# OCC Rules Regarding the Availability of OCC Information

> Briefs, arguments, decisions, and more.

URL: https://www.frixlaw.com/law-library/documents/fr%3A2026-15867

## Record

- **Collection:** Federal Register
- **Document type:** Proposed Rule
- **Published:** August 5, 2026
- **Citation:** 91 FR 50610

## Text

DEPARTMENT OF THE TREASURY
Office of the Comptroller of the Currency
12 CFR Parts 4, 5, 7, 21, and 163
[Docket ID OCC-2026-0133]
RIN 1557-AF50
OCC Rules Regarding the Availability of OCC Information

AGENCY:

Office of the Comptroller of the Currency, Treasury.

ACTION:

Notice of proposed rulemaking.

SUMMARY:

The Office of the Comptroller of the Currency (OCC) is proposing changes to its rules on information disclosure. The proposal would clarify the process for obtaining OCC approval to disclose non-public OCC information and allow for the disclosure of confidential supervisory information without OCC approval in certain circumstances, provided that applicable safeguards are observed. It also refines the OCC's process for requesting records under the Freedom of Information Act (FOIA), amends the rules to provide for expedited process of FOIA requests, and makes other structural and conforming changes.

DATES:

Comments must be received on or before October 5, 2026.

ADDRESSES:

Commenters are encouraged to submit comments through the Federal eRulemaking Portal. Please use the title “OCC Rules Regarding the Availability of OCC Information” to facilitate the organization and distribution of the comments. You may submit comments by any of the following methods:

•
Federal eRulemaking Portal—Regulations.gov:

Go to
https://regulations.gov/.
Enter Docket ID “OCC-2026-0133” in the Search Box and click “Search.” Public comments can be submitted via the “Comment” box below the displayed document information or by clicking on the document title and then clicking the “Comment” box on the top-left side of the screen. For help with submitting effective comments, please click on “Commenter's Checklist.” For assistance with the
Regulations.gov
site, please call 1-866-498-2945 (toll free) Monday-Friday, 9 a.m.-5 p.m. ET, or email
regulationshelpdesk@gsa.gov.

•
Mail: Chief Counsel's Office,
Attention: Comment Processing, Office of the Comptroller of the Currency, 400 7th Street SW, Suite 1E-216, Washington, DC 20219.

•
Hand Delivery/Courier:
400 7th Street SW, Suite 1E-216, Washington, DC 20219.

Instructions:
You must include “OCC” as the agency name and Docket ID “OCC-2026-0133” in your comment. In general, the OCC will enter all comments received into the docket and publish the comments on the
Regulations.gov
website without change, including any business or personal information provided such as name and address information, email addresses, or phone numbers. Comments received, including attachments and other supporting materials, are part of the public record and subject to public disclosure. Do not include any information in your comment or supporting materials that you consider confidential or inappropriate for public disclosure.

You may review comments and other related materials that pertain to this action by the following method:

•
Viewing Comments Electronically—Regulations.gov:

Go to
https://regulations.gov/.
Enter Docket ID “OCC-2026-0133” in the Search Box and click “Search.” Click on the “Documents” tab and then the document's title. After clicking the document's title, click the “Document Comments” tab. Comments can be viewed and filtered by clicking on the “Sort By” drop-down on the right side of the screen or the “Refine Results” options on the left side of the screen. Supporting materials can be viewed by clicking on the “Documents” tab. Click on the “Sort By” drop-down on the right side of the screen or the “Refine Documents Results” options on the left side of the screen by checking the “Supporting & Related Material” checkbox. For assistance with the
Regulations.gov
site, please call 1-866-498-2945 (toll free) Monday-Friday, 9 a.m.-5 p.m. ET, or email
regulationshelpdesk@gsa.gov.

The docket may be viewed after the close of the comment period in the same manner as during the comment period.

FOR FURTHER INFORMATION CONTACT:

Sadia A. Chaudhary, Special Counsel, or Joanne Phillips, Special Counsel, Chief Counsel's Office, (202) 649-5490, Office of the Comptroller of the Currency, 400 7th Street SW, Washington, DC 20219. If you are deaf, hard of hearing or have a speech disability, please dial 7-1-1 to access telecommunications relay services.

SUPPLEMENTARY INFORMATION:

I. Background and Policy Objectives

A. Background

The Office of the Comptroller of the Currency (OCC) creates and obtains a wide range of information in connection with the performance of its responsibilities to charter, regulate, and supervise national banks, Federal savings associations, and Federal branches and agencies of foreign banks (collectively, banks). Under the Freedom of Information Act (FOIA)
1

and the agency's current implementing rule found in subpart B of 12 CFR part 4, some of this information is required to be disclosed to the public upon request. Other information is generally exempt from disclosure, such as the supervisory conclusions that the agency reaches about the banks it supervises. To ensure that this exempt information is protected, the OCC's current regulatory framework in subpart C of 12 CFR part 4 governs its disclosure by the agency, its supervised entities, and others.
2

1
5 U.S.C. 552.

2
For purposes of this rulemaking, a supervised entity includes a bank, bank subsidiary, Federal branch or agency of a foreign bank, and any other entity supervised by the OCC.

Currently, subpart C applies to non-public OCC information (NPOI), which is information created or obtained by the OCC in the performance of its duties, such as reports of examination (ROE), supervisory correspondence, and information related to enforcement actions. Under the current subpart C, a supervised entity may disclose NPOI only with OCC prior approval, subject to specified exceptions.
3

Moreover, the current subpart C suggests that a person who engages in the unauthorized disclosure or use of NPOI may be subject to criminal penalties.

3
The exceptions can be found at 12 CFR 4.37(b)(2).

B. 2024 FOIA Proposal

In 2024, the OCC issued a notice of proposed rulemaking to amend the agency's current subpart B.
4

The proposal would have provided for expedited processing of FOIA requests and established procedures for a requestor to appeal a denial of an expedited processing or fee waiver request. The proposal also would have removed the competitive harm standard for information provided to the government on an involuntary basis and made a conforming amendment to ensure that the OCC's regulations were consistent with the FOIA and authoritative case law.

4
89 FR 13289 (Feb. 22, 2024).

The OCC received and reviewed five comments on the 2024 proposal but did not finalize it. Some of the changes proposed herein address amendments included in the 2024 proposal.
5

5

See
the discussion below of proposed § 4.16(d) and (e) and § 4.20.

C. Overview of Proposal

Based on its supervisory experience, the OCC believes that the current NPOI disclosure framework in subpart C hampers a supervised entity's ability to effectively manage its operations by significantly limiting its ability to share information in legitimate situations, such as in negotiating a business combination or with an affiliate. Subpart C's restrictive and one-size-fits-all approach to categorizing information and controlling its disclosure fails to account for the type of NPOI at issue, the context in which disclosure is sought, and the intended recipients of the information. Further, it hinders government accountability by limiting the public's access to information that is necessary to understand how the OCC supervises and ensures supervised entities' safe and sound operations. In addition, the OCC has observed that the current framework, including the broad definition of NPOI and reference to criminal penalties, has had a chilling effect on supervised entities' willingness to make independent determinations about what is covered by subpart C and to seek the OCC's approval to disclose NPOI. Moreover, the reference to criminal penalties may be contrary to controlling legal authorities and plainly falls outside of the OCC's enforcement authorities.

To address these concerns, the OCC proposes substantive changes to establish a more nuanced approach to the agency's NPOI disclosure framework that allows for greater disclosure of NPOI, particularly as it relates to supervised entities and government agencies, while continuing to provide appropriate safeguards to protect the information. Specifically, the proposal codifies and incorporates a definition of “confidential supervisory information” (CSI) as a subset of NPOI.
6

It would permit a supervised entity to disclose CSI without OCC prior approval in six situations, each of which describes (1) to whom the CSI would be disclosed to (
e.g.,
an affiliate or counterparty); (2) the context of the disclosure (
e.g.,
negotiating a business combination transaction or hiring a new senior executive officer); and (3) any applicable safeguards (
e.g.,
the recipient has signed a qualified confidentiality agreement or the CSI is used only for purposes of due diligence). The proposal also clarifies when a supervised entity can share CSI with Federal agencies.

6
References to NPOI in the proposal include both non-CSI NPOI and CSI, unless the context indicates otherwise.

For CSI not covered by the six situations and NPOI that is not CSI (non-CSI NPOI), the proposal clarifies that the current disclosure framework, under which the OCC decides on a case-by-case basis whether to permit disclosure and, if so, any applicable safeguards. The proposal would also remove the reference in current part 4 to criminal penalties, add expedited processing procedures for information requests under the FOIA, and make technical, streamlining, and conforming changes. As a whole, this rulemaking would represent a significant change to the current information disclosure framework for CSI, which the OCC believes is necessary and appropriate for the reasons discussed below, as well as an effort to streamline and clarify the OCC's overall information disclosure framework.

D. Major Policy Considerations

One of the OCC's primary goals in this rulemaking is to adjust the relative weight that the current disclosure rules accord to the goals of maintaining the confidentiality of NPOI and permitting its disclosure in a variety of situations. The current framework generally over prioritizes confidentiality relative to other interests, including a supervised entity's business need to disclose information and to whom. It also accords insufficient weight to the compelling supervisory and governmental goals that a more permissive disclosure framework would advance, such as engendering confidence in the financial system and providing the transparency necessary to hold the agency accountable.

In considering a recalibration of the balance between confidentiality and limited disclosure, however, the OCC recognizes that its effective supervision requires a candid exchange of information with and between supervised entities and others. To create an environment conducive to these exchanges, all parties must be confident that NPOI will be protected from inappropriate disclosure. Unfettered or inadequately controlled disclosure could present a wide range of risks. Those risks include implicating a supervised entity's financial condition, including by driving away customers, investors, and business partners and potentially leading to bank runs, and the OCC's ability to ensure its safety and soundness. This concern would chill the OCC's ability to provide meaningful criticism to its supervised entities that is crucial for remediation of weaknesses and would make supervised entities apprehensive about openly sharing information with the OCC that could be led to a negative reaction by the public were it to become widely known.

To help address the challenges associated with the current disclosure rule, the OCC proposes a two-tiered disclosure framework. This framework would recognize that CSI and non-CSI NPOI are materially different types of information and the situations in which a supervised entity or government agency may want to disclose them may materially differ. Specifically, the proposed framework would provide supervised entities with greater flexibility to disclose CSI in a variety of situations, subject to tailored safeguards. The agency believes that this flexibility would more appropriately balance the costs and benefits of protecting the confidentiality of NPOI and permitting its limited disclosure, while also advancing important supervisory and governmental objectives.

Another important goal of this proposal is to align the OCC's NPOI disclosure framework with relevant case law developments and the Administration's policy against the overcriminalization of Federal laws
7

(particularly for regulatory offenses). The OCC is concerned that the reference in current subpart C to the criminal penalties for the unlawful use or disclosure of NPOI in violation of 18 U.S.C. 641 (
i.e.,
a fine or prison) inappropriately chills lawful disclosure.
8

Among other things, the OCC is hopeful that by removing the reference to potential criminal liability, supervised entities' disclosure will no longer be inappropriately chilled.

7

See, e.g.,
Executive Order 14294, “Fighting Overcriminalization in Federal Statutes” (May 9, 2025).

8
Section 641 states that a person (1) who embezzles, steals, purloins, or knowingly converts to his use or the use of another, or without authority, sells, conveys or disposes of (A) any record, voucher, money, or thing of value of the United States (or department or agency thereof); or (B) any property made or being made under contract for the United States (or department or agency thereof); or (2) who receives, conceals, or retains the same with intent to convert it to his use or gain, knowing it to have been embezzled, stolen, purloined or converted, shall be subject to fine or imprisonment.

