Banking as a Service (BaaS): Full Guide

Banking as a Service (BaaS): Full Guide

Key Takeaways

  • Banking as a Service (BaaS) allows non-bank companies to offer regulated financial products - accounts, payments, cards, lending - by integrating with licensed banks through APIs, without obtaining their own banking license.
  • The global BaaS market reached $637 billion in 2024 and is projected to exceed $1.49 trillion by 2030, growing at a CAGR of 15.7% (Grand View Research, 2024).
  • A fintech launching on BaaS infrastructure can reach market in 3-6 months, compared to 18-36 months for companies building banking infrastructure from scratch (McKinsey, 2025).
  • BaaS platforms operate under the banking license of their sponsor bank partner, making regulatory compliance the sponsor bank’s responsibility - but fintechs remain accountable for consumer protection, data privacy, and AML obligations in every jurisdiction they serve.
  • The U.S. Office of the Comptroller of the Currency (OCC), the Monetary Authority of Singapore (MAS), and Australia’s APRA have all issued guidance tightening oversight of bank-fintech partnerships, making sponsor bank governance a critical evaluation criterion.

Banking as a Service is the infrastructure model that lets non-bank companies offer banking products - accounts, payments, cards, and lending - through API connections to licensed banks, without building or licensing their own banking stack. BaaS platforms sit between the sponsor bank (which holds the license) and the fintech (which owns the customer relationship), providing the API layer, compliance tooling, and operational infrastructure that makes the partnership work.

Contents


How Does Banking as a Service Work?

Banking as a Service works by separating the banking license from the banking product. A licensed bank (the sponsor bank) makes its regulated infrastructure available through APIs. A BaaS platform packages those APIs into developer-friendly products. A fintech integrates those products into its own application, delivering banking services under its own brand while the sponsor bank’s license covers the regulatory requirements.

The architecture operates in three layers.

The license layer. The sponsor bank holds the banking license and maintains the regulatory capital, reporting obligations, and supervisory relationships required by financial regulators. In Singapore, this means compliance with MAS requirements. In Australia, APRA prudential standards. In Hong Kong, the HKMA Banking Ordinance. The sponsor bank is ultimately responsible for every financial product issued under its license, regardless of which fintech distributes it.

The platform layer. The BaaS platform provides the middleware - APIs for account creation, payment initiation, card issuance, KYC/AML screening, and transaction monitoring. This layer handles the technical and operational complexity that most fintechs cannot build in-house: connecting to payment networks, managing ledger systems, implementing real-time compliance screening, and maintaining audit trails. The platform translates the sponsor bank’s core banking system into modern, RESTful APIs that developers can integrate in weeks rather than months.

The distribution layer. The fintech builds the customer-facing application - the mobile app, the website, the embedded checkout flow. It owns the brand, the user experience, and the customer relationship. From the customer’s perspective, they are using the fintech’s product. Behind the interface, every transaction flows through the BaaS platform to the sponsor bank’s licensed infrastructure.

This three-layer separation is what makes BaaS fundamentally different from traditional banking partnerships. The fintech does not need to understand core banking systems. The sponsor bank does not need to build consumer-facing products. The BaaS platform bridges the gap.

The BaaS Value Chain: Who Does What?

Understanding who is responsible for what in a BaaS arrangement is critical for risk management, compliance, and contract negotiation. The value chain has three participants, each with distinct roles and obligations.

RoleResponsibilityExamplesRevenue Model
Sponsor bankHolds banking license, maintains regulatory capital, files supervisory reports, bears ultimate regulatory liabilityLicensed banks in each jurisdictionInterest income, per-transaction fees, BaaS platform fees
BaaS platformProvides APIs, compliance tooling, ledger infrastructure, payment network connectivity, developer documentationTechnology companies connecting banks to fintechsPlatform fees (monthly + per-API-call), revenue share, setup fees
Fintech / distributorBuilds customer-facing product, owns brand and UX, acquires and manages customer relationships, handles first-line customer supportNeobanks, lending apps, payment platforms, e-commerce companiesInterchange, subscription fees, interest margin, transaction fees

