Castleigh Johnson Advisory

Fintech compliance advisory built by a former Federal Reserve Bank Examiner. Bank Partnership Readiness, Regulatory Health Checks, and Fract...
1 joined
Profile picture
Castleigh JohnsonProfile picture@warywilt·Jun 23

What sponsor banks actually look for in fintech due diligence (and what kills deals)

I spent years reviewing fintech compliance programs as a Federal Reserve Bank Examiner. Here's what actually matters when a sponsor bank's BSA officer sends you that 47-item due diligence checklist.


The three things that kill deals:


1. A BSA/AML program that looks like it was written by a lawyer who's never seen an examination.

Banks don't want theory. They want evidence of a functioning program — a designated BSA officer, a written risk assessment calibrated to your customer base, transaction monitoring with documented tuning rationale, and SAR procedures that someone is actually following. A policy document without operational evidence fails.


2. Vendor management that stops at contract signing.

Your bank partner is now responsible for your third-party risk too. They need to see that you've assessed your critical vendors (KYC provider, payment processor, fraud tool), documented ongoing oversight, and have a plan for when one fails. "We use Stripe and Persona" is not a vendor management program.


3. Incident response that's theoretical.

The bank will ask: what happens when you have a potential OFAC hit at 11pm? If the answer is "we'd figure it out," the deal stalls. You need documented escalation procedures with defined roles and a clear SAR filing path.


What actually moves deals forward:

A compliance program organized the way a BSA officer reviews it — not by topic, but by regulatory obligation. OFAC screening with testing evidence. CDD/EDD with documented risk tiers. A training log proving your team is operationally compliant.


The fintech founders who close sponsor bank deals fastest aren't necessarily the most compliant. They're the most prepared to demonstrate compliance quickly.

Profile picture
Castleigh JohnsonProfile picture@warywilt·Jun 23

What sponsor banks actually look for in fintech due diligence (and what kills deals)

I spent years reviewing fintech compliance programs as a Federal Reserve Bank Examiner. Here's what actually matters when a sponsor bank's BSA officer sends you that 47-item due diligence checklist.


The three things that kill deals:


1. A BSA/AML program that looks like it was written by a lawyer who's never seen an examination.


Banks don't want theory. They want evidence of a functioning program — a designated BSA officer, a written risk assessment calibrated to your customer base, transaction monitoring with documented tuning rationale, and alert/SAR procedures that someone is actually following. A policy document without operational evidence fails.


2. Vendor management that stops at contract signing.


Your bank partner is now responsible for your third-party risk too. They need to see that you've assessed your critical vendors (KYC provider, payment processor, fraud tool), documented ongoing oversight, and have a documented plan for when one of them fails. "We use Stripe and Persona" is not a vendor management program.


3. Incident response that's theoretical.


The bank will ask: what happens when you have a potential OFAC hit at 11pm? If the answer is "we'd figure it out," the deal stalls. You need documented escalation procedures with defined roles and a clear path to SAR filing.


What actually moves deals forward:


A compliance program organized the way a BSA officer reviews it — not by topic chapter, but by regulatory obligation. OFAC screening with testing evidence. CDD/EDD procedures with documented risk tiers. A training log that proves your team isn't just clicking through annual certification.


The fintech founders who close sponsor bank deals fastest aren't necessarily the most compliant. They're the most prepared to demonstrate compliance quickly.


If you're in a sponsor bank conversation and need to know where your gaps are before the bank asks, that's exactly what a Regulatory Health Check is for.