Sample CompanyScope Profile
SoFi Technologies, Inc. (NASDAQ: SOFI)
Report Date: July 1, 2026 · Gap Mode — Preliminary (public sources only) · RuleboardAI GovRiskCompliance v1 2026
SAMPLE DOCUMENT — ILLUSTRATIVE USE ONLY
This profile was produced entirely from public sources as a sample deliverable for the RuleboardAI marketing website. No client engagement exists between RuleboardAI and SoFi Technologies, Inc. No client documentation was reviewed. All data is sourced from public filings and regulatory records as cited below.
Not an audit, legal opinion, or attestation. Built from public sources only.
Table of Contents
- 1. Executive Summary & Risk Posture
- 1A. Control Maturity Scorecard
- 1B. Risk Appetite Conformance
- 2. RCPS Classification Profile
- 3. Workflow Scope Determination
- 3B. Detailed Workflow Assessment
- 4. Detailed Risk Findings — Top 9 Flags
- 5. Regulatory Obligation Map
- 6. Workflow Linkage Map
- 7. Escalations — Items Requiring Review
- 8. Next Actions — Prioritized
- 9. Peer Benchmarking Reference
- 10. RuleboardAI Engagement Options
- 11. Confidence Legend, Data Gaps & Disclaimers
- Source Appendix
Executive summary at a glance
Public-source, preliminary — figures summarize the detail below.RCPS maturity
Seven-axis control maturity
Composite maturity
2.6 / 5.0
Defined
Achievable target
3.8 / 5.0
- Governance3.1 / 5
- Risk Management2.2 / 5
- Compliance2.9 / 5
- Cybersecurity2.0 / 5
- Third-Party Risk2.7 / 5
- Privacy3.0 / 5
- Monitoring2.3 / 5
RCPS maturity is scored 1–5 across seven axes. The vertical marker on each bar is the achievable target from the sample assessment. Illustrative — scored per entity during classification.
Composite 2.6 of 5 against an achievable 3.8. Cybersecurity and risk management are the weakest axes.
Findings
Nine findings by severity
- 4
High
- 5
Medium
- 0
Low
Four high-severity and five medium-severity flags identified from public records.
Workflow scoping
48 workflowsEvery client is scored against the same 48-workflow universe across 11 categories. The engine sorts each workflow into one of three buckets — nothing applicable is missed, nothing irrelevant is run.
- 27
In scope
Applies to this client — runs this cycle.
- 9
Conditional
Applies only if a trigger is met — flagged for review.
- 12
Out of scope
Not applicable to this client — documented, not ignored.
Illustrative split — the actual scope is determined per client during RCPS classification.
RCPS classification
Type 7 National Bank / BHC (primary) · Type 4 Broker-Dealer · Type 5 RIA · Type 16 Fintech Platform (secondary)
Every score and label in this profile follows the published RCPS Methodology & Scoring Standards — including what the scores mean and what they cannot conclude.
1. Executive Summary & Risk Posture
Overall Posture
SoFi Technologies, Inc. is a publicly traded (NASDAQ: SOFI), Delaware-incorporated bank holding company and financial holding company headquartered at 234 1st Street, San Francisco, CA 94105. As of December 31, 2025, SoFi reported total assets of $50.7 billion (up 40% year-over-year), total deposits of $37.5 billion, total net revenue of $3.6 billion, and net income of $481.3 million. The company employs approximately 6,100 people across three reported segments: Lending, Financial Services, and Technology Platform. With 13.7 million members and over 20.2 million products at year-end 2025, SoFi has grown from a pre-bank fintech into a full-service nationally chartered bank holding company subject to multi-regulator oversight (OCC, Federal Reserve, CFPB, SEC, FINRA, FinCEN/BSA, FDIC, state). This profile is produced entirely from public sources; no internal documentation was reviewed (Gap Mode). Overall preliminary risk posture: Elevated, driven by rapid asset growth, multi-regulator complexity, new $50B+ asset threshold triggers, and historical enforcement actions across multiple subsidiaries.
Top Risk
The single highest-priority build item identified from public sources is BSA/AML and KYC program adequacy at scale: SoFi crossed the $10 billion asset threshold (triggering direct CFPB supervision as of January 1, 2024) and is now approaching the $50 billion OCC heightened-standards threshold. Publicly, SoFi Bank's AML/BSA program details are not disclosed in regulatory filings beyond acknowledgment of obligations. Two subsidiary enforcement actions (FINRA $1.1M CIP/ITPP fine, 2024; SEC $300K conflict-of-interest order, 2021) and an FTC consent order (2019, active until 2039) signal that compliance program maturity has historically lagged growth. Full program details cannot be confirmed from public sources — this is the most critical data gap.
Regulatory Stack
Primary federal regulators: OCC (SoFi Bank, N.A., Cottonwood Heights, UT — charter confirmed active per OCC May 2026 national bank list); Federal Reserve (bank holding company and financial holding company, BHCA §4(l)); CFPB (direct supervision commenced January 1, 2024 — assets exceeded $10B threshold); FinCEN/BSA (Bank Secrecy Act obligations for SoFi Bank and affiliates); SEC (SoFi is a public reporting company, CIK 0001818874; SoFi Wealth LLC and SoFi Capital Advisors LLC are investment advisers; SoFi Securities LLC is a broker-dealer); FINRA (SoFi Securities LLC, CRD 151717); FDIC (deposit insurer for SoFi Bank, N.A., up to $250K per depositor; expanded coverage up to $3M through reciprocal deposit program). State regulators: multiple state agencies supervise various SoFi lending and money-transmission activities; Technology Platform segment serves clients internationally (Latin America via Technisys S.A.).
Fund / BDC Overlay
SoFi is not a registered investment company or fund complex in the traditional sense. SoFi Wealth LLC operates a robo-advisory service; SoFi Capital Advisors LLC provides investment advisory services. No registered '40 Act funds or BDCs are identified from public sources. ETFs previously sponsored by SoFi (SFY, SFYX) were closed and are no longer active. SoFi Crypto launched December 2025; SoFiUSD stablecoin launched in 2025. Fund overlay: Not applicable in the traditional sense; investment adviser registration confirmed.
Key Person Risk
Anthony Noto (CEO, age 57, Director) is the sole identified key executive whose departure would be material. The 10-K cites key-person dependency risk. CFO: Chris Lapointe. CRO: Arun Pinto. General Counsel: Rob Lavet. CTO: Jeremy Rishel. Board: Tom Hutton (Independent Chair, separate from CEO — confirmed governance strength). Auditor: Deloitte & Touche LLP (since 2017). Key-person concentration on Noto is a Likely medium risk; details of succession planning are not confirmable from public sources.
1A. Control Maturity Scorecard
Scores are Likely/Conditional inferences from public disclosures only. No internal documentation reviewed. Many scores reflect a data gap rather than a confirmed deficiency.
| GRC Category | Current Maturity | Target | Evidence / Basis |
|---|---|---|---|
| 1. SOC 2 Compliance | 2 — Developing (Conditional) | 4 | No public SOC 2 Type II report identified. Cybersecurity 10-K disclosure references ISO 27002:2013 and NIST CSF; third-party penetration tests confirmed. SOC 2 status unknown from public sources. |
| 2. Financial Regulation | 3 — Defined (Likely) | 5 | Multi-regulator structure confirmed (OCC, Fed, CFPB, SEC, FINRA, FinCEN). Capital ratios comply — SoFi Bank “well capitalized” per 10-K. BSA/AML program exists (regulatory requirement) but program details not publicly disclosed. Historical enforcement: FINRA $1.1M (2024 CIP/ITPP), SEC $300K (2021 conflict), FTC consent order (2019–2039). |
| 3. International Frameworks (DORA/ISO/BCP) | 2 — Developing (Conditional) | 3 | No DORA applicability confirmed (US-primary, no EU-regulated entity identified). ISO 27002:2013 referenced in 10-K cybersecurity disclosure. BCP/ISO 22301 status not publicly disclosed. Technisys S.A. (Luxembourg) may trigger EU obligations — cannot confirm from public sources. |
| 4. Internal Governance | 3 — Defined (Likely) | 4 | Board-level governance confirmed: independent chair (Hutton), four fully independent committees (Audit, Risk, Compensation, Nominating & CG). Risk Committee oversees cybersecurity — confirmed per DEF 14A 2026. COSO/ERM framework referenced in 10-K. Internal audit team confirmed (annual IT/IS audits). Policy library details not publicly disclosed. |
| 5. Ongoing / Scheduled Monitoring | 3 — Defined (Conditional) | 4 | Regulatory change monitoring implied by multi-regulator environment. CISO provides quarterly cybersecurity updates to Risk Committee — confirmed per 10-K. Training completion details not public. Vendor renewal risk management exists (third-party security risk program confirmed). |
| 6. Privacy & Data Protection (GDPR/CCPA) | 3 — Defined (Likely) | 4 | CCPA obligations confirmed — SoFi serves California consumers. GDPR applicability limited (US-primary); Technisys/EU ops may create GDPR exposure (Conditional). Privacy policy and data practices publicly available on sofi.com. Data retention and DPIA details not publicly disclosed. |
| 7. Cybersecurity | 3 — Defined (Likely) | 4 | Frameworks confirmed: ISO 27002:2013, NIST CSF, PCI-DSS, FFIEC guidelines, CIS controls (10-K Item 1C). CISO confirmed (20+ years experience, 4 years at SoFi). Annual internal audits and periodic external pen tests confirmed. No material incidents disclosed. Zero Trust maturity not publicly assessable. |
| 8. HR & People Risk | 2 — Developing (Conditional) | 3 | Code of ethics/insider trading policy (Ex-19.1 in 10-K) confirmed — MNPI policy filed publicly. FINRA registration for SoFi Securities personnel implied. Whistleblower program: SEC Dodd-Frank channel implied for public company; internal whistleblower program details not publicly confirmed. Background check program details not public. |
| 9. Third-Party / Supply Chain Risk | 3 — Defined (Likely) | 4 | Third-Party Security Risk Management program confirmed (10-K Item 1C). Supplier onboarding due diligence confirmed. Technology Platform segment serves as B2B infrastructure provider — vendor risk is both buyer and supplier facing. Galileo concentration risk (one large client departure caused 23% drop in tech platform accounts in 2025) — confirmed public signal of concentration risk. |
| 10. ESG / Non-Financial Reporting | 2 — Developing (Conditional) | 3 | No TCFD-aligned or CSRD report identified from public sources. SEC climate disclosure rules (pending/phased implementation). ESG governance documents page on IR website returned no substantive content. SoFi's ESG posture from public disclosures: limited. SFDR N/A (no EU-distributed funds confirmed). |
| 11. Operational Risk | 3 — Defined (Likely) | 4 | ERM framework referenced in 10-K. RCSA implied by bank regulatory requirements. DR/BCP details not publicly disclosed. Rapid balance sheet growth ($50.7B total assets, +40% YoY) and crossing of multiple asset thresholds creates operational scaling risk. OCC proposed raising heightened standards threshold from $50B to $700B (Dec 2025) — may relieve some near-term burden. |
GRC Category
1. SOC 2 Compliance
Current Maturity
2 — Developing (Conditional)
Target
4
Evidence / Basis
No public SOC 2 Type II report identified. Cybersecurity 10-K disclosure references ISO 27002:2013 and NIST CSF; third-party penetration tests confirmed. SOC 2 status unknown from public sources.
GRC Category
2. Financial Regulation
Current Maturity
3 — Defined (Likely)
Target
5
Evidence / Basis
Multi-regulator structure confirmed (OCC, Fed, CFPB, SEC, FINRA, FinCEN). Capital ratios comply — SoFi Bank “well capitalized” per 10-K. BSA/AML program exists (regulatory requirement) but program details not publicly disclosed. Historical enforcement: FINRA $1.1M (2024 CIP/ITPP), SEC $300K (2021 conflict), FTC consent order (2019–2039).
GRC Category
3. International Frameworks (DORA/ISO/BCP)
Current Maturity
2 — Developing (Conditional)
Target
3
Evidence / Basis
No DORA applicability confirmed (US-primary, no EU-regulated entity identified). ISO 27002:2013 referenced in 10-K cybersecurity disclosure. BCP/ISO 22301 status not publicly disclosed. Technisys S.A. (Luxembourg) may trigger EU obligations — cannot confirm from public sources.
GRC Category
4. Internal Governance
Current Maturity
3 — Defined (Likely)
Target
4
Evidence / Basis
Board-level governance confirmed: independent chair (Hutton), four fully independent committees (Audit, Risk, Compensation, Nominating & CG). Risk Committee oversees cybersecurity — confirmed per DEF 14A 2026. COSO/ERM framework referenced in 10-K. Internal audit team confirmed (annual IT/IS audits). Policy library details not publicly disclosed.
