Skip to content

Domain Atlas / Lending & credit collections AI

Case fileUnited States — federal. Consumer Financial Protection Bureau administrative adjudications 2019-BCFP-0003, In the Matter of Enova International, Inc. (issued 25 January 2019, $3,200,000 civil money penalty, four permanent conduct prohibitions, five-year term), and 2023-CFPB-0014 (issued 15 November 2023, $15,000,000 civil money penalty, a seven-year ban on Covered Loans, a ban on using or selling the associated consumer information, five behavioural prohibitions, a compliance plan and an executive-compensation provision, seven-year term). Both were entered without Enova admitting or denying the findings. The conduct spans consumer lending across US states, with harmed cohorts the orders identify state by state, including Idaho and Delaware, Ohio and Texas. NO FEDERAL ORDER IS IN FORCE: the 2019 order was superseded by the 2023 order, and the 2023 order was terminated by the Bureau on 2 September 2025 — Enova reports it as effective 29 August 2025 — with an express waiver of any alleged non-compliance.large deployment

Enova International servicing defects & the debits nobody authorised

Explore this deployment in the PAN Lab ↗

In the PAN Lab, the readouts of this case's model organization carry a shaded evidence band whose width follows the least-established class among the modeling inputs the readings rest on.

The least-established input behind this case's model organization's readings is an assumption, not a measurement. Evidence base: 1 assumed · 11 published baseline.

In two consent orders four years apart, the Consumer Financial Protection Bureau found that Enova International, Inc. and its subsidiaries branded CashNetUSA and NetCredit debited or attempted to debit consumers' bank accounts without authorisation, and attributed the conduct to defects in Enova's own servicing and payment-processing software. Consent Order 2019-BCFP-0003, issued 25 January 2019, carried a $3,200,000 civil money penalty, four permanent conduct prohibitions and a five-year term, and applied the statutory unfairness test under 12 U.S.C. 5531(c)(1) directly to a software defect: 'The injury was caused by an error in Enova's software. The cost of debugging software would not have been significant and the erroneous practice did not confer any benefit to consumers or competition.' Consent Order 2023-CFPB-0014, issued 15 November 2023, found that Enova had VIOLATED four named paragraphs of the 2019 order and, because an order prescribed by the Bureau is federal consumer financial law, that each violation was itself a violation of the Consumer Financial Protection Act. It carried a $15,000,000 civil money penalty, a seven-year ban on Covered Loans, a ban on using or selling the associated consumer information, five behavioural prohibitions and a seven-year term. The Bureau's own headline described Enova as a repeat offender. The 2023 order enumerates eleven separately-described defect classes, each with its date range, consumer count and remediation figure, and names their machine causes: 'a coding error with its internal systems', 'flaws in Respondent's system logic', 'Enova's code failed to register', 'Respondent's automatic payment generation system', 'Respondent's internal systems did not accurately record'. Neither order uses the words algorithm, model, score, machine learning or artificial intelligence. The Bureau's aggregate for the 2023 order is 'violations of federal consumer protection law that involved over 111,000 consumers' — a figure dominated by two non-debit cohorts, the 50,565 unique consumers who did not receive a proper authorisation copy and the 43,359 customers charged incorrect amounts due, with the consumers debited from unauthorised accounts by the discrete code defects numbering in the low thousands. Both orders were entered without Enova admitting or denying the findings.[3]

What happened

Enova International is a Chicago-based online lender, listed on the New York Stock Exchange, operating through subsidiaries branded CashNetUSA and NetCredit. It builds its servicing stack in house. This case is not about who it lends to or on what terms. It is about whether the code that moves money after the loan is made does what the contract says, and about what a regulator can do when the answer is no.

