Sample CompanyScope Profile

SoFi Technologies, Inc. (NASDAQ: SOFI)

Report Date: July 1, 2026  ·  Gap Mode — Preliminary (public sources only)  ·  RuleboardAI GovRiskCompliance v1 2026

SAMPLE DOCUMENT — ILLUSTRATIVE USE ONLY

This profile was produced entirely from public sources as a sample deliverable for the RuleboardAI marketing website. No client engagement exists between RuleboardAI and SoFi Technologies, Inc. No client documentation was reviewed. All data is sourced from public filings and regulatory records as cited below.

Not an audit, legal opinion, or attestation. Built from public sources only.

Executive summary at a glance

Public-source, preliminary — figures summarize the detail below.

RCPS maturity

Seven-axis control maturity

Illustrative

Composite maturity

2.6 / 5.0

Defined

Achievable target

3.8 / 5.0

  • Governance3.1 / 5
  • Risk Management2.2 / 5
  • Compliance2.9 / 5
  • Cybersecurity2.0 / 5
  • Third-Party Risk2.7 / 5
  • Privacy3.0 / 5
  • Monitoring2.3 / 5

RCPS maturity is scored 1–5 across seven axes. The vertical marker on each bar is the achievable target from the sample assessment. Illustrative — scored per entity during classification.

Composite 2.6 of 5 against an achievable 3.8. Cybersecurity and risk management are the weakest axes.

See the full maturity scorecard →

Findings

Nine findings by severity

Illustrative
Findings by severity9 total
  • 4

    High

  • 5

    Medium

  • 0

    Low

Four high-severity and five medium-severity flags identified from public records.

See all nine findings →

Workflow scoping

48 workflows

Every client is scored against the same 48-workflow universe across 11 categories. The engine sorts each workflow into one of three buckets — nothing applicable is missed, nothing irrelevant is run.

  • 27

    In scope

    Applies to this client — runs this cycle.

  • 9

    Conditional

    Applies only if a trigger is met — flagged for review.

  • 12

    Out of scope

    Not applicable to this client — documented, not ignored.

Illustrative split — the actual scope is determined per client during RCPS classification.

See the workflow determination →

RCPS classification

Type 7 National Bank / BHC (primary) · Type 4 Broker-Dealer · Type 5 RIA · Type 16 Fintech Platform (secondary)

Every score and label in this profile follows the published RCPS Methodology & Scoring Standards — including what the scores mean and what they cannot conclude.

1. Executive Summary & Risk Posture

Overall Posture

SoFi Technologies, Inc. is a publicly traded (NASDAQ: SOFI), Delaware-incorporated bank holding company and financial holding company headquartered at 234 1st Street, San Francisco, CA 94105. As of December 31, 2025, SoFi reported total assets of $50.7 billion (up 40% year-over-year), total deposits of $37.5 billion, total net revenue of $3.6 billion, and net income of $481.3 million. The company employs approximately 6,100 people across three reported segments: Lending, Financial Services, and Technology Platform. With 13.7 million members and over 20.2 million products at year-end 2025, SoFi has grown from a pre-bank fintech into a full-service nationally chartered bank holding company subject to multi-regulator oversight (OCC, Federal Reserve, CFPB, SEC, FINRA, FinCEN/BSA, FDIC, state). This profile is produced entirely from public sources; no internal documentation was reviewed (Gap Mode). Overall preliminary risk posture: Elevated, driven by rapid asset growth, multi-regulator complexity, new $50B+ asset threshold triggers, and historical enforcement actions across multiple subsidiaries.

Top Risk

The single highest-priority build item identified from public sources is BSA/AML and KYC program adequacy at scale: SoFi crossed the $10 billion asset threshold (triggering direct CFPB supervision as of January 1, 2024) and is now approaching the $50 billion OCC heightened-standards threshold. Publicly, SoFi Bank's AML/BSA program details are not disclosed in regulatory filings beyond acknowledgment of obligations. Two subsidiary enforcement actions (FINRA $1.1M CIP/ITPP fine, 2024; SEC $300K conflict-of-interest order, 2021) and an FTC consent order (2019, active until 2039) signal that compliance program maturity has historically lagged growth. Full program details cannot be confirmed from public sources — this is the most critical data gap.

Regulatory Stack

Primary federal regulators: OCC (SoFi Bank, N.A., Cottonwood Heights, UT — charter confirmed active per OCC May 2026 national bank list); Federal Reserve (bank holding company and financial holding company, BHCA §4(l)); CFPB (direct supervision commenced January 1, 2024 — assets exceeded $10B threshold); FinCEN/BSA (Bank Secrecy Act obligations for SoFi Bank and affiliates); SEC (SoFi is a public reporting company, CIK 0001818874; SoFi Wealth LLC and SoFi Capital Advisors LLC are investment advisers; SoFi Securities LLC is a broker-dealer); FINRA (SoFi Securities LLC, CRD 151717); FDIC (deposit insurer for SoFi Bank, N.A., up to $250K per depositor; expanded coverage up to $3M through reciprocal deposit program). State regulators: multiple state agencies supervise various SoFi lending and money-transmission activities; Technology Platform segment serves clients internationally (Latin America via Technisys S.A.).

Fund / BDC Overlay

SoFi is not a registered investment company or fund complex in the traditional sense. SoFi Wealth LLC operates a robo-advisory service; SoFi Capital Advisors LLC provides investment advisory services. No registered '40 Act funds or BDCs are identified from public sources. ETFs previously sponsored by SoFi (SFY, SFYX) were closed and are no longer active. SoFi Crypto launched December 2025; SoFiUSD stablecoin launched in 2025. Fund overlay: Not applicable in the traditional sense; investment adviser registration confirmed.

Key Person Risk

Anthony Noto (CEO, age 57, Director) is the sole identified key executive whose departure would be material. The 10-K cites key-person dependency risk. CFO: Chris Lapointe. CRO: Arun Pinto. General Counsel: Rob Lavet. CTO: Jeremy Rishel. Board: Tom Hutton (Independent Chair, separate from CEO — confirmed governance strength). Auditor: Deloitte & Touche LLP (since 2017). Key-person concentration on Noto is a Likely medium risk; details of succession planning are not confirmable from public sources.

1A. Control Maturity Scorecard

Scores are Likely/Conditional inferences from public disclosures only. No internal documentation reviewed. Many scores reflect a data gap rather than a confirmed deficiency.

GRC Category

1. SOC 2 Compliance

Current Maturity

2 — Developing (Conditional)

Target

4

Evidence / Basis

No public SOC 2 Type II report identified. Cybersecurity 10-K disclosure references ISO 27002:2013 and NIST CSF; third-party penetration tests confirmed. SOC 2 status unknown from public sources.

GRC Category

2. Financial Regulation

Current Maturity

3 — Defined (Likely)

Target

5

Evidence / Basis

Multi-regulator structure confirmed (OCC, Fed, CFPB, SEC, FINRA, FinCEN). Capital ratios comply — SoFi Bank “well capitalized” per 10-K. BSA/AML program exists (regulatory requirement) but program details not publicly disclosed. Historical enforcement: FINRA $1.1M (2024 CIP/ITPP), SEC $300K (2021 conflict), FTC consent order (2019–2039).

GRC Category

3. International Frameworks (DORA/ISO/BCP)

Current Maturity

2 — Developing (Conditional)

Target

3

Evidence / Basis

No DORA applicability confirmed (US-primary, no EU-regulated entity identified). ISO 27002:2013 referenced in 10-K cybersecurity disclosure. BCP/ISO 22301 status not publicly disclosed. Technisys S.A. (Luxembourg) may trigger EU obligations — cannot confirm from public sources.

GRC Category

4. Internal Governance

Current Maturity

3 — Defined (Likely)

Target

4

Evidence / Basis

Board-level governance confirmed: independent chair (Hutton), four fully independent committees (Audit, Risk, Compensation, Nominating & CG). Risk Committee oversees cybersecurity — confirmed per DEF 14A 2026. COSO/ERM framework referenced in 10-K. Internal audit team confirmed (annual IT/IS audits). Policy library details not publicly disclosed.

GRC Category

5. Ongoing / Scheduled Monitoring

Current Maturity

3 — Defined (Conditional)

Target

4

Evidence / Basis

Regulatory change monitoring implied by multi-regulator environment. CISO provides quarterly cybersecurity updates to Risk Committee — confirmed per 10-K. Training completion details not public. Vendor renewal risk management exists (third-party security risk program confirmed).

GRC Category

6. Privacy & Data Protection (GDPR/CCPA)

Current Maturity

3 — Defined (Likely)

Target

4

Evidence / Basis

CCPA obligations confirmed — SoFi serves California consumers. GDPR applicability limited (US-primary); Technisys/EU ops may create GDPR exposure (Conditional). Privacy policy and data practices publicly available on sofi.com. Data retention and DPIA details not publicly disclosed.

GRC Category

7. Cybersecurity

Current Maturity

3 — Defined (Likely)

Target

4

Evidence / Basis

Frameworks confirmed: ISO 27002:2013, NIST CSF, PCI-DSS, FFIEC guidelines, CIS controls (10-K Item 1C). CISO confirmed (20+ years experience, 4 years at SoFi). Annual internal audits and periodic external pen tests confirmed. No material incidents disclosed. Zero Trust maturity not publicly assessable.

