TL;DR
- Holding a money transmitter license does not end regulatory scrutiny; the 2023 Interagency Guidance (Fed, OCC, FDIC) makes clear third-party use "does not diminish" a licensee's responsibility for outsourced activity.
- NYDFS FILMS ratings and the CSBS Money Transmission Modernization Act, adopted by 40+ states, treat third-party oversight, including provider fee accuracy, as a named exam criterion, not a courtesy check.
- Manual invoice review is the exposed gap: teams eyeball totals instead of reconciling effective rates against contracted rates at transaction level.
- Real leakage found this way: a $300K KYC overcharge at Deel, 8.5% fee leakage at BlindPay, $150K at Toku, and $58K annualized at Thera and Bloom.
Short answer
Getting the license is the easy half. Once you hold a money transmitter license, regulators hold you accountable for every provider moving money on your behalf, including what they charge you.
Third-party oversight is a named exam criterion rather than a checkbox. The 2023 interagency guidance says using third parties does not diminish your responsibility. NYDFS rates internal controls inclusive of agent oversight. The CSBS model act standardises delegate oversight across 40+ states.
So the question an examiner asks is simple. How do you know your providers are performing to contract, including what they bill you? "We review invoices" is not an answer.
Every fintech founder has the same roadmap slide. Get the MTL. Unlock direct money movement. Cut out the middleman. Own the margin.
Fair. The money transmitter license is valuable. But the industry is obsessed with getting licensed and almost silent on what licensure actually obligates you to do. The license is not the finish line. It is the moment regulators start holding you accountable for everything in your money movement stack, including the parts you outsource.
Here is the part nobody prices in. When you hold an MTL, your upstream providers become your problem. Every FX provider, KYC vendor, payout rail, and banking partner moving money on your behalf is, in the regulator's eyes, an extension of you.
The evidence is not buried. It is written down, in plain language, by every regulator that matters.
You retain full responsibility for outsourced activity
Start with the 2023 Interagency Guidance on Third-Party Relationships, issued jointly by the Federal Reserve, OCC, and FDIC (Fed SR 23-4, OCC 2023-17, FDIC FIL-29-2023).
The guidance is explicit. A banking organization's use of third parties "does not diminish its responsibility to meet these requirements to the same extent as if its activities were performed by the banking organization in-house." Examiners hold the institution accountable for vendor performance as if it performed the activity itself.
This binds banks directly. It reaches every licensed fintech through bank partnerships. Your sponsor bank's examiner expectations become your contract terms. If a bank moves money for you, or you move money through one, this framework is already flowing down to you.
The guidance already describes the contract nobody checks
Read the Costs and Compensation section of that same guidance. Contracts, it says, "commonly describe compensation and fees, including cost schedules, calculations for base services, and any fees based on volume of activity and for special requests." The stated reason is to reduce misunderstandings and disputes over billing.
Read that as a description of a sound provider contract, because that is what it is. The regulator is describing a document that prices every charge you will ever receive, in terms specific enough to check a charge against.
Then look at whether anyone checks. A contract term you never verify is not a control. It is a decoration.
Ongoing monitoring is continuous and performance-based
The guidance requires ongoing monitoring to confirm a third party's ability to meet its contractual obligations. That includes performance measures and benchmarks, the right to audit and require remediation, review of audit and testing results, and escalation of issues when identified. Higher-risk activities require more comprehensive or continuous monitoring.
Moving money on your behalf is the definition of a higher-risk activity.
KPMG's summary of the monitoring requirements is a useful shorthand if you want the short version.
State regulators examine this directly
This is not just a bank flow-down story. State money transmitter regulators test it themselves.
NYDFS assigns every licensed money transmitter a FILMS rating. One of the rated components is internal controls and auditing, and the department's own language says the evaluation is inclusive of agent oversight.
Massachusetts has told licensees the same thing since 2012. Division of Banks guidance states that a significant component of a licensee's internal control practices is ensuring an adequate level of oversight of third party providers, and exercising an appropriate level of due diligence in selecting them.
And the standard is now near-universal. The CSBS Money Transmission Modernization Act has been adopted in full or in part by 40+ states, covering 99% of reported money transmission activity. It standardizes audited financials, authorized delegate oversight, and event reporting across the country. The full model act text is public.
So the requirement exists. Here is what actually happens in practice.
The gap
Provider invoices arrive monthly as PDFs or CSVs with thousands of line items. Contracts live in a legal folder nobody in finance opens. Fee verification means someone eyeballs the total. Nobody reconciles effective rates against contracted rates at transaction level. Nobody catches when a provider misapplies a fee cap, a tier, or corridor pricing.
The result is fee leakage that compounds silently. We know because we keep finding it. A $300K KYC overcharge, found while scaling Deel's financial operations by manually reconciling provider invoices against contract terms. 8.5% fee leakage at BlindPay from a systematically misapplied fee cap. $150K identified at Toku. $58K annualized at Thera and Bloom. These are not edge cases. They are what happens when the monitoring requirement is met with a spreadsheet and good intentions.
The compliance side of the same gap surfaces at the worst possible time. During a state exam. During a bank partner audit. During an enterprise customer's vendor due diligence, when they ask how you verify what your providers charge you and the honest answer is that you don't.
The point
If you are pursuing an MTL, or you already hold one, third-party oversight is not a checkbox. It is a named exam criterion. The question an examiner will ask is simple. How do you know your providers are performing to contract, including what they charge you?
"We review invoices" is not an answer. Transaction-level verification of every provider charge against contract terms is. That is what regulators mean by monitoring. It also happens to be the same discipline that recovers real money.
The companies that treat provider oversight as infrastructure get two things: clean exams and recovered margin. Everyone else gets neither.
Frequently asked questions
Does a money transmitter license end my compliance work?
No. The license is where it starts. Once you hold an MTL, regulators hold you accountable for every provider moving money on your behalf, including what they charge you.
Is third-party oversight actually examined, or is it a checkbox?
It is examined directly. The 2023 interagency guidance says using third parties does not diminish your responsibility. NYDFS rates it under internal controls, and the CSBS model act standardises delegate oversight across 40+ states.
What does an examiner expect for provider fee monitoring?
Evidence that providers perform to contract, including what they bill. "We review invoices" does not qualify. Transaction-level verification of every provider charge against contract terms does.
What does weak provider oversight cost in practice?
Silent fee leakage. Manual review has missed a $300K KYC overcharge at Deel, 8.5% leakage at BlindPay, $150K at Toku, and $58K annualized at Thera and Bloom.
That is what we built Bluefyn to do. Contract-aware verification of every inbound provider charge, continuous and automated, at transaction level. The regulatory requirement and the financial win are the same product. Bluefyn never moves, holds or custodies funds. It analyses transaction and provider data.
If you are heading into licensure, a bank partnership, or an exam cycle, talk to us before the examiner asks the question.



