Financial services is one of the most heavily regulated industries in the United States, so it makes sense that it’s the most data-rich regulated source as well.
Every bank and credit union in the United States files detailed quarterly financials publicly. Every registered investment adviser discloses its assets, clients, and disciplinary history publicly. Every consumer complaint against every financial company is published daily. Every enforcement action lands on the public record the day it is issued.
Data is not hidden or locked up or fragmented. It’s sitting out on federal agency sites with free APIs, bulk downloads, often with no authentication required.
Which is why it’s kinda insane when GTM teams completely ignore all. The standard buy list, filter job title, add intent data, run ABM, somehow survives. Someone says, “Hey, you guys! A bank might be in-market for compliance software! Let’s sequence them!”
NARRATOR: THE BANK WAS NOT IN-MARKET FOR COMPLIANCE SOFTWARE
We’ve ranked these public data sources by how much of an edge they give you over other vendors competing for the same budget in the inboxes of finserv leaders.
Every national bank, state member bank, and insured nonmember bank files a Report of Condition and Income called the Call Report every quarter. The Uniform Bank Performance Report turns that into performance ratios with peer comparisons. This is the financial X-ray of every bank in America, filed publicly and quarterly, going all the way back to 1992 via the FDIC BankFind Suite’s free API. Data include:
Balance sheet and income statements by quarter
Loan portfolio by category and delinquency bucket
Capital ratios, net interest margin, and efficiency ratio
Deposit composition and funding mix
Branch-level deposits via the annual FDIC Summary of Deposits (openings, closings, deposit flows)
The pain is in the numbers. The numbers are public. You just have to go get them:
FFIEC CDR · FDIC BankFind Suite · API docs · Bulk downloads
The credit union parallel to the bank Call Report, and in one way, it goes further: the Profile (Form 4501A) hands you the non-financial layer for free. Branch locations, member services, and the names of senior management and volunteer officials, all in the same quarterly package.
That combination of a distress signal and a named executive contact in a single public source is rare. In almost every other data source in this vertical, you get the signal or the contact. The NCUA gives you both. Data include:
Net worth ratio, delinquency, ROA, and loan and share growth
Membership trajectory
Named senior management and volunteer officials
Branch locations and member service offerings
NCUA Credit Union Call Report Data
When a regulator finds a problem, it issues a public enforcement action. A consent order is not a soft signal. It is a legal mandate to remediate a specific problem by a specific deadline, and it is public the day it lands.
The OCC, Federal Reserve, FDIC, NCUA, and CFPB all maintain searchable public databases of their actions. This is the strongest forced-buying trigger in the entire vertical. An institution subject to a BSA/AML consent order must fix the problem. The question is not whether they are buying. It is who reaches them first.
That said, it is a trailing indicator; The pain has already materialized. Which means you do not have to convince anyone they have a problem. You just have to prove you already know what it is. Data per action:
Institution name and regulator
Action type (consent order, civil money penalty, cease-and-desist)
The conduct cited, in plain language
Dates, penalty amounts, and remediation terms
OCC enforcement actions · FDIC enforcement decisions · NCUA enforcement actions · CFPB enforcement actions
A live, public record of consumer complaints against financial companies. Over 13.8M complaints since 2011, updated daily. When a consumer submits a complaint, it is published after the company responds or after 15 days, whichever comes first. The consumer can include their own narrative. That narrative is public.
This is the closest thing to real-time consumer pain in any regulated industry. A spike in complaints about one product at one institution is a dated, quotable, public pain signal. GTM teams should be watching it.
A note for 2026: the CFPB’s enforcement posture has shifted under current leadership, which can affect how actively the database is maintained and how quickly complaints move through the pipeline. The data is public so treat its cadence as a variable, not a constant. Complaint details include:
Date received
Company name
Product and sub-product
Issue and sub-issue
Consumer narrative text
The company’s public response
State and ZIP code
Timely-response flag and disputed flag
Complaint database · Public API (no key required)
Under the Home Mortgage Disclosure Act, roughly 5,000 financial institutions disclose loan-level mortgage data annually in their Loan Application Registers. In practice, this is every reporting lender’s entire mortgage book, origins, denials, withdrawals, amounts, purposes, and applicant characteristics, filed publicly by March 2 of each year. A lender whose origination volume collapsed year over year, or whose denial rate spiked, is showing distress in their own public filing. You do not have to guess. You can read it. Per loan:
Loan type and purpose
Loan amount
Action taken (originated, denied, withdrawn, incomplete)
Pre-approval status
Property type and lien status
Applicant demographics
The reporting lender
HMDA Data Browser · Downloads and documentation
Every SEC-registered and state-registered investment adviser files Form ADV through the Investment Adviser Public Disclosure site. Part 1 carries the structured business data. Part 2 is the plain-language brochure the firm is required to hand clients. Both are public.
