40.1 Vendor Monitoring, Fintech Controls and Service-Company Notices
Key Takeaways
Vendor monitoring should consider control performance and consumer outcomes.
Fintech deposit advertising must describe insurance coverage accurately and identify the relevant insured bank where required.
Bank Service Company Act notice duties depend on covered services and the applicable authority.
Stage 4: Ongoing Monitoring
Risk management does not conclude upon contract execution; ongoing monitoring validates continuous adherence:
- Performance & SLA Dashboards: Regular review of operational uptime, transaction throughput, and SLA compliance metrics.
- Customer Complaint Surveillance: Tracking, investigating, and analyzing all consumer complaints directed at or arising from the vendor's operations to detect emerging compliance breakdown patterns.
- Evidence refresh: Obtain suitable control, financial and continuity evidence at a risk-appropriate frequency. Annual SOC reports can be useful; neither a particular SOC type nor an annual cycle is prescribed for every relationship.
- Compliance Transaction Testing: Bank compliance personnel should periodically sample and test transactions handled by the vendor (e.g., auditing adverse action letters mailed by a third-party print shop or verifying APR calculations performed by a loan servicing vendor).
Stage 5: Termination & Offboarding
The bank should maintain a documented exit strategy to ensure operational continuity and protect consumer data upon contract expiration or early termination:
- Transition Execution: Smooth transfer of services to an alternate provider or insourcing back into the bank without service disruption or customer harm.
- Verifiable Data Destruction: Formal certification confirming that all bank confidential information, customer records, and NPI have been securely returned or destroyed in accordance with NIST or DoD data destruction standards.
- Access Revocation: Prompt revocation of all digital credentials, system access, API keys, VPN tunnels, and physical badges.
3. Special Compliance Considerations for Fintech Partnerships & Banking-as-a-Service (BaaS)
The rapid expansion of Banking-as-a-Service (BaaS) and fintech partnership models has attracted intensive supervisory scrutiny from the OCC, FDIC, and Federal Reserve. In these arrangements, chartered banks provide balance sheet access, payment rails, and regulatory sponsorship to customer-facing fintech platforms.
White-Label Deposit Programs & FDIC Part 328 Subpart B
When fintech partners market white-label deposit accounts, compliance officers should enforce strict adherence to modernized FDIC advertising and signage regulations:
- Prohibition on Misrepresentation (12 U.S.C. § 1828(a)(4)): Fintechs are legally non-banks and should not state or imply that the fintech company itself is an FDIC-insured depository institution.
- Clear Identification of Chartered Bank: Marketing materials, digital landing pages, and mobile application disclosures should clearly identify the specific chartered insured bank that holds the customer deposits (e.g., "ABC Financial is a financial technology company, not a bank. Banking services provided by First Regional Bank, Member FDIC").
- Scope of Coverage: Marketing should accurately explain that FDIC insurance protects against the failure of the insured depository institution—not against the bankruptcy, theft, or failure of the fintech company itself.
- Pass-Through Recordkeeping: To ensure individual customer deposits qualify for pass-through insurance up to the $250,000 SMDIA under 12 CFR § 330.5, the bank should ensure the fintech maintains accurate, real-time sub-accounting records reconciling daily beneficial ownership balances.
Consumer Lending Partnerships & Truth in Lending (Reg Z)
Fintech lending arrangements (such as Buy-Now-Pay-Later or online installment loans) require rigorous oversight:
- Disclosure Timings & Accuracy: Ensuring APR calculations, finance charges, payment schedules, and right-of-rescission disclosures comply strictly with Regulation Z (12 CFR Part 1026).
- Credit Card Fee Restrictions: If issuing co-branded credit cards, ensuring compliance with the Credit CARD Act of 2009 restrictions on penalty fees and first-year fee limits.
