Mergers and Capital Measurement under Reg W: Aggregating Capital Until the Next Call Report

When two depository institutions merge, a practical question arises: how does the surviving bank measure its capital stock and surplus for Regulation W purposes during the gap between the merger date and the filing of the merged bank’s first consolidated Call Report?

The Federal Reserve provides helpful flexibility. The surviving bank may use the aggregate capital stock and surplus of the two merging depository institutions until the merged bank files its next Call Report. This allows the merged institution to capture the benefit of the combined capital base immediately, rather than being constrained to just one institution’s last-filed Call Report.

This is important because mergers can involve significant intercompany activity during integration, and being stuck with only one bank’s pre-merger capital figure could artificially constrain necessary post-merger transactions with affiliates.

The key requirement is that once the merged institution files its first consolidated Call Report, that becomes the new baseline for all Regulation W calculations on a go-forward basis.

DM Tip: In merger planning, calculate the combined Regulation W capacity early. Document the aggregate capital stock and surplus of both merging institutions as of their respective last Call Reports, and use this figure for compliance monitoring during the integration period until your first post-merger Call Report is filed.

The Fiduciary Exemption: Holding Shares With Sole Voting Discretion

Under Regulation W’s control analysis, owning shares typically implies the potential for control over the issuing company. But what if a company holds shares in a fiduciary capacity? Can it qualify for the exception from the definition of “control” even if it has sole voting discretion over those shares?

The answer is yes. Unlike the analogous provision in Section 4(f)(2) of the Bank Holding Company Act, which excludes fiduciaries with sole discretionary voting power, Regulation W’s fiduciary exemption does not impose such a limitation. A company may qualify for the fiduciary exception from control even if it exercises sole voting discretion over the shares held in trust.

This is an important distinction for bank trust departments that hold significant blocks of stock in fiduciary accounts. Under the BHC Act, sole voting discretion would negate the fiduciary exception and potentially create a control relationship. Under Regulation W, however, the trust department’s holdings in fiduciary accounts do not create an affiliate relationship solely because the bank has voting discretion.

The rationale reflects the different purposes of the two statutes. The BHC Act’s control provisions focus on preventing unauthorized concentrations of banking power, while Regulation W focuses on protecting banks from affiliate transaction risks. Fiduciary holdings with voting discretion do not create the same risk of self-dealing that Regulation W targets.

DM Tip: If your bank’s trust department holds significant equity positions with sole voting discretion, document that these holdings are in a fiduciary capacity to support the Regulation W control exemption. Be aware that the same analysis may differ under the BHC Act, so consult both frameworks.

Legal Considerations in Data Center Financing: A Practical Guide

The explosive growth of cloud computing, artificial intelligence, and digital infrastructure has made data center financing one of the most active — and complex — segments of the real estate and project finance markets. Whether you represent a lender, developer, or equity sponsor, here are the key legal considerations to keep in mind.

Land Use and Zoning

Data centers present unique land use challenges. Local zoning ordinances may not contemplate data center use as a permitted category, requiring special use permits, variances, or rezoning. Counsel should evaluate whether the site’s zoning classification permits the intended use — including the associated power infrastructure, cooling systems, and backup generators — and anticipate potential opposition from neighboring landowners or municipalities concerned about noise, water consumption, and aesthetic impact. Restrictive covenants and CC&Rs on the land should also be reviewed for compatibility.

Power and Utility Arrangements

Power availability is often the single most critical factor in site selection. Financing parties should carefully review power purchase agreements, utility service contracts, and any interconnection agreements with the local grid operator. Key issues include capacity commitments, curtailment risk, rate escalation provisions, and the enforceability of long-term supply arrangements. Increasingly, renewable energy procurement (through PPAs or virtual PPAs) adds another layer of contractual complexity.

Environmental and Permitting

Data centers carry meaningful environmental exposure. Water-intensive cooling systems may trigger water use permits or environmental impact assessments. Backup diesel generators raise air quality permitting requirements. Counsel should diligence the full permitting stack — building permits, environmental permits, stormwater management plans, and any applicable state or federal environmental review — and assess the timeline risk of delayed approvals.

