Feature Third-Party Risk
The FDIC Is Building a Fintech Certification Program. What BISDO and RAMP Mean for Your Third-Party Risk Program.
On July 21, 2026, the FDIC released a draft term sheet for a voluntary fintech certification program called BISDO — with a RAMP certification label. It won't create a safe harbor or a blacklist. But it will change what your bank partner asks you to prove.
Table of Contents
TL;DR
- On July 21, 2026, the FDIC circulated a draft term sheet for BISDO — the Banking Industry Standards Development Organization — a voluntary fintech certification program
- Certified providers would receive a RAMP (Risk-Assessed, Manageable Partnerships) label and appear in a public registry
- RAMP provides no safe harbor and creates no blacklist — but it signals what the FDIC thinks adequate fintech oversight looks like
- Between 2022–2025, regulators issued consent orders against seven sponsor banks in BaaS programs; more than 25% of FDIC enforcement actions targeted sponsor banks in embedded finance
- The practical implication: your bank partner’s examiner is already asking about your program. BISDO just proposes to make those standards explicit.
Consent orders against sponsor banks have a pattern. The bank gets the action. The fintech gets the lesson.
Between 2022 and 2025, regulators worked through Blue Ridge Bank, Evolve Bank & Trust, Thread Bank, Piermont Bank, Lineage Bank, Cross River Bank, and Green Dot Bank. The violations cluster around the same issues: BSA/AML deficiencies, inadequate fintech partner oversight, weak transaction monitoring, and consumer compliance failures. In every case, the chartered bank bore the regulatory consequence — regardless of what the partnership agreement said about who owned compliance.
The FDIC’s proposed solution isn’t another enforcement action. It’s a standards body.
What BISDO Is — and What It Isn’t
On July 21, 2026, the FDIC circulated a draft term sheet for the Banking Industry Standards Development Organization — BISDO. The concept: an industry-led body, developed in collaboration with the FDIC and major trade associations, that would establish voluntary standards for third-party service providers that partner with banks, and issue certifications to those that meet them.
The certification label is RAMP: Risk-Assessed, Manageable Partnerships. Providers that meet BISDO standards would receive RAMP certification and appear in a public registry.
The trade organizations collaborating with the FDIC on the proposal include the American Bankers Association, Independent Community Bankers of America, Bank Policy Institute, Financial Technology Association, American Fintech Council, and Coalition for Financial Ecosystem Standards — a broad coalition spanning banks and fintechs.
Here is what the FDIC has been explicit about: BISDO certification is not a regulatory endorsement, and RAMP does not create a regulatory safe harbor. Banks remain responsible for their own oversight of fintech partners. Certification doesn’t substitute for a bank’s due diligence. And absence from the registry doesn’t create a blacklist — a fintech that hasn’t pursued RAMP certification can still partner with banks.
So what is it actually?
The honest answer is that it’s a proposed piece of infrastructure for a market that currently has no standardization. Every bank that wants to partner with a fintech runs its own due diligence. Every fintech that wants to partner with multiple banks answers nearly identical questionnaires from each. The questions overlap substantially; the formats differ; the cycles pile up. BISDO’s pitch is that if a fintech demonstrates compliance with a common standard once, that demonstration should be reusable across multiple bank relationships.
The Standards Areas: What BISDO Would Actually Cover
The draft term sheet identifies the areas BISDO would assess. They are worth reading carefully, because they mirror what examiners already ask sponsor banks to demonstrate about their fintech partners:
- Third-party risk management — the fintech’s own TPRM program; whether it manages its vendors with the rigor its bank partners are now required to apply to them
- Governance and internal controls — board-level accountability structures, 3 Lines of Defense, control testing
- Cybersecurity — consistent with NIST CSF or similar frameworks; incident response, access controls, vulnerability management
- Operational resilience — business continuity plans that address critical functions, dependencies, and recovery procedures
- Information security — data classification, encryption, access management
- Consumer compliance — fair lending, UDAAP, Regulation E, complaint management
- BSA/AML controls — transaction monitoring, suspicious activity reporting, KYC/CIP procedures
- Due diligence — the fintech’s own process for evaluating its own vendors and subcontractors (fourth-party risk)
- Ongoing monitoring — not just point-in-time assessments, but continuous vendor oversight
- Business continuity — the fintech’s ability to maintain critical functions through disruptions
If you’re reading this list and thinking it looks like what an examiner asks your bank partner to show in their third-party risk management examination — you’re right. That’s the point.
