Initial research article published September 26, 2026.
Case and legal status
The OCC's January 24, 2024 consent order against Blue Ridge Bank addressed BSA/AML, capital, strategic planning, liquidity, information technology and third-party fintech risks. The order restricted onboarding of new third-party fintech relationships while deficiencies remained and required board oversight, remediation plans, risk assessments, staffing and reporting. The OCC terminated the order in November 2025, so the original restrictions are no longer active; the case remains a useful public control map.
What the order teaches
| Risk area | Management logic | Operational evidence |
|---|---|---|
| Fintech onboarding | Growth cannot outrun compliance capacity | Pre-launch risk assessment and capacity sign-off |
| BSA / AML | Aggregate customer and program risk at bank level | Alert coverage, SAR governance and risk ratings |
| Capital / liquidity | Feed partner growth into funding plans | Program forecasts, runoff stress and contingency triggers |
| IT / operations | Reconciliation and resilience at interfaces | Data lineage, exception queues and outage drills |
| Board governance | Decision-useful reporting | Limits, breaches, remediation aging and owners |
Accountability and remediation
The order illustrateswhy 'sponsor bank' is not a business-model exemption. A bank remains accountable for the products, customers, data, complaints, suspicious-activity controls and operational dependencies created by partners. Limiting new launches is a supervisory response when remediation capacity is already consumed. Termination is also informative: formal restrictions can be removed after sustained corrective work, but only the primary termination notice—not assumptions about private remediation—supports that conclusion.