Leaders Insights
Leaders Insights

Rester au meilleur niveau, un peu chaque jour.

DomainesMarketingDataFinanceIA
RessourcesApprendreTestOutilsBlogGlossaire
© 2026 Leaders Insights — Tous droits réservés.
Formations/Finance in fintech/Regulation, risks and checks/Running a due-diligence check on a fintech in one sitting
4/4+150 XP

Regulation, risks and checks

10How fintech regulation actually works, license by license+15011Spotting the risks that sink fintechs before the market notices+15012Reading a fintech's compliance stack like a regulator would+15013Running a due-diligence check on a fintech in one sitting+150

Running a due-diligence check on a fintech in one sitting

# Running a due-diligence check on a fintech in one sitting

It's 4:45 PM. A Series B term sheet closes tomorrow, and your investment committee wants one page: is this payments startup fundable, or is it sitting on a regulatory landmine? You have three hours, not three weeks. This lesson gives you the checklist that gets you a defensible answer by 8 PM.

Our working example: "PayFlow" (a composite, not a real company) is a US-based payments startup processing $2 billion in annualized volume, raising a $40 million Series B. It doesn't hold its own money transmitter license in most states. It routes transactions through a partner bank. This is the single most common structure in consumer fintech, and the single most common source of blow-ups (see the Synapse collapse of 2024, where a middleware failure between fintechs and partner banks froze deposits for over 100,000 users, a real and well-documented case).

Step 1: confirm licensing status, not just licensing claims

Most payment fintechs in the US don't hold a banking license. Instead they operate under one of two models:

  • Money Services Business (MSB) registered with FinCEN (Financial Crimes Enforcement Network), plus state-by-state money transmitter licenses (MTLs).
  • Bank Partnership / "Banking-as-a-Service" (BaaS) model, where a chartered bank holds the license and the fintech operates as its agent.

The check: Don't take the pitch deck's word for it. Search the NMLS Consumer Access database

(Nationwide Multistate Licensing System), which is free and public. Confirm the entity name matches exactly, check license status (active, suspended, surrendered), and check which states are covered versus which states the company claims to serve.

In Europe, the equivalent is an e-money institution (EMI) or payment institution (PI) license under PSD2 (the second Payment Services Directive), issued by a national regulator (e.g., the FCA in the UK, the ACPR in France) and passported across the EU/EEA. Check the FCA Financial Services Register or the equivalent national registry.

Red flag for PayFlow: if it claims "licensed in all 50 states" but NMLS shows active MTLs in only 38, that's a material gap, not a rounding error.

Step 2: mapmapUsing software to automate repetitive marketing tasks and campaigns, enabling personalisation at scale across channels like email, web, and social.Voir la définition complète → the partner-bank exposure

If PayFlow doesn't hold its own charter, its entire business depends on one or two partner banks (common names in this space: Cross River Bank, Evolve Bank & Trust, Column Bank). This is the single biggest single-point-of-failure risk in fintech.

Questions to answer in the data room:

1. How many partner banks does it use? (One is a red flag; concentration risk.)

2. What happens contractually if the bank terminates the relationship? Notice period, wind-down provisions, portability of customer funds.

3. Has the partner bank itself faced regulatory action? In 2024, the Federal Reserve and FDIC (Federal Deposit Insurance Corporation) issued consent orders against several BaaS-focused banks for deficient Bank Secrecy Act (BSA) and anti-money-laundering (AML) controls. A consent order against PayFlow's partner bank is a direct threat to PayFlow's ability to operate, even though PayFlow itself did nothing wrong.

Worked example: If PayFlow holds $2B in annualized volume through one partner bank, and that bank represents, say, 15% of the bank's total deposit base tied to fintech partnerships, a regulator ordering the bank to "de-risk" (reduce fintech exposure) could force PayFlow to migrate rails within 90 to 180 days. Ask: does PayFlow have a documented backup bank relationship already signed? If not, that's your single biggest risk line in the memo.

Step 3: pull the audit and financial statement history

Series B is early enough that PayFlow may not have a full-scope audit yet, but it should have:

  • SOC 2 Type II report (System and Organization Controls, an independent audit of security and operational controls over a period of time, not a point in time). Ask for the actual report, not a badge on the website.
  • Independent financial statements, ideally reviewed or audited by a recognized firm.
  • If it touches card payments, a current PCI-DSS (Payment Card Industry Data Security Standard) attestation of compliance.

