OCC Tightens Bank Supervision With Public MRA Manual and Technical Violation Rule

Daily Feed
OCC Tightens Bank Supervision With Public MRA Manual and Technical Violation Rule

The Office of the Comptroller of the Currency is drawing a harder line between real banking risk and bureaucratic busywork. On Aug. 27, the OCC [revised its supervision and enforcement manuals](https://crypto.news/?p=14480372), publicly released its Matters Requiring Attention handbook for the first time, and proposed a rule that would split violations into “substantive” and “technical” categories.

  • Risk first: focus shifts to material financial harm
  • MRA manual public: more transparency, less guesswork
  • Two violation buckets: substantive vs. technical
  • Crypto banks included: no special exemption, no new powers

The message is blunt: stop treating every paperwork flaw like a systemic threat. The OCC says examiners should focus on material financial risk, meaningful legal violations, and corrective actions that are proportionate to the problem. In other words, if a bank has a real control failure, hit it. If it is just a minor procedural hiccup, maybe don’t act like the sky is falling.

That sounds sensible because, frankly, supervision can get stupid when regulators confuse perfection with safety. But there is a catch: if “technical” problems are waved away too easily, banks can collect small compliance failures until they turn into a much bigger mess. Banking has a way of turning little sins into expensive disasters.

What the OCC changed

The OCC’s August 27 update includes two revised policy manuals and a joint final rule with the Federal Deposit Insurance Corporation regarding unsafe or unsound practices and [Matters Requiring Attention for Violations of Laws and](https://www.occ.gov/news-issuances/bulletins/2026/bulletin-2026-42.html). For the first time, the OCC also made its MRA manual public.

An MRA is a supervisory directive telling a bank’s board and management to correct a deficient practice. It is not usually a public enforcement action, but it can still bite hard inside a bank because it puts management on a formal clock to fix the problem.

The revised enforcement manual rests on three principles: escalation, tailoring, and limiting corrective actions to what is needed to resolve the specific deficiency. The OCC also says enforcement responses should be proportionate and predictable.

That is a clear move away from one-size-fits-all supervision. The agency is signaling that examiners should not pile on unrelated remediation or use the same hammer for every nail.

Substantive vs. technical violations

The biggest policy change is the proposed rule dividing banking law violations into two categories: substantive and technical. Comments are due 30 days after the proposal is published in the Federal Register.

According to the OCC, a violation is substantive when its nature, duration, frequency, or severity could meaningfully affect the bank or its customers. At least one of five criteria must apply:

  • systemic patterns
  • more-than-minimal financial effects
  • inaccurate books and records
  • customer harm or restitution
  • insider misconduct or self-dealing

A technical violation is a breach that does not rise to that level. The OCC says those violations would not be treated as the basis for an enforcement action or an MRA, though they still need to be corrected.

That distinction matters because banking supervision often gets tangled in its own shoelaces. A bank should not be treated like it set the building on fire because an examiner found a procedural defect that caused no meaningful harm. At the same time, regulators are right to worry that repeated “minor” problems can become the kind of sloppy culture that eventually wrecks a balance sheet.

Size and complexity still matter

The OCC is also making a point that gets lost in lazy headline reading: context matters. The same practice can draw a different supervisory response depending on whether it shows up at a community bank or at a large, complex institution.

That is not special pleading. It is how risk-based supervision is supposed to work. A weak process at a small local bank may be annoying; the same weakness at a sprawling institution with more counterparties, more exposure, and more moving parts can have a much bigger blast radius.

Comptroller Jonathan Gould described the changes as a return to “risk-based supervision.”

Jonathan Gould described the changes as a return to “risk-based supervision.”

That framing matters because it suggests the OCC wants supervisors to be more deliberate, not merely more lenient. The regulator is not saying “ignore problems.” It is saying “focus on the ones that actually matter.”

Why public MRAs matter

Making the MRA manual public is a meaningful transparency shift. Banks, compliance teams, and outside observers no longer have to infer the rules from examiner behavior alone.

That should reduce some of the fog that has long surrounded supervision. When expectations are unclear, banks waste time trying to read the regulator’s mind instead of fixing actual risk. A public manual does not eliminate judgment calls, but it gives institutions a better sense of where the line is supposed to be.

The OCC appears to be responding to a familiar complaint from the banking world: too often, examiners treat documentation flaws, internal process issues, and paperwork defects as if they were proof of deep systemic failure. Sometimes they are. Often, they are not.

This revised framework tries to separate the two.

What it means for crypto-related banks

The changes apply to all OCC-supervised national banks, federal savings associations, and federal branches. That includes federally supervised institutions involved in digital assets, including trust banks.

And no, this does not hand banks new crypto powers. The OCC did not suddenly hand out a blank check for every blockchain fever dream with a pitch deck and a prayer. Core requirements around capital, liquidity, cybersecurity, sanctions, anti-money-laundering controls, and consumer protection still apply.

That said, the practical effect could still matter a lot for crypto-adjacent institutions. Banks dealing with custody, records, settlement, vendor oversight, or reserve management live and die by operational precision. Those are exactly the kinds of areas where sloppy documentation or control failures can turn into supervisory pain.

A more disciplined MRA framework may help legitimate institutions avoid being buried under overreach for issues that are annoying but not existential. But it does not shield anyone from serious mistakes. If the books are wrong, customers are harmed, or insiders are self-dealing, the OCC is still going to care. A lot.

The upside and the risk

The upside is obvious: clearer standards, less arbitrary escalation, and less time wasted on minor defects that do not threaten safety and soundness. That is good for banks that want to focus on actual risk instead of compliance theater.

The risk is also obvious: if examiners are too cautious about calling something “substantive, ” important problems could sit around longer than they should. The line between a harmless technical violation and the beginning of a real compliance failure is not always neat. In practice, the difference may depend on repetition, context, and whether a problem starts causing real harm.

That is where the human factor stays in the system. The OCC may be narrowing the rules, but it is not replacing judgment with software. Examiners still have to decide whether a problem is serious enough to escalate. That will make consistency the real test.

Key questions and takeaways

  • What did the OCC change?
    It revised its supervision and enforcement manuals, made its MRA manual public, and proposed a rule that separates violations into substantive and technical categories.

  • Why does this matter?
    The OCC is trying to push bank supervision toward material risk and meaningful legal violations instead of minor procedural defects that do not create real harm.

  • What is an MRA?
    A Matter Requiring Attention is a supervisory directive that tells a bank’s board and management to fix a deficient practice.

  • What counts as a substantive violation?
    A violation whose nature, duration, frequency, or severity could meaningfully affect the bank or its customers, including issues tied to records, customer harm, insider misconduct, or material financial effects.

  • Do technical violations disappear?
    No. They still need to be corrected, but the OCC says they should not be the basis for an enforcement action or an MRA.

  • Does this help crypto banks?
    Potentially, especially where the issue is operational or procedural rather than truly risky. But it does not create new crypto permissions or lower core banking standards.

  • Will the OCC still crack down on real problems?
    Yes. The framework still leaves room for strong action where there is customer harm, inaccurate books and records, insider abuse, or more-than-minimal financial risk.

The smart read here is not that the OCC is going soft. It is that the agency wants to be sharper, more consistent, and less random. That is good for banks that take risk seriously and bad news for institutions that hide behind compliance theater.

If the OCC applies this framework consistently, it could cut through a lot of supervisory fog. If it does not, it becomes just another policy memo with fresh language and the same old examiner mood swings. Banking oversight has a talent for turning noble intentions into paperwork sludge, so execution will matter more than the press release.

Further reading

A few related OCC and crypto-banking angles worth keeping on the radar:

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog