Regulatory layering
Jurisdiction × activity × entity type: is it a license or a certification?
Regulation stacks up by country, by activity and by the kind of company you are. The first job is to separate law (licenses, mandatory rules) from optional proof (certifications) and from industry rules that partners enforce through contracts.
What it is
The rules that apply to you come from the combination of where you operate, what you do and what kind of entity you are. Some are licenses: you can't legally do the activity without one. Some are certifications: proof you meet a standard, usually demanded by customers or partners. And some are industry codes, enforced through contracts and fines rather than courts.
Knowing which layer a requirement comes from tells you who enforces it and what happens if you miss it.
Where you'll see it
| Industry | Law | Certification or industry rule |
|---|---|---|
| Payments | Money transmitter licenses | PCI DSS, enforced by the card networks |
| Healthcare | HIPAA | HITRUST certification |
| Telco | Telecom regulators and consent laws | Carrier codes of conduct and industry messaging guidelines |
| Payroll | Tax and labor law, by country and state | SOC 2 reports that customers ask for |
Questions to ask in week one
- Which jurisdictions, activities and entity types apply to us?
- For each requirement: is it law, a certification or a partner's rule?
- Who enforces it, and what's the penalty for missing it?
- Which requirements sit with us, and which with our customers?
- What is actually enforced today, compared with what's written?
The trap
Assuming "regulation" means government. In many industries the rules that block you day to day are written by networks and industry bodies, and enforced through contracts and fines.
In the Field Guides
B2B payments: order to cash
Separate the layers, because each has its own enforcer and its own penalty.
Payments law
- US
- UCC 3, 4 and 4A, Reg CC, Reg E (consumers only), Bank Secrecy Act, state money transmission and surcharge laws
- Canada
- PCMLTFA (anti-money laundering), Retail Payment Activities Act (RPAA)
- Enforced by
- Courts, FinCEN, states; FINTRAC, Bank of Canada
Credit and collections law
- US
- Reg B (including trade credit), FCRA (guarantors), FDCPA (consumer debt only), state collection-agency licensing, usury law, UCC 2 and 9, Bankruptcy Code, PACA
- Canada
- Interest Act, Criminal Code s.347, Bankruptcy and Insolvency Act s.81.1, provincial security, collection and construction acts
- Enforced by
- Courts, CFPB, states; provinces
Registration or license
- US
- FinCEN money services business (MSB) registration; state money transmitter licenses unless a bank partnership or exemption applies
- Canada
- FINTRAC MSB registration; RPAA registration
- Enforced by
- Same
Rail and network rules
- US
- Nacha, RTP and FedNow rules; card rules; PCI DSS v4.0.1
- Canada
- Payments Canada rules; card rules
- Enforced by
- Operators via banks; networks via acquirers
Accounting
- US
- ASC 326 (CECL), ASU 2025-05, ASC 606 (revenue at transfer of control)
- Canada
- Not researched
- Enforced by
- Auditors
Contract
- US
- Sponsor bank policy, insurer policies, lender eligibility, retailer compliance manuals (the de facto scheme rules of retail)
- Canada
- Same
- Enforced by
- Contract
Customer demand
- US
- SOC 1 and SOC 2 Type 2 reports, PCI attestation
- Canada
- Same
- Enforced by
- Enterprise procurement
Three things to know cold. FinCEN exempts a payment processor from money transmitter status only if it facilitates a purchase or bill payment, through clearing systems open only to regulated institutions, under an agreement with at least the seller (FIN-2014-R009). State law is converging: 31 states had enacted the CSBS model money transmission law by April 2026, with more since. And FINTRAC has treated providers of invoice payment services as MSBs since April 27, 2022, exempting only an entity that receives payments for a payee without transferring them on (FINTRAC). An AR platform that collects and then remits to the seller is usually in scope in Canada.
Phone payments are a trap: card numbers keyed by an AR clerk from a VoIP call pull those systems into PCI scope. A payer-entered pay link keeps the seller out.
