Skip to content
RiskTemplates · The Daily Brief Wednesday, August 26, 2026
Wire SEC Free-Riding Case: The Instant Deposit Credit Controls Broker-Dealers Need to Test AUG 25

Feature Third-Party Risk

The Bilt-Wells Fargo Breakup Is a Case Study in Bank Partner Exit Risk. Here's What Your Fintech Needs Before an Unplanned Transition.

When Wells Fargo ended its Bilt contract early, hundreds of rent payments failed and the CFPB stepped in. The lesson isn't about one fintech's stumble — it's about the gap in how every fintech plans for the scenario where the bank partner relationship ends on someone else's timeline.

By Rebecca Leung · August 26, 2026 ·
Table of Contents

TL;DR

  • Wells Fargo ended its Bilt contract early; Bilt’s transition to a new bank partner caused rent payments to fail for hundreds of customers
  • CFPB directed Bilt to provide full consumer redress in June 2026 — no formal enforcement action, but informal direction still required reimbursement for 500+ customers
  • This is not a Bilt story. It is a story about a gap that exists in nearly every fintech’s TPRM program: bank partner exit risk
  • OCC Bulletin 2023-17 and FDIC guidance require TPRM programs to cover the full vendor lifecycle — including termination scenarios your bank partner initiates, not just ones you plan

Wells Fargo canceled a contract. Hundreds of rent payments didn’t arrive. The CFPB called.

That’s the compressed version of what happened to Bilt in early 2026. The longer version is a case study in a risk category that gets underplanned at most fintechs: what happens when your bank partner relationship ends on someone else’s timeline.

Every fintech that relies on a bank sponsor — for deposits, credit cards, lending, payments — should read this story as a stress test for their own program. Not because Bilt did something unusual, but because the sequence of events that caused customer harm is one that any bank partner transition could replicate.


What Happened: The Bilt-Wells Fargo Transition

Bilt built a compelling product around a simple insight: rent is the largest monthly payment most Americans make, and nobody was rewarding it with points. The company partnered with Wells Fargo to issue its Bilt Rewards credit card and process rent payments — a card that generated genuine user adoption among a demographic that traditional card issuers largely ignored.

Then Wells Fargo ended the contract early.

The timeline is relevant. This wasn’t a planned transition with 18 months of runway. According to reporting from Banking Dive and Payments Dive, Wells Fargo initiated the early termination, and Bilt had to accelerate its transition to a new banking partner — a structure the company termed Bilt 2.0 — on a compressed timeline.

Fintech transitions are operationally complex under ideal conditions. Compressing one is where the failures happen.

For a segment of Bilt customers, the transition produced exactly the kind of failure that consumer protection regulators care most about: rent and mortgage payments that were debited from accounts but never delivered to the intended recipients. Customers incurred overdraft fees when their accounts were drawn down. They incurred late fees when their landlords or mortgage servicers never received the payment. They got through to customer support and didn’t get answers.

By the time the CFPB met with Bilt on June 2, 2026, the consumer harm was documented. The agency reviewed the situation and directed Bilt to provide full redress to all affected customers — reimbursing overdraft fees, late fees, and insufficient funds fees tied to the transition. Bilt’s reimbursement outreach identified more than 500 newly affected customers.


How the CFPB Handled It — and What That Signals

No formal enforcement action was taken. The CFPB described the Bilt matter as an example of its revised enforcement posture — the enforcement principles the bureau adopted in June 2026 that emphasize addressing consumer harm, due process, collaboration, and efficiency over formal proceedings in cases where companies cooperate and remediate.

Compliance teams at other fintechs reading this as “the CFPB backed off” should read it more carefully.

The CFPB met with Bilt. It evaluated the situation. It directed specific action. Bilt reimbursed customers. The bureau characterized the result as an example of its preferred approach working.

That is not deregulation. That is the bureau achieving its objective — consumer redress — without the overhead of a formal enforcement proceeding. For a fintech on the receiving end, the practical distinction between “informal direction to reimburse 500 customers” and “consent order requiring $X in redress” is thinner than the press coverage suggests.

The lesson for fintechs watching this case: if your bank partner transition causes consumer harm and the CFPB learns about it, informal engagement is not the same as no consequences. It is the same consequences with a smaller legal bill and no public press release. For now.


The Actual Problem: Bank Partner Exit Risk

Here is the gap the Bilt case exposes.

