From the original research pack. This draft has not received a complete claim-by-claim review. Fees, product terms, statistics and legal status may have changed. Its preparation date is not a publication date. Use the linked original sources.

For a few years, launching a debit card or a "bank account" inside an app took little more than an API key and a revenue-share contract. Then regulators started issuing orders against the small banks behind those apps, and one middleware company's collapse left real people unable to reach their money. This post explains what those enforcement actions said, what changed in how bank-fintech partnerships work, and where things stand as of September 17, 2026.

Key takeaways

  • Between 2022 and 2024, federal regulators issued a string of formal actions against banks that powered fintech programs, focusing on anti-money-laundering controls and oversight of fintech partners [1][2][3][4].
  • Orders required transaction lookbacks, stronger partner oversight, and in some cases regulator sign-off before adding new fintech partners or products [2][10].
  • The 2024 Synapse bankruptcy showed that FDIC "pass-through" insurance does not protect you when a non-bank middleman's records fail; the CFPB later set aside about $46 million from its civil penalty fund for affected consumers [5][6].
  • Since late 2025, some orders have been lifted (for example, Blue Ridge Bank's OCC consent order), but new ones still appear, such as the OCC's April 24, 2026 consent order against Community Federal Savings Bank [7][8][11].
  • The lasting change is operational: direct bank relationships, daily reconciliation, and fintech compliance programs that a bank can audit.

First, some definitions

Banking-as-a-service (BaaS) is an arrangement where a chartered bank lets a non-bank company offer bank products, such as deposit accounts, debit cards, or loans, under the non-bank's brand. The bank holds the deposits and the legal responsibility; the fintech owns the customer experience.

Sponsor bank (or partner bank): the chartered bank in that arrangement. Many are community banks with under $10 billion in assets, partly because smaller banks can earn higher debit card interchange fees under the Durbin Amendment. Related field note

Middleware: a technology company that sits between the bank and many fintechs, providing APIs, ledgers, and sometimes compliance tooling. Synapse Financial Technologies was one.

FBO account: a "for benefit of" or custodial account at the bank. Many customers' money is pooled in one account, and a separate ledger (often kept by the fintech or middleware) tracks who owns what.

Consent order: a formal, legally enforceable agreement between a bank and its regulator in which the bank agrees to fix specific problems. A cease-and-desist order is similar. Both are public, unlike most supervisory findings. Banks agree to them without necessarily admitting wrongdoing.

Related field note

The enforcement wave, 2022–2024

Several of the banks best known for fintech partnerships received formal actions in a short window. The details differ, but the themes repeat: Bank Secrecy Act and anti-money-laundering (BSA/AML) compliance, "know your customer" gaps, and weak oversight of the fintech partners that were onboarding customers on the bank's behalf.

Bank Regulator Action Timing Main themes (per order coverage)
Blue Ridge Bank OCC Consent order (after an earlier agreement) Order entered roughly two years before its November 2025 termination [7][8] BSA/AML and fintech partner oversight
Cross River Bank FDIC Consent order March 2023 (made public May 2023) [10] Fair lending; FDIC non-objection required for new fintech partnerships and credit products
Sutton Bank; Piermont Bank FDIC Consent orders February 1, 2024 (Sutton); February 26, 2024 (Piermont) [2] BSA/AML, transaction lookbacks, third-party (BaaS) partner oversight
Evolve Bank & Trust Federal Reserve, with the Arkansas State Bank Department Enforcement action announced June 14, 2024 [3][4] AML, risk management, and consumer compliance for fintech partnerships
Community Federal Savings Bank OCC Consent order April 24, 2026 [11] Suspicious-activity monitoring and BSA/AML controls that did not keep pace with payments growth

Table note: this is a selection, not a complete list. Timing and themes are drawn from regulator releases and trade-press coverage cited; check each order on the regulator's enforcement search for full terms. Explore the payment path

What the orders typically required

Reading across coverage of these orders, the common requirements were:

  • Prior approval for growth. Cross River's order, for example, required FDIC non-objection before any new fintech partnership or credit product [10]. For a fintech waiting to launch, that kind of condition can mean an open-ended delay.
  • Lookbacks and independent reviews. Piermont had to review transactions since September 2022 for suspicious activity reporting, and Sutton had to review prepaid card customers back to July 2020 [2]. The OCC's 2026 Community Federal order requires an independent consultant review of suspicious-activity monitoring [11], and commentators said a 2026 OCC order signaled regulators want access to consultant work product [12].
  • Third-party risk programs. Banks had to inventory partnerships, assign accountable staff per program, and show they could monitor each partner's compliance, not just rely on contracts [2].
  • Board accountability. Boards had to adopt and oversee written action plans.

