Feature Third-Party Risk
The Contract Says It's the Fintech's Problem. Seven BaaS Consent Orders Say Otherwise.
Between 2022 and 2025, the FDIC, OCC, and Federal Reserve issued consent orders against at least seven sponsor banks in Banking-as-a-Service programs — despite partnership agreements that assigned compliance responsibilities to fintech partners. Here's what every sponsor bank and fintech needs to understand about third-party liability in 2026.
Table of Contents
TL;DR
- Between 2022 and 2025, the FDIC, OCC, and Federal Reserve issued consent orders against at least seven sponsor banks in Banking-as-a-Service programs — regardless of what their partnership agreements said about compliance responsibilities.
- The 2023 Interagency Guidance (OCC Bulletin 2023-17) added explicit requirements for fourth-party subcontractor oversight, concentration risk monitoring, and fintech-specific due diligence.
- A consent order doesn’t care what your contract says: the bank holding the charter bears the regulatory consequence.
- In 2026, fintech compliance maturity directly affects sponsor-bank relationship terms, due diligence speed, concentration limits, and long-term program viability.
There is a sentence that appears in every BaaS program agreement: “Fintech Partner is solely responsible for ensuring compliance with all applicable laws and regulations in connection with the services it provides to End Users.”
It is a reasonable sentence. It reflects a reasonable allocation of risk between private parties who each understand their respective parts of the program. It also does not protect the sponsor bank from a consent order.
Between 2022 and 2025, the FDIC, OCC, and Federal Reserve issued consent orders against at least seven sponsor banks operating Banking-as-a-Service programs. The pattern is unambiguous: regardless of what the partnership agreement says about compliance responsibilities, it is the chartered bank — not its fintech partner — that bears the regulatory consequences of fair lending and Bank Secrecy Act failures. The fintech may face its own civil liability. The charter is the bank’s.
That dynamic has reshaped what both sides of a BaaS relationship need to build, prove, and document in 2026.
Why the Contract Doesn’t Transfer Regulatory Accountability
The core legal reality of banking regulation is that regulatory obligations follow the charter. When the OCC or FDIC examines a bank, they are examining the bank — not the fintech program, not the middleware platform, not the subcontractor stack. The bank’s ability to demonstrate compliance is evaluated against what the bank’s own oversight program produced, not against representations the bank received from its partners.
That’s not a technicality. It’s the reason the 2024 Synapse collapse resulted in regulatory action and proposed rulemaking aimed at sponsor banks and at the FDIC’s custodial deposit recordkeeping rules — not at Synapse itself. The bank sponsors had a duty to maintain accurate deposit records for their customers. That duty belonged to the charter, regardless of the fact that the middleware platform was managing the ledger.
The enforcement record from 2022 through 2025 reinforces this consistently. When an OCC- or FDIC-supervised bank’s fintech partner runs a BSA/AML program that fails to file required SARs, or a fair lending program that produces discriminatory outcomes in credit decisions, the consent order that follows names the sponsor bank. The consent order requires the bank to remediate — which often means rebuilding its oversight program for the fintech partner, not just directing the fintech to fix the problem.
What the 2023 Interagency Guidance Changed for BaaS
The 2023 Interagency Guidance on Third-Party Relationships — OCC Bulletin 2023-17, issued jointly with the FDIC and Federal Reserve — replaced the OCC’s 2013 guidance and created a unified interagency standard for the first time. The timing was deliberate: by 2023, the BaaS enforcement pattern was already established, and the guidance expanded explicitly to address it.
Several additions to the 2023 guidance are directly relevant to fintech and BaaS relationships:
Fintech partnerships are explicitly in scope. The 2023 guidance defines a “third-party relationship” as “any business arrangement between a banking organization and another entity, by contract or otherwise.” That last phrase matters: relationships where no formal contract exists — pilots, informal referral arrangements, data-sharing agreements — are covered. Fintech partnerships have always been third-party relationships; the 2023 guidance makes the point explicit.
Concentration risk is now a required assessment. The guidance requires banking organizations to assess concentration risk when a single third party — or a small number of third parties — represents material exposure to the bank. In BaaS programs, this often manifests in two directions: fintech programs that represent a material share of the bank’s total deposits or payment volume, and middleware or core platforms that multiple fintech programs depend on simultaneously. Both create concentration risk. Both require documented assessment.
Fourth-party oversight is an expectation, not a recommendation. Examiners are actively testing whether banks can identify their third parties’ material subcontractors. For a BaaS sponsor bank, this means understanding not just what your fintech partner does, but what infrastructure it runs on — the cloud provider, the payment processor, the data vendor — and whether you have visibility into disruptions or failures at that level.
The Subprocessor Problem
The Synapse collapse made fourth-party risk concrete. Synapse was not a bank. It was middleware — a platform connecting fintech programs to their sponsor banks and managing the ledger that tracked which consumer owed what dollar at which bank. When Synapse filed Chapter 11 in April 2024, the trustee discovered that the ledger couldn’t reconcile which customer was owed which dollars. More than 200,000 customer accounts and approximately $160 million in deposits were frozen.
The sponsor banks had done due diligence on Synapse as a third party. None of them had assessed what happened to their customers’ funds if Synapse itself failed.
That’s the fourth-party risk problem. Your fintech partner runs on infrastructure you may never have evaluated. That infrastructure can fail in ways your contract with the fintech doesn’t address. And when it does, the regulatory question is whether the bank’s oversight program gave it reasonable visibility into that risk.
The 2023 Interagency Guidance is explicit: banks should understand their critical vendors’ key subprocessors and the risk those subprocessors represent. For examiners, “I didn’t know the middleware ran on that cloud provider” is not a satisfying answer when the middleware goes down.
| Risk Layer | Description | Examiner Expectation |
|---|---|---|
| Third-party (fintech partner) | Direct partner relationship | Full lifecycle due diligence, contract review, ongoing monitoring |
| Fourth-party (partner’s subcontractors) | Middleware, cloud infra, payment processors your partner uses | Identification of material subprocessors; assessment of disruption risk |
| Concentration (program-level) | Single fintech represents material deposit share or volume | Documented concentration risk assessment; contingency planning |
| Concentration (platform-level) | Multiple programs depend on same middleware or core system | Platform-level disruption scenario; wind-down planning |
What Fintechs Must Demonstrate in 2026
The enforcement pattern has changed the due diligence conversation from “do you have these policies?” to “can you prove they work?”
Banks are now required to assess five areas during fintech partner due diligence:
-
Financial condition: Audited financials, burn rate, runway, and capital adequacy. A fintech that can’t produce 12-month audited financials is a material gap in the bank’s ability to assess financial risk.
-
Compliance management: The documented structure of the compliance program — policies, procedures, training, testing, and escalation. Not a description of it. The actual documents.
-
Information security program: Documented controls, penetration testing results, SOC 2 report if applicable, and incident response procedures. Banks are increasingly requesting evidence of controls, not just attestation.
-
Business continuity and recovery capabilities: What happens if the fintech fails? A BCP that only covers technology outages — not the scenario where the fintech program is wound down — does not answer the question examiners are asking.
-
Subcontractor management: Who are your material subcontractors, what do they do for you, and how would their failure affect your bank partner’s customers? This is the fourth-party question, and it’s the one most fintechs aren’t prepared to answer.
The FDIC’s August 2026 proposal for BISDO and RAMP certification is intended to standardize this due diligence exchange — helping banks receive structured assessments they can evaluate once, across multiple vendor relationships. For the background on that initiative, see our earlier coverage of the BISDO/RAMP framework. The framework doesn’t create a safe harbor, but it does signal where regulators expect the industry to move.
For context on what examiners specifically look for in vendor due diligence documentation under OCC Bulletin 2023-17, see our breakdown of the critical vendor due diligence file. For the DORA parallel — which has created third-party risk documentation requirements for US fintechs with EU operations — see our DORA ICT register analysis.
Concentration Risk: The Exposure Banks Aren’t Measuring Well
One enforcement-adjacent risk that has gotten less attention than the consent order pattern is concentration risk in BaaS programs. Most community banks entering fintech partnerships think about credit risk and compliance risk. Few systematically think about what happens if their fintech partner’s program grows to represent 20% of the bank’s total deposits — and then exits.
