Banks: 3 OCC Letters Reshaping Crypto Guidance, Custody, and Exams

The OCC now treats crypto‑asset custody, execution, riskless principal trading, and limited incidental holdings as permissible national bank activities, provided the bank runs them through standard risk-management, BSA/AML, and OFAC controls. There’s no special carve‑out anymore: the OCC rescinded its earlier requirement that banks get a supervisory non‑objection before starting, which means these activities now move through routine examination like any other banking service. Permissibility is technology-neutral. Your control environment is what gets evaluated.
TL;DR:
- Banks can now conduct crypto custody, execution, and limited incidental holdings through routine exams without prior non-objection, provided controls meet OCC standards.
- Operational controls must justify key management choices, account models, and audit coverage, with fiduciary status explicitly clarified under OCC guidance.
- Riskless principal crypto transactions are classified as incidental powers, requiring transaction logs, reconciliation, and current records to demonstrate no market risk.
- Outsourcing crypto services does not transfer responsibility; banks need thorough due diligence, contractual controls, ongoing monitoring, and contingency plans for vendors.
- Combining strong governance, operational readiness, and layered compliance checks is essential to pass OCC examinations and demonstrate a robust risk management environment.
Table of Contents
- OCC Crypto Guidance: What Changed With IL 1183 and IL 1184
- Custody and Safekeeping: The Operational Controls Examiners Expect
- Riskless Principal Crypto Transactions Under IL 1188
- Outsourcing Crypto Services: Third-Party Risk Management Expectations
- Strengthening AML, BSA, and Governance Controls for Crypto Activities
- Building an Exam-Ready Package for OCC Review
- The OCC’s Broader Strategic Posture on Crypto
- How the OCC Classifies Crypto Assets: Payment, Investment, and Security Tokens
- Stablecoin Custody and Reserve Activities Under OCC Oversight
- Operational, Compliance, and Reputational Risks the OCC Has Flagged
- Consumer Protection Expectations for Bank Crypto Products
- Coordination With the SEC, CFTC, and FinCEN on Crypto Rules
- Authoritative OCC and Interagency Documents to Bookmark
- A Governance-First Read on Where OCC Guidance Is Headed
- A Structured Path to Crypto Readiness for Banks
- Sources
OCC Crypto Guidance: What Changed With IL 1183 and IL 1184
Three documents rewired the playing field in 2025. The first, NR-2025-16, announced the policy shift: crypto custody, certain stablecoin reserve activities, and node participation are permissible, and the prior non-objection process under IL 1179 is gone.
Interpretive Letter 1183 did the legal heavy lifting. It formally rescinds IL 1179, reaffirms the permissibility positions laid out in IL 1170, IL 1172, and IL 1174, and states plainly that the OCC will now examine these activities under its ordinary supervisory processes rather than a special pre-clearance track.
Interpretive Letter 1184 builds on that foundation with custody and outsourcing examples, distinguishing fiduciary custody arrangements (where the bank holds crypto assets under trust powers with attendant fiduciary duties) from non-fiduciary safekeeping (where the bank holds keys or assets as agent without discretionary trust authority).
The practical effect for a bank compliance officer:
- No more waiting on a case-by-case non-objection letter before launching a custody or execution product
- Activities discussed in IL 1170/1172/1174 remain the baseline permissibility precedent
- Your examiner will now assess crypto activities the same way they assess any other line of business: through the standard exam cycle, informed by your risk profile and control maturity
That last point matters more than it sounds. Standard exam treatment means crypto isn’t quarantined into a special review queue anymore. It also means there’s no regulatory grace period to lean on if your controls are thin.
Custody and Safekeeping: The Operational Controls Examiners Expect
The joint interagency bulletin on crypto-asset safekeeping, issued by the OCC alongside the Federal Reserve and FDIC, is the closest thing to an operational rulebook banks have for this space. It covers key management, account structures, recordkeeping, and audit coverage in more detail than any interpretive letter.
