Featured answer: Embedded-finance and neo-conglomerate risk arises when regulated financial services, technology platforms and commercial partners share customers, data and operations across different legal and supervisory perimeters. Control requires ecosystem mapping, clear accountability, consolidated incident and conduct data, dependency limits and stress tests that follow services rather than entities.
The ECB's July 2026 Occasional Paper on neo-conglomerates examines groups and ecosystems combining financial and non-financial activities in ways that challenge traditional regulatory perimeters. White-label arrangements can place the customer interface with a commercial or technology partner while the regulated institution remains responsible for core financial services. This creates a practical governance gap: legal contracts divide tasks, but customer harm, data failure and operational disruption move across the whole service chain. Boards need an ecosystem view that is more detailed than a vendor register and more decision-oriented than a group chart.
The practical question for risk leaders is not whether uncertainty can be removed. It is whether exposure, assumptions, limitations and management actions are explicit enough to support a decision before risk capacity is consumed. The analysis below treats current regulatory publications according to their legal status and labels the numerical example as hypothetical.
Key takeaways
- Map the end-to-end customer service across regulated and unregulated entities.
- Assign accountability for onboarding, marketing, data, complaints and incidents.
- Aggregate concentration across common technology and distribution partners.
- Test platform failure, partner misconduct and rapid customer migration.
- Preserve exit data, portability and service continuity before dependence grows.
Why embedded finance neo conglomerate risk matters now
Embedded finance separates brand, customer interface, product manufacturing, balance sheet and technology. A customer may believe the platform provides the service even when a bank or insurer carries the regulated contract. Misaligned disclosures, incentives or complaint routing can create conduct risk and delay remediation. The regulated entity cannot outsource accountability merely because it does not control the interface.
Data fragmentation makes risk difficult to observe. The platform may hold behavioural and marketing data, the financial institution holds contractual and transaction data, and a cloud or identity provider holds operational logs. Without agreed identifiers, retention and access rights, no party can reconstruct the full customer journey or detect systematic harm. Data quality therefore becomes a prudential and conduct issue, not just an analytics concern.
Concentration can hide behind multiple contracts. Several brands may rely on one white-label financial provider, while several providers rely on the same cloud, identity or payment platform. A disruption can trigger simultaneous customer contacts, withdrawals, claims or payment failures. Exit plans need realistic capacity, data portability and communications, because replacing a visible customer interface is not equivalent to replacing a back-office vendor.
The risk should be mapped as a transmission chain. A trigger changes values, cash flows, behaviour or operating capacity; those first-order effects can then alter collateral, funding, counterparty strength, customer outcomes and management options. Timing matters as much as end-state loss. A modest deterioration that arrives before liquid resources or governance approval can be more dangerous than a larger loss that develops slowly.
Technical framework
Build a service graph with nodes for legal entities, platforms, critical systems, datasets and customer touchpoints. For service k, calculate dependency score Dk = Σwj × cj × sj, where w is activity share, c substitutability factor and s severity if unavailable. Add a responsibility matrix for every customer outcome and control. Scenario tests should combine platform outage, corrupted onboarding data, misleading marketing, complaint surge, liquidity outflow and partner insolvency. Measure affected customers, value at risk, time to detect, time to restore, unresolved complaints, data-reconciliation breaks and capacity of alternative providers.
No single metric is sufficient. Sensitivities explain local behaviour, base-case projections describe the central path, severe but plausible scenarios explore nonlinear outcomes, and reverse stress testing identifies combinations that breach a capital, liquidity, funding, mandate or service boundary. Where probability estimates are used, the team should show sampling error, parameter uncertainty and dependence assumptions rather than presenting the output as a precise forecast.
Data requirements and controls
The inventory should include legal agreements, customer journeys, APIs, data fields, consent and retention rules, marketing approvals, pricing, complaints, incidents, service levels, subcontractors, transaction volumes and exit dependencies. Use stable service and customer identifiers across parties. Contracts should secure timely access to event and audit data, but governance must also test whether those rights can be exercised during dispute or insolvency.
Every material input needs an owner, effective date, source and transformation record. Reconcile exposure totals to an authoritative ledger or administrator, reconcile scenario outputs to finance or actuarial views, and retain the exact input and model version used for each committee paper. Missing data, overrides and manual adjustments should be visible in the result rather than repaired silently.
Validation and independent challenge
Independent assurance should trace representative customer journeys from advertisement to closure, reconcile partner and regulated-entity records, test access to audit logs and sample complaint outcomes. Resilience exercises should disable a real dependency in a controlled environment and test manual alternatives, capacity and data recovery. Conduct validation should examine incentives and outcome differences by channel. Legal review must distinguish contractual allocation from regulatory accountability.
A useful challenger is designed around a specific uncertainty. Repeating the production method with different software adds little. The challenger should vary a key assumption, data source, method or dependency structure and compare decision impact. Findings need severity, owner, compensating control and closure evidence; a long limitations list without consequences is not governance.
Hypothetical practical example
The following figures are illustrative and are not empirical market observations. A hypothetical retailer offers savings accounts through a white-label bank and a separate technology platform. The retailer owns the app and marketing, the bank owns the account and the platform performs onboarding. A faulty rule rejects identity documents for one customer segment, while complaint messages remain in the retailer's system. Each firm's dashboard appears normal. A joined service-level control detects that rejection rates doubled and complaints were not transferred within 24 hours, enabling remediation before regulatory and reputational damage expands.
The example is not a recommended calibration. It demonstrates the required decision path: establish the baseline, state the shock, identify the binding constraint, test feasible actions and quantify residual exposure. Before operational use, every parameter must be replaced with controlled institution-specific evidence.
