Fintech Regulation: US Agencies, Licensing, and Compliance

Fintech regulation in the United States is not a single statute but a layered system: federal agencies supervise banking, consumer protection, securities, commodities, and anti-money-laundering compliance, while states handle most licensing for non-bank financial companies. Which rules apply to a given product depends on what the company actually does — lend, move money, deal in digital assets, give investment advice, or hold consumer financial data — and a company that does more than one of those things answers to more than one regulator.

Who Regulates Fintech in the United States

No single agency owns fintech oversight. Responsibility is split by activity and by charter.

Federal Agencies

Three banking regulators supervise the banks that fintechs commonly partner with. The Office of the Comptroller of the Currency (OCC) oversees national banks. The Federal Reserve Board oversees state-chartered banks that are Fed members. The Federal Deposit Insurance Corporation (FDIC) insures deposits and supervises state-chartered banks that are not Fed members.1Office of the Comptroller of the Currency. OCC Bulletin 2024-21 – Bank-Fintech Arrangements: Request for Information When a fintech partners with one of these banks to offer products like high-yield savings accounts or loans, the bank’s regulator can examine the arrangement and hold both parties to safety and soundness standards.2FDIC. Agencies Issue Statement on Bank Arrangements with Third Parties to Deliver Deposit Products

Beyond banking, several agencies bring their own registration, reporting, and conduct requirements:

  • The Consumer Financial Protection Bureau (CFPB) enforces federal consumer financial laws.
  • The Securities and Exchange Commission (SEC) regulates investment platforms and certain digital asset activity.
  • The Commodity Futures Trading Commission (CFTC) regulates commodity futures and derivatives markets, including for digital commodities.
  • The Financial Crimes Enforcement Network (FinCEN) oversees anti-money-laundering compliance for payment companies.
  • The Federal Trade Commission (FTC) enforces data security rules against non-bank financial institutions.
  • The Internal Revenue Service (IRS) governs tax reporting for digital asset transactions.

One live caveat: the CFPB has undergone significant operational changes since early 2025, including reduced staffing, closed supervisory examinations, and terminated enforcement cases as part of a broader reorganization.3U.S. Government Accountability Office. Consumer Financial Protection Bureau: Status of Reorganization The consumer protection statutes it enforces are still in effect, and state attorneys general can independently pursue violations of many of the same laws, but the practical posture of federal enforcement has shifted.

State Licensing

Most non-bank fintechs are primarily regulated at the state level. A company that transmits money, makes loans, or offers certain financial services typically needs a separate license in each state where it operates. That means managing up to fifty different sets of rules for licensing, capital requirements, reporting, and consumer protection. The Nationwide Multistate Licensing System (NMLS) lets companies manage applications and renewals through a single portal, but the underlying state rules still differ.

Alternatives to the State Patchwork

Fintechs that want to bypass state-by-state licensing can apply for a special purpose national bank charter from the OCC. If granted, the company becomes a federally regulated institution held to the same safety and soundness standards as any national bank. Applicants need a detailed three-year business plan, capital and liquidity levels proportionate to their risk profile, a full anti-money-laundering program, and a consumer compliance program that addresses fair lending and unfair practices.4Office of the Comptroller of the Currency. Exploring Special Purpose National Bank Charters for Fintech Companies The charter remains available but has faced legal challenges from state regulators.

Several states also run regulatory sandboxes that let startups test new products with a limited number of consumers before facing full licensing requirements. Arizona, Nevada, and Utah have enacted broad fintech sandbox statutes. Wyoming has a sector-specific sandbox, and Kansas, Kentucky, and Texas enacted their own sandbox programs in 2025.

Rules for Online Lending

Online lenders, buy-now-pay-later providers, and peer-to-peer lending platforms are subject to the same federal consumer credit laws that govern traditional banks. Using an algorithm instead of a human underwriter changes nothing about the underlying obligations.

