Regulators are sharpening their focus on smaller institutions that have raced into payments and FinTech-adjacent business lines without matching investment in compliance.
In May 2026, the Office of the Comptroller of the Currency (OCC) published an April 2026 consent order against a Northeast-based federal savings association over shortcomings in its Bank Secrecy Act/Anti-Money Laundering (BSA/AML) programme, the latest signal that community banks pursuing FinTech-driven growth are firmly in the enforcement crosshairs, claimed AscentAI.
AscentAI recently took the time to discuss how to overcome risk in community bank and FinTech partnerships.
Bank-FinTech partnerships have become standard practice across the industry, but they carry heightened risk in a period of regulatory flux. There are currently no rules that clearly define who owns which compliance obligations in these arrangements. Earlier open banking guidance that placed responsibility on banks has been withdrawn, and replacement guidance still being drafted may or may not shift more of the burden onto FinTechs.
That uncertainty offers no shelter. State regulators apply their own standards to these partnerships, and federal enforcement continues apace, with smaller banks increasingly targeted.
Coalition for Financial Ecosystem Standards (CFES) co-founder Sima Gandhi said, “For many community banks around the country, partnering with fintechs is the way forward.” She added, “For a smaller bank a consent order could kill the program and end viability financially.”
The stakes are structural. FDIC-insured sponsor banks supply the charter, licences and deposit infrastructure, but they also carry the compliance obligations for everything their FinTech partners do, from customer-facing activity to underwriting and transaction processing.
Under the Bank Secrecy Act, obligations sit with the financial institution, not its partners, meaning the bank must ensure FinTechs carry out customer due diligence and transaction monitoring, and must be satisfied that partners continually meet cybersecurity and data protection requirements.
Banks typically push FinTechs to accept compliance responsibilities contractually, but without regulatory separation of duties, confusion can arise where responsibilities overlap or where the bank lacks full visibility into a partner’s compliance profile.
Embedding KYC, AML, cybersecurity and data integrity requirements into vendor contracts, with penalties including termination, is one remedy. An industry standards body, however, has developed a potentially more seamless option.
CFES has created the Standardized Assessment for Risk Management & Compliance (STARC), which uses independent audits to certify FinTechs against measurable criteria across six areas: BSA/AML, compliance management systems, third-party risk management, complaint handling, operational risk, and marketing and product compliance.
Each area is scored against a five-level maturity scale, from Level 5 (Rudimentary) to Level 1 (Optimized), assessing elements including governance, risk assessment, training, monitoring, issue management and reporting.
According to the American Fintech Council, “The framework and these initial standards were developed through extensive consultation with banks, fintechs, regulators, and consumer advocates.” With regulatory clarity unlikely soon, STARC could give smaller banks the structure and confidence to pick reliable FinTech partners to fuel growth.
Want to read the full AscentAI post? Find it here.
Copyright © 2026 RegTech Analyst
Copyright © 2018 RegTech Analyst