Stress testing and decision use
Scenario design should combine a coherent narrative with explicit paths for relevant risk factors. The path must reflect when cash, collateral, losses and management actions occur. At minimum, management should see a baseline, an adverse case, a severe reverse-stress case and targeted sensitivities to the assumptions that drive the decision.
Management actions should not be treated as free offsets. Asset sales may crystallise losses; hedges may require collateral; repricing may change customer retention; capital actions require approval; and several firms may attempt the same mitigation. Report gross impact, action benefit, execution cost, time to implement and residual risk separately.
Risk-management and governance framework
One accountable executive at the regulated institution should own each end-to-end service. Product approval must include partner incentives, data lineage, customer communications, resilience and exit. Risk appetite should cover partner concentration, unresolved data breaks, complaint transfer, critical-service recovery and customer-outcome indicators. Ecosystem changes require reassessment even when no individual contract is materially amended.
Risk appetite should be expressed in measures that management can control. Each operating threshold, escalation threshold and hard limit needs a frequency, owner, response time and approved action. Exceptions must record rationale, expiry and compensating controls. Repeated exceptions indicate that the limit, the model or the business strategy needs reconsideration.
Regulatory perspective
The ECB Occasional Paper is analytical research and policy evaluation, not binding legislation. Existing banking, insurance, payments, consumer-protection, outsourcing, DORA, AML and data-protection obligations may apply depending on the activity and jurisdiction. Firms must identify the responsible regulated entity and applicable rules for each service. References to a regulatory perimeter should not be read as permission to leave customer or operational risk unmanaged outside it.
Source hierarchy matters. Binding legislation and directly applicable rules must be distinguished from supervisory guidance, consultations, international standards, stress-test specifications and the author's analytical recommendations. Institutions should confirm entity-specific requirements rather than treating a cross-sector article as legal advice.
What risk leaders should do now
- Create an end-to-end service and accountability graph.
- Reconcile customer, incident and complaint data across partners.
- Set ecosystem concentration and substitutability limits.
- Exercise partner outage, misconduct and insolvency scenarios.
- Secure tested data-access and portability rights.
- Report customer outcomes and residual accountability gaps to the board.
Implementation sequence
Begin with a focused diagnostic covering exposure, systems, models, policies, committees and open findings. Prioritise the gaps most likely to change a decision under stress. Assign accountable owners and evidence of completion, then integrate the work into existing risk, finance, treasury, actuarial or investment processes. A separate project that never reaches pricing, limits, allocation or contingency plans will not improve resilience.
After implementation, review effectiveness on a fixed schedule. Ask whether indicators arrived early enough, whether assumptions remained credible, whether actions were executable and whether realised outcomes revealed missing dependencies. Feed those findings into data, calibration, scenario design and risk appetite.
Limitations
This article provides a professional framework, not institution-specific legal, regulatory, actuarial or investment advice. Appropriate methods depend on portfolio structure, contractual terms, data, accounting treatment and applicable law. Current claims are dated 16 Aug 2026; later rules or market developments may change the interpretation.
Conclusion
Neo-conglomerates test whether governance follows the service or stops at the legal boundary. Institutions that map customer outcomes, data and operational dependencies across the ecosystem can retain accountability while benefiting from specialised partners. Those that rely on fragmented contracts risk discovering the true system only after an incident.
The durable standard is evidence that analysis changes decisions before losses or cash demands become unavoidable. That evidence should include controlled data, documented assumptions, severe scenarios, credible actions, independent challenge and traceable approvals.
References
- European Central Bank, Neo-conglomerates and EU regulatory perimeter challenges, Occasional Paper No 394, July 2026
- European Central Bank, Occasional Papers index, No 394
- European Banking Authority, EBA Work Programme 2026
- Bank for International Settlements, The financial stability implications of artificial intelligence, 26 January 2026
Frequently Asked Questions
What is embedded finance neo conglomerate risk?
Embedded-finance and neo-conglomerate risk arises when regulated financial services, technology platforms and commercial partners share customers, data and operations across different legal and supervisory perimeters. Control requires ecosystem mapping, clear accountability, consolidated incident and conduct data, dependency limits and stress tests that follow services rather than entities.
Why does embedded finance neo conglomerate risk matter in 2026?
The ECB's July 2026 Occasional Paper on neo-conglomerates examines groups and ecosystems combining financial and non-financial activities in ways that challenge traditional regulatory perimeters. White-label arrangements can place the customer interface with a commercial or technology partner while the regulated institution remains responsible for core financial services. This creates a practical governance gap: legal contracts divide tasks, but customer harm, data failure and operational disruption move across the whole service chain. Boards need an ecosystem view that is more detailed than a vendor register and more decision-oriented than a group chart.
How should institutions measure embedded finance neo conglomerate risk?
Build a service graph with nodes for legal entities, platforms, critical systems, datasets and customer touchpoints. For service k, calculate dependency score Dk = Σwj × cj × sj, where w is activity share, c substitutability factor and s severity if unavailable. Add a responsibility matrix for every customer outcome and control. Scenario tests should combine platform outage, corrupted onboarding data, misleading marketing, complaint surge, liquidity outflow and partner insolvency. Measure affected customers, value at risk, time to detect, time to restore, unresolved complaints, data-reconciliation breaks and capacity of alternative providers.
How should embedded finance neo conglomerate risk be validated?
Independent assurance should trace representative customer journeys from advertisement to closure, reconcile partner and regulated-entity records, test access to audit logs and sample complaint outcomes. Resilience exercises should disable a real dependency in a controlled environment and test manual alternatives, capacity and data recovery. Conduct validation should examine incentives and outcome differences by channel. Legal review must distinguish contractual allocation from regulatory accountability.
What should risk leaders do first?
Create an end-to-end service and accountability graph. Reconcile customer, incident and complaint data across partners. Set ecosystem concentration and substitutability limits.