Breaking Regulatory Compliance
The OCC's New Two-Tier Violation Framework: What 'Substantive vs. Technical' Means for Your Compliance Program
OCC Bulletin 2026-42, published September 1, proposes for the first time a formal distinction between 'substantive' and 'technical' violations of banking law — with MRAs limited to substantive violations only. Comment deadline is October 1.
Table of Contents
TL;DR
- On September 1, 2026, the OCC proposed a first-ever formal distinction between “substantive” and “technical” violations of banking law — with MRAs reserved exclusively for substantive violations
- A violation is substantive if it meets one of five criteria: systemic pattern, more-than-minimal financial impact, bad books and records, consumer harm, or insider misconduct
- Technical violations must be corrected but cannot generate MRAs or examiner-prescribed remediation
- The comment deadline is October 1, 2026 — less than four weeks out
- This NPRM runs parallel to, but is separate from, the OCC/FDIC final rule on unsafe/unsound practices (OCC Bulletin 2026-40)
Eight days after the OCC and FDIC finalized the first-ever statutory definition of “unsafe or unsound practice”, the OCC published a second piece of its supervisory reform package — this one aimed at a question the final rule didn’t answer.
The final rule addressed unsafe or unsound practices. But what about violations of actual laws and regulations? When an examiner finds a BSA violation, a fair lending gap, or an OFAC screening miss — does every one of those findings generate an MRA? Under the current framework, the answer is essentially yes, subject to examiner discretion. Under the proposed rule published in OCC Bulletin 2026-42 on September 1, the answer becomes: it depends on whether the violation is “substantive” or “technical.”
The comment deadline is October 1. That’s a short window for a proposed rule that will meaningfully change how examiners communicate legal violations to the banks they supervise.
What the NPRM Actually Proposes
OCC Bulletin 2026-42 proposes to amend the OCC’s regulatory framework for how it issues MRAs in response to violations of banking or banking-related laws and regulations. At the core is a simple binary: every violation the OCC identifies will be classified as either “substantive” or “technical.”
Substantive violations trigger MRAs. They get the full weight of the formal supervisory finding process — documented in examination reports, tracked for remediation, potentially escalated to enforcement action if not addressed.
Technical violations do not trigger MRAs. The OCC can require correction, but under the proposal, it cannot prescribe how the bank must correct the violation, and it cannot require remediation steps unrelated to the correction itself. The examiner documents the finding, but the bank retains meaningful discretion over how to respond.
This matters because MRAs carry mandatory corrective action requirements and appear in examination reports that bank partners, auditors, and counterparties can request. Technical violations, by contrast, would be a lower-pressure supervisory communication — more like the “supervisory observation” category created by the companion final rule for non-law-violation findings.
The Five-Category Substantive Test
The heart of the proposed rule is its definition of when a violation crosses from technical to substantive. The general standard is whether the violation’s “nature, duration, frequency, or severity could meaningfully impact the bank or its customers.” That’s broad — intentionally so. But the rule backs it up with five specific categories. A violation is substantive if any one of the following applies:
1. Systemic pattern. The violation reflects a pattern across multiple incidents or transactions, as opposed to a one-off error. A single SAR filing miss during a system outage looks different from a monitoring program that systematically fails to flag a category of transactions. Examiners have always distinguished these informally; the NPRM proposes to codify the distinction.
2. More-than-minimal financial effect. The violation had a material financial impact on the bank or its customers — losses, overcharges, missed payments, or economic harm that exceeded a de minimis threshold. The rule does not define “minimal” quantitatively, which is one area where commenters may want to push for more precision.
3. Inaccurate or unreliable books and records. The violation corrupted the bank’s financial records or reporting — CALL Report errors, ledger inaccuracies, regulatory filing misstatements. This is a bright line: if the violation touched the integrity of the institution’s books, it’s substantive.
4. Consumer harm or restitution required. The violation caused identifiable harm to consumers, requiring restitution or remediation payments. This includes fair lending violations resulting in adverse action on protected-class borrowers, fee overcharges requiring customer credits, or UDAAP-grounded conduct resulting in consumer losses.
5. Insider misconduct or self-dealing. The violation involved an officer, director, or employee acting in their own interest at the bank’s or customers’ expense. This is the classic supervisory bright line — any time misconduct or self-dealing is involved, the finding is substantive by definition.
If a violation doesn’t meet any of the five criteria, it’s technical. The examiner can require correction but cannot escalate it to MRA status.
What This Changes for BSA/AML and OFAC Programs
The banking law areas where these categories will matter most are BSA/AML and OFAC — precisely the areas where compliance teams often face examination findings that look serious in isolation but represent discrete, correctable gaps rather than systemic program failures.
Under the current framework, an examiner who identifies a CTR filing error or an OFAC hit that was resolved but not escalated through the right internal channels can issue an MRA based largely on their judgment. Under the proposed rule, they would need to assess whether the violation meets one of the five categories before doing so.
An isolated CTR error with no pattern, no customer harm, and no books/records impact would likely be a technical violation — correctable without an MRA. A monitoring program that missed a category of high-risk transactions for six months, producing dozens of unfiled SARs, would almost certainly be substantive under the systemic pattern and potentially the consumer harm categories.
This distinction is already embedded in how sophisticated compliance teams evaluate their own programs. The NPRM proposes to make it the formal examiner standard — and that’s a significant shift from the consent order anatomy we’ve mapped before.
What “Technical Violation” Actually Means for Your Operations
One of the most practically important aspects of the proposed rule is what happens after a technical violation is identified. The OCC can require the bank to correct it. But the rule explicitly limits the examiner’s authority in two ways:
First, the examiner cannot prescribe how the bank corrects the violation. If a system error caused a handful of incorrect CALL Report fields, the examiner can require correction — but cannot mandate a specific technology change, a vendor replacement, or a management restructuring as the remedy.
