Abstract editorial illustration for this guide

This guide is general legal information, not legal advice, and does not create an attorney–client relationship. Rules change and vary by state — verify current requirements with official sources or a licensed attorney.

Most fintech products that look like banking — debit cards, deposit accounts, payment apps, lending programs — run on a partnership: a chartered bank supplies the regulated infrastructure, and a fintech supplies the customer experience. Regulators allow this model, but on one non-negotiable condition. The bank remains fully responsible for the activities performed through it, exactly as if it performed them itself.

That single principle explains almost everything about how these deals are structured. Because the bank cannot delegate its regulatory responsibility, it pushes obligations onto the fintech through contract, monitors the fintech like an examiner would, and reserves the right to shut the program down. Understanding that flow-down — what the regulators expect of banks, and therefore what banks demand of fintechs — is the core skill in negotiating and operating these partnerships.

Key takeaways

  • The OCC, Federal Reserve, and FDIC issued unified third-party risk management guidance in June 2023 covering the full life cycle of a bank's relationships, including fintech partners.
  • A July 2024 joint statement flagged specific risks in deposit-focused bank–fintech arrangements, from misleading deposit-insurance marketing to fragile ledgering by intermediaries.
  • The 2024 Synapse collapse — where account records held by a failed intermediary left end users unable to access funds — pushed the FDIC to propose custodial-account recordkeeping rules.
  • Program agreements allocate compliance work through audit rights, data ownership, BSA/AML duties, subcontractor controls, and wind-down plans; these clauses determine who absorbs the pain when something breaks.
  • Fintechs should expect bank-grade oversight — due diligence questionnaires, ongoing reporting, and examiner access — as the price of admission.

Why regulators tightened their focus

Banking-as-a-service grew faster than the controls around it. Supervisors began finding programs where the bank had limited visibility into who its end customers were, marketing that blurred the line between the insured bank and the uninsured fintech, and reconciliation gaps between the bank's books and the fintech's ledger. The stress case arrived in April 2024, when middleware provider Synapse filed for bankruptcy: end users of multiple fintech apps were locked out of funds held at partner banks because the authoritative record of who owned what sat with the failed intermediary.

Three months later, the federal banking agencies issued a joint statement on third-party deposit arrangements, paired with a request for information on bank–fintech arrangements generally. The message: the model is permitted, but the agencies had seen enough weak practice to spell out their concerns in writing.

The 2023 interagency guidance: one framework for every partner

The foundational text is the Interagency Guidance on Third-Party Relationships: Risk Management, finalized in June 2023. It replaced each agency's separate guidance with a single risk-based framework applying to all banking organizations and all third-party relationships — vendors, fintechs, and everything between. Two of its themes matter most for fintech deals.

First, proportionality: oversight should scale with the risk and criticality of the relationship, and a fintech that touches customer funds or customer-facing compliance is near the top of that scale. Second, life-cycle thinking: risk management is not a one-time diligence exercise but a sequence of stages, each with expected practices. Banks build their vendor-management programs around these stages, so fintechs experience them as the rhythm of the relationship:

  1. Planning. The bank defines the strategic purpose, risk appetite, and exit expectations before it ever signs.
  2. Due diligence and selection. Financial condition, compliance program maturity, information security, operational resilience, and management background all get reviewed — expect document requests measured in the hundreds.
  3. Contract negotiation. Supervisory expectations are converted into enforceable terms; this is where the flow-down happens.
  4. Ongoing monitoring. Reporting packages, complaint data, compliance testing, periodic audits, and annual reviews continue for the life of the program.
  5. Termination. Wind-down and portability plans ensure customers are not stranded if either side exits.

The contract terms that carry the weight

Program agreements are long because they are doing regulatory work. When negotiating, both sides should pressure-test the clauses below — they decide who pays, who fixes, and who explains to the examiner. General drafting principles for high-stakes agreements are covered in our article on the contract clauses that control risk; these are the partnership-specific ones:

  • Compliance responsibility matrix. A section-by-section allocation of who performs KYC, transaction monitoring, disclosure delivery, complaint handling, and error resolution — with the bank retaining oversight of all of it.
  • Audit and examination rights. The bank (and its regulators) get access to the fintech's records, systems, and premises; the guidance effectively requires it.
  • Data ownership and portability. Who owns customer records, in what format they exist, and how fast they transfer on termination — the exact issue Synapse turned into a crisis.
  • Ledger and reconciliation standards. Frequency of reconciliation between fintech subledgers and bank accounts, and what happens when they disagree.
  • Subcontractor (fourth-party) controls. Approval rights and flow-down obligations for the fintech's own critical vendors.
  • Marketing approval and insurance representations. Pre-approval of customer-facing materials, especially any statement about FDIC insurance.
  • Reserves, indemnities, and termination triggers. Financial cushions for losses and fines, and the bank's right to suspend onboarding or exit on compliance failures.
  • Wind-down plan. A tested route for migrating or returning customer funds and data if the program ends, voluntarily or not.