The consent orders do not describe a decision system. They describe a pipeline, and they locate a named defect at almost every stage of it. A consumer's authorised bank account is written into an account-of-record store; a second, uncontrolled writer exists, because Enova bought consumer applications from third-party lead generators and wrote the bank details on them over the account already on file. The system computes what is due. It turns that obligation into a scheduled debit through what the 2023 order calls "Respondent's automatic payment generation system", and once produced, a payment can become, in the Bureau's own word, "irreversibly generated". Consumers and call-centre representatives then try to change what has already been produced — extensions, self-service due-date adjustments, skip statements, payment plans — and this is where most of the defect classes live, because the consumer-facing surface says the change is confirmed while the pipeline has already committed. Finally the debit hits the rails, failures are re-presented under system logic that did not account for intervening payments, and a third-party card-processing vendor reports a payment as failed when it had in fact succeeded.

The 2019 order found two things. Enova overwrote existing customers' bank-account records with details taken from purchased applications and then debited the substituted accounts, reaching 5,520 consumers. And it failed to honour granted loan extensions on its expedited-funding product, because a defect created two loan records per affected consumer, one showing a zero balance. The order records the second failure's control loop in a level of detail that is rare anywhere. Consumers first notified Enova in September 2013. In November 2013 Enova identified a coding error as the source. It implemented a fix in January 2014. When the fix failed ten days later, Enova manually disabled it. It did not re-enable the fix until May 2014, and did not run daily checks in the interim to ensure the issue had been resolved. Affected consumers were not told that full loan payments rather than extension fees had been taken from their accounts until April 2015.

Then the order does something unusual enough to be worth quoting whole. Under the Consumer Financial Protection Act an act is unfair only if the substantial injury it causes is not outweighed by countervailing benefits, and the Bureau applied that test to a software defect: "The injury was caused by an error in Enova's software. The cost of debugging software would not have been significant and the erroneous practice did not confer any benefit to consumers or competition." A federal regulator put engineering effort on one side of a statutory scale. The penalty was $3.2 million and the order carried four permanent conduct prohibitions and a five-year term. It required nothing about testing, change control, regression checks or monitoring.

The 2023 order is the second-order proof that the first remedy did not reach the defect. It finds that acts and practices described in its own findings violated four named paragraphs of the 2019 order, and that each order violation is itself a violation of federal consumer financial law, because an order prescribed by the Bureau is federal consumer financial law. The Bureau's own headline called Enova a repeat offender. What the order enumerates is eleven separately-described defect classes, each with its date range, its consumer count and the remediation Enova represents that it provided. The lead-generator issue, July to August 2020: 356 consumers, over $79,000. The debit-card processing issue, from as early as 2013 to 2019: 1,378 consumers, over $457,000, where the vendor reported a payment as failed when it had succeeded and representatives reprocessed it "in some cases up to four additional times, until there was no error message". A coding error in August 2019: 156 consumers in Idaho debited one to three times more than they had authorised, over $35,000, self-identified within a week. Re-presentments, 2016 to 2019: 1,625 instances across 1,587 unique consumers, over $186,000. The pre-default payment plan path, 2020 to 2021: 54 consumers in Delaware, Ohio and Texas. Unexpected generated payments, 2015 to 2020: 39 consumers. The self-service due-date feature in 2020: 309 instances across 296 consumers, over $36,000. Skip statements in 2020: 116 consumers, over $13,000. Incorrect amounts due through at least 2021: over $906,000 to 43,359 affected customers, including a single line-of-credit minimum-payment miscalculation worth over $583,000. Other debiting without authorisation: over $1.07 million to 11,510 consumers. And loan-extension cancellations from 2011 to 2020: about 3,500 extensions cancelled, over 2,500 consumers debited the full loan balance instead of the fee, over $1 million. Alongside those, 57,310 instances affecting 50,565 unique CashNetUSA consumers where the required copy of the electronic fund transfer authorisation was not provided or did not identify the account.

The Bureau's aggregate across all of it is "violations of federal consumer protection law that involved over 111,000 consumers". That figure is dominated by the two non-debit cohorts — the 50,565 who did not get a proper authorisation copy and the 43,359 charged incorrect amounts. The consumers debited from accounts they had not authorised by the discrete code defects number in the low thousands.

Three findings give the case its shape.

