Feature Third-Party Risk
Fourth-Party Risk After Synapse: What OCC and FDIC Now Expect from Your Subcontractor Oversight Program
Synapse collapsed and 100,000+ customers lost access to $265M in deposits they thought were FDIC-insured. The cause wasn't fraud — it was middleware risk nobody was watching. Here's what OCC and FDIC now expect from your fourth-party and subcontractor oversight program.
Table of Contents
Synapse filed for Chapter 11 bankruptcy on April 22, 2024. Over the next few weeks, more than 100,000 customers found themselves locked out of roughly $265 million in deposits they believed were FDIC-insured. Accounts at Yotta, Juno, and Copper were frozen. Customer service lines went quiet. The trustee reported a reconciliation gap of up to $95 million between bank-held funds and amounts owed to fintech end users.
The companies that failed those customers had sponsor bank relationships. They had third-party risk programs. Some had written agreements with indemnification clauses and audit rights. None of it helped.
Synapse wasn’t a third party to most affected fintechs — it was a fourth party. Yotta contracted with sponsor banks. Those banks used Synapse as middleware. Synapse failed. The money disappeared into a ledger nobody could reconcile.
That’s the fourth-party risk problem in its most concrete form.
TL;DR
- Synapse was a fourth-party failure: fintechs contracted with banks, banks depended on Synapse, Synapse’s ledger collapsed — and $265M in customer deposits were frozen
- July 2024 joint statement from OCC, FDIC, and Fed tightened what banks must demonstrate about direct oversight of fintech partners and middleware dependencies
- 26% of financial institutions still don’t assess fourth-party risk at all, per the 2026 Ncontracts TPRM Survey
- OCC and FDIC examiners are now specifically reaching past your vendor list to ask about critical subcontractor dependencies
- The AI supply chain adds a new fourth-party layer most programs haven’t mapped yet
- The minimum examiner expectation: know who your critical vendors depend on, document it, and contract for notification rights if that changes
What Fourth-Party Risk Actually Means
Your TPRM program covers vendors you directly contract with. Fourth-party risk is the risk created by your vendors’ vendors — the subcontractors, cloud platforms, data providers, and technology dependencies that sit one layer beneath your vendor relationships.
You don’t have a contract with fourth parties. You can’t audit them directly. You often don’t know they exist. But if they fail, the disruption flows through your vendor to your operations and your customers.
This is not theoretical risk. It’s the exact failure mode the Synapse collapse exposed:
- Bank (third party to fintech customers): Evolve Bank, AMG National Trust, Lineage Bank
- Middleware (fourth party — vendor to the banks, invisible to fintech customers): Synapse Financial Technologies
- Fintechs (customer-facing, dependent on banks, dependent on Synapse): Yotta, Juno, Copper
When Synapse’s ledger systems failed, no single institution had an authoritative record of which customer was owed which dollars. The resulting reconciliation gap locked customers out for months.
The interagency TPRM guidance — OCC Bulletin 2023-17 and the parallel FDIC FIL-29-2023 — explicitly requires banking organizations to understand their critical vendors’ subcontracting practices as part of due diligence. What Synapse proved is that the concept isn’t academic: middleware concentration risk is real, it’s material, and it can freeze customer funds overnight.
What Regulators Did After Synapse
The regulatory response unfolded in layers.
June 2024 — Evolve Bank cease-and-desist: The Federal Reserve issued a cease-and-desist against Evolve Bank — the largest of Synapse’s partner banks — citing gaps in its BSA/AML program, risk management, and consumer protection. The order made the bank’s supervisory failures explicit: Evolve had relied on Synapse’s representations about ledger accuracy without independently verifying them.
July 25, 2024 — Joint statement on bank-fintech arrangements: The OCC, Federal Reserve, and FDIC issued a joint statement addressing what they’d observed in BaaS and bank-fintech structures. Key messages:
- Banks cannot delegate compliance obligations to fintech partners or middleware providers
- Oversight capability must be real and exercisable, not just contractual
- Concentration risk needs board-level visibility
- Banks must be able to wind down fintech programs without harming customers
October 2024 — FDIC custodial accounts rule: The FDIC proposed formal rulemaking requiring banks that hold custodial deposits for fintech programs to maintain their own beneficial owner ledgers — not rely on middleware providers to do it. The rule directly targets the Synapse failure mechanism: pooled FBO accounts where nobody had an authoritative, current record of which end user was owed what.