Most fintech TPRM programs treat vendor offboarding as an edge-case procedure — something you plan for when you decide to leave a relationship. The checklist covers revoking API credentials, returning or destroying data, confirming that SLAs are terminated, and documenting the exit.

That framework assumes the fintech is the one initiating the exit, on a timeline it controls, for a vendor that holds business data and system access.

It does not address what happens when the bank partner is the vendor, holds customer funds, and terminates the relationship on its own timeline.

A bank partner in a BaaS or card-issuing structure is not a typical vendor:

  • Customer funds are held at the bank, not at the fintech. The fintech has reconciliation records, but the actual money lives in the bank’s ledger.
  • The bank’s charter is what makes the product work. The fintech can’t just substitute a different ledger; it needs a new chartered banking partner to provide the same regulatory infrastructure.
  • Customer-facing services are dependent on the bank’s systems — payment rails, card networks, account numbers — in ways that can’t be cleanly migrated without a planned cutover.
  • Regulatory notifications and compliance obligations may run through the bank, not the fintech, in ways that become unclear during a transition.

When the bank partner exits on its own timeline, none of the normal vendor offboarding assumptions hold. The fintech has to migrate a live product — with live customer funds and live payment obligations — to a new banking partner, under time pressure it didn’t choose, while continuing to fulfill service commitments to customers.

That is what happened to Bilt. The payments that failed weren’t a system error in the traditional sense — they were the consequence of a transition that moved faster than the operational infrastructure could absorb.


Why This Is Not Unique to Bilt

The Synapse bankruptcy in April 2024 produced a different version of the same story: middleware collapse, customer funds temporarily inaccessible, FDIC rulemaking on custodial deposits, $65 million to $95 million in unreconciled funds. The FDIC’s subsequent custodial deposit rulemaking — which took effect in 2025 — is the regulatory response to what Synapse proved: that fintechs did not have the records, processes, or infrastructure to reconnect customers with their funds when the intermediary layer failed.

Bilt’s situation is a smaller-scale version of the same failure mode. Not insolvency, but transition friction that produced real financial harm for real customers.

The OCC consent order against Community Federal Savings Bank from May 2026 was a third data point: when an OCC-regulated sponsor bank faces enforcement action driven partly by fintech-partner activity, the fintech program gets disrupted regardless of its own compliance posture. Program pauses, enhanced due diligence, potential termination — the consequences for the fintech depend on what the bank does next.

The pattern across these cases is the same: bank partner relationships end in ways fintechs don’t control, and fintechs don’t have exit plans designed for that scenario.


What a Real Bank Partner Exit Plan Covers

Most TPRM programs document what to do when a fintech exits a relationship with a technology vendor. Fewer address what to do when the bank partner — the most critical and least replaceable component of the fintech’s infrastructure — terminates or fails.

A bank partner exit plan for this specific scenario should cover:

ComponentWhat to Address
Customer notificationWhen and how to notify customers of the transition; regulatory notification obligations if applicable
Payment continuityHow in-flight payments are handled during the cutover window; who bears the cost of failures
Fund reconciliationProcess for confirming that all customer funds are accurately reflected in the new bank partner’s ledger before cutover
Account number migrationHow customer account numbers, card numbers, and routing information are transitioned to the new bank partner
Customer support capacityAdditional support resources during the transition window; documented escalation procedures
In-flight transaction resolutionWhat happens to transactions that were initiated but not settled at the time of cutover; who is responsible for completion or reversal
Regulatory notificationWhether the OCC, FDIC, CFPB, or state regulators need to be notified of a bank partner change; what documentation is required
New partner validationWhat testing is required before production traffic is moved to the new banking partner

That list is not complete — the specific requirements depend on product type, state licensing, and what the bank partner agreement requires. But every fintech that has not worked through these questions against a specific scenario should do so before the scenario arrives.

OCC Bulletin 2023-17, the FDIC’s third-party risk guidance, and the CFPB’s supervisory attention following Synapse all point in the same direction: regulators expect fintechs to have exit and transition planning for critical third parties, and a bank partner is the most critical third party a fintech has.


So What?

The Bilt case is useful not because Bilt failed catastrophically — the harm was real but manageable, the CFPB chose informal remediation, and no formal enforcement record was created — but because it makes visible a failure mode that is usually invisible until it happens.