Check the trend, not just the snapshot. A SOC 2 with a dozen noted exceptions in "logical access controls" is a governance signal, not a deal-killer by itself, but it tells you where operational risk concentrates.

Step 4: read the regulatory correspondence file

This is the step most diligence teams skip because it's tedious, and it's the one that matters most.

Ask directly for:

  • Any CFPB (Consumer Financial Protection Bureau) complaints, inquiries, or civil investigative demands.
  • Any state regulator examination findings (state MTL regulators conduct periodic exams).
  • Any FinCEN or BSA/AML-related inquiries.
  • Board minutes referencing regulatory matters (often the most candid source).

The real-world comparable: in 2024 to 2025, the CFPB brought several actions against fintechs and their bank partners over unauthorized transfers and deceptive fee disclosures. A company with a clean public record but an unresolved internal CFPB inquiry disclosed only in board minutes is exactly what a fast diligence sweep is designed to surface.

If PayFlow's legal team hesitates to produce this file, that hesitation is itself information.

Vérification des acquis

1. A payments startup like PayFlow routes transactions through a partner bank rather than holding its own money transmitter license. What does this structure imply for due diligence?

2. Why should a diligence reviewer check the NMLS Consumer Access database rather than relying on the pitch deck's licensing claims?

3. A fintech claims to serve customers in all 50 US states. During your NMLS check, you find it holds active money transmitter licenses in only 35 states. What is the most reasonable interpretation of this finding?

CHOIX MULTIPLES

4. Select ALL correct answers about the two primary licensing models for US payment fintechs described in the lesson.

Sélectionnez toutes les réponses correctes.

CHOIX MULTIPLES

5. Select ALL correct answers about why the Synapse collapse is relevant context for fintech due diligence.

Sélectionnez toutes les réponses correctes.

Step 5: check capital and safeguarding of customer funds

Payments companies hold other people's money, even briefly. The key question: is customer money legally segregated from company operating funds?

In the US, MTL regulations generally require "permissible investments" equal to outstanding customer liabilities, held separately. In the EU/UK, EMI and PI rules under PSD2 require safeguarding, customer funds must sit in segregated accounts at an authorized credit institution or be covered by an insurance policy.

The check: ask for the bank statement showing the segregated account balance, and reconcile it against the reported customer liability figure on the balance sheet, on the diligence date, not a quarter-old figure. A mismatch here is the fintech equivalent of a bank run waiting to happen (this is essentially what went wrong operationally in the Synapse case).

Building the one-page go/no-go memo

Structure your findings into four lines:

1. Licensing: verified active / gaps found in X states / fully dependent on partner bank.

2. Partner-bank concentration: single point of failure? Backup in place?

3. Audit trail: SOC 2 clean / exceptions noted / no audit yet (expected at this stage or not).

4. Regulatory correspondence: clean / open inquiry (disclosed) / open inquiry (undisclosed, escalate immediately).

A single undisclosed regulatory inquiry is grounds for pausing the close regardless of how good the other three lines look.

🎬 [VIDEO: "How Fintech Banking Partnerships Actually Work" - youtube.com/@Fintech - a walkthrough of the BaaS model, partner-bank risk, and why so many fintechs don't hold their own charter, useful visual companion to Steps 1 and 2 above]

Key Takeaways

  • Verify licensing independently: use NMLS Consumer Access (US) or the FCA Register / national equivalents (Europe), never rely on pitch deck claims alone.
  • Partner-bank concentration is the top structural risk in non-chartered fintechs; always check for a documented backup banking relationship.
  • Demand the actual SOC 2 and audit reports, not marketing summaries, and read the exceptions, not just the cover page.
  • The regulatory correspondence file is the highest-signal, most-skipped document; a hesitant legal team is itself a data point.
  • Reconcile segregated customer fund balances against reported liabilities on the diligence date; mismatches here are the leading indicator of the kind of freeze seen in the 2024 Synapse collapse.

Précédent

Reading a fintech's compliance stack like a regulator would