{beacon} Workweek Newsletter

3 news stories, 2 reading recommendations, & 1 question. ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌
Fintech Takes
Alex Johnson
Aug 10th, 2026
{cta_url_read_in_browser = community_base_url + "/library/" + article_id + "?utm_source=newsletter&utm_medium=email&utm_campaign=" + edition_slug + "&utm_content=read_in_browser"}{cta_url_read_in_app = community_base_url + "/library/" + article_id + "?utm_source=newsletter&utm_medium=email&utm_campaign=" + edition_slug + "&utm_content=read_in_app"}{cta_url_join_conversation = community_base_url + "/library/" + article_id + "?utm_source=newsletter&utm_medium=email&utm_campaign=" + edition_slug + "&utm_content=join_conversation" + "#comments"} {if profile.vars.member_status == "lead" || profile.vars.member_status == "unfit"} {else}{if profile.vars.member_status == "fit"} {else}{if profile.vars.member_status == "member"} {else} {/if}{/if}{/if}

In partnership with

Sponsor logo

Happy Monday, Fintech Takers!

I hope you had a productive weekend.

Mine was smokey, but that didn’t stop us.

My family and I cut down a 90-foot pine tree that was starting to rot and was uncomfortably close to my cabin. It was a challenging set of conditions, but, fortunately for me, no tree is too tall for Nate Johnson to climb and Tom Johnson is a steely-eyed chainsaw man.

See the image below for the before and after.

And read on for some fintech news and analysis!

- Alex

P.S. — Software companies embedding payments within their platforms are about to learn the same lessons that co-brand card issuers and retailers spent the last five decades learning. If you’re curious to understand what those lessons are (and how you might learn from them), please register for my upcoming virtual event!

Was this email forwarded to you?


Sponsored by Persona

Airport security treats every traveler roughly the same, whether they fly 50 times a year or once.

Most fintech verification flows follow a similar model: verify a user at onboarding, then rely on that decision long after the context has changed. 

Persona's Strategic Guide to Identity Verification explores a more adaptive approach.

Not every user or moment calls for the same screening.

Risk signals and context can tell you when verification should stay light and when it needs to escalate.

The guide breaks down which signals earn TSA PreCheck, and which verification methods fit which use case and warrant a second look.

Get the guide to build a verification strategy that applies the right scrutiny at the right moment, one that reduces fraud (not people).

Verification should adapt. Fraud already does.


You can just do things … especially if you do them with people who know what they’re doing and trust their instincts.

3 FINTECH NEWS STORIES

#1: Gates vs. Primitives

What happened?

Bank trade associations and fintech trade associations are working with regulators to define a common set of standards for managing the risks of bank-fintech partnerships:

The Federal Deposit Insurance Corp. is working with banking and financial technology trade associations to establish an independent standard-setting body that would help certify whether bank service providers meet federal regulatory guidelines.

The new organization would set baseline standards that would make it easier for banks to evaluate whether fintechs and other third-party service providers meet risk management standards and to onboard those firms to internal bank systems, according to a July 21 draft term sheet obtained exclusively by Bloomberg Law.

A uniform standard “would address these inefficiencies by standardizing and certifying common third-party risk management (TPRM) information that can be assessed once, refreshed over time, and reused by multiple banks, while preserving each bank’s responsibility for institution-specific risk assessment, contract decisions, integration, monitoring, and oversight,” the document said.

The standards would be voluntary, and banks and fintechs wouldn’t be punished for electing not to use them.

At the same time, contracting with a certified fintech wouldn’t give banks a safe harbor from supervisory scrutiny, the FDIC’s draft term sheet said.

And SOLO, a collaborative data-sharing network, is running a pilot — that is being observed by regulators — to enable banks to share customer verification data:

The SOLO Network today announced a FinCEN-observed bank reliance pilot in coordination with the U.S. Department of the Treasury, the Office of the Comptroller of the Currency (OCC), and the Federal Deposit Insurance Corporation (FDIC), demonstrating the first scalable framework for making trusted customer verification reusable across financial institutions.

The SOLO Network does not require institutions to standardize how they perform verification. Instead, it standardizes how completed verification is represented, evidenced, audited, and independently evaluated. Participating institutions generate standardized, auditable verification artifacts documenting the work performed, evidence reviewed, and standards applied, enabling trusted verification to become reusable across the network while allowing every receiving institution to independently determine whether it satisfies its own compliance and risk requirements.