The first is the relapse, and it is a deployment-gate absence stated by a regulator. After the 2019 order, Enova kept obtaining consumer bank-account information from lead generators and launched a project to route those leads through "a newly developed proprietary framework" intended, among other outcomes, to "generate more profitable decisions on extending loan offers to consumers". The order continues: "At the time the new process launched in 2020, no one at Enova had checked to determine whether the new process would overwrite existing consumer bank account information, as it had before." It did, for 356 consumers, roughly eighteen months after a federal order permanently enjoined exactly that.

The second is a fully specified machine rule that voided a promise the company had already confirmed in writing. Enova's internal systems compared the account balance on the day before a granted extension was to be funded against the balance at the time of approval, and "a mismatch between the two balances resulted in an automatic cancelation of the approved loan extension. Interim partial payments would create such a mismatch." A consumer who paid something toward the loan lost the extension. Notification went out only after that check ran, the day before the original due date, telling the consumer to apply for a new extension to avoid a full-balance debit — which the Bureau found "was often insufficient time for consumers to act". And the rule the code enforced appeared in no consumer-facing document: the extension contract did not say it, and until 2020 neither did the online portal nor the confirmation email, which had told consumers "You have successfully extended your loan".

The third is what happened to the arriving signal. Where self-detection was instrumented it was fast — the Idaho coding error was identified within a week. Where detection depended on complaints it was slow, and the order measures it. On the self-service due-date feature Enova "received complaints about these unauthorized debits relatively soon after the feature began" but "it took three months for Enova to identify that it was a systemic problem". On skip statements consumers complained "in the first weeks" and it took four months. On the debit-card vendor issue, running from as early as 2013 to 2019, "Respondent received consumer complaints about this issue, but it treated these complaints as isolated and failed to identify it as a systemic problem impacting 1,378 consumers." Six years between an arriving signal and its correct classification.

The 2023 remedy is a much richer control stack than 2019's: a $15 million penalty, a seven-year ban on Covered Loans, a ban on using the associated consumer information for marketing or selling or transferring it, five behavioural prohibitions including a new one requiring the consumer's express informed consent before debiting on lead-generator information, a 90-day compliance plan with dated implementation steps, the Board holding ultimate responsibility, the Chief Executive Officer personally required to review every plan, report and submission and to authorise corrective actions, a sworn compliance report at one year, an unaffiliated third-party redress consultant retained under Enforcement Director non-objection down to its sampling protocol, and a first-of-its-kind requirement that executive compensation agreements consider what each executive did to ensure compliance, with an annual report to the Bureau. Not one line of it addresses code review, deployment gating, regression testing or automated payment-integrity monitoring, which is what every finding in it is about.

Enova's own account is materially softer and is its own. It said the 2019 issues "impacted less than 0.2% of total payments processed by Enova during the period in which the errors occurred", that they were "identified and self-disclosed to the CFPB in 2014", and that they "arose from technical systems errors, all of which have since been resolved". On the 2023 order it said the matters "do not arise from deliberate attempts to avoid law, but instead resulted from unintended computer and system errors", that "the majority of items were self-reported by Enova to the CFPB", and that the settlement was "not expected to have a material impact on the Company or its operations". The orders corroborate self-identification expressly for two classes and find the opposite on the vendor issue. Enova's stated remedial steps are architectural and it named them itself: centralised payment processing implemented in 2021, enhanced processes to identify and address customer impacts quickly, and sunsetting its single-payment product in 2022.

On 2 September 2025 the Bureau terminated the 2023 order. The two-page termination order recites that Enova had paid the $15,000,000 penalty, retained the third-party consultant, provided further redress to consumers "whom the third-party consultant determined had not previously received complete redress", and taken steps to implement the conduct provisions — and then states that "the Bureau hereby terminates this Consent Order. The Bureau also waives any alleged non-compliance by Enova with the Consent Order." The order had been written to run to at least November 2030. Roughly five years of it, including the product ban and the executive-compensation provision, ended early. Enova's annual report puts the termination as "Effective August 29, 2025".

The company is larger than it was at either order. It reports approximately $7.8 billion in credit or financing extended in 2025, consumer lending in 37 US states plus Brazil, small-business financing in 49 states and the District of Columbia, and 1,836 employees. As of July 2026 the live regulatory question about it is a charter rather than a code defect: a coalition of 20 state attorneys general has urged the Federal Reserve to reject its approximately $369 million acquisition of Grasshopper Bank, arguing that letting high-cost nonbank lenders acquire banks would let them bypass state usury caps. That is advocacy and a pending application, not a finding. A separate private class action alleging usury-law evasion through a bank partner, filed on 20 August 2024, is at the motion-to-compel-arbitration stage, which is pleadings rather than findings.

One boundary has to stay visible in all of this. Neither consent order examines Enova's underwriting or its decision layer, and neither uses the words algorithm, model, score, machine learning or artificial intelligence. Everything known about that layer comes from Enova's own securities filings, which describe "a fully integrated decision engine" making "automated decisions regarding marketing, fraud, underwriting, customer contact and collections", handling "more than 100 algorithms and over 1,000 variables", supported by approximately 90 data and analytics professionals, with fraud models the company says identify fraudulent applications "with a very low false positive rate". No regulator, court or auditor has examined any of it, and that rate is unpublished and unmeasured externally. The single place the record connects the two layers is the 2020 relapse, where a decision-layer deployment built to generate more profitable decisions silently restored a prohibited defect because nobody checked.

The sociotechnical reading

Almost every case in this domain governs a decision rule: who gets credit, at what price, who gets sued. This one is here because the rule was uncontroversial and the code that executed it was wrong, in eleven separately-documented ways, and consumers lost money each time. An atlas built only around decision quality has no slot for that failure mode, and it is one of the most common failure modes in deployed financial software.

Start with what the regulator actually did, because it is unusual. Statutory unfairness requires the Bureau to weigh substantial injury against countervailing benefits. In 2019 it put "the cost of debugging software" on that scale and found it would not have been significant. That is a public authority pricing engineering effort inside a legal test. Read next to the eleven defect classes of 2023 it becomes the sharpest question this case asks: if the fix is cheap and the injury is measured, what is it about a governance regime that leaves the fix undone for years?

The answer the record gives has three parts, and none of them is about intent.

The first is that a remedy written in conduct language cannot reach a defect in code. The 2019 order prohibited outcomes — do not debit without authorisation, do not fail to honour extensions — and prescribed no engineering control at all. Four years later the Bureau had to find the same outcomes recurring, including one instance created by a brand-new deployment nobody had checked against the order. The 2023 order answers with a great deal more governance machinery, and still contains nothing about change control, regression testing or payment-integrity monitoring. Both orders are aimed at the output of a pipeline whose defects are inputs.

The second is that a repair at the write point does not repair the store. Enova stopped overwriting bank-account records on newly purchased applications in June 2014, and 265 consumers whose records had already been overwritten were debited or attempted at least 6,425 more times, through December 2018. Four and a half years of harm from a practice that had already stopped. This is the shape governance discussions most often miss, and it generalises well past lending: closing an ingest path is a different project from cleaning what the ingest path wrote, and only one of them is visible in a status report.

The third is about where the correction loop leaks. The intake half worked — complaints arrived early in every one of the slow-detection classes. The aggregation half did not, and the order measures the gap in months and, once, in years. What makes that measurement useful is that it is channel-specific rather than general: self-detection where instrumented resolved in a week, complaint-driven detection took three months, four months, or six years. So the deployment was not blind. It was blind in exactly one channel, the one that depends on someone treating a pile of individual reports as a distribution.

There is a fourth thing here that the other lending cases do not have, and it is the humans. In two defect classes the corrective action of a customer service representative IS the harm: reprocessing a payment the vendor had falsely reported as failed, and failing to cancel a payment the pipeline had already generated while arranging a skip statement on a call. Neither is a training failure. Both are the same structural fact — a person inside a loop whose committed state they cannot see, whose diligence therefore produces debits. The consumer is in the same position one layer out, and worse: an automated balance comparison cancelled an extension the company had already confirmed, and the notice arrived one day before the due date, which the Bureau found was often insufficient time to act. The consumer's corrective window is set by the timing of a machine check nobody told them about.

