Legal Considerations in Data Center Financing: A Practical Guide

The explosive growth of cloud computing, artificial intelligence, and digital infrastructure has made data center financing one of the most active — and complex — segments of the real estate and project finance markets. Whether you represent a lender, developer, or equity sponsor, here are the key legal considerations to keep in mind.

Land Use and Zoning

Data centers present unique land use challenges. Local zoning ordinances may not contemplate data center use as a permitted category, requiring special use permits, variances, or rezoning. Counsel should evaluate whether the site’s zoning classification permits the intended use — including the associated power infrastructure, cooling systems, and backup generators — and anticipate potential opposition from neighboring landowners or municipalities concerned about noise, water consumption, and aesthetic impact. Restrictive covenants and CC&Rs on the land should also be reviewed for compatibility.

Power and Utility Arrangements

Power availability is often the single most critical factor in site selection. Financing parties should carefully review power purchase agreements, utility service contracts, and any interconnection agreements with the local grid operator. Key issues include capacity commitments, curtailment risk, rate escalation provisions, and the enforceability of long-term supply arrangements. Increasingly, renewable energy procurement (through PPAs or virtual PPAs) adds another layer of contractual complexity.

Environmental and Permitting

Data centers carry meaningful environmental exposure. Water-intensive cooling systems may trigger water use permits or environmental impact assessments. Backup diesel generators raise air quality permitting requirements. Counsel should diligence the full permitting stack — building permits, environmental permits, stormwater management plans, and any applicable state or federal environmental review — and assess the timeline risk of delayed approvals.

Real Estate Structure

Data center deals frequently involve ground leases, build-to-suit arrangements, or sale-leasebacks. Each structure presents distinct issues for lenders, including leasehold mortgageability, estoppel and SNDA requirements, and the treatment of tenant improvements and trade fixtures. For colocation facilities, master lease structures with subletting rights and non-disturbance protections for subtenants are critical to preserving collateral value.

Construction and Development Risk

Financing a data center during the construction phase introduces the typical suite of construction lending issues — guaranteed maximum price contracts, performance bonds, completion guarantees, and disbursement mechanics — with the added complexity of specialized mechanical, electrical, and plumbing (MEP) systems. Lenders should pay close attention to the contractor’s data center track record, commissioning protocols, and the treatment of delays tied to long-lead equipment (e.g., transformers, switchgear, and generators).

Tenant and Revenue Considerations

Lenders underwriting data center cash flows must evaluate the creditworthiness of tenants (often hyperscale cloud providers or enterprise users), the durability of lease terms, and the risk of early termination or contraction options. Customer concentration risk is a recurring theme, as a single anchor tenant may represent the majority of revenue. Counsel should also consider the interplay between the lease structure and any managed services or interconnection agreements that contribute to the revenue stack.

Tax Incentives and Regulatory Matters

Many jurisdictions offer tax incentives — including sales tax exemptions on equipment, property tax abatements, and enterprise zone benefits — to attract data center development. These incentive agreements should be carefully structured to survive financing events, including foreclosure. On the regulatory side, data privacy and security laws (such as state data breach notification statutes) may impose obligations on facility operators that indirectly affect the lender’s collateral package.

Insurance

Data centers require specialized insurance coverage beyond a standard commercial property policy. Key coverages include business interruption (with extended indemnity periods reflecting long equipment replacement timelines), equipment breakdown, cyber liability, and environmental liability. Lenders should require evidence of adequate coverage and ensure that policy terms align with the credit agreement’s insurance requirements.

DM Tips:

Data center financing sits at the intersection of real estate, project finance, technology, and energy law. A successful transaction requires early coordination among specialists in each of these areas, careful diligence on the site and its permitting and utility arrangements, and deal structures that account for the asset class’s distinctive risk profile. Duane Morris is fluent in these issues consistently advises clients on this increasingly important part of the infrastructure landscape.

