All posts
Compliance·· 10 min read

FDIC Pass-Through Insurance for Fintechs Post-Synapse

After Synapse's collapse exposed $85 million in unreconciled funds, FDIC pass-through insurance is no longer a marketing checkbox — it's a structural and legal obligation.

By AtlasForge Financial Editorial
FDIC Pass-Through Insurance for Fintechs Post-Synapse

The bankruptcy of Synapse Financial Technologies in April 2024 did not just strand roughly 100,000 end users without access to their money for months. It revealed, in the starkest possible terms, that "FDIC-insured" printed on a fintech app's onboarding screen can mean almost nothing if the underlying ledger architecture is broken. The Federal Deposit Insurance Corporation itself confirmed that the shortfall between what Synapse's partner banks held and what end users were owed reached as high as $85 million at one point during the reconciliation process — a gap that no insurance fund was designed to cover, because insurance presupposes accurate records.

For compliance officers, banking-as-a-service product leads, and any fintech that routes customer deposits through a for-benefit-of (FBO) account at an FDIC-member institution, the post-Synapse landscape demands a fundamentally different level of rigor. The rules themselves have not changed as dramatically as the enforcement posture and disclosure expectations have — and that gap between the letter of the law and operational reality is where the next casualty will emerge.

What Pass-Through Insurance Actually Means

FDIC deposit insurance does not attach to a bank account number. It attaches to a depositor's ownership interest in funds held at an insured institution, up to $250,000 per depositor, per institution, per ownership category under 12 C.F.R. § 330. Pass-through insurance — sometimes called "pass-through coverage" or "beneficiary coverage" — is the mechanism by which that per-depositor limit flows through an omnibus custodial account to each underlying beneficial owner.

For a fintech operating an FBO account structure, pass-through coverage requires four conditions to be satisfied simultaneously:

  1. The account must be titled in a way that indicates a fiduciary or custodial relationship (e.g., "[Fintech Name] FBO Its Customers").
  2. The fintech must maintain contemporaneous, accurate records identifying each beneficial owner and their specific balance.
  3. The beneficial owners themselves must qualify as insured depositors — generally, natural persons, corporations, partnerships, or certain trusts.
  4. The aggregate deposits of each beneficial owner at the same insured institution across all accounts — including any direct personal accounts — must be considered when calculating coverage limits.

Condition two is where Synapse failed operationally. Without reliable sub-ledger records, there was no way to demonstrate which dollars belonged to which user, and pass-through coverage became legally moot regardless of what the marketing page said.

The FBO Account Structure: A Closer Look

An FBO ("for benefit of") account is not a term of art defined by the FDIC. It is a banking industry convention describing an omnibus demand-deposit or money-market account held by a custodian — typically the fintech or its program manager — at a partner bank, with the ultimate beneficial interest belonging to the fintech's end users.

The structural elegance is real: a single account relationship at one bank can serve hundreds of thousands of end users, reducing KYC overhead for the bank and enabling the fintech to scale without opening individual accounts. The structural risk is equally real: the custodian becomes the single point of failure for record integrity.

Sweep Programs and Multi-Bank FBO Structures

Many fintechs and neobanks have implemented multi-bank sweep arrangements to extend effective FDIC coverage beyond $250,000 per user. In a sweep structure, deposits are automatically distributed across multiple FDIC-member banks — each holding up to $250,000 of a given user's funds — multiplying the theoretical coverage ceiling. A network of 20 partner banks, for example, could provide up to $5 million in coverage per depositor.

This architecture is legitimate and widely used, but it dramatically increases sub-ledger complexity. Every sweep event must be recorded accurately, and the fintech must be able to produce a per-user, per-bank balance snapshot on demand. After Synapse, regulators are no longer willing to assume that capability exists without evidence.

