Banking and AML Guidance API: OCC, FDIC, Federal Reserve, and FinCEN in One Query

Short answer: a bank's supervisory expectations do not live in the CFR. They live in four separate archives run by four regulators, each with its own numbering, its own format, and its own idea of what happens to a document when it is replaced. Vaquill AI's corpus pulls six of those streams into one search surface under corpusType=AGENCY_GUIDANCE: OCC Bulletins (606, since 1994), OCC Interpretive Letters (448, 1996 to present), FDIC Financial Institution Letters (2,313, since 1994), Federal Reserve SR and CA Letters (336, since 1990), FinCEN Administrative Rulings (85, since 1988), and FinCEN Guidance (127). The design decision that matters most for compliance work is not coverage size. It is that superseded FDIC letters stay queryable, because an exam finding is always judged against the expectation that was live at the time.

TL;DR

  • Four regulators, four archives, none of them the CFR. The rules sit at 12 CFR (OCC, Fed, FDIC) and 31 CFR chapter X (FinCEN). The expectations sit in bulletins, letters, advisories, and rulings that the CFR never touches.
  • Six sources, each separately filterable with source=: occ_bulletin, occ_interpretive_letter, fdic_fil, frb_sr_letter, fincen_ruling, fincen_guidance.
  • Supervisory guidance does not have the force of law. The banking agencies said so themselves in a 2018 joint statement and codified it as a rule in 2021. It still drives every exam you will ever sit through.
  • Superseded FDIC letters remain in the corpus and are reachable with actStatus: "superseded". A corpus that silently drops them cannot answer what the expectation was in the year the finding was written.
  • The FDIC set spans both indexes. All 2,313 FILs come from the FDIC's active list and its inactive one.
  • CFTC Staff Letters (943, 2008 to present) sit alongside as a derivatives-side source under the same corpusType.

A grid of six source filter codes for OCC bulletins and interpretive letters, FDIC FILs, Federal Reserve SR letters, and FinCEN rulings and guidance.

4-question check
Question 1 of 4

Which source in this corpus has the longest coverage window?

One of ten posts in our federal agency guidance series.

For related coverage, see Federal Agency Guidance API: 34 Sub-Regulatory Sources in One Endpoint for the corpus this sits in, IRS Guidance API: Revenue Rulings, Revenue Procedures, Notices, and Announcements for the tax side of the same pattern, and The Long-Tail Regulators: CFTC, FCC, FERC, DOE, and CPSC Guidance in One API.

The assembly problem

Ask a compliance engineer where the third-party risk expectation for a bank is written and you get a shrug, then a browser tab per regulator. That is the actual state of the art at most institutions.

The regulations are easy. OCC rules sit at 12 CFR chapter I, the Federal Reserve at chapter II, the FDIC at chapter III, and FinCEN's Bank Secrecy Act rules at 31 CFR chapter X. All of that is in the CFR corpus, refreshed daily, and machine readable.

The expectations are the hard part. They arrive as bulletins, letters, advisories, and rulings published on four different websites, in four different numbering schemes, with no shared index and no common format.

Loading diagram...
Sourcesource codeDocumentsWindow
OCC Bulletinsocc_bulletin606since 1994
OCC Interpretive Lettersocc_interpretive_letter4481996 to present
FDIC Financial Institution Lettersfdic_fil2,313since 1994, active and inactive indexes
Federal Reserve SR and CA Lettersfrb_sr_letter336since 1990
FinCEN Administrative Rulingsfincen_ruling85since 1988
FinCEN Guidancefincen_guidance127alerts, advisories, notices, bulletins, fact sheets
CFTC Staff Letterscftc_staff_letter9432008 to present

All seven live under corpusType=AGENCY_GUIDANCE, which spans 34 named federal sources and 21,906 sections, refreshed weekly. The corpus types reference lists every token.

What each instrument is, and who it binds

OCC Bulletins

The OCC's main channel for policy addressed to national banks and federal savings associations. Bulletins are numbered by year, carry a subject line, and often state on their face what they rescind.

