Workweek Newsletter {beacon}

Five questions about the FDIC’s Standard-Setting Initiative ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌
Fintech Takes
Alex Johnson
Aug 14th, 2026
{cta_url_read_in_browser = community_base_url + "/library/" + article_id + "?utm_source=newsletter&utm_medium=email&utm_campaign=" + edition_slug + "&utm_content=read_in_browser"}{cta_url_read_in_app = community_base_url + "/library/" + article_id + "?utm_source=newsletter&utm_medium=email&utm_campaign=" + edition_slug + "&utm_content=read_in_app"}{cta_url_join_conversation = community_base_url + "/library/" + article_id + "?utm_source=newsletter&utm_medium=email&utm_campaign=" + edition_slug + "&utm_content=join_conversation" + "#comments"} {if profile.vars.member_status == "lead" || profile.vars.member_status == "unfit"} {else}{if profile.vars.member_status == "fit"} {else}{if profile.vars.member_status == "member"} {else} {/if}{/if}{/if}

In partnership with

Sponsor logo

Happy Friday, Fintech Takers!

I hope your week has gone well and you have fun plans for the weekend.

One of my readers replied to Wednesday’s newsletter with some additional and really wonderful history nerd trivia on time zones, meridians, and international dysfunction. I have added it into a new section at the bottom of today’s newsletter, if you’re interested.   

Also, separately, are you going to Money 20/20 this year? Do you enjoy playing basketball? Can you get there by Sunday morning? If you answered “yes” to each of these questions, you should fill out this form.

- Alex

Was this email forwarded to you?


Sponsored by C&R Software

What's the least digital part of your business? For most fintech companies, it's collections.

Onboarding got reimagined. Payments now happen instantly. Collections still runs on a call center script and a form letter; the one workflow nobody wants to redesign because it only shows up once something's gone wrong.

That's backwards.

A customer in hardship is paying closer attention to how you treat them than they ever did at signup.

Your app promised "we've got you." Collections is where they find out whether that was UX design or values.

C&R Software's Debt Manager pairs AI-native decisioning with human oversight, so the same care shows up in hardship and in good times.

Give collections the same rebuild everything else already got.


Voluntary, Non-Binding, and Full of (Contradictory) Promises

In Monday’s newsletter, I wrote about the news (first reported by Evan Weinberger at Bloomberg Law) that the FDIC is working with banking and fintech trade associations to establish an independent standard-setting body that would help certify whether third parties that work with banks (including legacy tech vendors and, obviously, fintech companies) meet federal regulatory guidelines.

My analysis on Monday focused on the challenges inherent in standard setting and the importance, particularly in financial services, of aiming at small, well-defined targets. Today, I want to turn my attention, more specifically, to what the FDIC and the banking and fintech trade associations are (reportedly) considering, and to share five questions that have been stuck in my brain all week. Today’s analysis is based on Evan’s reporting, particularly a draft term sheet for the new standards initiative, obtained exclusively by Bloomberg Law.

But before we get to my questions, a quick levelset on what is being proposed.

The draft term sheet, which is seven pages long and dated July 21, 2026, lays out how the FDIC and the industry trade groups — ABA, ICBA, BPI, FTA, and AFC (as well as CFES, which is an existing standard-setting body for bank-fintech partnerships) — propose to fix third-party risk management in banking. The core idea is straightforward: Right now, banks each run their own diligence on the same vendors and fintech partners, asking the same questions and demanding the same packages of documents. This is a lot of work for banks (especially community banks, which lack the resources of their larger peers) and a lot of repeat work for the vendors and fintech companies. Nobody thinks this is a good use of anyone's time.

The proposal is, essentially, to do the work once and let everybody use it.

The proposal splits that work across four different roles:

  1. The Banking Innovation Standards Development Organization (BISDO) — A voluntary nonprofit standards body that would write, adopt, or recognize standards for third-party risk management. It would also set the requirements for who's allowed to assess third parties using the standards.

  2. Qualified Assessors — Independent firms that would be accredited by BISDO and actually run the assessment engagements (questionnaires, evidence review, control testing, site visits where needed, etc.) They would produce attestation reports based on these assessments.

  3. Risk-Assessed, Manageable Partnerships (RAMP) — The certification program. RAMP would issue the certifications, using the assessor's report as its primary evidence.