Real Estate Structure

Data center deals frequently involve ground leases, build-to-suit arrangements, or sale-leasebacks. Each structure presents distinct issues for lenders, including leasehold mortgageability, estoppel and SNDA requirements, and the treatment of tenant improvements and trade fixtures. For colocation facilities, master lease structures with subletting rights and non-disturbance protections for subtenants are critical to preserving collateral value.

Construction and Development Risk

Financing a data center during the construction phase introduces the typical suite of construction lending issues — guaranteed maximum price contracts, performance bonds, completion guarantees, and disbursement mechanics — with the added complexity of specialized mechanical, electrical, and plumbing (MEP) systems. Lenders should pay close attention to the contractor’s data center track record, commissioning protocols, and the treatment of delays tied to long-lead equipment (e.g., transformers, switchgear, and generators).

Tenant and Revenue Considerations

Lenders underwriting data center cash flows must evaluate the creditworthiness of tenants (often hyperscale cloud providers or enterprise users), the durability of lease terms, and the risk of early termination or contraction options. Customer concentration risk is a recurring theme, as a single anchor tenant may represent the majority of revenue. Counsel should also consider the interplay between the lease structure and any managed services or interconnection agreements that contribute to the revenue stack.

Tax Incentives and Regulatory Matters

Many jurisdictions offer tax incentives — including sales tax exemptions on equipment, property tax abatements, and enterprise zone benefits — to attract data center development. These incentive agreements should be carefully structured to survive financing events, including foreclosure. On the regulatory side, data privacy and security laws (such as state data breach notification statutes) may impose obligations on facility operators that indirectly affect the lender’s collateral package.

Insurance

Data centers require specialized insurance coverage beyond a standard commercial property policy. Key coverages include business interruption (with extended indemnity periods reflecting long equipment replacement timelines), equipment breakdown, cyber liability, and environmental liability. Lenders should require evidence of adequate coverage and ensure that policy terms align with the credit agreement’s insurance requirements.

DM Tips:

Data center financing sits at the intersection of real estate, project finance, technology, and energy law. A successful transaction requires early coordination among specialists in each of these areas, careful diligence on the site and its permitting and utility arrangements, and deal structures that account for the asset class’s distinctive risk profile. Duane Morris is fluent in these issues consistently advises clients on this increasingly important part of the infrastructure landscape.

Overhauled Third-Party Risk Management Guidance: What Banks and Their Vendors Need to Do Now

On September 11, 2026, the FDIC, Federal Reserve Board, OCC, and NCUA jointly proposed a package of three documents that would reshape third-party risk management (“TPRM”) oversight for banks and credit unions: (1) new interagency guidance replacing the 2023 TPRM framework, (2) a practical companion guide for community banks, and (3) a joint statement putting core service providers on notice. Comments are due November 16, 2026 — here is what your institution needs to know. 

What Went Wrong With the 2023 Guidance

The agencies acknowledge the 2023 framework failed on four fronts: it was interpreted too broadly, drove checklist compliance instead of risk-proportionate oversight, incentivized process over substance, and chilled engagement with fintechs and innovative providers. The bottom line for institutions: disproportionate compliance spending on low-risk relationships and lock-in with legacy vendors. 

How the New All-Bank Framework Changes Day-to-Day TPRM

The proposed guidance would replace the 2023 Guidance and 2024 community bank resources.

Three shifts matter most for compliance teams:

Risk-Based Prioritization. TPRM practices should be calibrated to the magnitude and likelihood of harm of each relationship — not merely whether it supports a “critical activity.” Lower-risk relationships may warrant less detailed due diligence, standard-form contracts, or less frequent monitoring.

Principles, Not Prescriptions. The guidance is expressly non-binding; non-compliance alone will not trigger supervisory criticism. The framework is organized into four components:

  1. Risk Identification and Assessment — identifying third-party relationships, cataloguing associated risks, and assessing their severity.
  2. Risk Oversight — covering due diligence, contract negotiation, ongoing monitoring, termination planning, and cross-cutting topics such as subcontractor oversight, operational resilience, and insurance/indemnification.
  3. Residual Risk Acceptance — recognizing that institutions may reasonably accept some amount of residual risk based on their risk appetite.
  4. Governance — establishing appropriate board and management oversight structures.

Encouraging Innovation. The guidance recognizes co-ventures, consortia for joint due diligence, standard-setting organizations, and third-party consultants as legitimate TPRM strategies — a clear signal that engaging with fintechs and newer providers should not be treated as inherently higher risk.