Overhauled Third-Party Risk Management Guidance: What Banks and Their Vendors Need to Do Now

On September 11, 2026, the FDIC, Federal Reserve Board, OCC, and NCUA jointly proposed a package of three documents that would reshape third-party risk management (“TPRM”) oversight for banks and credit unions: (1) new interagency guidance replacing the 2023 TPRM framework, (2) a practical companion guide for community banks, and (3) a joint statement putting core service providers on notice. Comments are due November 16, 2026 — here is what your institution needs to know. 

What Went Wrong With the 2023 Guidance

The agencies acknowledge the 2023 framework failed on four fronts: it was interpreted too broadly, drove checklist compliance instead of risk-proportionate oversight, incentivized process over substance, and chilled engagement with fintechs and innovative providers. The bottom line for institutions: disproportionate compliance spending on low-risk relationships and lock-in with legacy vendors. 

How the New All-Bank Framework Changes Day-to-Day TPRM

The proposed guidance would replace the 2023 Guidance and 2024 community bank resources.

Three shifts matter most for compliance teams:

Risk-Based Prioritization. TPRM practices should be calibrated to the magnitude and likelihood of harm of each relationship — not merely whether it supports a “critical activity.” Lower-risk relationships may warrant less detailed due diligence, standard-form contracts, or less frequent monitoring.

Principles, Not Prescriptions. The guidance is expressly non-binding; non-compliance alone will not trigger supervisory criticism. The framework is organized into four components:

  1. Risk Identification and Assessment — identifying third-party relationships, cataloguing associated risks, and assessing their severity.
  2. Risk Oversight — covering due diligence, contract negotiation, ongoing monitoring, termination planning, and cross-cutting topics such as subcontractor oversight, operational resilience, and insurance/indemnification.
  3. Residual Risk Acceptance — recognizing that institutions may reasonably accept some amount of residual risk based on their risk appetite.
  4. Governance — establishing appropriate board and management oversight structures.

Encouraging Innovation. The guidance recognizes co-ventures, consortia for joint due diligence, standard-setting organizations, and third-party consultants as legitimate TPRM strategies — a clear signal that engaging with fintechs and newer providers should not be treated as inherently higher risk.

New Playbook for Community Banks Under $30 Billion

The Federal Reserve separately proposed a Third-Party Risk Management Guide for Traditional Community Banking Organizations (“TCBOs”) — institutions under $30 billion focused on serving local communities. Banks with complex bank-fintech partnership models are excluded. The guide gives TCBOs an operational roadmap organized in two parts:

Overarching Risk Management Topics. Four cross-cutting themes applicable to most TCBO third-party relationships:

  • Operational Resilience — assessing how a vendor’s disruptions could impair the institution’s operations, including through review of SOC reports, penetration testing, and business continuity testing.
  • System and Information Security — managing vulnerabilities created when vendors access sensitive banking systems.
  • Compliance with Rules and Regulations — ensuring third parties performing regulated functions maintain compliance, including with payment network rules.
  • Financial Resilience — evaluating a vendor’s financial stability, particularly when it is privately held or a newer market entrant.

Vendor-by-Vendor Considerations. The guide identifies eight categories of third parties most commonly used by TCBOs and provides risk-specific guidance for each:

  • Core Providers
  • IT Infrastructure Providers
  • Cybersecurity Providers
  • Payment Processing and Digital Banking Providers
  • Loan Management System Providers
  • Card Issuing and Processing Providers
  • BSA/AML and Financial Crime Platform Providers
  • Fraud Prevention and Detection Providers

For core providers, the guide addresses core conversion considerations — costs, integration challenges, and middleware alternatives — in significant detail.

The Board is seeking comment on the $30 billion asset threshold, whether to add “deposit placement networks” as a vendor category, and whether the guide’s detail level risks creating de facto supervisory standards. 

Core Service Providers Face Direct Supervisory Scrutiny

The Joint Statement on Community Banks’ Engagement with Core Service Providers (Federal Reserve, FDIC, and OCC) marks a significant escalation. The agencies will now factor three criteria into examination frequency and scope decisions for core providers:

  • Transparency — whether a core provider furnishes timely due diligence information, complies with service level agreements, promptly discloses security incidents, and avoids complex billing practices that are difficult for banks to reconcile.
  • Contract Features — whether contract terms make it unreasonably difficult for community banks to exit relationships or engage supplemental providers. Examples of problematic terms include opaque pricing, excessive “back billing” windows, unsupported deconversion fees, and limitations on third-party integrations with the core platform.
  • Technology — whether the core provider invests in maintaining up-to-date systems, including the frequency and severity of security incidents, management of end-of-life assets, and demonstrated operational resilience.