Truth in Lending Act

The Truth in Lending Act (TILA), implemented through the CFPB’s Regulation Z, requires lenders to clearly disclose the cost of credit before a borrower commits: the annual percentage rate, finance charges, payment schedule, and total amount financed. The purpose is to let consumers compare offers on equal terms.5Federal Trade Commission. Truth in Lending Act These disclosure obligations apply whether a human or an algorithm makes the lending decision.6Consumer Financial Protection Bureau. 12 CFR Part 1026 – Truth in Lending (Regulation Z)

Fair Credit Reporting Act

The Fair Credit Reporting Act (FCRA) governs how consumer financial data is collected, shared, and used in credit decisions. Under FCRA, you have the right to access the data in your credit file, dispute inaccurate information, and be told when information in a credit report has been used against you.7Consumer Financial Protection Bureau. A Summary of Your Rights Under the Fair Credit Reporting Act Fintech lenders that use alternative data sources like rent payment history or utility bills must still meet FCRA’s accuracy and dispute resolution requirements.8Federal Trade Commission. Fair Credit Reporting Act

Equal Credit Opportunity Act and Algorithmic Decisions

The Equal Credit Opportunity Act (ECOA) prohibits lenders from discriminating based on race, color, religion, national origin, sex, marital status, age, or because an applicant receives public assistance. When a lender denies credit or takes other unfavorable action, it must send the applicant a written notice stating the specific reasons for the decision.9Consumer Financial Protection Bureau. 12 CFR Part 1002 (Regulation B) – Section 1002.9 Notifications Vague explanations like “you did not meet our internal standards” do not satisfy the law.

Algorithmic lending complicates this. A machine-learning model might deny credit based on factors the applicant would never guess, and the CFPB has said complexity is not an excuse for vagueness. A lender using AI must disclose the actual reasons the algorithm flagged, even if the relationship between that factor and creditworthiness is not obvious.10Consumer Financial Protection Bureau. CFPB Circular 2023-03 – Adverse Action Notification Requirements and the Proper Use of Sample Forms If the model’s real driver was the applicant’s profession, for example, citing “insufficient projected income” would likely fail the specificity test. Regulators also scrutinize these models for disparate impact on protected groups, even without intentional discrimination.

Rules for Payments and Money Transmission

Fintechs that move money face two overlapping layers of regulation: federal anti-money-laundering obligations and state-by-state transmission licensing. Consumer-facing apps also owe federal protections on electronic fund transfers.

Bank Secrecy Act and FinCEN Registration

Non-bank companies that facilitate money movement are classified as Money Services Businesses (MSBs) under the Bank Secrecy Act. Any MSB must register with FinCEN and implement an anti-money-laundering compliance program.11Financial Crimes Enforcement Network. Am I an MSB? That program has to include procedures for verifying customer identity (KYC), ongoing transaction monitoring, and employee training.

MSBs also have two critical reporting duties. Currency Transaction Reports (CTRs) are required for any cash transaction over $10,000.12FFIEC. Assessing Compliance with BSA Regulatory Requirements Suspicious Activity Reports (SARs) must be filed when a transaction appears to involve illegal funds or lacks an apparent lawful purpose, regardless of dollar amount.11Financial Crimes Enforcement Network. Am I an MSB? Failure to maintain a compliant program or file required reports carries severe civil and criminal penalties.

State Money Transmitter Licenses

Beyond FinCEN registration, most states require a separate Money Transmitter License (MTL). A fintech operating nationwide may need licenses in nearly every state and territory, each with its own application fee, surety bond, and ongoing reporting requirements. Application fees alone run from nothing in a few states to $10,000 in others, before surety bonds, background checks, or legal costs.

Consumer Protections for Electronic Payments

If you use a digital wallet or peer-to-peer payment app linked to your bank account, the Electronic Fund Transfer Act (EFTA) and Regulation E protect you from unauthorized transactions and errors, including the right to dispute incorrect charges and have your financial institution investigate within set time limits.13Consumer Financial Protection Bureau. Electronic Fund Transfers FAQs

Your liability for unauthorized transfers depends on how fast you report:

  • Within 2 business days: your loss is capped at $50.
  • After 2 business days but within 60 days of your statement: your loss can reach $500.
  • After 60 days from your statement: you could be liable for the full amount of any unauthorized transfers that occur after that 60-day window.