In addition, the U.S. Department of Justice (DOJ) has jurisdiction for violations of section 641 (not the OCC), and recent case law calls into question when misappropriation of NPOI would be prosecuted by the DOJ under section 641.
9

In light of these developments, the

OCC does not want to create or perpetuate a misimpression about the depth or breadth of criminality for unauthorized disclosure of NPOI and, thus, proposes to remove this reference from the rule. Nevertheless, while the OCC would not expect to refer the unauthorized disclosure of NPOI to the DOJ for criminal prosecution absent extraordinary circumstances, removing the section 641 reference would not preclude the OCC from referring a matter to the DOJ where appropriate, after which the DOJ would decide whether to pursue a criminal matter.
10

9

See Kelly
v.
United States,
590 U.S. 391 (2020);
United States
v.
Blaszczak,
56 F.4th 230 (2d Cir. 2022).
See also
Br. on Remand for the Unites States at 7,
Blaszczak, supra,
Dkt. No. 453 (“In light of the Supreme Court's holding in
Kelly,
it is now the position of the [DOJ] that in a case involving confidential government information, that

information typically must have economic value in the hands of the relevant government entity to constitute `property' for purposes of 18 U.S.C. 1343 and 1348. . . . A related, though not necessarily identical, analysis applies when determining what confidential information is a `thing of value' under 18 U.S.C. 641.”); Resp. to Letter Br. at 7,
Blaszczak, supra,
Dkt. No. 497 (“Although `[c]onfidential business information has long been recognized as property,
Kelly
and
Cleveland
make clear that information cannot be deemed `business' information when the `business' is a regulatory function . . . that is governmental in nature and has no private analogue. Unlike confidential news material or stock-trading statistics, which have inherent market value to their owners. . . . [t]he [property] at issue here [has] value to the government only as a regulator, not `as a property holder.' ” (internal citations omitted)).

10
By removing the reference to section 641, the OCC does not intend to augment or modify its use of its enforcement mechanisms, under 12 U.S.C. 1818 or otherwise. Furthermore, removing this reference would not obviate the agency's obligation to report certain matters to the U.S. Department of the Treasury (Treasury) or the Office of the Inspector General (
e.g.,
unauthorized disclosure of NPOI by an OCC employee). The OCC also will remove references to section 641 from other agency issuances, such as bulletins and ROEs.

E. Feedback on Current Regulatory Framework

In addition to the insight that the OCC has gained through its supervisory experience, the agency has received feedback directly from stakeholders about the current NPOI disclosure framework, including through the Economic Growth and Regulatory Paperwork Reduction Act of 1996 (EGRPRA) process.
11

For example, two EGRPRA commenters discussed the need for supervised entities to share CSI during the due diligence process for certain corporate transactions, subject to confidentiality safeguards. One commenter supported allowing supervised entities in formal negotiations regarding a business combination to share CSI with its proposed counterparties and their advisors on a “need to know” basis, subject to confidentiality safeguards. Another commenter supported a framework that would require OCC prior approval to disclose CSI, if approval were readily obtainable through an established, uniform, and expeditious process.

11
12 U.S.C. 3311.

Stakeholders have also provided feedback directly to the OCC, Board of Governors of the Federal Reserve System (Board), and Federal Deposit Insurance Corporation (FDIC) to convey that the current CSI framework makes it difficult for supervised entities to address regulators' supervisory concerns. They also noted its negative impact on bank partnerships, particularly for community banks, and explained that these partnerships can provide consumers and small businesses in rural and underserved markets with access to digital tools, lower-cost loans, and tailored products that might not otherwise be available. This feedback provided to the OCC through its outreach and stakeholder engagement during the supervisory process helped to inform this proposal.

II. Description of Proposal

The proposed rule combines current subparts B and C into a new subpart B and includes revisions to the disclosure of both NPOI and information under the FOIA. Proposed §§ 4.10 through 4.14 generally replace components of current subpart C and incorporate a clearer more detailed approach to the agency's NPOI disclosure. Proposed §§ 4.15 through 4.24 (1) replace current subpart B, while also streamlining, conforming, and clarifying the agency's administration of the FOIA rule; and (2) include certain process-related provisions in current subpart C.

The OCC also proposes to make conforming edits to 12 CFR parts 5, 7, 21, and 163 by revising section references within those parts that would change as a result of this proposed rule.

Section-by-Section Discussion

1. Proposed § 4.10, Purpose and Scope

Proposed § 4.10 sets out the purpose and scope of the new subpart. The proposed purpose statement is based on the purpose statements in current subparts B and C (§§ 4.11(a) and 4.31(a), respectively). The proposed purpose statement includes substantive revisions to reflect the new NPOI disclosure framework, along with certain other non-substantive and conforming changes. The proposed purpose statement would recognize additional considerations that the subpart is attempting to weigh. For example, the proposed purpose statement would recognize supervised entities' interest in efficient disclosure of CSI without a request when necessary or appropriate for a business purpose or other purpose enumerated in the purpose statement.

The proposed scope provision is based on the scope provisions in current subparts B and C (§§ 4.11(b) and 4.31(b), respectively). It describes the types of information that are not within the new subpart's scope and, therefore, to which the new subpart does not apply.
12

The OCC believes that by clarifying the information that is not subject to the new subpart, the agency facilitates stakeholders' ability to determine the appropriate disclosure framework for any information.

12
Under the proposal, suspicious activity reports (SAR) information would continue to be excluded from Part 4.

2. Proposed § 4.11, Definitions

Proposed § 4.11 defines certain terms used in new subpart B, setting forth a common lexicon and promoting consistency and clarity.
13

It includes (1) newly defined terms; (2) revisions to definitions of terms defined in current § 4.32; and (3) defined terms where the OCC is not proposing any substantive changes. This section-by-section discussion focuses on the newly defined terms and revisions to current definitions; existing definitions that are substantively unchanged are not discussed below.

13
However, certain terms defined in current subpart B (
e.g.,
at 12 CFR 4.17) are included in proposed § 4.23 (fees for requesting information under the FOIA).

Affiliate
and
control.
The OCC proposes to define both of these terms in a manner substantively consistent with their meanings in the Bank Holding Company Act (12 U.S.C. 1841(k)).
14

Accordingly, affiliate would mean a person that controls, is controlled by, or is under common control with another company and includes any employee, officer, director, or agent thereof. An affiliate of a branch or agency of a foreign bank would include the foreign bank. Control would mean (1) the person directly or indirectly or acting through one or more other persons owns, controls, or has power to vote 25 percent or more of any class of voting securities of the supervised entity; (2) the person controls in any manner the election of a majority of the directors or trustees of the supervised entity; or (3) the OCC determines, after notice and an opportunity for a hearing, that the person directly or indirectly exercises a controlling influence over the

management or policies of the supervised entity. This definition provides internal consistency because the proposed definition of affiliate uses the term and concept of control. The OCC believes these proposed definitions are well understood and appropriate for the scope and content of this proposal.
15

14
While the proposed definitions of affiliate and control are consistent with their definitions in the Bank Holding Company Act, the OCC would retain interpretive authority with respect to these definitions for purposes of proposed 12 CFR part 4. The OCC would generally expect to interpret the meaning of these terms consistent with their meanings in 12 CFR part 225 as of the date of this issuance.

15

See
the discussion below of proposed § 4.14(b)(1)(i) for an additional explanation of the use of the term “affiliates.”

Confidential supervisory information (CSI).
The OCC proposes to define this term by cross-reference to proposed § 4.12(b), which sets forth a complete description of CSI and its disclosure under the new subpart.

Demand.
The OCC proposes to define this term as a written request, subpoena, order, motion to compel, civil investigative demand, search warrant, or other judicial or administrative process to provide information covered by proposed subpart B. This term is intended to not require a formalistic request but operate functionally and include, for example, a supervisory request from another Federal banking agency or a State banking regulator.

Disclose.
The OCC proposes to define this term as directly or indirectly making information available in any manner, including any action or inaction that causes or permits access to the information. The OCC expects that this definition would provide clarity and consistency about what constitutes a disclosure and prevent evasion of the limitations on disclosure set forth in the new subpart.

Government agency.
The OCC proposes to define this term as an agency of the Federal government (other than the OCC or the Office of Thrift Supervision (OTS)) or of any State, Tribal, or foreign government and any person officially connected with the agency, such as its employee, officer, director, or agent. This definition includes Federal agencies with which the OCC has historically shared information, as well as other Federal or State government agencies with which the OCC may share information, including under its rule implementing the Guiding and Establishing National Innovation for U.S. Stablecoins Act (GENIUS Act) (12 U.S.C. 5901
et seq.
).
16

16
The OCC's proposal to implement the GENIUS Act can be found at 91 FR 10202 (Mar. 2, 2026).

Nonexempt information.
Whereas the FOIA uses the term “exempt” to identify information that may be withheld from disclosure under that statute, the OCC proposes to define the term “nonexempt” as information that the agency would not withhold under the FOIA. This would distinguish (1) NPOI, which falls within a FOIA exemption and is therefore “exempt” from disclosure under FOIA; and (2) information that does not fall within a FOIA exemption and is therefore
not
exempt from disclosure under FOIA (
i.e.,
“nonexempt” information).

Non-public OCC information (NPOI).
The OCC proposes to define this term as a record (or portion thereof) that the OCC may withhold under the FOIA. This definition of NPOI is substantively consistent with the definition of this term in the current rule at § 4.32(b)(1) and reflects documents that the OCC would generally withhold from disclosure. In addition, the proposal would state that notwithstanding the above, NPOI does not include final orders, amendments, or modifications of final orders or other actions or documents that are specifically required to be published or disclosed to the public pursuant to 12 U.S.C. 1818(u) or 12 U.S.C. 2906 or that the OCC is specifically required to publish, publicly disclose, or otherwise make available to the public pursuant to other applicable laws or rules.

For example, a consent order not yet fully executed by the OCC and a supervised entity is NPOI and may not be released by the supervised entity until the order is executed, at which point the public consent order would no longer be NPOI. Finally, whereas § 4.32(b)(2) states that NPOI is the property of the OCC, proposed § 4.13(d) states that NPOI is the OCC's property only to the extent that it is in the agency's possession. This distinction is addressed more fully below in the discussion of proposed § 4.13(d)(1)(i).

By proposing to define CSI, nonexempt information, and NPOI, the rule would enable a stakeholder to readily identify the disclosure provisions that apply to any piece of information. In addition, the proposed definition of NPOI is intended to serve as a counterpoint to the proposed definition of nonexempt information. By specifically referencing the FOIA, the NPOI definition would incorporate the exemptions and exclusions in the FOIA, as interpreted by the agency and the courts. The OCC is soliciting comment regarding whether the proposed definitions of CSI and NPOI are appropriate.

Person.
The OCC proposes to define this term as an individual, company, trust, joint venture, pool, syndicate, sole proprietorship, unincorporated organization, or any other form of entity (but to not include the OCC or OTS). This proposed definition is intended to provide clarity and consistency in the new subpart B. In the proposal, the agency sometimes uses a more specific term than person when it either intends to limit or emphasize the applicability of a provision to a subset of persons. The reference to any other form of entity in conjunction with the term person is intended to ensure that the definition has an expansive reach.

Predecessor agency.
The OCC proposes to define this term with respect to the OCC to mean the OTS, Federal Home Loan Bank Board, or any other predecessor to these agencies.

Qualifying confidentiality agreement.
The OCC proposes to define this term by cross-reference to the more complete description and discussion of the term in proposed § 4.14(c).

Record.
The OCC proposes to define this term by cross-reference to the definition in the FOIA at 5 U.S.C. 552(f)(2).

