Skip to content
RiskTemplates · The Daily Brief Tuesday, August 4, 2026
Wire Gotbit SEC Settlement: The Crypto Wash-Trading Controls That Matter Now AUG 3

Feature Third-Party Risk

Your Bank Partner Just Got an OCC Consent Order. What Happens to Your Fintech Program.

In May 2026, the OCC made public a consent order against Community Federal Savings Bank for BSA/AML deficiencies tied to fintech-partner payment processing growth—wire, ACH, and cross-border volume the bank couldn't supervise. Fintechs whose programs run through enforcement-action banks face program pause, enhanced scrutiny, or termination. Here's what your TPRM program needs to monitor.

By Rebecca Leung · August 2, 2026 ·
Table of Contents

TL;DR

  • In May 2026, the OCC made public a consent order against Community Federal Savings Bank for BSA/AML deficiencies driven by fintech-partner payment processing growth—wire, ACH, and cross-border volume the bank couldn’t adequately supervise
  • The OCC stated the concerns were “largely unrelated to digital assets”—payment processing volume alone triggered the action
  • When your bank partner gets an enforcement action, your fintech program faces enhanced scrutiny, potential volume restrictions, or termination—regardless of the quality of your own controls
  • Separately, the Bilt/Wells Fargo case (CFPB, June 2026) shows that bank partners can also exit early—and the CFPB holds the fintech responsible for customer harm during the transition
  • Your TPRM program should treat your bank partner’s exam record, enforcement history, and program capacity as active monitoring metrics

Most fintech TPRM programs are designed around a specific threat model: the vendor fails, goes under, or gets breached, and the fintech has to manage the consequence. What fewer programs model is the scenario where the bank partner is the regulated entity that gets an enforcement action—and the fintech program gets caught in the remediation fallout.

May 2026 provided a clear case study. So did June 2026. They point in opposite directions: one shows what happens when a bank absorbs too much fintech-driven risk, the other shows what happens when a bank exits the partnership entirely.

The CFSB Case: When BaaS Volume Outgrows BSA/AML Controls

On May 21, 2026, the OCC made public a consent order (docket AA-ENF-2025-21) entered in April 2026 against Community Federal Savings Bank, a federal savings association based in Woodhaven, New York.

The core finding: since 2020, CFSB had significantly expanded its payment processing business relative to its size, resulting in substantial annual wire and ACH activity—including cross-border activity involving foreign financial institutions. The bank’s compliance infrastructure did not grow with it.

Specific deficiencies the OCC cited:

  • Alert thresholds not calibrated to actual risk. The bank’s automated transaction monitoring system was configured for a different risk profile than the payment processing volume it was processing. Alerts were not tuned for the patterns associated with the fintech-originated wire and ACH transactions running through the bank.
  • Deficient SAR monitoring. The alert triage process failed to identify suspicious activity patterns that should have generated Suspicious Activity Reports. Automated alert triage failures compounded the problem.
  • Inadequate customer due diligence. CDD processes were not calibrated for the risk level of the bank’s payment processing customer base.
  • Weak independent testing. Internal audit and compliance testing failed to surface the monitoring gaps that examiners found. Independent testing is supposed to be the backstop; here it wasn’t.
  • Inadequate staffing. BSA compliance resources did not scale with transaction volume.

The OCC consent order includes a remediation plan requiring a compliance committee with quarterly board reporting, a written remediation plan, an independent third-party consultant to review BSA/AML controls, improved independent testing, and adequate staffing and training.

One sentence in the order stands out: concerns were “largely unrelated to customers involved in digital assets activities.” That’s the OCC pre-empting the inference that this is a crypto-adjacent problem. It isn’t. Payment processing volume—wires, ACH, cross-border transfers—is the issue. The United Texas Bank enforcement action from the same period was crypto-driven. CFSB is the non-crypto version of the same pattern: rapid volume growth, static controls.

What This Means If Your Fintech Runs Through a Bank Like CFSB

The OCC’s enforcement action is against the bank. But the operational consequences land on the fintech programs running through it.

Here’s how the sequence typically unfolds:

Immediate: The bank’s compliance committee—required by the consent order—begins assessing which programs contributed to the deficiencies. Fintech programs that drove high wire or ACH volume, or programs with cross-border exposure, are reviewed first.

30–90 days: The bank may impose enhanced due diligence requirements on fintech partners. This means additional documentation requests: transaction monitoring configurations, alert disposition rates, SAR filing history, CDD procedures, independent testing schedules. These are your documentation, but the bank is the one with the OCC to answer to.