Algorithmic Underwriting & Fair Lending (Regulation B / ECOA)
Many fintech platforms leverage machine learning algorithms, artificial intelligence, and non-traditional alternative data (e.g., educational history, utility payments, or digital footprint metrics) to underwrite credit:
- Fair lending testing: Test for unlawful discrimination under the applicable ECOA and FHA standards. Regulation B’s July 2026 amendment removed its effects test; distinguish older exam-cutoff teaching from current ECOA law, and assess FHA liability separately.
- Adverse action notices: Provide applicable ECOA reasons and separate FCRA consumer-report and credit-score disclosures; do not equate score factors with principal reasons or use a generic model output as a reason.
Bank Secrecy Act / Anti-Money Laundering (BSA/AML) & Sanctions
In BaaS partnerships, banks frequently outsource customer onboarding and identity verification to the fintech:
- Non-Delegable Anti-Money Laundering Responsibility: The bank cannot delegate its statutory AML responsibilities under 31 CFR Chapter X. The bank's Board remains accountable for BSA compliance.
- CIP and CDD Execution: The bank should independently audit and validate the fintech's Customer Identification Program (CIP), Customer Due Diligence (CDD), and Office of Foreign Assets Control (OFAC) sanctions screening.
- Direct Transaction Surveillance: The bank should maintain direct, uninhibited access to all transactional data to conduct automated transaction monitoring and submit Suspicious Activity Reports (SARs) and Currency Transaction Reports (CTRs) within federal deadlines.
FDIC CMS examination framework.
Service-company notice and incident terms
The Bank Service Company Act requires notice to the bank’s federal supervisor for covered services within thirty days after the service contract is made or the service starts, whichever occurs first. Classify the service before treating every supplier as covered. The bank computer-security incident rule’s thirty-six-hour deadline applies to the bank after it determines a notification incident; it is not a universal vendor contractual notice period. A bank service provider must notify affected bank contacts as soon as possible after determining it has a qualifying disruption or degradation lasting or reasonably likely to last four or more hours. Negotiate appropriate access, confidentiality, performance, notice and termination provisions and escalate material limitations. Retaining responsibility for compliance does not establish automatic liability for every unrelated vendor action.
A regional bank contracts with a third-party technology vendor to host its online loan application portal and calculate APR and finance charge disclosures under the Truth in Lending Act (Regulation Z). Due to a vendor software coding defect, the portal systematically understated finance charges and APRs on 1,400 closed-end home equity loans over an eight-month period. When federal regulators discover the violation, the bank's executive management claims the bank is not responsible because the vendor contract included a warranty guaranteeing regulatory compliance. How will regulatory agencies view the bank's liability under the Interagency Guidance on Third-Party Relationships?
The bank is completely shielded from liability because the vendor provided an express contractual warranty guaranteeing compliance with Regulation Z.
The regulatory agencies will assess civil money penalties exclusively against the software vendor, as banks are exempt from vendor operational errors under the Bank Service Company Act.
The bank remains responsible for its own applicable Regulation Z disclosures and cannot use the vendor warranty to excuse those violations.
The bank can disclaim liability provided it terminates the vendor contract within 30 days of receiving the regulatory examination report.
A community bank partners with a financial technology startup to offer white-label consumer checking accounts through the fintech's mobile application. The fintech company launches a marketing campaign on social media stating: 'Open an account today and earn 5.5% APY—your money is held at an FDIC-insured institution and your savings are 100% government-guaranteed up to $2,000,000 against any platform loss or corporate bankruptcy.' The advertisement does not name the partner bank. In reviewing this marketing campaign, what critical compliance defect should the bank's compliance officer identify?
The advertisement only violates compliance rules if the annual percentage yield (APY) offered exceeds the national average deposit rate by more than 100 basis points.
The bank has no supervisory obligation to review fintech marketing materials until the fintech reaches 50,000 active customer accounts.
The advertisement is fully compliant because the funds will ultimately be swept into an FDIC-insured master account at the chartered bank.
The fintech violates 12 CFR Part 328 Subpart B and Section 18(a)(4) of the FDIA by omitting the identity of the insured bank, misleading consumers about the scope of deposit insurance, and claiming insurance covers fintech insolvency.
Sections you finish are checked off in the contents.