Defining ‘Securities’ Under Regulation W: Looking to Federal Securities Laws

Regulation W applies to several transactions involving “securities,” including purchases of or investments in securities issued by an affiliate and acceptance of affiliate securities as collateral. But how does the Federal Reserve define “securities”?

The Federal Reserve generally looks to the federal securities laws for guidance, as confirmed in the 2002 preamble to its Final Rule implementing Regulation W. This means the definition of “security” under Section 2(a)(1) of the Securities Act of 1933 and Section 3(a)(10) of the Securities Exchange Act of 1934 provides the framework.

Under federal securities law, the term “security” is interpreted broadly to include stocks, bonds, debentures, notes, investment contracts, and a wide range of other instruments. The Supreme Court’s Howey test for investment contracts and the Reves “family resemblance” test for notes provide additional guidance for instruments that are not clearly labeled.

This broad interpretation means that banks should not assume an instrument falls outside Regulation W simply because it is not a traditional stock or bond. Partnership interests, LLC membership interests, certain loan participations, and structured products may all qualify as securities depending on their characteristics.

DM Tip: When evaluating whether an instrument issued by an affiliate constitutes a “security” for Regulation W purposes, apply the federal securities law definitions broadly. When in doubt, treat the instrument as a security and comply with Regulation W requirements. Document your analysis, especially for novel or hybrid instruments

Asset Exchanges With Affiliates: When Cash Makes the Difference

If a bank and an affiliate engage in an asset exchange, where the bank gives one asset and receives another, is this a purchase of assets by the bank from the affiliate? The answer is yes, unless the asset being received by the bank is cash.

This distinction is important for structuring intercompany transactions. If the bank exchanges a portfolio of loans for a different portfolio of loans held by an affiliate, that constitutes a purchase of assets from an affiliate, a covered transaction subject to quantitative limits, collateral requirements, and the low-quality asset prohibition.

However, if the bank exchanges an asset for cash from the affiliate, that is simply a sale by the bank to the affiliate, which is not a covered transaction from the bank’s perspective (though it may be subject to Section 23B’s market-terms requirement).

The practical distinction matters in corporate reorganizations and portfolio rebalancing within holding company structures. Banks should be aware that any non-cash asset received from an affiliate in an exchange triggers Regulation W’s full suite of protections.

DM Tip: When contemplating asset swaps with affiliates, consider whether the transaction can be restructured as two separate cash transactions (bank sells for cash, then buys separately) rather than a direct asset exchange. If a direct exchange is necessary, ensure the assets received are measured and counted against your Regulation W limits.

Repurchasing Sold Assets That Have Deteriorated: The Prior-Sale Safe Harbor under Reg W

Here is a practical scenario: a bank previously sold an asset to an affiliate with recourse (meaning the affiliate can require the bank to repurchase if the asset goes bad). The asset has since become a low-quality asset. May the bank repurchase it?

Yes, provided the asset was not a low-quality asset at the time the bank originally sold it. This is an important safe harbor. The policy rationale is that the bank’s recourse obligation was established when the asset was healthy, and the bank should be able to honor its pre-existing contractual commitment even though the asset has since deteriorated.

However, if the asset was already a low-quality asset when the bank first sold it to the affiliate, the bank may not repurchase it. The low-quality asset prohibition in 12 CFR 223.15 prevents a bank from purchasing low-quality assets from affiliates, and this prohibition would apply to the repurchase.

This distinction highlights the importance of timing and documentation. Banks that sell assets to affiliates with recourse should document the asset’s quality status at the time of sale, including any examination classifications, to support a future repurchase if necessary.

DM Tip: If selling assets to affiliates with recourse, document the asset’s classification status at the time of sale. Maintain this documentation throughout the recourse period so that, if repurchase becomes necessary, you have clear evidence that the asset was not a low-quality asset when originally sold.

Classified Assets and Restructuring: Once a Low-Quality Asset, now a Harder Path Out

Under Regulation W, a bank generally may not purchase a “low-quality asset” from an affiliate. But what exactly qualifies as a low-quality asset, and can an asset escape that status through restructuring?

