In partnership with

Hey, fintech fam! πŸ’œ

I hope you're settling into the new month well.

I’ve been thinking a lot lately about what happens when fintech companies scale faster than the systems, roles, and accountability structures inside them.

Because eventually, someone becomes the person who catches everything.

The question nobody knows how to answer. The project without a clear owner. The decision that falls somewhere between Product, Risk, Operations, and Legal.

And according to today’s guest contributor, that person is very often the Chief Compliance Officer.

Christina Rea-Baxter calls this becoming the company's β€œhuman API.”

Christina penned today’s guest column covering this topic. She’s an Academy of Fintech member and compliance executive who has spent her career inside fintech companies, including as the former Chief Compliance Officer of Binance.US.

It’s also incredibly timely as we build the FTW Security Summit on October 1, where we’re bringing Chief Compliance Officers, Chief Risk Officers, Heads of Identity, Heads of Product, security leaders, and the technologists building alongside them into the same room.

Because compliance shouldn't be the department everyone turns to for permission. It should be part of a company-wide operating system for making better decisions.

And if you work in this world and want to help us bring that room together, we're looking for volunteers for FTW! Reply to this email if that’s you.

Let’s get into it. ✨

Everything GTM. One platform.

Small teams don't have time to stitch together five tools and hope it works.

Apollo gives you everything you need to find leads, reach them, and close deals β€” all in one place:

  • 230M+ verified contacts

  • AI-powered outreach

  • Data enrichment

  • Inbound lead capture

  • Meeting scheduler

  • And more

Stop juggling tools and start building pipeline that scales.

With Apollo, the AI revenue engine powering 4M+ users.

GUEST CONTRIBUTOR: CHRISTINA REA-BAXTER

Your CCO Is Not Your Company's Human API

Compliance Has Somehow Become Default

Every company has a human API.

You know the person: they know who to call, where the bodies are buried, which process exists only in someone's head, and how to translate a vague question into an actual decision.

When something falls between functions, everyone routes the request through them.

In fintech, that person is very often the Chief Compliance Officer.

Β· Β  Β  Β  Product has a question? Ask Compliance.

Β· Β  Β  Β  Operations are stuck? Ask Compliance.

Β· Β  Β  Β  Risk and the business disagree? Ask Compliance.

Β· Β  Β  Β A new initiative has no obvious owner? Somehow, Compliance owns it now.

At first, this looks a lot like influence. The CCO is invited into every consequential conversation because people trust their judgment.

They understand the product, the regulators, the customer journey, and what happens when those pieces do not fit together.

But at some point, being trusted turns into becoming organizational infrastructure.

The CCO stops advising the business and starts carrying it: escalation path, institutional memory, tie-breaker, process designer, project manager, and unofficial permission slip.

If every difficult decision lands with Compliance, it’s not that you have an unusually helpful compliance function - it’s more likely that you have an accountability problem.

How Competence Becomes a Trap

Nobody deliberately designs this job; it just kind of accumulates one reasonable request at a time.

Good compliance officers are trained to spot what is missing.

They ask the question nobody else thought to ask. They step in because the deadline is real, the customer impact matters, and allowing a preventable failure to unfold feels irresponsible.

Meet Chief Compliance Officers and more at FTW: SF.
Tickets are on sale now!

The first time, stepping in is leadership. The tenth time, it is a pattern.

By the hundredth time, the company has learned something dangerous: if we wait long enough, Compliance will catch it.

That is how a capable executive becomes a human API.

Instead of building clear ownership, usable systems, and decision-making muscle across the company, everyone learns the same shortcut: route uncertainty to the person most likely to resolve it.

The CCO's competence masks the design flaw, sometimes for years.

❝

Heroic people make a poorly designed company look efficient.

Christina Rea

This Is a Management Problem Wearing a Compliance Costume

The pattern is not unique to compliance.

Many organizations run on a handful of human APIs: the operations leader who can fix every broken workflow, the lawyer asked to settle every disagreement, the product executive who carries the whole roadmap in her head.

For a while, heroic people make a poorly designed company look efficient.

Work moves, and problems disappear; leadership sees responsiveness and assumes the system is working.

It is not.

The organization is borrowing speed from one person's attention, and the interest eventually comes due.

Compliance is simply where the flaw becomes especially dangerous.

The function is supposed to advise and challenge the business, not become the place where the business sends decisions it does not want to own.

Compliance Is Not a Corporate Permission Slip

Somewhere along the way, many organizations turned Compliance into the Department of Yes or No.

The business proposes. Compliance approves or rejects. Everyone leaves believing accountability has been transferred.

It has not.

The business owns the business decision. Compliance interprets obligations, explains the risk, tests whether controls are credible, and challenges choices that create unacceptable exposure.

Sometimes the answer is no. Often the better answer is, 'Here are the conditions under which this could work.'

