Feature Third-Party Risk
The Bilt-Wells Fargo Breakup Is a Case Study in Bank Partner Exit Risk. Here's What Your Fintech Needs Before an Unplanned Transition.
When Wells Fargo ended its Bilt contract early, hundreds of rent payments failed and the CFPB stepped in. The lesson isn't about one fintech's stumble — it's about the gap in how every fintech plans for the scenario where the bank partner relationship ends on someone else's timeline.
Table of Contents
TL;DR
- Wells Fargo ended its Bilt contract early; Bilt’s transition to a new bank partner caused rent payments to fail for hundreds of customers
- CFPB directed Bilt to provide full consumer redress in June 2026 — no formal enforcement action, but informal direction still required reimbursement for 500+ customers
- This is not a Bilt story. It is a story about a gap that exists in nearly every fintech’s TPRM program: bank partner exit risk
- OCC Bulletin 2023-17 and FDIC guidance require TPRM programs to cover the full vendor lifecycle — including termination scenarios your bank partner initiates, not just ones you plan
Wells Fargo canceled a contract. Hundreds of rent payments didn’t arrive. The CFPB called.
That’s the compressed version of what happened to Bilt in early 2026. The longer version is a case study in a risk category that gets underplanned at most fintechs: what happens when your bank partner relationship ends on someone else’s timeline.
Every fintech that relies on a bank sponsor — for deposits, credit cards, lending, payments — should read this story as a stress test for their own program. Not because Bilt did something unusual, but because the sequence of events that caused customer harm is one that any bank partner transition could replicate.
What Happened: The Bilt-Wells Fargo Transition
Bilt built a compelling product around a simple insight: rent is the largest monthly payment most Americans make, and nobody was rewarding it with points. The company partnered with Wells Fargo to issue its Bilt Rewards credit card and process rent payments — a card that generated genuine user adoption among a demographic that traditional card issuers largely ignored.
Then Wells Fargo ended the contract early.
The timeline is relevant. This wasn’t a planned transition with 18 months of runway. According to reporting from Banking Dive and Payments Dive, Wells Fargo initiated the early termination, and Bilt had to accelerate its transition to a new banking partner — a structure the company termed Bilt 2.0 — on a compressed timeline.
Fintech transitions are operationally complex under ideal conditions. Compressing one is where the failures happen.
For a segment of Bilt customers, the transition produced exactly the kind of failure that consumer protection regulators care most about: rent and mortgage payments that were debited from accounts but never delivered to the intended recipients. Customers incurred overdraft fees when their accounts were drawn down. They incurred late fees when their landlords or mortgage servicers never received the payment. They got through to customer support and didn’t get answers.
By the time the CFPB met with Bilt on June 2, 2026, the consumer harm was documented. The agency reviewed the situation and directed Bilt to provide full redress to all affected customers — reimbursing overdraft fees, late fees, and insufficient funds fees tied to the transition. Bilt’s reimbursement outreach identified more than 500 newly affected customers.
How the CFPB Handled It — and What That Signals
No formal enforcement action was taken. The CFPB described the Bilt matter as an example of its revised enforcement posture — the enforcement principles the bureau adopted in June 2026 that emphasize addressing consumer harm, due process, collaboration, and efficiency over formal proceedings in cases where companies cooperate and remediate.
Compliance teams at other fintechs reading this as “the CFPB backed off” should read it more carefully.
The CFPB met with Bilt. It evaluated the situation. It directed specific action. Bilt reimbursed customers. The bureau characterized the result as an example of its preferred approach working.
That is not deregulation. That is the bureau achieving its objective — consumer redress — without the overhead of a formal enforcement proceeding. For a fintech on the receiving end, the practical distinction between “informal direction to reimburse 500 customers” and “consent order requiring $X in redress” is thinner than the press coverage suggests.
The lesson for fintechs watching this case: if your bank partner transition causes consumer harm and the CFPB learns about it, informal engagement is not the same as no consequences. It is the same consequences with a smaller legal bill and no public press release. For now.
The Actual Problem: Bank Partner Exit Risk
Here is the gap the Bilt case exposes.
Most fintech TPRM programs treat vendor offboarding as an edge-case procedure — something you plan for when you decide to leave a relationship. The checklist covers revoking API credentials, returning or destroying data, confirming that SLAs are terminated, and documenting the exit.
That framework assumes the fintech is the one initiating the exit, on a timeline it controls, for a vendor that holds business data and system access.
It does not address what happens when the bank partner is the vendor, holds customer funds, and terminates the relationship on its own timeline.
A bank partner in a BaaS or card-issuing structure is not a typical vendor:
- Customer funds are held at the bank, not at the fintech. The fintech has reconciliation records, but the actual money lives in the bank’s ledger.
- The bank’s charter is what makes the product work. The fintech can’t just substitute a different ledger; it needs a new chartered banking partner to provide the same regulatory infrastructure.
- Customer-facing services are dependent on the bank’s systems — payment rails, card networks, account numbers — in ways that can’t be cleanly migrated without a planned cutover.
- Regulatory notifications and compliance obligations may run through the bank, not the fintech, in ways that become unclear during a transition.
When the bank partner exits on its own timeline, none of the normal vendor offboarding assumptions hold. The fintech has to migrate a live product — with live customer funds and live payment obligations — to a new banking partner, under time pressure it didn’t choose, while continuing to fulfill service commitments to customers.
That is what happened to Bilt. The payments that failed weren’t a system error in the traditional sense — they were the consequence of a transition that moved faster than the operational infrastructure could absorb.
