WASHINGTON — The modern consumer finance app often looks like a single brand. Behind the glass, a bank holds deposits or issues cards while a technology firm runs marketing, onboarding, and support. The industry calls the structure a partnership or banking-as-a-service. Economically it is a rent swap. Each side leases a scarce asset the other cannot cheaply build.

U.S. federal banking agencies have spent the mid-2020s writing that structure into supervisory English. In June 2023, the OCC, Federal Reserve, and FDIC issued final Interagency Guidance on Third-Party Relationships: Risk Management (OCC Bulletin 2023-17). The guidance covers business arrangements with third parties generally and explicitly notes novel fintech structures. It does not treat outsourcing of customer contact as outsourcing of accountability.

The bank rents the perimeter. The fintech rents distribution. Supervisors still knock on the bank’s door.

What each side is leasing

The bank’s scarce assets are legal and institutional: a charter or membership path into payment systems, deposit insurance branding, compliance programs, and sometimes balance-sheet capacity. The fintech’s scarce assets are commercial: mobile UX, performance marketing, vertical software distribution, and speed of product iteration. Contracts then split economics — interchange share, deposit-rate spread, program fees, minimums — while brand surfaces usually favor the fintech in the customer’s hand and the bank in the account agreement’s fine print.

That split is why “who owns the customer” is the wrong first question. Ownership is layered. The fintech may own the push notification. The bank owns many legal duties when the product is a bank deposit or bank credit. When something breaks — fraud, misleading marketing, BSA failures, operational outage — the agencies’ third-party framework expects the banking organization to have assessed, contracted, monitored, and exited the relationship with the same seriousness it would apply to other critical vendors.

Deposit delivery made the rent explicit

In July 2024, the same three agencies issued a Joint Statement on Banks’ Arrangements with Third Parties to Deliver Bank Deposit Products and Services. The statement focuses on arrangements where a nonbank markets, distributes, or facilitates bank deposit products to end users. Banks may pursue deposits, revenue, geography, or technology this way. The agencies flag risk-management and compliance issues when the customer relationship is mediated by someone who is not the bank.

The same day, the agencies released a request for information on bank-fintech arrangements (OCC Bulletin 2024-21), seeking industry detail on how these programs work and how risk is managed. That RFI is itself evidence: supervisors see a large market structure, not a handful of quirky pilots. They are still mapping the rent.

Where the structure breaks

Layer Typical bank contribution Typical fintech contribution Failure mode
License / perimeter Charter, deposit insurance context, payment access None (or MTL for adjacent activity) Bank concentration; program exit stranding users
Balance sheet Deposits, card receivables, liquidity Occasionally credit risk share Rapid deposit inflows without bank controls
Customer acquisition Limited brand reach in niche verticals Paid growth, partnerships, app UX Misaligned incentives on quality of customers
Compliance operations Ultimate BSA/AML and consumer compliance duty Day-to-day KYC tooling and marketing copy Nested third parties; bank loses line of sight
Complaint / brand Legal account of record Support chat the customer actually uses Ping-pong when losses hit

Rent is not ownership

Fintechs that treat the sponsor bank as a commodity API eventually rediscover switching costs. Migration of ledgers, card BINs, compliance files, and deposit portfolios is slow and political. Banks that treat fintech partners as pure fee income eventually rediscover supervisory concentration risk when one program is a large share of deposits or operational dependency. Both sides can earn rents for years. Neither has purchased immunity from the other side’s failure.

The interagency guidance’s practical message is boring on purpose. Examiners expect a bank to inventory its third parties, risk-rate them, contract for audit rights, data, and an exit path, and monitor nested relationships when a fintech partner uses further vendors of its own. A glossy app does not move the duty off the bank’s books. On the commercial side, the matching lesson holds: the partnership prices as rent for specific scarce assets, retention control determines who bears churn risk, and either side’s rent can rise — or the agency exam cycle can shorten the lease.

History rhymes with earlier third-party models. Affinity cards, white-label deposits, and merchant-branded products all rented bank licenses to nonbank distribution. What is new is the software-defined scale and the speed at which a single fintech program can gather deposits or card accounts across many states. That scale is exactly why the 2023 guidance and 2024 deposit statement exist. Concentration and nested vendors turn a marketing partnership into a safety-and-soundness topic.

Boards on both sides can run a simple rent audit quarterly. What fee does the bank earn per active account, and is it compensation for risk or a race to the bottom? What CAC does the fintech pay, and who owns retention if the bank ends the program? Which party’s name appears on the account agreement, the FDIC legend where applicable, and the complaint log? Fuzzy answers mean the partnership is under-specified relative to what examiners will ask.

Bank–fintech distribution will continue because the scarcity is real. Charters and insurance trust are hard to replicate. Mobile distribution and vertical software are hard for many community banks to build alone. The durable analysis is a rent ledger: who pays whom for perimeter, for attention, and for residual risk when the customer complains. Supervisory texts from 2023–2024 already write residual risk next to the bank’s name.

Source notes