This is where the OCC's supervisory expectations on third-party relationships, model risk, concentration risk, and BSA program elements have landed for three decades. OCC Bulletin 2013-29 on third-party relationships is the archetype: widely treated as a standard, quoted in vendor contracts, and then rescinded in 2023 when the agencies issued joint third-party risk management guidance.

Who it binds: OCC-supervised institutions, through examination rather than enforcement.

OCC Interpretive Letters

Sequentially numbered letters answering whether a specific activity is permissible for a national bank. They are the closest thing in banking law to a private ruling that everyone can read.

The interpretive letter series is where novel activities get their first legal footing, including the sequence that walked national banks through crypto-asset custody and stablecoin reserve activity between 2020 and 2021, and the later letters that layered on supervisory non-objection.

Who it binds: formally, the addressee. Practically, everyone reads them as the OCC's position.

FDIC Financial Institution Letters

FILs are the FDIC's announcement channel to insured state nonmember banks, and they are the highest-volume set here at 2,313 documents. Format is FIL-XX-YYYY.

A FIL can be an interagency policy statement, a call report change, a deposit insurance clarification, or a warning about a fraud pattern. The mix is broad, which makes filtering by text quality more important than filtering by type.

Who it binds: FDIC-supervised institutions, plus everyone who reads the interagency ones because all three agencies issued the same content under different numbers.

Federal Reserve SR and CA Letters

SR letters carry supervision and regulation policy to Reserve Banks and the institutions they supervise, including bank holding companies. CA letters carry consumer affairs policy.

SR 11-7 on model risk management is the one everybody in bank model validation can cite from memory, and it has outlived several rounds of rulemaking around it. That longevity is the argument for having the archive: a 2011 letter is still driving 2026 validation programs.

Who it binds: Fed-supervised institutions and, through the SR letter route, Reserve Bank examiners.

FinCEN Administrative Rulings

FinCEN's formal answers to specific questions about the Bank Secrecy Act regulations, running from 1988. Eighty-five documents is a small set, and it is small because the instrument is deliberately narrow.

A ruling responds to a stated factual situation, usually about whether a business model is a money services business, whether a particular transaction triggers a filing obligation, or how a definition in 31 CFR chapter X applies. They are cited in money-transmitter licensing analysis constantly.

Who it binds: the requester directly, and everyone else as FinCEN's stated reading of its own rules.

FinCEN Guidance

The broad bucket: alerts, advisories, notices, bulletins, and fact sheets, 127 documents. Advisories carry a FIN-YYYY-Axxx identifier and describe typologies, red flags, and jurisdictions of concern.

This is the material that ends up in a bank's transaction monitoring tuning and in the narrative of a SAR. When FinCEN publishes an advisory on a ransomware payment typology or on a sanctioned jurisdiction, the red-flag list in that document becomes an examinable expectation within a quarter.

Who it binds: nobody, formally. Everyone, practically.

Supersession is the whole point

Supervisory guidance is a chain. A bulletin rescinds an earlier bulletin. An interagency statement replaces three agency-specific ones. A FIL moves from the FDIC's active index to its inactive index and effectively disappears from the front door.

A corpus that keeps only what is currently active looks cleaner and is useless for the work compliance teams actually do.

Here is the scenario. An exam covering fiscal 2021 produces a finding on third-party oversight. Your remediation memo has to state the expectation as it stood in 2021, which was the 2013 OCC bulletin and its FDIC and Fed counterparts, not the 2023 interagency guidance that replaced them. If your research tool only knows the current document, it will confidently hand you an expectation that did not exist during the exam period.

All 2,313 FDIC letters in this corpus come from both the active and the inactive index, and the superseded ones stay reachable through the actStatus filter described in the status and currency reference:

POST /us/statutes/search
{
  "query": "third party risk management vendor due diligence",
  "corpusType": "AGENCY_GUIDANCE",
  "source": ["fdic_fil"],
  "actStatus": "superseded",
  "limit": 20
}

That distinction is worth stating in your own product UI too. "We have the old letter" and "we can show you the world as of March 2021" are different promises, and only one of them is true.

