Blog › ICP guides

Fintech attorney on retainer: BSA/AML compliance, money transmitter licensing, CFPB enforcement, and financial regulatory counsel on monthly retainer

August 6, 2026 · ~22 min read

A Series B fintech company — payments infrastructure, $42 million raised, 95 employees, launching a consumer-facing P2P money transfer product with international remittance capability to Mexico and Colombia — receives a letter from FinCEN indicating that the company has been identified as operating as a money services business (MSB), specifically a money transmitter under 31 C.F.R. §1010.100(ff)(5)(i)(A), without having registered with FinCEN as required by 31 U.S.C. §5330 and 31 C.F.R. §1022.380. The FinCEN letter requests confirmation of the company’s Bank Secrecy Act compliance program, suspicious activity report filing history, and currency transaction reporting practices within 30 days.

The company’s retained fintech attorney — a J.D. specializing in financial regulatory compliance, money services business law, and CFPB enforcement — advises that the FinCEN letter requires an immediate multi-track response. First: emergency FinCEN MSB registration through FinCEN’s BSA E-Filing System if the company has not completed the Form 107 registration. Registration must be completed within 180 days of establishing the MSB under 31 C.F.R. §1022.380(b), and failure to register is a criminal violation of 31 U.S.C. §5330(d) subject to a fine of up to $5,000 per day of violation. Second: simultaneous state money transmitter license applications in each state where the company has transmitted money without a license — money transmission without a license is a criminal offense in most states, and the statute of limitations analysis must consider precisely when unlicensed transmission began. Third: implementation of a BSA/AML compliance program satisfying the four pillars of 31 U.S.C. §5318(h) — internal policies, procedures, and controls; BSA compliance officer designation; employee training; and independent testing and audit — along with assessment of whether any suspicious transactions during the unregistered period require backdated SAR filings under 31 C.F.R. §1022.320. Fourth: engagement with FinCEN through outside counsel to present the company’s remediation timeline and demonstrate good-faith compliance steps taken since the inquiry was received.

Fintech attorneys and financial regulatory counsel on monthly retainer — J.D.s specializing in Bank Secrecy Act compliance, money transmission licensing, CFPB enforcement defense, and payments regulatory compliance — do their highest-value advisory work between the FinCEN registration deadlines, state MTL examination notices, and CFPB Civil Investigative Demands that make fintech regulatory exposure publicly visible. This guide covers BSA/AML compliance advisory, money transmission licensing, CFPB enforcement advisory, Regulation E compliance, and PCI DSS legal advisory: the regulatory frameworks behind each service area and how to structure a fintech regulatory retainer that makes the ongoing compliance advisory work visible between enforcement events.

BSA/AML compliance advisory

BSA/AML compliance advisory is the retainer function that advises money services businesses and other fintech companies on their obligations under the Bank Secrecy Act, implements AML compliance programs that satisfy FinCEN’s examination expectations, manages the SAR and CTR filing obligations that arise from transaction monitoring, and ensures that the company’s customer due diligence practices satisfy the FinCEN CDD Rule. The ongoing BSA/AML advisory function is the regulatory bedrock of fintech compliance, touching every transaction that flows through the company’s payments infrastructure.

Bank Secrecy Act AML program requirements and FinCEN registration

31 U.S.C. §5318(h) requires financial institutions, including money services businesses, to establish anti-money laundering programs that include at a minimum four specific elements. 31 C.F.R. §1022.210(d) specifies how each element applies to MSBs: (1) internal policies, procedures, and controls that govern the MSB’s BSA compliance obligations — including transaction monitoring criteria, SAR and CTR filing procedures, customer identification and verification procedures, and record-keeping requirements; (2) designation of a BSA compliance officer responsible for day-to-day management of the AML program, ensuring that it is adequately funded and staffed, and reporting to senior management on AML compliance matters; (3) ongoing employee training to ensure that employees understand the AML program, recognize indicators of suspicious activity relevant to the MSB’s specific products and customer base, and know how to escalate potential SAR situations; and (4) independent testing to audit and evaluate the AML program for effectiveness, conducted by the compliance function, internal audit, or an external auditor on a periodic basis.

FinCEN MSB registration under 31 U.S.C. §5330 and 31 C.F.R. §1022.380 is a threshold compliance obligation for any business that qualifies as an MSB under 31 C.F.R. §1010.100(ff). Every MSB — except an agent of an MSB that is itself registered with FinCEN — must register with FinCEN on FinCEN Form 107 within 180 days of the date on which the business first becomes an MSB. The MSB must re-register every two years: the re-registration period runs from December 1 of the year in which FinCEN Form 107 renewal is due through January 31 of the following calendar year. The MSB must retain a copy of the completed Form 107 and the confirmation of FinCEN’s receipt of the registration for five years and make it available to FinCEN and appropriate law enforcement agencies upon request. Failure to register as an MSB is a criminal violation of 31 U.S.C. §5330(d) — any person who fails to comply with the registration requirements is liable for a civil penalty of not more than $5,000 for each day the violation continues.

