Sullivan
Microsoft has discontinued support for Internet Explorer. To access the Sullivan website, please install a modern browser like Microsoft Edge or Google Chrome.

Biography

Roy focuses on bank regulatory and compliance matters, including international banks and their branches and agencies in New York. He has been involved in the formation of these offices, including drafting, filing and supporting the necessary applications. Upon establishment, he has advised on the application of Federal and New York laws with respect to their activities and operations. For over 10 years, Roy was responsible for and worked closely with the large compliance teams at two foreign banks.

Education
  • Boston College (B.A., magna cum laude)
  • Boston College Law School (J.D., cum laude)
Bar & Court Admissions
  • New York
Professional Qualifications
  • Institute of International Bankers' Legal and Regulatory Committee and Compliance Officers' Committee
  • Association of the Bar of the City of New York’s Banking Law Committee and the Banking Law Committee of the New York State Bar Association
Awards & Honors
  • The Legal 500 U.S. (2020)
Viewpoints
All Viewpoints
FinCEN's Proposed AML Enhancements for Money Service Businesses and Other Financial Institutions
On September 17, 2020, the Financial Crimes Enforcement Network ("FinCEN") published an Advance Notice of Proposed Rulemaking ("Notice") to obtain public comments on proposed enhancements to anti-money laundering ("AML") programs.[1] The Notice poses 11 questions for the public regarding FinCEN’s interest in new regulations requiring financial institutions to adopt "effective and reasonably designed" AML programs. The Notice does not propose any new rules. Instead, it presents areas where FinCEN is focusing attention and may in the future propose new rules depending on public comments and suggestions and other political considerations. Key Changes Suggested by the Notice 1. Adopt new regulations clearly defining an ‘‘effective and reasonably designed’’ AML program. FinCEN’s proposed rule would focus on defining "effectiveness" and "reasonably designed." FinCEN would define a compliant AML program as one that would: Identify, assess and mitigate risks from illegal activities in view of the financial institution’s own risk profile and any published federal AML priorities. Covered financial institutions include banks, brokers, money service businesses, casinos, and among others. Comply with the recordkeeping and reporting requirements of the Bank Secrecy Act of 1970. Provide information with a high degree of usefulness to the government consistent with the institution’s own risk profile and any published federal AML priorities.[2] 2. Adopt an express regulatory requirement for a risk assessment program. FinCEN recognizes that today almost all financial institutions who are subject to AML requirements (for example, banks, brokers, money service businesses, casinos, and others) design their AML programs based on risk assessments. FinCEN views the risk assessment process as a critical part of AML programs. Some financial institutions, like banks and brokers, are required by law to conduct risk assessments. Even though a risk assessment is not an express requirement for all financial institutions, under current practice AML program examiners (for example, the IRS) impose risk assessments as part of the evaluations of whether AML programs are effective. Therefore, a risk assessment is often a de facto requirement for all financial institutions subject to AML obligations, and now FinCEN believes that given the importance of a risk assessment, it should be required by law. 3. Publish a bi-annual list of national AML priorities. FinCEN is considering whether to issue AML priorities and then require financial institutions to consider such priorities in risk assessments. 4. Adopt a specific requirement to reasonably manage and mitigate the risks identified in the risk assessment and the published AML priorities. FinCEN believes the vast majority of financial institutions are doing just this without any express requirement, but as part of a well-designed AML program. This requirement would formalize this process. Our Assessment of FinCEN’s Proposed New Regulations In our view, FinCEN’s Notice does not make the case that a new set of rules and regulations are needed at this point. In fact, the Notice states that the vast majority of financial institutions are already doing what the Notice would require. If there is a problem in the implementation of the detailed AML requirements that would be corrected by new laws, FinCEN should expressly outline these issues. Financial institutions are already swamped with AML compliance obligations and most certainly make strenuous efforts to adhere to the existing regulations. FinCEN’s proposals can be implemented without new regulations. There is nothing stopping FinCEN from publishing a list of AML priorities right now. FinCEN is already issuing guidance on a host of issues and could just as well make financial institutions focus on these matters even more with some simple guidance. FinCEN is not requesting comments on the costs of the new rules. Small financial institutions already have to hire expensive consultants to comply on AML and risk assessments are becoming the purview of experts with the attendant additional costs. However, we note that generally before FinCEN can adopt new regulations, it must first solicit public comment and undertake a cost benefit analysis. [1] Available at https://www.govinfo.gov/content/pkg/FR-2020-09-17/pdf/2020-20527.pdf. [1] 85 Fed. Reg. 58026 (Sept 18,2020). Available at https://www.govinfo.gov/content/pkg/FR-2020-09-18/pdf/FR-2020-09-18.pdf.
