Find a lawyerOur capabilitiesYour career
Locations
Our capabilities
News

Select language:

Locations
Our capabilities
News

Select language:

hamburger menu showcase image
  1. Our thinking
  2. Blogs
  3. A Fresh Take
  4. Key Takeaways from the OCC and FDIC CSI Proposals
9MIN

Key Takeaways from the OCC and FDIC CSI Proposals

Subscribe
Aug 14 2026

Two of the three federal banking agencies—the Federal Deposit Insurance Corporation (“FDIC”) and the Office of the Comptroller of the Currency (“OCC” and, together with the FDIC, the “Agencies”)—have proposed revisions to their regulations governing confidential supervisory information (“CSI”) for the first time in decades (together, the “Proposals”). The FDIC’s June 25, 2026 proposal (the “FDIC Proposal”) and the OCC’s August 3, 2026 proposal (the “OCC Proposal”) respond to years of industry criticism that the existing CSI sharing restrictions are impractical and overbroad, and both Proposals would generally relax certain of the longstanding requirements that a supervised financial institution obtain agency approval before sharing CSI. 

The Proposals would move both Agencies from a regime in which agency approval is generally required before an institution may disclose CSI to one that permits disclosure without prior approval in enumerated circumstances, in some cases subject to qualifying confidentiality agreements and other tailored safeguards. Those circumstances cover several of the industry’s highest priorities, such as sharing with potential merger counterparties, service providers, and affiliates. In particular, the OCC Proposal would permit disclosure of CSI by an institution in six circumstances where disclosure is necessary or appropriate for the efficacy of the supervisory process: to affiliates, service providers, senior executive officer candidates, potential counterparties in business or other combinations, U.S.-based consultants and attorneys of those counterparties, and not-for-profit entities. The FDIC Proposal would authorize disclosure of CSI by an institution where necessary or appropriate for business purposes in four contexts: within the corporate group; to external counsel, accountants, auditors, and qualifying service providers; to majority shareholders and incoming senior executives; and in certain merger transactions. 

The Proposals would make additional changes as well, such as streamlining how Freedom of Information Act (“FOIA”) requests are processed, easing restrictions on CSI that is at least 25 years old, and clarifying each Agency’s discretion to release CSI on its own initiative.

In this blog post, we summarize five key takeaways from these Proposals and look ahead to what’s next. 

Key Takeaways 

1. The Proposals do not fix the ongoing problem of a fragmented agency approach to CSI. 

The Proposals would reduce the need for case-by-case approvals but would leave institutions to continue to navigate materially different regimes. Definitions, eligible recipients, qualifying confidentiality agreements, geographic limits, and agency-notification procedures still vary among the OCC, FDIC, Board of Governors of the Federal Reserve System (“FRB”), Consumer Financial Protection Bureau (“CFPB”), and state banking and financial services regulators, such that financial institutions are subject to multiple overlapping regimes with different, and potentially conflicting, standards. The FDIC Proposal states that its restrictions would apply to any person holding FDIC CSI, regardless of whether the FDIC is the appropriate federal banking agency, and expressly declines to restrict or authorize disclosure of another agency’s CSI. Likewise, the OCC Proposal notes that the agency’s exceptions do not relieve a supervised institution of another regulator’s CSI disclosure restrictions. A financial institution holding overlapping FDIC and OCC CSI (a common occurrence) would therefore be expected to satisfy both agencies’ CSI regimes. Financial institutions therefore would need to identify the source and type of information, the regulator asserting control, the potential recipient, and the purpose before relying on a relevant exception to allow disclosure of CSI without prior approval. This amounts to a web of operational complexity for financial institutions.

2. Definitions of CSI are converging but remain distinct. 

Although the definitions of CSI in each Proposal have converged around similar principles, meaningful differences remain. Both Proposals build on the same foundational principle: information a supervised institution creates for its own business purposes and holds in its own possession is excluded from the restricted category—meaning the same document may be CSI in the agency’s hands and not CSI in the institution’s. But the agencies define the restricted category and condition the exclusion differently.

