FDIC Strategies Related to Crypto-Asset Risks, EVAL-24-01 (redacted)

Bitcoin Research — Law, Regulation, Markets & Origins (2026)

Banking

2023-10-17

Document text

Research, not advice. Part of the Bitcoin research archive (October 2026). Claims labelled unverified, contested or fringe are reported, not endorsed; statuses of bills and rules are as of the date checked. Government, court and patent records are public domain; the research notes are CC BY 4.0.

FDIC Strategies Related to Crypto-Asset Risks

October 2023                                                                   EVAL-24-01

                                 Evaluation Report
                          Audits, Evaluations, and Cyber
                                      

                                 REDACTED VERSION
                                PUBLICLY AVAILABLE

                    The redactions contained in this report are
                     based upon requests from FDIC senior
                      management to protect the Agency’s
                           information from disclosure.

                  IntegrityIndependenceAccuracyObjectivityAccountability
                                             

                                                NOTICE

Pursuant to Pub. L. 117-263, section 5274, non-governmental organizations and business entities
identified in this report have the opportunity to submit a written response for the purpose of clarifying or
providing additional context to any specific reference. Comments must be submitted to
[email protected] within 30 days of the report publication date as reflected on our public website.
Any comments will be appended to this report and posted on our public website. We request that
submissions be Section 508 compliant and free from any proprietary or otherwise sensitive information.
                       Executive Summary

FDIC Strategies Related to Crypto-Asset Risks
        According to a September 2022 White House Fact Sheet, millions of people globally,
        including 16 percent of adult Americans, have purchased crypto assets. The Fact
        Sheet also stated, crypto assets “present potential opportunities to reinforce the U.S.
        leadership in the global financial system and remain at the technological frontier.”
        Executive Order 14067 (March 2022) stated that the U.S. has an interest in
        responsible financial innovation and expanding access to safe and affordable
        financial services using crypto assets. The Executive Order also stated that the U.S.
        has an interest in reducing the cost of domestic and cross-border funds transfers and
        payments and modernizing its public payment systems, which may be possible
        through the use of crypto assets.

        While crypto assets present many potential opportunities and benefits, they also
        pose a number of risks to the U.S. financial system. In recent years, the crypto-asset
        sector has experienced significant volatility. The total market capitalization of crypto
        assets fluctuated from about $132 billion in January 2019 to $3 trillion in
        November 2021. More concerning, the market capitalization has fallen by 60 percent
        to $1.2 trillion as of April 2023. These events highlight various risks that the
        crypto-asset sector could pose to financial institutions, including liquidity, market,
        pricing, and consumer protection risks. Financial institutions can be exposed to
        crypto-asset risks when providing services to crypto-asset companies or engaging in
        crypto-asset-related activities.

        While currently limited, if material exposure of financial institutions to the risks posed
        by crypto-related activities were to manifest, it may affect the Federal Deposit
        Insurance Corporation’s (FDIC) mission to maintain stability and public confidence in
        the Nation’s financial system. The FDIC carries out its mission by, among other
        things, supervising and examining financial institutions for safety and soundness and
        consumer protection. The exposure of financial institutions to the risks posed by
        crypto-related activities presents safety and soundness risks and consumer
        protection concerns. According to the FDIC, it is taking a deliberate and cautious
        approach to bank participation in crypto-related activities.

        As stated in Executive Order 14067, crypto assets present numerous opportunities to
        foster innovation and cost savings. The FDIC has an opportunity to take actions to
        uphold the United States’ interests in the financial sector. However, because crypto
        assets also pose significant risks to the financial sector, the FDIC should ensure it

October 2023    EVAL-24-01
Executive Summary

          can effectively address those risks, and promote safety and soundness and
          consumer protection.

          The objective of our review was to determine whether the FDIC has developed and
          implemented strategies that address the risks posed by crypto assets.

Results
          The FDIC has started to develop and implement strategies that address the risks
          posed by crypto assets. However, the Agency has not assessed the significance
          and potential impact of the risks. Specifically, the FDIC has not yet completed a risk
          assessment to determine whether the Agency can sufficiently address
          crypto-asset-related risks through actions such as issuing guidance to supervised
          institutions. In addition, the FDIC’s process for providing supervisory feedback on
          FDIC-supervised institutions’ crypto-related activities is unclear. As part of its
          process, the FDIC requested financial institutions to provide information pertaining to
          their crypto-related activities. Additionally, the FDIC issued letters (pause letters),
          between March 2022 and May 2023, to certain FDIC-supervised financial institutions
          asking them to pause, or not expand, planned or ongoing crypto-related activities,
          and provide additional information. However, the FDIC did not (1) establish an
          expected timeframe for reviewing information and responding to the supervised
          institutions that received pause letters, and (2) describe what constitutes the end of
          the review process for supervised institutions that received a pause letter.

          Until the FDIC assesses the risks of crypto activities and provides supervised
          institutions with effective guidance, the FDIC and some FDIC-supervised institutions
          may not take appropriate actions to address the most significant risks posed by
          crypto assets. In addition, based on evidence obtained during our evaluation, the
          FDIC’s lack of clear procedures causes uncertainty for supervised institutions in
          determining the appropriate actions to take. If financial institutions do not receive
          timely feedback from the FDIC and do not understand what constitutes the end of the
          FDIC’s review process, this uncertainty creates risk that the FDIC will be viewed as
          not being supportive of financial institutions engaging in crypto-related activities.

Recommendations
          This report contains two recommendations for the FDIC to: (1) establish a plan with
          timeframes for assessing risks pertaining to crypto-related activities and (2) update

October 2023     EVAL-24-01                           ii
Executive Summary

         and clarify the supervisory feedback process related to its review of supervised
         institutions’ crypto-related activities.

         The FDIC concurred with both report recommendations and proposed corrective
         actions that were sufficient to address the intent of the recommendations. Therefore,
         we consider these recommendations to be resolved and open pending completion of
         the corrective actions. The FDIC plans to complete all corrective actions by
         January 30, 2024.

October 2023    EVAL-24-01                          iii
                            Contents

BACKGROUND......................................................................................................................... 3

EVALUATION RESULTS .......................................................................................................... 8

           The FDIC Should Continue Its Efforts to Assess Risks Related to Crypto Assets ........................ 8
           The FDIC Should Improve Its Supervisory Feedback Process for Crypto-Related Activities ...... 11

FDIC COMMENTS AND OIG EVALUATION ............................................................................13

Appendices

     1.   Objective, Scope, Methodology                                                                                         15
     2.   Acronyms and Abbreviations                                                                                            17
     3.   FDIC Comments                                                                                                         18
     4.   Summary of the FDIC’s Corrective Actions                                                                              23

Figure

     1.    Crypto-Asset Market Capitalization – January 2019 to April 2023                                                        2
                                                                               Federal Deposit Insurance Corporation
                                                                                          Office of Inspector General
                                                                                       Audits, Evaluations, and Cyber

             October 17, 2023

             Subject FDIC Strategies Related to Crypto-Asset Risks

             According to a September 2022 White House Fact Sheet, millions of people globally,
             including 16 percent of adult Americans, have purchased crypto assets. 1 The Fact
             Sheet also stated, crypto assets “present potential opportunities to reinforce the U.S.
             leadership in the global financial system and remain at the technological frontier.” A
             March 2022 Executive Order stated that the U.S. has an interest in responsible
             financial innovation and expanding access to safe and affordable financial services
             using crypto assets. 2 The Executive Order also stated that the U.S. has an interest
             in reducing the cost of domestic and cross-border funds transfers and payments and
             modernizing its public payment systems that may be possible through the use of
             crypto assets. 3

             In March 2022, the U.S. Government Accountability Office (GAO) issued a report
             that described a number of benefits resulting from crypto assets. 4 According to
             GAO, cryptocurrencies, a type of crypto asset, are growing as a means of payment
             by individuals, businesses, and governments around the world. Because
             cryptocurrencies are digitally based and generally do not depend on intermediaries,
             they have the potential to reduce user costs. In addition, cryptocurrency users can
             conduct transactions in a manner that may provide greater privacy for their financial
             activities.