OCC Gives Banks Keys to the Crypto Kingdom
On July 22, 2020, the Office of the Comptroller of the Currency (“OCC”) published an Interpretive Letter (the “Letter”) declaring that national banks and federal savings associations (collectively, “national banks”) may provide cryptocurrency-related custody and other services.[1] The announcement marks a revolutionary moment for the cryptocurrency industry where, until now, custody has been provided by crypto-specialist firms, typically under a state trust license. In the Letter the OCC notes that, although providing custody for cryptocurrencies differs in several respects from other custody activities[2], such services are a “modern form of … traditional bank activities.” As an example, there is no physical possession of cryptocurrencies.  Instead, a national bank “holding” cryptocurrencies on behalf of a customer is actually taking possession of the cryptographic access keys to that unit of cryptocurrency, that is, private keys. According to the OCC, by providing these services, “banks can continue to fulfill the financial intermediation function they have historically played.” Moreover, national banks’ crypto custody services may extend beyond passively holding private keys. As expressed by the OCC, the custody function is a gateway to providing a whole host of other cryptocurrency services that are appropriate for custody customers. National banks may also facilitate customers’ cryptocurrency and fiat currency exchange transactions, transaction settlement, trade execution, recording keeping, valuation, tax services, and reporting. Basically, national banks may become full service crypto‑banking providers. We note, however, that the Letter does not authorize national banks to open FDIC-insured deposit accounts denominated in cryptocurrencies. The OCC cautions national banks that comprehensive control systems need to be in place to manage risks of this business. In addition, as part of its ordinary supervisory process, any national bank looking into conducting cryptocurrency custody services should consult with the OCC supervisors. Furthermore, it should be noted that additional requirements may apply depending on the nature of the cryptocurrency being custodied. As the Letter notes, different cryptocurrencies may also be subject to different OCC regulations and guidance outside of the custody context, as well as non-OCC regulations. For example, cryptocurrencies that are considered “securities” for purposes of federal securities laws may be subject to the OCC’s regulations on recordkeeping and confirmation requirements for securities transactions, as well as securities laws and regulatory requirements overseen by the SEC and FINRA. Importantly, the OCC is authorizing these services within the existing authorities that national banks possess. There is no new regulation or guideline or other new law that needs to be put into place before this authority can be relied upon. The Party is Just Getting Started – Who’s invited? National banks now need to decide how to enter this new line of business. The OCC notes that depending on their risk appetite and business model, national banks may offer to store copies of their customers’ private keys while permitting the customer to retain their own copy, while others may generate new private keys which would be held solely by the institution on behalf of the customer. National banks may provide these services in non-fiduciary capacity, meaning merely holding a customer’s private key and related records, or in a fiduciary capacity, such as an investment advisor, a trustee, an executor of a will, or any similar capacity in which the bank possesses investment discretion on behalf of the customer. Due to the undeveloped financial infrastructure presently available for cryptocurrency, custodying in a fiduciary capacity presents both major business opportunities for national banks as well as compliance and technology challenges. In the past, money center banks have been cautious in dealing with cryptocurrency counterparties, in part due to the perception that the regulators held a skeptical view of the industry and would, at exam time, be tougher on such relationships. The OCC has tried to head this view off by specifically stating in the Letter that national banks can work within any lawful business and that cryptocurrency custody actives constitute such a lawful business. We believe that this shift in a key regulator’s tone can have consequences also in other financial institutions who may now take a more positive attitude towards cryptocurrencies. What about state-chartered banks? Because many state laws, New York included, have so-called “wildcard” statutes that permit state banks to conduct all the same activities as national banks, the Letter has broader application than just national banks. Nonetheless, the prudential conditions stated in the Letter demonstrate that banks will need to devote a serious effort to perform these services. We expect that those few banks already servicing the cryptocurrency business will quickly move to take full advantage and expand their services. Larger banks with existing robust institutional custody businesses are likely to follow suit. The Letter provides opportunities also for many foreign banks that have branches in the U.S.  