Overview

Reprinted with permission from Law360.

Fintech partnerships are a core part of many banks' growth strategies, allowing them to reach new customers and generate new revenue streams. Despite these benefits, such arrangements carry operational, compliance, legal and regulatory risks that banks must manage throughout the relationship, especially when a fintech or third-party service provider fails.

Such failures can happen quickly, although rarely without some form of advance warning, leaving an unprepared sponsor bank to manage regulatory scrutiny, customer harm and other consequences without adequate time to respond.

Few episodes illustrate these risks as starkly as the collapse of Synapse, the banking-as-a-service middleware provider whose April 2024 bankruptcy left customers unable to access approximately $90 million in funds spread across the multiple banks that relied on Synapse's ledgering systems. Some of those funds remain unreturned, notwithstanding the Consumer Financial Protection Bureau's efforts to distribute tens of millions of dollars from its civil penalty fund to affected consumers.

More recently, the bankruptcy of a well-funded corporate card fintech, Parker, in May 2026 raised similar issues, although on a smaller scale. In that case, customers reportedly lost access to their credit cards with little warning or explanation, and Parker filed for bankruptcy shortly thereafter.

For sponsor banks, getting ahead of similar events is crucial. Despite banking regulators' increasing openness to bank-fintech relationships, they still expect sponsor banks to actively oversee fintech partners, as detailed in existing regulatory guidance.

Scrutiny of, and enforcement activity involving, bank-fintech sponsorship arrangements also continues. And recent remarks made by Federal Deposit Insurance Corp. Chairman Travis Hill in June indicate that updated interagency third-party risk management guidance is expected in the near future.

Accordingly, sponsor banks should view these recent fintech failures as a learning opportunity to assess their own internal controls and readiness to manage similar situations with their fintech partners.

As discussed below, several areas of focus have emerged for banks planning for these events, including ongoing oversight of a fintech's financial health, contingency planning for a wind-down and a robust, coordinated plan for communicating with customers.

Regulatory Backdrop

Existing sources of regulatory guidance anchor sponsor banks' obligations in this area. Most importantly, the 2023 "Interagency Guidance on Third-Party Relationships: Risk Management," issued jointly by the Office of the Comptroller of the Currency, the Federal Reserve and the FDIC, establishes a five-stage life cycle for managing any third-party relationship, including those with fintechs.

These stages are: (1) planning, (2) due diligence and third-party selection, (3) contract negotiation, (4) ongoing monitoring, and (5) termination.

The guidance broadly clarifies that a bank's reliance on a third party does not diminish its responsibility to conduct its activities safely, soundly and in compliance with applicable law, and requires banks to exercise sufficient oversight to ensure that outsourced activities remain compliant.

As part of the initial planning stage, the guidance specifically requires banks to outline their contingency plans if they need to transition an activity away from a third party.

The OCC's separate guidance on new, modified, or expanded bank products and services likewise requires that a bank develop and maintain a contingency plan if the bank must terminate a relationship with a third party.

This guidance further requires that a bank's due diligence and planning for any new activity, including one delivered through a fintech partnership, include a business and financial plan with performance or risk metrics that signal the need to pursue an exit strategy.

Most of the recommendations below trace back to a specific stage, consideration or requirement within these frameworks, and several aspects of these frameworks have since been reinforced, or further developed, through enforcement actions.

Based on remarks made by Hill in June, it is expected that the banking regulators will issue updated interagency third-party risk management guidance in the near term.[1] Separately, some of the banking agencies are in the process of coordinating with banking and fintech trade associations on a proposed independent standard-setting body that would allow fintechs to undergo a single third-party risk assessment that would be reusable across multiple sponsor banks.

Although the goal of this body is to ease the diligence burden, early proposals indicate that a bank's responsibility to monitor and oversee its fintech partners would not be displaced. Regardless of the final form of any guidance, banks will face additional scrutiny in their oversight of fintech partners.

Warning Signs for Banks

Distress at a fintech partner often shows up well before the fintech files for bankruptcy or ceases operating. A late-stage acquisition falling through, a sudden change in leadership, layoffs, a stalled fundraising round or a shift in business model are all signals that a fintech partner may be heading toward trouble.

When those signals coincide with a sponsor bank that is already under heightened regulatory scrutiny or in its own distressed situation, risks for that bank can compound quickly.

As noted below, banks should establish monitoring systems in the initial planning stage to flag these warning signs early. Early detection can provide the lead time needed to begin implementing a transition away from a fintech partner, but likely only for banks that already have established a strong contingency plan.

Lessons Learned: What Banks Should Do Now

In distressed situations involving a fintech partner, a strong program agreement between a bank and a fintech is not enough on its own to protect a bank from the fallout. Sponsor banks should therefore consider implementing the following contractual mechanisms, and operational and compliance systems, in advance of any sign of trouble.

Integrate fintech oversight into the bank's existing governance and compliance architecture.

When a fintech partner fails, a bank needs its compliance and legal functions and operational risk team to respond in a coordinated way. That coordination is more likely if the fintech relationship has been inventoried, risk-rated and reported through the bank's existing compliance management system and board risk committee all along, rather than managed by a single business line as a stand-alone function.

