Skip to content
RiskTemplates · The Daily Brief Sunday, September 27, 2026
Wire OFAC Just Codified Its Penalty Playbook. What 31 CFR Part 505 Means for Your Sanctions Compliance Program. SEP 26

Feature Operational Risk

FTC Made Corpay's CEO Pay Personally. The $100 Million Unauthorized Fee Case Rewrites What 'Authorization' Means for Billing Controls.

On September 17, 2026, the FTC announced a $100 million settlement with Corpay (formerly FleetCor) and personally named CEO Ronald Clarke for charging unauthorized fees on commercial fuel cards. The injunction's 'clear and unavoidable' disclosure standard goes further than any prior FTC action. Here's what every compliance team with a recurring billing product needs to audit.

By Rebecca Leung · September 26, 2026 ·
Table of Contents

TL;DR

  • On September 17, 2026, the FTC announced a $100 million settlement with Corpay Inc. (formerly FleetCor Technologies) for charging commercial fuel card customers fees they never authorized — and personally named CEO Ronald Clarke in the action
  • The court-approved injunction’s “clear and unavoidable” disclosure standard goes beyond the “clear and conspicuous” benchmark most compliance teams have used — fees disclosed only through hyperlinks or terms-of-service pages don’t meet it
  • Individual liability attached to Clarke because he received executive-level briefings on customer complaints about unauthorized charges — the knowledge element is the key enforcement hook
  • For any company with a recurring billing product: account terms authorization is not “express informed consent” for specific fees the customer didn’t encounter in the authorization flow

The FTC has been telegraphing this for months. Chairman Ferguson’s August public warning that H2 2026 would see a surge of enforcement actions the industry would “have a hard time keeping up with” set the table. The Corpay case is the main course.

On September 17, 2026, the FTC announced a $100 million settlement with Corpay Inc. — the commercial fleet card company formerly known as FleetCor Technologies — for charging customers fees they never authorized. The settlement came after a federal court upheld FTC summary judgment on the underlying claims. And it came with a permanent injunction whose “clear and unavoidable” fee disclosure standard reshapes what compliance programs need to build.

The case also came with something that should concentrate every C-suite’s attention: CEO Ronald Clarke was personally named.

What Corpay Did

Corpay’s commercial fuel card program is a B2B product — fleet operators use the cards to manage fuel purchases, track expenses, and control employee spending. The customer relationship is commercial, not consumer. That matters because the FTC’s enforcement actions more often target consumer products. The Corpay case extends the “unfair or deceptive acts or practices” framework squarely into commercial fee structures.

According to the FTC, Corpay charged its commercial customers fees that customers “never knew about and did not agree to pay.” The specific mechanics:

Fees disclosed only in terms of service. New fee categories were added to Corpay’s account terms — fees for fuel card maintenance, account management, and other services — without presenting those fees to existing customers in a way that required them to specifically see and acknowledge the charge. The disclosure existed; it was just inaccessible to anyone who didn’t re-read the full terms document.

Fees accessible only through hyperlinks. Certain fee disclosures in Corpay’s online enrollment and account management flows were linked out to separate documents rather than displayed in the transaction flow. The FTC’s position — upheld by the court — is that a disclosure that requires the customer to navigate to a different page to encounter it is not a disclosure that reaches the customer before they’re billed.

Fees introduced post-enrollment without affirmative consent. When Corpay added new fee categories to its commercial card program, the notification mechanism relied on terms-of-service updates rather than affirmative customer consent. Customers who didn’t read update notices were billed for fees they hadn’t specifically authorized.

The pattern the court found: Corpay’s authorization architecture was designed to minimize the friction of adding fees, not to ensure customers understood what they were agreeing to.

The “Clear and Unavoidable” Standard

The permanent injunction’s disclosure requirement is the part compliance teams need to read carefully.

Corpay is now required to provide “clear and unavoidable information” about any charge before billing a customer. The injunction specifies that material fee disclosures cannot be hidden behind a hyperlink or contained only in terms-of-service language. The disclosure must appear in the customer’s path through the billing or enrollment flow in a way that cannot be bypassed without affirmative action.

“Unavoidable” is the operative word. Most compliance teams have calibrated their disclosure reviews to the FTC’s “clear and conspicuous” standard — meaning the disclosure should be visible, not buried, and in language a reasonable customer can understand. That standard has been the baseline for a long time.

The Corpay injunction’s “clear and unavoidable” framing is a step further. A disclosure can be clear and conspicuous while still being avoidable — a checkbox the customer could skip, a disclosure panel on a page the customer wasn’t required to read, a terms link that appeared but wasn’t clicked. Unavoidable means the customer cannot complete the authorization flow without encountering the disclosure.

The practical implication: if your billing authorization UI allows a customer to complete enrollment or add a recurring charge without seeing the specific fee amount and affirmatively acknowledging it, that authorization flow doesn’t meet the Corpay injunction standard — and arguably doesn’t meet the FTC’s current enforcement expectations for any company operating in this space.

