OCC Issues September 2026 Enforcement Actions Targeting Individual Misconduct
The Office of the Comptroller of the Currency (OCC) released its scheduled enforcement actions for September 2026, highlighting direct regulatory penalties against individual actors within the traditional banking sector. The release details specific administrative measures taken under federal banking statutes to penalize misconduct, address internal control failures, and enforce individual accountability across federally regulated financial institutions.
What Happened: The September 2026 Actions
According to the OCC release issued on September 17, 2026, the regulator executed Orders of Prohibition against two distinct institution-affiliated parties (IAPs). These regulatory orders are designed to deter, correct, or prevent statutory violations, unsafe or unsound banking practices, and breaches of fiduciary duty.
The regulatory actions target specific individuals across two major national banking institutions:
* **Zena Montejano:** The OCC issued an Order of Prohibition (Docket No. AA-ENF-2026-38) against Zena Montejano, a former home-based Contact Center Personal Banker based in Corona, California, for U.S. Bank, N.A., located in Cincinnati, Ohio. The action followed findings that Montejano embezzled approximately $329,088 from the bank. * **Jorge Troncoso:** The OCC issued an Order of Prohibition (Docket No. AA-ENF-2026-6) against Jorge Troncoso, a former Branch Banker at a Houston, Texas, branch of PNC Bank, N.A., located in Wilmington, Delaware. The action stemmed from Troncoso making unauthorized debits from multiple customer accounts, resulting in bank losses of at least $74,550.
Regulatory Mechanics and Individual Accountability
Under 12 USC 1813(u), the statutory definition of an "institution-affiliated party" encompasses a broad array of personnel, including bank directors, officers, employees, and controlling shareholders. By deploying Orders of Prohibition under 12 USC 1818(e)(7), the OCC legally bars named individuals from participating in any capacity in the affairs of a bank or other covered financial institution.
These regulatory steps emphasize that federal oversight extends past macro-prudential capital rules and liquidity requirements down to direct individual conduct. QFN analysis indicates that while enforcement actions frequently target institutional risk management frameworks, actions directed at IAPs serve as a direct mechanism to police internal fraud and operational risk at the employee level.
Implications for Financial Infrastructure and Compliance
For financial institutions, payments infrastructure providers, and digital asset firms building compliance frameworks, regulatory enforcement updates serve as a baseline for internal controls. The cases highlight ongoing vulnerabilities in both traditional branch environments and home-based or remote customer service operations.
Preventing unauthorized debits and internal embezzlement requires robust dual-control mechanisms, continuous monitoring of account-level adjustments, and stringent oversight of remote banking infrastructure. As the financial sector modernizes through automated payment rails, tokenized assets, and digital ledger integrations, traditional risks like internal fraud and unauthorized account access remain core operational challenges that regulators monitor closely.
The OCC maintains a searchable public database of all public enforcement actions taken since August 1989, accessible via its official portal for ongoing tracking of regulatory decisions.
Read the original report from the [Office of the Comptroller of the Currency](https://www.occ.gov/news-issuances/news-releases/2026/nr-occ-2026-79.html).
Source * [OCC News Release 2026-79](https://www.occ.gov/news-issuances/news-releases/2026/nr-occ-2026-79.html)
