Summary
The FDIC is exploring a "Banking Innovation Standards Development Organization" (BISDO) — a voluntary public-private standard-setting body that would develop uniform standards and certify third-party service providers partnering with banks. An independent assessor would evaluate fintech responses to standardized due-diligence questions; passing vendors receive a certificate banks can accept. The aim is to reduce duplication (hundreds of banks asking the same questions of the same vendors), make exams more predictable, and help community banks that lack resources to vet tech providers. It follows heightened scrutiny of bank-fintech and BaaS relationships.
Key Points
- BISDO term sheet circulated among trade groups (dated July 21); two meetings so far
- Independent non-profit standard-setting body + conformity assessment (attestation/certification) program
- Groups: ABA, ICBA, Bank Policy Institute, FTA, American Fintech Council, Consumer Bankers Association, Coalition for Financial Ecosystem Standards
- Certification: provider/solution/controls "assessed once, kept current and used by multiple banks"
- Scope: third-party risk management, governance, cybersecurity/operational resilience, consumer compliance, BSA/AML, complaint management, info security, due diligence, business continuity
- Fully voluntary; compliance NOT a safe harbor (evidence of sound practices only)
- FDIC in preliminary talks with Fed and OCC; neither has officially joined
- Precedents: FDIC 2023 RFI; PCI Security Standards Council; CFPB recognition of FDX
- Open questions: governance, funding, representation, whether effectively mandatory, pace of standards vs technology
- Benefit: lowers cost of vetting partners, expands vendor universe for community banks, more predictable exams
- Risk: could become "another well-intentioned framework on a shelf" if execution/oversight falters