B2B Sales Strategy

    Sales Strategy for Fintech Companies Selling to Banks

    How a fintech sells to banks and credit unions: the five stages of a third-party relationship, the September 2026 proposal, and the core provider as gatekeeper.

    The five stages of a third-party relationship as the FDIC's letter on the 2023 interagency guidance names them, read as the five conversations a fintech's sale passes through.
    September 18, 202610 min read
    Share:
    The short answer

    A fintech selling to banks sells through the bank's third-party risk process. The FDIC's 2023 letter names five stages: planning, due diligence, contract negotiation, ongoing monitoring and termination. On 11 September 2026 the agencies proposed replacing that guidance with one tailored to risk, open for comment. Core service providers are the other gate.

    Key takeaways

    • The FDIC's letter on the 2023 interagency guidance names five stages of a third-party relationship, planning, due diligence, contract negotiation, ongoing monitoring and termination, and a fintech's sale passes through each.
    • On 11 September 2026 the agencies proposed replacing the 2023 guidance, which the FDIC says has frequently been interpreted in an overly broad manner; comments are due 60 days after Federal Register publication and nothing is final.
    • The bank's responsibility does not move: both the 2023 letter and the 2026 proposal say the use of third parties does not diminish a bank's duty to manage risk and comply with law.
    • The agencies issued a joint statement on community banks' engagement with core service providers, and Jack Henry runs a Fintech Integration Network for product integration with its core platforms.

    Reviewed and updated September 18, 2026

    On 11 September 2026 the four federal regulators of banks and credit unions asked for comment on guidance that would replace the rules of thumb every bank uses to evaluate a fintech vendor. The joint release from the Federal Reserve Board, the Federal Deposit Insurance Corporation, the National Credit Union Administration and the Office of the Comptroller of the Currency says of the proposal: "It is intended to assist banks and credit unions to better align and tailor their third-party risk management practices to the risks of individual third-party relationships" (Federal Reserve Board, joint press release, 11 September 2026). The FDIC's letter on the same day gives the reason: the guidance it would replace, issued in 2023, "has frequently been interpreted in an overly broad manner and with an insufficient focus on tailoring risk management principles" (FDIC, Proposed Interagency Third-Party Risk Management Guidance, 11 September 2026).

    This page is for the fintech company that sells to banks and credit unions and is working out its own sales strategy. It is not about selling to fintech companies, which cold email for fintech covers, and it does not repeat the lead generation play for this reader, including the argument that the word fintech covers two markets, which is in fintech lead generation. A fintech whose customers are merchants or consumers is making a different sale. Here the customer is a regulated institution, and the point is simple: that institution's third-party risk process is the sales process, whether the seller plans for it or not.

    The buyer is a life cycle, not a title

    The regulators describe a vendor relationship as a sequence, and the sequence is what a fintech sells through. The FDIC's letter announcing the 2023 guidance says it assists banks "by providing examples of considerations in the planning, due diligence, contract negotiation, ongoing monitoring, and termination stages of managing third-party relationships" (FDIC, Interagency Guidance on Third-Party Relationships: Risk Management, 6 June 2023). The same letter states the principle that explains why no bank will skip a stage: a banking organization's use of third parties does not diminish or remove its responsibility to perform all activities in a safe and sound manner and in compliance with applicable laws and regulations. The 2026 proposal keeps that principle.

    Five stages means five conversations, and a sales strategy that plans only for the first one stalls at the second. The letter names the stages without describing them, so what follows is our reading. Planning is where a business line decides it wants what the fintech offers. Due diligence is where the institution examines the fintech itself. Contract negotiation is where the terms the guidance gives examples of are argued. Ongoing monitoring is what the institution will ask of the fintech for as long as the contract runs, and termination is what it asks the fintech to make possible before it signs. Which titles hold each stage in a given bank, and why the internal sponsor matters more than any title, is covered in fintech lead generation; this page does not restate it.

    The letter also says the process is meant to scale: "sound third-party risk management takes into account the level of risk, complexity, and size of the banking organization, as well as the nature of the specific third-party relationship." A fintech's strategy should therefore differ by the kind of relationship it is asking for. The FDIC singles out the heaviest kind: business relationships with third parties engaged in lending, payment or deposit activities for the benefit of the bank or through the bank are to be evaluated under both the third-party guidance and the rules that apply to traditional lending and deposit relationships.

