
OCC Splits Bank Violations Into 'Substantive'
A revised enforcement manual and a new rulemaking proposal recalibrate how the Office of the Comptroller of the Currency escalates bank violations — tightening scrutiny on large, complex institutions while giving technical infractions a route around the Matters Requiring Attention process entirely.
The Office of the Comptroller of the Currency, under Comptroller Jonathan V. Gould, revised its bank-enforcement manuals on Aug. 27, 2026, and proposed splitting rule violations into 'substantive' and 'technical' tiers — freeing technical infractions from the Matters Requiring Attention process while reserving escalated enforcement for material risk at large, complex banks.
The Ledger Desk · 4 min read- The OCC revised PPM 5310-3 (bank enforcement actions) and, for the first time, publicly released PPM 5400-11 (Matters Requiring Attention), both dated Aug. 27, 2026.
- A companion proposed rule would split violations into 'substantive' and 'technical' categories, letting technical violations be resolved outside the formal MRA process.
- Escalated enforcement is now explicitly reserved for large or complex banks; the same conduct at a community bank may not trigger the same response.
- The changes follow a joint OCC-FDIC final rule that redefines 'unsafe or unsound practice' around material financial risk rather than process deficiencies.
- The violations NPRM's comment period runs 30 days from Federal Register publication, so the category definitions are not yet final.
The Office of the Comptroller of the Currency revised its core bank-enforcement manuals on Aug. 27, 2026, and proposed splitting rule violations into 'substantive' and 'technical' tiers, per OCC News Release 2026-72. Comptroller Jonathan V. Gould framed the package as a 'return to risk-based supervision,' moving away from 'check-the-box compliance.' The practical effect: technical violations would no longer automatically route through the Matters Requiring Attention process, while enforcement tightens for large, complex banks.
What the OCC announced
On Aug. 27, 2026, the OCC issued a revised Policies and Procedures Manual 5310-3 governing bank enforcement actions and, for the first time, released PPM 5400-11 on Matters Requiring Attention publicly, per OCC News Release 2026-72. Alongside the manuals, the agency proposed amendments to its Violations of Laws and Regulations framework. Comptroller Jonathan V. Gould framed the package as codifying the OCC's 'return to risk-based supervision,' explicitly moving away from what he called 'check-the-box compliance.'
A new fork in how violations get classified
The proposed rule would split violations into two categories — 'substantive' and 'technical' — and route only substantive violations through the formal MRA process, per the OCC's release. Technical violations, by design, would no longer require the same escalation path. That is a structural change, not a wording tweak: MRA issuance and clearance have long functioned as the OCC's primary countable unit of supervisory pressure on a bank.
Enforcement now explicitly tiers by bank size
Revised PPM 5310-3 permits escalated enforcement against large or complex banks for practices that would not trigger action against a community bank, according to the OCC. Reported by PYMNTS, this formalizes a size-based enforcement gradient rather than a single national standard. Institutions scaling quickly toward that 'large or complex' threshold — including bank-fintech partnership structures — face a materially higher enforcement bar than their charter size alone might suggest.
The compliance-metrics gap this creates
Bank compliance functions commonly use MRA count and aging as an internal proxy for supervisory risk exposure. If technical violations are resolved outside the MRA process going forward, that proxy stops measuring what it used to measure — a bank's MRA count could fall without its underlying material-risk exposure changing at all. Compliance teams that have not yet rebuilt their internal risk dashboards around the substantive/technical distinction are tracking a metric the OCC itself is in the process of redefining.
What happens next
The Violations of Laws and Regulations proposal is a Notice of Proposed Rulemaking, not a final rule: the comment period runs 30 days from Federal Register publication, per the OCC. The PPM revisions themselves implement a separate, already-final joint OCC-FDIC rule redefining 'unsafe or unsound practice' around material financial risk, which FDIC Chairman Travis Hill said shifts examiner attention 'towards underlying fundamental risks and away from banks' processes for managing those risks.'
- What did the OCC actually change on Aug. 27, 2026?
- It revised Policies and Procedures Manual 5310-3 governing bank enforcement actions, published PPM 5400-11 on Matters Requiring Attention publicly for the first time, and proposed a rule splitting violations of law into 'substantive' and 'technical' categories, per OCC News Release 2026-72.
- Why does the substantive/technical split matter for a bank's compliance function?
- Under the proposal, only substantive violations need route through the formal MRA process; technical violations can be addressed outside it. That changes what MRA counts and timelines actually measure inside a bank's own risk-reporting.
- Does the stricter standard apply to every OCC-supervised bank?
- No. PPM 5310-3 explicitly permits escalated enforcement for practices at large or complex banks that would not trigger action against a community bank, formalizing a size-tiered standard rather than a uniform one.
- Is this OCC acting alone?
- No. The PPM revisions implement a joint OCC-FDIC final rule that redefines 'unsafe or unsound practice' to prioritize material financial risk over process failures, with FDIC Chairman Travis Hill describing the same shift in the FDIC's own statement.
- OCC Rewrites Enforcement Playbook to Focus on Big Bank Risks — PYMNTS
- OCC Enforcement and Supervisory Standards Update (News Release 2026-72) — Office of the Comptroller of the Currency