Timely reporting is genuinely consequential.14Consumer Financial Protection Bureau. Regulation E – Section 1005.6 Liability of Consumer for Unauthorized Transfers A consumer who ignores a compromised payment app for months could lose far more than someone who catches it early.

Instant Payments Through FedNow

The Federal Reserve’s FedNow Service, launched in 2023, enables real-time payments around the clock. Fintechs that access FedNow through a partner bank are subject to Regulation J’s subpart governing the service. A sending bank must have sufficient funds in its settlement account at the time of the transaction; overdrafts become due immediately and carry an automatic security interest in the sender’s assets held at the Federal Reserve Bank. The receiving bank must credit the beneficiary’s account immediately upon acceptance. Where FedNow transactions also qualify as electronic fund transfers, EFTA protections take precedence over any conflicting FedNow rule.15eCFR. 12 CFR Part 210 Subpart C – Funds Transfers Through the FedNow Service

Rules for Crypto and Digital Assets

Jurisdiction over cryptocurrency has been the most contested corner of fintech law. For years, the core question was whether a given token was a security (SEC), a commodity (CFTC), or something else. A 2026 SEC interpretation substantially reshaped that split.

The SEC’s 2026 Interpretation

In 2026, the SEC issued a formal interpretation declaring that most crypto assets are not themselves securities.16U.S. Securities and Exchange Commission. SEC Clarifies the Application of Federal Securities Laws to Crypto Assets The interpretation establishes a token taxonomy with distinct categories: digital commodities, digital collectibles, digital tools, stablecoins, and digital securities. It was a sharp departure from the prior administration’s enforcement-heavy posture, which had treated many token sales and crypto platforms as unregistered securities offerings.

The SEC still uses the Howey test to determine when a crypto asset becomes subject to securities law. Under Howey, an investment contract exists when someone invests money in a common enterprise expecting profits primarily from others’ efforts. The 2026 interpretation clarifies that a crypto asset that is not itself a security can become part of an investment contract under certain conditions, and can also cease being subject to one. It also addresses the securities-law treatment of airdrops, protocol staking, and protocol mining. Tokens that fall into the “digital securities” category remain fully subject to registration, disclosure, and anti-fraud provisions.16U.S. Securities and Exchange Commission. SEC Clarifies the Application of Federal Securities Laws to Crypto Assets

CFTC Authority

The CFTC regulates digital assets classified as commodities, a category that includes Bitcoin and other tokens whose value derives from supply, demand, and the programmatic operation of a functional crypto system rather than from a central team’s managerial efforts. The CFTC has exclusive authority over commodity futures and derivatives markets and exercises anti-fraud and anti-manipulation enforcement over the underlying spot markets. As of mid-2026, the agency’s spot-market jurisdiction still rests largely on those existing enforcement powers rather than comprehensive statutory oversight.

Stablecoins Under the GENIUS Act

Stablecoins received their first dedicated federal framework when the Guiding and Establishing National Innovation for U.S. Stablecoins (GENIUS) Act was signed into law on July 18, 2025.17The White House. Fact Sheet: President Donald J. Trump Signs GENIUS Act into Law The law imposes:

  • One-to-one reserve backing: at least one dollar of permitted reserves for every dollar of stablecoins in circulation.
  • Permitted reserves limited to cash, insured deposits, short-dated U.S. Treasury bills, certain repurchase agreements backed by Treasuries, government money market funds, and central bank reserves.
  • Monthly public disclosure of reserve composition.
  • Insolvency priority: stablecoin holders’ claims rank ahead of all other creditors if an issuer becomes insolvent.

