Bank-Fintech Partnership Compliance Oversight: What Regulators Expect

How sponsor banks supervise fintech and BaaS partners: third-party risk expectations, who owns BSA/AML, ledger access, and oversight cadence.
Alexandre Berkovic

TL;DR: Bank-fintech partnership compliance oversight is the governance, monitoring, testing, and recordkeeping a chartered bank maintains over the fintech and middleware partners that deliver its products to end users. The June 2023 Interagency Guidance on Third-Party Relationships states that using third parties does not diminish a banking organization's responsibility to operate safely and soundly and comply with the law. Klaros Group found that fintech partner banks faced a 9% to 15% probability of a formal enforcement action between the first quarter of 2023 and the first quarter of 2024, against 1.8% for banks without fintech programs.

The Charter Carries the Obligation

Flow diagram showing a transaction passing from End User through Fintech and Middleware to the Bank that holds the charter
A single end-user transaction can pass through the fintech and one or more middleware providers before reaching the bank that holds the charter.

Bank-fintech partnership compliance oversight refers to the controls a chartered bank uses to supervise the third parties that originate, service, or distribute its products — the fintech that owns the customer relationship, the program manager or middleware provider that maintains the system of record, and the processors behind them. The bank sets the risk parameters. The bank answers for the outcomes.

The structure explains why oversight is hard. In a typical Banking-as-a-Service arrangement, the end user downloads a fintech's application, passes an onboarding flow the fintech designed, and holds a balance that legally sits in a pooled custodial account at the bank. The July 2024 interagency joint statement notes that banks often rely on intermediaries — platform providers, processors, middleware, program managers — to maintain the deposit and transaction system of record, process payments, perform compliance functions, and resolve disputes. Four or five entities can touch a single transaction. One of them holds the charter.

That distinction drives everything else. Most fintech partners are not subject to bank-level BSA obligations, and those registered as money services businesses carry materially lighter requirements than an insured depository institution. A partnership agreement can allocate who performs a function and who indemnifies whom when it fails. It cannot move the statutory obligation off the bank. The bank's BSA officer remains accountable for every end user onboarded through every partner, which makes partner-originated customer due diligence an extension of the bank's own program rather than a vendor deliverable. Regulators read through the contract to the practice.

Why the Oversight Bar Moved

Three developments raised the supervisory baseline. The first consolidated the rules. On June 6, 2023, the Federal Reserve, FDIC, and OCC issued final joint guidance on third-party risk management, replacing each agency's separate prior guidance and organizing expectations around five lifecycle stages: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. The guidance scales expected oversight to the criticality of the activity. Fintech programs that deliver deposit accounts and move payments under the bank's charter sit at the top of that scale.

The second catalogued what had gone wrong. On July 25, 2024, the agencies issued a joint statement on third-party deposit arrangements alongside a request for information on bank-fintech arrangements. The statement created no new supervisory expectations. What it did was enumerate the failure patterns examiners had observed: operations fragmented across third parties in ways that obscured who performed what; insufficient bank access to the deposit and transaction system of record, impairing the bank's ability to determine its own deposit obligations; reliance on third parties for suspicious activity monitoring, customer identification, and sanctions screening; weak audit scope; and partner incentives skewed toward growth rather than control.

The third was enforcement. Klaros Group calculated that from the first quarter of 2023 through the first quarter of 2024, a fintech partner bank's odds of a formal enforcement action ran to 15% under the FDIC, 10% under the OCC, and 9% under the Federal Reserve, against 1.8% for the 4,406 banks without fintech programs. Across those actions, findings cluster around BSA/AML program deficiencies, third-party risk management weaknesses, consumer protection problems, and board oversight gaps.

The June 14, 2024 Federal Reserve action against Evolve Bancorp and Evolve Bank & Trust shows the pattern. Examinations conducted in 2023 found the bank had engaged in unsafe and unsound banking practices by failing to have an effective risk management framework for its fintech partnerships, along with AML and consumer compliance deficiencies. The order required enhanced recordkeeping, written policies to monitor risks associated with each individual partner and program, and board approval in writing before onboarding new partners. None of that is exotic. It describes oversight infrastructure examiners probe during any BSA examination of a community bank, applied to a customer base the bank never met directly.

What Examiners Actually Test

Oversight is assessed on evidence, not intent. A bank that can produce dated testing results, reconciliation exceptions with resolution notes, and board minutes documenting partner-level risk decisions sits in a different position than one holding a contract and a questionnaire. Five areas carry most of the examination weight.

Who Performs Onboarding, and Who Signs Off

End-user identity verification usually happens inside the fintech's application, using the fintech's vendors. The bank's customer identification program still governs it. That means the bank approves the onboarding rules, receives the underlying verification records rather than a pass/fail summary, and samples partner-originated decisions to confirm the documented standard is the applied standard. Beneficial ownership collection on fintech-onboarded business entities must reach the same evidentiary standard the bank applies to accounts it opens in a branch.

Monitoring Tuned to the Program, Not the Bank

Transaction monitoring calibrated to a community bank's commercial deposit base will not detect risk in a payments program moving high-velocity, low-value transfers. Each partner program needs scenarios and thresholds reflecting its own product, geography, and customer profile, and the bank needs visibility into how those monitoring rules were derived and tuned. Alert disposition can be performed by partner or outsourced staff. SAR decisioning cannot be delegated — the filing decision, the narrative, and the supporting file belong to the bank's BSA officer.

