Skip to content
RiskTemplates · The Daily Brief Tuesday, August 25, 2026
Wire SEC's Tricolor Fraud Case: The Double-Pledging Controls Lenders Missed AUG 20

Feature Compliance Strategy

Three Bosses, One Compliance Team: How Nonbank Fintechs Navigate FTC, State, and Sponsor Bank Oversight in 2026

Nonbank fintechs answer to at least three distinct oversight relationships simultaneously—FTC, state regulators, and their sponsor bank. Each has different priorities, evidence standards, and enforcement timelines. Here's how to build a compliance program that holds up across all three.

Table of Contents

TL;DR

  • Nonbank fintechs have at least three simultaneous oversight relationships—FTC, state regulators, and sponsor bank—each with different evidence standards, enforcement timelines, and priority areas
  • The FTC’s March 2026 debanking warning letters to PayPal, Stripe, Visa, and Mastercard extended Section 5 enforcement posture to account access decisions, not just advertising
  • OCC Bulletin 2025-24 (effective January 2026) reduced mandatory examination requirements for community banks—your bank partner may get fewer rote policy checks, but your compliance evidence requirements didn’t change
  • CFPB reform reducing federal supervision would push more enforcement authority to state AGs, who showed in the Cash App settlement they’ll act bipartisan, coordinated, and at scale

The first compliance question most fintech founders ask is “do we have a bank charter?” The answer determines a lot—including who supervises you directly. But not having a charter doesn’t mean not having supervisors. It usually means having more of them, operating on different schedules, with different priorities, and no single point of contact for all of them at once.

Most compliance guides are written for banks. You have a sponsor bank, a stack of state MTL licenses, an FTC exposure you haven’t fully mapped, and one compliance hire trying to figure out who’s actually asking what. Here’s the structure you need.

Your Regulatory Map (The Non-Bank Version)

A nonbank fintech’s oversight landscape in 2026 looks like this:

Federal — FTC. The Federal Trade Commission has authority over unfair or deceptive acts or practices under Section 5 of the FTC Act for nonbank financial companies. This covers advertising and disclosure accuracy, enrollment and cancellation practices, account closure procedures, data handling, and any claim you make about your product that a consumer could reasonably rely on. The FTC doesn’t examine on a schedule—it investigates and enforces through complaint-driven or market-monitoring action, which means enforcement can arrive without warning.

Federal — FinCEN. Bank Secrecy Act requirements apply to money services businesses regardless of bank charter. CIP, CDD, SARs, CTRs, and transaction monitoring are federal obligations, with your actual examination handled in most cases by your state financial regulator under FinCEN examination authority delegation.

Federal — CFPB. For many fintechs, CFPB supervision has been limited by asset threshold or product category. But the agency can still enforce Reg E, TILA, ECOA, and FCRA against nonbanks through its independent enforcement authority—regardless of whether you’re subject to CFPB examination. The agency’s 2026 regulatory agenda, released in July 2026, signals where it intends to focus its reduced supervisory resources.

State — Financial Regulators. Every state where you transmit money, make loans, or collect debt requires a license. Those licenses mean state examiners: the NYDFS, California DFPI, Texas Department of Banking. Each state can examine for compliance with state consumer protection laws, licensing requirements, and BSA/AML obligations. Examination frequency and depth vary significantly by state and by product category.

State — AGs. State attorneys general have independent authority to enforce federal consumer financial laws—including UDAP, Reg E, and EFTA—without CFPB involvement. The Cash App/Block settlement announced in July 2026 illustrated what coordinated AG enforcement looks like: 46 states, $45 million, and a consent order covering fraud disclosure design, KYC practices, and customer support access. That enforcement pattern didn’t need a lead federal agency.

Sponsor Bank. Your bank partner isn’t a regulator, but their oversight program functions like one. They can restrict your program, require enhanced due diligence, or terminate the relationship. And they’re answerable to their own examiners for every risk that runs through their charter. Post-Synapse, sponsor banks have moved to continuous monitoring—tracking fintech partner metrics on an ongoing basis across reconciliation, complaints, incident response, and your own TPRM program. Their oversight calendar doesn’t match anyone else’s.

What the FTC Is Watching in 2026

FTC enforcement against nonbank financial companies has always covered disclosure accuracy and advertising claims. The 2026 development worth mapping into your compliance program is the debanking enforcement posture.

In March 2026, FTC Chairman Andrew Ferguson sent warning letters to the CEOs of PayPal, Stripe, Visa, and Mastercard, citing publicly reported instances of account denials and closures and flagging that denying consumers access to payment services based on political or religious views may violate Section 5. Analysis from Holland & Knight characterizes this as the FTC treating account access as a consumer protection issue—not just a payment fraud or fraud prevention issue.

