Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Breaking Regulatory Compliance

United Texas Bank's OCC Consent Order at Charter Conversion: The BSA/AML Lesson for Crypto Banking

When United Texas Bank converted to a national charter in May 2026, it arrived at the OCC already carrying a Federal Reserve BSA/AML consent order from 2024. Two months later, the OCC issued its own Cease and Desist. Here's what that sequence tells compliance teams about what national bank standards actually require for crypto-focused BSA/AML programs.

By Rebecca Leung · July 21, 2026 ·
Table of Contents

United Texas Bank arrived at the OCC with its bags already packed.

When UTB completed its conversion to a nationally chartered bank on May 27, 2026 — the first post-Dodd-Frank OCC charter conversion — it was already operating under a Federal Reserve Bank of Dallas and Texas Department of Banking consent order that had been in place since August 2024. That order, issued over concerns about UTB’s BSA/AML compliance infrastructure, was written against a bank processing $120 billion or more in annual crypto transactions with a compliance program that hadn’t scaled to match.

Two months after the charter conversion, the OCC announced its July 2026 enforcement actions: a Cease and Desist against United Texas Bank for BSA/AML deficiencies, consented to as part of the OCC conversion itself.

This sequence isn’t unusual. It’s a pattern. And if your institution is growing a crypto business, applying for a new charter, or managing existing BSA/AML findings while transaction volume compounds, the UTB timeline is exactly the scenario your compliance program should be stress-tested against.

TL;DR

  • OCC issued a Cease and Desist against United Texas Bank in July 2026 for BSA/AML deficiencies — consented to as part of its historic national charter conversion
  • UTB had already been under a Federal Reserve/Texas Banking consent order since August 2024 for similar BSA/AML infrastructure concerns
  • UTB processes $120B+ in annual crypto transactions and built a proprietary AML platform (UTB Prism Sentinel) with real-time blockchain surveillance — but carrying unresolved deficiencies into a charter conversion doesn’t make them disappear
  • The OCC’s national bank examination standards require demonstrably adequate programs, not work-in-progress infrastructure
  • This is the second major BSA/AML enforcement action at a bank serving crypto and fintech clients since May 2026 — the pattern points to a systematic gap between crypto transaction growth and AML program maturity

The Timeline That Matters

To understand what happened here, you have to understand the sequence.

August 2024: Federal Reserve Bank of Dallas and Texas Department of Banking issue a consent order against United Texas Bank for BSA/AML compliance infrastructure concerns. At that point, UTB is a state-chartered bank under Texas and Federal Reserve supervision, running crypto correspondent banking at a scale that had outgrown its monitoring infrastructure.

May 15, 2026: The OCC approves United Texas Bank’s application to convert to a nationally chartered bank (OCC Corporate Decision 1375). This is not a routine approval — UTB becomes one of the first institutions to complete an OCC charter conversion since Dodd-Frank was enacted 15 years earlier. The conversion gives UTB federal deposit insurance, Federal Reserve master account connectivity, commercial lending authority, digital asset custody rights, and stablecoin infrastructure capacity.

May 27, 2026: Charter conversion completes.

July 2026: OCC announces enforcement actions. United Texas Bank consents to a Cease and Desist Order (Docket No. AA-ENF-2026-29) for deficiencies in its BSA/AML compliance program that resulted in violations of law or regulation. The OCC simultaneously terminates enforcement actions against Patriot Bank, Quontic Bank, Sidney Federal Savings and Loan, and Texas Heritage National Bank — institutions that had resolved their findings.

UTB was not one of the resolutions. It was one of the new actions.


What the OCC Is Actually Testing

The OCC’s BSA/AML examination standard under 12 CFR 21.21 requires national banks to develop and maintain a written BSA/AML compliance program covering four pillars: internal controls; independent testing; designated BSA/AML compliance officer; and ongoing training.

For a bank processing $120 billion annually in crypto transactions, “adequate” means something very different than it does for a community bank with a correspondent banking portfolio of comparable notional size. The difference is in three areas where crypto-focused programs consistently underperform:

1. Transaction monitoring calibration at crypto scale

Crypto transactions don’t look like wire transfers. They’re pseudonymous, they settle in seconds, they can involve dozens of intermediate addresses before hitting a fiat on-ramp, and the suspicious activity typologies — mixer usage, chain-hopping, peel chains, bridge transactions — require blockchain analytics tools and staff who understand on-chain behavior, not just pattern matching against traditional structuring scenarios.

A traditional AML system transplanted into a crypto banking environment will generate alerts on the wrong signals and miss the signals that actually matter. The OCC has been explicit that monitoring systems must be calibrated for an institution’s actual risk profile — not a prior institution’s profile, not a vendor’s default rules, and not the institution’s risk profile from three years ago before volume tripled.