Notably, the agencies state that certain core providers may qualify as “institution-affiliated parties” under the Federal Deposit Insurance Act, given the degree to which they participate in the conduct of a bank’s affairs. This determination could expose core providers to enforcement actions — a significant escalation in regulatory posture. 

Comments on all three proposals are due November 16, 2026.

DM Tips

For banking organizations: Begin assessing how the shift from checklist-based compliance to risk-based prioritization would affect your existing TPRM program. Community banks in particular should view the TCBO Guide and core provider statement as new leverage in vendor negotiations.

For core service providers: The agencies are now tying examination frequency and scope to provider-level transparency, contract fairness, and technology investment. The institution-affiliated party discussion adds enforcement teeth to what was previously a supervisory expectations framework.

Consolidation = Control: The GAAP Presumption Under Regulation W

One of the most important threshold questions under Regulation W is whether one company “controls” another, because control determine affiliate status. The Federal Reserve has provided one helpful bright-line rule that simplifies this analysis in many cases: if a company consolidates another company on its financial statements prepared under U.S. GAAP, that first company is presumed to have a controlling influence (and therefore control) over the second company.

This presumption is found in 12 CFR 223.3(g)(1)(iii) and is (fortunately) consistent with the Board’s approach in Regulation Y at 12 CFR 225.32(g). The reasoning is quite basic: U.S. GAAP consolidation standards require consolidation when one entity has a controlling financial interest in another. If the accounting standards have already determined that control exists for financial reporting purposes, the Federal Reserve treats that as strong evidence of control for regulatory purposes as well.

This means compliance officers can use their institution’s consolidated financial statements as a starting point for identifying control relationships. If an entity appears on a bank’s consolidated balance sheet, it should presume it is controlled by the banking organization and evaluate whether that creates an affiliate relationship under Regulation W.

However, remember that the GAAP consolidation test is only one of several bases for finding control under 12 CFR 223.3(g). Control can also exist through voting power, board representation, or other factors even without GAAP consolidation.

DM Tip: Use your institution’s GAAP consolidation analysis as a first-pass screen for Regulation W control relationships. Any entity that is consolidated should be evaluated for affiliate status. Flag new consolidation entries immediately for compliance review.

Applying for a National Trust Charter: Key Requirements From the OCC

This blog post provides an overview of the basic requirements and key considerations for institutions applying for a national trust charter with the OCC.

Interest in national trust bank charters has surged in recent years, with the Office of the Comptroller of the Currency (OCC) processing a number of charter applications from companies seeking to offer fiduciary, custody, and related trust services under a federal charter framework. From payroll-focused trust banks to digital asset custodians, the national trust charter has become an increasingly attractive option for institutions that want to operate under federal supervision without necessarily obtaining FDIC deposit insurance.

What Is a National Trust Bank?

A national trust bank (NTB) is a national bank whose operations are limited to those of a trust company and activities related thereto. Traditional services offered by NTBs include personal trust and estate administration, retirement plan services, investment management and advisory activities, corporate trust administration, custody and safekeeping, and cash management. Most NTBs do not offer loans or accept deposits and are not FDIC-insured.

In February 2026, the OCC issued a final rule amending 12 CFR 5.20 to clarify that national trust banks may engage in non-fiduciary activities in addition to fiduciary activities, so long as those activities fall within the “operations of a trust company and activities related thereto.” This rule, effective April 1, 2026, aligned the regulatory text with the OCC’s longstanding statutory authority without expanding or contracting the OCC’s chartering power.