A low-quality asset includes, among other things, assets classified by examiners as “‘”substandard,” “doubtful,” or “loss.” The question arises: if a classified asset is restructured, does it lose its low-quality status? The answer is no. The asset remains a low-quality asset until it is re-examined and de-classified by bank examiners.

This is a strict rule. The bank cannot unilaterally determine that restructuring has cured an asset’s low-quality status. Only an independent examination and explicit de-classification by examiners can remove the low-quality label. This prevents banks from engaging in cosmetic restructurings to circumvent the low-quality asset purchase prohibition.

The practical impact is significant for banks contemplating asset purchases from affiliates. Even if an affiliate has restructured a loan and the borrower is now current, the bank cannot purchase that asset from the affiliate unless examiners have affirmatively removed the classified designation.

DM Tip: Before purchasing any asset from an affiliate, obtain the most recent examination classification status. Do not rely on restructuring, cure, or current payment status alone. If the asset was previously classified, confirm in writing with your examiners that it has been formally de-classified before completing the purchase.

Pledging Collateral for Affiliate Borrowings: A “Guarantee” in Disguise under Reg W?

Sometimes a guarantee does not look like a traditional guarantee. Consider the following: a bank pledges its own collateral to secure a borrowing made by an affiliate from a third-party lender. Is this a guarantee by the bank on behalf of the affiliate?

Yes. The Federal Reserve treats a bank’s pledge of collateral to secure an affiliate’s borrowing as a guarantee on behalf of the affiliate for purposes of Regulation W. The covered transaction amount is the lesser of: (i) the market value of the pledged collateral; or (ii) the amount of the borrowing.

This interpretation, confirmed in a 1993 General Counsel opinion, makes economic sense. When the bank pledges its assets to secure an affiliate’s debt, the bank is effectively promising the lender that its assets will be available to satisfy the affiliate’s obligation if the affiliate defaults. That is the functional equivalent of a guarantee.

The measurement as the lesser of collateral value or borrowing amount reflects the actual exposure. If the bank has pledged collateral worth less than the full borrowing, its maximum exposure is the collateral value. If the collateral exceeds the borrowing, the exposure is limited to the borrowing amount because that is all the lender can claim.

DM Tip: Audit all instances where bank assets are pledged to secure obligations of any affiliate. Each such arrangement should be booked as a guarantee for Regulation W purposes, measured at the lesser of collateral market value or the secured obligation amount, and included in quantitative limit calculations.

Sole Proprietorships – Not a ‘”Company” Under Regulation W

Regulation W applies to transactions between a bank and its affiliates, but the definition of “affiliate” requires that the counterparty be a “company.” This raises a fundamental question: what qualifies as a company for Regulation W purposes?

The answer excludes sole proprietorships – a sole proprietorship is not a company for purposes of Regulation W. This means that even if an individual who operates a sole proprietorship also controls a bank, the sole proprietorship itself cannot be an affiliate of the bank under Regulation W.

This distinction is rooted in the definition of “company” under banking law, which generally encompasses corporations, partnerships, limited liability companies, business trusts, and similar organizations, but not unincorporated businesses operated by a single individual in their personal capacity.

However, banks should not treat this as a blanket safe harbor. Transactions with sole proprietors who are insiders may still be subject to other regulatory requirements, including Regulation O governing insider lending, and general safety and soundness standards. Additionally, the attribution rule could apply if loan proceeds to a sole proprietor are transferred to an affiliated entity.

DM Tip: While sole proprietorships fall outside Regulation W’s affiliate framework, ensure your compliance program still captures transactions with sole proprietors who are insiders or who may transfer proceeds to affiliated entities. Cross-reference your Regulation O and Regulation W monitoring systems.

Mergers and Capital Measurement under Reg W: Aggregating Capital Until the Next Call Report

When two depository institutions merge, a practical question arises: how does the surviving bank measure its capital stock and surplus for Regulation W purposes during the gap between the merger date and the filing of the merged bank’s first consolidated Call Report?