Finally, and this is what makes the case a complete governance arc rather than an enforcement story: the remedy decayed before the system did. The 2023 order was the recidivism finding, carried the richest remedy in this domain's records, and was terminated about five years into a seven-year term with the Bureau expressly waiving any alleged non-compliance. The product ban went with it. The executive-compensation provision — an attempt to install accountability where the record showed it structurally absent — lapsed before an annual reporting cycle could accumulate much history. Whatever an atlas wants to say about whether governance works, this file is a reminder that a remedy's duration is itself a governed quantity, and that it is governed by someone other than the party the remedy binds.

One honest limit runs under all of it. The layer nobody examined is the one the company markets. Its filings describe a decision engine with more than a hundred algorithms and over a thousand variables making automated marketing, fraud, underwriting, contact and collections decisions, and fraud models it says work with a very low false positive rate. No regulator has looked at any of that, and nothing in this file asserts anything about it. Keeping the examined surface and the marketed surface visibly apart is the main editorial discipline this case demands — and the one place the record joins them is the moment a new decision-layer deployment reintroduced a prohibited defect because nobody had checked.

The concepts used in this reading are defined in the Field Guide; the governance responses live in the Practice Library. The model organization for this case can be stress-tested in the PAN Lab.

Grounding sources for this case

The same sources that ground this model organization in the PAN library: evaluations, government documents, investigative reporting, and advocacy documentation, each labeled by tier.

consumerfinancialprotectionb2025dGroundingGovernmentSave

Consumer Financial Protection Bureau (2025, September 2). Order Terminating the Consent Order, In the Matter of Enova International, Inc., File No. 2023-CFPB-0014 (Document 3, 2 pages) https://files.consumerfinance.gov/f/documents/cfpb_enova-international-2023_termination-consent-order_2025-09.pdf

https://files.consumerfinance.gov/f/documents/cfpb_enova-international-2023_termination-consent-order_2025-09.pdf

Grounds: model org: enova_lending_servicing_defects

consumerfinancialprotectionb2023aGroundingGovernmentSave

Consumer Financial Protection Bureau (2023, November 15). CFPB Fines Repeat Offender Enova $15 Million for Violating Order, Deceiving Customers, and Withdrawing Funds Without Consent (archived newsroom page; body text no longer retrievable, headline intact) https://www.consumerfinance.gov/archive/newsroom/cfpb-fines-repeat-offender-enova-15-million-for-violating-order-deceiving-customers-and-withdrawing-funds-without-consent/

https://www.consumerfinance.gov/archive/newsroom/cfpb-fines-repeat-offender-enova-15-million-for-violating-order-deceiving-customers-and-withdrawing-funds-without-consent/

Grounds: model org: enova_lending_servicing_defects

enovainternational2019GroundingVendorSave

Enova International, Inc. (2019, January 25). Form 8-K Exhibit 99.1: Enova Reaches Agreement with CFPB for Consumer Loan Payment Processing Errors, filed with the U.S. Securities and Exchange Commission (the operator's own investor-relations posting of the same release returns HTTP 403 to automated fetches; this filed exhibit is the verified copy) https://www.sec.gov/Archives/edgar/data/1529864/000114420419002835/tv511629_ex99-1.htm

https://www.sec.gov/Archives/edgar/data/1529864/000114420419002835/tv511629_ex99-1.htm

Grounds: model org: enova_lending_servicing_defects

Seeing your organization in this case file?

The histories here are documented after the harm. Mapping a live deployment's pathways and pressures, before the incident report, is engagement work: intake, diagnosis, prescription, and monitoring, with every limitation stated.

Sources & Evidence

Claims made on this page and what supports them. The full registry lives in Evidence.

