Open Review of Management, Banking and Finance

The regulation of fintech banks: questions and perspectives.

by Valerio Lemma

Abstract: This analysis concerns the regulation of fintech banks, having regard to the possibility of a business model in which the production and delivery of banking products and services are based on technology-enabled innovation. We will go deep into European Central Bank’s definition of ‘fintech bank’, in order to understand the role and the scope of supervision.

Indeed, this paper highlights the possibility that the software of fintech banks will unbundle banking into its core functions of settling payments, performing maturity transformation, sharing risk and allocating capital. Hence, we will consider both the benefit of machine-learning techniques in respect of credit scoring, and the risk of using self-executing software that may affect the supply and demand.

Summary: 1. Introduction. – 2.   The ECB and the definition of ‘fintech bank’. – 3. The regulatory relevance of fintech. – 4. New ways of (dis)intermediation. – 5. Concluding remarks.

1. The direct effects of innovation on banking are catching the attention of the European policymakers, and they are challenging the choices of the EU regulators, as the rules of the EU capital market provide for the public intervention in the real economy and financial market (having regard to Articles 41 and 47 of the Italian Constitution, as well as Article 127 of the Treaty on European Union).

In the banking industry, there are evidences that the application of the fintech innovations interacts with the business model of a credit institution, and therefore it requires assessing and managing the risks that could arise because of the use of algorithms, software and platforms designed and run by third parties.[1] To this end, obviously, the policymakers are called to prevent that the benefits (of fintech) will resolve to the detriment of the overall financial stability or the common welfare.

As a preliminary remark, we set a boundary of this analysis with respect to the awareness on opportunities and benefits that may arise from the application of mechanisms able to drive the credit institutions both towards the maximization of their outcome and away from the most dangerous transactions. In this respect, it is worth beginning from the micro prudential aspects of the application of algorithms and of the use of big data, as their impact on financial processes, procedures, and services may reduce their operational risk profile (being it dependent on the type of technology underlying the business model). However, this would result in a new kind of risk, due to the capacity of software to reach the aforesaid goals, as well as in a combination of outsourcing risks and cyber-security issues.

2. European Central Bank’s definition of ‘fintech bank’ goes beyond the identification of a new type of market player that falls within the scope of its special guidelines, and suggested that this player presents the features of the credit institution set forth by the Regulation (EU) no. 575/2013 and the fintech firm provided by the Financial Stability Board.

The material effects of this definition refer to the identification of a new phenomenon, due to the possibility that technological evolution and financial innovation allow a greater efficiency in the circulation of capital, as well as the convenience of services alternative to banking, financial services and insurance.[2]

In this respect, it is worth considering that the monitoring of this phenomenon suggests the existence of “a business model in which the production and delivery of banking products and services are based on technology-enabled innovation”, and this leads to the identification of a decentralized network, in which supervised entities and other firms may satisfy a portion of the demand for investment, credit, or risk mitigation. [3] Thus there is the need to focus on the role of law in the implementation of minimum standards and the development of supervisory remedies.

Up to date, scholars have made empirical observations of fintech firms able to supply financial services supporting lower (operating) expenses and transaction costs, due to the flexibility of their organizational structure. [4] Therefore, our research concerns a comprehensive assessment of the applicable regulatory framework, in order to verify the opportunity to extend the scope of supervision and the tasks of the national and supranational authorities.

Any economist may argue that in capital markets the parties are fungible, however, from a policymaking perspective any regulator shall consider that, in dealing with savings, individual rights do matter. In this respect, we have to assume that the role of private law will continue to refer to the safeguard of transparency, having regard to the protection of the good faith from the bargaining power. This implies the responsibility of individuals and the use of contractual sanctions able to avoid that a transaction jeopardizes the welfare. Nowadays, we are facing a new phenomenon that recognizes specific value to certain attributes of the personality (that can also be shared or traded without being a direct and immediate burden for the person), and promotes both the ‘objectivation’ and the ‘contractualization’ of such attributes. Moreover, there are problems of the individuals’ capacity to be in the position to negotiate them, to understand what they are negotiating, and to withdraw from such negotiations (or the relevant agreements). So, policy makers are called to set up a system of safeguards and backstops able to protect the weak parties from such shortfalls as the exploitation of fintech tools, misconduct in managing personal data and abuse of power due to profiling. In this situation, we cannot accept the thesis that reduces the relevant shortfalls to data limitations only, nor to the mere incapacity of analyzing all the data collected. Accordingly, it is not efficient a system that is based on the consensus, as the weak party may provide his/her acceptance without understanding the actual implications of such act.

