In this essay
A bank–fintech partnership is an arrangement in which a licensed bank provides something only a bank can provide (a licence, a settlement account, a sponsored card BIN, access to a payment scheme) and a fintech provides something the bank cannot build or sell quickly (a product, a distribution channel, a merchant base, a technology platform). The partnership works when each side is honest about which of those it is bringing.
I write this from the fintech seat. Simpaisa runs payment infrastructure in five regulated markets, every one of which depends on partner banks for settlement, and our card issuance runs on a partner bank's sponsored BIN. I have never worked inside a bank. What follows is what banks asked us for, and what we learned to bring before they asked.
The four shapes of partnership
Settlement and sponsorship. The bank holds the accounts through which the fintech's funds flow and, for cards, sponsors the fintech's programme on the bank's BIN. The fintech runs the product; the bank owns the regulatory relationship for the funds. This is the most common shape in payments and the one most fintechs start with.
Distribution. The fintech sells the bank's product (a loan, an account, a card) to customers the bank does not reach, under the bank's licence. The bank owns the product and the risk; the fintech owns the customer experience and acquisition.
Technology. The fintech supplies software the bank runs under its own brand: onboarding, KYC, fraud tooling, a payments API. The bank owns everything customer-facing; the fintech is a vendor with a partnership label.
Banking-as-a-service. The bank exposes its licence and accounts as an API and the fintech builds a full product on top, from onboarding to ledger. This is the deepest shape and the one where the division of responsibility is most often unclear, which is why regulators have looked at it hardest. I cover it separately in banking-as-a-service versus open banking versus embedded finance.
What the bank owns, and what it will never give up
Whatever the shape, four things stay with the bank.
The licence, and with it the regulator's questions. When the regulator asks who the customer is, where the funds came from and why a transaction was allowed, the bank has to answer, even if the fintech's system holds the data.
The settlement account. Funds in flight sit in the bank's books. The bank's treasury sees the balances; the bank's auditors reconcile them.
The BIN, in card programmes. The card says the fintech's name; the network sees the bank. A chargeback, a scheme fine or a compliance breach lands on the bank's membership.
The right to switch the programme off. Every sponsorship agreement contains it. A fintech that has not planned for that clause has not read the agreement.
Understanding this changes how a fintech approaches the partnership. You are not asking the bank to trust your product. You are asking the bank to let your product operate under its licence, and to be able to explain to its regulator why that was safe.
What the bank actually asks for
Due diligence from a partner bank follows a pattern. In our experience the requests fall into five groups, and a fintech that has the answers ready before the first meeting shortens the timeline by months.
Who you are. Ownership, directors, source of funds, regulatory status in every market, litigation history. Banks are screening for the risk that the partner is a vehicle for something else.
What controls you run. KYC and KYB procedures, sanctions and PEP screening, transaction monitoring, fraud controls, and the evidence that they operate. A description is not evidence. A sample of decisions, with reasons, is.
What certifications you hold. For anything touching cards, PCI DSS Level 1. For information security generally, ISO 27001. Simpaisa holds both and was audited without findings, and I would say the single most useful thing we did in any bank conversation was to bring the audit reports rather than the certificates. The certificate says you passed; the report shows what was tested.
How money moves. Flow of funds diagrams for every product, showing which account holds the money at each step, who can move it, and how it is reconciled. Banks want to see that the fintech reconciles daily and can explain every break. Our own reconciliation reached 90 percent straight-through processing before any bank asked; the remaining exceptions and how they were handled were what the bank was most interested in.
What happens when it goes wrong. Incident procedures, complaint handling, business continuity, and what the fintech will do if the bank exits. A bank that sees a credible wind-down plan trusts the partnership more, not less.
What the fintech should ask for
The conversation is not one-sided. A fintech entering a partnership should get clear answers on: settlement timing and cut-offs, limits and how they change, the bank's own regulatory obligations that will flow down as requirements, the escalation path when a transaction is held, the reporting the bank will need and in what format, and the notice period and conditions on termination.
Most partnership failures I have seen were not about fraud or capital. They were about a limit the fintech did not know existed, a reporting obligation that arrived as a surprise, or a termination clause read for the first time when it was triggered.
A partnership checklist
Before signing, both sides should be able to complete this list without ambiguity.
- Which party is the regulated entity for each product, in each market.
- Which party owns the customer and merchant contracts.
- Where funds sit at every step, and who reconciles.
- Which controls each party runs, and what evidence is exchanged, how often.
- Which certifications are required, and when they are re-verified.
- What the bank reports to its regulator about the partnership, and what the fintech must supply.
- Limits, cut-offs and how changes are communicated.
- Incident, complaint and exit procedures, with named owners.
FAQ
Why do banks partner with fintechs? To reach customers, merchants or markets they cannot reach alone, and to add products or technology faster than they can build. The partnership is worth it to the bank when the added book is larger than the added risk, and the risk can be explained to the regulator.
What does a fintech need to partner with a bank? Clear ownership and regulatory status, working KYC, AML and fraud controls with evidence, security certifications such as PCI DSS and ISO 27001, documented flow of funds with daily reconciliation, and credible incident and exit procedures.
What is a sponsor bank? A bank that lets a fintech's card programme or payment product operate under the bank's licence and network membership. The fintech runs the product; the bank owns the regulatory relationship.
What are the risks of bank-fintech partnerships? For the bank: regulatory exposure for activity it does not directly run. For the fintech: dependence on a partner that can change limits or exit. Both are managed by clear responsibility, shared evidence and a tested exit plan.
How long does bank due diligence take? Months, typically, and longer when the fintech assembles evidence after being asked. Fintechs that bring audit reports, flow-of-funds diagrams and control evidence to the first meeting shorten it considerably.
Closing thought and further reading
Banks do not partner with fintechs to be disrupted. They partner to grow a book they cannot reach alone, at a risk they can explain to their regulator.
Building through similar complexity?
Discuss the operating decisions behind the essay, or explore where my experience can help.


