top of page
Men in Suits

Embedded Finance Partnerships: Governance Risks When Non-Banks Offer Banking

In April 2024, more than 100,000 people woke up to find their money gone. Not stolen, exactly. Frozen. Roughly $265 million sat somewhere between a fintech app, a piece of middleware called Synapse, and four different banks — and for weeks, nobody could say with certainty whose ledger was actually correct. People borrowed money for groceries. Some delayed surgeries. A few pushed back weddings. None of them had done anything wrong. They’d simply trusted an app that looked and felt exactly like a bank.

That’s the uncomfortable truth sitting underneath embedded finance: the product can look flawless right up until the one thing nobody was clearly accountable for finally breaks.


Executive Summary

Embedded finance is what happens when a non-bank company — a retailer, a payroll platform, a budgeting app — offers banking products like cards, accounts, or lending, using a licensed, FDIC-insured bank operating quietly behind the brand the customer actually sees. The products work fine most of the time. The governance question is what happens when they don’t, and right now, regulators are answering that question with real enforcement, not just guidance. More than a quarter of the FDIC’s formal enforcement actions in the recent period targeted sponsor banks specifically. The UK’s FCA fined a Banking-as-a-Service provider £21.1 million in 2025 over financial crime control failures. The Basel Committee has moved to extend its traditional third-party outsourcing principles to cover exactly this kind of layered arrangement. None of this is theoretical anymore, and none of it is shrinking — the embedded finance market itself is running around $150 billion in 2026, with projections pushing toward $450 billion by the early 2030s. Boards overseeing companies in this space need to treat the full service chain as something they govern directly, not something a partnership contract quietly handles on their behalf.


Embedded finance governance showing a non-bank fintech, middleware platform, and sponsor bank working together with board oversight and risk management.

Quick Answers

What is Embedded Finance Governance?

It’s when a non-bank company offers banking-like products — debit cards, deposit accounts, lending, payments — under its own brand, while a licensed bank sits behind the scenes actually holding the money and carrying the regulatory charter. The customer usually never sees the bank’s name at all.


What’s the difference between embedded finance and a company simply “being a bank”?

 A bank holds a charter, carries deposit insurance directly, and answers to banking regulators as the primary entity. An embedded finance company holds none of that itself — it’s relying entirely on a sponsor bank’s charter and infrastructure, often through a middleware provider sitting in between the two.


Who’s actually accountable when an embedded finance product fails?

That’s precisely the question the industry hasn’t answered cleanly, and it’s the core governance risk. In principle, the sponsor bank carries ultimate regulatory responsibility. In practice, when ledgers between the fintech, the middleware provider, and the bank don’t match, accountability gets genuinely murky — which is exactly what happened with Synapse.


What happened with Synapse, and why does it matter?

 Synapse was a middleware company connecting fintech apps to FDIC-insured partner banks. When it collapsed into bankruptcy in April 2024, its internal ledgers didn’t match what its four partner banks actually held, leaving more than 100,000 customers locked out of $265 million for months. It’s become the defining case study in why embedded finance needs real governance, not just a partnership agreement.


Why “We’re Not a Bank” Doesn’t Mean “We Have No Responsibility”

Every embedded finance product rests on roughly the same three-layer stack, whatever the front-end branding looks like. At the bottom sits the sponsor bank — chartered, FDIC-insured, the entity actually authorised to hold deposits. In the middle sits an orchestration or middleware layer, handling ledgering, account management, and often the technical connective tissue between the bank and the brand. At the top sits the consumer-facing company — the app, the card, the brand the customer actually trusts.


The historical fault line runs straight through that middle layer. When an orchestration provider sits between the bank and the brand without airtight, continuously reconciled ledgering, accountability blurs. And blurred accountability, it turns out, is precisely what regulators — and eventually depositors — end up paying for.


Synapse is the clearest illustration available. It functioned as the bridge connecting fintech platforms like Yotta, Mercury, and several others to FDIC-insured partner banks, without taking deposits directly itself. When internal disputes escalated — one partner bank demanding a $50 million reserve, a major fintech client abruptly pulling its deposits, a proposed rescue acquisition falling through — the whole structure unravelled fast. By the time Synapse filed for Chapter 11 bankruptcy in April 2024, its four partner banks discovered they genuinely could not reconcile what their own records showed against what Synapse’s ledgers claimed customers were owed. A court-appointed trustee later estimated the shortfall at somewhere between $65 million and $95 million. Some customers went without any resolution for months.


This matters far beyond one company’s failure. The embedded finance market isn’t a fringe experiment shrinking under regulatory pressure — it’s expanding rapidly, commonly estimated near $150 billion in 2026 and heading toward $450 billion within the next decade at a compound growth rate near 20 to 25 percent. A governance gap at this scale, left unaddressed, doesn’t stay small.


What Real Oversight Actually Looks Like

The board-level test here is refreshingly simple to state, even though answering it honestly is harder than most companies expect. Can management explain how the product actually works, where exactly it earns money, how it can fail, and precisely how customers get protected if a partner in the chain can’t perform? If any part of that answer depends on an untested contract clause, or simply on trusting the partner’s brand reputation, the operating model isn’t actually ready to scale — no matter how polished the customer-facing product looks.


