Leaders Insights
Leaders Insights

Rester au meilleur niveau, un peu chaque jour.

DomainesMarketingDataFinanceIA
RessourcesApprendreTestOutilsBlogGlossaire
© 2026 Leaders Insights — Tous droits réservés.
Formations/Fintech: how the sector works/Regulation, major laws and compliance/The regulatory bodies map: who enforces what and how examinations work
5/5+150 XP

Regulation, major laws and compliance

10Payments regulation: PSD2, the EMI license and open banking rules+15011AML, KYC and sanctions screening in practice+15012Consumer protection law: fair lending and disclosure rules+15013Data privacy and open finance: GDPR, CCPA and data-sharing consent+15014The regulatory bodies map: who enforces what and how examinations work+150

The regulatory bodies map: who enforces what and how examinations work

# The regulatory bodies mapmapUsing software to automate repetitive marketing tasks and campaigns, enabling personalisation at scale across channels like email, web, and social.Voir la définition complète →: who enforces what and how examinations work

A fintech's chief compliance officer gets an email on a Tuesday: "OCC wants a walkthrough of your BSA/AML program by Friday, and they're pulling it through your bank partner, not you." That sentence contains the entire architecture of fintech regulation in one line: the fintech itself often has no direct regulator, but its bank partner does, and that regulator's authority flows straight through the partnership contract into the fintech's operations.

This lesson builds the mapmapUsing software to automate repetitive marketing tasks and campaigns, enabling personalisation at scale across channels like email, web, and social.Voir la définition complète →: who owns which risk, and what actually happens when an examiner shows up.

Why fintechs are regulated indirectly

Most fintech lending, deposit, and payments products in the US are not built on the fintech's own charter. They're built on a partner bank's charter, using arrangements sometimes called "bank-fintech partnerships" or, in lending, "rent-a-bank" models.

That matters because US bank regulators supervise banks, not fintechs. When a fintech partners with a bank, the fintech becomes a "third party" under the bank's risk management, and the bank's regulator gains indirect but real authority over the fintech through examination of the bank.

The US mapmapUsing software to automate repetitive marketing tasks and campaigns, enabling personalisation at scale across channels like email, web, and social.Voir la définition complète →: four bodies, four risk lenses

OCC (Office of the Comptroller of the Currency): charters and supervises national banks and federal savings associations. If your bank partner is nationally chartered (think Cross River Bank was historically state-chartered, but many partner banks are OCC-supervised), the OCC's third-party risk management guidance (Bulletin 2021-19) is the rulebook governing how that bank must vet, contract with, and monitor you.

FDIC (Federal Deposit Insurance Corporation): supervises state-chartered banks that aren't Federal Reserve members, insures deposits up to $250,000 per depositor per bank (as of 2026, unchanged since 2010). Many fintech "banking-as-a-service" partners, like the banks behind neobank apps, are FDIC-supervised state nonmember banks.

Federal Reserve: supervises state-chartered banks that are Fed members and bank holding companies. Owns systemic risk and monetary policy transmission; relevant to fintechs mainly through payment system access and holding company structures.

CFPB (Consumer Financial Protection Bureau): created by the Dodd-Frank Act (2010), enforces consumer protection law directly against nonbanks above certain size thresholds, not just through bank partners. This is the one body that can reachreachThe number of unique people exposed to your message in a given period. Unlike impressions, reach counts each person once, no matter how often they see it.Voir la définition complète → fintechs directly. It enforces the Truth in Lending Act (TILA), Equal Credit Opportunity Act (ECOA), and Electronic Fund Transfer Act (EFTA), among others. In 2024-2025 the CFPB finalized a rule to supervise large nonbank companies offering digital payment apps directly, a meaningful expansion of direct fintech oversight (status and enforcement posture has fluctuated with leadership changes, so verify current scope before relying on it).

FinCEN (Financial Crimes Enforcement Network): a bureau of the US Treasury, administers the Bank Secrecy Act (BSA, 1970) and its Anti-Money Laundering (AML) requirements. FinCEN doesn't examine most fintechs directly, but it sets the rules (Know Your Customer/KYC, Suspicious Activity Reports/SARs, Currency Transaction Reports/CTRs) that banks push down into fintech partnership contracts. Money services businesses (MSBs), which include many crypto and payments companies, register directly with FinCEN.

SEC (Securities and Exchange Commission): relevant when fintech products touch securities, robo-advisors, crypto tokenstokensA token is the basic unit of text that language models process, often a word fragment, whole word, or punctuation mark rather than a single character.Voir la définition complète → deemed securities, tokenized funds. The SEC's ongoing enforcement actions against crypto platforms (Coinbase, Ripple litigation through 2023-2025) illustrate this boundary being actively contested.

CFTC (Commodity Futures Trading Commission): owns derivatives and, per ongoing jurisdictional debate, many crypto commodities like Bitcoin.

The Europe mapmapUsing software to automate repetitive marketing tasks and campaigns, enabling personalisation at scale across channels like email, web, and social.Voir la définition complète →: fewer bodies, broader single-market reachreachThe number of unique people exposed to your message in a given period. Unlike impressions, reach counts each person once, no matter how often they see it.Voir la définition complète →

ECB (European Central Bank): supervises the largest, "significant" euro-area banks directly through the Single Supervisory Mechanism (SSM), and sets monetary policy for the eurozone. Fintechs partnering with a major euro-area bank are indirectly touched by ECB supervisory standards.

EBA (European Banking Authority): writes binding technical standards applied across the EU, including rules under PSD2 (the second Payment Services Directive, 2015/2018) covering open bankingopen bankingCadre réglementaire (PSD2 en Europe) obligeant les banques à partager les données clients via des API standardisées, avec consentement, transformant les données bancaires en actif compétitif. APIs and strong customer authentication.

