Skip to content
Client Focus

Regulatory readiness

US bank supervision: OCC, FDIC, Federal Reserve, FFIEC and NYDFS

United States banking agencies permit a range of digital asset activity, including node operation and custody, provided it is conducted in a safe and sound manner. The examination question is operational: where does the activity run, who administers it, and what is the record.

What the regime is

OCC Interpretive Letter 1183 reaffirmed that national banks may engage in crypto-asset custody, certain stablecoin activities and node operation, and removed the prior supervisory non-objection requirement. The FDIC took parallel action for supervised institutions. Neither changed the standard: the activity must be safe and sound.

In practice the applicable expectations are the ones banks already operate under. The 2023 Interagency Guidance on Third-Party Relationships governs provider oversight. FFIEC IT Examination Handbook booklets govern outsourcing and continuity. NYDFS 23 NYCRR Part 500 applies to New York licensed entities. BSA/AML and OFAC obligations apply at the boundary between fiat and on-chain settlement.

Who it applies to

  • National banks and federal savings associations supervised by the OCC.
  • State non-member banks supervised by the FDIC.
  • State member banks and holding companies supervised by the Federal Reserve.
  • Entities licensed by NYDFS, including virtual currency business activity licensees.

Last reviewed: August 22, 2026

An empty bank boardroom with natural light

What the rules require in operation

Each obligation is stated with the operating consequence and the evidence a supervisor or auditor asks to see.

Obligations, operational meaning and evidence for US bank supervision
ObligationWhat it means for a digital asset operationEvidence to produce
Safe and sound node operationHost hardening, client diversity, validator key protection, monitoring and change control for every node the bank operates or relies on.Architecture records, hardening baselines, change tickets and monitoring output.
Third-party risk managementDue diligence, contract terms and ongoing monitoring for chain infrastructure, monitoring and analytics providers.Assessment files, oversight records and performance reporting.
Information security programAccess management, encryption, logging and incident response extended to the on-chain estate.Control testing results, access reviews and incident records.
BSA/AML and sanctionsScreening of counterparties and addresses at the boundary, with escalation for mixer and sanctioned exposure.Screening decisions, case files and escalation records.
Business continuityContinuity and recovery planning that assumes networks continue operating during a bank outage.Plans, test results and recovery time measurement.
Separation of dutiesIndependent reporting lines between teams that build a system and teams that monitor it, where required by the bank or its supervisor.Service agreement terms, access records and attestation of the separation.

Key dates

  1. March 2025

    OCC Interpretive Letter 1183 published.

  2. March 2025

    FDIC FIL-7-2025 issued for supervised institutions.

  3. June 2023

    Interagency Guidance on Third-Party Relationships finalized.

  4. Ongoing

    FFIEC handbook expectations and NYDFS Part 500 examinations.

How Client Focus supports it

Run

ITIL-based incident, problem and change management with named service owners and hop-by-hop timestamps on every escalation.

Secure

Continuous monitoring, analyst validation and a published notification clock, with incident records retained for reporting.

Trust and compliance

Control frameworks, separation of duties and the due-diligence pack supervisors and procurement teams ask for.

Prepare for supervisory review.

Whether you are designing a new system, running one in production, or defending one, Client Focus brings engineering, network operations and security operations under one accountable model. Every request is reviewed by a principal of the firm.