The Enforcement Context That Explains Why This Is Happening Now
BISDO didn’t emerge from a policy vacuum. The enforcement record created the conditions for it.
Between 2022 and 2025, bank-fintech partnership enforcement produced a pattern visible in the data: more than a quarter of the FDIC’s formal enforcement actions targeted sponsor banks in embedded finance partnerships. More than one in five OCC enforcement actions did the same. The enforcement action against Cross River Bank in 2023, the Federal Reserve consent order against Evolve, the OCC’s 2025 guidance on BaaS sponsor expectations — each reinforced the same principle: banks cannot delegate responsibility for their fintech partners’ compliance to the fintechs themselves.
The practical result is a rising cost of bank-fintech partnership formation. Banks are running lengthier due diligence processes. Fintechs are spending more time on questionnaire responses and less time on product development. Community banks — which would most benefit from fintech partnerships to extend their product footprint — often lack the staff to run rigorous TPRM reviews efficiently.
BISDO is the FDIC’s answer to a structural problem: duplicative, resource-intensive, unstandardized due diligence that burdens both sides of the relationship without necessarily producing better outcomes than a common standard would.
The FTC’s blog on Safeguards Rule notification requirements and the Consumer Finance Monitor’s coverage of BISDO both frame this as infrastructure, not enforcement — a way to make the due diligence market function more efficiently rather than a new compliance burden.
What This Means for Fintechs Right Now
BISDO is proposed, not final. The certification program, if it launches, will require additional rule-making, industry consensus on specific standards, and operational infrastructure for assessments and registry maintenance. None of that is imminent.
But the standards areas in the draft term sheet are not aspirational. They describe what examiners already look for when they assess whether a bank’s third-party risk program adequately covers its fintech partners. That examination expectation exists today, regardless of whether BISDO ever launches.
There are three things fintechs should take from this proposal:
1. Audit your program against the BISDO standards areas now. The 11 areas in the term sheet — TPRM, governance, cybersecurity, operational resilience, InfoSec, consumer compliance, BSA/AML, complaint management, due diligence, monitoring, BCP — are what your bank partner’s examiner is already reviewing your bank partner on, with you as the subject. If your internal programs don’t address these areas, you’re a potential exam finding waiting to be written.
2. Prepare for bank partner due diligence to get more structured. Whether or not BISDO launches, its publication signals that regulators view standardization of fintech due diligence as a policy objective. Expect bank partner questionnaires to become more rigorous and more consistent over the next 12–18 months, informed by the standards areas the FDIC has now publicized.
3. If you’re scaling to multiple bank partners, track BISDO’s development. The efficiency case for RAMP certification is strongest for fintechs seeking relationships with multiple sponsor banks — demonstrating compliance with a common standard once rather than running 10 separate due diligence cycles. That benefit doesn’t exist today, but if BISDO progresses, it will.
The Due Diligence Gap It’s Trying to Close
The embedded finance market has a structural asymmetry that BISDO is designed to address. Large, established fintechs can absorb the due diligence cost of multiple bank relationships — they have compliance teams, legal counsel, and institutional knowledge of what questions are coming. Earlier-stage companies and smaller operators often can’t.
The result is a market where the fintechs best positioned to use BISDO certification — those for whom a reusable credential would most reduce partnership friction — are also the ones who most need to build the underlying programs to earn that certification.
The FDIC has said that the current approach of continuous monitoring by sponsor banks produces good outcomes in principle but inconsistent implementation in practice. BISDO’s pitch to the market is that consistent standards produce more consistent outcomes than individual bank judgment about what adequate fintech oversight looks like.
