Breaking Regulatory Compliance
United Texas Bank's OCC Consent Order at Charter Conversion: The BSA/AML Lesson for Crypto Banking
When United Texas Bank converted to a national charter in May 2026, it arrived at the OCC already carrying a Federal Reserve BSA/AML consent order from 2024. Two months later, the OCC issued its own Cease and Desist. Here's what that sequence tells compliance teams about what national bank standards actually require for crypto-focused BSA/AML programs.
Table of Contents
United Texas Bank arrived at the OCC with its bags already packed.
When UTB completed its conversion to a nationally chartered bank on May 27, 2026 — the first post-Dodd-Frank OCC charter conversion — it was already operating under a Federal Reserve Bank of Dallas and Texas Department of Banking consent order that had been in place since August 2024. That order, issued over concerns about UTB’s BSA/AML compliance infrastructure, was written against a bank processing $120 billion or more in annual crypto transactions with a compliance program that hadn’t scaled to match.
Two months after the charter conversion, the OCC announced its July 2026 enforcement actions: a Cease and Desist against United Texas Bank for BSA/AML deficiencies, consented to as part of the OCC conversion itself.
This sequence isn’t unusual. It’s a pattern. And if your institution is growing a crypto business, applying for a new charter, or managing existing BSA/AML findings while transaction volume compounds, the UTB timeline is exactly the scenario your compliance program should be stress-tested against.
TL;DR
- OCC issued a Cease and Desist against United Texas Bank in July 2026 for BSA/AML deficiencies — consented to as part of its historic national charter conversion
- UTB had already been under a Federal Reserve/Texas Banking consent order since August 2024 for similar BSA/AML infrastructure concerns
- UTB processes $120B+ in annual crypto transactions and built a proprietary AML platform (UTB Prism Sentinel) with real-time blockchain surveillance — but carrying unresolved deficiencies into a charter conversion doesn’t make them disappear
- The OCC’s national bank examination standards require demonstrably adequate programs, not work-in-progress infrastructure
- This is the second major BSA/AML enforcement action at a bank serving crypto and fintech clients since May 2026 — the pattern points to a systematic gap between crypto transaction growth and AML program maturity
The Timeline That Matters
To understand what happened here, you have to understand the sequence.
August 2024: Federal Reserve Bank of Dallas and Texas Department of Banking issue a consent order against United Texas Bank for BSA/AML compliance infrastructure concerns. At that point, UTB is a state-chartered bank under Texas and Federal Reserve supervision, running crypto correspondent banking at a scale that had outgrown its monitoring infrastructure.
May 15, 2026: The OCC approves United Texas Bank’s application to convert to a nationally chartered bank (OCC Corporate Decision 1375). This is not a routine approval — UTB becomes one of the first institutions to complete an OCC charter conversion since Dodd-Frank was enacted 15 years earlier. The conversion gives UTB federal deposit insurance, Federal Reserve master account connectivity, commercial lending authority, digital asset custody rights, and stablecoin infrastructure capacity.
May 27, 2026: Charter conversion completes.
July 2026: OCC announces enforcement actions. United Texas Bank consents to a Cease and Desist Order (Docket No. AA-ENF-2026-29) for deficiencies in its BSA/AML compliance program that resulted in violations of law or regulation. The OCC simultaneously terminates enforcement actions against Patriot Bank, Quontic Bank, Sidney Federal Savings and Loan, and Texas Heritage National Bank — institutions that had resolved their findings.
UTB was not one of the resolutions. It was one of the new actions.
What the OCC Is Actually Testing
The OCC’s BSA/AML examination standard under 12 CFR 21.21 requires national banks to develop and maintain a written BSA/AML compliance program covering four pillars: internal controls; independent testing; designated BSA/AML compliance officer; and ongoing training.