GRC Category

8. HR & People Risk

Current Maturity

2 — Developing (Conditional)

Target

3

Evidence / Basis

Code of ethics/insider trading policy (Ex-19.1 in 10-K) confirmed — MNPI policy filed publicly. FINRA registration for SoFi Securities personnel implied. Whistleblower program: SEC Dodd-Frank channel implied for public company; internal whistleblower program details not publicly confirmed. Background check program details not public.

GRC Category

9. Third-Party / Supply Chain Risk

Current Maturity

3 — Defined (Likely)

Target

4

Evidence / Basis

Third-Party Security Risk Management program confirmed (10-K Item 1C). Supplier onboarding due diligence confirmed. Technology Platform segment serves as B2B infrastructure provider — vendor risk is both buyer and supplier facing. Galileo concentration risk (one large client departure caused 23% drop in tech platform accounts in 2025) — confirmed public signal of concentration risk.

GRC Category

10. ESG / Non-Financial Reporting

Current Maturity

2 — Developing (Conditional)

Target

3

Evidence / Basis

No TCFD-aligned or CSRD report identified from public sources. SEC climate disclosure rules (pending/phased implementation). ESG governance documents page on IR website returned no substantive content. SoFi's ESG posture from public disclosures: limited. SFDR N/A (no EU-distributed funds confirmed).

GRC Category

11. Operational Risk

Current Maturity

3 — Defined (Likely)

Target

4

Evidence / Basis

ERM framework referenced in 10-K. RCSA implied by bank regulatory requirements. DR/BCP details not publicly disclosed. Rapid balance sheet growth ($50.7B total assets, +40% YoY) and crossing of multiple asset thresholds creates operational scaling risk. OCC proposed raising heightened standards threshold from $50B to $700B (Dec 2025) — may relieve some near-term burden.

Composite: 2.6 — Developing/Defined  →  Target 3.8

Dominant uplift priorities: BSA/AML program documentation; SOC 2 attestation; ESG/climate disclosure; BCP/DR testing evidence; whistleblower and HR program detail.

1B. Risk Appetite Conformance

External benchmarks: OCC Heightened Standards (12 CFR Part 30), CFPB Supervision and Examination Manual, FFIEC BSA/AML Examination Manual, SEC Regulation Best Interest / fiduciary standard (SoFi Wealth), NIST CSF 2.0. Verdicts are Conditional inferences from public evidence only.

Domain

BSA/AML / KYC

Inherent Risk

High

Within Tolerance?

Unknown

Basis

FINRA $1.1M CIP/ITPP fine (2024, conduct 2018–2019). Bank-level BSA program mandated; program quality not verifiable from public sources.

Domain

Capital Adequacy

Inherent Risk

Medium

Within Tolerance?

Within Tolerance

Basis

SoFi Bank confirmed “well capitalized” per all OCC metrics (10-K 2025). CET1, Tier 1, Total Capital ratios met. $10B+ triggers active.

Domain

Consumer Protection / UDAAP

Inherent Risk

High

Within Tolerance?

Unknown

Basis

CFPB direct supervision commenced Jan 1, 2024. FTC consent order (active to 2039) on savings-claim advertising. No CFPB enforcement action found; status of examination findings not public.

Domain

Cybersecurity / Data

Inherent Risk

Medium

Within Tolerance?

Conditional

Basis

NIST CSF and ISO 27002 referenced; no material incidents. Zero Trust, SIEM, EDR maturity not publicly confirmable.

Domain

Fiduciary / Conflicts of Interest

Inherent Risk

Medium

Within Tolerance?

No (Historical)

Basis

SEC $300K order (2021) against SoFi Wealth LLC for undisclosed proprietary ETF conflicts. Remediated per SEC order — ongoing monitoring status unknown.

Domain

Operational Resilience

Inherent Risk

Medium

Within Tolerance?

Unknown

Basis

BCP/DR not publicly tested/disclosed. Rapid growth ($50.7B assets) increases operational complexity.

Domain

Model / Credit Risk

Inherent Risk

High

Within Tolerance?

Conditional

Basis

Lending segment $36.4B originations (FY2025). Credit model details proprietary. 10-K cites model risk as a key risk factor. Held-for-investment loan book growing.

Domain

ESG Disclosure

Inherent Risk

Low

Within Tolerance?

No

Basis

No TCFD or comparable public climate disclosure identified. SEC climate rules may require disclosure in future filings.

Read-out: Three domains are Unknown (BSA/AML, Consumer Protection, Operational Resilience) and one is a confirmed historical Non-Conformance (fiduciary/conflicts). Capital adequacy is Within Tolerance. Full conformance assessment requires client engagement and internal documentation review.

2. RCPS Classification Profile

Institution types assigned: Type 7 — National Bank / Bank Holding Company (PRIMARY) + Type 4 — Broker-Dealer (SECONDARY, SoFi Securities LLC) + Type 5 — Investment Adviser (SECONDARY, SoFi Wealth LLC / SoFi Capital Advisors LLC) + Type 16 — Fintech / Payments Platform (SECONDARY, Technology Platform segment: Galileo + Technisys)

7-Axis RCPS Classification

RCPS Axis

1 — Listing Status

Code

PUB

Classification

Publicly listed

Basis / Note

NASDAQ: SOFI; CIK 0001818874; SEC reporting company (Exchange Act)

RCPS Axis

1A — Fund Overlay

Code

NONE

Classification

No registered fund overlay

Basis / Note

No active '40 Act funds; SoFi ETFs (SFY, SFYX) closed; robo-advisory via SoFi Wealth LLC does not constitute a fund complex

RCPS Axis

2 — Company Size

Code

S5

Classification

Large Enterprise

Basis / Note

Total assets $50.7B (Dec 31, 2025); Total net revenue $3.6B (FY2025); ~6,100 employees

RCPS Axis

3 — Industry

Code

I-FINTECH / I-BANK

Classification

Fintech + National Bank

Basis / Note

Nationally chartered bank (SoFi Bank, N.A.); bank holding company; financial holding company; technology platform (Galileo, Technisys) serving third-party financial institutions

RCPS Axis

4 — Geography

Code

US-ONLY (primary) / US-LATAM (secondary)

Classification

US-primary with LatAm tech exposure

Basis / Note

SoFi Bank operations: US only. Technology Platform (Technisys): serves financial institutions in North America and Latin America. No EU-regulated entity confirmed.

RCPS Axis

5 — Data Intensity

Code

D4

Classification

Maximum data intensity

Basis / Note

Consumer financial data (13.7M members); deposit, lending, investment, and payment data; technology platform processes 128.5M accounts; crypto operations launched Dec 2025

RCPS Axis

6 — Ownership

Code

PUB-PARENT

Classification

Public corporate parent

Basis / Note

SoFi Technologies, Inc. is the publicly traded parent; SoFi Bank, N.A. is a wholly owned subsidiary; no PE or private ownership layer

RCPS Axis

7 — Growth Stage

Code

G4

Classification

Scale-up / Rapid Growth

Basis / Note

35% YoY member growth; 40% YoY total asset growth; first $1B+ EBITDA year (2025); still investing in growth (guidance for 2026 implies continued acceleration)

Entity Profile — Key Attributes

Attribute

Legal Name

Value

SoFi Technologies, Inc.

Attribute

HQ

Value

234 1st Street, San Francisco, CA 94105

Attribute

Founded

Value

2011 (as Social Finance, Inc.); became public 2021 via SPAC merger

Attribute

CIK (SEC)

Value

0001818874

Attribute

NASDAQ Ticker

Value

SOFI

Attribute

Shares Outstanding (Jan 30, 2026)

Value

1,275,263,850 shares (common stock, $0.0001 par)

Attribute

Market Cap (June 30, 2025, non-affiliates)

Value

~$20.0 billion (per 10-K cover)

Attribute

Bank Charter

Value

SoFi Bank, National Association — OCC-chartered national bank; approved January 18, 2022; HQ: 2750 East Cottonwood Parkway, Cottonwood Heights, UT (per OCC national bank list, May 2026)

Attribute

Bank Holding Company

Value

Yes — regulated by Federal Reserve under BHCA; Financial Holding Company (FHC) elected under §4(l) BHCA

Attribute

CFPB Supervision

Value

Direct CFPB supervision commenced January 1, 2024 (>$10B asset threshold triggered)

Attribute

Total Assets

Value

$50.7 billion (Dec 31, 2025)

Attribute

Total Deposits

Value

$37.5 billion (Dec 31, 2025)

Attribute

Total Net Revenue (FY2025)

Value

$3.6 billion (+35% YoY)

Attribute

Net Income (FY2025)

Value

$481.3 million

Attribute

Members

Value

13.7 million (Dec 31, 2025, +35% YoY)

Attribute

Products

Value

20.2 million (Dec 31, 2025, +37% YoY)

Attribute

Tech Platform Accounts

Value

128.5 million (Dec 31, 2025)

