THE CREDIT CURRENT RESEARCH LIBRARY
Deep-dive library
Supervisory Cases

FRB / Evolve: fintech oversight, funding concentration and controlled growth

The June 2024 Evolve order links fintech oversight to AML, consumer compliance, credit, liquidity and board reporting. Its restrictions show why partner growth and exit both require a bank-wide risk assessment.

September 27, 2026
Current version

Initial full research published September 27, 2026. Historical events retain their dates; hypothetical examples and analytical recommendations are labeled.

What the action is, and what it is not

The Federal Reserve announced its Evolve action on June 14, 2024. The underlying consent cease-and-desist order, dated June 11, names Evolve Bancorp, Inc. and Evolve Bank & Trust, both of West Memphis, Arkansas, and was taken jointly with the Arkansas State Bank Department. Evolve Bank & Trust is a state-chartered Federal Reserve member bank; Bancorp is its holding company. Those entity distinctions matter when reading capital, cash-flow and governance provisions. [1][2]

The Fed explicitly said the action was independent of the Synapse bankruptcy proceedings. It cited examination findings concerning fintech partnerships, AML, risk management and consumer compliance. The public order is not a judicial determination of responsibility for every loss or customer dispute connected with Synapse. Conflating the proceedings would overstate what this evidence establishes. [1]

As of this September 27, 2026 review, the official order and announcement remain the verified public record located; no later official termination was found in the searched Fed releases. That search result is not evidence of confidential remediation progress. The restrictions described below are the terms of the 2024 order, and any later written supervisory approval or modification would govern the relevant activity. [2][3]

The breadth is the point

The order addresses the Open Banking Division alongside board oversight, capital, liquidity, lending, interest-rate risk, information technology, internal audit, BSA/AML and sanctions controls. It also requires holding-company cash-flow planning and source-of-strength support. The lesson is broader than an onboarding checklist: a partner business affects the entire institution. [2]

Analytical implication: a sponsor program can create several exposures simultaneously. Customer funds may supply deposits, the partner may owe indemnification, the bank may hold loans, and a technology provider may control essential records. Those exposures can deteriorate together if the partner fails. Reporting each in a separate committee can hide their common cause.

Recommended risk assessment therefore identifies the partner's economic role, customer obligations, funding contribution, data dependencies and exit costs in one record. It should show both normal operation and disruption. A contract can describe responsibilities accurately while leaving the bank unable to execute them at short notice.

Growth restrictions and the cost of exit

The order requires prior written supervisory approval for specified new Open Banking Division relationships, activities and products, including certain additions for existing partners. It also requires a liquidity impact analysis before exiting a fintech relationship. These are respondent-specific provisions, not a general ban on bank-fintech partnerships. [2]

That two-sided structure is instructive. Adding a partner can increase compliance and operating risk; removing one can create funding outflows, customer-transition work and replacement costs. A governance process that approves launch but has no funded exit plan is incomplete. A bank should know how long it would take to move records, service customers, settle transactions and replace deposits.

Worked example: partner exit as a liquidity event

Hypothetical bank: total deposits are $1 billion and one partner supplies $250 million. If 60% of that partner's deposits leave during a transition, the outflow is $150 million, or 15% of the bank's starting deposit base. Suppose immediately usable cash is $80 million and a tested borrowing line can supply $50 million. The simple scenario leaves a $20 million gap before other flows, collateral haircuts or operating needs.

The example does not describe Evolve's balance sheet. It demonstrates why a nominally small partner by revenue can be material by funding. A $2 million annual fee stream does not offset a $150 million liquidity requirement. Nor should a bank assume that all advertised borrowing capacity can be drawn instantly without operational preparation and eligible collateral.

Recommended contingency testing should include actual access procedures, settlement timing, pledged collateral and customer communication. Stress assumptions should consider correlated departures by customers using the same app or middleware. Thousands of end users do not necessarily provide independent funding behavior when their access depends on one platform.

Consumer and financial-crime controls share data

Accurate account ownership, transaction history and complaint records support both consumer treatment and financial-crime monitoring. A missing linkage can prevent an investigator from understanding activity and prevent a customer-service team from explaining a balance. The remediation priorities should reflect these shared dependencies rather than build separate incomplete data stores.

Recommended monitoring combines record reconciliation, exception age, complaint recurrence, suspicious-activity workflow performance and partner financial condition. Avoid conflating suspicious activity with established wrongdoing. A model alert initiates a review; it does not prove that the customer is a criminal or justify an unsupported consumer decision.

Independent testing should attempt to reconstruct a customer account without relying solely on the partner's dashboard. It should also test who can approve a new product, alter a threshold, release a payment or change a customer record. Permissions and production logs must match the bank's documented authority.

Board evidence and strategic tradeoffs

The attractive side of fintech partnerships is distribution and specialized technology. The cost is a more complex operating perimeter and potentially concentrated dependencies. A bank needs sufficient staff and systems to understand that perimeter before scaling. Adding a review committee without giving it reliable information or authority does little to reduce the exposure.

Recommended board reporting should connect partner contribution to capital, liquidity, compliance and exit capacity. A program that meets a revenue target while accumulating unresolved data gaps should not be presented as unqualified success. Equally, an order does not establish that every partnership is uneconomic or that all fintech models should be abandoned.

A later official termination, modification or disclosed approval would change the status analysis. Sustained independent evidence of reconciled records, effective controls and tested exits would strengthen the operating assessment. This case supports a narrow but consequential conclusion: partnership strategy must be governed as a bank-wide business with real funding and customer obligations, not as a collection of technology contracts.

Sources