Service provider.
The OCC proposes to define this term as an unaffiliated person (including an employee, officer, director, or agent of the person) that is hired by or partnered with a supervised entity to perform specific, specialized functions for or on behalf of the entity related to the supervised entity's operations or provision of services. This term would include persons performing consulting, legal, and auditing services if the elements of the definition are satisfied. This definition would not include customers or financial counterparties. This is because, in the OCC's experience, these general contractual relationships typically do not involve persons that (1) perform specific, specialized functions for or on behalf of a supervised entity that are related to the entity's operations or otherwise provide services to the supervised entity; and (2) have historically demonstrated a business need for NPOI. This definition is informed by the OCC's supervisory experience with respect to banks' service providers, including its review of corporate transactions and application of the third-party risk management guidance.
17

Based on that experience, the OCC concluded that the current provisions that address the concept of “service provider” are too narrow to capture the appropriate range of service providers.
18

Disclosure of CSI to service providers is described below in the section-by-section discussion of proposed § 4.14(b)(1)(ii). The OCC is seeking comment on the proposed

definition of service provider and is considering alternative definitions, as described below.

17
Interagency Guidance on Third-Party Relationships: Risk Management, 88 FR 37920 (June 9, 2023).

18
The current rule does not define the term “service provider,” but instead includes within certain substantive provisions persons that would meet the definition under the proposed subpart.

Supervised entity.
The OCC is proposing to revise the current definition of this term to include any permitted stablecoin issuer or foreign payment stablecoin issuer for which the OCC has regulatory or enforcement authority pursuant to the GENIUS Act. Under the GENIUS Act, Congress expanded the OCC's regulatory or enforcement authority to include these entities, and the proposed revisions would ensure that new subpart B applies to these entities. The proposed definition would also incorporate any individual officially connected with a supervised entity, such as its employee, officer, director, or agent thereof. The proposed revisions would also streamline new subpart B by negating the need to repeatedly reference the individuals officially connected to a supervised entity when discussing the entity.

The definition of “supervised entity” is intended to be read broadly, as evidence by the inclusion of the phrase “any other entity supervised by the OCC,” and to include such entities as service providers subject to OCC examination authority under the Bank Service Company Act.
19

19
12 U.S.C. 1867.

Testimony.
The OCC is proposing to revise the definition of “testimony” to mean a transcribed interview or a sworn statement regardless of it being provided orally or in writing and regardless of it being provided before a court, another tribunal, or another officer (
e.g.,
at a deposition). The proposed definition would clarify the meaning of the term, which does not depend on the location of an activity. In addition, the proposed definition would include certain technical and conforming changes.

Unusual circumstances.
The OCC is proposing to add a definition of this term and defined it by cross reference to its definition in the FOIA at 5 U.S.C. 552(a)(6)(B)(iii). The proposed definition would clarify when, in order to reasonably and properly process a FOIA request, it is necessary (1) to search for and collect the requested records from field facilities or other establishments that are separate from the office processing the request; (2) to search for, collect, and appropriately examine a voluminous amount of separate and distinct records which are demanded in a single request; or (3) for a consultation, which shall be conducted with all practicable speed, with another agency having a substantial interest in the determination of the request or among two or more components of the agency having substantial subject-matter interest therein. This proposed definition would (1) ensure that this term of art is used in a manner that is consistent with its use in the FOIA; and (2) provide internal consistency in the NPOI disclosure provisions that address similar considerations.

In addition to the definitions discussed above, the proposal would carry forward two definitions in current § 4.32 with technical and conforming revisions: (1) “complete request;” and (2) “show a compelling need.”

3. Proposed § 4.12, Disclosure of OCC Information in General; Categories of OCC Information

Proposed § 4.12 addresses information disclosure in general and discusses the categories of information addressed in the proposal.

a. General

Proposed § 4.12(a) provides that the OCC (1) will disclose nonexempt information as provided in proposed § 4.16 and the FOIA; and (2) will not disclose NPOI except as provided in this subpart or as otherwise required by law.
20

20
Information disclosure is also subject to other applicable law, including the Gramm-Leach-Bliley Act (GLBA), also known as the Financial Services Modernization Act of 1999, Public Law 106-102, 113 Stat. 1338 (Nov. 1999) and the Right to Financial Privacy Act (RFPA), Public Law 95-630, 92 Stat. 3697 (Nov. 10, 1978). For example, the disclosure of CSI that contains a customer's personally identifiable information (PII) would be subject to applicable laws, including GLBA and RFPA, on the disclosure of PII.

b. Confidential Supervisory Information

Proposed § 4.12(b) discusses CSI. Section 4.12(b)(1) explains that CSI is a subset of NPOI that is exempt from disclosure under either (1) FOIA Exemption 5 (5 U.S.C. 552(b)(5)) (privileged interagency or intra-agency memoranda or letters) in connection with the bank examination privilege; or (2) FOIA Exemption 8 (5 U.S.C. 552(b)(8)) (information contained in or related to certain examination, operating, or condition reports concerning financial institutions, which is commonly known as the bank examination exemption).
21

Proposed § 4.12(b)(2) sets out four examples of CSI: (1) a record created or obtained by the OCC or OTS in connection with the performance of its responsibilities (
e.g.,
a record concerning supervision, licensing, regulation, and examination of a supervised entity); (2) a record compiled by either agency in connection with its enforcement responsibilities; (3) an ROE, supervisory correspondence, agency investigatory file, and any internal agency memorandum (whether in the possession of the OCC or any other person); and (4) sworn statement or deposition testimony from a current or former employee, officer, or agent of the OCC or OTS concerning information acquired by that person in the course of his or her performance of official agency duties or due to his or her official status at the agency. These four examples are listed in current § 4.32(b)(1) as examples of NPOI but are referred to colloquially as CSI.

21
Courts have identified two purposes underlying the application of the FOIA bank examination exemption. The first purpose is to “ensure the security of financial institutions” by preventing runs on banks from the disclosure of sensitive exam-related information.
Leopold
v.
Dep't of Just.,
628 F. Supp. 3d 275, 286 (D.D.C. 2022) (noting that main purpose of FOIA exemption (b)(8) is to prevent “release of examination reports [that] `might undermine public confidence and cause unwarranted run on banks'”). The second purpose is “to safeguard the relationship between the banks and their supervising agencies.”
Fagot
v.
FDIC,
584 F. Supp. 1168, 1173 (D.P.R. 1984) (recognizing as a secondary purpose the need “to provide banks and financial institutions supervised by the federal government sufficient assurance of confidentiality to promote full cooperation with the regulatory agencies”).
See also Consumers Union of U.S., Inc.
v.
Heimann,
589 F.2d 531, 533 (D.C. Cir. 1978). Further, matters that are “related to” ROEs have been found to include real-time information about the status of financial institutions.
Williams & Connolly LLP
v.
Off. of the Comptroller of the Currency,
39 F. Supp. 3d 82, 90 (D.D.C. 2014) (concluding that the “related to” language in FOIA exemption (b)(8) “casts a wide net of non-disclosure over any documents that are logically connected to an `examination, operating, or condition report”).

There are two other examples of NPOI in the current rule that the OCC does not include in the proposed description of CSI. First, § 4.32(b)(1)(iv) of the current rule states that confidential OCC information obtained by or incorporated into the records of a third party (including a government agency) is an example of NPOI. The OCC did not include this example in the proposed definition of CSI because this type of information does not always meet the definition of CSI and, therefore, it should be assessed on a case-by-case basis. For instance, confidential information disclosed by the OCC to another government agency about the OCC's financial condition is NPOI but not CSI.

Second, § 4.32(b)(1)(vi) of the current rule describes confidential information related to operating and no longer operating banks and related persons as an example of NPOI. The OCC did not include this provision because it is not an example of a type of information but rather establishes that the status of information (
e.g.,
whether certain

information is CSI, non-CSI NPOI, or nonexempt under FOIA) does not depend on the operating status of the entity to which it relates. For example, an ROE about a bank is CSI regardless of whether the bank is still in operation. (The concept that the status of information is not tied to the operating status of an entity is addressed below in the discussion of proposed § 4.13(d)(2)(ii)).

The proposal also describes types of information that would be excluded from the definition of CSI. Proposed § 4.12(b)(3) states that, notwithstanding proposed § 4.12(b)(1), CSI does not include information created or collected by a supervised entity for its own business purposes if the information (1) is in the supervised entity's own possession; (2) was not prepared for the OCC, Board, FDIC, or the Consumer Financial Protection Bureau (CFPB) in response to the applicable agency's supervisory or enforcement activities; and (3) is not supervisory feedback from the OCC, Board, FDIC, or CFPB or information on the enforcement activities of these agencies or a summary of such information. This exclusion is intended to clarify that the supervised entity's mere sharing of its business information with the OCC does not impose on the supervised entity the OCC's CSI restrictions on the information. For example, a national bank's business plan located on the bank's computer system would likely satisfy the three elements above and, therefore, the bank computer system-stored business plan would not be CSI. But, if the bank shares a copy of the business plan with the OCC in connection with a supervisory activity, the business plan would be CSI because of the context in which the supervised entity shared the information.
22

This means that the same business plan can be both CSI, when in the possession of the OCC, and not CSI, when in the possession of the supervised entity.

22

See, e.g.,
proposed 12 CFR 4.13(d)(1)(i).

The proposed exclusion from the meaning of CSI also includes provisions focused on the purpose for which the information was created or collected and whether it reflects certain supervisory feedback. These proposed provisions are intended to ensure that information that is created or collected in connection with the regulatory or supervisory activities of the Federal banking agencies and the CFPB is CSI even though similar information created or collected for a supervised entity's own business purposes is not. The OCC included the Board, FDIC, and CFPB in the exclusion because, in the OCC's experience, information may be prepared in response to the supervisory or enforcement activities or contain supervisory feedback from more than one of these agencies.
23

The OCC invites comment on whether this exclusion should be limited to the OCC or expanded to include other regulators (
e.g.,
the U.S. Securities and Exchange Commission (SEC)).

23
This proposed provision would apply to an agency as defined in 5 U.S.C. 551(1), other than the Board.

c. Non-Public OCC Information and Confidential Supervisory Information Obtained by Third Parties

Proposed § 4.12(c) confirms that NPOI, including CSI, that is obtained by or incorporated into the records of a third party (including a government agency) remains NPOI or CSI, as applicable, regardless of how the information was obtained. This provision would ensure that information covered by proposed subpart B remains covered regardless of whether it is incorporated or disclosed by another person.

4. Proposed § 4.13, Disclosure of Non-Public OCC Information or Confidential Supervisory Information, in General

Proposed § 4.13 addresses the disclosure of all NPOI: CSI and non-CSI NPOI.
24

24
Proposed § 4.13 is based on provisions in current §§ 4.36, 4.37, and 4.38, with substantive revisions.
See e.g.,
current § 4.36(a), (c), and (d); § 4.37(a)(2) and (d); and § 4.38.

a. Unauthorized Disclosure of Non-Public OCC Information Prohibited

Under § 4.37(b) of the current rule, national banks, Federal savings associations, or holding companies (and any director, officer, or employee thereof) are prohibited from sharing NPOI without OCC approval, subject to limited exceptions in § 4.37(b)(2) for sharing, when necessary and appropriate for business purposes, with a person or organization officially connected with the bank or holding company as officer, director, employee, attorney, auditor, independent auditor, or (in some cases) a consultant.
25

Proposed § 4.13(a)(1)(i) sets forth the general rule, derived from the current rule, that CSI may not be disclosed except (1) when otherwise permitted by new subpart B; (2) with prior OCC approval; or (3) when the disclosure is in published statistical material or an anonymized anecdote that does not disclose, either directly or indirectly, the affairs of any person. By qualifying the general prohibition on the disclosure of CSI with these three exceptions, this proposed provision clarifies and increases the disclosure of CSI compared to the current framework, while continuing to protect its confidentiality as appropriate. The details of how the agency proposes to strike this balance are set forth below.