Notably, the OCC's April 2026 order against Community Federal Savings Bank, which Banking Dive identified as a partner for Wise U.S. dollar accounts and Crypto.com prepaid cards, carried no monetary penalty, according to Fincrime Central [11][13]. Banking Dive reported the OCC found the bank's automated alert system had auto-closed "a very high percentage" of alerts [11]. Enforcement in this space has largely been about fixing controls and limiting growth rather than fines.

Synapse: the failure that changed the conversation

The enforcement wave was already underway when Synapse, a BaaS middleware firm, filed for bankruptcy in April 2024. End users of fintech apps built on Synapse found their accounts frozen, and reconciliations later showed a gap between what the ledgers said customers had and what the partner banks actually held. Related field note

Two lessons stood out:

  1. Pass-through insurance has limits. FDIC pass-through coverage can protect each customer's share of a pooled account if the bank fails and the records properly identify owners. It does not cover a fintech or middleware failure, or missing records.
  2. Ledgers are the product. When the "book of record" lives outside the bank, and nobody reconciles it daily, a failure can strand money even when the bank itself is sound.

The Consumer Financial Protection Bureau (CFPB) pursued Synapse in court, and after the bankruptcy case was dismissed, the Bureau moved to compensate harmed consumers from its Civil Penalty Fund. Reporting in December 2025 put that allocation at about $46 million [5][6][14]. Whether that fully covers losses has been disputed, and Bloomberg Law reported questions about use of the fund [15]. Readers should check the CFPB's site for current claims information.

The FDIC also proposed a rule in September 2024 (published October 2, 2024) that would require banks to keep direct records for custodial accounts with transactional features and reconcile them daily [16][17]. When the FDIC board rolled back several other proposals on March 3, 2025, a law firm noted the agency "has not withdrawn" the custodial accounts proposal [23]. As of September 17, 2026, we could not confirm a final rule or a later withdrawal; check the FDIC's rulemaking page before relying on it.

What changed in practice

1. Fewer middlemen, more direct relationships

After Synapse, many fintechs moved to contract directly with a bank, or chose BaaS providers where the bank sees and controls the ledger. Banks, for their part, became less willing to sponsor programs where they could not see end-customer-level data.

2. Banks pruned their partner lists

Banks under orders often had to slow or halt new partner onboarding, and some offboarded existing programs. For a fintech, the practical effect was forced migrations to new banks, which can mean new account numbers, new cards, and customer confusion.

3. Compliance moved closer to the fintech

Sponsor banks began expecting fintech partners to run real compliance programs: a BSA officer, transaction monitoring, complaint handling, and audit rights for the bank. Due diligence questionnaires grew longer, and launch timelines grew with them.

4. Pricing shifted

Higher compliance costs pushed up minimum fees and revenue shares that banks charge programs. Smaller, early-stage fintechs felt this most. (Specific pricing is private and varies widely; we have not seen reliable public benchmarks.)

5. Some fintechs decided to become banks

Getting a charter removes dependence on a sponsor bank. That is one driver of the 2025–2026 charter application wave. Related field note

2025–2026: a softer supervisory tone, but not a free pass

Since 2025, federal banking regulators have signaled a changed supervisory approach, and several orders have ended:

  • Blue Ridge Bank: the OCC terminated its consent order; the bank announced it in November 2025, nearly two years after the order was entered [7][8][18].
  • Other terminations: the OCC's monthly enforcement releases in 2026 routinely list terminated orders, though many involve traditional community banks rather than fintech partner banks; a March 2026 batch of four terminations reported by PYMNTS did not involve banks identified as BaaS sponsors [19][20]. The FDIC also publishes orders terminating earlier consent orders on its enforcement site [21].

But new actions have not stopped. The OCC's Community Federal Savings Bank consent order in April 2026 was read by law firms as "a warning for community banks in the fintech partnership space," specifically about growth outpacing compliance [9][22]. A termination means a bank satisfied its regulator; it does not by itself mean a bank's programs are lower-risk than a bank that was never under an order.