New Playbook for Community Banks Under $30 Billion

The Federal Reserve separately proposed a Third-Party Risk Management Guide for Traditional Community Banking Organizations (“TCBOs”) — institutions under $30 billion focused on serving local communities. Banks with complex bank-fintech partnership models are excluded. The guide gives TCBOs an operational roadmap organized in two parts:

Overarching Risk Management Topics. Four cross-cutting themes applicable to most TCBO third-party relationships:

  • Operational Resilience — assessing how a vendor’s disruptions could impair the institution’s operations, including through review of SOC reports, penetration testing, and business continuity testing.
  • System and Information Security — managing vulnerabilities created when vendors access sensitive banking systems.
  • Compliance with Rules and Regulations — ensuring third parties performing regulated functions maintain compliance, including with payment network rules.
  • Financial Resilience — evaluating a vendor’s financial stability, particularly when it is privately held or a newer market entrant.

Vendor-by-Vendor Considerations. The guide identifies eight categories of third parties most commonly used by TCBOs and provides risk-specific guidance for each:

  • Core Providers
  • IT Infrastructure Providers
  • Cybersecurity Providers
  • Payment Processing and Digital Banking Providers
  • Loan Management System Providers
  • Card Issuing and Processing Providers
  • BSA/AML and Financial Crime Platform Providers
  • Fraud Prevention and Detection Providers

For core providers, the guide addresses core conversion considerations — costs, integration challenges, and middleware alternatives — in significant detail.

The Board is seeking comment on the $30 billion asset threshold, whether to add “deposit placement networks” as a vendor category, and whether the guide’s detail level risks creating de facto supervisory standards. 

Core Service Providers Face Direct Supervisory Scrutiny

The Joint Statement on Community Banks’ Engagement with Core Service Providers (Federal Reserve, FDIC, and OCC) marks a significant escalation. The agencies will now factor three criteria into examination frequency and scope decisions for core providers:

  • Transparency — whether a core provider furnishes timely due diligence information, complies with service level agreements, promptly discloses security incidents, and avoids complex billing practices that are difficult for banks to reconcile.
  • Contract Features — whether contract terms make it unreasonably difficult for community banks to exit relationships or engage supplemental providers. Examples of problematic terms include opaque pricing, excessive “back billing” windows, unsupported deconversion fees, and limitations on third-party integrations with the core platform.
  • Technology — whether the core provider invests in maintaining up-to-date systems, including the frequency and severity of security incidents, management of end-of-life assets, and demonstrated operational resilience.

Notably, the agencies state that certain core providers may qualify as “institution-affiliated parties” under the Federal Deposit Insurance Act, given the degree to which they participate in the conduct of a bank’s affairs. This determination could expose core providers to enforcement actions — a significant escalation in regulatory posture. 

Comments on all three proposals are due November 16, 2026.

DM Tips

For banking organizations: Begin assessing how the shift from checklist-based compliance to risk-based prioritization would affect your existing TPRM program. Community banks in particular should view the TCBO Guide and core provider statement as new leverage in vendor negotiations.

For core service providers: The agencies are now tying examination frequency and scope to provider-level transparency, contract fairness, and technology investment. The institution-affiliated party discussion adds enforcement teeth to what was previously a supervisory expectations framework.

Consolidation = Control: The GAAP Presumption Under Regulation W

One of the most important threshold questions under Regulation W is whether one company “controls” another, because control determine affiliate status. The Federal Reserve has provided one helpful bright-line rule that simplifies this analysis in many cases: if a company consolidates another company on its financial statements prepared under U.S. GAAP, that first company is presumed to have a controlling influence (and therefore control) over the second company.

This presumption is found in 12 CFR 223.3(g)(1)(iii) and is (fortunately) consistent with the Board’s approach in Regulation Y at 12 CFR 225.32(g). The reasoning is quite basic: U.S. GAAP consolidation standards require consolidation when one entity has a controlling financial interest in another. If the accounting standards have already determined that control exists for financial reporting purposes, the Federal Reserve treats that as strong evidence of control for regulatory purposes as well.

This means compliance officers can use their institution’s consolidated financial statements as a starting point for identifying control relationships. If an entity appears on a bank’s consolidated balance sheet, it should presume it is controlled by the banking organization and evaluate whether that creates an affiliate relationship under Regulation W.