The Chartering Process at a Glance

The OCC’s chartering process for NTBs generally follows these stages:

  1. Prefiling: Organizers are encouraged to consult with the OCC’s licensing staff early in the process to discuss the proposal and identify potential issues before filing a formal application.
  2. Application Filing: Organizers file a charter application under Sections 21, 24(Seventh), and 92a of the National Bank Act and 12 CFR 5.20, along with a request for fiduciary powers under 12 USC 92a and 12 CFR 5.26. While a separate fiduciary powers application is not required for a trust-only charter, the charter application should address all information outlined in both the charter and fiduciary powers application forms.
  3. Preliminary Conditional Approval: If the OCC determines the proposal meets regulatory and policy requirements, it grants preliminary conditional approval—typically subject to specific conditions.
  4. Organization Phase: The organizers establish the bank’s corporate existence and complete all preopening requirements, including a preopening examination by the OCC.
  5. Final Approval: The OCC grants final approval and authorization to open only after all preopening requirements have been satisfied.

Business Plans: A Critical Component

Business plan is the centerpiece of any charter application. According to the OCC’s Comptroller’s Licensing Manual, the plan must adequately address regulatory and policy considerations and must:

  • Demonstrate the organizing group’s collective ability to establish and operate a successful bank in the economic and competitive conditions of the market to be served.
  • Articulate the risks of the proposed operation and the policies, processes, personnel, and control systems that the bank will use to monitor and control those risks.
  • Include detailed financial projections, analysis of risk, and planned risk management systems and controls.

Capital and Liquidity Requirements

Capital and liquidity requirements for NTBs are tailored to each institution and are set as conditions of the charter approval. While NTBs are subject to the minimum leverage and risk-based capital ratios in 12 CFR Part 3, the OCC recognizes that these ratios are generally not optimal measures of capital adequacy for trust banks because off-balance-sheet asset management activities are not captured in the capital ratio calculations. Accordingly, the OCC ordinarily requires a higher level of capital than the standard ratios.

NTBs are also required by 12 USC 92a(i) to have initial capital and surplus not less than the capital and surplus required of state banks offering similar services in the state where the trust bank is located.

In practice, recent conditional approvals illustrate the range. For example, initial paid-in capital requirements have ranged from $7 million (Paycom National Trust Bank, 2024) to $10 million (UKG National Trust Bank, 2026), with ongoing tier 1 capital minimums of $5 million to $7 million. The OCC typically also requires that a significant portion of tier 1 capital be held in “Eligible Liquid Assets,” along with a separate requirement to maintain liquid assets sufficient to cover at least 180 days of operating expenses.

The OCC expects that capital and liquidity will increase beyond these initial minimums as the size, complexity, and risks of the NTB’s activities evolve over time.

Management and Governance

The OCC evaluates the qualifications of all proposed organizers, directors, and executive officers. Background investigations, including submission of fingerprints, are required. The OCC expects that the organizing group brings relevant experience in banking, fiduciary services, risk management, and compliance.

During the first two to three years of operation, NTBs are generally required to obtain the OCC’s prior written determination of no objection before appointing any new senior executive officers or board members. Similarly, any significant deviation from the approved business plan during this period requires advance notice and OCC no-objection.

Information Technology and Security

Before the OCC will grant final charter approval, the NTB must submit for review a complete description of its information systems architecture, its IT risk assessment and management plan, and its information security program. The security program must comply with the Interagency Guidelines Establishing Standards for Safeguarding Customer Information under 12 CFR 30, Appendix B. An independent review of the bank’s security measures, including firewall implementation and testing, is also required.

BSA/AML and Compliance Obligations

Like all national banks, NTBs must maintain a robust BSA/AML program that meets the requirements of 12 CFR 21.21. The OCC also expects trust banks to establish comprehensive compliance policies, insider policies, and internal and external audit frameworks prior to opening.

Key Timing Considerations

Organizers should be mindful of two important deadlines typically imposed as conditions of preliminary approval:

  • Capital must be raised within 12 months of preliminary conditional approval.
  • The bank must open for business within 18 months of that date.

If either deadline is missed, the approval expires. The OCC has indicated it is generally opposed to granting extensions except under the most extenuating circumstances.

