Feature Compliance Strategy
Three Bosses, One Compliance Team: How Nonbank Fintechs Navigate FTC, State, and Sponsor Bank Oversight in 2026
Nonbank fintechs answer to at least three distinct oversight relationships simultaneously—FTC, state regulators, and their sponsor bank. Each has different priorities, evidence standards, and enforcement timelines. Here's how to build a compliance program that holds up across all three.
Table of Contents
TL;DR
- Nonbank fintechs have at least three simultaneous oversight relationships—FTC, state regulators, and sponsor bank—each with different evidence standards, enforcement timelines, and priority areas
- The FTC’s March 2026 debanking warning letters to PayPal, Stripe, Visa, and Mastercard extended Section 5 enforcement posture to account access decisions, not just advertising
- OCC Bulletin 2025-24 (effective January 2026) reduced mandatory examination requirements for community banks—your bank partner may get fewer rote policy checks, but your compliance evidence requirements didn’t change
- CFPB reform reducing federal supervision would push more enforcement authority to state AGs, who showed in the Cash App settlement they’ll act bipartisan, coordinated, and at scale
The first compliance question most fintech founders ask is “do we have a bank charter?” The answer determines a lot—including who supervises you directly. But not having a charter doesn’t mean not having supervisors. It usually means having more of them, operating on different schedules, with different priorities, and no single point of contact for all of them at once.
Most compliance guides are written for banks. You have a sponsor bank, a stack of state MTL licenses, an FTC exposure you haven’t fully mapped, and one compliance hire trying to figure out who’s actually asking what. Here’s the structure you need.
Your Regulatory Map (The Non-Bank Version)
A nonbank fintech’s oversight landscape in 2026 looks like this:
Federal — FTC. The Federal Trade Commission has authority over unfair or deceptive acts or practices under Section 5 of the FTC Act for nonbank financial companies. This covers advertising and disclosure accuracy, enrollment and cancellation practices, account closure procedures, data handling, and any claim you make about your product that a consumer could reasonably rely on. The FTC doesn’t examine on a schedule—it investigates and enforces through complaint-driven or market-monitoring action, which means enforcement can arrive without warning.
Federal — FinCEN. Bank Secrecy Act requirements apply to money services businesses regardless of bank charter. CIP, CDD, SARs, CTRs, and transaction monitoring are federal obligations, with your actual examination handled in most cases by your state financial regulator under FinCEN examination authority delegation.
Federal — CFPB. For many fintechs, CFPB supervision has been limited by asset threshold or product category. But the agency can still enforce Reg E, TILA, ECOA, and FCRA against nonbanks through its independent enforcement authority—regardless of whether you’re subject to CFPB examination. The agency’s 2026 regulatory agenda, released in July 2026, signals where it intends to focus its reduced supervisory resources.
State — Financial Regulators. Every state where you transmit money, make loans, or collect debt requires a license. Those licenses mean state examiners: the NYDFS, California DFPI, Texas Department of Banking. Each state can examine for compliance with state consumer protection laws, licensing requirements, and BSA/AML obligations. Examination frequency and depth vary significantly by state and by product category.
State — AGs. State attorneys general have independent authority to enforce federal consumer financial laws—including UDAP, Reg E, and EFTA—without CFPB involvement. The Cash App/Block settlement announced in July 2026 illustrated what coordinated AG enforcement looks like: 46 states, $45 million, and a consent order covering fraud disclosure design, KYC practices, and customer support access. That enforcement pattern didn’t need a lead federal agency.
Sponsor Bank. Your bank partner isn’t a regulator, but their oversight program functions like one. They can restrict your program, require enhanced due diligence, or terminate the relationship. And they’re answerable to their own examiners for every risk that runs through their charter. Post-Synapse, sponsor banks have moved to continuous monitoring—tracking fintech partner metrics on an ongoing basis across reconciliation, complaints, incident response, and your own TPRM program. Their oversight calendar doesn’t match anyone else’s.
What the FTC Is Watching in 2026
FTC enforcement against nonbank financial companies has always covered disclosure accuracy and advertising claims. The 2026 development worth mapping into your compliance program is the debanking enforcement posture.