MSB definition scope under 31 C.F.R. §1010.100(ff) encompasses six categories of money services businesses: (1) currency dealer or exchanger; (2) check casher; (3) issuer of traveler’s checks, money orders, or stored value; (4) seller or redeemer of traveler’s checks, money orders, or stored value; (5) money transmitter; and (6) the U.S. Postal Service. The “money transmitter” subcategory (§1010.100(ff)(5)) applies to any person who provides money transmission services, defined as the acceptance of currency, funds, or other value that substitutes for currency from one person and the transmission of currency, funds, or other value to another location or person by any means, including through electronic funds transfer systems. A company that operates a consumer P2P payment app, processes international remittances, or provides digital wallet services where funds are accepted from consumers and transmitted to other parties is generally a money transmitter subject to federal MSB registration and state money transmitter licensing requirements.

Currency Transaction Reports under 31 C.F.R. §1010.311 require financial institutions, including MSBs, to file FinCEN Form 112 for each transaction in currency — including currency received for a money transmission, currency exchanged, or currency paid out in connection with an MSB transaction — of more than $10,000 conducted in a single business day. Structuring, defined under 31 U.S.C. §5324 as breaking up currency transactions into amounts of $10,000 or less to evade the CTR filing requirement, is a separate and standalone BSA criminal offense. The retained fintech attorney advising on CTR compliance evaluates whether the company’s transaction monitoring system is configured to identify transactions that individually are below the $10,000 CTR threshold but that, in aggregate across multiple transactions on the same business day by the same customer, exceed the threshold and require a CTR filing. FinCEN’s regulations require aggregation of multiple transactions by the same customer on the same business day when the financial institution has knowledge that the transactions are by the same person.

FinCEN Customer Due Diligence Rule and beneficial ownership identification

The FinCEN Customer Due Diligence Rule, codified at 31 C.F.R. §1010.230 and effective May 11, 2018, requires covered financial institutions to establish and maintain written customer due diligence procedures that incorporate four core elements: (1) customer identification and verification — identifying and verifying the identity of customers to the extent reasonable and practicable, consistent with the customer identification program (CIP) requirements that apply to the specific type of financial institution; (2) beneficial owner identification and verification — identifying and verifying the identity of the beneficial owners of legal entity customers (defined as natural persons who own 25% or more of the equity interests of the entity, plus a single “control” person with significant responsibility to manage or direct the legal entity); (3) nature and purpose understanding — understanding the nature and purpose of customer relationships to develop customer risk profiles; and (4) ongoing monitoring — conducting ongoing monitoring of the customer relationship to identify and report suspicious transactions, and on a risk basis to maintain and update customer information.

Beneficial ownership identification threshold under the CDD Rule uses a 25% equity ownership threshold and requires identification of any natural person who owns, directly or indirectly, 25% or more of the equity interests of a legal entity customer, plus one control person (an individual with significant responsibility to control, manage, or direct the legal entity customer, which may include a CEO, CFO, COO, managing member, general partner, president, vice president, or treasurer). The retained fintech attorney advising on CDD Rule implementation evaluates whether the company’s onboarding and customer risk assessment procedures for business accounts properly identify the beneficial owners of the entity, document the verification steps taken for each beneficial owner’s identity, and incorporate the beneficial ownership information into the company’s SAR monitoring processes.

Suspicious Activity Reports under 31 C.F.R. §1022.320 require MSBs to file FinCEN Form 111 for any transaction or attempted transaction involving $2,000 or more where the MSB knows, suspects, or has reason to suspect that the transaction: involves funds from illegal activity or is intended to evade reporting; is designed to evade any BSA reporting requirement; lacks a lawful purpose or is not the type of transaction that the customer in question would normally be expected to engage in; or involves the use of the MSB to facilitate criminal activity. The 30-day SAR filing deadline runs from the date on which the MSB initially detects the facts that may constitute a basis for filing a SAR; a 60-day deadline applies when no suspect has been identified at the time of detection. The SAR tipping-off prohibition under 31 U.S.C. §5318(g)(2) prohibits disclosing to the subject of a SAR that a SAR has been filed or that the transaction has been reported to FinCEN; the retained attorney advises compliance staff on what communications with a customer are permissible during the SAR investigation period and after a SAR has been filed.

FinCEN Geographic Targeting Orders (GTOs) issued under 31 U.S.C. §5326 authorize FinCEN to impose additional BSA reporting and record-keeping requirements on financial institutions in specific geographic areas when FinCEN determines that the additional reporting is necessary to prevent evasion of BSA requirements or to carry out the BSA’s purposes. FinCEN has issued GTOs targeting specific real estate markets (requiring title insurance companies to identify the beneficial owners of LLCs purchasing residential real estate in certain metropolitan areas), specific cross-border corridors, and specific MSB categories. The retained fintech attorney advises on GTO applicability to the company’s business activities and geographic markets, and ensures that the company’s compliance program incorporates the additional requirements imposed by any applicable GTO.

Money transmitter licensing — state MTL requirements and NMLS multistate licensing

Money transmission licensing is a state-by-state regulatory regime that operates alongside the federal MSB registration requirement: FinCEN MSB registration addresses federal BSA compliance obligations, while state money transmitter licenses (MTLs) address state consumer protection, safety and soundness, and anti-fraud requirements for money transmission. Forty-nine states plus the District of Columbia, Puerto Rico, the U.S. Virgin Islands, and Guam separately regulate money transmission, each with its own licensing statute, application requirements, examination process, annual reporting obligations, and enforcement authority. Operating as a money transmitter in a state without the required MTL is a criminal offense in most states, often a felony.

