Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Feature Third-Party Risk

The Contract Says It's the Fintech's Problem. Seven BaaS Consent Orders Say Otherwise.

Between 2022 and 2025, the FDIC, OCC, and Federal Reserve issued consent orders against at least seven sponsor banks in Banking-as-a-Service programs — despite partnership agreements that assigned compliance responsibilities to fintech partners. Here's what every sponsor bank and fintech needs to understand about third-party liability in 2026.

By Rebecca Leung · September 4, 2026 ·
Table of Contents

TL;DR

  • Between 2022 and 2025, the FDIC, OCC, and Federal Reserve issued consent orders against at least seven sponsor banks in Banking-as-a-Service programs — regardless of what their partnership agreements said about compliance responsibilities.
  • The 2023 Interagency Guidance (OCC Bulletin 2023-17) added explicit requirements for fourth-party subcontractor oversight, concentration risk monitoring, and fintech-specific due diligence.
  • A consent order doesn’t care what your contract says: the bank holding the charter bears the regulatory consequence.
  • In 2026, fintech compliance maturity directly affects sponsor-bank relationship terms, due diligence speed, concentration limits, and long-term program viability.

There is a sentence that appears in every BaaS program agreement: “Fintech Partner is solely responsible for ensuring compliance with all applicable laws and regulations in connection with the services it provides to End Users.”

It is a reasonable sentence. It reflects a reasonable allocation of risk between private parties who each understand their respective parts of the program. It also does not protect the sponsor bank from a consent order.

Between 2022 and 2025, the FDIC, OCC, and Federal Reserve issued consent orders against at least seven sponsor banks operating Banking-as-a-Service programs. The pattern is unambiguous: regardless of what the partnership agreement says about compliance responsibilities, it is the chartered bank — not its fintech partner — that bears the regulatory consequences of fair lending and Bank Secrecy Act failures. The fintech may face its own civil liability. The charter is the bank’s.

That dynamic has reshaped what both sides of a BaaS relationship need to build, prove, and document in 2026.

Why the Contract Doesn’t Transfer Regulatory Accountability

The core legal reality of banking regulation is that regulatory obligations follow the charter. When the OCC or FDIC examines a bank, they are examining the bank — not the fintech program, not the middleware platform, not the subcontractor stack. The bank’s ability to demonstrate compliance is evaluated against what the bank’s own oversight program produced, not against representations the bank received from its partners.

That’s not a technicality. It’s the reason the 2024 Synapse collapse resulted in regulatory action and proposed rulemaking aimed at sponsor banks and at the FDIC’s custodial deposit recordkeeping rules — not at Synapse itself. The bank sponsors had a duty to maintain accurate deposit records for their customers. That duty belonged to the charter, regardless of the fact that the middleware platform was managing the ledger.

The enforcement record from 2022 through 2025 reinforces this consistently. When an OCC- or FDIC-supervised bank’s fintech partner runs a BSA/AML program that fails to file required SARs, or a fair lending program that produces discriminatory outcomes in credit decisions, the consent order that follows names the sponsor bank. The consent order requires the bank to remediate — which often means rebuilding its oversight program for the fintech partner, not just directing the fintech to fix the problem.

What the 2023 Interagency Guidance Changed for BaaS

The 2023 Interagency Guidance on Third-Party Relationships — OCC Bulletin 2023-17, issued jointly with the FDIC and Federal Reserve — replaced the OCC’s 2013 guidance and created a unified interagency standard for the first time. The timing was deliberate: by 2023, the BaaS enforcement pattern was already established, and the guidance expanded explicitly to address it.

Several additions to the 2023 guidance are directly relevant to fintech and BaaS relationships:

Fintech partnerships are explicitly in scope. The 2023 guidance defines a “third-party relationship” as “any business arrangement between a banking organization and another entity, by contract or otherwise.” That last phrase matters: relationships where no formal contract exists — pilots, informal referral arrangements, data-sharing agreements — are covered. Fintech partnerships have always been third-party relationships; the 2023 guidance makes the point explicit.

Concentration risk is now a required assessment. The guidance requires banking organizations to assess concentration risk when a single third party — or a small number of third parties — represents material exposure to the bank. In BaaS programs, this often manifests in two directions: fintech programs that represent a material share of the bank’s total deposits or payment volume, and middleware or core platforms that multiple fintech programs depend on simultaneously. Both create concentration risk. Both require documented assessment.

