When Fintech Growth Outpaces Compliance: What the OCC’s Consent Order Against Community Federal Savings Bank Means for Your Institution

Over the past few years, many community banks have pursued fintech partnerships to diversify revenue and expand consumer offerings.  These types of partnerships, however, come with enhanced regulatory scrutiny, and it is crucial that community banks evaluate compliance programs as part of any fintech partnership.

On May 21, 2026, the Office of the Comptroller of the Currency (OCC) publicly released a consent order (docketed as AA-ENF-2025-21) against Community Federal Savings Bank (CFSB), a single-branch federal savings association in Woodhaven, New York. The enforcement action targets BSA/AML compliance failures that the OCC tied directly to CFSB’s rapid expansion into payment processing and fintech-adjacent business lines.

For community bank executives and compliance professionals, this action is not just another BSA/AML enforcement headline. It is a case study in what happens when a bank scales its business without proportionally scaling its compliance infrastructure.

What Happened at CFSB

CFSB is a small bank by traditional measures — roughly $866 million in assets as of year-end 2025. But its transaction volumes tell a different story. Since 2020, CFSB significantly grew its payment processing line, resulting in substantial annual wire and ACH activity, including cross-border transactions involving foreign financial institutions. That growth was fueled by CFSB’s role as a sponsor bank for several prominent fintechs, including Wise, Crypto.com, Airwallex, ChipperCash, and LemFi, among others. Crucially, CFSB’s fintech partners offer international payment or multi-currency services.

The OCC found that CFSB failed to develop and maintain controls and risk management processes commensurate with its growth. The consent order identifies violations of four distinct regulatory provisions: 12 CFR 21.21 (BSA/AML program requirements), 12 CFR 163.180(d) (suspicious activity reporting), 31 CFR 1020.210(a) (Anti-money laundering program requirements for federally-regulated banks), and 31 CFR 1010.520(b)(3) (information sharing requirements under Section 314(a) of the USA PATRIOT Act).

Specifically, the OCC found that CFSB’s automated suspicious activity monitoring system’s “filtering criteria and thresholds” were not adequately calibrated to the bank’s “payment processing risk profile, the significant increases in higher risk products and services, and international exposures.” Further, CFSB’s automated alert triage system contained several deficiencies, which resulted in the system auto-closing a “very high percentage” of alerts that should have been escalated for human review.

The OCC also found that CFSB’s customer due diligence program was deficient and that CFSB did not “understand the nature of certain customers’ businesses and the purpose of transactions flowing through its payment processing line, including risks related to foreign financial institutions.” Perhaps most strikingly, CFSB failed to determine whether it held correspondent accounts for foreign financial institutions, a fundamental obligation under the USA PATRIOT Act’s enhanced due diligence requirements. The OCC additionally noted  the bank’s internal auditor failed to identify BSA/AML program weaknesses and failed to test high-risk areas of the bank’s BSA/AML program.

Due to systemic breakdowns in internal controls, weak independent testing, and inadequate staffing, the OCC ultimately concluded that CFSB had not established and maintained a reasonably designed BSA/AML compliance program.

The Fintech Sponsor Bank Angle

This enforcement action did not occur in a vacuum. CFSB’s growth trajectory — from under $140 million in assets in 2017 to nearly $900 million by 2024 — was driven almost entirely by fintech partnerships. The bank served as the underlying banking rails for companies whose business models generate enormous transaction volumes; however, the Bank failed to scale its regulatory compliance programs with its growth.

The consent order makes clear that community banks entering into payment processing partnerships need to install sophisticated monitoring systems, robust customer identification programs, and modify staffing levels to ensure regulatory compliance. When your fintech partners are facilitating cross-border remittances, multi-currency accounts, and cryptocurrency-linked products, you inherit the risk profile of those activities — regardless of your asset size—and may need to manage complexities far beyond what a single-branch community bank would ordinarily face.

Notably, the order was signed through the Assistant Deputy Comptroller for Novel Bank Supervision and included an unusual clarification—the regulatory action is “based on concerns largely unrelated to customers involved in digital assets activities.” This suggests the OCC’s concerns centered on BSA/AML-related issues regarding payment processing and cross-border activity rather than digital assets specifically. Thus, banks considering fintech partnerships in the cross-border payment processing space are likely subject to  the same regulatory scrutiny.

