The Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC) on August 27 issued a joint final rule establishing a uniform definition of “unsafe or unsound practice” and setting standards for how examiners should use supervisory findings.
The agencies said the rule is intended to ensure that examiners “prioritize concerns related to material financial risks over those regarding policies, process, documentation and other nonfinancial risks.” The rule will take effect 60 days after publication in the Federal Register.
While the rule does not specifically address cryptocurrency, its emphasis on material financial risks has attracted attention from the digital-asset industry because of the continuing debate over whether banks have restricted services to crypto companies for reasons unrelated to financial risk.
What the Rule Does
The term “unsafe or unsound practice” has long been used by federal banking regulators as a supervisory and enforcement tool, but the agencies said the term had not previously been defined in regulation in a uniform manner.
The final rule defines an unsafe or unsound practice as conduct that is contrary to generally accepted standards of prudent operation and that has caused, or could reasonably cause, material financial harm to an institution or pose a significant risk to the Deposit Insurance Fund.
The framework is tied to Section 8 of the Federal Deposit Insurance Act. The rule also establishes standards for supervisory findings, including Matters Requiring Attention (MRAs), and directs examiners to consider the specific risk profile and circumstances of each institution.
The agencies emphasized that the rule applies to the institutions they supervise and the agencies’ examination and supervisory processes. The rule follows a proposal issued by the OCC and FDIC in October 2025, with the final version containing modifications from the proposal.
Why Crypto Firms Are Watching
The connection to crypto is primarily contextual rather than explicit in the rule itself. Crypto companies and industry groups have for several years argued that some banks restricted or ended relationships with digital-asset businesses because of regulatory pressure rather than demonstrated financial risk.
That debate intensified around what the crypto industry has called “Operation Chokepoint 2.0,” a term used by Castle Island Ventures partner Nic Carter to describe what he characterized as coordinated efforts to restrict banking access for crypto companies.
The new rule does not use that terminology and does not make a finding that regulators previously directed banks to discriminate against crypto businesses. However, the agencies’ decision to place greater emphasis on material financial risks rather than nonfinancial considerations is relevant to that debate. The development follows the OCC and FDIC’s earlier removal of reputation risk as a stand-alone supervisory category, a change finalized in April 2026.
Crypto industry participants have argued that reputation-based concerns contributed to restrictions on banking services for digital-asset companies. Regulators and other participants in the debate have disputed aspects of that characterization.
The Debanking Debate
The U.S. debate over crypto banking access has included regulatory records, congressional investigations and litigation. House Financial Services Committee investigations and records released through Freedom of Information Act litigation have documented instances in which regulators communicated with banks about their cryptocurrency-related activities.
The material has been cited by crypto companies and their supporters as evidence of regulatory pressure on banks to limit digital-asset activity. Those records do not, by themselves, establish that every instance of a bank reducing crypto exposure resulted from regulatory direction, and the scope and interpretation of the records remain contested.
The debate also reached the executive branch. The Trump administration has taken steps aimed at addressing what it describes as politically motivated restrictions on lawful businesses’ access to financial services. Against that backdrop, the OCC and FDIC’s latest rule provides another indication of the agencies’ shift toward a more explicitly financial-risk-focused supervisory approach.
What the Rule Does Not Change
The rule does not require banks to provide services to cryptocurrency companies. It also does not remove existing requirements relating to bank safety and soundness, Bank Secrecy Act and anti-money-laundering obligations, sanctions compliance or consumer protection.
Banks remain responsible for managing the financial, operational, legal and compliance risks associated with their customers and activities. The rule also does not specifically identify cryptocurrency as an activity that regulators must treat differently from other industries.
For crypto companies, that distinction is important. A change in examiner guidance does not automatically create a right to a banking relationship or prevent an individual bank from deciding that a particular customer or activity presents unacceptable risk.
The Federal Reserve Is Still Outstanding
The OCC and FDIC are not the only federal banking regulators reconsidering how nonfinancial risks are treated in supervision. The Federal Reserve has separately proposed removing reputation risk as a distinct supervisory consideration. If the Federal Reserve ultimately finalizes its proposal, the change would bring the three major federal banking regulators closer to a common approach to reputation risk.
The timing matters for the crypto industry because banks with digital-asset clients can fall under different federal supervisory regimes depending on their charter and regulatory structure.
Crypto Banking Is Still a Separate Question
The latest rule comes as the U.S. banking system is also seeing greater participation from crypto and stablecoin companies.
The OCC has approved or conditionally approved national trust-bank applications involving several digital-asset companies, while Congress has established a federal framework for payment stablecoins through the GENIUS Act.
These developments have opened additional paths for crypto businesses to operate within the regulated financial system, but they do not eliminate the distinction between regulatory permission to conduct an activity and a bank’s decision to provide services to a particular customer.
Why the Rule Matters
The practical significance of the OCC-FDIC rule will depend on how examiners apply the new standards during bank examinations. For crypto businesses, the key question is whether a stronger focus on measurable financial risks reduces the influence of broader nonfinancial concerns when banks assess relationships with digital-asset companies.
The rule itself does not answer that question. What it does establish is a clearer supervisory framework centered on material financial harm and risk to the Deposit Insurance Fund, rather than allowing “unsafe or unsound practice” to operate without a uniform regulatory definition.
What’s Next
The final rule will become effective 60 days after publication in the Federal Register. The Federal Reserve’s separate proposal on reputation risk remains outstanding, while congressional investigations and litigation concerning past crypto-bank relationships continue to shape the broader debate over access to financial services.
For the crypto industry, the next test will be whether the regulatory shift changes banks’ actual decisions about serving digital-asset companies. The Crypto Times takes no position on the broader political debate over debanking and will report on regulatory and banking developments as they occur.
Also Read: Ripple-Backed Evernorth’s XRP Treasury Clears SEC S-4; Nasdaq Vote Set Sept 30
