Request a demo
Origami risk leadspace gradient background
Insights / Blog

How ERM technology helps financial institutions address Matters Requiring Attention

July 22, 2026

ERM technology helps financial institutions address Matters Requiring Attention (MRAs) by centralizing the three areas that drive most MRA findings: internal controls, risk assessments, and audit documentation. When these are managed on a unified platform, financial institutions can respond to MRAs faster, demonstrate corrective action more clearly, and reduce the conditions that lead to findings in the first place.

Why BSA/AML MRAs Keep Happening

Complying with Bank Secrecy Act/Anti-Money Laundering (BSA/AML) regulations is one of the most demanding compliance requirements facing financial institutions. Regulators issued 42 BSA/AML-related enforcement actions in 2024, — a 45% increase in a single year. The October 2024 resolution against TD Bank resulted in more than $3.1 billion in combined penalties, the largest BSA/AML enforcement action in U.S. history, underscoring how seriously regulators are treating compliance gaps.

At the same time, the regulatory framework around MRAs is shifting. In October 2025, the OCC and FDIC jointly proposed a rulemaking that would narrow the scope of what qualifies as an MRA, limiting citations to practices that present material financial risk or constitute actual legal violations. The implication is significant: while fewer MRAs may be issued overall, those that are issued will signal more serious deficiencies. Receiving one carries more weight than before.

For compliance leaders, this shifts the calculus. The goal is building a program that can demonstrate its own soundness before an examiner has to ask.

The Three Deficiencies Behind Most MRAs

Research analyzing OCC examination data found that a small set of recurring deficiencies accounts for the vast majority of MRAs issued. Understanding these is the starting point for any meaningful response strategy.

1. Internal Controls Deficiencies

Internal controls are the most common driver of MRA findings. The challenge is that controls are fragmented across departments, inconsistently documented, and difficult to demonstrate to an examiner. Without a single source of truth, proving the effectiveness of controls becomes a manual, time-intensive exercise.

2. Risk Assessment Gaps

Risk assessments are a cornerstone of an effective BSA/AML program. The FFIEC BSA/AML Examination Manual identifies risk assessment as a primary scoping tool for examinations. Examiners may accept an institution’s conclusions but still cite a deficiency if the supporting documentation doesn’t show how those conclusions were reached. Without that paper trail, the reasoning is invisible to regulators.

3. Audit Weaknesses

In the traditional three lines of defense model, internal audit is the last line before regulators. Examiners typically review the most recent BSA audit report to scope an examination. An audit function that operates in isolation from risk assessments and controls leaves gaps that are difficult to close quickly under examination pressure.

All three deficiencies are symptoms of fragmented risk management. When controls, assessments, and audit activity live in separate systems or spreadsheets, the burden of demonstrating program effectiveness falls on manual effort and institutional memory.

How ERM Technology Addresses Each Root Cause

A well-configured ERM system directly targets each of the three deficiency areas.

For internal controls, ERM technology establishes centralized ownership and accountability. Controls are embedded in processes rather than layered on top of them, with standardized methodologies applied consistently across the enterprise. When an examiner asks for evidence of control effectiveness, the documentation is already organized, timestamped, and tied to ownership.

For risk assessments, the platform links assessments to specific risks and controls, creating a traceable chain of reasoning. Supporting documentation is stored in context, not buried in a shared drive or a single person’s inbox. Examiners can follow the logic from risk identification through assessment to the controls designed to address it.

For audit, ERM technology integrates audit findings directly with the controls and risk assessments they evaluate. When a finding surfaces, it triggers an action plan with assigned owners and timelines. Progress updates as controls are adjusted. The audit function gains visibility into the broader program rather than operating as a periodic check on disconnected data.

Together, these capabilities make it possible to coordinate a documented, timely response to an MRA. That way you can build the kind of program that reduces the likelihood of receiving one.

What Exam-Ready Looks Like Today

The institutions that navigate BSA/AML examinations most effectively have compliance programs built for transparency. When an examiner walks in, the risk assessment is current, controls are documented with clear ownership, and audit findings have visible resolution paths.

That transparency is hard to manufacture under examination pressure. It must be built into the program’s architecture. ERM technology makes that architecture possible. The 2025 OCC/FDIC proposed rulemaking makes it more urgent. As the threshold for what qualifies as an MRA rises, the institutions that receive them will be those with the most significant gaps.

Closing those gaps through a well-configured ERM system that connects risk assessments, controls, and audit in a single environment is how financial institutions move from reactive compliance to a program built to hold up.

Origami Risk supports financial institutions in building that foundation. The Origami Risk GRC platform connects enterprise risk management, compliance management, internal audit, and controls management in one configurable environment, giving compliance leaders the visibility and documentation they need to respond to examiners confidently and reduce findings over time.

For a practical guide to assessing your ERM maturity and building a program that holds up to scrutiny, download The Risk Intelligence Playbook.

Frequently Asked Questions

What Is a Matter Requiring Attention (MRA)?

An MRA is a written supervisory finding issued by a bank examiner (typically from the OCC, FDIC, or Federal Reserve) requiring a financial institution to take corrective action. MRAs are communicated formally to a bank’s board and management. Under a 2025 proposed rulemaking from the OCC and FDIC, the threshold for issuing an MRA may narrow to practices that present material financial risk or constitute actual legal violations.

What Is the Difference Between MRA and MRIA?

A Matter Requiring Immediate Attention (MRIA) is a more urgent form of supervisory finding, issued when a deficiency poses an immediate risk to the financial condition of the institution. MRAs allow more time for resolution but still require timely and documented corrective action, with examiner follow-up built into the supervisory process.

What Are the Most Common Causes of BSA/AML MRAs?

The three most common drivers are internal controls deficiencies, risk assessment gaps, and audit weaknesses. Internal controls are the most frequent source of findings. This is typically because controls are fragmented, inconsistently documented, or difficult to demonstrate to an examiner. Risk assessment gaps arise when institutions cannot demonstrate the reasoning behind their compliance conclusions. Audit weaknesses occur when the internal audit function operates in isolation from the broader compliance program.

How Does an ERM System Help a Financial Institution Respond to an MRA?

An ERM system creates a centralized environment for managing controls, risk assessments, and audit findings. When an MRA is received, the institution can build a documented response with assigned owners, timelines, and progress tracking tied directly to the controls and assessments in question. This makes it possible to demonstrate corrective action clearly to regulators.

How Long Does It Take to Resolve an MRA?

Resolution timelines vary based on the nature and severity of the finding. The OCC expects timely and effective corrective action, and examiner follow-up is standard. Institutions with centralized ERM infrastructure are generally better positioned to resolve MRAs faster because action plans, ownership, and documentation are already structured and accessible.

Can ERM Technology Help Prevent MRAs?

Yes. When risk assessments are current and well-documented, controls are consistently applied with clear ownership, and audit findings are connected to corrective action, the conditions that generate MRA findings are less likely to develop. ERM technology supports each of these areas, giving compliance leaders a proactive foundation rather than a reactive one.

Related articles

Insight_Blog_Finding Added Value in a RMIS
Blog

Finding Added Value in a RMIS: Five Benefits of Using the System for Litigation Management

Insight_Blog_Operational Resilience
Blog

Operational Resilience vs. Business Continuity: What Every Risk Leader Needs to Know

Insight_Blog_ERM Programs Fail
Blog

Why Your ERM Program Produces Reports No One Acts On

Connect with us

Whether you’re exploring solutions or ready to scale, our team is here to help build something great.