Second, the examiner cannot impose remediation steps unrelated to correction of the violation. This is a meaningful constraint. Under the current informal framework, an examiner who finds a technical error sometimes uses it as an entry point to require broader compliance program enhancements that go beyond what the specific violation required. The proposed rule would prohibit that: the remediation must be proportionate to the actual violation.
For compliance teams, this means that documenting your own analysis of violation severity — before the examination communication — will become more important. If your internal assessment characterizes a finding as technical and the examiner disagrees, having a documented rationale will matter.
The OCC Also Proposed to Limit Its Own BSA Lookback
One detail buried in the broader reform package that connects directly to the violations framework: the OCC’s revised Policies and Procedures Manual (OCC Bulletin 2026-41, also published September 1) includes a new limit on examiner lookback periods for suspicious activity reporting. For SAR-related findings, examiners generally face a one-year lookback cap.
This matters for the substantive/technical analysis because the “systemic pattern” category depends partly on duration. A BSA monitoring gap that persisted for 18 months looks different under a framework that caps examiner review at 12 months. Compliance programs should maintain contemporaneous records of SAR decisions — including documented decisions not to file — specifically because examiner review of past decisions remains meaningful within the lookback window.
Why the Comment Deadline Matters
The October 1 comment deadline is unusually short for an NPRM with this scope. Four weeks from Federal Register publication to comment close is compressed, and it’s worth asking why.
The OCC has signaled that the violations framework is intended to accompany the final rule that took effect August 27. Finalizing this rule quickly — by Q1 2027 — would complete the supervisory reform package the OCC has been building since 2025. Industry associations, law firms, and compliance trade groups should be preparing comments now.
For individual institutions, the more useful response is internal: use the comment period as a forcing function to audit your issues management program against the five-category substantive test. Where do your open BSA, OFAC, fair lending, and consumer compliance findings fall on that spectrum? What would the examiner classify as substantive versus technical? If you can’t answer that question confidently, your issues log needs to be retooled.
So What Does This Mean for Your Compliance Program?
The OCC’s proposed violation framework is part of a consistent pattern: the agency is moving from a check-the-box, documentation-driven supervision model toward a risk-based model focused on material findings. The final rule defined “unsafe or unsound” for the first time in 70 years. This NPRM proposes to apply the same materiality logic to legal violations.
For compliance programs built around the assumption that any identified violation generates an MRA, the framework requires recalibration. You still need to find, document, and remediate every violation — technical or substantive. What changes is the supervisory weight each finding carries, and the examiner’s authority to prescribe your remedy.
Three things your compliance function should do before October 1:
1. Map your open issues against the five categories. Go through every open compliance finding and ask: which of the five criteria would this meet? If the answer is “none,” it’s probably a technical violation under the proposed rule. That’s useful information for your risk committee and your examiner relationship.
2. Review your issues management escalation criteria. If your current escalation framework treats every legal violation as an MRA-equivalent, you need to update it. The proposed rule does not eliminate the compliance obligation — it changes the examiner communication and remediation authority. Your internal escalation should track the proposed standard so that it’s defensible if an examiner challenges your characterization.
3. Consider commenting. If the five-category list creates ambiguity for your regulatory footprint — particularly around BSA/AML pattern violations, OFAC screening errors, or fair lending disparities — the comment period is your opportunity to shape the final rule. Comments that offer specific, operationally grounded scenarios are far more useful than general objections.
The Issues Management Tracker is built to track this kind of nuanced severity categorization — with severity tiers, root cause classification, and escalation tracking across source types. If you’re rebuilding your issues log in anticipation of the new framework, it gives you a pre-built structure to start from.
Sources:
- OCC Bulletin 2026-42: Matters Requiring Attention for Violations of Laws and Regulations (NPRM)
- Federal Register: Violations of Laws or Regulations (September 1, 2026)
- OCC News Release: OCC Acts to Improve Transparency and Consistency to Bank Enforcement and Supervisory Standards
- ACAMS: OCC Proposal Targets Systemic BSA, OFAC Violations for MRAs
- Cooley Insights: FDIC, OCC Redefine ‘Unsafe or Unsound Practices’ and Raise Bar for MRAs
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is OCC Bulletin 2026-42 and how does it differ from the final rule published the same day?
What makes a violation 'substantive' under the proposed rule?
What is a 'technical violation' and what happens when an examiner finds one?
Does this proposal apply to the FDIC and Federal Reserve?
When is the comment deadline and how should compliance teams approach it?
How should my issues management program adapt in anticipation of this rule?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
● Don't wait for your own enforcement action
Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Regulatory Compliance
SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test
The SEC's Doximity insider trading judgment exposes two MNPI control tests: earnings access and post-termination trading.
Sep 11, 2026
Regulatory Compliance
FinCEN Health Care Fraud Analysis: $17.5 Billion in Suspicious Activity
FinCEN's health care fraud analysis reveals $17.5B in suspicious activity. Here is how BSA teams should update monitoring and SAR controls.
Sep 10, 2026
Regulatory Compliance
The CFPB Eliminated Federal Disparate Impact. Illinois Made It State Law. What Lenders with Illinois Customers Must Do Before January 2027.
Illinois enacted SB 3777 on July 31, 2026, creating an independent state-law disparate impact standard for credit decisions under the Illinois Human Rights Act — effective January 1, 2027. The federal government moved in exactly the opposite direction three months earlier. Lenders using AI or algorithmic underwriting need to understand what changed and what it requires.
Sep 9, 2026