EmpiricalIn two consent orders four years apart, the Consumer Financial Protection Bureau found that Enova Internationa…

In two consent orders four years apart, the Consumer Financial Protection Bureau found that Enova International, Inc. and its subsidiaries branded CashNetUSA and NetCredit debited or attempted to debit consumers' bank accounts without authorisation, and attributed the conduct to defects in Enova's own servicing and payment-processing software. Consent Order 2019-BCFP-0003, issued 25 January 2019, carried a $3,200,000 civil money penalty, four permanent conduct prohibitions and a five-year term, and applied the statutory unfairness test under 12 U.S.C. 5531(c)(1) directly to a software defect: 'The injury was caused by an error in Enova's software. The cost of debugging software would not have been significant and the erroneous practice did not confer any benefit to consumers or competition.' Consent Order 2023-CFPB-0014, issued 15 November 2023, found that Enova had VIOLATED four named paragraphs of the 2019 order and, because an order prescribed by the Bureau is federal consumer financial law, that each violation was itself a violation of the Consumer Financial Protection Act. It carried a $15,000,000 civil money penalty, a seven-year ban on Covered Loans, a ban on using or selling the associated consumer information, five behavioural prohibitions and a seven-year term. The Bureau's own headline described Enova as a repeat offender. The 2023 order enumerates eleven separately-described defect classes, each with its date range, consumer count and remediation figure, and names their machine causes: 'a coding error with its internal systems', 'flaws in Respondent's system logic', 'Enova's code failed to register', 'Respondent's automatic payment generation system', 'Respondent's internal systems did not accurately record'. Neither order uses the words algorithm, model, score, machine learning or artificial intelligence. The Bureau's aggregate for the 2023 order is 'violations of federal consumer protection law that involved over 111,000 consumers' — a figure dominated by two non-debit cohorts, the 50,565 unique consumers who did not receive a proper authorisation copy and the 43,359 customers charged incorrect amounts due, with the consumers debited from unauthorised accounts by the discrete code defects numbering in the low thousands. Both orders were entered without Enova admitting or denying the findings.

EmpiricalThe 2019 order found that from 2010 onward Enova overwrote existing customers' bank-account records with accou…

The 2019 order found that from 2010 onward Enova overwrote existing customers' bank-account records with account details taken from applications it had purchased from third-party lead generators, and then debited the substituted accounts, affecting 5,520 consumers. Enova stopped overwriting records on newly purchased applications in June 2014, but 'After June 2014, Enova continued to debit or attempt to debit 265 consumers' bank accounts that had already been overwritten, at least 6,425 times,' continuing until December 2018 for any of those consumers who still held an outstanding line of credit — so a repair applied at the ingest point left the contaminated store producing unauthorised debits for four and a half more years. The 2023 order found the same pathway carrying 356 further consumers in July and August 2020 and over $79,000, and answered with a prohibition the 2019 order had not contained: no debiting an account using information received from a Lead Generator 'without directly obtaining the consumer's express informed consent'. Separately, the 2019 order requires an electronic fund transfer authorisation to be signed or similarly authenticated with a copy returned to the consumer identifying the specific account; the 2023 order found 57,310 instances affecting 50,565 unique CashNetUSA consumers where that copy was not provided or did not name the account, and found that failure to violate the earlier order. The 2023 order also bans Enova from using the associated consumer information to market any consumer financial product and from selling or transferring it. The lead generators are named in the record by role only, and no reliable identification of any of them exists in the public sources.

EmpiricalThe 2023 order describes a fully specified machine rule that revoked a promise Enova had already confirmed in …

The 2023 order describes a fully specified machine rule that revoked a promise Enova had already confirmed in writing: 'Respondent's internal systems would compare the current account balance on the day before the loan extension was to be funded to the account balance at the time of the extension approval. A mismatch between the two balances resulted in an automatic cancelation of the approved loan extension. Interim partial payments would create such a mismatch.' Notification went out only after that check ran, 'which occurred the day before the due date of the original payday loan', telling the consumer to apply for a new extension to avoid a full-balance debit — 'But that was often insufficient time for consumers to act.' Between 2011 and 2020 about 3,500 granted extensions were cancelled, over 2,500 consumers were debited the full loan balance instead of the extension fee, and over $1 million was recorded as remediated on Enova's own representation. The rule appeared in no consumer-facing document: 'The loan extension contract did not inform consumers that Respondent would cancel the loan extension if the consumer made any partial payment on their loan balance before the original due date... and until 2020, neither did the online portal or the confirmation email' — which had told consumers 'You have successfully extended your loan'. The Bureau found the extension conduct both unfair and deceptive on that basis. The same order attributes the 296-consumer self-service due-date harm to two causes at once: 'First, Enova's code failed to register certain consumers' modification of their payment due date. Second, Enova's online portal allowed consumers to select the SSDDA option even if their upcoming minimum payment had already been irreversibly generated.'

