OCC Proposes Easing Non-Public Information Disclosure Rules and Removing Criminal Penalty References

On August 3, 2026, the Office of the Comptroller of the Currency (OCC) published a notice of proposed rulemaking (NPRM) that would substantially overhaul its framework governing the disclosure of non-public OCC information (NPOI), including examination reports, supervisory correspondence, and enforcement-related materials. For financial institutions and their counsel, the proposal carries meaningful practical consequences across internal investigations, regulatory defense, M&A diligence and third party contracting by making it easier, in many circumstances, to share NPOI. At the same time, if adopted, the proposed rules, if adopted, would counterintuitively demand greater vigilance from financial institutions, requiring them to reassess their protocols for safeguarding NPOI and preventing its unauthorized use of disclosure.

Background: Why the Current Framework Is a Problem

Under existing rules, supervised entities must obtain prior OCC approval before disclosing NPOI in nearly all circumstances. Disclosure without approval carries potential criminal liability under 18 U.S.C. § 641, a reference the OCC itself now acknowledges has had a significant chilling effect. Institutions and their counsel have routinely faced difficult judgment calls about whether routine sharing, including with affiliates, deal counterparties, outside advisors, or even board candidates, requires formal OCC approval.

What the NPRM Would Change

The proposal makes two key changes:

  1. A New Tiered Framework for “Confidential Supervisory Information”

First, the NPRM carves out a defined subcategory of NPOI called “confidential supervisory information” (CSI), which is generally, examination-privileged or bank examination-exempt materials under FOIA Exemptions 5 and 8, and creates six categories of permissible disclosure without prior OCC approval:

  • Affiliates within a corporate family, which resolves uncertainty particularly for enterprise wide risk management functions.
  • S.-incorporated service providers where the provider has a legitimate business need, a formal contract with the institution, and executes a qualifying confidentiality agreement (QCA). Notably, foreign-incorporated vendors fall outside this exception and would still require case-by-case OCC approval.
  • Senior executive officer candidates for an open position, subject to certain conditions, including board approval and a QCA.
  • M&A counterparties under 12 CFR 5.33, subject to conditions. This will permit deal parties to share sensitive regulatory information during due diligence.
  • S.-based attorneys, consultants and advisors working on a transaction may receive CSI once counterparty-disclosure conditions are satisfied. Foreign-based advisers remain subject to prior approval.
  • Trade associations and nonprofits may receive anonymized CSI for aggregated publication or member advocacy, subject to a QCA and a discrete, time-limited written agreement.

Materials that do not constitute CSI (i.e., information an institution created for its own business purposes, not prepared in response to OCC supervisory or enforcement activity, and not constituting supervisory feedback) fall entirely outside the proposal’s restrictions. This carve-out is important for institutions assessing what actually triggers disclosure obligations.

The NPRM also introduces a notice-and-objection procedure for sharing CSI with the Federal Reserve, FDIC, and other federal agencies. Institutions would notify the OCC and, absent an objection within 15 days (30 days for non-Fed/FDIC agencies), could proceed.

  1. Removal of Criminal Penalty References

The proposal eliminates the current rule’s express suggestion that unauthorized NPOI disclosure may constitute a federal crime under 18 U.S.C. § 641. The OCC states it would not expect to refer unauthorized disclosures to DOJ for criminal prosecution except in extraordinary circumstances.

This is a meaningful development, as the criminal penalty reference has historically played a role in how institutions and counsel approach NPOI issues, including in the context of government investigations, where disclosure to co-regulators or in response to subpoenas raise complex questions that need navigation. While removing the reference does not eliminate the OCC’s ability to make a DOJ referral where warranted, it signals that inadvertent or good faith disclosure generally will not result in criminal prosecution.

A Word of Caution

Even without the threat of criminal penalties for improper disclosure, NPOI—and particularly CSI—remains highly confidential.  The OCC expressly noted in the NPRM that its administrative and civil enforcement mechanisms would remain available, which misuse of NPOI for financial gain, such as through insider trading, may be independently unlawful under antifraud statutes.  Paradoxically, expanding the universe of permissible disclosures, and increasingly relying on banks’ contractual confidentiality arrangements to govern those disclosures, could require banks to exercise greater vigilance over how recipients handle NPOI.  For example, if a third party receiving CSI in connection with a possible merger were to misuse that information to profit from an unrelated transaction, the OCC could closely  scrutinize whether the bank maintained reasonable controls governing the disclosure, safeguarding and permitted use of that information.

Comment Period

Comments are due 60 days after publication in the Federal Register. Institutions and industry groups should consider engaging, particularly on the scope of the QCA requirements, the foreign-advisor restriction, and whether additional exceptions should be incorporated in the final rule, which the OCC has indicated it is open to.

This post is as of the posting date stated above. Sidley Austin LLP assumes no duty to update this post or post about any subsequent developments having a bearing on this post.