Attribute

Employees

Value

~6,100 (Dec 31, 2025; ~82% US, ~18% international)

Attribute

Three Business Segments

Value

Lending ($1.8B revenue); Financial Services ($1.54B revenue, +88% YoY); Technology Platform ($450M revenue)

Attribute

CEO

Value

Anthony Noto (age 57)

Attribute

CFO

Value

Chris Lapointe

Attribute

CRO

Value

Arun Pinto

Attribute

General Counsel

Value

Rob Lavet

Attribute

CTO

Value

Jeremy Rishel

Attribute

Board Chair

Value

Tom Hutton (Independent)

Attribute

Auditor

Value

Deloitte & Touche LLP (since 2017)

Attribute

Key Subsidiaries

Value

SoFi Bank, N.A.; SoFi Securities LLC (CRD 151717); SoFi Wealth LLC; SoFi Capital Advisors LLC; Galileo Financial Technologies; Technisys S.A. (Luxembourg); SoFi Digital Assets LLC; Wyndham Capital Mortgage

Attribute

RuleboardAI Classification

Value

Type 7 National Bank/BHC (Primary) + Type 4 Broker-Dealer + Type 5 RIA + Type 16 Fintech Platform (Secondary)

3. Workflow Scope Determination

All 48 workflows evaluated. Engine operates within the 19 U.S. institution types. Status: In Scope (confirmed applicable), Conditional (depends on trigger/confirmation), Suppressed (not applicable, with rationale).

Category 1 — SOC 2 Compliance

#

1.1

Workflow

Control Inventory Audit

Status

Conditional

Trigger / Rationale

SoFi Bank subject to OCC/FFIEC IT controls; SOC 2 formal audit status unknown; likely relevant for Galileo/Technisys B2B platform customers

#

1.2

Workflow

Evidence Collection Checklist

Status

Conditional

Trigger / Rationale

Applicable if SOC 2 audit pursued; Galileo/Technisys likely have customer contractual requirements for SOC 2 evidence

#

1.3

Workflow

Gap Analysis Report

Status

In Scope

Trigger / Rationale

Referenced frameworks (NIST CSF, ISO 27002, FFIEC) confirm gap analysis applicability; SOC 2 gap likely material

#

1.4

Workflow

Vendor Risk Assessment

Status

In Scope

Trigger / Rationale

Third-Party Security Risk Management program confirmed in 10-K; vendor risk assessment formally in scope

#

1.5

Workflow

Penetration Test Review Memo

Status

In Scope

Trigger / Rationale

External pen tests confirmed per 10-K cybersecurity disclosure; review memo workflow in scope

Category 2 — Financial Regulation

#

2.1

Workflow

Capital Adequacy Report

Status

In Scope

Trigger / Rationale

OCC and Federal Reserve capital requirements confirmed; SoFi Bank “well capitalized” — ongoing reporting obligation

#

2.2

Workflow

AML Transaction Monitoring

Status

In Scope

Trigger / Rationale

BSA/AML obligations confirmed for SoFi Bank N.A. and affiliates; FinCEN IA AML Rule (eff. Jan 1, 2028) will apply to investment adviser affiliates

#

2.3

Workflow

SAR Draft

Status

In Scope

Trigger / Rationale

SoFi Bank SAR filing obligations under BSA confirmed; prior FINRA CIP/ITPP fine heightens materiality

#

2.4

Workflow

SEC Filing Readiness Check

Status

In Scope

Trigger / Rationale

SoFi is a public reporting company (10-K, 10-Q, 8-K, proxy); SoFi Wealth/Capital Advisors file Form ADV; in scope

#

2.5

Workflow

KYC Onboarding Audit

Status

In Scope

Trigger / Rationale

FINRA $1.1M CIP/ITPP fine (May 2024) for 2018–2019 conduct confirms this is a demonstrated gap area; high priority

Category 3 — International Frameworks (DORA / ISO 27001 / BCP)

#

3.1

Workflow

DORA ICT Risk Assessment

Status

Conditional

Trigger / Rationale

SoFi is US-primary; Technisys S.A. (Luxembourg) may trigger EU DORA obligations as ICT provider to EU-regulated entities — cannot confirm from public sources

#

3.2

Workflow

ISO 27001 Gap Report

Status

In Scope

Trigger / Rationale

ISO 27002:2013 referenced in 10-K; formal ISO 27001 certification status unknown; gap report recommended

#

3.3

Workflow

BCP Review

Status

In Scope

Trigger / Rationale

OCC and FFIEC BCP requirements apply to SoFi Bank; BCP documentation status not publicly disclosed

#

3.4

Workflow

IR Playbook Audit

Status

In Scope

Trigger / Rationale

SEC cyber incident disclosure rules (Reg S-K Item 106) apply; GDPR Art. 33 not confirmed applicable; playbook audit in scope

#

3.5

Workflow

Data Residency Check

Status

Conditional

Trigger / Rationale

US-primary; Technisys Latin America operations may implicate data residency requirements in specific jurisdictions — cannot confirm from public sources

Category 4 — Internal Governance

#

4.1

Workflow

Policy Library Review

Status

In Scope

Trigger / Rationale

Bank holding company compliance program required; MNPI/insider trading policy confirmed (Ex-19.1); full policy library details not public

#

4.2

Workflow

Board Risk Report

Status

In Scope

Trigger / Rationale

Risk Committee confirmed (min. 3 board members, meets quarterly); board receives quarterly cybersecurity updates from CISO

#

4.3

Workflow

Control Testing Schedule

Status

In Scope

Trigger / Rationale

OCC/Fed supervision requires annual control testing; internal audit team confirmed

#

4.4

Workflow

Remediation Tracker

Status

In Scope

Trigger / Rationale

Three resolved enforcement actions (FTC 2019, SEC 2021, FINRA 2024) confirm need for ongoing remediation tracking

#

4.5

Workflow

Audit Committee Prep Pack

Status

In Scope

Trigger / Rationale

Audit Committee confirmed (chaired by Gary Meltzer); Deloitte as auditor; PCAOB-registered audit; in scope

Category 5 — Ongoing / Scheduled Monitoring

#

5.1

Workflow

Regulatory Change Monitor

Status

In Scope

Trigger / Rationale

OCC proposed $50B→$700B heightened standards threshold change (Dec 2025); CFPB supervision active; FinCEN IA AML Rule (2028); crypto regulation evolving; active horizon scanning required

#

5.2

Workflow

Vendor Renewal Risk Flag

Status

In Scope

Trigger / Rationale

Third-party security program confirmed; Galileo client concentration loss (2025) underscores vendor/client concentration monitoring need

#

5.3

Workflow

Training Compliance Tracker

Status

In Scope

Trigger / Rationale

AML training, cybersecurity awareness training (including phishing) confirmed; completion tracking details not public

#

5.4

Workflow

Access Review Report

Status

In Scope

Trigger / Rationale

ISO 27002 and FFIEC requirements apply; access review details not publicly disclosed

Category 6 — Privacy & Data Protection

#

6.1

Workflow

GDPR Compliance Audit

Status

Conditional

Trigger / Rationale

US-primary; Technisys Luxembourg/EU nexus may create GDPR exposure — cannot confirm from public sources

#

6.2

Workflow

CCPA DSR Tracker

Status

In Scope

Trigger / Rationale

SoFi serves California consumers at scale (13.7M+ members); CCPA/CPRA obligations confirmed

#

6.3

Workflow

Data Retention Policy Review

Status

In Scope

Trigger / Rationale

SEC recordkeeping rules apply (SoFi Securities, SoFi Wealth); BSA recordkeeping applies to SoFi Bank; CCPA minimization applies

#

6.4

Workflow

Privacy Impact Assessment

Status

Conditional

Trigger / Rationale

SoFi Crypto (launched Dec 2025) and SoFiUSD stablecoin involve new high-risk data processing — DPIA/PIA may be required

Category 7 — Cybersecurity

#

7.1

Workflow

Vulnerability Management Review

Status

In Scope

Trigger / Rationale

ISO 27002 and NIST CSF confirmed in 10-K; FFIEC IT exam applies; scan cadence details not public

#

7.2

Workflow

Security Awareness Training

Status

In Scope

Trigger / Rationale

Phishing training campaigns confirmed in 10-K

#

7.3

Workflow

Endpoint Security Audit

Status

In Scope

Trigger / Rationale

FFIEC and NIST CSF scope confirmed; EDR coverage details not public

#

7.4

Workflow

Zero Trust Architecture Gap

Status

Conditional

Trigger / Rationale

NIST 800-207 not explicitly cited; zero trust posture at SoFi Bank not publicly assessable

Category 8 — HR & People Risk

#

8.1

Workflow

Background Check Compliance

Status

In Scope

Trigger / Rationale

FINRA registration requirements for SoFi Securities personnel; OCC fitness-and-propriety standards for SoFi Bank officers

#

8.2

Workflow

Insider Threat Policy Review

Status

In Scope

Trigger / Rationale

MNPI / insider trading policy publicly filed (Ex-19.1 in 10-K); SEC Rule 204A-1 code of ethics (SoFi Wealth)

