Two Takeaways from Turpin v. Charlotte Latin Schools, Inc.

 

Turpin v Charlotte Latin Schools, Inc. 86A23-2 Supreme Court of North Carolina Opinion of the Court

The North Carolina Supreme Court’s recent decision in Turpin v. Charlotte Latin Schools, Inc., No. 86A23-2 (N.C. Aug. 14, 2026) involves parents and their children expelled from a private school after the parents allegedly challenged curriculum changes. The facts of the case involve divisive political issues that often dominate social media and the news cycle. But for civil litigators, the opinion also includes two civil procedure developments that will likely matter far more than the underlying facts.

 

1. The Supreme Court Formally Adopts the Incorporation-by-Reference Doctrine

For years, North Carolina Court of Appeals decisions have held that a court reviewing a Rule 12(b)(6) motion may consider documents beyond the literal four corners of the complaint so long as the documents are referenced in the complaint, central to the plaintiff’s claims, and not disputed as to authenticity. Federal courts have long applied the same “incorporation-by-reference doctrine.” But until Turpin, the North Carolina Supreme Court had never expressly endorsed this standard for documents that were not attached to the complaint.

In Turpin, the Court took the opportunity to do exactly that. The Court set forth a clear three-part test: a court reviewing a motion to dismiss under Rule 12(b)(6) may consider a document submitted by the movant if (1) the document is referenced in the complaint, (2) the document is central to the factual allegations or the claims asserted, and (3) there is no dispute about the document’s authenticity.

The Court’s formal adoption of this rule confirms a powerful tool for defendants at the pleading stage. In Turpin, for example, the enrollment contracts, related emails, and a PowerPoint presentation were all considered on the motion to dismiss even though they were not attached to the complaint. Previously, counsel had to rely on Court of Appeals authority like Oberlin Capital, L.P. v. Slavin, 147 N.C. App. 52 (2001), when arguing that such documents outside the complaint could be considered. Now, there is binding Supreme Court precedent.

For moving parties drafting a Rule 12(b)(6) motion, it will be even more important to identify and consider every document that is referenced in the complaint and central to the plaintiff’s claims. If its authenticity is undisputed, consider attaching it to your motion and argue from its actual contents, not just from the plaintiff’s characterization in the complaint. And if you are on the plaintiff’s side, draft your complaint with the understanding that any document you reference may be examined by the court at the pleading stage and may even be credited over conflicting allegations.

2. A Signal That North Carolina’s Pleading Standard May Be Ripe for Change

Perhaps the most intriguing passage in Turpin has nothing to do with the facts of the case. In the course of analyzing the Turpins’ fraud claim, the Court acknowledged that the fraud claims might fail under the federal Twombly/Iqbal “plausibility” standard. The majority also added a notable aside.

The Court observed that the federal courts moved away from the “notice pleading” test two decades ago, replacing the familiar “no set of facts” standard with a requirement that a plaintiff plead “enough facts to state a claim to relief that is plausible on its face.” The Court noted the tension between the nearly identical language in the state and federal rules, stating that “[i]t is strange that both federal law and state law use almost exactly the same language in their pleading rules but there could be such a stark difference in outcomes.” Then the Court remarked that “[i]n an appropriate case, this Court might examine the resulting tension and whether our state law should evolve to avoid this outcome in the future.”

The Court stopped short of changing the standard, explaining that “defendants did not ask us to do so here, nor did the defendants in other recent cases where we have restated the familiar ‘no set of facts’ standard.” Yet the Supreme Court was clearly suggesting that if a party properly raises the issue, the Court may be willing to consider whether North Carolina should adopt a plausibility standard akin to Twombly and Iqbal.

The dissent reinforced this theme. Justice Riggs questioned how defendants could ever succeed at the 12(b)(6) stage “if all a plaintiff needs to do is allege that a statement was made somewhere, to someone.” The dissent explicitly asked: “How vague is too vague to survive under Rule 12(b)(6)?” and “Do we permit every vague statement, merely because we must assume that it is true?” Justice Riggs urged the Court to “clarify specificity under the notice pleading requirements.”

Turpin thus seems to be an invitation for party filing a Rule 12(b)(6) motion in a case where the complaint is long on conclusions and short on plausible factual support to consider briefing the question of whether North Carolina should adopt the Twombly/Iqbal plausibility standard. The Supreme Court is at least open to the argument.

For plaintiffs, the signal is equally important. Even under the current notice pleading standard, the Turpin majority repeatedly emphasized that the plaintiffs would have a “daunting task” proving their fraud claim and that their sixty-page complaint “occasionally resemble[d] a press release more than a legal filing.” If the plausibility standard does come to North Carolina, vague and conclusory complaints will no longer survive on the theory that some conceivable set of facts might support relief.

