Skip to content

FinTech and the office of the CFO

Subscribe

Banking-as-a-service: where the regulatory responsibility actually sits

Understand where regulatory responsibility sits in banking-as-a-service, including the roles of licensed banks, providers, fintech brands, and customers.

Banking-as-a-service: where the regulatory responsibility actually sits

In every US enforcement action we could verify, the respondent is the bank. Contracts move money between the parties. They do not move the obligation.

The regulatory obligation attaches to the charter, not to the party the customer sees. Everything below the bank layer is allocated by contract.

The argument for banking-as-a-service has always been a division of labour. The bank supplies the charter and the balance sheet. The fintech supplies the product, the interface and the customer. Middleware sits between them and makes the plumbing work. Everyone does what they are good at.

That division works commercially. It does not work as a division of regulatory responsibility, and the enforcement record of the last three years says so with unusual clarity. We went through the orders we could verify against a primary document. In each one, the respondent is the bank, or the bank and its holding company. No fintech, no middleware provider and no programme manager appears as a respondent.

What the orders actually say

Blue Ridge Bank. The OCC entered a consent order on 24 January 2024 for unsafe or unsound practices, failure to correct previously reported problems, and Bank Secrecy Act and anti-money laundering programme deficiencies. It replaced a formal agreement dated 29 August 2022, which is itself the story: this was an escalation, not a first contact.

Article V of that order is titled Third-Party Risk Management and expressly cross-references OCC Bulletin 2023-17, the transmittal for the interagency guidance. The order reaches fintech partners and, in terms, subpartners. The bank could not enter a new fintech relationship, or offer new products through an existing one, without OCC non-objection, and where it could not show that money-laundering risk was effectively controlled it had to obtain no supervisory objection for each fintech relationship and each subpartner before continuing to onboard end users. The order was terminated on 13 November 2025.

Evolve Bank and Trust. The Federal Reserve Board, with the Arkansas State Bank Department, issued an order effective 11 June 2024. The Board's language is worth quoting because it locates the failure precisely: examinations conducted in 2023 found that Evolve engaged in unsafe and unsound banking practices by failing to have in place an effective risk management framework for those partnerships.

The Board also stated that the action was independent of the Synapse bankruptcy proceedings. That is a distinction reporting frequently collapses, and it should not be. Inside the order, one paragraph does more work than any commentary: ledger and sub-ledger responsibilities of the bank and its fintech partners must be clearly defined, established and maintained, including in the event of a material business disruption.

Green Dot. The Federal Reserve issued a combined cease and desist and civil money penalty order effective 19 July 2024, with a penalty of $44 million. Among five unfair or deceptive practice findings, one is the single most useful sentence in this entire area for anyone negotiating a BaaS contract: from August 2020 through at least September 2020, due to a third-party payment processor's data migration error, the bank engaged in an unfair act or practice by failing to release extended authorisation holds in time.

A vendor made the error. The bank committed the violation. That is the whole of banking-as-a-service regulation in one finding.

The order goes further than the finding. Green Dot must refrain from making, or allowing to be made, any misleading representation in connection with any product or service, whether offered directly or through a third party. Within thirty days it had to give a copy of the order to every existing material third-party partner, and to prospective ones before contracting. Its consumer compliance risk management plan must cover products offered through third parties, including service-level standards for those third parties and for their own partners, servicers, vendors and sub-servicers.

Synapse and the ledger

The collapse of Synapse Financial Technologies in April 2024 is usually described as a middleware failure. The regulatory description is narrower and more useful. The FDIC, in its proposed recordkeeping rule of 2 October 2024, set out the arrangement: Synapse provided APIs and infrastructure allowing businesses to embed banking services, held relationships with several insured depository institutions, and in those arrangements the fintech companies developed the user interfaces and application logic and, importantly, maintained the ledgers of their customers, including the deposit amounts attributed to each individual customer.

The FDIC's own words on the consequence were that the bankruptcy resulted in severe hardship for consumers that is deeply troubling to the FDIC. Its proposed fix goes to the point: records maintained as of the end of each day to determine individual beneficial ownership interests in a custodial account and to reconcile those interests to the funds on deposit. The FDIC added that it believes it is unlikely that insured depository institutions currently have all the records necessary.

That proposed rule, Recordkeeping for Custodial Accounts, remains a proposal. It was published on 2 October 2024, the comment period was extended to 16 January 2025, and as at 30 July 2026 it has not been finalised or withdrawn. It was notably not among the proposals the FDIC withdrew in March 2025.

What we have not printed. Figures for the shortfall in end-user funds at Synapse circulate widely. The word shortfall does not appear anywhere in the FDIC's proposed rule, and the range in circulation comes from Chapter 11 trustee filings rather than from any regulator document. We could not reach the docket, so we have not published a number. The case is In re Synapse Fin. Tech., Inc., No. 1:24-bk-10646-MB (Bankr. C.D. Cal.), cited by the FDIC.