#

8.3

Workflow

Offboarding Access Revocation

Status

In Scope

Trigger / Rationale

Standard requirement for bank-regulated entity; details not public

#

8.4

Workflow

Whistleblower Program Assessment

Status

In Scope

Trigger / Rationale

SEC Dodd-Frank whistleblower obligations apply to public company; SoFi Bank — OCC whistleblower requirements apply; internal program details not public

Category 9 — Third-Party / Supply Chain Risk

#

9.1

Workflow

Vendor Onboarding Due Diligence

Status

In Scope

Trigger / Rationale

Third-Party Security Risk Management program confirmed; risk-based DD during supplier onboarding confirmed

#

9.2

Workflow

Ongoing Vendor Monitoring

Status

In Scope

Trigger / Rationale

Ongoing monitoring confirmed in 10-K cybersecurity disclosure

#

9.3

Workflow

Concentration Risk Assessment

Status

In Scope

Trigger / Rationale

Galileo large-client departure (FY2025) caused 23% drop in technology platform accounts — confirmed from public earnings disclosures; concentration risk is a demonstrated finding

#

9.4

Workflow

Vendor Exit & Termination Plan

Status

In Scope

Trigger / Rationale

Galileo client exit demonstrates real-world need; exit plan details not public

Category 10 — ESG / Non-Financial Reporting

#

10.1

Workflow

ESG Program Readiness

Status

Conditional

Trigger / Rationale

No public ESG report or substantive ESG governance document identified; program maturity unknown

#

10.2

Workflow

Climate / TCFD Disclosure

Status

Conditional

Trigger / Rationale

No TCFD-aligned disclosure identified from public sources; SEC climate rules (phased) may require disclosure

#

10.3

Workflow

SFDR Classification Review

Status

Suppressed

Trigger / Rationale

No EU-distributed investment products confirmed; SFDR not applicable

#

10.4

Workflow

CSRD / ESRS Reporting Assessment

Status

Suppressed

Trigger / Rationale

US-primary entity; no EU subsidiary triggering CSRD confirmed

Category 11 — Operational Risk

#

11.1

Workflow

Operational Risk Register Review

Status

In Scope

Trigger / Rationale

OCC/Fed ERM requirements apply; RCSA implied; details not publicly disclosed

#

11.2

Workflow

DR Gap Report

Status

In Scope

Trigger / Rationale

FFIEC BCP requirements apply to SoFi Bank; DR documentation details not public

#

11.3

Workflow

BCP Test & Exercise Review

Status

In Scope

Trigger / Rationale

OCC heightened-standards implications (assets $50.7B approaching or at threshold); BCP exercise results not public

#

11.4

Workflow

Process Resilience & Outsourcing Review

Status

In Scope

Trigger / Rationale

SoFi Bank relies on Galileo for technology infrastructure; Technology Platform = outsourced service provider to third parties; dual exposure confirmed

3B. Detailed Workflow Assessment — Selected In-Scope / Conditional Workflows

2.5 | KYC Onboarding Audit In Scope

Objective: Verify that SoFi's customer identification program (CIP) and identity theft prevention program (ITPP) meet FinCEN CDD Rule and BSA requirements across all regulated subsidiaries.

Frameworks: FinCEN CDD Rule; BSA; FINRA Rule 4370 (CIP); FATF Guidance.

Observation: FINRA fined SoFi Securities LLC $1.1 million (May 2024, AWC No. 2019062705801) for failing to establish and maintain reasonable CIP and ITPP programs for SoFi Money accounts (conduct period: December 2018 – April 2019). Approximately 800 fraudulent accounts were opened; ~$8.6M was transferred from customers of other institutions; ~$2.5M was withdrawn. The largely automated account-opening process failed to flag invalid SSNs, addresses, and high-risk emails. SoFi self-reported and remediated in April 2019. Post-remediation program quality cannot be confirmed from public sources.

Next Action: Obtain current CIP/ITPP policy documentation and evidence of post-2019 program enhancements; validate current fraud-alert SLA metrics against BSA exam standards.

2.2 | AML Transaction Monitoring In Scope

Objective: Confirm existence and adequacy of BSA/AML transaction monitoring program at SoFi Bank, N.A.

Frameworks: Bank Secrecy Act; FinCEN Regulations; FFIEC BSA/AML Examination Manual; FinCEN Investment Adviser AML Rule (effective January 1, 2028).

Observation: SoFi Bank is subject to full BSA/AML program requirements as a federally chartered national bank. The 10-K acknowledges BSA/AML obligations. No public enforcement action by FinCEN or OCC on AML program found. With $37.5B in deposits, 13.7M members, crypto operations (SoFi Crypto, SoFiUSD stablecoin launched 2025), and cross-border Tech Platform clients, AML transaction volume and complexity is material. FinCEN's new IA AML Rule (eff. Jan 1, 2028) will extend AML obligations to SoFi Wealth LLC and SoFi Capital Advisors LLC.

Next Action: Request BSA/AML program documentation, TM system vendor identity, SAR filing statistics (if disclosable), and CISO/BSA Officer assessment of crypto-related AML controls.

9.3 | Concentration Risk Assessment In Scope

Objective: Assess client and vendor concentration risk in SoFi's Technology Platform segment.

Frameworks: DORA ICT third-party (Conditional for US entity); OCC Third-Party Risk Management guidance (OCC 2013-29); internal ERM.

Observation: In FY2025, a single unnamed large Galileo client fully exited the platform, causing Technology Platform accounts to fall from 167.7 million to 128.5 million — a 23% decline. This is confirmed from public earnings disclosures. The concentration of revenue from one large client represents a material operational and revenue risk. Client identity, contractual terms, and SoFi's concentration risk management framework details are not publicly disclosed.

Next Action: Request client concentration analysis for Technology Platform; review OCC third-party risk management framework documentation; validate exit and termination plan per 9.4.

4. Detailed Risk Findings — Top 9 Flags + Strategic Alternatives

F-001 | KYC / CIP Program — Prior Enforcement + Evolving Obligations

HIGH

Confidence: Confirmed (public enforcement record) / Conditional (post-remediation status)

Regulatory Citation: FINRA AWC No. 2019062705801 (May 2024); BSA 31 U.S.C. §5318; FinCEN CDD Rule 31 CFR §1010.230; FinCEN IA AML Rule (eff. Jan 1, 2028)

SoFi Securities LLC was fined $1.1M by FINRA in May 2024 for failing to maintain a reasonable CIP and ITPP for SoFi Money during December 2018 – April 2019. Approximately 800 fraudulent accounts were opened; $8.6M transferred from external accounts; $2.5M withdrawn. Separately, FinCEN's new Investment Adviser AML Rule will require SoFi Wealth LLC and SoFi Capital Advisors LLC to implement AML programs by January 1, 2028.

Data gap / current gap: Post-remediation CIP/ITPP program documentation and testing results are not confirmable from public sources. IA AML compliance programs for investment adviser affiliates are not yet required (pre-2028) but planning should be underway.

Remediation: Obtain CIP/ITPP program documentation; conduct gap assessment against current FFIEC and FinCEN standards; initiate IA AML program design for 2028 compliance.

Owner: Chief Risk Officer; BSA/AML Officer

Deadline: IA AML Rule: January 1, 2028; CIP remediation validation: next examination cycle

Strategic Alternatives

Option

Option 1 — Internal

Action

Enhance BSA/Compliance team

Details

Owner: CRO + BSA Officer; conduct internal AML program refresh and IA AML readiness assessment. Est. Lift: Medium

Option

Option 2 — Vendor

Action

Engage AML regulatory consulting firm

Details

Pros: Specialized expertise; benchmarking against peer banks at similar asset scale. Cons: Cost; integration of external recommendations with existing Galileo transaction monitoring infrastructure.

Option

Option 3 — Risk Acceptance

Action

Accept residual gap for pre-2028 IA AML

Details

Viable when: Only for the IA AML Rule timeline gap (pre-2028); not viable for bank CIP obligations. Approval: Chief Risk Officer + General Counsel

F-002 | CFPB Direct Supervision — Commenced January 1, 2024

HIGH

Confidence: Confirmed

Regulatory Citation: Dodd-Frank Act §1025; CFPB Supervision and Examination Manual; 12 U.S.C. §5515

SoFi Bank and affiliates became subject to direct CFPB supervision and examination commencing January 1, 2024, triggered by total assets exceeding $10 billion for four consecutive quarters. Prior to this date, OCC examined SoFi Bank for compliance with CFPB rules. This represents a structural change in supervisory regime: the CFPB has now had direct examination authority for approximately 18 months as of this report date.

Data gap / current gap: Outcome of any CFPB examination findings since January 1, 2024 is not publicly disclosed. UDAAP compliance posture under direct CFPB examination cannot be confirmed from public sources. The FTC consent order (active to 2039) regarding advertising savings claims may also inform CFPB examination scope.

Remediation: Engage counsel to review first CFPB examination cycle findings; conduct UDAAP self-assessment across all consumer-facing products; review advertising claims compliance against FTC consent order terms.

