Embedded finance has quietly become the invisible engine behind everyday transactions, powering everything from lending widgets on Shopify dashboards to insurance upsells inside rideshare apps. But as the sector matures, regulators are no longer content to let compliance obligations stay as hidden as the technology itself.
According to AscentAI, every embedded finance arrangement rests on a three-layer accountability structure, and it’s here that compliance disputes and enforcement actions most often originate.
AscentAI recently discussed embedded finance’s next chapter, including growth, regulation, and accountability.
The platform, whether an e-commerce site, HR software or gig economy app, distributes the product and owns the customer relationship.
The BaaS or middleware provider manages API connectivity, ledgering and routing between platform and bank. The sponsor or licensed bank holds the charter and ultimately carries the regulatory obligation for consumer funds.
Fintechs providing middleware are typically treated as third-party technology partners rather than directly regulated entities, but banks partnering with fintechs are expected to oversee their partners’ operational risk, while fintechs must in turn demonstrate compliance maturity to secure those partnerships.
The US illustrates just how complicated this picture has become, with a multi-agency regulatory framework, escalating enforcement through 2024, and a marked policy shift under the Trump administration in 2025. Since the start of 2024, more than a quarter (25.6%) of the FDIC’s formal enforcement actions have targeted sponsor banks in embedded finance partnerships, according to Alloy, while more than one in five OCC enforcement actions have done the same.
The financial toll is significant too: 75% of sponsor banks say they have lost $100,000 or more to compliance violations within their embedded finance partnerships, and 80% report difficulty monitoring multiple fintech partners across jurisdictions. Nearly a third, 29%, are now considering scaling back or shutting down their embedded finance programmes altogether because of mounting compliance pressure.
For compliance teams, the path forward involves real-time monitoring technology and deeper visibility into fintech partners’ risk management, effectively pushing sponsor banks into a “compliance-as-a-service” role. Sponsor banks should benchmark their third-party risk management programmes against the OCC’s 2024 continuous monitoring expectations and interagency joint guidance, and conduct BSA/AML gap analyses wherever FBO accounts are in use.
Fintechs, meanwhile, need to map liability across their entire stack and identify precise obligations at each layer rather than assuming the bank will absorb everything.
The embedded finance firms defining the next decade won’t be the ones with the flashiest APIs. They’ll be the ones that treated compliance as core architecture, not an afterthought.
AscentAI’s full post can be viewed here.
Read the daily FinTech news
Copyright © 2026 FinTech Global









