Leaders Insights
Leaders Insights

Stay at the top of your field, a little every day.

DomainsMarketingDataFinanceAI
ResourcesLearnTestToolsBlogGlossary
© 2026 Leaders Insights — All rights reserved.
Tracks/Finance in fintech/Regulation, risks and checks/Spotting the risks that sink fintechs before the market notices
2/4+150 XP

Regulation, risks and checks

10How fintech regulation actually works, license by license+15011Spotting the risks that sink fintechs before the market notices+15012
Reading a fintech's compliance stack like a regulator would
+150
13Running a due-diligence check on a fintech in one sitting+150

Spotting the risks that sink fintechs before the market notices

# Spotting the risks that sink fintechs before the market notices

In May 2024, roughly 100,000 Americans woke up unable to access their own money. Their funds sat in accounts branded by fintech apps like Yotta and Juno, but the actual dollars lived at partner banks, routed through a middleman called Synapse. When Synapse collapsed into bankruptcy, nobody could agree on whose ledger was correct. Some depositors are still missing money, more than a year later. No hack occurred. No fraud was proven. The system just failed to answer a basic question: whose money is this, exactly.

That question, and two others like it, are what this lesson trains you to ask before a fintech's problems become public.

Three risks, one lesson

Fintech failures rarely come from one dramatic villain. They come from three recurring, boring-sounding risk categories that compound quietly:

  • Compliance risk: the danger that a firm breaks, or can't prove it follows, financial regulation
  • Custody risk: the danger that customer assets aren't safe, segregated, or recoverable if the firm fails
  • Concentration risk: the danger of over-reliance on one partner, client, or revenue stream

Synapse was a custody and concentration failure. Wirecard was a compliance failure disguised as a growth story. Learning to tell them apart is the actual skill here, not memorizing definitions.

Compliance risk: when the numbers are the fraud

Compliance risk is exposure to fines, license loss, or shutdown because a firm fails to meet regulatory requirements, or actively hides that it doesn't.

Wirecard, once a DAX-listed German payments giant worth over €24 billion at its 2018 peak, collapsed in June 2020 when auditors discovered that €1.9 billion supposedly held in Philippine bank accounts didn't exist. The company had fabricated a large share of its Asian business through fictitious "third-party acquirer" partnerships for years. BaFin (Germany's financial regulator, the Bundesanstalt für Finanzdienstleistungsaufsicht) was criticized afterward for defending Wirecard against short-sellers' fraud allegations instead of investigating them.

The lesson isn't "audit your auditors." It's that compliance risk hides in plain sight in growth metrics that seem too smooth. Wirecard's Asian revenue growth was inconsistent with the size and maturity of those markets. Nobody who wasn't looking for it noticed.

Where compliance risk lives in fintech today:

  • AML/KYC gaps (Anti-Money Laundering / Know Your Customer, the rules requiring firms to verify customer identity and monitor for illicit funds). In the US, enforced by FinCEN (Financial Crimes Enforcement Network) and state regulators; in the EU, under AMLD (Anti-Money Laundering Directive) frameworks and increasingly the EU's AMLA (Anti-Money Laundering Authority, operational from 2025).
  • Unlicensed lending or money transmission: operating across US states without the required money transmitter licenses, or in the EU without an EMI (Electronic Money Institution) or PI (Payment Institution) license under PSD2 (the second Payment Services Directive).
  • Misleading marketing about insurance, covered next.

Custody risk: whose money is it, actually

Custody risk is the danger that customer funds aren't held the way customers believe, aren't legally protected, or can't be traced back to them individually.

Synapse was a Banking-as-a-Service (BaaS) middleware provider: it connected fintech apps to FDIC-insured partner banks (the Federal Deposit Insurance Corporation insures US bank deposits up to $250,000 per depositor, per bank) without being a bank itself. Many customer-facing apps advertised "FDIC insured" accounts. But FDIC insurance only protects against bank failure, not against a middleman's ledger being wrong or its bankruptcy freezing fund flows. When Synapse folded, reconciling which end-user owned which dollar, across multiple partner banks and the failed Synapse database, became forensically difficult. As of 2025, some funds remain unrecovered, an outcome regulators and consumer advocates have called a preventable failure of oversight.

The custody question to always ask: if this middleman disappeared tomorrow, could my money be identified and returned by end of week?

For crypto platforms, custody risk is even sharper: are customer coins held 1:1 in segregated wallets, or commingled with the firm's own trading capital? FTX's 2022 collapse was fundamentally this failure. The CFTC (Commodity Futures Trading Commission) and SEC (Securities and Exchange Commission) have since pushed harder on proof-of-reserves disclosures, though standards remain inconsistent industry-wide.

