Techno Time

FDIC Weighs BISDO Standards to Streamline Bank-FinTech Oversight

Thursday 20 August 2026 12:45
FDIC
FDIC

The Federal Deposit Insurance Corporation (FDIC) is considering the creation of an industry-led standards organization that could certify FinTech companies and other bank service providers against common risk-management benchmarks, potentially changing how banks assess, onboard and oversee third-party partners.

The proposal, detailed in a July 21 draft term sheet obtained by Bloomberg Law, would create the Banking Innovation Standards Development Organization (BISDO) alongside a voluntary certification program known as Risk-Assessed, Manageable Partnerships (RAMP).

According to an analysis by Ballard Spahr, the initiative could represent one of the most significant changes in the federal approach to bank-FinTech partnerships and third-party service providers in recent years.

A Common Framework for Repeated Vendor Reviews

The proposal addresses a longstanding problem in the banking sector: banks frequently conduct overlapping reviews of the same vendors using different processes, while service providers repeatedly respond to similar requests in varying formats.

Under the draft framework, information could be assessed once, updated over time and reused by multiple banks.

The approach could be particularly valuable for community banks with limited compliance resources. Service providers could receive clearer expectations and distribute assessment costs across multiple banking relationships, while supervisors could gain access to more consistent and comparable information.

Certification, however, would not eliminate a bank's responsibility to determine whether a provider is appropriate for its specific risk profile. Banks would still be responsible for negotiating contracts, integrating systems, monitoring performance and maintaining ongoing oversight.

Cybersecurity, AML and Third-Party Risk Standards

BISDO could develop, adopt or recognize standards aligned with supervisory expectations. Independent, qualified assessors would evaluate service providers and individual solutions, while an authoritative registry would show whether certifications are active, suspended or withdrawn.

The proposed program would also include ongoing monitoring, provider reporting, feedback and escalation mechanisms, corrective-action procedures and an emergency “circuit breaker” that could suspend a certification in exceptional circumstances.

Potential standards could address third-party risk management, governance and internal controls, cybersecurity, operational resilience, information security, consumer compliance, Bank Secrecy Act and anti-money laundering controls, complaint management, due diligence, continuous monitoring and business continuity.

Potential Reach Extends Beyond Banking-as-a-Service

The proposed framework could have a broader reach than banking-as-a-service arrangements.

As Ballard Spahr noted, it could apply to technology and nontechnology companies, both new and established providers, as well as customer-facing and back-office functions. Standards could also be tailored to specific products, platforms, business models or control areas.

BISDO could incorporate existing standards or build on them rather than creating every benchmark from scratch.

Voluntary Certification Would Not Provide a Safe Harbor

Participation in the program would be voluntary, and an organization’s absence from the registry would not place it on a blacklist.

At the same time, certification would not constitute regulatory endorsement or provide a legal safe harbor.

Banks would remain responsible for safe and sound operations, compliance with applicable laws, consumer protection and oversight of outsourced activities.

Ballard Spahr cautioned that the absence of a safe harbor could weaken the incentive for regulated institutions to rely on the program, even if certification could serve as evidence of sound risk-management practices.

Governance and Funding Questions Remain

Several major questions remain unresolved, including who would govern BISDO and how authority would be divided among banks, FinTech companies, regulators, consumer representatives and other stakeholders.

The organizers must also determine how the organization would be funded while maintaining its independence, which services should receive initial standards, and how certification methodology, assessor qualifications and oversight, registry administration, standards updates and integration with federal and state examinations would work.

Bloomberg Law reported that the FDIC is working with major banking and FinTech trade groups and could provide seed funding. The Office of the Comptroller of the Currency (OCC) was also expected to join the effort.

The FDIC declined to comment, and no formal proposal, final governance structure or implementation timetable has been announced.

Initiative Follows Synapse Collapse

The proposal comes amid heightened scrutiny of banking-as-a-service arrangements and follows the 2024 collapse of Synapse Financial Technologies, which left consumers’ funds stranded.

It also revives an idea previously explored during the tenure of former FDIC Chair Jelena McWilliams.

If BISDO moves forward, its central test will be whether a voluntary certification program without legal protection can gain enough influence to reduce duplicative bank reviews while preserving banks’ responsibility for risk management, compliance and oversight of third-party providers.