Feature Compliance Strategy
X Money Picked a Sponsor Bank with an FDIC Consent Order. Read It Before Your Next BaaS Review.
Cross River Bank is X Money's banking backbone. Its 2023 FDIC consent order for unsafe or unsound fair lending practices is the BaaS case study every compliance team needs to work through.
Table of Contents
TL;DR
- X Money launched nationwide on July 27, 2026 with Cross River Bank (NJ, FDIC member) as its banking backbone — FDIC-insured deposits, 6% APY, metal Visa debit card.
- Cross River entered an FDIC consent order in March 2023 for unsafe or unsound fair lending practices in its fintech partner programs, requiring regulatory approval before adding new partners.
- X Payments holds money transmitter licenses in 41 states + D.C. — New York and Massachusetts are not yet covered.
- A sponsor bank’s enforcement history is a due diligence item, not background noise. Use this as the case study.
X Money went live on July 27, 2026. Elon Musk’s financial product is now available to X Premium and Premium+ subscribers across the U.S., offering a high-yield deposit account, a metal Visa debit card, and peer-to-peer payments — all inside the X app.
The banking backbone is Cross River Bank, a New Jersey-chartered FDIC-member institution that has been one of the most active BaaS partner banks in the country for years, facilitating fintech credit products through partnerships with major players in the consumer lending space. Now it is holding X Money deposits.
Cross River also has an FDIC consent order from March 2023.
That consent order — entered for unsafe or unsound fair lending practices related to its fintech partner lending programs — is a case study that every BaaS compliance team, on both the bank side and the fintech side, should work through before their next partner review.
What X Money actually is
X Money accounts are FDIC-insured through Cross River Bank, with up to $10 million in aggregate pass-through coverage via a cash sweep network. The product offers a 6% annual percentage yield and a metal Visa debit card. Peer-to-peer payments between X users and instant transfers to linked bank accounts are part of the initial rollout.
The product has two distinct regulatory layers:
Layer 1 — The bank layer. Cross River Bank holds the deposits. As an FDIC-member bank, it bears the bank-regulatory obligations that go with deposit-taking: BSA/AML, fair lending, CRA, consumer protection, and the regulatory capital requirements that constrain what it can do with deposited funds. The deposit accounts, the 6% APY, and the FDIC pass-through insurance structure all sit here.
Layer 2 — The money transmission layer. X Payments LLC holds the money transmitter licenses. As of the July 27 launch, X Payments is licensed in 41 states and Washington D.C. New York and Massachusetts are among the states where licensing is still pending. Residents of unlicensed states have limited product access until the remaining licenses are in hand.
This two-layer structure is standard in BaaS. It is also where the compliance complexity lives.
Cross River’s enforcement record
Cross River Bank’s relationship with fintech partners has drawn FDIC attention twice.
In 2018, the FDIC imposed a civil money penalty in connection with Cross River’s partnership with Freedom Financial Network. The finding involved unfair and deceptive practices in the origination of more than 24,000 consumer loans across multiple product types. The fine was $641,750. Cross River neither admitted nor denied the violations.
In March 2023, the FDIC issued a consent order against Cross River for unsafe or unsound practices in its fair lending program. The order found that Cross River had failed to maintain adequate internal controls, oversight, and governance over consumer lending conducted through its fintech partners. Among the remedies: Cross River was required to obtain FDIC prior approval before entering any new fintech partnership arrangement.
That second order is directly relevant to X Money. Cross River had to obtain regulatory approval before adding X as a partner. By July 2026, the bank has apparently satisfied that condition — but the consent order remains public record in the FDIC’s enforcement actions database, and the examination cycle that produced it established what regulators now expect from Cross River’s third-party program on an ongoing basis.
Senator Elizabeth Warren sent X a letter in April 2026 flagging Cross River’s consent order as a reason for heightened scrutiny of X Money’s banking arrangements. The letter is not a regulatory action, but it illustrates how quickly a sponsor bank’s enforcement history becomes part of the political and reputational context around a high-profile product launch.
