# When regulators intervene and what it costs the marketing team
In July 2022, the UK's Financial Conduct Authority (FCA) fined and publicly censured a string of firms over misleading financial promotions, but the case that made marketers nervous was closer to home: BlockFi paid $100 million to the SEC and 32 US states in February 2022, largely because its "earn interest on crypto" ads implied a savings account when the product was an unregistered security. The creative team's word choices, not the finance team's spreadsheets, triggered the penalty.
That is the pattern this lesson dissects. Regulators rarely fine a fintech for having a bad product. They fine it for how the product was described, to whom, and with what fine print. Marketing is where compliance risk becomes visible to the public, and where it becomes expensive.
Fintech marketing sits at the intersection of two heavily regulated worlds: financial services and advertising. That means two rulebooks apply simultaneously.
In the US, the Federal Trade Commission (FTC) polices deceptive advertising under the FTC Act, while the Consumer Financial Protection Bureau (CFPB) enforces fair-treatment rules for consumer financial products, including the prohibition on Unfair, Deceptive, or Abusive Acts or Practices (UDAAP). In the EU and UK, the relevant bodies are national regulators like the FCA (UK) or BaFin (Germany), operating under frameworks such as the UK's Consumer Duty rules (effective 2023) and the EU's Consumer Credit Directive and MiFID II disclosure requirements for investment products.
The common thread: claims must be clear, fair, not misleading, and targeted appropriately. Violating any one of those three is a marketing decision, not a product flaw.
Reverse-engineering real cases shows the same handful of triggers recurring.
1. Overstating safety or insurance. Neobank marketing that implied FDIC insurance (the US Federal Deposit Insurance Corporation, which protects bank deposits up to $250,000 as of 2024) when the fintech itself was not a bank and deposits were only insured indirectly through a partner bank. The CFPB and FDIC jointly warned several fintechs in 2022 to 2023 about this exact language. The fix is not legal boilerplate, it is precise copy: "deposits held at [Partner Bank], Member FDIC" instead of a bare FDIC logo next to the fintech's own name.
2. Misleading rate or return claims. "Earn up to 8% APY" ads where 8% applied to a capped, promotional tier that under 1% of users actually accessed. This is a classic UDAAP "deceptive" pattern: technically true, practically misleading. The FTC's own guidance on endorsements and testimonials covers adjacent territory: claims must reflect typical results, not best-case outliers.
3. Dark patterns in sign-up flows. The CFPB's 2023 circular on "dark patterns" (interface designs that trick users into actions they didn't intend) named pre-checked consent boxes, hidden fee disclosures, and confusing cancellation flows as UDAAP violations. This puts UX and growth marketinggrowth marketingAn experimental, data-driven approach to rapid growth by identifying and scaling the most efficient acquisition levers.View full definition → squarely inside compliance scope, not outside it.
4. Targeting vulnerable groups without safeguards. Buy-now-pay-later (BNPL) firms faced scrutiny (CFPB report, 2022) for ad targeting that concentrated on younger, lower-income users with limited credit-checking friction. This is a fair-treatment issue: the concern isn't the product, it's who was funneled toward it and how easy it was made to overcommit.
5. Crypto and "guaranteed returns" language. Celsius Network and BlockFi both faced enforcement partly over promotional language suggesting stability or guaranteed yield for products that were, legally, unregistered securities carrying real loss risk. Regulators treat "guaranteed," "risk-free," and "stable" as trigger words requiring hard evidence.
Costs come in layers, and marketing teams typically only see the first one coming.
| Cost type | Example | Estimate / order of magnitude |
|---|---|---|
| Direct fine | BlockFi, SEC + states, 2022 | $100 million (confirmed, SEC press release) |
| Restitution to consumers | CFPB actions against BNPL and neobank misrepresentation cases | Often several million, case-dependent |
| Campaign teardown cost | Full creative, legal review, and re-approval cycle | Weeks of delay, agency and legal hours, opportunity cost of paused spend |
| Reputational cost | Press coverage of enforcement action | Hard to quantify, but customer acquisition costcustomer acquisition costCustomer Acquisition Cost (CAC) is the total sales and marketing spend divided by the number of new customers gained in a period. It measures how efficiently you grow.View full definition → (CACCACCustomer Acquisition Cost (CAC) is the total sales and marketing spend divided by the number of new customers gained in a period. It measures how efficiently you grow.View full definition →) typically rises post-scandal as trust signals weaken |
A simple worked illustration of the acquisition-cost knock-on effect: if a fintech's blended CACCACCustomer Acquisition Cost (CAC) is the total sales and marketing spend divided by the number of new customers gained in a period. It measures how efficiently you grow.View full definition → is an estimated $150 per funded customer pre-scandal, and post-enforcement conversion rates on paid channelspaid channelsVisitors arriving via paid ads or sponsored placements, where you pay a platform to display your message rather than earning visits organically.View full definition → drop by even 15% (a plausible range seen in reputational-crisis case studies, not a specific confirmed figure), CACCACCustomer Acquisition Cost (CAC) is the total sales and marketing spend divided by the number of new customers gained in a period. It measures how efficiently you grow.View full definition → rises to roughly $150 / 0.85 ≈ $176. At 50,000 planned acquisitions, that is an incremental $1.3 million in spend just to hold volume steady, on top of any fine.
Every serious fintech marketing org now runs a pre-launch review gate before a campaign, landing pagelanding pageA standalone web page built for a single campaign goal, designed to maximise conversions by removing distractions and focusing visitors on one action.View full definition →, or in-app prompt ships. A defensible checklist covers:
The FTC's Business Guidance Resource Center is a genuinely useful free reference for building this checklist, especially its endorsement and financial-claims guidance.
Knowledge check
1. In the BlockFi case discussed in the lesson, what was the core regulatory problem that led to enforcement action?
2. According to the lesson's central pattern, why is marketing especially exposed to regulatory risk in fintech?
3. Why does the lesson describe fintech marketing as sitting at the intersection of 'two heavily regulated worlds'?
4. Select ALL correct answers about the common regulatory standard applied to marketing claims across the frameworks described in the lesson.
Select all the correct answers.
5. Select ALL correct answers about why enforcement actions like the BlockFi case matter for marketing teams specifically, rather than just legal or finance teams.
Select all the correct answers.
Treat published enforcement decisions (CFPB and FTC actions are public, FCA final notices are public in the UK) as case studies, the same way a product manager reads competitor teardown. Look specifically for the quoted advertising language the regulator objected to. That exact phrasing is the training data for your next campaign review.
🎬 [VIDEO: "How the CFPB Takes Action Against Companies" - youtube.com/@CFPBvideo - a short, official explainer of how the US consumer protection regulator investigates and penalizes deceptive financial marketing practices]
The skill isn't memorizing rules. It's pattern-matching your own upcoming campaign against the last twenty campaigns that got fined.