25
The exceptions can be found at 12 CFR 4.37(b)(2).

Proposed § 4.13(a)(1)(ii) makes clear that non-CSI NPOI is not subject to restrictions on disclosure unless and to the extent that the OCC imposes conditions on further disclosure.
26

This provision would ensure that conditions or limitations that the OCC imposes when it discloses NPOI are not lost simply because the information is further disclosed.
27

(The OCC's authority to apply conditions and limitations on disclosure of NPOI is described in the discussion of proposed § 4.13(c)(1).)

26
The OCC retains, however, its authority to control or impose limitations on the subsequent use and disclosure of NPOI in the possession of another person under proposed § 4.13(f). Should the OCC subsequently exercise its authority to condition further disclosure of NPOI, future disclosures would be subject to applicable conditions. Further, if the OCC imposes conditions or limitations on NPOI after the initial disclosure because it determines that the person with access to or disclosing the information was doing so for reasons other than the purpose provided in the relevant provision or otherwise in contravention of the objectives of this subpart, the OCC may order the cessation of use of the NPOI, or its return to the OCC or destruction pursuant to proposed § 4.13(a)(3).

27
This provision would also mean that a supervised entity is permitted to share information that is excluded from the meaning of CSI under proposed § 4.12(b)(3) (
i.e.,
information in a supervised entity's possession and created for its own business purposes, provided the information meets the other requirements) even if that information continues to be NPOI because it may be withheld under another FOIA exemption. A supervised entity's ability to further disclose NPOI under the proposal is only restricted if the OCC prohibits disclosure of the NPOI as a condition of its disclosure. When a supervised entity is in possession of information excluded from CSI but that remains NPOI, the requirements of § 4.13(a)(2)(ii) would not be met, and, therefore, the supervised entity is not prohibited from further disclosing the information.

Proposed § 4.13(a)(1)(iii) provides that, notwithstanding (a)(1)(i) and (a)(1)(ii), further disclosure of NPOI is permissible in response to a Federal court order in a judicial proceeding in which the OCC had the opportunity to appear and oppose the disclosure. The applicability of this provision would not be contingent on whether the agency availed itself of the opportunity to oppose disclosure.

Proposed § 4.13(a)(2) addresses the disclosure of NPOI by recipients of the information. First, under proposed § 4.13(a)(2)(i), a supervised entity, government agency, or other person

with access to NPOI that is subject to a condition on disclosure may not disclose the information except as authorized by the subpart or the OCC. This provision would clarify that NPOI that is subject to conditions on disclosure remains subject to those conditions regardless of who seeks to disclose it: the conditions on disclosure attach to and travel with the NPOI itself. Second, under proposed § 4.13(a)(2)(ii), a supervised entity, government agency, or other person that obtains unauthorized access to NPOI may not further disclose or make a copy of the information. For example, if the disclosure of NPOI is subject to a condition, an unauthorized recipient may not further disclose the NPOI even in observance of the condition, except as otherwise authorized by this subpart or the OCC. This provision would foreclose a potential claim that a person with unauthorized access to NPOI can disclose the information at will. Both of these provisions are meant to clarify aspects of the current framework.

Under proposed § 4.13(a)(3), if the OCC determines that a supervised entity, government agency, or other person is disclosing NPOI for reasons other than the purpose provided in the relevant provision of this subpart or in contravention of the objectives of this subpart, the OCC can order that (1) use of the disclosed information cease; and (2) the disclosed information to be returned to the OCC or destroyed such that the person no longer has access to the NPOI. This provision would ensure that the OCC can retain appropriate control over NPOI that is disclosed in contravention of the purpose or objectives of the subpart. A person that wishes to disclose NPOI, including CSI, for a purpose other than those addressed in the proposal should seek approval under proposed § 4.17.
28

28
The OCC notes, however, that its authority to require the cessation of use, return, or destruction of NPOI under proposed § 4.13(a)(3) also applies to requests for NPOI under proposed § 4.17, if the NPOI is not used for the approved purpose.

Proposed §§ 4.13(a)(2) and (a)(3) are intended to preserve the OCC's discretion to prevent further disclosure of NPOI or to require the return or destruction of disclosed information in the event that a person inappropriately obtain or misuse NPOI, including under false pretexts, to the detriment of the OCC or supervised entities.

b. Discretionary Disclosure of Non-Public OCC Information by the OCC

Proposed § 4.13(b) addresses the OCC's disclosure of NPOI. Proposed § 4.13(b)(1) permits the OCC to disclose NPOI whenever it determines that disclosure may be necessary or appropriate. Proposed § 4.13(b)(2) addresses disclosing NPOI that is over a certain age, in response to a FOIA request. Specifically, this provision would provide that, in responding to a FOIA request for a record that was created or received 25 or more years before the request, the OCC will not withhold the record on the grounds that it contains NPOI unless the agency determines that a FOIA exemption is applicable and there is good cause to withhold it. Under the proposal, good cause may exist if the OCC determines that disclosure conflicts with the purposes of the subpart or is otherwise prohibited by law. For example, if 30-year old NPOI contains PII, the OCC may determine that good cause exists to withhold disclosure or condition disclosure (under proposed § 4.13(c), discussed below) on redaction of the PII.

This provision is an example of the OCC's recalibration of the appropriate balance between allowing for the limited disclosure of NPOI while protecting its confidentiality. The OCC's rationale for permitting disclosure in this situation is that, after such a long period of time (25 or more years), there is a very low risk that disclosure of the NPOI would chill the necessary candid discussions between, for example, OCC bank examiners and supervised entities. In contrast, as discussed below, disclosure will provide greater transparency about the agency's supervisory approach, which increases trust in the process and is good government.

Disclosure of older CSI also would allow the public, and academics, to better understand the U.S. banking system and the OCC's role in governance of that system. The disclosure of this information to the public would enhance the public's ability to provide meaningful feedback to the agency on its regulatory and governance initiatives and to hold the agency accountable for having a strong, efficient regulatory framework. Increasing public knowledge of the U.S. banking system would further the public's ability to participate in the regulation of that system. Since the information is aged 25 years or more, the disclosure would not implicate the same types of privacy considerations because, after 25 years, most personnel involved in the communications would no longer be employed at their respective entities and most of the concerns, criticisms, and other information shared would no longer be applicable to the institution. Information 25 years old or more should generally not provide potentially insight into the current operations or conditions of a supervised entity such that its competitors could gain unfair advantage or the public would be discouraged from doing business with it. Thus, the OCC believes that disclosure of this aged information would generally not dissuade open communication in the same way that disclosure of current information could. As always, the OCC can place conditions or limitations on any disclosure or prohibit it on a case-by-case basis, under proposed §§ 4.13 and 4.17, respectively.

The OCC is seeking comment on whether it should adopt proposed § 4.13(b)(2). The agency is considering whether the data should be aggregated or anonymized before it is released. The OCC also seeks comment on whether the 25-year age limit is appropriate or whether a different age limit would strike a better balance between protection and transparency.

c. Conditions and Limitations

This provision addresses conditions or limitations on the disclosure of NPOI. Proposed § 4.13(c)(1) states that the OCC may condition or limit the disclosure of NPOI in any way necessary to give effect to the purposes of this subpart. This would enable the agency to more appropriately balance the equities of confidentiality and limited disclosure, including on a case-by-case basis.

Proposed §§ 4.13(c)(2) through 4.13(c)(4) set forth three examples of conditions the OCC may impose, and they carry forward provisions in the current § 4.38 with conforming and technical changes. First, the OCC may condition approval for the disclosure of NPOI on the entry of a protective order in an adversarial matter or a confidentiality agreement in a non-adversarial matter. Second, in a case where a protective order has been entered, the OCC may condition the disclosure of NPOI on the inclusion of additional or amended provisions in the protective order. Third, the OCC may (1) condition its authorization of deposition testimony on the parties' agreement to appropriate limitations, such as keeping a transcript of the testimony under seal or limiting its availability; (2) allow use of a transcript in other litigation; and (3) require that a person who requests to use the transcript in other litigation provide the OCC with a copy of the transcript at his or her personal expense. This example further provides that an OCC employee whose deposition is transcribed does not waive his or her right to review the transcript and note errors. These examples are intended to provide clarity with respect to specific situations.

d. Nature of Non-Public OCC Information

Proposed § 4.13(d) addresses the nature of NPOI in different circumstances: (1) when NPOI is in the OCC's possession; (2) when NPOI is disclosed despite a restriction on disclosure; (3) when CSI is both subject to the bank examination privilege and disclosed; and (4) when CSI pertains to a supervised entity that is no longer operating.

First, proposed § 4.13(d)(1)(i) states that NPOI is the property of the OCC to the extent that it is in the OCC's possession. Among other things, this provision would resolve potential confusion about whether the information exempted from the definition of CSI in proposed § 4.12(b)(3)—because (among other things) it is not in the OCC's possession—is the OCC's property: it is not.
29

This provision would also support the Administration's policy against the overcriminalization of Federal law and is consistent with related case law.

29
As discussed above, proposed § 4.12(b)(3) states that, notwithstanding proposed § 4.12(b)(1), CSI does not include information created or collected by a supervised entity for its own business purposes if the information (1) is in the supervised entity's own possession; (2) was not prepared for the OCC, Board, FDIC, or CFPB in response to the applicable agency's supervisory or enforcement activities; and (3) is not supervisory feedback from the OCC, Board, FDIC, or CFPB or information on the enforcement activities of these agencies or a summary of such information.

Second, § 4.13(d)(1)(ii) would clarify that NPOI remains the OCC's property to the extent the information is restricted from further disclosure under this subpart, regardless of whether it is disclosed to another person. Thus, the OCC would not lose its property rights because a disclosure not in compliance with this subpart occurs. This provision also ensures that the OCC's property rights with respect to particular NPOI are coextensive with the OCC's restrictions on sharing the information, which (as discussed above) may change depending on who is in possession of the NPOI. For example, if the OCC has disclosed CSI (
e.g.,
an ROE) to a supervised entity without conditions limiting the entity's ability to disclose the CSI as permitted under the subpart, then the OCC's property interest in the CSI when in the possession of the supervised entity to which it was disclosed only extends to the OCC's ability to prohibit further disclosure (consistent with proposed subpart B). In that instance, the supervised entity may disclose the CSI to its affiliate, as permitted under proposed § 4.14(b)(1)(i), but not generally. The OCC invites comment on whether the proposal's approach on the extent to which the OCC may assert property rights over NPOI, including CSI, strikes the proper balance between permitting appropriate disclosures and ensuring the OCC has the ability to protect the confidentiality of the information. Are there alternative approaches that would more appropriately strike this balance, such as maintaining OCC property rights (1) for NPOI except when disclosed pursuant to proposed § 4.14; or (2) for all NPOI unless expressly released in response to a request for NPOI under proposed § 4.17?

Third, proposed § 4.13(d)(2)(i) states that, with respect to CSI that is subject to the bank examination privilege, only the OCC can waive that privilege. Therefore, the OCC's or another person's disclosure of CSI is not and should not be interpreted as a waiver of the privilege. Finally, proposed § 4.13(d)(2)(ii) clarifies that CSI remains CSI regardless of whether the supervised entity it relates to is operating or no longer operating.
30

30
As noted above, this provision is based on § 4.32(b)(1)(vi) of the current rule.

e. Duty of Person Served

In this section, the proposal incorporates certain provisions from current § 4.37 that address the duties of a person (other than a current or former OCC or OTS employee) served with a demand for NPOI, with technical and conforming revisions. See the discussion below on proposed § 4.15 for information about the duties of and restrictions on current or former OCC or OTS employees or agents.

f. Intention of OCC Not To Waive Rights

Proposed § 4.13(f) addresses the OCC's rights with respect to NPOI when it is in the possession of another person. Specifically, as proposed, the OCC does not waive its right to control or impose limitations on the use and disclosure of NPOI regardless of the fact that (1) the NPOI is in the possession of a supervised entity, government agency, or other person, and (2) their possession is in compliance with the new subpart B. As an example, under the proposal, even if the OCC permits disclosure of CSI, meaning the OCC has disclosed information it has a basis for withholding under FOIA Exemption 5 in connection with the bank examination privilege or FOIA exemption 8, this disclosure does not constitute a waiver of the examination privilege related to the information disclosed.