The Federal Reserve provides helpful flexibility. The surviving bank may use the aggregate capital stock and surplus of the two merging depository institutions until the merged bank files its next Call Report. This allows the merged institution to capture the benefit of the combined capital base immediately, rather than being constrained to just one institution’s last-filed Call Report.

This is important because mergers can involve significant intercompany activity during integration, and being stuck with only one bank’s pre-merger capital figure could artificially constrain necessary post-merger transactions with affiliates.

The key requirement is that once the merged institution files its first consolidated Call Report, that becomes the new baseline for all Regulation W calculations on a go-forward basis.

DM Tip: In merger planning, calculate the combined Regulation W capacity early. Document the aggregate capital stock and surplus of both merging institutions as of their respective last Call Reports, and use this figure for compliance monitoring during the integration period until your first post-merger Call Report is filed.

The Fiduciary Exemption: Holding Shares With Sole Voting Discretion

Under Regulation W’s control analysis, owning shares typically implies the potential for control over the issuing company. But what if a company holds shares in a fiduciary capacity? Can it qualify for the exception from the definition of “control” even if it has sole voting discretion over those shares?

The answer is yes. Unlike the analogous provision in Section 4(f)(2) of the Bank Holding Company Act, which excludes fiduciaries with sole discretionary voting power, Regulation W’s fiduciary exemption does not impose such a limitation. A company may qualify for the fiduciary exception from control even if it exercises sole voting discretion over the shares held in trust.

This is an important distinction for bank trust departments that hold significant blocks of stock in fiduciary accounts. Under the BHC Act, sole voting discretion would negate the fiduciary exception and potentially create a control relationship. Under Regulation W, however, the trust department’s holdings in fiduciary accounts do not create an affiliate relationship solely because the bank has voting discretion.

The rationale reflects the different purposes of the two statutes. The BHC Act’s control provisions focus on preventing unauthorized concentrations of banking power, while Regulation W focuses on protecting banks from affiliate transaction risks. Fiduciary holdings with voting discretion do not create the same risk of self-dealing that Regulation W targets.

DM Tip: If your bank’s trust department holds significant equity positions with sole voting discretion, document that these holdings are in a fiduciary capacity to support the Regulation W control exemption. Be aware that the same analysis may differ under the BHC Act, so consult both frameworks.

Legal Considerations in Data Center Financing: A Practical Guide

The explosive growth of cloud computing, artificial intelligence, and digital infrastructure has made data center financing one of the most active — and complex — segments of the real estate and project finance markets. Whether you represent a lender, developer, or equity sponsor, here are the key legal considerations to keep in mind.

Land Use and Zoning

Data centers present unique land use challenges. Local zoning ordinances may not contemplate data center use as a permitted category, requiring special use permits, variances, or rezoning. Counsel should evaluate whether the site’s zoning classification permits the intended use — including the associated power infrastructure, cooling systems, and backup generators — and anticipate potential opposition from neighboring landowners or municipalities concerned about noise, water consumption, and aesthetic impact. Restrictive covenants and CC&Rs on the land should also be reviewed for compatibility.

Power and Utility Arrangements

Power availability is often the single most critical factor in site selection. Financing parties should carefully review power purchase agreements, utility service contracts, and any interconnection agreements with the local grid operator. Key issues include capacity commitments, curtailment risk, rate escalation provisions, and the enforceability of long-term supply arrangements. Increasingly, renewable energy procurement (through PPAs or virtual PPAs) adds another layer of contractual complexity.

Environmental and Permitting

Data centers carry meaningful environmental exposure. Water-intensive cooling systems may trigger water use permits or environmental impact assessments. Backup diesel generators raise air quality permitting requirements. Counsel should diligence the full permitting stack — building permits, environmental permits, stormwater management plans, and any applicable state or federal environmental review — and assess the timeline risk of delayed approvals.

