Abstract editorial illustration for this guide

This guide is general legal information, not legal advice, and does not create an attorney–client relationship. Rules change and vary by state — verify current requirements with official sources or a licensed attorney.

Who regulates fintech in the United States? The honest answer is: no one agency — and, depending on what your product does, possibly half a dozen at once, plus fifty state regulators. The U.S. has no "fintech license" and no dedicated fintech agency. Instead, regulation follows activities: move money and you look like a money transmitter; extend credit and lending laws attach; hold customer funds through a bank partner and banking regulators reach you indirectly; touch securities and the SEC appears.

That activity-based structure means the first legal task for any fintech is not filling out an application — it is mapping the product. This article draws that map: the federal agencies that matter, the state regimes layered underneath, and a method for figuring out which boxes your product ticks.

Key takeaways

  • U.S. fintech regulation is activity-based: the rules that apply depend on whether you transmit money, lend, take deposits, offer investments, or handle consumer data.
  • Key federal players include the CFPB (consumer financial products), FinCEN (anti-money laundering), the FTC (nonbank consumer protection and data security), the SEC and CFTC (investments), and the banking agencies (OCC, Federal Reserve, FDIC) through bank partners.
  • State law adds its own layer — money transmitter licenses, lending licenses, and usury limits — and most states have now enacted the CSBS Money Transmission Modernization Act in whole or part.
  • Partnering with a bank does not outsource compliance: banking regulators expect banks to supervise their fintech partners, and those expectations flow down by contract.
  • Several major rules, including the CFPB's open banking rule under Section 1033, remain in flux as of mid-2026 — build your map to be updated, not carved in stone.

Why there is no single regulator

American financial regulation grew up in layers: banking law from the national-bank era, securities law from the 1930s, the Bank Secrecy Act from 1970, consumer credit statutes from the late twentieth century, and the Consumer Financial Protection Bureau after 2008. Each statute created its own agency with jurisdiction defined by function, not by technology. Fintech companies sit on top of this lattice, and a single app can implicate several regimes simultaneously — a payments feature, a credit feature, and an investment feature each pull in different overseers.

Two practical consequences follow. First, "are we regulated?" is the wrong question; "which of our activities are regulated, and by whom?" is the right one. Second, the answer changes as the product changes, so every significant feature launch deserves a fresh pass over the map.

Matching activities to agencies

Common fintech activities and their primary overseers
If your product…Expect oversight fromCore legal regimes
Transmits or holds customer moneyFinCEN (federal), state money transmission regulatorsBank Secrecy Act, state money transmitter laws
Extends consumer creditCFPB, FTC, state lending regulatorsTILA, ECOA, FCRA, state licensing and usury laws
Offers deposit accounts via a bank partnerOCC, Federal Reserve, or FDIC (through the bank); CFPBThird-party risk guidance, deposit insurance rules, EFTA/Regulation E
Offers investments or tradingSEC, FINRA; CFTC for derivatives and certain digital assetsSecurities laws, broker-dealer and adviser registration
Collects consumer financial dataFTC, CFPB, state attorneys generalGLBA privacy and safeguards rules, state privacy laws

The federal layer, agency by agency

CFPB and FTC: consumer protection

The CFPB writes and enforces rules for consumer financial products — lending disclosures, electronic transfers, credit reporting — and polices unfair, deceptive, or abusive acts and practices, a risk area we cover in depth in our article on UDAAP and CFPB enforcement. Its posture toward nonbanks has swung with administrations, and as of mid-2026 several of its recent rules are under reconsideration, but the underlying statutes still apply. The FTC covers much of the nonbank world too, enforcing its own deception and unfairness standards along with the Gramm-Leach-Bliley privacy and safeguards rules for many nonbank financial companies.

FinCEN: anti-money laundering

The Financial Crimes Enforcement Network administers the Bank Secrecy Act. Fintechs that qualify as money services businesses must register with FinCEN within 180 days, maintain an AML program, and file required reports. The full framework — programs, customer identification, and reporting — is laid out in our AML, KYC, and Bank Secrecy Act primer.

OCC, Federal Reserve, and FDIC: the bank channel

The banking agencies rarely supervise fintechs directly. Their reach is indirect but powerful: they examine the chartered banks that fintechs partner with, and their 2023 interagency guidance on third-party risk management tells banks to conduct due diligence on, contract carefully with, and monitor their fintech partners. In practice, those supervisory expectations arrive at the fintech's door as contract obligations and audit requests — the dynamic explored in our guide to bank–fintech partnerships.

SEC and CFTC: investments and markets

Robo-advisers, brokerage apps, and platforms offering securities fall under SEC jurisdiction and typically FINRA membership; derivatives and many digital-asset activities implicate the CFTC. Token offerings continue to raise classification questions that depend on how the asset is structured and sold — an area where the law was still developing as of 2026, and where early legal analysis pays for itself.