Checklist: Key Steps and Documents

The following checklist summarizes the major steps and documents prospective applicants should have in hand or underway before and during the chartering process:

Pre-Application

  • Schedule a prefiling meeting with the OCC’s licensing staff to discuss the proposal and identify potential issues
  • Review the OCC’s Comptroller’s Licensing Manual – Charters booklet and the Charter Application form
  • Identify and vet proposed organizers, directors, and executive officers; begin background investigation paperwork and fingerprint submissions

Application Package

  • Completed Charter Application (covering both charter and fiduciary powers information)
  • Detailed business plan with financial projections, risk analysis, and description of risk management systems and controls
  • Capital and liquidity plan, including proposed initial paid-in capital, ongoing tier 1 capital minimums, eligible liquid asset targets, and 180-day operating expense liquidity reserve
  • Biographical and financial information for all proposed organizers, directors, and officers
  • Proposed Articles of Association and Organization Certificate

Organization Phase (Post-Preliminary Approval)

  • Raise initial paid-in capital within 12 months of preliminary conditional approval
  • Submit IT systems architecture, risk assessment, and management plan for OCC review
  • Implement an information security program compliant with 12 CFR 30, Appendix B, and complete an independent security review
  • Establish BSA/AML program (12 CFR 21.21), compliance policies, insider policies, and internal/external audit frameworks
  • Complete preopening examination and satisfy all remaining OCC conditions
  • Open for business within 18 months of preliminary conditional approval

DM Tips: For organizations considering a national trust charter, the following steps can help position an application for success:

  • Engage early with the OCC’s licensing staff to discuss your proposal and surface potential issues before filing.
  • Develop a detailed, risk-focused business plan that includes financial projections, a capital and liquidity analysis, and a description of the risk management systems and controls your institution will employ.
  • Ensure adequate capitalization tailored to the scope and complexity of your proposed operations, and plan for capital and liquidity to grow as your activities scale.
  • Assemble a qualified management team with demonstrated experience in banking, fiduciary services, and compliance, and begin background investigations early.
  • Build out IT infrastructure and security programs well in advance, as the OCC will require a complete systems review and independent security assessment before granting final approval.
  • Establish BSA/AML and compliance frameworks from the outset to satisfy preopening examination requirements.
  • A well-prepared application remains the foundation for a successful charter process.

Reach out to us if you’re considering a National Trust Bank charter to dig deeper on the process, expectations, and timing.

FinCEN Sounds the Alarm on Digital Asset Investment Scam Centers: What Financial Institutions Need to Know

On September 3, 2026, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) issued Alert FIN-2026-Alert 005, urging financial institutions to be vigilant in detecting, identifying, and reporting suspicious activity connected to digital asset investment scam centers and the laundering of their illicit proceeds. The Alert builds on FinCEN’s September 2023 guidance on digital asset investment scams and reflects the growing scale and sophistication of this threat.

A Rapidly Growing Threat

The numbers are staggering. According to the FBI’s Internet Crime Complaint Center, reported U.S. victim losses from digital asset investment scams have surged from $907 million in 2021 to $7.2 billion in 2025. Total annual revenue collected by Southeast Asian scam centers is estimated in the tens of billions of dollars. These operations are predominantly run by transnational criminal organizations (TCOs) based in Southeast Asia—primarily in Cambodia, Burma, and Laos—with operations now expanding into South Asia, the Pacific Islands, Africa, the Middle East, and South America.

The Alert arrives on the heels of Executive Order 14390, issued by President Trump on March 6, 2026, declaring it the policy of the United States to protect Americans from cybercrime, fraud, and predatory schemes.

How the Scams Work

Scam center operators use a range of fraud schemes—including investment, romance, and government impersonation scams—to induce victims to make payments, often in digital assets. Scammers commonly initiate contact through social media or text messages and exploit enthusiasm around new technologies, including digital assets and artificial intelligence, to lure victims with the promise of outsized returns. TCOs have also adopted AI tools to scale and refine their schemes.

A human trafficking dimension makes these operations especially disturbing: criminal gangs have trafficked hundreds of thousands of people to scam centers, where victims have their passports confiscated and are coerced into perpetrating online fraud.

