A fintech partnership can give a community bank deposit growth, fee income, and reach it could not build alone. It can also transfer the institution's compliance obligations to a party that does not hold them, which is the failure mode behind most of the enforcement activity in this space.
The governing principle is simple and repeatedly ignored: the bank holds the charter, so the bank holds the obligations. A partner can perform the work. It cannot assume the responsibility.
Arrangements differ enough that "fintech partnership" is not a useful risk category on its own.
Deposit gathering. The fintech markets and services the customer relationship; deposits sit on the bank's balance sheet. The bank gets funding and fee income, and takes on the customer identification, deposit compliance, and BSA obligations for customers it never meets.
Banking as a service. The bank provides the regulated rails — accounts, payments, cards — while one or more fintechs own the customer experience. Often layered, with a middleware provider between the bank and the end programs, which is where visibility is lost.
Lending partnerships. The fintech originates or markets, the bank funds or holds. This raises questions about which party is the actual lender, and about compliance with the full consumer lending rule set for loans the bank's own staff never underwrote.
Payments and card programs. The bank sponsors issuance or acquiring, with the program manager operating the product.
Technology provision only. The fintech supplies software to the bank with no customer-facing role. This is ordinary vendor risk, and it is the only one of these models that is.
The first four all share a feature that distinguishes them from vendor relationships: a third party stands between the bank and the customer.
The bank does. Specifically and non-delegably:
Customer identification and due diligence. The bank's CIP obligation applies to customers onboarded through a partner's interface. The bank must be satisfied that identification and verification actually occurred to its standard, which requires access to the records rather than an attestation.
BSA/AML monitoring and reporting. Suspicious activity in partner-originated accounts is the bank's to detect and report. That requires transaction-level data in a form the bank's monitoring can consume — not a monthly summary.
Consumer compliance. Reg E error resolution, Reg DD disclosure accuracy, Reg B adverse action notices, and fair lending analysis all attach to the bank. If the fintech's app mishandles a Reg E dispute, the bank has the violation.
UDAAP. This is the sharpest edge. The fintech's marketing, onboarding flow, fee presentation, and app design create the net impression the customer receives, and the bank is accountable for it. A bank that has never reviewed its partner's marketing has unexamined UDAAP exposure on every acquisition channel.
Deposit insurance representations. How the product describes FDIC coverage is a bank obligation, and misdescription in a partner's materials is a serious problem.
In layered arrangements the bank may hold funds in an omnibus or custodial structure while the record of which end customer owns what sits with a fintech or a middleware provider.
If that record is unreliable — or if the party maintaining it fails — the bank may be unable to determine who owns the money. End customers lose access to funds while reconciliation is attempted, and the bank is the regulated party facing customers, regulators, and press.
This is not hypothetical. A middleware failure in this pattern left large numbers of end customers unable to reach their money while ledgers were disputed, and it reshaped supervisory attention to these arrangements.
The controls that address it: the bank maintaining or independently reconciling its own record of beneficial ownership at the account level, at a frequency measured in days rather than months; contractual rights to the data; and a tested ability to reconstruct ownership without the partner's cooperation.
Where accounts are held in a custodial structure, pass-through insurance to the end customers depends on recordkeeping conditions being satisfied — the fiduciary relationship disclosed in the account records and the interests of the owners ascertainable.
If those conditions fail, coverage may not pass through, and customers who were told their funds were insured may not be. Because the representation was made in the bank's name, the consequence lands on the bank.
Beyond ordinary third-party diligence, these arrangements warrant:
Two failure patterns recur.
Approval without capacity. A bank approves a program its compliance and operations functions cannot support at scale, then grows into a monitoring gap. Growth controls exist for this reason, and they should be enforced by system limits rather than by intention.
The revenue owner also owning the risk assessment. Where the executive whose results depend on the partnership also decides whether it is adequately controlled, the assessment is compromised. The separation should mirror credit approval.
The board should approve material partnerships explicitly, receive reporting on program volumes, complaint themes, and monitoring results, and be told plainly what proportion of the institution's deposits or fee income depends on a single partner.
The scenario to plan for is a partner that fails or must be terminated while it holds the customer relationship for a material share of the bank's deposits.
Questions that need answers before signing: can the bank identify and contact the end customers directly? Can it reconstruct account ownership without the partner? Can it fund an outflow if a large share of those deposits leaves at once? Who services the customers during transition? What happens to in-flight transactions?
