HOMEPLATFORMPARTNERSPRICINGRESEARCH
Who we serve
Community BanksSponsor BanksFintechs
Blog · Sponsor Banks & BaaS

Who Owns What: Risk Allocation in BaaS Partnerships

Sponsor bank liability in fintech partnerships cannot be delegated. Who performs each obligation, who owns it with the regulator, and what ownership requires.

By Canarie Team · May 25, 2026

Every BaaS partnership runs on a division of labor: the fintech onboards customers, answers tickets, and writes the marketing; the bank holds the charter. The division of labor is negotiable. The division of accountability is not. Sponsor bank liability follows a single principle regulators have stated repeatedly: performance can be delegated, regulatory accountability cannot, and the contract that says otherwise is not binding on an examiner.

Key Takeaways:

  • The bank owns every regulatory obligation attached to activity on its charter, regardless of which entity performs the work
  • Owning an obligation operationally means four things: set the standard, get the data, verify the work, retain the evidence
  • Indemnification clauses shift money after the fact; they do not shift examination findings, MRAs, or enforcement exposure
  • When a partner fails, the finding lands on the bank, and parallel regulatory actions against both parties have occurred

The Principle: Performance Can Be Delegated, Accountability Cannot

The Interagency Guidance on Third-Party Relationships (OCC Bulletin 2023-17, adopted by the FDIC as FIL-29-2023) states the rule plainly: using third parties does not diminish a bank's responsibility to operate in a safe and sound manner and comply with applicable law, as if the bank were performing the activity itself. That final clause is the whole allocation framework. Whatever the fintech does on the bank's charter, the regulatory analysis treats as done by the bank.

This is why "who owns what" is the first question a bank should answer before signing, and the question examiners effectively re-ask at every exam. The answer has two layers, who performs the task day to day, and who answers for it to the regulator, and confusion between the layers is where sponsor bank compliance programs fail.


Who Performs vs. Who Owns: The Allocation Table

Obligation areaWho typically performsWho owns it with the regulator
BSA/AML: CIP, monitoring, SAR filingFintech runs onboarding and first-line screeningBank, under 31 CFR § 1020.210; SAR decisions are the bank's
Reg E error resolutionFintech operates dispute intake and supportBank owns the regulatory clock under 12 CFR § 1005.11
ComplaintsFintech handles intake and responseBank owns oversight, trend analysis, and escalation
UDAAP in marketingFintech writes and runs campaignsBank answers for deceptive or unfair claims on its products
Fair lending in underwriting modelsFintech builds and operates the modelBank owns ECOA compliance and disparate impact analysis
GLBA privacy and safeguardsFintech holds and processes customer dataBank owns privacy notices under Reg P (12 CFR Part 1016) and partner security oversight
Deposit insurance representationsFintech's website and app make the claimsBank answers for misrepresentation under 12 CFR Part 328 subpart B
CRANo fintech role; delivery is digital-firstBank's obligation in full, regardless of delivery model

Two rows deserve emphasis. On BSA/AML, the fintech can collect identity documents and generate alerts, but the compliance program, its pillars, and every SAR filing decision belong to the bank, which is why AML requirements for sponsor banks center on the bank's independent visibility into partner activity. On Reg E, the 10-business-day investigation clock starts when notice reaches the fintech, because the fintech is the bank's intake channel; a dispute aging inside the partner's ticket queue is the bank's violation in progress.


What "The Bank Owns It" Means Operationally

Ownership without operational content is a slogan. For each row in the table, owning the obligation means the same four activities:

  1. Set the standard. The bank defines what compliant performance looks like, CDD thresholds, dispute routing rules, marketing claim requirements, model testing expectations, rather than accepting the partner's defaults.
  2. Get the data. The bank has direct, ongoing access to the records the obligation runs on: transaction data, dispute queues, complaint logs, model outputs. Data the bank must request is data the bank does not control.
  3. Verify the work. Scheduled, risk-based verification that the partner's performance meets the standard: file pulls, testing, metric review, sweeps.
  4. Retain the evidence. Every verification leaves a dated, attributable artifact the bank holds, so ownership is provable at examination rather than asserted.

A bank that can show all four for each obligation area has operationalized ownership. A bank that can show a contract clause and a quarterly call has delegated it, whatever the agreement says.


