Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Third-Party Risk

Fourth-Party Risk After Synapse: What OCC and FDIC Now Expect from Your Subcontractor Oversight Program

Synapse collapsed and 100,000+ customers lost access to $265M in deposits they thought were FDIC-insured. The cause wasn't fraud — it was middleware risk nobody was watching. Here's what OCC and FDIC now expect from your fourth-party and subcontractor oversight program.

By Rebecca Leung · July 20, 2026 ·
Table of Contents

Synapse filed for Chapter 11 bankruptcy on April 22, 2024. Over the next few weeks, more than 100,000 customers found themselves locked out of roughly $265 million in deposits they believed were FDIC-insured. Accounts at Yotta, Juno, and Copper were frozen. Customer service lines went quiet. The trustee reported a reconciliation gap of up to $95 million between bank-held funds and amounts owed to fintech end users.

The companies that failed those customers had sponsor bank relationships. They had third-party risk programs. Some had written agreements with indemnification clauses and audit rights. None of it helped.

Synapse wasn’t a third party to most affected fintechs — it was a fourth party. Yotta contracted with sponsor banks. Those banks used Synapse as middleware. Synapse failed. The money disappeared into a ledger nobody could reconcile.

That’s the fourth-party risk problem in its most concrete form.

TL;DR

  • Synapse was a fourth-party failure: fintechs contracted with banks, banks depended on Synapse, Synapse’s ledger collapsed — and $265M in customer deposits were frozen
  • July 2024 joint statement from OCC, FDIC, and Fed tightened what banks must demonstrate about direct oversight of fintech partners and middleware dependencies
  • 26% of financial institutions still don’t assess fourth-party risk at all, per the 2026 Ncontracts TPRM Survey
  • OCC and FDIC examiners are now specifically reaching past your vendor list to ask about critical subcontractor dependencies
  • The AI supply chain adds a new fourth-party layer most programs haven’t mapped yet
  • The minimum examiner expectation: know who your critical vendors depend on, document it, and contract for notification rights if that changes

What Fourth-Party Risk Actually Means

Your TPRM program covers vendors you directly contract with. Fourth-party risk is the risk created by your vendors’ vendors — the subcontractors, cloud platforms, data providers, and technology dependencies that sit one layer beneath your vendor relationships.

You don’t have a contract with fourth parties. You can’t audit them directly. You often don’t know they exist. But if they fail, the disruption flows through your vendor to your operations and your customers.

This is not theoretical risk. It’s the exact failure mode the Synapse collapse exposed:

  • Bank (third party to fintech customers): Evolve Bank, AMG National Trust, Lineage Bank
  • Middleware (fourth party — vendor to the banks, invisible to fintech customers): Synapse Financial Technologies
  • Fintechs (customer-facing, dependent on banks, dependent on Synapse): Yotta, Juno, Copper

When Synapse’s ledger systems failed, no single institution had an authoritative record of which customer was owed which dollars. The resulting reconciliation gap locked customers out for months.

The interagency TPRM guidance — OCC Bulletin 2023-17 and the parallel FDIC FIL-29-2023 — explicitly requires banking organizations to understand their critical vendors’ subcontracting practices as part of due diligence. What Synapse proved is that the concept isn’t academic: middleware concentration risk is real, it’s material, and it can freeze customer funds overnight.


What Regulators Did After Synapse

The regulatory response unfolded in layers.

June 2024 — Evolve Bank cease-and-desist: The Federal Reserve issued a cease-and-desist against Evolve Bank — the largest of Synapse’s partner banks — citing gaps in its BSA/AML program, risk management, and consumer protection. The order made the bank’s supervisory failures explicit: Evolve had relied on Synapse’s representations about ledger accuracy without independently verifying them.

July 25, 2024 — Joint statement on bank-fintech arrangements: The OCC, Federal Reserve, and FDIC issued a joint statement addressing what they’d observed in BaaS and bank-fintech structures. Key messages:

  • Banks cannot delegate compliance obligations to fintech partners or middleware providers
  • Oversight capability must be real and exercisable, not just contractual
  • Concentration risk needs board-level visibility
  • Banks must be able to wind down fintech programs without harming customers

October 2024 — FDIC custodial accounts rule: The FDIC proposed formal rulemaking requiring banks that hold custodial deposits for fintech programs to maintain their own beneficial owner ledgers — not rely on middleware providers to do it. The rule directly targets the Synapse failure mechanism: pooled FBO accounts where nobody had an authoritative, current record of which end user was owed what.

Each of these actions carries the same underlying message: the bank owns the risk, regardless of how many layers of technology sit between the bank and the end customer.


What Examiners Are Now Checking

Three years into the interagency TPRM guidance, examinations have shifted from checking whether a program exists to checking whether it actually functions. For fourth-party risk specifically, examiners are reaching deeper than the vendor list.

