Summary. A payments or lending product built by a technology company is regulated as financial services from the first transaction, whether or not anyone at the company has read the rules. The framework is fragmented across federal prudential regulators, the CFPB, FinCEN, OFAC, and fifty state banking departments, and the same product can be lawful in one structure and unlicensed money transmission in another. This article maps the regime: when a product requires money transmitter licensing, how bank partnership structures work and where they fail, the consumer protection statutes applying to accounts and credit, the AML program every covered company must build, and the third-party risk expectations that now govern what a sponsor bank will permit.


Two founders build a payroll product for restaurants. It calculates wages, and — because the restaurants asked — it also moves money: the restaurant funds an account, the product holds the balance for two days, and on payday it disburses to employees' debit cards. There is also an optional feature letting employees draw earned wages early, for a $3 flat fee.

They have built four regulated products and believe they have built one.

Holding the restaurant's funds and disbursing them to third parties is money transmission in most states, requiring licensure in each — a process taking twelve to thirty months and requiring surety bonds, minimum net worth, permissible investments, background checks on control persons, and ongoing examination. Loading funds to prepaid cards brings the product within Regulation E's prepaid account rules. The earned wage access feature is either a fee-bearing credit product subject to the Truth in Lending Act or it is not, depending on structure and on which state's law applies, and the answer has changed in several states within the last two years. And the whole operation is a money services business for Bank Secrecy Act purposes, requiring FinCEN registration, a written AML program, a customer identification program, transaction monitoring, and suspicious activity reporting.

None of that is obvious from the product spec. All of it attaches from the first transaction.

Financial regulation does not ask what a company calls itself. It asks what functions the product performs.

The map

There is no single financial regulator in the United States. There are, functionally, five layers.

Federal prudential regulators — the OCC (national banks and federal savings associations), the Federal Reserve (state member banks and holding companies), the FDIC (state nonmember banks and deposit insurance), and the NCUA (credit unions). A fintech generally does not deal with them directly. It deals with them through its sponsor bank, whose examiner's expectations become the fintech's contractual obligations.

The Consumer Financial Protection Bureau — rulemaking, supervision, and enforcement for federal consumer financial law. Supervisory authority reaches banks over $10 billion and specified larger participants in defined nonbank markets, plus any nonbank the Bureau determines poses risks to consumers. Enforcement authority reaches essentially every covered person, regardless of size.

FinCEN — the Bank Secrecy Act, money services business registration, and AML program requirements.

OFAC — economic sanctions, which apply to all U.S. persons with no size threshold, no licensing trigger, and strict liability.

State regulators — money transmitter licensing, lender licensing, usury, debt collection, and state UDAP statutes, administered by fifty banking departments and enforced by fifty attorneys general.

The Federal Trade Commission retains authority over nonbank entities outside the CFPB's reach, and the SEC and CFTC attach where the product involves securities or derivatives.

Money transmission

The federal layer. A money services business under 31 C.F.R. § 1010.100(ff) includes dealers in foreign exchange, check cashers, issuers or sellers of traveler's checks or money orders, providers and sellers of prepaid access, and money transmitters. An MSB must register with FinCEN within 180 days of establishing the business, renew every two years, and maintain a list of agents. Registration is not a license and confers no authority; it is a reporting obligation, and failure to register is a felony under 18 U.S.C. § 1960 when combined with unlicensed transmitting.

The state layer is where the burden sits. Nearly every state requires a money transmitter license to engage in the business of receiving money for transmission or transmitting money. Requirements typically include an application with detailed disclosures, surety bonds scaled to volume, minimum net worth, permissible investments equal to outstanding transmission obligations, fingerprinting and background checks on officers, directors, and 10-percent-plus owners, audited financial statements, business plans, AML program documentation, annual reports, and periodic examination. Multi-state licensure through the Nationwide Multistate Licensing System has improved coordination, and the Money Transmission Modernization Act — adopted in a growing number of states — has harmonized definitions, exemptions, and net worth standards, but the process remains long and expensive.