Deposits, insurance, and the custodial-account problem

Most BaaS programs pool end-user funds in custodial "for benefit of" (FBO) accounts at the bank. Pass-through deposit insurance can protect each end user up to the standard limit, but only if ownership records adequately identify each owner and their balance. When the authoritative ledger lives at a nonbank intermediary and that intermediary fails, proving who owns what becomes slow and contested.

In response, the FDIC proposed a rule in September 2024 — published in the Federal Register that October as Recordkeeping for Custodial Accounts — that would require banks holding custodial deposit accounts with transactional features to maintain, in a standardized format, records identifying each beneficial owner and balance, even when a third party keeps the day-to-day ledger. Check the FDIC's site for the proposal's current status before relying on it, but its direction of travel is already the market's expectation: banks increasingly demand direct, continuous access to program ledgers rather than trusting periodic reports.

Watch the marketing: The July 2024 joint statement singled out misrepresentation of deposit insurance. A fintech is not FDIC-insured; its partner bank is. Customer-facing copy must say precisely that — including when insurance applies (bank failure, not fintech failure) — and FDIC rules restrict misuse of the FDIC name and logo.

Compliance workstreams neither side can skip

Beyond deposits, the recurring workstreams in a partnership map to familiar regulatory regimes. Anti-money-laundering duties — customer identification, monitoring, suspicious-activity reporting — remain the bank's legal obligation even when the fintech runs the front end, a division of labor explored in our AML and KYC compliance primer. Consumer-protection exposure, including unfair or deceptive practices in marketing and fees, reaches both parties, as discussed in our piece on UDAAP enforcement risk. And security expectations flow down hard: banks will test a fintech's safeguards program against the standards described in our guide to fintech data privacy and cybersecurity.

Fintechs should also confirm which activities the partnership actually covers. Operating through a bank does not automatically eliminate state licensing questions for money flows the fintech handles itself — the broader jurisdictional picture is mapped in our U.S. fintech regulatory map.

Frequently asked questions

Does the 2023 interagency guidance apply directly to fintechs?

No — it is guidance to banking organizations. But its practical effect reaches fintechs immediately, because banks implement it through due diligence demands, contract terms, and ongoing monitoring. A fintech that cannot satisfy those expectations will struggle to sign or keep a partner bank.

Are end-user funds in an FBO account FDIC-insured?

They can be, on a pass-through basis, if the requirements are met — including records that identify each owner's interest. Insurance protects against the bank's failure, not the fintech's. If the fintech or a middleware provider fails while holding the authoritative ledger, users may face delays even though the bank is sound.

Who gets penalized when a program violates consumer law?

Potentially both parties. Banking agencies act against the bank, and enforcement actions in this sector routinely require banks to strengthen partner oversight. The CFPB, FTC, and state attorneys general can proceed against the fintech directly. Contracts then reallocate costs through indemnities — which is why those clauses are fought over.

How long does it take to launch with a partner bank?

Materially longer than it used to. Between deeper due diligence, compliance build-out, and bank-side approvals, timelines of six months to a year from term sheet to launch are common for deposit or card programs. Fintechs that arrive with a documented compliance program shorten the path considerably.

Preparing for the next review

Whichever side of the table you sit on, assume the relationship will be examined — by the bank's regulators, by auditors, or by a court after a failure. Keep the responsibility matrix current as the product evolves, reconcile ledgers on a schedule you could defend publicly, rehearse the wind-down plan before you need it, and re-run partner due diligence annually rather than filing it away. Partnerships built to that standard have a way of never becoming case studies.

Sources & further reading

Accord Legal Review Editorial Team

Accord Legal Review is an independent publisher of U.S. legal guides. Our editorial organization researches primary sources — statutes, regulations, and official agency guidance — and keeps volatile figures pointed at the live official source. Read our editorial standards.