THE CREDIT CURRENT RESEARCH LIBRARY
Deep-dive library
Supervisory Cases

Cross River: fair-lending controls across a partner network

The March 2023 FDIC order shows why partner lending requires usable data, capacity planning and bank-level accountability.

September 26, 2026
Current version

Initial source-linked research article with operating analysis and illustrative examples.

A historical enforcement case

The FDIC’s March 8, 2023 consent order, FDIC-22-0040b, is the primary record for this case study. The document establishes remedial requirements concerning Cross River Bank’s fair-lending compliance and oversight of credit products and third parties. The analysis below concerns that order’s design and requirements; it does not assert that every requirement remains outstanding or that the bank’s current operations have the same deficiencies.

The central lesson is that a bank cannot evaluate outcomes across a distributed lending business without access to the underlying decisions. A partner may own the interface or operate a model, but a bank-level control function still needs a coherent view of applications, offers, approvals, pricing, exceptions and complaints.

What the order required

The order called for inventories of credit products and third parties and imposed a non-objection process for new third parties and new credit products. It also required independent work addressing fair-lending information systems, staffing and resources, and risk assessment. The information review extended to the completeness, accuracy and accessibility of relevant data and model information.

The order’s resource analysis considered business complexity and growth, including products, partners, merchants and decision volumes. This is an important supervisory design choice: capacity cannot be judged only by the number of staff today. It must be assessed against the work created by the business model and planned expansion.

Why partner boundaries matter

Analysis: different partners can define an application, withdrawal or approval differently. One may retain all prequalification outcomes while another sends only booked loans. A consolidated approval rate built from those feeds may compare incompatible populations. The apparent trend can then reflect a data-definition change rather than a shift in treatment or credit risk.

A useful operating design establishes a common event dictionary and reconciles each partner’s population to source records. Preserve channel, product, policy and model versions so changes can be separated. Partner contracts should support the bank’s access to records and ability to investigate; an assurance that a partner is “monitoring fairness” is not a substitute for reviewable evidence.

An illustrative expansion gate

Imagine a fictional bank adding a new installment product through an existing technology partner. The user interface looks familiar, but the credit policy, offered terms and acquisition channels differ. Treating the launch as a minor software change could skip the product-level assessment. This example illustrates the operating logic of a product gate; it is not a claim about Cross River’s actual launches.

GateIllustrative evidenceReason to pause
PopulationReconciled application and decision countsMissing declines or incompatible definitions
Model and policyVersioned variables, rules and explanationsThe bank cannot reproduce outcomes
CapacityWorkload forecast and accountable reviewersGrowth exceeds review or complaint capacity
Launch authorityDocumented approvals and applicable non-objectionAn approval requirement has not been satisfied
MonitoringComparable outcomes and exception reportingA new product cannot be isolated in reporting

Competing interpretations

A centralized process can slow launches and require substantial integration work. That cost is real. However, the relevant comparison is not unrestricted speed against perfect oversight. It is the expected benefit of growth against the cost of undetected errors, remediation and restrictions if control capacity falls behind.

Analysis: a reusable data contract and standardized evidence package can lower the marginal cost of oversight. Centralization should not erase important differences between products, though. Risk assessments that treat every partner as interchangeable can miss different underwriting methods, customer populations and distribution incentives.

Evidence that would change the view

A strong remediation assessment would look for complete data, independently tested controls, sufficient resources and sustained operation after changes. A policy document alone demonstrates intention. A reproducible investigation, supported by reconciled populations and timely corrective action, demonstrates a process working.

For any current diligence decision, obtain the latest official enforcement record and verified status of applicable restrictions. This historical article is not a current permission-to-launch opinion. A later termination, modification or material new enforcement action should produce a new revision on this same topic page, with the original order analysis retained.

Sources