CONTEXT. JUDGEMENT. ACTION.
EDITIONBUSINESS.

Useful journalism to understand, manage and grow a business.

Search
Explore Edition Business
Guide · Estados Unidos (las referencias regulatorias citadas son de ese país; no deben extrapolarse automáticamente)

How to Evaluate a Partnership Between a Financial Institution and a Fintech

A partnership can accelerate innovation, but it also increases operational and compliance dependencies. This guide proposes evaluating the strategy, financial soundness, controls, technology, and responsibilities before signing and throughout the partnership.

A classic stone building is joined by a curved bridge to a structure of stacked teal glass blocks.
AI-generated conceptual illustration · Edition Business

A partnership between a financial institution and a fintech can facilitate access to new technologies, products, and capabilities. It can also help reduce costs or improve certain controls. But these benefits depend on both parties understanding which risks they share, who is responsible when problems arise, and how they will verify that controls work.

For this reason, the evaluation should not be limited to reviewing the product or platform. It should cover the partner, the business relationship, the systems involved, and the ability to maintain the service through changes or disruptions. Uday Gulvadi and Scott Rosenbaum, of Stout, note the importance of due diligence and ongoing third-party monitoring; Marissa Tartarini, of Elliott Davis, also emphasizes governance, operational readiness, contracts, and consumer protection.

1. Confirm that the partnership serves a specific objective

Before comparing providers, define the problem the partnership is intended to solve: for example, enabling a digital feature, improving a process, or expanding the range of services. Clarify what each party contributes and how the project fits with the institution’s strategy, risk tolerance, and available resources.

Also evaluate the partner’s experience and capabilities: its structure, governance, management team, track record, and product knowledge. An attractive proposal does not replace the ability to operate the service or the availability of competent staff to manage its risks. Also review whether the institution has sufficient resources to integrate and oversee the solution.

2. Assess the partner’s financial soundness and continuity

The financial assessment should help determine whether the provider can sustain operations and what would happen if its circumstances changed. Items to review may include financial statements, annual reports, sources of funding, customer base, and business position.

Continuity matters as much as initial viability. Consider how services would be maintained and how customers, data, and processes would be protected if the fintech experienced a disruption or ceased operating. Examine its continuity, disaster recovery, and incident response plans; also check how it backs up data and what measures it has planned to restore systems.

3. Conduct due diligence on compliance and controls

The review should cover the provider’s legal status, the licenses applicable to its activities and jurisdiction, and its compliance policies and procedures. When the product involves financial crime risks, it is important to understand how the relationship fits within BSA/AML controls—the U.S. Bank Secrecy Act and anti-money laundering framework—and the institution’s policies.

It is not enough to receive a description of the controls. Request documentation that allows you to assess how they are applied: risk assessments, prior audits, performance indicators, and reports to management or the board. Check who reviews alerts, how issues are escalated, and what capacity each party has to meet its responsibilities as activity grows.

For partnerships involving payments or FBO (for benefit of) accounts, clarify how transactions are recorded and reconciled, who can access the relevant books or records, and how discrepancies are detected. Tartarini highlights the value of daily reconciliations, access protocols, and clear reporting, alongside plans to respond to payment disruptions or accounting inconsistencies.

A dark metal padlock is connected by three curved cables to a stack of technological blocks on a surface.
AI-generated conceptual illustration · Edition Business

4. Review information security and technology integration

Determine what data is collected, where it is stored, who can access it, and how long it is retained. The review should include security controls, incident reports, available assessments, and the procedure for deleting information when it should no longer be retained.

On the technical side, identify dependencies between platforms, the systems that need to exchange information, and the consequences of a failure or delay. Integration must be viable for both parties, not just for the provider. It is also advisable to establish how product changes, vulnerabilities, and service disruptions will be managed.

5. Allocate responsibilities in the contract

The contract should translate the risk assessment into verifiable obligations. Specify roles, deliverables, service levels, and mechanisms for reporting and escalating incidents. Include provisions on data security and privacy, breach response, third-party access, audits, and subcontractor management.

If the fintech participates in customer communications or promotions, determine who reviews and approves materials before publication and who handles complaints or corrects confusing information. It is also useful to agree on what happens when the relationship ends, including the return or deletion of data and the removal of references to the financial institution from the partner’s channels.

Indemnification and loss-allocation clauses require specific legal analysis: their scope depends on the contract, the product, and the applicable rules. They do not replace controls or eliminate the responsibilities that fall to each party.

6. Establish monitoring throughout the relationship

Due diligence does not end with signing. Set a review frequency and update the assessment when the product, processes, scale, or risk profile changes. Keep evidence of decisions, reviews, authorized exceptions, incidents, and corrective actions; documentation makes it possible to verify what was monitored and how the response was handled.

Monitoring can combine operational and control indicators, complaint trends, audit results, security incidents, and compliance with contractual commitments. Ensure findings have assigned owners and resolution deadlines, and that significant matters reach the appropriate level of governance.

Regulatory scope

The regulatory references in the documents relate to the United States. The joint guidance on due diligence for fintech companies mentioned by Gulvadi and Rosenbaum was issued by the Federal Reserve, the FDIC, and the OCC, and updated in 2023. Tartarini’s article also refers to U.S. provisions on payments, fraud prevention, consumer protection, and suspicious activity reporting.

These references should not be automatically extrapolated to other countries or interpreted as a complete list of obligations. Applicability depends on the jurisdiction, product, partnership model, and the roles of each participant. Before formalizing a partnership, the institution should obtain legal and compliance advice tailored to its circumstances.

Sources and methodology

  1. Due Diligence Essentials for a Successful Bank-Fintech ... ↗www.stout.com
  2. Fintech partnerships: Risk and compliance strategies for ... ↗www.elliottdavis.com
Editorial methodology →Corrections
Report an error ↗

Continue exploring