GRC Category
5. Ongoing / Scheduled Monitoring
Current Maturity
3 — Defined (Conditional)
Target
4
Evidence / Basis
Regulatory change monitoring implied by multi-regulator environment. CISO provides quarterly cybersecurity updates to Risk Committee — confirmed per 10-K. Training completion details not public. Vendor renewal risk management exists (third-party security risk program confirmed).
GRC Category
6. Privacy & Data Protection (GDPR/CCPA)
Current Maturity
3 — Defined (Likely)
Target
4
Evidence / Basis
CCPA obligations confirmed — SoFi serves California consumers. GDPR applicability limited (US-primary); Technisys/EU ops may create GDPR exposure (Conditional). Privacy policy and data practices publicly available on sofi.com. Data retention and DPIA details not publicly disclosed.
GRC Category
7. Cybersecurity
Current Maturity
3 — Defined (Likely)
Target
4
Evidence / Basis
Frameworks confirmed: ISO 27002:2013, NIST CSF, PCI-DSS, FFIEC guidelines, CIS controls (10-K Item 1C). CISO confirmed (20+ years experience, 4 years at SoFi). Annual internal audits and periodic external pen tests confirmed. No material incidents disclosed. Zero Trust maturity not publicly assessable.
GRC Category
8. HR & People Risk
Current Maturity
2 — Developing (Conditional)
Target
3
Evidence / Basis
Code of ethics/insider trading policy (Ex-19.1 in 10-K) confirmed — MNPI policy filed publicly. FINRA registration for SoFi Securities personnel implied. Whistleblower program: SEC Dodd-Frank channel implied for public company; internal whistleblower program details not publicly confirmed. Background check program details not public.
GRC Category
9. Third-Party / Supply Chain Risk
Current Maturity
3 — Defined (Likely)
Target
4
Evidence / Basis
Third-Party Security Risk Management program confirmed (10-K Item 1C). Supplier onboarding due diligence confirmed. Technology Platform segment serves as B2B infrastructure provider — vendor risk is both buyer and supplier facing. Galileo concentration risk (one large client departure caused 23% drop in tech platform accounts in 2025) — confirmed public signal of concentration risk.
GRC Category
10. ESG / Non-Financial Reporting
Current Maturity
2 — Developing (Conditional)
Target
3
Evidence / Basis
No TCFD-aligned or CSRD report identified from public sources. SEC climate disclosure rules (pending/phased implementation). ESG governance documents page on IR website returned no substantive content. SoFi's ESG posture from public disclosures: limited. SFDR N/A (no EU-distributed funds confirmed).
GRC Category
11. Operational Risk
Current Maturity
3 — Defined (Likely)
Target
4
Evidence / Basis
ERM framework referenced in 10-K. RCSA implied by bank regulatory requirements. DR/BCP details not publicly disclosed. Rapid balance sheet growth ($50.7B total assets, +40% YoY) and crossing of multiple asset thresholds creates operational scaling risk. OCC proposed raising heightened standards threshold from $50B to $700B (Dec 2025) — may relieve some near-term burden.
Composite: 2.6 — Developing/Defined → Target 3.8
Dominant uplift priorities: BSA/AML program documentation; SOC 2 attestation; ESG/climate disclosure; BCP/DR testing evidence; whistleblower and HR program detail.
1B. Risk Appetite Conformance
External benchmarks: OCC Heightened Standards (12 CFR Part 30), CFPB Supervision and Examination Manual, FFIEC BSA/AML Examination Manual, SEC Regulation Best Interest / fiduciary standard (SoFi Wealth), NIST CSF 2.0. Verdicts are Conditional inferences from public evidence only.
| Domain | Inherent Risk | Within Tolerance? | Basis |
|---|---|---|---|
| BSA/AML / KYC | High | Unknown | FINRA $1.1M CIP/ITPP fine (2024, conduct 2018–2019). Bank-level BSA program mandated; program quality not verifiable from public sources. |
| Capital Adequacy | Medium | Within Tolerance | SoFi Bank confirmed “well capitalized” per all OCC metrics (10-K 2025). CET1, Tier 1, Total Capital ratios met. $10B+ triggers active. |
| Consumer Protection / UDAAP | High | Unknown | CFPB direct supervision commenced Jan 1, 2024. FTC consent order (active to 2039) on savings-claim advertising. No CFPB enforcement action found; status of examination findings not public. |
| Cybersecurity / Data | Medium | Conditional | NIST CSF and ISO 27002 referenced; no material incidents. Zero Trust, SIEM, EDR maturity not publicly confirmable. |
| Fiduciary / Conflicts of Interest | Medium | No (Historical) | SEC $300K order (2021) against SoFi Wealth LLC for undisclosed proprietary ETF conflicts. Remediated per SEC order — ongoing monitoring status unknown. |
| Operational Resilience | Medium | Unknown | BCP/DR not publicly tested/disclosed. Rapid growth ($50.7B assets) increases operational complexity. |
| Model / Credit Risk | High | Conditional | Lending segment $36.4B originations (FY2025). Credit model details proprietary. 10-K cites model risk as a key risk factor. Held-for-investment loan book growing. |
| ESG Disclosure | Low | No | No TCFD or comparable public climate disclosure identified. SEC climate rules may require disclosure in future filings. |
Domain
BSA/AML / KYC
Inherent Risk
High
Within Tolerance?
Unknown
Basis
FINRA $1.1M CIP/ITPP fine (2024, conduct 2018–2019). Bank-level BSA program mandated; program quality not verifiable from public sources.
Domain
Capital Adequacy
Inherent Risk
Medium
Within Tolerance?
Within Tolerance
Basis
SoFi Bank confirmed “well capitalized” per all OCC metrics (10-K 2025). CET1, Tier 1, Total Capital ratios met. $10B+ triggers active.
Domain
Consumer Protection / UDAAP
Inherent Risk
High
Within Tolerance?
Unknown
Basis
CFPB direct supervision commenced Jan 1, 2024. FTC consent order (active to 2039) on savings-claim advertising. No CFPB enforcement action found; status of examination findings not public.
Domain
Cybersecurity / Data
Inherent Risk
Medium
Within Tolerance?
Conditional
Basis
NIST CSF and ISO 27002 referenced; no material incidents. Zero Trust, SIEM, EDR maturity not publicly confirmable.
Domain
Fiduciary / Conflicts of Interest
Inherent Risk
Medium
Within Tolerance?
No (Historical)
Basis
SEC $300K order (2021) against SoFi Wealth LLC for undisclosed proprietary ETF conflicts. Remediated per SEC order — ongoing monitoring status unknown.
Domain
Operational Resilience
Inherent Risk
Medium
Within Tolerance?
Unknown
Basis
BCP/DR not publicly tested/disclosed. Rapid growth ($50.7B assets) increases operational complexity.
Domain
Model / Credit Risk
Inherent Risk
High
Within Tolerance?
Conditional
Basis
Lending segment $36.4B originations (FY2025). Credit model details proprietary. 10-K cites model risk as a key risk factor. Held-for-investment loan book growing.
Domain
ESG Disclosure
Inherent Risk
Low
Within Tolerance?
No
Basis
No TCFD or comparable public climate disclosure identified. SEC climate rules may require disclosure in future filings.
Read-out: Three domains are Unknown (BSA/AML, Consumer Protection, Operational Resilience) and one is a confirmed historical Non-Conformance (fiduciary/conflicts). Capital adequacy is Within Tolerance. Full conformance assessment requires client engagement and internal documentation review.
2. RCPS Classification Profile
Institution types assigned: Type 7 — National Bank / Bank Holding Company (PRIMARY) + Type 4 — Broker-Dealer (SECONDARY, SoFi Securities LLC) + Type 5 — Investment Adviser (SECONDARY, SoFi Wealth LLC / SoFi Capital Advisors LLC) + Type 16 — Fintech / Payments Platform (SECONDARY, Technology Platform segment: Galileo + Technisys)
7-Axis RCPS Classification
| RCPS Axis | Code | Classification | Basis / Note |
|---|---|---|---|
| 1 — Listing Status | PUB | Publicly listed | NASDAQ: SOFI; CIK 0001818874; SEC reporting company (Exchange Act) |
| 1A — Fund Overlay | NONE | No registered fund overlay | No active '40 Act funds; SoFi ETFs (SFY, SFYX) closed; robo-advisory via SoFi Wealth LLC does not constitute a fund complex |
| 2 — Company Size | S5 | Large Enterprise | Total assets $50.7B (Dec 31, 2025); Total net revenue $3.6B (FY2025); ~6,100 employees |
| 3 — Industry | I-FINTECH / I-BANK | Fintech + National Bank | Nationally chartered bank (SoFi Bank, N.A.); bank holding company; financial holding company; technology platform (Galileo, Technisys) serving third-party financial institutions |
| 4 — Geography | US-ONLY (primary) / US-LATAM (secondary) | US-primary with LatAm tech exposure | SoFi Bank operations: US only. Technology Platform (Technisys): serves financial institutions in North America and Latin America. No EU-regulated entity confirmed. |
| 5 — Data Intensity | D4 | Maximum data intensity | Consumer financial data (13.7M members); deposit, lending, investment, and payment data; technology platform processes 128.5M accounts; crypto operations launched Dec 2025 |
| 6 — Ownership | PUB-PARENT | Public corporate parent | SoFi Technologies, Inc. is the publicly traded parent; SoFi Bank, N.A. is a wholly owned subsidiary; no PE or private ownership layer |
| 7 — Growth Stage | G4 | Scale-up / Rapid Growth | 35% YoY member growth; 40% YoY total asset growth; first $1B+ EBITDA year (2025); still investing in growth (guidance for 2026 implies continued acceleration) |
RCPS Axis
1 — Listing Status
Code
PUB
Classification
Publicly listed
Basis / Note
NASDAQ: SOFI; CIK 0001818874; SEC reporting company (Exchange Act)
RCPS Axis
1A — Fund Overlay
Code
NONE
Classification
No registered fund overlay
Basis / Note
No active '40 Act funds; SoFi ETFs (SFY, SFYX) closed; robo-advisory via SoFi Wealth LLC does not constitute a fund complex
RCPS Axis
2 — Company Size
Code
S5
Classification
Large Enterprise
Basis / Note
Total assets $50.7B (Dec 31, 2025); Total net revenue $3.6B (FY2025); ~6,100 employees
RCPS Axis
3 — Industry
Code
I-FINTECH / I-BANK
Classification
Fintech + National Bank
Basis / Note
Nationally chartered bank (SoFi Bank, N.A.); bank holding company; financial holding company; technology platform (Galileo, Technisys) serving third-party financial institutions
RCPS Axis
4 — Geography
Code
US-ONLY (primary) / US-LATAM (secondary)
Classification
US-primary with LatAm tech exposure
Basis / Note
SoFi Bank operations: US only. Technology Platform (Technisys): serves financial institutions in North America and Latin America. No EU-regulated entity confirmed.
RCPS Axis
5 — Data Intensity
Code
D4
Classification
Maximum data intensity
Basis / Note
Consumer financial data (13.7M members); deposit, lending, investment, and payment data; technology platform processes 128.5M accounts; crypto operations launched Dec 2025
RCPS Axis
6 — Ownership
Code
PUB-PARENT
Classification
Public corporate parent
Basis / Note
SoFi Technologies, Inc. is the publicly traded parent; SoFi Bank, N.A. is a wholly owned subsidiary; no PE or private ownership layer
RCPS Axis
7 — Growth Stage
Code
G4
Classification
Scale-up / Rapid Growth
Basis / Note
35% YoY member growth; 40% YoY total asset growth; first $1B+ EBITDA year (2025); still investing in growth (guidance for 2026 implies continued acceleration)
Entity Profile — Key Attributes
| Attribute | Value |
|---|---|
| Legal Name | SoFi Technologies, Inc. |
| HQ | 234 1st Street, San Francisco, CA 94105 |
| Founded | 2011 (as Social Finance, Inc.); became public 2021 via SPAC merger |
| CIK (SEC) | 0001818874 |
| NASDAQ Ticker | SOFI |
| Shares Outstanding (Jan 30, 2026) | 1,275,263,850 shares (common stock, $0.0001 par) |
| Market Cap (June 30, 2025, non-affiliates) | ~$20.0 billion (per 10-K cover) |
| Bank Charter | SoFi Bank, National Association — OCC-chartered national bank; approved January 18, 2022; HQ: 2750 East Cottonwood Parkway, Cottonwood Heights, UT (per OCC national bank list, May 2026) |
| Bank Holding Company | Yes — regulated by Federal Reserve under BHCA; Financial Holding Company (FHC) elected under §4(l) BHCA |
| CFPB Supervision | Direct CFPB supervision commenced January 1, 2024 (>$10B asset threshold triggered) |
| Total Assets | $50.7 billion (Dec 31, 2025) |
| Total Deposits | $37.5 billion (Dec 31, 2025) |
| Total Net Revenue (FY2025) | $3.6 billion (+35% YoY) |
| Net Income (FY2025) | $481.3 million |
| Members | 13.7 million (Dec 31, 2025, +35% YoY) |
| Products | 20.2 million (Dec 31, 2025, +37% YoY) |
| Tech Platform Accounts | 128.5 million (Dec 31, 2025) |
| Employees | ~6,100 (Dec 31, 2025; ~82% US, ~18% international) |
| Three Business Segments | Lending ($1.8B revenue); Financial Services ($1.54B revenue, +88% YoY); Technology Platform ($450M revenue) |
| CEO | Anthony Noto (age 57) |
| CFO | Chris Lapointe |
| CRO | Arun Pinto |
| General Counsel | Rob Lavet |
| CTO | Jeremy Rishel |
| Board Chair | Tom Hutton (Independent) |
| Auditor | Deloitte & Touche LLP (since 2017) |
| Key Subsidiaries | SoFi Bank, N.A.; SoFi Securities LLC (CRD 151717); SoFi Wealth LLC; SoFi Capital Advisors LLC; Galileo Financial Technologies; Technisys S.A. (Luxembourg); SoFi Digital Assets LLC; Wyndham Capital Mortgage |
| RuleboardAI Classification | Type 7 National Bank/BHC (Primary) + Type 4 Broker-Dealer + Type 5 RIA + Type 16 Fintech Platform (Secondary) |
Attribute
Legal Name
Value
SoFi Technologies, Inc.
Attribute
HQ
Value
234 1st Street, San Francisco, CA 94105
Attribute
Founded
Value
2011 (as Social Finance, Inc.); became public 2021 via SPAC merger
Attribute
CIK (SEC)
Value
0001818874
Attribute
NASDAQ Ticker
Value
SOFI
Attribute
Shares Outstanding (Jan 30, 2026)
Value
1,275,263,850 shares (common stock, $0.0001 par)
Attribute
Market Cap (June 30, 2025, non-affiliates)
Value
~$20.0 billion (per 10-K cover)
Attribute
Bank Charter
Value
SoFi Bank, National Association — OCC-chartered national bank; approved January 18, 2022; HQ: 2750 East Cottonwood Parkway, Cottonwood Heights, UT (per OCC national bank list, May 2026)
Attribute
Bank Holding Company
Value
Yes — regulated by Federal Reserve under BHCA; Financial Holding Company (FHC) elected under §4(l) BHCA
Attribute
CFPB Supervision
Value
Direct CFPB supervision commenced January 1, 2024 (>$10B asset threshold triggered)
Attribute
Total Assets
Value
$50.7 billion (Dec 31, 2025)
Attribute
Total Deposits
Value
$37.5 billion (Dec 31, 2025)
Attribute
Total Net Revenue (FY2025)
Value
$3.6 billion (+35% YoY)
Attribute
Net Income (FY2025)
Value
$481.3 million
Attribute
Members
Value
13.7 million (Dec 31, 2025, +35% YoY)
Attribute
Products
Value
20.2 million (Dec 31, 2025, +37% YoY)
Attribute
Tech Platform Accounts
Value
128.5 million (Dec 31, 2025)
Attribute
Employees
Value
~6,100 (Dec 31, 2025; ~82% US, ~18% international)
Attribute
Three Business Segments
Value
Lending ($1.8B revenue); Financial Services ($1.54B revenue, +88% YoY); Technology Platform ($450M revenue)
Attribute
CEO
Value
Anthony Noto (age 57)
Attribute
CFO
Value
Chris Lapointe
Attribute
CRO
Value
Arun Pinto
Attribute
General Counsel
Value
Rob Lavet
Attribute
CTO
Value
Jeremy Rishel
Attribute
Board Chair
Value
Tom Hutton (Independent)
Attribute
Auditor
Value
Deloitte & Touche LLP (since 2017)
Attribute
Key Subsidiaries
Value
SoFi Bank, N.A.; SoFi Securities LLC (CRD 151717); SoFi Wealth LLC; SoFi Capital Advisors LLC; Galileo Financial Technologies; Technisys S.A. (Luxembourg); SoFi Digital Assets LLC; Wyndham Capital Mortgage
Attribute
RuleboardAI Classification
Value
Type 7 National Bank/BHC (Primary) + Type 4 Broker-Dealer + Type 5 RIA + Type 16 Fintech Platform (Secondary)
3. Workflow Scope Determination
All 48 workflows evaluated. Engine operates within the 19 U.S. institution types. Status: In Scope (confirmed applicable), Conditional (depends on trigger/confirmation), Suppressed (not applicable, with rationale).
Category 1 — SOC 2 Compliance
| # | Workflow | Status | Trigger / Rationale |
|---|---|---|---|
| 1.1 | Control Inventory Audit | Conditional | SoFi Bank subject to OCC/FFIEC IT controls; SOC 2 formal audit status unknown; likely relevant for Galileo/Technisys B2B platform customers |
| 1.2 | Evidence Collection Checklist | Conditional | Applicable if SOC 2 audit pursued; Galileo/Technisys likely have customer contractual requirements for SOC 2 evidence |
| 1.3 | Gap Analysis Report | In Scope | Referenced frameworks (NIST CSF, ISO 27002, FFIEC) confirm gap analysis applicability; SOC 2 gap likely material |
| 1.4 | Vendor Risk Assessment | In Scope | Third-Party Security Risk Management program confirmed in 10-K; vendor risk assessment formally in scope |
| 1.5 | Penetration Test Review Memo | In Scope | External pen tests confirmed per 10-K cybersecurity disclosure; review memo workflow in scope |
#
1.1
Workflow
Control Inventory Audit
Status
Conditional
Trigger / Rationale
SoFi Bank subject to OCC/FFIEC IT controls; SOC 2 formal audit status unknown; likely relevant for Galileo/Technisys B2B platform customers
#
1.2
Workflow
Evidence Collection Checklist
Status
Conditional
Trigger / Rationale
Applicable if SOC 2 audit pursued; Galileo/Technisys likely have customer contractual requirements for SOC 2 evidence
#
1.3
Workflow
Gap Analysis Report
Status
In Scope
Trigger / Rationale
Referenced frameworks (NIST CSF, ISO 27002, FFIEC) confirm gap analysis applicability; SOC 2 gap likely material
#
1.4
Workflow
Vendor Risk Assessment
Status
In Scope
Trigger / Rationale
Third-Party Security Risk Management program confirmed in 10-K; vendor risk assessment formally in scope
#
1.5
Workflow
Penetration Test Review Memo
Status
In Scope
Trigger / Rationale
External pen tests confirmed per 10-K cybersecurity disclosure; review memo workflow in scope
Category 2 — Financial Regulation
| # | Workflow | Status | Trigger / Rationale |
|---|---|---|---|
| 2.1 | Capital Adequacy Report | In Scope | OCC and Federal Reserve capital requirements confirmed; SoFi Bank “well capitalized” — ongoing reporting obligation |
| 2.2 | AML Transaction Monitoring | In Scope | BSA/AML obligations confirmed for SoFi Bank N.A. and affiliates; FinCEN IA AML Rule (eff. Jan 1, 2028) will apply to investment adviser affiliates |
| 2.3 | SAR Draft | In Scope | SoFi Bank SAR filing obligations under BSA confirmed; prior FINRA CIP/ITPP fine heightens materiality |
| 2.4 | SEC Filing Readiness Check | In Scope | SoFi is a public reporting company (10-K, 10-Q, 8-K, proxy); SoFi Wealth/Capital Advisors file Form ADV; in scope |
| 2.5 | KYC Onboarding Audit | In Scope | FINRA $1.1M CIP/ITPP fine (May 2024) for 2018–2019 conduct confirms this is a demonstrated gap area; high priority |
#
2.1
Workflow
Capital Adequacy Report
Status
In Scope
Trigger / Rationale
OCC and Federal Reserve capital requirements confirmed; SoFi Bank “well capitalized” — ongoing reporting obligation
#
2.2
Workflow
AML Transaction Monitoring
Status
In Scope
Trigger / Rationale
BSA/AML obligations confirmed for SoFi Bank N.A. and affiliates; FinCEN IA AML Rule (eff. Jan 1, 2028) will apply to investment adviser affiliates
#
2.3
Workflow
SAR Draft
Status
In Scope
Trigger / Rationale
SoFi Bank SAR filing obligations under BSA confirmed; prior FINRA CIP/ITPP fine heightens materiality
#
2.4
Workflow
SEC Filing Readiness Check
Status
In Scope
Trigger / Rationale
SoFi is a public reporting company (10-K, 10-Q, 8-K, proxy); SoFi Wealth/Capital Advisors file Form ADV; in scope
#
2.5
Workflow
KYC Onboarding Audit
Status
In Scope
Trigger / Rationale
FINRA $1.1M CIP/ITPP fine (May 2024) for 2018–2019 conduct confirms this is a demonstrated gap area; high priority
Category 3 — International Frameworks (DORA / ISO 27001 / BCP)
| # | Workflow | Status | Trigger / Rationale |
|---|---|---|---|
| 3.1 | DORA ICT Risk Assessment | Conditional | SoFi is US-primary; Technisys S.A. (Luxembourg) may trigger EU DORA obligations as ICT provider to EU-regulated entities — cannot confirm from public sources |
| 3.2 | ISO 27001 Gap Report | In Scope | ISO 27002:2013 referenced in 10-K; formal ISO 27001 certification status unknown; gap report recommended |
| 3.3 | BCP Review | In Scope | OCC and FFIEC BCP requirements apply to SoFi Bank; BCP documentation status not publicly disclosed |
| 3.4 | IR Playbook Audit | In Scope | SEC cyber incident disclosure rules (Reg S-K Item 106) apply; GDPR Art. 33 not confirmed applicable; playbook audit in scope |
| 3.5 | Data Residency Check | Conditional | US-primary; Technisys Latin America operations may implicate data residency requirements in specific jurisdictions — cannot confirm from public sources |
#
3.1
Workflow
DORA ICT Risk Assessment
Status
Conditional
Trigger / Rationale
SoFi is US-primary; Technisys S.A. (Luxembourg) may trigger EU DORA obligations as ICT provider to EU-regulated entities — cannot confirm from public sources
#
3.2
Workflow
ISO 27001 Gap Report
Status
In Scope
Trigger / Rationale
ISO 27002:2013 referenced in 10-K; formal ISO 27001 certification status unknown; gap report recommended
#
3.3
Workflow
BCP Review
Status
In Scope
Trigger / Rationale
OCC and FFIEC BCP requirements apply to SoFi Bank; BCP documentation status not publicly disclosed
#
3.4
Workflow
IR Playbook Audit
Status
In Scope
Trigger / Rationale
SEC cyber incident disclosure rules (Reg S-K Item 106) apply; GDPR Art. 33 not confirmed applicable; playbook audit in scope
#
3.5
Workflow
Data Residency Check
Status
Conditional
Trigger / Rationale
US-primary; Technisys Latin America operations may implicate data residency requirements in specific jurisdictions — cannot confirm from public sources
Category 4 — Internal Governance
| # | Workflow | Status | Trigger / Rationale |
|---|---|---|---|
| 4.1 | Policy Library Review | In Scope | Bank holding company compliance program required; MNPI/insider trading policy confirmed (Ex-19.1); full policy library details not public |
| 4.2 | Board Risk Report | In Scope | Risk Committee confirmed (min. 3 board members, meets quarterly); board receives quarterly cybersecurity updates from CISO |
| 4.3 | Control Testing Schedule | In Scope | OCC/Fed supervision requires annual control testing; internal audit team confirmed |
| 4.4 | Remediation Tracker | In Scope | Three resolved enforcement actions (FTC 2019, SEC 2021, FINRA 2024) confirm need for ongoing remediation tracking |
| 4.5 | Audit Committee Prep Pack | In Scope | Audit Committee confirmed (chaired by Gary Meltzer); Deloitte as auditor; PCAOB-registered audit; in scope |
#
4.1
Workflow
Policy Library Review
Status
In Scope
Trigger / Rationale
Bank holding company compliance program required; MNPI/insider trading policy confirmed (Ex-19.1); full policy library details not public
#
4.2
Workflow
Board Risk Report
Status
In Scope
Trigger / Rationale
Risk Committee confirmed (min. 3 board members, meets quarterly); board receives quarterly cybersecurity updates from CISO
#
4.3
Workflow
Control Testing Schedule
Status
In Scope
Trigger / Rationale
OCC/Fed supervision requires annual control testing; internal audit team confirmed
#
4.4
Workflow
Remediation Tracker
Status
In Scope
Trigger / Rationale
Three resolved enforcement actions (FTC 2019, SEC 2021, FINRA 2024) confirm need for ongoing remediation tracking
#
4.5
Workflow
Audit Committee Prep Pack
Status
In Scope
Trigger / Rationale
Audit Committee confirmed (chaired by Gary Meltzer); Deloitte as auditor; PCAOB-registered audit; in scope
Category 5 — Ongoing / Scheduled Monitoring
| # | Workflow | Status | Trigger / Rationale |
|---|---|---|---|
| 5.1 | Regulatory Change Monitor | In Scope | OCC proposed $50B→$700B heightened standards threshold change (Dec 2025); CFPB supervision active; FinCEN IA AML Rule (2028); crypto regulation evolving; active horizon scanning required |
| 5.2 | Vendor Renewal Risk Flag | In Scope | Third-party security program confirmed; Galileo client concentration loss (2025) underscores vendor/client concentration monitoring need |
| 5.3 | Training Compliance Tracker | In Scope | AML training, cybersecurity awareness training (including phishing) confirmed; completion tracking details not public |
| 5.4 | Access Review Report | In Scope | ISO 27002 and FFIEC requirements apply; access review details not publicly disclosed |
#
5.1
Workflow
Regulatory Change Monitor
Status
In Scope
Trigger / Rationale
OCC proposed $50B→$700B heightened standards threshold change (Dec 2025); CFPB supervision active; FinCEN IA AML Rule (2028); crypto regulation evolving; active horizon scanning required