This is consistent with regulatory guidance requiring that oversight and accountability run throughout the third-party relationship life cycle, rather than being confined to a single stage or business line.

Monitor fintech health continuously, and establish escalation rights.

Leadership turnover, abrupt business plan pivots, slowing growth and failed M&A talks often signal distress months before a bankruptcy filing.

Program agreements can help address these concerns by requiring ongoing financial and operational disclosures and including clear escalation triggers tied to objective metrics. Beyond monitoring for distress, banks should consider negotiating a contractual right to unilaterally suspend new account origination or to begin an orderly transition when specified events occur.

Provide mechanisms to access customer data.

One of the most damaging aspects of the Synapse collapse was that partner banks could not independently determine which funds belonged to which customers, because ledgering and reconciliation depended entirely on Synapse's own systems.

Where relevant, program agreements should give the sponsor bank a mechanism to access customer account records directly from fintechs, independent of the fintech's cooperation or operational status, so the bank can act even if the fintech's platform fails.

Create and test a transition plan in advance.

Program agreements should require the parties to develop a transition plan if the relationship is terminated, transitioned or wound down. Sponsor banks should develop their own contingency plans regardless of whether fintechs participate meaningfully in that process.

Additionally, banks should consider running tabletop exercises that simulate a sudden program termination. This exercise can help surface gaps long before an actual failure does.

Prepare customer communications, including FDIC insurance messaging, in advance.

Deposit protection, card status and transition timelines should be reviewed on a regular cadence by regulatory and communications personnel, and kept ready to deploy on short notice. This should include plain language and precleared messaging on how and when customer funds are FDIC-insured through the sponsor bank.

The FDIC's rule addressing false advertising and misrepresentation of insured status makes knowing misrepresentations about deposit insurance coverage an independent basis for enforcement, separate from any underlying operational failure.

When multiple sponsor banks service a fintech's programs, a wind-down may require coordinated communication and an operational plan across sponsor banks.

Document oversight for regulators.

As suggested by regulatory guidance, examiners expect a wind-down plan to include more than a termination and transition clause in the program agreement.

Sponsor banks should maintain a clear and written wind-down plan for each fintech relationship, mapped to the stages of the interagency third-party risk management life cycle, that can be produced on request and updated as the relationship evolves.

Control the narrative.

When a fintech partner fails, the sponsor bank should be the first and clearest voice that customers hear, not the last. That requires the operational and communications infrastructure described above to already exist before a crisis begins.

Looking Ahead

Despite ongoing efforts to ease the burden of fintech oversight, as evidenced by reports on a proposed standard-setting body, banking regulators will not give banks a free pass on their oversight responsibilities.

Regulators continue to focus on this area through new guidance, enforcement activity and other supervisory actions. Given recent fintech failures, sponsor banks should build the infrastructure needed to navigate similar events now, rather than being caught unprepared when one occurs.

[1] Travis Hill, Chairman, FDIC, Testimony, Oversight of Prudential Regulators: Hearing Before the H. Comm. on Fin. Servs., 119th Cong. (June 4, 2026), https://www.fdic.gov/news/speeches/2026/oversight-prudential-regulators.


Disclosure: Barack Ferrazzano represented American Bank in the Synapse bankruptcy proceedings discussed in this article.

The opinions expressed are those of the author(s) and do not necessarily reflect the views of their employer, its clients, or Portfolio Media Inc., or any of its or their respective affiliates. This article is for general information purposes and is not intended to be and should not be taken as legal advice.


About the Lawyers

Stanley F. Orszula is a partner in Barack Ferrazzano's Financial Institutions Group. Clients rely on Stan for strategic counsel on Banking-as-a-Service (BaaS), fintech partnerships, digital assets, bank regulatory and compliance matters, and distressed loans and assets. Drawing on his prior experience as counsel at the FDIC, Stan advises banks through every stage of their BaaS programs: from initial board strategy through partner identification, due diligence, contract negotiation, regulatory approval, and exit planning. He has helped banks across the country launch credit, debit and prepaid cards, payment processing, real-time payments, commercial and consumer loans, and investment products.

Caitlin E. Hutchinson Maddox is an associate in Barack Ferrazzano's Financial Institutions Group. Clients rely on Caitlin for regulatory and transactional counsel on bank authority and control issues, affiliate transactions, consumer protection, and regulatory reform. Drawing on her prior experience as an associate in the financial institutions group at Davis Polk in New York, Caitlin advises banks, fintechs, and other financial services companies through complex regulatory matters and transactions. She has served as regulatory counsel on M&A transactions, capital markets offerings, and investigative and enforcement actions, helping clients navigate remediation matters with a strategic, practical approach.

Jump to Page

Barack Ferrazzano Kirschbaum & Nagelberg LLP Cookie Preference Center

Strictly Necessary Cookies

Always Active

Necessary cookies enable core functionality such as security, network management, and accessibility. These cookies may only be disabled by changing your browser settings, but this may affect how the website functions.

Functional Cookies

Always Active

Some functions of the site require remembering user choices, for example your cookie preference, or keyword search highlighting. These do not store any personal information.

Form Submissions

Always Active

When submitting your data, for example on a contact form or event registration, a cookie might be used to monitor the state of your submission across pages.

Analytical Cookies

Analytical cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek