Search

Trending publication

Nutter Bank Report: September 2026

Print PDF
| Legal Update

Headlines

  1. New Guidance Issued on Core Processors and Other Third-Party Service Providers
  2. Community Bank Eligibility for 18-Month Exam Cycle to Be Expanded
  3. FDIC Proposes to Extend National Bank Parity to Out-of-State State Banks Without Branches
  4. Agencies Clarify SAR Confidentiality Rules and Use of Digital Credentials for CIPs
  5. Other Developments: Bank Mergers, Exams, and Stablecoins

1. New Guidance Issued on Core Processors and Other Third-Party Service Providers

The federal banking agencies have jointly issued new guidance on their risk-based supervision of core data processing providers that supply community banking organizations (CBOs) with critical systems such as transaction processing, account management, payments processing, and online banking platforms. The Joint Statement on Community Banks’ Engagement with Core Service Providers released on September 11 notes that a few large core providers account for a significant percentage of the core provider market, which limits CBOs’ negotiating power and their ability to obtain due diligence information, negotiate contract terms, and monitor their providers. The federal banking agencies stated that they will consider a core provider’s transparency, contract features, and technology investments and capabilities in deciding how often and how extensively to examine the provider, what to include in examination reports furnished to CBOs, and whether to add the provider to the agencies’ service provider examination program. Contract practices cited as relevant include opaque pricing and billing, extensive “back billing” windows, unsupported or undefined deconversion fees, and excessive limits on integration by unaffiliated providers. The guidance also asserts that the agencies may have a reasonable basis to determine that certain core providers are “institution-affiliated parties” under the Federal Deposit Insurance Act and, as a result, may be held liable for the practices or violations of a CBO. The joint statement—which highlights an area that many CBOs have long been seeking reforms—was issued together with newly proposed guidance on third-party risk management principles. Click for a copy of the joint statement. 

Nutter Notes: The federal banking agencies, together with the NCUA, have proposed interagency third-party risk management guidance that would replace the 2023 Interagency Guidance on Third-Party Relationships: Risk Management and related supplemental resources. The proposal released on September 11 states that the 2023 guidance has often been read as a prescriptive checklist and applied without regard to the actual risk of each relationship. The proposed guidance would instead be principles-based and non-enforceable, stating that non-compliance would not result in supervisory action, although the agencies could act on violations of law, unsafe or unsound practices, or other material risks resulting from insufficient management of third-party risk. The proposed guidance suggests that banks consider four components in approaching third-party risk management: risk identification and assessment; risk oversight, including due diligence, contract negotiation, ongoing monitoring, and termination; residual risk acceptance; and governance. The proposal acknowledges that a bank with limited negotiating power may proceed with a relationship if the residual risks are within its risk appetite and tolerances, and that limited or no negotiation of contract terms are generally expected, so the absence of a particular term alone would not support an adverse finding. Read together with the joint statement on core providers, the proposal signals more flexible supervisory expectations for banks to tailor risk management programs to the assessed risk of each relationship and closer scrutiny of core providers, but neither guidance document reduces a bank’s ultimate responsibility for outsourced activities. Comments on the proposed guidance are due by November 16, 2026. Click for a copy of the proposed guidance. 

2. Community Bank Eligibility for 18-Month Exam Cycle to Be Expanded

The federal banking agencies have jointly issued an interim final rule that increases the number of community banks eligible for an 18-month on-site examination cycle instead of a 12-month cycle. The interim final rule released on September 10 implements Section 903 of the 21st Century ROAD to Housing Act, which raised the total asset threshold for an extended examination cycle from $3 billion to $6 billion. To qualify, a bank must have total assets of less than $6 billion, be well capitalized, have a composite CAMELS rating of 1 or 2, and a management component rating of 1 or 2 at its most recent examination. In addition, a qualifying bank may not be subject to a formal enforcement proceeding or order, and may not have undergone a change in control during the previous 12 months. The agencies estimate that approximately 188 additional banks will become eligible for an extended examination cycle, bringing the total number of banks that may qualify to approximately 4,016. The interim final rule became effective on September 14, 2026, and comments on the rule are due by October 14, 2026. Click for a copy of the interim final rule. 

