New Analysis Highlights Liability Risks in Bank-Fintech BaaS Partnerships

3 min readSources: National Law Review

Analysis reveals legal exposures in liability sharing within BaaS compliance failures.

Why it matters: As Banking-as-a-Service (BaaS) grows, clarity on compliance liability is vital for managing legal risks between banks and fintechs.

  • The 2024 Synapse Financial collapse froze thousands of accounts, sparking lawsuits over fund responsibilities.
  • In 2025, the OCC fined multiple sponsor banks for inadequate oversight of fintech AML/BSA compliance.
  • Over 10 BaaS-focused banks faced consent orders since 2023 from FDIC, OCC, and Federal Reserve on third-party risk management.
  • A 2024 interagency statement emphasized risks in bank-third party deposit product arrangements and control oversight.

Recent developments in Banking-as-a-Service (BaaS) highlight a growing focus on how liability is shared between banks and fintech partners amid compliance failures. The collapse of Synapse Financial Technologies in 2024, which left thousands of customer accounts frozen and tens of millions of dollars unreconciled, triggered lawsuits emphasizing disputes over accountability for missing funds. This incident underscored the complexities of compliance in tightly coupled bank-fintech partnerships.

Regulatory scrutiny intensified as the Office of the Comptroller of the Currency (OCC) fined several sponsor banks in 2025 for failing to enforce adequate Bank Secrecy Act (BSA) and Anti-Money Laundering (AML) programs within their fintech partners. This enforcement reflects a clear message: banks cannot treat BaaS as a regulatory shield. As noted by industry analysts, "BaaS is not a regulatory shield. It is a shared compliance environment" (Sanctions.io).

The coordinated regulatory approach became evident as at least 10 banks focused on BaaS have received consent orders from major authorities including the FDIC, OCC, and Federal Reserve since 2023. These actions indicate consensus on enforcing stronger third-party risk management (TPRM) standards for bank-fintech collaborations (RiskTemplate).

Further guidance arose from a July 2024 interagency joint statement by Federal Reserve, FDIC, and OCC, which highlighted risks in arrangements where banks use third parties to deliver deposit products. It emphasized vulnerabilities in controls, deposit obligations, oversight responsibilities, and visibility into customer impact (Derisk Partners).

Legal experts stress that regulators increasingly view compliance failures—including fraud monitoring, disclosures, and customer remediation—not as isolated operational issues but as systemic legal violations. As Philip R. Stein summarized, enforcement actions are shaping to hold both banks and fintechs jointly accountable for lapses (Bilzin Sumberg).

In this environment, banks must maintain strong oversight and control of third-party fintech activities, while fintechs should recognize the shared compliance environment and uphold robust AML and BSA programs. Effective legal risk management in BaaS partnerships hinges on clear allocation of liability and stringent compliance standards.

By the numbers:

  • 10+ BaaS-focused banks received consent orders since 2023 — FDIC, OCC, and Federal Reserve enforcement actions
  • 2024 — Collapse of Synapse Financial Technologies freezing thousands of accounts
  • 2025 — OCC fined multiple sponsor banks for deficient fintech AML/BSA programs

What's next: Ongoing regulatory scrutiny is expected to continue, with further enforcement actions and updated supervisory guidance on bank-fintech third-party risk expected in 2026.