Under the FDIC Proposal, the agency’s definition of “confidential information” (referred to herein as CSI) would move closer to the CSI definition used by the FRB in its CSI regulations. Where the FRB limits CSI to information exempt under FOIA Exemption 8 (the exemption for bank examinations and reports), the FDIC’s concept of CSI under the FDIC Proposal would reach any FDIC record or other FDIC information that is exempt from disclosure under any FOIA exemption. Both the FDIC and FRB definitions cover anything “derived from or related to” such information, and both definitions exclude documents required by law to be made public. The FDIC Proposal would qualify its definition with an explicit exclusion for an institution’s own documents, so that the FDIC’s concept of CSI would not include “documents prepared by or for an insured depository institution, or any other party, for its own business purposes that are in its own possession” (emphasis added). The proposed rule text provides that such documents would fall outside the definition of confidential information “even though copies of such documents in the FDIC’s possession otherwise would constitute confidential information.” 

The OCC would take a two-tiered approach, defining (1) non-public OCC information (“NPOI”), covering any record the agency may withhold under FOIA (other than information that the agency is required to publish, such as enforcement orders and Community Reinvestment Act performance evaluations), and (2) CSI, the subset of NPOI that is exempt under FOIA Exemption 8 or under Exemption 5 for privileged intra- or inter-agency documents in connection with the bank examination privilege. NPOI that is not CSI would not be restricted from being disclosed further by a supervised institution unless, and to the extent that, the OCC imposes conditions on that disclosure. The OCC, like the FDIC, proposes a business-purpose exclusion with respect to CSI, but it explicitly does not extend to material prepared for the OCC, FRB, FDIC, or CFPB in response to those agencies’ supervisory or enforcement activities, or to supervisory feedback or enforcement-activity information from those agencies, including “summaries of such information,” all of which would remain CSI even in the institution’s own hands.

3. Both Proposals would allow disclosures in a transaction context, but with material differences. 

Agency restrictions on sharing CSI consistently complicate bank M&A and have accordingly been a longstanding source of concern for the financial services industry. Absent agency approval, a supervised institution cannot, for example, share examination ratings, exam reports, or other materials considered CSI with counterparties, which constrains both what a potential acquirer or investor can diligence and what the supervised institution can say about its own supervisory standing, even if such information may be of significance in the context of the transaction. Both Proposals respond to these industry concerns by permitting sharing of CSI in a transaction context without prior agency approval, subject to certain limitations. Specifically, both Proposals would cap the number of counterparties that may receive CSI, require a qualifying confidentiality agreement with the CSI recipient, and require written waivers to the agency, among other safeguards. 

The Proposals’ respective requirements would, however, diverge in certain ways that matter in practice. For example, under the OCC Proposal, a private equity firm or other non-bank acquirer would be permitted to receive CSI, but not under the FDIC Proposal, which only reaches counterparties that are themselves insured depository institutions (“IDIs”). The transaction scope of the two exceptions also diverges, as a standalone acquisition of a controlling voting interest (rather than a merger, consolidation, or other combination enumerated in 12 CFR 5.33) would fall within the transaction categories referenced in the FDIC Proposal, but would not fall within the parameters set forth in the OCC Proposal. Another practical difference between the Proposals is that, under the FDIC Proposal, the counterparty cap would not apply to a counterparty once the parties have entered into a written agreement to enter into the transaction, whereas the OCC Proposal includes no analogous provision. The Proposals also offer different coverage when it comes to which advisors may receive CSI, with the OCC Proposal permitting disclosure specifically to U.S.-based consultants and U.S.-based attorneys, whereas the FDIC Proposal permits disclosure to both U.S. and non-U.S. attorneys and auditors, but includes no explicit provision for consultants. The Proposals’ requirements for a qualifying confidentiality agreement also diverge, with the OCC Proposal requiring certain additional elements not demanded by the FDIC.

These differences will require attention and consideration in advance of disclosure of CSI, and we expect will be an important area for comment. 

4. For service providers, the FDIC adds an exception while the OCC’s changes both expand and narrow its existing exception. 

The FDIC currently has no express service provider exception in its regulations, although FDIC exam manual guidance would allow for some disclosures. The FDIC Proposal would explicitly include exceptions for the IDI’s external legal counsel, accountants or auditors, as well as for “qualifying service providers” that have a contractual relationship with the IDI and provide certain products or services (including fintech), consulting or advisory services, or technological infrastructure. These exceptions would require a qualifying confidentiality agreement (which must limit the access and use of CSI, among other requirements). 