             While crypto assets present many potential opportunities and benefits, they also
             pose a number of risks to the U.S. financial system. In recent years, the crypto-asset
             sector has experienced significant volatility. As shown in Figure 1, the total market
             capitalization of crypto assets fluctuated from about $132 billion in January 2019 to
             $3 trillion in November 2021. More concerning, the market capitalization has fallen
             by 60 percent to $1.2 trillion as of April 2023. These events highlight various risks

1
   FACT SHEET: White House Releases First-Ever Comprehensive Framework for Responsible Development of
Digital Assets (September 16, 2022). By “crypto asset,” the FDIC refers generally to any digital asset implemented
using cryptographic techniques.
2
  Executive Order 14067, Ensuring Responsible Development of Digital Assets (March 9, 2022). The FDIC has
determined that Executive Order 14067 is non-binding on the FDIC. We have included discussion of the Executive
Order in this report because it provides context to the Federal Government’s overall approach to crypto assets.
3 Public payment systems are mechanisms established to facilitate the clearing and settlement of monetary and other

financial transactions.
4 Government Accountability Office, Blockchain: Emerging Technology Offers Benefits for Some Applications but

Faces Challenges, GAO-22-104625 (March 2022).

    October 2023      EVAL-24-01
FDIC Strategies Related to Crypto-Asset Risks

              that the crypto-asset sector could pose to financial institutions, including liquidity,
              market, pricing, and consumer protection risks. 5 Financial institutions can be
              exposed to crypto-asset risks by providing services to crypto-asset companies or by
              engaging in crypto-related activities. 6

                     Figure 1: Crypto-Asset Market Capitalization—January 2019 to April 2023

              Source: CoinMarketCap data as of July 26, 2023

              While currently limited, if material exposure of financial institutions to the risks posed
              by crypto-related activities were to manifest, it may affect the Federal Deposit
              Insurance Corporation’s (FDIC) mission to maintain stability and public confidence in
              the Nation’s financial system. The FDIC carries out its mission by, among other
              things, supervising and examining financial institutions for safety and soundness and
              consumer protection. The exposure of financial institutions to the risks posed by
              crypto-related activities presents safety and soundness risks and consumer
              protection concerns. According to the FDIC, the Board of Governors of the Federal
              Reserve System (FRB), and the Office of the Comptroller of the Currency (OCC),
              financial institutions should be aware of a number of key risks. These risks include:
                  • Volatility in crypto-asset markets which could potentially impact deposit flows
                      associated with crypto-asset companies.

5
  For purposes of this report, a financial institution means either 1) a state-chartered bank or savings institution that is
not a member of the Federal Reserve System or 2) an FDIC-insured depository institution. We use the terms “bank”
and “financial institution” interchangeably throughout this report.
6 In FIL-16-2022, the FDIC defined the term “crypto-related activities” to include acting as crypto-asset custodians;

maintaining stablecoin reserves; issuing crypto and other digital assets; acting as market makers or exchange or
redemption agents; participating in blockchain- and distributed ledger-based settlement or payment systems,
including performing node functions; as well as related activities such as finder activities and lending. The FIL stated
this listing is based on known existing or proposed crypto-related activities engaged in by FDIC-supervised
institutions, but given the changing nature of this area, other activities may emerge that fall within the scope of this
FIL. The inclusion of an activity within this listing should not be interpreted to mean that the activity is permissible for
FDIC-supervised institutions.

    October 2023      EVAL-24-01                                     2
FDIC Strategies Related to Crypto-Asset Risks

                  •    Susceptibility to stablecoin run risk which could potentially impact deposit
                       outflows for banking organizations that hold stablecoin reserves. 7
                  •    Contagion risk resulting from interconnections among certain crypto-asset
                       participants, including through lending, investing, funding, service, and
                       operational arrangements. These interconnections may also lead to
                       concentration risks for financial institutions with exposures to the crypto-asset
                       sector.

              As stated in Executive Order 14067, crypto assets present numerous opportunities to
              foster innovation and cost savings. The FDIC has an opportunity to take actions to
              uphold the United States’ interests in the financial sector. However, because crypto
              assets also pose significant risks to the financial sector, the FDIC should ensure it
              can effectively address those risks, and promote safety and soundness and
              consumer protection.

              The objective of our review was to determine whether the FDIC has developed and
              implemented strategies that address the risks posed by crypto assets. We
              conducted this evaluation in accordance with the Council of the Inspectors General
              on Integrity and Efficiency Quality Standards for Inspection and Evaluation.
              Appendix 1 presents our evaluation objective, scope, and methodology.

BACKGROUND
              The FDIC achieves its mission, in part, by carrying out a supervision program to
              promote safe and sound operations at financial institutions and ensure compliance
              with federal consumer protection laws. Further, the FDIC is responsible for
              managing resolutions and receiverships. The Division of Risk Management
              Supervision (RMS) supervises financial institutions to help ensure that they operate
              in a safe and sound manner; the Division of Depositor and Consumer Protection
              (DCP) supervises financial institutions to promote compliance with federal consumer
              protection laws and regulations; and the Divisions of Resolutions and Receiverships
              (DRR) and Complex Institution Supervision and Resolution close and liquidate failing
              and failed institutions.

              FDIC Efforts to Address Crypto-Asset Risks

              The FDIC developed an initial approach to address crypto-asset risks in 2021. The
              FDIC’s approach, at that time, included a plan to provide clear guidance to the public
              on: (1) how the FDIC’s existing rules and policies apply to crypto assets, (2) the

7 The term “stablecoins” refers to a category of cryptocurrencies with mechanisms that are aimed at maintaining a

stable value, such as by tying the value of the coin to a specific currency, asset, or pool of assets or by algorithmically
controlling supply in response to changes in demand in order to stabilize value.

 October 2023         EVAL-24-01                                     3
FDIC Strategies Related to Crypto-Asset Risks

            types of activities that are permissible for financial institutions to engage in, and
            (3) the FDIC’s supervisory expectations for financial institutions that engage in such
            activities. The approach also included working with the FRB and OCC to coordinate
            policies for how and under what circumstances financial institutions can engage in
            activities involving crypto assets.

            In 2022, the FDIC shifted to a “bottom up” approach to understanding crypto-asset
            risks. In March 2022, the FDIC established the Crypto Asset Risks Interdivisional
            Working Group to focus on this new (and still current) approach to crypto-asset
            risks. 8 According to the FDIC, its current approach to engaging with supervised
            institutions as they consider crypto-related activities includes: (1) developing an
            understanding of supervised institutions’ crypto-related activities, (2) providing
            institutions with case-specific supervisory feedback, and (3) providing broader
            industry guidance on an interagency basis.

