The OCC has shifted focus, encouraging you to manage real threats over perfect documentation. But your audit trail still matters.
The Office of the Comptroller of the Currency revised PPM 5310-3 and PPM 5400-11 in August 2026, moving from procedural compliance to material financial risks. Comptroller Jonathan V. Gould stated, "A supervisory culture based on check-the-box compliance can distract examiners and bank executives from material financial risks that can endanger the viability of a bank if unaddressed."
This creates a challenge for compliance officers. Should you focus on risk-based supervision or maintain the procedural rigor that's kept you compliant?
Prioritizing Material Financial Risk
The OCC's new framework allows large banks to operate differently than community banks. Enforcement actions will now escalate for large institutions based on practices that wouldn't affect smaller banks. This acknowledges that a $500 billion institution faces different threats than a $200 million community bank.
Under the new Matters Requiring Attention (MRA) guidance, examiners will issue MRAs only for actions meeting specific standards related to financial risk. This means you can stop treating every documentation gap as a crisis.
Your team has limited time. If you're spending days documenting a vendor management framework that doesn't address real third-party risks, you're managing paperwork, not risk. The OCC's shift recognizes that procedural perfection can create a false sense of security while actual threats grow.
The OCC and FDIC also introduced a uniform definition of "unsafe or unsound practice," with a materiality threshold. FDIC Chairman Travis Hill explained that examiners will focus "only on issues that can have a material impact on the financial condition of an institution and on actual violations of relevant laws or regulations." This allows you to deprioritize low-impact findings.
For information security officers, this means focusing your third-party risk assessment on payment processors and core banking vendors, not minor suppliers. The regulatory framework now supports concentrating resources where losses actually occur.
Maintaining Procedural Discipline
Risk-first advocates miss that procedural compliance shows you knew about a risk before it materialized.
When a control fails, your documentation proves you had a framework. Without it, every materialized risk looks like negligence. The OCC may emphasize material risks, but enforcement actions still require evidence of what you knew and when.
Procedural rigor also creates institutional memory. Your fraud analyst's documentation can save successors months of trial and error. Access control matrices might seem bureaucratic, but they're essential for answering questions during incident investigations.
The revised framework still requires addressing "actual violations of relevant laws or regulations." Your PCI DSS compliance, Bank Secrecy Act obligations, and GLBA safeguards are still necessary. You need evidence you met those requirements.
Risk-based prioritization assumes you can accurately assess which risks are material before they manifest. Consider a team that dismisses change management documentation as overhead. Six months later, an unauthorized change introduces a vulnerability exposing cardholder data. The "immaterial" gap just became a material breach.
Compliance frameworks exist because hindsight makes every materialized risk look obvious. Procedural discipline protects you when your risk assessment is wrong.
Balancing Both Approaches
Most compliance officers aren't choosing between these approaches; they're balancing both and struggling with resource allocation.
The OCC's guidance allows you to tier procedural rigor. Maintain strict documentation for high-risk areas (third-party payment processors, privileged access management, customer authentication) while using lighter-touch approaches for lower-risk functions. The key is articulating why you made that distinction.
The revised MRA framework lets you push back on findings that don't meet the materiality threshold. If an examiner flags your incident response plan for lacking a specific communication template, you can argue it's a procedural concern, not a material risk, if your response capability is sound.
Large banks see the guidance as permission to implement risk-based controls that might not satisfy a checklist audit but reduce actual exposure. This works when you can quantify risk reduction. It fails when you're cutting corners and calling it risk-based supervision.
Our Take
The OCC's framework is correct in principle but dangerous if you abandon procedural discipline.
Reallocate resources toward material financial risks. But prove you're managing those risks through documentation, testing, and process. The shift isn't from procedure to risk; it's from procedure-for-its-own-sake to procedure-that-demonstrates-risk-management.
Your compliance framework should answer two questions: "What are our material risks?" and "How do we know we're managing them?" The second question requires procedural evidence. The OCC's guidance means you can stop answering that question for risks that don't matter.
Operationally, conduct an annual review classifying compliance activities into three tiers: material risk controls (maintain or increase rigor), regulatory requirements (maintain current state), and procedural overhead (reduce or eliminate). Document that classification and your rationale. That documentation is itself a procedural control, demonstrating risk-based thinking.
Institutions that treat this as a binary choice will struggle. Those that use the OCC's framework to justify better resource allocation while maintaining procedural foundations will succeed.
Your audit trail still matters. It just doesn't matter equally for everything.