Why This Is Not Unique to Bilt
The Synapse bankruptcy in April 2024 produced a different version of the same story: middleware collapse, customer funds temporarily inaccessible, FDIC rulemaking on custodial deposits, $65 million to $95 million in unreconciled funds. The FDIC’s subsequent custodial deposit rulemaking — which took effect in 2025 — is the regulatory response to what Synapse proved: that fintechs did not have the records, processes, or infrastructure to reconnect customers with their funds when the intermediary layer failed.
Bilt’s situation is a smaller-scale version of the same failure mode. Not insolvency, but transition friction that produced real financial harm for real customers.
The OCC consent order against Community Federal Savings Bank from May 2026 was a third data point: when an OCC-regulated sponsor bank faces enforcement action driven partly by fintech-partner activity, the fintech program gets disrupted regardless of its own compliance posture. Program pauses, enhanced due diligence, potential termination — the consequences for the fintech depend on what the bank does next.
The pattern across these cases is the same: bank partner relationships end in ways fintechs don’t control, and fintechs don’t have exit plans designed for that scenario.
What a Real Bank Partner Exit Plan Covers
Most TPRM programs document what to do when a fintech exits a relationship with a technology vendor. Fewer address what to do when the bank partner — the most critical and least replaceable component of the fintech’s infrastructure — terminates or fails.
A bank partner exit plan for this specific scenario should cover:
| Component | What to Address |
|---|---|
| Customer notification | When and how to notify customers of the transition; regulatory notification obligations if applicable |
| Payment continuity | How in-flight payments are handled during the cutover window; who bears the cost of failures |
| Fund reconciliation | Process for confirming that all customer funds are accurately reflected in the new bank partner’s ledger before cutover |
| Account number migration | How customer account numbers, card numbers, and routing information are transitioned to the new bank partner |
| Customer support capacity | Additional support resources during the transition window; documented escalation procedures |
| In-flight transaction resolution | What happens to transactions that were initiated but not settled at the time of cutover; who is responsible for completion or reversal |
| Regulatory notification | Whether the OCC, FDIC, CFPB, or state regulators need to be notified of a bank partner change; what documentation is required |
| New partner validation | What testing is required before production traffic is moved to the new banking partner |
That list is not complete — the specific requirements depend on product type, state licensing, and what the bank partner agreement requires. But every fintech that has not worked through these questions against a specific scenario should do so before the scenario arrives.
OCC Bulletin 2023-17, the FDIC’s third-party risk guidance, and the CFPB’s supervisory attention following Synapse all point in the same direction: regulators expect fintechs to have exit and transition planning for critical third parties, and a bank partner is the most critical third party a fintech has.
So What?
The Bilt case is useful not because Bilt failed catastrophically — the harm was real but manageable, the CFPB chose informal remediation, and no formal enforcement record was created — but because it makes visible a failure mode that is usually invisible until it happens.
Three questions for your next TPRM review:
1. Does your bank partner agreement address what happens if the bank terminates early? Most MSAs and BaaS agreements cover the fintech’s exit rights in detail. Fewer address what the bank’s obligations are to support a transition if it terminates — payment continuity, data delivery, cooperation on account migration. If your agreement doesn’t address this, you are negotiating from scratch under time pressure when the termination notice arrives.
2. Do you have a bank partner contingency plan that isn’t the same as your general BCP? A business continuity plan addresses operational disruptions. A bank partner contingency plan addresses what happens to your product infrastructure if the bank relationship ends. They are different documents, with different triggers, different decision trees, and different remediation procedures. If your BCP covers bank partner transition as a subsection, it probably doesn’t cover it in enough detail.
3. Have you tested your reconciliation process against a transition scenario? The Synapse bankruptcy revealed that reconciliation records at fintechs were frequently insufficient to reconnect customer funds with customer accounts. A transition scenario is a stress test for the same capability: can you confirm, in real time, where every dollar of customer funds is and whether every in-flight transaction has been completed or returned?
If the answer to any of these is no — or “I think so” — the Bilt case is worth reading as a prompt to find out.
For related coverage, see our analysis of BaaS vendor exit planning in the wake of Synapse, what OCC bank partner consent orders mean for fintech programs, and the X Money / Cross River Bank enforcement case.
Sources:
- CFPB directs Bilt to reimburse customers affected by card transition (Banking Dive, June 2026)
- CFPB tells Bilt to repay fees from card-swap problems (Payments Dive, June 2026)
- CFPB issues response to Bilt’s bank transition troubles (American Banker, June 2026)
- 3 Takeaways from Bilt’s Breakup and Troubled Transition from Wells Fargo (Finovate, 2026)
- OCC Bulletin 2023-17 — Interagency Guidance on Third-Party Relationships
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What happened with Bilt and Wells Fargo in 2026?
Did the CFPB take formal enforcement action against Bilt?
What is bank partner exit risk and why does it matter for fintechs?
Does my TPRM program need to cover bank partner exit scenarios?
What did the Synapse bankruptcy add to the regulatory picture on bank partner transitions?
What does a bank partner exit plan need to cover?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
AiNET’s $1.8M SEC Data Center Settlement: A Vendor Certificate Is Not Evidence
The AiNET SEC data center settlement shows how a false Tier III claim can survive procurement. Here is the vendor evidence fix.
Aug 25, 2026
Third-Party Risk
What Your Sponsor Bank Is Actually Monitoring: The 2026 Fintech Oversight Playbook
Post-Synapse, sponsor banks moved from periodic due diligence reviews to continuous monitoring of fintech partners across seven operational dimensions. Here's what your bank partner's oversight team is tracking—and what documentation you need ready.
Aug 23, 2026
Third-Party Risk
DORA Register of Information: Turn the 2024 Dry-Run Results Into a Data-Quality Control
Only 6.5% of 947 integrated DORA dry-run registers passed all 116 checks. Here is a repeatable remediation and evidence process.
Aug 16, 2026