            To gain an understanding of the crypto-related activities and the associated risks, on
            April 7, 2022, the FDIC issued Financial Institution Letter (FIL) 16-2022, Notification
            and Supervisory Feedback Procedures for FDIC-Supervised Institutions Engaging in
            Crypto-Related Activities. The FIL requested that FDIC-supervised institutions notify
            the FDIC if they intended to engage in, or were currently engaged in, crypto-related
            activities. The FIL requested that institutions “provide information necessary to allow
            the agency to assess the safety and soundness, consumer protection, and financial
            stability implications of such activities.” Also, the FIL stated that the FDIC will review
            the notification and information received and request additional information as
            needed. In addition, the FIL stated that the FDIC would provide relevant supervisory
            feedback to the FDIC-supervised institution, as appropriate, in a timely manner. The
            FRB and OCC have issued similar requests to their supervised institutions. 9

            In response to FIL 16-2022, a number of FDIC-supervised institutions provided
            notifications of their intent to engage in, or engagement in, crypto-related activities.
            According to FDIC data, as of January 2023, the Agency was aware of 96
            FDIC-supervised financial institutions that either had expressed interest or were
            engaged in crypto-related activities. Some of these activities included
            crypto-asset-custody services, deposit services, crypto-asset-collateralized lending,
            and facilitation of customer purchase and sale of crypto assets through a third party.

            In June 2022, the Directors of RMS and DCP issued a memorandum to the Regional
            Directors (RD memo) to facilitate the tracking and review of notifications received in

8 The FDIC’s Crypto Asset Working Group includes: RMS, DCP, DRR, Division of Insurance and Research, Division

of Complex Institution Supervision and Resolution, and the Legal Division.
9 Federal Reserve SR 22–6 / CA 22–6: Engagement in Crypto-Asset-Related Activities by Federal

Reserve-Supervised Banking Organizations (August 16, 2022); OCC, Interpretive Letter 1179 (November 18, 2021).

 October 2023       EVAL-24-01                                4
FDIC Strategies Related to Crypto-Asset Risks

              response to the FIL. 10                                   (b) (8)

                                                                                            The FDIC amended the
              RD memo in October 2022                                          (b) (8)

              According to the FDIC, as part of its review of financial institutions’ crypto-related
              activities, between March 2022 and May 2023, the FDIC sent letters to
                                                                                                  (b) (8)

              supervised institutions. The letters asked that the institutions pause from proceeding
              with planned activities or expanding existing activities and to provide additional
              information. The FDIC asked these                 financial institutions to pause their
                                                        (b) (8)

              crypto-related activities in order to assess the safety and soundness, consumer
              protection, and financial stability implications of such activities before providing
              supervisory feedback. According to the FDIC, as of August 2023, the FDIC had
              provided of these            supervised institutions with supervisory feedback related to
                         (b) (     (b) (8)

              their planned or ongoing crypto-related activities. 11

              FDIC Efforts to Address Crypto-Related Activities of Failed Institutions

              The resolution of failing or failed institutions (FFI) engaged in crypto-related activities
              poses complex challenges to the FDIC. The challenges include the assessment of
              franchise value, operational considerations, and deposit insurance determinations.
              As a result, DRR developed a strategy to address these challenges. In
              January 2021, DRR began developing a Digital Assets Operational Plan to ensure its
              readiness to respond to and execute on resolution scenarios related to crypto assets.

10 Regional Director Memorandum, Procedures for Reviewing Notifications of Engagement in Crypto-Related

Activities (June 6, 2022, amended October 31, 2022).
11 According to the FDIC, the Agency has provided (b) (8) supervised institutions with supervisory feedback related to

their planned or ongoing crypto-related activities. Only of these           institutions had received a pause letter.
                                                          (b) (8    (b) (8)

 October 2023         EVAL-24-01                                    5
FDIC Strategies Related to Crypto-Asset Risks

              In December 2022, DRR completed the first phase of its plan by developing and
              documenting five known potential use cases. 12 According to DRR, this plan will be a
              living document, and DRR will update the plan as new digital asset activities,
              legislative developments, and advances in technology emerge. In addition, DRR
              entered into a contract for crypto-asset management and liquidation services
              associated with FFIs.

              FDIC Efforts to Address Misrepresentations of Deposit Insurance

              A separate, but related issue, is the risk of misrepresentations about FDIC deposit
              insurance by non-bank entities (such as crypto companies). In 2022, a
              cryptocurrency company filed for bankruptcy. This company had been
              misrepresenting to its customers for over a year that the funds it held for customers
              were insured by the FDIC. In July 2022, the FDIC and FRB issued a joint letter
              demanding that this firm cease and desist from making such claims. According to
              the FDIC, between July 2022 and June 2023, the Agency issued 11 additional public
              advisory letters to non-bank entities that appeared to be making crypto-related
              misrepresentations about FDIC deposit insurance. 13 These advisory letters
              demanded that the recipients stop making false and misleading statements regarding
              FDIC deposit insurance and take immediate action to address these misleading and
              false statements or to provide documentation that their claims are true and
              accurate. 14 The FDIC also issued FIL 35-2022 Advisory to FDIC-Insured Institutions
              Regarding Deposit Insurance and Dealings with Crypto Companies, and a Fact
              Sheet: What the Public Needs to Know About FDIC Deposit Insurance and Crypto
              Companies. FIL 35-2022 and the Fact Sheet provided additional information about
              deposit insurance coverage and the risks of misrepresentations of FDIC insurance
              coverage.

              The FDIC obtains information on potential deposit insurance misrepresentations
              through various methods, including monitoring three public portals. DCP monitors
              two of the portals, which also contain other consumer protection and deposit
              insurance complaints. The Legal Division created the third portal in July 2022. 15
              This third portal is focused on complaints and inquiries related to misrepresentations
              of deposit insurance. Along with setting up the new portal, the FDIC updated internal

12 The five potential use cases include:   (1) crypto assets held and owned by the FFI, (2) crypto assets held by the
FFI as loan collateral, (3) crypto assets held by the FFI in custody for customers, (4) bank-created stabletoken on a
permissioned ledger, and (5) a multibank permissioned payment system.
13 These 11 letters do not represent all public advisory letters that the FDIC has issued regarding misrepresentations

about FDIC deposit insurance. For purposes of this report, we included the number of letters issued to address
crypto-related misrepresentations only.
14 The Federal Deposit Insurance Act prohibits any person from representing or implying that an uninsured deposit is

insured or from knowingly misrepresenting the extent and manner in which a deposit liability, obligation, certificate, or
share is insured and authorizes the FDIC to enforce these prohibitions. 12 U.S.C.1828(a)(4).
15 This portal was created as part of the FDIC’s final rule on False Advertising, Misrepresentation of Insured Status,

and Misuse of the FDIC’s Name or Logo, which became effective July 5, 2022. This rule established the process by
which the FDIC will identify and investigate conduct that may violate section 18(a)(4) of the FDI Act.

 October 2023         EVAL-24-01                                    6
FDIC Strategies Related to Crypto-Asset Risks

              processes for evaluating, escalating, and responding to misrepresentation
              complaints and inquiries. The Legal Division is the primary group responsible for
              responding to misrepresentation issues.