In March 2026, FTC Chairman Andrew Ferguson sent warning letters to the CEOs of PayPal, Stripe, Visa, and Mastercard, citing publicly reported instances of account denials and closures and flagging that denying consumers access to payment services based on political or religious views may violate Section 5. Analysis from Holland & Knight characterizes this as the FTC treating account access as a consumer protection issue—not just a payment fraud or fraud prevention issue.
For a nonbank fintech, the practical implication: your account closure and suspension policies are now potential FTC exposure, not just customer service design. The criteria for denying or restricting accounts should be documented, consistently applied, and disclosed in plain language that customers can understand. Inconsistent enforcement of your own policies—approving some users and denying others under identical circumstances—is the pattern that generates complaint-driven FTC investigations.
The FTC’s prior enforcement actions provide the roadmap: Hello Digit (August 2022, algorithmic savings product causing overdrafts) cited a gap between what marketing promised and what the algorithm produced. The FTC Safeguards Rule and its 30-day breach notification requirement remain a parallel obligation for any nonbank handling customer financial information.
What OCC Bulletin 2025-24 Actually Changes for You
OCC Bulletin 2025-24, effective January 1, 2026, announced that the OCC would eliminate mandatory policy-based examination requirements for community banks. Rather than a standardized checklist, examiners now tailor procedures to each bank’s actual risk profile—size, complexity, and activities.
If your sponsor bank is a community bank, this might read as regulatory relief: fewer rote policy checks, more focused examination. But the compliance strategy implication runs the other way.
When mandatory OCC policy checklists drove community bank examinations, a fintech partner could get some indirect credit for the bank’s compliance documentation—if the bank’s examination passed, that was some evidence the program was running. With risk-proportionate examination, the bank’s own examiner will focus on whatever risk the bank actually has—which, if you’re a high-volume fintech partner, may be concentrated in your program’s operating metrics.
In other words: the OCC reducing mandatory examination requirements for community banks increases the probability that your bank partner’s examination focuses precisely on the risks your fintech program creates—because those are the material risks in a proportionate review. Your compliance documentation and operational evidence become the bank’s substantiation, not an examination checkbox.
This is why sponsor bank continuous monitoring has intensified in 2026, not relaxed. Banks need the ongoing evidence to show their examiners that the programs running through their charter are operating correctly—and with fewer mandatory policy reviews to lean on, that evidence increasingly comes from your program metrics.
The State AG Problem Isn’t Going Away With CFPB Reform
The House CFPB reform discussion draft released July 24, 2026 would raise the agency’s supervisory threshold substantially, removing most nonbank fintechs from direct CFPB supervisory reach. The full analysis of what that discussion draft means for compliance programs covers the mechanics. The compliance strategy point is simpler: CFPB supervisory reduction doesn’t reduce state AG enforcement authority.
State AGs enforce directly under state UDAP laws and their authority to bring actions under federal consumer financial statutes. The Cash App settlement—46 states, bipartisan, July 2026—was brought under that authority without CFPB involvement. The enforcement theory covered product design choices (fraud disclosure), KYC adequacy, and whether customers who experienced problems could access meaningful support.
Those three areas—disclosure accuracy, KYC adequacy, and customer support access—are the consistent threads across state AG fintech enforcement. They are also not areas where CFPB supervision changes the underlying state law exposure.
Building a Compliance Program That Works for Three Bosses
The practical challenge for a small compliance team isn’t understanding who the regulators are. It’s building a calendar and documentation system that doesn’t require maintaining three separate compliance programs for three separate audiences.
The workable structure is to build to the highest common denominator—your sponsor bank’s evidence standards—and verify that your disclosures and product design meet FTC and state requirements on top of that.
