IVINSKAS DAILY NEWSFEED RESEARCH LIBRARY
Deep-dive library
Supervisory Cases

Blue Ridge Bank consent order

A historical control map for fintech onboarding, BSA/AML, capital, liquidity and board accountability.

September 26, 2026
Current version

Initial research article published September 26, 2026.

Case and legal status

The OCC's January 24, 2024 consent order against Blue Ridge Bank addressed BSA/AML, capital, strategic planning, liquidity, information technology and third-party fintech risks. The order restricted onboarding of new third-party fintech relationships while deficiencies remained and required board oversight, remediation plans, risk assessments, staffing and reporting. The OCC terminated the order in November 2025, so the original restrictions are no longer active; the case remains a useful public control map.

What the order teaches

Risk areaManagement logicOperational evidence
Fintech onboardingGrowth cannot outrun compliance capacityPre-launch risk assessment and capacity sign-off
BSA / AMLAggregate customer and program risk at bank levelAlert coverage, SAR governance and risk ratings
Capital / liquidityFeed partner growth into funding plansProgram forecasts, runoff stress and contingency triggers
IT / operationsReconciliation and resilience at interfacesData lineage, exception queues and outage drills
Board governanceDecision-useful reportingLimits, breaches, remediation aging and owners

Accountability and remediation

The order illustrateswhy 'sponsor bank' is not a business-model exemption. A bank remains accountable for the products, customers, data, complaints, suspicious-activity controls and operational dependencies created by partners. Limiting new launches is a supervisory response when remediation capacity is already consumed. Termination is also informative: formal restrictions can be removed after sustained corrective work, but only the primary termination notice—not assumptions about private remediation—supports that conclusion.

Sources