Owner: General Counsel; Chief Compliance Officer

Deadline: Ongoing; first CFPB exam cycle already underway

Strategic Alternatives

Option

Option 1 — Internal

Action

UDAAP self-assessment

Details

Owner: Compliance team; map all consumer-facing product flows to CFPB examination priorities. Est. Lift: Medium

Option

Option 2 — Vendor

Action

Engage CFPB-specialized regulatory counsel

Details

Pros: Deep CFPB examination knowledge; can model exam findings. Cons: Cost; need for internal coordination across 13.7M member-facing products.

Option

Option 3 — Risk Acceptance

Action

Not viable

Details

CFPB supervision is non-negotiable for >$10B assets. Approval: N/A

F-003 | FTC Consent Order — Active Until 2039

MEDIUM

Confidence: Confirmed

Regulatory Citation: FTC Docket No. C-4673; In re Social Finance, Inc. and SoFi Lending Corp. (2019); Federal Trade Commission Act §5

The FTC approved a final consent order against Social Finance, Inc. and SoFi Lending Corp. in February 2019 (conduct: 2018) for deceptive advertising regarding student loan refinancing savings — ads were alleged to have inflated average consumer savings, sometimes doubling the actual figure. The consent order prohibits SoFi from misrepresenting savings claims unless substantiated by competent and reliable evidence. The order remains active and will terminate on February 22, 2039 (or 20 years from any subsequent enforcement action, whichever is later).

Data gap / current gap: Ongoing compliance with consent order terms is not publicly verified. Any advertising review or substantiation process details are not public. SoFi's current student loan refinancing advertising must be evaluated against order terms continuously.

Remediation: Confirm existence of advertising substantiation review process tied to the FTC order; document compliance reporting to FTC (required under Part III of the order).

Owner: General Counsel; Chief Marketing Officer

Deadline: Ongoing through 2039

Strategic Alternatives

Option

Option 1 — Internal

Action

Advertising compliance review program

Details

Owner: Legal + Marketing; annual review of all savings-related claims against FTC order terms. Est. Lift: Low

Option

Option 2 — Vendor

Action

Engage advertising law specialist

Details

Pros: Specialized expertise in FTC substantiation standards. Cons: Cost; SoFi has presumably built this capability internally given 6+ years under order.

Option

Option 3 — Risk Acceptance

Action

Accept residual compliance management risk

Details

Viable when: Base compliance program already established; accept residual risk of inadvertent non-compliance. Approval: General Counsel

F-004 | SEC Conflict-of-Interest Order — SoFi Wealth LLC (2021)

MEDIUM

Confidence: Confirmed

Regulatory Citation: SEC IA Release No. 5826 (August 19, 2021); Investment Advisers Act Section 206(2); SEC Rule 206(4)-7

The SEC charged SoFi Wealth LLC in August 2021 for breaching fiduciary duty by failing to disclose conflicts of interest when it reallocated approximately 20,000 automated portfolio accounts from third-party ETFs to two SoFi-sponsored ETFs (SFY and SFYX) in April 2019, without informing clients of the company's economic interest in those funds. SoFi Wealth also failed to assess tax consequences for clients (~$772K short-term capital gains, ~$662K long-term capital gains imposed). SoFi Wealth agreed to a cease-and-desist order, censure, and $300,000 civil penalty without admitting or denying findings.

Data gap / current gap: Remediation and undertakings required by the SEC order were completed (order acknowledged remedial acts). Ongoing monitoring status of SoFi Wealth's conflict disclosure practices and compliance program enhancements are not publicly verifiable.

Remediation: Confirm SEC order undertakings have been fulfilled; review current SoFi Wealth conflict-of-interest disclosure practices against Reg BI / fiduciary standard; verify no recurrence in subsequent product rollouts (e.g., SoFi Crypto, SoFiUSD).

Owner: SoFi Wealth Chief Compliance Officer; General Counsel

Deadline: Order compliance ongoing; SoFi Crypto-related conflict review: immediate

Strategic Alternatives

Option

Option 1 — Internal

Action

Conflict review for new products

Details

Owner: SoFi Wealth CCO; systematic conflict-of-interest pre-launch review for all new products. Est. Lift: Low

Option

Option 2 — Vendor

Action

Third-party RIA compliance consultant

Details

Pros: Independent review of SoFi Wealth Form ADV disclosures and conflicts policy. Cons: Limited marginal value if internal program already enhanced post-2021 order.

Option

Option 3 — Risk Acceptance

Action

Accept residual compliance management risk

Details

Viable when: Remediation confirmed complete; low recurrence risk given heightened CFPB and SEC scrutiny. Approval: General Counsel

F-005 | $50 Billion Asset Threshold — OCC Heightened Standards Exposure

HIGH

Confidence: Confirmed (threshold crossed); Conditional (regulatory outcome pending OCC rulemaking)

Regulatory Citation: 12 CFR Part 30 (OCC Heightened Standards); Dodd-Frank Act §165; OCC Proposed Rule (December 23, 2025 — raising threshold from $50B to $700B)

As of December 31, 2025, SoFi reported total assets of $50.7 billion, crossing the existing $50 billion OCC heightened standards threshold for national banks (12 CFR Part 30 App. D). This would normally trigger enhanced risk management, liquidity, and governance requirements. However, on December 23, 2025, the OCC proposed raising this threshold to $700 billion. If finalized as proposed, SoFi Bank would be exempt from the heightened standards. Until the rule is finalized, SoFi Bank technically operates at a threshold with regulatory uncertainty.

Data gap / current gap: Status of SoFi Bank's compliance with existing $50B heightened standards (if applicable) is not publicly confirmed. OCC proposed rulemaking timeline and final outcome are uncertain.

Remediation: Monitor OCC rulemaking; engage regulatory counsel to assess current obligations under existing $50B threshold; document readiness for either outcome.

Owner: Chief Risk Officer; General Counsel

Deadline: OCC rulemaking finalization (timeline uncertain); interim: immediate regulatory counsel review

Strategic Alternatives

Option

Option 1 — Internal

Action

Regulatory monitoring and threshold readiness

Details

Owner: CRO + Legal; track OCC rulemaking and maintain readiness materials. Est. Lift: Low

Option

Option 2 — Vendor

Action

Engage OCC-specialized bank regulatory counsel

Details

Pros: Real-time rulemaking intelligence; can assess applicability of current Part 30 Appendix D obligations. Cons: Cost.

Option

Option 3 — Risk Acceptance

Action

Accept pending regulatory clarity

Details

Viable when: OCC proposed rule raises threshold significantly; monitor for finalization before committing to full heightened-standards program build. Approval: Chief Risk Officer

F-006 | Technology Platform Concentration Risk — Galileo Client Exit

MEDIUM

Confidence: Confirmed

Regulatory Citation: OCC Third-Party Risk Management Guidance (OCC 2023-17); FFIEC IT Handbook — Outsourcing Technology Services

In FY2025, a single large, unnamed Galileo client fully transitioned off the Technology Platform, causing total Technology Platform accounts to fall from 167.7 million to 128.5 million (a 23% decline). This is a confirmed, material event from public earnings disclosures. It demonstrates single-client concentration risk in SoFi's B2B technology infrastructure business and reflects the vulnerability of the Galileo platform to large-customer churn.

Data gap / current gap: Client concentration data for the Technology Platform (top client as % of segment revenue), exit and termination plan details, and contractual protections are not publicly disclosed.

Remediation: Request top-10 client concentration analysis for Galileo/Technology Platform; review vendor exit and termination plan documentation; assess revenue diversification strategy.

Owner: Technology Platform CEO / Business Unit Head; Chief Risk Officer

Deadline: Immediate

Strategic Alternatives

Option

Option 1 — Internal

Action

Client diversification and concentration monitoring

Details

Owner: Galileo BU leadership; establish concentration thresholds and monitor quarterly. Est. Lift: Medium

Option

Option 2 — Vendor

Action

Third-party business continuity review

Details

Pros: Independent assessment of platform resilience to large-client exits. Cons: Sensitivity of client data.

Option

Option 3 — Risk Acceptance

Action

Accept concentration as inherent to platform model

Details

Viable when: Platform is actively diversifying; no single client represents >20% of segment revenue. Approval: CEO + Board Risk Committee

F-007 | SOC 2 Attestation Status — Unknown

MEDIUM

Confidence: Unknown

Regulatory Citation: AICPA Trust Services Criteria; FFIEC IT Handbook — Audit; OCC Third-Party Risk Management Guidance

SoFi's 10-K cybersecurity disclosure references ISO 27002:2013, NIST CSF, PCI-DSS, FFIEC, and CIS controls — but does not reference a SOC 2 Type II attestation. Galileo Financial Technologies is the foundational processing infrastructure for SoFi's B2B Technology Platform business. Institutional clients and banking customers typically require SOC 2 Type II attestations from their critical infrastructure providers. Whether SoFi/Galileo holds a current SOC 2 Type II is not confirmable from public sources.

Data gap / current gap: SOC 2 Type II attestation status for Galileo Financial Technologies and SoFi Bank's core processing environment is unknown from public sources.

