What is banking-as-a-service, and who is actually the bank?
The app has your money. The app is not a bank. Somewhere behind it, a bank you have never heard of is the one holding it.
Three brands, one balance, and only one of them is regulated.
What is actually being rented
Three things, and it helps to separate them because they can be bought from different places.
The licence. Only a licensed institution may hold customer deposits, issue cards under a scheme licence, or access payment rails directly. This is the piece that cannot be built, only borrowed.
The infrastructure. Ledgers, card issuing, payment processing, statements. A company could build this and many do, but it is slow.
The compliance perimeter. The bank remains responsible to its regulator for what happens on its licence, which means the partner's onboarding, monitoring and sanctions screening are, in a regulatory sense, the bank's problem.
Why companies do it
Because embedding an account into a product that people already use is a better distribution story than persuading people to open an account.
A payroll company that also holds the account gets the deposit. A marketplace that also issues the card sees the spending. Software companies discovered that payments attached to a workflow convert far better than payments sold on their own, and banking attached to a workflow is the same argument one layer deeper.
The economics are interest income, interchange, and the fact that a customer whose money sits with you does not leave casually.
What breaks, and it has broken
The failure mode is the middle layer. When a middleware provider sits between the app and the bank, it often keeps the ledger that says which customer owns what, while the bank holds the pooled funds. If those two records ever disagree, the money exists but nobody can prove whose it is.
That is not hypothetical. When a large middleware provider collapsed in 2024, hundreds of thousands of end customers were locked out of their own balances for months, because the reconciliation between the ledgers and the pooled accounts did not hold up. Regulators responded by pushing banks to keep their own records of individual ownership rather than trusting a partner's.
The lesson for anyone building on this model is unglamorous and specific. Ask who holds the record of ownership, ask how often it is reconciled against the bank's own books, and ask what happens to your customers if the layer in the middle stops answering the phone.
A restaurant with a licensed kitchen lets three delivery brands sell food under their own names. The brands take the orders, design the packaging and own the customer. When somebody gets ill, the health inspector visits the kitchen. And if the brand's order book and the kitchen's tickets ever disagree, nobody can prove which meal was whose.
The regulatory direction
Supervisors have moved from treating this as a bank's commercial choice to treating it as a bank's supervisory responsibility. A bank renting its licence is expected to oversee the partner as an extension of itself, which raises the cost of the model and reduces the number of banks willing to offer it.
The practical consequence for builders is that partner selection has become a due diligence exercise in both directions. The bank is assessing you. You should be assessing whether the bank has the risk function to survive holding you.
Where you meet it
Every app that offers you an account and is not a bank. Every card issued by a company that clearly does not have branches. Every set of terms with a line naming an institution you have never heard of as the actual holder of your money.
Building this? A second pair of eyes on the architecture is what the advisory is for. →