Banks offering custody need to make deliberate choices, not default ones:
- Key management architecture: cold storage versus hot wallets, multi-signature schemes, and hardware security module deployment all carry different risk profiles that examiners will ask you to justify
- Account model: omnibus accounts pool customer assets on-chain (cheaper, but harder to trace customer-level ownership), while segregated accounts isolate each customer’s holdings (costlier, but cleaner for reconciliation and insolvency protection)
- Insurance posture: crime and specie insurance coverage for digital assets is still a developing market, and gaps should be disclosed internally, not discovered during an incident
- Independent audit coverage: key management, wallet reconciliation, and access controls need testing by parties outside the team that operates them
Pro Tip: Don’t let your custody agreement stay silent on fiduciary status. IL 1184’s fiduciary versus non-fiduciary distinction changes your duty of care, your disclosure obligations, and how examiners will read your contracts. Get outside counsel to confirm which bucket your product actually falls into before you launch, not after.
AML and OFAC overlay applies here just as it does everywhere else in the bank. A custody client onboarding process that skips wallet-address screening or source-of-funds review on inbound transfers is a gap examiners will find quickly.
Riskless Principal Crypto Transactions Under IL 1188
Interpretive Letter 1188 confirms national banks can execute riskless principal transactions in crypto-assets, grounded in the incidental powers clause of 12 U.S.C. § 24(Seventh). A riskless principal trade means the bank takes the position momentarily to fill a customer order and offsets it immediately, never carrying market exposure. That’s the legal distinction that separates it from proprietary trading, which the OCC treats far more cautiously.
The letter frames this as a modern equivalent to traditional brokerage and custody functions banks have run for decades, just applied to a new asset class. Examiners will look for evidence the bank actually operates this way in practice, not just on paper. That means:
- Transaction-matching logs showing each customer order paired against an offsetting trade within a defined window
- Settlement risk controls that flag any position held longer than the bank’s documented threshold
- Reconciliation performed on a cadence tight enough to catch drift between customer positions and bank holdings
- Legal opinions or internal memos documenting the functional-equivalence analysis under Section 24(Seventh)
Keep these records live, not archived. An examiner asking “show me you don’t carry inventory risk” wants current data, not a policy statement from eighteen months ago.
Outsourcing Crypto Services: Third-Party Risk Management Expectations
The OCC has been consistent on one point across NR-2025-42 and every custody-related bulletin: outsourcing crypto custody or execution to a vendor does not transfer the bank’s responsibility. The bank remains accountable for the outcome regardless of who runs the technology.
Building a defensible TPRM program for crypto vendors means covering:
- Due diligence before signing: financial stability, security architecture, regulatory history, and insolvency protections for customer assets
- Contractual controls: audit rights, data ownership, service level commitments, and exit provisions if the relationship ends
- Ongoing monitoring: SOC 2 reports, penetration test results, and incident notifications on a defined schedule
- Contingency planning: a documented path to transition custody or execution in-house or to another vendor if the relationship fails
Vendors handling key management deserve extra scrutiny. Ask for insolvency analysis proving customer asset segregation, and negotiate a contractual right to access key escrow under defined trigger conditions. A structured operational risk policy built around these questions makes vendor reviews repeatable instead of ad hoc.
Pro Tip: Keep a running file of vendor SOC reports, penetration test summaries, and your own monitoring logs. Examiners rarely accept “we trust our vendor” as an answer, but they respond well to a paper trail showing you’re actively verifying that trust.
Strengthening AML, BSA, and Governance Controls for Crypto Activities
Permissibility didn’t lower the compliance bar. Guidance tied to the safekeeping bulletin is explicit that BSA/AML and OFAC programs need to be calibrated for the pseudonymous, cross-border nature of on-chain transactions, which behave differently than a wire transfer or an ACH batch.