So what?

I’m not going to go super deep into the details on the FDIC standards story that Evan Weinberger at Bloomberg Law originally broke. Jason Mikula — our permanently embedded reporter on BaaS Island (whether he wants the job or not!) — already did that.

Instead, I’d like to make a broader point, which connects the FDIC standards story with the SOLO pilot story.

The fundamental problem we’re trying to solve is that fintech companies have made the financial services ecosystem far more competitive than it used to be.

“What’s the problem with more competition?,” I hear you asking.

On a surface level, nothing. Competition is good. It leads to innovation and, ultimately, better products and pricing for customers.

However, one emergent property of a more competitive financial services ecosystem is the incentive for all participants to move faster and to take more risks in order to win, which can, if left unchecked, become a race to the bottom.

Bank regulatory supervision is not well suited to address this challenge. Our system is designed around the idea of a “regulatory perimeter.” Inside that perimeter are banks, which are directly and closely supervised by agencies like the Fed, OCC, and FDIC. Due to this constant supervision, the resting assumption is that the companies inside the perimeter are, comparatively, safe. Conversely, companies outside that perimeter are not under constant regulatory supervision, and are, therefore, considered, comparatively, unsafe.

Historically, the main way that companies inside the perimeter interacted with companies outside the perimeter was to engage their services as vendors. This model of bank/non-bank “partnership” was the dominant model for many decades and it is governed by a number of different laws, regulations, and processes — the Bank Service Company Act, Third-party Risk Management Guidance, etc. — all built around the assumption that risk always flowed from the outside in.

Those laws, regulations, and processes obviously didn’t work very well when they were applied to bank-fintech partnerships in the 2010s and (so far) in the 2020s, especially the banking-as-a-service model, which inverted the historical relationship and made banks, functionally, vendors to fintech companies.

This is why the FDIC is spearheading this initiative around standard setting, which is designed to reduce the amount of time and work that any one bank has to spend vetting new fintech partners. Instead, the idea would be to create a set of uniform standards that all fintech companies could be assessed against and a registry of all the fintech companies that are deemed to be "manageable" risks for banks to work with.

I see a few problems with this approach.

First, according to Evan’s and Jason’s reporting, regulators would not endorse any particular standard-setting or certification organization under this framework. Additionally, banks and fintech companies would not be required to adhere to these standards and inclusion in the registry of "manageable" service providers would not provide a bank that chose to work with one of them safe harbor in the event of a problem.

Second, fintech is a very big industry, and different categories of fintech companies present very different risks to banks, end customers, and the safety and soundness of the financial system overall. A BaaS middleware provider, a KYC vendor, a lead-gen affiliate, a core processor, and a lending-as-a-service platform share almost no risk surface. So the baseline standard either gets set generically enough to cover all of them — in which case it certifies nothing meaningful — or it fragments into dozens of domain-specific standards, and you've rebuilt the entire diligence problem inside the standard-setting body.

Third, and most importantly, even if the FDIC figures out how to define sufficiently specific standards and gives them real teeth, they still wouldn’t be solving the fundamental race-to-the-bottom problem.

A highly competitive marketplace encourages all market participants, inside and outside the regulatory perimeter, to move fast and to take risks. When you erect barriers to slow companies down and to stop them from taking risks, you aren’t solving for this incentive. It still exists. And unless you (the regulator) think that you can stop everyone working at every one of the tens of thousands of banks and fintech companies operating in the U.S. from doing something bad before they do it, you’re not going to be as successful as you want to be. They will just find a way around you and the bad thing you were trying to stop will happen anyway.

This is why I’m intrigued by what SOLO is doing. It’s both a complement to robust regulatory supervision and an acknowledgement of its limitations.

Both SOLO and the FDIC are trying to create standards to make risk and compliance data reusable. The difference is that the FDIC is trying to make judgments about firms reusable, which is inherently broad, subjective, and context dependent (hence the lack of any teeth in its effort). Standards only work when they are narrow, specific, and easy to document and audit. By applying standards not to banks’ and fintech companies’ customer verification methods, but to the outputs of those methods instead, SOLO is trying to sufficiently limit the scope so as to make collaboration across institutions achievable. 

