FinTech Regulation: A Comprehensive Guide to Navigating Regulatory Frameworks
Last updated:4 August 2026

If you last read a guide to fintech regulation a couple of years ago, a good deal of what you learned about the United States has quietly gone out of date.
Agencies have been reorganized, budgets cut, crypto policy reversed, and a stablecoin law passed. What almost none of it changed is the part that matters to you: what a fintech company is actually required to do before it launches. The statutes are largely where they were. What moved is who's likely to notice when you get it wrong.
That gap between the rules on paper and the enforcement behind them is what most guides skip, and it's the thing we spend the most time explaining to clients.
Here's how the regulatory landscape works now, which rules bind you regardless of who's enforcing them, and where the compliance budget is worth spending.
Key Takeaways
- Nobody regulates "fintech." You're regulated by the activity you perform, which means a single product can pull in four agencies at once.
- Federal enforcement has softened considerably. The underlying statutes haven't, and private plaintiffs and state attorneys general have moved into the space.
- Licensing, not rulemaking, is where most US fintech firms lose time. Over 50 state and territorial jurisdictions each issue their own money transmitter license.
- Crypto regulation reversed direction in 2025. Guidance written before that year should be read with a date attached.
- Bank partnerships are the fastest route to market and the one regulators watch hardest after Synapse.
- AML, sanctions and fair lending obligations are the ones we'd never advise economizing on. They carry personal liability and they don't move with the political weather.

Nobody Regulates "FinTech"
Start here, because it's the misunderstanding that costs the most money.
There's no financial technology regulator and no fintech charter. US financial regulations attach to activities, so nothing about the fintech industry is regulated as a category. Move money and you're a money transmitter. Extend credit and you're a lender. Take deposits and you need a bank. Offer something that pays a return on someone's investment and you may be selling a security, whatever you call it in your pitch deck.
So the first compliance question isn't which of the fintech laws apply to your category. It's what your product does, function by function, and which regulatory requirements attach to each function. If you provide financial services of more than one kind, expect more than one answer. We've watched teams build a perfectly good compliance program for the business they described in their deck and miss the license they needed for the payments rail underneath it.
The federal regulators and what actually triggers them
Two of these deserve more than a table row.
The CFPB. Every guide written before 2025 treats the CFPB as the center of consumer protection in the financial sector. In 2026 that's no longer a safe assumption. Congress cut the agency's maximum annual Federal Reserve draw from $785 million to $446 million, its acting director has proposed reducing headcount from roughly 1,400 to 200, enforcement authority moved to the DOJ, and litigation over whether the agency can be wound down at all was argued in February 2026.
Our advice to clients hasn't changed a word because of any of it. The Consumer Financial Protection Act still exists. UDAAP is still on the books. State attorneys general have explicit authority to enforce it, New York and California among them have staffed up to do exactly that, and a plaintiff's firm doesn't need a federal agency's permission to file. Treating a quiet regulator as a repealed statute is the most expensive mistake available in this market right now.
FinCEN and the Corporate Transparency Act. In March 2025 FinCEN issued an interim final rule that removed beneficial ownership reporting for all US-created entities, narrowing the reporting company definition to foreign entities registered to do business in the States. If your compliance calendar still has a BOI filing on it for a Delaware C-corp, delete it. If you have a foreign subsidiary registered in a US state, you're still in scope.
State regulators, and why there are more than fifty of them
Federal laws set the floor. States build most of the building.
Every state, plus DC and the territories, licenses money transmission separately, with its own application, its own bond, its own net worth minimum and its own examination cycle. That's over 50 jurisdictions for one activity.
The Money Transmission Modernization Act has harmonized definitions in a growing number of states and the NMLS handles filing, and it's still the single largest line item in most early-stage US launch budgets.
Some states matter more than their size suggests. New York's DFS runs its own examination program and its own virtual currency regime. California's DFPI has broad authority over consumer financial products and enforces the California Consumer Privacy Act alongside it. Both have become more active as federal enforcement receded.
Learn about our expertise in the industry and what we have to offer
Licensing: What You Need Before You Launch
Money transmitter licenses
If you hold or move customer funds, this is your default path, and it's slow. Plan on 12 to 24 months for meaningful national coverage, plus surety bonds scaled per state and audited financials. Most fintech businesses we work with sequence it: launch in a handful of states where their customers actually are, add coverage as revenue supports it.
Banking licenses
Banking licenses come in more than one shape. A full national bank charter gives you direct access to payment systems and removes your dependence on a partner. It also brings capital requirements, an examination relationship and a multi-year application. Few fintech firms need one.
What changed recently is the middle option. In December 2025 the OCC conditionally approved five national trust bank charters for Circle, Ripple, Paxos, BitGo and Fidelity Digital Assets, and Circle received final approval in July 2026. A national trust charter permits custody and safekeeping without deposit-taking or lending, which suits a narrow set of business models and nothing else. It's a real option now where it wasn't two years ago. It is not a general-purpose banking license.
The bank partnership route
Most fintech companies still launch by partnering with a chartered bank and operating under its authority. You get to market faster, you offer banking services without holding a charter, you inherit the bank's regulatory relationships, and its compliance function gives you a structure you'd otherwise have to build.
The trade is that the bank owns the regulatory risk, so the bank owns you. Post-Synapse, sponsor banks have tightened diligence substantially: expect real scrutiny of your BSA program, your reconciliation and ledgering, your complaint handling and your marketing copy before you sign.
Regulators expect the bank to maintain genuine third party risk management over the partnership rather than a contract and a quarterly call.
One thing we'd raise early with any team taking this route. Get the ledger architecture right on day one. The Synapse failure left end users unable to reach their own money because nobody could reconstruct who owned what, and every diligence conversation since has started there.
Regulatory sandboxes
There's still no federal regulatory sandbox in the United States. Arizona created the first state program in 2018, Utah and Wyoming followed in 2019, and North Carolina and others have added their own since.
They're genuinely useful for a narrow product test under supervision, and they're the main place US regulators engage with financial technology innovation before it reaches the market. They don't give you a license, they don't travel across state lines, and we've rarely seen one change a company's go-to-market plan.
Consumer Protection Laws You Can't Design Around
This is the body of law that survives every change in enforcement posture, because most of it carries a private right of action.
Unfair or deceptive acts and practices. UDAP under the FTC Act, and UDAAP under the Consumer Financial Protection Act, which adds "abusive" to the list. The practical test is whether a reasonable consumer would understand what they're getting. Most enforcement we see starts with a screen, a fee disclosure or a marketing claim, not with a bad intention.
Fair lending. The Equal Credit Opportunity Act and Regulation B govern any credit decision. If you're doing online lending with a model, you need adverse action notices with specific reasons, and you need to be able to explain the model's decisions. "The algorithm decided" is not a reason under Reg B, and disparate impact liability doesn't care whether you intended the outcome.
Payments and credit disclosure. Regulation E for electronic fund transfers, including error resolution and unauthorized transaction liability, which is where a lot of mobile payments products get caught. Regulation Z for credit terms. Both are prescriptive about timing and wording in a way that surprises product teams.
Data privacy. The California Consumer Privacy Act gives consumers access, deletion and opt-out rights over customer data, and other states have passed comparable laws with slightly different definitions. The Gramm-Leach-Bliley Act's Safeguards Rule applies to financial institutions and has specific security program requirements. If you touch card data, PCI DSS applies on top of all of it as a contractual obligation rather than a statute, and it's the one teams most often discover late. If you serve Europe, the General Data Protection Regulation applies to you regardless of where you're incorporated, and its consent standard is stricter than anything in US law.
The practical answer to that patchwork is to build to the strictest applicable standard once rather than maintaining regional variants of the same consent flow. Teams that split it end up debugging four privacy states in production.
Learn how we built macro-investing app with its own token and reward system