Fourth-party oversight is an expectation, not a recommendation. Examiners are actively testing whether banks can identify their third parties’ material subcontractors. For a BaaS sponsor bank, this means understanding not just what your fintech partner does, but what infrastructure it runs on — the cloud provider, the payment processor, the data vendor — and whether you have visibility into disruptions or failures at that level.

The Subprocessor Problem

The Synapse collapse made fourth-party risk concrete. Synapse was not a bank. It was middleware — a platform connecting fintech programs to their sponsor banks and managing the ledger that tracked which consumer owed what dollar at which bank. When Synapse filed Chapter 11 in April 2024, the trustee discovered that the ledger couldn’t reconcile which customer was owed which dollars. More than 200,000 customer accounts and approximately $160 million in deposits were frozen.

The sponsor banks had done due diligence on Synapse as a third party. None of them had assessed what happened to their customers’ funds if Synapse itself failed.

That’s the fourth-party risk problem. Your fintech partner runs on infrastructure you may never have evaluated. That infrastructure can fail in ways your contract with the fintech doesn’t address. And when it does, the regulatory question is whether the bank’s oversight program gave it reasonable visibility into that risk.

The 2023 Interagency Guidance is explicit: banks should understand their critical vendors’ key subprocessors and the risk those subprocessors represent. For examiners, “I didn’t know the middleware ran on that cloud provider” is not a satisfying answer when the middleware goes down.

Risk LayerDescriptionExaminer Expectation
Third-party (fintech partner)Direct partner relationshipFull lifecycle due diligence, contract review, ongoing monitoring
Fourth-party (partner’s subcontractors)Middleware, cloud infra, payment processors your partner usesIdentification of material subprocessors; assessment of disruption risk
Concentration (program-level)Single fintech represents material deposit share or volumeDocumented concentration risk assessment; contingency planning
Concentration (platform-level)Multiple programs depend on same middleware or core systemPlatform-level disruption scenario; wind-down planning

What Fintechs Must Demonstrate in 2026

The enforcement pattern has changed the due diligence conversation from “do you have these policies?” to “can you prove they work?”

Banks are now required to assess five areas during fintech partner due diligence:

  1. Financial condition: Audited financials, burn rate, runway, and capital adequacy. A fintech that can’t produce 12-month audited financials is a material gap in the bank’s ability to assess financial risk.

  2. Compliance management: The documented structure of the compliance program — policies, procedures, training, testing, and escalation. Not a description of it. The actual documents.

  3. Information security program: Documented controls, penetration testing results, SOC 2 report if applicable, and incident response procedures. Banks are increasingly requesting evidence of controls, not just attestation.

  4. Business continuity and recovery capabilities: What happens if the fintech fails? A BCP that only covers technology outages — not the scenario where the fintech program is wound down — does not answer the question examiners are asking.

  5. Subcontractor management: Who are your material subcontractors, what do they do for you, and how would their failure affect your bank partner’s customers? This is the fourth-party question, and it’s the one most fintechs aren’t prepared to answer.

The FDIC’s August 2026 proposal for BISDO and RAMP certification is intended to standardize this due diligence exchange — helping banks receive structured assessments they can evaluate once, across multiple vendor relationships. For the background on that initiative, see our earlier coverage of the BISDO/RAMP framework. The framework doesn’t create a safe harbor, but it does signal where regulators expect the industry to move.

For context on what examiners specifically look for in vendor due diligence documentation under OCC Bulletin 2023-17, see our breakdown of the critical vendor due diligence file. For the DORA parallel — which has created third-party risk documentation requirements for US fintechs with EU operations — see our DORA ICT register analysis.

Concentration Risk: The Exposure Banks Aren’t Measuring Well

One enforcement-adjacent risk that has gotten less attention than the consent order pattern is concentration risk in BaaS programs. Most community banks entering fintech partnerships think about credit risk and compliance risk. Few systematically think about what happens if their fintech partner’s program grows to represent 20% of the bank’s total deposits — and then exits.

Regulators are thinking about it. Examination teams are asking sponsor banks to demonstrate that they’ve assessed program concentration risk, not just vendor-level due diligence. The questions look like:

  • What percentage of your total deposits does the fintech program represent?
  • What is your wind-down plan if the fintech exits the program?
  • How quickly could you convert the fintech’s customer accounts to direct bank relationships if needed?
  • What would a simultaneous exit by your two largest fintech programs do to your funding position?

These are not hypothetical questions in 2026. They are examination questions with expected documented answers.

So What?