National Competent Authorities (NCAs): day-to-day supervision in the EU is largely national. Germany's BaFin, France's ACPR, and Ireland's Central Bank are the ones fintechs actually deal with, since many fintechs "passport" a license from one EU member state across the whole bloc under single-market rules.

FCA (Financial Conduct Authority): the UK's conduct regulator (post-Brexit, no longer inside the EU passporting regime), covering consumer protection, market conduct, and most fintech authorizations (payments institutions, e-money institutions). The FCA's regulatory sandbox has been a template other regulators copied.

PRA (Prudential Regulation Authority): part of the Bank of England, handles prudential (capital, solvency) supervision of UK banks and larger insurers, working alongside the FCA in the UK's "twin peaks" model.

The one-line risk ownership cheat sheet

| Risk area | US owner | EU/UK owner |

|---|---|---|

| Bank safety and soundness | OCC / FDIC / Fed | ECB / national NCAs / PRA |

| Consumer protection, fair lending | CFPB | FCA |

| Anti-money laundering | FinCEN (rules), banks (execution) | EBA (standards), NCAs (enforcement) |

| Securities and tokenstokensA token is the basic unit of text that language models process, often a word fragment, whole word, or punctuation mark rather than a single character.Voir la définition complète → | SEC | ESMA / NCAs |

| Payments and open bankingopen bankingCadre réglementaire (PSD2 en Europe) obligeant les banques à partager les données clients via des API standardisées, avec consentement, transformant les données bancaires en actif compétitif. | Fed (rails), CFPB (conduct) | EBA / PSD2, FCA |

Walking through a real third-party risk examination

Here's the sequence when a bank partner faces an OCC or FDIC exam that includes your fintech as a "critical activity" third party.

1. Pre-exam document request. The examiner sends the bank a request list; the bank forwards relevant items to you. Typical asks: your information security policy, SOC 2 report, BSA/AML procedures, vendor management of your own subcontractors, incident response plan, and board or executive oversight minutes covering the partnership.

2. Contract and due diligence review. Examiners check whether the bank did adequate due diligence before onboarding you (financial condition, legal history, data security posture) and whether the contract gives the bank real audit rights, termination rights, and data ownership clarity. Weak contracts are a top finding.

3. Walkthrough and testing. Examiners (sometimes with the fintech present, sometimes remotely through the bank) test controls: pull a sample of loan files or accounts, check KYC documentation completeness, verify SAR filing timeliness, test whether marketing claims match actual APR disclosures under TILA.

4. Matters Requiring Attention (MRAs) or Consent Orders. If examiners find gaps, the bank receives an MRA (a formal, non-public directive to fix something by a deadline) or, for serious or repeated issues, a public consent order. These trickle down contractually: the bank often requires the fintech to co-sign a remediation plan with specific dates and evidence of closure.

5. Remediation and follow-up exam. The fintech implements fixes, generates evidence (updated policies, retrained staff, corrected disclosures), and the bank reports progress to examiners, sometimes with a third-party review to validate the fix actually worked.

The practical lesson: a fintech's compliance team should assume every internal control gets read by an examiner eventually, just with an 18 to 24 month lag through the bank's exam cycle.

Vérification des acquis

1. Why does a bank regulator like the OCC have real authority over a fintech that has no bank charter of its own?

2. A fintech's compliance officer wants to know which federal regulator's third-party risk guidance will most directly shape how their bank partner must vet and monitor them. What determines the answer?

3. What is the core structural reason fintech lending and deposit products are often described as 'rent-a-bank' models?

CHOIX MULTIPLES

4. Select ALL correct answers about why the US fintech regulatory map involves multiple different bodies rather than one single regulator.

Sélectionnez toutes les réponses correctes.

CHOIX MULTIPLES

5. Select ALL correct answers about what happens when a bank regulator examines a bank that has fintech partnerships.

Sélectionnez toutes les réponses correctes.

Where enforcement actually lands

Recent history is instructive rather than exhaustive. US bank regulators have issued consent orders against partner banks over BSA/AML weaknesses tied to fintech partnerships (several 2023-2024 actions against banks like Blue Ridge Bank and Cross River Bank involved fintech program deficiencies, publicly available on the FDIC's enforcement action database). The CFPB has brought direct actions against nonbank fintechs for deceptive marketing and junk fees. The pattern: banks get hit for oversight failures, fintechs get hit for direct consumer harm, and both get hit when AML controls fail.

🎬 [VIDEO: "How Banking Regulation Works in the US" - youtube.com - search for Federal Reserve or OCC explainer content covering the US bank regulatory structure and examination process]

Key Takeaways

  • In the US, most consumer-facing fintechs are regulated indirectly through their bank partner's regulator (OCC, FDIC, or Fed), while the CFPB and FinCEN's rules can reachreachThe number of unique people exposed to your message in a given period. Unlike impressions, reach counts each person once, no matter how often they see it.Voir la définition complète → fintechs more directly.
  • In Europe, national authorities (BaFin, ACPR, Central Bank of Ireland) handle day-to-day supervision under EU-wide standards from the EBA and ECB; the UK's FCA and PRA operate a separate "twin peaks" system post-Brexit.
  • A bank partner's third-party risk exam follows a predictable sequence: document request, due diligence and contract review, control testing, findings (MRA or consent order), and a remediation plan the fintech typically must co-execute.
  • Weak third-party contracts, especially missing audit rights or unclear data ownership, are a recurring examiner finding independent of the underlying business.
  • Assume a lag of 18 to 24 months between an internal control gap and an examiner finding it: build compliance evidence now, not reactively.

Précédent

Data privacy and open finance: GDPR, CCPA and data-sharing consent