For critical activity vendors, examiners now expect documentation of:

  1. Subcontractor identification — Who are the critical subcontractors your core processor, payment platform, and key technology vendors depend on? Not a complete list of every sub-vendor, but the ones that are material to service delivery.

  2. Dependency mapping — What does each subcontractor do in the chain? If the subcontractor failed, what’s the impact to your operations?

  3. Risk indicators — Are there any known concerns about the subcontractor’s financial health, security posture, or regulatory standing?

  4. Notification rights — Does your contract with the vendor require them to notify you if a critical subcontractor changes, fails, or is acquired?

The practical minimum examiners accept is documented evidence that you asked the right questions and got answers. Not a full due diligence workup on every sub-vendor — but enough to show you’ve mapped the dependency and thought through the failure scenario.

For BaaS and bank-fintech relationships specifically, examiners are checking whether banks have exercised their oversight rights, not just whether those rights exist on paper. A contract that gives the bank audit rights over a fintech partner is meaningless if the bank has never used them. Examiners want to see evidence of independent review: internal team visits, third-party assessments, reconciliation testing, or at minimum documented attempts to verify the fintech’s representations.

For a deeper look at what examiners are finding in first-tier TPRM programs, our 2026 TPRM Examination Findings analysis covers the full gap inventory.


The AI Supply Chain Problem

Traditional fourth-party risk mapping was hard enough when vendors were using identifiable subcontractors with SOC 2 reports. The AI supply chain makes it significantly harder.

When a vendor embeds a large language model — GPT, Claude, Gemini, or a third-party foundation model — into their product or internal operations, that model provider becomes your fourth party. You likely have:

  • No visibility into the model provider’s data handling practices or security posture
  • No contractual relationship giving you notification rights if the model provider changes
  • No assessment of what happens to your vendor’s product if the foundation model is deprecated or breached
  • No documentation of where your data goes when it’s processed by that model

According to Treasury’s AI risk management guidance, AI dependency monitoring is a distinct risk domain that traditional vendor risk programs weren’t designed to surface.

The interagency TPRM guidance’s subcontracting disclosure requirement applies directly: when a critical vendor uses AI models from third-party providers, those providers fall within the definition of subcontractors the guidance requires you to assess. Your vendor questionnaire and ongoing monitoring protocol need to surface this.

This connects to the broader cloud concentration risk problem our cloud provider concentration risk analysis covers — when multiple vendors in your critical path all depend on the same foundation model provider or cloud region, you have concentration risk several layers deep.


Building a Minimum-Viable Fourth-Party Program

You don’t need a team of analysts to get fourth-party risk management to an examiner-defensible level. The program doesn’t need to be perfect. It needs to be documented, proportional, and evidence-based.

Step 1: Map your critical vendors

Start with your critical activity vendor list. These are the vendors whose failure would materially disrupt your operations, harm customers, or create regulatory exposure. If you don’t have a documented critical activity list, that’s the prerequisite.

Step 2: Ask about their subcontractors

Add a fourth-party risk section to your vendor due diligence questionnaire and annual review. Key questions:

  • Who are your critical subcontractors for the services you provide us?
  • Which cloud providers do you depend on for service delivery?
  • Do you use AI models or foundation models from third parties? Which ones?
  • How would you notify us if a critical subcontractor changed, failed, or was acquired?

Step 3: Contract for notification rights

At next renewal for every critical activity vendor, add a clause requiring them to notify you of material changes to critical subcontractors within a defined timeframe (30 days is a common standard). This gives you a documented, contractual mechanism — and something to show an examiner beyond “we asked.”

Step 4: Document what you know and what you don’t

Not all fourth parties will cooperate. Large technology vendors and cloud providers often resist disclosing their full subcontractor footprints. Document the request, document the response (or non-response), and document your assessment of the residual risk from the gaps. An examiner’s concern is whether you’re aware of the exposure — not whether you’ve solved it.

Step 5: Assess concentration

Across your critical vendors, identify whether multiple vendors share the same critical subcontractors — particularly cloud infrastructure providers. If your core processor, payment platform, and lending origination system all run on AWS us-east-1, that’s a concentration exposure your BCP needs to address.

The TPRM Kit includes vendor questionnaire templates with fourth-party sections, subcontractor mapping worksheets, and contract checklist language for subcontractor notification rights — aligned to what the interagency guidance requires and what examiners are checking in 2026.


DORA’s Fourth-Party Mandate: What It Means for US Firms

If your institution has EU customers, EU subsidiaries, or operates within scope of the Digital Operational Resilience Act, the fourth-party obligation is explicit rather than inferred.

DORA requires financial entities to assess ICT third-party risk including all subcontracting arrangements. It mandates that contracts with critical ICT providers include the right to audit subcontractors and receive notification of subcontractor changes. The DORA standard is more prescriptive than the US interagency guidance — but the direction is the same.

For US firms with any EU footprint, DORA’s fourth-party requirements provide a useful template for what the most rigorous version of the program looks like. For the operational resilience and ICT incident reporting dimensions, our DORA first ICT incident report analysis covers what the first wave of DORA incident data revealed about third-party dependencies.


So What?

The Synapse collapse wasn’t a compliance failure in the traditional sense. Nobody misrepresented a SOC 2 report. No vendor contract was violated. The problem was a structural gap: institutions in the BaaS chain relied on middleware they didn’t assess, couldn’t monitor, and had no independent ability to verify — and when that middleware collapsed, the ledger broke.

The 26% of financial institutions that still don’t assess fourth-party risk at all are carrying Synapse-scale exposure without knowing it. The regulators know this. The July 2024 joint statement, the FDIC custodial accounts rule, and the 2026 examination focus on subcontractor mapping are all pointed at the same gap.

You don’t need to audit every sub-vendor. You need to know who the critical ones are, what they do, what happens if they fail, and whether your vendor contracts give you the notification rights to find out when something changes. That’s the examiner’s minimum expectation. Start there.

If you’re building out your fourth-party oversight program and need documentation templates aligned to what examiners are checking, the Third-Party Risk Management Kit includes subcontractor mapping tools, vendor questionnaire modules, and written agreement checklists covering the 14 required contract elements under the interagency guidance.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is fourth-party risk and how is it different from third-party risk?
Third-party risk is the risk your vendors pose to your institution. Fourth-party risk is the risk your vendors' vendors pose — the subcontractors, cloud providers, data processors, and platform dependencies that sit one layer deeper. You don't have a direct contract with fourth parties, but if they fail, the impact lands on you through your vendor. Synapse was a fourth party to most affected fintechs: Yotta, Juno, and Copper contracted with sponsor banks (their third parties), and Synapse was the middleware those banks depended on — a critical fourth-party dependency that nobody in the chain had formally assessed.
What did the July 2024 joint statement require for bank-fintech partnerships?
The July 25, 2024 joint statement from the OCC, FDIC, and Federal Reserve addressed what regulators observed in BaaS and bank-fintech arrangements after Synapse: sponsor banks were relying entirely on fintech partners' representations about their compliance and operational integrity, with no independent oversight capability. The statement required banks to maintain direct oversight capability of fintech partners, maintain exercisable termination rights, monitor fintech concentration risk, and ensure boards have meaningful visibility into fintech-related risk. Critically, it signaled that banks cannot pass compliance responsibility to fintech partners or middleware providers — the bank's charter means the bank owns the risk.
What does the FDIC's October 2024 custodial accounts rule require?
The FDIC's proposed 'Synapse rule' — formally a proposed rule on Recordkeeping for Custodial Accounts — would require banks that hold custodial deposits for fintech programs to maintain accurate, real-time ledgers of each beneficial owner's funds. The Synapse collapse exposed a gap: pooled FBO accounts at sponsor banks held fintech customer deposits, but no single entity maintained a current, authoritative ledger of which customer was owed which dollars. When Synapse's systems failed, the reconciliation became impossible. The proposed rule targets exactly this failure: banks would be required to keep beneficial owner records themselves, not delegate that function to middleware.
What do OCC and FDIC examiners actually ask about fourth-party risk?
Examiners reviewing TPRM programs in 2026 specifically check whether institutions have mapped critical subcontractor dependencies for each critical activity vendor. Practical questions include: Can you identify who your core processor's critical subcontractors are? What cloud providers does your payment processor depend on? If your lending platform's data vendor went down, what's your RTO? Examiners don't require full due diligence on every subcontractor — but they expect documented evidence that you've asked your critical vendors about their sub-dependency exposure, received answers, and understand the risk. The failure mode they cite most often: 'we didn't know that vendor X was dependent on Y until Y failed.'
How does AI change fourth-party risk exposure?
AI supply chains add a layer most TPRM programs haven't mapped yet. When a vendor embeds a third-party large language model (like GPT or Claude) into their product, that foundation-model provider becomes your fourth party — and you likely have no visibility into the model provider's data handling, security posture, or business continuity. The interagency guidance's requirement to understand subcontracting practices applies here. Examiners in the AI-adjacent supervision track are starting to ask whether vendors who use embedded AI models have disclosed those providers and what the bank's contract requires if the AI provider changes or fails.
What's the minimum viable fourth-party oversight program that satisfies examiners?
The minimum floor examiners accept: (1) For each critical activity vendor, a documented list of that vendor's critical subcontractors and what they do in the service delivery chain. (2) Contractual rights requiring your vendors to notify you of material subcontractor changes. (3) Evidence that you asked and got answers — not just that a questionnaire exists. (4) A documented process for assessing what happens if a critical subcontractor fails. That's it at the minimum. Examiners aren't expecting full due diligence workups on every subcontractor; they expect evidence that you've mapped the dependency and thought through the failure scenario.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.