Skip to main content
ExplainerBank SupervisionExplainerAug 17, 2026, 12:04 PM· 5 min read· in opinion

Is the Fed's Sunset of Dedicated Fintech Supervision a Stealth Deregulation of Non-Bank Financial Risk?

In 2025, the Federal Reserve folded its specialized oversight of crypto and fintech partnerships back into its standard supervisory process. While framed as a maturation of the sector, the shift effectively reclassifies novel financial technologies as routine vendor risks.

By Salma Barakat

Regulatory Traditionalists 40%Fintech Industry Advocates 35%Systemic Risk Analysts 25%
Regulatory Traditionalists
Argue that standard supervisory frameworks are robust enough to manage digital risks without requiring siloed, specialized teams.
Fintech Industry Advocates
Believe the integration into standard supervision validates the sector's maturity and removes unnecessary barriers to innovation.
Systemic Risk Analysts
Question whether standard vendor-management frameworks possess the technical depth to audit decentralized ledgers and complex algorithmic partnerships.

When you open a high-yield savings account through a sleek financial technology app, you are rarely depositing your money directly into a tech company. Instead, you are interacting with a software layer that routes your funds to a fully chartered, federally insured partner bank operating quietly in the background. How safe that money is—and how insulated it is from the tech company's potential missteps—depends entirely on how federal regulators supervise that specific partnership. For consumers, the arcane mechanics of bank examination are the invisible guardrails protecting their digital wallets.[6]

For a brief window, the Federal Reserve treated these modern banking arrangements as a unique, systemic threat requiring dedicated scrutiny. In August 2023, the central bank launched the Novel Activities Supervision Program (NASP). This specialized unit was designed to deploy highly technical examiners to scrutinize banks' involvement in crypto assets, distributed ledger technology, and complex, API-driven partnerships with non-bank financial firms. The program signaled that the delivery of financial services through technology platforms was fundamentally different from traditional banking and required a new regulatory playbook.[4]

However, the era of specialized fintech oversight was short-lived. In August 2025, the Federal Reserve quietly announced that it would sunset the NASP. The central bank formally rescinded the supervisory letter that created the program, declaring that it would integrate the oversight of these novel technologies back into its "standard supervisory process." Rather than maintaining a siloed team of tech-focused examiners, the Fed opted to fold digital assets and fintech partnerships into the routine examinations conducted at every chartered institution.[1]

The Federal Reserve framed this sunset not as a retreat, but as a victory for the sector's maturation. The official rationale was straightforward: over the course of two years, the central bank had strengthened its understanding of these technologies, their risk profiles, and how banks manage them. Consequently, the Fed concluded that it no longer needed a standalone overlay to monitor the space. The integration was presented as a natural evolution, signaling confidence in the existing supervisory framework's ability to absorb the risks of the digital age.[1][4]

How the sunset of the Novel Activities Supervision Program shifts the regulatory burden.

Yet, a closer look at the regulatory mechanics reveals a more complex reality regarding how these risks are now managed. By dissolving the specialized program, the Federal Reserve effectively shifted the oversight of complex fintech partnerships into the realm of standard third-party risk management. In the standard supervisory process, these relationships are governed by frameworks such as the Interagency Guidance on Third-Party Relationships, known as SR 23-4, which was issued jointly by federal banking agencies in 2023.[2][6]

Yet, a closer look at the regulatory mechanics reveals a more complex reality regarding how these risks are now managed.

Under the SR 23-4 framework, a sophisticated financial technology platform is treated essentially as a vendor. The regulatory burden of due diligence, performance monitoring, and compliance verification falls squarely on the shoulders of the partner bank. Instead of federal examiners directly probing the fintech's algorithmic lending models or cryptographic security, the examiners audit the bank's internal vendor-management paperwork to ensure the bank is keeping its partner in line.[2]

We compared the scope of the specialized NASP framework with the standard vendor-management guidelines. The shift effectively downgrades fintech partnerships from "novel systemic risks" that require dedicated technical scrutiny to routine "third-party vendor risks." By relying on banks to police their own tech partners through standard contractual and compliance audits, the Federal Reserve reduces the immediate requirement for specialized technical examiners, fundamentally altering the intensity of the regulatory gaze.[1][2][6]

For the financial technology industry, this integration is widely celebrated as a necessary normalization. Legal analysts and industry advocates argue that treating fintech partnerships as perpetually "novel" or inherently dangerous stifles innovation and unfairly penalizes modern financial delivery methods. By removing the standalone regulatory overlay, the Fed eliminated a layer of heightened scrutiny that many viewed as a barrier to entry, allowing non-bank financial firms to operate with the same risk-based expectations as traditional bank vendors.[3][7]

Consumer financial apps rely on complex partnerships with chartered banks operating behind the scenes.