The exemptions that matter:

The agent-of-payee exemption, recognized in many states and codified in the MTMA, exempts a person who receives money as the agent of the payee, where the payee's receipt by the agent satisfies the payor's obligation. This is the exemption on which most marketplace and platform payment models depend, and it requires a genuine written agency agreement with the payee and a real discharge of the underlying obligation. It is not available if the platform is the agent of the payer.

Payment processor exemptions — narrower, generally limited to processing through clearing and settlement systems for a merchant.

The bank exemption — banks and their agents. This is why the sponsor bank model exists: a fintech operating as an agent of a licensed bank, with the bank as the transmitter of record, may avoid state licensing. Whether it does depends on whether the bank actually holds the funds and bears the obligation, which turns on the flow-of-funds architecture rather than the contract's labels.

Closed-loop and limited-purpose exemptions for stored value usable only with the issuer or a defined merchant group.

The analysis to run before building. Draw the flow of funds. At every point, ask: whose money is it, and who owes an obligation to whom? If the company ever has control over funds that it owes to someone else, money transmission is presumed and an exemption must be identified. If the funds move directly from payer to a bank account in the payee's name and the company only transmits instructions, they generally are not.

The bank partnership model

Most fintechs do not become banks. They partner with one.

How it works. A chartered bank issues the account, holds the deposits, extends the credit, or transmits the funds. The fintech provides the interface, the customer relationship, marketing, and often servicing and underwriting models. Deposits sit at the bank and are FDIC-insured at the bank; the fintech's own insolvency does not insure anyone.

What the model provides:

Interest rate exportation. A state-chartered insured bank may charge the interest permitted by its home state to borrowers anywhere, under 12 U.S.C. § 1831d — the state-bank analogue to the national bank rule of Marquette National Bank v. First of Omaha Service Corp., 439 U.S. 299 (1978). A bank partnership can therefore lend nationally on uniform terms without fifty state usury analyses.

Licensing relief, where the fintech operates as the bank's agent and the bank is the true party in interest.

Access to payment rails — ACH origination, wire, card issuing through a network, and increasingly instant payment systems — which are otherwise available only to financial institutions.

Where it fails:

The true lender problem. Courts and state regulators have looked past the nominal lender to identify who has the predominant economic interest and who bears the risk. Where the bank originates and immediately sells the entire receivable to the fintech, which set the credit policy, marketed the product, funded the loans through a purchase commitment, and bears all the credit risk, states have argued the fintech is the true lender and the loan is subject to the borrower's state usury cap. Structures with meaningful bank participation — retained interest, genuine underwriting authority, real risk retention, and bank control over credit policy — fare far better.

The Madden problem. In Madden v. Midland Funding, LLC, 786 F.3d 246 (2d Cir. 2015), the Second Circuit held that a nonbank assignee could not rely on the originating national bank's rate exportation. The OCC and FDIC subsequently adopted "valid-when-made" rules providing that interest permissible when a loan is made remains permissible after transfer. Those rules survived a challenge but do not resolve the true lender question, which is analytically distinct and remains live in state enforcement and in litigation.

Third-party risk management. The federal banking agencies' 2023 Interagency Guidance on Third-Party Relationships governs how banks manage fintech partners across planning, due diligence, contracting, ongoing monitoring, and termination. The practical result is that a sponsor bank's examiner expectations flow into the fintech's contract: audit rights, compliance management system requirements, complaint reporting, marketing approval, change control, business continuity, and — importantly — the bank's right to terminate. Under the Bank Service Company Act, 12 U.S.C. § 1867(c), the agencies may examine a bank's service providers directly.

Reconciliation and recordkeeping. The 2023–2024 failures in the banking-as-a-service sector arose not from credit losses but from ledger failures: fintechs and middleware providers that could not reconcile customer-level records to the bank's ledger, leaving end users unable to access funds. The regulatory response has been an intensified focus on daily reconciliation, direct bank visibility into subledgers, and clarity about custodial account titling and FDIC pass-through insurance requirements. Any product holding customer funds at a partner bank should be able to prove, on any given day, exactly whose money is where.

