Mapping the New Bank-Fintech Reality
As U.S. Regulators Tighten Their Focus on Bank-Fintech Partnerships, the Wolfsberg Group Provides a Timely Roadmap
Dr. Zoya Faynleyb, CAMS, CRCM, CAFP
Managing Principal, Arcsalus Advisors
William A. “Dru” Childress, CPA, CRCM
Founder & Managing Partner, Arcsalus Advisors
August 2026

Introduction

Over the past two years, bank-fintech partnerships have moved from being viewed primarily as an innovation opportunity to becoming one of the most closely scrutinized areas of financial services supervision.

The collapse of Synapse Financial Technologies in 2024 exposed significant operational and governance weaknesses in parts of the Banking-as-a-Service (BaaS) ecosystem. Hundreds of thousands of end users experienced disruptions accessing their funds, while the subsequent reconciliation process highlighted the complexity of for-benefit-of (FBO) account structures, third-party recordkeeping, and the challenges of determining beneficial ownership when multiple intermediaries are involved.

The regulatory response has been equally significant. In June 2024, the Federal Reserve issued an enforcement action against Evolve Bank & Trust, citing deficiencies in anti-money laundering, risk management, consumer compliance, and oversight of its fintech partnerships. The order specifically required the bank to strengthen governance, monitoring, recordkeeping, and oversight of its fintech relationships.

Since then, regulators across the federal banking agencies have continued emphasizing stronger third-party risk management, more robust governance over fintech partnerships, and greater

transparency into FBO account structures. The FDIC has also proposed enhanced recordkeeping requirements designed to ensure that banks maintaining custodial or FBO accounts through fintech partners can accurately identify each beneficial owner and balance, reflecting lessons learned from the Synapse failure.

Against this backdrop, the newly released Wolfsberg Group Guidance on the Provision of Banking Services to Non-Bank Payment Service Providers arrives at an important moment. Although the guidance is not a regulatory requirement, the Wolfsberg Group is an association of thirteen global banks whose publications have long represented leading industry practices and frequently influence supervisory expectations. The new guidance builds on the Group’s Payment Transparency Standards and incorporates the June 2025 updates to FATF Recommendation 16, which require complete originator and beneficiary information in cross-border wire transfers.

More importantly, the guidance reflects a broader shift in regulatory thinking.

Historically, banks focused their due diligence on understanding the legal entity they were onboarding. Today’s payment landscape requires something more sophisticated: understanding the entire ecosystem surrounding that customer – including underlying merchants, consumers, payment flows, nested PSP relationships, intermediaries, and the controls governing each stage of the payment lifecycle. The guidance emphasizes that financial institutions should apply a risk-based approach, understand each PSP’s business model and payment flows, and evaluate the effectiveness of the PSP’s own financial crime controls before and throughout the relationship.

What the U.S. agencies have addressed largely through recordkeeping and third-party risk management, Wolfsberg approaches from the payment chain itself – the nested, bundled, and cross-border flows where domestic guidance has the least to say. For U.S. banks and credit unions that provide banking services to fintech payment processors, merchant acquirers, money transmitters, and embedded finance providers, the Wolfsberg framework serves as both a practical playbook and a glimpse into where supervisory expectations are heading.


The Evolution of the PSP Relationship

Until recently, many financial institutions treated payment processors much like any other commercial customer. That approach is becoming increasingly difficult to justify.

Today’s fintech payment processors are far more complex than traditional commercial customers. Many aggregate thousands of underlying customers, route payments through multiple intermediaries, facilitate domestic and cross-border transactions, operate through BaaS models, leverage nested payment networks and downstream payment service providers, and introduce multiple layers between the originator and the ultimate beneficiary. These increasingly interconnected payment ecosystems can significantly reduce a bank’s visibility into the underlying transactions, making it more challenging to identify financial crime risks and underscoring the need for a deeper understanding of payment flows and the fintech’s own control environment.

As a result, banks frequently have limited visibility into the underlying payment activity occurring through their own accounts. The Wolfsberg Group identifies this reduced transparency as one of the defining risks of modern payment processor relationships.