For a plain-language regulatory primer on BaaS risks, the Consumer Financial Protection Bureau's guidance on bank partnerships is a solid free starting point.

Concentration risk: the single point of failure

Concentration risk is over-dependence on one entity, whether a partner bank, a single large client, a funding source, or a geography.

Synapse again illustrates this well: dozens of fintech apps depended entirely on one middleware provider with no backup plan. When it failed, there was no orderly transfer path. Regulators have since pushed partner banks toward direct oversight of BaaS relationships rather than fully outsourcing compliance to intermediaries.

Concentration risk also shows up as:

  • Revenue concentration: a B2B fintech where one enterprise client is 40%+ of revenue
  • Funding concentration: a neobank reliant on one wholesale funding line or one venture investor for runway
  • Geographic concentration: a payments firm processing most volume through one correspondent bank corridor

A quick worked example. Suppose a fintech lender's revenue comes from three partner banks, split 70/20/10. If the 70% partner exits (a real, recurring event as banks reassess BaaS risk appetite post-2024), the firm doesn't lose 70% of revenue gradually, it can lose it within a regulatory notice period, often 90 days. Run that math before assuming a growth chart is sustainable: 70% of a $50 million run-rate is $35 million gone in a quarter.

Knowledge check

1. A fintech's collapse leaves customers unsure whose ledger correctly reflects their account balances, because their money passed through a middleman connecting the app to partner banks. Which risk category does this best illustrate?

2. A company fabricates evidence of business activity and assets that don't actually exist, to appear compliant and financially healthy to regulators and investors. This is best classified as which risk?

3. Why is it useful to distinguish compliance, custody, and concentration risk as separate categories rather than treating 'fintech risk' as one general concern?

MULTIPLE CHOICE

4. Select ALL correct answers about concentration risk in fintech.

Select all the correct answers.

MULTIPLE CHOICE

5. A fintech app displays customer balances, but the actual cash is held at a partner bank and routed through a middleman processor. Select ALL correct answers about how to assess this situation.

Select all the correct answers.

Practical due-diligence checks

You don't need a compliance license to run a first-pass check on a fintech, whether as an investor, partner, employee, or informed customer.

Compliance checks:

  • Does the firm disclose its licenses (state money transmitter licenses in the US, EMI/PI license number in the EU)? Check via NMLS Consumer Access (US) or national regulator registers (BaFin, the FCA's Financial Services Register in the UK).
  • Are there recent consent orders or enforcement actions? Search the CFPB, OCC (Office of the Comptroller of the Currency), or FCA (Financial Conduct Authority) enforcement databases.

Custody checks:

  • Read the terms of service: does it name the actual FDIC-insured bank holding funds, or only the fintech brand?
  • For crypto or e-money products, is there a public proof-of-reserves or independent attestation, and how recent is it?

Concentration checks:

  • In funding announcements or 10-KKThe average number of new users each existing user generates through referrals. Above 1.0, growth compounds on itself and becomes exponential.View full definition →/annual filings, look for "significant customer" or "significant partner" disclosure language, required under US securities rules when concentration is material.

Previous

How fintech regulation actually works, license by license

Next

Reading a fintech's compliance stack like a regulator would

  • Ask (or infer from press) how many banking partners a BaaS-dependent fintech actually has. One is a red flag; three or more with disclosed redundancy is healthier.
  • 🎬 [VIDEO: "How Wirecard's $2 Billion Fraud Unraveled" - youtube.com - a concise breakdown of the accounting mechanics behind Europe's biggest fintech fraud, useful for seeing compliance risk in action]

    Key Takeaways

    • Compliance risk is exposure from broken or hidden regulatory failures. Check licenses and enforcement history first; Wirecard's fraud was findable years before its collapse by anyone questioning its Asian revenue growth.
    • Custody risk is about whether customer money is legally segregated and traceable. Always ask who actually holds the funds, not just whose logo is on the app; Synapse showed that "FDIC insured" branding doesn't guarantee recoverability.
    • Concentration risk turns a single partner's exit into a sudden, not gradual, crisis. Quantify what percentage of revenue or funding sits with one counterparty.
    • These risks compound: Synapse was custody risk built on concentration risk, with weak oversight (a compliance gap) allowing it to persist unaddressed.
    • Due diligence is accessible without a law degree: licensing registers, enforcement databases, and disclosure filings are free, public, and often ignored until it's too late.