#
5.2
Workflow
Vendor Renewal Risk Flag
Status
In Scope
Trigger / Rationale
Third-party security program confirmed; Galileo client concentration loss (2025) underscores vendor/client concentration monitoring need
#
5.3
Workflow
Training Compliance Tracker
Status
In Scope
Trigger / Rationale
AML training, cybersecurity awareness training (including phishing) confirmed; completion tracking details not public
#
5.4
Workflow
Access Review Report
Status
In Scope
Trigger / Rationale
ISO 27002 and FFIEC requirements apply; access review details not publicly disclosed
Category 6 — Privacy & Data Protection
| # | Workflow | Status | Trigger / Rationale |
|---|---|---|---|
| 6.1 | GDPR Compliance Audit | Conditional | US-primary; Technisys Luxembourg/EU nexus may create GDPR exposure — cannot confirm from public sources |
| 6.2 | CCPA DSR Tracker | In Scope | SoFi serves California consumers at scale (13.7M+ members); CCPA/CPRA obligations confirmed |
| 6.3 | Data Retention Policy Review | In Scope | SEC recordkeeping rules apply (SoFi Securities, SoFi Wealth); BSA recordkeeping applies to SoFi Bank; CCPA minimization applies |
| 6.4 | Privacy Impact Assessment | Conditional | SoFi Crypto (launched Dec 2025) and SoFiUSD stablecoin involve new high-risk data processing — DPIA/PIA may be required |
#
6.1
Workflow
GDPR Compliance Audit
Status
Conditional
Trigger / Rationale
US-primary; Technisys Luxembourg/EU nexus may create GDPR exposure — cannot confirm from public sources
#
6.2
Workflow
CCPA DSR Tracker
Status
In Scope
Trigger / Rationale
SoFi serves California consumers at scale (13.7M+ members); CCPA/CPRA obligations confirmed
#
6.3
Workflow
Data Retention Policy Review
Status
In Scope
Trigger / Rationale
SEC recordkeeping rules apply (SoFi Securities, SoFi Wealth); BSA recordkeeping applies to SoFi Bank; CCPA minimization applies
#
6.4
Workflow
Privacy Impact Assessment
Status
Conditional
Trigger / Rationale
SoFi Crypto (launched Dec 2025) and SoFiUSD stablecoin involve new high-risk data processing — DPIA/PIA may be required
Category 7 — Cybersecurity
| # | Workflow | Status | Trigger / Rationale |
|---|---|---|---|
| 7.1 | Vulnerability Management Review | In Scope | ISO 27002 and NIST CSF confirmed in 10-K; FFIEC IT exam applies; scan cadence details not public |
| 7.2 | Security Awareness Training | In Scope | Phishing training campaigns confirmed in 10-K |
| 7.3 | Endpoint Security Audit | In Scope | FFIEC and NIST CSF scope confirmed; EDR coverage details not public |
| 7.4 | Zero Trust Architecture Gap | Conditional | NIST 800-207 not explicitly cited; zero trust posture at SoFi Bank not publicly assessable |
#
7.1
Workflow
Vulnerability Management Review
Status
In Scope
Trigger / Rationale
ISO 27002 and NIST CSF confirmed in 10-K; FFIEC IT exam applies; scan cadence details not public
#
7.2
Workflow
Security Awareness Training
Status
In Scope
Trigger / Rationale
Phishing training campaigns confirmed in 10-K
#
7.3
Workflow
Endpoint Security Audit
Status
In Scope
Trigger / Rationale
FFIEC and NIST CSF scope confirmed; EDR coverage details not public
#
7.4
Workflow
Zero Trust Architecture Gap
Status
Conditional
Trigger / Rationale
NIST 800-207 not explicitly cited; zero trust posture at SoFi Bank not publicly assessable
Category 8 — HR & People Risk
| # | Workflow | Status | Trigger / Rationale |
|---|---|---|---|
| 8.1 | Background Check Compliance | In Scope | FINRA registration requirements for SoFi Securities personnel; OCC fitness-and-propriety standards for SoFi Bank officers |
| 8.2 | Insider Threat Policy Review | In Scope | MNPI / insider trading policy publicly filed (Ex-19.1 in 10-K); SEC Rule 204A-1 code of ethics (SoFi Wealth) |
| 8.3 | Offboarding Access Revocation | In Scope | Standard requirement for bank-regulated entity; details not public |
| 8.4 | Whistleblower Program Assessment | In Scope | SEC Dodd-Frank whistleblower obligations apply to public company; SoFi Bank — OCC whistleblower requirements apply; internal program details not public |
#
8.1
Workflow
Background Check Compliance
Status
In Scope
Trigger / Rationale
FINRA registration requirements for SoFi Securities personnel; OCC fitness-and-propriety standards for SoFi Bank officers
#
8.2
Workflow
Insider Threat Policy Review
Status
In Scope
Trigger / Rationale
MNPI / insider trading policy publicly filed (Ex-19.1 in 10-K); SEC Rule 204A-1 code of ethics (SoFi Wealth)
#
8.3
Workflow
Offboarding Access Revocation
Status
In Scope
Trigger / Rationale
Standard requirement for bank-regulated entity; details not public
#
8.4
Workflow
Whistleblower Program Assessment
Status
In Scope
Trigger / Rationale
SEC Dodd-Frank whistleblower obligations apply to public company; SoFi Bank — OCC whistleblower requirements apply; internal program details not public
Category 9 — Third-Party / Supply Chain Risk
| # | Workflow | Status | Trigger / Rationale |
|---|---|---|---|
| 9.1 | Vendor Onboarding Due Diligence | In Scope | Third-Party Security Risk Management program confirmed; risk-based DD during supplier onboarding confirmed |
| 9.2 | Ongoing Vendor Monitoring | In Scope | Ongoing monitoring confirmed in 10-K cybersecurity disclosure |
| 9.3 | Concentration Risk Assessment | In Scope | Galileo large-client departure (FY2025) caused 23% drop in technology platform accounts — confirmed from public earnings disclosures; concentration risk is a demonstrated finding |
| 9.4 | Vendor Exit & Termination Plan | In Scope | Galileo client exit demonstrates real-world need; exit plan details not public |
#
9.1
Workflow
Vendor Onboarding Due Diligence
Status
In Scope
Trigger / Rationale
Third-Party Security Risk Management program confirmed; risk-based DD during supplier onboarding confirmed
#
9.2
Workflow
Ongoing Vendor Monitoring
Status
In Scope
Trigger / Rationale
Ongoing monitoring confirmed in 10-K cybersecurity disclosure
#
9.3
Workflow
Concentration Risk Assessment
Status
In Scope
Trigger / Rationale
Galileo large-client departure (FY2025) caused 23% drop in technology platform accounts — confirmed from public earnings disclosures; concentration risk is a demonstrated finding
#
9.4
Workflow
Vendor Exit & Termination Plan
Status
In Scope
Trigger / Rationale
Galileo client exit demonstrates real-world need; exit plan details not public
Category 10 — ESG / Non-Financial Reporting
| # | Workflow | Status | Trigger / Rationale |
|---|---|---|---|
| 10.1 | ESG Program Readiness | Conditional | No public ESG report or substantive ESG governance document identified; program maturity unknown |
| 10.2 | Climate / TCFD Disclosure | Conditional | No TCFD-aligned disclosure identified from public sources; SEC climate rules (phased) may require disclosure |
| 10.3 | SFDR Classification Review | Suppressed | No EU-distributed investment products confirmed; SFDR not applicable |
| 10.4 | CSRD / ESRS Reporting Assessment | Suppressed | US-primary entity; no EU subsidiary triggering CSRD confirmed |
#
10.1
Workflow
ESG Program Readiness
Status
Conditional
Trigger / Rationale
No public ESG report or substantive ESG governance document identified; program maturity unknown
#
10.2
Workflow
Climate / TCFD Disclosure
Status
Conditional
Trigger / Rationale
No TCFD-aligned disclosure identified from public sources; SEC climate rules (phased) may require disclosure
#
10.3
Workflow
SFDR Classification Review
Status
Suppressed
Trigger / Rationale
No EU-distributed investment products confirmed; SFDR not applicable
#
10.4
Workflow
CSRD / ESRS Reporting Assessment
Status
Suppressed
Trigger / Rationale
US-primary entity; no EU subsidiary triggering CSRD confirmed
Category 11 — Operational Risk
| # | Workflow | Status | Trigger / Rationale |
|---|---|---|---|
| 11.1 | Operational Risk Register Review | In Scope | OCC/Fed ERM requirements apply; RCSA implied; details not publicly disclosed |
| 11.2 | DR Gap Report | In Scope | FFIEC BCP requirements apply to SoFi Bank; DR documentation details not public |
| 11.3 | BCP Test & Exercise Review | In Scope | OCC heightened-standards implications (assets $50.7B approaching or at threshold); BCP exercise results not public |
| 11.4 | Process Resilience & Outsourcing Review | In Scope | SoFi Bank relies on Galileo for technology infrastructure; Technology Platform = outsourced service provider to third parties; dual exposure confirmed |
#
11.1
Workflow
Operational Risk Register Review
Status
In Scope
Trigger / Rationale
OCC/Fed ERM requirements apply; RCSA implied; details not publicly disclosed
#
11.2
Workflow
DR Gap Report
Status
In Scope
Trigger / Rationale
FFIEC BCP requirements apply to SoFi Bank; DR documentation details not public
#
11.3
Workflow
BCP Test & Exercise Review
Status
In Scope
Trigger / Rationale
OCC heightened-standards implications (assets $50.7B approaching or at threshold); BCP exercise results not public
#
11.4
Workflow
Process Resilience & Outsourcing Review
Status
In Scope
Trigger / Rationale
SoFi Bank relies on Galileo for technology infrastructure; Technology Platform = outsourced service provider to third parties; dual exposure confirmed
3B. Detailed Workflow Assessment — Selected In-Scope / Conditional Workflows
2.5 | KYC Onboarding Audit In Scope
Objective: Verify that SoFi's customer identification program (CIP) and identity theft prevention program (ITPP) meet FinCEN CDD Rule and BSA requirements across all regulated subsidiaries.
Frameworks: FinCEN CDD Rule; BSA; FINRA Rule 4370 (CIP); FATF Guidance.
Observation: FINRA fined SoFi Securities LLC $1.1 million (May 2024, AWC No. 2019062705801) for failing to establish and maintain reasonable CIP and ITPP programs for SoFi Money accounts (conduct period: December 2018 – April 2019). Approximately 800 fraudulent accounts were opened; ~$8.6M was transferred from customers of other institutions; ~$2.5M was withdrawn. The largely automated account-opening process failed to flag invalid SSNs, addresses, and high-risk emails. SoFi self-reported and remediated in April 2019. Post-remediation program quality cannot be confirmed from public sources.
Next Action: Obtain current CIP/ITPP policy documentation and evidence of post-2019 program enhancements; validate current fraud-alert SLA metrics against BSA exam standards.
2.2 | AML Transaction Monitoring In Scope
Objective: Confirm existence and adequacy of BSA/AML transaction monitoring program at SoFi Bank, N.A.
Frameworks: Bank Secrecy Act; FinCEN Regulations; FFIEC BSA/AML Examination Manual; FinCEN Investment Adviser AML Rule (effective January 1, 2028).
Observation: SoFi Bank is subject to full BSA/AML program requirements as a federally chartered national bank. The 10-K acknowledges BSA/AML obligations. No public enforcement action by FinCEN or OCC on AML program found. With $37.5B in deposits, 13.7M members, crypto operations (SoFi Crypto, SoFiUSD stablecoin launched 2025), and cross-border Tech Platform clients, AML transaction volume and complexity is material. FinCEN's new IA AML Rule (eff. Jan 1, 2028) will extend AML obligations to SoFi Wealth LLC and SoFi Capital Advisors LLC.