    Five stages of a bank's third-party relationship, from planning to termination 1. Planning A business line wants what you offer 2. Due diligence The institution examines the fintech itself 3. Contract negotiation The terms are argued 4. Ongoing monitoring Asked of you for as long as the contract runs 5. Termination What you make possible before the bank signs
    The five stages of a third-party relationship as the FDIC's letter on the 2023 interagency guidance names them, read as the five conversations a fintech's sale passes through.

    The calendar: a rule that is changing while you sell

    The vertical's most important dates this year are regulatory, and they are public. The agencies published their proposed guidance in the Federal Register on 19 July 2021 and issued the final version on 6 June 2023, replacing each agency's earlier guidance. On 11 September 2026 they proposed to replace it again. The joint release says that "Comments on the proposed guidance are due 60 days after publication in the Federal Register," that the proposal "focuses on a principles-based approach and, as with all supervisory guidance, is non-binding," and that the Federal Reserve Board separately requested comment on a companion guide for the community banks it supervises. The FDIC adds that "Any finalized guidance would replace the 2023 Guidance and certain supplemental third-party risk management resources."

    For a sales plan that means three things. The banks a fintech is selling to are reading the same proposal, and their vendor management teams will be asked what changes. The proposal's stated direction is tailoring to risk, which is the argument a lower-risk fintech has wanted to make for years, and it can now make it in the regulators' words. And nothing has changed yet: until guidance is finalized, the 2023 guidance stands, and a seller who tells a bank that diligence requirements have been relaxed is misdescribing a request for comment. No source fetched for this page states a budget month common to banks and credit unions, so none is asserted; ask each institution when its planning cycle closes.

    1. 19 July 2021Proposed interagency guidance published

      In the Federal Register

    2. 6 June 2023Final guidance issued

      Replaced each agency's earlier guidance

    3. 11 September 2026Proposal to replace the 2023 guidance

      With a joint statement on core service providers

    4. 60 days after Federal Register publicationComments due

      Until guidance is finalized, the 2023 guidance stands

    The interagency third-party risk guidance as the FDIC's and the Federal Reserve Board's own pages date it, from the 2021 proposal to the comment period opened in September 2026.

    The gatekeeper: the core service provider

    Community banks buy central services from core service providers, and the regulators have now addressed that relationship in a formal statement. Alongside the proposal, the three bank agencies issued a joint statement on community banks' engagement with core service providers, which the release says "discusses certain factors the agencies will consider in making supervisory and enforcement decisions related to these core providers."

    The core providers know they are the door. Jack Henry, one of them, lists fintechs among the groups it serves, next to banks, credit unions and de novo banks, with the line "We help fintechs expand their reach and deliver their innovative solutions to a broader financial ecosystem," and runs what it calls the Fintech Integration Network, which it describes as giving fintechs direct access to its technical resources "to achieve product integration with our core platforms and complementary solutions" (Jack Henry, Fintech Integration Network, read 18 September 2026).

    That is the partnership-or-direct decision in a fintech's strategy. Selling direct, the fintech asks each bank to take on an integration with its core as part of the purchase. Integrating with the core first, the fintech arrives at the bank's due diligence stage with one of the institution's questions already answered, and its list becomes the institutions that run that core. Neither route removes the bank's own review, because the responsibility stays with the bank.

    Third parties engaged in lending, payment or deposit activities for or through the bankYesYes
    The bank and its direct customers of traditional bank productsNoYes
    Which framework the FDIC's 2023 letter says applies to each kind of relationship; yes marks what the letter states.

    What the rules require of the fintech's outreach

    The rule on the message is the ordinary one for commercial email. The Federal Trade Commission's guide states that the CAN-SPAM Act "makes no exception for business-to-business email" and that each separate email in violation is subject to penalties of up to $53,088; a valid physical postal address and a clear way to opt out belong in every commercial message (FTC, CAN-SPAM Act: A Compliance Guide for Business, read 18 September 2026).

    The vertical adds a discipline of its own. The guidance is supervisory and non-binding, and it is addressed to banks, not to vendors, so no fintech is approved under it and none should say so. A message that describes a product as meeting the interagency guidance is claiming something the guidance does not offer. Whether a specific practice is compliant is a question for counsel and for the institution's own regulators.