Three questions for your next TPRM review:

1. Does your bank partner agreement address what happens if the bank terminates early? Most MSAs and BaaS agreements cover the fintech’s exit rights in detail. Fewer address what the bank’s obligations are to support a transition if it terminates — payment continuity, data delivery, cooperation on account migration. If your agreement doesn’t address this, you are negotiating from scratch under time pressure when the termination notice arrives.

2. Do you have a bank partner contingency plan that isn’t the same as your general BCP? A business continuity plan addresses operational disruptions. A bank partner contingency plan addresses what happens to your product infrastructure if the bank relationship ends. They are different documents, with different triggers, different decision trees, and different remediation procedures. If your BCP covers bank partner transition as a subsection, it probably doesn’t cover it in enough detail.

3. Have you tested your reconciliation process against a transition scenario? The Synapse bankruptcy revealed that reconciliation records at fintechs were frequently insufficient to reconnect customer funds with customer accounts. A transition scenario is a stress test for the same capability: can you confirm, in real time, where every dollar of customer funds is and whether every in-flight transaction has been completed or returned?

If the answer to any of these is no — or “I think so” — the Bilt case is worth reading as a prompt to find out.


For related coverage, see our analysis of BaaS vendor exit planning in the wake of Synapse, what OCC bank partner consent orders mean for fintech programs, and the X Money / Cross River Bank enforcement case.

Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What happened with Bilt and Wells Fargo in 2026?
Wells Fargo ended its contract with rent-rewards fintech Bilt early in 2026. Bilt had to transition its credit card and rent payment platform to a new bank partner on a compressed timeline. During the transition, a segment of customers experienced serious failures: rent and mortgage payments were debited from accounts but never delivered to landlords or lenders. The CFPB met with Bilt in June 2026 and directed the company to provide full redress to affected customers, including reimbursement of overdraft fees, late fees, and insufficient funds fees for more than 500 newly identified customers.
Did the CFPB take formal enforcement action against Bilt?
No. Under the CFPB's revised enforcement principles adopted in June 2026, the bureau elected to pursue a collaborative approach rather than a formal enforcement action. CFPB staff met with Bilt, evaluated the situation, and directed the company to provide full consumer redress. Bilt agreed. The bureau described the approach as consistent with its emphasis on consumer harm remediation, due process, and efficiency. That said — informal CFPB direction that requires consumer reimbursement is not the absence of consequences. It is the consequences without the press release.
What is bank partner exit risk and why does it matter for fintechs?
Bank partner exit risk is the operational and compliance risk that arises when a fintech's bank partnership ends — whether by planned transition, early contract termination, or bank failure. For fintechs that use a sponsor bank for deposit accounts, payments, credit cards, or lending, the bank is not just a vendor: it holds customer funds and is embedded in the fintech's product infrastructure. When that relationship ends on a timeline the fintech doesn't control, customer-facing service failures become the fintech's problem — not the departing bank's.
Does my TPRM program need to cover bank partner exit scenarios?
Yes. OCC Bulletin 2023-17 and FDIC third-party risk guidance both require that third-party risk management address the full vendor lifecycle, including termination and offboarding. Bank partners are the highest-criticality category — they hold customer funds and their services are embedded in customer-facing products. A TPRM program that doesn't address what happens when the bank partner relationship ends has a material gap, regardless of whether you plan to leave the relationship.
What did the Synapse bankruptcy add to the regulatory picture on bank partner transitions?
When Synapse filed for bankruptcy in April 2024, it triggered FDIC custodial deposit rulemaking that has since taken effect, and CFPB supervisory attention on how fintechs reconcile customer funds in bank-sponsored structures. Regulators learned from Synapse that the question isn't just whether funds are safe at the bank — it's whether the fintech's records are complete enough to reunite those funds with customers if the middleware or sponsor relationship breaks down. Bilt's transition shows the same principle applies to credit card and payment products, not just deposit products.
What does a bank partner exit plan need to cover?
A bank partner exit plan should address: notification and communication procedures for affected customers; payment and transaction continuity protocols during the cutover period; in-flight transaction reconciliation to confirm payments are completed or reversed; customer support capacity for the transition window; regulatory notification obligations (if applicable); and new bank partner onboarding validation before production traffic is moved. The plan should be tested before it's needed — not written for the first time after a termination notice arrives.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.