Whose Ledger Is It, Anyway?

Print Friendly, PDF & Email
CCG Catalyst Commentary

Whose Ledger Is It, Anyway?

August 25, 2026

Whose Ledger Is It, Anyway? — CCG Catalyst

Any US bank that holds another company's customer funds — a payments program, a wealth platform, a payroll processor, an escrow operation — faces two architectural decisions that will matter more than any contract term. Will those funds sit in an omnibus FBO account or in direct accounts on the bank's own infrastructure, and who keeps the ledger that says whose money is whose. Synapse turned the second question from plumbing into policy. But dig into where the answer lives and you find something the industry has not absorbed: the dual ledger every examiner now expects is required by no generally applicable rule at all. The rule that would mandate it was proposed, softened, and shelved, and the brand-new statutory safe harbor that makes these deposits more attractive attaches no recordkeeping condition whatsoever. The expectation is real. The mandate is missing.

The most dangerous system in any bank is the one everybody assumes somebody else is running. I have seen that rule hold through every conversion, every outage, and every post-mortem I have been part of — and in May 2024 the industry got its costliest demonstration yet. The system in question was a ledger. Synapse, the middleware sitting between roughly 100 consumer and business money apps and four banks, filed for bankruptcy holding the only record of which end customer owned what inside the banks' FBO accounts. None of the four banks kept a copy. When access to Synapse's records was cut off, over 100,000 people were locked away from their money, and the trustee, a former FDIC chair, found a shortfall she estimated at $65 to $95 million that has never been fully explained. No bank failed, so deposit insurance was never triggered. The money was not stolen. It was unaccounted for, which turned out to be just as bad.

A definition before we go further, because "fintech" has become a word that means everything and therefore nothing. In this article it means something specific: a nonbank company that opens accounts and gathers customer funds under its own brand, holds those funds at a chartered bank, and keeps the customer-level records on its own system. The industry calls this company a program manager. It might be a neobank or a payments app, but as we will see, it might just as easily be a wealth platform, a payroll processor, or an escrow company that has never once called itself a fintech. The label does not matter. The structure does, and everything that follows applies to the structure.

Two Architectures and One Question

Start with the fork in the road, because the industry talks about it imprecisely. In the FBO model, the program manager's customers share an omnibus account — "Program Bank FBO Customers" on the bank's core — and a subledger somewhere allocates that balance across thousands of beneficial owners. It is capital-efficient, fast to launch, and it is how most of the sponsor banking industry was built. In the direct model, each end customer holds an individual account on the bank's system of record, either the legacy core or, more commonly, a parallel "sidecar" core built for the volume. Every balance is a bank record by construction; there is nothing to reconcile because there is no allocation layer.

Here is the point the architecture debate misses: the FBO-versus-direct choice is really a proxy for a single question — whose ledger is the record? A direct model answers it structurally. An FBO model leaves it open, and Synapse is what happens when the answer defaults to "the program manager's." The fix the industry converged on has a name that did not exist in polite conversation three years ago: the dual ledger — sometimes called twin ledger, synthetic ledger, sidecar. It is a bank-controlled record that mirrors, beneficial owner by beneficial owner, everything inside the omnibus account, reconciled daily against both the core and the program manager's books. It makes an FBO program behave, from the bank's chair, like a direct one.

Pass-through deposit insurance is the legal reason for this to matter and not just the operational one. Under the FDIC's records rules, the custodial capacity must show in the bank's own account titling, but the details of who owns what may live in records kept by the bank or by a third party. Coverage can survive on program-manager-held records in theory. In practice, a bank failure without those records means no prompt insurance determination, and a program manager's failure means insurance never triggers at all while customers stand locked out. The records rule permits the exact gap that swallowed Synapse's customers.

This Was Never a Fintech Problem

Now apply the definition above and notice how far past the neobanks it reaches. The company holding client money at your bank rarely looks like a fintech at all. Strip away the BaaS vocabulary and the structure — somebody else's customers, commingled in an account at your bank, with the ownership detail on somebody else's ledger — describes half of commercial banking.

Wealth management runs on it: RIA cash programs place advisory client cash across partner banks through platforms like Flourish, StoneCastle, and MaxMyInterest, while broker-dealer sweep programs move client balances through administrators like IntraFi and R&T Deposit Solutions. In every case, the bank sees an omnibus balance and the program's ledger knows the clients. Title and escrow companies hold closing funds the same way; 1031 qualified intermediaries hold exchange proceeds; benefits administrators hold HSA and COBRA balances; property managers hold rents and security deposits under state trust-account rules; claims administrators hold settlement funds; insurance agencies hold premium trust accounts. And the largest example hides in plain sight — mortgage servicers' principal, interest, tax, and escrow custodial accounts, billions parked at banks, with the beneficial detail living in the servicer's system, not the bank's.

