\n\n

In our client alert of September 30, 2026,1 we provided an executive summary of federal banking regulators’ Proposed Third-Party Risk Management Guidance (the “Proposal”), a related joint statement on community banks’ engagement with core service providers, and a proposed Federal Reserve guide for traditional community banks (the “Community Bank Guide”).2 This blog post covers what these agency pronouncements mean for fintechs and the banks that sponsor their programs.

The Proposal’s effect on a fintech turns on the model it uses. In a vendor model, the fintech supplies software or services the bank uses for its own customers, whereas in a partnership model, the fintech markets and distributes the bank’s products directly to consumers. The Community Bank Guide explicitly excludes “complex bank-fintech partnerships,” or relationships where “the fintech company, rather than the bank, markets, distributes, or otherwise provides access to the products or services.”3 The result is two tracks: greater flexibility for vendors, and a set of risks that may limit how much relief partnership programs actually gain.

The Vendor Model

For fintechs that sell to banks, the Proposal changes diligence, contracting, and subcontractor oversight. The Community Bank Guide and an anticipated FDIC certification program are also relevant for vendors.

Diligence. Where a vendor lacks a long operating history, the Proposal permits a bank to rely on outside sources, including peer bank feedback, trade group input, public information, management qualifications, and outside experts, in assessing whether engaging with the third party is within the bank’s risk appetite. For a startup vendor with a limited operating history, that may allow a bank to onboard the vendor based on references and management experience rather than on a limited track record. One limit applies: where a vendor is “unable or unwilling” to provide what the bank reasonably requests, outside sources alone “may not be sufficient” to proceed.4

Contracts. The guidance contains “no generally applicable expected contract terms.” A bank with limited negotiating leverage that cannot obtain every provision it wants may still “reasonably proceed.”5 The absence of a term an examiner considers a best practice will not, by itself, be a basis for an adverse finding. Conversely, this means the argument that a bank needs a particular clause because the guidance requires it is no longer valid.

Subcontractors. Fintech products commonly rely on subcontractors, including cloud hosting, identity verification, data aggregation, and card processing, which the existing guidance required banks to treat as fourth-party vendors requiring separate diligence. The Proposal changes this: a vendor’s use of subcontractors “does not typically create an independent third-party relationship,” and banks may oversee subcontractors through their contract with the vendor. Vendors should expect questions about their own subcontractor programs rather than direct bank outreach to subcontractors, though the bank’s ultimate responsibility for the risk remains.6

The Community Bank Guide. The Guide is a separate Federal Reserve Proposal for the smaller banks it supervises, defined as those under $30 billion in assets that focus on traditional banking in their local communities. The Guide is not a rule, and it applies only to those banks. It addresses eight kinds of vendors a community bank typically uses (core systems, IT, cybersecurity, payments and digital banking, loan systems, card issuing and processing, BSA/AML platforms, and fraud prevention) and, for each vendor, sets out what a bank may consider in due diligence, contract negotiation, and ongoing monitoring.7 These lists are things a bank may consider, but are not requirements. Two features make this guidance relevant to fintechs that sell to banks of any size.

First, six of the eight categories are markets in which fintechs are the principal sellers, and the lists are specific: the BSA/AML category, for example, covers how quickly sanctions-list updates must be applied, the bank’s right to adjust alert thresholds, and the bank’s ownership of alert histories and SAR filings “throughout and beyond the contract term.”8 No other agency document describes vendor diligence at this level of operational specificity and organizes it by vendor type. In the absence of directly applicable guidance, the industry may treat the Guide’s lists as a de facto reference, though their practical effect will not be clear until the Guide is finalized.

Second, where a vendor’s financial information cannot be independently verified, the Guide lets a bank take on the relationship anyway and manage the risk by contract, for example by requiring financial information later, requiring insurance, or placing a limit on growth until the vendor’s performance can be assessed.9 For a vendor with this risk profile, these accommodations and alternatives to independently verified financial information may lower the barrier to entry at the banks the Guide covers.

