Skip to content

Compliance

You remain liable to your customers, and the sponsor's exit does not transfer or suspend that. This is the asymmetry at the centre of the BaaS model: the sponsor holds the licence and the regulatory relationship, but your customers have a relationship with your brand and will hold you to it. What determines how badly an offboarding hurts is not the contract's liability clause. It is whether you hold enough of your own data and infrastructure to act without the sponsor.

The immediate operational question is whether you can tell customers where their money is. If balances live only in the sponsor's system and your view is derived from their reporting, you cannot answer that independently at the exact moment it is asked. An independently reconstructable ledger is the difference between a difficult announcement and an impossible one.

The second question is portability of identity. Onboarding records, verification evidence and risk decisions are yours if you orchestrated them, and largely the sponsor's if you used theirs. Re-onboarding an entire customer base at a new sponsor because the KYC evidence is not portable is a business-ending amount of friction, and it is decided years earlier by whether you owned that orchestration.

Notice periods in sponsor agreements are frequently shorter than the time required to integrate a replacement, and that gap is the actual risk. The mitigation is not a longer notice period, which sponsors rarely grant, but a second relationship established before it is needed, or an architecture where the sponsor is behind an interface you own.

None of this is a reason to avoid BaaS. It is a reason to treat sponsor concentration as the operational risk it is, with the same seriousness as a single-region deployment or a single payment provider.

Bring us the hard part.

Forty-five minutes with the people who would actually run the build.