Due Diligence, Done Once
By: Paul Schaus
August 11, 2026
Since the FDIC's draft term sheet surfaced, the commentary has split into two camps: this fixes everything, and this fixes nothing. Both camps are debating whether it will work. That is the wrong question. Standards bodies are not neutral plumbing — they encode the priorities of whoever writes them. The right question is who will govern this one, and that question is being answered over the next several months, in rooms most community banks are not in. Yet.
Since the draft term sheet surfaced, it has been a hot topic in bank technology circles, and the takes have arrived on schedule. Breathless on one side, dismissive on the other. Will a voluntary certification body reduce due diligence burden? Will banks trust it? Is it regulatory overreach or regulatory retreat? All interesting. All premature. Because the proposal on the table — a standards development organization for bank third-party risk, working name BISDO, paired with a certification program called RAMP — is not yet a program. It is a constitution with the important articles left blank. And in standard-setting, the blanks are the product.
Here is what three decades around bank technology has taught me about standards: they are never neutral. The card networks' operating rules encode the networks' economics. NACHA's rules reflect the institutions that sat on its committees. Core vendor "integration standards" have a way of standardizing exactly what the vendor already built. None of this is scandal — it is how standards work. The parties at the table write rules that fit the businesses they run, usually without malice and always without apology.
Now look at who is already at this table. The FDIC intends to seed-fund the body, and the working group spans the American Bankers Association, ICBA, the Bank Policy Institute, the fintech trade associations, and the Coalition for Financial Ecosystem Standards, the body the fintech side stood up in 2024 to write standards for itself, qualified assessor firms and all. Every one of those organizations is competent and every one has a constituency. The constituency the program is being justified in the name of — the community bank that cannot afford to vet a novel vendor — is represented at that table only by proxy.
This is not the industry's first attempt at shared vendor assurance, and history has one consistent lesson: each attempt served whoever built it. The largest banks solved their own duplication problem years ago with shared assessment utilities built by and for the largest banks; none of it ever reached a community bank. The fintechs, facing repetitive bank-by-bank diligence requests, organized CFES to standardize their own evidence packages. The regulators, for their part, kept handing the individual bank a bigger job: the 2021 interagency guide taught community banks how to vet fintechs one at a time, and the 2023 third-party guidance confirmed each bank owns the whole risk, no matter how many other banks vetted the same vendor last quarter. Then Synapse collapsed, customer funds froze, and the FDIC's 2024 request for information on bank-fintech arrangements made the whole architecture a live policy question.
What the term sheet adds is supervisory recognition — examiners prepared to accept a certification as onboarding evidence. That is the ingredient that turns a certificate from a marketing document into infrastructure. It is also the ingredient that raises the stakes on governance, because a certificate examiners accept is a certificate worth controlling.
And do not mistake this for one agency freelancing. The FDIC is holding the pen and reportedly writing the seed check, but the term sheet is drafted for every banking agency: its recognition provisions bind "federal banking agencies and state agency examiners," plural, and the OCC is reportedly days from joining. There is history here, too. A version of this idea was floated at the FDIC back in 2020; the chair who floated it later served as the Synapse bankruptcy trustee, personally tallying the missing money a standard like this might have caught. This is one agency moving first, not one agency moving alone — which is exactly how Washington builds anything quickly.
Read the term sheet's own list of open decisions and you are reading the real agenda for the next several months: board composition and membership model. Funding — member dues, assessor fees, certification fees. Initial standards scope. Assessor qualification and oversight. Renewal cycles and what forces a refresh. Registry design.
Run each blank through the who-writes-it test. A funding model calibrated to what incumbent vendors can afford becomes a moat against the emerging providers community banks most need. An initial scope defined by the largest institutions will standardize the diligence questions their stacks raise, not yours. Renewal rules written loosely let a certificate outlive the facts beneath it — and in a vendor market where ownership changes hands as often as this one does, a certificate frozen at signing date answers last year's question. Assessor rules without teeth turn the whole apparatus into a fee-for-stamp business. None of these outcomes require bad faith. They only require the affected parties to be absent while the defaults are chosen.
Which brings me to the part of this story I care most about. Federal policymaking has a provision built for exactly this moment: the request for comment. It is the one mechanism through which a bank's operating reality enters the record with the same formal standing as a trade association's position paper. And it is chronically underused by the institutions with the most at stake. Look at the comment docket for the FDIC's 2024 bank-fintech RFI: seventy-two comments were filed — trade associations, fintech companies from Stripe to Chime, consumer groups, law firms — and exactly three banks. All three were fintech sponsor banks whose partnership programs were the subject of the inquiry.
The term sheet is in preliminary consultation now, which means the informal window is already open: your trade associations are forming positions this quarter, and they form them from what members tell them. Be specific with yours. Then, when the formal comment opportunity comes — and with the FDIC funding the launch, it will come — file your own letter. It does not need to be lawyered. Two pages will do: which vendor categories you would rely on a certification for, what it should cost a small provider to participate, what should force a recertification, and how many governance seats community institutions should hold. If the request for comment is on the table, use it — the provision only protects the banks that invoke it.
We will be filing, and we will publish what we file. Because the alternative is the oldest story in bank technology: infrastructure built in your name, governed by someone else, invoiced to you. The FDIC has put a pen on the table and asked the industry to help write the rules of the next decade of bank-fintech partnership. In an earlier piece I argued that the regulators' new AI framework handed the pen back to the bank. This is the same pen. Pick it up.
CCG Catalyst advises community and regional banks, credit unions, and fintech companies on vendor evaluation, third-party risk, and technology strategy. If your institution wants help shaping a comment letter on the FDIC's proposed standards body — or a view on what certification should and should not change in your own diligence — reach out to our team at www.ccgcatalyst.com, or see the full library at CCG Insights.
See our latest announcement: CCG Catalyst's Paul Schaus Named a 2026 Top Consultant by Consulting Magazine
By: Paul Schaus | Founder & Managing Partner, CCG Catalyst Consulting
Disclaimer: The views expressed in this article represent the perspective of CCG Catalyst Consulting based on our direct experience advising financial institutions. This commentary is intended to stimulate industry discussion and does not constitute legal, accounting, or regulatory advice.