And the entity on the other side of the account can even be another bank. Foreign banks fit the program-manager definition twice over. The modern version is explicit: Monzo, a chartered UK bank, ran its US launch through Sutton Bank exactly the way a neobank would; Wise's US dollar accounts sit at Community Federal Savings Bank; Revolut entered through a US partner bank while its own charter application waits at the OCC. A regulated foreign bank, in its US posture, is simply a program manager with a home-country license. The older version is a century old and never gets named in this conversation: correspondent and payable-through accounts, where a foreign bank's customers transact through its omnibus account at a US institution. The foreign bank's ledger knows the customers, the US bank sees one balance. That is the FBO structure with a passport — it is the highest-risk recordkeeping gap in banking, and it is precisely what generated CBW Bank's $20 million BSA penalty: roughly thirty foreign financial institutions' customers moving $27 billion a year through a Kansas bank whose visibility into the underlying parties failed. The PATRIOT Act has required due diligence on exactly this structure since 2001, which makes correspondent banking the one version of the ledger problem regulators wrote rules for, decades before anyone said fintech.

Every one of these is the Synapse structure with a different logo, and most of them predate the word fintech by decades. The difference is maturity — the older categories grew up with statutory trust-account rules, licensing, and audit regimes that fintech program management never had. But from the bank's chair the control question is identical: if that counterparty fails, can you determine, today, who is owed what? For most banks the honest answer varies wildly by category, and nobody has inventoried it. That inventory — every deposit relationship that is really somebody else's client money — is the first assignment this article should generate.

Can the Bank and Fintech Share One Ledger?

This is the question I get most often when this topic comes up, usually framed exactly this way: if the bank and the program manager both run on the same platform, the same embedded-banking stack, is the same ledger allowed? Let me state the answer plainly: it is feasible. Nothing in the rules prohibits it. The FDIC's own proposed rule — the closest thing this field has to a written standard — expressly contemplated the bank relying on records maintained by a third party, provided the bank's access is direct, continuous, and unrestricted, responsibilities are contractually assigned, the records are independently validated, and the bank holds backup data access that survives the third party's insolvency. The modern platforms are built to that pattern; Treasury Prime's bank-direct model sells the embedded-banking stack to the bank itself, with dedicated per-program FBOs and real-time reconciliation, so the bank and its program managers work from one system with the bank as the customer of record. Feasible, permitted, and in production today.

But as with everything in this business, the answer comes down to the detail and the controls, and the options are not equal. Think of them as a ladder. At the bottom, one shared ledger that the bank reconciles to itself. You can do it — tie the subledger to the omnibus balance and check that it sums — but a ledger confirming its own arithmetic is the weakest control in the stack, and it is roughly what the Synapse banks had. A step up would be two instances, when the bank runs its own copy of the ledger, reconciled daily against the program manager's. Genuinely better; now there is an independent record. But if both instances come from the same provider, the concentration has not gone away — one vendor's failure, defect, or outage still takes both sides of the control down together. Which is why, from a control perspective, best practice is to separate not just the ledger but the provider: the bank's record is kept on different software, under a different contract, with a different failure mode than the system it is checking. Vendor diversity is not a procurement preference here. It is the control.

Another question I get: could the bank simply write its own twin ledger? Yes, it is not exotic software. But why would you? A homegrown ledger is shelfware the day it goes live — one internal customer, no product roadmap, no vendor investment, and a maintenance obligation that outlives the developer who built it. This is a category the market now serves well; our Spotlight tomorrow maps it, and the economics of buying a maintained bank-side ledger against building an orphan are not close.

My recommendation — shared is feasible, separate is better, separate provider is best, and build-your-own is a trap. Where a bank lands on that ladder should be a deliberate decision, documented for the examiner, not the residue of whatever the program's launch timeline allowed.

The Rule That Never Happened

You would assume the response was a regulation. Almost.

In September 2024 the FDIC proposed a custodial recordkeeping rule that reads like a specification for the dual ledger: banks must maintain the beneficial-owner records themselves or hold "direct, continuous, and unrestricted access" to them; reconcile daily, close of business; keep the data in a standardized file format; obtain periodic independent validation; and certify compliance annually at the top of the house. The agency put the cost at roughly $220,000 per bank to stand up.