The Act also directs federal and state regulators to develop tailored capital, liquidity, and risk management rules for issuers, and requires that redemption procedures be clearly disclosed to consumers.17The White House. Fact Sheet: President Donald J. Trump Signs GENIUS Act into Law

Robo-Advisors

Fintech platforms that provide automated investment advice are regulated as investment advisers under the Investment Advisers Act of 1940. That classification carries a fiduciary duty: the platform must act in the client’s best interest and provide only suitable recommendations based on the client’s financial situation.18U.S. Securities and Exchange Commission. IM Guidance Update – Robo-Advisers

In practice, robo-advisors must disclose that an algorithm manages accounts, explain what the algorithm does and does not do, describe its assumptions and limitations, and explain the degree of human oversight involved. If the platform builds a risk profile from a questionnaire, the questions must gather enough information to make the resulting portfolio genuinely appropriate, and the platform must have a system for catching inconsistent client responses rather than blindly following contradictory inputs.18U.S. Securities and Exchange Commission. IM Guidance Update – Robo-Advisers Registration with the SEC, written compliance policies, and custodial safeguards for client assets are all required.

Tax Reporting for Digital Asset Transactions

The IRS treats cryptocurrency and other digital assets as property, not currency. Every sale, exchange, or disposition is a taxable event, just like selling stock.19Internal Revenue Service. Frequently Asked Questions on Virtual Currency Transactions Hold an asset for more than a year and any gain is taxed at long-term capital gains rates of 0%, 15%, or 20% depending on income. Hold for a year or less and gains are taxed at ordinary income rates.

Starting with the 2025 tax year, digital asset brokers are required to report gross proceeds from sales to both the IRS and the customer on Form 1099-DA. For sales on or after January 1, 2026, brokers must also report the customer’s adjusted cost basis and whether the gain or loss is short-term or long-term for covered securities.20Internal Revenue Service. Instructions for Form 1099-DA (2025) If you use multiple exchanges, keep your own record of purchase dates and cost basis, because each broker only reports on assets it custodies for you. For sales of digital assets for real property, reporting requirements take effect for transactions on or after January 1, 2026.21eCFR. 26 CFR 1.6045-1 – Returns of Information of Brokers and Barter Exchanges

Data Privacy and Open Banking

Fintechs collect enormous volumes of sensitive financial data, and two federal frameworks set specific obligations for handling it.

The GLBA Safeguards Rule

The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to protect customer data. The FTC enforces the Safeguards Rule against non-bank financial institutions, and the definition is broad. It covers mortgage lenders, payday lenders, finance companies, check cashers, wire transferors, collection agencies, tax preparers, and non-SEC-registered investment advisors, among others.22eCFR. 16 CFR Part 314 – Standards for Safeguarding Customer Information The FTC has also taken the position that companies whose technology facilitates financial operations on behalf of financial institutions may themselves qualify, which pulls many fintechs into scope.

Covered companies must maintain a written information security program with specific elements:

  • Designate a qualified individual responsible for overseeing and enforcing the security program.
  • Conduct a risk assessment of reasonably foreseeable internal and external threats to customer data.
  • Encrypt all customer information both in transit over external networks and at rest.
  • Require multi-factor authentication for anyone accessing customer information on the company’s systems.
  • Regularly monitor and test the effectiveness of safeguards.
  • Maintain a written incident response plan if the company holds information on 5,000 or more consumers.

Companies with fewer than 5,000 consumer records face a reduced set of requirements but still must address risk assessment, safeguard design, testing, and oversight of service providers.22eCFR. 16 CFR Part 314 – Standards for Safeguarding Customer Information

Section 1033 and Open Banking

The CFPB’s Section 1033 rule, the Personal Financial Data Rights rule, requires financial institutions and fintech data providers to share consumer account data with authorized third parties at the consumer’s request, in a standardized, machine-readable electronic format.23eCFR. 12 CFR Part 1033 – Data Sharing and Open Data Access Requirements for Covered Persons Third parties that receive the data face limits on how they collect, use, and retain it.

Compliance is being phased in by institution size, with the largest depository institutions and non-depository participants facing an April 2026 compliance date and smaller institutions following in subsequent years. Institutions under $850 million in assets are exempt. The rule formalizes the data portability that many fintech apps already rely on while giving consumers more control over who sees their financial information and for how long. Given the CFPB’s ongoing reorganization, fintech companies should watch whether the compliance timeline or enforcement approach shifts as the agency’s operational scope evolves.