For a bank processing $120 billion annually in crypto transactions, “adequate” means something very different than it does for a community bank with a correspondent banking portfolio of comparable notional size. The difference is in three areas where crypto-focused programs consistently underperform:
1. Transaction monitoring calibration at crypto scale
Crypto transactions don’t look like wire transfers. They’re pseudonymous, they settle in seconds, they can involve dozens of intermediate addresses before hitting a fiat on-ramp, and the suspicious activity typologies — mixer usage, chain-hopping, peel chains, bridge transactions — require blockchain analytics tools and staff who understand on-chain behavior, not just pattern matching against traditional structuring scenarios.
A traditional AML system transplanted into a crypto banking environment will generate alerts on the wrong signals and miss the signals that actually matter. The OCC has been explicit that monitoring systems must be calibrated for an institution’s actual risk profile — not a prior institution’s profile, not a vendor’s default rules, and not the institution’s risk profile from three years ago before volume tripled.
2. Staffing that reflects actual complexity
The OCC cited BSA/AML staffing adequacy in its action against Community Federal Savings Bank in May 2026 for similar reasons. A BSA/AML team that could handle a $5 billion payment processing portfolio is not automatically equipped to handle $120 billion in crypto correspondent banking with on-chain analytics, enhanced due diligence for digital asset businesses, and SAR narratives that require blockchain attribution.
BSA/AML staffing tends to grow at a fraction of the rate of transaction volume in high-growth institutions. The gap between the two is where enforcement actions live.
3. Independent testing that actually reaches the crypto operation
The OCC’s examination procedures require independent testing that evaluates whether the BSA/AML program is working — not just whether it exists. That means testing suspicious activity alert rates, auto-closure logic, SAR narrative quality, CDD completeness for digital asset customers, and OFAC screening for crypto addresses.
For crypto-serving banks, independent testing scoped to “traditional correspondent banking activities” and treated the crypto book as out of scope is not independent testing. It’s a paper exercise.
Building a BSA/AML Program on a Moving Platform
United Texas Bank’s response to the Federal Reserve order was to build UTB Prism Sentinel — its proprietary integrated BSA/AML compliance platform with real-time blockchain surveillance. The bank describes it as central to its compliance framework and notes it conducts real-time blockchain surveillance to manage BSA and AML risk.
That approach is more sophisticated than most banks UTB’s size deploy, and it points in the right direction. The challenge is that building while the platform is running — processing $120 billion in annual crypto volume while simultaneously trying to remediate a Federal Reserve consent order and demonstrate OCC readiness — is a compliance engineering problem that most institutions underestimate.
The OCC’s willingness to approve the charter conversion while simultaneously issuing the C&D tells you something important: the OCC isn’t waiting for clean programs. It’s supervising banks-in-progress, with the expectation that the consent order creates a defined remediation path the institution can demonstrate progress against.
That’s not a lighter standard. If anything, it’s a harder one — because the OCC is now the examiner, the enforcement authority, and the body evaluating whether Prism Sentinel actually does what UTB says it does.
The Pattern Since May 2026
The CFSB enforcement action and the UTB Cease and Desist share a structural pattern worth naming:
| Institution | Business | Volume Driver | BSA/AML Failure Mode |
|---|---|---|---|
| Community Federal Savings Bank (May 2026) | Payment processing via fintech partners (Wise, Crypto.com) | Rapid growth in payment volume | Alert auto-closure; CDD gaps; staffing not scaled with volume |
| United Texas Bank (July 2026) | Crypto correspondent banking | $120B+ annual crypto transactions | BSA/AML infrastructure deficiencies; program not matching risk profile |
The failure mode is not technical. It’s a scaling problem — programs built at an earlier transaction volume, complexity, or counterparty profile that were never retested and recalibrated when the business changed.
The OCC’s July 2026 enforcement announcement is worth reading alongside the CFSB consent order analysis — not because the institutions are the same, but because the underlying compliance failure is the same: monitoring and staffing that scale on inertia, not on actual risk.
What This Means If You Serve Crypto Clients
If your institution provides banking services to crypto firms, processes crypto transactions, or is building toward a digital asset product, the UTB enforcement action is a calibration point — not a cautionary tale about someone else’s problem.
Assess your monitoring for actual risk, not historical risk. When did you last validate that your suspicious activity monitoring is calibrated for your current transaction volume and crypto-specific typologies? The answer “we recalibrated when we went live” is the answer that produces a CFSB or UTB situation two years later.