              Joint Statements by the Federal Regulatory Agencies

              The FDIC, FRB, and OCC jointly issued a number of public statements regarding the
              risks posed by crypto assets in 2021 and 2023. In November 2021, the FDIC, FRB,
              and OCC issued a joint statement summarizing their interagency crypto-asset policy
              sprint initiative. The initiative set forth the agencies’ plan to clarify the rules and
              regulations around how financial institutions can engage in crypto-related activities. 16
              In the joint statement, the agencies said that they planned to “provide greater clarity
              on whether certain activities related to crypto assets conducted by banking
              organizations are legally permissible.” The agencies also stated that they planned to
              provide “expectations for safety and soundness, consumer protection, and
              compliance with existing laws and regulations” related to certain crypto-related
              activities. 17

              In January and February 2023, the FDIC, FRB, and OCC issued two additional joint
              statements regarding financial institutions’ crypto-related activities. 18 In the
              January 2023 joint statement, the agencies highlighted key crypto-asset risks for
              financial institutions’ awareness. The joint statement also outlined the agencies’
              views regarding whether certain crypto-related activities are consistent with safe and
              sound banking practices. The agencies stated that “issuing or holding as principal
              crypto assets that are issued, stored, or transferred on an open, public, and/or
              decentralized network, or similar system is highly likely to be inconsistent with safe
              and sound banking practices.” 19 Further, the agencies warned that they have
              “significant safety and soundness concerns with business models that are
              concentrated in crypto-asset-related activities or have concentrated exposures to the
              crypto-asset sector.” In the February 2023 joint statement, the agencies discussed
              the heightened liquidity risks presented by certain funding sources of
              crypto-asset-sector participants and offered methods to manage such risks. The
              February 2023 statement also discussed the importance of establishing and
              maintaining effective risk management and controls commensurate with the level of
              liquidity risks and provided examples of certain practices. 20

16 Joint Statement on Crypto-Asset Policy Sprint Initiative and Next Steps (November 2021).
17 The joint statement listed these crypto-related activities:  (1) Crypto-asset safekeeping and traditional custody
services, (2) Ancillary custody services, (3) Facilitation of customer purchases and sales of crypto assets, (4) Loans
collateralized by crypto assets, (5) Issuance and distribution of stablecoins, and (6) Activities involving the holding of
crypto assets on the balance sheet.
18 Joint Statement on Crypto-Asset Risks to Banking Organizations (January 2023).
19 Decentralized network generally refers to crypto-asset protocols and platforms that allow for some form of

automated peer-to-peer transactions.
20 Joint Statement on Liquidity Risks to Banking Organizations Resulting from Crypto-Asset Market Vulnerabilities

(February 2023).

 October 2023          EVAL-24-01                                    7
FDIC Strategies Related to Crypto-Asset Risks

EVALUATION RESULTS
          We found that the FDIC has started to develop and implement strategies that
          address the risks posed by crypto assets. For example, the FDIC identified the risks
          associated with its supervised financial institutions’ crypto-related activities and
          issued FIL-16-2022, which established a strategy to review information financial
          institutions submitted pertaining to their crypto-related activities and provide
          supervisory feedback on these activities. However, the Agency has not assessed
          the significance and potential impact of the risks. Specifically, the FDIC has not yet
          completed a risk assessment to determine whether the Agency can sufficiently
          address crypto-asset-related risks through actions such as issuing guidance to
          supervised institutions. In addition, the FDIC’s process for providing supervisory
          feedback under FIL-16-2022 is unclear. As part of its process, the FDIC issued
          letters (pause letters) to certain FDIC-supervised financial institutions asking them to
          pause, or not expand, planned or ongoing crypto-related activities. However, the
          FDIC did not (1) establish an expected timeframe for reviewing information and
          responding to the supervised institutions that received pause letters and (2) describe
          what constitutes the end of the review process for supervised institutions that
          received a pause letter.

          Until the FDIC assesses the risks of crypto activities and provides supervised
          institutions with effective guidance, the FDIC and some FDIC-supervised institutions
          may not take appropriate actions to address the most significant risks posed by
          crypto assets. In addition, based on evidence obtained during our evaluation, the
          FDIC’s lack of clear procedures causes uncertainty for supervised institutions in
          determining the appropriate actions to take. If financial institutions do not receive
          timely feedback from the FDIC and do not understand what constitutes the end of the
          FDIC’s review process for paused crypto-related activities, this uncertainty creates
          risk that the FDIC will be viewed as not being supportive of financial institutions
          engaging in crypto-related activities.

          The FDIC Should Continue Its Efforts to Assess Risks Related to Crypto
          Assets

          The FDIC has identified numerous risks associated with its supervised financial
          institutions’ crypto-related activities. However, the Agency has not yet assessed the
          significance and potential impact of these risks through a risk assessment. A risk
          assessment would enable the FDIC to determine whether the crypto-asset-related
          risks can be sufficiently addressed as identified in the Crypto Asset Risks
          Interdivisional Working Group (“Crypto Asset Working Group”) Charter.

 October 2023   EVAL-24-01                            8
FDIC Strategies Related to Crypto-Asset Risks

              The Crypto Asset Working Group Charter (May 2022) describes its mission as being
              “responsible for assessing the safety and soundness, consumer protection, deposit
              insurance, resolution planning, and financial stability risks associated with
              crypto-asset-related activities that are, or may be, engaged in by financial
              institutions.” The Charter further states that the group “shall report out its
              assessment of these risks, including whether such risks can be sufficiently mitigated,
              and, as appropriate, provide recommendations for addressing those risks to the
              relevant officers of the agency.”

              The FDIC started to identify risks associated with financial institution crypto-related
              activities in its draft Framework for Developing an FDIC Policy View on Digital Assets
              Potential [Insured Depository Institution] Activity, Assessment Approach, and
              Potential Policy Issues (2021 Framework) and the draft Facilitation Bottom-Up Risk
              Assessment Framework (2022 Facilitation Framework) (September 26, 2022). In its
              2021 Framework, the FDIC identified potential financial institution crypto-related
              activities and the Agency’s approach for analyzing risks and developing a policy
              view. The FDIC used this as a briefing document during a discussion on a 2021
              FDIC Digital Assets Performance Goal with the former Chairman. In the 2022
              Facilitation Framework, the FDIC identified numerous risks, including consumer
              protection risks and financial stability risks specifically associated with financial
              institutions’ crypto-asset-facilitation activities. 21 The FDIC issued joint statements in
              January and February 2023, along with the FRB and OCC, which identified key
              crypto-asset risks and heightened liquidity risks presented by certain funding sources
              of crypto-asset-sector participants. However, the Crypto Asset Working Group has
              not completed a risk assessment of any of the crypto-related activities, including
              facilitation activities.

              According to the GAO’s Standards for Internal Control in the Federal Government
              (September 2014) (Green Book), “Risk assessment is the identification and analysis
              of risks related to achieving the defined objectives to form a basis for designing risk
              responses.” It also states, “Management analyzes the identified risks to estimate
              their significance...” 22 Furthermore, “Management designs overall risk responses for
              the analyzed risks based on the significance of the risk and defined risk tolerance.” 23
              The Green Book also states that documentation “provides a means to retain
              organizational knowledge and mitigate the risk of having that knowledge limited to a

21 Crypto-asset-facilitation activities are activities whereby a financial institution connects customers and third parties

to facilitate the customers’ purchase and sale (trades) of crypto assets.
22 Green Book 7.06 states Management estimates the significance of the identified risks to assess their effect on

achieving the defined objectives at both the entity and transaction levels. Management estimates the significance of
a risk by considering the magnitude of impact, likelihood of occurrence, and nature of the risk. Magnitude of impact
refers to the likely magnitude of deficiency that could result from the risk and is affected by factors such as the size,
pace, and duration of the risk’s impact. Likelihood of occurrence refers to the level of possibility that a risk will occur.
The nature of the risk involves factors such as the degree of subjectivity involved with the risk and whether the risk
arises from fraud or from complex or unusual transactions.
23 Green Book 6.08 defines risk tolerance as “the acceptable level of variation in performance relative to the

achievement of objectives.”