Whether the market accepts that pitch will depend on whether BISDO assessments are genuinely rigorous, whether certification provides enough due diligence efficiency to justify the cost of compliance, and whether examiners treat RAMP certification as meaningful evidence of a fintech’s compliance posture. None of those questions have answers yet.
What Hasn’t Been Resolved
The FDIC’s July 21 draft term sheet leaves several significant questions open:
Who conducts BISDO assessments? The term sheet doesn’t specify whether assessments will be conducted by BISDO staff, accredited third-party auditors, or some other mechanism. The quality and consistency of assessments will determine whether RAMP certification actually signals anything.
How often do certified fintechs need reassessment? Certification that reflects a point-in-time assessment quickly becomes stale in a regulated environment. The ongoing monitoring standards area suggests continuous compliance is intended, but the mechanics aren’t defined.
What are the costs? Certification programs charge fees. For a large fintech, assessment costs may be trivially small relative to the due diligence efficiency gained. For a community fintech, those costs may exceed the benefit.
How will regulators treat certification in examinations? The FDIC has said RAMP is not a safe harbor. But examiners exercise judgment. If a bank can demonstrate that a fintech partner holds current RAMP certification and has reviewed what that certification covers, will that influence examiner findings? The answer matters, and it isn’t given.
So What?
The consent order pattern against sponsor banks has been consistent: banks that outsource compliance judgment to their fintech partners receive enforcement actions. Banks that treat fintech oversight as an ongoing supervisory function — with documented TPRM programs, continuous monitoring, and evidence of periodic assessment — have fared better.
BISDO’s existence as a proposal reflects regulatory recognition that the current state of bank-fintech due diligence is inefficient, inconsistent, and producing worse outcomes for both sides than a market infrastructure could.
It also reflects a practical reality: the Bilt-Wells Fargo transition’s consumer failures and the seven BaaS consent orders didn’t happen because banks were indifferent to fintech risk. They happened because the signals of inadequate compliance were there in the due diligence record — and because the market lacked a common standard for what “adequate” looked like.
BISDO is proposing to provide that standard. The question for every fintech considering a bank partnership is whether their current compliance program would earn a RAMP certificate if one existed today.
If the honest answer is no — that’s the gap to close, independent of whether BISDO ever launches.
Related reading: OCC BaaS Consent Orders and What They Mean for Fintech TPRM Programs | Sponsor Bank Continuous Monitoring: What Fintechs Are Now Required to Support
Build the TPRM program your bank partner’s examiner is looking for. The Third-Party Risk Management (TPRM) Kit covers the full vendor lifecycle — risk tiering, due diligence questionnaire, contract review checklist, ongoing monitoring, and offboarding — structured to meet OCC Bulletin 2023-17 and FDIC third-party risk guidance. The BISDO standards areas map directly to what this kit addresses.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is BISDO and who proposed it?
What is RAMP certification?
What standards areas would BISDO cover?
Does BISDO certification create a regulatory safe harbor for fintechs?
Why is the FDIC proposing BISDO now?
Should my fintech pursue RAMP certification when it's available?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
The Bilt-Wells Fargo Breakup Is a Case Study in Bank Partner Exit Risk. Here's What Your Fintech Needs Before an Unplanned Transition.
When Wells Fargo ended its Bilt contract early, hundreds of rent payments failed and the CFPB stepped in. The lesson isn't about one fintech's stumble — it's about the gap in how every fintech plans for the scenario where the bank partner relationship ends on someone else's timeline.
Aug 26, 2026
Third-Party Risk
AiNET’s $1.8M SEC Data Center Settlement: A Vendor Certificate Is Not Evidence
The AiNET SEC data center settlement shows how a false Tier III claim can survive procurement. Here is the vendor evidence fix.
Aug 25, 2026
Third-Party Risk
What Your Sponsor Bank Is Actually Monitoring: The 2026 Fintech Oversight Playbook
Post-Synapse, sponsor banks moved from periodic due diligence reviews to continuous monitoring of fintech partners across seven operational dimensions. Here's what your bank partner's oversight team is tracking—and what documentation you need ready.
Aug 23, 2026