The state layer

Every state has a financial regulator, and their licenses are often the tallest compliance hurdle a young fintech faces. The heavyweight is money transmission licensing: sending, receiving, or holding funds for others generally requires a license in each state where you have customers. Because 50-state licensing was notoriously inconsistent, the Conference of State Bank Supervisors developed the Money Transmission Modernization Act, a model law standardizing definitions, net worth, surety bond, and permissible-investment requirements; by 2026 more than thirty states had enacted it in full or in part. Whether and when your product triggers licensing is a threshold question we unpack in our article on money transmitter licensing.

States also license consumer and commercial lenders, cap interest rates through usury laws, enforce their own consumer protection statutes through attorneys general, and increasingly impose data privacy and cybersecurity rules. Insurance sits entirely in this layer: there is no federal insurance regulator, so a company embedding coverage in its product needs producer or agency licenses from each state's insurance department, and the licensing and distribution rules that govern insurtech programs reach the marketing, quoting, and commission arrangements as well as the underwriting. New York's Department of Financial Services, with its cybersecurity regulation and BitLicense, shows how a single state can set a de facto national standard.

State variation: Exemptions differ sharply. An agent-of-payee exemption may cover your payment flow in one state and not exist in the next. Never generalize one state's analysis to the other forty-nine — check each jurisdiction where you have users.

Rules in motion: open banking and other moving targets

Parts of the map are being redrawn. The CFPB finalized its Section 1033 open banking rule in October 2024, requiring data providers to share consumer financial data on request — then, after litigation, told the court it viewed the rule as unlawful and began a rewrite; a federal court enjoined enforcement while reconsideration proceeds, and the CFPB issued a new advance notice of proposed rulemaking in August 2025. As of mid-2026, the original compliance dates are not being enforced. The Congressional Research Service maintains a useful neutral summary of the Section 1033 rulemaking.

Digital-asset legislation, deposit-insurance recordkeeping proposals, and shifting CFPB priorities all carry the same lesson: treat regulatory positions as versioned documents with review dates, not one-time findings.

Mapping your own product

A structured self-assessment beats guesswork. For each product feature, ask:

  • Do we take possession or control of customer funds at any point, even momentarily?
  • Do we extend credit, defer payment, or purchase receivables — including buy-now-pay-later structures?
  • Are we marketing deposit accounts, and if so, whose charter stands behind them?
  • Could anything we offer be characterized as a security or a derivative?
  • What consumer financial data do we collect, and which privacy regimes cover it?
  • In which states do our customers live, and which licenses or exemptions apply there?
  • Which obligations does our bank or program partner pass through to us by contract?

The corporate side matters too — choice of entity and governance affect licensing applications, which typically probe ownership and control. Our guide to choosing a U.S. business structure covers those foundations.

Frequently asked questions

Is there a federal fintech charter?

Not in any settled form. The OCC has explored special-purpose national charters, and some fintechs have obtained full bank charters or industrial loan company charters instead. Most fintechs still choose between state-by-state licensing and partnering with an existing chartered bank, each with distinct costs and supervisory consequences.

If we partner with a bank, do we still need our own licenses?

Sometimes. A properly structured bank partnership can cover activities performed by the bank, but activities the fintech performs itself — holding funds, moving money outside the bank's rails, lending in its own name — can still trigger state licensing and FinCEN registration. The analysis is structure-specific and state-specific.

Do B2B fintechs face lighter regulation than consumer fintechs?

Often, but not uniformly. Consumer-protection statutes like TILA and EFTA focus on consumers, so pure B2B products avoid some rules. Money transmission licensing and the Bank Secrecy Act, however, generally apply regardless of whether customers are businesses or individuals, and some states regulate commercial financing disclosures too.

How do regulators find out about a noncompliant fintech?

Common routes include consumer complaints to the CFPB or state attorneys general, referrals from bank examiners reviewing a partner bank's third-party program, competitor complaints, licensing applications in one state that reveal unlicensed activity in others, and news coverage. Voluntary remediation before contact is consistently cheaper than enforcement.

Keeping the map current

A regulatory map is a living document. Assign an owner, revisit it at every feature launch and funding round, track the open rulemakings that touch your activities, and log the assumptions behind each conclusion so they can be retested when the law moves. Companies that treat the map this way turn regulatory complexity from a launch blocker into a routine operating discipline — and they are far better positioned when a bank partner, investor, or examiner asks to see the analysis. For the rest of our coverage of this field, see the fintech law topic hub.

Sources & further reading

Accord Legal Review Editorial Team

Accord Legal Review is an independent publisher of U.S. legal guides. Our editorial organization researches primary sources — statutes, regulations, and official agency guidance — and keeps volatile figures pointed at the live official source. Read our editorial standards.