 October 2023          EVAL-24-01                                     9
FDIC Strategies Related to Crypto-Asset Risks

          few personnel, as well as a means to communicate that knowledge as needed to
          external parties, such as external auditors.”

          According to the FDIC, it is taking a deliberate and cautious approach to bank
          participation in crypto-asset-related activities. However, the FDIC has not yet
          analyzed the crypto-asset risks and documented its assessment of them.
          Specifically, the FDIC has not assessed their significance in order to determine the
          magnitude of impact, likelihood of occurrence, and nature of the risks. Also, the
          FDIC has not developed mitigation strategies, such as issuing guidance to financial
          institutions, to ensure that risks are within the defined risk tolerance.

          This occurred because the FDIC’s process for assessing and responding to risks
          related to FDIC-supervised institutions’ crypto-related activities is not mature. In
          early 2022, the FDIC adopted a new bottom-up approach to develop an
          understanding of supervised institutions’ crypto-asset-related activities and the
          associated risks. Since that time, the FDIC has made efforts to address crypto-asset
          risks, such as issuing two FILs, the RD memo, two interagency joint statements, and
          a number of public advisory letters to crypto-asset companies. While these efforts
          are positive and necessary to understanding the risks posed by crypto assets, the
          FDIC must continue its work to fully understand and address the risks.

          If the FDIC does not assess the significance of the risks posed by crypto assets, it
          might not take appropriate actions to address them. The FDIC should conduct risk
          assessments as a basis to develop mitigation strategies. Without a risk assessment,
          the FDIC may not develop and issue effective policies, procedures, and guidance to
          address these risks.

          If the FDIC does not provide its supervised institutions with effective guidance, the
          FDIC and some FDIC-supervised institutions may not take appropriate actions to
          address the most significant risks posed by crypto assets. This could impact the
          FDIC’s mission to promote financial stability. The FDIC promotes financial stability,
          in part, by ensuring safe and sound financial institution practices and protecting
          consumers from financial harm. Absent effective guidance, financial institutions may
          not employ safe and sound practices to mitigate risks while developing innovative
          strategies and business lines to stay competitive in the financial marketplace.

          Recommendation

          We recommend that the Crypto Asset Risks Interdivisional Working Group:

          1. Establish a plan with timeframes for assessing risks pertaining to crypto-related
             activities by:
             a) Continuing to identify and document crypto-asset risks,

 October 2023   EVAL-24-01                           10
FDIC Strategies Related to Crypto-Asset Risks

                        b) Performing and documenting an analysis of the identified risks to estimate
                           their significance, and
                        c) Developing and documenting strategies to address crypto-asset risks.

              The FDIC Should Improve Its Supervisory Feedback Process for
              Crypto-Related Activities

              The FDIC issued FIL-16-2022 which established a strategy to review information
              financial institutions submitted pertaining to their crypto-related activities and provide
              supervisory feedback on these activities. However, the FDIC’s process for providing
              supervisory feedback to FDIC-supervised institutions about their crypto-related
              activities is unclear. The FDIC asked some financial institutions to pause or refrain
              from expanding certain crypto-related activities until it completed a review and
              provided supervisory feedback. Under the FIL, the FDIC was to provide timely,
              relevant, supervisory feedback. However, the FDIC did not establish an expected
              timeframe for reviewing the activities and responding to the FDIC-supervised
              institutions that received a pause letter. Also, the FDIC did not define what
              constitutes the end of its review process for institutions that received a pause letter.
              While the FDIC has maintained communication with these institutions, the lack of a
              clear end to the review process results in an extended pause and uncertainty for
              some institutions.

              According to the FDIC, between March 2022 and May 2023, the FDIC sent letters to
                 supervised institutions as part of its review of the institutions’ crypto-related
              (b) (8)

              activities. The letters (pause letters) asked that the institutions pause from
              proceeding with planned activities or expanding existing activities and provide
              additional information. The pause letters stated that the institutions should provide
              additional information “in advance of implementation,” “pause all crypto asset-related
              activities,” or “not proceed with any crypto-asset activity.” The FDIC asked the
              institutions to pause their activities in order to review the institutions’ crypto-related
              activities before providing supervisory feedback. The activities that institutions
              provided information on include crypto-asset-custody services, facilitation of
              customer purchase and sale of crypto assets through a third party, and
              crypto-asset-collateralized lending. According to the FDIC, as of August 2023, out of
              the         supervised institutions that received a pause letter, the FDIC had only
                  (b) (8)

              provided institutions with supervisory feedback. (b) (8) supervised institutions
                             (b) (8)

              have decided not to pursue crypto-related activities or are no longer
              FDIC-supervised. 24 The remaining have not received any supervisory feedback
                                                             (b) (

              from the FDIC.

24 There are (b) (8) additional supervised institutions that are no longer pursuing crypto activities or are no longer

FDIC-supervised, but these (b) (8) institutions are included within the             institutions that received supervisory feedback.
                                                                          (b) (8)

 October 2023             EVAL-24-01                                  11
FDIC Strategies Related to Crypto-Asset Risks

             Review Timeframe Not Established
             The FDIC did not establish an expected timeframe for reviewing the institutions’
             activities and responding to the FDIC-supervised institutions that received pause
             letters. According to FIL 16-2022, “[t]he FDIC will provide relevant supervisory
             feedback to the FDIC-supervised institution, as appropriate, in a timely manner”
             (emphasis added). The FDIC established procedures for reviewing and responding
             to notifications under the FIL in an RD memo. The RD memo, however, (b) (8)

                                                                                           The FDIC
             pause letters also did not provide the financial institutions with a timeframe for FDIC
             review of the information nor a timeframe for providing supervisory feedback.

             Review End Process Not Described
             FDIC procedures do not describe what constitutes the end of the review process for
             supervised institutions that received a pause letter. The RD memo states that (b) (8)
                                                             (b) (8)

                        (b) (8)          It also states that                  (b) (8)
                             (b) (8)                  An FDIC official described final supervisory
             feedback as “the final version of the supervisory feedback to be transmitted to the
             bank.” This official further stated the term “does not have a special meaning beyond
             being the last stage of the internal review process.” The FDIC’s procedures do not
             describe the end of the review process and what the final supervisory feedback
             entails. By not clearly stating or documenting what constitutes the end of the FDIC’s
             review process, the FDIC may be causing confusion for the financial institutions that
             received a pause letter. For example, when one institution provided information on
             its planned crypto-related activities to the FDIC, it requested that the FDIC provide its
             approval of those activities. However, in the pause letter sent to the supervised
             institution, the FDIC stated that the FIL “does not provide for the issuance of an FDIC
             non-objection....” 25 The letter requested that the institution “not proceed with planned
             activities, pending FDIC supervisory feedback.” This example demonstrates that the
             institution may be confused about what would constitute the end of the FDIC’s review
             process.

             According to the GAO Standards for Internal Control in the Federal Government,
             “[m]anagement documents in policies… its responsibility for an operational process’s
             objectives and related risks, and control activity design, implementation, and
             operating effectiveness.” Policies may be further defined through day-to-day
             procedures. These procedures may "include the timing of when a control activity

25 A non-objection is when the banking regulatory agency communicates to the institution that it does not object to the

activity.

