The request usually arrives as a spreadsheet or a portal login, with a deadline and a long list of line items. Founders tend to read it as paperwork. It is not. It is the bank building its file on you. The bank's examiners can ask to see that file, and every answer you give ends up in it.
Each bank writes its own list, but most requests cover the same ground. What separates the fintechs that get through diligence cleanly from those stuck in rounds of follow-up is rarely the quality of their policies. It is whether each answer comes with evidence that the program runs the way the document says.
Why the bank asks for so much
To your sponsor bank, you are a third party, and often one of its higher-risk ones. The interagency guidance on third-party relationships that the federal banking agencies issued in 2023 expects banks to scale due diligence, contract terms and ongoing monitoring to the risk and complexity of each relationship. A fintech that holds the customer relationship, onboards customers and moves money on the bank's charter usually sits near the top of that scale. Recent enforcement actions against sponsor banks have pushed many to tighten oversight across their fintech portfolios.
Two consequences follow. First, the bank's examiners review its fintech partnerships, so a weakness in your program can become a finding against the bank. In some arrangements, the bank's federal regulator may also have authority under the Bank Service Company Act to examine services a third party performs for the bank. Second, you are usually also the bank's customer, subject to its own customer due diligence.
So the bank is not really asking whether you have a policy. It is asking whether it can defend relying on you.
What the request actually contains
Most requests group into these sections, though your bank may split, combine or add to them for your product.
| Section | What the bank typically asks for | What it is testing |
|---|---|---|
| Ownership and control | Beneficial owners and cap table, directors, control persons and senior management bios, organizational chart and background check consents. | Who is accountable, and whether anyone in the ownership or control chain raises sanctions, fitness or reputational concerns. |
| Licenses and registrations | State licenses held, pending or planned, FinCEN MSB registration where it applies, and your counsel's analysis of any exemption you rely on. | Whether the activity is permitted where you run it, and what the bank is relying on: your license or its charter. |
| Business model and funds flow | Product descriptions, target customers, geographies, projected volumes, funds flow diagrams and fee schedules. | Whether the bank understands where money moves, who holds it at each step and which customers become its own. |
| Program documents | Board-approved BSA/AML and sanctions policies, risk assessment, CIP, CDD and EDD procedures, customer risk rating, monitoring, investigations and referral to the bank, complaints and training. | Whether the program fits your products, your customers and the bank's own program. |
| Governance and staffing | The compliance lead and reporting line, board or committee minutes, delegation of authority and a staffing plan. | Whether compliance is independent of the business and resourced for your volume. |
| Your third parties | Vendors the program depends on, such as identity verification, processing and ledger providers, with your diligence, contracts and oversight records. | Whether you manage your third parties the way the bank has to manage you. |
| Data, ledger and reconciliation | How customer and transaction data reaches the bank, how your ledger is designed, and how often accounts are reconciled and breaks resolved. | Whether the bank can see its own customers and balances when it needs to. |
| Testing and findings | Your most recent independent BSA/AML review or audit, open findings with owners and dates, and prior regulator or bank-partner findings. | Whether problems get found, and whether they get fixed. |
| Financial and operational resilience | Financial statements, funding, information security program, business continuity plan and incident history. | Whether you will still be operating, and secure, through the life of the program. |
Two items are commonly underestimated. The first is the funds flow: if the diagram does not match the contracts, the ledger and the product, the bank will ask why. The second is automation. If AI or rules-based models touch onboarding, monitoring, screening or customer decisions, expect questions about what each one does, who approved it, how it was tested and who can override it.
An answer is not evidence
Most first drafts answer a diligence request with assertions. “We monitor all transactions.” “Compliance reports to the board.” “We reconcile daily.” Each one is a claim the bank then has to test, and that testing is where follow-up rounds come from. In the testing work I have done for banks, the question that mattered most was the simplest one: show me. A stronger response pairs every claim with the record that proves it.
- Transaction monitoring. Not the procedure alone, but alert volumes, aging, quality assurance results on dispositions, and a sample of escalations referred to the bank.
- Board oversight. Minutes showing when each policy was approved and what the board was told about compliance, not only a signed policy.
- Independence. A written delegation of authority, the reporting line on the organizational chart, and a documented decision where compliance stopped something the business wanted.
- Vendor oversight. A dated diligence file on each vendor, not a vendor list.
- Reconciliation. Reconciliation reports showing breaks and how each was resolved.
- Complaints. A log that captures every channel, with root cause analysis and what changed as a result.
- Testing. The independent review report and a findings tracker with owners, dates and closure evidence.
A simple self-test: read each policy, find every sentence that says the company “will” do something, and ask whether you could hand the bank a record that it did. Every sentence you cannot evidence is a likely follow-up request.
How to build a pack that answers the next request too
Index it to the request. Map each document to the bank's line item, with an owner, a date and a version. The bank reads one index instead of chasing attachments.
Make the numbers agree. Volumes, customer counts and geographies should match across the business plan, the risk assessment and the funds flow. Inconsistencies are a common trigger for follow-up questions, because they suggest the documents were written separately.
Disclose known gaps with a plan. If a control is still being built, say so, with an owner and a target date. A gap you disclose with a remediation plan is usually easier for a bank to accept than one its reviewers find.
Name one owner. One person runs the response and keeps answers consistent. Questions that turn on legal judgment, such as whether an activity needs a license or what the program agreement requires, go to your counsel. Ethixera Advisory is not a law firm, and a good pack shows where the legal analysis came from.
Keep it live. Diligence does not end at signing. Banks commonly require periodic reporting and send fresh requests when your product, customers or partners change. A pack kept as a living file turns each new request into an update, not a rebuild.
Seen from the bank side
Much of my testing and validation work has been for banks, in the second and third lines of defense. That is where a sponsor bank's reviewers sit when they read your file. We prepare fintechs the same way: read the program as those reviewers will, and build the evidence before they ask.
Top 10 U.S. Financial Institution
Directed BSA/AML testing and MRA validation across a multi-year remediation program. Managed quality assurance across the KYC customer file refresh program evaluating CDD/EDD standards.
What to do this quarter
- Get a representative request list, from your bank or a prospective one, and map what you have against every line.
- Name one diligence owner and set up the index before the request arrives.
- Refresh your BSA/AML and sanctions risk assessment so it matches your current products, customers, geographies and volumes.
- Inventory every vendor and partner the program depends on, and document the diligence behind each one.
- Pull the last quarter of evidence for your key controls: alerts, quality assurance, referrals to the bank, complaints and reconciliations.
- Confirm when your next independent BSA/AML review is due, and put every open finding on a tracker with an owner and a date.
- Ask your counsel to review your license position and the notice, audit and termination terms in your program agreement.
Diligence rewards a simple discipline: write down what you do, do what you wrote, and keep the record. Fintechs that build it before the request arrives spend diligence talking about their product. The rest spend it answering follow-ups.
Related: how Ethixera prepares fintechs through sponsor bank readiness and diligence preparation, the wider bank and fintech compliance practice it sits in, and compliance for venture-backed fintech founders.

