Feature Third-Party Risk
The FDIC Is Building a Fintech Certification Program. What BISDO and RAMP Mean for Your Third-Party Risk Program.
On July 21, 2026, the FDIC released a draft term sheet for a voluntary fintech certification program called BISDO — with a RAMP certification label. It won't create a safe harbor or a blacklist. But it will change what your bank partner asks you to prove.
Table of Contents
TL;DR
- On July 21, 2026, the FDIC circulated a draft term sheet for BISDO — the Banking Industry Standards Development Organization — a voluntary fintech certification program
- Certified providers would receive a RAMP (Risk-Assessed, Manageable Partnerships) label and appear in a public registry
- RAMP provides no safe harbor and creates no blacklist — but it signals what the FDIC thinks adequate fintech oversight looks like
- Between 2022–2025, regulators issued consent orders against seven sponsor banks in BaaS programs; more than 25% of FDIC enforcement actions targeted sponsor banks in embedded finance
- The practical implication: your bank partner’s examiner is already asking about your program. BISDO just proposes to make those standards explicit.
Consent orders against sponsor banks have a pattern. The bank gets the action. The fintech gets the lesson.
Between 2022 and 2025, regulators worked through Blue Ridge Bank, Evolve Bank & Trust, Thread Bank, Piermont Bank, Lineage Bank, Cross River Bank, and Green Dot Bank. The violations cluster around the same issues: BSA/AML deficiencies, inadequate fintech partner oversight, weak transaction monitoring, and consumer compliance failures. In every case, the chartered bank bore the regulatory consequence — regardless of what the partnership agreement said about who owned compliance.
The FDIC’s proposed solution isn’t another enforcement action. It’s a standards body.
What BISDO Is — and What It Isn’t
On July 21, 2026, the FDIC circulated a draft term sheet for the Banking Industry Standards Development Organization — BISDO. The concept: an industry-led body, developed in collaboration with the FDIC and major trade associations, that would establish voluntary standards for third-party service providers that partner with banks, and issue certifications to those that meet them.
The certification label is RAMP: Risk-Assessed, Manageable Partnerships. Providers that meet BISDO standards would receive RAMP certification and appear in a public registry.
The trade organizations collaborating with the FDIC on the proposal include the American Bankers Association, Independent Community Bankers of America, Bank Policy Institute, Financial Technology Association, American Fintech Council, and Coalition for Financial Ecosystem Standards — a broad coalition spanning banks and fintechs.
Here is what the FDIC has been explicit about: BISDO certification is not a regulatory endorsement, and RAMP does not create a regulatory safe harbor. Banks remain responsible for their own oversight of fintech partners. Certification doesn’t substitute for a bank’s due diligence. And absence from the registry doesn’t create a blacklist — a fintech that hasn’t pursued RAMP certification can still partner with banks.
So what is it actually?
The honest answer is that it’s a proposed piece of infrastructure for a market that currently has no standardization. Every bank that wants to partner with a fintech runs its own due diligence. Every fintech that wants to partner with multiple banks answers nearly identical questionnaires from each. The questions overlap substantially; the formats differ; the cycles pile up. BISDO’s pitch is that if a fintech demonstrates compliance with a common standard once, that demonstration should be reusable across multiple bank relationships.
The Standards Areas: What BISDO Would Actually Cover
The draft term sheet identifies the areas BISDO would assess. They are worth reading carefully, because they mirror what examiners already ask sponsor banks to demonstrate about their fintech partners:
- Third-party risk management — the fintech’s own TPRM program; whether it manages its vendors with the rigor its bank partners are now required to apply to them
- Governance and internal controls — board-level accountability structures, 3 Lines of Defense, control testing
- Cybersecurity — consistent with NIST CSF or similar frameworks; incident response, access controls, vulnerability management
- Operational resilience — business continuity plans that address critical functions, dependencies, and recovery procedures
- Information security — data classification, encryption, access management
- Consumer compliance — fair lending, UDAAP, Regulation E, complaint management
- BSA/AML controls — transaction monitoring, suspicious activity reporting, KYC/CIP procedures
- Due diligence — the fintech’s own process for evaluating its own vendors and subcontractors (fourth-party risk)
- Ongoing monitoring — not just point-in-time assessments, but continuous vendor oversight
- Business continuity — the fintech’s ability to maintain critical functions through disruptions
If you’re reading this list and thinking it looks like what an examiner asks your bank partner to show in their third-party risk management examination — you’re right. That’s the point.
