Hold customer money and you are running a bank you did not mean to open. The float sits in a pooled account at a partner bank, or with a banking-as-a-service middleman, or across a thousand agent tills. On your books it is a liability you owe your customers. On the partner’s books it is an asset they control. The two only feel like one thing until the partner has a bad day, and then the gap between them becomes your problem in a single morning.
So the decision is not “is my partner safe.” It is two numbers you can set today. Where does the float sit, and how much of it is allowed to sit with any one counterparty. Get those wrong and a partner’s liquidity problem arrives at your door as a run you cannot answer, no matter how solvent your own business is.
Everything we publish on capital comes back to one mechanic: African finance does not price risk so much as price the cost of checking. Float is that idea at its sharpest. You cannot cheaply verify your partner’s balance sheet. Your customers cannot cheaply verify yours. So everyone runs on assurance instead of proof, right up until a shock forces the whole chain to check at once. Float is not money you have. It is money you owe, parked where you cannot watch it.
Why these three lenses
One model would give you a tidy story and a false calm. I am routing this to three, each blind to what the others see, because “a partner’s problem becomes your solvency event” is three machines running together.
The first is a cycle-regime lens: contagion with the shape of an epidemic. It explains how distress travels, from the partner into your book and then customer to customer, and why it can peak before you have finished reading the first email. The second is an equilibrium lens: cheap talk, the economics of a costless message. It explains why “your funds are safe” tells you nothing, and what would make it mean something. The third is a complex lens: an agent-based run, where a system-wide panic emerges from thousands of small private decisions. It explains why a solvent float still runs, and where the tipping point sits.
Two layers I am folding in rather than shipping as their own cards. The behavioral piece, why one screenshot outruns a press release, lives inside the agent-based lens, because it sets how low each customer’s trigger sits, not the shape of the run. The governance piece, deposit insurance and trust-account law, lives inside the cheap-talk lens, because regulation is precisely the machinery that turns a costless promise into a bonded one. Neither earns a separate lens.
A note on the run’s tipping point, because a reader who knows the method will look for it. The withdrawal rate that turns orderly redemption into a run is a threshold, and I am carrying it inside the contagion and agent-based lenses rather than as a fourth card, where it reads as a reproduction rate above one and as a critical density. That keeps the ensemble to three spanning types instead of doubling up.
The framework: three machines behind one frozen morning
1. The contagion path: a partner’s bad day lands on your books as a run
Treat your customer base as a population. Most are dormant, content to leave a balance parked. A shock introduces an infected few: the customers who tried to cash out and could not, or who saw an agent turn someone away, or who read that the partner bank is in trouble. From there it transmits. A failed withdrawal becomes a screenshot, the screenshot becomes a WhatsApp group, the group becomes a queue at the till.
The number that governs everything is how many fresh panic-withdrawals each failed or visible one sets off. Above one, the wave grows until it exhausts your liquidity. Below one, it fades. The partner’s failure is the shock injected from outside your system, but whether it becomes a run is set inside it, by how fast a stuck withdrawal spreads and how quickly you can pay people and calm them. You cannot stop the partner from stumbling. You can lower the transmission rate, and you can hold the reserve that keeps the reproduction number under one for the days that matter.
Assumes distress transmits from a partner through your customer base with an epidemic shape: an injected shock, fast growth, a peak, then decay as people are paid or leave.
Fits because a frozen float spreads customer to customer through failed cash-outs, agent queues and messaging groups, not through any official channel.
Breaks when customers are unconnected or you honour withdrawals fast enough that each stuck one triggers less than one more.
Counteracts the belief that being solvent protects you. A solvent float still runs if it is illiquid for a week.
May reinforce panic if your own comms confirm the fear before you can fund the answer.
2. The assurance is cheap talk until something costly bonds it
“Your money is safe with us.” “We are fully insured.” “It sits in a segregated account.” These sentences cost the speaker nothing to say, so in equilibrium they carry no information. A partner in trouble says them in exactly the same words as a partner that is fine. A message only becomes credible when saying it falsely would cost the sender something, or when a third party you trust has already checked it.
This is what regulation is for, and it is why the governance layer belongs here rather than off to one side. A legally segregated trust account, ring-fenced from the partner’s creditors, is a bonded promise: Kenya’s payment rules require customer funds to sit in trust with no lending against them, and Ghana’s law puts e-money in trust so it cannot be encumbered in insolvency or liquidation.5, 8 Deposit insurance is another bond, but read its scope before you lean on it. It insures you against the bank failing. It has never insured you against the intermediary between you and the bank failing. When Synapse collapsed, customers had been told their money was federally insured; the assurance was cheap talk, because the insurance covered a bank failure that never happened while the ledger that said who owned what did not reconcile.3, 4
Assumes a costless message about safety carries no information, and only a costly, verifiable structure separates a safe partner from an unsafe one saying the same words.
Fits because “your funds are safe” is spoken identically by solvent and stressed partners, so it cannot be the thing you rely on.
