Nsight Blog | Ncontracts

Enforcement Actions Roundup: August 2026

Written by Toni Fennell, CRCM | Sep 10, 2026, 6:30:00 PM

Welcome to the latest Enforcement Actions Roundup. August was a quiet month on the enforcement front, with just one action to report: a Written Agreement from the Federal Reserve Board placing new source-of-strength and capital-conservation obligations directly on a bank holding company after deficiencies surfaced at its subsidiary bank. 

Each month, we break down what went wrong, why it matters, and what your financial institution (FI) can do to stay ahead — giving you two resources: the Enforcement Actions Tracker, a running tally of actions by agency, category, and topic, and the Enforcement Deep Dive below, a closer look at each action's details, takeaways, and controls to revisit.  

Related: Bookmark the Ncontracts Enforcement Action Tracker to search the latest enforcement actions by date, category, and regulator.      

2025/2026 Enforcement Action Tracker

 
  Year Fair Lending Advertising AML/CFT Underwriting UDAAP Electronic Funds Transfers Insider Activities Flood Insurance Financial Risk Concentration Military Lending Government Loan Programs
CFPB 2025 1 2     4 1         1  
  2026 YTD         1              
DOJ 2025                        
  2026 YTD     2               1
OCC 2025     3       1   8 3    
  2026 YTD   1 1                  
FRB 2025         1     3 1      
  2026 YTD       1     2   2      
FDIC 2025     5 3 1 1 1 10 6      
  2026 YTD 1   1 2     2 6 3      
NCUA 2025                        
  2026 YTD                        

 

Enforcement Actions Deep Dive: August 2026

CFPB Enforcement Actions

The CFPB issued no institutional enforcement actions in August 2026. 

OCC Enforcement Actions

The OCC issued no institutional enforcement actions in August 2026. 

FRB Enforcement Actions

FRB and State Regulator Enter Written Agreement with Bank Holding Company Over Source-of-Strength Deficiencies

The FRB and a state banking department entered into a Written Agreement with the holding company of the bank after an offsite review identified deficiencies at the organization. The agreement follows an earlier consent order already in place at the bank and extends source-of-strength obligations to the holding company on a consolidated basis. The board of directors must affirmatively demonstrate the holding company’s ability to serve as a source of financial and managerial strength to the bank, including a willingness to raise capital or contribute assets in the event of its financial distress.  

Within 60 days, the holding company must submit an acceptable capital plan addressing current and projected capital sources and uses, an analysis of asset quality and earnings capacity, a capital-raising action plan, and an enhanced capital contingency plan, together with a parent-only cash flow projection for 2026 and each subsequent calendar year. Effective immediately, the holding company may not declare or pay dividends, repurchase shares, make other capital distributions, or incur, increase, prepay, or guarantee debt without the prior written approval of its supervisors.   

The agreement also imposes notice requirements for new directors and senior executive officers, restricts indemnification and severance payments, and requires quarterly progress reports, including parent-company-only financial statements.  

Takeaways

This action illustrates that supervisory findings at a subsidiary bank do not stay contained at the bank level; a separate holding-company agreement layers explicit source-of-strength, capital-planning, and capital/debt-conservation obligations directly onto the parent. Institutions with a holding company structure should not assume that remediating conditions at the bank satisfies supervisory expectations at the consolidated organization; the holding company board should independently assess and document its capacity to serve as a source of financial and managerial strength.  

The agreement also confirms that capital conservation restrictions on dividends, repurchases, and debt attach immediately upon execution rather than on a future compliance date, so banks entering similar agreements should have dividend and debt approval workflows and board reporting processes ready in advance.  

Finally, the prior-notice requirement for new directors and senior executive officer appointments reinforces that governance changes during a formal enforcement period draw heightened regulatory scrutiny and should be tracked against a defined internal approval timeline.  

Controls to Evaluate

  1. Board and Senior Management Oversight: The financial institution has in place effective mechanisms through which the board and senior management execute their respective oversight responsibilities, including reviewing internal and external audit reports. The board and senior management have processes in place for the oversight of the FI's strategic objectives, including risk appetite, financial performance, capital adequacy, capital planning, liquidity, risk profile and risk culture, controls, compensation practices, and the selection and evaluation of management. Supervisors focus particular attention on the oversight of the risk management, compliance, and internal audit functions. This includes assessing the extent to which the board interacts with and meets with representatives of these functions. Internal controls are being adequately assessed and contribute to sound governance throughout the FI.  
  2. Asset Liability Committee (ALCO) Oversight: ALCO meets regularly to review investments, loan portfolios, interest rates, liquidity, and capital levels, and make adjustments as needed to meet risk tolerances and policy guidelines, including scenario analysis (stress testing) and even ESG risk considerations. 
  3. Comprehensive Strategic Planning: The Comprehensive Strategic Plan is formulated, documented, and communicated by the board annually, ensuring that it aligns with the risk appetite, capital plan, and liquidity requirements. The plan considers all business lines, risk categories, and material internal and external factors, including operational resilience, cybersecurity, and emerging threats identified through stress testing and industry intelligence. Strategic planning also considers the use of advanced technologies, including automation and AI, to ensure appropriate governance, risk management, and alignment with business objectives. The plan establishes short- and long-term goals and confirms that sufficient financial, technological, and human resources are available to support safe, sound, and sustainable operations. 

Related: Board Members: Keep an Eye on Internal Controls 

Related Ncontracts Content in Your Platform

Ncomply Sample Policies

Nrisk Risk Assessments

FDIC Enforcement Actions

The FDIC issued no institutional enforcement actions in August 2026. 

NCUA Enforcement Actions

The NCUA issued no institutional enforcement actions in August 2026. 

Budget pressure doesn't excuse gaps in compliance risk coverage. Examiners still expect the controls to hold. Our webinar breaks down how to protect what matters and streamline the rest.