However, remember that the GAAP consolidation test is only one of several bases for finding control under 12 CFR 223.3(g). Control can also exist through voting power, board representation, or other factors even without GAAP consolidation.

DM Tip: Use your institution’s GAAP consolidation analysis as a first-pass screen for Regulation W control relationships. Any entity that is consolidated should be evaluated for affiliate status. Flag new consolidation entries immediately for compliance review.

Applying for a National Trust Charter: Key Requirements From the OCC

This blog post provides an overview of the basic requirements and key considerations for institutions applying for a national trust charter with the OCC.

Interest in national trust bank charters has surged in recent years, with the Office of the Comptroller of the Currency (OCC) processing a number of charter applications from companies seeking to offer fiduciary, custody, and related trust services under a federal charter framework. From payroll-focused trust banks to digital asset custodians, the national trust charter has become an increasingly attractive option for institutions that want to operate under federal supervision without necessarily obtaining FDIC deposit insurance.

What Is a National Trust Bank?

A national trust bank (NTB) is a national bank whose operations are limited to those of a trust company and activities related thereto. Traditional services offered by NTBs include personal trust and estate administration, retirement plan services, investment management and advisory activities, corporate trust administration, custody and safekeeping, and cash management. Most NTBs do not offer loans or accept deposits and are not FDIC-insured.

In February 2026, the OCC issued a final rule amending 12 CFR 5.20 to clarify that national trust banks may engage in non-fiduciary activities in addition to fiduciary activities, so long as those activities fall within the “operations of a trust company and activities related thereto.” This rule, effective April 1, 2026, aligned the regulatory text with the OCC’s longstanding statutory authority without expanding or contracting the OCC’s chartering power.

The Chartering Process at a Glance

The OCC’s chartering process for NTBs generally follows these stages:

  1. Prefiling: Organizers are encouraged to consult with the OCC’s licensing staff early in the process to discuss the proposal and identify potential issues before filing a formal application.
  2. Application Filing: Organizers file a charter application under Sections 21, 24(Seventh), and 92a of the National Bank Act and 12 CFR 5.20, along with a request for fiduciary powers under 12 USC 92a and 12 CFR 5.26. While a separate fiduciary powers application is not required for a trust-only charter, the charter application should address all information outlined in both the charter and fiduciary powers application forms.
  3. Preliminary Conditional Approval: If the OCC determines the proposal meets regulatory and policy requirements, it grants preliminary conditional approval—typically subject to specific conditions.
  4. Organization Phase: The organizers establish the bank’s corporate existence and complete all preopening requirements, including a preopening examination by the OCC.
  5. Final Approval: The OCC grants final approval and authorization to open only after all preopening requirements have been satisfied.

Business Plans: A Critical Component

Business plan is the centerpiece of any charter application. According to the OCC’s Comptroller’s Licensing Manual, the plan must adequately address regulatory and policy considerations and must:

  • Demonstrate the organizing group’s collective ability to establish and operate a successful bank in the economic and competitive conditions of the market to be served.
  • Articulate the risks of the proposed operation and the policies, processes, personnel, and control systems that the bank will use to monitor and control those risks.
  • Include detailed financial projections, analysis of risk, and planned risk management systems and controls.

Capital and Liquidity Requirements

Capital and liquidity requirements for NTBs are tailored to each institution and are set as conditions of the charter approval. While NTBs are subject to the minimum leverage and risk-based capital ratios in 12 CFR Part 3, the OCC recognizes that these ratios are generally not optimal measures of capital adequacy for trust banks because off-balance-sheet asset management activities are not captured in the capital ratio calculations. Accordingly, the OCC ordinarily requires a higher level of capital than the standard ratios.

NTBs are also required by 12 USC 92a(i) to have initial capital and surplus not less than the capital and surplus required of state banks offering similar services in the state where the trust bank is located.

In practice, recent conditional approvals illustrate the range. For example, initial paid-in capital requirements have ranged from $7 million (Paycom National Trust Bank, 2024) to $10 million (UKG National Trust Bank, 2026), with ongoing tier 1 capital minimums of $5 million to $7 million. The OCC typically also requires that a significant portion of tier 1 capital be held in “Eligible Liquid Assets,” along with a separate requirement to maintain liquid assets sufficient to cover at least 180 days of operating expenses.

