Recently, we brought Phil Goldfeder (CEO, American Fintech Council), Evey Guo (Principal, FS Vector), and our own Saurabh Bajaj (Chief Product Officer) together to talk about what happens when you stop partnering with a bank and become one.
If you’re a compliance professional and you’re considering a bank charter, this recap was written for you. Or if you’d like the full recording, you can watch it anytime here.
TL;DR
A fintech that gets a bank charter takes over the compliance work its sponsor bank used to handle, including SAR filing, examiner-facing artifacts, BSA officer coverage, and the independent audit. Regulators expect proof that the program works, not just written policies, so build it on one data model and one decision engine from day one.
Your charter type decides your regulator. National banks, state banks, industrial loan companies, and uninsured national trust banks each answer to different supervisors.
Your business plan should read like an operations manual. Regulators want step-by-step product flows, and the OCC expects applicants to reach profitability by year three.
Copying your sponsor bank's stack tends to fail the first exam. Stitching together separate best-of-breed vendors creates conflicting definitions of normal activity.
Examiners want demos, not binders. Be ready to show traceability, explainability, governance, and monitoring in real time.
Why everyone’s suddenly talking about charters
Evey was blunt about the moment: “the charter window is wide open right now.” The OCC has approved more than 25 charters since late 2025, and the FDIC has been approving industrial loan company charters at a pace she hasn’t seen before (GM, Ford, and Stellantis among them).
Add the post-Synapse hangover, and fintechs are rethinking how much they want to depend on someone else’s charter.
What she hears from renters is consistent, too. The bank takes a cut of revenue, wants weekly compliance reporting, and puts your product launch behind its own priorities.
Her summary of the complaint: “I cannot control my own destiny.”
Her summary of the decision: “It’s a control and economics play.”
Three questions before you file for a bank charter
Do you have the capital? Evey described it as “a good amount of money that’s locked with the regulator for a period of time they cannot touch.”
Can you own the compliance program, and talk to the regulator directly instead of through your sponsor bank?
Do you have people with bank experience, or are you ready to hire them?
Pick a charter, pick a regulator
Evey's point was that the charter you pick shapes how you work with your regulators every day, so it helps to know the four main options and who supervises each.
Full-service national bank: the OCC supervises the bank, and the Fed supervises the parent as a bank holding company.
State bank: a state regulator plus the FDIC or Fed, with less preemption.
Industrial loan company: typically Utah-chartered and FDIC-insured, and the parent stays out of bank holding company rules. It can’t offer business demand deposit accounts, which is why Square, for instance, still partners with a bank for that piece.
Uninsured national trust bank: OCC-supervised, fiduciary activities only. Payroll and digital asset firms like it.
Evey’s field note on the regulators: “The OCC tends to be more strategic in their supervision… the FDIC tends to be more document-driven. They expect to see a lot of policy and procedures early on.” And the charter you choose “doesn’t really just determine who regulates you, [it determines] what working with those regulators actually looks like.”
Skip the homework and you can get stuck. Evey has watched applicants mid-application “start to feel like this charter is not providing what I’m wanting, so I should change route, but it’s already too late.”
Your business plan is not a pitch deck
The most common mistake she sees is organizations “writing their business plan like a pitch deck.” Regulators would rather see “step-by-step how each product’s operational flow looks, so they know what they’re approving.”
For the OCC, that also means a believable path to profitability, since “they at least expect any applicant to reach their profitability by year three of the de novo period.” If you’ve never been regulated, expect to spell out the program you’ll build from scratch, so the regulator knows “we are not issuing blank checks on a charter.”
One more practical tip for hiring your bank’s executives: look for someone “who can speak both the fintech language and speak the regulatory language.”
What gaps the sponsor bank was filling
Saurabh had this to say about life in a sponsor bank program: “The sponsor bank was quite literally filling the gaps, which the fintech never saw.” But once you become the bank, that list becomes yours.
“The SAR filing infrastructure, the examiner-facing artifacts, the BSA officer coverage, the independent audit function, all of that is now the fintech’s responsibility.” - Saurabh Bajaj
The tools you inherited can make it more complicated. They were tuned for the sponsor’s role, and as Saurabh put it, “Oversight is very different from when you actually own the customer and have to drive the operations.” Make a list, put a name next to each item, and treat any blank line as your first project.
Curious what that oversight looks like from the bank’s side? See how TransPecos Banks approached it.
Examiners want proof, not policy binders
Saurabh said the fintechs that get through a first exam have stopped presenting policy binders.
They’re “asking how to demonstrate the operation not just to document the lay of the land.”
Examiners are also asking for demos of traceability, explainability, governance, and monitoring, and “proof of operation is expected to be more real-time.”
He also flagged the early decisions that stick: “you can make two or three decisions in that window that are effectively irreversible for the next two to three years.” Think data model, vendor concentration, and auditability.
Two ways teams tend to get it wrong
When fintechs build their compliance tech for a bank, Saurabh sees them fall into one of two traps:
Lift and shift. You port your sponsor bank’s stack over: same monitoring, case management, and KYC vendor. Saurabh says, “It technically should work, but it fails at the first exam.”
The best-of-breed patchwork. You overcorrect and buy the top point solution for everything. Fintechs are dev-forward, so “they think stitching together is a simpler problem. It’s not.” His example: your onboarding risk assessment sets what normal looks like, and transaction monitoring in a different vendor has to answer “does the actual activity hold true with the expected activity?” With separate thresholds in separate tools, that’s two definitions of normal and one awkward exam conversation.
His advice on growth: “You don’t stand up a fourth, fifth, sixth vendor, every single time.”
What to build in from day zero
Saurabh’s foundations, so you’re not bolting things on later:
One risk data model, so every read and write hits the same customer state.
One decision engine on top of it, instead of five or six.
Unified operations, so analysts aren’t opening five tools to work one case.
Day-zero detection. Policies are easy to write, but “day-zero detection is what impacts the real customers.”
AI-native, human-in-the-loop tooling for compliance and fraud teams.
The payoff at exam time comes when an examiner says “walk me through what you know about the customer at every decision point,” and the answer is a simple query, not a scavenger hunt.
Your homework if you’re considering a bank charter
Here's what to work through before you file:
Treat GRC as a core capability. Saurabh’s version: “how do we build GRC as a core capability, not a bolt-on?”
Map your exit from the sponsor bank, including everything on that landlord list.
Rehearse the exam ask. Can you demo traceability today, or only describe it?
Would you like the full conversation? Watch the on-demand recording.

Kaitlin Harvey
Senior Growth Marketing Manager, Lifecycle & Content






