Financial services generate a massive share of revenue for software platforms adopting this model. Shopify's merchant solutions revenue, driven by embedded payments and lending, rose from $1.7 billion in Q1 2025 to $2.4 billion in Q1 2026 [4]. Advertisers utilizing embedded point-of-sale financing partners saw an average 39% increase in checkout conversions [5].
[1] 2 The Three-Layer Accountability Stack
The Banking as a Service (BaaS) architecture isolates non-bank platforms from regulatory liability, concentrating systemic risk at the sponsor bank level. The ecosystem relies on three distinct layers operating in tandem [4, 6]. First, the non-bank platform (e.g., an e-commerce site or HR software) controls the user interface and holds the primary customer relationship [6]. Second, the BaaS middleware provider manages API connectivity, internal sub-ledgering, and compliance automation [4, 6]. Third, the sponsor bank—typically a state or federally chartered institution—supplies the banking charter, originates the loans, holds deposit insurance, and ultimately absorbs the legal compliance obligations [4, 6, 7].
[2] Corporate Structure and Charter Arbitrage
[2] 1 The Utah Industrial Loan Company (ILC) Exemption
The Industrial Loan Company (ILC) charter offers commercial firms a direct backdoor to federal deposit insurance without triggering Federal Reserve supervision. Crafted via the Competitive Equality Banking Act of 1987 (CEBA), the ILC exemption explicitly excludes these institutions from the definition of a "bank" under the Bank Holding Company (BHC) Act [8, 9]. Utah processes the majority of these state-level charters, enabling technology and e-commerce conglomerates to issue loans and hold federally insured deposits [8, 10].
This structure allows firms to operate full-service banks without subjecting their parent companies to consolidated capital requirements or the traditional regulatory barrier separating banking from commerce [8, 10]. For Utah ILCs exceeding $100 million in assets, the authorization of Negotiable Order of Withdrawal (NOW) accounts renders them functionally indistinguishable from traditional commercial banks [8]. Following the expiration of a Dodd-Frank moratorium in 2013, fintechs like Square and Nelnet successfully secured ILC approvals in 2020, breaking a 12-year freeze [9, 10]. In 2021, Rakuten resubmitted its application for a Utah ILC, signaling the intent of massive e-commerce conglomerates to permanently embed retail banking into their core operations [9].
[2] 2 Internal BHC Arbitrage and the Equity Multiplier
Regulatory arbitrage also occurs internally within traditional bank structures. Approximately one in four dollars of U.S. non-bank financial intermediation takes place inside Bank Holding Companies (BHCs) through non-bank subsidiaries operating alongside regulated commercial banks [11]. These non-bank affiliates face substantially lighter capital regulations and lack access to insured deposits, forcing them to rely heavily on equity funding [11].
The median non-bank subsidiary maintains an equity-to-asset ratio of 69% [11]. This dynamic creates an "equity multiplier" where the median non-bank subsidiary accounts for only 2.5% of consolidated BHC assets but holds 16% of the organization's consolidated equity [11]. Following the implementation of binding Basel III capital minimums in 2015, BHCs increasingly utilized intra-company equity transfers to shift activity into these less-regulated subsidiaries to alleviate capital constraints on their commercial bank arms [11].
[2] 3 State Charter Shopping: South Dakota vs. Delaware Parity
Non-bank entities offering embedded wealth management and trust services weaponize state-level charter differences to maximize privacy and operational parity. South Dakota state-chartered banks operate under a broad parity statute (SDCL 51A-2-14.1) that automatically grants them any power conferred upon federally chartered banks, provided the state director finds it maintains competitive fairness [12]. This allows state-chartered entities to operate on a multi-state basis with consistency in interest rates and lending limits, neutralizing the primary advantage of a federal charter [12].
South Dakota law completely seals trust records from public court dockets in perpetuity, whereas Delaware limits sealing to three years subject to judicial review [13]. This absolute privacy guarantee, combined with zero state income tax and the explicit statutory authorization of "discretionary beneficiary" language, makes South Dakota the preferred domicile for embedded trust structures seeking maximum asset protection against creditor judgments [13, 14].