The OCC expects that capital and liquidity will increase beyond these initial minimums as the size, complexity, and risks of the NTB’s activities evolve over time.

Management and Governance

The OCC evaluates the qualifications of all proposed organizers, directors, and executive officers. Background investigations, including submission of fingerprints, are required. The OCC expects that the organizing group brings relevant experience in banking, fiduciary services, risk management, and compliance.

During the first two to three years of operation, NTBs are generally required to obtain the OCC’s prior written determination of no objection before appointing any new senior executive officers or board members. Similarly, any significant deviation from the approved business plan during this period requires advance notice and OCC no-objection.

Information Technology and Security

Before the OCC will grant final charter approval, the NTB must submit for review a complete description of its information systems architecture, its IT risk assessment and management plan, and its information security program. The security program must comply with the Interagency Guidelines Establishing Standards for Safeguarding Customer Information under 12 CFR 30, Appendix B. An independent review of the bank’s security measures, including firewall implementation and testing, is also required.

BSA/AML and Compliance Obligations

Like all national banks, NTBs must maintain a robust BSA/AML program that meets the requirements of 12 CFR 21.21. The OCC also expects trust banks to establish comprehensive compliance policies, insider policies, and internal and external audit frameworks prior to opening.

Key Timing Considerations

Organizers should be mindful of two important deadlines typically imposed as conditions of preliminary approval:

  • Capital must be raised within 12 months of preliminary conditional approval.
  • The bank must open for business within 18 months of that date.

If either deadline is missed, the approval expires. The OCC has indicated it is generally opposed to granting extensions except under the most extenuating circumstances.

Checklist: Key Steps and Documents

The following checklist summarizes the major steps and documents prospective applicants should have in hand or underway before and during the chartering process:

Pre-Application

  • Schedule a prefiling meeting with the OCC’s licensing staff to discuss the proposal and identify potential issues
  • Review the OCC’s Comptroller’s Licensing Manual – Charters booklet and the Charter Application form
  • Identify and vet proposed organizers, directors, and executive officers; begin background investigation paperwork and fingerprint submissions

Application Package

  • Completed Charter Application (covering both charter and fiduciary powers information)
  • Detailed business plan with financial projections, risk analysis, and description of risk management systems and controls
  • Capital and liquidity plan, including proposed initial paid-in capital, ongoing tier 1 capital minimums, eligible liquid asset targets, and 180-day operating expense liquidity reserve
  • Biographical and financial information for all proposed organizers, directors, and officers
  • Proposed Articles of Association and Organization Certificate

Organization Phase (Post-Preliminary Approval)

  • Raise initial paid-in capital within 12 months of preliminary conditional approval
  • Submit IT systems architecture, risk assessment, and management plan for OCC review
  • Implement an information security program compliant with 12 CFR 30, Appendix B, and complete an independent security review
  • Establish BSA/AML program (12 CFR 21.21), compliance policies, insider policies, and internal/external audit frameworks
  • Complete preopening examination and satisfy all remaining OCC conditions
  • Open for business within 18 months of preliminary conditional approval

DM Tips: For organizations considering a national trust charter, the following steps can help position an application for success:

  • Engage early with the OCC’s licensing staff to discuss your proposal and surface potential issues before filing.
  • Develop a detailed, risk-focused business plan that includes financial projections, a capital and liquidity analysis, and a description of the risk management systems and controls your institution will employ.
  • Ensure adequate capitalization tailored to the scope and complexity of your proposed operations, and plan for capital and liquidity to grow as your activities scale.
  • Assemble a qualified management team with demonstrated experience in banking, fiduciary services, and compliance, and begin background investigations early.
  • Build out IT infrastructure and security programs well in advance, as the OCC will require a complete systems review and independent security assessment before granting final approval.
  • Establish BSA/AML and compliance frameworks from the outset to satisfy preopening examination requirements.
  • A well-prepared application remains the foundation for a successful charter process.

Reach out to us if you’re considering a National Trust Bank charter to dig deeper on the process, expectations, and timing.

FinCEN Sounds the Alarm on Digital Asset Investment Scam Centers: What Financial Institutions Need to Know

On September 3, 2026, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) issued Alert FIN-2026-Alert 005, urging financial institutions to be vigilant in detecting, identifying, and reporting suspicious activity connected to digital asset investment scam centers and the laundering of their illicit proceeds. The Alert builds on FinCEN’s September 2023 guidance on digital asset investment scams and reflects the growing scale and sophistication of this threat.

A Rapidly Growing Threat

The numbers are staggering. According to the FBI’s Internet Crime Complaint Center, reported U.S. victim losses from digital asset investment scams have surged from $907 million in 2021 to $7.2 billion in 2025. Total annual revenue collected by Southeast Asian scam centers is estimated in the tens of billions of dollars. These operations are predominantly run by transnational criminal organizations (TCOs) based in Southeast Asia—primarily in Cambodia, Burma, and Laos—with operations now expanding into South Asia, the Pacific Islands, Africa, the Middle East, and South America.

The Alert arrives on the heels of Executive Order 14390, issued by President Trump on March 6, 2026, declaring it the policy of the United States to protect Americans from cybercrime, fraud, and predatory schemes.

How the Scams Work

Scam center operators use a range of fraud schemes—including investment, romance, and government impersonation scams—to induce victims to make payments, often in digital assets. Scammers commonly initiate contact through social media or text messages and exploit enthusiasm around new technologies, including digital assets and artificial intelligence, to lure victims with the promise of outsized returns. TCOs have also adopted AI tools to scale and refine their schemes.

A human trafficking dimension makes these operations especially disturbing: criminal gangs have trafficked hundreds of thousands of people to scam centers, where victims have their passports confiscated and are coerced into perpetrating online fraud.

The Laundering Ecosystem: Guarantee Marketplaces

The Alert devotes significant attention to “guarantee marketplaces”—online marketplaces operating as networks of Chinese-language chat groups on social connection platforms like Telegram. These marketplaces function as marketing venues, payment infrastructure, and trusted intermediaries between buyers and sellers of illicit services, including money laundering, social media account creation, and mass phishing services.

FinCEN highlighted its October 2025 final rule severing Cambodia-based Huione Group from the U.S. financial system, noting that Huione Group laundered at least $4 billion in illicit proceeds between August 2021 and January 2025. In June 2026, FinCEN proposed expanding that rule to cover Huione Group’s successor entities attempting to circumvent the original measure.

Key Red Flags for Financial Institutions

FinCEN identified 16 specific red flags to help financial institutions detect suspicious activity relevant for this Alert, including but not limited to:

  • Victim payment indicators, such as customers stating they were directed by purported law enforcement to make payments in digital assets, precious metals, or gift cards.
  • Guarantee marketplace indicators, such as transactions involving tokens issued by or associated with a guarantee marketplace, or blockchain analysis revealing links to known marketplace infrastructure.
  • Laundering technique indicators, such as stablecoin transactions originating from U.S.-based exchanges that undergo on-chain laundering patterns, or customers transacting through stablecoins whose issuers advertise they do not cooperate with law enforcement.

SAR Filing Guidance

Financial institutions are requested to reference the Alert in SAR filings by including the key term “FIN-2026-SCAMCENTERS” in SAR field 2 and the narrative, and by selecting “Fraud-Other” under SAR field 34(z) with the description “Scam Centers”. FinCEN also encourages institutions to include relevant technical cyber indicators—such as chat logs, phone numbers, digital asset addresses, and suspicious URLs—in SAR submissions.

The Bottom Line

In light of this Alert, financial institutions should consider the following actionable steps:

  • Update transaction monitoring rules to incorporate the specific red flags identified in the Alert, including indicators related to victim payments, guarantee marketplace activity, and on-chain laundering techniques.
  • Train frontline and compliance staff to recognize the hallmarks of digital asset investment scams, including customers who report being directed by purported government officials to make payments in digital assets or precious metals.
  • Review SAR filing procedures to ensure staff include the key term “FIN-2026-SCAMCENTERS” in SAR field 2 and the narrative, and select “Fraud-Other” under SAR field 34(z) with the description “Scam Centers.”
  • Leverage Section 314(b) information sharing with other financial institutions to identify repeat actors moving across institutions to evade detection.
  • Enhance due diligence on MSBs and digital asset service providers, particularly those operating in or connected to Southeast Asia, and monitor for entities that appear to obscure their location or corporate structure.
  • Refer potential victims to the FBI’s IC3 at ic3.gov or the nearest U.S. Secret Service field office.