The sponsor bank’s role goes beyond lending its license. Under regulatory frameworks in most jurisdictions, the sponsor bank must:

  • Maintain capital adequacy ratios covering all products issued under its license, including those distributed by fintech partners
  • File regulatory reports covering fintech-originated activity
  • Conduct ongoing due diligence on its fintech partners (third-party risk management)
  • Retain the right to terminate fintech partnerships if compliance standards are not met

Regulators globally are tightening their oversight of these partnerships. The U.S. OCC issued guidance in 2024 requiring sponsor banks to demonstrate that they actively supervise their fintech partners, not just contractually delegate compliance. MAS Notice 644 on Technology Risk Management applies the same principle in Singapore - the bank cannot outsource accountability.

BaaS Platform Responsibilities

The BaaS platform sits in the middle and carries operational risk. Its responsibilities typically include:

  • API reliability. Uptime SLAs of 99.9%+ for payment processing and account services
  • Compliance infrastructure. Real-time KYC/AML screening, transaction monitoring, sanctions list checking
  • Data security. Encryption, access controls, audit logging, and compliance with data protection regulations (PDPA in Singapore, Privacy Act in Australia)
  • Ledger management. Maintaining accurate records of all accounts, balances, and transactions
  • Regulatory change management. Updating compliance rules and API behavior when regulations change

Fintech Responsibilities

Even though the fintech does not hold the banking license, it is not free from regulatory obligations. In most jurisdictions, the fintech must:

  • Comply with consumer protection laws (fair lending, transparent pricing, complaint handling)
  • Implement its own AML/CFT program proportionate to its risk profile
  • Meet data privacy requirements for customer information it collects and stores
  • Maintain adequate capital for operational continuity
  • Report suspicious activity through the BaaS platform or directly to the relevant financial intelligence unit

The division of responsibility varies by jurisdiction and by the specific BaaS arrangement. For fintechs evaluating BaaS platforms, the contract - specifically, the regulatory responsibility matrix - is as important as the API documentation.

What Can You Build With BaaS?

BaaS infrastructure supports a broad range of financial products. The determining factor is not the product category but whether the fintech’s use case can operate under the sponsor bank’s license and within the BaaS platform’s technical capabilities.

Neobanking and digital banking. Launch a fully branded digital bank with accounts, debit cards, payments, and savings products. The fintech handles customer acquisition and the user interface. The BaaS platform provides the ledger, card issuance, payment processing, and compliance infrastructure.

Embedded payments. E-commerce platforms, SaaS companies, and marketplaces embed payment acceptance, payouts, and multi-currency settlement directly into their products. The end user never interacts with the underlying banking infrastructure.

Lending and credit. Fintechs offer loans, credit lines, or buy-now-pay-later products using the sponsor bank’s lending license. The BaaS platform handles credit decisioning APIs, loan origination, servicing, and regulatory reporting.

Card programs. Issue prepaid, debit, or virtual cards under the fintech’s brand. The BaaS platform connects to card networks (Visa, Mastercard) through the sponsor bank’s BIN (Bank Identification Number) sponsorship. Card programs require specific technical and regulatory infrastructure - see branded card programmes for fintechs for the operational requirements.

Multi-currency and cross-border payments. Process international payments, FX conversion, and multi-currency account management through the sponsor bank’s correspondent banking relationships and payment network access.

Wealth and investment products. Offer fractional investing, robo-advisory, or portfolio management products by connecting to the sponsor bank’s custody and trading infrastructure. This use case is more complex, as it typically requires additional licenses (securities dealing, fund management) beyond the banking license.

Compliance as a service. Some BaaS platforms offer standalone compliance modules - KYC verification, transaction monitoring, sanctions screening - that fintechs can integrate independently of full banking products. For fintechs that already hold their own licenses, this reduces the build vs buy decision to specific compliance components rather than the entire stack.