Then nothing. The proposal was not finalized. It was also, contrary to what much of the industry believes, never withdrawn — the FDIC's March 2025 housecleaning killed four other proposals and left this one untouched. It sits in the regulatory agenda as a "long-term action," final rule "to be determined." Chairman Hill voted for it as Vice Chairman, saying the Synapse problems "could have been identified much sooner if the partner banks maintained better records," while arguing it should reach the few dozen banks concentrated in this business rather than a thousand. Since taking the chair he has said nothing about its fate.

So where does the requirement live? In pieces. The July 2024 interagency statement names "lack of access to records" a core risk — guidance, not rule. The consent orders install it bank by bank: Evolve's order requires ledger and sub-ledger responsibilities "clearly defined, established, and maintained, including in the event of a material business disruption"; Thread's requires beneficial ownership documented and maintained. And this July, Congress passed the strongest incentive yet to gather custodial deposits — the ROAD to Housing Act excludes them from brokered-deposit treatment up to 20 percent of liabilities for healthy banks under $10 billion and attached no recordkeeping condition of any kind. I read the enrolled text expecting to find the ledger requirement relocated there. It is not.

Put plainly: the deposits just got more attractive by statute, the control that makes them safe is mandated nowhere, and the enforcement record shows what happens to banks that notice the first fact but not the second.

What the Market Did About It

Markets fill vacuums faster than agencies do, and this one is filling visibly. The sponsor bank population grew through the reckoning, roughly 142 banks to 156 during 2025, but it grew disciplined: the new entrants run bank-controlled infrastructure, and several cap program deposits near 20 percent of liabilities, a number that now conveniently matches the statute. The middleware repositioned itself as bank software, selling the stack to the bank instead of around it. And in the last ten months the core vendors have told you where they think this is going, with their checkbooks. Jack Henry bought Victor, the virtual-account platform built inside sponsor bank MVB. CSI bought Qolo, weeks after its KeyBank and Huntington partnerships. Synctera bought Cable, the automated control-testing platform. An entire vendor category — bank-side subledgers, virtual account management, sidecar cores, FBO-scale reconciliation — has formed around a rule that never happened.

That tells you something regulators' silence does not: the dual ledger is becoming the price of admission commercially, whatever the Federal Register says.

What I Would Do

If your bank holds program funds, fintech or otherwise, or wants the custodial deposits the new safe harbor just blessed, three moves follow from all of this.

Build to the shelved rule voluntarily. It is the only written specification in existence, everything in it is what examiners now ask for, and its own cost estimate is a rounding error against one consent order. Bank-held or continuously accessible beneficial-owner records, daily reconciliation, independent validation, an insolvency playbook per program manager. If the rule ever wakes up, you are already compliant. If it never does, you have the thing it described, which is the thing that matters.

Negotiate rights, not capabilities. Synapse's banks did not lack technology; they lacked entitlements — backup access independent of the middleware, step-in rights, data escrow. The dual ledger is a contract artifact as much as a system, and as the shared-ledger discussion above shows, the entitlements matter more than the copy count.

Treat the safe harbor and the control as one decision. Twenty percent of liabilities in custodial deposits is a genuine franchise opportunity; it is also precisely the concentration at which a ledger failure becomes an existential event. Take both or neither.

Banking has spent two hundred years on a simple premise: the bank's books are the books. Somewhere in the last decade of partnership models, parts of the industry quietly outsourced that premise. The dual ledger is not a new control. It is the oldest one in banking, coming home.

Tomorrow, we publish our Sector Spotlight on dual-ledger and FBO control technology — a verified map of the vendors behind bank-side subledgers, sidecar cores, virtual account management, and program reconciliation, who owns each player, and what to demand in an evaluation. This piece is the why; the Spotlight is the who.


CCG Catalyst advises community and regional banks, credit unions, and fintech companies on sponsor banking, deposit strategy, and vendor evaluation. If your institution is weighing a BaaS program, hardening an existing one, or sizing the custodial deposit opportunity, reach out to our team at www.ccgcatalyst.com, or see the full library at CCG Insights.

See our latest announcement: CCG Catalyst's Paul Schaus Named a 2026 Top Consultant by Consulting Magazine

By: Paul Schaus | Founder & Managing Partner, CCG Catalyst Consulting


Disclaimer: The views expressed in this article represent the perspective of CCG Catalyst Consulting based on our direct experience advising financial institutions. This commentary is intended to stimulate industry discussion and does not constitute legal, accounting, or regulatory advice.

Subscribe to our Insights