The Office of the Comptroller of the Currency (OCC) announced a major recalibration of its bank supervision and enforcement approach on Aug. 27 — a shift that could materially affect how crypto-focused banks are examined and disciplined. What changed - The OCC issued two updated policy manuals and a joint final rule with the Federal Deposit Insurance Corporation (FDIC). These manuals set current OCC supervisory policy. Separately, the OCC proposed a rule that would formally divide violations of banking law into “substantive” and “technical” categories — but that legal-violation framework is still a proposal and not yet binding until the formal federal rulemaking process concludes. - The updated enforcement manual centers on three principles: escalate responses when warranted, tailor actions to the specific deficiency, and limit corrective measures to what’s needed to resolve that deficiency. Enforcement should be proportionate and predictable, with examiners weighing the financial risk, the nature of any legal violation, and the institution’s size and complexity when deciding on formal action. Return to risk-based supervision - Comptroller Jonathan Gould characterized the changes as a return to “risk-based supervision.” In practice, OCC guidance makes clear that not all banks will be treated the same: the same practice at a large, complex institution could trigger enforcement while a community bank might not face action for similar conduct. Larger institutions face higher supervisory expectations because their failures can pose broader financial risk, but examiners must still tie any response to a specific deficiency. MRAs and a new public manual - Matters Requiring Attention (MRAs) — supervisory directives that require a bank’s board and management to fix deficiencies — were addressed directly. For the first time the OCC publicly released a dedicated MRA manual, instructing examiners to tailor MRAs based on financial risk and limiting MRAs to conduct that meets the new standard. MRAs are generally not public enforcement orders. The joint OCC-FDIC rule and the proposed violation framework - The joint final rule defines “unsafe or unsound” practices as conduct creating material financial risk and revises when supervisors may issue MRAs related to safety, soundness and legal compliance. The stated intent is to reduce MRAs driven primarily by policies, paperwork or process shortcomings that do not create material financial risk — while preserving the ability to act when weak controls cause real harm or legal violations. - Under the OCC’s proposed framework, a legal or regulatory breach would support an MRA or enforcement only if it’s “substantive.” A violation would be deemed substantive if its nature, duration, frequency or severity could meaningfully affect the bank or its customers — i.e., at least one of these five criteria applies: 1. Patterns or systemic problems. 2. More-than-minimal financial impact. 3. Inaccurate books, records or financial reporting. 4. Customer harm or need for restitution. 5. Insider misconduct or self-dealing. - “Technical” violations — isolated paperwork issues or minor process errors that don’t meet those thresholds — would not by themselves support an enforcement action or an MRA. Examiners could require correction, but could not prescribe the method or demand broad unrelated remediation. Technical violations still must be corrected and banks remain legally obligated to comply with applicable laws. Timeline and scope - Comments on the proposed legal-violation framework will be accepted for 30 days after the rule is published in the Federal Register. At the time of the OCC announcement there was no fixed calendar deadline because the publication date had not been set. - The changes apply to all OCC-supervised national banks, federal savings associations and federal branches — explicitly including federally supervised trust banks engaged in digital-asset custody, stablecoin reserve management or blockchain settlement. What this means for crypto banks - The new supervisory posture does not grant banks new crypto powers, nor does it roll back requirements on capital, liquidity, cybersecurity, sanctions, anti-money-laundering controls or consumer protection. Its significance is procedural and classificatory: examiners will have clearer guardrails to treat minor documentation or process issues as “technical,” while serious custody failures, inaccurate records, customer losses or systemic compliance breakdowns will remain substantive and subject to enforcement. - The OCC has already restored permitted digital-asset banking activities to standard supervisory channels after removing several special restrictions and reputation-risk references. At the same time, the agency continues to oversee digital-asset activity closely: Circle recently received final approval to form a federally supervised digital-asset trust bank, and other crypto firms remain in the pipeline with conditional charter applications. Stakeholder input - Banks, industry groups and consumer advocates are invited to comment on whether distinguishing substantive from technical violations will produce useful consistency or instead unduly limit supervisory intervention. Bottom line This update signals a more risk-focused, calibrated OCC approach to supervision that could reduce enforcement for trivial compliance defects while preserving the authority to act against conduct that poses meaningful financial or customer harm — an important shift for banks and crypto firms navigating federal oversight. Read more AI-generated news on: undefined/news