2. Staffing that reflects actual complexity

The OCC cited BSA/AML staffing adequacy in its action against Community Federal Savings Bank in May 2026 for similar reasons. A BSA/AML team that could handle a $5 billion payment processing portfolio is not automatically equipped to handle $120 billion in crypto correspondent banking with on-chain analytics, enhanced due diligence for digital asset businesses, and SAR narratives that require blockchain attribution.

BSA/AML staffing tends to grow at a fraction of the rate of transaction volume in high-growth institutions. The gap between the two is where enforcement actions live.

3. Independent testing that actually reaches the crypto operation

The OCC’s examination procedures require independent testing that evaluates whether the BSA/AML program is working — not just whether it exists. That means testing suspicious activity alert rates, auto-closure logic, SAR narrative quality, CDD completeness for digital asset customers, and OFAC screening for crypto addresses.

For crypto-serving banks, independent testing scoped to “traditional correspondent banking activities” and treated the crypto book as out of scope is not independent testing. It’s a paper exercise.


Building a BSA/AML Program on a Moving Platform

United Texas Bank’s response to the Federal Reserve order was to build UTB Prism Sentinel — its proprietary integrated BSA/AML compliance platform with real-time blockchain surveillance. The bank describes it as central to its compliance framework and notes it conducts real-time blockchain surveillance to manage BSA and AML risk.

That approach is more sophisticated than most banks UTB’s size deploy, and it points in the right direction. The challenge is that building while the platform is running — processing $120 billion in annual crypto volume while simultaneously trying to remediate a Federal Reserve consent order and demonstrate OCC readiness — is a compliance engineering problem that most institutions underestimate.

The OCC’s willingness to approve the charter conversion while simultaneously issuing the C&D tells you something important: the OCC isn’t waiting for clean programs. It’s supervising banks-in-progress, with the expectation that the consent order creates a defined remediation path the institution can demonstrate progress against.

That’s not a lighter standard. If anything, it’s a harder one — because the OCC is now the examiner, the enforcement authority, and the body evaluating whether Prism Sentinel actually does what UTB says it does.


The Pattern Since May 2026

The CFSB enforcement action and the UTB Cease and Desist share a structural pattern worth naming:

InstitutionBusinessVolume DriverBSA/AML Failure Mode
Community Federal Savings Bank (May 2026)Payment processing via fintech partners (Wise, Crypto.com)Rapid growth in payment volumeAlert auto-closure; CDD gaps; staffing not scaled with volume
United Texas Bank (July 2026)Crypto correspondent banking$120B+ annual crypto transactionsBSA/AML infrastructure deficiencies; program not matching risk profile

The failure mode is not technical. It’s a scaling problem — programs built at an earlier transaction volume, complexity, or counterparty profile that were never retested and recalibrated when the business changed.

The OCC’s July 2026 enforcement announcement is worth reading alongside the CFSB consent order analysis — not because the institutions are the same, but because the underlying compliance failure is the same: monitoring and staffing that scale on inertia, not on actual risk.


What This Means If You Serve Crypto Clients

If your institution provides banking services to crypto firms, processes crypto transactions, or is building toward a digital asset product, the UTB enforcement action is a calibration point — not a cautionary tale about someone else’s problem.

Assess your monitoring for actual risk, not historical risk. When did you last validate that your suspicious activity monitoring is calibrated for your current transaction volume and crypto-specific typologies? The answer “we recalibrated when we went live” is the answer that produces a CFSB or UTB situation two years later.

Independent testing must cover the crypto book. If your BSA/AML independent testing is scoped to traditional activities because your crypto business is newer or smaller, you have a gap the OCC will find. The independent testing requirement under 12 CFR 21.21 covers the whole institution, not just the parts that feel conventional.

Charter transitions transfer compliance obligations. If you’re operating under state or Federal Reserve supervision with open findings, converting to a national bank charter does not reset the clock. OCC examiners will inherit the finding history, treat open findings as pre-existing deficiencies, and calibrate their examination intensity accordingly.

Staffing is an examiner input. The OCC examiner looking at your BSA/AML program is making a judgment about whether the complexity of your business is matched by the capacity of your compliance team. Volume growth without headcount growth is a BSA/AML exam finding waiting to be documented.


So What?

The UTB enforcement action reinforces what the CFSB order established in May: the OCC is applying a consistent standard across the crypto-adjacent banking sector — and that standard is simple, even if meeting it isn’t.

Does your BSA/AML program actually work for your actual business? Not for the business you had two years ago, not for the transaction types your system was tuned for at launch, not for a compliance officer who has banking AML experience but has never written a SAR narrative for a pig butchering scheme.