Next Action: Request BSA/AML program documentation, TM system vendor identity, SAR filing statistics (if disclosable), and CISO/BSA Officer assessment of crypto-related AML controls.
9.3 | Concentration Risk Assessment In Scope
Objective: Assess client and vendor concentration risk in SoFi's Technology Platform segment.
Frameworks: DORA ICT third-party (Conditional for US entity); OCC Third-Party Risk Management guidance (OCC 2013-29); internal ERM.
Observation: In FY2025, a single unnamed large Galileo client fully exited the platform, causing Technology Platform accounts to fall from 167.7 million to 128.5 million — a 23% decline. This is confirmed from public earnings disclosures. The concentration of revenue from one large client represents a material operational and revenue risk. Client identity, contractual terms, and SoFi's concentration risk management framework details are not publicly disclosed.
Next Action: Request client concentration analysis for Technology Platform; review OCC third-party risk management framework documentation; validate exit and termination plan per 9.4.
4. Detailed Risk Findings — Top 9 Flags + Strategic Alternatives
F-001 | KYC / CIP Program — Prior Enforcement + Evolving Obligations
HIGHConfidence: Confirmed (public enforcement record) / Conditional (post-remediation status)
Regulatory Citation: FINRA AWC No. 2019062705801 (May 2024); BSA 31 U.S.C. §5318; FinCEN CDD Rule 31 CFR §1010.230; FinCEN IA AML Rule (eff. Jan 1, 2028)
SoFi Securities LLC was fined $1.1M by FINRA in May 2024 for failing to maintain a reasonable CIP and ITPP for SoFi Money during December 2018 – April 2019. Approximately 800 fraudulent accounts were opened; $8.6M transferred from external accounts; $2.5M withdrawn. Separately, FinCEN's new Investment Adviser AML Rule will require SoFi Wealth LLC and SoFi Capital Advisors LLC to implement AML programs by January 1, 2028.
Data gap / current gap: Post-remediation CIP/ITPP program documentation and testing results are not confirmable from public sources. IA AML compliance programs for investment adviser affiliates are not yet required (pre-2028) but planning should be underway.
Remediation: Obtain CIP/ITPP program documentation; conduct gap assessment against current FFIEC and FinCEN standards; initiate IA AML program design for 2028 compliance.
Owner: Chief Risk Officer; BSA/AML Officer
Deadline: IA AML Rule: January 1, 2028; CIP remediation validation: next examination cycle
Strategic Alternatives
| Option | Action | Details |
|---|---|---|
| Option 1 — Internal | Enhance BSA/Compliance team | Owner: CRO + BSA Officer; conduct internal AML program refresh and IA AML readiness assessment. Est. Lift: Medium |
| Option 2 — Vendor | Engage AML regulatory consulting firm | Pros: Specialized expertise; benchmarking against peer banks at similar asset scale. Cons: Cost; integration of external recommendations with existing Galileo transaction monitoring infrastructure. |
| Option 3 — Risk Acceptance | Accept residual gap for pre-2028 IA AML | Viable when: Only for the IA AML Rule timeline gap (pre-2028); not viable for bank CIP obligations. Approval: Chief Risk Officer + General Counsel |
Option
Option 1 — Internal
Action
Enhance BSA/Compliance team
Details
Owner: CRO + BSA Officer; conduct internal AML program refresh and IA AML readiness assessment. Est. Lift: Medium
Option
Option 2 — Vendor
Action
Engage AML regulatory consulting firm
Details
Pros: Specialized expertise; benchmarking against peer banks at similar asset scale. Cons: Cost; integration of external recommendations with existing Galileo transaction monitoring infrastructure.
Option
Option 3 — Risk Acceptance
Action
Accept residual gap for pre-2028 IA AML
Details
Viable when: Only for the IA AML Rule timeline gap (pre-2028); not viable for bank CIP obligations. Approval: Chief Risk Officer + General Counsel
F-002 | CFPB Direct Supervision — Commenced January 1, 2024
HIGHConfidence: Confirmed
Regulatory Citation: Dodd-Frank Act §1025; CFPB Supervision and Examination Manual; 12 U.S.C. §5515
SoFi Bank and affiliates became subject to direct CFPB supervision and examination commencing January 1, 2024, triggered by total assets exceeding $10 billion for four consecutive quarters. Prior to this date, OCC examined SoFi Bank for compliance with CFPB rules. This represents a structural change in supervisory regime: the CFPB has now had direct examination authority for approximately 18 months as of this report date.
Data gap / current gap: Outcome of any CFPB examination findings since January 1, 2024 is not publicly disclosed. UDAAP compliance posture under direct CFPB examination cannot be confirmed from public sources. The FTC consent order (active to 2039) regarding advertising savings claims may also inform CFPB examination scope.
Remediation: Engage counsel to review first CFPB examination cycle findings; conduct UDAAP self-assessment across all consumer-facing products; review advertising claims compliance against FTC consent order terms.
Owner: General Counsel; Chief Compliance Officer
Deadline: Ongoing; first CFPB exam cycle already underway
Strategic Alternatives
| Option | Action | Details |
|---|---|---|
| Option 1 — Internal | UDAAP self-assessment | Owner: Compliance team; map all consumer-facing product flows to CFPB examination priorities. Est. Lift: Medium |
| Option 2 — Vendor | Engage CFPB-specialized regulatory counsel | Pros: Deep CFPB examination knowledge; can model exam findings. Cons: Cost; need for internal coordination across 13.7M member-facing products. |
| Option 3 — Risk Acceptance | Not viable | CFPB supervision is non-negotiable for >$10B assets. Approval: N/A |
Option
Option 1 — Internal
Action
UDAAP self-assessment
Details
Owner: Compliance team; map all consumer-facing product flows to CFPB examination priorities. Est. Lift: Medium
Option
Option 2 — Vendor
Action
Engage CFPB-specialized regulatory counsel
Details
Pros: Deep CFPB examination knowledge; can model exam findings. Cons: Cost; need for internal coordination across 13.7M member-facing products.
Option
Option 3 — Risk Acceptance
Action
Not viable
Details
CFPB supervision is non-negotiable for >$10B assets. Approval: N/A
F-003 | FTC Consent Order — Active Until 2039
MEDIUMConfidence: Confirmed
Regulatory Citation: FTC Docket No. C-4673; In re Social Finance, Inc. and SoFi Lending Corp. (2019); Federal Trade Commission Act §5
The FTC approved a final consent order against Social Finance, Inc. and SoFi Lending Corp. in February 2019 (conduct: 2018) for deceptive advertising regarding student loan refinancing savings — ads were alleged to have inflated average consumer savings, sometimes doubling the actual figure. The consent order prohibits SoFi from misrepresenting savings claims unless substantiated by competent and reliable evidence. The order remains active and will terminate on February 22, 2039 (or 20 years from any subsequent enforcement action, whichever is later).
Data gap / current gap: Ongoing compliance with consent order terms is not publicly verified. Any advertising review or substantiation process details are not public. SoFi's current student loan refinancing advertising must be evaluated against order terms continuously.
Remediation: Confirm existence of advertising substantiation review process tied to the FTC order; document compliance reporting to FTC (required under Part III of the order).
Owner: General Counsel; Chief Marketing Officer
Deadline: Ongoing through 2039
Strategic Alternatives
| Option | Action | Details |
|---|---|---|
| Option 1 — Internal | Advertising compliance review program | Owner: Legal + Marketing; annual review of all savings-related claims against FTC order terms. Est. Lift: Low |
| Option 2 — Vendor | Engage advertising law specialist | Pros: Specialized expertise in FTC substantiation standards. Cons: Cost; SoFi has presumably built this capability internally given 6+ years under order. |
| Option 3 — Risk Acceptance | Accept residual compliance management risk | Viable when: Base compliance program already established; accept residual risk of inadvertent non-compliance. Approval: General Counsel |
Option
Option 1 — Internal
Action
Advertising compliance review program
Details
Owner: Legal + Marketing; annual review of all savings-related claims against FTC order terms. Est. Lift: Low
Option
Option 2 — Vendor
Action
Engage advertising law specialist
Details
Pros: Specialized expertise in FTC substantiation standards. Cons: Cost; SoFi has presumably built this capability internally given 6+ years under order.
Option
Option 3 — Risk Acceptance
Action
Accept residual compliance management risk
Details
Viable when: Base compliance program already established; accept residual risk of inadvertent non-compliance. Approval: General Counsel
F-004 | SEC Conflict-of-Interest Order — SoFi Wealth LLC (2021)
MEDIUMConfidence: Confirmed
Regulatory Citation: SEC IA Release No. 5826 (August 19, 2021); Investment Advisers Act Section 206(2); SEC Rule 206(4)-7
The SEC charged SoFi Wealth LLC in August 2021 for breaching fiduciary duty by failing to disclose conflicts of interest when it reallocated approximately 20,000 automated portfolio accounts from third-party ETFs to two SoFi-sponsored ETFs (SFY and SFYX) in April 2019, without informing clients of the company's economic interest in those funds. SoFi Wealth also failed to assess tax consequences for clients (~$772K short-term capital gains, ~$662K long-term capital gains imposed). SoFi Wealth agreed to a cease-and-desist order, censure, and $300,000 civil penalty without admitting or denying findings.
Data gap / current gap: Remediation and undertakings required by the SEC order were completed (order acknowledged remedial acts). Ongoing monitoring status of SoFi Wealth's conflict disclosure practices and compliance program enhancements are not publicly verifiable.
Remediation: Confirm SEC order undertakings have been fulfilled; review current SoFi Wealth conflict-of-interest disclosure practices against Reg BI / fiduciary standard; verify no recurrence in subsequent product rollouts (e.g., SoFi Crypto, SoFiUSD).
Owner: SoFi Wealth Chief Compliance Officer; General Counsel
Deadline: Order compliance ongoing; SoFi Crypto-related conflict review: immediate
Strategic Alternatives
| Option | Action | Details |
|---|---|---|
| Option 1 — Internal | Conflict review for new products | Owner: SoFi Wealth CCO; systematic conflict-of-interest pre-launch review for all new products. Est. Lift: Low |
| Option 2 — Vendor | Third-party RIA compliance consultant | Pros: Independent review of SoFi Wealth Form ADV disclosures and conflicts policy. Cons: Limited marginal value if internal program already enhanced post-2021 order. |
| Option 3 — Risk Acceptance | Accept residual compliance management risk | Viable when: Remediation confirmed complete; low recurrence risk given heightened CFPB and SEC scrutiny. Approval: General Counsel |
Option
Option 1 — Internal
Action
Conflict review for new products
Details
Owner: SoFi Wealth CCO; systematic conflict-of-interest pre-launch review for all new products. Est. Lift: Low
Option
Option 2 — Vendor
Action
Third-party RIA compliance consultant
Details
Pros: Independent review of SoFi Wealth Form ADV disclosures and conflicts policy. Cons: Limited marginal value if internal program already enhanced post-2021 order.
Option
Option 3 — Risk Acceptance
Action
Accept residual compliance management risk
Details
Viable when: Remediation confirmed complete; low recurrence risk given heightened CFPB and SEC scrutiny. Approval: General Counsel
F-005 | $50 Billion Asset Threshold — OCC Heightened Standards Exposure
HIGHConfidence: Confirmed (threshold crossed); Conditional (regulatory outcome pending OCC rulemaking)
Regulatory Citation: 12 CFR Part 30 (OCC Heightened Standards); Dodd-Frank Act §165; OCC Proposed Rule (December 23, 2025 — raising threshold from $50B to $700B)
As of December 31, 2025, SoFi reported total assets of $50.7 billion, crossing the existing $50 billion OCC heightened standards threshold for national banks (12 CFR Part 30 App. D). This would normally trigger enhanced risk management, liquidity, and governance requirements. However, on December 23, 2025, the OCC proposed raising this threshold to $700 billion. If finalized as proposed, SoFi Bank would be exempt from the heightened standards. Until the rule is finalized, SoFi Bank technically operates at a threshold with regulatory uncertainty.
Data gap / current gap: Status of SoFi Bank's compliance with existing $50B heightened standards (if applicable) is not publicly confirmed. OCC proposed rulemaking timeline and final outcome are uncertain.
Remediation: Monitor OCC rulemaking; engage regulatory counsel to assess current obligations under existing $50B threshold; document readiness for either outcome.
Owner: Chief Risk Officer; General Counsel
Deadline: OCC rulemaking finalization (timeline uncertain); interim: immediate regulatory counsel review
Strategic Alternatives
| Option | Action | Details |
|---|---|---|
| Option 1 — Internal | Regulatory monitoring and threshold readiness | Owner: CRO + Legal; track OCC rulemaking and maintain readiness materials. Est. Lift: Low |
| Option 2 — Vendor | Engage OCC-specialized bank regulatory counsel | Pros: Real-time rulemaking intelligence; can assess applicability of current Part 30 Appendix D obligations. Cons: Cost. |
| Option 3 — Risk Acceptance | Accept pending regulatory clarity | Viable when: OCC proposed rule raises threshold significantly; monitor for finalization before committing to full heightened-standards program build. Approval: Chief Risk Officer |
Option
Option 1 — Internal
Action
Regulatory monitoring and threshold readiness
Details
Owner: CRO + Legal; track OCC rulemaking and maintain readiness materials. Est. Lift: Low
Option
Option 2 — Vendor
Action
Engage OCC-specialized bank regulatory counsel
Details
Pros: Real-time rulemaking intelligence; can assess applicability of current Part 30 Appendix D obligations. Cons: Cost.