The objective, according to industry observers and community banking groups, was not explicitly to deregulate, but to remove the stigma associated with digital assets and API-driven banking. Market participants are now expected to meet familiar, mainstream compliance standards, a move that traditional banking associations believe appropriately safeguards the system while maintaining a level playing field. This shift provides regulatory certainty, allowing banks to expand their technological partnerships without the looming threat of a specialized federal strike team descending on their operations.[5][7]

Conversely, systemic risk analysts and consumer protection advocates view the sunset as a form of stealth deregulation. They argue that folding highly technical, fast-moving crypto and algorithmic risks into standard examination procedures allows complex vulnerabilities to hide within broader bank compliance checklists. The concern is that standard bank examiners, trained in traditional credit and liquidity risk, may lack the specialized software and cryptographic expertise needed to effectively audit decentralized ledgers or complex API integrations.[6]

This debate sits within a broader context of financial policy shifts in 2026. Recent executive orders aimed at "unleashing prosperity" have explicitly directed federal regulators to identify and remove barriers that impede fintech firms from entering into partnerships with federally regulated institutions. In this environment, the sunset of dedicated fintech supervision aligns neatly with a wider federal push to streamline application processes and encourage technological integration in the financial sector.[6]

The structure of a typical Banking-as-a-Service (BaaS) partnership.

Ultimately, the Federal Reserve's decision to sunset its dedicated fintech supervision represents a fundamental bet on the resilience of traditional bank regulation. The central bank is wagering that its century-old framework of third-party risk management is elastic enough to govern the complexities of the digital age. Whether that bet pays off will depend entirely on whether standard bank examiners can keep pace with the rapid evolution of the financial technology they are now tasked with overseeing.[1][6]

Key points

  1. In 2023, the Federal Reserve created a specialized program to monitor banks' involvement in crypto and complex fintech partnerships.
  2. The central bank sunset this dedicated oversight in 2025, folding novel financial technologies into its standard supervisory process.
  3. Fintech partnerships are now primarily regulated under standard third-party vendor management frameworks.
  4. Industry advocates view the shift as a normalization of digital finance, removing the stigma of 'novel' risk.
  5. Critics argue that standard bank examiners may lack the specialized technical expertise required to audit complex algorithmic systems.

Key terms

Novel Activities Supervision Program (NASP)
A former Federal Reserve initiative dedicated to examining highly technical and emerging financial risks, such as crypto assets and complex bank-fintech partnerships.
Banking-as-a-Service (BaaS)
A model where a licensed bank allows a non-bank technology company to offer financial products, like debit cards or loans, using the bank's regulatory infrastructure.
Third-Party Risk Management
The regulatory framework requiring banks to monitor and control the risks introduced by outside vendors, software providers, and fintech partners.
Distributed Ledger Technology (DLT)
A digital system for recording the transaction of assets in which the transactions and their details are recorded in multiple places at the same time, commonly known as blockchain.

Frequently asked

What was the Novel Activities Supervision Program?

It was a specialized Federal Reserve program launched in 2023 to closely monitor banks' involvement in crypto assets, distributed ledger technology, and complex partnerships with fintech companies.

Why did the Federal Reserve sunset the program?

The Fed stated that it had strengthened its understanding of these technologies and their associated risks, allowing it to integrate this oversight back into its standard, day-to-day bank examination process.

Does this mean fintech companies are no longer regulated?

No. Fintech companies partnering with banks are still heavily scrutinized, but they are now evaluated under standard third-party risk management guidelines, treating them similarly to other critical bank vendors.

What is third-party risk management in banking?

It is the regulatory requirement that banks must conduct rigorous due diligence, monitoring, and compliance checks on any external vendor or partner they use, ensuring the third party operates as safely as the bank itself.

Sources

Source coverage

7 outlets

3 viewpoints surfaced

Regulatory Traditionalists 40%Fintech Industry Advocates 35%Systemic Risk Analysts 25%
  1. [1]Board of Governors of the Federal Reserve SystemRegulatory Traditionalists

    Federal Reserve Board announces it will sunset its novel activities supervision program

    Read on Board of Governors of the Federal Reserve System
  2. [2]Board of Governors of the Federal Reserve SystemRegulatory Traditionalists

    SR 23-4: Interagency Guidance on Third-Party Relationships: Risk Management

    Read on Board of Governors of the Federal Reserve System
  3. [3]Paul Hastings LLPFintech Industry Advocates

    Federal Reserve Board Sunsets Novel Activities Supervision Program

    Read on Paul Hastings LLP
  4. [4]Troutman PepperRegulatory Traditionalists

    The Federal Reserve's Shift in Supervision Strategy for Novel Activities

    Read on Troutman Pepper
  5. [5]Independent Community Bankers of AmericaRegulatory Traditionalists

    Federal Reserve to sunset novel activities supervision program

    Read on Independent Community Bankers of America
  6. [6]Factlen Editorial TeamSystemic Risk Analysts

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team
  7. [7]DentonsFintech Industry Advocates

    Federal Reserve Sunsets Novel Activities Supervision Program

    Read on Dentons

Comments

Stay informed

Every angle. Every day.

Get opinion stories with full source coverage and perspective breakdowns delivered to your inbox.