Skip to content
RiskTemplates · The Daily Brief Wednesday, September 2, 2026
Wire Lugano Diamonds SEC Fraud Case: How $1B in Alleged Fake Revenue Beat the Control Stack SEP 1

Feature Third-Party Risk

The FDIC Is Building a Fintech Certification Program. What BISDO and RAMP Mean for Your Third-Party Risk Program.

On July 21, 2026, the FDIC released a draft term sheet for a voluntary fintech certification program called BISDO — with a RAMP certification label. It won't create a safe harbor or a blacklist. But it will change what your bank partner asks you to prove.

By Rebecca Leung · August 30, 2026 ·
Table of Contents

TL;DR

  • On July 21, 2026, the FDIC circulated a draft term sheet for BISDO — the Banking Industry Standards Development Organization — a voluntary fintech certification program
  • Certified providers would receive a RAMP (Risk-Assessed, Manageable Partnerships) label and appear in a public registry
  • RAMP provides no safe harbor and creates no blacklist — but it signals what the FDIC thinks adequate fintech oversight looks like
  • Between 2022–2025, regulators issued consent orders against seven sponsor banks in BaaS programs; more than 25% of FDIC enforcement actions targeted sponsor banks in embedded finance
  • The practical implication: your bank partner’s examiner is already asking about your program. BISDO just proposes to make those standards explicit.

Consent orders against sponsor banks have a pattern. The bank gets the action. The fintech gets the lesson.

Between 2022 and 2025, regulators worked through Blue Ridge Bank, Evolve Bank & Trust, Thread Bank, Piermont Bank, Lineage Bank, Cross River Bank, and Green Dot Bank. The violations cluster around the same issues: BSA/AML deficiencies, inadequate fintech partner oversight, weak transaction monitoring, and consumer compliance failures. In every case, the chartered bank bore the regulatory consequence — regardless of what the partnership agreement said about who owned compliance.

The FDIC’s proposed solution isn’t another enforcement action. It’s a standards body.


What BISDO Is — and What It Isn’t

On July 21, 2026, the FDIC circulated a draft term sheet for the Banking Industry Standards Development Organization — BISDO. The concept: an industry-led body, developed in collaboration with the FDIC and major trade associations, that would establish voluntary standards for third-party service providers that partner with banks, and issue certifications to those that meet them.

The certification label is RAMP: Risk-Assessed, Manageable Partnerships. Providers that meet BISDO standards would receive RAMP certification and appear in a public registry.

The trade organizations collaborating with the FDIC on the proposal include the American Bankers Association, Independent Community Bankers of America, Bank Policy Institute, Financial Technology Association, American Fintech Council, and Coalition for Financial Ecosystem Standards — a broad coalition spanning banks and fintechs.

Here is what the FDIC has been explicit about: BISDO certification is not a regulatory endorsement, and RAMP does not create a regulatory safe harbor. Banks remain responsible for their own oversight of fintech partners. Certification doesn’t substitute for a bank’s due diligence. And absence from the registry doesn’t create a blacklist — a fintech that hasn’t pursued RAMP certification can still partner with banks.

So what is it actually?

The honest answer is that it’s a proposed piece of infrastructure for a market that currently has no standardization. Every bank that wants to partner with a fintech runs its own due diligence. Every fintech that wants to partner with multiple banks answers nearly identical questionnaires from each. The questions overlap substantially; the formats differ; the cycles pile up. BISDO’s pitch is that if a fintech demonstrates compliance with a common standard once, that demonstration should be reusable across multiple bank relationships.


The Standards Areas: What BISDO Would Actually Cover

The draft term sheet identifies the areas BISDO would assess. They are worth reading carefully, because they mirror what examiners already ask sponsor banks to demonstrate about their fintech partners:

  • Third-party risk management — the fintech’s own TPRM program; whether it manages its vendors with the rigor its bank partners are now required to apply to them
  • Governance and internal controls — board-level accountability structures, 3 Lines of Defense, control testing
  • Cybersecurity — consistent with NIST CSF or similar frameworks; incident response, access controls, vulnerability management
  • Operational resilience — business continuity plans that address critical functions, dependencies, and recovery procedures
  • Information security — data classification, encryption, access management
  • Consumer compliance — fair lending, UDAAP, Regulation E, complaint management
  • BSA/AML controls — transaction monitoring, suspicious activity reporting, KYC/CIP procedures
  • Due diligence — the fintech’s own process for evaluating its own vendors and subcontractors (fourth-party risk)
  • Ongoing monitoring — not just point-in-time assessments, but continuous vendor oversight
  • Business continuity — the fintech’s ability to maintain critical functions through disruptions

If you’re reading this list and thinking it looks like what an examiner asks your bank partner to show in their third-party risk management examination — you’re right. That’s the point.