Year-over-year deltas are where this source earns its place: an AUM jump, a new custodian, a shift in client type, a fresh disciplinary disclosure. Change is the signal. Per firm:
Assets under management
Number and type of clients
Employee count
Custody arrangements and fee structure
Ownership and control persons
Disciplinary disclosures
IAPD search · Bulk Form ADV data files
The broker-dealer is parallel to IAPD. BrokerCheck, built on FINRA’s Central Registration Depository, covers brokerage firms and registered representatives with registration history, disclosures, and disciplinary record. Many professionals are dually registered, so BrokerCheck and IAPD are read together rather than separately.
Registration churn and disciplinary disclosures at a firm are pain and change signals for compliance, supervision, and wealthtech offerings. Most useful when velocity is the signal: not one disclosure, but a pattern of them over a twelve-month window.
Bank and credit union mergers require public applications to regulators before they close. Bank holding companies file the FR Y-9C with the Federal Reserve. Both reveal structural change before it is complete (and before any RFP is written).
A pending merger means a core conversion, a system integration, and a compliance harmonization are all coming, on a known timeline. That is a bundle of fresh, datable pressure. And unlike most triggers, it comes with a public document describing exactly what is about to happen. Per merger application:
Acquirer and target
Transaction structure
Regulatory approval status and timeline
Fed National Information Center · FDIC merger applications
Most states require breach notifications to be filed with the state attorney general when a company suffers a qualifying incident, and several also require publication. Financial firms are among the most frequent filers.
A breach disclosure is a dated, public, high-urgency pain signal for anyone selling security, compliance, incident response, or cyber insurance to financial institutions. Format and availability vary by state. Some states, like California, publish a searchable list; others require records requests. Mark as verify-by-state before building a workflow around it.
Search for data breach notifications + state.
Example: California AG breach list
The Nationwide Multistate Licensing System publishes mortgage company and loan-originator licensing through its Consumer Access site. License classification, status, and branch locations are all visible.
On its own, it is a denominator, not a trigger. Many licensed lenders have not originated a loan in months. Use it to validate and classify. Do not use it to trigger. Best paired with HMDA data to separate active lenders from dormant licensees.
Insurers file statutory financial statements with state regulators and the NAIC, and states run market-conduct examinations and publish consumer complaint data through the NAIC complaint index.
For insurtech, a complaint-index outlier or a market-conduct finding is a real pain signal. The data is harder to assemble uniformly than the banking equivalents (availability, format, and refresh rate vary by state and line of business) which is why it sits lower on the list. Verify coverage before promising it.
NAIC Consumer Insurance Search
Banks, credit unions, and fintechs broadcast their pressure in their hiring. A burst of BSA/AML analyst, fraud, compliance officer, or risk management reqs is pain in motion. The job descriptions often specify the system they use, the gap they aim to fill, and the volume they manage.
This is the highest-asymmetry unstructured source in the vertical and a strong leading indicator. Most valuable when it confirms a structured signal: an enforcement action plus a sudden BSA-officer search is a richer combination than either alone.
Indeed and LinkedIn Jobs
Public banks, insurers, fintechs, and payment companies disclose strategy, risk factors, capital plans, and segment results in 10-Ks, 10-Qs, and 8-Ks. Only the public slice of the market files, and Call Reports already cover banking financials in greater detail. Most useful for the large public names and for risk-factor language, you can quote back in an opening line.
Free, full-text searchable, API-accessible.
In financial services, the asymmetry is in plain sight, and almost nobody selling into the industry is using it.
Here are five recipes, ranked by the edge they create. Each one combines public sources into a specific dish: a pain-based segment plus a message angle no competitor can match, because no competitor has crossed the same data.
(Note - the messages are purely samples meant to give you an idea of what’s possible at the most basic level and are not up to PVP/PQS standards.)
Apron on. Let’s cook.
The Dish: An institution under a fresh regulatory order with a remediation deadline, scrambling to comply.
Ingredients: A regulatory enforcement action or consent order (the conduct, the deadline, the penalty) + the institution’s Call Report or 5300 (its size and the specific deficient area) + job postings (a sudden BSA officer or compliance-staff hiring burst).
Indicator Type: Trailing on the order, leading on the remediation.
Target Segment: AML/BSA and compliance regtech, risk consulting, audit and monitoring software, managed services for remediation.
The Asymmetry: You know the exact order, the deadline, and the conduct cited so you can see they are already trying to hire their way out of it (and before any vendor in your category has picked up the phone. The institution is not “evaluating options.” It is legally required to fix a named problem by a named date.
The Message: “I saw the OCC consent order from [date] and the BSA/AML findings and the [X]-month remediation window. I also noticed you’ve posted three BSA analyst roles in the last six weeks. We work with institutions in exactly this situation. Worth a conversation?”
The Dish: An institution with a public, escalating consumer-pain problem in one specific product line.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.