The Bottom Line

The substantive holdings on contract, fraud, and defamation in Turpin are worth reviewing, but the civil procedure discussion is at least equally interesting. First, the incorporation-by-reference doctrine is now binding Supreme Court precedent. Use it the next time you attach a contract, email chain, or some other document to a Rule 12(b)(6) motion. Second, the Court has signaled that they are open to a litigant willing to brief whether North Carolina should adopt the Twombly/Iqbal plausibility standard. If you represent defendants, that brief is now worth writing. If you represent plaintiffs, assume someone will write it soon and tighten your complaints accordingly. Either way, Turpin should impact how North Carolina litigants write their next Rule 12(b)(6) motion and complaint.

When Fintech Growth Outpaces Compliance: What the OCC’s Consent Order Against Community Federal Savings Bank Means for Your Institution

Over the past few years, many community banks have pursued fintech partnerships to diversify revenue and expand consumer offerings.  These types of partnerships, however, come with enhanced regulatory scrutiny, and it is crucial that community banks evaluate compliance programs as part of any fintech partnership.

On May 21, 2026, the Office of the Comptroller of the Currency (OCC) publicly released a consent order (docketed as AA-ENF-2025-21) against Community Federal Savings Bank (CFSB), a single-branch federal savings association in Woodhaven, New York. The enforcement action targets BSA/AML compliance failures that the OCC tied directly to CFSB’s rapid expansion into payment processing and fintech-adjacent business lines.

For community bank executives and compliance professionals, this action is not just another BSA/AML enforcement headline. It is a case study in what happens when a bank scales its business without proportionally scaling its compliance infrastructure.

What Happened at CFSB

CFSB is a small bank by traditional measures — roughly $866 million in assets as of year-end 2025. But its transaction volumes tell a different story. Since 2020, CFSB significantly grew its payment processing line, resulting in substantial annual wire and ACH activity, including cross-border transactions involving foreign financial institutions. That growth was fueled by CFSB’s role as a sponsor bank for several prominent fintechs, including Wise, Crypto.com, Airwallex, ChipperCash, and LemFi, among others. Crucially, CFSB’s fintech partners offer international payment or multi-currency services.

The OCC found that CFSB failed to develop and maintain controls and risk management processes commensurate with its growth. The consent order identifies violations of four distinct regulatory provisions: 12 CFR 21.21 (BSA/AML program requirements), 12 CFR 163.180(d) (suspicious activity reporting), 31 CFR 1020.210(a) (Anti-money laundering program requirements for federally-regulated banks), and 31 CFR 1010.520(b)(3) (information sharing requirements under Section 314(a) of the USA PATRIOT Act).

Specifically, the OCC found that CFSB’s automated suspicious activity monitoring system’s “filtering criteria and thresholds” were not adequately calibrated to the bank’s “payment processing risk profile, the significant increases in higher risk products and services, and international exposures.” Further, CFSB’s automated alert triage system contained several deficiencies, which resulted in the system auto-closing a “very high percentage” of alerts that should have been escalated for human review.

The OCC also found that CFSB’s customer due diligence program was deficient and that CFSB did not “understand the nature of certain customers’ businesses and the purpose of transactions flowing through its payment processing line, including risks related to foreign financial institutions.” Perhaps most strikingly, CFSB failed to determine whether it held correspondent accounts for foreign financial institutions, a fundamental obligation under the USA PATRIOT Act’s enhanced due diligence requirements. The OCC additionally noted  the bank’s internal auditor failed to identify BSA/AML program weaknesses and failed to test high-risk areas of the bank’s BSA/AML program.

Due to systemic breakdowns in internal controls, weak independent testing, and inadequate staffing, the OCC ultimately concluded that CFSB had not established and maintained a reasonably designed BSA/AML compliance program.

The Fintech Sponsor Bank Angle

This enforcement action did not occur in a vacuum. CFSB’s growth trajectory — from under $140 million in assets in 2017 to nearly $900 million by 2024 — was driven almost entirely by fintech partnerships. The bank served as the underlying banking rails for companies whose business models generate enormous transaction volumes; however, the Bank failed to scale its regulatory compliance programs with its growth.

The consent order makes clear that community banks entering into payment processing partnerships need to install sophisticated monitoring systems, robust customer identification programs, and modify staffing levels to ensure regulatory compliance. When your fintech partners are facilitating cross-border remittances, multi-currency accounts, and cryptocurrency-linked products, you inherit the risk profile of those activities — regardless of your asset size—and may need to manage complexities far beyond what a single-branch community bank would ordinarily face.

