Regulatory Tracker

Regulatory Tracker — Page 6 of 10

Archive of enforcement actions, consent orders, and supervisory guidance impacting the BaaS and embedded finance ecosystem.

Subscribe to alerts
US Treasury

In January 2026, the US Treasury heightened Bank Secrecy Act/AML scrutiny on banks for fraud detection, especially involving nonprofits and government funds. This indirectly raises compliance risks for fintech partners handling high-volume transactions.

CFPB

Evolve Bank & Trust

Civil Penalty Fund Allocation

The CFPB allocated $46 million related to the Synapse/Evolve situation, addressing harm to consumers affected by the Synapse Financial Technologies collapse. Evolve Bank & Trust was a key banking partner in the Synapse middleware ecosystem.

Ohio Division of Financial Institutions

Ohio's banking regulator reversed course in October 2025, easing its licensing position for bank partnerships under the Small Loan Act. This represents evolving state-level regulatory guidance on BaaS partnership structures.

OCC

The OCC issued a formal agreement with First National Bank of Pasco for unsafe practices, including BSA/AML risk management, suspicious activity reporting, and due diligence deficiencies. While not explicitly tied to fintech partnerships, the areas cited are highly relevant to BaaS oversight.

CFPB

Synapse Financial Technologies, Inc.

Stipulated Final Judgment and Order

The CFPB took enforcement action against Synapse Financial Technologies, a BaaS middleware provider. The citation references the CFPB's official enforcement actions page for Synapse.

Bank of Lithuania

The Bank of Lithuania issued guidance in 2025 preparing EMIs and PIs for the REGATA reporting transition (Q1 2026) and MiCAR crypto-asset reporting requirements, including new safeguarding reports due by June 30, 2026.

Bank of Lithuania

KogoPay UAB

License Revocation

The Bank of Lithuania revoked KogoPay UAB's electronic money institution (EMI) license in August 2025 due to capital shortfalls, delayed financial reporting, and insolvency. Bankruptcy proceedings were initiated after the firm admitted inability to meet its obligations.

DFPI

DFPI settled with a former mortgage lender/servicer for $1.8 million in penalties plus $550,316 in borrower refunds for overcharges, escrow failures, and violations of California lending laws.

FDIC

The FDIC adopted more visible and prescriptive enforcement approaches against banks involved in bank-fintech partnerships in 2025, shifting from non-public supervisory actions to more public consequences.

NYDFS

NYDFS settled with Paxos Trust Company, imposing a $26.5 million penalty for inadequate due diligence on a former partner and systemic AML program failures. Paxos agreed to invest $22 million in compliance improvements.

FCA

N/A — Industry-wide

Policy Statement / Guidance

The FCA published strengthened safeguarding rules (PS25/12) effective August 2025 for authorised EMIs, payment institutions, and small EMIs to protect client funds in the event of firm failure. Interim compliance measures take effect May 2026.

HKMA

Hong Kong's HKMA stablecoin licensing framework took effect August 1, 2025, requiring fiat-referenced stablecoin issuers to obtain a license by October 31, 2025 or face a mandatory closing-down period starting November 1, 2025.

NPCI

India's NPCI imposed new UPI compliance rules effective August 1, 2025, under which payment service providers face penalties, API restrictions, or suspension of new customer onboarding for non-compliance with peak-hour transaction requirements.

Central Bank of Brazil (BCB)

BCB Resolution 589 requires all PIX participants to implement self-service MED (fraud recovery) functionality in their apps by October 2025, with MED 2.0 planned for February 2026 enabling tracing and blocking across five account layers.

OCC

The OCC issued statements in June–July 2025 explicitly embracing bank-fintech partnerships while addressing risks such as crypto-asset safekeeping. No specific enforcement action was taken against a named bank, but the guidance signals supervisory expectations for sponsor banks.

OCC | FDIC | Federal Reserve | NCUA | FinCEN

OCC, FDIC, Federal Reserve, NCUA, and FinCEN issued an order allowing banks and credit unions to collect Taxpayer Identification Numbers (TINs/SSNs) from third-party sources such as credit reporting agencies instead of directly from customers during account opening. The order was initially issued June 27, 2025 and expanded July 31, 2025.

CFPB

Unknown Sponsor Bank

Guidance Withdrawal / Regulatory Rollback

The CFPB rolled back UDAAP oversight in June 2025, reducing some fintech supervisory burdens. The change affects the regulatory landscape for bank-fintech partnerships but core compliance risks persist.

DOJ

The DOJ updated its FCPA guidelines on June 9, 2025, prioritizing banks for anti-bribery controls in international transactions. The guidance has implications for BaaS and fintech firms engaged in cross-border banking.

OCC

OCC leadership in 2025 expressed support for bank-fintech partnerships while prioritizing risk management. The OCC continued scrutiny of fintech arrangements with emphasis on robust compliance frameworks.

FCA

The FCA conducted multi-firm reviews of risk management and wind-down planning at e-money and payments firms in 2024-2025, finding underdeveloped frameworks across the sector.

CFPB

Evolve Bank and Trust

Consent Order (Early Termination)

Evolve Bank & Trust's 2022 redlining-related consent order was terminated on May 29, 2025 after the bank complied with compensation and injunctive terms. Evolve is a major BaaS sponsor bank.

CFPB

The CFPB issued a memo on April 16, 2025, detailing reduced federal oversight of fintechs, rescinding prior enforcement priorities and deferring to state-led enforcement. The bureau also adopted a no-priority stance on nonbank registration.

NYDFS

Block, Inc.

Consent Order

The New York State Department of Financial Services issued a consent order against Block, Inc. on April 10, 2025, citing deficiencies in BSA/AML compliance, cybersecurity, and consumer protection. The action stemmed from examinations covering April 2021–September 2022 amid rapid transaction volume growth from $15.02 billion to $34.06 billion.

Bank of Lithuania

EMIs and PIs in Lithuania

Regulatory Requirement / Guidance

From April 9, 2025, EMIs and PIs in Lithuania must maintain approved wind-down plans as a regulatory requirement.

Showing 121144 of 239