Concrete steps that move a bank from adequate to strong:
- Build customer risk scoring models that account for wallet history and counterparty exposure, not just KYC data collected at onboarding
- Layer on-chain monitoring patterns (mixing service exposure, sanctioned address screening, unusual transaction clustering) on top of traditional transaction monitoring rules
- Document sanctions screening against OFAC’s SDN list at the wallet-address level, not just the customer-name level
- Maintain a SAR filing workflow that captures crypto-specific red flags your BSA officer can articulate to examiners
Governance evidence matters as much as the controls themselves. Board-approved policies, documented training completion, and a risk appetite statement that names crypto activities specifically all belong in your exam file. The OCC’s own emphasis on technology neutrality means examiners are grading your control environment, not the novelty of the asset class. A digital asset AML checklist built for the current cycle helps translate that standard into a repeatable process rather than a one-time policy exercise.
Independent audit coverage should test key management integrity, reconciliation accuracy, monitoring rule effectiveness, and incident response, not just confirm policies exist on paper.
Building an Exam-Ready Package for OCC Review
Examiners move faster, and form better impressions, when a bank shows up with an organized evidence file instead of scrambling to assemble documents mid-review. A well-prepared package typically layers three categories of material.
- Governance documentation: board and committee charters, meeting minutes referencing crypto activity approvals, signed policy documents, and completed training logs for staff and directors
- Operational artifacts: key-management architecture diagrams, custody agreements, reconciliation playbooks, and logs from settlement testing that prove the riskless principal model works as documented
- Compliance and vendor files: AML rule tuning documentation, redacted SAR examples showing your escalation flow in action, vendor risk assessments, penetration test and SOC reports, and a record of audit findings alongside their remediation status
An integrated package built around these three buckets, rather than scattered folders by department, is what separates a smooth exam from a drawn-out one.
| Evidence category | What to include | Who owns it |
|---|---|---|
| Governance | Charters, minutes, policy approvals, training logs | Board/legal |
| Operations | Key architecture diagrams, custody agreements, settlement logs | Operations/technology |
| Compliance | AML tuning records, redacted SARs, vendor assessments, audit findings | Compliance/risk |
A governance framework built for enterprise crypto oversight can help structure this before an exam notice ever lands, rather than assembling it under deadline pressure.
The OCC’s Broader Strategic Posture on Crypto
The 2025 wave of interpretive letters and bulletins reflects a deliberate strategic choice rather than a piecemeal reaction. The OCC withdrew from two prior interagency joint statements as they applied to national banks, a move documented in Bulletin 2025-2, signaling a preference for handling crypto activities inside the agency’s existing supervisory architecture rather than through special joint frameworks.
The underlying philosophy is technology neutrality: a bank offering crypto custody gets evaluated on the same risk-management criteria as a bank offering traditional trust or brokerage services. There’s no separate, stricter rulebook reserved for distributed ledger technology, and there’s no lighter one either.
This matters strategically for banks weighing whether to enter the space. The OCC isn’t inviting banks to experiment cautiously at the margins. It’s saying the activities are permissible under the same national bank powers that have governed custody, brokerage, and payments for decades, so long as the bank can demonstrate it manages the risk as competently as it manages any other line of business.
That framing raises the bar for smaller and mid-size banks without deep compliance benches. A community bank chartering into crypto custody faces the identical control expectations as a money-center bank, scaled to its size but not relaxed in substance. The strategic signal is that the OCC wants broader bank participation in digital assets, provided the control environment earns it. Banks that treat this as a green light to move fast without matching investment in risk infrastructure are the ones most likely to draw a matter requiring attention at their next exam.
How the OCC Classifies Crypto Assets: Payment, Investment, and Security Tokens
OCC guidance doesn’t create its own crypto-asset taxonomy from scratch. Instead, it defers heavily to how an asset functions economically and legally, which means a bank’s classification exercise has to draw on securities law, payments law, and the specific interpretive letters governing each activity.
Payment tokens, the category that includes most stablecoins used for settlement, get treated functionally like other payment instruments the bank already handles, with the custody and reserve-holding permissions addressed directly in the 2025 interpretive letters. Investment tokens, representing an ownership stake or a claim on future cash flows, trigger a different analysis that leans on whether the asset meets the definition of a security under federal securities law, a determination that ultimately sits with the SEC rather than the OCC.
Security tokens sit at the more complex end. A bank custodying or executing trades in an asset that functions as a security needs to confirm its activity doesn’t require registration or licensing beyond its national bank charter, and that often means coordinating with securities counsel before launch, not after.