 October 2023        EVAL-24-01                                   12
FDIC Strategies Related to Crypto-Asset Risks

          occurs and any follow-up corrective actions to be performed by competent personnel
          if deficiencies are identified.”

          The RD memo did not include an expected timeframe for reviewing a financial
          institution’s information and responding to an institution that received a pause letter.
          It also did not describe the end of the review process for these institutions. This
          occurred because the FDIC’s process for reviewing and responding to information
          received from FDIC-supervised institutions’ crypto-related activities is not mature. In
          early 2022, the FDIC adopted a new bottom-up approach to understand crypto-asset
          risks through use cases. The FDIC is continuing this effort in 2023.

          Based on evidence obtained during our evaluation, including our independent
          evaluation of the FDIC’s process, discussions with FDIC personnel, and statements
          made by individuals in the banking and crypto-asset industries, we determined that
          the FDIC’s lack of clear procedures and timely feedback regarding crypto-asset
          activities causes uncertainty for supervised institutions in determining the appropriate
          actions to take. While the FDIC has maintained communication with these
          institutions, the lack of a clear end to the review process results in an extended
          pause and uncertainty for some institutions. The uncertainty in the process creates
          risk that the FDIC will be viewed as not being supportive of financial institutions
          participating in crypto activities. Such a view leads to risk that the FDIC would
          inadvertently limit financial institution innovation and growth in the crypto space. This
          view has also been expressed by individuals in the banking and crypto-asset
          industries alleging that financial regulators have been cutting off crypto firms from
          accessing the banking system and stifling innovation.

          Recommendation

          We recommend that the Director of the Division of Risk Management Supervision:

          2. Update and clarify the supervisory feedback process to (a) establish an expected
             timeframe for reviewing information and responding to FDIC-supervised
             institutions pursuant to the Financial Institution Letter and (b) describe what
             constitutes the completion of its review of its supervised institutions’
             crypto-related activities.

FDIC COMMENTS AND OIG EVALUATION

          The FDIC’s Director of RMS provided a written response, dated
          September 27, 2023, to a draft of this report. The response is presented in its
          entirety in Appendix 3.

 October 2023   EVAL-24-01                            13
FDIC Strategies Related to Crypto-Asset Risks

          In its response, the FDIC concurred with both report recommendations. The FDIC’s
          proposed corrective actions were sufficient to address the intent of both
          recommendations, and the FDIC plans to complete corrective actions for these
          recommendations by January 30, 2024. We consider both recommendations to be
          resolved.

          Both recommendations in this report will remain open until we confirm that corrective
          actions have been completed and the actions are responsive. A summary of the
          FDIC’s corrective actions is contained in Appendix 4.

 October 2023   EVAL-24-01                           14
Appendix 1        Objective, Scope, and Methodology

        Objective

        The evaluation objective was to determine whether the FDIC has developed and
        implemented strategies that address the risks posed by crypto assets.

        We conducted this evaluation from June 2022 through June 2023 in accordance with
        the Council of the Inspectors General on Integrity and Efficiency Quality Standards
        for Inspection and Evaluation (issued December 2020).

        Scope and Methodology

        The scope of our evaluation focused on the FDIC’s efforts to develop and implement
        strategies that address crypto-asset risks. To obtain an understanding of the FDIC’s
        efforts, we interviewed FDIC officials and staff from the Crypto Asset Risks
        Interdivisional Working Group, the Division of Risk Management Supervision, the
        Division of Depositor and Consumer Protection, the Division of Resolutions and
        Receiverships, the Division of Complex Institution Supervision and Resolution, and
        the Legal Division. Additionally, we reviewed the following relevant FDIC
        documents:

        •    Digital Assets Operational Plan (Revised December 2022);
        •    Division of Resolutions and Receiverships contract with a third party for
             crypto-asset services to support resolution and receivership activities (effective
             September 2021);
        •    Draft Framework for Developing an FDIC Policy View on Digital Assets Potential
             [Insured Depository Institution] Activity, Assessment Approach, and Potential
             Policy Issues (2021);
        •    Draft Facilitation Bottom-Up Risk Assessment Framework (September 26, 2022);
        •    FDIC public advisory letters issued to companies that appeared to be making
             crypto-related false or misleading representations about FDIC deposit insurance
             (Letters issued between July 2022 and June 2023);
        •    FDIC letters issued to certain FDIC-supervised institutions asking for additional
             information on planned or ongoing crypto-related activities, and pause from
             proceeding with planned activities or expanding existing activities (Letters issued
             between March 2022 and May 2023);
        •    FDIC’s Crypto-Related Activity Tracking System data (as of January 2023);
        •    Financial Institution Letter 16-2022, Notification and Supervisory Feedback
             Procedures for FDIC-Supervised Institutions Engaging in Crypto-Related
             Activities (April 7, 2022);
        •    Financial Institution Letter 35-2022 Advisory to FDIC-Insured Institutions
             Regarding Deposit Insurance and Dealings with Crypto Companies, and Fact

October 2023    EVAL-24-01                           15
Objective, Scope, and Methodology

              Sheet: What the Public Needs to Know About FDIC Deposit Insurance and
              Crypto Companies (July 29, 2022);
          •   Regional Director Memorandum, Procedures for Reviewing Notifications of
              Engagement in Crypto-Related Activities (June 6, 2022, amended
              October 31, 2022);
          •   Remarks by FDIC Chairman Jelena McWilliams at Money 20/20 (October 2021);
          •   Remarks by FDIC Acting Chairman Martin J. Gruenberg at the Brookings
              Institution on The Prudential Regulation of Crypto-Assets (October 2022);
          •   The Crypto Asset Risks Interdivisional Working Group Charter (May 2022); and
          •   The Crypto Asset Risks Interdivisional Working Group minutes (April 2022
              through February 2023).

          We also reviewed joint statements issued by the FDIC, OCC, and FRB: Joint
          Statement on Crypto-Asset Policy Sprint Initiative and Next Steps
          (November 23, 2021); Joint Statement on Crypto-Asset Risks to Banking
          Organizations (January 3, 2023); and Joint Statement on Liquidity Risks to Banking
          Organizations Resulting from Crypto-Asset Market Vulnerabilities
          (February 23, 2023).

          We further reviewed Executive Order No. 14067, Executive Order on Ensuring
          Responsible Development of Digital Assets (March 9, 2022) and the associated
          reports directed by the Executive Order. Moreover, we reviewed the GAO Report,
          Emerging Technology Offers Benefits for Some Applications but Faces Challenges,
          GAO-22-104625 (March 2022).

          To gain an understanding of the FDIC’s supervisory actions provided to its
          supervised institutions regarding their crypto-related activities, we selected a sample
          of nine institutions engaged in or planning to engage in crypto-related activities. We
          selected the sample from the FDIC’s Crypto-Related Activity Tracking System (as of
          October 2022). For this sample, we reviewed the FDIC’s examination or visitation
          documentation, correspondence, and letters issued as of January 2023.

          In addition, we reviewed FRB’s SR 22–6 / CA 22–6: Engagement in
          Crypto-Asset-Related Activities by Federal Reserve–Supervised Banking
          Organizations (August 16, 2022) and the OCC Interpretive Letter 1179
          (November 18, 2021). We further interviewed these two Federal banking regulatory
          agencies to obtain information on their efforts in identifying and addressing risks
          associated with their supervised institutions’ crypto-related activities.

          We applied internal control principles promulgated by the GAO (the Green Book) to
          guide our work when appropriate. For example, we considered internal controls
          standards, and activities, related to (1) identifying, analyzing, and responding to risks
          and (2) implementing control activities such as documentation of responsibilities
          through policies.

