether aged and repeated observations rise; and whether loss events can be traced to issues that remained informal. Without that record, supporters and critics will be comparing intentions rather than performance.
Appendix / methodology notes
This report reviewed the joint OCC/FDIC final rule published in the Federal Register on September 1, 2026; the OCC bulletin and joint agency release dated August 27; the agencies’ impact analysis; and contemporaneous Reuters coverage. It distinguishes codified requirements from Blackrock Research inference.
Exhibit 1 is a functional mapping of the final rule’s four communication categories. Exhibit 2 transcribes agency counts, examination estimates and example consultant rates. It does not combine OCC and FDIC institution counts because charters and supervisory populations require reconciliation. It does not estimate compliance savings because the agencies state that the necessary information is unavailable.
The report treats a bank’s internal telemetry as the set of operational, customer, compliance and financial indicators used to identify and escalate risk before or outside a formal examiner finding. The recommended metrics are management tools, not regulatory thresholds. Nothing in this report is legal advice.