Skip to content

Fintech and bank partnerships: who owns the customer, who owns the risk

فن ٹیک اور بینک شراکت داری: گاہک کس کا، خطرہ کس کا

22 min read

Three ways to see it

  1. In Pakistan, three structures dominate. One: distribution partnership, where the fintech is essentially a digital channel for the bank's product. Two: BIN sponsorship, where a bank issues the card or wallet on behalf of the fintech. Three: balance-sheet partnership, where the bank books the loan and bears the credit risk while the fintech originates and services. Each requires written agreements that satisfy SBP outsourcing guidelines and the bank's own risk policy.

  2. The customer ownership question matters legally. If a complaint reaches the Banking Mohtasib, the bank is the regulated entity. The fintech may have built the experience, but the bank cannot disclaim responsibility for KYC, AML, or fair-dealing failures. Contracts must be explicit: which party performs CDD, who keeps records, who handles complaints, and how data flows between the two systems while respecting the PDPA 2023.

  3. Risk allocation is the heart of the deal. Credit risk usually goes where the asset sits: if the bank books the loan, the bank takes the loss when it defaults. Operational risk follows the activity: if the fintech runs the app, an outage that costs the bank fines and reputation can be passed back via indemnity clauses, capped at agreed amounts. Cybersecurity incidents typically have joint response plans with clear notification windows.

Quick check

Quick check: what makes modern AI different from a rule-based program?

The why-tree

Real Pakistani examples. SadaPay and NayaPay built consumer experiences while operating as electronic money institutions, regulated separately. Easypaisa and JazzCash grew under branchless banking and microfinance licenses. Tag Innovation got an in-principle approval for a digital retail bank. Each path has different capital, governance, and partnership rules. Read the SBP's Licensing and Regulatory Framework for Digital Banks before you choose.

Try this with Claude

Negotiation checklist. One: agree the exact license under which the activity runs and write it on page one. Two: name the regulator-facing officer on each side. Three: pre-agree the breach notification window in hours, not days. Four: build an exit plan that protects customer balances on day zero. Five: schedule a quarterly joint risk review with minutes shared to both boards. Six: treat the PDPA 2023 data-sharing clauses as a separate annex with its own sign-off.