CiberLATAMbywhalemate

OCC eases CSI disclosure rules

The OCC proposed a new framework for sharing confidential supervisory information and kept cyber incident reporting requirements in place.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

The Office of the Comptroller of the Currency, OCC, proposed in August 2026 a new framework for disclosing confidential supervisory information, CSI, aligned with the FDIC proposal. The change would loosen the current prior-approval regime for sharing CSI with affiliates, service providers and counterparties in corporate transactions.

Update August 25, 2026: the note adds that, alongside the proposal on confidential supervisory information, U.S. banks must report cyber incidents to their primary regulator within 36 hours of learning of them, while credit unions have 72 hours to notify the NCUA.

The Office of the Comptroller of the Currency, OCC, published in August 2026 a proposal for a new framework for disclosing confidential supervisory information, CSI, aligned with the FDIC's proposal. The change would loosen the current prior-approval regime for sharing CSI with affiliates, service providers and counterparties in corporate transactions.

What changes in CSI disclosure?

The proposal replaces a more rigid prior-authorization scheme with a more flexible one for certain transfers of confidential supervisory information. According to the research material, the goal is to allow banks and other supervised entities to share CSI with affiliates, service providers and counterparties in corporate transactions under a less restrictive framework than the one now in force.

That regulatory shift comes at a time when the OCC already has a published enforcement framework that can apply to national banks, federal savings associations and their subsidiaries. Available tools include cease-and-desist orders, civil money penalties and other administrative sanctions.

What deadlines apply to cyber incident reporting?

Under current U.S. banking rules, all banks must notify their primary regulator of cyber incidents within 36 hours of becoming aware of the incident, while all credit unions must report them to the National Credit Union Administration within 72 hours, according to FinXTech analysis published on August 20, 2026.

That deadline applies both to national charter banks supervised by the OCC and to state-chartered banks supervised by the FDIC or the Federal Reserve. In the case of credit unions, the obligation falls to the NCUA, with a longer reporting window than the one required for banks.

What other compliance standards remain in force?

Regulation S-P, issued by the SEC under authority granted by the Gramm-Leach-Bliley Act, keeps confidentiality and security requirements in place for customer information held by broker-dealers, investment advisers and investment companies. That regime complements the information security standards that banking regulators issue under GLBA.

In parallel, the research material also places the OCC as a regulator with direct sanctioning authority over entities within its scope. Its enforcement framework includes national banks, federal savings associations and their subsidiaries, with measures ranging from corrective orders to civil money penalties.

For financial groups with a presence in Latin America, the overlap among these rules matters because a single corporate structure can face different requirements depending on the type of entity and the authority supervising it. The OCC proposal on CSI, the SEC's Reg S-P, the agency's enforcement powers and the federal timelines for reporting cyber incidents remain direct reference points for banks and holding companies with operations in Argentina and Mexico.

Sources

View all