FinCrunch
← All coverage

FDIC hits Ledgerline’s partner bank with consent order over banking-as-a-service oversight

The order names a small Midwestern bank that runs deposit programs for the fintech middleware provider, and requires a wholesale rebuild of how the two firms monitor third-party accounts.

Samuel OkonkwoRegulation Desk
High-contrast black and white photograph looking up at the columned neoclassical stone facade of a government financial regulator building against a dark sky

The Federal Deposit Insurance Corporation has issued a consent order against Pinnacle Ridge Bank, a $1.9 billion-asset lender in Iowa that provides the chartered banking behind Ledgerline, a banking-as-a-service middleware provider. The order, which the bank agreed to without admitting or denying the agency’s findings, requires the bank to overhaul the compliance program governing the fintech deposit accounts it holds.

Under the banking-as-a-service model, a fintech that is not itself a bank offers checking accounts, cards or payments to its customers by routing them through a chartered partner bank, with a middleware layer like Ledgerline connecting the two and reconciling the underlying ledgers. The deposits sit at the bank; the customer relationship and the app sit with the fintech. Regulators supervise the bank, and the bank is responsible for what happens across the programs it sponsors — including ones it does not operate directly.

The FDIC’s order focuses on that responsibility. According to the document, examiners found deficiencies in the bank’s Bank Secrecy Act and anti-money-laundering program as applied to its fintech partners, weaknesses in third-party risk management, and gaps in the account reconciliation that is supposed to guarantee, at all times, which end customer owns which dollar. The order directs the bank to strengthen board oversight of the program, engage an independent party to review past transaction monitoring, and file regular progress reports with the agency.

The order does not impose a civil money penalty, and it does not order the bank to shut down its fintech programs. It does require the bank to obtain a written non-objection from the FDIC before onboarding new fintech partners or launching new products with existing ones — a provision that, in practice, slows growth while remediation is underway.

The action lands in an environment regulators have been signaling toward for two years. The 2024 collapse of the middleware provider Synapse — which left partner banks and their fintech customers unable to agree on who was owed what, freezing funds for tens of thousands of end users — turned reconciliation and third-party oversight from a back-office detail into the central supervisory question for the entire model. Interagency guidance on third-party relationships finalized in 2023 had already set the expectation that a bank owns the risk of any program it sponsors, however many intermediaries sit in between.

In a statement, Ledgerline said it was not itself a party to the order, that no customer funds were lost or frozen, and that it had already invested in strengthening its reconciliation and monitoring systems over the past year in coordination with its partner banks. Pinnacle Ridge Bank said it had begun implementing the required changes and expected to complete the bulk of the remediation within the timeline the order specifies. Neither the FDIC nor either firm characterized the order as evidence of customer harm; the deficiencies described are program and control weaknesses, which is what bank supervision is designed to catch before harm occurs rather than after.