The practical takeaway for compliance teams: classification isn’t a one-time label. A single token can carry payment characteristics in one use case and investment characteristics in another, depending on how a customer acquires and uses it. Banks should document the classification analysis for each product line separately, rather than assuming a blanket categorization covers every asset the bank touches.
Stablecoin Custody and Reserve Activities Under OCC Oversight
Stablecoins get specific, favorable treatment in the 2025 guidance wave. The OCC’s clarification confirms that banks may hold reserves backing stablecoins and provide custody services for stablecoin issuers, treating these activities as extensions of the custody and deposit-taking functions banks already perform.
The reserve-holding piece deserves particular attention. A bank acting as reserve custodian for a stablecoin issuer needs controls proving the reserve assets genuinely back the outstanding tokens on a dollar-for-dollar or otherwise disclosed basis, since any gap between reserves and circulating supply is exactly the kind of mismatch that draws examiner and market attention fast.

Banks providing stablecoin-related services should expect scrutiny on three fronts: whether reserve assets are held in a manner that protects them in the issuer’s insolvency, whether attestation or audit processes confirm reserve adequacy on a regular schedule, and whether the bank’s own risk appetite statement explicitly contemplates this activity rather than treating it as an extension of ordinary deposit services.
Stablecoin activity also intersects with payments regulation more directly than other crypto activities, since a token designed for transactional use functions economically like a payment rail. Banks should not assume that OCC’s favorable posture on stablecoin custody removes the need to track parallel guidance from FinCEN on money transmission characteristics or from state regulators where the issuer operates under a state money transmitter license.
Operational, Compliance, and Reputational Risks the OCC Has Flagged
The OCC’s guidance is permissive on activity, but it hasn’t softened its risk warnings. Three categories recur across the interpretive letters and bulletins.
Operational risk tops the list, centered on key management failures. A lost or compromised private key isn’t recoverable the way a forgotten bank password is, and the safekeeping bulletin treats this as the single highest-consequence failure mode in custody services. Banks need documented recovery procedures, redundant key storage, and tested incident response playbooks specifically built around irreversible loss scenarios.
Compliance risk stems from the pseudonymous, cross-border character of blockchain transactions. Traditional transaction monitoring rules tuned for wire transfers and card payments often miss patterns specific to on-chain activity, which means a compliance program that hasn’t been recalibrated for crypto will likely underperform even if it’s technically running.
Reputational risk gets less airtime in the interpretive letters but shows up consistently in supervisory commentary. A bank associated with a customer-facing crypto failure, whether a hack, a stablecoin depeg, or a vendor insolvency, faces headline risk disproportionate to the dollar exposure involved, given how closely crypto incidents get covered relative to comparable traditional-finance failures. Banks entering this space should model reputational exposure into their risk appetite discussions, not just capital and liquidity impact.
Consumer Protection Expectations for Bank Crypto Products
Consumer-facing crypto products carry the same fair-lending, disclosure, and complaint-handling expectations that apply to any retail banking product, with a few crypto-specific wrinkles layered on top.
Disclosures need to address volatility risk in plain language, since a customer opening a crypto custody account may not intuitively understand that the underlying asset value can swing sharply in ways a traditional deposit account never would. Banks should also clarify insurance status explicitly: crypto assets held in custody are not FDIC-insured the way deposit balances are, and any marketing material or account opening disclosure that blurs that line invites regulatory attention fast.
Complaint-handling processes need a crypto-specific track, since issues like failed transaction settlement, key recovery disputes, or delayed withdrawals don’t map neatly onto existing complaint categories built for checking accounts and credit cards. Banks should also review marketing materials carefully for language that could be read as implying government backing or guaranteed returns, both of which invite scrutiny under existing consumer protection frameworks even without crypto-specific rules attached.
Staff training deserves a direct mention here too. Frontline employees fielding customer questions about a bank’s crypto custody product need accurate, consistent talking points, since inconsistent answers across branches or call center representatives is a pattern examiners specifically probe for during consumer compliance reviews.