Consumer protection statutes

Electronic Fund Transfer Act and Regulation E15 U.S.C. § 1693; 12 C.F.R. Part 1005. Applies to electronic fund transfers to or from a consumer asset account, including debit card transactions, ACH, ATM, and — under the prepaid account rules — most stored value products and many fintech "accounts."

Core obligations: initial disclosures of terms, fees, liability, and error resolution rights; periodic statements or, for prepaid accounts, an alternative of balance access and 12-month history; change-in-terms notices; and preauthorized transfer authorization and revocation rights.

Error resolution is the operationally demanding part. On receipt of a notice of error within 60 days of the statement, the institution must investigate and determine within 10 business days, or provisionally credit the account and take up to 45 days (90 for new accounts, POS, and foreign-initiated transfers). Then report results within three business days, and if the error is not confirmed, provide an explanation and notice of the right to request documents.

Unauthorized transfer liability is capped: $50 if the consumer notifies within two business days of learning of loss or theft, $500 if within 60 days of the statement, and unlimited for transfers appearing on a statement and not reported within 60 days. The consumer's negligence is irrelevant — a point most product teams get wrong. Note the recurring hard question: a transfer the consumer was tricked into initiating is generally not "unauthorized" under Reg E as written, while a transfer initiated by a fraudster using stolen credentials is. The Bureau's interpretations in this area have been active, and the operational reality is that a program with weak fraud controls generates both losses and examination findings.

Prepaid accounts carry additional requirements: short-form and long-form fee disclosures in prescribed format, a prohibition on offering credit features for 30 days, and submission of agreements to the Bureau.

Remittance transfers — Subpart B of Regulation E — govern consumer international transfers over $15, with prescribed prepayment and receipt disclosures, exchange rate and fee disclosure, a 30-minute cancellation right, and error resolution obligations.

Truth in Lending Act and Regulation Z15 U.S.C. § 1601; 12 C.F.R. Part 1026. Applies to consumer credit extended by a creditor who regularly extends credit subject to a finance charge or payable in more than four installments and to whom the obligation is initially payable.

The two thresholds decide most fintech questions. A product with no finance charge and four or fewer installments is generally outside TILA — which is the structure of most "pay in four" products. A product with a fee that is a finance charge, or a fifth payment, is inside it, with disclosure, advertising, and — for credit cards — ability-to-pay, penalty fee, and rate increase restrictions.

Earned wage access is the live example. Structured as a non-recourse advance of already-earned wages with no mandatory fee, it has been treated by some regulators as not credit. Structured with a mandatory fee, a tip that functions as a price, or recourse against the employee, it looks like credit — and several states have enacted specific EWA statutes with licensing, fee caps, and disclosure requirements, while others have applied their lending laws. The federal position has shifted more than once. Any product in this space needs a current, state-by-state analysis, not a structural assumption.

Equal Credit Opportunity Act and Regulation B15 U.S.C. § 1691. Prohibits discrimination in any aspect of a credit transaction on the basis of race, color, religion, national origin, sex (including sexual orientation and gender identity), marital status, age, receipt of public assistance income, or the good faith exercise of rights under the Consumer Credit Protection Act.

Two obligations create most of the exposure for algorithmic underwriting. Adverse action notices must state the specific principal reasons for denial — and the Bureau has stated plainly that a creditor using a complex model must still provide accurate specific reasons, and that the model's opacity is not a defense. Disparate impact liability means a facially neutral variable that correlates with a protected characteristic and lacks a business necessity justification is actionable, which requires fair lending testing of models before and after deployment.

Fair Credit Reporting Act15 U.S.C. § 1681. Governs use of consumer reports (permissible purpose, certification, adverse action notices with the credit score used), furnishing of information to consumer reporting agencies (accuracy, dispute investigation within 30 days under § 1681s-2(b)), and — for many alternative data models — the question of whether the company has itself become a consumer reporting agency by assembling information for the purpose of furnishing reports to third parties.