Nutter Notes: Eligibility also does not guarantee an 18-month cycle. The agencies retain authority to examine any bank more frequently, and they clarified that they will continue off-site monitoring between exams, including by performing Call Report-based analyses. The agencies acknowledged that a longer cycle creates a longer window in which problems could develop before an on-site exam detects them. A ratings downgrade, a decline in capital, an enforcement action, or a change in control would likely return a bank to a 12-month cycle. State-chartered banks should confirm with their primary federal regulator and state supervisor how the two agencies’ alternating examination schedule will be adjusted. Banks approaching $6 billion in assets, or considering an acquisition, should factor these criteria into their planning. For a bank with total assets between $200 million and $6 billion, the statute extends the 18-month cycle only to banks with a composite CAMELS rating of 1. The federal banking agencies extended eligibility to banks with a composite rating of 2 under the interim final rule by exercising their discretionary authority under the statute. Banks with a composite rating of 2 therefore depend on the federal banking agencies’ continued exercise of that discretion for eligibility. Because a management rating of 1 or 2 is a condition of eligibility, banks should also be aware of the FFIEC’s proposed revisions to the CAMELS rating system discussed in our May issue. 

3. FDIC Proposes to Extend National Bank Parity to Out-of-State State Banks Without Branches

The FDIC has proposed amendments to its regulations to promote parity between out-of-state state banks and national banks in the application of host state laws when state banks provide services outside their chartering state. The proposed rule published by the FDIC on September 17 would amend Part 331 of the FDIC’s regulations to extend protections currently only available to an out-of-state bank with a branch located in the host state under Section 24(j) of the Federal Deposit Insurance Act. Section 24(j) provides that host state laws apply to a branch of an out-of-state state bank only to the same extent they apply to a branch of an out-of-state national bank, but it does not expressly address state banks that provide services in a host state without a branch. Under the proposal, when a host state law does not apply to an out-of-state national bank, it also would not apply to an out-of-state state bank providing services in the host state, with or without a branch, and the law of the state bank’s chartering state would apply instead. The FDIC explained that recent litigation over the Illinois Interchange Fee Prohibition Act (IFPA) has created uncertainty about how state laws apply to state banks that serve customers outside their home states. The proposal would not affect the interest rates state banks may charge, which are governed by Section 27 of the FDI Act, and would not itself determine that any particular host state law is preempted. Comments on the proposed rule are due by November 23, 2026. Click for a copy of the proposed rule. 

Nutter Notes: The proposal depends on preemption for national banks: a host state law would be inapplicable to an out-of-state state bank only if it is inapplicable to an out-of-state national bank, whether because of an OCC determination, a court decision, or another basis. As reported in our April issue, the OCC found the IFPA preempted for national banks, and on June 1 a federal district court permanently enjoined Illinois from enforcing the IFPA’s interchange fee prohibition against national banks, federal savings associations, payment card networks, and out-of-state state banks “subject to Riegle-Neal.” The Illinois Attorney General argued that Section 24(j) protects only state banks with a physical branch in Illinois, and the proposal would resolve that question in favor of banks without branches. The proposal could also create a competitive imbalance for Massachusetts-chartered banks, which remain subject to Massachusetts law, if out-of-state state banks serving Massachusetts customers without branches are not subject to Massachusetts laws that are preempted for national banks. The FDIC specifically invites comment on whether the proposal would affect settled applications of particular types of host state laws.