Each of these actions carries the same underlying message: the bank owns the risk, regardless of how many layers of technology sit between the bank and the end customer.
What Examiners Are Now Checking
Three years into the interagency TPRM guidance, examinations have shifted from checking whether a program exists to checking whether it actually functions. For fourth-party risk specifically, examiners are reaching deeper than the vendor list.
For critical activity vendors, examiners now expect documentation of:
-
Subcontractor identification — Who are the critical subcontractors your core processor, payment platform, and key technology vendors depend on? Not a complete list of every sub-vendor, but the ones that are material to service delivery.
-
Dependency mapping — What does each subcontractor do in the chain? If the subcontractor failed, what’s the impact to your operations?
-
Risk indicators — Are there any known concerns about the subcontractor’s financial health, security posture, or regulatory standing?
-
Notification rights — Does your contract with the vendor require them to notify you if a critical subcontractor changes, fails, or is acquired?
The practical minimum examiners accept is documented evidence that you asked the right questions and got answers. Not a full due diligence workup on every sub-vendor — but enough to show you’ve mapped the dependency and thought through the failure scenario.
For BaaS and bank-fintech relationships specifically, examiners are checking whether banks have exercised their oversight rights, not just whether those rights exist on paper. A contract that gives the bank audit rights over a fintech partner is meaningless if the bank has never used them. Examiners want to see evidence of independent review: internal team visits, third-party assessments, reconciliation testing, or at minimum documented attempts to verify the fintech’s representations.
For a deeper look at what examiners are finding in first-tier TPRM programs, our 2026 TPRM Examination Findings analysis covers the full gap inventory.
The AI Supply Chain Problem
Traditional fourth-party risk mapping was hard enough when vendors were using identifiable subcontractors with SOC 2 reports. The AI supply chain makes it significantly harder.
When a vendor embeds a large language model — GPT, Claude, Gemini, or a third-party foundation model — into their product or internal operations, that model provider becomes your fourth party. You likely have:
- No visibility into the model provider’s data handling practices or security posture
- No contractual relationship giving you notification rights if the model provider changes
- No assessment of what happens to your vendor’s product if the foundation model is deprecated or breached
- No documentation of where your data goes when it’s processed by that model
According to Treasury’s AI risk management guidance, AI dependency monitoring is a distinct risk domain that traditional vendor risk programs weren’t designed to surface.
The interagency TPRM guidance’s subcontracting disclosure requirement applies directly: when a critical vendor uses AI models from third-party providers, those providers fall within the definition of subcontractors the guidance requires you to assess. Your vendor questionnaire and ongoing monitoring protocol need to surface this.
This connects to the broader cloud concentration risk problem our cloud provider concentration risk analysis covers — when multiple vendors in your critical path all depend on the same foundation model provider or cloud region, you have concentration risk several layers deep.
Building a Minimum-Viable Fourth-Party Program
You don’t need a team of analysts to get fourth-party risk management to an examiner-defensible level. The program doesn’t need to be perfect. It needs to be documented, proportional, and evidence-based.
Step 1: Map your critical vendors
Start with your critical activity vendor list. These are the vendors whose failure would materially disrupt your operations, harm customers, or create regulatory exposure. If you don’t have a documented critical activity list, that’s the prerequisite.
Step 2: Ask about their subcontractors
Add a fourth-party risk section to your vendor due diligence questionnaire and annual review. Key questions:
- Who are your critical subcontractors for the services you provide us?
- Which cloud providers do you depend on for service delivery?
- Do you use AI models or foundation models from third parties? Which ones?
- How would you notify us if a critical subcontractor changed, failed, or was acquired?
Step 3: Contract for notification rights
At next renewal for every critical activity vendor, add a clause requiring them to notify you of material changes to critical subcontractors within a defined timeframe (30 days is a common standard). This gives you a documented, contractual mechanism — and something to show an examiner beyond “we asked.”