Gramm-Leach-Bliley15 U.S.C. §§ 6801–6809. The Privacy Rule requires initial and annual privacy notices and an opt-out from sharing nonpublic personal information with nonaffiliated third parties, with exceptions that cover most service provider sharing. The Safeguards Rule, 16 C.F.R. Part 314 as amended, requires nonbank financial institutions to maintain a written information security program with a qualified individual in charge, a written risk assessment, access controls, encryption of customer information in transit and at rest, multifactor authentication, secure development practices, service provider oversight, an incident response plan, penetration testing and vulnerability assessments, and an annual report to the board — plus notification to the FTC of security events affecting 500 or more consumers.

UDAAP12 U.S.C. § 5536. Unfair, deceptive, or abusive acts or practices. Unfair requires substantial injury not reasonably avoidable and not outweighed by benefits. Deceptive requires a material representation, omission, or practice likely to mislead a reasonable consumer. Abusive — the addition unique to the CFPB — reaches material interference with the ability to understand a term, and unreasonable advantage-taking of a consumer's lack of understanding, inability to protect their interests, or reasonable reliance on the covered person to act in their interests.

UDAAP is where most enforcement actually lands, because it does not require a rule violation. Recurring theories: fee disclosure buried or mismatched to actual charges; "free" claims with conditions; marketing that implies FDIC insurance the product does not have (now also a rule violation under the FDIC's amended 12 C.F.R. Part 328, which prohibits misrepresenting deposit insurance and misusing the FDIC name or logo); dark patterns in cancellation flows; and automatic renewal practices.

Other statutes to check by product: the Military Lending Act, 10 U.S.C. § 987, capping the military annual percentage rate at 36 percent for covered borrowers with severe consequences for violation, including voidness; the Servicemembers Civil Relief Act; the Fair Debt Collection Practices Act and Regulation F if collecting others' debts; Regulation II and the Durbin Amendment for debit interchange and routing; Regulation CC for funds availability; Regulation DD and the Truth in Savings Act for deposit account disclosures; NACHA operating rules for ACH, which are contractual but functionally mandatory; and card network rules, which are private but carry fines and termination rights that are far more immediate than most regulatory processes.

Section 1033 open banking. The Bureau's personal financial data rights rule requires covered institutions to make consumer financial data available to consumers and authorized third parties through developer interfaces, with restrictions on secondary use, standards for authorization and revocation, and a role for standard-setting bodies. The rule has been subject to litigation and revision; its compliance dates are tiered by institution size. Any product relying on data aggregation should track it closely, because it changes both the access rights and the obligations of everyone in the chain.

Anti-money laundering and sanctions

The Bank Secrecy Act requires covered financial institutions — including MSBs — to maintain an AML program. Five pillars:

  1. Internal policies, procedures, and controls, in writing, approved by senior management.
  2. A designated compliance officer with authority and resources.
  3. Ongoing training for relevant personnel.
  4. Independent testing, by internal audit or a qualified third party, on a risk-based schedule.
  5. Customer due diligence, including risk-based ongoing monitoring and, for legal entity customers, beneficial ownership identification of individuals owning 25 percent or more and one individual with significant control.

Customer identification program — collect name, date of birth, address, and identification number; verify identity through documentary or non-documentary methods; retain records; and check government lists.

Suspicious activity reports — file within 30 calendar days of initial detection (60 if no suspect is identified), for transactions at or above the applicable threshold that the institution knows, suspects, or has reason to suspect involve funds from illegal activity, are designed to evade BSA requirements, have no apparent lawful purpose, or facilitate criminal activity. Confidentiality is absolute: disclosing the existence of a SAR to the subject is a federal crime, and this rule frequently collides with customer service instincts and with contractual notice obligations, which should be drafted with a legal-compliance carve-out.

Currency transaction reports for cash over $10,000, funds transfer recordkeeping and the Travel Rule at $3,000, and record retention generally for five years.

OFAC deserves separate emphasis. Sanctions compliance is strict liability, applies to all U.S. persons regardless of size or licensing, and reaches blocked persons, blocked property, and comprehensively sanctioned jurisdictions. The obligations are to screen customers and counterparties against the SDN and consolidated lists at onboarding and on an ongoing basis and against list updates, to block or reject transactions as the program requires, to report blockings within 10 business days and annually, and to maintain records. Screening logic — fuzzy matching thresholds, handling of transliterations, and treatment of the 50 percent rule for entities owned by blocked persons — is a real engineering problem, not a checkbox.