Breaks when a bond exists and you have read it: a ring-fenced trust, an insurance scope you understand, a regulator that enforces both.
Counteracts the comfort of a reassuring partner call. Ask what would cost them if the words were false.
May reinforce false safety when a bond is named but its scope, like insurance against the wrong failure, does not cover your actual risk.
3. The run is emergent: each customer moves when the ones they can see move
No customer decides to start a run. Each follows a small private rule: pull my money if enough of the people I can see have pulled theirs, or if I personally hit a snag. Those triggers vary. A few withdraw at the first rumour, most need to see a crowd, some never move. Below a critical share of visible withdrawals the system absorbs them, because balances get topped back up and the float replenishes. Above that share, each withdrawal raises the visible count, which trips the next-lowest trigger, which raises the count again. The run is self-fulfilling and it emerged from arithmetic, not from anyone judging your fundamentals. The canonical model of exactly this is fifty years old: a run is a self-fulfilling equilibrium, where the expectation that others will withdraw makes withdrawing the rational move for you too.9
Concentration is what sets the starting density. If most of your float sits with one partner, that partner’s freeze does not nudge the system, it ignites the majority of it at once, and you begin the morning already above the critical line. Spread the float and one partner’s failure lands as a shock the population can absorb while you fund the gap. This is also where the behavioral layer sits: fear makes the private triggers low and makes one image travel faster than any statement you can draft, which is why the density climbs before your comms go out.
Assumes a run is an emergent outcome of many customers acting on heterogeneous local triggers, with a critical density of visible withdrawals above which it self-propagates.
Fits because real withdrawal panics ignite from a visible trigger and cascade regardless of the platform’s underlying solvency.
Breaks when withdrawals are invisible to other customers, or your float is spread so no single failure starts the system above the critical share.
Counteracts the plan to “communicate calm.” Below the threshold you may not need to, above it words rarely pull the density back down.
May reinforce the run if a clumsy freeze or a rationing rule becomes the visible trigger itself.
GEER: the moves, from the free and reversible to the slow and binding
Read together, the three lenses point at levers, not at hope. Work from the cheapest.
- Read the actual structure before you move another unit of float. For each partner: is the account legally in trust or merely called safe, ring-fenced from whose creditors, insured against whose failure. This costs a day and often finds that a promise you relied on covers the wrong risk.
- Demand the bond in writing. A segregated trust ring-fenced from the partner’s creditors, plus a reconciliation cadence stated in the contract, ideally daily. You are converting cheap talk into a claim you can enforce.
- Cap concentration with a hard number. No single partner holds more than a set share of float, and Kenya’s rule of a maximum 25 percent per institution once trust balances pass 100 million shillings is a ready-made anchor even where the law does not bind you.5, 6 A cap turns a fatal single failure into a survivable one.
- Hold a same-day liquidity buffer. Money you can deploy within hours to honour withdrawals while a partner is frozen. This is the reserve that keeps the reproduction number below one during the days recovery takes.
- Instrument the run before it starts. Track withdrawal rate against baseline, define the rate that counts as supercritical for your book, and pre-draft the comms and the funding move so you are not writing them at the peak.
RADAR: what to line up before a partner ever wobbles
Order by reversibility. Do the cheap dominant things now, buy the tail insurance next, and pre-commit the expensive irreversible move to a trigger so you never build it in a panic.
- Do now (T+3 to T+14). Map every unit of float: which partner, under what legal wrapper, insured against whose failure. Set a per-partner cap. If you are single-homed, this is your one urgent finding. Reversible, cheap, and dominant in every scenario, because a float map and a cap help whether or not anyone fails this year.
- Hedge (by T+14 to T+28). Stand up a second custody partner and arrange a same-day liquidity line you can draw without a fresh credit approval. This is tail insurance: you pay a little to carry two rails so one freeze does not take the whole float.
- Defer and trigger (T+28 and beyond). A full multi-partner architecture, or your own licence, is expensive and hard to unwind. Pre-commit it to an observable trigger: float exceeds the insured level by a set multiple, or any partner breaches the cap, or a partner’s own regulator issues a directive against it. When one fires, build. Until then, hold the cap and the buffer.
If you are the investor on the other side of this, underwrite the same two numbers. Ask for the float map and the concentration cap before the growth chart. A platform that cannot tell you where customer money sits, or that holds it all at one counterparty, is carrying a solvency event on someone else’s balance sheet, and you are pricing it whether you have looked or not.
CHAIN: what usually happens after the partner goes down
Pick the comparison group by structure, not by surface. The reference class is not “fintechs that failed.” It is platforms that pooled customer money at a few partner institutions where each customer’s claim ran through an intermediary’s ledger rather than to a named account of their own. Synapse and Evolve is the clean match: roughly 85,000 customers of one partnered app had about 112 million dollars locked, and across the failure end users were owed an aggregate near 265 million with tens of millions unaccounted for.1, 2 Every e-money issuer whose trust bank has ever wobbled sits in the same class.