An institution that cannot answer these has a concentration risk it has not measured, regardless of how the partnership is performing.
Structured coverage is available through the Certified Regulatory Vendor Program Manager program, the Certificate in Risk Management, and our bank compliance training.
These arrangements are not inherently imprudent, and the institutions that have done well with them share three characteristics.
They treated it as a line of business, not a vendor relationship. Dedicated staff, dedicated monitoring, and a program budget proportional to the revenue — not an addition to an existing compliance officer's caseload.
They kept their own record. Independent reconciliation of account-level ownership, so the bank is never dependent on a partner's ledger to answer who owns the money.
They constrained growth deliberately. Volume limits enforced in systems, raised only when the monitoring capability was demonstrably ahead of the volume.
The institutions that struggled generally did the opposite: accepted a program for the deposit growth, relied on the partner's compliance representations, had no independent visibility into transactions or ownership, and discovered the gap when a regulator or a partner failure exposed it.
For a community bank weighing an approach, the useful question is not whether the economics work. It is whether the institution is prepared to run a compliance program for customers it will never meet, onboarded through an interface it does not control, at a volume that may grow faster than its staffing. If the answer is no, the correct response is to decline rather than to sign and hope the partner is diligent.
Lending partnerships carry an exposure the deposit models do not, and it deserves separate treatment because the analysis is legal rather than operational.
Where a fintech markets and services a loan while a bank funds or holds it, the question arises of which party is the actual lender. It matters because banks and non-banks operate under different rules: a bank may export certain terms across state lines in ways a non-bank partner cannot, and the availability of that treatment depends on the bank genuinely being the lender rather than nominally so.
Arrangements where the bank's role is thin — no underwriting judgment, minimal retained economic interest, immediate sale of the whole loan, and a partner controlling the credit policy — have attracted challenges on the theory that the bank is a conduit. Litigation and state enforcement in this area have turned on facts about the substance of the relationship rather than on its documentation.
The practical implications for a community bank considering a lending partnership:
Retain genuine underwriting authority. The bank's credit policy should govern, the bank should be able to decline, and it should exercise that ability. A bank that has never declined a loan its partner presented has weak evidence of independent judgment.
Hold real economic exposure. Retaining a meaningful interest is both a credit discipline and evidence of the bank's role.
Own the compliance obligations visibly. Adverse action notices, fair lending analysis, servicing conduct, and disclosure accuracy are the bank's, and the bank should be able to show its own review of each rather than the partner's assurance.
Get counsel involved on structure, not just on contract terms. This is one of the areas where the legal analysis genuinely determines whether the model works.
The broader point is that a lending partnership is a credit business the bank is entering with a partner's origination capability, not a fee arrangement. Institutions that treat it as the latter tend to accept the credit and the legal exposure without having priced either.
The bank. Customer identification, BSA monitoring and reporting, consumer compliance including Reg E and Reg DD, UDAAP, and deposit insurance representations all attach to the chartered institution. A partner can perform the work, but the obligation is non-delegable, and supervisory expectations are explicit that using a third party does not diminish the bank's responsibility.
Where the bank holds funds in an omnibus or custodial structure while a fintech or middleware provider maintains the record of which end customer owns what, an unreliable record or a provider failure can leave the bank unable to determine ownership. End customers lose access while reconciliation is attempted, and the bank is the regulated party facing the consequences.
Only if the recordkeeping conditions are satisfied — the fiduciary relationship disclosed in the account records and the interests of the owners ascertainable. Where those conditions fail, coverage may not pass through, and because the representation was made in the bank's name the consequence falls on the bank.
Explicit allocation of compliance responsibility with the bank's ultimate accountability stated, audit and regulator access to the partner's records, specified data ownership and delivery including transaction-level data for monitoring, the right to approve marketing before use, incident notification timeframes, complaint data delivery, growth controls, termination rights including for regulatory reasons, and termination assistance for orderly customer transfer.
Because the common failure is approving a program the bank's compliance and operations functions cannot support at scale, then growing into a monitoring gap. Limits should be enforced by system configuration rather than by intention, and raised only when monitoring capability is demonstrably ahead of volume.
Whether the bank can identify and contact end customers directly, reconstruct account ownership without the partner, fund a large simultaneous outflow, service customers during a transition, and handle in-flight transactions. An institution unable to answer these holds an unmeasured concentration risk regardless of current performance.