The CEO Personal Liability Hook

Ronald Clarke’s personal liability rests on the two-part FTC test for individual accountability: authority and knowledge.

Authority is usually easy to establish for a CEO. Clarke had the authority to direct Corpay’s billing practices. He set the product strategy, approved the fee structure, and oversaw the teams responsible for the commercial card program.

Knowledge is where individual liability cases turn. The FTC established knowledge through executive-level reporting: Clarke received briefings on the volume and nature of customer complaints about unexpected charges over multiple years. He didn’t need to know that every specific fee was unauthorized — he needed to know that the billing practices were generating the kind of customer harm that signals an authorization problem, and to have the authority to direct corrective action.

That pattern — executives who receive complaint-volume metrics but don’t connect complaint patterns to control failures — is the specific exposure vector the Corpay case illuminates. A CEO who receives a quarterly report showing that “fee disputes” represent a significant portion of customer service contacts has received a signal. What they do with that signal determines personal liability.

This mirrors the individual accountability framework the SEC has applied to compliance officers in enforcement actions: knowledge of a compliance problem, combined with authority to address it and failure to act, is the basis for personal accountability. The FTC is running the same playbook at the CEO level.

The FTC’s Accelerating Trajectory

This case doesn’t appear in isolation. FTC Chairman Ferguson publicly forecast a sustained enforcement surge in the second half of 2026, with companies in financial services explicitly named as a priority sector.

The Corpay case is the most financially significant of this enforcement surge so far. But the underlying fee-authorization framework applies across the industry. Commercial card programs, subscription fintech products, bank overdraft and account service fee structures, payment platform variable fees — all of these are subject to the same “express informed consent” analysis the FTC applied to Corpay’s fuel card program.

One feature of the current FTC enforcement posture is worth noting: the agency is not limiting its actions to consumer products. Corpay’s customer base is commercial — small business fleet operators, not individual consumers. The FTC has historically focused more enforcement energy on consumer products, where the deception or unfairness more directly harms individual people with limited market power. The Corpay case extends the FTC’s authorization framework into B2B fee structures where the buyer is a business, not a person.

That’s a significant expansion. Companies that assumed “our customers are businesses, not consumers” provided protection from this enforcement framework should reconsider that assumption.

What Your Billing Controls Need to Answer

Every compliance team with a product that charges recurring fees, variable fees, or post-enrollment fees should treat the Corpay injunction as an audit checklist. The operational risk question is whether your billing authorization controls would survive FTC scrutiny — not whether you’ve been charged.

For your RCSA process, the relevant control failures are specific:

Authorization flow audit. For each recurring fee your product charges, can you document the step in the enrollment or authorization flow where the customer specifically saw that fee and acknowledged it? “Agreed to terms of service” is not documentation — it’s the absence of documentation.

Hyperlink disclosure inventory. Identify every fee disclosure in your customer-facing materials that currently appears only as a link to a separate document. Those are candidates for remediation under the Corpay standard.

New fee introduction process. What is your company’s required customer consent mechanism when a new fee category is introduced or an existing fee is changed? If the answer is “terms of service update with email notice,” that’s the Corpay fact pattern.

Complaint signal monitoring. What metrics does your executive team receive on billing complaints and fee disputes? Does that reporting distinguish between complaints about fee amounts and complaints about fees customers say they didn’t authorize? If it doesn’t, you’re missing the signal the FTC used to establish Clarke’s personal knowledge.

RCSA linkage. Does your risk and control self-assessment score billing authorization controls as a material operational risk? An RCSA that categorizes unauthorized billing as a low-severity control environment but doesn’t link it to the financial exposure of regulatory action, customer remediation costs, and reputational harm is underweighting the risk.

What Remediating Looks Like

The firms that have navigated FTC enforcement actions most cleanly have done three things before an investigation begins:

Rebuilt the authorization flow to be unavoidable. This means specific fee disclosure, in the transaction path, requiring affirmative acknowledgment, before the charge is processed. Not a terms link. Not a collapsible section. Not a disclosure panel after payment information is submitted.

Created a fee change protocol with documented customer consent. When fees change, the change is not effective until the customer affirmatively acknowledges the new amount in the billing interface. This is operationally uncomfortable — it adds friction — but it’s what the Corpay injunction requires for Corpay and what the FTC’s enforcement theory requires for everyone else.

Redesigned complaint monitoring to surface authorization failures. Billing complaint metrics should include a specific category for “customer disputes the fee was authorized” — separate from “customer disputes the fee amount” and “customer disputes the billing date.” That category is the early warning signal for an authorization control failure.

The Corpay settlement is $100 million. The complaint data that established Clarke’s personal knowledge was in Corpay’s own internal reporting. The compliance infrastructure that would have intercepted this problem is the same infrastructure the FTC’s injunction now requires Corpay to build.

So What?

The Corpay case establishes a fee authorization standard that goes beyond what most compliance programs have been built to. The “clear and unavoidable” disclosure requirement isn’t limited to commercial fuel cards — it’s the FTC’s current enforcement theory for any recurring billing product.

