Regulatory Tracker

Regulatory Tracker — Page 7 of 10

Archive of enforcement actions, consent orders, and supervisory guidance impacting the BaaS and embedded finance ecosystem.

Subscribe to alerts
Central Bank of the Republic of Turkey (TCMB)

Ininal

License Suspension

Turkey's TCMB suspended Ininal's EMI operational license in late March 2025 as part of an investigation into digital wallets facilitating illegal gambling transactions.

OCC

The OCC conditionally approved a fintech model by SmartBiz under rigorous compliance standards. The conditional approval reflects the OCC's approach of enabling fintech innovation while maintaining strict safety and soundness requirements.

OCC

The OCC reaffirmed that national banks and federal savings associations can engage in crypto-asset activities without obtaining a nonobjection from the agency. This aligns with the broader rollback of restrictive crypto guidance.

Central Bank of the Republic of Turkey (TCMB)

PayFix

License Revocation

Turkey's TCMB suspended and then fully revoked the electronic money institution (EMI) license of PayFix amid an investigation into illegal gambling and money laundering. Executive arrests and asset seizures accompanied the action.

Central Bank of the Republic of Turkey (TCMB)

Aypara

License Revocation

Turkey's TCMB suspended and then fully revoked the EMI license of Aypara, a digital wallet provider, as part of a crackdown on payment institutions facilitating illegal gambling transactions.

OCC

Patriot Bank, N.A.

Formal Agreement

On February 20, 2025, the OCC entered a formal agreement with Patriot Bank, National Association, after an examination identified BSA/AML compliance deficiencies tied to third-party risks, including prepaid card programs. The bank was required to develop enhanced plans for strategic and capital planning, customer due diligence, suspicious activity monitoring, and oversight of third-party program managers.

CFPB

CFPB (agency-wide action)

Stop-work order / Administrative action

In early 2025, CFPB Acting Director Vought issued a stop-work order on February 10, placed staff on administrative leave, and terminated probationary employees, effectively halting CFPB enforcement and supervision activities including those involving banks and fintechs.

FDIC

The FDIC released documents related to its supervision of crypto-related activities at banks, signaling a reevaluation of earlier pauses on crypto and fintech partnerships. This reflects evolving supervisory approaches to fintech innovation.

NYDFS

NYDFS reached a $2 million settlement with PayPal over a December 2022 cybersecurity incident that exposed unmasked consumer data, including Social Security numbers, in Form 1099-Ks. Violations included skipped testing, inadequate personnel training, and optional multi-factor authentication.

NYDFS

Yellowstone Capital

Judgment/Settlement

New York Attorney General Letitia James secured a judgment exceeding $1 billion against Yellowstone Capital and affiliates for predatory loans disguised as merchant cash advances to over 18,000 small businesses. The scheme involved usurious interest rates and hidden fees.

Bank of Lithuania

Alternative Payments

License Revocation

The Bank of Lithuania revoked the license of an unnamed EMI or PI, citing 10 regulatory violations, with one violation referred to the Court of Justice of the European Union (CJEU) concerning direct debit services.

Bank of Lithuania

Foxpay

License Revocation

The Bank of Lithuania revoked Foxpay's electronic money institution (EMI) license on November 22, 2024, for laundering approximately €17 million between 2023-2024 and bribing AML officers.

FCA

Unknown EMIs (6 institutions)

s166 Skilled Person Review

The FCA commissioned six s166 skilled person reviews of Electronic Money Institutions in 2024 through November. These reviews are used to independently assess whether firms meet regulatory requirements.

FCA

The FCA imposed voluntary requirements (VREQs) on three Electronic Money Institutions in 2024 through November. VREQs often restrict activities such as ceasing payment services, imposing onboarding bans, or requiring prior FCA consent for fund safeguarding.

FCA

The FCA disclosed aggregate enforcement data for Electronic Money Institutions (EMIs) and Payment Institutions (PIs) through November 2024, revealing ongoing use of VREQs, OIREQs, enforcement operations, and s166 skilled person reviews. In 2024 YTD, EMIs received 3 VREQs and 6 s166 reviews, while PIs received 1 enforcement operation, 1 OIREQ, 2 VREQs, and 1 s166 review.

CFPB

The CFPB finalized a rule defining larger participants in the general-use digital consumer payment applications market, enabling supervision of nonbanks with 50 million or more annual transactions. This rule was published around November 2024.

FCA

The FCA published updated guidance on its approach to payment services and electronic money in November 2024, reflected in tracked-changes revisions to its 2017 approach document.

FCA

Unknown Payment Institution

Enforcement Operation

The FCA opened one enforcement operation against a Payment Institution in 2024, as disclosed in its November 2024 FOI data. The specific institution and details of the enforcement were not publicly named.

FDIC

Sutton Bank

Consent Order

Sutton Bank faced FDIC examination and potential enforcement action related to its bank-fintech relationships. CEO J. Anthony Gorrell was reportedly involved in the heightened oversight.

BaFin

Solaris

Regulatory Oversight/Special Monitor

BaFin extended its special monitor mandate over German BaaS provider Solaris, requiring the company to obtain regulatory approval before onboarding new clients. The oversight dates back to 2022 and reflects ongoing concerns about the BaaS model following the Wirecard scandal.

FCA

The FCA fined Sigma Broking Limited £1,087,300 for transaction reporting failures. The base fine was doubled and a 40% aggravation increase was applied due to repeat offenses and failure to self-report.

OCC, FDIC, Federal Reserve

Industry-Wide

Guidance / Request for Information

The OCC, FDIC, and Federal Reserve issued a Request for Information seeking public comments on risks in bank-fintech arrangements, including accountability gaps, end-user confusion, rapid growth, concentration, liquidity, and data ownership.

OCC, Federal Reserve, FDIC

N/A — Industry-wide joint statement

Guidance / Joint Statement

The OCC, Federal Reserve, and FDIC jointly issued a statement on July 25, 2024, highlighting risks in third-party arrangements for bank deposit products and services. The statement emphasizes that banks retain full accountability for consumer protection, financial crimes prevention, and safe/sound practices despite outsourcing to fintechs.

NYDFS

NYDFS adopted Insurance Circular Letter No. 7 on July 11, 2024, establishing detailed requirements for insurers' use of artificial intelligence systems and external consumer data in underwriting and pricing. The guidance mandates discrimination assessments, actuarial validity testing, governance frameworks, and third-party vendor oversight.

Showing 145168 of 239