Remediation: Obtain SOC 2 Type II report for Galileo and SoFi Bank's critical control environment; if not yet obtained, scope and commission SOC 2 examination.

Owner: CISO; Galileo Head of Compliance

Deadline: 90 days (to confirm or initiate)

Strategic Alternatives

Option

Option 1 — Internal

Action

Engage existing auditor (Deloitte) to scope SOC 2

Details

Owner: CISO + Internal Audit; leverage existing relationship with Deloitte & Touche LLP. Est. Lift: High

Option

Option 2 — Vendor

Action

Engage specialist SOC 2 readiness firm

Details

Pros: Faster gap-to-report timeline; specialized tooling. Cons: Cost; coordination with Deloitte.

Option

Option 3 — Risk Acceptance

Action

Accept attestation gap pending prioritization

Details

Viable when: No contractual SOC 2 requirement currently outstanding from B2B clients. Approval: CISO + CRO

F-008 | ESG / Climate Disclosure Gap

MEDIUM

Confidence: Confirmed (absence of disclosure)

Regulatory Citation: SEC Climate Disclosure Rules (Release No. 33-11275, phased implementation); TCFD Framework; California SB 253 / SB 261 (climate disclosure laws, may apply to companies with California revenues)

No TCFD-aligned or SEC climate disclosure was identified from public sources for SoFi Technologies. SoFi's investor relations governance documents page returned no substantive content. With $3.6 billion in revenue and California headquarters, SoFi may be subject to California's SB 253 (Scope 1/2/3 emissions disclosure) and SB 261 (climate-related financial risk disclosure). SEC climate rules are being phased in for large accelerated filers.

Data gap / current gap: No public ESG report, TCFD disclosure, or climate risk assessment identified. ESG governance program maturity is unknown.

Remediation: Conduct ESG program readiness assessment; develop climate disclosure roadmap; assess California SB 253/261 applicability and timelines.

Owner: General Counsel; Chief Financial Officer; Board Audit Committee

Deadline: California SB 253: Scope 1/2 reporting beginning 2026 for FY2025 data (if applicable); SEC phased rules apply to large accelerated filers

Strategic Alternatives

Option

Option 1 — Internal

Action

ESG program design and disclosure roadmap

Details

Owner: CFO + Legal; build ESG team and disclosure framework. Est. Lift: High

Option

Option 2 — Vendor

Action

Engage ESG advisory firm

Details

Pros: Benchmarking; framework selection; data collection tooling. Cons: Cost; need for integration with financial reporting.

Option

Option 3 — Risk Acceptance

Action

Accept disclosure gap pending regulatory clarity

Details

Viable when: SEC and California timelines are still being assessed; minimal near-term enforcement risk for first-year non-filers. Approval: CFO + General Counsel

F-009 | Crypto / Digital Asset Regulatory Risk — SoFi Crypto + SoFiUSD

HIGH

Confidence: Confirmed (product launch); Conditional (regulatory treatment)

Regulatory Citation: SEC / CFTC jurisdiction over crypto assets (evolving); FinCEN virtual asset service provider guidance; OCC Conditional Approval No. 1277 (Jan 2022) — SoFi Bank prohibited from crypto-asset activities absent prior OCC non-objection under the Operating Agreement; OCC Interpretive Letters; Financial Innovation and Technology for the 21st Century Act (FIT21, pending); California DFPI crypto registration

SoFi launched SoFi Crypto (retail crypto trading) and SoFiUSD (a stablecoin) in December 2025. This is confirmed from FY2025 public earnings disclosures and the 10-K. Notably, the OCC's January 2022 conditional approval (CA #1277) for SoFi Bank stated that, while the Operating Agreement remains in effect, “the Resulting Bank shall not engage in any crypto-asset activities or services... unless it has received prior written determination of no supervisory objection from the OCC.” In other words, the prohibition is not absolute — the bank may conduct crypto activities if it first obtains OCC non-objection through the procedures set out in the Operating Agreement. The structure of SoFi Crypto and SoFiUSD relative to SoFi Bank N.A. vs. other corporate entities is not publicly detailed, and whether SoFi has sought or obtained the OCC's prior non-objection determination for the December 2025 crypto launches cannot be confirmed from public sources. If crypto activities are conducted within or linked to SoFi Bank without that prior OCC non-objection, this may conflict with the 2022 OCC condition.

Data gap / current gap: The legal entity structure for SoFi Crypto operations (i.e., whether conducted in SoFi Digital Assets LLC or another non-bank entity separate from SoFi Bank N.A.) is not publicly confirmed in sufficient detail. Critically, whether SoFi Bank has sought and obtained the OCC's prior written determination of no supervisory objection for the December 2025 crypto activities (the carve-out that permits crypto under CA #1277) is not publicly disclosed. Regulatory approvals for SoFiUSD stablecoin activities are not public.

Remediation: Map crypto product legal entity structure; confirm no SoFi Bank N.A. involvement in prohibited crypto activities per OCC condition; document OCC/FinCEN/SEC regulatory position for SoFi Crypto and SoFiUSD.

Owner: General Counsel; Chief Risk Officer; SoFi Digital Assets LLC compliance lead

Deadline: Immediate (pre-existing regulatory condition may be at risk)

Strategic Alternatives

Option

Option 1 — Internal

Action

Legal entity structure mapping and OCC condition review

Details

Owner: General Counsel; document SoFi Crypto/SoFiUSD entity structure and confirm OCC condition compliance. Est. Lift: Low-Medium

Option

Option 2 — Vendor

Action

Engage crypto-regulatory counsel

Details

Pros: Specialized expertise on OCC crypto guidance, FinCEN VASP rules, and stablecoin regulatory treatment. Cons: Fast-moving regulatory landscape; cost.

Option

Option 3 — Risk Acceptance

Action

Not viable

Details

OCC condition compliance is non-negotiable for charter maintenance. Approval: N/A

5. Regulatory Obligation Map

Status: ✓ ACTIVE (confirmed obligation). ● LIKELY (strong inference, not fully confirmed). ● N/A (not applicable with rationale).

Scroll for more →

FrameworkJurisdictionStatusKey ObligationsPriority
OCC National Bank SupervisionFederal (US)✓ ACTIVESafety and soundness; capital adequacy; CRA compliance; OCC examination; approval for branches/acquisitions; heightened standards (§50B threshold — pending OCC rulemaking clarification)High
Federal Reserve — BHCA / FHCFederal (US)✓ ACTIVEBank holding company regulation; financial holding company status (§4(l) BHCA); “well capitalized” and “well managed” requirements; affiliate transaction restrictions (§§23A/23B); Volcker Rule (applies — assets exceed $10B)High
CFPB Direct SupervisionFederal (US)✓ ACTIVEDirect examination authority (commenced Jan 1, 2024); UDAAP; fair lending; consumer protection laws; Truth in Lending Act; ECOA; EFTA; TILAHigh
FinCEN / BSAFederal (US)✓ ACTIVEBSA program; SAR filing; CTR filing; CDD/KYC; OFAC sanctions screening; FinCEN IA AML Rule (effective Jan 1, 2028 — investment adviser affiliates)High
FDIC InsuranceFederal (US)✓ ACTIVEDeposit insurance assessments ($19.3M FDIC expense FY2025); compliance with FDIA; examination by FDIC as secondary regulatorMedium
SEC — Public Reporting CompanyFederal (US)✓ ACTIVEAnnual 10-K, quarterly 10-Q, 8-K current reports; proxy (DEF 14A); PCAOB audit; Reg FD; insider trading restrictions; climate disclosure rules (phased)High
SEC — Investment Adviser ActFederal (US)✓ ACTIVESoFi Wealth LLC and SoFi Capital Advisors LLC: Form ADV; fiduciary duty; Rule 206(4)-7 compliance program; Code of Ethics (Rule 204A-1)Medium
FINRAFederal (US)✓ ACTIVESoFi Securities LLC (CRD 151717): broker-dealer rules; FINRA Rule 4512 (CIP); Rule 17a-3/17a-4 (recordkeeping); net capital; SIPC membershipHigh
FTC Consent Order (Docket C-4673)Federal (US)✓ ACTIVEProhibition on unsubstantiated savings claims in advertising; active through 2039; annual compliance reporting to FTCMedium
OCC Conditional Approval (Jan 2022)Federal (US)✓ ACTIVEProhibition on crypto-asset activities/services at SoFi Bank N.A. level; capital contribution conditionsHigh
CCPA / CPRACalifornia (US)✓ ACTIVEConsumer data subject rights; privacy notice; opt-out rights; CPPA enforcementMedium
State Banking / LicensingMulti-state (US)● LIKELYState money transmitter licenses; state mortgage originator licenses (Wyndham Capital Mortgage); state consumer lending laws; various state regulator supervisionMedium
California SB 253 / SB 261California (US)● LIKELYScope 1/2/3 GHG emissions reporting (SB 253); climate-related financial risk disclosure (SB 261); applicability depends on California revenue threshold ($1B+) — SoFi likely exceeds thresholdMedium
CRA (Community Reinvestment Act)Federal (US)✓ ACTIVEOCC evaluates SoFi Bank under CRA; performance assessment; public file maintenanceMedium
EU DORAEU● LIKELY (Conditional)Technisys S.A. (Luxembourg) may constitute an ICT third-party provider subject to DORA or serving DORA-regulated entities; requires confirmationLow
GDPREU● LIKELY (Conditional)Technisys Luxembourg operations may implicate GDPR for EU data subjects; requires entity-level mappingLow
Basel III / DFASTFederal (US)● LIKELYDFAST stress testing may apply at $50B+ threshold (under current rules); Basel III capital framework applies via OCC; DFAST applicability depends on regulatory clarification post OCC proposed ruleMedium
HIPAAFederal (US)● N/ASoFi is not a healthcare entity or business associate; not applicable
SFDR / CSRDEU● N/ANo EU-distributed investment products confirmed; no EU parent; not applicable under current structure