Worked example: an AML question, from the rule to the advisory

Take a real shape of question: a bank's monitoring team wants to know what is expected on suspicious activity reporting for a specific typology. Three hops, base URL https://api.vaquill.ai/api/v1, Authorization: Bearer vq_key_..., 4 credits per search.

Hop 1: the regulation. SAR obligations for banks sit in 31 CFR chapter X, including the general filing rule at 31 CFR 1010.320 and the bank-specific requirements in part 1020.

POST /us/statutes/search
{
  "query": "suspicious activity report filing obligation bank",
  "corpusType": "CFR",
  "titleNumber": "31",
  "limit": 10
}

Hop 2: the advisory. Now ask FinCEN what it has said about the typology, restricted to the two FinCEN sources.

POST /us/statutes/search
{
  "query": "ransomware payment red flags reporting",
  "corpusType": "AGENCY_GUIDANCE",
  "source": ["fincen_guidance", "fincen_ruling"],
  "matchType": "all",
  "limit": 10
}

Hop 3: the prudential overlay. The same typology usually has a supervisory expectation attached from the institution's primary federal regulator.

POST /us/statutes/search
{
  "query": "BSA AML program suspicious activity monitoring expectations",
  "corpusType": "AGENCY_GUIDANCE",
  "source": ["occ_bulletin", "fdic_fil", "frb_sr_letter"],
  "limit": 20
}

Twelve credits, and the output has the regulation, the typology guidance, and the supervisory expectation with the issuing agency attached to each. The compliance mapping recipe generalizes that chain. Every hit carries the official source URL for the publisher's own copy, so a second-line reviewer can verify at the agency site without leaving the queue.

Then pull the full text by identifier:

GET /us/statutes/section/{actId}
GET /us/statutes/section/{actId}/body

actId is stable and not guessable. Take it from the search or resolve response and store it, a rule the section identifier reference explains. Constructing one from a document number will usually 404.

Filter behavior that matters when compliance depends on it

Unknown filter values are rejected with 422, never silently matched as empty. Typo frb_sr_letters and you get an error whose message lists every valid source code. In a compliance workflow, a silent empty result is the dangerous failure, because it reads as "no guidance exists."

Failed calls are not charged, so validating filters against the live API costs nothing.

Paging comes from one ranking, so results never repeat or vanish between pages and a later page costs the same as the first. limit maxes at 50, offset at 70.

yearFrom and yearTo filter on the last amendment year the publisher credits, not on our rebuild date. About a fifth of sections across the whole corpus carry no amendment credit, because some publishers print none, and those drop out once you set either bound. For dated guidance, publishedFrom and publishedTo are the better filters.

The adjacent sources

CFTC Staff Letters (cftc_staff_letter, 943 documents, 2008 to present) cover no-action, exemptive, interpretative, and advisory letters from Commission staff. If your product touches swap dealers, FCMs, or introducing brokers, these matter as much as the banking set does on the depository side, and they behave the same way: staff positions that are not law but govern practice.

The same corpusType=AGENCY_GUIDANCE surface also carries a long tail of other federal regulators, from the FCC and FERC to the CPSC, BIS, and DDTC, each with its own coverage window and its own quirks. The long-tail regulators post walks that tail source by source, including which sets are live archives and which are frozen historical ones.

For the rulemaking side of the same agencies, corpusType=FEDERAL_REGISTER holds 202,526 agency rule documents, final and proposed, from 1994 to present, refreshed weekly. That is where a proposed rule lives before it becomes a CFR section, and corpusType=CFR holds 219,114 sections refreshed daily once it does.

Freshness, change detection, and provenance

The guidance sources refresh weekly. There is no charge for GET /boards, and every watchable source it returns carries cadence, lastRetrievedAt, and retrievalStatus, which is enough to audit the pipeline yourself instead of trusting a status page.

GET /us/statutes/coverage is also free, and for bank supervision the row that matters is the per-source count: it tells you how many SR/CA letters, OCC bulletins, interpretive letters and FILs are actually indexed before you build a screen that assumes one of them is complete. The full field list covers the rest of the response.