Option
Option 3 — Risk Acceptance
Action
Accept pending regulatory clarity
Details
Viable when: OCC proposed rule raises threshold significantly; monitor for finalization before committing to full heightened-standards program build. Approval: Chief Risk Officer
F-006 | Technology Platform Concentration Risk — Galileo Client Exit
MEDIUMConfidence: Confirmed
Regulatory Citation: OCC Third-Party Risk Management Guidance (OCC 2023-17); FFIEC IT Handbook — Outsourcing Technology Services
In FY2025, a single large, unnamed Galileo client fully transitioned off the Technology Platform, causing total Technology Platform accounts to fall from 167.7 million to 128.5 million (a 23% decline). This is a confirmed, material event from public earnings disclosures. It demonstrates single-client concentration risk in SoFi's B2B technology infrastructure business and reflects the vulnerability of the Galileo platform to large-customer churn.
Data gap / current gap: Client concentration data for the Technology Platform (top client as % of segment revenue), exit and termination plan details, and contractual protections are not publicly disclosed.
Remediation: Request top-10 client concentration analysis for Galileo/Technology Platform; review vendor exit and termination plan documentation; assess revenue diversification strategy.
Owner: Technology Platform CEO / Business Unit Head; Chief Risk Officer
Deadline: Immediate
Strategic Alternatives
| Option | Action | Details |
|---|---|---|
| Option 1 — Internal | Client diversification and concentration monitoring | Owner: Galileo BU leadership; establish concentration thresholds and monitor quarterly. Est. Lift: Medium |
| Option 2 — Vendor | Third-party business continuity review | Pros: Independent assessment of platform resilience to large-client exits. Cons: Sensitivity of client data. |
| Option 3 — Risk Acceptance | Accept concentration as inherent to platform model | Viable when: Platform is actively diversifying; no single client represents >20% of segment revenue. Approval: CEO + Board Risk Committee |
Option
Option 1 — Internal
Action
Client diversification and concentration monitoring
Details
Owner: Galileo BU leadership; establish concentration thresholds and monitor quarterly. Est. Lift: Medium
Option
Option 2 — Vendor
Action
Third-party business continuity review
Details
Pros: Independent assessment of platform resilience to large-client exits. Cons: Sensitivity of client data.
Option
Option 3 — Risk Acceptance
Action
Accept concentration as inherent to platform model
Details
Viable when: Platform is actively diversifying; no single client represents >20% of segment revenue. Approval: CEO + Board Risk Committee
F-007 | SOC 2 Attestation Status — Unknown
MEDIUMConfidence: Unknown
Regulatory Citation: AICPA Trust Services Criteria; FFIEC IT Handbook — Audit; OCC Third-Party Risk Management Guidance
SoFi's 10-K cybersecurity disclosure references ISO 27002:2013, NIST CSF, PCI-DSS, FFIEC, and CIS controls — but does not reference a SOC 2 Type II attestation. Galileo Financial Technologies is the foundational processing infrastructure for SoFi's B2B Technology Platform business. Institutional clients and banking customers typically require SOC 2 Type II attestations from their critical infrastructure providers. Whether SoFi/Galileo holds a current SOC 2 Type II is not confirmable from public sources.
Data gap / current gap: SOC 2 Type II attestation status for Galileo Financial Technologies and SoFi Bank's core processing environment is unknown from public sources.
Remediation: Obtain SOC 2 Type II report for Galileo and SoFi Bank's critical control environment; if not yet obtained, scope and commission SOC 2 examination.
Owner: CISO; Galileo Head of Compliance
Deadline: 90 days (to confirm or initiate)
Strategic Alternatives
| Option | Action | Details |
|---|---|---|
| Option 1 — Internal | Engage existing auditor (Deloitte) to scope SOC 2 | Owner: CISO + Internal Audit; leverage existing relationship with Deloitte & Touche LLP. Est. Lift: High |
| Option 2 — Vendor | Engage specialist SOC 2 readiness firm | Pros: Faster gap-to-report timeline; specialized tooling. Cons: Cost; coordination with Deloitte. |
| Option 3 — Risk Acceptance | Accept attestation gap pending prioritization | Viable when: No contractual SOC 2 requirement currently outstanding from B2B clients. Approval: CISO + CRO |
Option
Option 1 — Internal
Action
Engage existing auditor (Deloitte) to scope SOC 2
Details
Owner: CISO + Internal Audit; leverage existing relationship with Deloitte & Touche LLP. Est. Lift: High
Option
Option 2 — Vendor
Action
Engage specialist SOC 2 readiness firm
Details
Pros: Faster gap-to-report timeline; specialized tooling. Cons: Cost; coordination with Deloitte.
Option
Option 3 — Risk Acceptance
Action
Accept attestation gap pending prioritization
Details
Viable when: No contractual SOC 2 requirement currently outstanding from B2B clients. Approval: CISO + CRO
F-008 | ESG / Climate Disclosure Gap
MEDIUMConfidence: Confirmed (absence of disclosure)
Regulatory Citation: SEC Climate Disclosure Rules (Release No. 33-11275, phased implementation); TCFD Framework; California SB 253 / SB 261 (climate disclosure laws, may apply to companies with California revenues)
No TCFD-aligned or SEC climate disclosure was identified from public sources for SoFi Technologies. SoFi's investor relations governance documents page returned no substantive content. With $3.6 billion in revenue and California headquarters, SoFi may be subject to California's SB 253 (Scope 1/2/3 emissions disclosure) and SB 261 (climate-related financial risk disclosure). SEC climate rules are being phased in for large accelerated filers.
Data gap / current gap: No public ESG report, TCFD disclosure, or climate risk assessment identified. ESG governance program maturity is unknown.
Remediation: Conduct ESG program readiness assessment; develop climate disclosure roadmap; assess California SB 253/261 applicability and timelines.
Owner: General Counsel; Chief Financial Officer; Board Audit Committee
Deadline: California SB 253: Scope 1/2 reporting beginning 2026 for FY2025 data (if applicable); SEC phased rules apply to large accelerated filers
Strategic Alternatives
| Option | Action | Details |
|---|---|---|
| Option 1 — Internal | ESG program design and disclosure roadmap | Owner: CFO + Legal; build ESG team and disclosure framework. Est. Lift: High |
| Option 2 — Vendor | Engage ESG advisory firm | Pros: Benchmarking; framework selection; data collection tooling. Cons: Cost; need for integration with financial reporting. |
| Option 3 — Risk Acceptance | Accept disclosure gap pending regulatory clarity | Viable when: SEC and California timelines are still being assessed; minimal near-term enforcement risk for first-year non-filers. Approval: CFO + General Counsel |
Option
Option 1 — Internal
Action
ESG program design and disclosure roadmap
Details
Owner: CFO + Legal; build ESG team and disclosure framework. Est. Lift: High
Option
Option 2 — Vendor
Action
Engage ESG advisory firm
Details
Pros: Benchmarking; framework selection; data collection tooling. Cons: Cost; need for integration with financial reporting.
Option
Option 3 — Risk Acceptance
Action
Accept disclosure gap pending regulatory clarity
Details
Viable when: SEC and California timelines are still being assessed; minimal near-term enforcement risk for first-year non-filers. Approval: CFO + General Counsel
F-009 | Crypto / Digital Asset Regulatory Risk — SoFi Crypto + SoFiUSD
HIGHConfidence: Confirmed (product launch); Conditional (regulatory treatment)
Regulatory Citation: SEC / CFTC jurisdiction over crypto assets (evolving); FinCEN virtual asset service provider guidance; OCC Conditional Approval No. 1277 (Jan 2022) — SoFi Bank prohibited from crypto-asset activities absent prior OCC non-objection under the Operating Agreement; OCC Interpretive Letters; Financial Innovation and Technology for the 21st Century Act (FIT21, pending); California DFPI crypto registration
SoFi launched SoFi Crypto (retail crypto trading) and SoFiUSD (a stablecoin) in December 2025. This is confirmed from FY2025 public earnings disclosures and the 10-K. Notably, the OCC's January 2022 conditional approval (CA #1277) for SoFi Bank stated that, while the Operating Agreement remains in effect, “the Resulting Bank shall not engage in any crypto-asset activities or services... unless it has received prior written determination of no supervisory objection from the OCC.” In other words, the prohibition is not absolute — the bank may conduct crypto activities if it first obtains OCC non-objection through the procedures set out in the Operating Agreement. The structure of SoFi Crypto and SoFiUSD relative to SoFi Bank N.A. vs. other corporate entities is not publicly detailed, and whether SoFi has sought or obtained the OCC's prior non-objection determination for the December 2025 crypto launches cannot be confirmed from public sources. If crypto activities are conducted within or linked to SoFi Bank without that prior OCC non-objection, this may conflict with the 2022 OCC condition.
Data gap / current gap: The legal entity structure for SoFi Crypto operations (i.e., whether conducted in SoFi Digital Assets LLC or another non-bank entity separate from SoFi Bank N.A.) is not publicly confirmed in sufficient detail. Critically, whether SoFi Bank has sought and obtained the OCC's prior written determination of no supervisory objection for the December 2025 crypto activities (the carve-out that permits crypto under CA #1277) is not publicly disclosed. Regulatory approvals for SoFiUSD stablecoin activities are not public.
Remediation: Map crypto product legal entity structure; confirm no SoFi Bank N.A. involvement in prohibited crypto activities per OCC condition; document OCC/FinCEN/SEC regulatory position for SoFi Crypto and SoFiUSD.
Owner: General Counsel; Chief Risk Officer; SoFi Digital Assets LLC compliance lead
Deadline: Immediate (pre-existing regulatory condition may be at risk)
Strategic Alternatives
| Option | Action | Details |
|---|---|---|
| Option 1 — Internal | Legal entity structure mapping and OCC condition review | Owner: General Counsel; document SoFi Crypto/SoFiUSD entity structure and confirm OCC condition compliance. Est. Lift: Low-Medium |
| Option 2 — Vendor | Engage crypto-regulatory counsel | Pros: Specialized expertise on OCC crypto guidance, FinCEN VASP rules, and stablecoin regulatory treatment. Cons: Fast-moving regulatory landscape; cost. |
| Option 3 — Risk Acceptance | Not viable | OCC condition compliance is non-negotiable for charter maintenance. Approval: N/A |
Option
Option 1 — Internal
Action
Legal entity structure mapping and OCC condition review
Details
Owner: General Counsel; document SoFi Crypto/SoFiUSD entity structure and confirm OCC condition compliance. Est. Lift: Low-Medium
Option
Option 2 — Vendor
Action
Engage crypto-regulatory counsel
Details
Pros: Specialized expertise on OCC crypto guidance, FinCEN VASP rules, and stablecoin regulatory treatment. Cons: Fast-moving regulatory landscape; cost.
Option
Option 3 — Risk Acceptance
Action
Not viable
Details
OCC condition compliance is non-negotiable for charter maintenance. Approval: N/A
5. Regulatory Obligation Map
Status: ✓ ACTIVE (confirmed obligation). ● LIKELY (strong inference, not fully confirmed). ● N/A (not applicable with rationale).