State MTL application requirements vary significantly across jurisdictions. Net worth requirements range from $100,000 minimum in many states to $500,000 or more in New York (NYDFS requires net worth of $500,000 to $1 million depending on transaction volume) and $250,000 minimum in California (California Financial Code §2030 et seq.). Surety bond requirements typically range from $25,000 to $500,000 depending on the state and the applicant’s annual transaction volume. Application packages typically require: fingerprinting and background check submissions for all principals, directors, officers, and key personnel; three to five years of audited financial statements; a detailed business plan describing the money transmission products, customer base, geographic scope, and risk management framework; the AML compliance program; and state examination fees ranging from a few hundred dollars to tens of thousands of dollars for initial licensure in major states. The retained fintech attorney advises on which states require MTL applications based on the company’s existing and projected customer geography, the prioritization of MTL applications to minimize the period of unlicensed operation, and the application strategy for states with long review timelines (California, New York, and Texas MTL applications frequently take 12 to 18 months to receive approval).

NMLS multistate licensing through the Nationwide Multistate Licensing System (NMLS) provides a centralized platform for money transmitter licensing in 48 states through coordinated application submission and examination processes. The Multi-State MSB Licensing Agreement (MMLA) allows a company seeking MTLs in multiple participating states to submit a single application package through NMLS and undergo a coordinated multi-state examination, rather than filing separate applications with each state’s regulatory agency independently. The retained fintech attorney advises on the MMLA application strategy, including which states’ agencies will lead the coordinated examination, how to prepare the business plan and AML program submissions for the coordinated review, and how to manage responses to examination findings from multiple state agencies following the coordinated examination.

NYDFS BitLicense under 23 NYCRR Part 200 requires any person engaged in “virtual currency business activity” with or on behalf of a New York resident to obtain a BitLicense from the New York Department of Financial Services. “Virtual currency business activity” is defined broadly to include: receiving virtual currency for transmission or transmitting virtual currency; storing, holding, or maintaining custody or control of virtual currency on behalf of others; buying or selling virtual currency as a customer business; exchanging virtual currency as a customer business; and performing exchange services or acting as a payment processor for virtual currency transactions. The BitLicense application requires a comprehensive AML compliance program, a cybersecurity program satisfying 23 NYCRR Part 500, anti-fraud procedures, consumer protection policies, capital requirements (NYDFS has required applicants to maintain minimum capital of $10 million or more in many applications), and a two-year examination cycle. The retained fintech attorney advises on the BitLicense application strategy, including whether the company qualifies for NYDFS’s conditional BitLicense pathway (which allows companies to operate under a limited license while the full application is reviewed), and how to structure the BitLicense application to satisfy NYDFS’s requirements for cybersecurity, AML, and consumer protection.

CFPB enforcement advisory and consumer financial protection

CFPB enforcement advisory is the retainer function that prepares fintech companies for CFPB supervisory examination, defends companies against CFPB Civil Investigative Demands and enforcement actions, advises on UDAAP compliance across consumer-facing financial products, and ensures that consumer electronic fund transfer and remittance transfer services satisfy the Regulation E requirements enforced by the CFPB.

CFPB UDAAP enforcement under Dodd-Frank Section 1031

Dodd-Frank Wall Street Reform and Consumer Protection Act Section 1031, codified at 12 U.S.C. §5531, grants the CFPB authority to take supervisory and enforcement action against covered persons and service providers who engage in unfair, deceptive, or abusive acts or practices (UDAAP) in connection with consumer financial products or services. UDAAP is the CFPB’s broadest enforcement authority, and the CFPB has used it against fintech companies for practices ranging from misrepresentation of fees and terms to discriminatory algorithms in credit decisions.

Unfair acts or practices under Dodd-Frank Section 1031(c) are defined using a three-part test mirroring the FTC Act Section 5 unfairness standard: the act or practice causes or is likely to cause substantial injury to consumers; the injury is not reasonably avoidable by consumers acting reasonably in their own interest; and the injury is not outweighed by countervailing benefits to consumers or to competition. CFPB enforcement actions against fintech companies for unfairness have targeted practices including: charging consumers fees for services that were not properly disclosed at account opening; freezing consumer accounts without adequate notice or consumer opportunity to access funds; failing to implement adequate fraud detection systems that result in unauthorized transaction losses to consumers; and deploying deceptive auto-enrollment in fee-generating services. The retained fintech attorney advising on UDAAP unfairness risk evaluates whether specific product features, fee structures, or account management practices meet the three-part test for unfairness and recommends design modifications that reduce unfairness exposure.

Deceptive acts or practices under Dodd-Frank Section 1031 follow the FTC Act Section 5 deception framework: a representation, omission, or practice is deceptive if it is likely to mislead consumers acting reasonably under the circumstances, and the representation, omission, or practice is material (likely to affect the consumer’s decision-making). The CFPB has brought deception enforcement actions against fintech companies for: misrepresenting the fees associated with international money transfers; advertising “free” services that included undisclosed fees charged through alternative mechanisms; using dark patterns in mobile app design to steer consumers toward higher-cost options while obscuring lower-cost alternatives; and making misleading claims about the speed of fund transfers to international recipients.

Abusive acts or practices under Dodd-Frank Section 1031(d) introduce a concept not present in the FTC Act: an act or practice is abusive if it materially interferes with the ability of consumers to understand a term or condition of a consumer financial product or service, or if it takes unreasonable advantage of (a) consumers’ lack of understanding of the material risks, costs, or conditions of the product or service; (b) consumers’ inability to protect their interests in selecting or using the product or service; or (c) consumers’ reasonable reliance on a covered person to act in their interests. The CFPB’s abusiveness standard has been applied in enforcement actions targeting fintech companies that used complex fee structures designed to be difficult for consumers to understand, companies that deployed cross-selling practices that exploited consumers’ existing account relationships to enroll them in unwanted additional services, and companies that targeted financially vulnerable consumers with high-cost products in contexts where the consumer had limited alternatives.

CFPB Civil Investigative Demands (CIDs) are the CFPB’s primary pre-enforcement investigative tool under 12 U.S.C. §5562. A CID may require the production of documents, answers to interrogatories (written questions), or sworn testimony from the company’s officers, employees, and agents. The CFPB must provide a CID notification of purpose explaining the nature of the conduct being investigated and the applicable laws implicated by the investigation, but the CID need not constitute a formal accusation of wrongdoing. The retained fintech attorney responding to a CFPB CID advises on the scope of document production obligations, identifies potentially privileged materials (attorney-client communications, attorney work product) and prepares a privilege log, petitions to modify or set aside CIDs that are overbroad or unduly burdensome under 12 U.S.C. §5562(f), and manages the sworn testimony process including preparing company witnesses for CFPB investigational hearings. CFPB supervision — the CFPB’s ongoing examination authority over “larger participants” in consumer financial markets as defined by CFPB rulemaking — gives the CFPB access to the company’s books, records, accounts, and personnel without a CID and without prior notice of an investigation.

Regulation E compliance for electronic fund transfers

The Electronic Fund Transfer Act (EFTA), 15 U.S.C. §1693 et seq., and its implementing regulation, Regulation E (12 C.F.R. Part 1005), govern electronic fund transfers involving consumer accounts at financial institutions, including money transfers initiated through mobile apps, prepaid accounts, and digital wallets. The CFPB has supervisory and enforcement authority over Regulation E compliance for non-bank financial institutions and larger participants in consumer financial markets.

Consumer liability limitations under Regulation E §205.6 establish three tiers of consumer liability for unauthorized electronic fund transfers, based on the timing of the consumer’s notification to the financial institution: if the consumer notifies the financial institution within two business days of learning of the loss or theft of an access device, the consumer’s liability is limited to the lesser of $50 or the amount of unauthorized transfers occurring before notification; if the consumer notifies the financial institution more than two business days but within 60 days after the transmittal of a periodic statement reflecting the unauthorized transfer, the consumer’s liability is limited to the lesser of $500 or the sum of the unauthorized transfers occurring in the two-day period plus unauthorized transfers occurring after the two-day period and before notification that the institution could have prevented had notification been timely; if the consumer fails to notify the institution within 60 days after transmittal of the periodic statement showing the first unauthorized transfer, the consumer’s liability for subsequent unauthorized transfers is potentially unlimited (the institution must demonstrate that the subsequent transfers would not have occurred but for the consumer’s failure to timely notify). The retained attorney advising on Regulation E consumer liability applies these tiers to individual consumer disputes to determine the maximum recoverable loss and the institution’s reimbursement obligation.

Error resolution procedures under Regulation E §205.11 require financial institutions to investigate consumer-reported errors (unauthorized EFTs, incorrect transfer amounts, failure to properly identify a beneficiary, transfers not made) and determine whether an error occurred within 10 business days of receiving the consumer’s error notice (20 business days for accounts open less than 30 days). If the institution cannot complete its investigation within 10 business days, it must provisionally credit the consumer’s account for the disputed amount (or the amount of the alleged error, if less than the disputed amount) and complete the investigation within 45 days of receiving the error notice (90 days for transactions initiated at point-of-sale locations or for transactions initiated outside the United States). The retained fintech attorney advising on Regulation E error resolution evaluates the specific complaint against the statutory definition of “error,” assesses whether the provisional credit obligation has been triggered based on the investigation timeline, and advises on the required written notification to the consumer of the error resolution determination.

Prepaid account compliance under the 2017 CFPB Prepaid Rule (12 C.F.R. §1005.18) requires prepaid account providers (including digital wallets and prepaid debit card programs) to provide consumers with two standardized disclosure documents before acquiring a prepaid account: a short-form disclosure summarizing key fees and features using a prescribed format and a long-form disclosure providing a comprehensive fee schedule. The Prepaid Rule also extends Regulation E’s consumer liability limitations and error resolution procedures to prepaid accounts, requires prepaid account providers to make account information available to consumers upon request, and imposes specific requirements for prepaid accounts with associated credit features (including credit card-style protections for any covered separate credit feature accessible by a prepaid card). The retained attorney advises on whether the company’s digital wallet or prepaid card program qualifies as a “prepaid account” under §1005.2(b)(3), ensures that the company’s disclosure format and content satisfies the Prepaid Rule requirements, and advises on the error resolution and liability limitation provisions as applied to the specific account features offered.