Think of it less like a gate to collaboration (which is what the FDIC is doing, albeit a gate that can’t be locked or even closed) and more like a collaboration primitive; a building block that lowers the cost of following the safer path (rigorous due diligence) without trying to steer away from the incentive that all banks and fintech companies are still subject to — to move fast and take risks.

#2: Option Value

What happened?

Circle has named the founding validators for its upcoming payments-focused L1 blockchain:

BlackRock, the DTCC, Standard Chartered and Visa have signed on as founding validators for Circle's Arc open blockchain network ahead of a September launch for the public mainnet.

Galaxy, Global Payments, ICE, Mastercard, MoneyGram, SBI Group and Sumitomo Corporation are also lined up as validators, joining more than 100 ecosystem and institutional builders on Arc private mainnet.

Circle's Arc is one of several Layer-1 blockchain networks vying for supremacy on Wall Street, taking on the likes of Stripe's Tempo and Google Cloud's Universal Ledger.

So what?

My simplified explanation for why Stripe created Open Standard and the OUSD stablecoin is that it is trying to become Circle before Circle can become Stripe. The construction of Open Standard as a consortium owned by many members and controlled by none of them and the decision to pass almost all of the stablecoin yield to members rather than hoarding it appears to be specifically designed to fast-track the growth of OUSD, so that it can cut into USDC’s lead as the predominant regulated payment stablecoin, before USDC gets too far out ahead to catch.

James Wester and I talked through this theory in a lot more detail in this podcast episode, if you’re curious to dig deeper.

But, of course, this logic applies to Circle as well. Circle is, I believe, trying to become Stripe before Stripe can become it. And one of the things that Stripe already has is Tempo, a payments-optimized (i.e., more centralized) layer-1 blockchain.

Circle is building its own payments-focused L1 blockchain — Arc — and its validators (the institutions that run the network's consensus and confirm its transactions) are made up of many of the same companies that signed on as members of Open Standard, including Visa, Mastercard, Standard Chartered, and BlackRock.

This may strike you as odd (I thought Open Standard and Circle are competitors!) but it’s really not. OUSD isn’t real, yet. Arc isn’t quite real, yet (it officially launches on September 16th). These announcements — featuring big names like Visa and BlackRock — are designed to make them feel real, to make their success feel inevitable. But the reality for these companies is that their participation in Stripe’s and Circle’s various crypto payments initiatives — which also includes Visa and Standard Chartered acting as validators for Tempo — is, at this moment, entirely about cheap option value. The same thing happened with Libra in 2019. Visa and Mastercard (and Stripe) were members, until it became politically toxic.

Visa, Mastercard, BlackRock, and Standard Chartered don’t know if Circle will become Stripe before Stripe becomes Circle, or if Stripe will become Circle before Circle becomes Stripe, and they don’t need to know. They just need to purchase seats at both tables (which they can easily afford) and wait to see which one wins.

#3: Stablecoins + Gift Cards

What happened?

These words really shouldn’t be used together:

Seychelles-based crypto currency exchange KuCoin has rolled out a stablecoin gift card that enables businesses to distribute USDT and USDC globally for customer rewards, promotional campaigns and employee incentives.

Businesses can use KuCoin Gift Card to send crypto directly to customers, partners, employees and community members. Recipients can redeem the gift cards and receive the corresponding assets through the KuCoin exchange.

So what?

The reason those words don't belong together isn’t vibes (though I don’t like the vibes!). It’s mechanical, and it cuts against one of the best arguments the stablecoin industry has for itself.

You've heard that argument on every panel for three years: Cash is the money launderer's ideal instrument because it's a bearer asset that moves without leaving a record. Stablecoins are the inverse. Every transfer is written to a public ledger, permanently, and a compliant issuer can freeze a wallet in minutes. Criminals who use them are volunteering an evidence trail.

Now, in that context, consider what a gift card is.

It's a bearer instrument. Whoever holds the code holds the value, and the code can be handed to anyone, no questions asked.