Notably, the order was signed through the Assistant Deputy Comptroller for Novel Bank Supervision and included an unusual clarification—the regulatory action is “based on concerns largely unrelated to customers involved in digital assets activities.” This suggests the OCC’s concerns centered on BSA/AML-related issues regarding payment processing and cross-border activity rather than digital assets specifically. Thus, banks considering fintech partnerships in the cross-border payment processing space are likely subject to  the same regulatory scrutiny.

Given the heightened regulatory scrutiny, community banks seeking to expand their operations to include payment processing and cross-border activity must scale their BSA/AML services accordingly. Financial institutions should thus actively consider how to ensure that their regulatory compliance program is properly designed and implemented—and the costs of those programs—before entering into any fintech partnerships. This includes, among other things, updating your automated monitoring systems, adding additional staff, evaluating the third-party relationships and the geographies served by the partnerships, and understanding the transaction types to ensure the systems can adequately manage the increased risk.

Key Compliance Takeaways

  1. Suspicious Activity Monitoring. The OCC’s Order specifically noted that CFSB’s suspicious activity monitoring system was not calibrated to its payment processing business and CFSB’s automated triage system auto-closed alerts that should have been reviewed. To ensure regulatory compliance, whenever you onboard a new business line or partner that materially changes your transaction profile, you should also review your monitoring thresholds. This includes creating clear definitions of customer risk categories and ensuring an effective methodology is in place to assign a customer’s risk category. Finally, you should also have a system in place to periodically review all customers and accounts that exhibit higher-risk characteristics to ensure that a process is in place if your automated alert system fails to detect high-risk transactions.
  2. Know Your Customer and Their Business. The OCC’s Order specifically noted that CFSB did not “understand the nature of certain customers’ businesses and the purpose of transactions flowing through its payment processing line.” In a banking as a service (BaaS) or sponsor bank model, your regulatory obligations extend to understanding the end users and transaction flows facilitated by your fintech partners. If you cannot articulate the nature of your customers’ businesses and the purpose of transactions flowing through your systems, regulators may find you have a due diligence gap. Regular reviews of customer profiles can also ensure that any missing or inaccurate customer due diligence information is timely identified and remediated.
  3. Cross-Border Activities. The failure to identify correspondent accounts for foreign financial institutions is a fundamental gap with serious regulatory consequences. If your fintech partners facilitate cross-border payments, determine whether any of those relationships constitute correspondent banking under the USA PATRIOT Act and apply appropriate enhanced due diligence.
  4. BSA/AML Testing Program. Whether your BSA/AML audit is conducted internally or by a third party, it must test whether controls are functioning as designed to detect any illicit financial activity risk. An audit that avoids high-risk or non-traditional banking areas provides false comfort and, as CFSB’s experience demonstrates, will be cited as a deficiency in its own right.
  5. BSA/AML Staffing. The OCC’s Order noted that CFSB had “weak BSA staffing.” Compliance cannot be a part-time function when your bank processes volumes that rival institutions many times your size. Budget for the compliance team your risk profile demands, not the one your asset size might suggest, and ensure that management’s and staff’s respective responsibilities for establishing and revising customer risk profiles are clearly defined.
  6. Conduct periodic, proactive reviews of Suspicious Activity Reports (“SAR”). Do not wait for an enforcement action to undertake a lookback. Periodic self-assessments of past alert dispositions and SAR decisions — particularly after system changes or new partner onboarding —can catch gaps before examiners do. If you detect any issues regarding the quality or accuracy of prior SAR filings, promptly remediate and report them. The goal is to comprehensively and accurately report any suspicious activities.

Looking Ahead: OCC Supervisory Priorities

The CFSB consent order arrives in a regulatory environment where the OCC has been far more active in terminating existing enforcement actions than entering new ones. Across April, May, and June 2026, the OCC terminated numerous formal agreements and consent orders while issuing only two new institutional consent orders — both of which targeted specific, identified compliance failures rather than broad safety-and-soundness concerns.

This pattern suggests the OCC is being selective and deliberate about where it deploys new enforcement resources. BSA/AML compliance, particularly at institutions with high transaction volumes driven by fintech partnerships, clearly remains a priority. The OCC has previously signaled — including through a November 2025 bulletin establishing Community Bank Minimum BSA/AML Examination Procedures — that it expects compliance programs to be dynamic and proportionate to institutional risk.

For community banks operating in the fintech partnership ecosystem, the message is clear: the OCC will not excuse compliance shortcomings because your bank is small. If you choose to take on the risk profile of a payments company, you must build the compliance infrastructure of one.