For a nonbank fintech, the practical implication: your account closure and suspension policies are now potential FTC exposure, not just customer service design. The criteria for denying or restricting accounts should be documented, consistently applied, and disclosed in plain language that customers can understand. Inconsistent enforcement of your own policies—approving some users and denying others under identical circumstances—is the pattern that generates complaint-driven FTC investigations.

The FTC’s prior enforcement actions provide the roadmap: Hello Digit (August 2022, algorithmic savings product causing overdrafts) cited a gap between what marketing promised and what the algorithm produced. The FTC Safeguards Rule and its 30-day breach notification requirement remain a parallel obligation for any nonbank handling customer financial information.

What OCC Bulletin 2025-24 Actually Changes for You

OCC Bulletin 2025-24, effective January 1, 2026, announced that the OCC would eliminate mandatory policy-based examination requirements for community banks. Rather than a standardized checklist, examiners now tailor procedures to each bank’s actual risk profile—size, complexity, and activities.

If your sponsor bank is a community bank, this might read as regulatory relief: fewer rote policy checks, more focused examination. But the compliance strategy implication runs the other way.

When mandatory OCC policy checklists drove community bank examinations, a fintech partner could get some indirect credit for the bank’s compliance documentation—if the bank’s examination passed, that was some evidence the program was running. With risk-proportionate examination, the bank’s own examiner will focus on whatever risk the bank actually has—which, if you’re a high-volume fintech partner, may be concentrated in your program’s operating metrics.

In other words: the OCC reducing mandatory examination requirements for community banks increases the probability that your bank partner’s examination focuses precisely on the risks your fintech program creates—because those are the material risks in a proportionate review. Your compliance documentation and operational evidence become the bank’s substantiation, not an examination checkbox.

This is why sponsor bank continuous monitoring has intensified in 2026, not relaxed. Banks need the ongoing evidence to show their examiners that the programs running through their charter are operating correctly—and with fewer mandatory policy reviews to lean on, that evidence increasingly comes from your program metrics.

The State AG Problem Isn’t Going Away With CFPB Reform

The House CFPB reform discussion draft released July 24, 2026 would raise the agency’s supervisory threshold substantially, removing most nonbank fintechs from direct CFPB supervisory reach. The full analysis of what that discussion draft means for compliance programs covers the mechanics. The compliance strategy point is simpler: CFPB supervisory reduction doesn’t reduce state AG enforcement authority.

State AGs enforce directly under state UDAP laws and their authority to bring actions under federal consumer financial statutes. The Cash App settlement—46 states, bipartisan, July 2026—was brought under that authority without CFPB involvement. The enforcement theory covered product design choices (fraud disclosure), KYC adequacy, and whether customers who experienced problems could access meaningful support.

Those three areas—disclosure accuracy, KYC adequacy, and customer support access—are the consistent threads across state AG fintech enforcement. They are also not areas where CFPB supervision changes the underlying state law exposure.

Building a Compliance Program That Works for Three Bosses

The practical challenge for a small compliance team isn’t understanding who the regulators are. It’s building a calendar and documentation system that doesn’t require maintaining three separate compliance programs for three separate audiences.

The workable structure is to build to the highest common denominator—your sponsor bank’s evidence standards—and verify that your disclosures and product design meet FTC and state requirements on top of that.

Here’s what each oversight channel prioritizes in examination or investigation:

Oversight ChannelPrimary FocusEvidence Standard
Sponsor BankOperational metrics, TPRM, ongoing monitoringLive data: complaint volumes, SAR counts, monitoring alert rates, reconciliation pass rates
FTCDisclosure accuracy, advertising claims, enrollment/cancellation designDocumentation: what you told customers vs. what the product does
State Financial RegulatorsLicense compliance, BSA/AML, consumer complaint resolutionTransactional: exam-ready files, CTR/SAR logs, complaint resolution records
State AGsCustomer outcomes: fraud, account access, support qualityCustomer-facing: what happened to customers who had problems

The bank’s operational evidence bar is usually the highest and the most granular. A program that can produce complaint trend data, monitoring metrics, and documented vendor assessments on 48 hours’ notice is a program that has the underlying documentation that state and FTC examinations will ask for in a less real-time format.

The Priority Stack for a Solo Compliance Hire

If you’re the compliance team and you can’t do everything simultaneously, here’s how to sequence:

First: Controls that generate evidence automatically. Complaint logging, transaction monitoring alerts, CIP verification records, and incident logs should be configured to produce records without manual effort. If you have to compile these by hand each quarter, you’ll always be behind.