 October 2023    EVAL-24-01                            16
Appendix 2       Acronyms and Abbreviations

Crypto Asset Working Group   Crypto Asset Risks Interdivisional Working Group
DCP                          Division of Depositor and Consumer Protection
DRR                          Division of Resolutions and Receiverships
FDIC                         Federal Deposit Insurance Corporation
FFI                          Failing or failed institutions
FIL                          Financial Institution Letter
FRB                          Board of Governors of the Federal Reserve System
GAO                          United States Government Accountability Office
OCC                          Office of the Comptroller of the Currency
OIG                          Office of Inspector General
RD memo                      Regional Director memorandum
RMS                          Division of Risk Management Supervision
WO                           Washington Office

October 2023   EVAL-24-01                            17
 Appendix 3                 FDIC Comments

Federal Deposit Insurance Corporation
550 17th Street NW, Washington, D.C. 20429-9990                                   Division of Risk Management Supervision

TO:                 Terry L. Gibson
                    Assistant Inspector General, Audits, Evaluations, and Cyber
                    Office of Inspector General
                                                            Digitally signed by
                                                  DOREEN    DOREEN EBERLEY

FROM:               Doreen R. Eberley             EBERLEY   Date: 2023.09.27
                                                            18:43:57 -04'00'

                    Director, Division of Risk Management Supervision

DATE:               September 27, 2023

RE:                 Response to Draft Evaluation Report
                    FDIC Strategies Related to Crypto Asset Risks (No. 2022-007)

BACKGROUND

The FDIC has completed its review of the Office of Inspector General’s (OIG) draft evaluation
report entitled, FDIC Strategies Related to Crypto Asset Risks (No. 2022-007), provided on
August 31, 2023 (“draft report”). FDIC concurs with the OIG’s two recommendations, and
provides a response to the recommendations below, including a summary of management’s
planned actions.

FDIC’S APPROACH TO ENGAGING WITH BANKS ON CRYPTO-RELATED
ACTIVITIES

From the perspective of bank regulators, before banks engage in new or rapidly evolving
activities, such as those related to the crypto-asset arena, it is important that they understand that
the activity is permissible under applicable laws and regulations; that the activity can be
conducted in a safe and sound manner; that the bank has put in place appropriate measures and
controls to identify and manage the novel risks associated with those activities; and that the bank
complies with all relevant laws and regulations, including those related to anti-money
laundering/countering the financing of terrorism, and consumer protection. As the OIG points
out in its report, the crypto-asset sector has proven to be highly volatile and has exhibited a
number of risks to financial stability and institutions, including contagion risks due to high levels
of interconnectedness within the sector.

As the crypto-asset sector grew rapidly in 2021 and early 2022, banking regulators recognized
that there was also an increasing interest by some banks to engage in crypto-asset activities. The
FDIC had been generally aware of the interest in crypto-asset related activities through its
normal supervision process, but as interest accelerated, the FDIC recognized that there was
insufficient information on which banks had been engaging in, or were interested in engaging in,
crypto-related activities. To address that gap, and in consideration of various safety and
soundness, consumer protection, and financial stability concerns, the FDIC issued Financial
Institution Letter, Notification of Engaging in Crypto-Related Activities (FIL-16-2022) in April
FDIC Comments

2022, asking FDIC-supervised institutions to notify the FDIC of the crypto-related activities in
which they were engaged or intended to engage.1 FIL-16-2022 described some of the crypto-
related risks about which the FDIC was concerned and indicated that the FDIC would provide
supervisory feedback related to the planned or ongoing activities.

Subsequently, significant events, bankruptcies, and volatility in the crypto-asset industry exposed
a number of vulnerabilities in the crypto-asset sector. For example, the May 2022 Terra USD
collapse; the July 2022 bankruptcies of Three Arrows Capital (3AC), Voyager, and Celsius; the
November 2022 FTX bankruptcy; and the significant price decline of Bitcoin (BTC) in 2022
from over $47,000 to less than $17,000.2 Some of these disruptions involved consumers being
unable to access their funds. In addition, it became evident that false and misleading statements,
either direct or implied, by crypto-asset entities concerning the availability of deposit insurance
for a given crypto-asset product violated the law, and could give consumers the impression that
crypto-asset products are protected by FDIC deposit insurance, when they are not.3

In July 2022, the FDIC issued a fact sheet for consumers regarding deposit insurance4 and an
advisory reminding insured banks of the risks that could arise related to misrepresentations of
deposit insurance.5 While not specific to crypto-assets, the FDIC Board of Directors approved a
final rule on May 17, 2022, to help address instances in which firms misrepresent the availability
of deposit insurance in violation of the law.6 Also, on December 13, 2022, the FDIC Board of
Directors issued for public comment a proposed rule to amend its regulations on use of the
official FDIC sign and to clarify the FDIC regulation regarding misrepresentations of deposit
insurance. This proposed rule also adds crypto-asset to the definition of non-deposit product.7
The volatility in the crypto-asset sector continued as 2022 unfolded, including a rapid
deterioration in and ultimate bankruptcy of a large crypto-asset firm.8

The banking regulators had been observing and discussing the risks posed by the crypto-asset
sector, and determined to issue interagency guidance regarding those risks. In January 2023, the
FDIC, the Board of Governors of the Federal Reserve (Federal Reserve), and the Office of the
Comptroller of the Currency (OCC) released a joint statement on crypto-asset risks to banking
organizations (see FIL-01-2023, Joint Statement on Crypto-Asset Risks to Banking
Organizations, issued January 5, 2023).9 The statement describes the risks to banking

1
  See https://www.fdic.gov/news/financial-institution-letters/2022/fil22016.html
2
  See, for example,
https://www.washingtonpost.com/business/2022/07/06/voyager-bankruptcy-three-arrows/ and
https://www.washingtonpost.com/business/2022/07/13/crypto-bankruptcy-celsius-depositors/ and
https://www.nytimes.com/2022/11/11/business/ftx-bankruptcy.html and
https://coinmarketcap.com/currencies/bitcoin/
3
  See https://www.fdic.gov/news/press-releases/2022/pr22060.html
4
  See https://www.fdic.gov/news/press-releases/2022/pr22058.html
5
  See https://www.fdic.gov/news/financial-institution-letters/2022/fil22035.html
6
  See https://www.fdic.gov/news/financial-institution-letters/2022/fil22021.html
7
  See https://www.fdic.gov/news/financial-institution-letters/2022/fil22052.html
8
  See, for example, https://www.nytimes.com/2022/11/11/business/ftx-bankruptcy.html and
https://www.wsj.com/articles/crypto-crisis-a-timeline-of-key-events-11675519887
9
  See https://www.fdic.gov/news/financial-institution-letters/2023/fil23001.html

                                                      2
FDIC Comments

organizations and reminds banking organizations that they should ensure that crypto-asset-
related activities can be performed in a safe and sound manner, are legally permissible, and
comply with applicable laws and regulations, including those designed to protect consumers.