The OCC’s current rule permits disclosure to attorneys and auditors when necessary or appropriate for business purposes and to consultants under a written agreement. The OCC Proposal would fold all of these into a single “service provider” exception for CSI disclosure, defined to exclude customers and financial counterparties, that is nominally broader in covered providers but materially narrower in operation. In particular, under the OCC Proposal, a provider must be incorporated in the United States or a U.S. territory, have a business need and a formal or written services agreement, and sign a qualifying confidentiality agreement, and the supervised institution must log the general categories of CSI disclosed. A service provider’s confidentiality agreement would have to satisfy nine criteria (going further than the FDIC’s approach), including two provisions specific to service providers that have no analogue in the FDIC Proposal (or the current OCC rule): the provider must (1) consent to OCC regulation and enforcement to the same extent as if the supervised entity were performing the service itself, and (2) acknowledge institution-affiliated party status for purposes of OCC enforcement authority.

The practical result is that routine information sharing with outside counsel or auditors, which is permitted today by the OCC with minimal formality, would become subject under the OCC Proposal to the full set of conditions required in a qualifying confidentiality agreement. The OCC specifically asks whether the criteria related to service providers would be too burdensome and interfere with supervised institutions’ ability to obtain outside assistance from such service providers for remediation efforts; we expect this to be a primary focus of comment letters. 

5. The OCC would remove its reference to criminal penalties, while the FDIC is silent. 

The OCC Proposal would remove the current rule’s express warning that unlawful use or disclosure of NPOI may subject a person to criminal penalties under 18 U.S.C. § 641, out of concern that the reference “inappropriately chills lawful disclosure.” The OCC states that it would not expect to refer unauthorized disclosure to the Department of Justice for criminal prosecution “absent extraordinary circumstances,” but notes that removing the reference “would not preclude” a referral, where appropriate, at which point the Department of Justice could decide whether to pursue the matter. The OCC frames the change as aligning its rules with both the Trump Administration’s policy against overcriminalization of federal regulatory offenses and recent case law casting doubt on whether misappropriation of confidential regulatory information is prosecutable under 18 U.S.C. § 641. The same reasoning surfaces elsewhere in the OCC Proposal: the proposed 12 CFR 4.13(d) would provide that NPOI is the OCC’s property only to the extent it is in the agency’s possession (or restricted from further disclosure if not in the OCC’s possession)—a recalibration the OCC expressly ties to the overcriminalization policy and related case law. The FDIC’s existing rules contain no comparable criminal-penalty language, and the FDIC Proposal does not expressly discuss or address potential criminal penalties.

What’s Next 

Comments are due on the FDIC Proposal on August 31, 2026, and on the OCC Proposal on October 5, 2026. FRB Vice Chair for Supervision Michelle Bowman has said that the FRB is reviewing its limitations on the sharing of CSI, which may or may not result in further alignment between the federal banking agencies. Institutions that anticipate sharing CSI with affiliates, service providers, or transaction counterparties—particularly those supervised by multiple federal banking agencies—may wish to use the comment periods for the Proposals to press for consistency across the Agencies’ and FRB’s approaches to CSI disclosure requirements.

* * *

We will continue to monitor developments in this area and provide updates as warranted. 

To receive the latest insights on US legal developments, subscribe to the Freshfields A Fresh Take Blog.

Tags

financial institutionsfinancial regulatoryfinancial services regulationfinancial services

Authors

New York

Alison M. Hashmall

Partner
New York

David Sewell

Partner & US Head of Financial Services Regulatory
New York

Nariné Atamian

Senior Associate
Silicon Valley

Taylor Richards

Senior Associate
Latest Insights

Latest Insights

NAVIGATE TO
About usLocations and officesYour careerOur thinkingOur capabilitiesNews
CONNECT
Find a lawyerAlumniContact us
NEED HELP
Fraud and scamsComplaintsTerms and conditions
LEGAL
AccessibilityCookiesLegal noticesTransparency in supply chains statementResponsible procurementPrivacy

Select language:
Select language:
© 2026 Freshfields. Attorney Advertising: prior results do not guarantee a similar outcome