Ask an expert: what does the sponsor bank require beyond the law? I expect limits, reserves, KYB depth, tighter return thresholds and evidence of the 2026 fraud monitoring; none of it is public.
B2B payments: procure to pay
AP sits under more layers than most PMs expect, because it is a tax function, an internal-control function and a payments function at once.
Law
- US
- UCC 3 and 4 (checks); UCC 4A (wires; commercial ACH credits by agreement); IRC 6041 and 3406 (1099, backup withholding); Prompt Payment Act; SOX 404; state money transmission and unclaimed property
- Canada
- Income Tax Act (T4A); Excise Tax Act (GST/HST credits); federal construction prompt payment; PCMLTFA (anti-money laundering); RPAA (payment service providers)
- Enforced by
- Courts, IRS, states; CRA, FINTRAC, Bank of Canada
Accounting standards
- US
- ASU 2022-04 (supplier finance disclosure)
- Canada
- IAS 7 and IFRS 7 amendments
- Enforced by
- Auditors, securities regulators
Rail rules
- US
- Nacha Operating Rules
- Canada
- Payments Canada rules
- Enforced by
- Rail operators, through banks
Network rules
- US
- Interchange, straight-through programs, surcharges
- Canada
- Same, with a 2.4% surcharge cap
- Enforced by
- Networks, through issuers and acquirers
Contract
- US
- Treasury agreements (security procedures, Positive Pay, limits); rebate schedules
- Canada
- Same
- Enforced by
- Banks and issuers
Customer demand
- US
- SOC 1 Type 2 for any AP tool feeding the general ledger
- Canada
- Same
- Enforced by
- Buyers' auditors
The buyer rarely needs a license; the fintech in the middle often does. Taking a buyer's money and paying it on to suppliers is money transmission under US state law unless a bank structure or an exemption applies; one AP network's filing describes state rules requiring liquid assets of at least 100% of customer liabilities. FINTRAC has treated invoice payment services as money services businesses since April 27, 2022, exempting only an entity that receives payments for a payee without transferring them on (FINTRAC). The Bank of Canada has supervised payment service providers under the RPAA since September 8, 2025 (FAQ). My reading: an AP platform that holds buyer funds and pays Canadian suppliers is in scope for both, and the payee exemption doesn't help a payer's agent.
Ask an expert: which AP control failures do auditors cite most (vendor-master changes, segregation of duties, approval overrides, manual payments), and which license model do AP hubs use?
B2B payments: spend management
Business cards fall through most of the consumer law PMs expect.
Card law
- US
- Reg Z §1026.12: $50 cap on unauthorized use of any credit card; contracts differ at 10+ cards. No billing-error rights, CARD Act or Reg E for business accounts
- Canada
- Bank Act: $50 cap; unclear for business cardholders
- Enforced by
- CFPB, courts; FCAC
Credit law
- US
- Reg B (a limit cut can be adverse action); Section 1071 from 2028
- Canada
- No equivalent found
- Enforced by
- CFPB
Tax and employment law
- US
- IRC 62 and 274; FLSA; state reimbursement laws
- Canada
- Income Tax Act; Excise Tax Act; Canada Labour Code; Quebec labour law
- Enforced by
- IRS, DOL, states; CRA, ESDC, Quebec
Anti-money laundering, money movement
- US
- Bank Secrecy Act, through the bank; state money transmission if the platform holds funds
- Canada
- FINTRAC registration; RPAA registration
- Enforced by
- FinCEN, states; FINTRAC, Bank of Canada
License
- US
- The bank's charter; money transmitter licenses or an exemption; Visa agent registration
- Canada
- A bank or trust company issuer, or a fintech under its own Visa licence
- Enforced by
- Regulators; the network
Network rules
- US
- No zero liability on Corporate and Purchasing cards; misuse insurance; dispute windows
- Canada
- Same; misuse insurance of at least CAD 100,000 per cardholder
- Enforced by
- Networks, through issuers
Attestation
- US
- PCI DSS v4.0.1 for issuers and their agents; SOC 1 and 2
- Canada
- Same
- Enforced by
- Networks; customers
Bank policy
- US
- Credit box, KYB depth, reserves, prohibited industries
- Canada
- Same
- Enforced by
- The sponsor bank
Three things to know. Reg Z's $50 cap reaches business credit cards, but at 10 or more cards the company and issuer may agree other terms, and employees keep the cap only against use by someone else. Business debit, prepaid and just-in-time cards have no statutory cap, because Reg E covers only consumer accounts. And where a bank has primary oversight and control of a prepaid program, FinCEN says no participant must register as the provider of prepaid access.
