Regulatory Tracker

Regulatory Tracker — Page 9 of 11

Archive of enforcement actions, consent orders, and supervisory guidance impacting the BaaS and embedded finance ecosystem.

Subscribe to alerts
NYDFS

NYDFS established a prior approval requirement for virtual currency activities in 2022, requiring regulated entities to obtain approval before engaging in new or significantly different virtual currency-related business activities.

DFPI

In October 2022, the DFPI issued desist and refrain orders against 11 entities — nine crypto trading schemes, one DeFi platform, and one additional entity — for securities violations related to crypto activities.

DFPI

Nexo Group

Desist and Refrain Order

The California DFPI joined seven other states in a multi-state action against Nexo for offering its Earn Interest Product as unregistered securities via crypto deposit accounts. The desist and refrain order was issued on September 26, 2022.

OCC

Blue Ridge Bank

Formal Agreement

Blue Ridge Bancorp operated under a 2022 OCC formal agreement requiring improvements to BSA/AML compliance and third-party risk management. The order required OCC non-objection before onboarding new fintech partners or offering new products through existing third-party relationships.

OCC

The OCC outlined supervisory expectations for banks' use of artificial intelligence, relevant to BaaS platforms leveraging AI in lending and compliance. The guidance established standards for AI risk management in banking.

California DFPI

FinWise Bank

Cross-complaint (True Lender enforcement action)

The California DFPI filed a cross-complaint against OppFi in April 2022, alleging that OppFi—not its partner FinWise Bank—was the 'true lender' on high-interest loans, thereby violating California's 36% interest rate cap under AB 539. On February 24, 2026, a Los Angeles County Superior Court granted summary judgment in favor of OppFi, rejecting the DFPI's true lender theory.

FSB

The Financial Stability Board (FSB) issued observations in 2022 highlighting risks from Big Tech and fintech outsourcing to traditional banks, noting that complex structures complicate supervision of third-party fintech services.

CFPB

The CFPB announced on March 16, 2022, that it would leverage its UDAAP authority to prohibit discrimination in noncredit products such as deposits and payments. This guidance affects banks and their fintech partners offering these products.

DOJ

Unknown Sponsor Bank

Initiative/Investigation

The Department of Justice initiated redlining investigations using HMDA data, targeting banks and non-depository lenders—including potential fintech collaborators—for mortgage discrimination. The initiative bypasses prudential regulators in pursuing fair lending violations.

OCC

SoFi Bank, National Association

Conditional Charter Approval

The OCC conditionally approved SoFi's national bank charter, subjecting the fintech-turned-bank to full federal supervision. The approval included restrictions on crypto activities to ensure safe deposit and lending practices.

FTC

GLBA Safeguards Rule amendments became effective in January 2022 with a compliance deadline of December 2022. The amendments expanded coverage to 'finders' in fintech and mandated qualified overseers for information security programs.

OCC

Blue Ridge Bank

Consent Order

The OCC issued a consent order against Blue Ridge Bank for unsafe practices in its BaaS program involving approximately 50 fintech partners. The order required improvements in third-party fintech oversight, AML/SAR compliance, and IT controls, and remained active into late 2023.

California DFPI

California DFPI issued a consent order against Wheels Financial Group (LoanMart), an auto title loan servicer, following a 'true lender' investigation into its partnership with a Utah state-chartered bank to potentially evade interest rate caps. LoanMart agreed not to market or service high-interest loans under $10,000 through state-chartered banks.

FinCEN

CommunityBank of Texas, N.A.

Civil Money Penalty

FinCEN assessed an $8 million civil money penalty against CommunityBank of Texas (CBOT) for willful AML program deficiencies spanning 2015–2019. The bank received a $1 million credit for a prior OCC penalty related to the same conduct.

California DFPI

Nano Banc

Cease and Desist

California DFPI issued a cease-and-desist order against Nano Banc, a fintech-chartered bank, for making unapproved management changes that violated a prior consent order. The action addresses governance and compliance failures.

FCA

The FCA imposed requirements on Viola Money (Europe) Limited, an authorised electronic money institution, to cease all regulated electronic money and payment services on 14 December 2021 due to serious concerns about its business operations and client dealings.

Bank of Lithuania

The Bank of Lithuania imposed a €65,000 penalty on European Merchant Bank for failing to manage risks of high-risk clients and other AML violations. The regulator also restricted its ability to serve existing and new payment institutions.

FinCEN

FFIEC released its third 2021 update to the BSA/AML Examination Manual on December 1, 2021. The update added examiner evaluations for risks from charities/non-profits, PEPs, and independent ATM operators.

OCC

Trustmark National Bank

Civil Money Penalty / Consent Order

The DOJ, CFPB, and OCC settled a redlining lawsuit against Trustmark National Bank, a Mississippi-based national bank, imposing a $4 million OCC penalty for violations of the Fair Housing Act.

CFPB

The CFPB published a proposed rule on small business lending data collection under the Equal Credit Opportunity Act (Regulation B), with implications for fintech and bank-fintech lending partnerships.

CFPB

JPay LLC

Consent Order

The CFPB issued a consent order against JPay LLC for violations of the Electronic Fund Transfer Act (EFTA). JPay handles payment services for incarcerated individuals.

FFIEC

The FFIEC issued updated authentication guidance for internet-based financial services on August 11, 2021. The guidance emphasizes risk assessments, layered security including multi-factor authentication, and customer waivers to mitigate unauthorized transaction liability.

Federal Reserve

The Federal Reserve published a guide in August 2021 for community banks on conducting due diligence for fintech third-party relationships. The guide covers legal compliance, risk management processes, contract provisions for audits, and consumer protection alignment.

BSP (Bangko Sentral ng Pilipinas)

Lyka

Cease and Desist

The Bangko Sentral ng Pilipinas (BSP) ordered Lyka to suspend its payment system operations and register with the central bank. The action targeted Lyka's unregistered payment system activities.

Showing 193216 of 241