Building the compliance function

Before launch:

  • Map the flow of funds and get a written licensing analysis. This is the single most important document the company will produce in its first year.
  • Choose the structure deliberately — direct licensing, bank partnership, or an exempt model — and understand what each costs in time, capital, and control.
  • Diligence the sponsor bank as hard as it diligences you: its examination history, its appetite, its other programs, and its termination rights. Sponsor bank concentration is an existential risk, and a second bank relationship is worth its cost.
  • Build the compliance management system the bank's examiner expects: board and management oversight, policies, training, monitoring, complaint management, audit, and a change control process for marketing and product.
  • Build the AML program and OFAC screening before the first customer, not after.
  • Implement daily reconciliation to the bank ledger at the customer level.

At launch and continuously:

  • Complaint management — collect, categorize, resolve, and analyze for root cause, including CFPB complaint database entries. Examiners read complaints first.
  • Marketing review — every claim, every disclosure, every screen, with a record of approval. Most UDAAP findings come from screens nobody in compliance ever saw.
  • Fair lending testing of models, documented, before and after deployment.
  • Vendor management, because the obligations flow down and the bank will hold the fintech responsible for its subcontractors.
  • Change management — a new state, a new product feature, a new fee, or a new data use should trigger a documented legal review.
  • Recordkeeping — five years for BSA, and longer for many consumer statutes.

Conclusion

Three points determine most outcomes for a fintech.

Structure decides regulation. Whether a product is money transmission, credit, or neither turns on the flow of funds and the obligations between parties, not on the name of the feature. Getting a written analysis before building is cheap; restructuring a live product with customer balances is not.

The sponsor bank is a regulator. Its examiner's expectations arrive as contract terms and audit findings, and its right to terminate is the most powerful enforcement mechanism a fintech will face. Treat the relationship as a supervisory one, maintain the reconciliation and reporting the bank needs, and do not let it become a single point of failure.

UDAAP and OFAC have no thresholds. Every other obligation in this article attaches at some size, licensing trigger, or product boundary. Those two apply from the first transaction, to every U.S. person, with strict liability in the case of sanctions and with no need for a rule violation in the case of UDAAP. A company that gets everything else right and ships a misleading fee screen has still built its largest exposure.

A worked example

Return to the payroll company. Here is what a competent regulatory workstream looks like, in order.

Week 1 — the flow-of-funds map. Counsel and engineering draw every movement of money on one page: from the restaurant's bank account, to whom, held by whom, for how long, and disbursed to whom. Two facts emerge that the product spec obscured. The company's own operating account receives the restaurant's funds. And the company holds them for up to 48 hours before disbursement. Both facts point toward money transmission.

Week 2 — the structural choice. Three options are priced.

Direct licensing. Roughly 45 licenses, $8 million to $15 million in bonds and net worth across the states, twelve to thirty months to national coverage, and a compliance staff of four to six. Correct for a company that intends to build a durable payments franchise. Wrong for one with eleven months of runway.

Bank partnership. The sponsor bank becomes the transmitter of record. Restaurant funds move into a for-benefit-of account at the bank, titled so that FDIC pass-through insurance is available, with the company as the bank's agent and program manager. Time to market: four to seven months, most of it sponsor bank diligence.

Restructure to avoid transmission. Funds move directly from the restaurant's account to employees, with the company transmitting only instructions and never taking possession or control. This eliminates the licensing question entirely and eliminates float revenue with it.

The company chooses the bank partnership, and separately restructures the earned wage access feature.

Weeks 3–14 — sponsor bank diligence. The bank asks for the AML program, the CIP procedures, OFAC screening logic and match thresholds, the compliance management system, the complaint process, the information security program under the Safeguards Rule, penetration test results, SOC 2 reports for every subprocessor, financial statements, the flow-of-funds map, marketing materials, all consumer-facing screens, the Regulation E disclosures and error resolution procedure, business continuity and exit plans, and a subledger architecture that the bank can reconcile daily at the customer level. None of this is optional, and each item that does not exist adds weeks.