In Canada, a platform that holds end-user funds or moves reimbursements likely needs FINTRAC registration (since April 2022) and RPAA registration (since September 8, 2025). Banks are excluded from the RPAA, and so are agents of registered payment service providers, but agents of banks aren't named. My reading: "we act for the issuing bank" is no obvious exclusion for a Canadian card program manager. That needs counsel.
Sources: 15 U.S.C. 1645, Reg Z 1026.12 and 1026.3, Reg E, Reg B, FinCEN (search result), Bank Act, RPAA, Bank of Canada, FINTRAC, Visa Rules.
Ask an expert: which bank requirement costs us the most growth, and is it a legal rule or the bank's own risk appetite?
Telco: numbers and senders
Separate six layers, because each has a different enforcer and a different penalty.
Law
- US and Canada
- TCPA (the US consent law for calls and texts); state laws (Texas treats texts as telephone solicitation since Sept 2025); CASL (Canada's anti-spam law); Kari's Law and RAY BAUM'S Act for 911
- Elsewhere
- Spain's Orden TDF/149/2025; Colombia's Ley 2300
- Enforced by
- Courts, plaintiffs, regulators
Regulator rule
- US and Canada
- FCC rules: 47 CFR Part 9 (911), Part 52 (numbering), Part 64 (consent, robocalls); CRTC decisions
- Elsewhere
- India's TCCCPR, ACMA's register, CNMC's alias registry, CRC resolutions
- Enforced by
- FCC, CRTC, national regulators
Industry guideline
- US and Canada
- CTIA principles and handbook; Canadian short code guidelines; token policy from STI-GA (the industry board that governs SHAKEN)
- Elsewhere
- MEF's SenderID registry (UK)
- Enforced by
- Audits, contracts, token revocation
Carrier policy
- US and Canada
- Codes of conduct, filtering, fines, throughput tiers
- Elsewhere
- Allowlists, per-carrier ID approval
- Enforced by
- Blocking and fines
Platform-owner policy
- US and Canada
- Meta's Business Messaging Policy; Google's RCS acceptable use policy
- Elsewhere
- Same
- Enforced by
- Rejections, pauses, bans
Your policy
- US and Canada
- Acceptable use, KYC
- Elsewhere
- Same
- Enforced by
- You
Sources: Morgan Lewis, ISED, CTIA, WhatsApp policy.
Carrier policy is routinely stricter than the law. The 11th Circuit vacated the FCC's one-to-one consent rule on January 24, 2025 and the FCC later deleted it (Goodwin), yet providers report that toll-free and campaign reviewers still reject consent gathered by lead generators for unnamed "partners". The FCC's opt-out ceiling is 10 business days; carriers expect STOP to work immediately.
Canada is the useful contrast. CASL requires consent, sender identification and a working unsubscribe, with penalties up to CAD 10M for a business, but its private right of action has been suspended since 2017. Providers report there's no 10DLC-style registry for Canada-to-Canada traffic, while Canadian numbers texting US recipients must register with TCR. Toll-free reaches both countries, and Canadian short codes must answer STOP, ARRET, HELP, AIDE and INFO in English and French (CSC guidelines).
Ask an expert: when the law allows something carrier reviewers reject (lead-generator consent is the live case), who decides what the product enforces?
Field Guides are learning notes, not legal or compliance advice. Rules and fees change; check the cited primary sources before you act on anything here.