60–180 days: Volume restrictions may be imposed on programs the bank determines contributed elevated compliance risk. New account approvals, new product launches, or transaction volume caps may be subject to OCC-level approval before the bank lifts them.

If the remediation plan identifies your program as a contributing risk factor: Program termination is possible. This isn’t theoretical—Blue Ridge Bank’s 2023 FDIC enforcement action resulted in it winding down or significantly restricting multiple fintech partnerships as part of its remediation.

The specific outcome depends on your program’s risk profile and what the OCC’s remediation requirements focus on. But the threshold insight is: your program’s fate is partly determined by a process you have no seat at.

The Bilt Case: When the Bank Is the One Leaving

If the CFSB case is about what happens when a bank accumulates too much fintech risk, the Bilt/Wells Fargo case is the mirror image: what happens when the bank decides to exit the partnership early.

Bilt Rewards launched its rent-rewards credit card with Wells Fargo as the issuing bank in 2022. The partnership was structured to run through 2029. Wells Fargo ended it early—reportedly because the card economics weren’t working for the bank.

When Wells Fargo deactivated its version of the Bilt card in February 2026, Bilt transitioned to Column Bank and Cardless as new partners. The transition failed operationally: rent and mortgage payments were debited from customer accounts but never delivered to landlords or lenders. Card declines, frozen accounts, and missing statements followed. For a card marketed specifically around rent payment, the failure hit the product’s core value proposition.

The CFPB reviewed Bilt’s corrective measures and directed full redress for affected consumers. By June 4, 2026, Bilt had paid back overdraft fees, late fees, and insufficient funds fees to more than 500 affected customers. The CFPB elected not to pursue a formal public enforcement action after confirming remediation had been completed.

The regulatory signal: when a fintech’s bank partner relationship fails and customers get hurt, the CFPB holds the fintech responsible for remediation—not the bank that exited, and not a force majeure event outside anyone’s control.

The Exam Record as a TPRM Metric

Your bank partner’s public enforcement history is information your TPRM program should be monitoring actively, not finding out about through the news.

OCC enforcement actions are published at occ.gov. FDIC actions are at fdic.gov. Federal Reserve actions are at federalreserve.gov. These are public records—no FOIA required, no attorney relationship needed. A quarterly check of your bank partner names in each database takes less than an hour.

Beyond public enforcement actions, the TPRM lifecycle framework assigns monitoring responsibilities across the relationship lifecycle. For bank partner relationships, ongoing monitoring should include:

Monitoring ItemFrequencyOwner
Public enforcement action check (OCC, FDIC, Fed)QuarterlyCentral TPRM
Bank’s exam cycle and last examination dateAnnuallyRelationship Manager
Bank’s fintech portfolio size and growth rateAnnually (due diligence refresh)Risk/Compliance
Bank’s BSA/AML staffing relative to fintech-driven volumeAnnual assessmentRisk/Compliance
Contract audit rights and notification provisionsAnnual legal reviewLegal
Exit strategy refresh (successor institutions)AnnuallyRisk/Compliance + Legal

The first item is the one most consistently skipped. It’s also the one that would have flagged CFSB before programs were affected.

Contractual Provisions That Determine What Happens to You

When a bank receives an enforcement action, what happens to your fintech program is partly determined by what your bank partner agreement says.

Look at your current agreement for:

Regulatory notification obligation. Does the bank agree to notify you of material regulatory actions—consent orders, MRAs, cease and desist orders—within a specified period? Many bank partner agreements don’t require this. If yours doesn’t, you may find out about an enforcement action from the OCC press release, not from your relationship manager.

Termination for cause vs. for convenience. Can the bank terminate your program for any reason, or only for specified cause? If the agreement allows for-convenience termination, the bank’s decision to exit a fintech program as part of an enforcement action remediation plan may require minimal notice.

Volume restriction rights. Does the bank have the right to limit transaction volume or new account approvals without your consent? During an enforcement action remediation period, this becomes material.

Audit rights (both directions). The OCC’s 2023 interagency TPRM guidance requires banks to have audit rights over fintech partners. Your agreement should also give you visibility into the bank’s BSA/AML program performance—or at least require notification when the bank is subject to a regulatory finding related to your program.

Your vendor contract and due diligence review process should be applied to bank partner agreements with this lens: what does this contract say about what happens to my program if the bank is under regulatory pressure?

