US crypto & fintech regulation, in plain English
Every major rule from FinCEN, OCC, OFAC, the SEC and CFTC — explained, with who it affects and what to do. Free, always current, no signup.
Major rule trackers
The GENIUS Act: federal rules for payment stablecoins
Signed into law — illicit-finance rules being finalized (expected mid-2026)
The first major U.S. digital-asset law. It creates a federal licensing and supervision regime for payment-stablecoin issuers: 1:1 reserves in cash or short-dated Treasuries, bank-like safety-and-soundness standards, and full BSA/AML obligations. Treasury, FinCEN, and OFAC are now writing the implementing rules.
Open trackerU.S. Congress · SEC · CFTCThe CLARITY Act: who regulates crypto — the SEC or the CFTC?
Advancing through Congress — joint SEC/CFTC guidance already issued
The market-structure bill that aims to end the SEC-vs-CFTC turf war over crypto. It sets statutory rules for when a digital asset is a security (SEC) versus a digital commodity (CFTC), replacing years of enforcement-by-litigation with a defined regulatory perimeter.
Open trackerOCC Updates Cybersecurity Examination Work Program for Banks
The OCC has revised its Cybersecurity Supervision Work Program (CSW), which examiners use to assess cybersecurity risk at national banks and federal savings associations, updating its structure and references to reflect the evolving threat landscape and adoption of standardized frameworks. For compliance and risk officers at banks, neobanks, and trust companies under OCC supervision, this signals updated examiner expectations around cybersecurity controls and preparedness. Crypto custodians and fintechs with bank charters or partnerships should also take note, as vendor and third-party cybersecurity risk is often assessed through this lens.
OCC Joins Interagency Proposed Third-Party Risk Management Guidance
The OCC is co-issuing the same interagency third-party risk management proposal alongside the Fed, FDIC, and NCUA, signaling a unified supervisory approach across the federal banking agencies. National banks and federal savings associations should treat this as a near-certain indicator of forthcoming binding expectations on vendor oversight. The proposal's emphasis on risk-proportionate controls is particularly relevant for institutions using crypto or fintech service providers.
OCC/Fed/FDIC Raise Asset Threshold for 18-Month Exam Cycle to $6 Billion
An interim final rule from the OCC, Federal Reserve, and FDIC raises the total asset threshold that allows certain well-managed, well-capitalized insured depository institutions and U.S. branches of foreign banks to qualify for an extended 18-month on-site examination cycle. Smaller banks and trust companies that fall below the new threshold may see reduced examination frequency, affecting the pace of supervisory feedback on compliance programs. Fintech-partnered banks and crypto-custody trust companies under the threshold should be aware that less frequent exams do not reduce compliance obligations.
Regulators Clarify How They Will Oversee Core Tech Providers to Community Banks
The OCC, Federal Reserve, and FDIC have issued an interagency statement explaining how they will apply risk-based supervision and enforcement to core service providers — such as technology and data processors — that serve community banking organizations. This matters for fintechs and crypto firms acting as technology vendors or service providers to banks, as it signals heightened regulatory scrutiny of the bank-vendor relationship and the factors examiners will weigh when taking supervisory or enforcement action against those providers.
OCC Proposes Tailored Third-Party Risk Rules and Eases Core Provider Oversight Burden
The OCC announced a proposal to tailor third-party risk management requirements to actual risk levels, aiming to reduce compliance burden on community banks while maintaining safety standards — accompanied by new supervisory clarity on core service providers. Fintech and crypto firms that serve as third-party vendors to OCC-supervised banks should expect that the banks' due diligence, contracting, and monitoring obligations toward them may be recalibrated based on risk tier.
Agencies Propose Updated Third-Party Risk Management Guidance — Comment Period Open
The FDIC, Federal Reserve, NCUA, and OCC have jointly proposed updated guidance to help financial institutions manage risks in third-party relationships and are seeking public comment. Crypto firms, fintechs, and payment companies that serve as third-party vendors to regulated financial institutions — or that rely on third-party technology providers themselves — should review the proposal, as it will shape the due diligence, contracting, and oversight standards their bank clients must apply.
Federal Agencies Seek Public Comment on New Third-Party Risk Management Guidance
The FDIC, Federal Reserve, NCUA, and OCC are jointly requesting comment on proposed guidance designed to help regulated financial institutions better manage third-party relationship risks. This is directly relevant to fintechs and crypto firms that either rely on third-party vendors or are themselves vendors to regulated banks, as the final guidance will define the risk management expectations those institutions must meet.
Regulators Clarify: Mobile Driver's Licenses & Digital IDs Can Satisfy KYC Rules
Five federal regulators — OCC, FinCEN, the Federal Reserve, FDIC, and NCUA — jointly issued FAQs confirming that state-issued mobile driver's licenses and other government-issued verifiable digital credentials (VDCs) can be used to satisfy Customer Identification Program (CIP) requirements under the Bank Secrecy Act. This is significant guidance for crypto and fintech firms because it provides regulatory clarity on accepting digital identity documents during onboarding, reducing reliance on physical ID checks. Compliance officers should review the FAQs carefully to understand the conditions and limitations under which VDCs qualify as acceptable identity verification methods.
Regulators Clarify What Banks Can (and Can't) Tell Customers About SARs
Five federal regulators — OCC, Federal Reserve, FDIC, FinCEN, and NCUA — jointly clarified the rules around SAR confidentiality when institutions communicate with customers about potentially fraudulent transactions. The statement addresses a persistent compliance tension: institutions must protect SAR confidentiality (including not 'tipping off' subjects) while still being able to warn or question customers about suspicious activity without inadvertently disclosing a SAR has been filed. Compliance officers should review customer-facing fraud communication workflows to ensure staff are not crossing the tipping-off line.
OCC Proposes Two-Tier Framework for Violations: Substantive vs. Technical
The OCC is proposing to split regulatory violations into 'substantive' and 'technical' categories to better calibrate supervisory responses, including when Matters Requiring Attention (MRAs) are issued. For banks and trust companies engaged in crypto or fintech activities, this could affect how examiners escalate findings related to BSA/AML, KYC, or digital asset compliance gaps. Comment period is open, giving institutions an opportunity to shape the final framework.
OCC Revises Enforcement Action and MRA Policies and Procedures
The OCC has released updated internal policy manuals governing how bank enforcement actions and Matters Requiring Attention (MRAs) are issued and managed. These revisions signal a shift toward greater consistency and transparency in how the OCC responds to supervisory findings, which is directly relevant to banks and trust companies navigating crypto, BSA/AML, and fintech-related examination findings. Compliance officers should review the updated PPMs to anticipate examiner expectations.
OCC Announces Clearer, More Consistent Enforcement and Supervisory Standards
The OCC announced coordinated actions to improve transparency in how it issues MRAs and enforcement actions, including two revised policy manuals and a proposed rule change to the violations framework. For banks and trust companies—including those offering crypto custody or digital asset services—this means greater predictability in how examination findings will be escalated. Compliance teams should treat this as an opportunity to reassess their internal remediation and examiner-relations processes.
OCC & FDIC Finalize Rule Defining 'Unsafe or Unsound Practice' and MRA Standards
The OCC and FDIC have jointly issued a final rule that formally defines 'unsafe or unsound practice' under the Federal Deposit Insurance Act and restructures the supervisory framework for issuing MRAs and other supervisory communications. This rule directly affects how examiners at both agencies will identify and escalate compliance deficiencies—including those related to digital assets, BSA/AML, and fintech partnerships—at banks and insured depository institutions. Institutions should update their compliance risk frameworks to align with the new definitions and thresholds.
OCC Comptroller Signals Support for Digital Assets and GENIUS Act Next Steps
Comptroller Gould publicly addressed the OCC's role in advancing digital asset innovation and supporting the administration's digital currency priorities at the Wyoming Blockchain Symposium, including next steps related to the GENIUS Act. This signals that the OCC is actively shaping the federal regulatory framework for stablecoins and digital assets, which has direct implications for banks and trust companies considering or already offering crypto-related services. Compliance officers should treat this as an indicator of near-term guidance or rulemaking activity from the OCC in the digital asset space.
OCC Pushes to Revive De Novo Bank Chartering — Crypto Firms Take Note
The OCC is actively prioritizing the revival of de novo bank chartering and commends the FDIC for similar efforts, signaling a more welcoming regulatory environment for new bank applicants. For crypto firms and fintechs that have explored obtaining a national bank or trust charter, this renewed focus may lower barriers and accelerate application review timelines.
Treasury & OCC Signal Reduced Regulatory Burden for Community Banks
Treasury Secretary Bessent and Comptroller Gould publicly emphasized the Trump Administration's intent to reduce regulatory burden on community banks while maintaining protections against illicit financial activity. This signals a potential shift in supervisory tone and priorities that could influence AML/BSA examination expectations and future rulemaking for smaller depository institutions.
Agencies Ease Enforcement for Venezuela Earthquake Humanitarian Transactions
The OCC, Federal Reserve, FDIC, and NCUA issued a joint statement relaxing enforcement posture for financial transactions supporting humanitarian relief and financial stability in Venezuela following recent earthquakes. Compliance officers at banks and fintechs should be aware this may create a temporary, limited pathway for Venezuela-related transactions that would otherwise raise sanctions red flags — but it does not suspend OFAC rules outright, so careful documentation of the humanitarian nexus remains essential.
OCC/Fed/FDIC Update Compliance Guide for Community Bank Leverage Ratio Framework
The OCC, Federal Reserve, and FDIC jointly revised the Community Bank Leverage Ratio (CBLR) compliance guide, reflecting updates to the framework used by qualifying community banks as a simplified alternative to the full Basel III capital regime. Compliance officers at community banks and bank-affiliated trust companies should review the revised guide to confirm their institution's capital reporting and election procedures remain aligned with current agency expectations. Although not directly a crypto-specific rule, banks providing custody, payments, or crypto-related services need adequate capital frameworks underpinning those activities.
OCC Issues Revised CBLR Framework Compliance Guide for Community Banks
The OCC published a revised compliance guide for the Community Bank Leverage Ratio framework as part of broader regulatory relief efforts for community banks. This update is relevant to compliance officers at community banks that have elected or are considering electing the CBLR as their simplified capital adequacy standard, particularly those expanding into digital asset services or payments. Staying current on capital requirements is a foundational compliance obligation for any bank offering crypto custody or fintech-adjacent products.
OCC Seeks Comments on GENIUS Act Stablecoin Issuer License Application Forms
The OCC is proposing a new information collection under the Paperwork Reduction Act to support the licensing and registration process for entities that want to issue payment stablecoins under the GENIUS Act. This is an early procedural step in building out the federal licensing framework for stablecoin issuers. Compliance officers at firms considering or already planning to issue payment stablecoins should monitor this closely, as the application requirements will shape what documentation and controls are needed.
Federal Banking Agencies Issue Guidance on Protecting Sensitive Info During Exams
The OCC, Federal Reserve, and FDIC jointly issued a statement describing enhanced security procedures for how examiners handle highly sensitive information during bank examinations, such as reviewing certain materials on-site rather than transferring them to agency systems. For crypto-focused banks and trust companies holding sensitive customer data or proprietary technology details, this guidance clarifies how to engage with examiners while protecting confidential information. Compliance and legal teams should update their examination-management protocols to align with these enhanced procedures.
Banking Agencies Clarify Secure Handling of Sensitive Data in Bank Exams
The federal banking agencies issued a joint statement outlining enhanced security procedures for examiner review of highly sensitive bank information, including practices like on-site review rather than transferring data onto agency systems. Banks and trust companies — including those with crypto or digital asset operations — should understand these procedures to manage examination risk and protect sensitive data. This is directly relevant to any supervised institution preparing for or currently undergoing a regulatory examination.
OCC Releases July 2026 Enforcement Actions Against Banks
The OCC published its monthly enforcement actions for July 2026, which may include cease-and-desist orders, civil money penalties, or other formal actions against OCC-supervised banks. Compliance officers should review the published actions to identify any patterns related to AML, BSA, or other compliance failures that could signal supervisory priorities. Enforcement actions against peer institutions often foreshadow examination focus areas relevant to crypto-active banks and trust companies.
OCC Flags Updated FinCEN Guidance on Voluntary Info-Sharing Between Institutions
The OCC is drawing attention to FinCEN's refreshed Section 314(b) Fact Sheet, which clarifies how financial institutions can voluntarily share information about suspected money laundering or terrorist financing with one another under a statutory safe harbor from liability. Compliance officers should review the updated guidance to ensure their institution's 314(b) program reflects the latest expectations, particularly around fraud-related information sharing, which was a key focus of the update.
OCC Proposes BSA/AML and Sanctions Rules for Payment Stablecoin Issuers
The OCC, in coordination with FinCEN and OFAC, has proposed regulations implementing BSA/AML and sanctions compliance requirements specifically for permitted payment stablecoin issuers under its jurisdiction, as required by the GENIUS Act. This is a landmark proposal that will establish formal AML program, KYC, and sanctions screening obligations for federally supervised stablecoin issuers. Compliance officers at stablecoin issuers and banks exploring stablecoin activities should treat this as a top-priority rulemaking.
OCC Proposes BSA/AML and Sanctions Rules for Stablecoin Issuers Under GENIUS Act
The OCC has issued a proposed rulemaking to establish Bank Secrecy Act and sanctions compliance requirements specifically for OCC-supervised permitted payment stablecoin issuers (PPSIs), as mandated by the newly enacted GENIUS Act. This is a landmark development because it creates a dedicated AML/CFT and sanctions compliance framework for federally supervised stablecoin issuers for the first time. Any firm considering or currently operating as a payment stablecoin issuer under OCC oversight must prepare to meet these new BSA and OFAC compliance standards.
OCC Releases June 2026 Enforcement Actions Against Banks
The OCC published its monthly roundup of formal enforcement actions taken against national banks and federal savings associations. Compliance officers should review these actions to identify patterns in supervisory priorities, including any AML, BSA, or compliance program deficiencies that could signal broader exam focus areas.
OCC Clarifies How It Evaluates Bank Charter and License Applications
The OCC issued guidance clarifying the standards it uses when making decisions on filings such as charter applications, mergers, and licensing requests. This is directly relevant to crypto firms and fintechs pursuing national bank charters or trust company charters, as it signals what the OCC will and will not weigh in its approval decisions.
OCC Bulletin: Updated Standards for Charter and Filing Decisions
The OCC published a formal bulletin clarifying the standards it applies when deciding on regulatory filings, including charter applications and other approval requests. For crypto custodians, exchanges, and fintechs seeking federal licensing, understanding these standards is essential for structuring a credible application.
OCC Proposes New Reporting Forms for Payment Stablecoin Issuers
The OCC is proposing a new set of weekly and quarterly reporting forms specifically for permitted payment stablecoin issuers—including foreign issuers—under its jurisdiction, and is seeking a new OMB control number for this collection. This signals that the OCC is building out a formal, ongoing supervisory data infrastructure for stablecoin issuers, which will impose regular disclosure and reporting obligations on covered entities. Compliance officers at stablecoin issuers or institutions considering a stablecoin charter should treat this as an early indicator of the reporting burden they will face.
OCC Revises Its Licensing Manual Information Collection Requirements
The OCC is soliciting public comment on a revision to the information collection associated with its Licensing Manual, which governs applications and filings for national bank charters and related approvals. For crypto firms, fintechs, and trust companies pursuing OCC charters or special-purpose licenses, changes to the Licensing Manual directly affect the documentation and process requirements they must satisfy. Staying current with any revisions is essential for institutions actively exploring or pursuing federal licensing pathways.
Joint Final Rule Sets Common Data Standards for Financial Regulatory Reporting
Eight federal financial regulators, including the OCC, Fed, FDIC, SEC, and CFTC, have issued a joint final rule implementing the Financial Data Transparency Act of 2022, establishing standardized data formats for regulatory reporting submissions. Firms subject to reporting obligations across multiple regulators will need to align their data infrastructure and reporting pipelines to the new interoperability standards. This affects any regulated entity that files supervisory data with participating agencies.
OCC Proposes Weekly & Quarterly Reporting Forms for Stablecoin Issuers Under GENIUS Act
The OCC is seeking public comment on proposed weekly and quarterly reporting forms that permitted payment stablecoin issuers and foreign stablecoin issuers registered with the OCC under the GENIUS Act will be required to complete. This is an early but critical step in the GENIUS Act supervisory framework, and stablecoin issuers operating under OCC jurisdiction need to understand their forthcoming reporting obligations. Comments are due within 60 days of Federal Register publication.
OCC Comptroller Testifies on Agency Priorities Before House Financial Services
OCC Comptroller Jonathan Gould testified before the House Committee on Financial Services regarding the OCC's current priorities and activities. Congressional testimony from the OCC often signals upcoming regulatory focus areas, including those affecting banks engaged in digital asset activities and fintech partnerships. Compliance officers should review the testimony for guidance on OCC supervisory priorities relevant to their institutions.
Federal Banking Agencies Remove 'Reputation Risk' from Supervisory Guidance
The OCC, FDIC, and Federal Reserve jointly updated 15 interagency guidance documents to remove references to reputation risk as a supervisory consideration. This is significant for crypto and fintech firms that have historically faced banking access challenges when banks cited reputational concerns; its removal may reduce discretionary debanking of digital asset businesses.
OCC Bulletin: 'Reputation Risk' Removed from 15 Interagency Guidance Documents
The OCC, FDIC, and Federal Reserve have reissued 15 interagency guidance documents with all references to reputation risk removed, following a regulatory deregulation initiative. For crypto and fintech compliance officers, this shift may reduce the justification banks have used to restrict or terminate accounts for digital asset businesses based on perceived reputational concerns.
OCC Releases May 2026 Bank Enforcement Actions
The OCC has published its monthly enforcement actions for May 2026, which can include cease-and-desist orders, civil money penalties, and formal agreements tied to BSA/AML, compliance, and risk management failures at national banks and federal thrifts. Compliance officers at banks and fintechs with bank partners should review these actions to identify emerging supervisory themes and benchmark their own programs against cited deficiencies. Enforcement trends from the OCC often signal where examiners will focus next.
OCC Clarifies National Banks' Right to Charge Interchange and Other Non-Interest Fees
The OCC has adopted an interim final rule affirming that national banks have broad authority to assess non-interest charges and fees — including interchange fees from credit and debit card operations — even when those fees are set by or negotiated with third parties. This directly supports bank-fintech partnership models where fee structures are co-designed with program managers or payment processors, providing clearer legal footing for those arrangements.
OCC Preempts Illinois Law Banning Interchange Fees on Tax and Tip Portions
The OCC has issued an interim final order concluding that the Illinois Interchange Fee Prohibition Act — which would bar national banks and federal savings associations from charging interchange fees on the tax and gratuity portions of card transactions and restrict use of transaction data — is preempted by federal law. Payment processors and fintechs that issue cards or process transactions for national banks should note that the Illinois restriction will not apply to federally chartered institutions, though state-chartered entities and non-bank payment companies may still need to assess their own exposure.
OCC Interim Rule Clarifies National Banks' Authority to Charge Payment Card Interchange Fees
The OCC has issued an interim final rule amending its regulation on national bank non-interest charges and fees to explicitly confirm that national banks may charge non-interest fees — including interchange fees from payment card activity — even when those fees are set by a third party rather than the bank itself. This is relevant to banks and fintechs involved in payment card programs, including crypto debit and prepaid card products, where fee structures may be determined by card networks or program managers. Compliance officers should assess whether current fee disclosures and program agreements align with the clarified rule, and note that a public comment period is open.
OCC & FDIC Ban 'Reputation Risk' as a Basis for Supervisory or Account Actions
The OCC and FDIC have finalized a rule prohibiting themselves from using 'reputation risk' as a grounds for supervisory criticism or adverse action, and from pressuring banks to close or deny accounts based on a customer's lawful business activities, political views, or constitutionally protected speech. This is directly relevant to crypto and fintech firms that have experienced debanking or account closures, as it limits regulators' ability to push banks away from serving these industries on reputational grounds alone. Banks serving crypto clients should document this rule as support for maintaining those relationships.
OCC, FDIC & NCUA Propose Risk-Based AML/CFT Program Rules for Banks
The OCC, FDIC, and NCUA are jointly proposing amendments to require banks and credit unions to maintain AML/CFT programs that are risk-based, outcomes-focused, and aligned with the concurrent FinCEN AML Act rulemaking — modernizing a framework that has remained largely unchanged for decades. Banks with crypto-related customers or services should pay particular attention, as the risk-based approach may reshape how they assess and document illicit finance risks associated with digital assets. This proposal runs in parallel with the FinCEN proposal and compliance officers should review both together.
Want this mapped to your own program?
PliOS watches these sources for you and flags exactly which of your policies each new rule affects. Start with a free, AI-guided gap assessment — no credit card required.
Run My Free Assessment