Renewed Vigilance is Required in Wake of Recent Amendments to EU Artificial Intelligence Act

On June 16, 2026, with mounting pressure from member states and industry groups, the European Parliament formally endorsed a provisional agreement delaying a significant enforcement milestone in the European Union’s Regulation (EU) 2024/1689 (the “Artificial Intelligence Act” or  “AI Act”), with significant consequences for businesses. Completed just under two months before the new enforcement guidelines were to take effect, the agreement extends various enforcement deadlines, eliminates certain duplicative manufacturer requirements, broadens small business exemptions, and adds new prohibitions on certain AI-generated intimate content.

Though the EU’s delay grants organizations additional time to comply with some obligations under the AI Act, delaying implementation of compliance measures could prove costly. Unlike the prior General Data Protection Regulation’s (“GDPR’s”) early enforcement period, EU regulators have already signaled their intent to enforce the AI Act from day one. Moreover, the EU AI Act has an extraterritorial reach—any AI system influencing decisions affecting EU residents, regardless of where a company is headquartered, may fall within the scope of the AI Act. The AI Act penalties are significant: ranging from €7.5 million or 1% of global annual turnover to €35 million or 7% of global annual turnover. For small companies, even the lower tier penalties represent existential exposure. This is not an abstract compliance exercise—rather, it is a binding legal framework with real penalties, obligations, and exposure that begins the moment enforcement powers fully activate.

Many businesses may unknowingly use, and therefore may be considered deployers of, high-risk AI systems regulated under the AI Act. These systems include:

  • Employment and Workforce Management: AI systems used for recruitment, candidate screening, performance evaluation, work allocation, or monitoring employee behavior.
  • Access to Essential Services: AI systems that evaluate an individual’s eligibility for, or access to, healthcare or wellness services are high-risk. For companies operating employee benefits platforms—including employee assistance programs (“EAPs”)—this category is directly relevant if AI is used to triage, route, or assess employee mental health or wellness needs. The threshold may be lower than you expect.
  • Insurance Risk Assessment: AI systems used in health and life insurance pricing or risk classification. Meaning that if your platform feeds data into underwriting or coverage determination processes, this may be implicated.

The delay shifts certain deadlines by creating a rolling deadline format. For example, the compliance deadline for AI systems outlined under Annex III, including High-Risk AI System Requirements (Articles 9–17 and 26) has moved to December 2, 2027—a 17-month extension. The deadline to comply with the rules for AI systems integrated into products subject to product safety regulations (Annex I) would become August 2, 2028—a 12-month extension), but even with the extensions, these deadlines can creep up in a hectic business environment. Here are six steps to take now:

Conduct an AI Inventory

Map every AI tool your company uses in connection with its EU operations or EU employees. Be sure to include vendor-provided SaaS tools with AI features, not just bespoke systems. Many companies are surprised by how many systems qualify.

Classify by Risk

For each AI system you identify, work with legal advisors to assess its risk category: prohibited, high-risk, or limited/minimal risk. This requires knowledge of both what the system does and how the AI Act specifically defines its risk categories.

Audit Your Vendor Contracts

Review any agreements with AI vendors for compliance-relevant provisions, including documentation delivery, log access, incident notification, EU representative obligations, and allocation of deployer vs. provider responsibilities. Most off-the-shelf agreements do not yet reflect the AI Act’s requirements. And for deployers of high-risk AI systems, obligations cannot be outsourced to AI vendors even where the vendor bears primary provider responsibilities.

Implement Deployer-Side Controls

For any high-risk AI system, start human oversight procedures, log retention practices, employee or user notification mechanisms, and any applicable Fundamental Rights Impact Assessment (FRIA). Document these in writing—the AI requires documentation and enforcement will look for it.

Review Your AI Literacy Obligations

An often-overlooked requirement—enforced since February 2025—is that organizations must ensure that staff who work with AI have appropriate AI literacy training. This is a minor obligation that can be addressed with modest internal effort. If you have not already implemented an AI literacy training program, now is the time to do so.

Integrate AI Governance Into Your Broader Compliance Program

AI Act compliance is not a one-time project. Instead, it requires ongoing monitoring as your company’s AI tools evolve, guidance is updated, and enforcement develops. Building AI Act compliance into your company’s broader compliance program, alongside GDPR and sector-specific obligations, will serve to minimize risks and costs in the long-term.

Companies should begin completing core steps immediately. Organizations waiting until 2027 will be starting from behind, with enforcement already active. We are available to guide you through this process whether you need a full EU AI Act readiness assessment, targeted vendor contract review, or specific guidance on high-risk classification for your product or service, we can provide scoped, efficient support designed for your business needs.

 


This article is intended as general client information and does not constitute legal advice. The EU AI Act is a complex and evolving regulation. Please consult with counsel regarding your specific circumstances.