Indemnification Shifts Money, Not Examination Findings

Program agreements routinely include indemnification: the fintech will reimburse the bank for losses arising from the fintech's compliance failures. These clauses are worth negotiating, and they are worth exactly what they say, money after the fact, from a counterparty that may not have it when the failure is large enough to matter.

What indemnity cannot do is move the regulatory consequence. The examination finding is written against the bank. The MRA is issued to the bank. The consent order names the bank, constrains the bank's growth, and follows the bank into every future application. A fintech's indemnity payment does not amend a CAMELS rating or unwind a public enforcement action, and regulators price a bank's compliance posture, not its litigation recoveries. Contractual risk allocation belongs in the partnership agreement as one layer of protection; it is not a substitute for the oversight that prevents the finding.


When a Partner Fails: How It Actually Plays Out

The sequence is consistent across public enforcement history. The failure occurs at the partner: disputes mishandled, deposit insurance misdescribed, monitoring gaps in a growing program. Examiners find it at the bank, because the bank is the examined entity, and the finding is framed as the bank's oversight failure, which it is under the interagency guidance. Remediation lands on the bank: lookbacks, restitution funding mechanics, third-party reviews, growth restrictions on the program.

And liability can be simultaneous. The CFPB has brought parallel actions against banks and their nonbank partners arising from the same conduct, and the banking agencies have issued orders to sponsor banks over program-wide oversight while state and federal authorities pursued the fintechs separately. The lesson for allocation is that "the regulator will go after the fintech" and "the regulator will go after the bank" are not alternatives; both happen, and the bank's exposure does not wait for the partner's to resolve.


Owning Without Doing: How Banks Operationalize Ownership at Scale

The bank cannot perform every task, and the model does not ask it to. What scales is a published standard: the bank defines requirements once, per obligation area, with the control, cadence, data access, and evidence specification each partner inherits, then runs verification against that standard across the fleet. Ownership becomes a portfolio property, the bank can state its standard, show the data flowing, show verification operating, and produce the evidence, for every partner, on demand.

This is also the honest test for any partnership the bank is considering: if an obligation area exists where the bank cannot set the standard, get the data, verify, and evidence it, the bank is accepting accountability without control, and no indemnity clause prices that correctly.


How Sponsor Banks Operationalize Ownership with Canarie

Canarie is built for the four verbs of ownership. The bank defines its standard once, each obligation area carries its controls, cadences, and evidence specifications, and every fintech partner is evaluated against it continuously. Verification cycles leave artifacts automatically, evidence quality is comparable across partners, and the portfolio view shows exactly where ownership is demonstrated and where it is thin, before an examiner maps it for you.

See how sponsor banks prove ownership across the fleet →


Frequently Asked Questions

Can a sponsor bank transfer regulatory liability to its fintech partner by contract?

No. The interagency third-party guidance is explicit that a bank's use of third parties does not diminish its obligation to comply with applicable law as if it performed the activity itself. Contracts can allocate tasks, costs, and indemnity between the parties, but examination findings, MRAs, and enforcement actions attach to the regulated entity, the bank, regardless of contractual language.

Who files SARs in a bank-fintech partnership?

The bank. Under the Bank Secrecy Act, the compliance program obligation in 31 CFR § 1020.210 and the SAR filing obligation belong to the financial institution. A fintech partner can perform identity verification and escalate alerts, but the decision to file, the narrative quality, and the timeliness are the bank's responsibility, and examiners have cited banks for relying on partner-drafted narratives without independent review.

What is the bank's responsibility for a fintech's underwriting model?

The bank owns fair lending compliance for credit originated on its charter, which means it must understand the model's inputs, test for disparate impact under ECOA, and be able to explain adverse action reasons. "The partner built the model" is not a defense examiners accept; it is a description of the exact oversight gap they are looking for.

Does an indemnification clause protect a sponsor bank from enforcement?

It protects the bank's balance sheet, partially and after the fact, if the fintech remains solvent. It does not prevent or transfer the examination finding, the consent order, or the reputational and supervisory consequences, all of which attach to the bank. Indemnity is a useful secondary layer; the primary protection is oversight that catches the failure before a regulator does.

Topics:Sponsor BanksBaaSThird-Party RiskFintech Compliance

Ready to automate your compliance workflows?

See how Canarie transforms regulatory requirements into executed tasks with built-in evidence capture.

Explore the platform