The BaaS compliance chain: who owns what
The 2023 interagency guidance on third-party relationships — issued jointly by the FDIC, OCC, and Federal Reserve — made clear that a bank does not outsource its regulatory obligations when it partners with a fintech. If a fintech partner originates loans, takes deposits, transmits funds, or services accounts, the bank still owns the compliance outcome.
That principle applies across every obligation the bank would have if it ran the product itself:
- BSA/AML: Transaction monitoring, SAR filing, and customer identification requirements apply to customers onboarded through the fintech, not just the bank’s direct customers.
- Fair lending: If the fintech is making underwriting decisions or serving customers on the bank’s behalf, HMDA, ECOA, and disparate-impact analysis follow.
- Consumer protection: UDAP and UDAAP obligations apply to the product experience the fintech designs, even when the customer never interacts with the bank directly.
- Complaint management: A bank in a BaaS arrangement should receive, review, and act on complaints that arise from the fintech-side customer experience.
- Independent testing: The bank’s internal audit function must be able to assess partner-originated activity. Access to partner data, systems, and processes is not optional.
Cross River’s 2023 consent order was, at its core, a finding that the bank did not have adequate controls across these dimensions for its fintech partner programs. The order required the bank to build those controls — not outsource them further.
For fintech partners, this matters because the bank’s regulatory standing is tied to your operational quality. If your BSA controls are weak, your data pipelines are unreliable, or your complaint volumes spike, that surfaces in the bank’s next examination. A sponsor bank under a consent order requiring FDIC pre-approval for new partnerships is a bank that cannot easily absorb a compliance surprise from its partner roster.
What regulators focus on in BaaS exam cycles
The OCC’s 2026 consent order against Community Federal Savings Bank — covering its BaaS fintech partner program — identified the same recurring exam themes that appear in FDIC BaaS actions. Regardless of charter, examiners focus on:
Program governance. Does the bank’s board and senior management understand and oversee the third-party program? Are there clear policies covering how partners are onboarded, monitored, and offboarded?
Risk-based due diligence. Did the bank perform pre-contract due diligence on the fintech’s financial condition, BSA/AML program, complaint history, and operational controls? Is due diligence refreshed on a schedule that corresponds to the risk level of the partnership?
Contractual clarity. Do contracts with fintech partners spell out BSA/AML obligations, data access rights, error resolution timelines, audit rights, and customer complaint escalation paths?
Ongoing monitoring. Does the bank receive regular data from the partner — transaction reports, complaint logs, audit results — and does someone actually review and act on it?
Staffing and capacity. Is the bank’s compliance and examination-management team sized for the volume and complexity of the partner portfolio?
The last point is often the quiet failure. Banks with ten fintech partners sometimes staff their third-party programs as if they have one. Cross River’s 2023 consent order addressed governance deficiencies at a bank that had scaled its fintech partner count significantly faster than its oversight capacity.
Running the sponsor-bank due diligence
If you are on the fintech side entering or renewing a BaaS arrangement, the sponsor bank’s enforcement history is not a disqualifying factor by itself — but it is a specific due diligence item that belongs in every review, not an afterthought.
A workable checklist for the bank-side leg of due diligence:
- Search the FDIC enforcement actions database for any consent orders, civil money penalties, or formal agreements tied to the bank’s charter.
- Check the OCC enforcement actions list and the Federal Reserve’s enforcement page for the same institution.
- Assess whether any open orders have remediation conditions that constrain the bank’s ability to add new partners or enter new product lines.
- Ask the bank directly: Are there any open MRAs, MRBAs, or exam findings that relate to your third-party risk or BSA/AML programs?
- Review the contract terms covering your obligation to provide transaction monitoring data to the bank, the bank’s right to terminate or suspend the arrangement on exam-related grounds, and your access to customer data for error resolution.
For the Cash App multi-state settlement in 2026, the enforcement action fell on the fintech side — not the sponsor bank. That is often how it plays out when the consumer-facing product fails. But when the failure involves fair lending or BSA compliance, the bank’s examination is where the primary record lives.