6. Workflow Linkage Map

Source Workflow

2.5 KYC Onboarding Audit

Linked To

2.2 AML Transaction Monitoring

Shared Artifact / Rationale

Customer identity data feeds directly into TM system; CIP weakness = AML blind spot

Link

✓ LINK

Source Workflow

2.5 KYC Onboarding Audit

Linked To

8.1 Background Check Compliance

Shared Artifact / Rationale

Identity verification protocols applicable to both customer onboarding and employee screening

Link

● COND

Source Workflow

2.2 AML Transaction Monitoring

Linked To

2.3 SAR Draft

Shared Artifact / Rationale

TM system generates alerts that feed SAR decision workflow

Link

✓ LINK

Source Workflow

4.1 Policy Library Review

Linked To

8.2 Insider Threat Policy Review

Shared Artifact / Rationale

MNPI policy is part of overall policy library; Ex-19.1 filed with 10-K

Link

✓ LINK

Source Workflow

9.3 Concentration Risk Assessment

Linked To

11.4 Process Resilience & Outsourcing Review

Shared Artifact / Rationale

Galileo client concentration = both vendor dependency and outsourced service concentration risk

Link

✓ LINK

Source Workflow

1.4 Vendor Risk Assessment

Linked To

9.1 Vendor Onboarding Due Diligence

Shared Artifact / Rationale

Third-Party Security Risk Management program covers both SOC 2 vendor assessment and broader vendor DD

Link

✓ LINK

Source Workflow

F-009 Crypto Risk

Linked To

5.1 Regulatory Change Monitor

Shared Artifact / Rationale

Crypto regulatory landscape (SEC, CFTC, FinCEN, OCC) evolving rapidly; must be tracked in horizon scanning

Link

✓ LINK

Source Workflow

F-008 ESG Disclosure

Linked To

5.1 Regulatory Change Monitor

Shared Artifact / Rationale

California SB 253/261 and SEC climate rules are active regulatory changes requiring monitoring

Link

✓ LINK

Source Workflow

7.1 Vulnerability Management

Linked To

7.3 Endpoint Security Audit

Shared Artifact / Rationale

Shared artifact: vulnerability scan results feed endpoint remediation prioritization

Link

✓ LINK

Source Workflow

4.2 Board Risk Report

Linked To

4.5 Audit Committee Prep Pack

Shared Artifact / Rationale

Risk Committee and Audit Committee overlap; CISO reports quarterly to Risk Committee; Audit Committee reviews financial controls

Link

● COND

7. Escalations — Items Requiring Review

E-01 | OCC Conditional Approval vs. SoFi Crypto / SoFiUSD — Potential Conflict

Reason: The OCC's January 2022 conditional approval of SoFi Bank, N.A. expressly prohibited crypto-asset activities or services at the bank. SoFi launched SoFi Crypto and SoFiUSD stablecoin in December 2025. The legal entity structure for these activities (whether conducted outside SoFi Bank N.A.) is not publicly confirmed. This cannot be resolved from public sources and presents a potential charter-level compliance risk.

Who Must Review: General Counsel + Chief Risk Officer + OCC Relationship Manager

E-02 | CFPB Examination Findings — January 2024 Onwards

Reason: CFPB direct supervision began January 1, 2024. Any examination findings from the first CFPB examination cycle are confidential and not publicly disclosed. The FTC consent order and FINRA CIP/ITPP fine create relevant precedent for CFPB examination focus areas. Examination findings cannot be confirmed from public sources.

Who Must Review: General Counsel + Chief Compliance Officer + CFPB Relationship Manager

E-03 | BSA/AML Program Documentation — Post-Bank Charter Quality

Reason: SoFi Bank N.A. obtained its charter in January 2022. A full BSA/AML program is required. Prior enforcement (FINRA 2024 for 2018–2019 conduct) related to a pre-bank period. The quality of the post-charter BSA/AML program — including TM system, SAR filing cadence, and CDD compliance — cannot be verified from public sources.

Who Must Review: BSA/AML Compliance Officer + Chief Risk Officer + OCC/FinCEN Relationship Manager

E-04 | Technisys S.A. (Luxembourg) — EU Regulatory Obligations

Reason: Technisys S.A. is a Luxembourg société anonyme and subsidiary of SoFi. It provides core banking technology to financial institutions in Latin America and potentially the EU. DORA and GDPR obligations may attach. Cannot be determined from public sources.

Who Must Review: General Counsel + Technisys Chief Compliance Officer + EU regulatory counsel

8. Next Actions — Prioritized (Effort × Impact)

Scroll for more →

PriorityActionLinked Finding/WorkflowEffortImpactOwner
1Map SoFi Crypto/SoFiUSD entity structure vs. OCC 2022 condition; engage OCC counselF-009, E-01LowHighGeneral Counsel
2Obtain post-2019 CIP/ITPP program documentation and current BSA/AML program assessmentF-001, E-03, 2.5, 2.2MediumHighCRO, BSA Officer
3Initiate IA AML Rule (eff. 2028) readiness program for SoFi Wealth LLC and SoFi Capital Advisors LLCF-001, 2.2MediumHighCCO, CRO
4CFPB examination preparation: UDAAP self-assessment across all consumer products; FTC consent order compliance reviewF-002, F-003, E-02HighHighGeneral Counsel, CCO
5Confirm SOC 2 Type II status for Galileo Financial Technologies; scope examination if not yet obtainedF-007, 1.3HighMediumCISO, Internal Audit
6OCC $50B heightened standards monitoring: engage regulatory counsel; assess current Part 30 Appendix D obligations pending OCC rulemaking finalizationF-005LowMediumCRO, General Counsel
7Galileo concentration risk: obtain client concentration data; review exit/termination planF-006, 9.3, 9.4MediumMediumGalileo BU Leadership, CRO
8ESG/climate disclosure roadmap: assess California SB 253/261 applicability; begin emissions data collectionF-008, 10.1, 10.2HighMediumCFO, General Counsel
9Technisys EU regulatory mapping: assess DORA and GDPR obligations for Luxembourg entityE-04, 3.1, 3.5, 6.1MediumMediumGeneral Counsel, Technisys CCO

9. Peer Benchmarking Reference

SoFi Peer Archetype: High-Growth National Bank + Fintech Platform at Scale

SoFi is most comparable to the cohort of de novo or recently chartered national banks that have grown rapidly through digital channels (vs. legacy branch networks), including: Ally Financial (ALLY, established BHC, $196B assets), LendingClub Corporation (LC, national bank since 2021, ~$10B assets), Synchrony Financial (SYF, ~$100B assets), and Green Dot Corporation (GDOT, bank holding company). SoFi's Technology Platform segment has no direct peer among this cohort — Galileo and Technisys position SoFi as both a regulated financial institution and a B2B fintech infrastructure provider (comparable peers include FIS, Fiserv, Jack Henry — though those are non-bank technology companies).

GRC Category

Financial Regulation

SoFi (This Profile)

Defined (3)

Peer Norm (National Bank, $20–100B assets)

Defined–Managed (3.5)

Gap Signal

Slight lag — enforcement history and rapid growth

GRC Category

Cybersecurity

SoFi (This Profile)

Defined (3)

Peer Norm (National Bank, $20–100B assets)

Defined–Managed (3.5)

Gap Signal

Moderate lag — SOC 2 status unknown; zero trust gap unclear

GRC Category

Internal Governance

SoFi (This Profile)

Defined (3)

Peer Norm (National Bank, $20–100B assets)

Managed (4)

Gap Signal

Moderate gap — board structure strong; policy library depth unknown

GRC Category

BSA/AML

SoFi (This Profile)

Developing–Defined (2.5)

Peer Norm (National Bank, $20–100B assets)

Defined (3)

Gap Signal

Gap — prior FINRA CIP/ITPP finding; post-charter program quality unconfirmed

GRC Category

ESG / Disclosure

SoFi (This Profile)

Developing (2)

Peer Norm (National Bank, $20–100B assets)

Defined (3)

Gap Signal

Material gap — no public TCFD or climate report vs. large-bank peer norms

GRC Category

Privacy & Data

SoFi (This Profile)

Defined (3)

Peer Norm (National Bank, $20–100B assets)

Defined (3)

Gap Signal

Approximate parity

GRC Category

Third-Party Risk

SoFi (This Profile)

Defined (3)

Peer Norm (National Bank, $20–100B assets)

Managed (4)

Gap Signal

Moderate gap — Galileo concentration loss is a public signal

Benchmarks are directional and based on public evidence only. Not an audit.

