How Will Third Party Risk Management Expectations Impact the Future of Banking as a Service?
What is Banking as a Service?
Banking as a service (“BaaS”) refers to a partnership where a licensed financial institution (“Bank”) provides their banking infrastructure to a third-party company (“Fintech”) to enable the Fintech to market its own products (“Fintech Projects”) while providing an additional platform through which the Bank can market its products (“Bank Products”).
The Bank benefits from the partnership by virtue of the expansion of the market to which its products are offered, and the Fintech benefits from the ability to utilize the Bank’s regulatory and technology systems without the need (or cost) of replicating such systems within the Fintech (“Bank/Fintech Partnership”). To be clear, a Bank/Fintech Partnership does not enable the Fintech to directly access the Bank’s internal systems. The most popular model for such arrangements entails the creation of an “application platform interface” or “API”. The API becomes the outward facing customer access point for the Fintech Product and will enable the customers to access the Bank Products through the same portal.
The Bank might also consider direct acquisition of the API and/or the company that developed the API, which might prove to be more profitable for the Bank in the long run. That said, direct acquisition might negatively impact the near-term expansion of the market to which the Bank products are marketed, also a profitability issue.
Impact of the Guidance with respect to the Third-Party Relationships on the Future of Bank/Fintech Partnerships
The Final Interagency Guidance on Third-Party Relationships published by the Board of Governors of the Federal Reserve System (the “Federal Reserve”), Federal Deposit Insurance Corporation (“FDIC”) and the Office of the Comptroller of the Currency (“OCC” and together with the Federal Reserve and the FDIC, collectively, “Regulators”) issued on June 6, 2023 (the “Guidance”) expressly provides that Bank/Fintech Partnerships are subject to the Guidance. However, instead of issuing definitive guidelines, the Guidance approaches the ultimate regulation of Bank/Fintech Partnerships from a “safety and soundness” perspective, effectively requiring that Banks apply the same level of scrutiny to third-party relationships that is currently applicable to the Bank itself. Insofar as third-party relationships directly pertain to critical activities[1], heightened due diligence and risk managements procedures are recommended.
In the context of “critical activities”, the Guidance emphasizes that the performance by the Fintech of its obligations must be subject to direct regulatory supervision and oversight by the applicable Regulators. While the Guidance does not specify the scope of regulatory supervision to be applied to the Fintech, direct regulatory oversight raises the question as to whether the Regulators’ endgame might be to seek legislative approval for direct supervision of Fintechs insofar as their services pertain to critical activities of Banks (“Critical Fintechs”).
Potential Impact of Direct Regulation to Current Fintech Operating Model
Direct Regulation raises a number of questions, such as (i) whether a Critical Fintech will have to comply with all cybersecurity laws and regulations that apply to Banks[2], and (ii) whether the Guidelines will apply to the Critical Fintech’s third party vendor management.
The Guidance also recommends the inclusion of certain provisions in the documentation between a Bank and the Critical Fintech, such as (i) the establishment of escrow agreements to provide for the Bank’s access to source code and programs and (ii) the right of the Bank to compel transfer of the Bank’s accounts, data, or activities to another third party without penalty in the event of the Critical Fintech’s bankruptcy, business failure, or business interruption.
What About Copyright and Licensing Protection?
The Guidance does not address the need of any Fintech to protect its software code and algorithms, mobile and web applications, and user interfaces. In the case of a Critical Fintech, will the Fintech’s rights with respect to its proprietary copyright, patent and trade secrets be limited? To the extent of any proposed limitations, do the Regulators have the legal authority to implement such limitations?
In the near term, the operating structure of Critical Fintechs will have to be modified to enable segregation of its proprietary information and technology with respect to a particular Bank client from the balance of its proprietary information, technology and “know how”, perhaps requiring the Critical Fintech to create an independent subsidiary to house the technology, software and other proprietary information pertaining to each Bank/Fintech Partnership, with the copyright-protected and other proprietary information and technology held in a separate operating subsidiary that sublicences that information and technology to each of its subsidiaries that enter into Bank/Fintech Partnerships. As noted above, the risk of potential regulation of the Fintech in the future (the scope of which is not yet clear) may make the Bank’s direct acquisition of the API and/or the company that developed the API a more workable solution in the context of the issues raised in the Guidance.
[1] “Critical activities” are deemed to include activities that could (i) cause a banking organization to face significant risk if the third party fails to meet expectations; (ii) have significant customer impacts; or (iii) have a significant impact on a banking organization’s financial condition or operations.
[2] New York Cybersecurity Requirements for Financial Services Companies , California Consumer Privacy Act of 2018 or the European Union’s General Data Protection Regulations.
