MovoCash ran the identity checks. Metropolitan Commercial Bank paid the $30 million fine.
Starting in 2020, fraud actors opened prepaid card accounts using stolen identities and used them to collect pandemic unemployment benefits. The accounts were opened through MovoCash, a third-party program manager that operated the onboarding flow. More than $300 million in benefits was misdirected to fraudulent accounts before the scheme was shut down. When the enforcement actions arrived in 2023, they did not name the program manager. The Federal Reserve fined the bank roughly $14.5 million, and the New York State Department of Financial Services added $15 million more.
The identity verification seam belonged to a vendor. The consequence belonged to the bank.
Three stories, one pattern
If that were a one-off, it would be an anecdote. It is not a one-off. In April 2024, banking middleware provider Synapse collapsed into bankruptcy, and its ledgers disagreed with those of its partner banks by an estimated $65 to $96 million. Tens of thousands of ordinary people were locked out of their savings while a court-appointed trustee tried to reconstruct who held what. While that mess was still being untangled, the Federal Reserve issued an enforcement action against Evolve Bank & Trust, the best known of Synapse's partner banks, citing an inadequate risk management framework for its fintech partnerships. No monetary penalty was attached, but the remediation burden, the examiner scrutiny, and the headlines all landed on the bank whose name was on the accounts.
A month later, the Federal Reserve fined Green Dot $44 million for consumer compliance failures across its prepaid card programs, including blocking legitimate customers who were receiving unemployment benefits out of their own accounts without reasonable procedures to fix the blocks. Failure does not only mean letting fraud in. Locking good customers out is a failure too, and that one also landed on the regulated institution.
Different products, different vendors, different failure modes. Same address on the envelope.
Why it always lands on the bank
This is not regulatory laziness. It is the design. In June 2023, the federal banking agencies finalized their Interagency Guidance on Third-Party Relationships, and its core message is blunt: using a third party does not shrink a bank's responsibility to operate safely, soundly, and within the law. The Bank Service Company Act goes further. When a vendor performs a service for a bank, examiners can review that activity as if the bank performed it in-house.
From the examiner's chair, there is no such thing as "the vendor's part" of your stack. There is your charter, your customers, and your control environment. Every seam between your vendors is presumed to be yours.
Most institutions know this in the abstract. The pattern above is what it costs in practice.
The plot twist: sometimes the vendor does get caught
Direct vendor liability exists. In June 2023, the CFPB ordered payment processor ACI Worldwide to pay a $25 million civil penalty after a botched internal test initiated roughly $2.3 billion in unauthorized mortgage payment debits touching nearly 500,000 borrowers. No bank paid that fine. The processor did.
So regulators can reach past the bank, and occasionally they do. But two things are true at once: vendor fines are possible, and bank accountability is guaranteed. Nothing about the ACI order changed the rule for the institutions in the stories above, and no bank has ever walked out of an examination by pointing at its vendor.
So who should pay?
Here is where I stop pretending the question is simple. The case for the bank paying is solid. The bank chose the vendor, priced the risk, owns the customer relationship, and earns the margin on the account. Accountability follows the charter, and it should, because that is what makes a bank a bank.
The case for the vendor paying gets stronger every year. The vendor built the control, marketed it as compliant, operated it day to day, and profited on every transaction that flowed through it. A bank cannot examine a vendor's internals the way a regulator can, yet it carries the full consequence of what those internals do.
The rulebook has picked its answer. I am not fully convinced the rulebook is right, and the growth of banking-as-a-service is stress-testing that answer in public.
What I do with this
My work is delivering onboarding systems for banks and credit unions, so I do not read these orders as a spectator. I read every one of them the same way: this could have been any of us.
If the fine lands on you no matter who operated the seam, then vendor selection is really evidence selection. Before you sign, ask one question: when the examiner comes, can I show, applicant by applicant, exactly what was checked, what signals came back, and why the decision was made? A partner who hands you a per-applicant audit trail and downloadable signals is protecting your charter. A partner who hands you a black box and a service-level agreement is handing you undiluted accountability with no evidence to defend it. That is the standard I build to, because the regulators have told us plainly whose name goes on the order.
Which brings me back to the question I cannot close. When the vendor runs the control and the control fails, who should pay: the bank or the vendor? I know what the rulebook says. I am less sure it is right. Tell me why I am wrong in the comments.
Sources
- Federal Reserve enforcement action, Metropolitan Commercial Bank, 19 Oct 2023: federalreserve.gov
- NYDFS press release, Metropolitan Commercial Bank, 19 Oct 2023: dfs.ny.gov
- Federal Reserve enforcement action, Evolve Bank & Trust, 14 Jun 2024: federalreserve.gov
- Federal Reserve enforcement action, Green Dot, 19 Jul 2024: federalreserve.gov
- CFPB enforcement action, ACI Worldwide, 27 Jun 2023: consumerfinance.gov
- Interagency Guidance on Third-Party Relationships, 6 Jun 2023: federalreserve.gov