This provision was added to clarify the rule, particularly in light of the additional flexibility that the OCC is proposing for supervised entities to share CSI with certain persons. As discussed in more detail below,
31

the proposal allows a supervised entity to share CSI with certain persons closely associated with it, including certain government agencies, subject to specified safeguards. These persons and the OCC have a common interest in ensuring the efficacy of the supervision process, including the implementation of safe and sound banking practices.
32

31

See
the discussion below of proposed § 4.14(b).

32
The law governing common law privileges recognizes that a privilege is not waived when the holder of the privilege authorizes privileged information to be shared with a party having a common interest in the subject matter. Notably, some courts have extended common law privileges to potential business partners through common interest concepts. Through this proposed provision, the OCC applies this same rule to the bank examination privilege—
i.e.,
to further a common interest in the bank supervisory process, disclosure by a supervised entity of CSI to a potential counterparty in a business combination would not be a waiver of the OCC's privilege.

For example, affiliates, service providers, and incoming senior executive officers share a supervised entity's interest in ensuring the efficacy of the supervision process, including implementing effective and timely corrective actions to address concerns identified by the OCC. Enabling a potential counterparty to understand the OCC's supervisory concerns will allow the counterparty to plan to continue effective and timely corrective actions if a transaction will be consummated, promoting the goals of the supervisory process. Further, sharing of CSI also promotes a supervised entity's and its potential counterparties' common legal interest in ensuring that the entity's operations comply with Federal law. As for non-profits, including trade associations, sharing CSI would allow these persons to, among other activities, advocate on behalf of supervised entities or engage in academic research regarding bank activities, which can provide benefits to supervised entities such as promoting consistent bank supervision and remedial efforts to address supervisory concerns as well as allowing new analyses and insights into the banking sector. Maintaining a robust and effective bank supervisory scheme depends not just on communication between the OCC and each supervised entity. The OCC and supervised entities have a need to understand the larger landscape, including evaluating market risks and concentrations of credit in specific industries or investments. Allowing the sharing of CSI in the

circumstances discussed above through frank discussions of issues and potential improvements using specific facts confronting supervised entities, furthering the purpose of the privilege. Lastly, the common interest shared between the OCC and supervised entities extends to the sharing of CSI with government agencies engaged in supervisory or examination activities. By creating a framework that allows for sharing without the loss of important rights, this rulemaking advances these goals.

5. Proposed § 4.14, Disclosure of Confidential Supervisory Information by Recipient

This section addresses the circumstances under which the OCC and a supervised entity can disclose CSI.

a. OCC's Disclosure of Confidential Supervisory Information

Proposed § 4.14(a) states that the OCC may disclose CSI (1) about a supervised entity to that entity or (2) to a government agency, unless prohibited by law.

b. Supervised Entity's Disclosure of Confidential Supervisory Information

While the current framework permits the disclosure of NPOI by persons other than the OCC in limited circumstances and generally requires OCC prior approval, proposed § 4.14(b) provides increased flexibility by allowing a supervised entity to disclose CSI without OCC approval in six circumstances. Disclosure in this circumstance does not constitute a waiver of OCC legal privileges or the agency's ability to assert applicable FOIA exemptions. Moreover, the supervised entities must still comply with any applicable information disclosure restrictions of other financial regulators notwithstanding the OCC's exemptions. Based on its supervisory experience, the agency believes that the costs and benefits of confidentiality and limited disclosure of CSI favor disclosure in these circumstances, provided the proposed safeguards are observed. It is intended to address stakeholders' longstanding concerns about the costs and consequences associated with the current restrictive disclosure framework, including those referenced above in the context of EGRPRA and other stakeholder feedback.
33

For each of these six, the disclosure is only permissible if necessary or appropriate for the efficacy of the supervision process, as stated in proposed § 4.14(b)(1).

33

See
discussion above regarding EGRPRA comments.

The OCC considered making the exceptions in § 4.14(b)(1) of the proposed rule also available to a parent holding company that is lawfully in possession if its subsidiary supervised entity's CSI. This exception would allow the parent holding company to disclose such CSI without the prior approval of the OCC to the same extent, subject to the same conditions, and to the same categories of recipients for the parent holding company to which the supervised entity could disclose such information under § 4.14(b). This would allow the parent holding company to, for example, disclose CSI to affiliates, lawyers, auditors, accountants, and service providers of the parent holding company, when necessary or appropriate for business purposes, without a request to the OCC. The OCC observes that supervisory matters at a supervised entity are often intertwined with supervisory matters at the parent holding company and that actions related to such matters are often joint efforts between the supervised entity and its holding company. However, the OCC is concerned that allowing the parent holding company to further disclose CSI to the same extent as the supervised entity would cause the OCC's CSI to be disseminated broadly and to a wide range of entities with which the OCC has limited engagement. Since the OCC does not supervise the parent holding company, the OCC would have less visibility into whether the requirements attached to some of the disclosure exceptions such as qualifying confidentiality agreements and logs of disclosed information are being adhered to. Thus, the OCC decided not to adopt such an exception in the proposed rule. However, the OCC is still considering adopting this exception in the final rule and is seeking comment on whether allowing parent holding companies to use this exception would strike the proper balance between reducing unnecessary procedural hurdles with maintaining the confidentiality of the information.

If adopted, the OCC would define “parent holding company” as a company that has control of an insured depository institution with “control” defined consistently as in 12 U.S.C. 1841(a)(2).

Proposed § 4.14(b)(1)(i), Disclosure to an Affiliate
. As proposed, a supervised entity can disclose CSI to an affiliate under the standard discussed above.
34

In the OCC's experience, it is important for a supervised entity's affiliates to understand the entity's business operations because the affiliates often make decisions that have a direct effect on the supervised entity. The OCC has not proposed any specific conditions or limitations on sharing in these circumstances. This is because the interests of the entity and its affiliates are generally so aligned that the agency does not believe that any specific safeguards are needed.
35

34
As defined in proposed § 4.11, an affiliate includes any company that a supervised entity controls, is controlled by, or is under common control with, such as its holding company and any employee, officer, director, or agent of the affiliate. For a branch or agency of a foreign bank, affiliate would include the foreign bank.
See also
12 CFR 261.21(b)(1) for Board rules that allow sharing with affiliates.

35
The OCC notes, however, that a supervised entity's use of affiliates to perform functions for the entity or achieve the entity's strategic goals does not diminish the responsibility of the board of directors and management to ensure that both the relationship between the affiliate and the supervised entity and all functions of the entity are conducted in a safe and sound manner and serve the entity's best interests. To the extent a conflict were to arise with respect to the interests of a supervised entity and its affiliate, under proposed § 4.13(c), the OCC can, on a case-by-case basis, impose conditions or limitations on or prohibit any disclosure of NPOI. Further, proposed § 4.13(f) affirms that nothing in the subpart constitutes a waiver by the OCC of its right to control or impose conditions or limitations on the subsequent use and disclosure of the NPOI.

In considering the scope of this proposed change, the OCC notes that it has historically limited or placed controls on disclosures of information to certain foreign holding companies or other foreign affiliates based on the different levels of protection accorded to information in foreign legal regimes, challenges with enforcing confidentiality agreements in foreign jurisdictions, and the possibility of conflict between U.S. and foreign privacy laws. The OCC has not, however, included any such limits or controls in this provision. The agency has not observed these types of risks with respect to sharing with foreign affiliates and believes that the benefits of disclosure outweigh any risks. In addition, the agency is concerned that such restrictions would interfere with the ability of a foreign affiliate, such as a foreign holding company, to properly oversee and support a supervised entity. Nevertheless, the OCC invites comment on whether it should limit disclosure to only domestic affiliates.

Proposed § 4.14(b)(1)(ii), Disclosure to a Service Provider.
As noted above, § 4.37(b)(2) of the current rule allows a supervised entity to disclose NPOI to a limited category of service providers (attorneys, auditors, and independent auditors). The OCC is proposing to expand this exception to a broader

group of service providers, as defined in proposed § 4.11, subject to certain safeguards. Specifically, the service provider must (1) be incorporated in the United States or a U.S. territory; (2) have a business need for the information (such as assisting the supervised entity with remediating supervisory concerns or fulfilling supervisory expectations); (3) have a formal agreement with or be under a written contact to provide services to the supervised entity; and (4) have a qualifying confidentiality agreement,
36

as defined and described in proposed § 4.14(c). In addition, the supervised entity must keep a log of the general categories of information being disclosed to its service providers pursuant to this exception. The OCC proposes this expanded ability to share CSI with certain service providers based on the agency's understanding of the important role that these service providers play in a supervised entity's business and its appreciation that a service provider's ability to fulfill this role may be impeded if relevant CSI cannot be shared in a timely fashion.

36
As discussed in greater detail in below, the OCC would be an intended third-party beneficiary of any qualifying confidentiality agreement and permitted to enforce the terms of the agreement through a civil action.

Current § 4.37(b)(2) originated in 1995 and is not limited to domestic service providers.
37

The OCC proposes, however, to include this limit in the new subpart B based on concerns that have developed during the intervening period about data security, challenges with enforcing data confidentiality contracts in foreign jurisdictions, and the increasing volume and role of data in business operations.
38

The OCC is soliciting comments about this limit, as well as whether the other proposed safeguards are sufficient to prevent the disclosed information from being used for unintended purposes, such as coercing a supervised entity to provide CSI as a condition of providing services, or from otherwise being misappropriated.

37

See
60 FR 57315.

38

See, e.g.,
How big is Big Data? A comprehensive survey of data production, storage, and streaming in science and industry—PMC, National Library of Medicine: National Center for Biotechnology Information, October 19, 2023.

Proposed § 4.14(b)(1)(iii), Disclosure to a Senior Executive Officer Candidate.
The current rule does not allow a supervised entity to share NPOI with candidates for senior executive officer positions of the supervised entity or its top-tier holding company. The OCC is proposing to allow the disclosure of CSI in these situations when necessary or appropriate for a supervisory, business or other purpose identified in § 4.10(a), provided that the candidate has a qualifying confidentiality agreement. In addition, as proposed, the supervised entity (1) cannot disclose the information to more than one potential candidate at a time per open position; (2) must have formally ended discussions with a potential senior executive officer before it can make a disclosure to another potential candidate for the same position; and (3) must have board of directors' approval to share the information with a potential candidate.

The OCC would consider an individual to be a candidate once the supervised entity or its top-tier holding company, as applicable, has begun interviewing the individual and the board of directors of the supervised entity has approved the disclosure of the CSI to the individual. Disclosing CSI to the potential senior executive officer at this point would allow the individual and banking organization to better assess whether the employment opportunity is appropriate for the individual before the supervised entity undergoes the effort and time of onboarding the individual, thus permitting the supervised entity to more quickly turn to another potential candidate to fill the open position if the opportunity is not appropriate for the candidate.

The proposal would describe senior executive officer in proposed § 4.14(b)(1)(iii) by incorporating the positions listed in the definition of that term in 12 CFR 5.51(c)(4) as well as any other individual the OCC identifies in writing. Under the proposal, senior executive officers would include a supervised entity's president, chief operating officer, chief financial officer, chief lending officer, chief investment officer, and chief risk officer.