Real Estate Structure

Data center deals frequently involve ground leases, build-to-suit arrangements, or sale-leasebacks. Each structure presents distinct issues for lenders, including leasehold mortgageability, estoppel and SNDA requirements, and the treatment of tenant improvements and trade fixtures. For colocation facilities, master lease structures with subletting rights and non-disturbance protections for subtenants are critical to preserving collateral value.

Construction and Development Risk

Financing a data center during the construction phase introduces the typical suite of construction lending issues — guaranteed maximum price contracts, performance bonds, completion guarantees, and disbursement mechanics — with the added complexity of specialized mechanical, electrical, and plumbing (MEP) systems. Lenders should pay close attention to the contractor’s data center track record, commissioning protocols, and the treatment of delays tied to long-lead equipment (e.g., transformers, switchgear, and generators).

Tenant and Revenue Considerations

Lenders underwriting data center cash flows must evaluate the creditworthiness of tenants (often hyperscale cloud providers or enterprise users), the durability of lease terms, and the risk of early termination or contraction options. Customer concentration risk is a recurring theme, as a single anchor tenant may represent the majority of revenue. Counsel should also consider the interplay between the lease structure and any managed services or interconnection agreements that contribute to the revenue stack.

Tax Incentives and Regulatory Matters

Many jurisdictions offer tax incentives — including sales tax exemptions on equipment, property tax abatements, and enterprise zone benefits — to attract data center development. These incentive agreements should be carefully structured to survive financing events, including foreclosure. On the regulatory side, data privacy and security laws (such as state data breach notification statutes) may impose obligations on facility operators that indirectly affect the lender’s collateral package.

Insurance

Data centers require specialized insurance coverage beyond a standard commercial property policy. Key coverages include business interruption (with extended indemnity periods reflecting long equipment replacement timelines), equipment breakdown, cyber liability, and environmental liability. Lenders should require evidence of adequate coverage and ensure that policy terms align with the credit agreement’s insurance requirements.

DM Tips:

Data center financing sits at the intersection of real estate, project finance, technology, and energy law. A successful transaction requires early coordination among specialists in each of these areas, careful diligence on the site and its permitting and utility arrangements, and deal structures that account for the asset class’s distinctive risk profile. Duane Morris is fluent in these issues consistently advises clients on this increasingly important part of the infrastructure landscape.

Overhauled Third-Party Risk Management Guidance: What Banks and Their Vendors Need to Do Now

On September 11, 2026, the FDIC, Federal Reserve Board, OCC, and NCUA jointly proposed a package of three documents that would reshape third-party risk management (“TPRM”) oversight for banks and credit unions: (1) new interagency guidance replacing the 2023 TPRM framework, (2) a practical companion guide for community banks, and (3) a joint statement putting core service providers on notice. Comments are due November 16, 2026 — here is what your institution needs to know. 

What Went Wrong With the 2023 Guidance

The agencies acknowledge the 2023 framework failed on four fronts: it was interpreted too broadly, drove checklist compliance instead of risk-proportionate oversight, incentivized process over substance, and chilled engagement with fintechs and innovative providers. The bottom line for institutions: disproportionate compliance spending on low-risk relationships and lock-in with legacy vendors. 

How the New All-Bank Framework Changes Day-to-Day TPRM

The proposed guidance would replace the 2023 Guidance and 2024 community bank resources.

Three shifts matter most for compliance teams:

Risk-Based Prioritization. TPRM practices should be calibrated to the magnitude and likelihood of harm of each relationship — not merely whether it supports a “critical activity.” Lower-risk relationships may warrant less detailed due diligence, standard-form contracts, or less frequent monitoring.

Principles, Not Prescriptions. The guidance is expressly non-binding; non-compliance alone will not trigger supervisory criticism. The framework is organized into four components:

  1. Risk Identification and Assessment — identifying third-party relationships, cataloguing associated risks, and assessing their severity.
  2. Risk Oversight — covering due diligence, contract negotiation, ongoing monitoring, termination planning, and cross-cutting topics such as subcontractor oversight, operational resilience, and insurance/indemnification.
  3. Residual Risk Acceptance — recognizing that institutions may reasonably accept some amount of residual risk based on their risk appetite.
  4. Governance — establishing appropriate board and management oversight structures.