The contract. The bank obtains audit rights, marketing approval rights, complaint reporting, change control over product and fees, minimum reserve requirements, indemnification, and termination for convenience on 90 days' notice. Counsel negotiates a longer wind-down period with an obligation to cooperate in transferring the program, because a 90-day termination with no transition obligation is a business-ending term.

Regulation E build. Error resolution is implemented as a workflow with hard SLAs: acknowledge, investigate, provisionally credit at day 10, resolve by day 45, notify within three business days, and provide documents on request. Liability caps are coded so that consumer negligence never enters the calculation. Fraud rules are tuned with the understanding that a credential-theft transfer is unauthorized and a consumer-induced push payment generally is not — and that the difference must be documented for each disputed transaction.

Earned wage access. Restructured as a no-mandatory-fee, non-recourse advance with an optional expedited-delivery fee, and then analyzed state by state, because at least six states now regulate the product specifically and at least two treat any fee as a finance charge. The company launches the feature in a subset of states and adds others as analysis supports it.

Ongoing. Daily reconciliation to the bank ledger. Monthly complaint analysis with root-cause coding. Quarterly OFAC screening tuning review. Annual independent AML testing. Board-level reporting on the Safeguards Rule program. A change control gate that requires legal review before any new state, fee, or data use goes live.

Total elapsed time from spec to launch: roughly seven months. Total elapsed time had the company launched first and asked later: the same seven months, plus a rescission program, a state enforcement action, and a sponsor bank that will not take the call.

Frequently asked questions

Do we need a money transmitter license if a bank holds the funds? Often no, if the bank is genuinely the transmitter and the company acts as its agent, with the funds in accounts titled to the bank and the bank bearing the obligation to the end user. The analysis follows the flow of funds and the obligations, not the contract's labels.

Is our product FDIC insured? The bank is insured. Whether a particular customer's balance is covered depends on account titling, recordkeeping sufficient to identify each owner, and satisfaction of the pass-through requirements. Saying "FDIC insured" without that foundation is now both a UDAAP theory and a rule violation under 12 C.F.R. Part 328.

Are we a consumer reporting agency? If the company assembles or evaluates consumer information for the purpose of furnishing consumer reports to third parties, possibly yes — with permissible purpose, accuracy, dispute, and disclosure obligations attached. Companies building alternative data underwriting frequently cross this line without noticing.

How long does licensing actually take? Twelve to thirty months for national coverage, with the slowest states measured in years, and NMLS has improved coordination without collapsing the timeline.

What triggers CFPB attention? Complaints, most often. Then marketing that does not match the fee schedule, and error resolution that does not meet Regulation E's clocks.

Can we launch in one state first? Yes, and it is usually the right answer — but confirm that the analysis is genuinely geographic. OFAC, the Bank Secrecy Act, UDAAP, and the Safeguards Rule apply from the first customer regardless of where that customer lives.

Who examines us — the CFPB, the state, or the bank? All three, in different ways and on different schedules. State banking departments examine licensees directly. The CFPB supervises larger participants in defined markets and can investigate anyone by civil investigative demand. And the sponsor bank examines continuously, because its own examiners hold it responsible for the program. In practice the bank's audit arrives first, and the findings it generates are the best predictor of what a regulator will later ask about.

What is the single most expensive mistake? Launching without a written flow-of-funds analysis. Every other error in this article is a remediation project. That one can require unwinding live customer balances across states that each have their own view of what happened.

Does any of this change if we serve only businesses? Some of it. Regulation E, Regulation Z, ECOA's notice rules, and the GLBA privacy provisions are consumer statutes and largely fall away. Money transmission licensing, the Bank Secrecy Act, OFAC, the Safeguards Rule's reach over customer information, and the sponsor bank's third-party risk expectations do not. A business-facing product is a smaller compliance build, not an unregulated one.


Related articles

This article is provided for general informational purposes and does not constitute legal advice. Financial services regulation changes frequently, state money transmission and lending laws vary substantially, and several rules discussed here are subject to pending litigation or revision. Consult qualified financial services counsel before launching a payments, deposit, or credit product.