  4. The Registry — The authoritative record of who's certified, for what scope, under which standard, with what status. The term sheet says that this recordkeeping function could be handed off to a separate administrator entirely.

Certification could cover a whole provider or a specific solution (a product, platform, model, or defined service scope). The contemplated reach is much broader than just bank-fintech partnerships or BaaS: Technology and non-technology third parties, legacy and novel, customer-facing and back office. A certification would signal that a third party met a defined baseline, and the document describes it as a "green light to consider," which the drafters think will be especially useful to community banks that can't afford to evaluate a multitude of different options.

Participation would be voluntary for banks and third parties alike. Not being certified is explicitly not supposed to count against you. Banks would remain fully responsible for their own risk decisions, contracts, monitoring, and compliance.

At this point, there’s no information on how the BISDO (god, that’s a really dumb-sounding acronym when I say it in my head) would be governed. In the term sheet, the section on governance says "See separate document," and that document isn't public. Board composition, the membership model, controls for conflicts of interest, and the funding model are all unknowns at this point.

And speaking of unknowns, here are five questions that I have after reading the term sheet multiple times.

#1: How safe is that harbor?

In regulation, the idea of a safe harbor is simple: It’s a promise. If you follow this process or procedure, the regulator can't come after you for it later. It's valuable precisely because it's binding. It’s meant to create a sense of certainty.

On the topic of safe harbors, the term sheet is, well, very uncertain.

Under the section titled “Core Operating Principles,” the document says that “RAMP certification, registry status, or use of a certification mark would not constitute an endorsement, recommendation, approval, guarantee, or safe harbor by any supervisory authority."

That’s very clear! No safe harbor!

However, if you scroll down a little further in the document, you come to a different section titled “Supervisory Considerations.” In that section, it says that federal and state examiners "will accept a bank's reliance on certification with respect to due diligence in onboarding a third party or adopting and integrating associated technologies," and the agencies "will not take adverse supervisory or enforcement action against a bank with respect to the onboarding of a third party that received certification."

I’m not a lawyer (very important disclosure!), but that sounds very safe harbor-ish to me.

So, which is it? Would a bank have a safe harbor — refuge from adverse supervisory or enforcement action — regarding certified third parties? Or not?

Interestingly, at the end of the document, it lists a number of open items and questions that still need to be resolved, and one of them is “no-safe-harbor language.”

Indeed! 

#2: Will this be guidance, a rule, or a statute?

In the world of policymaking, you essentially have three choices: guidance, rules, and statutes.

Guidance is a regulatory agency telling you what it thinks good practice looks like. It’s fast to issue (and fast to undo), and, critically, it’s non-binding. Banks don’t have to follow guidance from the banking regulatory agencies, and, in 2021, those agencies adopted joint final rules codifying that supervisory guidance does not have the force and effect of law and cannot be used as the basis for formal enforcement actions.

Rules are different. They are legally binding and are used as the basis for enforcement actions. However, Congress must pass an enabling statute that empowers a regulatory agency to write and enforce rules and any rules must go through a drafting process outlined in the Administrative Procedure Act, which requires regulators to share their proposed rules with the public and provide the opportunity for the public to comment on them. This is a slow process and it must be repeated any time an agency wants to make a meaningful change to a rule. Additionally, rules can “incorporate by reference” the work of non-government organizations (such as standard-setting bodies), but there are limitations on this.

Statutes are laws passed by Congress. They are what enable and empower regulators to write rules and they can also empower non-government organizations (like private market self-regulatory organizations) to participate in the regulatory process directly.

It’s unclear, at present, which of these mechanisms the FDIC is planning to utilize to advance this standard-setting initiative. Each comes with its own challenges.

If the commitment lives in guidance, why would a bank rely on it? That same 2021 rule cuts both ways. Guidance can't bind banks, and it can't bind the agencies either. A promise not to enforce that's issued as guidance is worth exactly as much as any other guidance: Nothing, if the next chairman of the FDIC disagrees with it.

If it's a rule, which version of the standards goes in it? Rules can point to an outside organization's standards, but the agency has to name the specific edition. It can't say "whatever BISDO publishes going forward," because that would let a private group change the law without notice or public comment. So a rule would lock the standards at v1.0, while the term sheet's whole pitch is that certifications get "kept current." Does the FDIC rerun the rulemaking process every time BISDO revises a control?