Launching a multi-product fintech? Aerapass combines payments, trading, cards, compliance, and wealth management under one API layer - with direct regulatory coverage across four jurisdictions. Explore the platform

BaaS vs Traditional Banking Infrastructure

The fundamental difference between BaaS and traditional banking infrastructure is time to market and capital efficiency. Traditional approaches require either obtaining a banking license (18-36 months, $10M-$50M+ in regulatory capital depending on jurisdiction) or negotiating bespoke partnerships with individual banks (6-18 months of integration work per bank).

DimensionTraditional Banking InfrastructureBanking as a Service
Time to market18-36 months (license) or 6-18 months (bespoke partnership)3-6 months
Regulatory capital required$10M-$50M+ (varies by jurisdiction and license type)None (sponsor bank provides license)
Compliance burdenFull - all regulatory obligations rest with the license holderShared - sponsor bank holds license; fintech retains consumer protection and AML obligations
Technical integrationCustom build to core banking system; 6-12 months per bankAPI integration; weeks to months
Multi-jurisdiction coverageSeparate license or partnership per jurisdictionAvailable if BaaS platform has multi-jurisdiction sponsor bank network
Ongoing maintenanceInternal teams manage infrastructure, compliance updates, regulatory reportingBaaS platform manages infrastructure and compliance updates; fintech manages product and UX
ScalabilityLimited by internal infrastructure investmentScales with BaaS platform capacity
Vendor dependencyLow (own infrastructure)High (dependent on BaaS platform and sponsor bank stability)

Sources: McKinsey Fintech Infrastructure Analysis (2025); BIS Working Paper on Bank-Fintech Partnerships (2024)

The trade-off is control versus speed. Traditional infrastructure gives the fintech full control over its banking stack but requires significant capital, time, and regulatory expertise. BaaS gives speed and capital efficiency but introduces dependency on the platform and sponsor bank. The right choice depends on the fintech’s growth stage, regulatory ambition, and product complexity.

For a deeper analysis of this trade-off across individual infrastructure layers, see the build vs buy decision framework for fintechs.

BaaS vs Embedded Finance: What Is the Difference?

Banking as a Service and embedded finance are related but distinct concepts. BaaS is the infrastructure layer. Embedded finance is the distribution strategy. They are often confused because embedded finance products almost always run on BaaS infrastructure, but not all BaaS use cases are embedded finance.

BaaS is the API-based model that lets non-banks access banking infrastructure through a licensed bank. The fintech using BaaS may or may not be a financial services company. A neobank building its entire product on BaaS infrastructure is a financial services company. An e-commerce platform embedding checkout financing is not.

Embedded finance is the practice of integrating financial services into non-financial products and customer journeys. When a ride-sharing app offers driver banking, or a SaaS platform offers invoice financing, or an e-commerce marketplace offers seller advances - that is embedded finance. The financial product is embedded into a non-financial context.

The relationship between the two:

  • BaaS is an infrastructure model (how banking products are built and licensed)
  • Embedded finance is a distribution model (where banking products appear)
  • Most embedded finance runs on BaaS infrastructure
  • Not all BaaS products are embedded (a standalone neobank uses BaaS but is not “embedded” in a non-financial product)

Building financial products across multiple markets? Aerapass provides API-first payment infrastructure across four regulated jurisdictions, handling the compliance and connectivity layer so you can focus on your product. Explore global payments

How Do BaaS Platforms Handle Regulatory Compliance?

Regulatory compliance is the most complex and most misunderstood aspect of Banking as a Service. The common assumption - that the sponsor bank’s license covers everything - is incomplete and increasingly challenged by regulators.

The Shared Responsibility Model

Compliance in BaaS is not delegated - it is distributed. The sponsor bank holds the license and bears ultimate regulatory liability. But regulators in every major jurisdiction now require the fintech to maintain its own compliance obligations.

