Banking as a Service (BaaS) Explained: How It Works and Why It Keeps Making Headlines
Banking as a Service (BaaS) is the arrangement that lets a non-bank brand offer real bank accounts, cards or lending under its own name, while a licensed bank sits underneath holding the charter and the regulatory obligations. It is the reason a payroll app can issue you a debit card, or a retailer can offer a business current account, without either company being a bank itself. Understanding how it actually works — and where it has gone wrong — matters for anyone advising on fintech risk, treasury infrastructure, or CPD in financial technology.
The three-layer BaaS stack
A typical BaaS arrangement has three distinct layers, and confusing them is where a lot of the risk hides:
- The brand or fintech — owns the app and the customer relationship, but holds no banking charter of its own.
- The middleware or BaaS platform — the technology layer that connects the brand to the bank via APIs, and typically maintains the ledger of who owns what.
- The licensed sponsor bank — holds the actual deposits, moves the money, and carries the regulatory obligations (BSA/AML, fair lending, safeguarding) for everything happening above it.
The core principle is simple to state and easy to forget in practice: risk flows down to the bank at the bottom of the stack, while the customer relationship and the brand sit at the top. When the middleware layer fails, that separation becomes a serious problem.
Why BaaS became a regulatory flashpoint
For several years BaaS was framed mainly as a growth story. That changed in April 2024, when middleware provider Synapse collapsed into Chapter 11 with an estimated shortfall of up to $95 million between what its partner banks actually held and what was owed to end users — freezing roughly $265 million in deposits for more than 100,000 people, in some cases for months. The root cause was not fraud in the traditional sense; it was a ledger and reconciliation failure between Synapse and the banks it worked with, which meant nobody could say with confidence who owned which dollar.
Regulators responded directly at the sponsor-bank level. The Federal Reserve issued a cease-and-desist order against Evolve Bank & Trust in June 2024 over an ineffective risk-management framework, and the OCC entered a consent order against Blue Ridge Bank the same year over Bank Secrecy Act and anti-money-laundering deficiencies. The message from both was consistent: a bank's use of a third-party middleware provider does not reduce its own regulatory responsibility for what happens to customer funds.
Sponsor-bank BaaS vs embedded-software BaaS
Post-Synapse, it is worth distinguishing two models that both get called "BaaS" but carry very different risk profiles. In sponsor-bank BaaS, a bank rents its charter to outside fintech brands, deposits are held for those brands' end customers, and the middleware platform typically owns the ledger — this is the higher-risk, higher-scrutiny model. In embedded-software BaaS, a bank or credit union licenses modern tooling to serve its own existing members, keeps deposits and the ledger on its own core system, and takes on comparatively standard vendor risk rather than third-party custodial risk. Community banks in particular have leaned toward the second model as a way to modernise without taking on sponsor-bank-level exposure.
What finance and risk teams should actually watch for
If you are assessing a BaaS relationship, either as a fintech partnering with a sponsor bank or as a finance professional evaluating a vendor, the practical questions are: who owns the ledger of record, how often is it reconciled against the bank's own records, is deposit insurance pass-through actually structured correctly for end customers, and what third-party risk management framework governs the middleware layer. The FDIC's proposed custodial-account rule, put forward in September 2024, pushes in exactly this direction — requiring accurate per-owner records, daily reconciliation, and independent validation for custodial accounts with transactional features.
BaaS sits close to several adjacent infrastructure shifts finance teams are also tracking, including faster real-time payment rails and the open banking obligations reshaping account access under PSD3. Together they are why "embedded" financial infrastructure has become such a large part of how fintech products actually get built — see our roundup of notable fintech success stories for examples of the model working well when the governance is right.
FAQ
Is Banking as a Service the same as open banking?
No. Open banking is about giving third parties permissioned access to a customer's existing bank account data and payments. BaaS is about a non-bank brand issuing entirely new bank accounts or cards, underwritten by a licensed bank behind the scenes.
Who is liable if a BaaS middleware provider fails?
Regulators have made clear that the sponsor bank remains responsible for the activity, even though contractually it may look like the middleware provider or fintech brand is "in charge" day to day. That is precisely the lesson of the Synapse collapse.
Is BaaS declining after Synapse?
Not as a category, but the market has bifurcated: several middleware providers have exited or been acquired, sponsor banks face materially higher regulatory scrutiny, and embedded-software BaaS aimed at a bank's own members has grown as the lower-risk alternative.
Whatever side of the stack you sit on, BaaS is now a governance question first and a technology question second — and that shift is exactly what regulators are underwriting.
BaaS is the infrastructure layer; the customer-facing outcome it usually powers is embedded finance — a non-financial platform offering a financial product as part of its own experience, from Shopify Balance to Toast Capital.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience helping students advance their professional careers.
View all posts by Learnsignal Education Team

