Who’s liable? Embedded finance faces an accountability crisis

embedded finance

Embedded finance has quietly become the invisible engine behind everyday transactions, weaving payments, lending, banking, insurance and investment tools directly into platforms that were never built as financial institutions.

According to AscentAI, from BNPL widgets sitting inside e-commerce checkouts to insurance upsells tucked into rideshare apps, the model has expanded far beyond its payments origins. But as the sector matures, regulators are increasingly unwilling to let compliance obligations stay as hidden as the infrastructure itself.

AscentAI recently discussed embedded finance’s next chapter, including growth, regulation, and accountability.

At the core of every embedded finance arrangement sits a three-layer accountability structure, and it is here that most compliance disputes and enforcement actions originate. The platform, whether an e-commerce site, HR software provider or gig economy app, owns the customer relationship and distributes the product.

The BaaS or middleware provider sits in the middle, managing API connectivity, ledgering and routing between platform and bank. The sponsor or licensed bank holds the charter and carries ultimate regulatory accountability for consumer funds.

Because embedded finance touches lending laws, payments regulation, KYC/AML requirements and data privacy rules simultaneously, and often across multiple jurisdictions, the compliance burden multiplies quickly. Middleware fintechs are typically treated as third-party technology partners rather than directly regulated entities, but banks partnering with them are expected to oversee operational risk, while fintechs seeking bank partnerships must prove their compliance credentials.

Nowhere is this tension sharper than in the US, where a multi-agency regulatory framework, escalating enforcement through 2024 and a notable policy shift under the Trump administration in 2025 have created a complex and shifting landscape. Since the start of 2024, more than a quarter (25.6%) of the FDIC’s formal enforcement actions have targeted sponsor banks in embedded finance partnerships, while over a fifth of OCC enforcement actions have done the same, according to Alloy.

The financial toll is significant too: 75% of sponsor banks say they have lost $100,000 or more to compliance violations within their embedded finance partnerships, and 80% report difficulty monitoring multiple fintech partners across different jurisdictions. Perhaps most striking, 29% of sponsor banks are now considering scaling back or shutting down their embedded finance programmes altogether due to compliance pressure.

For compliance teams, the path forward involves real-time monitoring technology that gives sponsor banks deeper visibility into fintech partners’ risk activities, effectively adopting a “compliance-as-a-service” role.

Banks should benchmark their third-party risk programmes against the OCC’s 2024 continuous monitoring expectations and interagency joint guidance, and conduct BSA/AML gap analyses where FBO accounts are in use. Fintechs, meanwhile, need to map liability across the full stack rather than assuming sponsor banks absorb every obligation.

The direction of travel is clear, compliance is moving from a back-office function to a core architectural principle. The embedded finance firms that thrive over the next decade won’t be defined by the slickest APIs, but by how deeply compliance is built into their foundations.

AscentAI’s full post can be viewed here. 

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.