Regulation E remittance transfer rules and international payments compliance

Dodd-Frank Section 1073 added a new section to the EFTA covering international remittance transfers, codified at 15 U.S.C. §1693o-1 and implemented in Regulation E Subpart B, §§1005.30–1005.36. The remittance transfer rules apply to “remittance transfer providers” — any person who provides remittance transfer services in the normal course of business, subject to a de minimis safe harbor for providers who make 100 or fewer remittance transfers per year. A fintech company providing consumer P2P international money transfers to Mexico, Colombia, or other countries is a remittance transfer provider subject to these rules regardless of whether it holds a state MTL in the destination country’s jurisdiction.

Pre-payment disclosure requirements under Regulation E §1005.31 require the remittance transfer provider to disclose to the sender, before the sender makes any payment, the following information: the exchange rate to be used in the transfer (if the remittance is in a foreign currency); all fees imposed by the provider and any fees imposed by the provider’s agents in connection with the transfer; all taxes collected by the provider and known third-party taxes; the amount to be received by the designated recipient, expressed in the currency of the destination country; and the date on which funds will be available to the designated recipient. These pre-payment disclosures must be provided in the sender’s language if the provider communicates with the sender in a language other than English in the normal course of business.

Cancellation rights under Regulation E §1005.34 give the sender the right to cancel the remittance transfer within 30 minutes of payment for a full refund, unless the funds have already been picked up or deposited into the recipient’s account at the time the sender requests cancellation. If the sender requests cancellation after the 30-minute window but before the funds are available to the recipient, the provider may (but is not required to) honor the cancellation request. The retained attorney advising on cancellation rights implementation evaluates whether the company’s payment processing infrastructure can technically accommodate the 30-minute cancellation window, whether the consumer-facing app’s cancellation mechanism satisfies the Regulation E cancellation notice requirements, and how to handle cancellation requests received after the 30-minute window when the transfer status is uncertain.

Error resolution for remittance transfers under Regulation E §1005.33 applies if the consumer reports an error within 180 days of the scheduled date of fund availability to the recipient. The provider must investigate and respond within 90 days of receiving the error notice. Covered errors include: non-delivery of the transferred funds to the designated recipient; incorrect amount received by the recipient; incorrect amount charged to the sender; application of an incorrect exchange rate; and failure to make funds available by the disclosed availability date. Upon finding a confirmed error, the provider must refund the transfer amount and all fees charged, or re-transmit the remittance transfer at no additional cost to the sender. The retained attorney advising on remittance error resolution evaluates each reported error against the §1005.33 definition, assesses whether the provider’s investigation procedures satisfy the 90-day investigation obligation, and advises on the applicable remediation obligation (refund versus re-transmission) based on the nature of the error.

International AML compliance for remittance transfer providers encompasses OFAC sanctions screening obligations for international transfer destinations. The Office of Foreign Assets Control (OFAC) administers economic and trade sanctions programs that prohibit U.S. persons from engaging in transactions involving designated countries (Cuba, Iran, North Korea, Syria, Russia under specific sector-based sanctions), entities on the Specially Designated Nationals and Blocked Persons (SDN) List, and entities covered by non-SDN sanctions programs. A fintech company processing international remittances to Mexico and Colombia must screen each transfer’s originator and beneficiary against the OFAC SDN List and applicable sanctions programs, implement automated screening controls that flag potential matches for human review, and maintain records of all screening determinations and match dispositions. The retained attorney also advises on the BSA Travel Rule under 31 C.F.R. §1010.410, which requires financial institutions transmitting funds of $3,000 or more to collect and retain the name, address, account number, and identity documentation information of the originator, and to pass the originator’s name, account number, and address along with the beneficiary’s name and account number to the beneficiary’s financial institution in the transmittal order.

PCI DSS compliance legal advisory and payments regulatory advisory

PCI DSS compliance legal advisory is the retainer function that advises fintech companies on the Payment Card Industry Data Security Standard’s scope determination, merchant and service provider compliance level assessment, QSA engagement strategy, and contractual allocation of PCI DSS compliance obligations. GLBA compliance advisory addresses the privacy and information security obligations that apply to fintech companies qualifying as “financial institutions” under the Gramm-Leach-Bliley Act.

PCI DSS v4.0 compliance scope and merchant level determination

Payment Card Industry Data Security Standard version 4.0, published by the PCI Security Standards Council in March 2022 and mandatory for all assessments from March 31, 2024, establishes 12 security requirements organized across six security goal areas: Build and Maintain a Secure Network and Systems; Protect Account Data; Maintain a Vulnerability Management Program; Implement Strong Access Control Measures; Regularly Monitor and Test Networks; and Maintain an Information Security Policy. PCI DSS v4.0 introduced 64 new or modified requirements relative to PCI DSS v3.2.1, with a phased implementation timeline through March 31, 2025 for the most demanding new requirements.