Certification. The Proposal allows banks to rely on “standard-setting and certification organizations.” The FDIC is reported to be developing such an organization. A July draft term sheet reported by Bloomberg Law would establish a voluntary Banking Innovation Standards Development Organization (“BISDO”) and a certification program, Risk-Assessed, Manageable Partnerships (“RAMP”). The FDIC has not proposed it formally, and as described, a certification from RAMP would carry neither an agency endorsement nor a safe harbor.10 On the Proposal’s own terms, a certification would be an input rather than a substitute, as “it is important for effective risk management to be based on the banking organization’s own specific circumstances and performance criteria for the activity,” with the Proposal further noting that even agency examination reports on service providers are “not intended as a proxy or substitute” for a bank’s diligence.11 In practice, a certification may shorten a bank’s diligence but, on the Proposal’s current text, would not replace it. The Community Bank Guide also permits reliance on independent assessments where a community bank “is generally not expected to have the technical expertise” to assess a vendor itself.12 Whether a certification would be treated like those assessments, whether banks of every size may rely on certifications for lower-risk relationships, and whether a bank’s reliance on a certification would itself be treated as a reasonable decision, are questions the comment period could resolve.

The Partnership Model

The agencies state that the Proposal is intended to benefit partnership programs, removing language from existing guidance that “may unduly impede fintechs from entering partnerships with banking organizations.”13 Whether it will have that effect is less certain. Three risks temper the relief: (1) the consumer laws that govern partnership programs; (2) the withdrawal of the only written examination standard for these programs, without a replacement; and (3) state enforcement. None is a foregone conclusion, and each is worth examining now.

Classification. A relationship is considered “higher-risk” under the Proposal if its failure could cause an “actual non-trivial violation of law or regulation” with a material likelihood of that outcome.14 The risk-tier rating matters because the Proposal’s relief is graduated. Lower-risk relationships benefit from streamlined diligence and reduced monitoring, while higher-risk relationships call for more comprehensive oversight and additional staffing.15 Partnership programs are governed by consumer protection statutes, the Bank Secrecy Act, FDIC deposit insurance rules, and, for banks over $10 billion in assets, CFPB service-provider expectations. A failure by the fintech partner, whether in disclosures, recordkeeping, or customer identification, could constitute a violation of one or more of those laws. Because the fintech performs the customer-facing function at scale, such a violation may be difficult to characterize as trivial. Because the activity carries that risk, one can see a bank reasonably designating such a program as higher-risk where it might otherwise designate a vendor relationship as lower-risk.16 As a result, partnership programs arguably gain less from the Proposal than vendor relationships do. Each sponsor bank will make and document its own determination, but a program designated as higher-risk may remain subject to diligence and monitoring expectations substantially similar to those under the existing guidance. The principal change is that the bank must be able to articulate the basis for the designation. For a fintech partner, that suggests the diligence, reporting, and monitoring its sponsor bank will require is less likely to be reduced as a result of the Proposal.

The withdrawal of the 2024 statement. After the program failures of 2024, the agencies issued the Joint Statement on Banks’ Arrangements with Third Parties to Deliver Bank Deposit Products and Services (“2024 Statement”) describing what examiners look for in a partnership program, including recordkeeping and reconciliation, the allocation of compliance responsibility, and the bank’s ability to identify its own customers. The Proposal withdraws the 2024 Statement and leaves nothing in its place. The Proposal does not address consumer compliance, the FDIC has proposed no guide for the sponsor banks it supervises, and the Federal Reserve’s Community Bank Guide excludes complex partnerships.17 Some view the withdrawal as relief from heightened scrutiny, but the underlying legal obligations remain in force. The limit on examiner findings now comes from a general rule rather than program-specific guidance. Beginning November 2, the OCC and FDIC reserve violation-based findings for substantive violations, those that are a pattern, are systemic, or have more than a minimal effect on customers.18 A partnership program may meet that threshold more readily than a vendor relationship because an error in the program can potentially reach every program customer. The Federal Reserve’s Updated Statement of Supervisory Operating Principles, which governs its examiners, sets no comparable threshold for the institutions the Federal Reserve supervises, including state member banks.19 Withdrawing the statement does not change what an examiner may cite, rather it removes the only written account banks had of where findings were and were not likely.

