Regulatory Tracker

Regulatory Tracker — Page 8 of 11

Archive of enforcement actions, consent orders, and supervisory guidance impacting the BaaS and embedded finance ecosystem.

Subscribe to alerts
OCC, Federal Reserve, FDIC

N/A — Industry-wide joint statement

Guidance / Joint Statement

The OCC, Federal Reserve, and FDIC jointly issued a statement on July 25, 2024, highlighting risks in third-party arrangements for bank deposit products and services. The statement emphasizes that banks retain full accountability for consumer protection, financial crimes prevention, and safe/sound practices despite outsourcing to fintechs.

NYDFS

NYDFS adopted Insurance Circular Letter No. 7 on July 11, 2024, establishing detailed requirements for insurers' use of artificial intelligence systems and external consumer data in underwriting and pricing. The guidance mandates discrimination assessments, actuarial validity testing, governance frameworks, and third-party vendor oversight.

Federal Reserve

Evolve Bank & Trust

Cease and Desist

The Federal Reserve issued a joint cease-and-desist consent order against Evolve Bank & Trust, in coordination with the Arkansas State Bank Department, for inadequate risk management of third-party fintech partnerships. The order cited deficiencies in AML compliance, consumer compliance, and fraud risk oversight.

CFPB

The Bancorp Bank

Consent Order

The CFPB issued a $3.25M consent order against Chime Financial for illegal overdraft fee practices on deposit accounts held through partner banks The Bancorp Bank and Stride Bank.

CFPB

BloomTech, Inc.

Consent Order

CFPB issued a consent order against BloomTech, Inc. for originating 11,000+ income share agreements (ISAs) that violated TILA/Regulation Z, UDAAP, and the FTC Holder Rule. BloomTech was fined $64,235 (entity) and $100,000 (CEO), barred from consumer lending, and ordered to rescind ISAs.

OCC

The OCC entered into a Formal Agreement with The First National Bank of St. Ignace for weaknesses in capital planning, stress testing, strategic planning, and dividend payment violations.

OCC

Blue Ridge Bank, N.A.

Cease and Desist Order

The OCC issued a Cease and Desist Order against Blue Ridge Bank, N.A. for unsafe or unsound practices, including BSA/AML deficiencies, capital ratio issues, strategic planning failures, liquidity risk management weaknesses, and IT control deficiencies. This order superseded a prior formal agreement from August 2022.

RBI

Paytm Payments Bank

Cease and Desist

The RBI barred Paytm Payments Bank from onboarding new customers and restricted basic payment services including UPI, effective February 29, 2024, due to persistent non-compliance including KYC lapses and suspicious transactions linked to potential money laundering.

NYDFS

NYDFS imposed an $8 million penalty on Genesis Global Trading for cybersecurity and virtual currency regulation violations. Genesis surrendered its BitLicense and ceased operations in New York.

FTC

FloatMe Corp.

Complaint

The FTC filed a complaint in January 2024 against FloatMe, a fintech offering subscription cash advance products, alleging deception, subscription-related violations, and ECOA violations for discriminating against recipients of public assistance income.

FDIC

Cross River Bank

Consent Order

Cross River Bank faced regulatory penalties for fintech partnership oversight failures prior to 2024. The action prompted calls for stricter oversight and enhanced compliance requirements for the bank's fintech relationships.

OCC

Blue Ridge Bank

Consent Order

Blue Ridge Bank received a second OCC consent order in 2024 related to ongoing monitoring deficiencies in its fintech partnerships. The bank had already shed over a dozen fintech partners in response to regulatory pressure.

CFPB

Atlantic Union Bank

Consent Order

The CFPB issued a consent order against Atlantic Union Bank in December 2023 for failures in obtaining and documenting consumer affirmative consent for regulated overdraft services during 2017–2020. The order required new phone opt-in procedures including sending disclosures and obtaining signatures.

FDIC

First Fed Bank

Consent Order

The FDIC issued a consent order against First Fed Bank for unsafe practices, deceptive acts, and FTC Act violations stemming from its joint venture with fintech Quin Ventures. The bank was cited for misrepresenting credit products as unemployment insurance, approving unqualified consumers, and inaccurate fee disclosures.

CFPB

The CFPB fined Enova International $15 million for violating a 2019 consent order through unauthorized debits, failure to honor extensions, and misrepresentations under the Consumer Financial Protection Act. Enova faced a 7-year ban on certain short-term loans.

FDIC

Discover Financial Services

Consent Order (Proposed)

Discover Financial faced an FDIC probe prompting a leadership shift and enhanced risk and compliance efforts. CEO Roger Hochschild departed amid the investigation, with interim leadership appointed.

OCC

N/A — OCC internal reorganization

Organizational Announcement

The OCC established a new Office of Financial Technology in early 2023 to enhance supervisory expertise on digital assets, fintech partnerships, and emerging business models affecting OCC-supervised banks.

Bank of Lithuania

PayrNet (Railsr subsidiary)

Cease and Desist / Restrictions

The Bank of Lithuania imposed restrictions on PayrNet, a subsidiary of British BaaS provider Railsr, after finding gross and systematic AML violations. Grant Thornton Baltic was appointed to monitor mandatory AML improvements.

CFPB

The CFPB proposed a rule in February 2023 to create a registry for supervised nonbanks that use restrictive form contracts, signaling heightened scrutiny of nonbank fintech practices. The rule targeted terms and conditions that seek to waive consumer rights.

BaFin

Solaris

Cease and Desist

BaFin banned Solaris from entering new partnerships without regulatory approval and ordered AML-related upgrades. The BaaS provider was also required to observe transfer and cash payment limits for certain accounts.

NYDFS

Coinbase

Consent Order

The NY Department of Financial Services issued a consent order against Coinbase on January 4, 2023, for deficiencies in BSA/AML, KYC/CDD, transaction monitoring, and OFAC compliance. The order required remediation via an independent consultant and built on a prior MOU from February 2022.

CFPB

The CFPB fined ACI Worldwide $25 million in 2023 for processing $2.3 billion in unlawful payments tied to mortgage servicer Mr. Cooper, which caused overdraft fees for consumers. Banks remain liable for such third-party vendor failures.

FDIC

The FDIC published a rule on official sign and advertising requirements, false advertising, and misrepresentation of insured status in December 2022. The rule addresses how FDIC insurance status must be communicated, particularly relevant to fintech-bank deposit arrangements.

Showing 169192 of 241