Cardholder data environment scope determination is the foundational PCI DSS compliance task for fintech companies. The cardholder data environment (CDE) includes all system components that store, process, or transmit primary account numbers (PANs), cardholder names, service codes, or expiration dates (the combination of which constitutes “cardholder data” under PCI DSS definitions), plus all system components that are connected to or could affect the security of the systems that store, process, or transmit cardholder data. The retained attorney advising on CDE scope determination evaluates whether the company’s existing infrastructure design (tokenization systems, point-to-point encryption implementations, payment page outsourcing arrangements) successfully reduces the CDE scope, and whether scope reduction strategies are implemented consistently enough to support a reduced-scope PCI DSS assessment.

Merchant and service provider level determination under PCI DSS is based on annual Visa and Mastercard transaction volumes processed by the entity. Four merchant levels apply: Level 1 merchants process more than 6 million Visa or Mastercard transactions annually, or have experienced a data breach or attack resulting in account data compromise, and require annual on-site assessments by a Qualified Security Assessor (QSA) and quarterly network scans by an Approved Scanning Vendor (ASV); Level 2 merchants process 1 million to 6 million Visa or Mastercard transactions annually; Level 3 merchants process 20,000 to 1 million e-commerce transactions annually; Level 4 merchants process fewer than 20,000 e-commerce transactions annually or up to 1 million transactions of other types. Levels 2 through 4 can use Self-Assessment Questionnaires (SAQs) in lieu of a QSA-prepared Report on Compliance (ROC), though some Level 2 merchants elect QSA assessments for additional assurance or to satisfy contractual requirements from acquiring banks.

PCI DSS v4.0 new requirements effective by March 31, 2025 include requirements that present particular implementation challenges for fintech companies: targeted risk analyses documenting the approach, methodology, and results for each PCI DSS requirement where the company uses a customized implementation approach; documented annual penetration testing scope that confirms all CDE systems and network connections are included; phishing-resistant multi-factor authentication (MFA) for all users with access to the CDE; automated technical controls to detect and alert on failures of critical security controls (intrusion detection systems, firewalls, anti-malware software, audit log systems) within one business day of failure detection; and for e-commerce merchants, payment page script integrity management requiring detection and alerting for unauthorized modifications to payment scripts (SHA-256 or stronger cryptographic hash validation of scripts loaded on the payment page). The retained attorney advises on QSA engagement strategy, the structure of the Report on Compliance (ROC) for Level 1 assessments, the allocation of PCI DSS compliance responsibilities between the fintech company and its payment processing service providers in contracts, and the legal obligations arising from PCI DSS data breach response (notification to payment brands, acquirers, and affected cardholders; forensic investigation under PCI DSS Requirement 12.10; and potential liability to the payment card brands for assessments arising from the breach).

GLBA Privacy Rule and customer information protection

The Gramm-Leach-Bliley Act, 15 U.S.C. §§6801–6827, imposes privacy and information security requirements on “financial institutions,” defined as companies that are significantly engaged in providing financial products or services to consumers. Fintech companies providing payments services, consumer lending, digital banking, investment services, or insurance-adjacent services are typically subject to GLBA as financial institutions. The FTC enforces GLBA for entities not subject to the jurisdiction of a federal banking regulator; the CFPB enforces GLBA for larger participants in consumer financial markets subject to CFPB supervision.

GLBA Privacy Rule under 16 C.F.R. Part 313 (for FTC-regulated entities) and 12 C.F.R. Part 1016 (for CFPB-regulated entities) requires financial institutions to: (1) provide customers with an initial privacy notice describing the categories of nonpublic personal information (NPI) the institution collects, the categories of nonaffiliated third parties to whom NPI is disclosed, and the consumer’s opt-out rights, delivered at the time the customer relationship is established; (2) provide annual privacy notices to customers throughout the customer relationship (subject to the exception under the 2015 FAST Act allowing financial institutions to cease annual notice delivery if their privacy practices qualify for the exception); and (3) provide customers with the right to opt out of information sharing with nonaffiliated third parties before that sharing occurs, subject to specific exceptions for service provider arrangements under §313.13 and other enumerated exceptions under §313.15. The retained attorney advising on GLBA Privacy Rule compliance reviews the company’s privacy notice for accuracy, advises on whether the company’s information sharing practices satisfy the applicable exceptions, and evaluates whether the company’s opt-out mechanism satisfies the GLBA requirement that the consumer be given a reasonable opportunity to opt out before sharing occurs.

GLBA Safeguards Rule under 16 C.F.R. Part 314, as amended by the FTC in 2023, requires financial institutions to implement a comprehensive written information security program (WISP or ISMP) designed to protect the security and confidentiality of customer information, protect against anticipated threats to the security or integrity of customer information, and protect against unauthorized access or use of customer information that could result in substantial harm or inconvenience to any customer. The 2023 amended Safeguards Rule requires: designation of a qualified individual (a Chief Information Security Officer or equivalent) responsible for overseeing and implementing the information security program; a written risk assessment identifying and assessing foreseeable internal and external risks to customer information; safeguards including access controls (limiting customer information to authorized personnel), encryption of customer information at rest and in transit, multi-factor authentication for employees accessing customer information systems, penetration testing at least annually, vulnerability scanning at least every six months, and a vendor oversight program; and an incident response plan that includes procedures for assessing and containing a security event and notifying affected customers, relevant regulators, and (for qualifying cybersecurity events) the FTC. The 2023 amended Safeguards Rule also requires the qualified individual to report annually to the company’s board of directors (or equivalent oversight body) on the status of the information security program and material matters relating to the program.