The base rate is the uncomfortable part. A given partner failing in a given year is unlikely, but over the life of a company it is not negligible, and the payoff structure is brutally asymmetric. Ninety-nine percent of the time the concentration cap costs you a little operational friction. The one percent decides whether you exist, because recovery of a frozen, commingled float is a bankruptcy process measured in months to years, not a claim paid in days. Deposit insurance does not soften this, since it pays only if the bank itself fails, and it caps low: Kenya protects 500,000 shillings per depositor per institution, which is a household number, not a float number.7
Adjust for your present state. Single-homed float, no same-day liquidity, and a balance far above the insured level put you high on the curve. Then subtract the counterfactual before you overspend. Some withdrawal pressure is ordinary: payday cycles, a marketing push ending, seasonal outflows. That is not a run and does not need run defences. Net out your normal outflow and spend only against the excess.
Matrix-break flag. If regulators force real-time, per-beneficiary reconciliation and genuinely bankruptcy-remote trust, the direction the failures are already pushing supervisors, then the intermediary gap narrows and the lens that says “your claim runs through a ledger that may not reconcile” weakens.4 Watch your regulator for that rule. Building on the compliant structure early is the cheapest exit from this entire problem.
What these three lenses cannot see
The ensemble tells you the shape of the danger, not its date. It cannot name which partner fails or when. It assumes the run comes from the partner, so it is blind to the run you start yourself through an outage or a scandal, which no concentration cap will fix. It treats insurance scope as knowable, when pooled and cross-border structures can make it genuinely unclear who is covered against what. And it can miss a correlated shock, where your carefully diversified partners all clear through the same stressed institution and your diversification was never real.
Here is the decision that holds despite all of that. You cannot predict the failure. You can predict its consequence: if it lands while your float is single-homed and you hold no same-day liquidity, a solvable liquidity event becomes an existential one. So this quarter, map where every unit of customer money sits, set a hard per-partner cap, and open the second rail before you need it. The partner will never agree to be your point of failure, so you have to refuse to make them one.
Sources and notes
- Banking Dive, “Yotta CEO: 85K customers lose access to funds due to Synapse-Evolve tussle,” 2024. Verified: body states around 85,000 customers of the fintech startup with a total of $112 million in savings were locked out after the implosion of middleware provider Synapse. bankingdive.com
- Fintech Business Weekly, “The Synapse-Evolve Disaster: One Year Later,” 2025. Verified: body states end users were owed an aggregate of $265 million and that a shortfall of tens of millions remained unexplained. fintechbusinessweekly.substack.com
- The Reynolds Center for Business Journalism, “The FDIC loophole: How a fintech intermediary’s collapse exposed a dangerous gap in digital banking,” February 2025. Verified: body quotes the FDIC that account-holder funds in FDIC-insured banks are protected “in the event of a bank failure,” and explains that this did not protect customers when the intermediary, not the bank, collapsed. businessjournalism.org
- Davis Polk, “FDIC proposes to strengthen custodial deposit account recordkeeping in bank-fintech partnerships,” 2024, summarising the FDIC Notice of Proposed Rulemaking on custodial deposit accounts with transaction features. Verified: body states the proposal is meant to ensure banks and the FDIC can quickly assess amounts held by beneficial owners on the failure of a bank, fintech partner or other service provider. FDIC pages bot-block direct fetches, so this is the accessible mirror. davispolk.com
- Central Bank of Kenya, National Payment System Regulations 2014 (Legal Notice 109 of 2014). Verified in the machine-readable text: regulation 25 requires all monies received to be held in a Trust Fund whose balance is never less than what is owed to customers, sufficiently diversified across licensed commercial banks; the Fourth Schedule sets a maximum of 25 per cent of the total trust account balance per bank once the balance exceeds Kes 100 million. centralbank.go.ke (PDF)
- GSMA, “Kenya’s new regulatory framework for e-money issuers.” Verified human-readable companion to the regulation: customer funds must be held in trust with no lending or investment, and where trust balances exceed KES 100 million (about US$1.14 million) the funds must be placed in at least two strong-rated institutions with a maximum of 25% in each. gsma.com
- Kenya Deposit Insurance Corporation, “Deposit Insurance.” Verified: body states KDIC provides deposit insurance coverage of up to Ksh.500,000 to each depositor of a member institution in the event of a bank failure. kdic.go.ke
- Ghana Payment Systems and Services Act, 2019 (Act 987). Verified in the machine-readable parliamentary copy: a dedicated electronic money issuer must provide that electronic money owed to customers is held in trust and shall not be encumbered in case of insolvency or liquidation. repository.parliament.gh (PDF)
- Douglas W. Diamond and Philip H. Dybvig, “Bank Runs, Deposit Insurance, and Liquidity,” reprinted Federal Reserve Bank of Minneapolis Quarterly Review, Winter 2000 (orig. Journal of Political Economy, 1983). Verified: page carries the paper by Diamond and Dybvig modelling a bank run as a self-fulfilling equilibrium in which the expectation of others withdrawing makes withdrawing rational. minneapolisfed.org