MARKETS, CREDIT & POLICYAbout & methodology
c.The Credit CurrentDAILY INTELLIGENCEWhat matters in Credit
← All topics
TOPIC GUIDE

Policy & supervision

Laws, rulemaking, supervisory cases and governance.

Latest news

Fraud exposure is associated with payment stress and lost credit demand

Bank Policy Institute analysis of the CFPB Making Ends Meet Survey finds that people reporting fraud or scams were about 15 percentage points more likely to expect difficulty paying bills, nearly 7 points more likely to expect lower credit-card repayment, and about 13 points more likely to consider but abandon a credit application.

Published: Sep 27, 2026

Curtis backs proposed protections for AI whistleblowers

Utah Senator John Curtis announced his support for the bipartisan AI Whistleblower Protection Act. His office says the proposal would protect covered disclosures involving federal-law violations, national security or public safety, prohibit retaliation and prevent nondisclosure agreements from blocking protected reports.

Published: Sep 27, 2026

Sunwest takes on Nano Banc deposits after California closure

California closed Irvine-based Nano Banc on September 25 and appointed the FDIC as receiver. Sandy, Utah-based Sunwest Bank agreed to assume substantially all deposits and purchase selected assets. Sunwest says customer access continues and the branch is scheduled to reopen under its name September 28.

Published: Sep 27, 2026

OCC updates cyber examination mapping without new procedures

The OCC’s September 21 cybersecurity bulletin updates the structure and references of its examiner work program to align with the evolving NIST framework. The agency explicitly says examination procedures are unchanged and no new regulatory expectations are created.

Published: Sep 27, 2026

Proposed third-party guidance puts risk differentiation in focus

A September 11 interagency proposal would tailor third-party oversight to the risk of each relationship. The September 15 Federal Register notice sets November 16, 2026 as the comment deadline. The agencies also issued a separate statement about community banks and core service providers.

Published: Sep 27, 2026

Stablecoin policy moves into operating detail

GENIUS Act implementation proposals address reserves, capital, liquidity, custody, applications and reporting. Proposed requirements must be distinguished from effective obligations.

Published: Sep 26, 2026

Deep dives

Model-risk management after SR 11-7: what SR 26-2 changes

The April 17, 2026 interagency guidance supersedes SR 11-7 and SR 21-8, emphasizes materiality and excludes generative and agentic AI from its formal scope without removing broader governance responsibilities.

Published: Sep 27, 2026

12 CFR Part 5: a national charter is an operating commitment

The OCC’s April 2026 clarification preserves the existing scope of national trust-bank authority. For any charter applicant, the real questions remain permissible activities, sustainable capital, management, controls and the permissions needed beyond the charter.

Published: Sep 27, 2026

Trump v. Slaughter: presidential removal power and the limits of regulatory change

The Supreme Court’s June 2026 decision invalidated the FTC commissioners’ removal protection and overruled Humphrey’s Executor. It changes leadership accountability; it does not erase the underlying consumer-protection statutes. The same-day Federal Reserve case shows why agency-specific analysis matters.

Published: Sep 27, 2026

FRB / Wells Fargo: from an asset cap to completed remediation

The Fed ended its 2018 Wells Fargo action in March 2026, after lifting the asset cap in June 2025. The two milestones explain why remediation needs separate tests for growth permissions, control effectiveness and final closure.

Published: Sep 27, 2026

FRB / SouthPoint: why holding-company cash matters

SouthPoint’s August 2026 written agreement shows how parent-company capital, cash flow and distributions interact with a bank subsidiary’s remediation. The analysis separates holding-company obligations from the bank’s own FDIC order.

Published: Sep 27, 2026

CFPB / Apple Card: the handoff is part of the control

Apple Card’s dispute-routing and installment-enrollment findings show how a polished interface can still break an essential control. Apple’s order ended in September 2025; the separate Goldman Sachs record must be assessed independently.

Published: Sep 27, 2026

CFPB / Bilt: closing the loop on a bank transition

The CFPB closed its Bilt matter on September 21, 2026 after voluntary remediation. The case offers a practical framework for finding transition-related fees, reaching affected customers and demonstrating that repayment actually arrived.