For compliance teams, the immediate audit is straightforward even if the remediation isn’t:

  • Map every recurring fee to the specific authorization event in your enrollment or billing flow where the customer saw and acknowledged that fee
  • Identify hyperlink disclosures — every material fee disclosure that appears only as a link to a separate document is a control gap under the Corpay standard
  • Review your new-fee-introduction process — if it relies on terms updates rather than affirmative customer acknowledgment, it’s the Corpay fact pattern
  • Check your complaint reporting — does executive management receive data on complaints specifically about fee authorization, or only about fee amounts?

CEO Ronald Clarke’s personal liability wasn’t established by the fee structure alone. It was established by the combination of authority over that structure and repeated exposure to complaint data signaling it was broken. Every executive who receives billing complaint metrics and doesn’t specifically review the authorization-dispute subcategory is accumulating the same exposure.

The RCSA (Risk & Control Self-Assessment) provides the framework to assess billing authorization controls against the financial loss scenario they create — including regulatory penalty exposure, customer remediation costs, and the executive liability pathway the Corpay case established.


Sources: FTC v. Corpay Inc. — FTC Press Release, September 17, 2026; FTC Act Section 5 — Unfair or Deceptive Acts or Practices; FTC Enforcement Policy Statement on Negative Option Marketing, 2021; FTC Click-to-Cancel Rule, 2024; Gibson Dunn: FTC Individual Liability Standards in Consumer Protection Enforcement (2025)

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did Corpay (formerly FleetCor) do that violated the FTC Act?
According to the FTC, Corpay charged commercial fuel card customers fees they 'never knew about and did not agree to pay.' The violations included fees disclosed only in fine print or behind hyperlinks in online terms, fees added after initial enrollment without affirmative customer consent, and a billing structure where new fees were introduced with inadequate notice. A federal court upheld FTC summary judgment on these claims before the settlement was announced. The core finding: Corpay's authorization process — account terms and online disclosures — did not constitute express informed consent for each fee that was charged.
What is the 'clear and unavoidable' fee disclosure standard in the Corpay injunction?
The permanent injunction requires Corpay to provide 'clear and unavoidable information' about any charge before billing a customer. 'Unavoidable' means the customer must encounter the disclosure in a way that cannot be dismissed or skipped before completing the transaction — it cannot be buried in standard terms, disclosed only on a linked page, or presented in a way that a reasonable customer could complete enrollment without seeing it. This is a stricter standard than 'clear and conspicuous,' which many compliance teams have used as their benchmark.
Why was CEO Ronald Clarke personally named in the FTC action?
The FTC named Clarke personally because he had both the authority to direct Corpay's billing practices and actual knowledge that customers were complaining about unauthorized charges. Under FTC precedent, individual liability attaches when an individual holds a position of control at a company and knew or should have known about deceptive or unfair practices. Clarke reportedly received executive briefings on the volume and nature of customer complaints about unexpected fees over multiple years — giving the FTC the 'knowledge' element it needs to pierce corporate liability.
Does the 'express informed consent' standard apply only to commercial fuel card programs?
No. The injunction's framework is drawn from general FTC Act Section 5 principles about unfair and deceptive acts and practices, not from industry-specific rules. The 'express informed consent' requirement — that each billing event must be affirmatively authorized by the customer — applies to any recurring billing relationship where the fee structure can change, where fees are added after enrollment, or where fees are disclosed primarily in terms-of-service links rather than in the authorization flow itself. Commercial card programs, subscription fintech products, SAAS financial tools, bank fee programs with variable charges, and payment platform fee structures all share the same exposure.
What's the difference between 'account terms' authorization and 'express informed consent' for each fee?
This is the core issue the Corpay case resolves. Many companies have operated on the theory that a customer who agreed to terms of service — including a schedule of potential fees — has authorized any fee that falls within that schedule. The FTC's position, upheld by the court, is that account terms authorization is insufficient for fees that the customer didn't specifically understand at the time of enrollment. 'Express informed consent' for a billing event means the customer was presented with the specific charge, understood what they were authorizing, and affirmatively approved it — not that they clicked through a terms of service page that contained a fee schedule.
What should compliance teams audit in their billing authorization controls after this case?
Six audit questions: (1) For every recurring fee, can you document that the customer saw and affirmatively acknowledged that specific fee before it was first charged? (2) Are any material fee disclosures accessible only through a hyperlink or a terms document the customer wasn't required to read? (3) When new fees are introduced or existing fees changed, what is the required customer consent mechanism before the new fee is charged? (4) Does your fee disclosure appear in a position in the enrollment flow where a customer could complete enrollment without seeing it? (5) Does senior management receive reports on the volume and nature of billing complaints? (6) Do fee-related customer complaints receive separate operational risk treatment, or are they categorized as general customer service issues?
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

RCSA (Risk & Control Self-Assessment)

141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.