Also, in February 2023, the FDIC, Federal Reserve, and OCC issued a Joint Statement on
Liquidity Risks to Banking Organizations Resulting from Crypto-Asset Market Vulnerabilities
(see FIL-08-2023, issued on February 23, 2023).10 The statement highlights key liquidity risks
associated with certain sources of funding from crypto-asset-related entities that banking
organizations should be aware of. The statement reminds banking organizations to apply
existing risk management principles and provides examples of practices that could be effective.
The agencies also continue to emphasize that banking organizations are neither prohibited nor
discouraged from providing banking services to customers of any specific class or type, as
permitted by law or regulation.11

The FDIC has actively engaged with institutions that have advised the FDIC of their activities or
plans pursuant to FIL-16-2022. In what appears to be a product of changing market conditions
(e.g., crypto-asset firm bankruptcies and disruptions described above, challenging
macroeconomic conditions, crypto-asset service providers exiting certain business lines), a
number of FDIC-supervised institutions have provided updates on previously planned activities
and subsequently notified the FDIC that they no longer plan to pursue crypto-related activities.
The majority of banks that received pause letters have notified the FDIC that they are no longer
actively pursuing crypto-related activity.12

CONTEXT REGARDING FDIC ENTERPRISE RISK MANAGEMENT

The FDIC carries out its mission by, among other things, supervising and examining financial
institutions for safety and soundness and consumer protection. As part of its Enterprise Risk
Management (ERM) function, the FDIC maintains an enterprise-wide Risk Inventory, which is a
comprehensive, detailed list of risks that could hamper the FDIC’s ability to achieve its goals and
objectives. The risk attributes captured in the Risk Inventory include all the components from
the GAO Standards for Internal Control in the Federal Government (Green Book) related to risk
assessments that are outlined in the OIG draft evaluation report.

The Green Book outlines that a risk assessment “assesses the risk facing the entity as it seeks to
achieve its objectives.”13 The risk attributes captured in the Risk Inventory include: identifying
the risk, existing controls to mitigate the risk, impact, likelihood, residual risk, and planned
mitigations, among other things. The FDIC has identified risks related to staying abreast of

10
   See https://www.fdic.gov/news/financial-institution-letters/2023/fil23008.html
11
   See also, FIL 5-2015, Statement on Providing Banking Services, issued January 28, 2015.
12
   In the draft report’s discussion of banks that received pause letters, the draft report states that some banks have not
received any supervisory feedback. In those instances, banks are either no longer actively pursuing crypto-related
activity or banks have: not provided information requested by the FDIC; materially revised the proposed activities
and the FDIC has requested updated information; or the proposed activities are broad, complex, and significant (for
which FDIC staff are actively working on providing supervisory feedback).
13
   See GAO-14-704G Federal Internal Control Standards, page 7.

                                                            3
FDIC Comments

industry trends and emerging technology, as well as ongoing efforts related to crypto-assets as
controls for those risks.

FDIC MANAGEMENT RESPONSE TO RECOMMENDATIONS

FDIC concurs with the recommendations.

Recommendation 1: OIG recommends that the Crypto Asset Risks Interdivisional Working
Group:
       1. Establish a plan with timeframes for assessing risks pertaining to crypto-related
       activities by:
               a) Continuing to identify and document crypto-asset risks,
               b) Performing and documenting an analysis of the identified risks to estimate their
               significance, and
               c) Developing and documenting strategies to address crypto-asset risks.

Planned Action: The FDIC concurs with this recommendation. The FDIC will utilize the ERM
program to continue to identify and document risks that may face the FDIC in achieving its mission
associated with supervising banks pursuing crypto-related activities, including the significance of
those risks, and as appropriate, will identify any additional supervisory strategies to encourage bank
management to appropriately manage risks to the bank.

Estimated Completion Date: The divisions that are members of the Interdivisional Working will
provide a memorandum to the Chief Risk Officer documenting the risk assessment by January
30, 2024.

Recommendation 2: OIG recommends that the Director of the Division of Risk Management
Supervision (RMS): Update and clarify the supervisory feedback process to (a) establish an
expected timeframe for reviewing information and responding to FDIC-supervised institutions
pursuant to the Financial Institution Letter and (b) describe what constitutes the completion of its
review of its supervised institutions’ crypto-related activities.

Planned Action: The FDIC concurs with this recommendation. The RMS Director, in
coordination with the Director of the Division of Depositor and Consumer Protection, and in
consultation with the Legal Division as appropriate, will update joint internal processes to
include instructions for establishing expected timeframes for: 1) reviewing additional
information after it is requested and received by the FDIC, and 2) responding to FDIC-
supervised institutions after such date that the FDIC determines sufficient information has been
received. Those instructions may allow for consideration of factors, such as the complexity of
the activities or proposed activities, when establishing expected timeframes. In addition, the
FDIC will update joint internal processes to outline expectations for communicating to an
institution what constitutes the completion of the case-specific crypto-related activity review
process.

                                                   4
FDIC Comments

Estimated Completion Date: Internal processes will be updated via a joint regional director
memorandum that will be issued by January 30, 2024.

                                               5
 Appendix 4               Summary of the FDIC’s Corrective Actions

This table presents management’s response to the recommendations in the report and the
status of the recommendations as of the date of report issuance.

 Rec.         Corrective Action: Taken or              Expected         Monetary      Resolved:a      Open or
 No.                    Planned                      Completion Date    Benefits                      Closedb
                                                                                       Yes or No

   1      The FDIC will utilize the ERM              January 30, 2024       $0            Yes           Open
          program to continue to identify and
          document risks that may face the
          FDIC in achieving its mission
          associated with supervising banks
          pursuing crypto-related activities,
          including the significance of those
          risks, and as appropriate, will identify
          any additional supervisory strategies
          to encourage bank management to
          appropriately manage risks to the
          bank.

   2      The RMS Director, in coordination          January 30, 2024       $0            Yes           Open
          with the Director of the Division of
          Depositor and Consumer Protection,
          and in consultation with the Legal
          Division as appropriate, will update
          joint internal processes to include
          instructions for establishing expected
          timeframes for: 1) reviewing
          additional information after it is
          requested and received by the FDIC,
          and 2) responding to FDIC-
          supervised institutions after such
          date that the FDIC determines
          sufficient information has been
          received. Those instructions may
          allow for consideration of factors,
          such as the complexity of the
          activities or proposed activities, when
          establishing expected timeframes. In
          addition, the FDIC will update joint
          internal processes to outline
          expectations for communicating to an
          institution what constitutes the
          completion of the case-specific
          crypto-related activity review
          process.

a Recommendations are resolved when —

    1.   Management concurs with the recommendation, and the OIG agrees the planned corrective action is
         consistent with the recommendation.
    2.   Management does not concur or partially concurs with the recommendation, but the OIG agrees that the
         proposed corrective action meets the intent of the recommendation.
    3.   For recommendations that include monetary benefits, management agrees to the full amount of OIG
         monetary benefits or provides an alternative amount and the OIG agrees with that amount.
b Recommendations will be closed when the OIG confirms that corrective actions have been completed and are

responsive.

 October 2023         EVAL-24-01                                 23
                        Federal Deposit Insurance Corporation
                        Office of Inspector General

                                 3501 Fairfax Drive
                                 Room VS-E-9068
                                Arlington, VA 22226

                                  (703) 562-2035

                                    

         The OIG’s mission is to prevent, deter, and detect waste, fraud,
         abuse, and misconduct in FDIC programs and operations; and to
         promote economy, efficiency, and effectiveness at the agency.

         To report allegations of waste, fraud, abuse, or misconduct
         regarding FDIC programs, employees, contractors, or contracts,
         please contact us via our Hotline or call 1-800-964-FDIC.

FDIC OIG website             X, formerly known as Twitter

www.fdicoig.gov                     @FDIC_OIG
                                                                   www.oversight.gov/