The ICBA's lawsuit against the Office of the Comptroller of the Currency (OCC) isn't just a regulatory turf war. It's a direct challenge to whether the OCC can issue trust charters to crypto firms without requiring them to operate as traditional banks. For AML compliance officers, this matters because the charter your crypto partner holds determines which regulatory framework governs your shared compliance obligations.
If the lawsuit succeeds, it could invalidate existing trust charters or force the OCC to impose traditional banking requirements on crypto firms. This means your third-party risk assessments, customer due diligence protocols, and BSA obligations could shift overnight.
What This Checklist Covers
Use this checklist to audit your compliance posture if you work with OCC-chartered crypto firms or trust companies handling digital assets. It addresses regulatory dependency risks, third-party due diligence gaps, and contingency planning for potential charter revocations or regulatory restructuring.
Prerequisites
Before starting this checklist, confirm:
- Your institution has a relationship with an OCC-chartered crypto firm or trust company handling virtual assets, stablecoin reserves, or custody services.
- You have access to your third-party's charter documentation, including the original OCC approval letter and any conditional terms.
- You can review your institution's BSA/AML/CFT Framework to identify provisions that depend on your partner's regulatory status.
- You have authority to escalate findings to your MLRO or Chief Compliance Officer.
Compliance Checklist
Charter Status and Authority
1. Verify your crypto partner's current charter type and issuing authority
Obtain a copy of the OCC charter approval letter. Confirm whether it's a full-service national bank charter, a special purpose national bank charter, or a trust charter under 12 USC § 27. Check the OCC's public list of chartered institutions to verify active status.
Good looks like: A documented file containing the original charter letter, charter number, approval date, and any amendments. You can cite the specific legal authority and match it to OCC public records.
2. Document any conditional approval terms or operating restrictions
Review the charter for conditions the OCC imposed. Common restrictions include prohibition on accepting FDIC-insured deposits, requirements to maintain specific capital ratios, or limitations on permissible activities.
Good looks like: A compliance matrix mapping each charter condition to your institution's reliance on that partner. You know which services would become non-compliant if conditions change.
3. Identify which of your AML/CFT obligations depend on your partner's charter status
Map your Customer Due Diligence, Transaction Monitoring Rules, and Suspicious Activity Report processes to determine where you rely on your partner's regulatory classification. For example, do you treat them as a regulated financial institution for information-sharing purposes under 31 CFR § 1020.520?
Good looks like: A written analysis showing each BSA/AML control that assumes your partner is an OCC-regulated entity, with alternative controls documented if that status changes.
Regulatory Change Preparedness
4. Establish monitoring for OCC charter policy changes and legal challenges
Set up alerts for OCC policy statements, federal court filings naming the OCC, and Federal Register notices affecting trust charters or special purpose charters. The ICBA lawsuit is docketed in federal court and will generate public filings.
Good looks like: A designated team member receives and reviews OCC announcements weekly. Legal developments are escalated to your MLRO within 48 hours of publication.
5. Review your third-party risk management program for charter dependency
Examine your vendor due diligence questionnaires and annual reviews. Do they assess regulatory charter stability? Do they require notification if charter status changes?
Good looks like: Your third-party contracts include a representation that the vendor will notify you within 10 business days of any charter modification, OCC enforcement action, or legal challenge to its regulatory authority.
6. Document your institution's regulatory classification of the crypto partner
Review internal policies, board presentations, and exam responses to confirm how you've classified this relationship. Have you told your primary regulator that you rely on an OCC-chartered entity for AML compliance purposes?
Good looks like: Consistent classification across all documents. If you told examiners the partner is a "regulated trust company," you have evidence supporting that claim and a plan if it becomes inaccurate.
Information Sharing and Safe Harbor
7. Verify your 314(b) information sharing agreements are properly structured
If you share SARs or suspicious activity information with your crypto partner under 31 USC § 5318(g)(3), confirm both institutions are "financial institutions" as defined by the BSA. If the partner's charter is invalidated, it might lose that status.
Good looks like: Written legal analysis confirming both parties qualify for Safe Harbor under current law, with alternative information-sharing mechanisms documented if regulatory status changes.
8. Review customer identification program (CIP) reliance arrangements
If you rely on your partner's CIP under 31 CFR § 1020.220(a)(2)(ii), confirm the reliance is documented and that you've obtained written assurance the partner maintains an adequate CIP.
Good looks like: Annual certification from the partner that its CIP meets BSA requirements, with your institution retaining ultimate responsibility and the ability to verify compliance.
Contingency Planning
9. Develop a contingency plan for charter revocation or modification
Draft a response plan addressing how you'll maintain AML/CFT compliance if your partner loses its charter. What alternative service providers exist? What customer notifications are required?
Good looks like: A written plan approved by your MLRO that includes decision trees, alternative vendor contacts, and timeline estimates for transitioning services. The plan is tested annually.
10. Assess customer impact if your crypto partnership is disrupted
Identify which customer segments depend on services delivered through your OCC-chartered partner. Determine whether you have contractual obligations that become undeliverable if the partnership ends.
Good looks like: A customer impact analysis showing volume, revenue, and contractual exposure by customer segment, with communication templates pre-drafted for different scenarios.
Common Mistakes
Assuming charter stability is permanent. Regulatory authority evolves through legislation, rulemaking, and litigation. The ICBA lawsuit demonstrates that charter grants can be challenged years after issuance.
Treating OCC-chartered crypto firms identically to traditional banks. Trust charters and special purpose charters carry different authorities and restrictions than full-service bank charters. Your due diligence should reflect those distinctions.
Failing to monitor legal challenges to your partner's regulatory status. Court dockets are public. If you wait until a charter is revoked to start contingency planning, you're already behind.
Relying on verbal assurances about charter scope. Get the OCC approval letter. Read the conditions. Don't assume your partner can perform every activity a traditional bank can.
Next Steps
Within 30 days, complete items 1-3 and 6 to establish your baseline. Within 60 days, implement monitoring (item 4) and review your contracts (item 5). Within 90 days, complete the contingency planning items (9-10).
Escalate findings to your MLRO immediately if you discover your institution has misclassified a partner's regulatory status or if your AML/CFT framework has critical dependencies on a charter that's subject to legal challenge.
The outcome of the ICBA lawsuit won't be decided quickly, but your compliance posture shouldn't depend on how courts rule. Build resilience now.