The Laundering Ecosystem: Guarantee Marketplaces

The Alert devotes significant attention to “guarantee marketplaces”—online marketplaces operating as networks of Chinese-language chat groups on social connection platforms like Telegram. These marketplaces function as marketing venues, payment infrastructure, and trusted intermediaries between buyers and sellers of illicit services, including money laundering, social media account creation, and mass phishing services.

FinCEN highlighted its October 2025 final rule severing Cambodia-based Huione Group from the U.S. financial system, noting that Huione Group laundered at least $4 billion in illicit proceeds between August 2021 and January 2025. In June 2026, FinCEN proposed expanding that rule to cover Huione Group’s successor entities attempting to circumvent the original measure.

Key Red Flags for Financial Institutions

FinCEN identified 16 specific red flags to help financial institutions detect suspicious activity relevant for this Alert, including but not limited to:

  • Victim payment indicators, such as customers stating they were directed by purported law enforcement to make payments in digital assets, precious metals, or gift cards.
  • Guarantee marketplace indicators, such as transactions involving tokens issued by or associated with a guarantee marketplace, or blockchain analysis revealing links to known marketplace infrastructure.
  • Laundering technique indicators, such as stablecoin transactions originating from U.S.-based exchanges that undergo on-chain laundering patterns, or customers transacting through stablecoins whose issuers advertise they do not cooperate with law enforcement.

SAR Filing Guidance

Financial institutions are requested to reference the Alert in SAR filings by including the key term “FIN-2026-SCAMCENTERS” in SAR field 2 and the narrative, and by selecting “Fraud-Other” under SAR field 34(z) with the description “Scam Centers”. FinCEN also encourages institutions to include relevant technical cyber indicators—such as chat logs, phone numbers, digital asset addresses, and suspicious URLs—in SAR submissions.

The Bottom Line

In light of this Alert, financial institutions should consider the following actionable steps:

  • Update transaction monitoring rules to incorporate the specific red flags identified in the Alert, including indicators related to victim payments, guarantee marketplace activity, and on-chain laundering techniques.
  • Train frontline and compliance staff to recognize the hallmarks of digital asset investment scams, including customers who report being directed by purported government officials to make payments in digital assets or precious metals.
  • Review SAR filing procedures to ensure staff include the key term “FIN-2026-SCAMCENTERS” in SAR field 2 and the narrative, and select “Fraud-Other” under SAR field 34(z) with the description “Scam Centers.”
  • Leverage Section 314(b) information sharing with other financial institutions to identify repeat actors moving across institutions to evade detection.
  • Enhance due diligence on MSBs and digital asset service providers, particularly those operating in or connected to Southeast Asia, and monitor for entities that appear to obscure their location or corporate structure.
  • Refer potential victims to the FBI’s IC3 at ic3.gov or the nearest U.S. Secret Service field office.

* Note: All references to specific reports, rules, alerts, and figures used in this blog posting can be found linked in the FinCEN Alert if not linked directly herein.

Indemnification by a Bank to Its Parent: When Does It Become a Covered Transaction under Reg W?

Service contracts between banks and their parent holding companies frequently include indemnification clauses. A common arrangement is for the bank to indemnify its parent for losses caused by the bank’s own negligence or willful misconduct. Does this create a covered transaction?

The answer is no. When a bank indemnifies its parent holding company in a service contract for holding company losses caused by the negligence or willful misconduct of the bank, this does not constitute a covered transaction under Regulation W.

The rationale is that such indemnification clauses are standard commercial terms that reflect the bank’s responsibility for its own actions. The bank is not assuming the affiliate’s risk or extending credit to the affiliate; rather, it is agreeing to make the affiliate whole for damages the bank itself caused. This is more akin to tort liability than to the types of financial transactions Regulation W is designed to restrict.

Under Section 23A, covered transactions include extensions of credit, asset purchases, guarantees, and similar transactions where the bank’s resources are exposed to affiliate risk. An indemnification for the bank’s own misconduct does not fit this framework because the risk originates with the bank, not the affiliate.