[2] 4 The De Novo Threat to Sponsor Banks
The sponsor bank economic model contains a fatal strategic flaw: successful fintech partners eventually outgrow the need for sponsorship. Regional banks rely heavily on the deposit volume and interchange fee sharing generated by BaaS programs, with some sponsor banks attributing up to 51% of their total revenue and deposits to these partnerships [15].
As fintech platforms scale their transaction volumes and customer bases, they transition from partners to direct competitors. Supported by a regulatory environment increasingly open to granting national trust charters and full commercial licenses, mature fintechs bypass sponsor banks by securing their own de novo banking licenses and direct FDIC insurance [15]. Varo Money secured a national bank charter after a multi-year effort, and Revolut applied for FDIC-insured deposits to hold checking and savings accounts directly on its own balance sheet [10, 15]. This transition strips the regional sponsor bank of its primary deposit pool and transaction fee revenue, revealing the inherent instability of relying on embedded finance middleware for core funding [15].
[3] Definitional Arbitrage in Credit Markets
[3] 1 "Buy Now, Pay Later" (BNPL) Evasion of TILA
The "Buy Now, Pay Later" (BNPL) industry bypasses foundational consumer credit laws through structural design. By limiting repayment to four interest-free installments, the standard "Pay-in-4" BNPL product actively evades the Truth in Lending Act (TILA), which historically triggers regulatory protection only for credit extending beyond four payments or imposing a finance charge [16, 17]. The global BNPL market reached approximately $560.1 billion in Gross Merchandise Volume (GMV) in 2025, operating largely outside standard credit underwriting guardrails [18].
In May 2024, the Consumer Financial Protection Bureau (CFPB) intervened by issuing an interpretive rule classifying BNPL digital user accounts as "credit cards" under Regulation Z Subpart B [16, 19]. This designation forces BNPL lenders to investigate consumer disputes, issue refunds for returned items, and provide periodic billing statements [16, 20]. The CFPB deliberately excluded BNPL from Subpart G of Regulation Z, exempting providers from mandatory ability-to-repay (ATR) assessments and allowing rapid, frictionless checkout financing to persist [19, 20].
[3] 2 Consumer Default Masking and Credit Reporting Gaps
BNPL providers systematically avoid reporting loan performance to major credit bureaus, creating systemic blind spots in retail leverage. While BNPL charge-off rates appear low at 1.8% to 2.0%, between 34% and 41% of users report making at least one late payment, highlighting a massive gap between short-term delinquency and actual recognized defaults [18].
Consumers utilizing BNPL carry an average of $871 more in conventional credit card debt and $453 more in personal loans compared to non-users [21]. As BNPL providers slowly introduce selective credit reporting to mitigate their own risk, consumer behavior shifts immediately. One in six users reduced their BNPL activity in 2026 specifically to avoid credit score impacts, and 28% of users who missed a payment reported subsequent credit damage [5]. In 2026, Millennials overtook Gen Z as the heaviest BNPL users, with 76% adoption, and 21% of this cohort now make three or more BNPL purchases monthly [5].
[3] 3 Earned Wage Access (EWA) and the Non-Credit Designation
Earned Wage Access (EWA) providers segment the market into employer-integrated and direct-to-consumer (DTC) models to sidestep usury laws. The employer-integrated EWA market grew from $3.2 billion in 2018 to $22.8 billion in 2022, prompting severe regulatory debate over its classification as a loan [22]. A December 2025 CFPB advisory opinion formally declared that employer-partnered EWA—where advances do not exceed accrued wages, carry no legal recourse for non-repayment, and involve no credit underwriting—does not constitute consumer credit under TILA [23]. This ruling nullified a 2024 proposed interpretive rule that sought to treat both employer-integrated and DTC EWA models as debt subject to finance charge disclosures [22, 23].