Coordination With the SEC, CFTC, and FinCEN on Crypto Rules
OCC permissibility doesn’t operate in isolation. A bank’s crypto activity almost always sits inside a web of overlapping federal oversight, and missing one layer while satisfying another is a common, costly mistake.
The SEC’s jurisdiction kicks in whenever a crypto-asset functions as a security, regardless of what the OCC has said about a bank’s authority to custody or trade it. A bank offering custody for a token later determined to be a security needs to confirm its activity doesn’t require broker-dealer or transfer agent registration, a question the OCC’s interpretive letters explicitly leave to securities law.
The CFTC’s authority centers on commodity derivatives and, in some interpretations, spot markets for certain digital assets. Banks running trading desks that touch crypto derivatives need to layer CFTC-relevant controls, including position reporting and margin requirements, on top of whatever the OCC requires for the underlying custody or execution activity.
FinCEN’s money transmission and BSA rules apply regardless of which other regulator has weighed in, since virtually every crypto activity a bank performs touches the movement of value across accounts or borders. A bank’s AML program needs to satisfy FinCEN’s expectations independently, not simply inherit OCC’s risk-management language as a substitute.
The practical discipline here is treating each regulator’s requirements as additive rather than assuming OCC clearance satisfies the field. A compliance team that maps every crypto product against all four regulators’ current requirements, updating that map as guidance shifts, avoids the gap where one agency’s silence gets mistaken for another agency’s approval.

Authoritative OCC and Interagency Documents to Bookmark
For anyone building a compliance file, these are the primary documents worth keeping on hand rather than relying on summaries:
- Interpretive Letter 1183: the rescission of IL 1179 and the core permissibility statement
- Interpretive Letter 1188: riskless principal transaction authority and its statutory basis
- Interpretive Letter 1184: custody and outsourcing examples, fiduciary versus non-fiduciary distinctions
- Joint safekeeping bulletin (2025-17): operational expectations for key management and audit
- NR-2025-16 and NR-2025-42: agency-level summaries of the policy shift
The interpretive letters and the joint bulletin carry direct regulatory weight; the news releases are useful plain-language summaries but shouldn’t substitute for reading the letters themselves.
A Governance-First Read on Where OCC Guidance Is Headed
The technology-neutral framing in these letters isn’t a formality. It’s a direct statement that novelty buys a bank nothing anymore. What separates a permissible activity from a supervisory problem is whether the control environment can hold up under routine examination, the same bar applied to every other banking function.
That’s exactly where most banks underestimate their exposure. Teams get the legal permissibility question right and then treat documentation, audit coverage, and evidence tracking as an afterthought, assuming the interpretive letters do the compliance work for them. They don’t. A structured certification approach, one that maps controls to specific exam expectations and produces a verifiable record of what’s actually been tested and trained, closes exactly the gap that ad hoc compliance programs leave open. That’s the readiness problem DARE was built to address.
— Gregg
A Structured Path to Crypto Readiness for Banks
Building the evidence package OCC examiners expect, key management diagrams, vendor assessments, training logs, audit trails, from scratch under deadline pressure is where most banks lose ground. A certification program can give compliance, risk, and treasury teams a structured framework that maps directly to the control categories examiners actually test: custody governance, TPRM, AML program maturity, and operational resilience.

DARE isn’t a custody platform or an execution venue. It’s a certification and documentation framework that organizes the evidence your bank already needs to generate, modular learning tied to specific compliance domains, assessments that produce a verifiable credential, and annual renewal that keeps your readiness posture current as OCC guidance evolves. For a bank preparing a charter application or gearing up for its first exam cycle touching crypto activity, that structure turns scattered internal effort into something an examiner can actually follow.
If your team is assembling a crypto compliance program and wants a framework built around exam-ready evidence rather than internal guesswork, explore the DARE certification and see how the modules map to your current gaps.
Sources
- OCC Clarifies Bank Authority to Engage in Certain Cryptocurrency Activities | OCC
- Interpretive Letter 1183 — OCC
- Interpretive Letter 1188 — OCC
- Bank Activities: Crypto-Asset Safekeeping Services | OCC