That test needs to replace the older, weaker standard many boards have quietly relied on: did the partner pass due diligence when the relationship started. Due diligence at onboarding tells you almost nothing about whether a partnership is being actively, continuously governed two or three years later, after the original team that signed the contract has moved on and the relationship has scaled well past what anyone originally modelled.


A Framework for Governing the Full Service Chain

A handful of concrete practices separate companies actually governing this risk from companies simply hoping a partner handles it.


Map the full customer promise, not just the contract.

 Embedded finance governance should start from what the customer is actually promised — “receive a card,” “hold funds,” “make a transfer,” “resolve a complaint” — and then trace every activity required to deliver on that promise: onboarding, disclosures, authentication, decisioning, ledger posting, fraud and sanctions controls, settlement, statements, complaints, refunds, and account closure. A conventional vendor inventory starts with a company name and a signed agreement. Embedded finance governance has to start with the customer’s actual experience and work backward from there.


Treat reconciliation as a standing board-level metric.

 Whether internal ledgers match what the sponsor bank actually holds shouldn’t be something discovered during a crisis or an annual audit. It needs to be monitored continuously, with clear escalation triggers, precisely because the Synapse collapse showed how quickly a small, unreconciled gap can compound into something unrecoverable once multiple parties stop trusting each other’s numbers.


Assign compliance ownership explicitly, with no reliance gaps.

 Under regulations like the EU’s Anti-Money Laundering Regulation, BaaS providers are expected to maintain clear allocation of anti-money-laundering roles, full access to customer and transaction data, and genuine oversight and testing of fintech partners — not a vague assumption that “someone in the chain” is handling it.


Track the regulatory landscape actively, because it’s moving fast.

 The Basel Committee’s current third-party risk principles have explicitly extended traditional outsourcing concepts to cover a much wider range of arrangements. The FDIC’s proposed “Synapse rule” would require banks to maintain accurate recordkeeping of beneficial owners in custodial accounts. None of this is settled law yet — it’s actively evolving, which means a governance framework built once and left alone will be behind within a year or two.


A Real-World Example

The aftermath of Synapse’s collapse offers a genuinely instructive, if sobering, picture of what happens when governance fails at scale. Evolve Bank & Trust, one of Synapse’s four partner banks, was issued a cease-and-desist order by the Federal Reserve roughly two months after the bankruptcy filing, stemming from a supervisory review that had actually begun earlier. Lineage Bank, another partner, received a consent order from the FDIC. Regulators, meanwhile, acknowledged a genuine structural problem: banking-as-a-service arrangements had grown complex enough that oversight responsibility for the nonbank participants in the chain was never clearly assigned to anyone in the first place. The FDIC’s proposed response — tighter custodial recordkeeping requirements — exists specifically because this kind of gap needs a regulatory fix, not just better intentions from the companies involved.


FAQs

Is my money actually FDIC-insured in an embedded finance product?


Often yes, in principle, because the underlying funds typically sit at an FDIC-insured sponsor bank. But as Synapse demonstrated, insurance protects against bank failure specifically — it doesn’t automatically protect against a middleware provider’s ledgers failing to accurately reflect who owns what, which is a different kind of failure entirely.

Primarily the sponsor bank, since it holds the actual charter and deposit insurance. But regulatory attention to the nonbank participants in the chain has increased sharply since 2024, and expanded third-party risk principles from bodies like the Basel Committee are pushing toward broader, more direct oversight of the entire arrangement.

Any answer to “how do we know our ledgers match what the bank actually holds” that isn’t backed by continuous, verifiable reconciliation. If that answer relies on trust in a partner rather than an active, monitored process, that’s the exact gap that took down Synapse.

Both. Some of the most recognisable consumer banking apps in the country — names most people would assume are simply banks — actually operate through partnerships rather than owning a charter themselves. Scale doesn’t eliminate this risk; it just makes the consequences of a failure larger.



Key Insights

  • The failure point in embedded finance is rarely outright fraud — it’s reconciliation, or the lack of anyone actively confirming that what the ledger says matches what the bank actually holds.

  • Regulatory attention has shifted decisively toward sponsor banks and the nonbank middle layer, not just the consumer-facing fintech brand — more than a quarter of recent FDIC enforcement actions targeted sponsor banks directly.

  • Passing due diligence at the start of a partnership says very little about whether that partnership is still being actively governed years later, at a much larger scale.

  • A market growing this fast — toward $450 billion within a decade — means governance gaps that seem manageable today will only get more expensive to fix the longer they go unaddressed.


Key Takeaways

If your organisation offers, enables, or partners on embedded finance products, the board’s question shouldn’t be “did our partner pass due diligence.” It should be whether management can explain, in plain language, how the product actually works end to end, where the money genuinely sits at any given moment, and what happens to customers if any single link in that chain fails. Synapse didn’t collapse because anyone set out to defraud a customer. It collapsed because nobody was clearly, continuously accountable for making sure the numbers matched across every party in the chain. That’s a governance failure, not a technology one — and it’s exactly the kind of failure a board is positioned to catch, well before it reaches the headlines.


Comments


  • alt.text.label.LinkedIn
  • alt.text.label.Facebook
bottom of page