Exit Strategy: The Documentation You Need Before You Need It

The CFSB and Bilt cases together establish what a mature bank partner exit strategy looks like. You need documentation for two distinct scenarios:

Scenario 1: The bank gets enforcement action and restricts or terminates your program. Your exit strategy document should identify: (a) pre-qualified successor institutions, including any preliminary due diligence completed; (b) the minimum transition timeline from termination notice to operational readiness with a successor; (c) which product features would stop working during a transition period; and (d) how you would notify affected customers.

Scenario 2: The bank exits the partnership voluntarily. The Bilt case added specificity to what this scenario’s documentation should cover: a tested customer remediation procedure, including how to identify affected customers, what fees you would refund, and who in your organization owns customer communication.

The fourth-party risk dimension matters in both scenarios: if your likely successor bank partner uses a different core processor or card network than your current bank, the transition timeline must account for those additional vendor onboarding sequences. Bilt’s transition involved a new bank (Column) and a new card servicer (Cardless) simultaneously—the operational complexity doubled.

So What?

The OCC’s CFSB consent order is a textbook illustration of what has been building in fintech-bank enforcement since 2022: regulators hold the charter-holding bank accountable for all volume running through it. The bank’s BSA/AML program must be calibrated to the actual risk of that volume—not the risk at launch, not the risk at the last exam cycle.

For fintechs, this creates a dependency that requires active risk management, not passive trust. Your bank partner’s exam record, its compliance staffing relative to fintech-driven volume, its contract provisions around notification and termination—these are operational risk inputs, not legal background.

The TPRM kit’s bank partner monitoring module includes templates for tracking public enforcement actions, documenting exit strategy readiness, and maintaining the annual bank partner reassessment that regulatory examiners increasingly expect to see.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What happened with Community Federal Savings Bank's OCC consent order in 2026?
On May 21, 2026, the OCC made public a consent order (AA-ENF-2025-21) entered in April 2026 against Community Federal Savings Bank (CFSB), Woodhaven, New York. The order cited BSA/AML deficiencies related to the bank's rapid expansion of payment processing through fintech partnerships—significant wire, ACH, and cross-border volume without commensurate compliance infrastructure. The OCC stated that the concerns were 'largely unrelated to customers involved in digital assets activities,' making clear that payment processing volume itself triggered the action.
What does a bank partner's OCC consent order mean for fintech programs running through that bank?
A bank consent order typically triggers one or more consequences for fintech partners: (1) enhanced due diligence requirements the bank imposes on fintech partners to satisfy the OCC's remediation plan; (2) program restrictions or pauses on new account approvals or volume expansion while the bank remediates; (3) possible direct regulatory review of fintech program controls as part of the bank's examination; or (4) program termination if the bank's remediation plan identifies specific fintech relationships as sources of elevated compliance risk.
What does OCC Bulletin 2023-17 require banks to maintain for third-party risk management?
OCC Bulletin 2023-17 (the June 2023 interagency TPRM guidance, also issued as FDIC FIL-29-2023 and Fed SR 23-4) requires banks to maintain TPRM governance proportionate to the risk of their third-party relationships, with heightened requirements for critical activities. For fintech partnerships through which the bank delivers products, examiners expect pre-engagement due diligence, ongoing monitoring with periodic reassessments, clear contracts with audit rights and termination provisions, and documented exit strategies. The CFSB consent order illustrates what happens when fintech-driven volume growth outpaces these controls.
What should a fintech do if its bank partner receives an enforcement action?
Immediate steps: (1) Read the full consent order text—OCC, FDIC, and Federal Reserve enforcement actions are published publicly; (2) Contact your bank relationship manager to understand how the order affects your specific program; (3) Document your own BSA/AML controls, especially transaction monitoring thresholds and alert disposition processes; (4) Assess whether you can sustain your program through a bank remediation period that may include volume restrictions; (5) Review your exit strategy and evaluate whether pre-identified successor institutions are still viable.
What is the broader BaaS bank enforcement pattern in 2026?
The CFSB consent order is part of a documented pattern: Blue Ridge Bank (FDIC, 2023), Piermont Bank, and United Texas Bank (OCC C&D, June 2026) all received enforcement actions in which fintech-driven payment volume growth outpaced BSA/AML compliance infrastructure. The common thread is rapid expansion in wire, ACH, or crypto transaction volume without proportionate monitoring, staffing, and independent testing. Regulators hold the charter-holding bank accountable for all volume running through it—regardless of whether a fintech partner originated the transactions.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.