    The objections, in the regulators' own words

    The first objection is that the bank cannot outsource the risk. The FDIC's letter says so directly, and the 2026 proposal keeps it: responsibility stays with the bank to the same extent as if the activity were performed internally. A fintech cannot argue against this; it can only make the bank's job easier.

    The second is that the process is too heavy for the size of the purchase. The regulators have conceded the point. The FDIC says the 2023 guidance "has frequently been interpreted in an overly broad manner," and the proposal exists to focus attention on tailoring practices to the level of risk involved. A small fintech facing an enterprise-sized questionnaire is looking at the problem the agencies have just described.

    The third is the core. The joint statement on core service providers exists because community banks depend on them, and a bank that cannot easily connect a new product to its core will say no for reasons that have nothing to do with the product.

    Channel reality, and when outbound is the wrong play

    Written outreach by email and LinkedIn fits this market because the institutions are named, their regulators and charters are public, and the people who sponsor a purchase can be reached in writing. That written motion, one message per campaign, is the one RevenueFlow runs; RevenueFlow does not cold-call.

    Direct outbound is the wrong play in three cases. It is wrong when the fintech has nothing to hand a bank at the due diligence stage, because a first meeting that goes well leads straight to a request the company cannot answer. It is wrong for institutions on a core the product does not connect to, when a fintech that has chosen the integration route could be writing only to the ones it does. And it is wrong when the message leans on the September 2026 proposal as if it were final, because the bank's vendor management team has read it too.

    Three openers, each grounded in a page the buyer can check

    Three sample first lines a fintech could send, each tied to one fetched source. Each is free of results claims, real names and contact details.

    To the business sponsor at a community bank. The agencies' 11 September proposal says third-party risk management should be tailored to the risk of the individual relationship. Ours is a narrow one, and we have prepared the material your review will ask for at each stage, from planning to termination. If this is a product your team has been wanting, a short conversation is the ask. The proposal is quoted as a proposal, and the offer is the diligence material.

    To a vendor management lead at a credit union. The FDIC's letter on the interagency guidance lists five stages of a third-party relationship: planning, due diligence, contract negotiation, ongoing monitoring and termination. We have organised what we send institutions in that order. If it would help to see it before anyone on your side asks for a demo, a short conversation is the ask. The stages are the regulators' own.

    To a head of digital banking at a bank on a named core. Jack Henry describes its Fintech Integration Network as giving fintechs access to its technical resources to achieve product integration with its core platforms. We have completed that integration. If your institution runs that core, the connection work your team would expect is already done, and a short conversation is the ask. The programme is the core provider's own, and a fintech should send this only if it has completed the integration.

    To: Vendor management lead, a credit union

    The FDIC's letter on the interagency guidance lists five stages of a third-party relationship: planning, due diligence, contract negotiation, ongoing monitoring and termination. 1

    We have organised what we send institutions in that order. If it would help to see it before anyone on your side asks for a demo, a short conversation is the ask. 2

    Postal address and opt-out line in the footer. 3

    1. 1The five stages, from the FDIC's own letter of 6 June 2023.
    2. 2Offers the diligence material in the order the institution works, and claims no approval.
    3. 3The postal address and opt-out line the FTC's CAN-SPAM guide requires of every commercial email.
    The second sample opener taken apart, with the parts that tie it to the five stages the FDIC's letter names.

    What the strategy has to decide

    A fintech's sales strategy for regulated institutions is four decisions: what it will hand a bank at each of the five stages; whether it integrates with a core provider first or asks each bank to carry that work; how it describes the September 2026 proposal, which is a request for comment and not yet a rule; and which kind of relationship it is asking for, since lending, payment and deposit activities through the bank draw the heaviest review. What a supplier writing to fintech companies sees in reply, the opposite direction from this page, is in fintech cold email benchmarks.

    RevenueFlow's programme is written outreach, email and LinkedIn, one message per campaign, with the qualification criteria agreed in writing before launch and a fee per attended meeting that meets them. If reaching sponsors inside banks and credit unions in writing is the part you would rather have run, you can see what a campaign would look like for your market.