California Financial Information Privacy Act (Cal. Fin. Code §§4050–4060) extends GLBA privacy protections for California consumers by requiring California-regulated financial institutions to obtain opt-in consent before sharing NPI with nonaffiliated third parties, even for joint marketing purposes where GLBA would permit sharing with an opt-out mechanism. The retained attorney advising fintech companies with California customers evaluates whether the California FIPA’s opt-in consent requirement applies to the company’s information sharing practices and, if so, advises on how to obtain the required opt-in consent in a manner that satisfies both California FIPA and the GLBA Privacy Rule’s disclosure requirements.

Tracking fintech attorney retainer hours with a shared dashboard

Fintech attorneys and financial regulatory counsel on monthly retainer perform the advisory work between FinCEN inquiries, state MTL examination notices, and CFPB Civil Investigative Demands that shapes the company’s long-term regulatory risk profile. BSA/AML program gap analysis, SAR obligation evaluations for transaction monitoring alerts, state MTL annual report preparations, Regulation E error resolution advisory for consumer disputes, OFAC sanctions screening program reviews, GLBA Safeguards Rule vendor oversight documentation, and CFPB supervisory examination preparation generate no visible regulatory output for the company’s compliance committee, board of directors, or general counsel until a specific enforcement event is triggered. A FinCEN civil money penalty, a CFPB consent order, or a state MTL license revocation proceeding becomes the first visible evidence of work that the retained fintech attorney should have been documenting for months or years.

A retainer dashboard with a work log transforms the opaque monthly financial regulatory compliance fee into a documented compliance advisory record. The work log entry that identifies the specific BSA provision analyzed (31 C.F.R. §1022.320 SAR aggregation rule, 31 C.F.R. §1010.230 CDD Rule beneficial ownership verification, 23 NYCRR Part 200 BitLicense capital requirement), the factual application of that provision to the company’s transaction data or product structure, and the compliance recommendation reached gives the company’s compliance team and general counsel a contemporaneous record of the regulatory advisory that explains how the monthly retainer hours are being applied to reduce enforcement exposure. When a FinCEN examination notice arrives or a CFPB CID is received, the work log provides the documentation that demonstrates the company had engaged outside regulatory counsel, identified the relevant compliance issues, and taken remediation steps in advance of the enforcement event.

HourTab provides fintech attorneys and financial regulatory counsel with a public, no-login retainer dashboard URL that the retained attorney sends to the company’s compliance officer or general counsel once, and the client bookmarks. The dashboard shows the current retainer burn-down (hours used versus hours remaining in the monthly cycle), a chronological work log of regulatory advisory entries with matter type, regulatory provision, and compliance conclusion, and the reset date for the next billing period. The compliance team can check current retainer utilization without an email to the attorney, and the work log provides the ongoing compliance advisory record between the FinCEN inquiry letters, CFPB CIDs, and state MTL examination notices that make fintech regulatory exposure visible.

Frequently asked questions

What does a fintech attorney on retainer typically do?

A fintech attorney on monthly retainer provides ongoing advisory across the full spectrum of financial regulatory compliance obligations, including BSA/AML program review and FinCEN reporting advisory; FinCEN MSB registration management; state money transmitter license application, renewal, and examination management across all licensed states; NYDFS BitLicense advisory and application support; CFPB UDAAP compliance review across consumer-facing financial products and marketing materials; Regulation E consumer dispute and error resolution advisory; Regulation E remittance transfer compliance for international payment products; OFAC sanctions screening program advisory; GLBA Privacy Rule and Safeguards Rule compliance; PCI DSS scope determination and QSA engagement advisory; and CFPB Civil Investigative Demand response and supervisory examination preparation. See the FAQ entries below for detailed breakdowns of each service area and specific regulatory provisions involved.

What fintech regulatory advisory work is most commonly underlogged?

The most systematically underlogged categories in fintech attorney retainers are BSA/AML program gap analysis against the four 31 U.S.C. §5318(h) pillars and FinCEN examination expectations, which consumes 15 to 30 hours per annual review and produces no visible regulatory output until an examination or enforcement proceeding; state MTL annual report preparation across all licensed states, which runs 5 to 10 hours per state per annual cycle and represents 100 to 300 hours per year for a company with 20 to 30 licensed states; Regulation E error resolution advisory for individual consumer disputes, which takes 2 to 5 hours per complex dispute involving unauthorized transfer analysis, provisional credit obligation timing, and reimbursement calculation; SAR obligation analysis for transaction monitoring alerts requiring the attorney to apply the 31 C.F.R. §1022.320 aggregation rule to evaluate potential structuring activity, which takes 2 to 4 hours per complex alert; vendor contract cybersecurity and data sharing review for GLBA Safeguards Rule vendor oversight compliance, including SOC 2 report review, cybersecurity addenda negotiation, and annual vendor oversight documentation, which runs 5 to 10 hours per vendor per review cycle; and CFPB supervisory examination preparation including consumer complaint response procedure review, UDAAP risk assessment, and Regulation E compliance testing methodology, which typically consumes 20 to 40 hours per examination cycle.

