NYDFS established a prior approval requirement for virtual currency activities in 2022, requiring regulated entities to obtain approval before engaging in new or significantly different virtual currency-related business activities.
Regulatory Tracker
Regulatory Tracker — Page 9 of 11
Archive of enforcement actions, consent orders, and supervisory guidance impacting the BaaS and embedded finance ecosystem.
Subscribe to alerts11 different entities (crypto-related)
Desist and Refrain OrdersIn October 2022, the DFPI issued desist and refrain orders against 11 entities — nine crypto trading schemes, one DeFi platform, and one additional entity — for securities violations related to crypto activities.
Nexo Group
Desist and Refrain OrderThe California DFPI joined seven other states in a multi-state action against Nexo for offering its Earn Interest Product as unregistered securities via crypto deposit accounts. The desist and refrain order was issued on September 26, 2022.
Blue Ridge Bank
Formal AgreementBlue Ridge Bancorp operated under a 2022 OCC formal agreement requiring improvements to BSA/AML compliance and third-party risk management. The order required OCC non-objection before onboarding new fintech partners or offering new products through existing third-party relationships.
Unknown Sponsor Bank
GuidanceThe OCC outlined supervisory expectations for banks' use of artificial intelligence, relevant to BaaS platforms leveraging AI in lending and compliance. The guidance established standards for AI risk management in banking.
FinWise Bank
Cross-complaint (True Lender enforcement action)The California DFPI filed a cross-complaint against OppFi in April 2022, alleging that OppFi—not its partner FinWise Bank—was the 'true lender' on high-interest loans, thereby violating California's 36% interest rate cap under AB 539. On February 24, 2026, a Los Angeles County Superior Court granted summary judgment in favor of OppFi, rejecting the DFPI's true lender theory.
Unknown Sponsor Bank
GuidanceThe Financial Stability Board (FSB) issued observations in 2022 highlighting risks from Big Tech and fintech outsourcing to traditional banks, noting that complex structures complicate supervision of third-party fintech services.
Unknown Sponsor Bank
GuidanceThe CFPB announced on March 16, 2022, that it would leverage its UDAAP authority to prohibit discrimination in noncredit products such as deposits and payments. This guidance affects banks and their fintech partners offering these products.
Unknown Sponsor Bank
Initiative/InvestigationThe Department of Justice initiated redlining investigations using HMDA data, targeting banks and non-depository lenders—including potential fintech collaborators—for mortgage discrimination. The initiative bypasses prudential regulators in pursuing fair lending violations.
SoFi Bank, National Association
Conditional Charter ApprovalThe OCC conditionally approved SoFi's national bank charter, subjecting the fintech-turned-bank to full federal supervision. The approval included restrictions on crypto activities to ensure safe deposit and lending practices.
Unknown Sponsor Bank
GuidanceGLBA Safeguards Rule amendments became effective in January 2022 with a compliance deadline of December 2022. The amendments expanded coverage to 'finders' in fintech and mandated qualified overseers for information security programs.
Blue Ridge Bank
Consent OrderThe OCC issued a consent order against Blue Ridge Bank for unsafe practices in its BaaS program involving approximately 50 fintech partners. The order required improvements in third-party fintech oversight, AML/SAR compliance, and IT controls, and remained active into late 2023.
Wheels Financial Group, LLC d/b/a LoanMart
Consent OrderCalifornia DFPI issued a consent order against Wheels Financial Group (LoanMart), an auto title loan servicer, following a 'true lender' investigation into its partnership with a Utah state-chartered bank to potentially evade interest rate caps. LoanMart agreed not to market or service high-interest loans under $10,000 through state-chartered banks.
CommunityBank of Texas, N.A.
Civil Money PenaltyFinCEN assessed an $8 million civil money penalty against CommunityBank of Texas (CBOT) for willful AML program deficiencies spanning 2015–2019. The bank received a $1 million credit for a prior OCC penalty related to the same conduct.
Nano Banc
Cease and DesistCalifornia DFPI issued a cease-and-desist order against Nano Banc, a fintech-chartered bank, for making unapproved management changes that violated a prior consent order. The action addresses governance and compliance failures.
Viola Money (Europe) Limited
Cease and DesistThe FCA imposed requirements on Viola Money (Europe) Limited, an authorised electronic money institution, to cease all regulated electronic money and payment services on 14 December 2021 due to serious concerns about its business operations and client dealings.
The Bank of Lithuania imposed a €65,000 penalty on European Merchant Bank for failing to manage risks of high-risk clients and other AML violations. The regulator also restricted its ability to serve existing and new payment institutions.
Unknown Sponsor Bank
GuidanceFFIEC released its third 2021 update to the BSA/AML Examination Manual on December 1, 2021. The update added examiner evaluations for risks from charities/non-profits, PEPs, and independent ATM operators.
Trustmark National Bank
Civil Money Penalty / Consent OrderThe DOJ, CFPB, and OCC settled a redlining lawsuit against Trustmark National Bank, a Mississippi-based national bank, imposing a $4 million OCC penalty for violations of the Fair Housing Act.
Unknown Sponsor Bank
Proposed RuleThe CFPB published a proposed rule on small business lending data collection under the Equal Credit Opportunity Act (Regulation B), with implications for fintech and bank-fintech lending partnerships.
JPay LLC
Consent OrderThe CFPB issued a consent order against JPay LLC for violations of the Electronic Fund Transfer Act (EFTA). JPay handles payment services for incarcerated individuals.
Industry-Wide
GuidanceThe FFIEC issued updated authentication guidance for internet-based financial services on August 11, 2021. The guidance emphasizes risk assessments, layered security including multi-factor authentication, and customer waivers to mitigate unauthorized transaction liability.
Industry-Wide
GuidanceThe Federal Reserve published a guide in August 2021 for community banks on conducting due diligence for fintech third-party relationships. The guide covers legal compliance, risk management processes, contract provisions for audits, and consumer protection alignment.
Lyka
Cease and DesistThe Bangko Sentral ng Pilipinas (BSP) ordered Lyka to suspend its payment system operations and register with the central bank. The action targeted Lyka's unregistered payment system activities.