Skip to content
RiskTemplates · The Daily Brief Tuesday, September 15, 2026
Wire SEC's $64 Million Croft & Frost Offering Fraud Case: The Warning Email Compliance Teams Cannot Ignore SEP 14

Feature Compliance Strategy

Your BSA/AML Compliance Program Can't Scale in Arrears: What the CFSB Consent Order Means for Every Fintech

In April 2026, the OCC issued a consent order against Community Federal Savings Bank — sponsor bank for Wise, Crypto.com, Airwallex, ChipperCash, and LemFi — for BSA/AML compliance failures so severe that its alert system was auto-closing a very high percentage of suspicious-activity flags. Here's what that means for the fintechs riding those rails, and what every fintech compliance team can learn about scaling a BSA program that doesn't collapse under its own transaction volume.

By Rebecca Leung · September 14, 2026 ·
Table of Contents

TL;DR

  • The OCC issued a consent order against Community Federal Savings Bank (CFSB) in April 2026 for BSA/AML compliance failures — including auto-closing a “very high percentage” of suspicious-activity alerts and weak independent testing that missed program weaknesses entirely.
  • CFSB is the sponsor bank for Wise, Crypto.com, Airwallex, ChipperCash, and LemFi — high-volume cross-border payment businesses whose transaction monitoring depends partly on CFSB’s compliance infrastructure.
  • The core failure: CFSB’s BSA program didn’t scale with its transaction volume. The OCC’s “commensurate with risk” standard doesn’t give credit for prior-year controls that no longer fit current risk.
  • For every fintech compliance team: your BSA program needs to be sized for what you do now, not what you did when you wrote it. And your sponsor bank’s compliance failures are your TPRM exposure.

Community Federal Savings Bank is a single-branch federal savings association in Woodhaven, New York. One branch. One building. And — until the OCC’s April 2026 consent order made it public — it was the banking infrastructure underpinning wire and ACH flows for Wise, Crypto.com, Airwallex, ChipperCash, LemFi, and others.

The OCC’s finding, in plain terms: the bank’s BSA/AML compliance program was not built for the business it was running. Since 2020, CFSB had dramatically expanded its payment processing business, accumulating “significant annual wire and ACH activity, including cross-border activity involving foreign financial institutions.” The compliance program did not expand at the same pace. The result was a program that the OCC concluded had “systemic breakdowns in internal controls, weak independent testing, and inadequate staffing.”

The most damaging specific finding: CFSB’s transaction monitoring system was auto-closing a “very high percentage” of suspicious-activity alerts without review. Not routing them to analysts. Not escalating them for human judgment. Closing them automatically.

For fintechs who care about compliance program design — whether they’re riding CFSB’s rails or not — this order is a clinic.

The OCC consent order (AA-ENF-2025-21, entered April 2026, published May 21, 2026) identified a series of interconnected failures that together demonstrate what happens when compliance infrastructure doesn’t keep pace with business growth.

Internal controls: The bank’s controls over transaction monitoring were insufficient relative to its risk profile. The automatic alert disposition — closing flags without review — was the most visible symptom, but it was a symptom of a deeper control design failure.

Independent testing: The bank’s internal auditor “failed to identify BSA/AML program weaknesses” and did not scope audit work into the bank’s high-risk areas. This is the kind of finding that keeps examiners up at night. An audit function that doesn’t go where the risk is highest doesn’t give leadership any visibility into where the program is breaking down. By the time the OCC showed up, the gaps had compounded across multiple exam cycles.

Staffing: The OCC found that CFSB’s BSA/AML staff was not adequate to support the business it was running. This is the “commensurate with risk” standard in practice: if your transaction volumes have tripled since you last right-sized your compliance team, your compliance program is running a deficit.

Remediation ordered: CFSB was required to develop and implement a risk-based suspicious activity review program, engage an independent third-party consultant to review its SAR monitoring, rebuild its independent testing program, and ensure adequate staffing with appropriate training and expertise.