As the presence of many tech-fueled firms operating in the capital markets is an outstanding evidence, we are assuming that the mere application of software does not have effects on the qualification of the activity, as banking or finance refers to the exploitation of an organizational structure of people and own funds,[5] and therefore to a license related to the reserve of activity provided by the current regulatory framework.[6] On the contrary, we would consider that these firms cooperate through networking web-based platforms,[7] and they satisfy the demand of capital, maturity transformation and risk mitigation, usually by means of special purpose vehicles (SPVs) or contracts that directly connect demanders and suppliers. This cooperation would lead to new areas of competition and to the systemic importance of certain providers (with respect to cloud, business analytics and interface programming), and the use of common approaches to decentralization could imply pro-cyclicality (that should be regulated).

Because of the above, our preliminary remark considers that, within the internal market, any entity needs a license to collect savings or grant credit,[8] so that we are going to investigate the regulatory effects of a software that creates a network of independent companies able to replicate the activity of a credit institution. As it has been stated that «to its advocates, this wave of innovation promises a fintech revolution that will democratise financial services»,[9] the regulatory analysis of fintech must identify the backstops and the safeguards able to protect individual rights within a rapidly expanding environment where certain firms perform activities (outside the boundaries of the traditional supervision) that concerns savings, credit and money.[10]


3. Policymakers are in front of a turning point: promoting the deregulation of banking or applying the traditional principles to regulate fintech, and then to set the obligations of fintech firms vis-à-vis the individuals and any other supervised entity. In other words, the need for an inclusive market cannot jeopardize the competitive design of an industry that includes both traditional and high-tech businesses.

In this respect, the analysis of the scope of the prudential supervision may include any combination of transactions that can be executed by means of a platform and a software in order to let the capital circulates. Indeed, there are no doubts that such way of execution can be considered as any alternative to banking, and as such might be part of the same relevant market. In this respect, any asymmetry in regulation jeopardize the level playing field that ensure the fair competition for banking and financial services.

This leads this part of the research to consider the juridical difference between in-house performing of banking and the new opportunities due to networking, provided that the latter would require a set of parties and enterprises, whose responsibilities can be placed out of the subjective perimeter of the fintech bank.[11]

In considering the relevance of networking (as a way to non-bank financial intermediation), we focus on the importance of the bilateral agreements that lies under any link of these networks. over both the right to audit (for the supervised entities’ internal and external auditors) and the duty to provide ‘own funds’ to cover the expected losses (calculated on the basis of the relevant operational risks). Hence, our suggestion to update the current schemes provided by private law, which rely on assets and liabilities that are not virtual (and so cannot exploit the possibility offered by digitalization with respect to sharing, common usage, duplicability, intermediation, etc.).[12]

This also highlights that the current challenge in the banking industry is occurring – not only for capital, but also – for technology and connections. In this perspective, the functioning of the financial markets may be influenced by fintech goods (e.g. cryptocurrencies), information (e.g. big-data) and services (e.g. analysing, programming and coding). Furthermore, in this context, the web-based platforms would be the competitors and the territories where such competition occurs, as they are able to support the trading of big-data, application programme interfaces (APIs), algorithms, and decision-making software. It follows the need for disclosure and transparency, as well as the oversight of any form of the firms’ delegation of their decision-making process to artificial intelligence (programmed by third parties).