The allocation gap. In a partnership program, the compliance work, including complaint handling, account recordkeeping, and anti-money-laundering monitoring, is typically divided between the bank and the fintech. The Proposal directs examiners to defer to a bank’s reasonable decisions, but it does not speak specifically to partnership arrangements. Governor Cook, in her statement on the Proposal, welcomed comments on whether the agencies should say more about how consumer-protection, recordkeeping, and anti-money-laundering responsibilities are allocated in bank-fintech partnerships.20 Governor Barr, dissenting, noted that the Community Bank Guide excludes the banks with complex fintech partnerships.21 For a sponsor bank, the practical question is whether a written allocation of compliance responsibilities, with monitoring calibrated to risk, would be treated as a reasonable decision. The comment period may help resolve that question.

State and other enforcement. The federal restraint on supervisory findings does not reach the partner itself. A non-bank fintech is subject to direct enforcement by state attorneys general under state consumer protection law and under the authority the Consumer Financial Protection Act gives them to enforce federal consumer financial law.22 State enforcement does not necessarily track federal supervisory priorities. A program a federal examiner would not question can still draw a state investigation, and for partnership programs, that is where the exposure has been most consistent. The FTC’s authority remains in place, as does the CFPB’s, both over banks above $10 billion in assets and over a fintech in its own right where the fintech itself offers consumer financial products or services directly to consumers.23 None of those authorities is bound by the banking agencies’ narrower standard for examiner findings.

What sponsor banks and fintechs may wish to consider now

Most of the contracting discipline a sponsor bank is likely to want results from market practices that arrived after 2024, including a written allocation of compliance responsibility, ledger and reconciliation access, audit rights that reach subcontractors, wind-down provisions, and indemnification and liability terms calibrated to who controls what.24 A bank that has these contracting practices should consider keeping them. Two things, however, are different for a sponsor bank because of the Proposal, and one is different for a fintech that sells to it.

Evidence of oversight, not only allocation. Examiner deference under the Proposal runs to the bank’s decisions about how it structures and oversees the program, including how compliance work is allocated between the bank and its fintech partner, but it does not reach the underlying obligation itself, which remains the bank’s regardless of how the work is divided.25 Most program agreements specify who is responsible for what, but responsibility on paper is not the same as evidence of oversight in practice. To be best positioned for examinations, a bank should document that allocated responsibilities were actually tested through complaint reviews, testing results, and remediation records that demonstrate active monitoring rather than passive reliance on the partner’s representations. A pattern of undetected or unremediated errors at the program level is the kind of finding that can escalate into a violation-based determination under the Proposal’s higher-risk classification standard. Fintech partners should be prepared for requests for testing access, complaint data, and remediation records, as a bank’s underlying compliance obligation remains regardless of how the final guidance reads.

Self-identification. For a Federal Reserve-supervised bank, the Federal Reserve’s Updated Statement of Supervisory Operating Principles adds a reason for a bank to find problems first. A safety-and-soundness deficiency the bank identifies and promptly begins to remediate is presumptively a supervisory observation rather than a matter requiring attention or a formal finding a bank must fix.26 Whether that reaches a violation-based finding the statement does not say, but in a program where errors propagate quickly, program-level testing will be rewarded.

For fintechs that sell to banks. The Community Bank Guide’s eight categories are the list a community bank customer will likely work from going forward, and a fintech may wish to map its diligence package and standard contract to those categories now.

Comments on both proposals are due November 16, 2026. The allocation of compliance responsibility between a sponsor bank and its fintech partner is the Proposal’s central unresolved question, and Governor Cook’s invitation for comment on that point is the most direct opening for sponsor banks and fintechs to shape the final guidance.

We will follow the comment process and report when the guidance is final. Please contact any of the authors or your usual firm contact with questions about the Proposal or about submitting comments.