top of page

Want more great resources?

Subscribe to receive all the latest industry research, trends, and updates directly in your inbox.

BSA/AML Software for Fintech and BaaS Partnerships

  • 3 days ago
  • 5 min read

Last updated: September 1, 2026 | By: Ryan McInerny, Chief Product Officer

Key Summary

BSA/AML software for fintech and BaaS partnerships should help your bank or credit union collect documentation, monitor program activity, document decisions, ensure compliance, and prepare for audits or examinations. The right configuration depends on each program's products, customers/users, data, and risk profile. RiskScout recommends defining those requirements before selecting software or finalizing the partnership contract.

What do regulators expect from fintech oversight?

Your institution should manage a fintech or BaaS relationship throughout its full life cycle and remain accountable for activities performed through the arrangement.

The 2023 interagency guidance describes a life cycle that includes planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination. The depth of your controls should reflect the relationship's risk and complexity.

The agencies' 2024 community-bank guide provides considerations and examples for each stage. The guide is a voluntary resource and does not impose new requirements, so your bank or credit union must apply the relevant guidance to its own facts.

A contract can assign work to the fintech, but your institution still needs sufficient information, access, expertise, and controls to oversee that work.

What should BSA/AML software capture for each partner program?

Your AML solution should preserve the partner-level information needed to assess risk, monitor activity, and explain decisions.

  • Program profile. Record the products, services, customers, geographies, transaction channels, expected activity, and approved limits.

  • Ownership and licensing. Maintain verified business details, beneficial ownership, required licenses, key personnel, and material subcontractors.

  • Data inventory. Document each source, field definition, transfer method, frequency, reconciliation control, and responsible party.

  • Monitoring configuration. Connect rules, thresholds, customer groups, and review procedures to the program's assessed risk.

  • Ongoing reviews. Schedule document collection, attestations, enhanced due diligence, issue follow-up, and approvals.

  • Audit history. Retain changes, evidence, exceptions, decisions, escalation records, and reporting for internal and external review.

FFIEC BSA/AML risk-assessment guidance says an institution's assessment should reflect its products, services, customers, and geographic locations. It may need updates when introducing new products, services, or customer types.

How should software handle BaaS data and monitoring?


Your software should make the partner's data understandable, testable, and usable for risk-based monitoring.

Start with data mapping. Confirm which party creates each field, how you receive it, how missing or rejected records are resolved, and how totals reconcile to authoritative sources. Define how quickly material changes reach the bank.

Then test monitoring by program. Your program should be able to apply controls that fit the partner's products and expected activity while retaining institution-level oversight. Ask how changes are tested, approved, documented, and rolled back.

What risks can be elevated in third-party deposit arrangements?

Some third-party deposit arrangements may elevate operational, compliance, strategic, liquidity, concentration, and consumer-protection risks.

OCC Bulletin 2024-20 also identifies potential risks involving end-user confusion and misrepresentation of deposit-insurance coverage. Your evaluation should connect these risks to data access, disclosures, complaint handling, transaction monitoring, liquidity reporting, and concentration limits.

The presence of a risk does not determine the outcome. Your assessment, controls, monitoring, and ability to correct problems shape whether the arrangement remains manageable.

Should a BaaS program use your existing AML solution?

The bank or credit union can extend its existing AML solution, use a separate configuration, or adopt an integrated platform that supports partner-specific workflows.

  • Extend the current solution. This may reduce implementation work and vendor count. The tradeoff is that the existing system may require substantial data mapping, configuration, or manual oversight.

  • Use a separate partner configuration or instance. This can isolate program settings and queues. The tradeoff is additional administration, reporting, access management, and possible licensing costs.

  • Use an integrated BSA/AML platform with partner workflows. This can connect due diligence, monitoring, cases, and reporting. The tradeoff is migration or implementation work and the need to validate every promised capability.

Choose the structure after testing data ingestion, risk segmentation, alert capacity, reporting, permissions, record export, pricing, and contingency plans.

What are the signs a partnership is outgrowing its AML software?

Your program may need review when recurring operational problems weaken monitoring, documentation, or oversight.

  • Data does not reconcile reliably. Employees repeatedly repair files, resolve missing fields, or compare systems manually.

  • Alerts cannot be understood by program. Your team cannot separate partner activity, explain volumes, or tune controls without affecting unrelated customers.

  • Reviews keep moving past due. Document collection, EDD reviews, issue follow-up, or approvals depend on personal calendars and spreadsheets.

  • Partner changes arrive too late. New products, customers, geographies, or subcontractors reach the AML team after implementation.

  • Exam preparation requires reconstruction. Evidence and decisions must be gathered manually from several systems whenever reviewers ask for them.

Document the frequency, cause, ownership, and effect of each issue. That record helps determine whether the problem requires configuration changes, added staffing, stronger partner controls, or different software.

Scope your fintech or BaaS program

A useful software demonstration follows one partner from initial review through onboarding, monitoring, recurring due diligence, issue escalation, and examination support.

RiskScout's fintech and BaaS workflows support partner applications, recurring information collection, EDD scheduling, and audit or exam document bundles. Contact the RiskScout team to schedule a demo.

Frequently Asked Questions

What BSA/AML software works for fintech and BaaS partnerships?

The software should support partner-level risk information, configurable monitoring, recurring due diligence, documented case decisions, and oversight reporting. RiskScout provides these workflows within its BSA/AML platform for financial institutions managing fintech and BaaS relationships.

The bank or credit union remains responsible for conducting its activities safely, soundly, and in compliance with applicable laws and regulations. Contracts should clearly assign duties, information access, escalation, audit rights, and corrective-action responsibilities without limiting the bank's oversight.

Due diligence should reflect the activity and may cover ownership, financial condition, legal and regulatory status, risk management, controls, information security, operational resilience, subcontractors, and prior performance. Your institution should define what must be updated and monitored after onboarding.

Yes, if the system can ingest and reconcile partner data, distinguish the program's risk and activity, support appropriate monitoring, preserve records, and produce useful oversight reporting. Test those capabilities with representative data before launch.

Meet the Author

Ryan McInerny, Chief Product Officer at RiskScout

Ryan McInerny is the Chief Product Officer at RiskScout, where he is passionate about creating solutions to enhance the day-to-day lives of financial institution employees. He brings a wealth of regulatory and technical experience to his role as a former National Bank Examiner with the Office of The Comptroller of the Currency (OCC). At the OCC, Ryan was a member of the OCC’s northeast district committees for compliance and commercial credit, where he helped to identify changing industry trends and risk conditions. Ryan brings a strong business sense with his banking expertise, having received his Masters Degree in Business Analytics from UVA's Darden School of Business.


Stay Up to Date

Want to keep your finger on the pulse of the latest industry news, trends, and data? 

Enter your email and be the first to know when there's new content added. 

bottom of page