
North Dakota DFI: Block, Bayview Face Enforcement Over AML, Cyber Failures
Summary
- The North Dakota Department of Financial Institutions (DFI) and other state regulators took coordinated action against Block Inc. for Bank Secrecy Act (BSA) and anti-money laundering (AML) violations.
- Block Inc., operator of Cash App, agreed to an $80 million penalty and must hire an independent consultant to review and correct its BSA/AML program.
- Separately, the DFI and 52 state agencies acted against Bayview Companies for deficient cybersecurity practices and non-cooperation following a data breach affecting 5.8 million customers.
- Bayview Companies agreed to a monetary penalty, improved cybersecurity, independent assessments, and three years of additional reporting.
- These actions highlight the DFI's role in enforcing financial integrity and consumer data protection laws for thousands of nonbank financial service companies.
North Dakota DFI Takes Coordinated Enforcement Action
The North Dakota Department of Financial Institutions (DFI), in collaboration with numerous state regulatory bodies across the nation, has recently concluded two significant enforcement actions targeting major financial service providers.
The North Dakota Department of Financial Institutions (DFI), in collaboration with numerous state regulatory bodies across the nation, has recently concluded two significant enforcement actions targeting major financial service providers. These coordinated efforts underscore the DFI's commitment to upholding financial integrity and consumer protection within the state and nationwide. The actions address critical issues ranging from anti-money laundering compliance to robust cybersecurity practices, impacting millions of consumers.
One of the prominent cases involved Block Inc., the operator of the mobile payment service Cash App, which serves over 50 million consumers in the United States. This enforcement, part of a multistate initiative with 48 state financial regulatory agencies, focused on serious violations of the Bank Secrecy Act (BSA) and anti-money laundering (AML) statutes. These laws are fundamental to safeguarding the financial system from illicit activities, including terrorism financing and other illegal uses.
Separately, the North Dakota DFI, alongside 52 other state financial regulatory agencies, took action against Bayview Asset Management LLC and its affiliates—Lakeview Loan Servicing, Silver Hill Capital (formerly Community Loan Servicing), and Pingora Holdings, collectively known as the Bayview Companies. This enforcement stemmed from deficient cybersecurity protocols and a lack of full cooperation with regulators following a data breach that affected 5.8 million customers. Both the North Dakota DFI Block Bayview enforcement actions highlight the critical role of state regulators in ensuring compliance and protecting consumers.
Block Inc. Fined for AML Failures
The enforcement action against Block Inc. concluded with a multistate settlement requiring the company to pay an $80 million penalty to the participating state agencies. Beyond the financial penalty, Block Inc. has agreed to undertake substantial corrective measures. These include hiring an independent consultant to conduct a thorough review of its BSA/AML program, assessing its comprehensiveness and overall effectiveness. The company is mandated to submit a report detailing these findings to the states within nine months of the settlement.
Following the submission of this report, Block Inc. will have an additional 12 months to rectify any deficiencies identified during the independent review. State regulators, including lead agencies from Arkansas, California, Massachusetts, Florida, Maine, Texas, and Washington state, found that Block Inc. had failed to comply with specific BSA/AML requirements. These regulations necessitate financial services firms to perform rigorous due diligence on customers, verify identities, report suspicious activities, and implement appropriate controls for high-risk accounts. The non-compliance created a significant risk that Cash App's services could be exploited for money laundering, terrorism financing, or other illegal purposes.
DFI Commissioner Lise Kruse emphasized the importance of public confidence in the financial services industry, stating that all companies operating in this sector must adhere to North Dakota law. Her remarks underscored the collaborative effort among state regulators in leading this multistate enforcement initiative to ensure accountability and protect the integrity of the financial system.
Bayview Companies Cited for Cybersecurity Lapses
The Bayview Companies faced regulatory scrutiny due to inadequate information technology and cybersecurity practices, which were found to be non-compliant with both federal and state requirements. This deficiency was particularly critical given a data breach that compromised the personal information of 5.8 million customers. Furthermore, the companies were cited for hindering the supervisory process by failing to provide timely and complete responses to state requests during the initial stages of the examination, demonstrating a lack of cooperation.
As a result of this enforcement, the Bayview Companies have agreed to a monetary penalty, the specific amount of which was not disclosed in the public announcement. In addition to this penalty, the companies are required to implement a series of corrective actions aimed at enhancing their cybersecurity programs. This includes undergoing independent assessments of their systems and providing three years of ongoing reporting to the states to demonstrate sustained compliance and improvement. The multistate effort was spearheaded by regulators from California, Maryland, North Carolina, and Washington State.
This action serves as a stark reminder of the critical importance for financial institutions to meet state-mandated requirements for protecting consumer data and to fully comply with supervisory demands. The DFI and its partner agencies are dedicated to ensuring that companies maintain robust security measures and cooperate transparently with regulatory oversight, especially in the wake of data breaches.
Broader Regulatory Oversight and Consumer Resources
The North Dakota Department of Financial Institutions plays a vital role in overseeing a vast array of nonbank financial services companies operating within the state. This includes licensing and supervising nearly 1,700 such entities, with 183 specifically identified as money transmitters. More broadly, state financial regulators collectively license and supervise over 33,000 nonbank financial services companies through the Nationwide Multistate Licensing System (NMLS), encompassing mortgage companies, money services businesses, consumer finance providers, and debt collectors.
These enforcement actions against Block Inc. and the Bayview Companies exemplify the ongoing commitment of the DFI and its regulatory partners to safeguard consumers and maintain a secure financial environment. The DFI encourages North Dakota residents who have questions regarding these or other enforcement actions to contact the Department directly at dfi@nd.gov or by phone at (701) 328-9933. Additionally, consumers can utilize NMLS Consumer Access to verify the licensing status of any company doing business in North Dakota and to review past enforcement records.
The DFI's proactive stance, as demonstrated by the North Dakota DFI Block Bayview enforcement cases, is crucial for ensuring that financial service providers adhere to stringent regulatory standards, thereby fostering trust and stability within the financial sector for all citizens.
Source
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Finish Reading the Full Story and the Expert Analysis.
Wansom is AI and can make mistakes.