4. Agencies Clarify SAR Confidentiality Rules and Use of Digital Credentials for CIPs

The federal banking agencies, together with the NCUA and FinCEN, have jointly issued guidance clarifying how suspicious activity report (SAR) confidentiality requirements apply when banks communicate with customers about potentially fraudulent transactions, other suspicious activity, or account closures. The Joint Statement on Suspicious Activity Report Confidentiality Considerations Regarding Communications with Customers released on September 2 responds to comments on a June 2025 request for information on payments fraud. The joint statement explains that the Bank Secrecy Act (BSA) prohibits disclosing a SAR or information that would reveal its existence, including to the subject of the SAR, but that FinCEN’s regulation excludes from that prohibition the underlying facts, transactions, and documents on which a SAR is based. Banks therefore may discuss transaction dates, amounts, and parties, even if a reasonable person could deduce from those facts that a SAR was or may have been filed, so long as the communication does not reveal the existence of a SAR. The joint statement provides a non-exhaustive list of communications that typically would not reveal a SAR, including notifying a customer that an account restriction, account closure, or rejected deposit may be related to suspected fraud, asking about the purpose of a transaction or the source of funds, and providing warnings about fraud schemes, including “money mule” schemes. Banks should consider customer communications case by case. Separately, the agencies issued guidance on verifiable digital credentials on September 8. Click for a copy of the joint statement. 

Nutter Notes: The federal banking agencies, together with the NCUA and FinCEN, have issued frequently asked questions (FAQs) on the use of verifiable digital credentials (VDCs), such as state-issued mobile driver’s licenses (mDLs), to verify the identity of natural person customers under the Customer Identification Program (CIP) rule. The FAQs published on September 8 describe a VDC as a data structure containing information about an individual that is digitally signed by the issuing source, cryptographically bound to a device, and protected by an activation factor, such as a PIN or biometric data. They state that the CIP rule neither requires nor prohibits reliance on government-issued VDCs, and that an unexpired government-issued VDC, such as an mDL, would qualify as “government-issued identification” for documentary verification if it evidences nationality or residence and bears a photograph or similar safeguard. A bank may accept one, in person or remotely, if its CIP permits and it has systems to extract the relevant information from the credential. If a VDC shows indications of fraud, the bank must consider that in deciding whether it has a reasonable belief that it knows the customer’s true identity. The agencies also amended a prior FAQ to state that a bank may use VDCs as a non-documentary verification method, and that for VDCs issued and maintained by a non-government third party, the bank must ensure that the third party uses the same level of authentication the bank would use. Banks that want to accept VDCs should consider whether their written CIP procedures need to be updated. Like the joint statement, the FAQs do not alter existing BSA requirements or establish new supervisory expectations. Click for a copy of the FAQs. 

5. Other Developments: Bank Mergers, Exams, and Stablecoins

  • FDIC Proposes to Modernize and Reform Bank Merger Review

The FDIC on September 17 issued a proposed rule that would update the process by which it reviews merger transactions subject to approval under the Bank Merger Act. The proposed rule would create a letter filing with “deemed approval” for de minimis merger transactions and set processing timelines of 90 or 150 days for merger filings that do not qualify for expedited processing. It would also raise from 10% to 25% of the acquirer’s assets the size limit for expedited processing of eligible depository institutions and reduce public notice and comment requirements. Comments are due by November 23, 2026. Click for a copy of the proposed rule. 

Nutter Notes: The proposed rule would apply to a “merger in substance,” which is defined as an acquisition of 80% or more of another institution’s assets over a rolling 12-month period, limit removal of filings from expedited processing based on adverse comments or CRA protests, and require notice and non-objection for significant asset transfers that increase an FDIC-supervised institution’s assets by 25% or more over a rolling 12-month period. The FDIC plans to rescind its current Statement of Policy on Bank Merger Transactions when a final rule is adopted.

  • Federal Reserve Updates Statement of Supervisory Operating Principles

On September 24, the Federal Reserve’s Division of Supervision and Regulations issued an updated Statement of Supervisory Operating Principles that reflect, in part, the findings from the preliminary report by Starling Insights entitled Probative Inquiry into the 2023 Financial Sector Stress Events (Click to read the public exposure draft). The Statement states that the primary objective of supervision is to (i) “[i]dentity as early as possible significant threats to the safety and soundness of a [Fed-supervised] banking organization and to U.S. financial stability and any violation of law or regulation,” and (ii) “[e]ncourage or direct each [Fed-supervised] banking organization to take decisive and proportionate action to eliminate or mitigate those threats and violations as promptly as possible.” Accordingly, the Statement encourages more use of “supervisory observations” as a tool and reserving MRAs and MRIAs for the most significant and severe matters that result in material financial risk or violations of law. Click to read the Fed’s Statement. 