In practice, this means three distinct compliance layers:

  • Sponsor bank compliance. Regulatory capital, supervisory reporting, liquidity management, and oversight of all fintech partners operating under its license
  • Platform compliance. Real-time transaction monitoring, KYC/AML screening, sanctions checking, data security, and audit trail maintenance
  • Fintech compliance. Consumer protection, data privacy (PDPA, Privacy Act, GDPR), complaint handling, fair lending practices, and suspicious activity reporting

Regulatory Pressure Points

Regulators globally are increasing scrutiny of BaaS arrangements:

  • United States: The OCC, FDIC, and Federal Reserve issued joint guidance in 2023 requiring banks engaged in BaaS partnerships to demonstrate active supervision of their fintech partners, including on-site examinations of fintech operations
  • Singapore: MAS Notice 644 on Technology Risk Management applies to all outsourcing arrangements, including BaaS. The bank cannot outsource its regulatory accountability
  • Australia: APRA Prudential Standard CPS 230 on Operational Risk Management (effective July 2025) imposes explicit requirements on banks’ management of critical third-party arrangements, including BaaS platforms
  • Hong Kong: The HKMA updated its guidelines on banking partnerships in 2024 to require enhanced due diligence on fintech partners and regular compliance audits

What This Means for Fintechs Evaluating BaaS

When evaluating a BaaS platform, the compliance layer is as important as the API layer. Key questions to ask:

  • Which sponsor bank(s) does the platform work with, and in which jurisdictions?
  • How does the platform divide compliance responsibilities between the sponsor bank, the platform, and the fintech?
  • Does the platform provide real-time compliance tooling (KYC, transaction monitoring, sanctions screening) or does the fintech need to source these separately?
  • What happens to the fintech’s customers if the sponsor bank relationship ends?
  • How does the platform handle regulatory changes - is there a defined process for updating compliance rules and communicating changes to fintechs?

What Should You Look for in a BaaS Platform?

Choosing a BaaS platform is an infrastructure decision with multi-year consequences. The wrong choice constrains product development, creates compliance risk, and makes migration difficult. Here are the evaluation dimensions that matter most.

Jurisdictional coverage. How many markets can you launch in through this platform? A platform operating under a single sponsor bank in one jurisdiction will require you to find separate infrastructure for every additional market. Platforms with multi-jurisdiction sponsor bank networks let you expand without re-platforming.

API maturity. Evaluate the APIs for completeness (do they cover your full product roadmap?), documentation quality (can your engineers integrate without extensive support tickets?), and versioning stability (how often do breaking changes occur?). Request sandbox access and have your engineering team run a proof-of-concept before signing.

Compliance infrastructure depth. Does the platform provide the full compliance stack - KYC, AML screening, transaction monitoring, regulatory reporting - or only partial coverage? Gaps in compliance tooling mean the fintech must source and integrate additional vendors, increasing complexity and cost. See our customer management platform for an example of what a full compliance stack looks like.

Sponsor bank stability. Research the sponsor bank’s financial health, regulatory standing, and history with fintech partnerships. A sponsor bank under regulatory pressure may restrict or terminate its BaaS program, leaving fintechs scrambling for alternatives. This risk is not hypothetical - multiple BaaS arrangements in the U.S. were disrupted in 2023-2024 when regulators issued consent orders against sponsor banks.

Data portability and exit terms. Review the contract for data portability provisions. If the relationship ends, can you export customer data and transaction history in a standard format? Are there lock-in clauses that prevent migration? The cost of switching BaaS platforms is high enough without contractual barriers.

Pricing transparency. BaaS pricing models vary widely: monthly platform fees, per-API-call charges, per-account fees, revenue sharing, and transaction-based pricing. Request a total cost of ownership model based on your projected volumes, not just the headline rate card.

The BaaS Market: Size, Growth, and Direction

The global Banking as a Service market is growing rapidly, driven by fintech proliferation, regulatory modernization, and enterprise demand for embedded financial products.

Grand View Research valued the global BaaS market at $637 billion in 2024 and projects it to reach $1.49 trillion by 2030, growing at a compound annual growth rate (CAGR) of 15.7%. Allied Market Research offers a more conservative estimate of $65.8 billion by 2032 for the platform layer specifically (excluding transaction volumes flowing through BaaS infrastructure).

Regional Dynamics

Asia-Pacific is the fastest-growing BaaS region. Singapore’s forward-leaning regulatory environment (MAS FinTech Regulatory Sandbox, APIX initiative), Hong Kong’s virtual banking licenses, and Australia’s open banking framework (Consumer Data Right) create favorable conditions for BaaS adoption. The region’s large unbanked and underbanked population provides a structural demand driver.

Europe leads in regulatory infrastructure. PSD2 mandated open banking APIs across the EU, creating the technical foundation for BaaS distribution. The UK’s FCA has been the most active regulator in defining expectations for bank-fintech partnerships.

North America is the largest BaaS market by revenue but faces the most regulatory turbulence. The 2024 Synapse Financial collapse froze $160-200 million in customer funds, and consent orders against multiple sponsor banks disrupted several BaaS programs - prompting a fundamental reassessment of the sponsor bank model’s risk profile.

Three structural trends are reshaping the BaaS landscape:

Sponsor bank consolidation. Regulatory pressure is reducing the number of banks willing to serve as BaaS sponsors. The banks that remain are raising compliance standards and becoming more selective about fintech partners. This favors BaaS platforms with established, stable sponsor bank relationships.

Vertical BaaS. General-purpose BaaS platforms are being joined by vertically specialized platforms targeting specific industries (healthcare, real estate, logistics) or product categories (lending, payments, wealth). Vertical platforms offer deeper domain expertise at the cost of product breadth.

Compliance-first architecture. The BaaS platforms gaining market share are those that lead with compliance infrastructure rather than speed of integration. Regulators’ increased scrutiny means that fintechs are prioritizing platforms that can demonstrate robust compliance tooling over those that promise the fastest launch.

How Aerapass Fits the BaaS Model

Aerapass operates as an all-in-one financial infrastructure platform, providing the API layer between regulated financial services and the companies that want to offer them. The platform covers payments, multi-asset trading, card issuance, customer management (KYC/AML/compliance), and wealth management infrastructure across four licensed jurisdictions: Hong Kong, Singapore, Australia, and Canada.

For fintechs evaluating BaaS infrastructure, Aerapass offers several characteristics that align with the evaluation criteria outlined above:

  • Multi-jurisdiction coverage - A single integration provides access to regulated infrastructure across four markets, eliminating the need for separate partnerships per jurisdiction
  • Full compliance stack - KYC verification, AML screening, transaction monitoring, and regulatory reporting are built into the platform, not bolted on through third-party integrations
  • API-first architecture - RESTful APIs across all platform modules with sandbox environments for development and testing. See how Aerapass enables third-party integration for the technical approach
  • Multi-product breadth - Payments, trading, cards, compliance, and wealth management through one platform. Fintechs building multi-product offerings avoid the complexity of integrating separate BaaS providers for each capability
  • White-label capability - The platform supports fully branded deployment, allowing fintechs to present banking and investment products under their own brand. For a detailed comparison of white-label approaches, see the complete guide to white-label wealth management platforms

Aerapass manages over 100,000 users across 120+ countries, operating under the supervision of MAS, SFC/HKMA, ASIC, and FINTRAC respectively.

Frequently Asked Questions

What is Banking as a Service (BaaS)?

Banking as a Service is the infrastructure model that allows non-bank companies to offer regulated banking products - accounts, payments, cards, lending - by connecting to a licensed bank’s infrastructure through APIs. The BaaS platform sits between the sponsor bank (which holds the license) and the fintech (which owns the customer relationship), providing the technical and compliance middleware that makes the partnership work. The fintech does not need its own banking license to offer banking products.

How does BaaS differ from core banking?

Core banking is the internal technology system that a bank uses to manage its own operations - deposits, loans, payments, and general ledger. It is designed for the bank’s staff and processes. BaaS is the external-facing layer that exposes banking capabilities to third parties through APIs. A BaaS platform typically connects to one or more core banking systems and translates their functionality into developer-friendly APIs. Core banking is the engine; BaaS is the interface that lets non-bank companies use that engine.

What is a BaaS provider?