A practical checklist for founders and compliance teams

  • Look up your bank. Search the OCC, FDIC, and Federal Reserve enforcement databases and the bank's holding-company filings. Note whether any order restricts new partners.
  • Ask who holds the ledger. Does the bank maintain account-level records for each end user, and how often is the FBO account reconciled?
  • Read the pass-through disclosures. Make sure your marketing about FDIC insurance matches your structure. The FDIC's rules on misrepresenting insurance apply to non-banks too. Related field note
  • Plan for migration. Contract for data portability and a wind-down process in case your bank exits or is restricted.
  • Budget for compliance early. Expect your bank to audit your BSA/AML, complaints, and marketing review.

Explore the payment path

FAQ

What is a BaaS consent order? It is a public, enforceable agreement between a bank that offers banking services through fintech partners and its regulator, requiring specific fixes, often to anti-money-laundering controls and partner oversight.

Does a consent order mean my money at that bank is unsafe? Not by itself. Consent orders target compliance weaknesses; they are not a statement that the bank is failing. Your deposit insurance depends on the bank's status and proper recordkeeping, not on whether it has an order.

Did the Synapse customers get their money back? Partially. Banks returned some funds, and the CFPB allocated about $46 million from its Civil Penalty Fund for harmed consumers, according to December 2025 reporting [6][14]. Check the CFPB for current status.

Are regulators easing up on fintech partner banks? Some orders have been terminated since late 2025, and the supervisory tone has shifted, but new orders, like the April 2026 Community Federal Savings Bank action, show enforcement continues [7][11].

How can I find out which bank is behind my fintech app? Look at the app's footer disclosures, the account or cardholder agreement, or the back of your card. Related field note