The Enforcement Context That Explains Why This Is Happening Now
BISDO didn’t emerge from a policy vacuum. The enforcement record created the conditions for it.
Between 2022 and 2025, bank-fintech partnership enforcement produced a pattern visible in the data: more than a quarter of the FDIC’s formal enforcement actions targeted sponsor banks in embedded finance partnerships. More than one in five OCC enforcement actions did the same. The enforcement action against Cross River Bank in 2023, the Federal Reserve consent order against Evolve, the OCC’s 2025 guidance on BaaS sponsor expectations — each reinforced the same principle: banks cannot delegate responsibility for their fintech partners’ compliance to the fintechs themselves.
The practical result is a rising cost of bank-fintech partnership formation. Banks are running lengthier due diligence processes. Fintechs are spending more time on questionnaire responses and less time on product development. Community banks — which would most benefit from fintech partnerships to extend their product footprint — often lack the staff to run rigorous TPRM reviews efficiently.
BISDO is the FDIC’s answer to a structural problem: duplicative, resource-intensive, unstandardized due diligence that burdens both sides of the relationship without necessarily producing better outcomes than a common standard would.
The FTC’s blog on Safeguards Rule notification requirements and the Consumer Finance Monitor’s coverage of BISDO both frame this as infrastructure, not enforcement — a way to make the due diligence market function more efficiently rather than a new compliance burden.
What This Means for Fintechs Right Now
BISDO is proposed, not final. The certification program, if it launches, will require additional rule-making, industry consensus on specific standards, and operational infrastructure for assessments and registry maintenance. None of that is imminent.
But the standards areas in the draft term sheet are not aspirational. They describe what examiners already look for when they assess whether a bank’s third-party risk program adequately covers its fintech partners. That examination expectation exists today, regardless of whether BISDO ever launches.
There are three things fintechs should take from this proposal:
1. Audit your program against the BISDO standards areas now. The 11 areas in the term sheet — TPRM, governance, cybersecurity, operational resilience, InfoSec, consumer compliance, BSA/AML, complaint management, due diligence, monitoring, BCP — are what your bank partner’s examiner is already reviewing your bank partner on, with you as the subject. If your internal programs don’t address these areas, you’re a potential exam finding waiting to be written.
2. Prepare for bank partner due diligence to get more structured. Whether or not BISDO launches, its publication signals that regulators view standardization of fintech due diligence as a policy objective. Expect bank partner questionnaires to become more rigorous and more consistent over the next 12–18 months, informed by the standards areas the FDIC has now publicized.
3. If you’re scaling to multiple bank partners, track BISDO’s development. The efficiency case for RAMP certification is strongest for fintechs seeking relationships with multiple sponsor banks — demonstrating compliance with a common standard once rather than running 10 separate due diligence cycles. That benefit doesn’t exist today, but if BISDO progresses, it will.
The Due Diligence Gap It’s Trying to Close
The embedded finance market has a structural asymmetry that BISDO is designed to address. Large, established fintechs can absorb the due diligence cost of multiple bank relationships — they have compliance teams, legal counsel, and institutional knowledge of what questions are coming. Earlier-stage companies and smaller operators often can’t.
The result is a market where the fintechs best positioned to use BISDO certification — those for whom a reusable credential would most reduce partnership friction — are also the ones who most need to build the underlying programs to earn that certification.
The FDIC has said that the current approach of continuous monitoring by sponsor banks produces good outcomes in principle but inconsistent implementation in practice. BISDO’s pitch to the market is that consistent standards produce more consistent outcomes than individual bank judgment about what adequate fintech oversight looks like.
Whether the market accepts that pitch will depend on whether BISDO assessments are genuinely rigorous, whether certification provides enough due diligence efficiency to justify the cost of compliance, and whether examiners treat RAMP certification as meaningful evidence of a fintech’s compliance posture. None of those questions have answers yet.