It is clear that fintech is based on networks that allow the wide-spreading of big data and technology, and this is the way to cross jurisdictions and offshore of activities substitutional to banking and finance.  From this perspective, even if all the above is suggesting that a new form of capital circulation arises, there are no reason to avoid the supervision of this sort of ‘open banking’ has to be supervised (as a part of the wider definition of banking).  Thus the need for questioning the assumption that an intermediary (having a legally protected interest in funding and lending from the people) is the only firm that has an incentive to develop the organizational structure required for assessing the creditworthiness and managing the relevant risks of lending.

All the above emphasizes the need for regulating the innovations in banking, as this trend goes straight to the development of fintech bank.[13] In this respect, regulators cannot neglect the importance of any huge aggregate amount of data, as well as any third party owning or managing data processing services (art. 4, paragraph 1, point 18, of EU Regulation no. 575/2013, as amended by EU Regulation no. 2019/876 and art. 3, paragraph 1, point 17, of Directive 2013/36/EU).

It is worth recalling the advice of the European Banking Authority (EBA) with respect to the necessity of regulating the use of high-tech tools by credit institutions, obviously according to the general principle of proportionality (with respect to the size, structure and operational environment of the institution, as well as the nature, scale and complexity of its activities).[14]

From a regulatory perspective, the use of high-tech tools arises the risks associated with ‘cloudy chains’ and the ‘cooperation among providers’.[15] Indeed, a decentralized organization may exploit the application of fintech solutions, and this may lead to the use of business analytics able to improve the rational decision making process and the possibilities for correct behavior and safe management.[16]

We are not considering how the transaction costs enter into this analysis. It is sufficient to assume that the impact of technology on the negotiation of demands and supplies is relevant. This means also that the application of fintech to such combination has to achieve an economically significant scale, with respect to risk-taking, decision-making and record-keeping.[17] In this respect, we would also assume that the leveraging of digitalization would promote a change in the operational structure of firms, and the questions would refer to the way that the regulator will choose to go straight to this point.

A significant remark on this point refers to the possibility of setting up new regulatory standards for firms involved in the functioning of cryptography, blockchain applications and distributed ledgers used in the market for capital. Indeed, regulatory standards should ensure gains in the accuracy, efficiency and security of processes across payments, clearing, and settlements.

4. It is worth investigating whether there are new ways for (dis)intermediation. This analysis would not refer to the possibility of escaping from the prudential supervision, but to the opportunity of reaching an equilibrium able to sustain the wealth, the growth, and the stability of the financial market, as well as to safeguard individual rights and the common welfare. We are going to continue what was anticipated above with respect to the role of regulators in seeking to ensure that standards provided for protecting individual rights are effective.

In addition, it is useful to highlight that in March 2018 the EBA published its ‘Fintech Roadmap’, setting out the priorities for further work on financial innovation.[18] The content of such publication confirms that the European approach still considers innovation an important separate matter, [19] as it established the relevant supervisory authorities providing for the institution of a Committee as an integral part of these authorities (and, in addition to the ESMA’s Committee, it also required the Committees of EBA and EIOPA, as stated in article 9, paragraph 4, of both Regulation (EU) no. 1093/2010 and no. 1094/2010).[20]

Notwithstanding the above, we may observe that the role of supervision is still limited to observing the organizational structure and the business program designed by including certain self-executing activities that are available in the banking sector (and this observation occurs mainly when granting authorisation under Directive 2013/36/EU, Directive (EU) 2015/2366, and Directive 2009/110/EC). In this context, the supervisors may not be able to control the work that is behind the structuring of such self-execution tools, which is the reason for the risk that supervisors will delay their intervention on the new, developing industry of software developers and device manufacturers. [21]

In particular, we recall the EBA’s analysis of the national regulatory status of innovative business models or self-executing delivery mechanisms.[22] A close look at EBA’s methodology suggests that national regulators are not in the best position to consider high-tech activities and services (including the ones of an ancillary/non-financial nature), and global supervisors are still involved with the mere monitoring of fintech.[23]

In brief, the analysis of fintech is showing that the financial system is wider than the markets that are supervised. The possibility to identify a ‘market for fintech’ refers to the demand made by credit institutions, financial firms and insurance companies. The focus on this demand suggests the need for regulating internal controls over fintech providers, designed to avoid that a business model (drawn on certain machinery management mechanisms) allows the use big data and advanced analytics to collude. Thus, our interest leads us to the possibility of supervising programmers and coders, which cannot be considered as mere third-party, but as the professionals able to support the execution of the core reserved activities. This helps in recognising the rising of a new industry, whose radical innovations challenge the capacity of the current supervisory authorities to regulate and control this high-tech business.