Nutter Notes: Starling’s preliminary report indicated that the Federal Reserve Board and the Federal Reserve Bank of San Francisco supervisory staff knew or should have known in March 2022 about the interest rate risk imposed by Silicon Valley Bank’s bond portfolio and that one key reason for the lack of action was a “long-standing culture of excessive risk-aversion and indecision, and decision-making by committee consensus” at the Fed. In an effort to address this criticism, the Statement encourages supervisory staff to be more decisive to address significant risks that they identify, that leadership will not criticize honest mistakes by staff, and implement regular reporting by supervisory staff at each Reserve Bank to Reserve Bank leadership on any supervisory issues that they are uncertain about.

  • Federal Reserve Proposes Regulatory Framework for Payment Stablecoin Issuers

The Federal Reserve on September 24 released two proposals to establish a regulatory framework for payment stablecoin issuers under the GENIUS Act. The first proposal would require Federal Reserve-supervised permitted payment stablecoin issuers (PPSIs) to fully back their stablecoins with permissible reserve assets, such as short-term Treasury bills and certain other high-quality liquid assets, and would establish capital requirements, risk management standards, and rules for Board-supervised custodians of the reserve assets. The second proposal would establish an application process for insured state member banks seeking approval for a subsidiary to issue payment stablecoins. Comments on both proposals are due by November 30, 2026. Click for a copy of the proposed rule implementing the GENIUS Act and click for a copy of the proposed application procedures. 

Nutter Notes: Under the proposed application procedures, an insured state member bank would submit a letter application including a business plan, financial information, relevant policies and agreements, and biographical information for certain individuals. The Federal Reserve could deny an application only if it finds that the activities of the applicant, including the proposed PPSI, would be unsafe or unsound, and a denied applicant could request a hearing. The Federal Reserve noted that the proposals are similar to earlier OCC, FDIC, and NCUA proposals.

Nutter Bank Report
Nutter Bank Report is a monthly electronic publication of the Banking and Financial Services Group of the law firm of Nutter McClennen & Fish LLP. Chambers and Partners, the international law firm rating service, after interviewing our clients and our peers in the profession, has ranked Nutter’s Banking and Financial Services practice among the top banking practices in the nation. Visit the U.S. rankings at Chambers.com. The Nutter Bank Report is edited by Matthew D. Hanaghan. Assistance in the preparation of this issue was provided by Daniel W. Hartman, Jack Lowy, and Heather F. Merton. The information in this publication is not legal advice. For further information, contact:

Matthew D. Hanaghan

mhanaghan@nutter.com

Tel: (617) 439-2583

Daniel W. Hartman
dhartman@nutter.com
Tel: (617) 439-2872

Michael K. Krebs

mkrebs@nutter.com

Tel: (617) 439-2288

Kate Henry
khenry@nutter.com 
Tel: (617) 439-2304

This update is for information purposes only and should not be construed as legal advice on any specific facts or circumstances. Under the rules of the Supreme Judicial Court of Massachusetts, this material may be considered as advertising.

More Publications >
Back to Page

Nutter McClennen & Fish LLP Cookie Preference Center

Your Privacy

When you visit our website, we use cookies on your browser to collect information. The information collected might relate to you, your preferences, or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. For more information about how we use Cookies, please see our Privacy Policy.

Strictly Necessary Cookies

Always Active

Necessary cookies enable core functionality such as security, network management, and accessibility. These cookies may only be disabled by changing your browser settings, but this may affect how the website functions.

Functional Cookies

Always Active

Some functions of the site require remembering user choices, for example your cookie preference, or keyword search highlighting. These do not store any personal information.

Form Submissions

Always Active

When submitting your data, for example on a contact form or event registration, a cookie might be used to monitor the state of your submission across pages.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek