The Office of the Comptroller of the Currency today published a legal interpretation of letters issued in July and October 2020, and January 2021 to clarify that a bank may legally engage in certain cryptocurrency, distributed ledger and stablecoin activities, if it can demonstrate to the supervisory office this can be done in a “safe and sound manner.”

A bank should notify its supervisory office of its intention in writing to engage in these activities and should not act until “it receives written notification of the supervisory office’s non-objection,” stated Senior Deputy Comptroller and Chief Counsel Benjamin McDonough in the letter.
Banks or other financial services already engaged in cryptocurrencies, or other activities covered by the letter, do not have to retroactively seek permission but should expect the supervisory office to inspect these activities as part of normal inspections.
Further, the letter notes that supervisory offices “will evaluate the adequacy of the bank’s risk management systems and controls and risk measurement systems” to ensure the bank can engage with crypto, stablecoin and distributed ledgers safely and securely.
In particular, banks must address:
- Operational risk;
- Liquidity risk;
- Strategic risk; and
- Compliance risk, including the Bank Secrecy Act, anti-money laundering, sanctions requirements and consumer protection laws.
These requirements could present a challenge since some cryptocurrencies’ decentralized nature can mask the identity of their participants. A 2020 study by blockchain analysis firm CipherTrace found that 56% of virtual asset service providers (VASPs) globally have “weak or porous [know your customer] processes, meaning money launderers can use them to deposit or withdraw their ill-gotten funds with very minimal to zero KYC.
“To address compliance, the bank should demonstrate, in writing, an understanding of any compliance obligations related to the specific activities the bank intends to conduct,” the letter stated. “Prior to seeking supervisory non-objection, the bank should consider all applicable laws, ensure that the proposed structure of the activity is consistent with such laws, and that the compliance management system will be sufficient and appropriate to ensure compliance.”






