July 22, 2025

# Sponsor Banks Can Now Collect TINs from Third Parties - Here’s What That Means for Fintechs

FinCEN just changed the rules for how some banks and credit unions can collect a customer’s Taxpayer Identification Number (TIN). It’s a targeted shift, but it could ripple into your onboarding flows – especially if you rely on a sponsor or FBO relationship bank.

Let’s unpack what changed, who it applies to, and why [Fintechs](/content/industries/fintechs/index.html) should be watching closely.

### Why This Matters

Fintechs don’t operate in a vacuum. When your [sponsor bank](/content/industries/sponsor-banks/index.html) rewires its [CIP process](/content/glossary/customer-identification-program/index.html), you may be expected to change your flows too, but that can break your IRS reporting, introduce data conflicts, or expose you to backup withholding penalties.

### What the FinCEN Order Says

FinCEN now allows certain regulated banks and credit unions to collect a customer’s TIN from a third party – not directly from the customer – before account opening.

But there are guardrails. This new flexibility only applies if:

- The institution is regulated by the OCC, FDIC, or NCUA
- TINs are collected before the account is opened
- The process is risk-based, documented, and preserves a “reasonable belief” in customer identity
- There’s no added risk of money laundering, terrorist financing, or other illicit activity

> #### Read the full Order: [FinCEN Permits Banks to Use Alternative Collection Method for Obtaining TIN Information](https://www.fincen.gov/news/news-releases/fincen-permits-banks-use-alternative-collection-method-obtaining-tin-information)

### Who’s In and Who’s Out

**Covered by the Order:**

- OCC-regulated banks
- FDIC-insured banks
- NCUA-supervised CUs

**Not Covered:**

- Fintechs
- MSBs
- Non-bank FIs

If you’re a Fintech registered as a Money Services Business (MSB) – which includes most prepaid, neobank, and remittance models – this Order does not apply to you directly.

You’re still bound by:

- 31 CFR §1022.220 (MSB CIP rule)
- IRS tax reporting obligations under IRC §§ 3406 and 6109

### Real-World Scenario: Where This Gets Messy

Let’s say your partner bank collects a TIN upstream from a third-party vendor.

Later, your user updates their profile with a self-reported TIN – one that doesn’t match. Now you’ve got:

- Conflicting data
- Broken audit trails
- And a 1099 that could trigger a 24% backup withholding penalty under IRC §3406

### Visual Breakdown: What’s at Stake with Mismatched TINs

|     |     |     |
| --- | --- | --- |
| **TIN Status** | **Reporting Risk** | **Withholding Risk** |
| ✅ Valid and matches IRS | None | None |
| ⚠️ Invalid or mismatched | 1099 error | 24% backup withholding required |

### What Fintechs Should Do Now

- **Don’t change anything yet:** Stick with your current TIN collection and CIP flows unless a regulated bank partner formally requests changes.
- **Talk to your sponsor banks:** Ask if they plan to adopt the new framework – and under what written procedures.
- **Clarify ownership:** Who owns IRS tax compliance? Where’s the source of truth for the provided TIN?
- **Track your data lineage:** If a TIN comes from a third-party source, tag it. Preserve traceability for audits and disputes.
- **Prepare for mismatches:** What happens if the TIN collected by the bank doesn’t match the one you get later? Build a fallback plan.
- **Check with tax counsel:** Ensure you’re protected under backup withholding rules if you process reportable payments.

### Final Word

This isn’t a regulatory green light for Fintechs but it is a flexibility granted to banks – under strict controls – that might cascade into your [onboarding](/content/use-cases/onboarding/index.html) stack.

Unless your regulated partner makes a move, don’t change your flows. But be ready if they do.

And no, this isn’t legal advice. But it’s exactly the kind of thing your [compliance](/content/blog/regulatory-compliance/index.html) and ops teams should be tracking closely.