* Note: All references to specific reports, rules, alerts, and figures used in this blog posting can be found linked in the FinCEN Alert if not linked directly herein.

Indemnification by a Bank to Its Parent: When Does It Become a Covered Transaction under Reg W?

Service contracts between banks and their parent holding companies frequently include indemnification clauses. A common arrangement is for the bank to indemnify its parent for losses caused by the bank’s own negligence or willful misconduct. Does this create a covered transaction?

The answer is no. When a bank indemnifies its parent holding company in a service contract for holding company losses caused by the negligence or willful misconduct of the bank, this does not constitute a covered transaction under Regulation W.

The rationale is that such indemnification clauses are standard commercial terms that reflect the bank’s responsibility for its own actions. The bank is not assuming the affiliate’s risk or extending credit to the affiliate; rather, it is agreeing to make the affiliate whole for damages the bank itself caused. This is more akin to tort liability than to the types of financial transactions Regulation W is designed to restrict.

Under Section 23A, covered transactions include extensions of credit, asset purchases, guarantees, and similar transactions where the bank’s resources are exposed to affiliate risk. An indemnification for the bank’s own misconduct does not fit this framework because the risk originates with the bank, not the affiliate.

DM Tip: When drafting service agreements with affiliates, clearly limit indemnification to losses caused by the bank’s own negligence or willful misconduct. Broader indemnification clauses that cover affiliate losses regardless of fault could be viewed differently and may trigger Regulation W analysis.

Affiliate Purchases Bank Stock: Covered Transaction under Regulation W?

Not every transaction between a bank and its affiliate is a covered transaction under Regulation W. A notable exception is that an affiliate’s purchase of stock issued by the bank is not a covered transaction.

This makes sense from a policy perspective. The purpose of Section 23A and Regulation W is to protect the bank from losses arising from affiliate transactions. When an affiliate purchases the bank’s stock, the bank is receiving capital, not extending resources to the affiliate. The transaction strengthens the bank rather than exposing it to credit or counterparty risk from the affiliate.

This means that a holding company can invest additional equity capital in its subsidiary bank without triggering Regulation W’s quantitative limits, collateral requirements, or other restrictions. Similarly, other affiliates may purchase the bank’s stock or subordinated debt that constitutes equity capital without those purchases counting as covered transactions.

However, banks should note that while the affiliate’s purchase of bank stock is not a covered transaction, the reverse may be. If a bank purchases securities issued by an affiliate, that is a covered transaction subject to all Regulation W requirements.

DM Tip: When structuring capital injections from affiliates, confirm that the transaction involves the affiliate purchasing the bank’s stock (not a covered transaction) rather than the bank investing in affiliate securities (which would be a covered transaction). Document the direction of the capital flow clearly.

Business Trusts and Regulation W: Yes, They Are Companies

While a sole proprietorship is not a company under Regulation W, the analysis is different for trusts established for a business purpose. An ESOP, pension plan, or other business trust qualifies as a “company” for purposes of Regulation W.

This means that if a business trust meets the definition of an affiliate under 12 CFR 223.2, perhaps because it is controlled by the bank’s holding company or because it meets another affiliation criterion, transactions between the member bank and that trust are covered transactions subject to all Regulation W requirements.

This distinction matters particularly in the holding company context, where parent companies frequently establish ESOPs, pension trusts, or special-purpose trusts that hold bank stock or other assets. If such a trust is controlled by an entity that also controls the member bank, the trust is an affiliate, and any extension of credit from the bank to the trust, or any asset purchase, triggers Regulation W compliance obligations.

The key takeaway is that legal form matters under Regulation W. The trust structure, which creates a separate legal entity with its own assets and obligations, is sufficient to qualify as a company, unlike a sole proprietorship where no separate entity exists.

DM Tip: Inventory all trusts in your holding company structure, including ESOPs, pension trusts, and special-purpose vehicles. Do any of them qualify as an affiliate? If so, ensure all transactions with affiliated trusts are captured in your Regulation W monitoring system.

© 2009- Duane Morris LLP. Duane Morris is a registered service mark of Duane Morris LLP.

The opinions expressed on this blog are those of the author and are not to be construed as legal advice.

Proudly powered by WordPress