EmpiricalThe 2019 order records a correction loop failing at every hop, with dates: 'Consumers first notified Enova abo…

The 2019 order records a correction loop failing at every hop, with dates: 'Consumers first notified Enova about this issue in September 2013. In November 2013, Enova identified a coding error as the source of the problem. It implemented a coding fix in January 2014. When the fix failed ten days later, however, Enova manually disabled it. Enova did not re-enable the fix until May 2014, and did not run daily checks in the interim to ensure that the Flash Cash extension issue had been resolved.' Affected consumers were not told that full loan payments rather than extension fees had been taken from their accounts until April 2015. The 2023 order records the relapse and states the deployment-gate absence directly: after the 2019 order Enova 'continued to obtain consumer bank account information from Lead Generators and launched a project to route its Leads through a newly developed proprietary framework that was intended to, among other outcomes, generate more profitable decisions on extending loan offers to consumers. At the time the new process launched in 2020, no one at Enova had checked to determine whether the new process would overwrite existing consumer bank account information, as it had before.' It did, for 356 consumers, roughly eighteen months after a federal order permanently enjoined that conduct. NOTED AS AN ARGUMENT FROM ABSENCE, with the orders' full text as the evidence: neither the 2019 order nor the 2023 order contains any requirement about code review, change control, regression testing, deployment gating or automated payment-integrity monitoring.

EmpiricalThe 2023 order measures detection latency by channel in its own words. Self-detection where instrumented was f…

The 2023 order measures detection latency by channel in its own words. Self-detection where instrumented was fast: a coding error in August 2019 that caused Enova to debit or attempt to debit 156 CashNetUSA consumers in Idaho one to three times more than they had authorised was self-identified 'within one week of it first occurring', and the 2020 lead-generator relapse was also self-identified. Complaint-driven detection was slow: on the self-service due-date feature Enova 'received complaints about these unauthorized debits relatively soon after the feature began' but 'it took three months for Enova to identify that it was a systemic problem', and on skip statements consumers complained 'in the first weeks' and 'it took Enova four months'. Complaint-driven detection could fail entirely: on the third-party debit-card processing issue running from as early as 2013 to 2019, 'Respondent received consumer complaints about this issue, but it treated these complaints as isolated and failed to identify it as a systemic problem impacting 1,378 consumers' — a window of up to six years between an arriving signal and its correct classification, on a defect where the vendor reported a payment as failed when it had in fact succeeded and representatives reprocessed it 'in some cases up to four additional times, until there was no error message'. Enova's own characterization is materially softer and is attributed rather than adopted: it says the 2019 issues 'impacted less than 0.2% of total payments processed', that they were 'identified and self-disclosed to the CFPB in 2014', that the 2023 matters 'resulted from unintended computer and system errors', and that 'the majority of items were self-reported by Enova to the CFPB'. The orders record self-identification expressly for two classes and find the opposite on the vendor issue. Neither the vendor nor any lead generator is identified anywhere in the record.

enovainternational2019GroundingVendorSave

Enova International, Inc. (2019, January 25). Form 8-K Exhibit 99.1: Enova Reaches Agreement with CFPB for Consumer Loan Payment Processing Errors, filed with the U.S. Securities and Exchange Commission (the operator's own investor-relations posting of the same release returns HTTP 403 to automated fetches; this filed exhibit is the verified copy) https://www.sec.gov/Archives/edgar/data/1529864/000114420419002835/tv511629_ex99-1.htm

https://www.sec.gov/Archives/edgar/data/1529864/000114420419002835/tv511629_ex99-1.htm

Grounds: model org: enova_lending_servicing_defects

EmpiricalThe 2023 order built a control stack far richer than the 2019 order's and terminated early. It required a Comp…