What should a fintech attorney retainer agreement include?

Fintech attorney retainer agreements should specify the services covered (BSA/AML program advisory, state MTL management, CFPB UDAAP compliance, Regulation E consumer advisory, GLBA compliance, PCI DSS advisory, or a defined subset); the applicable legal frameworks (31 U.S.C. §5318, 31 C.F.R. §1022.210, 31 C.F.R. §1022.320, 31 C.F.R. §1010.230, 31 C.F.R. §1022.380, 12 U.S.C. §5531, EFTA 15 U.S.C. §1693 et seq., 12 C.F.R. Part 1005 including §§1005.30–1005.36, GLBA 15 U.S.C. §§6801–6827, state MTL statutes in all licensed states, and 23 NYCRR Part 200 if applicable); examination and enforcement activation terms specifying how hours are drawn down when a FinCEN examination notice, CFPB CID, or state MTL examination is received; the deliverables format (AML program gap analysis memos, SAR obligation analysis entries, MTL application packages, UDAAP compliance review memos, Regulation E advisory, OFAC screening program reviews, GLBA Safeguards assessments); and the work log format. Monthly retainer amounts for ongoing fintech regulatory advisory range from $5,000 to $15,000 per month for standard compliance advisory; $20,000 to $75,000 or more per month during active FinCEN investigations, CFPB CID response, or state enforcement actions.

What are typical retainer rates for fintech attorneys?

Fintech associates and regulatory counsel with 3 to 7 years of experience in BSA/AML compliance, money transmission licensing, or CFPB enforcement defense typically bill at $300 to $500 per hour. Senior fintech partners and financial regulatory counsel with 8 or more years of experience in FinCEN enforcement defense, CFPB CID response, or complex money transmitter licensing typically bill at $450 to $700 per hour. Former FinCEN officials, former CFPB enforcement attorneys, former NYDFS examiners, and attorneys holding CAMS (Certified Anti-Money Laundering Specialist) credentials from ACAMS typically command rates of $600 to $900 per hour or more. Monthly retainer amounts for ongoing fintech regulatory advisory (BSA/AML program maintenance, state MTL management, Regulation E compliance advisory, GLBA compliance) typically range from $5,000 to $15,000 per month; during active FinCEN investigation, CFPB CID response, or state enforcement action, monthly costs typically range from $20,000 to $75,000 or more depending on scope and the number of regulatory agencies involved simultaneously.

How should fintech attorney retainer hours be logged?

Fintech attorney retainer work log entries should capture the matter type (BSA/AML program review, FinCEN registration, SAR filing advisory, CTR filing review, CDD Rule compliance, state MTL application or renewal, BitLicense advisory, CFPB UDAAP review, Regulation E error resolution, remittance transfer compliance, OFAC screening, GLBA Safeguards Rule review, PCI DSS advisory), the specific task performed, the applicable regulatory provision analyzed, and the compliance conclusion or recommended action. A useful entry format is: “BSA/AML SAR Obligation Analysis — [Company] P2P payment transaction cluster. Identified cluster of 47 transactions between 2 accounts (Account A → Account B) totaling $38,400 over 8-day period: individual transactions ranged from $799 to $1,995 (all below $2,000 SAR threshold but pattern suggests potential structuring). Legal framework: 31 C.F.R. §1022.320 SAR filing obligation — MSBs must file SAR if transaction involves $2,000 or more AND MSB knows, suspects, or has reason to suspect transaction involves funds from illegal activity, is designed to evade BSA reporting, or lacks lawful purpose. Analysis: (1) Transaction amounts: individual transactions each below $2,000 threshold, but 31 C.F.R. §1022.320(a)(2) aggregation rule requires aggregating transactions if the MSB knows, suspects, or has reason to suspect that the transactions are part of an effort to evade SAR reporting requirements (structuring of MSB transactions); (2) Structuring indicators: 47 transactions between same accounts over 8-day period; amounts consistently below $2,000 SAR threshold; no apparent business purpose for frequent low-value transfers; velocity inconsistent with Account A’s prior transaction history; (3) Conclusion: transaction cluster presents sufficient basis for MSB to ‘suspect’ structuring under §1022.320 aggregation rule — combined value $38,400 exceeds $2,000 threshold; SAR filing recommended for structuring/layering; (4) SAR tipping-off: §5318(g)(2) prohibits disclosure to Account A or Account B that SAR has been or will be filed — advise compliance team on permissible vs. impermissible communications with accounts during investigation; (5) Account action: recommend placing Account A on enhanced due diligence (EDD) pending SAR investigation; assess whether account relationship can be continued under OFAC screening and CDD program requirements. 3.5 hours.” Entries that capture the specific regulatory provision analyzed, the factual application, and the compliance conclusion transform the fintech regulatory retainer into a documented compliance record between enforcement events.


HourTab gives fintech attorneys and financial regulatory counsel a public retainer dashboard URL their clients can bookmark — no client login, no portal, just a URL that shows hours used, hours remaining, and the work log behind the retainer. Learn more at hourtab.com.