Knowledge and Insights
Banking on Fintech: Key Considerations for Banking as a Service (BaaS) in 2026
By: IsabelOver the last several years, technological advancements have continued to transform our lives, changing the way consumers and businesses engage with financial services. Today, individuals rely on a wide range of applications to manage everyday transactions, including sending money instantly, purchasing goods through digital marketplaces, funding digital wallets, and accessing credit through online platforms, with the expectation that these services are seamless, immediate and always available. Behind the scenes, however, the infrastructure supporting these activities has become increasingly complex, requiring robust systems, controls and regulatory oversight to facilitate the safe and secure movement of funds.
As adoption accelerates and balances held in digital wallets continue to grow, it is more important than ever for financial institutions to maintain strong governance and risk management practices.
PARTNERING WITH FINTECHS
Many of the applications driving this digital transformation are developed by fintech companies, which are not U.S. chartered banks. In order to offer financial services, these fintechs must partner with a chartered financial institution. These partnerships provide access to critical banking infrastructure, including payment rails and the ability to hold customer funds.
From a bank’s perspective, these arrangements are known as Banking as a Service (BaaS), as the institution is effectively extending its charter to enable the fintech’s operations. While the fintech delivers the customer experience, the bank retains responsibility for ensuring that all activities are conducted in a safe, sound and compliant manner.
BaaS continues to present a meaningful growth opportunity for financial institutions, particularly as demand for embedded finance and digital-first solutions increases. As these partnerships expand in volume and complexity, it becomes increasingly important for banks to maintain a thorough understanding of the fintech’s business model, processes and risk profile.
RISKS TO LOOK OUT FOR
Consumers expect transactions to be processed in real time, and many BaaS arrangements rely on real-time payment platforms to meet these expectations. These technologies allow funds to move instantly between accounts, reducing friction but also limiting the time available to detect and prevent fraud. As a result, both banks and fintech partners must implement monitoring capabilities that can identify suspicious activity as it occurs. In addition to fraud risk, institutions must consider other critical areas such as identity verification, data protection and the integrity of customer onboarding processes.
Ongoing monitoring is equally important. Institutions should be prepared to address customer complaints, investigate unusual activity, and monitor and evaluate whether controls remain effective as transaction volumes scale. The rapid growth of digital platforms has also increased the volume of sensitive data being exchanged, making cybersecurity and data governance key priorities. Ultimately, banks must view fintech partners as an extension of their own operations, as this approach is essential not only for mitigating risk, but also for demonstrating to regulators that the institution maintains full oversight of activities conducted under its charter.
EVOLVING REGULATORY EXPECTATIONS
Regulatory agencies continue to increase their focus on third-party risk management and data governance within BaaS arrangements. One notable area of development is consumer financial data rights, which are shaping how institutions and fintechs collect, share and protect customer information. As regulations evolve, financial institutions are expected to demonstrate clear ownership of compliance responsibilities, even when activities are carried out by third-party partners. This includes maintaining effective BSA/AML, consumer protection and reporting programs.
Given the pace of change, banks offering BaaS should closely monitor regulatory developments and be prepared to adapt their programs to meet new expectations. Staying ahead of these changes will be critical to avoiding disruption and maintaining compliance.
EFFECTIVELY MANAGE RISK & MAINTAIN COMPLIANCE
No matter where your institution is in its BaaS journey, whether evaluating new opportunities or managing an established program, it is essential to take a proactive and disciplined approach to risk management. This includes conducting thorough due diligence, maintaining open lines of communication with fintech partners and implementing strong monitoring and control processes.
At Mercadien, our Financial Institutions Services Group works with banks and credit unions across the country to help navigate these challenges. Our professionals bring deep experience in BSA/AML, consumer compliance and risk management and can assist with developing programs, performing independent reviews and strengthening overall governance frameworks.
By taking a structured approach and maintaining strong oversight, financial institutions can confidently pursue BaaS opportunities while protecting their organization and meeting regulatory expectations.
DISCLAIMER: This advisory resource is for general information purposes only. It does not constitute business or tax advice and may not be used or relied upon as a substitute for business or tax advice regarding a specific issue or problem. Advice should be obtained from a qualified accountant, tax practitioner or attorney licensed to practice in the jurisdiction where that advice is sought.