The Enforcement Context That Explains Why This Is Happening Now

BISDO didn’t emerge from a policy vacuum. The enforcement record created the conditions for it.

Between 2022 and 2025, bank-fintech partnership enforcement produced a pattern visible in the data: more than a quarter of the FDIC’s formal enforcement actions targeted sponsor banks in embedded finance partnerships. More than one in five OCC enforcement actions did the same. The enforcement action against Cross River Bank in 2023, the Federal Reserve consent order against Evolve, the OCC’s 2025 guidance on BaaS sponsor expectations — each reinforced the same principle: banks cannot delegate responsibility for their fintech partners’ compliance to the fintechs themselves.

The practical result is a rising cost of bank-fintech partnership formation. Banks are running lengthier due diligence processes. Fintechs are spending more time on questionnaire responses and less time on product development. Community banks — which would most benefit from fintech partnerships to extend their product footprint — often lack the staff to run rigorous TPRM reviews efficiently.

BISDO is the FDIC’s answer to a structural problem: duplicative, resource-intensive, unstandardized due diligence that burdens both sides of the relationship without necessarily producing better outcomes than a common standard would.

The FTC’s blog on Safeguards Rule notification requirements and the Consumer Finance Monitor’s coverage of BISDO both frame this as infrastructure, not enforcement — a way to make the due diligence market function more efficiently rather than a new compliance burden.


What This Means for Fintechs Right Now

BISDO is proposed, not final. The certification program, if it launches, will require additional rule-making, industry consensus on specific standards, and operational infrastructure for assessments and registry maintenance. None of that is imminent.

But the standards areas in the draft term sheet are not aspirational. They describe what examiners already look for when they assess whether a bank’s third-party risk program adequately covers its fintech partners. That examination expectation exists today, regardless of whether BISDO ever launches.

There are three things fintechs should take from this proposal:

1. Audit your program against the BISDO standards areas now. The 11 areas in the term sheet — TPRM, governance, cybersecurity, operational resilience, InfoSec, consumer compliance, BSA/AML, complaint management, due diligence, monitoring, BCP — are what your bank partner’s examiner is already reviewing your bank partner on, with you as the subject. If your internal programs don’t address these areas, you’re a potential exam finding waiting to be written.

2. Prepare for bank partner due diligence to get more structured. Whether or not BISDO launches, its publication signals that regulators view standardization of fintech due diligence as a policy objective. Expect bank partner questionnaires to become more rigorous and more consistent over the next 12–18 months, informed by the standards areas the FDIC has now publicized.

3. If you’re scaling to multiple bank partners, track BISDO’s development. The efficiency case for RAMP certification is strongest for fintechs seeking relationships with multiple sponsor banks — demonstrating compliance with a common standard once rather than running 10 separate due diligence cycles. That benefit doesn’t exist today, but if BISDO progresses, it will.


The Due Diligence Gap It’s Trying to Close

The embedded finance market has a structural asymmetry that BISDO is designed to address. Large, established fintechs can absorb the due diligence cost of multiple bank relationships — they have compliance teams, legal counsel, and institutional knowledge of what questions are coming. Earlier-stage companies and smaller operators often can’t.

The result is a market where the fintechs best positioned to use BISDO certification — those for whom a reusable credential would most reduce partnership friction — are also the ones who most need to build the underlying programs to earn that certification.

The FDIC has said that the current approach of continuous monitoring by sponsor banks produces good outcomes in principle but inconsistent implementation in practice. BISDO’s pitch to the market is that consistent standards produce more consistent outcomes than individual bank judgment about what adequate fintech oversight looks like.

Whether the market accepts that pitch will depend on whether BISDO assessments are genuinely rigorous, whether certification provides enough due diligence efficiency to justify the cost of compliance, and whether examiners treat RAMP certification as meaningful evidence of a fintech’s compliance posture. None of those questions have answers yet.


What Hasn’t Been Resolved

The FDIC’s July 21 draft term sheet leaves several significant questions open:

Who conducts BISDO assessments? The term sheet doesn’t specify whether assessments will be conducted by BISDO staff, accredited third-party auditors, or some other mechanism. The quality and consistency of assessments will determine whether RAMP certification actually signals anything.

How often do certified fintechs need reassessment? Certification that reflects a point-in-time assessment quickly becomes stale in a regulated environment. The ongoing monitoring standards area suggests continuous compliance is intended, but the mechanics aren’t defined.

