Skip to main content
Should Regulators Publish MRA Data?Regulations and Standards
5 min readFor AML/KYC Compliance Officers

Should Regulators Publish MRA Data?

Your enforcement action count just dropped 50% over the last decade. That's not a headline from one administration; it's the trend across four. Now your team is trying to figure out what it means for your AML program when the Federal Reserve issued 87 public actions annually under one supervisor and 37 under the current one.

The question isn't whether enforcement is declining. It is. The question is whether that decline reflects a shift in regulatory strategy or a gap in oversight, and what your compliance program should do about it.

The Case for Non-Public Supervisory Tools

Matters Requiring Attention (MRAs) and Memorandums of Understanding (MOUs) offer targeted remediation without the market disruption of a public consent order. When your examiner flags a BSA/AML deficiency through an MRA, you get a corrective timeline without the reputational hit or stock price drop that accompanies a published enforcement action.

Public enforcement creates collateral damage. A consent order triggers board resignations, customer attrition, and analyst downgrades before you've even addressed the underlying control gap. If regulators can achieve the same compliance outcome through an MRA that requires you to upgrade your transaction monitoring system within 90 days, why impose the additional cost?

Former supervisory officials point to the shrinking number of banks, from over 5,000 in 2015 to fewer than 4,000 today, as evidence that the system is consolidating and stabilizing. Fewer banks mean fewer potential violators. The decline in enforcement actions, by this logic, reflects a healthier industry, not regulatory laxity.

There's also the operational reality that complex enforcement actions take years to develop. An asset cap tied to a $3 billion money laundering settlement isn't comparable to a capital deficiency citation at a community bank. If your team spent 18 months building a case that spans multiple business lines and jurisdictions, you're not going to hit the same annual action count as an agency processing straightforward violations.

And MRAs did increase between 2021 and 2024 across most bank categories, according to the Fed's supervision and regulation report, before dropping sharply last year. If non-public tools are doing the corrective work, the public enforcement count becomes less meaningful as a performance metric.

The Case for Transparency and Public Enforcement

Your compliance culture doesn't respond to tools your board can't see. When enforcement actions drop by 48% at one regulator while another sees only a 4% increase, you're not looking at industry-wide improvement, you're looking at inconsistent supervisory pressure.

Aaron Klein at Brookings calls this "a culture of regulatory laxity at the Fed," and the numbers support that framing. The Federal Reserve's enforcement activity fell from an average of 87 actions annually under one supervisor to 37 under the current one. That's not explained by bank consolidation or fewer violations. The OCC supervised a similar decline in bank count but saw a 4% increase in enforcement activity over the same period.

If MRAs and MOUs are compensating for fewer public actions, your compliance team has no way to benchmark what "acceptable" looks like. You can't see peer deficiencies. You can't track whether your transaction monitoring gaps are common or outliers. You can't tell your board whether the regulator's tolerance for AML control weaknesses has shifted or stayed constant.

Public enforcement actions serve a signaling function. When FinCEN publishes a consent order detailing how a bank failed to file SARs on structuring activity, your team gets a compliance roadmap: here's what the regulator considers a material deficiency, here's the remediation standard, here's the penalty range. Without that transparency, you're guessing at supervisory expectations.

The sharp drop in MRAs last year raises another concern: if non-public tools are declining alongside public enforcement, what's filling the gap? Klein notes that regulators provide limited data on MRAs, MRIAs, and MOUs, making it impossible to verify whether the decline in public actions reflects a strategic shift or a reduction in supervisory intensity.

And the argument that enforcement actions create collateral damage cuts both ways. If your institution can resolve a BSA deficiency through a quiet MOU, so can your competitor, and neither of you faces public accountability for the control failure. That asymmetry undermines market discipline.

Where Practitioners Actually Land

Your compliance program operates in the gap between these two positions. You can't rely on public enforcement trends to predict examiner focus, but you also can't ignore a 50% decline in supervisory actions at your primary regulator.

Most AML/KYC teams are responding by treating the decline as a risk factor, not a signal to ease up. If your regulator is issuing fewer public actions, you don't have the same external pressure to justify budget increases or headcount requests to your board. That makes it harder to maintain program investment when revenue is flat or declining.

At the same time, you're seeing more emphasis on self-identification and voluntary disclosure. If regulators are shifting from public enforcement to non-public remediation, your ability to find and fix issues before an exam becomes more important. That means more frequent control testing, more robust SAR quality reviews, and more documentation of risk assessment decisions.

Our Take

Regulators should publish anonymized, aggregate MRA data by deficiency category and bank size. You don't need to know which institution failed to implement adequate KYC procedures, you need to know that 40% of MRAs in a given quarter involved customer due diligence gaps at banks under $10 billion in assets.

The current lack of transparency creates two problems. First, your compliance team can't benchmark effectively. You're building an AML program without knowing whether your control gaps are common or outliers. Second, the public can't assess whether the decline in enforcement actions reflects better bank behavior or reduced supervisory intensity.

If non-public tools are doing the corrective work, prove it. Release the data. Show that MRAs are catching issues earlier, that remediation timelines are shorter, that repeat violations are declining. Without that transparency, the 50% drop in enforcement activity looks like a gap in oversight, not a strategic shift.

Your compliance program should operate as if public enforcement trends don't matter, because they shouldn't. Build controls based on regulatory requirements, not enforcement statistics. But demand better data from your regulators so you can explain to your board whether the current supervisory environment reflects a mature, stable banking system or a period of reduced accountability.

You Might Also Like