State legislatures address this federal vacuum with conflicting frameworks, enabling severe jurisdictional arbitrage.
| State | EWA Classification | Licensing Requirement | Key Consumer Protections |
| Connecticut | Small Loan (Credit) | Licensed small loan lender | Advances capped at $750; restricted to once per pay period; debt collection prohibited [24]. |
| California | Loan (Credit) | Licensed lender | Subject to state usury caps and consumer lending laws [22, 23]. |
| Missouri | Non-Credit | Annual registration ($1,000 fee) | No requirement for a free tier; tipping allowed; debt collection prohibited [24]. |
| Arkansas | Finance Product (Non-Credit) | None | Mandatory no-cost option; default tip must be $0; credit card repayment banned [24]. |
| Nevada/Utah | Non-Credit | State registration | Exempt from standard lending usury caps [22]. |
This state-by-state patchwork allows payroll service providers to deploy non-recourse EWA products in states like Missouri and Utah entirely outside the boundaries of interest rate caps, while forcing them to adhere to strict small-loan underwriting in Connecticut.
[4] Regulatory Engineering in Insurance
[4] 1 Group Policies and the IDD Ancillary Exemption
Embedded insurance platforms bypass individual distribution licensing requirements by structuring products as group policies. The non-bank platform (e.g., a travel booking site or ticketing app) acts as the single master policyholder, enrolling its retail customers merely as beneficiaries who accept existing terms [25, 26]. This eliminates the need for the platform to secure a brokerage license.
Within the European Union, the Insurance Distribution Directive (IDD) explicitly exempts "ancillary insurance intermediaries" from licensing if the insurance is complementary to the core good or service [26]. To qualify for this exemption, the policy must cover breakdown, loss, or non-use of the core service, and the annual premium must not exceed €600 [26]. If the embedded insurance product fails these criteria, cross-border deployment requires a formal distribution license. However, passporting rights within the European Economic Area (EEA) allow a license in one member state to legally cover distribution across the entire bloc [27].
[4] 2 Risk Retention Groups (RRGs) and Single-State Domiciling
In the United States, embedded insurance providers leverage the Liability Risk Retention Act (LRRA) of 1986 to consolidate regulatory oversight. Risk Retention Groups (RRGs) are member-owned liability insurance companies that domicile and receive regulatory scrutiny in a single state, but are federally mandated to operate across all 50 states simply by filing registrations [28].
This framework eliminates the requirement for traditional insurance companies to secure and maintain distinct licenses in every state of operation, drastically lowering compliance costs [28]. RRGs are statutorily restricted to providing liability insurance and can only issue policies to members facing similar industry risks, making them the primary vehicle for embedded liability coverage in niche platform ecosystems (e.g., gig economy platforms embedding driver liability) [28].
[4] 3 Cross-Border Fragmentation and Solvency II Evasion
Despite efforts to harmonize global insurance standards, deep fragmentation allows embedded insurance providers to arbitrage reporting requirements. Regulatory regimes like the EU's Solvency II and the International Association of Insurance Supervisors' Insurance Capital Standard (ICS) apply capital standards inconsistently [29]. European insurers frequently engage in "shadow reinsurance"—ceding risks to less regulated, unrated off-balance-sheet entities outside the EU to artificially lower their capital requirements and cost of capital under Solvency II [30]. The prescriptive, accounting-based regulation of the U.S. contrasts sharply with the principles-based Solvency II framework, creating compliance duplication but also allowing agile insurtechs to domicile risk in the most favorable jurisdictions [31].
[5] Transatlantic Divergence in Open Banking Standards
[5] 1 The EU Mandate: PSD3, FiDA, and Interoperability
The European Union regulates embedded finance by mandating interoperability through centralized infrastructure. The incoming Financial Data Access (FiDA) regulation explicitly broadens mandatory data sharing beyond checking accounts to include mortgages, pensions, savings, and non-life insurance products [32, 33].
Combined with the Third Payment Services Directive (PSD3), the EU framework legally enshrines "write" access, enabling third-party platforms to initiate payments directly from bank accounts rather than relying solely on card networks [34, 35]. This regulatory harmonization dramatically lowered API integration costs, driving European embedded finance volumes to expand three times faster than direct lending over the past decade [32, 36]. By 2030, embedded channels are projected to drive 20% to 25% of all retail and SME banking sales in Europe [32, 36].
[5] 2 UK Deregulation and Pro-Growth Stance
While the EU focuses on the FiDA framework, the United Kingdom aggressively pursues a pro-growth deregulation strategy to attract financial technology. In 2026, the UK replaced the onshored EU Prospectus Regulation with a new domestic framework separating public offers from trading admissions [37].