The “Commensurate with Risk” Standard Is Not Static

Every BSA/AML compliance professional knows the phrase. The FFIEC BSA/AML Examination Manual uses it extensively: controls must be “commensurate with the bank’s risk profile.” The OCC applies it as the benchmark for whether a program is adequately designed.

What the CFSB order makes clear is that “commensurate” is a moving target. A program that was adequate at 2020 transaction volumes may not be adequate at 2025 transaction volumes. A compliance function sized for a small community bank may not be adequate for a bank processing Wise’s payment corridors.

The OCC isn’t asking whether you had controls in place five years ago. It’s asking whether your controls are sufficient for the risk you carry today. If your business has grown and your compliance program hasn’t, you are running a deficit — whether or not you know it.

For fintechs, this principle applies directly. Your BSA/AML program needs to reflect your current product mix, customer risk profile, transaction volumes, and geographic exposure. A program you built at Series A doesn’t work at Series C without updates. A risk assessment written when you had 10,000 customers isn’t adequate for 500,000. The obligation to refresh isn’t optional — it’s built into the standard.

What Auto-Closing Alerts Actually Means

The auto-closure finding deserves more attention than it typically gets in post-mortems.

Every transaction monitoring system generates alerts. No compliance team can manually review every alert a modern system generates, especially at scale. Alert management — the process of reviewing, escalating, closing, and documenting alerts — is where the rubber meets the road in BSA/AML compliance.

The OCC’s finding that CFSB auto-closed a “very high percentage” of alerts points to a system design and operational failure. A well-run alert management program looks something like this: alerts are generated based on pre-defined rules and scenarios; alerts that meet certain criteria (small dollar amount, known counterparty, no unusual patterns) can be closed efficiently by a trained analyst with documented rationale; higher-risk alerts are escalated for investigation; investigations that identify unusual activity result in SAR filings.

Auto-closure without review removes the human judgment from the process. It doesn’t mean no alerts are being reviewed — but it does mean that the threshold for human review has been set so high, or the automated disposition logic is so broad, that a substantial portion of potentially suspicious activity is being cleared without examination.

For an institution running cross-border payment volume through multiple fintech corridors, this is precisely the scenario where correspondent banking and money movement risks are highest. The CFSB finding is, in that context, a significant compliance failure — one that the OCC found could not be remediated without external oversight.

The Independent Testing Failure Is the Quieter Problem

Auto-closing alerts is visible. The failure of independent testing to catch it is the problem that compounds.

BSA/AML independent testing — the fourth pillar of the FFIEC framework — is supposed to provide exactly the kind of detection the CFSB story shows was missing. A competent, properly scoped audit function reviewing transaction monitoring operations should ask: what is our alert auto-closure rate, and is that rate appropriate? What percentage of alerts result in human review? What is the disposition rate on investigated alerts?

CFSB’s auditor didn’t scope its work into the bank’s high-risk business areas. That means it was reviewing the low-risk areas while the high-risk areas operated without independent scrutiny. The OCC wasn’t learning anything from the audit reports that it couldn’t have inferred from the risk profile.

For financial institutions and fintechs building or operating BSA independent testing programs, the CFSB finding is a reminder that scoping is everything. If your audit coverage doesn’t follow your risk concentration, it isn’t providing the assurance it’s supposed to provide. The FFIEC independent testing requirements aren’t fulfilled by running an audit that avoids your highest-risk lines. That’s the compliance equivalent of testing the fire alarm in the break room but not in the server room.

What This Means for Fintechs on CFSB’s Rails

Wise, Crypto.com, Airwallex, ChipperCash, and LemFi are not named in the consent order. But they are not insulated from it.