If an act of Congress is the endgame, an obvious comparison is FedRAMP, which does for federal agencies buying cloud software what RAMP would do for banks buying fintech: Certify a vendor once, let every agency reuse it. FedRAMP operated through OMB guidance for eleven years before Congress finally wrote it into law in 2022. But what Congress codified was a government program, staffed inside the General Services Administration, not a non-government standard-setting body.

Given that Evan’s reporting stated that the FDIC is trying to move fast on this, and that it and other federal banking regulators are expected to release new third-party risk management guidance in the coming weeks, I would guess that guidance will be the tool that the FDIC and the other agencies will rely on, at least in the short term.

#3: Who pays?

In any certification scheme, an important question is who pays the person doing the grading. There are three basic models:

  1. The company being graded pays. The third party seeking certification hires the assessor and signs the check. This is the easiest model to stand up, because the cost sits with the party that wants the certificate. It's also the model that gave us the credit rating agencies, where the company being rated both chooses its rater and pays it. As we learned in 2008, that model can be dangerous.

  2. The user pays. The banks relying on the certification foot the bill. This model has better incentives because the people paying want an accurate answer rather than a flattering one. However, it is harder to make work commercially at scale.

  3. The government pays. Taxpayer or agency funded, like FedRAMP. This model removes the conflict, but puts the agency on the hook for the result.

The term sheet appears to pick the first one, though it never quite says so. In the list of benefits to third parties, it states that the framework would "allow assessment costs to be spread across multiple client institutions." That only makes sense if the third party is paying up front and recovering the cost from the banks that use its certification.

If this is the model — the third party picks and pays its own assessor — what stops it from shopping for the friendliest one? The term sheet says assessor qualifications may include "independence safeguards" and "conflict-of-interest controls," which is the right instinct, but not a complete answer. It doesn't say whether the third party chooses its assessor, whether it can switch mid-engagement, or whether a firm can sell remediation consulting to a company it just graded.

With regard to how the standards body itself is funded, Evan reported that the FDIC is expected to provide seed funding, though that’s obviously not a long-term solution. The term sheet mentions a few different potential sources of sustainable funding (BISDO member dues, fees related to qualified assessors, etc.), but leaves the question open.

#4: Did the FDIC invite anyone else to this party?

The term sheet doesn't say "FDIC." Not once. It refers to “federal banking agencies,” which includes the FDIC, the OCC, and the Federal Reserve.

This matters because interagency work in banking regulation has a normal cadence. Guidance is drafted jointly, cleared by each agency's leadership, and published simultaneously with every agency's name on the front. The 2023 third-party risk management guidance — issued jointly by the FDIC, OCC, and Federal Reserve — was published that way. As was the 2021 rule on supervisory guidance.

Obviously, this standards initiative could still turn into official interagency guidance. We’re very early in the process. Nothing official has been announced or released yet. The term sheet — which, to be clear, was leaked to Bloomberg Law — could change significantly. And, as Evan reported, new interagency guidance on third-party risk management is in the works, and the OCC is, reportedly, expected to get involved in this standard setting initiative soon.

That said, I’m guessing the Bloomberg Law story caught the other federal banking regulators by surprise. Hell, I’m guessing there are some folks at the FDIC who weren't read in on this initiative and were caught by surprise too. FDIC leadership seems to be moving fast on this, which is, in some ways, encouraging. However, it is also potentially a sign that they’ve already gotten a bit far out over their skis.

The reason I say this is because the term sheet doesn't stop at federal agencies. It says "federal banking agencies and state agency examiners will accept a bank's reliance on certification," and “will not take adverse supervisory or enforcement action against a bank with respect to the onboarding of a third party that received certification under BISDO/RAMP.”

The FDIC cannot make those promises on behalf of the states.

There are more than fifty state banking departments, each with its own enabling statutes, its own commissioner, and its own examiners. Nothing in the reporting I’ve seen suggests any of them have been consulted so far. This isn't a technicality when it comes to this particular problem, either. The bank-fintech partnership business runs overwhelmingly through state-chartered banks, where the FDIC is the federal supervisor and a state department is the chartering authority. Two examiners show up at those banks. Under this term sheet, one of them has made commitments and the other has been volunteered.