The Financial Conduct Authority (FCA) implemented the Private Intermittent Securities and Capital Exchange System (PISCES) to allow UK markets to run trading venues specifically for private company shares, actively bypassing EU regulatory models to compete directly with US private markets [38]. The FCA's open finance roadmap extends consent-based data sharing to SME lending, investments, and pensions, supporting 145 active third-party providers and 17 million active users [6].
[5] 3 US Gridlock: Section 1033 Injunctions and Data Fee Disputes
The U.S. approach to open banking is narrow, market-led, and currently stalled in systemic litigation. Section 1033 of the Dodd-Frank Act grants consumers the right to access their financial data, but the CFPB's 2024 implementing rule restricted this obligation strictly to consumer credit cards and Regulation E accounts [33, 39]. Unlike the EU's FiDA, Section 1033 focuses exclusively on "read-only" access and does not mandate "write" access for payment initiation [35].
The CFPB's phased compliance schedule was slated to begin in April 2026 but was suspended after a federal court in Kentucky enjoined the agency from enforcing the rule [40, 41]. The litigation, driven by banking trade groups including the Bank Policy Institute, centers on the rule's initial prohibition against banks charging data aggregators and fintechs for API access [40, 42, 43]. Banks argue that building and maintaining secure API infrastructure imposes substantial costs that must be recovered [42, 43].
In response to the injunction, the CFPB initiated a new rulemaking process in mid-2026 to evaluate permitting data-access fees after a specific threshold of free requests is met [43]. While the federal rule remains in limbo, states like New York have advanced "Mini-1033" legislation to mandate data sharing, establish developer interfaces, and prohibit access fees at the state level [39].
[6] Outsourced Compliance and Sponsor Bank Risk
[6] 1 The Synapse Collapse and FBO Account Fragility
Banking as a Service relies on complex ledger synchronization that, when broken, triggers catastrophic consumer harm. The fragility of outsourced ledger models materialized in April 2024 with the bankruptcy of middleware provider Synapse. The collapse severed the data connection between platform interfaces and partner banks, freezing over $265 million in consumer funds for 100,000 customers [6, 44]. Partner banks were unable to process withdrawals because they lacked accurate customer balance records, exposing a fundamental mismatch between the middleware's internal ledgers and the actual funds held in the bank's "For Benefit Of" (FBO) custodial accounts [6, 45].
[6] 2 Retaliatory Enforcement from the FDIC and OCC
Regulators responded to the Synapse failure by aggressively targeting the charter holders, effectively forcing banks to act as proxy regulators. Since the beginning of 2024, 25.6% of all formal Federal Deposit Insurance Corporation (FDIC) enforcement actions have been directed at sponsor banks engaged in embedded finance partnerships [7, 46]. The Office of the Comptroller of the Currency (OCC) mirrored this trend, directing over 20% of its enforcement actions at sponsor banks [7].
The FDIC introduced stringent new rules for Insured Depository Institutions (IDIs) operating FBO accounts. Sponsor banks are now explicitly prohibited from delegating deposit accounting responsibility to middleware providers [45, 46]. The regulation mandates that banks maintain continuous internal visibility into third-party ledgers, execute daily reconciliations to track beneficial owners, and conduct independent audits [45].
The financial toll of these enforcement actions is severe. 75% of sponsor banks report losing $100,000 or more strictly to compliance violations within their embedded finance programs [7]. Confronted with the asymmetry between the revenue generated by fintech partnerships and the regulatory liability they impose, 29% of current sponsor banks are actively considering shutting down or scaling back their embedded finance operations [7, 47].
[7] Shadow Banking and Capital Migration
[7] 1 Exploiting the Regulatory Perimeter
Embedded finance accelerates the migration of traditional banking activities into the shadow banking sector. Shadow banks—institutions performing bank-like maturity transformation without a banking license—rely on short-term funding like commercial paper or repurchase agreements (repos) to finance long-term assets [48, 49]. Because these non-bank platforms lack access to the Federal Reserve's discount window and do not hold insured deposits, they operate with significantly higher leverage and lack formal liquidity support during market stress [48, 49].