Each of these firms relies on CFSB for some portion of its banking infrastructure — payment processing rails, account maintenance, wire execution, ACH settlement. The transaction monitoring that catches suspicious patterns in those flows runs partly through CFSB’s compliance program. A consent order requiring a complete rebuild of that program creates real operational and compliance uncertainty.

First, there’s the timeline question. Consent order remediation typically takes 12–24 months of active OCC oversight. During that period, CFSB must bring in an independent third-party consultant, rebuild its monitoring program, improve its testing, and demonstrate to the OCC that the new controls are operating effectively. Fintechs on its rails should expect changes to onboarding controls, SAR filing practices, and potentially transaction monitoring thresholds during this period.

Second, there’s the secondary exposure question. If CFSB’s BSA/AML program was auto-closing a high percentage of suspicious alerts in the periods before the consent order, were SAR filings for the fintechs’ underlying customers adequate? If a regulator later scrutinizes those filings, the fintech’s own BSA obligation doesn’t disappear because the sponsor bank handled the filing.

Third, there’s the TPRM question. For any fintech whose sponsor bank or critical vendor has just received a regulatory consent order, that event should trigger a review of your third-party risk management posture. What contractual protections do you have? What is the notification obligation? What are the contingency options? The IDScan.net breach post from this morning covers similar territory from the KYC vendor angle — and the principle is the same: your vendor’s compliance failure lands on your desk.

Note also that the OCC has separately denied charter applications for Wise and Bunq in 2026, citing AML concerns. The CFSB order and the charter denials together suggest that OCC scrutiny of the specific fintech risk ecosystem around cross-border payment corridors is intensifying.

Building a BSA/AML Program That Passes the Commensurate Test

The CFSB story is not an edge case. It’s a pattern that plays out repeatedly in BSA/AML enforcement: fast business growth, compliance infrastructure that doesn’t keep pace, and an independent testing function that misses the accumulation of risk. The pattern has played out at large broker-dealers and community banks alike.

Here’s the discipline that prevents it:

Tie your BSA risk assessment refresh to business growth events, not just the calendar. An annual refresh is the floor. When you add a new payment corridor, onboard a significant new customer segment, or substantially increase transaction volumes, that’s a trigger for an out-of-cycle BSA risk assessment update. The FFIEC manual anticipates this: the assessment should reflect your current risk, not last year’s risk.

Audit your alert disposition, not just your alert generation. Your transaction monitoring system’s alert volume tells you how noisy it is. Your alert disposition rates — what percentage is closed without review, investigated, or escalated to SAR — tell you whether the program is actually working. If your auditor isn’t reviewing disposition data, you’re leaving the most important question unanswered.

Make independent testing scope follow risk concentration. If your highest-risk business lines are not in the audit scope, your audit is providing a false sense of assurance. Audit scope documentation should show explicit coverage of your highest-risk product lines, customer segments, and transaction corridors. If it doesn’t, that’s the conversation to have with your audit function before the next examination.

Staff for your current business, not your former self. “Adequate staffing” is a moving target that tracks with transaction volume, customer complexity, and product mix. If your transaction volume has grown materially since you last reviewed your BSA staffing model, you should be reassessing it — not waiting for an OCC exam to identify the gap.

The AML/BSA Risk Assessment Template covers the institutional risk assessment structure the FFIEC exam manual uses — four risk categories (products and services, customer types, geographies, delivery channels) with inherent-to-residual scoring. It ships pre-populated with 32 fintech-specific risk factors and includes a five-pillar control inventory mapped to the standard with owners, evidence, and testing status. If your current BSA risk assessment isn’t organized around those categories, the CFSB order is a good reason to fix it.

So What?

The CFSB consent order is fundamentally about a compliance program that didn’t grow with its business. That failure isn’t unique to sponsor banks. It’s one of the most common compliance gaps across fintech.

If you’re running a growing fintech, ask yourself: when was your BSA/AML risk assessment last updated? Does your transaction monitoring scope cover your current customer base and product corridors? Is your independent testing function scoped into your highest-risk areas? Does your compliance team have the bandwidth to review alerts, run the program, and actually investigate suspicious patterns?

