BankThink

The FDIC's fintech certifications end where partnership risks begin

FDIC
An FDIC plan to help community banks evaluate potential fintech partners is valuable, as far as it goes. But it cannot account for the unique and specific risks that arise when two companies operate in partnership, writes Raghu Mittal, of EarnIn.
Al Drago/Bloomberg
  • Key insight: The FDIC's plan to help community banks evaluate potential fintech partners cannot account for the unique and specific risks that arise when two companies operate in partnership.
  • What's at stake: A bank may maintain robust internal controls and a fintech may operate a well-controlled platform, but their partnership could still have many gaps.
  • Forward look: Unless the FDIC devises a mechanism to update certifications to reflect changes that may occur at a fintech, a valid certificate could give banks an outdated picture of that fintech.

The FDIC has proposed a new certification program to standardize the assessment of fintech providers. The primary motivation behind exploring this program is to solve the challenge community banks face in vetting multiple fintech partners with their limited technology and risk teams. Under this proposal, fintechs can undergo a single assessment for multiple banks to use. The assessment of a bank-fintech partnership is outside the scope of this certification. As some of the most significant risks lie in how a bank-fintech partnership is structured, the concern is that banks would assume that part is already handled, given the certification.

Processing Content

On July 21, 2026, the FDIC circulated a draft term sheet among the banking and trade groups participating in the FDIC's preliminary discussions. The draft term sheet outlines the basic structure of the program. It proposes setting up a banking innovation standards development organization, or BISDO, and a certification program called Risk-Assessed, Manageable Partnerships, or RAMP. As per this draft, independent assessors would evaluate fintech solutions and controls against common standards. A certificate, once issued, could be used by the fintech with any bank and an active registry would keep track of which certifications remain active.

RAMP is a credible answer to a costly problem. Banks have a similar diligence process, often asking the same questions with several prospective fintechs. On the other hand, fintechs also repackage substantially similar evidence across different prospective banks. So, a single standardized assessment can lower the burden for both banks and fintechs as well as widen the set of vendors a bank can evaluate.

The draft is also upfront about its limits. RAMP would merely be a green light for a bank to consider a fintech, and the banks would still remain responsible for conducting diligence and maintaining oversight. However, despite BISDO's transparency about RAMP's limitations, in practice, a disclaimer alone may not be enough to prevent certification being treated as a broader endorsement.

One way for a bank to assess a fintech is to separate risks into three categories. First, entity-level risk to evaluate the fintech as a company including its financial condition, governance and security program. Second, solution-level risk entailing the controls around specific products. Lastly, relationship-level risk to assess the implementation of integration, data flows, incentives and commercial terms.

While the first two risks can be assessed once and reused, the risk in a bank-fintech partnership, the relationship-level risk, is unique and specific to the partnership. A bank may maintain robust internal controls and a fintech may operate a well-controlled platform, but their partnership could still have many gaps. Therefore, a fintech with the same certification can present very different risk profiles in different bank partnerships.

Read more:

For instance, the joint solution may not have answers to basic but critical questions such as which record governs when there is a disagreement about a customer's balance, who resolves an item that neither system can settle alone, or how quickly the bank can get data when a customer needs an answer. Such relationship-level gaps would not surface in a standard assessment and would be based on factors such as the commercial agreement between both parties, their engineering and system integration design, and the diligence put in by each party to brainstorm edge case scenarios.

The primary driver for the FDIC to launch this certification is to support community banks that lack resources to conduct specialized reviews. Lack of resources may lead banks to rely on RAMP for things it was not designed to do. A bank procurement team under pressure to launch may see a RAMP certificate and assume that the difficult questions have already been answered. Faster closure of partnership and speedier integration rollout is in the interests of both bank and fintech. Over time, a "green light to consider" could become the reason a partnership is approved.

A registry may also steer banks toward a select few fintechs who have the RAMP certificate, increasing shared exposure. If several community banks select the same certified fintech and there is a disruption with that fintech, it could impact many banks at once. The risk may also grow after certification as a fintech adds clients or changes its systems and controls. Unless the FDIC devises a mechanism to update the certification to reflect those changes, a valid certificate could give banks an outdated picture of the fintech.

RAMP is still worth building, as it will help both banks and fintechs and make the system more efficient. There is a risk that community banks, due to lack of resources and under pressure to launch products faster, may treat the certificate as an overall endorsement of the partnership. One potential fix is for RAMP to also standardize recurring relationship questions, such as which record controls when balances differ, who owns exceptions that cross both systems, and what happens to pending transactions when the relationship ends. Each bank and fintech would answer those questions for their own arrangement and retain the answers. RAMP would not certify them, but examiners could confirm that the work was done. Examiners' recognition of certification for onboarding would be conditional on the bank and fintech completing that relationship assessment.


For reprint and licensing requests for this article, click here.
Regulation and compliance Fintech Community banking FDIC
MORE FROM AMERICAN BANKER
Load More