OCC and FDIC finalize narrower supervisory standards that cover stablecoin-law violations
Regulation · · Ketju Research
What changed
Effective November 2, 2026, the OCC and FDIC will use a nationwide definition of unsafe or unsound practice requiring conduct contrary to prudent operation that has caused, or is likely to cause, material financial harm or material risk to the Deposit Insurance Fund. The agencies may issue an MRA for conduct meeting a related financial-risk standard or for an actual violation of banking or banking-related law; lesser violations may be directed for remediation without an MRA, and supervisory observations remain informal. The rule requires tailoring to an institution’s risks and reliance on objective facts and sound reasoning. The preamble expressly identifies the GENIUS Act as a newly adopted banking-related law that the agencies must be able to implement and examine.
Who it affects
- OCC-supervised national banks, federal savings associations, and federal branches or agencies conducting stablecoin, crypto-custody, or other digital-asset activities
- FDIC-supervised insured state nonmember banks, insured state-licensed foreign branches, and insured state savings associations conducting covered digital-asset activities
- Investment advisers and funds diligencing supervised banks as digital-asset custodians, stablecoin counterparties, or payment providers
What is still open
- How OCC and FDIC examiners will apply the material-harm and Deposit Insurance Fund risk thresholds to stablecoin issuance, reserve management, crypto custody, and related operational risks
- When a GENIUS Act or other digital-asset compliance failure will be treated as an MRA-level violation rather than an other violation requiring remediation
- How differences between OCC, FDIC, and other regulators’ supervisory frameworks will affect multi-regulator digital-asset banking arrangements
What it means for an advisor
- Update bank-custodian and stablecoin-counterparty diligence to account for the November 2 supervisory framework and ask how covered institutions classify and remediate digital-asset findings
- Do not treat the absence of an MRA as evidence that a bank has no digital-asset compliance weakness, because lesser violations and supervisory observations may follow different channels
- Reassess escalation and business-continuity procedures where an advisory workflow depends on a supervised bank’s stablecoin, custody, settlement, or payment services
Sources
- Unsafe or Unsound Practices, Matters Requiring Attention · Office of the Comptroller of the Currency and Federal Deposit Insurance Corporation · · effective
Version 1, published . Educational analysis, not legal advice.