Embedded finance refers to integrating financial services (payments, lending, banking, insurance, etc.) directly into a non-financial platform or user experience. Beyond payments, platforms can embed:
- Lending (loans, BNPL, cash advances)
- Banking (accounts, wallets, debit cards)
- Insurance (coverage at point of sale)
- Investments (trading, savings tools)
Embedded finance is the invisible layer powering millions of daily transactions, from the lending widget inside a Shopify dashboard, to the insurance upsell in a rideshare app. But as the sector matures, regulators are no longer willing to let the compliance obligations remain as invisible as the technology itself.
Understanding Who Is Responsible for What in Embedded Finance
A three-layer accountability structure exists at the heart of every embedded finance arrangement. This is where compliance disputes — and enforcement actions — often originate.
- The platform (e.g., an e-commerce site, HR software, gig economy app) — distributes the product and owns the customer relationship.
- The BaaS/middleware provider — handles API connectivity, ledgering, and routing between platform and bank.
- The sponsor/licensed bank — holds the charter, absorbs the regulatory obligation, and is ultimately accountable for consumer funds.
Operating at the intersection of finance and technology invites significant regulatory complexity. Embedded finance must comply with lending laws, payments regulations, KYC/AML rules, and data privacy requirements, and these obligations multiply when platforms operate across multiple jurisdictions.
Currently, fintechs providing the middleware are often viewed as third-party technology partners and are not directly regulated. However, banks engaging in fintech partnerships are responsible for oversight in assessing their partners’ operational risk. Similarly, fintechs seeking bank partnerships must demonstrate quality and compliance maturity.
United States Sees Escalating Enforcement, Shifting Politics
The US presents a most complex regulatory picture for embedded finance, with a multi-agency framework, escalating enforcement through 2024, and a significant policy pivot under the Trump administration in 2025.
- Since the beginning of 2024, more than a quarter (25.6%) of the FDIC’s formal enforcement actions have been directed at sponsor banks in embedded finance partnerships. More than 1 in 5 OCC enforcement actions have similarly targeted sponsor banks in embedded finance. Alloy
- 75% of sponsor banks say they lost $100,000 or more to compliance violations in their embedded finance partnerships. And 80% of sponsor banks report difficulty meeting compliance requirements stemming from the need to monitor multiple fintech partners across various jurisdictions. Alloy
- 29% of sponsor banks are considering shutting down or scaling back their embedded finance programs due to compliance pressure. Alloy
What Compliance Teams Need to Do
By implementing technology that enables real-time monitoring and offers deeper insight into fintech partners’ risk management activities, sponsor banks can take on a “compliance-as-a-service” or “bank-as-regulator” role.
Sponsor banks should review their third-party risk management program against the OCC’s 2024 continuous monitoring expectations and the interagency joint guidance. Conduct a BSA/AML gap analysis if you use or operate FBO accounts.
Fintechs should map liability across your stack. Identify the precise compliance obligations at each layer: platform, middleware, and sponsor bank. Don’t assume the bank absorbs everything.
From Middleware to Mainstream Accountability
Fintech companies are now leaving the old “compliance as a separate department” approach and integrating regulatory requirements into their product development and business processes. This proactive stance can help attract investment, secure partnerships, build stronger customer relationships, and gain competitive advantage. LegalNodes
The embedded finance firms that will define the next decade won’t be those with the most innovative APIs. They’ll be the ones that made compliance as core to their architecture as the financial rails themselves.


