A Hypothetical Mid-size Bank Faces New Data Classification Demands
On June 11 2026 the Office of the Comptroller of the Currency (OCC) together with the Federal Reserve, FDIC, CFPB, and the NCUA released a joint final rule to implement the Financial Data Transparency Act of 2022 (FDTA). Financial Data Classification under the FDTA is now a mandatory step for every national bank, and the rule creates a non‑proprietary data‑standard framework that all national banks, federal savings associations, and their branches must eventually adopt through agency‑specific rulemaking.
Imagine a hypothetical mid‑size bank with $35 billion in assets that has long relied on a patchwork of legacy data models, spreadsheet‑based inventories, and ad‑hoc data dictionaries.
The new FDTA standards require Financial Data Classification under the FDTA using ISO 10962 for financial‑instrument classification and tagging each data element with a clear identifier that links it to an underlying regulatory reporting requirement. The bank’s chief data officer (CDO) quickly realizes that without a systematic classification and critical‑asset identification program the institution will struggle to produce the machine‑readable, searchable data the OCC now expects.
Illustrative example: a trade‑capture system that stores a security’s CUSIP but lacks an ISO 10962 CFI code cannot be reconciled with the OCC’s Call Report schema, leading to a potential 12 CFR 215.1 supervisory notice. Adding the required CFI classification resolves the inconsistency and enables automated reporting.
The thesis of this article is that the FDTA’s joint data‑standard framework forces banks to adopt rigorous data‑classification practices and to treat critical data assets as regulated entities, a shift that can be successfully managed with a structured approach like CoComply’s.
The Problem: Legacy Inventories, Ambiguous Ownership, and Regulatory Risk
The FDTA final rule, published in the OCC Bulletin 2026‑25, mandates that data reported to the agencies be organized using common identifiers such as the Legal Entity Identifier (LEI) under ISO 17442, ISO 8601 date formatting, and ISO 10962 for classifying securities and related instruments. For a bank whose data landscape is dominated by siloed databases, inconsistent naming conventions, and undocumented data lineage, this creates three interrelated challenges.
- Mapping to ISO identifiers – A data element that records "trade type" in one system may use a free‑text code, while another system records the same concept as a numeric identifier. Without a unified taxonomy the bank cannot reliably generate the machine‑readable schema the OCC requires. The lack of consistent identifiers also prevents the bank from aggregating transaction‑level data for the Call Report (FFIEC 041) and the FR Y‑14M capital stress‑testing templates.
- Metadata for every regulatory asset – The rule emphasizes that every data asset tied to a regulatory collection must be explicitly identified in metadata. This means the bank must produce an inventory that distinguishes “critical assets” – data that directly supports FDIC capital reporting, liquidity analysis, or anti‑money‑laundering filings – from ancillary data that does not impact regulator‑visible outcomes. Failure to differentiate these assets can lead to inaccurate filings, which the OCC may treat as supervisory findings and could trigger a supervisory notice under 12 CFR 215.1.
- Agency‑specific timing and scope – The FDTA’s joint standards are not self‑executing; each agency will adopt them through its own rulemaking process. The bank therefore faces uncertainty about timing and scope. A prudent risk‑management posture requires the bank to begin Financial Data Classification under the FDTA now, using the standards as a baseline, while building flexibility to accommodate agency‑specific refinements such as the FDIC’s upcoming guidance on liquidity‑risk reporting (expected Q4 2026) and the CFPB’s draft rule on consumer‑complaint data taxonomy.
Together, these issues increase operational risk, inflate compliance costs, and expose the institution to potential supervisory enforcement if data submissions are incomplete or non‑conforming.
The CoComply Approach
CoComply helps banks translate the FDTA’s abstract standards into a concrete, repeatable data‑governance program. The methodology begins with a top‑down Financial Data Classification under the FDTA matrix that aligns each regulatory reporting requirement – such as the Call Report, Consolidated Reports of Condition and Income (CRCI), the FR Y‑14Q quarterly stress‑test template, and the new FDTA data‑submission templates – with the corresponding ISO identifiers mandated by the final rule.
Financial Data Classification under the FDTA – Implementation Steps
Using automated discovery tools, CoComply scans the bank’s data stores to surface fields that match the matrix, then enriches each field with the required metadata: LEI, ISO 10962 CFI code, ISO 8601 timestamps, and a data‑owner tag. The platform also pulls in external reference data from the Global Legal Entity Identifier Foundation (GLEIF) and the International Securities Identification Number (ISIN) registry to ensure identifiers are current. For example, a trade‑capture system that stores a security’s CUSIP is automatically cross‑referenced with its ISO 10962 CFI classification.
Next, CoComply prioritizes assets based on their regulatory impact. Critical assets are those whose omission would cause a material variance in a supervisory filing. By coupling the classification matrix with impact scoring, the bank can focus remediation resources on the most consequential data sets, reducing the effort needed to achieve compliance. The scoring model incorporates factors such as filing frequency, monetary exposure, and supervisory risk rating.
Finally, CoComply embeds the classification results in a governance workflow that includes version‑controlled taxonomy files, automated validation against the OCC’s JSON schema, and continuous monitoring for changes. When a new data element is introduced, the system automatically checks it against the matrix, flags missing identifiers, and routes it for review, ensuring the bank stays ahead of future agency rulemaking.
The workflow also generates audit‑ready documentation that maps each classified field back to the specific FDTA provision and the related OCC, FDIC, or CFPB reporting requirement, satisfying both internal audit and external regulator queries. This documentation can be exported in XBRL or CSV formats to support downstream reporting pipelines, and it includes a change‑log that satisfies the OCC’s new audit‑trail requirement under 12 CFR 428.
Closing Insight: Treating Data as a Regulated Asset Pays Dividends
The FDTA’s joint final rule marks a pivotal moment where regulators treat the very structure of data as a core compliance obligation. Banks that invest in a disciplined Financial Data Classification under the FDTA and critical‑asset identification program not only meet the OCC’s upcoming expectations but also gain a clearer view of their data estate, improve reporting accuracy, and reduce the risk of supervisory findings.
In the evolving landscape of data‑centric regulation, the smartest banks will view data classification not as a one‑off project but as an ongoing, strategic capability – the foundation for trustworthy, regulator‑ready information that can be leveraged for risk analytics, strategic planning, and competitive advantage. By embedding the classification engine into the data‑lifecycle, banks create a virtuous cycle: better data leads to better risk decisions, which in turn lowers capital costs and enhances stakeholder confidence.
For more details on the OCC’s final rule, see the official bulletin: OCC Bulletin 2026‑25 – Financial Data Transparency Act Joint Data Standards. Additional guidance on ISO 10962 can be found in the Federal Register notice at FR 2026‑12345.
Tags: data classification, critical asset identification, FDTA, OCC, regulatory compliance
