Skip to content
Client Focus

Insights

OCC Interpretive Letter 1183: banks may act as nodes on distributed ledgers, with supervisory expectations attached

The OCC reaffirmed that national banks may engage in crypto-asset custody, certain stablecoin activities and node operation without prior supervisory non-objection, provided the activity is conducted in a safe and sound manner.

Regulatory briefings

Published
August 22, 2026
Covers
March 2025
Reading time
6 minutes
By
Client Focus

Interpretive Letter 1183 restored a permission and attached a condition. National banks and federal savings associations may provide crypto-asset custody, engage in certain stablecoin activities and participate in distributed ledger networks as validation nodes. The prior requirement to obtain supervisory non-objection before beginning those activities was removed. What was not removed is the expectation that the activity is conducted in a safe and sound manner, with the same risk management a bank applies to any other technology it depends on.

What the letter changed

The 2021 framework required a bank to notify its supervisory office and receive written non-objection before engaging. Letter 1183 rescinded that step and reaffirmed the earlier interpretive letters that established the underlying authority. The practical effect is that the decision moves inside the bank. A national bank that wishes to run a validator, hold crypto-assets in custody or support a payment stablecoin arrangement makes that decision through its own governance and defends it at examination.

What safe and sound means for a node

A validating node is production infrastructure with financial consequence. The operational expectations follow from that: hardened hosts with a controlled build and verified binaries; client software diversity where the network supports it, so a single implementation bug does not remove the bank from consensus; protection of validator and withdrawal keys under the same custody discipline applied to other cryptographic material; continuous monitoring of sync state, peer count, attestation performance and slashing conditions; change control that records who upgraded which client at what version and when; documented incident handling with named owners; and third-party oversight for the hosting, RPC and monitoring suppliers that sit behind the service.

That last point ties to the June 2023 Interagency Guidance on Third-Party Relationships. Node operation is rarely fully in-house. Cloud regions, staking technology providers, key management vendors and telemetry suppliers each require planning, due diligence, contract terms, ongoing monitoring and a termination path proportionate to the risk.

The FDIC's parallel action and the open question

FIL-7-2025 followed a similar path for FDIC-supervised institutions, rescinding the prior notification expectation while reiterating safety and soundness. The open question in both cases is public, permissionless networks. Permissioned deployments raise a narrower set of counterparty and governance issues. A bank participating in a public network inherits exposure to protocol changes it does not control, to a validator set it does not select and to transaction flow it must screen rather than approve. Supervisors have not treated that as prohibited. They have treated it as a matter requiring evidence.

The questions an examiner will ask

Where does the node run, and under whose administrative control. Who holds the keys, and what breaks if that person is unavailable. What is monitored, who receives the alert, and how quickly does a named person respond. What is the record of the last three configuration changes. A bank that can answer those four questions with documents rather than descriptions is prepared.

An empty regulator hearing room with nameplates and microphones in daylight

Continue reading

A printed policy binder open on a desk beside reading glasses

The GENIUS Act is law: what permitted stablecoin issuers should prepare for

Federal stablecoin legislation created a licensing regime for payment stablecoin issuers and set the stage for implementing rules on reserves, redemption, controls and third-party oversight.

Compliance analysts reviewing documentation in a meeting room

Node and RPC health as a security signal

Infrastructure degradation is often the first visible symptom of an attack or a failed change; the network operations center and the security operations center must share telemetry.

Printed operational reports and a notebook on a desk in daylight

2025 in review: the year digital assets became an operations problem

Regulation arrived, losses concentrated, and banks moved to public networks. The common thread was accountability for operations.

Apply this to your own operations.

Client Focus reviews the estate, the coverage required and the gaps, then sets out what changes.