Join our Newsletter — 33% off our NHI Course

What is the difference between a bank charter and a bank-as-a-service partnership?

A bank charter gives an institution the legal authority to hold deposits, extend credit, and operate under direct regulatory supervision. A bank-as-a-service partnership lets a fintech build products on top of a licensed bank’s infrastructure and permissions. The distinction matters because the fintech gains speed, but the bank remains central to regulatory standing and core financial functions.

What a bank charter actually changes

A bank charter is the legal and regulatory foundation for banking activity. It is what allows an institution to accept deposits, make loans, and operate as a regulated bank rather than as a technology company or intermediary. The chartered entity is the party regulators supervise directly, so the core balance-sheet functions, compliance obligations, and prudential controls sit with the bank itself.

That status matters because it defines who owns the regulated activity. When a firm has a charter, it is not just providing software or front-end distribution, it is legally responsible for the underlying banking functions and for meeting the rules that come with them. In practice, the charter is the difference between being a bank and merely partnering with one.

For readers comparing operating models, the key point is that a charter creates standalone authority. It does not remove risk, but it changes where the risk lives, who answers to regulators, and how the institution is expected to manage capital, liquidity, consumer protection, and safety-and-soundness duties.

How a bank-as-a-service partnership works

A bank-as-a-service partnership is an outsourcing and distribution model, not a charter. The fintech typically builds the customer experience, product layer, and workflow, while a licensed bank supplies the regulated rails underneath, such as deposit accounts, payment access, or lending capacity. The fintech can move faster because it does not need to become a bank itself.

That arrangement is useful when speed to market, product iteration, or specialized customer experience matters more than owning the regulated balance sheet. The trade-off is structural dependence: the fintech is tied to the bank’s permissions, compliance posture, risk appetite, and operational continuity. If the bank changes terms, tightens controls, or exits a program, the partnership can change quickly.

For an external view of how regulated financial relationships fit into control expectations, the EBA AML/CFT Guidance illustrates why the regulated institution remains accountable for the banking relationship even when another company owns the customer-facing layer.

Why the distinction matters in practice

The difference is mainly about authority, accountability, and control. A charter means the institution can do the regulated banking work in its own right. A bank-as-a-service partnership means a fintech can offer bank-like products without holding that authority, because the licensed bank remains the regulated counterparty.

That distinction affects product design, compliance ownership, customer disclosures, and operational resilience. It also affects what can be promised to customers. A fintech can market convenience and speed, but it cannot accurately imply that it independently holds the banking powers that belong to the chartered bank.

From a control perspective, the model also changes the security and compliance boundary. The bank must govern the underlying account, transaction, and identity controls, while the fintech must avoid overreaching into activities that should remain under the bank’s supervision. For a broader control lens, the NIST SP 800-53 Rev 5 Security and Privacy Controls and the NIST Cybersecurity Framework 2.0 are useful references for understanding how governance, protection, detection, and recovery responsibilities should be assigned across a regulated partnership.

Risk and Threat Considerations

Bank-as-a-service arrangements create concentration risk, compliance drift risk, and dependency risk. If the sponsoring bank’s controls weaken, the fintech can inherit the operational and regulatory consequences even though it does not hold the charter itself.

Failure mechanism: The partnership can fail when the fintech assumes the bank is handling a control that was never clearly assigned, or when the bank and fintech each believe the other owns customer, transaction, or compliance oversight.

Impact: That can produce control gaps, delayed incident response, customer harm, and forced product shutdowns or migration work if the bank relationship is interrupted or regulators challenge the operating model.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OV-01 — Oversight of External Dependencies Bank-as-a-service is a regulated dependency that needs clear oversight and accountability.
Recommendation — Assign oversight for the bank dependency and review it as a critical external relationship.
NIST SP 800-53 Rev 5 SA-9 — External System Services The partnership relies on a bank-provided service boundary and shared responsibility.
PM-11 — Mission and Business Process Definition The charter versus partnership distinction changes who performs core banking processes.
Recommendation — Define required controls and responsibilities for the bank service in the agreement. Map each banking process to the party that is legally and operationally responsible.
ISO/IEC 27001:2022 A.5.19 — Information security in supplier relationships The fintech-bank model is a supplier relationship with security and control obligations.
A.5.22 — Monitoring, review and change management of supplier services A BaaS model can change quickly if the bank alters terms or controls.
Recommendation — Set supplier security requirements and review them throughout the partnership. Monitor the bank service and reassess control ownership whenever terms change.

Practitioner Guidance

What to verify: Confirm which party owns deposit handling, underwriting, dispute handling, AML monitoring, customer identity decisions, and regulatory reporting. If the answer is “shared,” document the exact handoff points and the escalation path for exceptions.

Decision rule: If the fintech depends on the bank for a core regulated function, treat the bank relationship as a critical dependency, not just a vendor integration. If the fintech wants to control the banking function itself, it needs a charter or a different regulated operating model.

What practitioners underestimate: The commercial layer often moves faster than the regulatory layer. A partnership can scale quickly, but the most important question is whether the operating model still makes sense when a regulator, auditor, or sponsor bank asks who is actually accountable for the banking activity.

Practitioner takeaway: The charter determines who is legally the bank, while bank-as-a-service determines who is building on top of that bank. In practice, the safest operating model is the one where authority, accountability, and control ownership are explicit before the first customer is onboarded.