DM Tip: When drafting service agreements with affiliates, clearly limit indemnification to losses caused by the bank’s own negligence or willful misconduct. Broader indemnification clauses that cover affiliate losses regardless of fault could be viewed differently and may trigger Regulation W analysis.

Affiliate Purchases Bank Stock: Covered Transaction under Regulation W?

Not every transaction between a bank and its affiliate is a covered transaction under Regulation W. A notable exception is that an affiliate’s purchase of stock issued by the bank is not a covered transaction.

This makes sense from a policy perspective. The purpose of Section 23A and Regulation W is to protect the bank from losses arising from affiliate transactions. When an affiliate purchases the bank’s stock, the bank is receiving capital, not extending resources to the affiliate. The transaction strengthens the bank rather than exposing it to credit or counterparty risk from the affiliate.

This means that a holding company can invest additional equity capital in its subsidiary bank without triggering Regulation W’s quantitative limits, collateral requirements, or other restrictions. Similarly, other affiliates may purchase the bank’s stock or subordinated debt that constitutes equity capital without those purchases counting as covered transactions.

However, banks should note that while the affiliate’s purchase of bank stock is not a covered transaction, the reverse may be. If a bank purchases securities issued by an affiliate, that is a covered transaction subject to all Regulation W requirements.

DM Tip: When structuring capital injections from affiliates, confirm that the transaction involves the affiliate purchasing the bank’s stock (not a covered transaction) rather than the bank investing in affiliate securities (which would be a covered transaction). Document the direction of the capital flow clearly.

Business Trusts and Regulation W: Yes, They Are Companies

While a sole proprietorship is not a company under Regulation W, the analysis is different for trusts established for a business purpose. An ESOP, pension plan, or other business trust qualifies as a “company” for purposes of Regulation W.

This means that if a business trust meets the definition of an affiliate under 12 CFR 223.2, perhaps because it is controlled by the bank’s holding company or because it meets another affiliation criterion, transactions between the member bank and that trust are covered transactions subject to all Regulation W requirements.

This distinction matters particularly in the holding company context, where parent companies frequently establish ESOPs, pension trusts, or special-purpose trusts that hold bank stock or other assets. If such a trust is controlled by an entity that also controls the member bank, the trust is an affiliate, and any extension of credit from the bank to the trust, or any asset purchase, triggers Regulation W compliance obligations.

The key takeaway is that legal form matters under Regulation W. The trust structure, which creates a separate legal entity with its own assets and obligations, is sufficient to qualify as a company, unlike a sole proprietorship where no separate entity exists.

DM Tip: Inventory all trusts in your holding company structure, including ESOPs, pension trusts, and special-purpose vehicles. Do any of them qualify as an affiliate? If so, ensure all transactions with affiliated trusts are captured in your Regulation W monitoring system.

Anti-Tying Restrictions: Navigating the Combined-Balance Discount Exception

The anti-tying provisions of 12 U.S.C. § 1972 are among the most significant restrictions governing how banks market and price their products. Generally, a bank may not condition the availability or pricing of one product on a customer’s purchase of another product. However, the combined-balance discount exception provides meaningful flexibility for banks seeking to reward full-relationship customers.

Safe Harbor for Combined Balances

Under 12 CFR 225.7(b)(2), a bank may condition product availability or pricing on a customer obtaining a “loan, discount, deposit, or trust service.” The Federal Reserve has identified 20 categories of qualifying services, including but not limited to:

  • All types of extensions of credit, letters of credit, and financial guarantees
  • All forms of deposit accounts, safe deposit box services, and escrow services
  • Cash management, payroll, and payment/settlement services
  • Fiduciary, custody, and transfer agent services
  • Credit card and merchant processing services
  • Remote/mobile deposit capture and deposit sweep services

Expanded Definition of “Customer”

For combined-balance discount purposes, “customer” may include not only the natural person but also any members of that person’s “immediate family” (as defined in 12 CFR 225.41(b)(3)) who reside at the same address. This allows household-level product bundling. Additionally, financial products including insurance products may count toward the combined balance.

