OCC eases CSI disclosure rules
The OCC proposed a new framework for sharing confidential supervisory information and kept cyber incident reporting requirements in place.
The Office of the Comptroller of the Currency, OCC, proposed in August 2026 a new framework for disclosing confidential supervisory information, CSI, aligned with the FDIC proposal. The change would loosen the current prior-approval regime for sharing CSI with affiliates, service providers and counterparties in corporate transactions.
Update August 25, 2026: the note adds that, alongside the proposal on confidential supervisory information, U.S. banks must report cyber incidents to their primary regulator within 36 hours of learning of them, while credit unions have 72 hours to notify the NCUA.
The Office of the Comptroller of the Currency, OCC, published in August 2026 a proposal for a new framework for disclosing confidential supervisory information, CSI, aligned with the FDIC's proposal. The change would loosen the current prior-approval regime for sharing CSI with affiliates, service providers and counterparties in corporate transactions.
What changes in CSI disclosure?
The proposal replaces a more rigid prior-authorization scheme with a more flexible one for certain transfers of confidential supervisory information. According to the research material, the goal is to allow banks and other supervised entities to share CSI with affiliates, service providers and counterparties in corporate transactions under a less restrictive framework than the one now in force.
That regulatory shift comes at a time when the OCC already has a published enforcement framework that can apply to national banks, federal savings associations and their subsidiaries. Available tools include cease-and-desist orders, civil money penalties and other administrative sanctions.
What deadlines apply to cyber incident reporting?
Under current U.S. banking rules, all banks must notify their primary regulator of cyber incidents within 36 hours of becoming aware of the incident, while all credit unions must report them to the National Credit Union Administration within 72 hours, according to FinXTech analysis published on August 20, 2026.
That deadline applies both to national charter banks supervised by the OCC and to state-chartered banks supervised by the FDIC or the Federal Reserve. In the case of credit unions, the obligation falls to the NCUA, with a longer reporting window than the one required for banks.
What other compliance standards remain in force?
Regulation S-P, issued by the SEC under authority granted by the Gramm-Leach-Bliley Act, keeps confidentiality and security requirements in place for customer information held by broker-dealers, investment advisers and investment companies. That regime complements the information security standards that banking regulators issue under GLBA.
In parallel, the research material also places the OCC as a regulator with direct sanctioning authority over entities within its scope. Its enforcement framework includes national banks, federal savings associations and their subsidiaries, with measures ranging from corrective orders to civil money penalties.
For financial groups with a presence in Latin America, the overlap among these rules matters because a single corporate structure can face different requirements depending on the type of entity and the authority supervising it. The OCC proposal on CSI, the SEC's Reg S-P, the agency's enforcement powers and the federal timelines for reporting cyber incidents remain direct reference points for banks and holding companies with operations in Argentina and Mexico.
Sources
- Suspicious Activity Reports and other reports and statements.customsmobile.com· CustomsMobile
- FTC Safeguards Rule in 2026: What It Means for Data Securityc2datatechnology.com· C2 Data Technology
- Data Retention And Disposal: GLBA Compliance Requirementsarchondatastore.com· Archon Data Store
- Cybersecurity Incident Reporting Is About To Get More Complicatedfinxtech.com· FinxTech
- FDIC and OCC Propose New Frameworks for Disclosure of Confidential Supervisory Informationstblaw.com· Simpson Thacher & Bartlett LLP
- US banks officially permitted to buy and sell crypto assetscryptobriefing.com· Crypto Briefing
- Enforcement Actions | OCCocc.gov· Office of the Comptroller of the Currency (OCC)
- Data Breach: Who Has to Tell You, and Why the Answer ...adviceonly.com· AdviceOnly
- FTC's 30-Day Breach Notification Rule for Tax Firmsverito.com· Verito
- Does Encryption Exempt a Tax Firm From FTC Breach ...verito.com· Verito
- The Safeguards Rule Breach Report Non-Bank Lendersnatlawreview.com· National Law Review
- Memorandum - FDIC and OCC Propose New Frameworks ...stblaw.com· Simpson Thacher & Bartlett LLP
- Cybersecurity Requirements for Dallas Financial Firmsuprite.com· Uprite
- You Have Thirty Days to Confess and the FTC Will Post It on the Internet: The Safeguards Rule Breach Report Non-Bank Lenders Keep Forgetting They Owemondaq.com· Mondaq
- NCUA Announces New Cyber Threat Reporting Requirementnelsonmullins.com· Nelson Mullins
- 2026 Cybersecurity and Privacy Regulation Trend Analysissecuritypost.org· SecurityPost
- CISO Application Risk Intelligence Briefing for Week of August 19veracode.com· Veracode
- SEC Cyber Incident Disclosure Rules: What Counts as Materialtetmo.com· Tetmo Cyber Security Brief
- America's CUs Urges House Dems to Avoid Imposing Broad New AI Regs on Credit Unionsthecudaily.com· America's Credit Unions (CU Daily)