What Hasn’t Been Resolved
The FDIC’s July 21 draft term sheet leaves several significant questions open:
Who conducts BISDO assessments? The term sheet doesn’t specify whether assessments will be conducted by BISDO staff, accredited third-party auditors, or some other mechanism. The quality and consistency of assessments will determine whether RAMP certification actually signals anything.
How often do certified fintechs need reassessment? Certification that reflects a point-in-time assessment quickly becomes stale in a regulated environment. The ongoing monitoring standards area suggests continuous compliance is intended, but the mechanics aren’t defined.
What are the costs? Certification programs charge fees. For a large fintech, assessment costs may be trivially small relative to the due diligence efficiency gained. For a community fintech, those costs may exceed the benefit.
How will regulators treat certification in examinations? The FDIC has said RAMP is not a safe harbor. But examiners exercise judgment. If a bank can demonstrate that a fintech partner holds current RAMP certification and has reviewed what that certification covers, will that influence examiner findings? The answer matters, and it isn’t given.
So What?
The consent order pattern against sponsor banks has been consistent: banks that outsource compliance judgment to their fintech partners receive enforcement actions. Banks that treat fintech oversight as an ongoing supervisory function — with documented TPRM programs, continuous monitoring, and evidence of periodic assessment — have fared better.
BISDO’s existence as a proposal reflects regulatory recognition that the current state of bank-fintech due diligence is inefficient, inconsistent, and producing worse outcomes for both sides than a market infrastructure could.
It also reflects a practical reality: the Bilt-Wells Fargo transition’s consumer failures and the seven BaaS consent orders didn’t happen because banks were indifferent to fintech risk. They happened because the signals of inadequate compliance were there in the due diligence record — and because the market lacked a common standard for what “adequate” looked like.
BISDO is proposing to provide that standard. The question for every fintech considering a bank partnership is whether their current compliance program would earn a RAMP certificate if one existed today.
If the honest answer is no — that’s the gap to close, independent of whether BISDO ever launches.
Related reading: OCC BaaS Consent Orders and What They Mean for Fintech TPRM Programs | Sponsor Bank Continuous Monitoring: What Fintechs Are Now Required to Support
Build the TPRM program your bank partner’s examiner is looking for. The Third-Party Risk Management (TPRM) Kit covers the full vendor lifecycle — risk tiering, due diligence questionnaire, contract review checklist, ongoing monitoring, and offboarding — structured to meet OCC Bulletin 2023-17 and FDIC third-party risk guidance. The BISDO standards areas map directly to what this kit addresses.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is BISDO and who proposed it?
What is RAMP certification?
What standards areas would BISDO cover?
Does BISDO certification create a regulatory safe harbor for fintechs?
Why is the FDIC proposing BISDO now?
Should my fintech pursue RAMP certification when it's available?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
OCC's 2026 Third-Party Risk Guidance Rewrite: What Banks Should Change Now
The 2026 third-party risk guidance proposal rewrites vendor tiering and gives community banks leverage with core providers.
Sep 11, 2026
Third-Party Risk
Everest Ransomware Hit Citizens Bank and Frost Bank Through a Vendor Nobody Will Name. Six Class Actions Later, Here's What Your TPRM Program Needs.
In April 2026, the Everest ransomware group claimed 3.65 million records from Citizens Bank and Frost Bank via a shared third-party vendor. Neither bank has named the vendor. Six class actions were filed against the banks. Here is what this means for your TPRM program.
Sep 10, 2026
Third-Party Risk
NYDFS Said It in October. Examiners Are Checking in 2026. What Your Vendor Program Needs to Reflect the Part 500 Third-Party Guidance.
NYDFS's October 2025 industry letter on third-party cybersecurity risk established that covered entities cannot delegate Part 500 compliance to vendors. With MFA, asset inventory, and annual certification requirements now fully active, examiners are reviewing whether vendor programs actually reflect the guidance — not just acknowledge it. Here's what your TPRM program needs.
Sep 7, 2026