Published: Sep 27, 2026

Blue Ridge Bank consent order

A historical control map for fintech onboarding, BSA/AML, capital, liquidity and board accountability.

Published: Sep 26, 2026

Official policy

Cybersecurity supervision — OCC 2026-48 ↗

Updates the structure and references of the Cybersecurity Supervision Work Program and rescinds the 2023 bulletin. The OCC says the update adds no procedures and establishes no new regulatory expectations.

Source date: Sep 21, 2026

Section 1071 small-business lending — 2026 final rule ↗

Official implementation page links the May 1, 2026 final rule revising coverage, data collection and other provisions, with compliance extended to January 1, 2028. The CFPB notes that supporting implementation materials will be updated later.

Source date: May 1, 2026

FDIC digital signs and ATM disclosures — 2026 final rule ↗

Amends Part 328 requirements for digital deposit-taking channels, ATMs and related signs. Effective March 2, 2026, with an April 1, 2027 compliance date for these amendments; distinguish this timetable from other Part 328 obligations.

Source date: Jan 29, 2026

Digital identity — NIST SP 800-63-4 ↗

Final guidance on identity proofing, authentication and federation, replacing SP 800-63-3. Useful for evaluating assurance levels and vendor controls; it does not independently establish compliance with bank CIP requirements.

Source date: Jul 31, 2025

OCC — Retail Lending handbook ↗

Retail lending strategy, underwriting, portfolio monitoring, collections and controls; useful context for roll rates and risk-adjusted pricing.

Source date: Oct 28, 2021

OCC — Loan-purchase risk management ↗

Credit analysis, documentation, monitoring and counterparty considerations for purchased loans and participations. The posted text removes reputation-risk references as of March 20, 2025.

Source date: Sep 10, 2020

Independent credit risk review — SR 20-13 ↗

Interagency guidance on independent, ongoing credit review and communication of portfolio performance to management and the board. Discusses tailoring review systems to the institution’s size, complexity and risk profile.

Source date: May 8, 2020

Lending limits — 12 CFR Part 32 ↗

Single-borrower lending limits, combination rules and exceptions for covered OCC-supervised institutions. A useful starting point for concentration controls and connected-borrower analysis.

Independent audits and reporting — 12 CFR Part 363 ↗

Independent audit, management reporting and audit-committee requirements for covered insured institutions. Check the applicable asset thresholds and effective dates rather than assuming one requirement applies to every bank.

Resolution and receivership — 12 CFR Part 360 ↗

Rules addressing FDIC resolutions and receiverships, including claims and selected contractual and securitization issues. Useful for separating the failed bank, the receivership and an acquiring institution.

Payday and covered high-cost loans — 12 CFR Part 1041 ↗

Covered-loan definitions, payment-transfer restrictions, consumer notices and recordkeeping. The text identifies reserved provisions; read it with current implementation and enforcement materials rather than applying removed underwriting requirements.

Adverse-action notices — 12 CFR 1002.9 ↗

Notification timing, incomplete applications, specific reasons and business-credit variations under Regulation B. Relevant to automated underwriting and the evidence supporting the reasons given to an applicant.

Debt-validation notices — 12 CFR 1006.34 ↗

Validation information, itemization and delivery requirements for covered debt collectors. Applicability turns on the FDCPA and Regulation F definitions; originating creditors are not automatically covered debt collectors.

SBA business lending — 13 CFR Part 120 ↗

Regulatory framework for SBA business-loan programs, including 7(a) and 504 requirements and lender oversight. Business lending is distinct from consumer credit; program eligibility and guaranty conditions require separate review.

Utah commercial-financing registration and disclosures ↗

DFI’s official implementation resource for Title 7, Chapter 27, including registration, transaction disclosures and links to statutory requirements. Relevant to business financing and merchant finance; review the Act’s exemptions.

FFIEC BSA/AML Examination Manual ↗

Official examination modules for BSA/AML programs, regulatory requirements and selected products and customer risks. Sections carry their own update dates; the manual explains examination procedures and does not replace the underlying rules.

Merchant Processing — Comptroller’s Handbook ↗

Examiner guidance on card-payment merchant processing and related risk management. Merchant acquiring and processing differ from card issuance, making this a useful companion to issuer and POS-lending controls.