AML, Sanctions and KYC
If a fintech company gets one thing right, make it this. Anti money laundering failures carry personal liability for compliance officers, they're the fastest way to lose a sponsor bank, and no political cycle has made them go away.
The three laws that apply
Bank Secrecy Act. Requires banks and other financial institutions to run an AML program covering money laundering and terrorist financing, file suspicious activity reports, and keep records that let investigators reconstruct a transaction.
USA PATRIOT Act. Added the Customer Identification Program requirement, the legal basis for your onboarding KYC checks.
Anti Money Laundering Act of 2020. Modernized the framework and expanded whistleblower incentives, which changed internal reporting more than teams expected.
What a working program needs
- Identity verification proportionate to risk, with enhanced diligence for higher-risk customers and beneficial ownership on entity accounts
- Transaction monitoring tuned to your own product rather than to a vendor's defaults
- Suspicious activity reporting inside the 30-day window
- Sanctions screening against Office of Foreign Assets Control lists at onboarding and per transaction
- Independent testing, plus training that reaches the people who see customers
Crypto gets no exemption
FinCEN treats convertible virtual currency businesses as money services businesses under the Bank Secrecy Act, so everything above applies to crypto firms in identical terms. That hasn't wavered through any shift in policy.
The failure mode nobody plans for
It's rarely a missing rule. It's alert fatigue: more alerts than the team can clear, a backlog that grows quietly, and an examiner who finds it. Sizing alert volume to the team you have does more than another detection scenario.
Crypto and Digital Assets: Read the Date on Everything
More stale advice circulates here than anywhere else in fintech regulation. Check the date on anything you read.
What reversed
Through 2022 and 2023 the Securities and Exchange Commission argued most tokens were securities. In February 2025 it repurposed its crypto enforcement unit, cut it from about 50 staff to 30, and pointed it at fraud. Actions against Coinbase and Kraken were dismissed, and staff then concluded certain protocol staking isn't a securities transaction.
What didn't change
The Howey test is Supreme Court doctrine. If someone invests money in a common enterprise expecting profits from the entrepreneurial or managerial efforts of others, that's an investment contract and federal securities laws apply. This SEC is unlikely to pursue a registration failure. A private plaintiff or a future one still can.
What's new
The GENIUS Act, signed in July 2025, created the first federal regulatory framework for payment stablecoins: who may issue, reserve backing, redemption. The OCC opened an implementing rulemaking in 2026.
State law still applies
New York's BitLicense, and specialized regimes in other states, sit on top of all of it. Federal warmth doesn't preempt a state license.
Regulation Outside the United States
United Kingdom
The Financial Conduct Authority handles conduct across the financial services industry; the Prudential Regulation Authority handles bank safety and soundness. Authorization is more demanding than US founders expect, and Consumer Duty raised the standard from "disclosed it" to "delivered a good outcome."
European Union
The Payment Services Directive built Europe's open banking regime. MiCA gives crypto-asset service providers a passportable authorization, currently the clearest crypto framework anywhere. DORA covers operational resilience. The General Data Protection Regulation governs customer data throughout.
Everywhere else
The Financial Stability Board coordinates without binding anyone. Singapore's MAS and Hong Kong's HKMA compete for fintech businesses on supervisory approach. Emerging-market regulatory authorities use fintech regulation to push financial inclusion, licensing mobile money and agent banking to reach people traditional financial institutions never served.
Across multiple jurisdictions, build for the strictest regime you're subject to. Harmonization isn't coming soon.