Independent testing must cover the crypto book. If your BSA/AML independent testing is scoped to traditional activities because your crypto business is newer or smaller, you have a gap the OCC will find. The independent testing requirement under 12 CFR 21.21 covers the whole institution, not just the parts that feel conventional.
Charter transitions transfer compliance obligations. If you’re operating under state or Federal Reserve supervision with open findings, converting to a national bank charter does not reset the clock. OCC examiners will inherit the finding history, treat open findings as pre-existing deficiencies, and calibrate their examination intensity accordingly.
Staffing is an examiner input. The OCC examiner looking at your BSA/AML program is making a judgment about whether the complexity of your business is matched by the capacity of your compliance team. Volume growth without headcount growth is a BSA/AML exam finding waiting to be documented.
So What?
The UTB enforcement action reinforces what the CFSB order established in May: the OCC is applying a consistent standard across the crypto-adjacent banking sector — and that standard is simple, even if meeting it isn’t.
Does your BSA/AML program actually work for your actual business? Not for the business you had two years ago, not for the transaction types your system was tuned for at launch, not for a compliance officer who has banking AML experience but has never written a SAR narrative for a pig butchering scheme.
For the growing category of banks that serve digital asset businesses — whether as correspondent banks, stablecoin issuers, or payment processors for crypto fintechs — that question has become the exam.
Building a BSA/AML-Ready Control Environment
One of the consistent OCC findings in the UTB and CFSB actions is the gap between documented controls and working controls. The bank has a transaction monitoring system. The bank has a BSA officer. The bank has a training program. None of those exist check-the-box certifications equal to an adequate program when volume and complexity have outgrown the controls’ original design.
A Risk and Control Self-Assessment tests whether your controls are working — not just whether they exist. The scoring rubric is built specifically to surface the gap between “we have this” and “this actually catches what it’s supposed to catch.” The 141 pre-populated risk assessments include compliance and BSA/AML controls, and the self-assessment questionnaire is designed to surface the volume-to-staffing and calibration gaps that produce OCC findings before the examiner does.
If your last BSA/AML control assessment scored everything green because the controls exist, that’s exactly the result that gets written up.
External Sources
- OCC Announces Enforcement Actions for July 2026 — OCC (July 2026)
- United Texas Bank Achieves Historic Post-Dodd-Frank OCC Conversion — PR Newswire (May 2026)
- Wall Street Gets New Crypto Rival After Texas Bank Completes Regulatory Pivot — CoinDesk (May 2026)
- OCC Updates BSA/AML Examination Procedures for Community Banks — Davis Polk (2025)
- BSA/AML in 2025–2026: Five Developments Every Compliance Leader Needs to Know — Wolters Kluwer
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the OCC's July 2026 Cease and Desist order against United Texas Bank require?
Why did United Texas Bank have both a Federal Reserve and an OCC enforcement action?
What makes BSA/AML compliance harder for crypto-focused banks?
What does OCC national bank charter conversion mean for BSA/AML compliance standards?
What is UTB Prism Sentinel and does it satisfy OCC examination requirements?
What should compliance teams at crypto-serving banks do after seeing this enforcement action?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
● Don't wait for your own enforcement action
Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.
RCSA (Risk & Control Self-Assessment)
141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.
◆ Keep reading
Related posts.
Regulatory Compliance
Effective Challenge in Model Risk Management: Document the Disagreement
Model risk management effective challenge needs a decision trail. Build a challenge memo that preserves evidence, responses, conditions, and escalation.
Jul 24, 2026
Regulatory Compliance
FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now
FinCEN's student aid fraud alert gives banks nine red flags, a SAR keyword, and a clear transaction-monitoring task for ACH refunds.
Jul 23, 2026
Regulatory Compliance
Magnolia Diagnostics False Claims Act Settlement: Why Investors Paid Part of the $24 Million
The Magnolia Diagnostics False Claims Act settlement reached investors, requisition controls, and $24M in payments. Here is what to fix.
Jul 23, 2026