Overcoming Risk in Community Bank/Fintech Partnerships

“On May 21, 2026, the Office of the Comptroller of the Currency (OCC) made public an April 2026 consent order (AA-ENF-2025-21) against a federal savings association based in the Northeast for deficiencies in its Bank Secrecy Act/Anti-Money Laundering (BSA/AML) compliance program. The order is the latest in a growing line of enforcement actions demonstrating that regulators are paying close attention to smaller institutions — particularly those that have expanded rapidly into payment processing and fintech-adjacent business lines without proportionally scaling their compliance infrastructure. For community banks pursuing revenue growth through fintech partnerships and payments services, the lessons are both clear and urgent.”1

Bank-fintech partnerships are the norm, and in a period of regulatory uncertainty and volatility, they are also a risk. Currently, no rules dictate who owns what when it comes to compliance within bank/fintech partnerships. Previous open banking guidance that put the onus on banks has been withdrawn and new guidance is being drafted that may or may not place more regulatory burden on fintechs.

However, the unsteady regulatory landscape does not mean regulators will ignore perceived violations. State regulators have their own standards when it comes to these partnerships and federal action continues apace, with smaller banks increasingly in the crosshairs. Sima Gandhi, co-founder of the Coalition for Financial Ecosystem Standards (CFES) stated, “For many community banks around the country, partnering with fintechs is the way forward.” However, she adds, “For a smaller bank a consent order could kill the program and end viability financially.”2

While FDIC-insured sponsor banks provide the banking charter, regulatory licenses and deposit infrastructure, they also own the compliance obligations. The bank is responsible for every regulatory requirement surrounding even the customer-facing, underwriting, or transaction processes the fintech undertakes.

For instance, under the Bank Secrecy Act, obligations fall on the financial institution, and not the fintech partners. It is the bank’s responsibility to ensure that fintech partners perform customer due diligence and transaction monitoring. With respect to data protection and cybersecurity, the bank needs assurance that fintechs continually meet security requirements.

Of course, banks demand fintechs accept compliance responsibilities, but due to lack of specific regulatory segregation of bank vs. fintech responsibilities, confusion can reign when compliance responsibilities overlap, or when the bank is not fully versed in the fintech’s compliance profile.

One way to clarify the process is to place compliance and risk requirements into vendor contracts, with specific mentions of KYC, AML, cybersecurity, data integrity, and appropriate penalties, including termination, for failing to meet the contract terms. However, an industry standards organization has developed a system that may be more seamless for community banks.

The STARC Framework

To help community banks seize the lucrative opportunities fintech partnerships can provide, the Coalition for Financial Ecosystem Standards (CFES) has developed its Standardized Assessment for Risk Management & Compliance (STARC). STARC requires independent audits to certify that a fintech has achieved measurable compliance criteria across six core areas:

  • Bank Secrecy Act/Anti-Money Laundering (BSA/AML): Protocols preventing financial crimes.
  • Compliance Management System (CMS): The overarching structure governing consumer protection and compliance policies.
  • Third-Party Risk Management (TPRM): Oversight of critical vendors and sub-contractor risks.
  • Complaint Handling: Systems for logging, tracking, and resolving consumer grievances.
  • Operational Risk: Internal controls protecting against system failures and human error.
  • Marketing and Product Compliance: Ensuring transparent messaging, compliance with fair lending guidelines, and fair consumer treatment.

And for each compliance area, the following program elements are evaluated using a 5-level maturity scale that ranges from Level 5 (Rudimentary), denoting informal or reactive approaches, to Level 1 (Optimized) denoting highly automated, strategic systems that optimize risk mitigation:

  • Governance, oversight, and staffing
  • Risk assessment
  • Training
  • Policies and procedures
  • Monitoring and testing
  • Issue management
  • Reporting
  • Change management3

Per the American Fintech Council, “The framework and these initial standards were developed through extensive consultation with banks, fintechs, regulators, and consumer advocates.”4 With regulatory uncertainty for the foreseeable future and regulators paying close attention to bank/fintech partnerships, the Stark Framework can give smaller banks the structure and confidence to choose more reliable and compliant fintech partners to fuel their growth strategies.

1https://www.financialservicesperspectives.com/2026/06/the-occs-recent-consent-order-is-a-warning-for-community-banks-in-the-fintech-partnership-space/
2https://www.independentbanker.org/w/starc-framework-for-bank-fintech-risk-management
3https://crosscheckcompliance.com/resources/industry-insights/fintech-compliance-certification-cfes/
4https://www.fintechcouncil.org/press-releases/american-fintech-council-afc-joins-cfes-advisory-board-to-advance-its-premier-standards-based-approach-to-risk-management-and-compliance-in-bank-fintech-partnerships