Regulatory Analysis

Supervision just moved the goalposts. Model and AI risk fell outside them.

The OCC and FDIC have redrawn bank supervision around material financial harm. Read with SR 26-2, four separate routes to a supervisory finding on AI now miss.

The shifts

Five changes — and the gap each one leaves you

  1. Harm is now financial, and defined.

    Capital, asset quality, earnings, liquidity, sensitivity to market risk. Reputational risk unrelated to financial condition is expressly out.

    Your gapConduct, customer and trust exposures that never touch the balance sheet have lost their supervisory owner.

  2. Process findings lost their teeth.

    Weak policy and documentation now land as a supervisory observation — no corrective action, no board presentation, and the examiner may not track your response or escalate because you declined.

    Your gapYour control environment loses its external reviewer. The board becomes the only one validating it — but the same facts still drive your ratings.

  3. Tailoring cuts both ways.

    As risk rises the materiality threshold falls, harm is assessed at business-line level, and expectations increase. For large banks this is not deregulation.

    Your gapEnterprise-level materiality thresholds will systematically understate what your examiner now treats as material.

  4. SR 26-2 shrank the model perimeter.

    A complexity test, a $30bn relevance threshold, and generative and agentic AI placed expressly outside scope.

    Your gapA GenAI deployment can miss all four routes to a supervisory finding — SR 26-2 scope, the MRA standard, the violation prong, and the unsafe-or-unsound test. Deterministic rules and spreadsheets leave the model inventory without entering anything else.

  5. The OCC and FDIC aligned. The Fed did not.

    The final rule amends OCC and FDIC regulations only.

    Your gapIn a multi-charter group, policy written to one standard will not satisfy the other — and findings get misclassified at the margin.

Side by side

What changed, for the examiner and for you

AreaFor the examinerFor the bank
Unsafe or unsound practiceNow defined by regulation: imprudence plus likely material financial harm or DIF riskA far higher bar for formal action — and a defined standard you can hold examiners to
MRAsOnly for imprudence plus reasonably expected material harm, or a substantive violation of lawFewer MRAs; open process-only findings are candidates for closure or downgrade
Process & documentationDemoted to supervisory observations; may not be tracked or escalated for non-adoptionNothing required — but the underlying facts can still drive your ratings
Violations of lawSplit into substantive (five categories) and technical, where the OCC may direct correction but not howBSA/AML, OFAC, Reg W, Reg O, Call Report accuracy and customer impact stay firmly in scope
Model risk
SR 11-7 → SR 26-2
Narrower model definition, materiality tiering, flexible validation cadence, $30bn thresholdSmaller inventory in scope — and a larger population of tools governed by nothing in particular
And the trap

PPM 5310-3 keeps a 12 CFR 30 notice of deficiency available for large or complex banks with serious internal control or risk management deficiencies that do not meet the MRA standard or constitute unsafe or unsound practices — precisely the findings the reform appears to demote. This is not an amnesty on control weakness.

Where to start

One thing to do, whoever you are

  • Community & small banksDrop the controls you copied from bigger banks. Validation cadences, committee structures and documentation standards borrowed from a $100B peer are no longer defensible as prudent operation at your size — and peer practice is expressly not the standard.
  • Regional & midsizeMove your issue taxonomy from two states (MRA or not) to four rungs — supervisory observation, technical violation, MRA, enforcement action — each with its own routing, ownership and board treatment. Then map it against both the OCC/FDIC and the CFPB.
  • Large & systemically importantRe-triage the open MRA population now, before the first examination cycle sets precedent.
  • Fintechs & BaaS partnersRewrite the bank-partner evidence pack around the five substantive violation categories.
  • EveryoneShift the evidence model from “we followed the process” to “this was prudent, on objective facts.” Those are different burdens, and most functions are built for the first.

Sources. OCC News Release 2026-72 and OCC/FDIC IA-2026-71 (27 August 2026); interagency final rule Unsafe or Unsound Practices, Matters Requiring Attention (12 CFR 4.92, 12 CFR part 305); OCC PPM 5310-3 and PPM 5400-11; OCC NPRM Violations of Laws or Regulations(Docket OCC-2026-0529); SR 26-2 (17 April 2026). Full citations in the whitepaper.

Provided for general information; not legal advice. AI Risk Consulting LLC is not a law firm. The violations rulemaking is a proposal and may change or may not be finalised.

Engage us

Put this to work

Re-baselining an issue inventory against the new standard. Rebuilding the evidence model around prudent operation rather than process. Setting the internal AI standard now the external one has narrowed. That is the work we do.

Talk to us
Shape the research

What should we look at next?

We write about what practitioners are actually deciding. If there is a supervisory question you are working through and nobody has written the piece you need, tell us and we will dig into it.

Suggest a topic
New research and practitioner notes as they publish.Follow us on LinkedIn