Scroll for more →
| Framework | Jurisdiction | Status | Key Obligations | Priority |
|---|---|---|---|---|
| OCC National Bank Supervision | Federal (US) | ✓ ACTIVE | Safety and soundness; capital adequacy; CRA compliance; OCC examination; approval for branches/acquisitions; heightened standards (§50B threshold — pending OCC rulemaking clarification) | High |
| Federal Reserve — BHCA / FHC | Federal (US) | ✓ ACTIVE | Bank holding company regulation; financial holding company status (§4(l) BHCA); “well capitalized” and “well managed” requirements; affiliate transaction restrictions (§§23A/23B); Volcker Rule (applies — assets exceed $10B) | High |
| CFPB Direct Supervision | Federal (US) | ✓ ACTIVE | Direct examination authority (commenced Jan 1, 2024); UDAAP; fair lending; consumer protection laws; Truth in Lending Act; ECOA; EFTA; TILA | High |
| FinCEN / BSA | Federal (US) | ✓ ACTIVE | BSA program; SAR filing; CTR filing; CDD/KYC; OFAC sanctions screening; FinCEN IA AML Rule (effective Jan 1, 2028 — investment adviser affiliates) | High |
| FDIC Insurance | Federal (US) | ✓ ACTIVE | Deposit insurance assessments ($19.3M FDIC expense FY2025); compliance with FDIA; examination by FDIC as secondary regulator | Medium |
| SEC — Public Reporting Company | Federal (US) | ✓ ACTIVE | Annual 10-K, quarterly 10-Q, 8-K current reports; proxy (DEF 14A); PCAOB audit; Reg FD; insider trading restrictions; climate disclosure rules (phased) | High |
| SEC — Investment Adviser Act | Federal (US) | ✓ ACTIVE | SoFi Wealth LLC and SoFi Capital Advisors LLC: Form ADV; fiduciary duty; Rule 206(4)-7 compliance program; Code of Ethics (Rule 204A-1) | Medium |
| FINRA | Federal (US) | ✓ ACTIVE | SoFi Securities LLC (CRD 151717): broker-dealer rules; FINRA Rule 4512 (CIP); Rule 17a-3/17a-4 (recordkeeping); net capital; SIPC membership | High |
| FTC Consent Order (Docket C-4673) | Federal (US) | ✓ ACTIVE | Prohibition on unsubstantiated savings claims in advertising; active through 2039; annual compliance reporting to FTC | Medium |
| OCC Conditional Approval (Jan 2022) | Federal (US) | ✓ ACTIVE | Prohibition on crypto-asset activities/services at SoFi Bank N.A. level; capital contribution conditions | High |
| CCPA / CPRA | California (US) | ✓ ACTIVE | Consumer data subject rights; privacy notice; opt-out rights; CPPA enforcement | Medium |
| State Banking / Licensing | Multi-state (US) | ● LIKELY | State money transmitter licenses; state mortgage originator licenses (Wyndham Capital Mortgage); state consumer lending laws; various state regulator supervision | Medium |
| California SB 253 / SB 261 | California (US) | ● LIKELY | Scope 1/2/3 GHG emissions reporting (SB 253); climate-related financial risk disclosure (SB 261); applicability depends on California revenue threshold ($1B+) — SoFi likely exceeds threshold | Medium |
| CRA (Community Reinvestment Act) | Federal (US) | ✓ ACTIVE | OCC evaluates SoFi Bank under CRA; performance assessment; public file maintenance | Medium |
| EU DORA | EU | ● LIKELY (Conditional) | Technisys S.A. (Luxembourg) may constitute an ICT third-party provider subject to DORA or serving DORA-regulated entities; requires confirmation | Low |
| GDPR | EU | ● LIKELY (Conditional) | Technisys Luxembourg operations may implicate GDPR for EU data subjects; requires entity-level mapping | Low |
| Basel III / DFAST | Federal (US) | ● LIKELY | DFAST stress testing may apply at $50B+ threshold (under current rules); Basel III capital framework applies via OCC; DFAST applicability depends on regulatory clarification post OCC proposed rule | Medium |
| HIPAA | Federal (US) | ● N/A | SoFi is not a healthcare entity or business associate; not applicable | |
| SFDR / CSRD | EU | ● N/A | No EU-distributed investment products confirmed; no EU parent; not applicable under current structure |
6. Workflow Linkage Map
| Source Workflow | Linked To | Shared Artifact / Rationale | Link |
|---|---|---|---|
| 2.5 KYC Onboarding Audit | 2.2 AML Transaction Monitoring | Customer identity data feeds directly into TM system; CIP weakness = AML blind spot | ✓ LINK |
| 2.5 KYC Onboarding Audit | 8.1 Background Check Compliance | Identity verification protocols applicable to both customer onboarding and employee screening | ● COND |
| 2.2 AML Transaction Monitoring | 2.3 SAR Draft | TM system generates alerts that feed SAR decision workflow | ✓ LINK |
| 4.1 Policy Library Review | 8.2 Insider Threat Policy Review | MNPI policy is part of overall policy library; Ex-19.1 filed with 10-K | ✓ LINK |
| 9.3 Concentration Risk Assessment | 11.4 Process Resilience & Outsourcing Review | Galileo client concentration = both vendor dependency and outsourced service concentration risk | ✓ LINK |
| 1.4 Vendor Risk Assessment | 9.1 Vendor Onboarding Due Diligence | Third-Party Security Risk Management program covers both SOC 2 vendor assessment and broader vendor DD | ✓ LINK |
| F-009 Crypto Risk | 5.1 Regulatory Change Monitor | Crypto regulatory landscape (SEC, CFTC, FinCEN, OCC) evolving rapidly; must be tracked in horizon scanning | ✓ LINK |
| F-008 ESG Disclosure | 5.1 Regulatory Change Monitor | California SB 253/261 and SEC climate rules are active regulatory changes requiring monitoring | ✓ LINK |
| 7.1 Vulnerability Management | 7.3 Endpoint Security Audit | Shared artifact: vulnerability scan results feed endpoint remediation prioritization | ✓ LINK |
| 4.2 Board Risk Report | 4.5 Audit Committee Prep Pack | Risk Committee and Audit Committee overlap; CISO reports quarterly to Risk Committee; Audit Committee reviews financial controls | ● COND |
Source Workflow
2.5 KYC Onboarding Audit
Linked To
2.2 AML Transaction Monitoring
Shared Artifact / Rationale
Customer identity data feeds directly into TM system; CIP weakness = AML blind spot
Link
✓ LINK
Source Workflow
2.5 KYC Onboarding Audit
Linked To
8.1 Background Check Compliance
Shared Artifact / Rationale
Identity verification protocols applicable to both customer onboarding and employee screening
Link
● COND
Source Workflow
2.2 AML Transaction Monitoring
Linked To
2.3 SAR Draft
Shared Artifact / Rationale
TM system generates alerts that feed SAR decision workflow
Link
✓ LINK
Source Workflow
4.1 Policy Library Review
Linked To
8.2 Insider Threat Policy Review
Shared Artifact / Rationale
MNPI policy is part of overall policy library; Ex-19.1 filed with 10-K
Link
✓ LINK
Source Workflow
9.3 Concentration Risk Assessment
Linked To
11.4 Process Resilience & Outsourcing Review
Shared Artifact / Rationale
Galileo client concentration = both vendor dependency and outsourced service concentration risk
Link
✓ LINK
Source Workflow
1.4 Vendor Risk Assessment
Linked To
9.1 Vendor Onboarding Due Diligence
Shared Artifact / Rationale
Third-Party Security Risk Management program covers both SOC 2 vendor assessment and broader vendor DD
Link
✓ LINK
Source Workflow
F-009 Crypto Risk
Linked To
5.1 Regulatory Change Monitor
Shared Artifact / Rationale
Crypto regulatory landscape (SEC, CFTC, FinCEN, OCC) evolving rapidly; must be tracked in horizon scanning
Link
✓ LINK
Source Workflow
F-008 ESG Disclosure
Linked To
5.1 Regulatory Change Monitor
Shared Artifact / Rationale
California SB 253/261 and SEC climate rules are active regulatory changes requiring monitoring
Link
✓ LINK
Source Workflow
7.1 Vulnerability Management
Linked To
7.3 Endpoint Security Audit
Shared Artifact / Rationale
Shared artifact: vulnerability scan results feed endpoint remediation prioritization
Link
✓ LINK
Source Workflow
4.2 Board Risk Report
Linked To
4.5 Audit Committee Prep Pack
Shared Artifact / Rationale
Risk Committee and Audit Committee overlap; CISO reports quarterly to Risk Committee; Audit Committee reviews financial controls
Link
● COND
7. Escalations — Items Requiring Review
E-01 | OCC Conditional Approval vs. SoFi Crypto / SoFiUSD — Potential Conflict
Reason: The OCC's January 2022 conditional approval of SoFi Bank, N.A. expressly prohibited crypto-asset activities or services at the bank. SoFi launched SoFi Crypto and SoFiUSD stablecoin in December 2025. The legal entity structure for these activities (whether conducted outside SoFi Bank N.A.) is not publicly confirmed. This cannot be resolved from public sources and presents a potential charter-level compliance risk.
Who Must Review: General Counsel + Chief Risk Officer + OCC Relationship Manager
E-02 | CFPB Examination Findings — January 2024 Onwards
Reason: CFPB direct supervision began January 1, 2024. Any examination findings from the first CFPB examination cycle are confidential and not publicly disclosed. The FTC consent order and FINRA CIP/ITPP fine create relevant precedent for CFPB examination focus areas. Examination findings cannot be confirmed from public sources.
Who Must Review: General Counsel + Chief Compliance Officer + CFPB Relationship Manager
E-03 | BSA/AML Program Documentation — Post-Bank Charter Quality
Reason: SoFi Bank N.A. obtained its charter in January 2022. A full BSA/AML program is required. Prior enforcement (FINRA 2024 for 2018–2019 conduct) related to a pre-bank period. The quality of the post-charter BSA/AML program — including TM system, SAR filing cadence, and CDD compliance — cannot be verified from public sources.
Who Must Review: BSA/AML Compliance Officer + Chief Risk Officer + OCC/FinCEN Relationship Manager
E-04 | Technisys S.A. (Luxembourg) — EU Regulatory Obligations
Reason: Technisys S.A. is a Luxembourg société anonyme and subsidiary of SoFi. It provides core banking technology to financial institutions in Latin America and potentially the EU. DORA and GDPR obligations may attach. Cannot be determined from public sources.
Who Must Review: General Counsel + Technisys Chief Compliance Officer + EU regulatory counsel
8. Next Actions — Prioritized (Effort × Impact)
Scroll for more →
| Priority | Action | Linked Finding/Workflow | Effort | Impact | Owner |
|---|---|---|---|---|---|
| 1 | Map SoFi Crypto/SoFiUSD entity structure vs. OCC 2022 condition; engage OCC counsel | F-009, E-01 | Low | High | General Counsel |
| 2 | Obtain post-2019 CIP/ITPP program documentation and current BSA/AML program assessment | F-001, E-03, 2.5, 2.2 | Medium | High | CRO, BSA Officer |
| 3 | Initiate IA AML Rule (eff. 2028) readiness program for SoFi Wealth LLC and SoFi Capital Advisors LLC | F-001, 2.2 | Medium | High | CCO, CRO |
| 4 | CFPB examination preparation: UDAAP self-assessment across all consumer products; FTC consent order compliance review | F-002, F-003, E-02 | High | High | General Counsel, CCO |
| 5 | Confirm SOC 2 Type II status for Galileo Financial Technologies; scope examination if not yet obtained | F-007, 1.3 | High | Medium | CISO, Internal Audit |
| 6 | OCC $50B heightened standards monitoring: engage regulatory counsel; assess current Part 30 Appendix D obligations pending OCC rulemaking finalization | F-005 | Low | Medium | CRO, General Counsel |
| 7 | Galileo concentration risk: obtain client concentration data; review exit/termination plan | F-006, 9.3, 9.4 | Medium | Medium | Galileo BU Leadership, CRO |
| 8 | ESG/climate disclosure roadmap: assess California SB 253/261 applicability; begin emissions data collection | F-008, 10.1, 10.2 | High | Medium | CFO, General Counsel |
| 9 | Technisys EU regulatory mapping: assess DORA and GDPR obligations for Luxembourg entity | E-04, 3.1, 3.5, 6.1 | Medium | Medium | General Counsel, Technisys CCO |
9. Peer Benchmarking Reference
SoFi Peer Archetype: High-Growth National Bank + Fintech Platform at Scale
SoFi is most comparable to the cohort of de novo or recently chartered national banks that have grown rapidly through digital channels (vs. legacy branch networks), including: Ally Financial (ALLY, established BHC, $196B assets), LendingClub Corporation (LC, national bank since 2021, ~$10B assets), Synchrony Financial (SYF, ~$100B assets), and Green Dot Corporation (GDOT, bank holding company). SoFi's Technology Platform segment has no direct peer among this cohort — Galileo and Technisys position SoFi as both a regulated financial institution and a B2B fintech infrastructure provider (comparable peers include FIS, Fiserv, Jack Henry — though those are non-bank technology companies).
| GRC Category | SoFi (This Profile) | Peer Norm (National Bank, $20–100B assets) | Gap Signal |
|---|---|---|---|
| Financial Regulation | Defined (3) | Defined–Managed (3.5) | Slight lag — enforcement history and rapid growth |
| Cybersecurity | Defined (3) | Defined–Managed (3.5) | Moderate lag — SOC 2 status unknown; zero trust gap unclear |
| Internal Governance | Defined (3) | Managed (4) | Moderate gap — board structure strong; policy library depth unknown |
| BSA/AML | Developing–Defined (2.5) | Defined (3) | Gap — prior FINRA CIP/ITPP finding; post-charter program quality unconfirmed |
| ESG / Disclosure | Developing (2) | Defined (3) | Material gap — no public TCFD or climate report vs. large-bank peer norms |
| Privacy & Data | Defined (3) | Defined (3) | Approximate parity |
| Third-Party Risk | Defined (3) | Managed (4) | Moderate gap — Galileo concentration loss is a public signal |
GRC Category
Financial Regulation
SoFi (This Profile)
Defined (3)
Peer Norm (National Bank, $20–100B assets)
Defined–Managed (3.5)
Gap Signal
Slight lag — enforcement history and rapid growth
GRC Category
Cybersecurity
SoFi (This Profile)
Defined (3)
Peer Norm (National Bank, $20–100B assets)
Defined–Managed (3.5)
Gap Signal
Moderate lag — SOC 2 status unknown; zero trust gap unclear
GRC Category
Internal Governance
SoFi (This Profile)
Defined (3)
Peer Norm (National Bank, $20–100B assets)
Managed (4)
Gap Signal
Moderate gap — board structure strong; policy library depth unknown
GRC Category
BSA/AML
SoFi (This Profile)
Developing–Defined (2.5)
Peer Norm (National Bank, $20–100B assets)
Defined (3)
Gap Signal
Gap — prior FINRA CIP/ITPP finding; post-charter program quality unconfirmed
GRC Category
ESG / Disclosure
SoFi (This Profile)
Developing (2)
Peer Norm (National Bank, $20–100B assets)
Defined (3)
Gap Signal
Material gap — no public TCFD or climate report vs. large-bank peer norms
GRC Category
Privacy & Data
SoFi (This Profile)
Defined (3)
Peer Norm (National Bank, $20–100B assets)
Defined (3)
Gap Signal
Approximate parity
GRC Category
Third-Party Risk
SoFi (This Profile)
Defined (3)
Peer Norm (National Bank, $20–100B assets)
Managed (4)
Gap Signal
Moderate gap — Galileo concentration loss is a public signal
Benchmarks are directional and based on public evidence only. Not an audit.