A useful operating model distinguishes three roles:

  • Compliance owns the compliance program: standards, monitoring, testing, reporting, regulatory engagement, and escalation of material compliance issues.

  • Compliance advises when a business owner needs regulatory expertise to evaluate an option or design an appropriate control.

  • Compliance challenges when the business's assumptions, risk acceptance, evidence, or execution are not good enough.

Compliance should not own every cross-functional problem with regulatory implications by default.

Almost every meaningful fintech decision has regulatory implications. That does not make every meaningful fintech decision a compliance decision.

Lean Does Not Have to Mean Ambiguous

Early-stage founders may reasonably object: everyone wears multiple hats.

Of course they do. A growing fintech cannot build a separate department for every risk, and a good CCO should be commercially aware, collaborative, and willing to operate beyond a narrow job description.

The problem is not the β€œmultiple hats” but the more insidious β€œinvisible” hats.

If the CCO temporarily owns a cross-functional initiative because they are the best person to stabilize it, name that choice.

Define the authority, resources, end date, and eventual owner. Temporary range can be a strength. Permanent ambiguity becomes an operating model.

The same is true of fractional or outsourced leadership.

A company cannot buy a block of senior compliance time and quietly assume it has also acquired a chief risk officer, general counsel, head of operations, product strategist, project manager, and unlimited implementation team.

Clear scope is not bureaucracy. It is how critical work gets a real owner and enough capacity.

Build a Company That Can Answer Its Own Questions

Clarify decision rights. Every significant initiative needs a business owner, a decision-maker, required advisers, and a clear escalation path.

Require a point of view. Do not let teams hand Compliance a blank page. Ask for the recommendation, evidence, assumptions, and proposed controls.

Turn repeat answers into infrastructure. A recurring question should become a standard, decision tree, playbook, threshold, or training moment.

Track demand, not just output. Patterns in compliance requests often expose weak ownership, poor process design, or under-resourced functions elsewhere.

Protect challenge capacity. Reserve time for independent oversight, regulatory judgment, material-risk escalation, and credible challenge.

About Today’s Guest Contributor: Christina Rea-Baxter is the Founder & CEO of RayCor Consulting, where she advises banks, fintechs, payment companies, and digital asset firms on financial crimes compliance, governance, regulatory strategy, and AI governance. She is a former Chief Compliance Officer of Binance.US, a New York attorney, and a frequent expert witness in fintech- and crypto-related litigation.

Chief Compliance Officers, Founders, and C-Suite Leaders Belong at FTW: SF

3 days. 3 Summits. One thesis: AI doesn’t matter unless it improves people’s financial lives.

Day 3 of FTW: SF (The Security Summit) is designed for:

  • Chief Compliance Officers

  • Chief Risk Officers

  • Heads of Identity

  • CISOs

  • CTOs

  • CPOs

  • And more

Innovation without security doesn’t scale, and the stakes are higher than ever. In AI-native fintechs, security is everyone’s job. You can’t afford to miss this.

I WANT IT, I GOT IT (CHRISTINA’S VERSION)

  • πŸ“š Today's Read: Thinking in Bets by Annie Duke. I’ve been thinking a lot lately about how we make decisions when we don’t have complete information and how easily we confuse a good outcome with a good decision. It pairs perfectly with my current rabbit hole into Bayesian statistics. What’s a book that genuinely changed the way you make decisions?

  • 🍝 Today's Order: I recently went to Opto in New York and am still thinking about two dishes: the socca with summer corn, Australian black truffle, and brown butter, and the tagliolini al Amalfi limone with cultured butter and Parmigiano Reggiano. Bright, rich, unexpectedly perfect, and absolutely worth ordering for the table, although I make no promises about sharing.

  • πŸŒ€ Today's Rabbit Hole: Bayesian statistics. I recently had a former OCC statistician on my podcast, Risk & Rebels, and our conversation sent me down a completely unexpected rabbit hole about how we update our beliefs when new evidence arrives. It sounds highly technical, and it can be, but it is also a fascinating way to think about risk, judgment, and why smart people can look at the same evidence and reach different conclusions. Listen & subscribe on YouTube, Spotify, and Apple.

FINTUNES (CHRISTINA’S VERSION)

LET’S CONNECT

πŸ“° Share this newsletter with a friend and start growing your network.

πŸ”— Connect with me on LinkedIn for daily insights on leadership.

🀝 Grow your business through content & community by partnering with me.

πŸ“£ Promote yourself to 50,000 subscribers by sponsoring this newsletter or the Humans of Fintech podcast.

🎀 Host an epic event by booking me as a speaker, moderator, or emcee.

πŸ“š Increase your expertise by ordering your copy of my book, Fintech Feminists: Increasing Inclusion, Redefining Innovation, and Changing the Future for Women Around the World.

Thanks for spending time with Christina and me today!

Love,

Nicole πŸ’œ