The European Systemic Risk Board (ESRB) identified excessive leverage in non-bank financial intermediaries (NBFIs) as a critical vulnerability. As of 2023, Liability-Driven Investment (LDI) funds exhibited average gross leverage ratios five times their Net Asset Value (NAV), while highly leveraged Alternative Investment Funds (AIFs) utilize synthetic leverage to exploit pricing discrepancies [50]. Undertakings for Collective Investment in Transferable Securities (UCITS) using absolute value at risk approaches allow for leverage levels that frequently exceed those of hedge funds [50].
[7] 2 The Basel III Endgame Catalyst
Tightening capital regulations on traditional banks directly fuels the expansion of this unregulated sector. The U.S. banking agencies' March 2026 proposals for the Basel III Endgame alter how banks calculate and manage risk-weighted assets, fundamentally changing the economics of traditional lending [51]. As capital requirements increase, traditional banks are incentivized to offload riskier loans to non-bank intermediaries [52].
Macroprudential research indicates that the optimal capital requirement for licensed banks must actually be set lower when shadow banking is present than it would be in a perfectly enforced system [48, 53]. Over-regulation simply triggers regulatory arbitrage, shifting systemic risk into opaque, highly leveraged vehicles outside the supervisory perimeter [48]. Furthermore, when banks possess superior information about asset risk, stringent capital requirements force them to refinance their safest assets in the shadow banking sector where their private information functions as better collateral, leaving unsecured traditional creditors with lower-quality collateral [48].
[8] Competitive Implications for Incumbent Banks
[8] 1 Asymmetric Customer Acquisition Costs (CAC)
Embedded finance creates an insurmountable structural cost disadvantage for traditional retail banks. In the European small and medium enterprise (SME) lending market, acquiring a qualified lead through traditional banking channels is 15 to 20 times more expensive than acquiring the identical lead through an embedded finance partnership within an ERP or procurement platform [32, 36].
Software platforms embed accounting APIs to access real-time cash flow patterns, ledger entries, and payment histories. This enables AI underwriting systems to evaluate creditworthiness instantly, reducing default rates by over 20% while issuing credit at the exact moment of commercial need [2]. The EU's AI Act requires "explainability" for these automated credit decisions, forcing AI systems to provide clear reasons for rejections [2].
[8] 2 Margin Compression and Ecosystem Lock-in
Traditional banks, burdened by legacy branch networks and standalone digital applications, are relegated to the role of infrastructure providers. They capture only wholesale margins, while non-bank platforms capture the high-margin retail relationship, cross-sell opportunities, and the associated data exhaust [54]. For merchants, embedding finance directly increases sales conversions, basket sizes, and customer lifetime value by 2 to 5 times [34, 36]. By failing to own the point of commercial intent, traditional banks lose the ability to cross-subsidize services, permanently compressing their Net Interest Margin (NIM) and transforming retail banking from a destination into an invisible utility [54, 55].
Sources:
- precedenceresearch.com
- openledger.com
- mordorintelligence.com
- techfunnel.com
- partnercentric.com
- fintech.global
- ascentregtech.com
- fdic.gov
- bpi.com
- americanbanker.com
- newyorkfed.org
- sd.gov
- bankerstrust.com
- sterlingtrustees.com
- americanbanker.com
- gtlaw.com
- harvard.edu
- chargeflow.io
- consumerfinance.gov
- stinson.com
- empower.com
- capstonedc.com
- thomsonreuters.com
- americanbanker.com
- hfw.com
- dlapiper.com
- qover.com
- riskretention.org
- lumarpub.com
- naic.org
- casact.org
- marqeta.com
- cepa.org
- fabrick.com
- oliverwyman.com
- mckinsey.com
- aoshearman.com
- traverssmith.com
- consumerfinancemonitor.com
- openbankingtracker.com
- cozen.com
- consumerbankers.com
- pymnts.com
- gminsights.com
- finzly.com
- treasuryprime.com
- prosightfa.org
- harvard.edu
- imf.org
- europa.eu
- pwc.com
- bis.org
- newyorkfed.org
- athenacredxpert.com
- harvard.edu