A draft framework linked to the Federal Deposit Insurance Corporation would create a voluntary certification system for fintech companies and other service providers used by banks. The proposal is designed to reduce repeated vendor reviews, especially for community banks, but it expressly does not remove a bank’s responsibility for safe operations, legal compliance or consumer protection.
Bloomberg Law first reported the initiative on August 5 after obtaining a July 21 draft term sheet. The document describes a proposed Banking Innovation Standards Development Organization, or BISDO, and a related certification program called Risk-Assessed, Manageable Partnerships, or RAMP. The FDIC declined to comment to Bloomberg Law, and the term sheet says it is subject to review and modification. This is therefore an early framework, not an adopted rule, operating certification registry or supervisory safe harbor.
The accountability question is whether reusable assurance can lower the cost of bank-fintech partnerships without turning a certification mark into a substitute for institution-specific scrutiny. The draft recognizes that tension. It would allow common controls and evidence to be assessed once and reused by multiple banks, while leaving each bank responsible for deciding whether a provider is suitable for its customers, systems and risk profile.
How the proposed certification model would work
Under the term sheet, BISDO could develop, adopt or recognize standards aligned with supervisory expectations for third-party risk management. RAMP would issue certifications, and independent qualified assessors would evaluate whether a provider or a particular product, platform, model or service conforms to the applicable standard. A registry would record certified providers, the scope of certification, assessment and renewal dates, limitations and status.
The framework contemplates several certification states, including active, conditional, suspended, withdrawn and expired. It also proposes periodic or event-driven monitoring, provider self-reporting of material incidents or control issues, and mechanisms for corrective action. Assessment depth would vary with factors such as service criticality, data sensitivity, solution complexity and customer impact.
That structure could make vendor evidence more comparable and reduce the burden of banks asking the same provider for similar questionnaires, audit reports and control documents. The draft says the benefit could be greatest for community banks that have fewer specialists and less negotiating leverage when reviewing complex technology providers.
The model would be voluntary. A provider’s absence from the registry would not be a blacklist, and banks could use uncertified providers after conducting their own risk-based review. Certification would also cover a defined scope rather than guarantee a company’s future performance or every service it offers.
Certification would not transfer responsibility
The most consequential language concerns supervisory reliance. The draft says federal and state examiners would accept a bank’s reliance on certification for due diligence related to the tested technology and would not take adverse action merely because a bank onboarded a certified provider. But the same document says certification is not an endorsement, approval, guarantee or safe harbor, and would not restrict regulators from examining or taking action against third parties.
Those provisions are not necessarily incompatible, but the boundary will matter. A standardized assessment can show that specified controls existed and were tested at a given time. It cannot determine whether a bank configured the product correctly, reconciled customer balances, monitored subcontractors, investigated complaints, planned for provider failure or understood how funds and data move through the full service chain.
The FDIC’s existing interagency guidance on third-party relationships already treats risk management as a continuing lifecycle. It covers planning, due diligence, contract negotiation, monitoring and termination rather than a one-time onboarding exercise. Any final certification model would need to fit that lifecycle and make clear which evidence banks may reuse and which judgments remain institution-specific.
Why vendor oversight has become an accountability issue
Bloomberg Law connected the proposal’s urgency to the 2024 collapse of banking-as-a-service intermediary Synapse Financial Technologies. The failure left customers unable to access funds and exposed disagreements among banks and technology providers over ledger records and account balances. Bloomberg reported that customer shortfalls were estimated at as much as roughly $90 million and that the Consumer Financial Protection Bureau later agreed to distribute $46 million from its civil penalty fund to affected consumers.
The proposed framework could improve visibility if certifications are narrowly scoped, renewed promptly and linked to incident reporting. It could also create false comfort if banks treat a registry entry as proof that a multi-party program is safe end to end. Payments programs often depend on several entities for account records, payment initiation, settlement, fraud controls, compliance and customer service. A provider-level assessment does not by itself verify the integrity of the combined arrangement.
For payments and compliance teams, the useful test is not simply whether a vendor is certified. Banks would still need to map responsibility for customer funds and records, verify daily reconciliations, identify critical subcontractors, test access and change controls, monitor complaints and exceptions, and maintain credible exit and continuity plans. They would also need to understand exactly which product version and control environment the certification covers.
Open questions before implementation
The draft leaves major governance and funding decisions unresolved. These include board composition, conflicts controls, the role of public-sector advisers, assessor independence, audit frequency, renewal cycles, appeals, registry transparency and the process for suspending certification. It also contemplates possible FDIC seed funding, according to Bloomberg Law, while longer-term dues and fees remain to be determined.
Industry participation is broad but still preliminary. Bloomberg Law reported collaboration involving the American Bankers Association, Independent Community Bankers of America, Bank Policy Institute, Financial Technology Association, American Fintech Council and Coalition for Financial Ecosystem Standards. The American Fintech Council confirmed that it was working with trade groups and regulators; several other organizations declined to comment or did not immediately respond.
A well-designed standard could make vendor assurance less repetitive and more current. The safeguard is to keep certification evidentiary rather than exculpatory: useful information for a bank’s decision, but not a transfer of accountability when customers, funds or payment operations are harmed.