Here’s what each oversight channel prioritizes in examination or investigation:
| Oversight Channel | Primary Focus | Evidence Standard |
|---|---|---|
| Sponsor Bank | Operational metrics, TPRM, ongoing monitoring | Live data: complaint volumes, SAR counts, monitoring alert rates, reconciliation pass rates |
| FTC | Disclosure accuracy, advertising claims, enrollment/cancellation design | Documentation: what you told customers vs. what the product does |
| State Financial Regulators | License compliance, BSA/AML, consumer complaint resolution | Transactional: exam-ready files, CTR/SAR logs, complaint resolution records |
| State AGs | Customer outcomes: fraud, account access, support quality | Customer-facing: what happened to customers who had problems |
The bank’s operational evidence bar is usually the highest and the most granular. A program that can produce complaint trend data, monitoring metrics, and documented vendor assessments on 48 hours’ notice is a program that has the underlying documentation that state and FTC examinations will ask for in a less real-time format.
The Priority Stack for a Solo Compliance Hire
If you’re the compliance team and you can’t do everything simultaneously, here’s how to sequence:
First: Controls that generate evidence automatically. Complaint logging, transaction monitoring alerts, CIP verification records, and incident logs should be configured to produce records without manual effort. If you have to compile these by hand each quarter, you’ll always be behind.
Second: Disclosure accuracy. Read your current marketing materials, your terms, and your disclosures against what your product actually does. The gap between marketing language and product behavior is the most common FTC and state AG enforcement trigger. Fix mismatches before they generate complaints.
Third: TPRM documentation for critical vendors. Your sponsor bank will ask for this. State examiners may ask for it. Document your critical vendor list and evidence of your due diligence—even a simple risk tier and assessment for each critical vendor is a significant improvement over nothing.
Fourth: Annual testing. Run a tabletop or control test exercise at least annually and document the results. An untested compliance program is a policy program. Evidence that controls ran, produced results, and generated remediation when gaps appeared is what separates a documented program from an operating one.
So What?
Nonbank fintechs don’t have regulatory simplicity in 2026—they have regulatory plurality. FTC enforcement posture is shifting. State AGs are coordinating. CFPB supervision may contract while state AG enforcement expands. Your sponsor bank runs its own oversight program on its own timeline.
The compliance programs that hold up across all three channels are built around a consistent foundation: policies that run, controls that produce evidence, and disclosures that match the product. Each regulator interprets that differently, but the underlying program is the same.
A governance framework that documents your risk appetite, control ownership, and oversight responsibilities across all three relationships gives you the structure to manage multiple audiences without rebuilding your program for each. The Enterprise Risk Management Framework provides that structure—risk appetite, three-lines-of-defense design, and committee governance that satisfies bank partner oversight, state examiner review, and FTC-standard documentation simultaneously.
Sources:
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Enterprise Risk Management Framework (ERMF)
Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Who are the primary regulators for a nonbank fintech in 2026?
How has the FTC's enforcement posture toward fintechs changed in 2025-2026?
What does my sponsor bank expect from my compliance program that's different from what regulators expect?
With CFPB reform reducing federal supervision for many fintechs, does state AG exposure increase?
How do I prioritize when FTC, state, and sponsor bank requirements seem to conflict?
What's the most common gap in a nonbank fintech compliance program when audited or examined?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Enterprise Risk Management Framework (ERMF)
Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.
◆ Keep reading
Related posts.
Compliance Strategy
FINRA's Low-Priced Securities AML Trap: What the Pictet and Blue Ocean Fines Mean for Your Surveillance Program
FINRA fined Pictet Overseas ($610K) and Blue Ocean ATS ($550K) for AML failures on low-priced securities in 2026. One firm missed $300M in transactions routed through an affiliate's omnibus account. The other had one employee reviewing two reports. Here's the five-part compliance trap these cases expose.
Aug 25, 2026
Compliance Strategy
Conduct Risk KRIs: Indicators, Thresholds, and Incentive Blind Spots
Build conduct risk key risk indicators that expose sales pressure, weak overrides, complaints, cancellations, and customer harm before they become findings.
Aug 21, 2026
Compliance Strategy
Five Statutes Generated 75% of All FDIC Compliance Violations in 2025. Here's What They Are.
The FDIC's 2026 Consumer Compliance Supervisory Highlights identified 1,155 violations in 2025 exams. Five statutes — TILA, EFTA, the Flood Act, TISA, and HMDA — drove three-quarters of them. Here is what examiners actually cited and what your compliance program needs to test.
Aug 18, 2026