What Changed Post-2024: FDIC Disclosure and Recordkeeping Expectations

In January 2025, the FDIC finalized amendments to its official sign rules and deposit insurance disclosure requirements, building on a notice-and-comment process that began in mid-2023. The final rule, effective July 1, 2025, imposes three categories of new obligations directly relevant to fintech custodial structures:

1. Mandatory "not insured by the FDIC" clarification for non-deposit products. Fintechs that hold both FDIC-insured deposits and non-deposit investment products (even money-market funds) in the same user interface must clearly separate disclosures and cannot use language implying insurance coverage extends to non-deposit balances.

2. Third-party recordkeeping standards for pass-through eligibility. Banks that accept FBO deposits from fintechs must now maintain — or contractually require the fintech to maintain — records sufficient to allow the FDIC to calculate pass-through coverage within 24 hours of appointment as receiver. This is a direct response to the Synapse reconciliation timeline, which stretched to more than nine months.

3. Ongoing disclosure on digital interfaces. Any digital platform that represents customer funds as FDIC-insured must display a standardized disclosure that (a) identifies the specific insured institution holding the funds, (b) explains the $250,000 per-depositor limit, and (c) notes that coverage depends on accurate recordkeeping by the custodian.

The Federal Reserve's 2025 supervision letter SR 25-3, issued in March 2025, reinforced these expectations for state-member banks that serve as program banks for fintechs, adding examination scrutiny on the bank's own due-diligence processes when onboarding a BaaS partner.

Key compliance insight: The FDIC's new recordkeeping standard is not a best-practice recommendation — it is a condition of pass-through eligibility. A fintech whose sub-ledger cannot support a 24-hour reconciliation is, in a legal sense, operating an uninsured custodial account regardless of what its partner bank's FDIC certificate says.

Calculating Per-Depositor Coverage: The Math Fintechs Get Wrong

Even when sub-ledger records are impeccable, per-depositor coverage calculations are routinely miscommunicated to end users. Here are the three most common errors:

  • Double-counting sweep positions. A user with $200,000 in a fintech sweep account and $100,000 in a personal checking account at Bank A — one of the sweep destinations — has $300,000 exposed at that single institution, $50,000 of which is uninsured. The fintech's app rarely warns the user to check for this overlap.
  • Ignoring ownership category distinctions. The FDIC insures deposits separately by ownership category: single accounts, joint accounts, certain retirement accounts (IRAs, for example, receive a separate $250,000 limit), and revocable-trust accounts with named beneficiaries. A fintech that pools all user funds in a single "individual" FBO category may be leaving coverage on the table for users who could qualify for higher limits under trust or retirement categories.
  • Treating the $250,000 limit as a per-app limit. It is a per-depositor, per-institution limit. If the fintech routes all user funds to a single partner bank — a common cost-optimization choice among early-stage platforms — every user's effective ceiling is $250,000, full stop, no matter how the marketing describes it.

The CFPB's 2024 supervisory highlights, published in October 2024, cited misleading FDIC insurance representations as an emerging unfair, deceptive, or abusive act or practice (UDAAP) concern in the context of fintech deposit products. That is a meaningful escalation: it means consumer-protection enforcement, not just prudential supervision, is now a live risk vector for inaccurate coverage claims.

Operational Checklist: What a Compliant FBO Structure Requires in 2026

Compliance is not a static state. It is a set of live operational capabilities. A fintech running a custodial deposit product should be able to answer "yes" to every item on this list:

  1. Real-time sub-ledger: Can you produce a per-user, per-bank balance snapshot within one business hour?
  2. Reconciliation cadence: Are your FBO account balances at each partner bank reconciled against your sub-ledger at least daily, with exception reports reviewed by a named compliance officer?
  3. Sweep audit trail: Is every sweep transaction — origination, receipt, and confirmation — logged with timestamps and bank confirmation numbers, and retained for at least five years?
  4. Disclosure accuracy: Does every digital touchpoint that mentions FDIC insurance identify the specific holding bank, state the $250,000 per-depositor limit, and include the custodian-recordkeeping caveat required under the July 2025 final rule?
  5. Overlap detection: Does your platform alert users when their projected balance at any single partner bank — including personal accounts they may have self-reported — approaches $240,000?
  6. Contingency plan: Do you have a contractual right to retrieve a full sub-ledger export from your core banking processor or BaaS provider within 24 hours, independent of that provider's operational status?
  7. Legal review of account agreements: Do your end-user agreements accurately describe the custodial nature of the account and disclaim any claim against the fintech itself (as opposed to the insured institution) for deposit losses attributable to bank failure?

Item six is the Synapse lesson made concrete. The barrier to reconciliation was not the absence of data — it was that the data was siloed across Synapse's proprietary ledger, which became inaccessible when the company filed for bankruptcy. Structural data portability is now a compliance requirement, not a vendor negotiation point.

What Program Banks Must Now Demand From Fintech Partners

The supervisory pressure is flowing in both directions. Program banks — the FDIC-member institutions that hold the actual deposits — are under examination scrutiny for the quality of their third-party oversight. The OCC's third-party risk management guidance (OCC Bulletin 2023-17) and the joint agency guidance issued in June 2023 by the OCC, FDIC, and Federal Reserve collectively establish that a program bank cannot outsource its compliance responsibilities to the fintech.

In practice, this means program banks are increasingly requiring:

  • Monthly sub-ledger attestations from fintech partners, signed by a named officer, confirming that FBO balances reconcile to the bank's records.
  • Annual third-party audits of the fintech's sub-ledger controls, conducted by a SOC 1 Type II auditor or equivalent.
  • Contractual data-access rights allowing the bank — and by extension the FDIC — to extract the full beneficial-ownership ledger without the fintech's active cooperation if necessary.
  • Concentration limits capping the total FBO deposit volume any single fintech can place at the bank, to reduce systemic exposure if a fintech partner fails.

For fintechs, this means the era of the "light" BaaS relationship — where the program bank was primarily a regulatory umbrella and the fintech handled everything else — is over. Banks are pricing their compliance overhead into program fees, and fintechs that cannot demonstrate operational rigor are finding their program bank options narrowing considerably.

Building Infrastructure That Survives a Regulator's Scrutiny

The structural answer to post-Synapse compliance is not more legal disclaimers. It is better infrastructure. Specifically, it requires a sub-ledger architecture that is:

  • Source-of-truth independent: Your sub-ledger should not depend on your BaaS provider's ledger being correct. It should reconcile against bank statements directly, using automated bank data feeds where available.
  • Auditable in near-real-time: Every credit and debit to a user's beneficial interest should carry a transaction ID, timestamp, originating bank reference, and the resulting balance before and after — queryable by your compliance team without engineering support.
  • Portable on short notice: The full sub-ledger should be exportable to a standard format (CSV, JSON, or Parquet) within hours, without proprietary transformation logic that breaks if your vendor goes dark.

For fintechs evaluating infrastructure partners, the AtlasForge Financial Platform was designed with exactly these constraints in mind — including a reconciliation engine that produces FDIC-ready beneficial-ownership snapshots on demand, and an API layer that preserves full audit history independent of downstream processor availability. If you are building a deposit product and want to understand how the AtlasForge Financial API handles FBO account structures, the technical documentation walks through sweep-network integrations and per-user coverage calculations in detail.

For end users trying to understand how their everyday spending balance maps to insured deposits, Safe to Spend 365 surfaces real-time coverage estimates alongside daily balance information — with plain-language disclosures that meet the July 2025 FDIC standard by design, not by retrofit.

The Synapse collapse was not a black swan. It was a stress test that the industry failed because the infrastructure was never built to be stress-tested. The fintechs that will earn — and keep — user trust over the next decade are the ones treating FDIC pass-through insurance as an engineering problem, not a marketing claim. The regulatory environment after 2024 gives them no other viable option.


For further reading: the FDIC's official deposit insurance FAQ is available at fdic.gov, and the CFPB's 2024 supervisory highlights covering UDAAP concerns in fintech deposit products are available at consumerfinance.gov. For questions about how AtlasForge structures FBO compliance tooling, visit our contact page.

Further reading

Ready to build on AtlasForge?

Get sandbox API keys in 60 seconds — or install the Safe to Spend 365 app.