| |||||||||
| |||||||||
| | |||||||||
Happy Wednesday, Fintech Listeners! I’m in New York for FinovateFall and the Cash Flow Intelligence Summit. The weather is glorious. Fintech friend reunions have already commenced. And there is plenty of fintech news, already, to talk about! I’ll give you a full readout of the week in Friday’s newsletter. Today, I’ve got something good for your ears. A conversation that I’ve been wanting to have for a while. — Alex P.S. The conventional wisdom in fintech is that friction is always a bad thing, but I don't think that's true. In lending, you're not just trying to convert more applicants. You're trying to curate the best possible portfolio of customers. And in a world where low friction is the default (which, in 2026, it is), less friction doesn't automatically get you there. That's what we're digging into on September 30th. Join us? Was this email forwarded to you? Sponsored by WEX Every embedded payments roadmap drafted this quarter is a bet on what B2B buyers will expect in 2027. Some of those bets will look prescient; others will look expensive. 3 BIG IDEAS FROM THE PODCAST ![]() This week's episode of the Fintech Takes podcast brought together my two favorite Jasons — Jason Mikula (of Fintech Business Weekly) and Jason Henrichs (of Alloy Labs and Breaking Banks). The Jasons joins me again to pick apart a proposal that's been circulating since August; a new FDIC-backed standard-setting body for third-party risk management. The proposed name for it, BISDO, doesn’t do much for me, but this episode that orbits around the value and limitations of industry standards sure did! Tune in for the full conversation here And read below for my three big ideas... #1: Close Encounters of the Unknown KindThe premise behind the FDIC’s standards effort is hard to argue with. Banks, especially community banks, can spend enormous amounts of time reviewing the same third-party providers, asking many of the same questions, and redoing much of the same due diligence from scratch. If some of that work could be assessed once, refreshed over time and reused, you could make bank-fintech partnerships easier without making them riskier. That’s the theory, anyway. The trouble starts one layer down, with a deceptively simple question: What exactly are we standardizing? Because “third party” sounds like a category, but in financial services, it really isn’t. Which brings us, regrettably but necessarily, to the acronyms. The FDIC draft would create BISDO, a standard-setting body, and RAMP, short for Risk-Assessed Manageable Partnerships, which would certify providers or individual solutions against those standards. The architecture makes sense, but the category is where things get slippery. Mikula traces that slipperiness back to the old bank technology world, when “third party” largely meant FIS, Fiserv, Jack Henry, and a handful of others. This pre-fintech state was relatively easy for regulators to wrap their arms around, though far less delightful for the banks buying technology. Henrichs remembers opening his first core contract in 2006 and finding language that essentially said if the vendor offered a service – or substantially the same service – he’d have to buy it from them. His reaction was basically, what kind of idiot would sign this? But that was before he saw the same language in the FIS and Jack Henry contracts too. Fintech helped break that world open. As a result, banks got more choices, but the universe of “third parties” expanded and diversified tremendously. Fiserv is one kind of partner; a new deposit opening provider like MANTL is another. Fintech programs looking for sponsor banks are something else entirely (and when it comes to BaaS, Alloy Labs identified six distinct archetypes, each with different inherent risks). So, the first problem with standardizing third-party diligence isn’t diligence. It’s deciding what third party is doing what, and with what kind of risk. #2: Without Teeth, How Useful Will This Be?The FDIC's draft proposal would build a four-part system. A standard-setting body, tentatively named BISDO, would define what good third-party risk management looks like. Independent assessors would evaluate individual vendors or fintech programs against those standards. A certification, Risk-Assessed Manageable Partnerships (RAMP), would be issued based on those assessments. And a registry would track whether any given RAMP certification is active, suspended, or withdrawn, with an emergency circuit breaker built in to pull one quickly if something goes wrong. While the draft term sheet is a bit contradictory on this point (read this for more details), my understanding is that use of the standards would be voluntary and a bank that picked a fully RAMP-certified vendor would get no formal protection (and no reduced exam scrutiny, no defense a regulator is bound to honor), simply because that vendor holds the credential. To be overly cynical, there's a possibility here that the independent assessors doing the certifying (and getting paid to do it), are the ones who stand to benefit the most, while no other party would really save that much time or reduce risk all that much. Without a safe harbor, earning RAMP certification doesn't change what a bank owes a regulator if something goes wrong. A standard only changes behavior if following it changes outcomes for the people adhering to it. #3: How Do You Disseminate Novel Knowledge and Experiences?A standard is supposed to make examiners' jobs easier by offering them a shared bar to check every fintech program against (instead of relying on individual judgment every time). Henrichs offered a specific reason that assumption breaks down in practice, one that has nothing to do with the standard itself and everything to do with individual examiners. An examiner who doesn't understand BaaS, or AI, or whatever the novel activity happens to be, isn't doing anything wrong by asking more questions. But inside the bank, an examiner asking questions is never neutral. Chief Compliance Officers and Chief Risk Officers, in Henrich’s framing, don't like answering questions. Lots of questions start to read as danger, whether or not the questions being asked are actually good ones (after all, the examiner may just be trying to learn). Someone working in compliance may see the volume of scrutiny and assume regulators must be worried about something specific, even when they aren't. As a bank answers those questions and documents everything, they may think, I don't know what the answer to this thing is, but they're asking a lot of questions, and that sure feels dangerous. I'm shutting this down. When there’s a longstanding relationship between the bank and its regulator, the bank can surface what it’s doing proactively, and the regulator has enough familiarity to respond intelligently. However, when there's high turnover in who's assigned to the exam, or when the examiner simply lacks the requisite background knowledge, things break down. For novel activities, Henrichs talked about the idea of a dedicated group that works across the country and, ideally, across the FDIC, OCC, and Fed, with something like a red phone that banks can use to chat through an unfamiliar activity in advance. But the catch is that this exact thing existed under the last administration and, from the conversations I’ve had with bankers, they didn’t work all that well. These novel activities groups centralized expertise, but that expertise never filtered back down to the regional offices that were responsible for conducting the exams. Put another way, it doesn't matter how much expertise the FDIC, OCC, or Fed have on staff somewhere if the people actually conducting the exam (who the banks have relationships with) aren’t the ones who have it. A dedicated group with real knowledge does nothing for a bank if that bank never talks to that group, and instead deals with a field examiner who doesn’t understand the acronyms that are being thrown their way. Sponsored by Brico Bank charters are having a moment. WHAT I'M LISTENING TO #1: Why Money Launderers Love $100 Bills (Odd Lots) 🎧I wish I had the time to learn way more about money laundering. Not because I want to do it, to be clear. It’s just a fascinating (and often surprisingly relatable) world, as this episode demonstrates. #2: Movies The Worst Guy You Know Says Are His Favorite (Organizing Things) 🎧When Shea Serrano and Jason Concepcion start a new podcast, I will listen to it and (most likely) recommend it. That’s what’s happening now. (Also, if you don’t read Shea’s newsletter GOOD MOVIE, you are missing out.) Thanks for the read! Let me know what you thought by replying back to this email. — Alex | |||||||||
|
