Whose Compliance Program Is It, Anyway? Sponsor Banks, FinTechs, and the New AML Accountability in BaaS

For a decade, Banking-as-a-Service ran on a comfortable fiction: the sponsor bank “owned” BSA/AML compliance, and the fintech simply rode on its charter. That fiction is now officially dead. Between the April 2026 joint AML program proposal from the FDIC, NCUA, and OCC, FinCEN’s parallel rulemaking under the AML Act of 2020, and a steady drumbeat of enforcement against payments-heavy banks, U.S. regulators have made one thing clear — in a BaaS partnership, accountability is shared, continuous, and measured by outcomes, not org charts.

1. The April 2026 Joint Proposal: Compliance Must Live Where the Risk Lives

On April 8, 2026, the federal banking agencies proposed a rewrite of AML/CFT program requirements covering roughly 8,100 banks and credit unions, aligned with FinCEN’s companion rule. The four pillars survive — internal controls, independent testing, a designated officer, training — but how they must operate changes fundamentally. Internal controls must be risk-based and “reasonably designed” around actual customers, products, and geographies, and programs must be updated whenever any of those change. A new fintech partner, a new payment corridor, or a new customer segment is no longer a commercial event with compliance implications; it is a compliance event, full stop. The agencies are also explicit that technology — APIs, digital identity, real-time data feeds — is expected to be part of the program’s plumbing, and that examiners will judge whether programs produce usable outcomes for law enforcement, not whether binders look complete.

2. Enforcement Is Already Telling the Story

The rulemaking only formalizes what enforcement has been signaling all year. In April 2026, the OCC issued a consent order against Community Federal Savings Bank after the bank rapidly scaled its payment-processing business — including significant cross-border volume — without scaling the AML program underneath it. A month earlier, FinCEN assessed a historic $80 million penalty against Canaccord Genuity for running an AML function that was, in FinCEN’s words, not proportional to the risks of its business model. Different institutions, same lesson: growth in payments and partner-driven volume without proportional compliance investment is the fact pattern regulators are actively hunting.

3. What Shared Accountability Means for FinTechs

FinCEN’s guidance has already established that fintechs in BaaS arrangements share compliance responsibility with their sponsor banks. Under the 2026 proposals, that translates into concrete operational expectations:

  • Data transparency by design — fintechs must feed customer identity, transaction, and risk data into the bank’s monitoring environment via APIs, not quarterly spreadsheets.
  • Program parity — the fintech’s own KYC, sanctions screening, and transaction monitoring must stand on their own, because banks are now contractually pushing full BSA obligations downstream.
  • Change-driven risk assessment — every new product, state, or customer segment triggers a documented reassessment on both sides of the partnership.
  • Evidence of effectiveness — both parties need metrics showing controls actually detect and report suspicious activity, not merely that they exist.

4. The Sponsor Bank’s Lens: Partner Oversight Is Program Design

For sponsor banks, fintech oversight is no longer a vendor-management checkbox; it is a core element of program design. Expect deeper pre-onboarding diligence on fintech compliance programs, contractual audit rights that are actually exercised, independent testing that reaches through to partner-originated activity, and faster off-boarding of partners who cannot produce clean data. FinTechs that arrive at diligence with a documented, independently audited AML program will command better terms, faster launches, and more durable banking relationships. Those that cannot will increasingly find the BaaS door closed.

5. FinCheck’s Perspective & Way Forward

At FinCheck, we sit on both sides of these partnerships — helping fintechs and MSBs build bank-grade programs, and helping programs withstand bank and examiner scrutiny. Our read: the 12-month implementation window that will likely follow a final rule is not time to wait; it is time to close gaps. Practical priorities for the next two quarters:

  • Refresh your BSA/AML risk assessment against current products, geographies, and partner flows — not last year’s business.
  • Commission an independent AML audit before your sponsor bank or examiner does it for you.
  • Instrument your data: if you cannot deliver monitoring-ready data to a bank partner via API, treat that as a strategic deficiency.
  • Right-size resourcing — Canaccord’s $80 million penalty is the price tag regulators now attach to under-resourced programs.
  • If you lack senior compliance leadership, a fractional CCO delivers the accountability regulators expect at a fraction of full-time cost.

Closing Thoughts

The BaaS model is not going away — but the era of outsourced accountability is. The winners in 2026 and beyond will be the banks and fintechs that treat compliance as shared infrastructure: continuously risk-assessed, technology-instrumented, and independently validated.

FinCheck LLC helps FinTechs, MSBs, crypto, and gaming businesses build and validate AML programs that stand up to bank-partner and regulatory scrutiny — from BSA/AML risk assessments and independent audits to FBO/BaaS setup and fractional compliance leadership. If your growth is outpacing your compliance program, let’s talk before your regulator does.

Payroll Fraud Meets AML: What FinCEN’s New Advisory (FIN-2026-A002) Means for MSBs, Payroll Firms, and FinTechs

Payroll Fraud Meets AML: What FinCEN’s New…

On June 5, 2026, FinCEN — jointly with the FDIC, OCC, and NCUA and in…

The Post-MiCA Era Begins: What the July 1 CASP Deadline and AMLA’s Ramp-Up Mean for Global Crypto Compliance

The Post-MiCA Era Begins: What the July…

On July 1, 2026, the era of transitional tolerance for crypto-asset service providers (CASPs) in…

Whose Compliance Program Is It, Anyway? Sponsor Banks, FinTechs, and the New AML Accountability in BaaS

Whose Compliance Program Is It, Anyway? Sponsor…

For a decade, Banking-as-a-Service ran on a comfortable fiction: the sponsor bank “owned” BSA/AML compliance,…