Field Guide

BaaS Compliance: What Fintechs Need Before Launch

The short version

Banking-as-a-Service (BaaS) pre-launch compliance is the set of BSA/AML program elements a fintech must have operating before a sponsor bank will place it on the bank's charter: the program pillars, onboarding controls (CIP, KYC, CDD), transaction monitoring matched to the fintech's product and customer base, SAR readiness, and evidence that each control operates. The bank evaluates these before any customer is onboarded, because the bank holds the regulatory responsibility for the resulting activity. Remediating a program after an examination finding is more costly than building it before go-live.

In a Banking-as-a-Service arrangement, a fintech builds and operates the customer-facing product while a chartered bank holds the charter and the regulatory responsibility for the accounts and activity that result. Pre-launch compliance is the program a fintech must have in place, and be able to evidence, before that bank permits go-live.

This article describes the arrangement from the fintech's side. (For the bank's view of the same relationship, see the sponsor-bank oversight guide.) It covers why compliance gates the launch, what the bank checks, the program required at go-live, the controls that must operate on day one, and a checklist to run before diligence begins.

Compliance as the launch gate

In a Banking-as-a-Service model, the fintech builds the experience and the bank holds the charter. That split determines the order of operations. Under the 2023 Interagency Guidance on Third-Party Relationships (OCC, FRB, FDIC), a bank's BSA/AML responsibility for the activity of its third-party partners is non-delegable, so the bank must be satisfied with the fintech's program before any customer is onboarded. A product with no defensible compliance program behind it does not go live; the program is part of what the fintech is shipping.

What the sponsor bank checks before go-live

Sponsor-bank diligence is thorough, and it covers the same areas the bank's own examiners will later test. The bank generally asks for:

AreaWhat the bank wants to see
Written programA BSA/AML policy and procedures sized to the fintech's product, not a generic template.
Risk assessmentA current assessment that matches the fintech's actual customers, products, and geographies.
Accountable ownerA named compliance officer on the fintech side who can answer for the program.
Onboarding controlsCIP, KYC, and CDD procedures, including beneficial ownership for business customers.
Monitoring & SARsA transaction-monitoring approach fit for the fintech's customer base and a SAR / escalation process.
Evidence it operatesProof the controls run in practice, not just that the policy exists.

Diligence runs in both directions. The 2024 banking-as-a-service fallout, the April 2024 Synapse collapse that froze roughly $265 million in end-user funds and the consent orders that followed at several partner banks, is the basis for a fintech vetting the sponsor in return: its reconciliation and for-benefit-of ledger practices, its enforcement history, and whether it can support the oversight it will require of the fintech. A sponsor operating under a consent order may be constrained in the new activity it can support.

The program required at launch

A large department is not required. The BSA program pillars must be stood up in operating form, sized to the fintech's stage:

The program is not required to be large. It is required to be genuine, documented, and matched to the product being launched.

Onboarding controls: CIP, KYC, CDD

A fintech's early risk concentrates at onboarding, which is why the bank examines this area closely. The minimum is a Customer Identification Program that verifies who the customer is, due diligence that risk-rates the customer and accounts for their expected activity, and, for business customers, beneficial-ownership collection that identifies the people behind the entity. The objective is a defensible, risk-based decision at account opening, documented well enough to be reconstructed months later.

Transaction monitoring and SAR readiness from day one

Detection capability is expected to exist before transaction volume does. Before launch, the fintech has a monitoring approach tuned to its specific customer base and product, rather than generic rules borrowed from a different business, plus a working path from a detected alert to a filing decision. SAR readiness means the reviewer, the decision-maker, and the timeline are identified before the first suspicious pattern appears. (On drafting the filing itself, see the SAR narrative guide.)

The evidence the bank wants

Each of the items above is assessed on evidence rather than on assertion. A policy stating that monitoring happens carries less weight than a record showing that it did. Controls instrumented to produce a timestamped artifact from the start supply that record. Diligence generally moves faster for a fintech that can produce the records than for one that can only describe the process.

A pre-launch compliance checklist

Building the compliance program alongside the product, rather than after it, places the program in operating form before sponsor-bank diligence begins. Where each control is instrumented to leave a record, the review consists of confirming work already performed.

Common questions

Why does compliance block a fintech launch?
Because the sponsor bank carries the regulatory responsibility for everything its fintech partners do. Before it lets a fintech onto its charter, the bank has to be convinced the fintech's compliance program is real and defensible. Compliance is a go-live gate, not a post-launch task: no defensible program, no launch.
What does a sponsor bank require before letting a fintech go live?
Typically a written BSA/AML program, a risk assessment that matches the product, a named compliance officer, customer identification and due-diligence procedures, a transaction-monitoring approach suited to the customer base, SAR and escalation procedures, and evidence that these operate. The bank's own examiners will later test the same things, so the bank front-loads the diligence.
What compliance program does a fintech need at launch?
At minimum the BSA program pillars stood up for real: internal controls (written policies and procedures), a designated BSA officer, training, a plan for independent testing, and customer due diligence including beneficial ownership. The program does not have to be large, but it has to be genuine, documented, and matched to the actual product and risk.
How early should a fintech start on compliance?
Before the fintech selects a sponsor bank, and well before a launch date is set. Sponsor-bank diligence can take months, and the program has to exist before that diligence starts. Building compliance in parallel with the product, rather than after it, shortens the path to launch and costs less than retrofitting the program after a finding.
Can a fintech outsource its compliance before launch?
A fintech can have compliance work performed by an outside team, including a fractional or embedded officer, but it still owns the program and remains answerable for it. Outsourcing the work is common and reasonable; outsourcing the accountability is not possible. The bank will still expect a named, accountable owner on the fintech side.
About this library

This reference library is maintained by Rupture Labs, the company behind Compliance Command Center, compliance software built and reviewed by practitioners. Contact.

Primary sources

The authoritative texts this guide is grounded in. Government sites may block automated access but resolve in a browser.