While most branches do not have trust powers, the OCC letter allows for non-trust related use of this express authority with respect to nonfiduciary custody services. One of the roadblocks in the security token market has been the lack of “qualified custodians,” such as banks and broker‑dealers. Qualified custodians are important actors with respect to cryptocurrencies deemed to be securities under federal securities laws, such securities tokens, that require in certain cases the use of a qualified custodian for maintaining client funds and securities. Here again, national banks have an opportunity to play a role. We also expect that expanding the universe of qualified custodians will provide a necessary boost to the budding securities token market. Frenemies’ Warming Relationship Given that Brian Brooks, Acting Comptroller of the Currency and head of the OCC, hails from the virtual currency world, it is not a shock that the OCC would be supportive of the industry and as banks become more expert in the complexities of the cryptocurrency business we expect that this first step will presage a number of new bank and cryptocurrency opportunities. The Letter may stand as a turning point in the notorious “frenemy” relationship between banks and cryptocurrency. Banks entering the industry full pelt could have two significant consequences. First, it is possible that more merchants and consumers will find a lower barrier to using cryptocurrencies in everyday transactions. Second, it may rebuff those prognosticators who have maintained that banks would be made obsolete and disintermediated by new cryptocurrency-related businesses and technologies. If you cannot beat them, join them. We recommend that any institutions looking to take advantage of the Letter and its direct and indirect consequences carefully consider the new business opportunities available and be attentive to applicable laws, rules, and standards in this highly regulated area. *  *  *  *  * [1] The Office of the Comptroller of the Currency, Interpretive Letter #1170, July 22, 2020, available at https://www.occ.treas.gov/topics/charters-and-licensing/interpretations-and-actions/2020/int1170.pdf. [2] In general custody involves the holding, directly or indirectly, client funds or securities, or having any authority to obtain possession of them.  See, for example, the Investment Advisers Act of 1940 Rule 206(4)-2(d)(2).

Roy C. Andersen

Roy focuses on bank regulatory and compliance matters, including international banks and their branches and agencies in New York. He has been involved in the formation of these offices, including drafting, filing and supporting the necessary applications. Upon establishment, he has advised on the application of Federal and New York laws with respect to their activities and operations. For over 10 years, Roy was responsible for and worked closely with the large compliance teams at two foreign banks.

Viewpoints
All Viewpoints
FinCEN's Proposed AML Enhancements for Money Service Businesses and Other Financial Institutions
On September 17, 2020, the Financial Crimes Enforcement Network ("FinCEN") published an Advance Notice of Proposed Rulemaking ("Notice") to obtain public comments on proposed enhancements to anti-money laundering ("AML") programs.[1] The Notice poses 11 questions for the public regarding FinCEN’s interest in new regulations requiring financial institutions to adopt "effective and reasonably designed" AML programs. The Notice does not propose any new rules. Instead, it presents areas where FinCEN is focusing attention and may in the future propose new rules depending on public comments and suggestions and other political considerations. Key Changes Suggested by the Notice 1. Adopt new regulations clearly defining an ‘‘effective and reasonably designed’’ AML program. FinCEN’s proposed rule would focus on defining "effectiveness" and "reasonably designed." FinCEN would define a compliant AML program as one that would: Identify, assess and mitigate risks from illegal activities in view of the financial institution’s own risk profile and any published federal AML priorities. Covered financial institutions include banks, brokers, money service businesses, casinos, and among others. Comply with the recordkeeping and reporting requirements of the Bank Secrecy Act of 1970. Provide information with a high degree of usefulness to the government consistent with the institution’s own risk profile and any published federal AML priorities.