Regulators are thinking about it. Examination teams are asking sponsor banks to demonstrate that they’ve assessed program concentration risk, not just vendor-level due diligence. The questions look like:
- What percentage of your total deposits does the fintech program represent?
- What is your wind-down plan if the fintech exits the program?
- How quickly could you convert the fintech’s customer accounts to direct bank relationships if needed?
- What would a simultaneous exit by your two largest fintech programs do to your funding position?
These are not hypothetical questions in 2026. They are examination questions with expected documented answers.
So What?
The practical impact of the consent order pattern on BaaS programs is this: the due diligence infrastructure you build with your fintech partner will be evaluated as a component of your compliance program — not as a vendor management exercise. For sponsor banks, that means treating fintech partnerships with the same examination readiness posture you apply to your own operations. For fintechs, it means that your compliance program’s quality directly affects your access to sponsor bank relationships, your concentration limit, and your program’s survivability if your bank partner changes its risk appetite.
Here’s where most programs are underdeveloped:
Ongoing monitoring, not just onboarding. OCC 2023-17 is explicit that one-time due diligence is insufficient. Most fintech-bank programs do thorough onboarding due diligence and then shift to annual questionnaires. Examiners are asking about continuous monitoring — automated compliance metrics, real-time alerts on KRIs, and documented escalation when monitoring flags an issue.
Subcontractor visibility. Fintechs that can produce a current map of their material subcontractors, with documented risk assessments for each, answer the fourth-party question before it’s asked. Most can’t do this without a structured exercise.
Documented wind-down planning. Both sides need it. The bank’s wind-down plan for the fintech program and the fintech’s runoff plan for customer accounts should be in writing and reviewed at least annually. Synapse didn’t have one. Its sponsor banks didn’t have one either.
The Third-Party Risk Management (TPRM) Kit includes vendor due diligence questionnaires, ongoing monitoring templates, a fourth-party risk assessment framework, concentration risk tracking, and contract review checklists designed for bank-fintech relationships. It was built around the 2023 Interagency Guidance requirements — so your documentation answers the examination questions regulators are now asking, not the ones they were asking in 2019.
Sources:
- OCC Third-Party Relationships: Interagency Guidance on Risk Management (Bulletin 2023-17)
- Who Owns the Compliance Failure? Bank-Fintech Liability Allocation in BaaS Programs (National Law Review)
- FDIC Considers Industry Standard-Setting Organization for Third-Party Service Providers (Consumer Finance Monitor, August 2026)
- BaaS Sponsor Bank Liability: 2026 Fintech Compliance Guide (DeRisk Partners)
- Third-Party Oversight Requirements for Sponsor Banks (Canarie)
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
If the bank-fintech agreement assigns compliance responsibility to the fintech, is the bank protected from enforcement?
What does the 2023 Interagency Guidance add specifically for bank-fintech and BaaS relationships?
What is fourth-party risk and why are examiners focusing on it?
What does concentration risk mean in a third-party context?
What does the FDIC's BISDO/RAMP program mean for fintech compliance requirements?
What should a fintech do today to demonstrate third-party risk compliance to its bank partner?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
OCC's 2026 Third-Party Risk Guidance Rewrite: What Banks Should Change Now
The 2026 third-party risk guidance proposal rewrites vendor tiering and gives community banks leverage with core providers.
Sep 11, 2026
Third-Party Risk
Everest Ransomware Hit Citizens Bank and Frost Bank Through a Vendor Nobody Will Name. Six Class Actions Later, Here's What Your TPRM Program Needs.
In April 2026, the Everest ransomware group claimed 3.65 million records from Citizens Bank and Frost Bank via a shared third-party vendor. Neither bank has named the vendor. Six class actions were filed against the banks. Here is what this means for your TPRM program.
Sep 10, 2026
Third-Party Risk
NYDFS Said It in October. Examiners Are Checking in 2026. What Your Vendor Program Needs to Reflect the Part 500 Third-Party Guidance.
NYDFS's October 2025 industry letter on third-party cybersecurity risk established that covered entities cannot delegate Part 500 compliance to vendors. With MFA, asset inventory, and annual certification requirements now fully active, examiners are reviewing whether vendor programs actually reflect the guidance — not just acknowledge it. Here's what your TPRM program needs.
Sep 7, 2026