The 2023 order built a control stack far richer than the 2019 order's and terminated early. It required a Compliance Plan within 90 days with dated implementation steps and a mechanism for apprising the Board of progress; gave the Board 'the ultimate responsibility for ensuring that Respondent complies with this Consent Order' and required the Chief Executive Officer, with the Board, to review all plans, reports and submissions before they went to the Bureau and to authorise corrective actions; required a sworn Compliance Report at one year; required an unaffiliated qualified third-party consulting firm retained within 60 days to determine from Enova's business records whether redress had reached all Affected Consumers, with the Enforcement Director holding non-objection over the firm AND over its sampling protocol with a revise-and-resubmit loop, and a Redress Plan where gaps were found; imposed a seven-year ban on Covered Loans and a ban on using or selling the associated consumer information; and required, first of its kind in Bureau practice, that executive compensation agreements taking effect after the order consider the actions the executive took to ensure compliance, with an annual Executive Compensation Report to the Bureau. Self-provided remediation across the enumerated defect classes sums to roughly $3.8 million, recorded in the orders as Respondent's own representations, against penalties of $3.2 million and then $15 million. On 2 September 2025 the Bureau terminated the order — written to run to at least November 2030 — reciting that the penalty had been paid, the consultant retained, further redress provided to consumers 'whom the third-party consultant determined had not previously received complete redress', and steps taken to implement the conduct provisions, and then stating: 'the Bureau hereby terminates this Consent Order. The Bureau also waives any alleged non-compliance by Enova with the Consent Order.' Enova reports the termination as 'Effective August 29, 2025'. The Covered Loans ban and the executive-compensation provision fell with the order roughly five years early, and a waiver of alleged non-compliance is not a finding of compliance. Enova's own stated remedial steps are architectural: centralised payment processing implemented in 2021, enhanced processes to identify and address customer impacts quickly, and sunsetting its single-payment product in 2022.

consumerfinancialprotectionb2025dGroundingGovernmentSave

Consumer Financial Protection Bureau (2025, September 2). Order Terminating the Consent Order, In the Matter of Enova International, Inc., File No. 2023-CFPB-0014 (Document 3, 2 pages) https://files.consumerfinance.gov/f/documents/cfpb_enova-international-2023_termination-consent-order_2025-09.pdf

https://files.consumerfinance.gov/f/documents/cfpb_enova-international-2023_termination-consent-order_2025-09.pdf

Grounds: model org: enova_lending_servicing_defects

EmpiricalThe layer neither consent order examines is the one Enova markets, and every statement about it here is the op…

The layer neither consent order examines is the one Enova markets, and every statement about it here is the operator's own, taken from its Annual Report on Form 10-K for the fiscal year ended 31 December 2025 and attributed rather than adopted. Enova describes 'a fully integrated decision engine that evaluates and rapidly makes credit and other determinations throughout the customer relationship, including automated decisions regarding marketing, fraud, underwriting, customer contact and collections that leverage artificial intelligence and machine learning-enabled models', states that the engine 'currently handles more than 100 algorithms and over 1,000 variables', reports approximately 90 data and analytics professionals supporting it, and says its fraud models identify fraudulent applications 'with a very low false positive rate' — a rate Enova does not publish and no regulator has measured. The same filing states the release posture: 'Our software development life cycle is rapid and iterative to increase the efficiency of our platform,' with integration systems designed to 'launch new products rapidly, modify our business operations quickly and account for complex regulatory requirements imposed in the jurisdictions in which we operate.' No regulator, court or auditor has examined the decision engine, and nothing in that description appears in either consent order; no claim about model quality, disparate impact or the false-positive rate is made here. The filing also supplies the operating scale: approximately $7.8 billion in credit or financing extended in 2025, consumer lending in 37 US states plus Brazil, small-business financing in 49 states and the District of Columbia, 1,836 employees, and information collected from nearly 100 million credit reports during 2025. As of July 2026 a coalition of 20 state attorneys general had urged the Federal Reserve to reject Enova's approximately $369 million acquisition of Grasshopper Bank on the ground that nonbank acquisition of banks would let high-cost lenders bypass state usury caps; that is advocacy and a pending application, not a finding.