[2] 2. Adopt an express regulatory requirement for a risk assessment program. FinCEN recognizes that today almost all financial institutions who are subject to AML requirements (for example, banks, brokers, money service businesses, casinos, and others) design their AML programs based on risk assessments. FinCEN views the risk assessment process as a critical part of AML programs. Some financial institutions, like banks and brokers, are required by law to conduct risk assessments. Even though a risk assessment is not an express requirement for all financial institutions, under current practice AML program examiners (for example, the IRS) impose risk assessments as part of the evaluations of whether AML programs are effective. Therefore, a risk assessment is often a de facto requirement for all financial institutions subject to AML obligations, and now FinCEN believes that given the importance of a risk assessment, it should be required by law. 3. Publish a bi-annual list of national AML priorities. FinCEN is considering whether to issue AML priorities and then require financial institutions to consider such priorities in risk assessments. 4. Adopt a specific requirement to reasonably manage and mitigate the risks identified in the risk assessment and the published AML priorities. FinCEN believes the vast majority of financial institutions are doing just this without any express requirement, but as part of a well-designed AML program. This requirement would formalize this process. Our Assessment of FinCEN’s Proposed New Regulations In our view, FinCEN’s Notice does not make the case that a new set of rules and regulations are needed at this point. In fact, the Notice states that the vast majority of financial institutions are already doing what the Notice would require. If there is a problem in the implementation of the detailed AML requirements that would be corrected by new laws, FinCEN should expressly outline these issues. Financial institutions are already swamped with AML compliance obligations and most certainly make strenuous efforts to adhere to the existing regulations. FinCEN’s proposals can be implemented without new regulations. There is nothing stopping FinCEN from publishing a list of AML priorities right now. FinCEN is already issuing guidance on a host of issues and could just as well make financial institutions focus on these matters even more with some simple guidance. FinCEN is not requesting comments on the costs of the new rules. Small financial institutions already have to hire expensive consultants to comply on AML and risk assessments are becoming the purview of experts with the attendant additional costs. However, we note that generally before FinCEN can adopt new regulations, it must first solicit public comment and undertake a cost benefit analysis. [1] Available at https://www.govinfo.gov/content/pkg/FR-2020-09-17/pdf/2020-20527.pdf. [1] 85 Fed. Reg. 58026 (Sept 18,2020). Available at https://www.govinfo.gov/content/pkg/FR-2020-09-18/pdf/FR-2020-09-18.pdf.
OCC Gives Banks Keys to the Crypto Kingdom
On July 22, 2020, the Office of the Comptroller of the Currency (“OCC”) published an Interpretive Letter (the “Letter”) declaring that national banks and federal savings associations (collectively, “national banks”) may provide cryptocurrency-related custody and other services.[1] The announcement marks a revolutionary moment for the cryptocurrency industry where, until now, custody has been provided by crypto-specialist firms, typically under a state trust license. In the Letter the OCC notes that, although providing custody for cryptocurrencies differs in several respects from other custody activities[2], such services are a “modern form of … traditional bank activities.” As an example, there is no physical possession of cryptocurrencies.  Instead, a national bank “holding” cryptocurrencies on behalf of a customer is actually taking possession of the cryptographic access keys to that unit of cryptocurrency, that is, private keys. According to the OCC, by providing these services, “banks can continue to fulfill the financial intermediation function they have historically played.” Moreover, national banks’ crypto custody services may extend beyond passively holding private keys. As expressed by the OCC, the custody function is a gateway to providing a whole host of other cryptocurrency services that are appropriate for custody customers. National banks may also facilitate customers’ cryptocurrency and fiat currency exchange transactions, transaction settlement, trade execution, recording keeping, valuation, tax services, and reporting. Basically, national banks may become full service crypto‑banking providers. We note, however, that the Letter does not authorize national banks to open FDIC-insured deposit accounts denominated in cryptocurrencies. The OCC cautions national banks that comprehensive control systems need to be in place to manage risks of this business. In addition, as part of its ordinary supervisory process, any national bank looking into conducting cryptocurrency custody services should consult with the OCC supervisors. Furthermore, it should be noted that additional requirements may apply depending on the nature of the cryptocurrency being custodied. As the Letter notes, different cryptocurrencies may also be subject to different OCC regulations and guidance outside of the custody context, as well as non-OCC regulations. For example, cryptocurrencies that are considered “securities” for purposes of federal securities laws may be subject to the OCC’s regulations on recordkeeping and confirmation