Ledger Access and Reconciliation

The 2024 joint statement singles out lack of access to records as a distinct risk, because a bank that cannot independently reconcile pooled custodial balances to end-user sub-ledgers cannot determine what it owes and to whom. The Synapse collapse in 2024 turned that abstraction into frozen consumer accounts. Adequate controls mean the bank receives sub-ledger data on a defined cadence, reconciles it against its own core, documents exceptions, and holds contractual rights to the data and to its transfer if the partner fails. Reconciliation is a compliance control as much as an operational one, since unexplained variances defeat any attempt to reconstruct a customer's transaction history.

Independent Testing on a Risk-Based Cadence

Ongoing monitoring under the interagency guidance is continuous rather than annual. In practice, the bank independently tests whether each partner operates inside the agreed compliance parameters: sampling partner-originated transactions for BSA/AML and consumer compliance, reviewing disclosures and marketing, analyzing complaint data, and validating that the partner's own vendors perform as represented. Quarterly or more frequent testing fits high-volume programs. The contractual right to require independent third-party audit is what makes this enforceable.

Complaints, Fourth Parties, and Exit Planning

Complaints arrive at the fintech and often never reach the bank, which breaks two things at once: the bank loses its earliest signal of systemic problems, and it risks missing dispute investigation timeframes it is legally obligated to meet. Downstream dependencies carry a similar visibility problem. Banks are not expected to supervise every subcontractor directly, but they are expected to know the dependencies exist and to judge whether their partner's oversight is adequate. Termination planning closes the lifecycle with a tested plan for transferring accounts and data if the partner fails.

Function Commonly performed by Accountable to the regulator
End-user identity verification Fintech, using its own vendors Bank
Transaction monitoring and alert review Fintech, program manager, or bank Bank
SAR decisioning and filing Bank BSA officer Bank
Sanctions screening Fintech, middleware, or bank Bank
Deposit and transaction system of record Program manager or middleware provider Bank
Complaint intake and dispute resolution Fintech customer support Bank
Independent program testing Bank internal audit or external firm Bank

The right-hand column never changes. That is the supervisory point, and it explains why banks that treat partner oversight as vendor management rather than as an extension of their own program keep drawing the same findings.

What the Fintech Has to Supply

Fintechs experience this as a diligence burden that keeps growing after the deal closes. The programs that clear sponsor scrutiny fastest treat the bank as a standing supervisor rather than a counterparty, and they build the evidence pipeline before anyone asks for it. A partner-ready package generally includes:


     

     

     

     

     

     

     

     


The tension is that a small team has to produce this evidence continuously while volume grows. Documentation lags first, quality follows, and the gap surfaces during an examination rather than in a monthly report. Fintechs that automate the routine review and documentation work rather than staffing it linearly are the ones whose compliance infrastructure holds up as the program scales.

Where Sphinx Fits

Sphinx operates at the investigation and documentation layer of partner programs, working inside the systems banks and fintechs already use. Agents review onboarding cases, triage monitoring alerts, gather evidence, and record dispositions with the reasoning attached, producing the kind of file a sponsor bank's testing team or an examiner can review independently. Where oversight failures are documentation failures at heart, that auditable decision trail is the part that has to hold under scrutiny.

Frequently Asked Questions

Who is responsible for BSA/AML compliance in a bank-fintech partnership?

The chartered bank. The June 2023 Interagency Guidance on Third-Party Relationships states that a banking organization's use of third parties does not diminish its responsibility to operate safely and soundly and comply with applicable laws. A fintech can perform compliance functions under the bank's program, and the contract can allocate cost and indemnification, but the statutory obligation stays with the bank.

Can a fintech perform KYC on the bank's behalf?

Yes, and most do. The bank's customer identification program still governs the standard, so the bank must approve the onboarding rules, receive the underlying verification records rather than summary outcomes, and independently sample partner-originated decisions to confirm the documented standard matches what is applied.

What does the 2023 interagency third-party risk guidance require?

The guidance sets out risk management expectations across five lifecycle stages: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. It is principles-based rather than prescriptive, scaling expected oversight to the criticality of the activity. Fintech programs delivering deposit and payment products under a bank's charter are generally treated as critical activities.

Why do sponsor banks need direct access to the fintech's customer ledger?

Without independent access to the sub-ledger, a bank cannot reconcile pooled custodial balances to individual end users, which means it cannot determine its own deposit obligations. The July 2024 interagency joint statement names lack of access to records as a distinct risk, noting that such uncertainty can delay end users' access to their funds.

How often should a sponsor bank test its fintech partners' compliance?

Testing frequency should be risk-based, with quarterly or more frequent transaction sampling for high-volume or higher-risk programs. Annual review alone does not satisfy the ongoing monitoring expectation in the interagency guidance, which contemplates monitoring sufficient to detect issues in time to address them.

Get Your Free AI Compliance Handbook

What compliance leaders need to know about AI-driven fraud, autonomous laundering, and how your team can
fight back.
Submit
Thank you! Your submission has been received!
Something went wrong while submitting the form. Please try again.