Sources

  1. Ncontracts, "Financial Services Enforcement Action Tracker," https://www.ncontracts.com/enforcement-action-tracker (accessed 2026-09-17)
  2. Banking Dive, "Piermont, Sutton banks hit with FDIC consent orders over BaaS," https://www.bankingdive.com/news/piermont-sutton-bank-fdic-consent-orders-aml-bsa-baas-third-party-partners/711815/ (April 1, 2024; accessed 2026-09-17)
  3. Board of Governors of the Federal Reserve System, enforcement action press release, June 14, 2024, https://www.federalreserve.gov/newsevents/pressreleases/enforcement20240614a.htm (accessed 2026-09-17)
  4. Banking Dive, "Fed hits Synapse partner Evolve with enforcement action," https://www.bankingdive.com/news/federal-reserve-synapse-partner-evolve-enforcement-action-aml-risk-fintech-baas-compliance/719027/ (June 2024; accessed 2026-09-17)
  5. American Banker, "CFPB to refund $46 million to Synapse victims," https://www.americanbanker.com/news/cfpb-to-refund-46-million-to-synapse-victims (accessed 2026-09-17)
  6. Crowdfund Insider, "CFPB Allocates $46M To Victims Of Synapse Fintech Collapse," https://www.crowdfundinsider.com/2025/12/256754-cfpb-allocates-46m-to-victims-of-synapse-fintech-collapse/ (December 2025; accessed 2026-09-17)
  7. Banking Dive, "OCC terminates Blue Ridge Bank consent order," https://www.bankingdive.com/news/occ-terminates-blue-ridge-bank-consent-order/805617/ (accessed 2026-09-17)
  8. Richmond BizSense, "Blue Ridge Bank clears regulatory fog, released from OCC consent order after nearly two years," https://richmondbizsense.com/2025/11/24/blue-ridge-bank-clears-regulatory-fog-released-from-occ-consent-order-after-nearly-two-years/ (November 24, 2025; accessed 2026-09-17)
  9. Financial Services Perspectives (Bradley Arant Boult Cummings), "The OCC's Recent Consent Order Is a Warning for Community Banks in the Fintech Partnership Space," https://www.financialservicesperspectives.com/2026/06/the-occs-recent-consent-order-is-a-warning-for-community-banks-in-the-fintech-partnership-space/ (June 2026; accessed 2026-09-17)
  10. American Banker, "FDIC order against Cross River Bank is a warning on fintech alliances," https://www.americanbanker.com/news/fdic-consent-order-against-cross-river-bank-a-fintech-partnership-warning (May 1, 2023; accessed 2026-09-17)
  11. Banking Dive, "OCC cites AML deficiencies at NY bank that partners with fintechs," https://www.bankingdive.com/news/occ-community-federal-savings-bank-new-york-aml-bsa-sar-deficiencies-fintech-partner/821272/ (May 27, 2026; accessed 2026-09-17)
  12. Cullen and Dykman LLP, "OCC Consent Order Signals Increased Regulatory Access to Independent Consultant Work Product," https://www.cullenllp.com/blog/occ-consent-order-signals-increased-regulatory-access-to-independent-consultant-work-product/ (2026; accessed 2026-09-17)
  13. American Banker, "Sponsor bank for Wise, Crypto.com told to fix AML program," https://www.americanbanker.com/payments/news/sponsor-bank-for-wise-crypto-com-told-to-fix-aml-program (2026; accessed 2026-09-17); see also Fincrime Central, "Community Federal Savings Bank Faces OCC Action Imposing Zero Dollar Fine," https://fincrimecentral.com/community-federal-savings-bank-occ-aml-rule/
  14. American Banker, "Synapse bankruptcy dismissed, CFPB may start paying victims," https://www.americanbanker.com/news/synapse-bankruptcy-dismissed-cfpb-may-start-paying-victims (accessed 2026-09-17)
  15. Bloomberg Law, "CFPB Payments to Synapse Victims Clouded by Questions Over Fund," https://news.bloomberglaw.com/banking-law/cfpb-payments-to-synapse-victims-clouded-by-questions-over-fund (accessed 2026-09-17)
  16. Federal Register, "Recordkeeping for Custodial Accounts," https://www.federalregister.gov/documents/2024/10/02/2024-22565/recordkeeping-for-custodial-accounts (October 2, 2024; accessed 2026-09-17)
  17. Sullivan & Cromwell, "FDIC Proposes Recordkeeping and Reconciliation Requirements for Fintech Custodial Accounts," https://www.sullcrom.com/insights/memo/2024/September/FDIC-Proposes-Recordkeeping-Reconciliation-Requirements-Fintech-Custodial-Accounts (September 2024; accessed 2026-09-17)
  18. Blue Ridge Bankshares, "Blue Ridge Bankshares, Inc. Announces Termination of Consent Order," https://www.prnewswire.com/news-releases/blue-ridge-bankshares-inc-announces-termination-of-consent-order-302615056.html (November 2025; accessed 2026-09-17)
  19. OCC, "OCC Announces Enforcement Actions for May 2026," https://www.occ.gov/news-issuances/news-releases/2026/nr-occ-2026-40.html (accessed 2026-09-17)
  20. PYMNTS, "OCC Ends Restrictions on 4 Banks," https://www.pymnts.com/bank-regulation/2026/occ-ends-restrictions-on-4-banks/ (March 18, 2026; accessed 2026-09-17)
  21. FDIC, "Order Terminating Consent Order FDIC-24-0022b," https://orders.fdic.gov/sfc/servlet.shepherd/document/download/069SJ00000zQbYsYAK?operationContext=S1 (accessed 2026-09-17)
  22. Wagner Hicks PLLC, "When Fintech Growth Outpaces Compliance: What the OCC's Consent Order Against Community Federal Savings Bank Means for Your Institution," https://www.wagnerhicks.law/when-fintech-growth-outpaces-compliance/ (2026; accessed 2026-09-17)
  23. Steptoe, "FDIC Board of Directors Rolls Back Several Biden-Era Rulemaking Actions," https://www.steptoe.com/en/news-publications/fdic-board-of-directors-rolls-back-several-biden-era-rulemaking-actions.html (March 5, 2025; accessed 2026-09-17)

Last updated September 17, 2026. This article is for educational purposes only and is not financial, legal, tax, or investment advice. Enforcement actions can be modified or terminated at any time; verify current status directly with the OCC, FDIC, Federal Reserve, and CFPB, and confirm current terms with any provider.

KEEP THE THREAD GOINGRevoke an app’s access to your bank data →Build the dispute evidence file while fulfilling the order →Hosted checkout reduces PCI scope; it does not erase the merchant boundary →Return to the library →