10. RuleboardAI Engagement Options

Option A — Verification Sprint (4–6 Weeks)

Scope: Targeted LOA delivery; client provides: BSA/AML program overview, CIP/ITPP post-2019 documentation, SOC 2 status, legal entity structure for SoFi Crypto, and Galileo concentration data. RuleboardAI converts Gap Mode findings to Confirmed/Likely and closes the top escalations (E-01 through E-04). Deliverable: Updated CompanyScope profile with reduced data gaps and confirmed findings.

Ideal for: Closing the 9 data gaps identified in this profile quickly using minimum client effort.

Option B — Program Build (3–6 Months)

Scope: Full 48-workflow gap assessment with client documentation review. Builds a compliance program roadmap covering: BSA/AML program refresh (F-001, E-03), IA AML Rule readiness (2028), CFPB UDAAP self-assessment (F-002), OCC/Fed $50B threshold planning (F-005), SOC 2 readiness for Galileo (F-007), and ESG disclosure roadmap (F-008). Deliverable: Remediation roadmap with prioritized workstreams, effort/cost estimates, and regulatory exam readiness plan.

Ideal for: Building institutional GRC infrastructure ahead of CFPB exam cycle and OCC regulatory changes.

Option C — Managed Monitoring (Ongoing)

Scope: Monthly public-source monitoring of SoFi's regulatory environment: OCC rulemaking, CFPB enforcement database, FINRA BrokerCheck, SEC EDGAR, FTC enforcement, FinCEN advisories, California DFPI, crypto regulatory developments. Monthly RuleboardAI horizon scan briefings. Automatic escalation alerts for new enforcement actions or material regulatory changes affecting the SoFi RCPS profile.

Ideal for: Staying ahead of the fast-moving regulatory environment for a $50B+ fintech bank with crypto, stablecoin, and multi-regulator exposure.

11. Confidence Legend, Data Gaps & Disclaimers

Confidence Legend

Label

Confirmed

Meaning

Verified against a primary public source (cited).

Label

Likely

Meaning

Strong inference; applicability clear; specifics unconfirmed from public sources.

Label

Conditional

Meaning

Depends on a trigger or an artifact not yet seen.

Label

Unknown

Meaning

Cannot be determined from public sources; routed to Escalation and/or Data Gap.

Data Gaps

DG-1

SOC 2 Type II attestation status for Galileo Financial Technologies and SoFi Bank's core processing environment

Cannot confirm from public sources. Galileo serves as critical B2B infrastructure; institutional clients typically require SOC 2 Type II; absence of confirmed attestation is a control assurance gap

DG-2

Post-2019 CIP/ITPP program documentation and current BSA/AML program quality metrics

Cannot confirm from public sources. FINRA 2024 fine relates to 2018–2019 conduct; remediation confirmed but post-charter (post-2022) program quality cannot be verified from public sources

DG-3

CFPB examination findings since January 1, 2024

Cannot confirm from public sources. CFPB has had direct examination authority for 18+ months; findings are confidential but are the most material regulator-facing risk for SoFi given UDAAP obligations and FTC consent order overlap

DG-4

SoFi Crypto / SoFiUSD legal entity structure relative to SoFi Bank N.A. and OCC 2022 conditional approval restriction

Cannot confirm from public sources. If crypto activities are conducted within or linked to SoFi Bank N.A., this may conflict with the charter condition; cannot be confirmed or denied from public sources

DG-5

ESG/climate program documentation; California SB 253/261 applicability assessment

Cannot confirm from public sources. No public TCFD report or climate disclosure identified; SoFi almost certainly exceeds California's $1B revenue threshold; regulatory exposure is plausibly Confirmed but program status is Unknown

DG-6

Technisys S.A. (Luxembourg) EU regulatory obligations — DORA, GDPR applicability

Cannot confirm from public sources. Public disclosures do not confirm or deny EU regulatory obligations for the Luxembourg subsidiary; material if Technisys provides ICT services to EU-regulated banks

DG-7

Galileo client concentration data (top clients as % of Technology Platform revenue)

Cannot confirm from public sources. The unnamed large client departure (23% account drop) is confirmed; the current revenue concentration profile, contractual protections, and exit plan are not public

DG-8

Internal whistleblower program documentation

Cannot confirm from public sources. SEC Dodd-Frank and OCC requirements apply; no public confirmation of internal program structure, reporting channels, or non-retaliation policy

DG-9

BCP/DR test results and exercise cadence for SoFi Bank N.A.

Cannot confirm from public sources. FFIEC BCP requirements mandate regular testing; results are not publicly disclosed; at $50.7B in assets, operational resilience is a material supervisory focus

Disclaimers

  1. Public Sources Only. This profile was produced entirely from publicly available sources including SEC EDGAR filings, OCC press releases and national bank lists, FINRA BrokerCheck/AWC records, FTC enforcement database, and public news sources. No client documentation, internal policies, examination reports, or confidential supervisory information was reviewed or accessed. This is Gap Mode — Preliminary.
  2. No Client Engagement. SoFi Technologies, Inc. is not a client of RuleboardAI. This profile is produced as a sample deliverable demonstrating RuleboardAI's CompanyScope methodology applied to a publicly available, recognized financial institution. No confidential relationship exists.
  3. Not an Audit, Legal Opinion, or Attestation. Nothing in this document constitutes an audit, legal advice, regulatory opinion, or attestation of any kind. Findings are preliminary inferences from public information and are subject to change upon review of client documentation.
  4. Point-in-Time. All data and findings are as of July 1, 2026. Regulatory status, enforcement records, and financial data reflect sources available as of that date. SoFi's regulatory environment and financial profile are evolving rapidly.
  5. Accuracy. While reasonable care was taken to cite primary sources, public sources may themselves contain errors or lag real-time regulatory status. All material facts should be verified directly with SoFi and its regulators before any business, investment, or compliance decision is made.
  6. RuleboardAI Methodology. This profile applies the RuleboardAI RCPS Classification Model and GRC workflow taxonomy (48 workflows, 11 categories, v1 — GovRiskCompliance 2026). Maturity scores are Likely/Conditional inferences. Full maturity scores require Verification Sprint or Program Build engagement.

Source Appendix

Source

SEC EDGAR — SoFi Technologies (CIK 0001818874)

Description

EDGAR filing page for all SoFi public filings

Source

SoFi 10-K FY2025 (filed February 17, 2026)

Description

Annual report for fiscal year ended December 31, 2025

Source

SoFi 10-K FY2024 (filed February 24, 2025)

Description

Annual report for fiscal year ended December 31, 2024

Source

SoFi DEF 14A 2026 Proxy Statement (filed April 30, 2026)

Description

Proxy for 2026 annual meeting; board composition and governance

Source

SoFi Q4 2025 Earnings Disclosures (January 30, 2026)

Description

Financial highlights including total assets $50.7B, members 13.7M

Source

OCC — Conditional Approval SoFi Bank N.A. (January 18, 2022)

Description

OCC press release approving SoFi Bank charter with conditions including no crypto activities

Source

OCC National Banks Active List (May 2026)

Description

Confirms SoFi Bank, National Association active status; OCC Charter No. 20862

Source

FINRA AWC No. 2019062705801 — SoFi Securities LLC (May 2024)

Description

$1.1M fine for CIP/ITPP failures; SoFi Money accounts 2018–2019

Source

SEC IA Release No. 5826 — SoFi Wealth LLC (August 19, 2021)

Description

$300K penalty; failure to disclose conflicts of interest re: proprietary ETF allocations

Source

FTC Consent Order — Docket No. C-4673 (February 2019)

Description

Final consent order; SoFi advertising savings claim restrictions; active through 2039

Source

SoFi Cybersecurity 10-K Disclosure (via Board Cybersecurity tracker)

Description

Item 1C cybersecurity disclosure; frameworks, CISO, Risk Committee oversight

Source

SoFi Leadership Team

Description

C-suite roster

Source

OCC Interpretive Letter / Conditional Approval #1277 (SoFi Bank)

Description

OCC conditional approval documentation

Source

Stock Titan — SoFi 10-K FY2025 Summary

Description

Regulatory environment, capital ratios, employee count, asset thresholds

Source

Companies Market Cap — SoFi 10-K Data

Description

Key financial metrics from FY2025 10-K

Powered by RuleboardAI | Generated 07-01-2026 | Confidential — SoFi Technologies (SAMPLE) — GovRiskCompliance v1 2026 | Public Sources Only

RuleboardAI | www.ruleboardai.com | Ashwin Tatikola

SAMPLE DOCUMENT — ILLUSTRATIVE USE ONLY

This profile was produced entirely from public sources as a sample deliverable for the RuleboardAI marketing website. No client engagement exists between RuleboardAI and SoFi Technologies, Inc. No client documentation was reviewed. All data is sourced from public filings and regulatory records as cited below.

Not an audit, legal opinion, or attestation. Built from public sources only.