If the honest answers to those questions are “over a year ago,” “probably not,” “I’m not sure,” and “barely” — you’re closer to the CFSB pattern than you might be comfortable with.

The OCC’s consent order against CFSB is a public record. The exam that led to it reflects scrutiny that will be applied to the next institution in this pattern, and the one after that. The question isn’t whether examiners will eventually look at your BSA program at scale. It’s whether your program will hold up when they do.


Sources: OCC Enforcement Actions for May 2026 — NR-OCC-2026-40 | American Banker — Sponsor Bank for Wise, Crypto.com Told to Fix AML Program | Wagner Hicks PLLC — When Fintech Growth Outpaces Compliance | National Law Review — OCC’s Recent Consent Order Is a Warning for Community Banks | Financial Services Perspectives — OCC Consent Order Warning for Community Banks

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the OCC find wrong with CFSB's BSA/AML program?
The OCC identified systemic breakdowns across the key pillars: weak internal controls, an auto-closure rate on suspicious activity alerts that the OCC characterized as a 'very high percentage,' an internal auditor that failed to scope its work into high-risk areas and thus missed program weaknesses entirely, and staffing that was not commensurate with the bank's risk profile. CFSB had significantly expanded its payment processing business since 2020 — processing substantial wire and ACH volume including cross-border activity — but did not build its BSA/AML infrastructure at the same pace.
Which fintechs use CFSB as their sponsor bank?
American Banker and Fintech Business Weekly reported that CFSB serves as sponsor bank for Wise, Crypto.com, Airwallex, ChipperCash, and LemFi, among others. These are high-volume, cross-border payment businesses — exactly the customer profile that generates significant BSA/AML obligations and requires robust transaction monitoring infrastructure.
What does 'commensurate with risk' mean in BSA/AML compliance?
'Commensurate with risk' is the standard the OCC and FFIEC apply when evaluating whether a BSA/AML program is adequately designed and resourced. It means the sophistication, coverage, staffing, and testing intensity of your compliance program must match your actual risk profile — transaction volumes, customer types, geographies, and product complexity. A bank running Wise and Crypto.com transaction volumes through a single-branch institution's compliance infrastructure is not commensurate with its risk.
What does this order mean for the fintechs on CFSB's rails?
Their transaction monitoring and SAR filing obligations are partly executed by CFSB's compliance program. If that program is under-resourced and auto-closing alerts, fintechs face secondary exposure: the bank's SAR filing failures could affect regulatory views of the fintech's own BSA compliance, and the consent order's remediation timeline creates uncertainty about product roadmaps, onboarding controls, and transaction processing stability. Fintechs should treat a sponsor bank consent order as a TPRM trigger event.
How does the CFSB order relate to the OCC consent order against CFSB's fintech tenants?
CFSB itself is the subject of the enforcement action. Its fintech customers — Wise, Crypto.com, Airwallex, etc. — are not named in the consent order, but they are directly affected. The OCC's finding that CFSB lacked adequate controls over its high-risk business lines translates directly to the fintechs that depend on those rails. Separately, note that the OCC also denied charter applications to Wise and Bunq earlier in 2026, citing AML concerns — suggesting regulators have a broader view of AML risk at the firms using CFSB as sponsor.
What are the five pillars of a BSA/AML compliance program?
The FFIEC BSA/AML Examination Manual outlines five pillars: (1) internal policies, procedures, and controls; (2) designation of a BSA compliance officer; (3) an ongoing employee training program; (4) an independent testing function; and (5) customer due diligence and beneficial ownership procedures. The CFSB consent order found failures across at least three of these: internal controls, independent testing, and adequate staffing. A program that passes examination needs documented, operating controls across all five.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AML/BSA Risk Assessment Template (Fintech Edition)

32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.