10. RuleboardAI Engagement Options
Option A — Verification Sprint (4–6 Weeks)
Scope: Targeted LOA delivery; client provides: BSA/AML program overview, CIP/ITPP post-2019 documentation, SOC 2 status, legal entity structure for SoFi Crypto, and Galileo concentration data. RuleboardAI converts Gap Mode findings to Confirmed/Likely and closes the top escalations (E-01 through E-04). Deliverable: Updated CompanyScope profile with reduced data gaps and confirmed findings.
Ideal for: Closing the 9 data gaps identified in this profile quickly using minimum client effort.
Option B — Program Build (3–6 Months)
Scope: Full 48-workflow gap assessment with client documentation review. Builds a compliance program roadmap covering: BSA/AML program refresh (F-001, E-03), IA AML Rule readiness (2028), CFPB UDAAP self-assessment (F-002), OCC/Fed $50B threshold planning (F-005), SOC 2 readiness for Galileo (F-007), and ESG disclosure roadmap (F-008). Deliverable: Remediation roadmap with prioritized workstreams, effort/cost estimates, and regulatory exam readiness plan.
Ideal for: Building institutional GRC infrastructure ahead of CFPB exam cycle and OCC regulatory changes.
Option C — Managed Monitoring (Ongoing)
Scope: Monthly public-source monitoring of SoFi's regulatory environment: OCC rulemaking, CFPB enforcement database, FINRA BrokerCheck, SEC EDGAR, FTC enforcement, FinCEN advisories, California DFPI, crypto regulatory developments. Monthly RuleboardAI horizon scan briefings. Automatic escalation alerts for new enforcement actions or material regulatory changes affecting the SoFi RCPS profile.
Ideal for: Staying ahead of the fast-moving regulatory environment for a $50B+ fintech bank with crypto, stablecoin, and multi-regulator exposure.
11. Confidence Legend, Data Gaps & Disclaimers
Confidence Legend
| Label | Meaning |
|---|---|
| Confirmed | Verified against a primary public source (cited). |
| Likely | Strong inference; applicability clear; specifics unconfirmed from public sources. |
| Conditional | Depends on a trigger or an artifact not yet seen. |
| Unknown | Cannot be determined from public sources; routed to Escalation and/or Data Gap. |
Label
Confirmed
Meaning
Verified against a primary public source (cited).
Label
Likely
Meaning
Strong inference; applicability clear; specifics unconfirmed from public sources.
Label
Conditional
Meaning
Depends on a trigger or an artifact not yet seen.
Label
Unknown
Meaning
Cannot be determined from public sources; routed to Escalation and/or Data Gap.
Data Gaps
SOC 2 Type II attestation status for Galileo Financial Technologies and SoFi Bank's core processing environment
Cannot confirm from public sources. Galileo serves as critical B2B infrastructure; institutional clients typically require SOC 2 Type II; absence of confirmed attestation is a control assurance gap
Post-2019 CIP/ITPP program documentation and current BSA/AML program quality metrics
Cannot confirm from public sources. FINRA 2024 fine relates to 2018–2019 conduct; remediation confirmed but post-charter (post-2022) program quality cannot be verified from public sources
CFPB examination findings since January 1, 2024
Cannot confirm from public sources. CFPB has had direct examination authority for 18+ months; findings are confidential but are the most material regulator-facing risk for SoFi given UDAAP obligations and FTC consent order overlap
SoFi Crypto / SoFiUSD legal entity structure relative to SoFi Bank N.A. and OCC 2022 conditional approval restriction
Cannot confirm from public sources. If crypto activities are conducted within or linked to SoFi Bank N.A., this may conflict with the charter condition; cannot be confirmed or denied from public sources
ESG/climate program documentation; California SB 253/261 applicability assessment
Cannot confirm from public sources. No public TCFD report or climate disclosure identified; SoFi almost certainly exceeds California's $1B revenue threshold; regulatory exposure is plausibly Confirmed but program status is Unknown
Technisys S.A. (Luxembourg) EU regulatory obligations — DORA, GDPR applicability
Cannot confirm from public sources. Public disclosures do not confirm or deny EU regulatory obligations for the Luxembourg subsidiary; material if Technisys provides ICT services to EU-regulated banks
Galileo client concentration data (top clients as % of Technology Platform revenue)
Cannot confirm from public sources. The unnamed large client departure (23% account drop) is confirmed; the current revenue concentration profile, contractual protections, and exit plan are not public
Internal whistleblower program documentation
Cannot confirm from public sources. SEC Dodd-Frank and OCC requirements apply; no public confirmation of internal program structure, reporting channels, or non-retaliation policy
BCP/DR test results and exercise cadence for SoFi Bank N.A.
Cannot confirm from public sources. FFIEC BCP requirements mandate regular testing; results are not publicly disclosed; at $50.7B in assets, operational resilience is a material supervisory focus
Disclaimers
- Public Sources Only. This profile was produced entirely from publicly available sources including SEC EDGAR filings, OCC press releases and national bank lists, FINRA BrokerCheck/AWC records, FTC enforcement database, and public news sources. No client documentation, internal policies, examination reports, or confidential supervisory information was reviewed or accessed. This is Gap Mode — Preliminary.
- No Client Engagement. SoFi Technologies, Inc. is not a client of RuleboardAI. This profile is produced as a sample deliverable demonstrating RuleboardAI's CompanyScope methodology applied to a publicly available, recognized financial institution. No confidential relationship exists.
- Not an Audit, Legal Opinion, or Attestation. Nothing in this document constitutes an audit, legal advice, regulatory opinion, or attestation of any kind. Findings are preliminary inferences from public information and are subject to change upon review of client documentation.
- Point-in-Time. All data and findings are as of July 1, 2026. Regulatory status, enforcement records, and financial data reflect sources available as of that date. SoFi's regulatory environment and financial profile are evolving rapidly.
- Accuracy. While reasonable care was taken to cite primary sources, public sources may themselves contain errors or lag real-time regulatory status. All material facts should be verified directly with SoFi and its regulators before any business, investment, or compliance decision is made.
- RuleboardAI Methodology. This profile applies the RuleboardAI RCPS Classification Model and GRC workflow taxonomy (48 workflows, 11 categories, v1 — GovRiskCompliance 2026). Maturity scores are Likely/Conditional inferences. Full maturity scores require Verification Sprint or Program Build engagement.
Source Appendix
| Source | Description | URL |
|---|---|---|
| SEC EDGAR — SoFi Technologies (CIK 0001818874) | EDGAR filing page for all SoFi public filings | View source |
| SoFi 10-K FY2025 (filed February 17, 2026) | Annual report for fiscal year ended December 31, 2025 | View source |
| SoFi 10-K FY2024 (filed February 24, 2025) | Annual report for fiscal year ended December 31, 2024 | View source |
| SoFi DEF 14A 2026 Proxy Statement (filed April 30, 2026) | Proxy for 2026 annual meeting; board composition and governance | View source |
| SoFi Q4 2025 Earnings Disclosures (January 30, 2026) | Financial highlights including total assets $50.7B, members 13.7M | View source |
| OCC — Conditional Approval SoFi Bank N.A. (January 18, 2022) | OCC press release approving SoFi Bank charter with conditions including no crypto activities | View source |
| OCC National Banks Active List (May 2026) | Confirms SoFi Bank, National Association active status; OCC Charter No. 20862 | View source |
| FINRA AWC No. 2019062705801 — SoFi Securities LLC (May 2024) | $1.1M fine for CIP/ITPP failures; SoFi Money accounts 2018–2019 | View source |
| SEC IA Release No. 5826 — SoFi Wealth LLC (August 19, 2021) | $300K penalty; failure to disclose conflicts of interest re: proprietary ETF allocations | View source |
| FTC Consent Order — Docket No. C-4673 (February 2019) | Final consent order; SoFi advertising savings claim restrictions; active through 2039 | View source |
| SoFi Cybersecurity 10-K Disclosure (via Board Cybersecurity tracker) | Item 1C cybersecurity disclosure; frameworks, CISO, Risk Committee oversight | View source |
| SoFi Leadership Team | C-suite roster | View source |
| OCC Interpretive Letter / Conditional Approval #1277 (SoFi Bank) | OCC conditional approval documentation | View source |
| Stock Titan — SoFi 10-K FY2025 Summary | Regulatory environment, capital ratios, employee count, asset thresholds | View source |
| Companies Market Cap — SoFi 10-K Data | Key financial metrics from FY2025 10-K | View source |
Source
SEC EDGAR — SoFi Technologies (CIK 0001818874)
Description
EDGAR filing page for all SoFi public filings
URL
Source
SoFi 10-K FY2025 (filed February 17, 2026)
Description
Annual report for fiscal year ended December 31, 2025
URL
Source
SoFi 10-K FY2024 (filed February 24, 2025)
Description
Annual report for fiscal year ended December 31, 2024
URL
Source
SoFi DEF 14A 2026 Proxy Statement (filed April 30, 2026)
Description
Proxy for 2026 annual meeting; board composition and governance
URL
Source
SoFi Q4 2025 Earnings Disclosures (January 30, 2026)
Description
Financial highlights including total assets $50.7B, members 13.7M
URL
Source
OCC — Conditional Approval SoFi Bank N.A. (January 18, 2022)
Description
OCC press release approving SoFi Bank charter with conditions including no crypto activities
URL
Source
OCC National Banks Active List (May 2026)
Description
Confirms SoFi Bank, National Association active status; OCC Charter No. 20862
URL
Source
FINRA AWC No. 2019062705801 — SoFi Securities LLC (May 2024)
Description
$1.1M fine for CIP/ITPP failures; SoFi Money accounts 2018–2019
URL
Source
SEC IA Release No. 5826 — SoFi Wealth LLC (August 19, 2021)
Description
$300K penalty; failure to disclose conflicts of interest re: proprietary ETF allocations
URL
Source
FTC Consent Order — Docket No. C-4673 (February 2019)
Description
Final consent order; SoFi advertising savings claim restrictions; active through 2039
URL
Source
SoFi Cybersecurity 10-K Disclosure (via Board Cybersecurity tracker)
Description
Item 1C cybersecurity disclosure; frameworks, CISO, Risk Committee oversight
URL
Source
OCC Interpretive Letter / Conditional Approval #1277 (SoFi Bank)
Description
OCC conditional approval documentation
URL
Source
Stock Titan — SoFi 10-K FY2025 Summary
Description
Regulatory environment, capital ratios, employee count, asset thresholds
URL
Source
Companies Market Cap — SoFi 10-K Data
Description
Key financial metrics from FY2025 10-K
URL
Powered by RuleboardAI | Generated 07-01-2026 | Confidential — SoFi Technologies (SAMPLE) — GovRiskCompliance v1 2026 | Public Sources Only
RuleboardAI | www.ruleboardai.com | Ashwin Tatikola
SAMPLE DOCUMENT — ILLUSTRATIVE USE ONLY
This profile was produced entirely from public sources as a sample deliverable for the RuleboardAI marketing website. No client engagement exists between RuleboardAI and SoFi Technologies, Inc. No client documentation was reviewed. All data is sourced from public filings and regulatory records as cited below.
Not an audit, legal opinion, or attestation. Built from public sources only.
Want this for your company?