What the OCC’s consent order to Anchorage means for the crypto industry

Quick Take
- The Office of the Comptroller of the Currency levied a consent order against crypto bank Anchorage at the close of last month, criticizing the firm’s anti-money laundering practices.
- What should other crypto firms take away from the development?
We'd love your feedback.
The US’s national bank regulator served crypto bank Anchorage Digital with a consent order and demanded that it clean up its program for complying with anti-money laundering (AML) requirements stipulated by a US law called the Bank Secrecy Act (BSA).
In recent months, the Office of the Comptroller of the Currency (OCC) under acting head Michael Hsu, has taken a harder stance toward crypto than it did under Hsu's predecessor. At a time of generally heightened tension between regulators and the crypto industry, some have speculated that this formal order from the OCC against a prominent crypto custodian for institutions may signify the beginning of a coming wave of crypto enforcement.
But a closer look at the Anchorage case reveals why that shouldn’t necessarily be the conclusion.
What went wrong?
From the outside looking in, consent orders should not be seen as clear-cut accusations and resolutions.
According to Jeffrey Alberts, a partner at Pryor Cashman and part of its FinTech group, regulators are generally trying to protect the confidentiality of their dealings with firms during the enforcement process. For that reason, many orders, including this one, don’t actually tell us about the exact nature of the violation.
It contains only a brief description of the violations: “As of 2021, the Bank failed to adopt and implement a compliance program that adequately covers the required BSA/AML program elements, including, in particular, internal controls for customer due diligence and procedures for monitoring suspicious activity, BSA officer and staff, and training.”
“Internal controls for customer due diligence” is broad language that could encompass a variety of processes. It doesn’t clarify exactly where things went wrong, and is followed by a somewhat boilerplate list of requirements related to BSA/AML program elements. But it can give a slightly narrowed window on the types of controls the OCC was looking at.
The language could be referencing something as fundamental as the basics around Anchorage’s know-your-customer (KYC) onboarding and AML compliance programs. But it could also be something more nuanced, such as a discrepancy between how the firm and the OCC assess the risk level of certain accounts, which in the context of crypto can be a more complicated topic than in traditional banking.
Ultimately, Anchorage did not receive a fine with its consent order, which indicates that the infraction was likely minor or easily hashed out between the firm and the regulator.
Anchorage did not respond to requests for comment, though at the time the order came down, the firm said the order reflected “areas for improvement” identified by the OCC.
Wider implications
What is the takeaway for other crypto custodians from all this?
It's true that Hsu has taken a harder stance on crypto than his predecessor, Brian Brooks. It was Brooks who granted conditional charters to Anchorage and other crypto firms.
Hsu has emphasized the risks of the crypto industry and has called for crypto firms that offer banking-like services to be supervised as closely and as comprehensively as banks.
“The OCC holds all nationally chartered banks to the same high standards, whether they engage in traditional or novel activities,” Hsu said when the consent order against Anchorage was published. “When institutions fall short, we will take action and hold them accountable to ensure compliance with federal laws and regulations.”
Still, the Anchorage consent order by itself doesn’t imply that OCC is commencing a wave of enforcement.
“Fintech companies tend to get into trouble,” said Alberts. “More frequently than traditional banks, in part because they're just doing novel things. And when you do novel things, it's easy to accidentally screw up.”
Crypto and fintech firms usually move faster and operate leaner than other traditional entities, and things can fall through the cracks. Part of being an OCC-regulated firm includes the regulator taking a closer look at your processes on at least an annual basis, if not more frequently. And those examinations are pretty comprehensive, with OCC examiners physically present at the firm’s place of operations, asking for documents and follow-up questions. The OCC tests the foundations and points out where firms have to fill the cracks.
Ben Gray, global general counsel at Paxos, a firm seeking a de novo charter from the OCC, said it’s not always helpful to read into the meaning of various actions coming out of regulators.
Often it just means that the process is working — at least if the goal is for crypto custodians to be regulated like banks.
“People tend to use specific orders or actions as markers to better understand 'what are regulators thinking?'" said Gray. “But regulators have been upfront that they are paying attention to this area. And we expect crypto companies are eventually going to be subject to the same kind of oversight that every other financial institution is accustomed to."
© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