What Compliance Costs, and Who It Favours
Regulatory compliance is a barrier to entry, and incumbents know it. Established financial firms have compliance departments and regulator relationships built over decades; a startup pays for that gap in legal fees, licensing capital and calendar time before earning a dollar. Financial regulators talk about a level playing field, and on the rulebook there is one. On the cost of compliance there isn't, and that gap is a quiet tax on financial innovation.
Three things that close the gap
RegTech. Buy the mechanical parts: identity verification, sanctions screening, transaction monitoring, reporting. Building these in-house rarely pays off.
Sequencing. License for the states and products you're actually launching. The five-year plan can wait.
Bank partnership. Converts a licensing problem into a diligence problem, the faster of the two to solve.
Where not to economize
AML, sanctions and operational resilience. Regulators everywhere have moved cybersecurity and continuity from a technology topic to a supervisory one, and a fintech company that can't evidence its incident response finds out during an examination.
Where to Start
Map what your product does function by function and identify the applicable laws for each. Decide your licensing route early, since it sets your timeline more than engineering does. Stand up AML, sanctions and fair lending before launch, since retrofitting costs more.
Fintech regulations exist to keep the financial system stable and to protect consumers from products they can't evaluate. The companies that handle their compliance obligations well decided early which laws and regulations applied and built accordingly.
We build regulated financial products for teams working through this, and we're happy to look at where your architecture and your obligations meet.
FAQ

No single agency. Regulation follows activity, so a company can answer to four or five regulatory bodies at once: the SEC for investment characteristics, FinCEN for money transmission, the CFPB and FTC for consumer conduct, the OCC or Federal Reserve if a charter is involved, plus a money transmitter license per state. Map your product's functions against that list first.
Usually not. Most fintech firms launch through a chartered bank partnership while holding their own state money transmitter licenses. A banking license buys independence and direct access to payment systems, at the cost of capital requirements and a permanent examination relationship. National trust charters, granted to five crypto custody firms in December 2025, suit a narrow set of business models.
A written AML program, customer identification at onboarding, risk-based due diligence, transaction monitoring, suspicious activity reporting, OFAC screening, independent testing and training. The Bank Secrecy Act sets the baseline, the Anti Money Laundering Act of 2020 expanded it, and both apply identically to crypto businesses.
Enforcement has, the law hasn't. The SEC narrowed digital assets enforcement to fraud in 2025 and clarified that certain protocol staking isn't a securities transaction. The Howey test, the Bank Secrecy Act's application to virtual currency, and regimes like New York's BitLicense are unchanged.
Priorities differ more than mechanics. The US regulates by activity across a federal and state split, producing the most fragmented licensing burden of any major market. The UK and EU run centralized authorization with a stronger consumer outcomes duty and, in MiCA, a clearer crypto framework. Emerging markets more often regulate for financial inclusion.