My guess is this ends up being one of the constraints that matters most, and not for legal reasons. The federal agencies can sort out their differences internally, on their own timeline. Fifty-plus state regulators who learned about their own commitments from a leaked term sheet are a different kind of problem, and they hold the charters of the banks this framework is built around.

#5: If a certified third party blows up, who eats it?

Seven pages, and not one word about liability. No indemnification, no insurance requirement, no allocation of responsibility among BISDO, RAMP, the assessors, and the third party. It isn't in the body of the document and it isn't in the list of open decisions at the end of the document either, which is the more telling omission. The folks who wrote the term sheet (and this thing really feels like it had multiple authors) catalogued what they knew they hadn't figured out yet, and liability didn't even make the list.

That's a strange gap for a framework whose entire purpose is convincing banks to rely on somebody else's work. Reliance is what creates lawsuits.

Existing assurance regimes have addressed this, and their solutions are instructive. SOC 2 reports come with explicit restricted-use language limiting who's entitled to rely on them, and the accounting firms that issue them carry errors-and-omissions insurance coverage. Banks know this, which is why they read a SOC 2 as one input rather than the definitive answer. The pricing of that risk is baked into how the document gets used.

So the question that decides what a RAMP certification is actually worth is whether banks are permitted to rely on it in a legally meaningful way. If certifications are issued on a restricted-use basis — good between the third party and RAMP and nobody else — then a bank that relied on one and got burned has no claim against anyone. If they do permit third-party reliance, no serious assessor will sign up without a liability cap, and whatever that cap turns out to be becomes the ceiling on what the certification is worth.

Which loops back to something the term sheet says repeatedly and emphatically: Banks remain responsible for safe and sound operation, compliance with applicable law, consumer protection, ongoing monitoring, and oversight. That's the correct answer legally. It also means the bank absorbs the same loss it absorbs today. And if that's true, the real question is what benefit is the certification really providing?


Payments People, This Is for You

Revenue from embedded payments climbs in a straight line. The risk doesn't.

Ron Griswold (WEX) has watched it happen the same way almost every time. Things feel manageable, manageable, manageable — and then the complexity shows up all at once, with no warning that it was coming.

On August 19th, we get into where that spike tends to hit, and why almost nobody sees it early enough.


MORE QUESTIONS TO PONDER TOGETHER

Big news for the endlessly curious (yes, you): I’m collecting your fintech questions on a rolling basis. 

What’s keeping you up at night? What great mysteries in financial services beg to be unraveled? Think of it this way, if a stranger is a friend you just haven't met yet, your question is a Fintech Takes conversation waiting to happen. 

One that could headline a Friday newsletter or be answered in an upcoming Fintech Office Hours event.

Drop your question here, whenever inspiration strikes!


WHERE I'LL BE

✈️ FinovateFall | September 9-11 | New York City

My can't miss fall conference! September in New York is glorious and the fintech conversations will be too.

✈️ Cash Flow Intelligence Summit | September 10 | New York City

Nova Credit has rebranded this from the "Cash Flow Underwriting Summit" to the "Cash Flow Intelligence Summit." Come find out why.

✈️ FDATA Global Open Finance Summit | September 17 | Toronto

This will be my first time at an FDATA event and my first time back to Toronto in a long time. If you work in open banking in Canada and want to yell at me for my bad takes in the past, this is your chance!

✈️ AI-Native Banking & Fintech Conference | September 29 | Salt Lake City

The name of this event is a mouthful, but the content and networking are both A+.Event's name | Month, Day | Where

💻 Bonus: The Back-Office AI Playbook: Where Banks Are Seeing Real Results (Fintech Takes Banking x Gradient Labs AI) | August 20 | Virtual*

Most banks have a KYC backlog, a disputes queue, and a collections team stretched thin. Kiah Haslett sits down with Gradient Labs' CTO, Dr. Neal Lathia, to break down how agentic AI is already clearing that work at Wise, Current, and Zego, and what it took to get there. August 20th, 12 PM ET. Register to save your spot.

*This rec is brought to you by one of our fantastic brand partners.


Thanks for the read! Let me know what you thought by replying back to this email.

— Alex

LinkedIn Twitter Instagram Podcast

@Alex Johnson

Unsubscribe