The guidance the orders point back to

The Interagency Guidance on Third-Party Relationships was issued by the OCC, Federal Reserve and FDIC on 6 June 2023 and published on 9 June 2023. OCC Bulletin 2023-17 transmits it and rescinds the earlier 2013 and 2020 bulletins. It applies to all banks with third-party relationships, and one of its listed topics is bank-fintech arrangements.

The agencies followed with a request for information on bank-fintech arrangements published on 31 July 2024, with comments extended to 30 October 2024. As of May 2025 the OCC stated that the agencies continue to review the feedback. No successor guidance has issued. In other words, the supervisory expectations in this area are currently set by the 2023 guidance and by the enforcement record, not by a bespoke BaaS rule.

The EU reaches the same place by statute

European law does not need an enforcement pattern to make the point, because it is written into the directive. Article 20(2) of PSD2 provides that payment institutions remain fully liable for any acts of their employees, or any agent, branch or entity to which activities are outsourced. Agents must be entered in the register under Article 14 before they may provide payment services. The Electronic Money Directive goes further in one respect: Article 3(5) provides that e-money institutions shall not issue electronic money through agents at all, though they may distribute and redeem through persons acting on their behalf.

PSD3 and the Payment Services Regulation would rewrite parts of this, and as at 30 July 2026 they are politically agreed but not adopted. PSD2 and the Electronic Money Directive remain the operative law.

What follows for the two sides of the table

For a bank, the practical test is not whether the contract allocates a risk but whether the bank can evidence that it controlled it. Every one of the orders above turns on framework, oversight and records rather than on a single bad transaction. A partner list is not a risk framework, and a right to audit that has never been exercised is not oversight.

For a fintech, the reading is different and slightly counterintuitive. The absence of your name from the enforcement record is not protection. The orders reach you through your bank partner, which is why they bar new programmes without supervisory non-objection and require the order to be handed to every material partner. When a bank's order lands, the fintech's product roadmap is what stops. The commercial exposure is real even where the regulatory exposure sits elsewhere.

And the ledger question is now the first question. If the party that maintains the record of who owns what is not the party that holds the deposits, the reconciliation between those two records is the control that everything else rests on. Both the Evolve order and the FDIC's proposed rule say so directly, from opposite directions.

What we have not printed, part two. Enforcement actions against several other banks in this space are widely discussed. Those institutions are FDIC-supervised and privately held, so there is no public filing route to the order text, and the FDIC's order repository did not return retrievable content. We have named only the three actions we could verify against a primary document. We would rather publish three verified than eight remembered.

This is reporting on regulation as it stood at the date of publication. It is not legal or compliance advice, and obligations differ by jurisdiction and change. Take qualified advice on your own circumstances.

References

Every figure and legal citation in this article is drawn from the sources below. Where an instrument is proposed rather than in force we say so in the text.

  1. Office of the Comptroller of the Currency, Consent order AA-ENF-2023-68, Blue Ridge Bank, N.A., filed as an exhibit, 24 January 2024. https://www.sec.gov/Archives/edgar/data/842717/000119312524015560/d870968dex101.htm

  2. Blue Ridge Bankshares, Form 8-K reporting termination of the OCC consent order, 13 November 2025. https://www.sec.gov/Archives/edgar/data/842717/000119312525280430/brbs-20251113.htm

  3. Board of Governors of the Federal Reserve System, Enforcement action against Evolve Bancorp and Evolve Bank and Trust, 14 June 2024. https://www.federalreserve.gov/newsevents/pressreleases/enforcement20240614a.htm

  4. Board of Governors of the Federal Reserve System, Evolve order, full text, effective 11 June 2024. https://www.federalreserve.gov/newsevents/pressreleases/files/enf20240614a1.pdf

  5. Board of Governors of the Federal Reserve System, Green Dot Bank and Green Dot Corporation, cease and desist order and civil money penalty, effective 19 July 2024. https://www.sec.gov/Archives/edgar/data/1386278/000138627824000037/federalreserveboardconse.htm

  6. Federal Deposit Insurance Corporation, Recordkeeping for Custodial Accounts, proposed rule, 89 FR 80135, published 2 October 2024. https://www.federalregister.gov/documents/2024/10/02/2024-22565/recordkeeping-for-custodial-accounts

  7. OCC, Federal Reserve and FDIC, Request for information on bank-fintech arrangements, 89 FR 61577, published 31 July 2024. https://www.federalregister.gov/documents/2024/07/31/2024-16838/request-for-information-on-bank-fintech-arrangements-involving-banking-products-and-services

How we work. This article was researched and written by the Financy editorial team. We do not republish press releases. Every number and legal citation is checked against a primary source, which is named and linked above. Where an instrument is proposed rather than in force, we say so. Corrections are made openly on the article itself, never by silent edit. If you believe something here is wrong, write to info@financyhub.com and tell us what and why.

Filed under Banking & BaaS · Get The Weekly Brief

The briefing

Keep reading the stack.

One email a week on financial technology and the finance stack.