What are the costs? Certification programs charge fees. For a large fintech, assessment costs may be trivially small relative to the due diligence efficiency gained. For a community fintech, those costs may exceed the benefit.

How will regulators treat certification in examinations? The FDIC has said RAMP is not a safe harbor. But examiners exercise judgment. If a bank can demonstrate that a fintech partner holds current RAMP certification and has reviewed what that certification covers, will that influence examiner findings? The answer matters, and it isn’t given.


So What?

The consent order pattern against sponsor banks has been consistent: banks that outsource compliance judgment to their fintech partners receive enforcement actions. Banks that treat fintech oversight as an ongoing supervisory function — with documented TPRM programs, continuous monitoring, and evidence of periodic assessment — have fared better.

BISDO’s existence as a proposal reflects regulatory recognition that the current state of bank-fintech due diligence is inefficient, inconsistent, and producing worse outcomes for both sides than a market infrastructure could.

It also reflects a practical reality: the Bilt-Wells Fargo transition’s consumer failures and the seven BaaS consent orders didn’t happen because banks were indifferent to fintech risk. They happened because the signals of inadequate compliance were there in the due diligence record — and because the market lacked a common standard for what “adequate” looked like.

BISDO is proposing to provide that standard. The question for every fintech considering a bank partnership is whether their current compliance program would earn a RAMP certificate if one existed today.

If the honest answer is no — that’s the gap to close, independent of whether BISDO ever launches.


Related reading: OCC BaaS Consent Orders and What They Mean for Fintech TPRM Programs | Sponsor Bank Continuous Monitoring: What Fintechs Are Now Required to Support


Build the TPRM program your bank partner’s examiner is looking for. The Third-Party Risk Management (TPRM) Kit covers the full vendor lifecycle — risk tiering, due diligence questionnaire, contract review checklist, ongoing monitoring, and offboarding — structured to meet OCC Bulletin 2023-17 and FDIC third-party risk guidance. The BISDO standards areas map directly to what this kit addresses.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is BISDO and who proposed it?
BISDO stands for Banking Industry Standards Development Organization — a voluntary, industry-led body proposed by the FDIC in a July 21, 2026 draft term sheet. It would develop standards and issue certifications to third-party service providers that partner with banks. The FDIC is developing it in collaboration with major trade groups: the American Bankers Association, Independent Community Bankers of America, Bank Policy Institute, Financial Technology Association, American Fintech Council, and Coalition for Financial Ecosystem Standards.
What is RAMP certification?
RAMP stands for Risk-Assessed, Manageable Partnerships — the certification label that BISDO would award to third-party service providers that meet its standards. Certified vendors would appear in a public registrar. RAMP certification would not constitute a regulatory endorsement or provide a regulatory safe harbor. Absence from the registry would not create a blacklist either — uncertified vendors could still be used by banks.
What standards areas would BISDO cover?
The draft term sheet identifies potential standards covering: third-party risk management, governance and internal controls, cybersecurity, operational resilience, information security, consumer compliance, BSA/AML controls, complaint management, due diligence, ongoing monitoring, and business continuity. These map almost exactly to what bank examiners already look for in sponsor bank TPRM programs.
Does BISDO certification create a regulatory safe harbor for fintechs?
No. Explicitly not. The FDIC has stated that RAMP certification would not constitute a regulatory endorsement and would not provide a safe harbor. Banks would still be responsible for their own oversight of fintech partners. The intended benefit is efficiency — reducing duplicative due diligence when multiple banks are reviewing the same fintech — not regulatory protection.
Why is the FDIC proposing BISDO now?
Enforcement data tells the story. Between 2022 and 2025, the OCC, FDIC, and Federal Reserve issued consent orders against seven sponsor banks operating Banking-as-a-Service programs. More than one-quarter of the FDIC's formal enforcement actions and more than one-fifth of the OCC's targeted sponsor banks in embedded finance partnerships. The regulatory cost of inadequate third-party oversight is no longer theoretical. BISDO is a proposed infrastructure response to a demonstrated enforcement problem.
Should my fintech pursue RAMP certification when it's available?
That depends on your distribution model. If you work with a single bank partner and have an established due diligence relationship, the marginal value is low. If you're trying to scale to multiple bank partners, or if you're an early-stage company seeking a first bank relationship, having a RAMP certificate could meaningfully reduce the friction of initial due diligence cycles. The more important near-term action is ensuring your TPRM program already covers the standards areas BISDO intends to assess — because those are also what examiners assess your bank partner on today.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.