    The Federal Reserve Board, FDIC, Jack Henry and FTC pages were fetched on 18 September 2026 from the pages linked. The September 2026 guidance is a proposal open for comment; until it is finalized the 2023 guidance stands. Supervisory guidance is addressed to institutions, not vendors. Rules change; confirm them at the source. Nothing here is legal advice.

    Sources: Federal Reserve Board, joint press release of 11 September 2026, FDIC, Proposed Interagency Third-Party Risk Management Guidance, FDIC, Interagency Guidance on Third-Party Relationships: Risk Management, Jack Henry, Fintech Integration Network, FTC, CAN-SPAM compliance guide

    Questions

    Frequently asked questions.

    Frequently asked questions
    How do banks evaluate a fintech vendor?
    Through a third-party risk management process. The FDIC's letter announcing the 2023 interagency guidance says it gives examples of considerations in the planning, due diligence, contract negotiation, ongoing monitoring and termination stages of a third-party relationship, and that sound practice takes into account the level of risk, complexity and size of the bank and the nature of the relationship. Relationships involving lending, payment or deposit activities through the bank draw an additional layer of rules.
    What did the September 2026 third-party risk proposal change for fintechs?
    Nothing yet. On 11 September 2026 the Federal Reserve Board, FDIC, NCUA and OCC requested comment on guidance intended to help banks and credit unions tailor third-party risk management to the risks of individual relationships. The release calls it principles-based and non-binding, comments are due 60 days after Federal Register publication, and the agencies plan to rescind existing guidance only when it is finalized. Until then the 2023 guidance stands.
    Should a fintech integrate with a core banking provider before selling to community banks?
    It is a strategy choice with a published route. Jack Henry describes its Fintech Integration Network as giving fintechs access to its technical resources to achieve product integration with its core platforms and complementary solutions. A fintech that integrates first arrives at a bank's due diligence stage with one question answered and can write only to institutions on that core. The bank still runs its own review, because responsibility stays with the bank.
    When is direct outbound the wrong play for a fintech selling to banks?
    When the company has nothing to hand a bank at the due diligence stage, because a good first meeting leads straight to a request it cannot answer. When it writes to institutions on a core its product does not connect to. And when the message treats the September 2026 proposal as if it were final, since the bank's vendor management team has read the same request for comment and knows the 2023 guidance still applies.
    fintech salesB2B sales strategythird-party risk managementselling to bankscore providers
    Byline

    About the author.

    RevenueFlow Team

    B2B cold email experts helping companies generate qualified leads through done-for-you outreach campaigns.

    RevenueFlow Team

    Your next move

    Ready to scale your outreach?

    We build GTM engines that book real meetings. See the receipts.

    Further reading

    Related articles.

    B2B Sales Strategy

    Sales Strategy for Logistics Companies: Segment, Seat, Cycle

    How a broker, forwarder, carrier or 3PL sets its sales strategy: Armstrong's segments and contract terms, the four provider seats shippers keep, and the rate cycle.

    11 min readRead →
    B2B Sales Strategy

    Sales Strategy for Manufacturing Companies: Direct or Reps

    How a manufacturer decides whose salespeople carry its line: the published definition of a representative, MANA's agreement clauses and the split commission problem.

    10 min readRead →
    B2B Sales Strategy

    SDR Outsourcing for Fintech Companies: Assessability Test

    For the fintech weighing an outside setter: the three assessability sentences, the promotion rules that bind every message, the sponsor test and which model fits.

    11 min readRead →
    B2B Sales Strategy

    Lead Generation for Trucking Companies: Three Routes

    How a motor carrier finds freight customers: the load board, the broker relationship and the shipper's annual bid, with the calendar and the rules on outreach.

    11 min readRead →
    B2B Sales Strategy

    MEDDIC vs BANT: What Each Qualifies and When to Use Which

    MEDDIC and BANT from the originators' own text: IBM's BANT form as a gate after the first call, PTC's six themes as an audit of a live deal, and when to run each.

    10 min readRead →
    B2B Sales Strategy

    Gap Selling vs SPIN Selling: What Each Method Diagnoses

    Gap Selling and SPIN Selling from their authors' own pages: four question types that develop a stated need, against a measured gap between two states.

    9 min readRead →