We are aware that the traditional models of transactions and the basic rules of private law do not consider the sustainability of development and financial stability as duties of the party. Hence, we cannot deny that regulation and control would result in losses (of efficiency) and an increase in the level of the systemic risks (despite the relevant public intervention). This does not cast the doubt that the harmonization of all rules across EU countries is delayed by the practical difficulty of setting regulatory standards concerning technology, given their different economies, judicial systems, social, and cultural backgrounds.

However, regulatory differences in private law (and its enforcement) can not only suggest a sort of ‘forum shopping’ (in choosing the jurisdiction and the law applicable to the contracts), but also delay technology diffusion as in the case of conflicting competition, financial, and intellectual property laws. These elements create uncertainties and raise transactional costs, as public or private remedies should avoid that the outcomes of a single transaction jeopardize the common welfare. This does not undermine the enforcement of private law but highlights it. Indeed, the alternative would drive individuals within a hierarchy with a regulation of the juridical relations of the groups based on pure orders and their executions.

5. Above and beyond, it is important to highlight the possibility that the software of fintech banks will unbundle banking into its core functions of settling payments, performing maturity transformation, sharing risk and allocating capital. Because of this unbundling, a chain may be weaved and a new sequence of non-bank financial intermediation is activated. Therefore, the industry may lead to a structure that promotes the outsourcing of each function to an independent fintech firms, such that they are able to act as innovative trading platforms alternative to payment service providers, aggregators and robo-advisors and lenders.

According to the above, however, the need for new form of supervision over programmers and coders arise. Even if the current EU legal framework provides the principles of proportionality and flexibility, the regulation of fintech banks cannot retrain from consider the innovative business model and delivery mechanisms.[24] Otherwise, there will be doubt about the effectiveness of any supervisory methodology that considers only the capital and organizational adequacy, without taking into account the role of algorithms, software, platforms and big-data (with respect to article 12(4) od CRD IV).

Obviously, our conclusion will focus on the prudential regulation and in particular on the broader ongoing digital transformation across institutions’ credit risk management functions. We are aware that the fintech banks will exploit also machine-learning techniques in order to improve their capabilities in both credit scoring and monitoring of quality of existing debtors, however this may imply that all the banks using the same software may align their offering, so that the effect may be similar to the one of certain unfair market practices aimed at reducing competition. In order to confirm this risk, we can rely on ‘best practices’ regarding innovation facilitators, intended to provide indicative support for supervisors and to promote convergence in the design of the fintech tools and the operation of innovative mechanisms. However, at current stage of the supervisory practices, it may not be possible to perform a comparative analysis of the innovation facilitators, which would identify the premises required for establishing the safeguards useful to ensure a competitive approach to the market.[25]

In this respect, the innovative use of technology by supervised entities may lead to a close relationship between micro-prudential supervision and the protection of competition, which can be put at risk by a misuse of big-data and business analytics too.[26]

In conclusion, the role of the supervising authorities seems to be fundamental for ensuring the functioning of a safe and competitive market for capital. In particular, we cannot exclude that the current trends would lead to dependencies on fintech providers, such as device manufacturers, programmers and coders. Indeed, all the above leads us to highlight that banking and finance requires specific backstop in order to set up business models able to promote an efficient use of the fintech innovations, as it is the use that maximize anyone’s position without reducing the wellness of the other market participants. Indeed, it seems necessary to extend the supervision to the logic behind the software used by fintech banks, and then to the humans that lie under the design of algorithms, the evolution of big data and the intertwining of the networks.



Valerio Lemma is Full Professor of Law and Economics at the Law Faculty of Università degli Studi Guglielmo Marconi in Rome, and Coordinator of the Master programme in «Financial market regulation» at Luiss University.