Watches let you subscribe to a board and receive changes with a per-section diff, delivered by webhook. A webhook that fires when a new FIL or SR letter lands is worth more to a compliance team than any retrieval tuning, because the failure mode in this domain is missing a document, not ranking it third.

The sourcing rule is the government publisher's own copy, and a commercial aggregator is never used as a source or as a fallback. Where a publisher blocks automated access, the corpus is paused and says so in the API response rather than quietly filling the gap from somewhere else. The collection layer is published at github.com/Vaquill-AI/open-us-law.

FAQ

Is bank supervisory guidance part of the CFR?

No. The banking agencies' regulations sit in the CFR (12 CFR chapters I, II, and III for the OCC, Federal Reserve, and FDIC, and 31 CFR chapter X for FinCEN), but bulletins, FILs, SR letters, and advisories are published separately on each agency's own site. That split is the reason a CFR-only data source leaves a compliance product half built.

Does supervisory guidance have the force of law?

No. The federal banking agencies issued a joint Statement Clarifying the Role of Supervisory Guidance in 2018, stating that guidance does not have the force and effect of law and does not form the basis for enforcement actions, and each agency codified that statement as a rule in 2021. Examiners still measure institutions against it, so the practical weight is higher than the legal weight.

Can I query superseded FDIC Financial Institution Letters?

Yes. All 2,313 FILs in the corpus come from both the FDIC's active and inactive indexes, and superseded letters are reachable by filtering on actStatus: "superseded". That matters when a remediation memo has to state the expectation that was live during the exam period rather than the one that replaced it.

What is the difference between an OCC Bulletin and an OCC Interpretive Letter?

A Bulletin carries policy and supervisory expectations to all OCC-supervised institutions. An Interpretive Letter answers whether a specific activity is legally permissible for a national bank, usually in response to a request. Bulletins tell you how to run the program; interpretive letters tell you whether you may run it at all.

What is the difference between an SR letter and a CA letter?

SR letters carry Federal Reserve supervision and regulation policy to Reserve Banks and supervised institutions. CA letters carry consumer affairs policy. Both are in the corpus under the same frb_sr_letter source code, 336 documents going back to 1990.

How many FinCEN documents are in the corpus and how far back do they go?

Two sets: 85 FinCEN Administrative Rulings going back to 1988, and 127 FinCEN Guidance documents covering alerts, advisories, notices, bulletins, and fact sheets. The rulings answer specific factual questions about the BSA regulations, and the guidance set is where typologies and red-flag lists live.

Can I ask what a bulletin said on a specific past date?

Not as a corpus-wide query. A bulletin resolves to its live text and only that, with no as_of=DATE parameter to rewind the corpus to an exam date. Alongside it you get amendment history, lastAmendedYear, a yearFrom/yearTo currency filter, change events per refresh, and per-section diffs on watched boards, and you can still retrieve the superseded document itself.

Are CFTC staff letters covered too?

Yes, as an adjacent source: cftc_staff_letter, 943 documents from 2008 to present, covering no-action, exemptive, interpretative, and advisory letters. They sit under the same corpusType=AGENCY_GUIDANCE and take the same filters as the banking sources.

How do I stop a new FIL or SR letter from slipping past me?

Use the free GET /boards endpoint to find the watchable source, then create a watch and take deliveries by webhook. The guidance sources refresh weekly, and each captured change carries a per-section diff, so a monitoring job reads changes rather than re-crawling and re-diffing the agency site yourself.

What happens if I pass a source code that does not exist?

The API returns 422 and the error message lists every valid source code, so the surface documents its own vocabulary. Failed calls are not charged. This is deliberate: in compliance work, a filter that silently matches nothing is far more dangerous than a loud error.

The most complete US primary law API.
Every US statute, regulation, constitution, and executive order through one REST and MCP API. 4M+ sections, section-level citations, and links to the official source. Plus a free open dataset.
18 min read

New legal AI guides, weekly.

Priyansh Khodiyar

Priyansh Khodiyar

Co-Founder & CTO

Priyansh leads engineering and AI at Vaquill, from the matter workbench to drafting, document comparison, document matrix, and citation-verified research.