Reverse due diligence — the fintech evaluating the bank — is the half of BaaS compliance that teams most often skip because the bank relationship feels like a vendor relationship. It is not. The sponsor bank’s regulatory standing is load-bearing for your product’s ability to operate.
The Third-Party Risk Management (TPRM) Kit includes due diligence checklists, ongoing monitoring frameworks, and contract-review guidance that cover both sides of a BaaS relationship — whether you are the bank onboarding a new fintech or the fintech doing reverse due diligence on your sponsor.
FAQ
What is Cross River Bank’s FDIC enforcement history?
Two events. In 2018, Cross River paid a civil money penalty of $641,750 related to its Freedom Financial Network partnership, covering unfair and deceptive practices in the origination of more than 24,000 consumer loans. In March 2023, the FDIC issued a consent order for unsafe or unsound fair lending practices in Cross River’s fintech partner lending programs. The 2023 order required FDIC prior approval before Cross River could enter any new fintech partnership and mandated remediation of governance and control deficiencies across its third-party program.
What role does Cross River Bank play in X Money?
Cross River is the FDIC-member institution holding X Money deposits. It provides the deposit account, the 6% APY, and the FDIC pass-through insurance structure (up to $10 million aggregate). X Payments LLC — a separate entity — holds money transmitter licenses in 41 states and D.C. and handles fund movement. Each layer carries its own distinct regulatory obligations.
What does an FDIC consent order mean for a bank’s fintech partnerships?
A consent order means examiners found specific deficiencies and imposed a remediation plan with ongoing supervisory conditions. For BaaS partners, an open consent order can mean the bank faces restrictions on adding new partners or is under heightened examiner scrutiny that extends directly to its partner programs. That scrutiny reaches the fintech’s operational controls, complaint management, and BSA/AML systems.
What states is X Money not fully available in?
As of the July 27, 2026 launch, X Payments holds money transmitter licenses in 41 states and D.C. New York and Massachusetts are among the states where the license remains pending. Users in unlicensed states have limited access to the product until licensing is complete in those markets.
How should a fintech evaluate a potential sponsor bank’s regulatory standing?
Check the FDIC, OCC, and Federal Reserve enforcement action databases for the bank’s charter. Look for consent orders, formal agreements, and civil money penalties. For any open orders, read the remediation conditions — they describe what constraints currently apply to the bank’s ability to expand partnerships or enter new product lines. Then ask the bank directly about any open exam findings in its third-party risk or BSA/AML program before signing.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is Cross River Bank's FDIC enforcement history?
What role does Cross River Bank play in X Money?
What does a sponsor bank need in its fintech third-party program?
What states does X Payments not have a money transmitter license in?
How should a fintech evaluate a potential sponsor bank's regulatory standing?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Compliance Strategy
FINRA Is Still Barring Brokers Over Text Messages. Here's What the Off-Channel Enforcement Split Means for Your Records Program.
The SEC ended its off-channel enforcement wave after 95 cases and $2.3 billion in penalties. FINRA didn't follow. While the SEC pivoted to fraud and fiduciary cases, FINRA fined BTIG $600,000 and started barring individuals from the industry. Here's what the divergence means for broker-dealer compliance programs.
Aug 6, 2026
Compliance Strategy
Q2 2026: $931 Million in Penalties, One Theme — Firms That Had Controls and Didn't Use Them
Corlytics tracked 37 major penalties totaling $931M in Q2 2026. The pattern isn't missing frameworks — it's firms ignoring the ones they already have. Here's what that means for your escalation and issues management process.
Aug 5, 2026
Compliance Strategy
46 State AGs Just Settled with Cash App for $45 Million. Here's What Your Fraud Disclosure, KYC Design, and Customer Support Look Like Under That Lens.
On July 8, 2026, a bipartisan coalition of 46 state attorneys general announced a $45M settlement with Block Inc. over Cash App's fraud disclosure failures, identity verification gaps that enabled fraudsters, and the absence of any official customer support phone number. Combined with the January 2025 CFPB order, Block paid $220M in 18 months. Here's what that enforcement record means for your compliance program.
Aug 2, 2026