So wrap a stablecoin in one. The stablecoin stops moving. It sits in a KuCoin-controlled wallet while the claim on it circulates the way anything digital circulates: Forwarded emails, screenshots, Telegram messages. The ledger records a mint and, eventually, a redemption. Everything in between is invisible to KuCoin, to Circle, to Tether, and to every regulator on earth. You've taken the most traceable dollar-denominated instrument ever built and bolted an untraceable transfer leg onto it. The gift card wrapper isn't incidental to the product. The wrapper is the product.

In fairness, there is one control here: Redemption runs through KuCoin, so whoever converts a code into spendable USDT has to clear KuCoin's KYC.

So, as long as we trust KuCoin, we should be good.

One problem: We shouldn’t trust KuCoin!

In January 2025, KuCoin's operator pleaded guilty to operating an unlicensed money transmitting business and agreed to pay more than $297 million. Per the DOJ, it failed to implement effective AML and KYC programs, failed to report suspicious transactions, and failed to register with FinCEN. Until at least July 2023 it didn't require customers to provide any identifying information at all, and employees repeatedly posted on public social media that KYC wasn't mandatory, including in replies to customers who'd said they were in the U.S. When KuCoin finally made KYC mandatory in August 2023, it still didn't apply it to existing users who only wanted to withdraw. This March, a CFTC consent order converted KuCoin's two-year U.S. exit into an indefinite bar.

So the only point in this architecture where a human being gets identified is redemption KYC, administered by a company with a criminal conviction for not administering redemption KYC.

Here's the part that should bother the policy people. When FinCEN exempted low-risk prepaid products in 2011, it named three capabilities that disqualify a product from the low-risk exemption: International use, person-to-person transfers, and reloading from a non-depository source. Any one is enough to blow the exemption. KuCoin's product has all three — global from day one, freely transferable, funded with stablecoins. And it's built for volume: bulk issuance with API integration, sold to businesses, so you can programmatically mint ten thousand bearer claims on dollars. KuCoin is functionally prohibited from operating in the U.S., so FinCEN’s exemption criteria are irrelevant in this case. But still, the design of the product points at exactly the risks that FinCEN and other regulators worry about.

If on-chain traceability is why stablecoins are safer than cash, then a bearer wrapper on a stablecoin isn't a feature, and the people who make the traceability argument for a living owe the rest of us an opinion about this one.


Sponsored by Gradient Labs

Lots of conversations about AI agents start at "should we?"

Kiah Haslett skips straight to the specifics on August 20th at 12:00 PM ET, joined by CTO of Gradient Labs (Dr. Neal Lathia) to explore where agentic AI is already working inside banks: KYC, disputes, collections, all drawn from deployments at Wise, Current, and Zego.

You'll leave The Back-Office AI Playbook: Where Banks Are Seeing Real Results with a concrete read on where your institution could begin.

So, what are you doing Thursday, August 20th at 12 PM ET?


2 READING RECOMMENDATIONS

#1: Sponsor Banks Doing It For Themselves (by Matthew Goldman, CardsFTW) 📚

A fun update from Matthew on sponsor banks bringing processing and program management in-house, which is a trend I had not spotted until I read this edition of his newsletter.

#2: The Future Of Distribution (In Lending) Seems Obvious (by Carlos Caro, The Free Toaster) 📚

This article (and this one and this one) provide a good foundation for anyone who is curious about the role that AI will have on distribution in consumer lending.

1 QUESTION FROM FINITY

There are a TON of interesting questions being asked in Finity (our digital community for fintech and banking nerds). I’ll share one question, sourced from the community, each week. However, if you’d like to join the conversation, please apply to join!

As stablecoins have become payments infrastructure, I’ve found myself writing about them (and the crypto industry, more broadly) more often than I used to. This is, to a degree, foreign territory for me, as I am more TradFi in my fintech heart of hearts than I am DeFi.
So, here’s my question: Are my occasional thoughts on crypto and stablecoins useful to you? Do they add something to the discourse that is missing? Or is there something missing from my coverage of stablecoins and crypto that you’d like to see me add in?
I’m happy to consider anything except NFTs.

If you have any thoughts on this question, reply to this email or DM me in Finity!

Thanks for the read! Let me know what you thought by replying back to this email.

— Alex

LinkedIn Twitter Instagram Podcast

@Alex Johnson

Unsubscribe
{if profile.vars.member_status == "member"}{/if}