Encouraging Innovation. The guidance recognizes co-ventures, consortia for joint due diligence, standard-setting organizations, and third-party consultants as legitimate TPRM strategies — a clear signal that engaging with fintechs and newer providers should not be treated as inherently higher risk.

New Playbook for Community Banks Under $30 Billion

The Federal Reserve separately proposed a Third-Party Risk Management Guide for Traditional Community Banking Organizations (“TCBOs”) — institutions under $30 billion focused on serving local communities. Banks with complex bank-fintech partnership models are excluded. The guide gives TCBOs an operational roadmap organized in two parts:

Overarching Risk Management Topics. Four cross-cutting themes applicable to most TCBO third-party relationships:

  • Operational Resilience — assessing how a vendor’s disruptions could impair the institution’s operations, including through review of SOC reports, penetration testing, and business continuity testing.
  • System and Information Security — managing vulnerabilities created when vendors access sensitive banking systems.
  • Compliance with Rules and Regulations — ensuring third parties performing regulated functions maintain compliance, including with payment network rules.
  • Financial Resilience — evaluating a vendor’s financial stability, particularly when it is privately held or a newer market entrant.

Vendor-by-Vendor Considerations. The guide identifies eight categories of third parties most commonly used by TCBOs and provides risk-specific guidance for each:

  • Core Providers
  • IT Infrastructure Providers
  • Cybersecurity Providers
  • Payment Processing and Digital Banking Providers
  • Loan Management System Providers
  • Card Issuing and Processing Providers
  • BSA/AML and Financial Crime Platform Providers
  • Fraud Prevention and Detection Providers

For core providers, the guide addresses core conversion considerations — costs, integration challenges, and middleware alternatives — in significant detail.

The Board is seeking comment on the $30 billion asset threshold, whether to add “deposit placement networks” as a vendor category, and whether the guide’s detail level risks creating de facto supervisory standards. 

Core Service Providers Face Direct Supervisory Scrutiny

The Joint Statement on Community Banks’ Engagement with Core Service Providers (Federal Reserve, FDIC, and OCC) marks a significant escalation. The agencies will now factor three criteria into examination frequency and scope decisions for core providers:

  • Transparency — whether a core provider furnishes timely due diligence information, complies with service level agreements, promptly discloses security incidents, and avoids complex billing practices that are difficult for banks to reconcile.
  • Contract Features — whether contract terms make it unreasonably difficult for community banks to exit relationships or engage supplemental providers. Examples of problematic terms include opaque pricing, excessive “back billing” windows, unsupported deconversion fees, and limitations on third-party integrations with the core platform.
  • Technology — whether the core provider invests in maintaining up-to-date systems, including the frequency and severity of security incidents, management of end-of-life assets, and demonstrated operational resilience.

Notably, the agencies state that certain core providers may qualify as “institution-affiliated parties” under the Federal Deposit Insurance Act, given the degree to which they participate in the conduct of a bank’s affairs. This determination could expose core providers to enforcement actions — a significant escalation in regulatory posture. 

Comments on all three proposals are due November 16, 2026.

DM Tips

For banking organizations: Begin assessing how the shift from checklist-based compliance to risk-based prioritization would affect your existing TPRM program. Community banks in particular should view the TCBO Guide and core provider statement as new leverage in vendor negotiations.

For core service providers: The agencies are now tying examination frequency and scope to provider-level transparency, contract fairness, and technology investment. The institution-affiliated party discussion adds enforcement teeth to what was previously a supervisory expectations framework.

© 2009- Duane Morris LLP. Duane Morris is a registered service mark of Duane Morris LLP.

The opinions expressed on this blog are those of the author and are not to be construed as legal advice.

Proudly powered by WordPress