This exception offers banks significant latitude to design relationship-based pricing programs, but careful documentation is essential to demonstrate compliance.

DM Tip: Review your product bundling and discount programs to ensure they fall within the safe harbor. Document which products count toward combined balances and maintain records showing that household-level aggregation is limited to immediate family members residing at the same address.

What Is a Financial Holding Company?

In the world of banking regulation, corporate structure matters. One of the most significant structural designations a banking organization can achieve is that of a financial holding company (FHC). This post explains what an FHC is, how it differs from a standard bank holding company (BHC), and how a BHC elects to become one.

Bank Holding Companies

A bank holding company is any company that controls a bank, as defined under the Bank Holding Company Act of 1956 (BHCA). BHCs are subject to supervision and regulation by the Federal Reserve Board and are generally limited to engaging in activities that are closely related to banking—such as lending, trust services, and certain insurance agency activities.

Financial Holding Companies: Expanded Powers

The Gramm-Leach-Bliley Act of 1999 (GLBA) amended the BHCA to create a new category: the financial holding company (“FHC”). An FHC is a bank holding company that has made a specific election and met certain qualifying criteria, thereby gaining the ability to engage in a broader range of financial activities.

These expanded activities include:

  • Securities underwriting and dealing – Activities previously reserved for registered broker-dealers and investment banks.
  • Insurance underwriting – The ability to underwrite and sell insurance products, not merely act as an agent.
  • Merchant banking – Making equity investments in commercial companies, subject to certain holding-period and portfolio limitations.
  • Other financial activities – Any activity that the Federal Reserve Board determines, by regulation or order, to be financial in nature, incidental to a financial activity, or complementary to a financial activity.

The FHC framework effectively broke down the walls between banking, securities, and insurance that had existed since the Glass-Steagall era.

How a Bank Holding Company Elects FHC Status

The process for a BHC to become an FHC is an election, not an application requiring prior approval. Here is how it works:

1. File a Declaration

The BHC files a written declaration with the appropriate Federal Reserve Bank. The declaration must include:

  • A statement that the BHC elects to be treated as a financial holding company.
  • A certification that all depository institutions controlled by the BHC are well-capitalized and well-managed – terms of art in bank reg land.
  • A certification that all such depository institutions have at least a “Satisfactory” rating under the Community Reinvestment Act (CRA).

2. Satisfy the Statutory Criteria

To qualify, the BHC must demonstrate that each of its subsidiary depository institutions meets three requirements at the time of the election:

  • Well-capitalized – The institution meets the capital adequacy standards established by its primary federal banking regulator.
  • Well-managed – The institution has received a composite rating of 1 or 2, and a management rating of 1 or 2, in its most recent examination.
  • Satisfactory CRA rating – The institution has received at least a “Satisfactory” rating on its most recent CRA performance evaluation.

3. Effectiveness of the Election

The election becomes effective on the 31st calendar day after the declaration is received by the Federal Reserve, unless the Federal Reserve notifies the BHC prior to that date that the election is ineffective because the BHC does not meet the required criteria.

4. Ongoing Compliance

FHC status is not permanent in a practical sense. If any subsidiary depository institution ceases to be well-capitalized or well-managed, or if a CRA rating falls below “Satisfactory,” the FHC may face restrictions. The Federal Reserve may limit the FHC’s ability to commence new financial activities or make acquisitions until the deficiency is corrected. If the deficiency is not corrected within 180 days, the Federal Reserve may require the company to divest its subsidiary banks or cease engaging in FHC-only activities.

Why It Matters

The FHC election is a gateway to diversified financial services. For banking organizations seeking to compete across the full spectrum of financial products—from traditional deposit-taking and lending to securities, insurance, and merchant banking—FHC status is essential. Understanding the election process and the ongoing obligations that come with it is critical for any institution considering this path.

Contact us to dive deeper.

© 2009- Duane Morris LLP. Duane Morris is a registered service mark of Duane Morris LLP.

The opinions expressed on this blog are those of the author and are not to be construed as legal advice.

Proudly powered by WordPress