Second: Disclosure accuracy. Read your current marketing materials, your terms, and your disclosures against what your product actually does. The gap between marketing language and product behavior is the most common FTC and state AG enforcement trigger. Fix mismatches before they generate complaints.

Third: TPRM documentation for critical vendors. Your sponsor bank will ask for this. State examiners may ask for it. Document your critical vendor list and evidence of your due diligence—even a simple risk tier and assessment for each critical vendor is a significant improvement over nothing.

Fourth: Annual testing. Run a tabletop or control test exercise at least annually and document the results. An untested compliance program is a policy program. Evidence that controls ran, produced results, and generated remediation when gaps appeared is what separates a documented program from an operating one.

So What?

Nonbank fintechs don’t have regulatory simplicity in 2026—they have regulatory plurality. FTC enforcement posture is shifting. State AGs are coordinating. CFPB supervision may contract while state AG enforcement expands. Your sponsor bank runs its own oversight program on its own timeline.

The compliance programs that hold up across all three channels are built around a consistent foundation: policies that run, controls that produce evidence, and disclosures that match the product. Each regulator interprets that differently, but the underlying program is the same.

A governance framework that documents your risk appetite, control ownership, and oversight responsibilities across all three relationships gives you the structure to manage multiple audiences without rebuilding your program for each. The Enterprise Risk Management Framework provides that structure—risk appetite, three-lines-of-defense design, and committee governance that satisfies bank partner oversight, state examiner review, and FTC-standard documentation simultaneously.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Who are the primary regulators for a nonbank fintech in 2026?
At the federal level: FTC for UDAP and the Safeguards Rule, CFPB for certain consumer financial products within its supervisory scope, FinCEN for BSA/AML, and OFAC for sanctions. At the state level: the financial regulator in each state where you're licensed (money transmitter, lender, debt collector), plus state AGs with independent enforcement authority under state and federal consumer protection laws. Overlaid on all of that: your sponsor bank's compliance requirements, which function as a fourth oversight channel with their own evidence standards and no fixed examination schedule.
How has the FTC's enforcement posture toward fintechs changed in 2025-2026?
FTC Chairman Andrew Ferguson shifted the agency's enforcement focus in 2025-2026 toward platform access and debanking. In March 2026, the FTC sent warning letters to the CEOs of PayPal, Stripe, Visa, and Mastercard about the potential that denying account access based on political or religious views could violate Section 5 of the FTC Act. Separately, the FTC continues active Section 5 enforcement across subscription practices, data handling, and advertising claims—the September 2025 Amazon Prime settlement is the most recent large-dollar example.
What does my sponsor bank expect from my compliance program that's different from what regulators expect?
Sponsor banks care about operational evidence of live controls—not policy documents. A regulatory examiner reviews your policies and asks about your processes. Sponsor bank oversight increasingly asks for metrics: complaint volumes, transaction monitoring alert rates, SAR filing counts, CIP completion rates, your own TPRM documentation for the vendors you use. Policies are baseline. Evidence that the policies are running is what post-Synapse sponsor bank oversight looks for. If you can't produce complaint trend data from the last 90 days on short notice, that's a gap.
With CFPB reform reducing federal supervision for many fintechs, does state AG exposure increase?
Yes. The House CFPB reform discussion draft released July 24, 2026 would raise the supervisory threshold to $21 billion in assets, removing most fintechs from direct CFPB supervisory reach. But state AGs retain independent authority to enforce federal consumer financial laws. The Cash App settlement—$45 million, 46 state AGs, July 2026—illustrates the bipartisan and coordinated nature of state enforcement. CFPB pulling back in supervision doesn't create a regulatory vacuum; state AGs fill it.
How do I prioritize when FTC, state, and sponsor bank requirements seem to conflict?
They rarely conflict on substance—all three care about accurate disclosures, fair customer treatment, and documented controls. Where they diverge is evidence standards and communication norms. A practical approach: build your program to the bank's evidence standards (operational metrics, documented testing, continuous monitoring) and verify that your disclosures and product design also satisfy FTC and state requirements. The bank's evidence bar is usually the highest, so clearing that standard typically covers the others.
What's the most common gap in a nonbank fintech compliance program when audited or examined?
Policy-to-practice gaps. Most fintechs have serviceable policies—written internally or purchased as templates. Where examiners, state AGs, and sponsor bank oversight teams consistently find gaps is in the evidence that policies are actually running: complaint logs that aren't being reviewed and trended, transaction monitoring that hasn't been tuned to the actual product risk, advertising claims that don't match product terms, CIP verification that works in the tech stack but has never been tested for exception handling.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Enterprise Risk Management Framework (ERMF)

Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.