Legislative Pulse

Banks and Fintechs Share Regulatory Risks

By 16/08/2026 3 min read 19 views
Banks and Fintechs Share Regulatory Risks - fintech risks
Banks and Fintechs Share Regulatory Risks

Regulators have consistently held banks accountable for compliance failures in Banking-as-a-Service (BaaS) programs, with the Federal Deposit Insurance Corporation (FDIC), Office of the Comptroller of the Currency (OCC), and Federal Reserve issuing consent orders against seven sponsor banks between 2022 and 2025. The pattern is clear: chartered banks, not their fintech partners, bear the regulatory consequences of fair lending and Bank Secrecy Act (BSA)/Anti-Money Laundering (AML) failures.

The FDIC, OCC, and Board of Governors of the Federal Reserve System’s June 2023 Interagency Guidance on Third-Party Relationships: Risk Management codified this principle, stating that third-party use does not diminish or remove a banking organization’s responsibility to perform all activities in a safe and sound manner, in compliance with applicable laws and regulations.

They issued guidance to clarify the responsibility of banks in BaaS programs.

The following table summarizes regulator enforcement actions taken in the past few years:

      • Unsafe/unsound fair lending practices; weak oversight of fintech partners’ credit models (Reg. B/ECOA)
      • Systemic BSA/AML internal controls breakdowns; weak independent testing; failure to remediate 2022 deficiencies; “troubled condition” designation
      • Failure to maintain adequate compliance management system for consumer financial protection regulations
      • Inadequate internal controls and information systems relative to scope of third-party relationships, risk management, and compliance with AML/BSA controls, training, and testing

Regulators have consistently held the sponsor bank—not the fintech—responsible for compliance failures and now treat the absence of a wind-down contingency plan as an independent violation.

This enforcement pattern is a structural feature of bank regulatory law.

The Bank Secrecy Act (31 U.S.C. § 5311 et seq.) and its implementing regulations impose BSA/AML obligations directly on “banks” as defined at 31 CFR 1010.100(d).

Each federal banking agency’s regulations—including 12 CFR 21.21 (OCC), 12 CFR 208.63 (Federal Reserve), and 12 CFR 326.8 (FDIC)—require the bank itself to maintain a multi-part BSA program: internal controls, independent testing, a designated BSA officer, ongoing training, and appropriate risk-based procedures for ongoing customer due diligence.

Fintech partners are technology providers with less stringent AML requirements than banks.

The Synapse Financial Technologies (Synapse) bankruptcy has become a test case for contract provisions that attempt to shift the economic consequences of compliance failures.

Related: San Francisco cuts parental leave eligibility

Synapse operated as middleware connecting approximately 100 fintechs to partner banks, serving roughly 10 million end users.

When a planned asset sale to TabaPay collapsed in May 2024, Synapse cut off partner banks’ access to its technology platform, freezing consumer access to funds.

The Consumer Financial Protection Bureau (CFPB) commencing an adversary proceeding in August 2025 and entering a stipulated judgment in September 2025, allocating approximately $46 million to victims from the CFPB’s Civil Penalty Fund.

Courts are scrutinizing broad-form “no-fault” indemnities—particularly where there is bargaining power imbalance—and reading indemnification clauses narrowly against a party seeking to escape a nondelegable statutory duty.

Sophisticated market participants should draft contracts that anticipate regulatory expectations instead of merely allocating blame after the fact, including provisions for regulatory risk termination triggers.

The contract should explicitly acknowledge that BSA/AML, fair lending, and safety-and-soundness compliance ownership is nondelegable and remains with the bank.

Within that framework, the fintech should provide representations and ongoing covenants, including BSA/AML and Office of Foreign Assets Control (OFAC) program maintenance, fair lending data provision, and beneficial ownership and ledger reconciliation recordkeeping.

Liability caps and indemnification provisions should be calibrated to specific compliance functions, with tiered caps that reflect the actual risk of each compliance obligation.

Termination and wind-down provisions should include orderly wind-down planning and data transition protocols to minimize consumer harm and creditor recovery uncertainty.

Banks and their partners can minimize the risk of compliance failures by drafting contracts that prioritize regulatory compliance and risk management.

Leave a Comment

Your email address will not be published. Required fields are marked *