Know the Payment Flow – Not Just the Customer

One of the most valuable concepts in the guidance is that understanding payment flows is just as important as understanding the legal entity.

The guidance differentiates among three primary payment flow types:

  • Proprietary payments made by the PSP for its own operations
  • Third-party payments processed on behalf of customers
  • Bundled or netted payments, where many transactions are aggregated into a single transfer

These distinctions matter because each creates a different financial crime risk profile.

Many-to-many bundled payment flows, for example, significantly reduce transparency for the sponsoring bank. KYC screening, sanctions filtering, and suspicious activity monitoring become more dependent on the PSP’s own controls rather than the bank’s visibility into individual transactions.

For U.S. compliance teams, this means account opening should include detailed mapping of how money actually moves – not simply documenting products and services.


Due Diligence Needs to Go Beyond Traditional KYC

The guidance makes clear that enhanced due diligence for payment processors should extend well beyond beneficial ownership, licensing, and corporate documentation.

Financial institutions should seek to understand:

  • Business models and customer segments
  • Payment corridors
  • Geographic exposure
  • Funding sources
  • Use of agents and downstream partners
  • Licensing across jurisdictions
  • Expected transaction flows
  • Growth strategy and expansion plans

Just as importantly, institutions should evaluate the maturity of the PSP’s own financial crime program, including governance, staffing, transaction monitoring, sanctions screening, fraud controls, audit results, and customer due diligence processes.

This represents a shift from “Know Your Customer” toward “Know Your Customer’s Control Environment.”


AI Is Now Part of the Compliance Conversation

One notable addition is Wolfsberg’s recognition that many payment processors now use artificial intelligence and machine learning within AML, sanctions, and fraud programs.

Rather than simply asking whether AI is used, banks should understand:

  • What decisions AI supports
  • How models are governed
  • Whether outputs are explainable
  • How effectiveness is independently validated
  • Whether sufficient human oversight exists

As fintech adoption of AI accelerates, evaluating AI governance will increasingly become part of third-party risk assessments rather than a niche technology review.


Ongoing Monitoring Is As Important As Onboarding

Perhaps the biggest takeaway is that onboarding is only the beginning.

Payment processors evolve rapidly. They launch products, expand internationally, add payment corridors, onboard new merchant segments, and enter partnerships with other PSPs – sometimes within months.

The guidance recommends ongoing due diligence triggered by events such as:

  • Ownership changes
  • New products
  • Licensing changes
  • Financial crime incidents
  • Significant transaction growth
  • New payment corridors
  • Material negative news

Banks should also perform periodic account activity reviews to identify unexpected changes in customer behavior, payment transparency, nesting arrangements, or exposure to higher-risk jurisdictions.

For many institutions, these expectations will require stronger collaboration among BSA/AML, payments, vendor management, compliance, fraud, and business relationship teams


What This Means for Community Banks and Credit Unions

Community financial institutions increasingly view fintech banking relationships as strategic growth opportunities.

The Wolfsberg guidance should not be interpreted as discouraging these relationships.

Instead, it provides a roadmap for how institutions can confidently support innovative payment companies while maintaining an appropriate risk appetite.

Institutions that invest in understanding payment flows, strengthening enhanced due diligence, evaluating PSP control environments, and implementing meaningful ongoing monitoring will be better positioned to compete in the growing embedded finance ecosystem.


Conclusion

The future of payments will continue to involve greater collaboration between banks and fintechs.

The institutions that succeed will not necessarily be those with the largest compliance departments – they will be those with the deepest understanding of how payments actually move through increasingly interconnected ecosystems.

The Wolfsberg guidance reinforces a simple but powerful principle:

Risk management for payment processors should focus not only on who your customer is, but also on how your customer’s customers move money.

As payment ecosystems become more complex, that distinction may become the defining factor between institutions that confidently grow their fintech banking business and those that struggle to manage the associated risks.

Arcsalus Advisors helps financial institutions build that understanding.

Read the full Wolfsberg Group guidance as published on July 15, 2026, here The Wolfsberg Group publishes Guidance on the provision of banking services to non-bank payment service providers (PSPs) – Wolfsberg Group.

Share the Post: