Photo of Cristina Diaz

Cristina Diaz is a senior counsel in the firm’s Financial Services Group and is based in the New York office. With more than 20 years of banking law experience, Cristina brings a unique combination of in-house insight and private practice depth. She advises foreign and domestic banks, fintechs, and digital assets businesses on bank regulation, compliance, and enforcement.

Cristina’s practice spans bank chartering and licensing, permissible activities, capital requirements, regulatory enforcement, M&A, and corporate governance. She advises clients navigating the intersection of traditional banking and emerging financial services, including digital assets companies seeking to acquire or establish national banks, and banks exploring partnerships with fintechs and digital assets firms. She regularly helps clients navigate complex relationships and remediation initiatives with state and federal financial regulators, including the Federal Reserve, OCC, FDIC, and the Utah Department of Financial Institutions.

Key Takeaway

On September 2, 2026, the Federal Reserve, FDIC, NCUA, OCC, and FinCEN confirmed that a bank may tell a customer that an account restriction or closure, or a rejected deposit, may be related to suspected fraud or other suspicious activity, so long as the communication does not reveal that a SAR was or will be filed.

What Happened

On September 2, 2026, the Federal Reserve, the FDIC, the NCUA, the OCC, and FinCEN issued a joint statement on the application of SAR confidentiality to banks’ communications with their customers (Joint Statement). The Bank Secrecy Act prohibits a bank from disclosing a suspicious activity report or any information that would reveal that one exists, and in particular from notifying any person involved in a transaction that the transaction has been reported. In practice, those prohibitions have led many banks to say nothing at all when a payment is held, a deposit is rejected, or an account is closed and the customer asks why. The Joint Statement confirms that the SAR confidentiality prohibitions are narrower than that practice: the regulators confirmed that a bank may communicate with a customer about potentially fraudulent transactions, other suspicious activity, or account closures, provided the communication does not reveal the existence of a SAR. The Joint Statement responds to comments on the agencies’ payments fraud initiative and invokes Executive Order 14331 on fair banking.

Continue Reading You Can Say More Than You Think: Regulators Clarify SAR Confidentiality for Customer Communications

On August 27, 2026, the Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC) jointly issued a final rule that, for the first time, gives the term “unsafe or unsound practice” a binding regulatory definition.1 With it came a uniform standard for Matters Requiring Attention (MRAs) and revised OCC examination manuals.2 The Federal Reserve did not join the rulemaking, but has adopted comparable standards through guidance. What that means for holding companies and state-chartered institutions is addressed below.3 The regulation takes effect November 2, 2026, and the revised OCC examination manuals took effect upon their issuance on August 27.

For boards, general counsel, and risk and compliance leaders, the headlines suggest clarity and potential relief. However, while the rule changes what federal bank examiners may require to bring enforcement, it does not change the standards of prudent risk management a bank is held to, the discretion examiners keep over ratings, or the exposure that sits with state supervisors, the holding company, and individual officers and directors. This client alert explains what changed and how to consider responding.

Continue Reading OCC and FDIC Redefine “Unsafe or Unsound Practices”: The New Supervisory Framework for Banks

Cristina Diaz was recently featured in an in-depth Corporate Counsel Q&A that covers her return to private practice after more than a decade in-house at UBS.

In the interview, Cristina discusses what her years in-house taught her about turning regulatory requirements into practical business solutions, why she returned to private practice, and how she approaches

What You Need to Know

Key takeaway #1: On August 13, 2026, FinCEN issued a Financial Trend Analysis showing 67,540 Bank Secrecy Act (BSA) reports filed between 2023 and 2025 involved more than $4.9 billion in reported suspicious activity potentially related to human smuggling.

Key takeaway #2: Money services businesses (MSBs) filed approximately 97% of the reports, while depository institutions filed approximately only 3% but accounted for nearly 61% of the total reported suspicious activity.

Key takeaway #3: Financial institutions should consider whether the red flags and typologies highlighted in the FTA are appropriately incorporated into their automated transaction-monitoring scenarios for detecting potentially suspicious human smuggling-related activity.

Continue Reading Following the Money: FinCEN Maps the Financial Footprint of Human Smuggling

What You Need to Know

Key takeaway #1: Bank regulators have shifted from prior approval to examination scrutiny. Banks no longer need supervisory nonobjection to lend against crypto collateral. Regulators are likely to focus their examinations on collateral operations, BSA/AML and sanctions compliance, and third-party risk management.

Key takeaway #2: Control-based perfection trumps filing, with a June 3, 2027, New York deadline to re-perfect existing security interests. Under the 2022 UCC amendments, a security interest in controllable electronic records perfected by control as of June 3, 2027, will have priority over a filing-only perfection, regardless of timing. Lenders relying on filing alone should consider taking steps to comply with UCC Article 12’s control arrangements before the adjustment date.

Key takeaway #3: Custody terms determine ownership in insolvency. Documents that permit a custodian or platform to use or rehypothecate pledged assets may impair the secured nature of a claim, leaving the lender with an unsecured one. Parties should confirm segregation, retained borrower title, and a prohibition on rehypothecation in custody documentation.

Key takeaway #4: Bankruptcy safe harbors may not apply; margin mechanics are the practical protection. Because spot crypto lending may fall outside the Bankruptcy Code’s safe harbors, conservative advance rates and market-based loan-to-value triggers are the principal protections.

Key takeaway #5: No capital recognition for digital asset collateral, and state licensing may apply. Digital asset collateral currently earns no credit risk mitigation relief under U.S. capital rules, and nonbank lenders may face state licensing obligations.

Continue Reading Lending Against Digital Assets: Five Key Takeaways for Lenders After a Year of Regulatory and UCC Change