The practical impact of the consent order pattern on BaaS programs is this: the due diligence infrastructure you build with your fintech partner will be evaluated as a component of your compliance program — not as a vendor management exercise. For sponsor banks, that means treating fintech partnerships with the same examination readiness posture you apply to your own operations. For fintechs, it means that your compliance program’s quality directly affects your access to sponsor bank relationships, your concentration limit, and your program’s survivability if your bank partner changes its risk appetite.

Here’s where most programs are underdeveloped:

Ongoing monitoring, not just onboarding. OCC 2023-17 is explicit that one-time due diligence is insufficient. Most fintech-bank programs do thorough onboarding due diligence and then shift to annual questionnaires. Examiners are asking about continuous monitoring — automated compliance metrics, real-time alerts on KRIs, and documented escalation when monitoring flags an issue.

Subcontractor visibility. Fintechs that can produce a current map of their material subcontractors, with documented risk assessments for each, answer the fourth-party question before it’s asked. Most can’t do this without a structured exercise.

Documented wind-down planning. Both sides need it. The bank’s wind-down plan for the fintech program and the fintech’s runoff plan for customer accounts should be in writing and reviewed at least annually. Synapse didn’t have one. Its sponsor banks didn’t have one either.

The Third-Party Risk Management (TPRM) Kit includes vendor due diligence questionnaires, ongoing monitoring templates, a fourth-party risk assessment framework, concentration risk tracking, and contract review checklists designed for bank-fintech relationships. It was built around the 2023 Interagency Guidance requirements — so your documentation answers the examination questions regulators are now asking, not the ones they were asking in 2019.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

If the bank-fintech agreement assigns compliance responsibility to the fintech, is the bank protected from enforcement?
No. The pattern in BaaS enforcement actions from 2022 to 2025 is consistent: regardless of what the partnership agreement says about compliance responsibilities, it is the chartered bank that bears the regulatory consequence of fair lending, BSA/AML, and consumer protection failures. Contracts can allocate risk between private parties; they cannot reallocate regulatory accountability from a chartered institution to an unchartered fintech.
What does the 2023 Interagency Guidance add specifically for bank-fintech and BaaS relationships?
OCC Bulletin 2023-17, issued jointly with the FDIC and Federal Reserve, expanded on earlier third-party risk guidance to explicitly address fintech partnerships, BaaS arrangements, and concentration risk. New requirements include monitoring for fourth-party (subcontractor) risk, specific due diligence protocols for fintech partnerships, and concentration risk assessment when a single third party represents material exposure. The guidance applies the same lifecycle framework — planning, due diligence, contracting, monitoring, and termination — to fintech partners as to any other third party.
What is fourth-party risk and why are examiners focusing on it?
Fourth-party risk refers to the risk posed by a third party's subcontractors and downstream vendors — the companies your vendors rely on to deliver their service to you. In BaaS arrangements, this often means the cloud infrastructure provider, payment processor, or data vendor that your middleware or fintech partner depends on. Examiners are focusing on it because the Synapse collapse in 2024 demonstrated how middleware failure could freeze consumer funds across multiple fintech programs simultaneously, exposing the bank sponsor's inability to see or control risks two layers down the stack.
What does concentration risk mean in a third-party context?
Concentration risk in third-party management refers to the risk of having critical business functions or exposures concentrated in a single vendor, or in a small number of vendors. For BaaS sponsor banks, concentration risk can arise when multiple fintech programs depend on the same middleware or core system, or when a single fintech partner represents a material percentage of the bank's total deposit base or payment volume. Regulators are actively asking about concentration risk assessments for critical vendors and BaaS arrangements.
What does the FDIC's BISDO/RAMP program mean for fintech compliance requirements?
The FDIC's August 2026 proposal for a Banking Industry Standards Development Organization (BISDO) and voluntary RAMP certification is designed to help banks evaluate fintech service providers more efficiently — but it does not create a safe harbor, a blacklist, or a substitute for individual due diligence. RAMP certification, if implemented, would be one data point in a bank's due diligence process. The underlying enforcement standard — bank accountability regardless of contract language — does not change under BISDO.
What should a fintech do today to demonstrate third-party risk compliance to its bank partner?
The OCC's 2023 Interagency Guidance lays out what banks are required to assess during due diligence: financial condition, compliance management, information security program, business continuity and recovery capabilities, and subcontractor management. Fintechs that can produce documented evidence across all five areas — not just describe them — materially reduce due diligence friction. This includes vendor risk assessments for your own critical subcontractors, because your bank partner is now required to understand what's in your stack.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.