Step 4: Document what you know and what you don’t
Not all fourth parties will cooperate. Large technology vendors and cloud providers often resist disclosing their full subcontractor footprints. Document the request, document the response (or non-response), and document your assessment of the residual risk from the gaps. An examiner’s concern is whether you’re aware of the exposure — not whether you’ve solved it.
Step 5: Assess concentration
Across your critical vendors, identify whether multiple vendors share the same critical subcontractors — particularly cloud infrastructure providers. If your core processor, payment platform, and lending origination system all run on AWS us-east-1, that’s a concentration exposure your BCP needs to address.
The TPRM Kit includes vendor questionnaire templates with fourth-party sections, subcontractor mapping worksheets, and contract checklist language for subcontractor notification rights — aligned to what the interagency guidance requires and what examiners are checking in 2026.
DORA’s Fourth-Party Mandate: What It Means for US Firms
If your institution has EU customers, EU subsidiaries, or operates within scope of the Digital Operational Resilience Act, the fourth-party obligation is explicit rather than inferred.
DORA requires financial entities to assess ICT third-party risk including all subcontracting arrangements. It mandates that contracts with critical ICT providers include the right to audit subcontractors and receive notification of subcontractor changes. The DORA standard is more prescriptive than the US interagency guidance — but the direction is the same.
For US firms with any EU footprint, DORA’s fourth-party requirements provide a useful template for what the most rigorous version of the program looks like. For the operational resilience and ICT incident reporting dimensions, our DORA first ICT incident report analysis covers what the first wave of DORA incident data revealed about third-party dependencies.
So What?
The Synapse collapse wasn’t a compliance failure in the traditional sense. Nobody misrepresented a SOC 2 report. No vendor contract was violated. The problem was a structural gap: institutions in the BaaS chain relied on middleware they didn’t assess, couldn’t monitor, and had no independent ability to verify — and when that middleware collapsed, the ledger broke.
The 26% of financial institutions that still don’t assess fourth-party risk at all are carrying Synapse-scale exposure without knowing it. The regulators know this. The July 2024 joint statement, the FDIC custodial accounts rule, and the 2026 examination focus on subcontractor mapping are all pointed at the same gap.
You don’t need to audit every sub-vendor. You need to know who the critical ones are, what they do, what happens if they fail, and whether your vendor contracts give you the notification rights to find out when something changes. That’s the examiner’s minimum expectation. Start there.
If you’re building out your fourth-party oversight program and need documentation templates aligned to what examiners are checking, the Third-Party Risk Management Kit includes subcontractor mapping tools, vendor questionnaire modules, and written agreement checklists covering the 14 required contract elements under the interagency guidance.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is fourth-party risk and how is it different from third-party risk?
What did the July 2024 joint statement require for bank-fintech partnerships?
What does the FDIC's October 2024 custodial accounts rule require?
What do OCC and FDIC examiners actually ask about fourth-party risk?
How does AI change fourth-party risk exposure?
What's the minimum viable fourth-party oversight program that satisfies examiners?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
Third-Party Risk Management Lifecycle RACI: Fix the Handoffs Between Procurement, Security, Legal, Business Owners, and Risk
A TPRM lifecycle RACI that assigns clear ownership at each stage — planning, due diligence, contracting, onboarding, monitoring, and offboarding — so findings don't fall between functions.
Jul 24, 2026
Third-Party Risk
Vendor Due Diligence Without a SOC 2: What Evidence Can Actually Substitute
A vendor due diligence checklist for evaluating security evidence when a vendor has no SOC 2 report, with a risk-based substitution matrix.
Jul 23, 2026
Third-Party Risk
Three Vendors, One Existential Risk: What the OCC's Community Bank Core Provider RFI Actually Asked
The OCC published Bulletin 2025-39 asking community banks hard questions about their relationships with Fiserv, FIS, and Jack Henry. The questions reveal exactly what examiners are now checking — and what most TPRM programs haven't addressed.
Jul 23, 2026