A BaaS provider is a technology company that operates the platform layer between a licensed bank and fintech companies. The BaaS provider packages the sponsor bank’s regulated infrastructure into APIs, manages compliance tooling, maintains the ledger and payment connectivity, and provides the developer tools that fintechs use to build financial products. BaaS providers are distinct from sponsor banks (which hold the license) and from fintechs (which build the customer-facing products).

Is BaaS regulated?

BaaS itself is not a separately regulated activity in most jurisdictions. Instead, the regulatory framework applies to the participants: the sponsor bank is regulated as a bank, and the fintech may be regulated depending on the products it offers and the jurisdiction it operates in. However, regulators are increasingly issuing specific guidance on bank-fintech partnerships. The OCC, MAS, APRA, and HKMA have all published guidelines that directly affect how BaaS arrangements must be structured, supervised, and reported. The regulatory trend is toward greater scrutiny, not less.

What are the risks of using a BaaS platform?

The primary risks are sponsor bank dependency (if the sponsor bank exits BaaS or receives a consent order, the fintech’s products are disrupted), platform vendor lock-in (switching BaaS providers is expensive and time-consuming), compliance gaps (the fintech remains responsible for consumer protection and AML obligations even though the sponsor bank holds the license), and regulatory change (new rules can alter the economics or viability of the BaaS model). Fintechs mitigate these risks through careful platform selection, contractual protections, diversified sponsor bank relationships, and maintaining internal compliance capabilities.

How long does it take to launch a fintech product using BaaS?

A fintech launching a straightforward product (digital account with debit card and payments) on a mature BaaS platform can reach production in 3-6 months. This includes API integration (4-8 weeks), compliance onboarding and sponsor bank due diligence (4-12 weeks), testing and certification (2-4 weeks), and regulatory notification if required (varies by jurisdiction). More complex products (lending, multi-currency, wealth) take longer due to additional compliance requirements and technical integration depth. By comparison, building the same product on proprietary banking infrastructure takes 18-36 months and requires significantly more capital (McKinsey, 2025).

Can a fintech use multiple BaaS providers?

Yes. Some fintechs use different BaaS providers for different product lines (one for payments, another for lending) or different jurisdictions. This approach offers resilience against single-provider risk but increases integration complexity and compliance overhead. Multi-provider strategies work best when the fintech has strong internal engineering and compliance teams capable of managing multiple vendor relationships.

Ready to explore BaaS infrastructure? See how Aerapass fintech solutions provide regulated financial infrastructure across four jurisdictions through a single API integration.


Regulatory Disclosure: Aerapass financial services are provided through Aerapass, a Major Payment Institution licensed by the Monetary Authority of Singapore and regulated across four jurisdictions (Hong Kong, Singapore, Australia, and Canada). This article is for educational purposes only and does not constitute financial, legal, or regulatory advice. Regulatory requirements vary by jurisdiction and change over time. Companies evaluating BaaS infrastructure should consult qualified legal and compliance advisors in each market they intend to serve.

Sources cited: Grand View Research (BaaS Market Report, 2024), Allied Market Research (BaaS Platform Market, 2024), McKinsey & Company (Fintech Infrastructure Analysis, 2025), Bank for International Settlements (Bank-Fintech Partnership Working Paper, 2024), LexisNexis Risk Solutions (True Cost of Financial Crime Compliance, 2025), OCC (Third-Party Risk Management Guidance, 2024), MAS (Notice 644, Technology Risk Management), APRA (CPS 230, Operational Risk Management).

The content on this page is produced by Aerapass for general informational purposes only and does not constitute financial advice, investment advice, or any other form of professional advice. Aerapass is a technology platform provider serving financial institutions, wealth managers, and fintech companies. Before making any financial decision, you should consult with a qualified, licensed financial advisor who can take your individual objectives and circumstances into account.

Aerapass product screenshot
Contact us

Let's connect

Share your requirements and our team will prepare a tailored walkthrough showing how Aerapass supports compliant onboarding, global payments, risk workflows, and scalable financial infrastructure.