Banking-as-a-Service (BaaS) pre-launch compliance is the set of BSA/AML program elements a fintech must have operating before a sponsor bank will place it on the bank's charter: the program pillars, onboarding controls (CIP, KYC, CDD), transaction monitoring matched to the fintech's product and customer base, SAR readiness, and evidence that each control operates. The bank evaluates these before any customer is onboarded, because the bank holds the regulatory responsibility for the resulting activity. Remediating a program after an examination finding is more costly than building it before go-live.
In a Banking-as-a-Service arrangement, a fintech builds and operates the customer-facing product while a chartered bank holds the charter and the regulatory responsibility for the accounts and activity that result. Pre-launch compliance is the program a fintech must have in place, and be able to evidence, before that bank permits go-live.
This article describes the arrangement from the fintech's side. (For the bank's view of the same relationship, see the sponsor-bank oversight guide.) It covers why compliance gates the launch, what the bank checks, the program required at go-live, the controls that must operate on day one, and a checklist to run before diligence begins.
Compliance as the launch gate
In a Banking-as-a-Service model, the fintech builds the experience and the bank holds the charter. That split determines the order of operations. Under the 2023 Interagency Guidance on Third-Party Relationships (OCC, FRB, FDIC), a bank's BSA/AML responsibility for the activity of its third-party partners is non-delegable, so the bank must be satisfied with the fintech's program before any customer is onboarded. A product with no defensible compliance program behind it does not go live; the program is part of what the fintech is shipping.
What the sponsor bank checks before go-live
Sponsor-bank diligence is thorough, and it covers the same areas the bank's own examiners will later test. The bank generally asks for:
| Area | What the bank wants to see |
|---|---|
| Written program | A BSA/AML policy and procedures sized to the fintech's product, not a generic template. |
| Risk assessment | A current assessment that matches the fintech's actual customers, products, and geographies. |
| Accountable owner | A named compliance officer on the fintech side who can answer for the program. |
| Onboarding controls | CIP, KYC, and CDD procedures, including beneficial ownership for business customers. |
| Monitoring & SARs | A transaction-monitoring approach fit for the fintech's customer base and a SAR / escalation process. |
| Evidence it operates | Proof the controls run in practice, not just that the policy exists. |
Diligence runs in both directions. The 2024 banking-as-a-service fallout, the April 2024 Synapse collapse that froze roughly $265 million in end-user funds and the consent orders that followed at several partner banks, is the basis for a fintech vetting the sponsor in return: its reconciliation and for-benefit-of ledger practices, its enforcement history, and whether it can support the oversight it will require of the fintech. A sponsor operating under a consent order may be constrained in the new activity it can support.
The program required at launch
A large department is not required. The BSA program pillars must be stood up in operating form, sized to the fintech's stage:
- Internal controls. Written policies and procedures that describe what the fintech actually does.
- A designated BSA officer. A named, accountable person, even if the role is fractional at first.
- Training. Role-specific training for the people who touch onboarding, support, and operations.
- Independent testing. A plan for periodic independent review, scoped to the fintech's risk.
- Customer due diligence. Risk-based CDD and beneficial-ownership collection at onboarding.
The program is not required to be large. It is required to be genuine, documented, and matched to the product being launched.
Onboarding controls: CIP, KYC, CDD
A fintech's early risk concentrates at onboarding, which is why the bank examines this area closely. The minimum is a Customer Identification Program that verifies who the customer is, due diligence that risk-rates the customer and accounts for their expected activity, and, for business customers, beneficial-ownership collection that identifies the people behind the entity. The objective is a defensible, risk-based decision at account opening, documented well enough to be reconstructed months later.
Transaction monitoring and SAR readiness from day one
Detection capability is expected to exist before transaction volume does. Before launch, the fintech has a monitoring approach tuned to its specific customer base and product, rather than generic rules borrowed from a different business, plus a working path from a detected alert to a filing decision. SAR readiness means the reviewer, the decision-maker, and the timeline are identified before the first suspicious pattern appears. (On drafting the filing itself, see the SAR narrative guide.)
The evidence the bank wants
Each of the items above is assessed on evidence rather than on assertion. A policy stating that monitoring happens carries less weight than a record showing that it did. Controls instrumented to produce a timestamped artifact from the start supply that record. Diligence generally moves faster for a fintech that can produce the records than for one that can only describe the process.
A pre-launch compliance checklist
- A written BSA/AML program sized to the fintech's product rather than adopted from a template.
- A current risk assessment matching the fintech's actual customers and products.
- A named compliance officer accountable on the fintech side.
- CIP, KYC, and CDD procedures, including beneficial ownership for businesses.
- Transaction monitoring tuned to the fintech's customer base rather than borrowed rules.
- A working SAR and escalation process with named reviewers and timelines.
- A plan for independent testing, scoped to the fintech's risk.
- Evidence that each control operates, retained from day one.
- Compliance work started before sponsor-bank diligence rather than during it.
Building the compliance program alongside the product, rather than after it, places the program in operating form before sponsor-bank diligence begins. Where each control is instrumented to leave a record, the review consists of confirming work already performed.