The OCC proposes this change because senior executive officers of the supervised entity are generally involved in managing all aspects of a supervised entity, including remediating supervisory issues. Therefore, a person considering a senior executive officer position at a supervised entity should be fully apprised of the issues that a supervised entity is facing, including supervisory issues, in order to accurately assess his or her suitability for the position. Conversely, a supervised entity must be able to assess a candidate's ability to understand and manage the supervised entity, including any supervisory issues. Otherwise, the supervised entity may expend the time and effort to hire a new senior executive officer only for the person to quickly leave the position because he or she was unable to handle the scope of issues requiring remediation. Thus, the exchange of relevant CSI is necessary for both parties to ensure that the correct person is selected for the position.

The proposal would also extend the permission for a supervised entity to disclose CSI to the senior executive officer candidates of the supervised entity's top-tier holding company. Top-tier parent companies control the supervised entities and make decisions that have material and direct effects on the supervised entity. Additionally, the interests of supervised entities and their affiliates are generally aligned—this is particularly true for a supervised entity's top-tier holding company.
39

The OCC invites comment on whether this extension of authority to share CSI is appropriate. Should there be any additional safeguards, such as (1) limiting the authority to domestic candidates; (2) requiring documentation of the role of the top-tier holding company's senior executive officer in decision making and other relevant responsibilities related to the supervised entity; or (3) limiting the disclosed CSI to information directly connected to those responsibilities?

39

See
supra note 35.

As proposed, the OCC does not include candidates for a supervised entity's board of directors in the scope of the provision. The agency does not believe that board candidates would have the same need for CSI as senior executive officer candidates, due to nature and scope of a board member's role in the operations of a supervised entity. For example, a board member would typically be less involved in addressing supervisory issues than a senior executive officer. For this reason, the proposal does not extend this exception to board candidates but invites public comment on whether this distinction is appropriate. Nevertheless, the OCC invites comment on whether the rule should expressly extend to board candidates. If so, should the sharing be limited to certain categories of CSI? In addition, the agency invite comment on whether the rule should expressly extend to candidates for positions not covered by the proposed definition of “senior executive officer,” such the chief compliance officer or chief Bank Secrecy Act officer, both of which are often directly involved in and responsible for the remediation of supervisory concerns expressed by the OCC and for other positions?

Proposed § 4.14(b)(1)(iv), Disclosure to a Potential Counterparty in a Business or Other Combination.
The current rule does not specifically allow a supervised entity to share NPOI with

potential counterparties in business combinations or other combinations. Stakeholders have shared with the OCC that this limitation is very problematic, as it severely limits the ability to conduct due diligence of potential counterparties, and they have encouraged the OCC to allow supervised entities to share CSI in these situations.
40

Moreover, the OCC is aware that the strong need for CSI as part of the due diligence process creates incentives to skirt the OCC's restrictions on CSI, which can negatively impact the OCC's interests in CSI and adherence to its rules as well as make the OCC less able to control the sharing of information. The OCC considered this and other feedback it received from stakeholders over the years and intends for certain of the proposed revisions to be responsive to these concerns. If the counterparty does not have the resources or expertise to remediate the supervised entity's problems, the transaction could lead to a situation where the issues with the supervised entity remain unaddressed for an unacceptably long period of time, a situation that both regulators and supervised institutions seek to avoid.
41

Therefore, the OCC is proposing to allow a supervised entity to share CSI without OCC approval with a potential counterparty in connection with certain business combinations or other combination,
42

subject to the safeguards discussed below. The OCC seeks comment on whether business combination, as defined in 12 CFR 5.33 (d)(2)(i)-(iv), and other combinations, as defined in 5.33(d)(10)(i)-(ii), is sufficiently broad or whether additional types of business combinations or other combinations as defined in 12 CFR 5.33 should be included? Alternatively, should the scope of transaction covered by this provision be expanded to include other types of corporate transactions, such as the purchase or sale of assets or other transactions?

40

See
discussion above regarding EGRPRA comments.

41
For this reason, the OCC has historically allowed the disclosure of CSI to potential counterparties in certain transactions involving troubled institutions.

42
A “business combination” is defined in 12 CFR 5.33 (d)(2)(i)-(iv) as: (1) any merger or consolidation between a national bank or a Federal savings association and one or more depository institutions or State trust companies, in which the resulting institution is a national bank or Federal savings association; (2) in the case of a Federal savings association, any merger or consolidation with a credit union in which the resulting institution is a Federal savings association; (3) in the case of a national bank, any merger between a national bank and one or more of its nonbank affiliates; (4) the acquisition by a national bank or a Federal savings association of all, or substantially all, of the assets of another depository institution. “Other combination” is defined in § 5.33(d)(10)(i)-(ii) as any merger or consolidation between a national bank or a Federal savings association and one or more depository institutions or State trust companies, in which the resulting institution is not a national bank or Federal savings association; and in the case of a Federal stock savings association, any merger or consolidation with a credit union in which the resulting institution is a credit union.

The OCC proposes to allow a supervised entity to share CSI without OCC approval with a potential counterparty to a single transaction or a series of transactions involving a business combination or other combination if (1) the potential counterparty is engaged in good faith negotiations regarding the potential transaction or series of transactions with the supervised entity; (2) the supervised entity provides the CSI to the potential counterparty solely to enable the person to perform the person's own reasonable due diligence or other duties related to the transaction or series of transactions; (3) the potential counterparty to which the supervised entity discloses CSI has a qualifying confidentiality agreement (as defined in proposed § 4.11 and discussed below) with the supervised entity; (4) the OCC receives written acknowledgement from the potential counterparty that the CSI was not created for the purpose of aiding in due diligence of the potential counterparty and the potential counterparty will perform its own diligence and make its own financial decisions regarding the transaction or series of transactions; (5) the OCC receives a written waiver from the potential counterparty of any and all potential claims the potential counterparty may have against the OCC arising from the CSI, including the accuracy and completeness thereof; (6) the supervised entity has not disclosed CSI under this paragraph to three or more other potential counterparties to the transaction or series of transactions; and (7) the potential counterparty to which the supervised entity discloses the CSI agrees in writing that it will not reference the CSI in any agreement with the supervised entity or an affiliate of the supervised entity. These proposed safeguards are based on the OCC supervisory experience in the context of requests for CSI in the context of proposed business combinations and are intended to complement each other.

The first proposed safeguard (requiring that the potential counterparty be engaged in good faith negotiations about the transaction(s)) is intended to ensure that a supervised institution shares CSI only when the potential counterparty has demonstrated its commitment through good faith negotiations, not simply based on the possibility of a business or other combination. The OCC considered requiring a finalized purchase or similar agreement but was concerned that this would largely defeat the purpose of the provision to facilitate counterparty due diligence. For such due diligence to occur, the parties need to exchange complete and accurate information during the diligence phase. Without this information, each counterparty cannot know the other's condition and may be reluctant to enter into the business or other combination. Alternatively, the parties may enter into a business or other combination that should not and would not have occurred had fulsome due diligence, enabled by the disclosure of CSI, been allowed.

The second proposed safeguard (requiring that the CSI be disclosed solely to enable each person in a potential transaction to perform reasonable due diligence) is intended to ensure sharing is conducted consistent with the purpose of the exception. The disclosure has to be for the purpose of due diligence, and due diligence cannot be a pretext to obtain the CSI. Importantly, by enabling more effective due diligence, the act of sharing CSI also supports the ability of the acquirer to make a fulsome assessment of whether they have the capabilities necessary to handle any supervisory issues prior consummating a business combination. As a result, the proposal enables acquirers to be better prepared to remediate any supervisory issues at the target.
43

43
Arguably, using the need to conduct due diligence in a potential business or other combination as a pretext for gaining access to CSI would likely mean that the entity was unable to demonstrate a legitimate necessity for the information. Disclosing CSI in that circumstance would run counter to the purpose of proposed subpart.

The purpose of the third proposed safeguard (requiring a potential counterparty to which the supervised entity discloses CSI to have a qualifying confidentiality agreement with the supervised entity) is self-evident: to ensure that the counterparty maintains confidentiality regarding the CSI. The proposed disclosure of CSI under this provision is for the specific purpose of aiding with the reasonable due diligence or other activities or tasks related to potential transaction(s); it is not a vehicle for the unfettered release of CSI. To this end, the counterparty to whom the information is disclosed must agree to appropriate confidentiality safeguards.

The purpose of the fourth proposed safeguard (requiring the potential counterparty provide the OCC with written acknowledgement that (1) the

CSI was not created to aid its due diligence; and (2) it will perform its own due diligence and make its own decisions regarding the transaction(s)) is to ensure that the potential counterparty independently conducts its own due diligence with respect to the potential transaction(s). This safeguard also serves as notice to the potential counterparty that it may not use the CSI to supplant or as a proxy for this independent conduct and judgment. The OCC believes that this will promote more successful business and other combinations, as well as address concerns that OCC examiners will feel pressure (or be pressured) to tailor their supervisory findings to accommodate, for example, due diligence for an on-going or future transaction.

The purpose of the fifth proposed safeguard (requiring the potential counterparty to waive potential claims against the OCC arising from the CSI, including its accuracy and completeness) is to mitigate the risk that a counterparty asserts a claim against the OCC if the CSI affects the outcome of a business or other combination(s). It would effectively require a potential counterparty to acknowledge that (1) the CSI reflects, in whole or in part, the OCC's judgment in the exercise of its supervisory and regulatory responsibilities; and (2) it has no legal interests or duties owed to it based on the CSI.

The sixth proposed safeguard (limiting the disclosure of CSI without OCC approval to no more than three potential counterparties) is intended both (1) to facilitate a competitive environment with multiple potential counterparties that leads to a consummated transaction; and (2) to maintain control over the disclosed information. The OCC believes that limiting supervised entities' authority to disclosure CSI without OCC approval to no more than three counterparties would strike the appropriate balance. The OCC is seeking comment on whether it is clear what is meant by counterparties “to the transaction or series of transactions” in this limitation. Does the OCC need to clarify what would be considered a discreet “transaction” or “series of transactions” for the purposes of this limitation?

The OCC considered further limiting this disclosure by stating that the CSI could only be disclosed to a potential counterparty's senior executive officers or members of its board of directors. The agency decided, however, that a supervised entity should use its business judgement about the persons at the counterparty with which to disclose the CSI, that said, the disclosure must be limited to those persons with a need to know, such as the decision makers and the staff performing the due diligence and those engaging in the negotiations or integration planning. Nevertheless, the agency invites comment on whether this provision should be limited to a specific group of persons at the counterparty and, if so, how to define the group.

Finally, the seventh proposed safeguard (prohibiting any agreement between parties to reference the CSI) is intended to ensure that CSI shared by a supervised entity is used for the intended purpose of enabling the counterparty to engage in reasonable due diligence or other activities or tasks related to the transaction or series of transactions. Requiring this safeguard to be agreed to in writing helps to remove incentive for a counterparty to use this provision to obtain a flow of CSI over time or to condition the transaction on changes to information contained in CSI, such as ROEs and ratings. For example, a potential counterparty would be contractually prohibited from obtaining CSI to determine where CSI-based contractual conditions to a merger consummation are met. The OCC is concerned that such CSI-based contractual conditions could create adverse impacts and pressures on the supervisory process. Accordingly, the OCC believes that inclusion of this safeguard would help to appropriately balance the need for confidentiality of the supervisory process, the appropriate separation between the supervisory process and active corporate transactions, and access to the information for due diligence.

The OCC believes that these proposed safeguards appropriately balance the costs and benefits of confidentiality and limited disclosure of CSI and will lead to more well-informed business and other combination decisions—a goal that is shared by the OCC, supervised entities, and potential counterparties. Importantly, by enabling more effective due diligence, the act of sharing CSI also supports the ability of the acquirer to make a fulsome assessment of whether they have the capabilities necessary to handle any supervisory issues prior consummating a business combination. As a result, the proposal enables acquirers to be better prepared to remediate any supervisory issues at the target.

The OCC invites comments on these proposed safeguards, as well as on whether (1) alternative or additional safeguards would be appropriate; (2) the rule should specify what constitutes a good faith negotiation; and (3) the proposal strikes the correct balance by not requiring a definitive agreement before sharing is permitted.

Proposed § 4.14(b)(1)(v), Disclosure to a U.S.-Based Consultant and U.S.-Based Attorney of a Potential Counterparty.
Proposed § 4.14(b)(1)(v) would allow a supervised entity to disclose CSI to the U.S.-based consultants and U.S.-based attorneys of a potential counterparty, provided that the requirements in proposed § 4.14(b)(1)(iv) (sharing with a counterparty) are satisfied. This proposed provision is intended to recognize the business realities of the complex business and other combinations referenced in proposed § 4.14(b)(1)(iv). Based on its supervisory experience, the OCC understands that if a supervised entity can share CSI with a potential counterparty but not with that counterparty's consultants or attorneys, then individuals who are critical to evaluating the potential transaction and have a business need to know the information would not have access to relevant CSI. The OCC proposes, however, to limit this provision to U.S.-based consultants and U.S.-based attorneys. As discussed above, the OCC declined to propose this geographic location limitation when sharing CSI with affiliates. (
See
the discussion about proposed § 4.14(b)(1)(i)). The agency has reached a different conclusion here, however, because a supervised entity has control over whom it hires as a consultant or attorney (and there are many U.S.-based options). In contrast, a supervised entity's affiliates are oftentimes established by a parent entity, not the supervised entity itself. When the OCC considered this fact in the context to the different levels of protection accorded to information in foreign legal regimes, challenges with enforcing confidentiality agreements in foreign jurisdictions, and the possibility of conflict between U.S. and foreign privacy laws, the agency determined that the potential risks of disclosing CSI to a foreign-based consultant or attorney outweighed the benefits. A supervised entity that wants to share CSI with a foreign-based consultant or foreign-based attorney of a potential counterparty could seek approval, however, under proposed § 4.17, which would be assessed on a case-by-case basis.

Proposed § 4.14(b)(1)(vi), Disclosure to a Not-for-Profit Entity.
Under this proposed provision, a supervised entity can disclose CSI to a not-for-profit entity (including a not-for-profit trade

association)
44

when necessary or appropriate for a supervisory purpose, if the purpose of the disclosure is to enable the not-for-profit to: (1) aggregate the anonymized CSI of entities supervised by the OCC, Board, or FDIC; and (2) either make the aggregated information publicly available or, in the case of a trade association, advocate for the best interests of its members, including with respect to the fairness, effectiveness, and efficiency of the OCC's regulatory and supervisory processes. In addition, the supervised entity would be required to (1) have a qualifying confidentiality agreement with the not-for-profit entity; (2) have a written agreement with the entity describing in detail a discrete and time-limited information collection for purposes of either the specific information aggregation or advocacy activities; and (3) disclose no more CSI than described in the written agreement. The not-for-profit entity could not further disclose the non-anonymized CSI without OCC prior approval under proposed § 4.13(a)(1)(i)(B).

44
A “trade association” is an association of tradesmen, businessmen, or manufacturers in a particular trade or industry for the protection and advancement of their common interests.
See
Definition of Trade Association by Merriam-Webster,
https://www.merriam-webster.com/dictionary/trade%20association, last accessed
June 12, 2026. For example, a banking trade association would be an organization comprised of banks for the purpose of protecting and advancing the banking industry's common interests.

Through its supervisory experience, the OCC has seen the value of aggregated data to supervised entities and other stakeholders (
e.g.,
aggregated data public welfare investments). This information can allow interested persons to identify emerging trends, thereby directly or indirectly helping supervised entities avoid problems or lessen their effects. The OCC is, however, proposing to limit this disclosure-for-aggregation provision to not-for-profit entities for two main reasons. First, these entities are more commonly established for analysis and, particularly in the case of banking trade associations, for advocacy in support of consistent, efficient, and effective treatment of certain supervised entities, and they use this data in the service of their important role in the financial services ecosystem. For example, under this provision, supervised entities could share CSI with a not-for-profit university or think-tank that uses anonymized, aggregated data to identify, evaluate, and publish research about emerging risks associated with novel technologies. This research would benefit not only individual supervised entities but the financial system and national economy as a whole. Second, a not-for-profit entity may be less likely to use the CSI in contravention of the subpart than a for-profit entity, which could use the data for its own financial benefit at the expense of the supervised entity.

The OCC seeks comment on whether the provision should contain additional safeguards. For example, should the supervised entity be required to specify a particular purpose for sharing the CSI, beyond what would be required under the proposal? Should the provision expressly state that the OCC can require that the CSI be destroyed or returned if the agency determines that the specific purpose does not further the broader purpose? Are there entities not covered by this provision that should be added because of the nature of their work or their interests? The agency invites the public to comment on these issues.

Other possible exceptions:
The OCC is also considering other exceptions that it could add to § 4.14(b). One such exception that OCC is considering would permit a supervised entity to disclose CSI to a shareholder that owns greater than 50 percent of the voting shares of the supervised entity. The OCC believes that this type of disclosure is often important for the prompt remediation of supervisory concerns because shareholders owning the majority of the shares of a supervised entity are often intimately involved in efforts at the institution to remediate supervisory concerns. In the OCC's experience, open, direct, and timely communication about the problems at the supervised entity is often important for the majority shareholder to provide remediation support. Moreover, understanding significant OCC concerns at the supervised entity could also be important for the majority shareholder to choose directors for the supervised entity that have the proper qualifications and expertise to provide the leadership necessary to address the concerns. If the OCC did decide to include such an exception, it might require the majority shareholder to have a qualifying confidentiality agreement in place and to have a business need for the information. The OCC is seeking comment on whether it should include this exception and, if so, whether it should place additional controls on the disclosure of information to majority shareholders.

Another possible exception that the OCC is considering adopting would allow a supervised entity to share CSI with another supervised entity or, possibly, with the holding company of another supervised entity, for the purpose of promoting the best interests of the financial institutions, including informing best practices or promoting government accountability. If the OCC does implement such an exception, it might require that the receiving party have a signed qualifying confidentiality agreement in place and that the supervised entity making the disclosure provides notice to the OCC after the disclosure and a copy of the CSI disclosed under this provision within 15 calendar days of making the disclosure. The OCC is seeking comment on whether such an exception would be helpful or whether it would be overly broad and permit supervised entities to pressure each other into disclosing CSI in situations that could chill candid information exchange between the OCC and its institutions. The OCC further seeks comment on whether there are other exceptions that it should adopt.

Proposed § 4.14(b)(2), Disclosure of CSI to Government Agencies.
Proposed § 4.14(b)(2) sets forth a supervised entity's authority to disclose CSI to certain government agencies, with three sets of requirements based on the recipient of the disclosure. Specifically, the proposal would include separate requirements for a supervised entity's disclosure of CSI to (1) the Board (which includes the Federal Reserve Banks); (2) the FDIC; and (3) an agency other than the Board or the FDIC.
45

45
For the purposes of this provision, agency is defined in 5 U.S.C. 551(1) and includes “each authority of the Government of the United States.”

With respect to the Board, under proposed § 4.14(b)(2)(i), a supervised entity would be permitted to disclose CSI if necessary for the Board's performance of its statutory duties, provided the supervised entity notifies the OCC in writing of the proposed disclosure and includes a copy of the CSI it proposes to disclose.
46

The OCC would have 15 calendar days after acknowledging receipt of the notice to object to the proposed disclosure. The supervised entity may disclose the CSI if the OCC does not object within 15 days or sooner or if expressly permitted to do so in writing by the OCC. The OCC could always waive the 15-day period or share the CSI itself, if appropriate, in the case of an imminent receivership or other circumstances. The proposal provides that disclosure of CSI to the Board under this provision is done with the understanding that the Board will not further disclose the information, except as otherwise permissible under this subpart. (If the Board wants to

further disclose the CSI, the provisions in proposed § 4.17 would apply.)

46
As discussed below, proposed § 4.18 describes where to send a notice of proposed disclosure.

The OCC has included this provision to ensure that the current requirement for agency approval prior to sharing NPOI with the Board does not interfere with supervisory communications between the supervised entity's Board-regulated holding company (if any) and the Board's supervision of such holding company. The OCC recognizes the importance of timely communication with the Board, including for the Board's compliance with section 5(c) of the Bank Holding Company and section 10(b) of the Home Owners' Loan Act. For example, supervised entities are often asked questions by the Board for information that cannot be answered without providing CSI. Although the OCC generally approves a supervised entity's request to disclose this information to the Board, this provision would allow for more efficient disclosure. Based on its supervisory experience, the OCC believes that the proposed 15-day period described above is appropriate.

For disclosure of CSI to the FDIC, § 4.14(b)(2)(ii) of the proposal provides that a supervised entity may disclose CSI if four conditions are met. First, the supervised entity must receive a demand from the FDIC for the information. Second, the information is necessary for performance of the FDIC's statutory duties related to its authority to carry out resolution-related activities, deposit insurance assessments, or backup supervisory activities. Third, the supervised entity notifies the OCC in writing of the demand and provides the OCC with a copy of the information disclosed. Fourth, the supervised entity may disclose the CSI if the OCC does not object within 15 days or sooner or if expressly permitted to do so in writing by the OCC. The OCC can always waive the 15-day period or share the information itself, in the case of an imminent receivership or other circumstances. Lastly, the supervised entity makes the disclosure with the understanding that the FDIC will not further disclose the information without authorization from the OCC. As with CSI disclosed to the Board, if the FDIC wants to further disclose the CSI, the provisions in proposed § 4.17 would apply. The OCC also notes that records or other information provided to the FDIC in a failing bank or other resolution-related context is typically a supervised entity's own records or other information and not CSI as defined in § 4.12(b).

The OCC believes that these requirements would strike the appropriate balance between the FDIC's need for access to CSI in the specified circumstances and the OCC's obligation to protect the information. In making this determination, the OCC recognized that it would often know that the FDIC would need this information and why (
e.g.,
the pending receivership of a supervised entity). For any other Federal agency,
47

under proposed § 4.14(b)(2)(iii), a supervised entity can disclose CSI to an agency (1) only in response to a demand from the agency; and (2) if the supervised entity notifies the OCC in writing of the proposed disclosure and includes a copy of the CSI it proposes to disclose. The notification must include a copy of a written agreement between the supervised entity and the agency in which the agency agrees to not disclose the CSI and expressly provides that the OCC is (1) an intended third-party beneficiary of the agreement; and (b) permitted to enforce its terms through a civil action in the U.S. District Court for the District of Columbia or any other court with jurisdiction and in which venue is appropriate. The OCC would have 30 calendar days after acknowledging receipt of the notice to object to the proposed disclosure. If the OCC does not object within 30 days, the supervised entity may disclose the CSI (or sooner if expressly permitted by the OCC). If an agency wants to further disclose the CSI, the provisions in proposed § 4.17 would apply.

47
This proposed provision would apply to an agency as defined in 5 U.S.C. 551(1), other than the Board or the FDIC.

The OCC has included this provision in recognition that sharing CSI with a Federal agency (other than the Board and FDIC) can be necessary and appropriate and the current requirement for OCC prior approval can result in unnecessary delays. That said, the OCC proposes to include additional safeguards because the reasons for which a supervisory entity would want to share with an agency other than the Board are less obvious and more infrequent. For these reasons, the OCC believes that the proposed 30-day period described above is appropriate to provide the agency with additional time to consider the demand. The OCC is seeking comment on whether this exception should be expanded to include other circumstances or to include demands from State agencies.

c. Qualifying Confidentiality Agreement

This subsection would set out the requirements for a qualifying confidentiality agreement, as that term is used in proposed § 4.14. Specifically, a qualifying confidentiality agreement would be an agreement between a supervised entity and a person that receives CSI pursuant to § 4.14 that (1) is written; (2) states the recipient's awareness of and agreement to abide by the prohibitions on the disclosure of CSI in § 4.13 (including the prohibition on further disclosure of the information without OCC approval); (3) is governed by the laws of the United States or a State of the United States; (4) prohibits the use of the information by the recipient for any purpose other than as permitted by the relevant provision of proposed § 4.14 (b) as expressly identified in the confidentiality agreement; (5) for recipients that are not individuals, limits access to the information at the recipient to directors, officers, or employees with a business need to know the information; (6) requires the information to be destroyed or returned to the supervised entity either at the end of the relevant relationship with the supervised entity (
e.g.,
consultancy, service provider) or at the conclusion of the purpose for which it was shared; (7) expressly provides that the OCC is an intended third-party beneficiary of the agreement and is permitted to enforce the terms of the agreement through a civil action filed in the U.S. District Court for the District of Columbia and any other court having jurisdiction and venue over disputes arising from the agreement; (8) expressly provides that the OCC must be informed of any violation of the agreement by either party; and (9) for a qualifying confidentiality agreement required when CSI is disclosed to a supervised entity's service provider, the agreement provides that the person performing the service (A) acknowledges and consents to regulation and enforcement by the OCC to the same extent as if the service was being performed by the supervised entity itself; and (B) acknowledges itself to be an institution-affiliated party as defined in 12 U.S.C. 1813(u)(4).

The first criteria (in writing), third criteria (governed by domestic laws), and seventh criteria (enforceable by the OCC) would help ensure that the agreement is judicially enforceable in the event of breach. The second criteria (awareness of prohibitions on disclosure and further disclosure) and fourth criteria (limitation on use of the disclosed CSI) would help ensure that the parties to the agreement understand the purpose of and limitations on the CSI disclosure. The fifth criteria (access limited to those with need to know), sixth criteria (treatment of CSI at end of relevant relationship), eighth criteria (inform the OCC of violations of the agreement), and ninth criteria (service

providers)
48

would help the OCC to ensure control over the disclosed CSI, including when disclosed to a service provider, the purpose for which it was disclosed has ended, or the agreement is breached. In addition to inviting public comment generally on this provision, the OCC seeks feedback on whether to require that all individuals with access to the disclosed information be listed in an appendix to the agreement. The OCC also seeks comment on whether the ninth criteria is too burdensome on service providers and whether this requirement would interfere with supervised entities receiving outside assistance from service providers for remediation efforts.

48
If the CSI is being disclosed by a supervised entity to allow a service provider to assist in remediating an OCC supervisory concern, only those individuals associated with the service provider who are directly involved in remediating the concern and who need to know the information to assist in the remediation may have access to the information. The OCC intends this provision, as proposed, to prevent the release of CSI to subcontractors without OCC approval.

6. Proposed § 4.15, Restrictions on Current and Former OCC Employees or Agents; Former OTS Employees or Agents

Proposed § 4.15 incorporates provisions from current § 4.37(a), which set out the restrictions on current OCC and former OCC and OTS employees disclosing NPOI other than to OCC employees or agents for use in the performance of their duties, along with clarifying, conforming, and technical revisions. For example, current § 4.37(a)(2) addresses certain individuals who are “subpoenaed” for NPOI. Proposed § 4.15(b)(1) uses the defined term “demand” to clarify that the section applies to a broader category of legal processes that require information to be provided. Current § 4.37(a)(2) also states that if an individual receives a subpoena and is required to appear or produce NPOI, that individual must appear “[i]f necessary.” To address any confusion about when the individual must appear, proposed § 4.15(b)(2) replaces “[i]f necessary with “[i]f ordered by a court or otherwise compelled by law.” The changes in this proposed section are not intended to substantively alter the provisions addressed.

7. Proposed § 4.16, Requesting Nonexempt Information Under the FOIA and Available Nonpublic Information

Proposed § 4.16 primarily addresses the process for requesting the disclosure of records under the FOIA and NPOI. The provisions on disclosure under FOIA are based primarily on current § 4.15 but include the substantive changes discussed below, as well as technical and conforming edits.

As proposed, § 4.16(a) explains that the disclosure of nonexempt information will be governed by the FOIA and in accordance with proposed § 4.18 (where to submit a request.) Proposed § 4.16(b) explains that NPOI that is authorized to be disclosed pursuant to proposed § 4.13(b) will be disclosed in accordance with this section. Section 4.16(c) carries forward the current rule's exceptions for requests to disclose FDIC and other agency's records.

Proposed § 4.16(d)(1) carries over from the current rule the provisions on what a records request must include. Proposed § 4.16(d)(2) addresses the OCC's initial determination to grant a request for information, clarifying the current rule by stating that in making this determination, the agency will only withhold information if, (1) it reasonably foresees that disclosure would harm an interest protected by an applicable exemption described in 5 U.S.C. 552(b) of the FOIA; or (2) the disclosure is prohibited by law. For consistency with other proposed provisions, § 4.16(d)(2)(iii) also provides that the OCC has the discretion to make disclosures of NPOI on a case-by-case basis. Sections 4.16(d)(3) and (4) carry over provisions from the current rule about when the OCC grants and denies a request.

Section 4.16(d)(5) memorializes a process for the expedited processing of requests for information that the OCC has previously followed, consistent with statutory requirements. The FOIA provides that, in connection with a request for nonexempt information, a person may request expedited processing or a waiver of the fees associated with the request.
49

The statute also establishes the timeframes that apply to expedited processing, addresses appeals rights, and defines “compelling need.”
50

The FOIA also directs the OCC to promulgate an implementing rule on expedited records requests and fee waivers,
51

specifying that the rule should provide for expedited processing when the requestor demonstrates a compelling need or in other cases determined by the agency.
52

The OCC's current FOIA rule does not address expedited review, although it is OCC policy to comply with the statutory time frames.
53

To comply with these provisions in the FOIA, the OCC is proposing to memorialize its expedited processing framework.
54

By setting out this process in a rule, stakeholders will have a clear understanding of how the process works.

49
Fees are discussed in greater detail below under proposed § 4.23.

50
5 U.S.C. 552(a)(6)(E).

51
5 U.S.C. 552(a)(6)(E)(i) and (a)(4)(A)(i).

52
5 U.S.C. 552(a)(6)(E).

53
5 U.S.C. 552(a)(6)(E)(i)(I). As noted above, the OCC proposed to amend its FOIA regulations in 2024 but the proposal was not finalized. Those amendments would have incorporated this requirement.

54
The OCC currently grants requests for expedited processing when a requestor submits a certified statement demonstrating compelling need by showing that (1) the request involves circumstances in which the lack of expedited processing could reasonably be expected to pose an imminent threat to the life or physical safety of an individual; (2) the records requested pertain to a matter of current exigency to the public; or (3) the request involves the loss of substantial due process rights. The OCC evaluates requests against the established criteria, notifies requestors of its determination, and, when expedited processing is granted, the OCC processes the request as soon as practicable.

Proposed § 4.16(d)(5) would codify the OCC's existing practices for handling expeditated processing requests, and proposed § 4.16(d)(5)(ii) explains the three scenarios in which the OCC will grant a request. First, it will grant the request if the requestor sufficiently demonstrates that the lack of expedited processing could reasonably be expected to pose an imminent threat to the life or physical safety of an individual. Second, it will grant the request if the requestor sufficiently demonstrates that (1) the requested records pertain to a matter of current exigency to the public; (2) a processing delay would compromise a significant recognized interest to and throughout the general public; (3) the request involves an actual or alleged Federal government activity; and (4) the requestor is primarily engaged in disseminating information. Third, it will grant a request if the requestor demonstrates that expedited review is necessary to prevent the loss of substantial due process rights, such as when delayed access to the requested records could impair the requestor's ability to participate in an administrative or judicial proceeding.

The proposed provision also explains that the OCC will (1) notify the requestor of its decision on the expediated processing request within 10 calendar days of receiving the request; (2) base its decision solely on the information in the initial request; and (3) process grants of expedited processing as soon as practicable. Finally, the proposal provides in § 4.16(d)(5)(v) and (vi) that the requestor may appeal a denial and the OCC will

expeditiously consider the appeal and notify the requestor of its determination.

Proposed § 4.16(e) would clarify a person's right to appeal a denial of a request, including denials of requests for records, expedited processing, and fee waivers. Proposed §§ 4.16(f) (judicial review), 4.16(g) (time limits for responding to FOIA requests), 4.16(h) (date of receipt of request or appeal), 4.16(i) (dispute resolution services), and 4.16(j) (segregability) are carried over from the current subpart B, with limited conforming, streamlining, and clarifying changes.
55

55
The provisions related to the denial of fee waiver requests are addressed in the discussion of proposed § 4.23.

8. Proposed § 4.17, Requesting Non-Public OCC Information

Proposed § 4.17 consolidates and clarifies current §§ 4.33; 4.35(a)(3); and 4.40(b). These provisions set out the current rules for seeking disclosure of NPOI from the OCC and address form requests, expedited requests, requests arising from adversarial matters, records requests, additional information that the OCC may require, and testimony requests. The proposal also includes clarifying, conforming, and technical edits.

9. Proposed § 4.18, Where To Submit a Request for Nonexempt Information Under the FOIA, a Request for Non-Public OCC Information, or a Notice Under This Subpart

Proposed § 4.18 combines and streamlines the provisions in §§ 4.15(b) and 4.34 of current rule. The section (1) specifies where to submit a request for nonexempt information under the FOIA or a request for NPOI (including a combination of NPOI and nonexempt information); and (2) address requests for authentication of a record or notice under this subpart. These revisions are intended to reduce duplication by consolidating provisions in current subparts B and C on where to send requests and notices and make the provisions easier to use; they are not intended to include substantive changes.

10. Proposed § 4.19, Disclosing and Using OCC Records in Litigation

Proposed § 4.19 would republish current § 4.39, which addresses disclosing and using OCC records in litigation, with minor technical and conforming changes.

11. Proposed § 4.20, Predisclosure Notice for Confidential Commercial Information

Proposed § 4.20 incorporates the current § 4.16 provisions on predisclosure notice for confidential commercial information, specifying when the OCC would be required to notify submitters of records containing confidential commercial information that the agency received a FOIA request for the information and may be required to disclose it. The changes to this section are technical and conforming, except with respect to the definition of “confidential commercial information.”

The OCC proposes to define this term as commercial or financial information obtained by the OCC from a submitter that may be exempt from disclosure under FOIA Exemption 4 (5 U.S.C. 552(b)(4)).
56

This definition reflects two substantive changes from the current rule. First, it does not reference the competitive harm standard, thereby reflecting the Supreme Court's 2019 decision the
Food Marketing Institute
v.
Argus Leader Media
(
Argus
).
57

In
Argus,
the Court overruled the longstanding substantial competitive harm standard for information provided to the government on an involuntary basis, holding that commercial or financial information submitted to the government will be considered “confidential” for purposes of FOIA Exemption 4 at least where the information is “both customarily and actually treated as private by its owner and provided to the government under an assurance of privacy.”
58

To conform the definition to
Argus,
the OCC is proposing to remove the requirement that disclosure of the information reasonably could cause substantial competitive harm to the submitter. Second, the proposal replaces the term “record” in the current definition with “commercial or financial information obtained from a [submitter].”
59

This change would provide a clear link between the rule and the FOIA. As a conforming amendment, the OCC also proposes to replace the term “person” (which is used in the FOIA) with the term “submitter.”

56
FOIA Exemption 4 protects trad

[Text truncated at 120,000 characters. The full text is on the page linked above.]

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/documents/fr%3A2026-15867. Public record. Not legal advice.