For the growing category of banks that serve digital asset businesses — whether as correspondent banks, stablecoin issuers, or payment processors for crypto fintechs — that question has become the exam.


Building a BSA/AML-Ready Control Environment

One of the consistent OCC findings in the UTB and CFSB actions is the gap between documented controls and working controls. The bank has a transaction monitoring system. The bank has a BSA officer. The bank has a training program. None of those exist check-the-box certifications equal to an adequate program when volume and complexity have outgrown the controls’ original design.

A Risk and Control Self-Assessment tests whether your controls are working — not just whether they exist. The scoring rubric is built specifically to surface the gap between “we have this” and “this actually catches what it’s supposed to catch.” The 141 pre-populated risk assessments include compliance and BSA/AML controls, and the self-assessment questionnaire is designed to surface the volume-to-staffing and calibration gaps that produce OCC findings before the examiner does.

If your last BSA/AML control assessment scored everything green because the controls exist, that’s exactly the result that gets written up.


External Sources

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the OCC's July 2026 Cease and Desist order against United Texas Bank require?
The OCC issued a Cease and Desist Order against United Texas Bank (Docket No. AA-ENF-2026-29) for deficiencies in its Bank Secrecy Act/anti-money laundering compliance program that resulted in violations of law or regulation. The bank consented to the order as part of its conversion to a national bank supervised by the OCC (OCC Corporate Decision 1375). The order requires UTB to remediate identified BSA/AML program deficiencies under OCC supervision.
Why did United Texas Bank have both a Federal Reserve and an OCC enforcement action?
United Texas Bank operated under a Federal Reserve Bank of Dallas and Texas Department of Banking consent order since August 2024, arising from BSA/AML compliance infrastructure concerns related to its crypto transaction volume. In May 2026, UTB completed a historic conversion to a nationally chartered bank supervised by the OCC — the first such post-Dodd-Frank conversion. As part of that conversion, UTB consented to the OCC C&D in July 2026, reflecting that the BSA/AML deficiencies from the prior action had not been fully remediated before the charter transfer was finalized.
What makes BSA/AML compliance harder for crypto-focused banks?
Crypto-focused banks face BSA/AML challenges that traditional AML programs weren't designed for: transaction volumes that dwarf traditional correspondent banking, pseudonymous counterparties requiring blockchain attribution rather than name matching, token-specific typologies (mixer usage, chain-hopping, bridge transactions), and the speed of crypto settlement. United Texas Bank processes over $120 billion in annual crypto transactions — a volume that requires real-time blockchain surveillance rather than batch monitoring, purpose-built crypto KYC/CDD workflows, and AML staff with digital asset expertise, not just traditional banking background.
What does OCC national bank charter conversion mean for BSA/AML compliance standards?
Converting from a state-chartered bank to an OCC national bank raises the supervisory bar. State-chartered banks operate under state and Federal Reserve BSA/AML examination frameworks; national banks are subject to OCC BSA/AML examination procedures, which include specific program adequacy standards under 12 CFR 21.21. For crypto-focused banks, the conversion brings OCC's heightened scrutiny of digital asset activities, including its 2023 guidance requiring notification before engaging in new crypto-related activities and its ongoing assessment of whether AML programs adequately cover the specific risk profile of digital asset customers.
What is UTB Prism Sentinel and does it satisfy OCC examination requirements?
UTB Prism Sentinel is United Texas Bank's proprietary BSA/AML compliance platform, which includes real-time blockchain surveillance for crypto transaction monitoring. Building a proprietary AML system rather than buying a commercial platform is unusual for a bank UTB's size, but the crypto transaction volumes involved make it more defensible than trying to adapt a traditional AML system. Whether Prism Sentinel satisfies OCC examination requirements will depend on whether it meets the substantive adequacy standards in 12 CFR 21.21: identifying, managing, controlling, and reporting suspicious activity specific to the institution's actual risk profile.
What should compliance teams at crypto-serving banks do after seeing this enforcement action?
Three immediate actions: First, assess whether your AML program's suspicious activity monitoring is calibrated for your actual crypto transaction volume and typologies — not the volume when you last tuned the system. Second, if you're operating under any existing enforcement action (Fed, state, FDIC), assume the OCC will inherit it in full at any charter conversion and require demonstrated remediation. Third, evaluate whether your BSA/AML staffing and independent testing reflect the actual complexity of your digital asset business, not a traditional banking headcount model. The OCC pattern from both CFSB and UTB is the same: volume outgrows controls, and independent testing fails to surface the gap.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

● Don't wait for your own enforcement action

Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.

RCSA (Risk & Control Self-Assessment)

141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.