# Running a due-diligence check on a fintech in one sitting
It's 4:45 PM. A Series B term sheet closes tomorrow, and your investment committee wants one page: is this payments startup fundable, or is it sitting on a regulatory landmine? You have three hours, not three weeks. This lesson gives you the checklist that gets you a defensible answer by 8 PM.
Our working example: "PayFlow" (a composite, not a real company) is a US-based payments startup processing $2 billion in annualized volume, raising a $40 million Series B. It doesn't hold its own money transmitter license in most states. It routes transactions through a partner bank. This is the single most common structure in consumer fintech, and the single most common source of blow-ups (see the Synapse collapse of 2024, where a middleware failure between fintechs and partner banks froze deposits for over 100,000 users, a real and well-documented case).
Most payment fintechs in the US don't hold a banking license. Instead they operate under one of two models:
The check: Don't take the pitch deck's word for it. Search the NMLS Consumer Access database
In Europe, the equivalent is an e-money institution (EMI) or payment institution (PI) license under PSD2 (the second Payment Services Directive), issued by a national regulator (e.g., the FCA in the UK, the ACPR in France) and passported across the EU/EEA. Check the FCA Financial Services Register or the equivalent national registry.
Red flag for PayFlow: if it claims "licensed in all 50 states" but NMLS shows active MTLs in only 38, that's a material gap, not a rounding error.
If PayFlow doesn't hold its own charter, its entire business depends on one or two partner banks (common names in this space: Cross River Bank, Evolve Bank & Trust, Column Bank). This is the single biggest single-point-of-failure risk in fintech.
Questions to answer in the data room:
1. How many partner banks does it use? (One is a red flag; concentration risk.)
2. What happens contractually if the bank terminates the relationship? Notice period, wind-down provisions, portability of customer funds.
3. Has the partner bank itself faced regulatory action? In 2024, the Federal Reserve and FDIC (Federal Deposit Insurance Corporation) issued consent orders against several BaaS-focused banks for deficient Bank Secrecy Act (BSA) and anti-money-laundering (AML) controls. A consent order against PayFlow's partner bank is a direct threat to PayFlow's ability to operate, even though PayFlow itself did nothing wrong.
Worked example: If PayFlow holds $2B in annualized volume through one partner bank, and that bank represents, say, 15% of the bank's total deposit base tied to fintech partnerships, a regulator ordering the bank to "de-risk" (reduce fintech exposure) could force PayFlow to migrate rails within 90 to 180 days. Ask: does PayFlow have a documented backup bank relationship already signed? If not, that's your single biggest risk line in the memo.
Series B is early enough that PayFlow may not have a full-scope audit yet, but it should have:
Check the trend, not just the snapshot. A SOC 2 with a dozen noted exceptions in "logical access controls" is a governance signal, not a deal-killer by itself, but it tells you where operational risk concentrates.
This is the step most diligence teams skip because it's tedious, and it's the one that matters most.
Ask directly for:
The real-world comparable: in 2024 to 2025, the CFPB brought several actions against fintechs and their bank partners over unauthorized transfers and deceptive fee disclosures. A company with a clean public record but an unresolved internal CFPB inquiry disclosed only in board minutes is exactly what a fast diligence sweep is designed to surface.
If PayFlow's legal team hesitates to produce this file, that hesitation is itself information.
Vérification des acquis
1. A payments startup like PayFlow routes transactions through a partner bank rather than holding its own money transmitter license. What does this structure imply for due diligence?
2. Why should a diligence reviewer check the NMLS Consumer Access database rather than relying on the pitch deck's licensing claims?
3. A fintech claims to serve customers in all 50 US states. During your NMLS check, you find it holds active money transmitter licenses in only 35 states. What is the most reasonable interpretation of this finding?
4. Select ALL correct answers about the two primary licensing models for US payment fintechs described in the lesson.
Sélectionnez toutes les réponses correctes.
5. Select ALL correct answers about why the Synapse collapse is relevant context for fintech due diligence.
Sélectionnez toutes les réponses correctes.
Payments companies hold other people's money, even briefly. The key question: is customer money legally segregated from company operating funds?
In the US, MTL regulations generally require "permissible investments" equal to outstanding customer liabilities, held separately. In the EU/UK, EMI and PI rules under PSD2 require safeguarding, customer funds must sit in segregated accounts at an authorized credit institution or be covered by an insurance policy.
The check: ask for the bank statement showing the segregated account balance, and reconcile it against the reported customer liability figure on the balance sheet, on the diligence date, not a quarter-old figure. A mismatch here is the fintech equivalent of a bank run waiting to happen (this is essentially what went wrong operationally in the Synapse case).
Structure your findings into four lines:
1. Licensing: verified active / gaps found in X states / fully dependent on partner bank.
2. Partner-bank concentration: single point of failure? Backup in place?
3. Audit trail: SOC 2 clean / exceptions noted / no audit yet (expected at this stage or not).
4. Regulatory correspondence: clean / open inquiry (disclosed) / open inquiry (undisclosed, escalate immediately).
A single undisclosed regulatory inquiry is grounds for pausing the close regardless of how good the other three lines look.
🎬 [VIDEO: "How Fintech Banking Partnerships Actually Work" - youtube.com/@Fintech - a walkthrough of the BaaS model, partner-bank risk, and why so many fintechs don't hold their own charter, useful visual companion to Steps 1 and 2 above]