Given the heightened regulatory scrutiny, community banks seeking to expand their operations to include payment processing and cross-border activity must scale their BSA/AML services accordingly. Financial institutions should thus actively consider how to ensure that their regulatory compliance program is properly designed and implemented—and the costs of those programs—before entering into any fintech partnerships. This includes, among other things, updating your automated monitoring systems, adding additional staff, evaluating the third-party relationships and the geographies served by the partnerships, and understanding the transaction types to ensure the systems can adequately manage the increased risk.

Key Compliance Takeaways

  1. Suspicious Activity Monitoring. The OCC’s Order specifically noted that CFSB’s suspicious activity monitoring system was not calibrated to its payment processing business and CFSB’s automated triage system auto-closed alerts that should have been reviewed. To ensure regulatory compliance, whenever you onboard a new business line or partner that materially changes your transaction profile, you should also review your monitoring thresholds. This includes creating clear definitions of customer risk categories and ensuring an effective methodology is in place to assign a customer’s risk category. Finally, you should also have a system in place to periodically review all customers and accounts that exhibit higher-risk characteristics to ensure that a process is in place if your automated alert system fails to detect high-risk transactions.
  2. Know Your Customer and Their Business. The OCC’s Order specifically noted that CFSB did not “understand the nature of certain customers’ businesses and the purpose of transactions flowing through its payment processing line.” In a banking as a service (BaaS) or sponsor bank model, your regulatory obligations extend to understanding the end users and transaction flows facilitated by your fintech partners. If you cannot articulate the nature of your customers’ businesses and the purpose of transactions flowing through your systems, regulators may find you have a due diligence gap. Regular reviews of customer profiles can also ensure that any missing or inaccurate customer due diligence information is timely identified and remediated.
  3. Cross-Border Activities. The failure to identify correspondent accounts for foreign financial institutions is a fundamental gap with serious regulatory consequences. If your fintech partners facilitate cross-border payments, determine whether any of those relationships constitute correspondent banking under the USA PATRIOT Act and apply appropriate enhanced due diligence.
  4. BSA/AML Testing Program. Whether your BSA/AML audit is conducted internally or by a third party, it must test whether controls are functioning as designed to detect any illicit financial activity risk. An audit that avoids high-risk or non-traditional banking areas provides false comfort and, as CFSB’s experience demonstrates, will be cited as a deficiency in its own right.
  5. BSA/AML Staffing. The OCC’s Order noted that CFSB had “weak BSA staffing.” Compliance cannot be a part-time function when your bank processes volumes that rival institutions many times your size. Budget for the compliance team your risk profile demands, not the one your asset size might suggest, and ensure that management’s and staff’s respective responsibilities for establishing and revising customer risk profiles are clearly defined.
  6. Conduct periodic, proactive reviews of Suspicious Activity Reports (“SAR”). Do not wait for an enforcement action to undertake a lookback. Periodic self-assessments of past alert dispositions and SAR decisions — particularly after system changes or new partner onboarding —can catch gaps before examiners do. If you detect any issues regarding the quality or accuracy of prior SAR filings, promptly remediate and report them. The goal is to comprehensively and accurately report any suspicious activities.

Looking Ahead: OCC Supervisory Priorities

The CFSB consent order arrives in a regulatory environment where the OCC has been far more active in terminating existing enforcement actions than entering new ones. Across April, May, and June 2026, the OCC terminated numerous formal agreements and consent orders while issuing only two new institutional consent orders — both of which targeted specific, identified compliance failures rather than broad safety-and-soundness concerns.

This pattern suggests the OCC is being selective and deliberate about where it deploys new enforcement resources. BSA/AML compliance, particularly at institutions with high transaction volumes driven by fintech partnerships, clearly remains a priority. The OCC has previously signaled — including through a November 2025 bulletin establishing Community Bank Minimum BSA/AML Examination Procedures — that it expects compliance programs to be dynamic and proportionate to institutional risk.

For community banks operating in the fintech partnership ecosystem, the message is clear: the OCC will not excuse compliance shortcomings because your bank is small. If you choose to take on the risk profile of a payments company, you must build the compliance infrastructure of one.

Renewed Vigilance is Required in Wake of Recent Amendments to EU Artificial Intelligence Act

On June 16, 2026, with mounting pressure from member states and industry groups, the European Parliament formally endorsed a provisional agreement delaying a significant enforcement milestone in the European Union’s Regulation (EU) 2024/1689 (the “Artificial Intelligence Act” or  “AI Act”), with significant consequences for businesses. Completed just under two months before the new enforcement guidelines were to take effect, the agreement extends various enforcement deadlines, eliminates certain duplicative manufacturer requirements, broadens small business exemptions, and adds new prohibitions on certain AI-generated intimate content.

