IVINSKAS DAILY NEWSFEED RESEARCH LIBRARY
Deep-dive library
Supervisory Cases

FDIC / Choice Bank: partner growth must come with complete AML evidence

The December 18, 2023 Choice Financial Group order connects board oversight, partner customer data, monitoring, lookbacks and staffing. It is a case study in proving that outsourced activity remains visible to the bank.

September 27, 2026
Current version

Initial full research published September 27, 2026. Historical events retain their dates; hypothetical examples and analytical recommendations are labeled.

Identify the respondent and the record

The relevant respondent is Choice Financial Group, Fargo, North Dakota, the insured state nonmember bank commonly branded Choice Bank. The FDIC and North Dakota Department of Financial Institutions issued consent order FDIC-23-0086b on December 18, 2023. December 13 was the consent-agreement date, not the order's effective date. The order was publicly released in the January 2024 enforcement cycle, which can cause inconsistent shorthand dates. [1][2]

The agencies recorded BSA-related findings from the June 2023 examination; the bank consented without admitting or denying violations. The original order says its provisions remain effective until modified, terminated, suspended or set aside. For this September 27, 2026 review, the original text and release record were verified, but a complete current-status result could not be obtained from the dynamic FDIC order database. No later termination was located. Accordingly, this article analyzes the documented order and does not certify that every provision remains active today. [1][2]

The operating problem the order addresses

The order connects board oversight with customer identification, due diligence, suspicious-activity monitoring, independent testing, staffing and partner activity. It calls for a lookback covering specified third-party relationships and for validation addressing data gaps in monitoring systems. The supervisory concern is not solved merely by buying an AML platform: the platform needs a complete, reliable view of the activity it is intended to monitor. [1]

The underlying customer-identification regulation requires a bank program reasonably designed to identify customers, with risk-based verification and records. That is a general legal framework; the particular remediation deadlines and governance arrangements in Choice's order are respondent-specific. Other institutions should not copy a consent order's timetable and describe it as a universal regulatory deadline. [3]

Map the customer through every provider

Analytical recommendation: construct a data map from application to account creation, transaction processing, alert generation and investigation. Identify the institution's actual customer under the relevant arrangement, the identifiers used by each provider and the linkage between them. A bank can receive the correct aggregate settlement balance while lacking the customer-level detail needed for monitoring.

The critical evidence is completeness. Reconcile record counts and monetary totals, then inspect rejected files, duplicate identifiers, late events and records with missing fields. A technically successful API response may contain only a subset of expected activity. Daily monitoring of ingestion success should therefore include business-population reconciliation, not merely server uptime.

Contracts can allocate operational tasks, but the bank must assess whether it can obtain the information necessary to perform its responsibilities. Establish delivery standards, correction duties, retention, audit access and escalation rights. Test those rights before a partner becomes financially stressed, when cooperation and access can become harder.

Worked example: the silent monitoring gap

Hypothetical partner program: 50,000 accounts generate two million monthly transactions. A data transformation drops 1% of transactions with an unrecognized transaction type. The system still processes 1.98 million records and can appear healthy, yet 20,000 transactions are missing. If the missing type is concentrated in cash-equivalent transfers, the risk significance may be much larger than its numerical share.

Assume investigators normally review 500 alerts monthly. A lower alert count after the mapping change could look like improved customer quality or better rule tuning. It may instead reflect missing inputs. Before celebrating efficiency, reconcile the input population and compare alert rates within consistent transaction categories. The example illustrates a mechanism; it is not a claim about Choice's actual systems or transaction volume.

A corrective plan would restore the records, identify the affected dates, rerun appropriate scenarios and assess whether past investigations or required reports need revision. The lookback should be governed by a documented scope and legal assessment, not a blanket instruction to file a report on every exception.

Staffing and independent challenge

Recommended capacity planning starts with work arrival, handling time, complexity and deadlines. A partner that doubles transaction volume may increase investigation work faster than volume if it introduces new products or geographies. Use scenario-based staffing estimates and review actual queue aging. A low total backlog can conceal a small group of highly aged, difficult cases.

Independent testing should challenge whether the risk assessment reflects real business activity and whether data and rules implement it. Review both high-risk alerts and samples that did not alert. Testing only the output queue cannot identify all activities excluded before scoring. Preserve enough historical configuration to recreate what the system saw at the relevant time.

Board oversight should receive a concise view of unresolved control gaps, overdue remediation, data completeness and material partner changes. Attendance at a meeting is not evidence that a significant weakness was understood. Minutes and decision records should show what was challenged, what resources were committed and why remaining risk was accepted or reduced.

Economics and limits of the case

Partner distribution can generate useful scale and fee income, but monitoring, data engineering and customer support are real unit costs. A program that appears profitable before these costs may not remain attractive after realistic oversight is included. Common dependencies also matter: multiple brands using one processor may create a single failure point despite a large partner count.

There is a legitimate tradeoff between catching more suspicious patterns and imposing excessive friction on ordinary customers. Better data and targeted rules can improve that tradeoff; indiscriminate alert expansion can overwhelm investigators. Evaluate quality, timeliness and documented disposition rather than treating the largest alert count as the best program.

An official termination or modification would change the legal-status conclusion. Demonstrated data completeness, effective lookback execution and sustained testing would strengthen the operational conclusion. Public materials do not reveal all remediation results, and this case study does not infer a CAMELS rating. Its lasting lesson is that a bank must be able to reconstruct partner activity with sufficient detail to make and evidence its own compliance decisions.

Sources