
Maintenance
Part of Digital account guide: banks, nonbanks, balances, insurance, and access
Digital bank and finance app due-diligence checklist
Digital bank and finance app checklist covering legal identity, charter, partners, custody, records, insurance, fees, data, security, support, and exit risk.
What to take away
- Verify the product's legal provider, charter status, and partner institutions independently.
- Trace each balance from customer ledger to bank, broker, custodian, or issuer.
- Test insurance and protection claims against the failure they cover.
- Review operations, data access, complaints, migrations, and account closure before relying on the service.
- Scale exposure to what you can verify and recover.
Due diligence is not a hunt for a perfect app. It is a structured decision about which functions and amounts a product can safely carry for a particular user or business.
This checklist uses public records, governing documents, operational tests, and support responses. It does not predict failure or provide investment advice.
1. Define the intended use
- List the features you plan to use.
- Estimate average and maximum balance.
- Record monthly transaction count and size.
- Identify payments that cannot be late.
- Decide how long an access interruption is tolerable.
- Name an alternate account or payment route.
- Separate personal, business, and client money.
A product acceptable for occasional shared expenses may be unsuitable for payroll or operating reserves.
2. Verify legal identity and status
- Record the app brand and legal entity.
- Determine whether it is a bank, credit union, broker, lender, money transmitter, or service provider.
- Search the relevant official directory.
- Match legal name, website, address, certificate, charter, or registration number.
- Identify every partner named for the selected feature.
- Confirm whether marketing uses a trade name.
- Save the search results with a date.
Do not treat app-store review, press coverage, or a partner logo as official verification.
3. Map third parties
- Identify the bank or credit union.
- Identify program manager, middleware, processor, and card issuer.
- Identify broker, custodian, or sweep administrator.
- Find which entity maintains the customer system of record.
- Determine who performs reconciliation.
- Determine who handles support, disputes, and account closure.
- Record subcontractors that can affect core access where disclosed.
The OCC's guide to bank due diligence on fintech companies notes variation in operational history and governance and organizes review around business experience, financial condition, legal and regulatory knowledge, risk management, information security, resilience, and operational capability. Although written for community banks, the fintech due-diligence categories supply useful questions for judging a service on more than interface design.
4. Trace balances and custody
- Name the entity owing each displayed balance.
- Identify whether it is a deposit, prepaid balance, brokerage cash, security, loan proceeds, rewards, or digital asset.
- Record where funds are held.
- Determine whether accounts are direct, custodial, pooled, or swept.
- Find when funds reach the destination institution.
- Identify the beneficial-owner recordkeeper.
- Check whether app totals are reconciled to institution totals.
- Record withdrawal rules and holds.
If the product offers several balances, repeat the map for each one.
5. Test protection language
- Name the insurer or protection program.
- Name the covered institution and failure.
- Record limits and aggregation rules.
- Identify registration, titling, disclosure, or recordkeeping conditions.
- Separate deposit insurance from SIPC, private insurance, reserve claims, and fraud policies.
- Identify excluded products.
- Find treatment of nonbank insolvency.
- Ask how users would access funds if the app stopped operating.
Replace "protected up to" with a complete conditional sentence. If you cannot, the claim remains unverified.
6. Review financial and operational capacity
- Check years in operation and material ownership changes.
- Identify dependence on one bank, processor, or cloud service where disclosed.
- Review official enforcement actions and material litigation.
- Look for audited financial information if relevant and available.
- Review uptime and incident history without assuming a status page is complete.
- Examine reserves, holds, or negative-balance policies.
- Check whether rapid growth could strain support or reconciliation.
Silence is not evidence of weakness, but it limits what can be verified.
7. Read fees and economics
- Capture monthly, transaction, withdrawal, ATM, card, exchange, inactivity, and support fees.
- Identify revenue from interchange, spread, lending, subscription, data, or partner payments where disclosed.
- Compare yield calculation and change authority.
- Check minimum balances and qualifying activities.
- Identify fee treatment during failed or returned transactions.
- Calculate cost at your expected volume.
- Record notice requirements for changes.
An unsustainably generous promotion is not proof of misconduct. Treat it as a prompt to understand duration, funding, and conditions.
8. Evaluate data and permissions
- List data collected and imported.
- Identify whether the app reads balances, transactions, identity records, contacts, location, or device data.
- Determine whether it can initiate payments.
- Review sharing with affiliates, banks, processors, analytics, and advertisers.
- Find consent-revocation and account-deletion controls.
- Record retention after closure.
- Check data-export options.
Do not connect a primary bank login until you know the access method and revocation path.
9. Review security and resilience
- Confirm supported authentication methods.
- Protect recovery email and phone.
- Enable transaction, login, and profile alerts.
- Find device and session management.
- Review lost-device and takeover procedures.
- Confirm backups and alternate access channels where disclosed.
- Identify the official status page and incident contacts.
- Test statement download and support without exposing credentials.
Security claims need scope. A certified cloud component does not establish end-to-end account safety.
10. Assess customer treatment
- Find the formal error-notice route.
- Compare support hours with payment deadlines.
- Test whether support can identify the legal provider and partner bank.
- Read freeze, termination, and appeal terms.
- Identify complaint escalation and regulator.
- Check accessibility and language support.
- Search for recurring documented issues, then verify them independently.
- Preserve all case numbers and promised dates.
The Consumer Financial Protection Bureau's advisory on funds stored in payment apps distinguishes nonbank app balances from traditional insured accounts and urges users to understand where funds are held. Use that distinction before relying on customer-service assurances.
11. Test migration and exit
- Read change-of-bank and assignment clauses.
- Identify notice period for material changes.
- Check how routing changes affect direct deposits and debits.
- Determine whether data and statements remain available after closure.
- Confirm return method for a residual balance.
- Plan withdrawal before closing linked accounts.
- Revoke external access and recurring payments.
- Obtain a final statement and closure confirmation.
Decision record
| Finding | Evidence | Risk | Control | Decision |
|---|---|---|---|---|
| Partner bank verified | Official directory | Low | Recheck after notice | Accept |
| Subledger access unclear | Terms and support | High access risk | Keep low balance | Limited use |
| No alternate support | Published policy | Deadline risk | Do not use for payroll | Reject payroll use |
Record the decision by use case, not as a permanent rating of the company.
Common questions
How much research is enough?
Research should scale with balance, transaction volume, deadline sensitivity, and recovery difficulty. Unknown custody or legal identity is a stopping point.
Are customer reviews useful?
They can reveal questions to investigate. They rarely prove cause, frequency, or current policy without records.
Does a regulator listing guarantee service quality?
No. It verifies a status or registration within that directory's scope, not uptime, fairness, solvency, or fit.
When should a product be reviewed again?
After a partner, ownership, terms, routing, protection, or feature change, and periodically when it carries material funds.