Though the EU’s delay grants organizations additional time to comply with some obligations under the AI Act, delaying implementation of compliance measures could prove costly. Unlike the prior General Data Protection Regulation’s (“GDPR’s”) early enforcement period, EU regulators have already signaled their intent to enforce the AI Act from day one. Moreover, the EU AI Act has an extraterritorial reach—any AI system influencing decisions affecting EU residents, regardless of where a company is headquartered, may fall within the scope of the AI Act. The AI Act penalties are significant: ranging from €7.5 million or 1% of global annual turnover to €35 million or 7% of global annual turnover. For small companies, even the lower tier penalties represent existential exposure. This is not an abstract compliance exercise—rather, it is a binding legal framework with real penalties, obligations, and exposure that begins the moment enforcement powers fully activate.

Many businesses may unknowingly use, and therefore may be considered deployers of, high-risk AI systems regulated under the AI Act. These systems include:

  • Employment and Workforce Management: AI systems used for recruitment, candidate screening, performance evaluation, work allocation, or monitoring employee behavior.
  • Access to Essential Services: AI systems that evaluate an individual’s eligibility for, or access to, healthcare or wellness services are high-risk. For companies operating employee benefits platforms—including employee assistance programs (“EAPs”)—this category is directly relevant if AI is used to triage, route, or assess employee mental health or wellness needs. The threshold may be lower than you expect.
  • Insurance Risk Assessment: AI systems used in health and life insurance pricing or risk classification. Meaning that if your platform feeds data into underwriting or coverage determination processes, this may be implicated.

The delay shifts certain deadlines by creating a rolling deadline format. For example, the compliance deadline for AI systems outlined under Annex III, including High-Risk AI System Requirements (Articles 9–17 and 26) has moved to December 2, 2027—a 17-month extension. The deadline to comply with the rules for AI systems integrated into products subject to product safety regulations (Annex I) would become August 2, 2028—a 12-month extension), but even with the extensions, these deadlines can creep up in a hectic business environment. Here are six steps to take now:

Conduct an AI Inventory

Map every AI tool your company uses in connection with its EU operations or EU employees. Be sure to include vendor-provided SaaS tools with AI features, not just bespoke systems. Many companies are surprised by how many systems qualify.

Classify by Risk

For each AI system you identify, work with legal advisors to assess its risk category: prohibited, high-risk, or limited/minimal risk. This requires knowledge of both what the system does and how the AI Act specifically defines its risk categories.

Audit Your Vendor Contracts

Review any agreements with AI vendors for compliance-relevant provisions, including documentation delivery, log access, incident notification, EU representative obligations, and allocation of deployer vs. provider responsibilities. Most off-the-shelf agreements do not yet reflect the AI Act’s requirements. And for deployers of high-risk AI systems, obligations cannot be outsourced to AI vendors even where the vendor bears primary provider responsibilities.

Implement Deployer-Side Controls

For any high-risk AI system, start human oversight procedures, log retention practices, employee or user notification mechanisms, and any applicable Fundamental Rights Impact Assessment (FRIA). Document these in writing—the AI requires documentation and enforcement will look for it.

Review Your AI Literacy Obligations

An often-overlooked requirement—enforced since February 2025—is that organizations must ensure that staff who work with AI have appropriate AI literacy training. This is a minor obligation that can be addressed with modest internal effort. If you have not already implemented an AI literacy training program, now is the time to do so.

Integrate AI Governance Into Your Broader Compliance Program

AI Act compliance is not a one-time project. Instead, it requires ongoing monitoring as your company’s AI tools evolve, guidance is updated, and enforcement develops. Building AI Act compliance into your company’s broader compliance program, alongside GDPR and sector-specific obligations, will serve to minimize risks and costs in the long-term.

Companies should begin completing core steps immediately. Organizations waiting until 2027 will be starting from behind, with enforcement already active. We are available to guide you through this process whether you need a full EU AI Act readiness assessment, targeted vendor contract review, or specific guidance on high-risk classification for your product or service, we can provide scoped, efficient support designed for your business needs.

 


This article is intended as general client information and does not constitute legal advice. The EU AI Act is a complex and evolving regulation. Please consult with counsel regarding your specific circumstances.