requirements for securities transactions, as well as securities laws and regulatory requirements overseen by the SEC and FINRA. Importantly, the OCC is authorizing these services within the existing authorities that national banks possess. There is no new regulation or guideline or other new law that needs to be put into place before this authority can be relied upon. The Party is Just Getting Started – Who’s invited? National banks now need to decide how to enter this new line of business. The OCC notes that depending on their risk appetite and business model, national banks may offer to store copies of their customers’ private keys while permitting the customer to retain their own copy, while others may generate new private keys which would be held solely by the institution on behalf of the customer. National banks may provide these services in non-fiduciary capacity, meaning merely holding a customer’s private key and related records, or in a fiduciary capacity, such as an investment advisor, a trustee, an executor of a will, or any similar capacity in which the bank possesses investment discretion on behalf of the customer. Due to the undeveloped financial infrastructure presently available for cryptocurrency, custodying in a fiduciary capacity presents both major business opportunities for national banks as well as compliance and technology challenges. In the past, money center banks have been cautious in dealing with cryptocurrency counterparties, in part due to the perception that the regulators held a skeptical view of the industry and would, at exam time, be tougher on such relationships. The OCC has tried to head this view off by specifically stating in the Letter that national banks can work within any lawful business and that cryptocurrency custody actives constitute such a lawful business. We believe that this shift in a key regulator’s tone can have consequences also in other financial institutions who may now take a more positive attitude towards cryptocurrencies. What about state-chartered banks? Because many state laws, New York included, have so-called “wildcard” statutes that permit state banks to conduct all the same activities as national banks, the Letter has broader application than just national banks. Nonetheless, the prudential conditions stated in the Letter demonstrate that banks will need to devote a serious effort to perform these services. We expect that those few banks already servicing the cryptocurrency business will quickly move to take full advantage and expand their services. Larger banks with existing robust institutional custody businesses are likely to follow suit. The Letter provides opportunities also for many foreign banks that have branches in the U.S.  While most branches do not have trust powers, the OCC letter allows for non-trust related use of this express authority with respect to nonfiduciary custody services. One of the roadblocks in the security token market has been the lack of “qualified custodians,” such as banks and broker‑dealers. Qualified custodians are important actors with respect to cryptocurrencies deemed to be securities under federal securities laws, such securities tokens, that require in certain cases the use of a qualified custodian for maintaining client funds and securities. Here again, national banks have an opportunity to play a role. We also expect that expanding the universe of qualified custodians will provide a necessary boost to the budding securities token market. Frenemies’ Warming Relationship Given that Brian Brooks, Acting Comptroller of the Currency and head of the OCC, hails from the virtual currency world, it is not a shock that the OCC would be supportive of the industry and as banks become more expert in the complexities of the cryptocurrency business we expect that this first step will presage a number of new bank and cryptocurrency opportunities. The Letter may stand as a turning point in the notorious “frenemy” relationship between banks and cryptocurrency. Banks entering the industry full pelt could have two significant consequences. First, it is possible that more merchants and consumers will find a lower barrier to using cryptocurrencies in everyday transactions. Second, it may rebuff those prognosticators who have maintained that banks would be made obsolete and disintermediated by new cryptocurrency-related businesses and technologies. If you cannot beat them, join them. We recommend that any institutions looking to take advantage of the Letter and its direct and indirect consequences carefully consider the new business opportunities available and be attentive to applicable laws, rules, and standards in this highly regulated area. *  *  *  *  * [1] The Office of the Comptroller of the Currency, Interpretive Letter #1170, July 22, 2020, available at https://www.occ.treas.gov/topics/charters-and-licensing/interpretations-and-actions/2020/int1170.pdf. [2] In general custody involves the holding, directly or indirectly, client funds or securities, or having any authority to obtain possession of them.  See, for example, the Investment Advisers Act of 1940 Rule 206(4)-2(d)(2).