The Platform PM
Primitive 08

Regulatory layering

Jurisdiction × activity × entity type: is it a license or a certification?

Regulation stacks up by country, by activity and by the kind of company you are. The first job is to separate law (licenses, mandatory rules) from optional proof (certifications) and from industry rules that partners enforce through contracts.

What it is

The rules that apply to you come from the combination of where you operate, what you do and what kind of entity you are. Some are licenses: you can't legally do the activity without one. Some are certifications: proof you meet a standard, usually demanded by customers or partners. And some are industry codes, enforced through contracts and fines rather than courts.

Knowing which layer a requirement comes from tells you who enforces it and what happens if you miss it.

Where you'll see it

IndustryLawCertification or industry rule
PaymentsMoney transmitter licensesPCI DSS, enforced by the card networks
HealthcareHIPAAHITRUST certification
TelcoTelecom regulators and consent lawsCarrier codes of conduct and industry messaging guidelines
PayrollTax and labor law, by country and stateSOC 2 reports that customers ask for

Questions to ask in week one

  1. Which jurisdictions, activities and entity types apply to us?
  2. For each requirement: is it law, a certification or a partner's rule?
  3. Who enforces it, and what's the penalty for missing it?
  4. Which requirements sit with us, and which with our customers?
  5. What is actually enforced today, compared with what's written?

The trap

Assuming "regulation" means government. In many industries the rules that block you day to day are written by networks and industry bodies, and enforced through contracts and fines.

In the Field Guides

B2B payments: order to cash

Separate the layers, because each has its own enforcer and its own penalty.

Payments law

US
UCC 3, 4 and 4A, Reg CC, Reg E (consumers only), Bank Secrecy Act, state money transmission and surcharge laws
Canada
PCMLTFA (anti-money laundering), Retail Payment Activities Act (RPAA)
Enforced by
Courts, FinCEN, states; FINTRAC, Bank of Canada

Credit and collections law

US
Reg B (including trade credit), FCRA (guarantors), FDCPA (consumer debt only), state collection-agency licensing, usury law, UCC 2 and 9, Bankruptcy Code, PACA
Canada
Interest Act, Criminal Code s.347, Bankruptcy and Insolvency Act s.81.1, provincial security, collection and construction acts
Enforced by
Courts, CFPB, states; provinces

Registration or license

US
FinCEN money services business (MSB) registration; state money transmitter licenses unless a bank partnership or exemption applies
Canada
FINTRAC MSB registration; RPAA registration
Enforced by
Same

Rail and network rules

US
Nacha, RTP and FedNow rules; card rules; PCI DSS v4.0.1
Canada
Payments Canada rules; card rules
Enforced by
Operators via banks; networks via acquirers

Accounting

US
ASC 326 (CECL), ASU 2025-05, ASC 606 (revenue at transfer of control)
Canada
Not researched
Enforced by
Auditors

Contract

US
Sponsor bank policy, insurer policies, lender eligibility, retailer compliance manuals (the de facto scheme rules of retail)
Canada
Same
Enforced by
Contract

Customer demand

US
SOC 1 and SOC 2 Type 2 reports, PCI attestation
Canada
Same
Enforced by
Enterprise procurement

Three things to know cold. FinCEN exempts a payment processor from money transmitter status only if it facilitates a purchase or bill payment, through clearing systems open only to regulated institutions, under an agreement with at least the seller (FIN-2014-R009). State law is converging: 31 states had enacted the CSBS model money transmission law by April 2026, with more since. And FINTRAC has treated providers of invoice payment services as MSBs since April 27, 2022, exempting only an entity that receives payments for a payee without transferring them on (FINTRAC). An AR platform that collects and then remits to the seller is usually in scope in Canada.

Phone payments are a trap: card numbers keyed by an AR clerk from a VoIP call pull those systems into PCI scope. A payer-entered pay link keeps the seller out.

Ask an expert: what does the sponsor bank require beyond the law? I expect limits, reserves, KYB depth, tighter return thresholds and evidence of the 2026 fraud monitoring; none of it is public.

B2B payments: procure to pay

AP sits under more layers than most PMs expect, because it is a tax function, an internal-control function and a payments function at once.

Law

US
UCC 3 and 4 (checks); UCC 4A (wires; commercial ACH credits by agreement); IRC 6041 and 3406 (1099, backup withholding); Prompt Payment Act; SOX 404; state money transmission and unclaimed property
Canada
Income Tax Act (T4A); Excise Tax Act (GST/HST credits); federal construction prompt payment; PCMLTFA (anti-money laundering); RPAA (payment service providers)
Enforced by
Courts, IRS, states; CRA, FINTRAC, Bank of Canada

Accounting standards

US
ASU 2022-04 (supplier finance disclosure)
Canada
IAS 7 and IFRS 7 amendments
Enforced by
Auditors, securities regulators

Rail rules

US
Nacha Operating Rules
Canada
Payments Canada rules
Enforced by
Rail operators, through banks

Network rules

US
Interchange, straight-through programs, surcharges
Canada
Same, with a 2.4% surcharge cap
Enforced by
Networks, through issuers and acquirers

Contract

US
Treasury agreements (security procedures, Positive Pay, limits); rebate schedules
Canada
Same
Enforced by
Banks and issuers

Customer demand

US
SOC 1 Type 2 for any AP tool feeding the general ledger
Canada
Same
Enforced by
Buyers' auditors

The buyer rarely needs a license; the fintech in the middle often does. Taking a buyer's money and paying it on to suppliers is money transmission under US state law unless a bank structure or an exemption applies; one AP network's filing describes state rules requiring liquid assets of at least 100% of customer liabilities. FINTRAC has treated invoice payment services as money services businesses since April 27, 2022, exempting only an entity that receives payments for a payee without transferring them on (FINTRAC). The Bank of Canada has supervised payment service providers under the RPAA since September 8, 2025 (FAQ). My reading: an AP platform that holds buyer funds and pays Canadian suppliers is in scope for both, and the payee exemption doesn't help a payer's agent.

Ask an expert: which AP control failures do auditors cite most (vendor-master changes, segregation of duties, approval overrides, manual payments), and which license model do AP hubs use?

B2B payments: spend management

Business cards fall through most of the consumer law PMs expect.

Card law

US
Reg Z §1026.12: $50 cap on unauthorized use of any credit card; contracts differ at 10+ cards. No billing-error rights, CARD Act or Reg E for business accounts
Canada
Bank Act: $50 cap; unclear for business cardholders
Enforced by
CFPB, courts; FCAC

Credit law

US
Reg B (a limit cut can be adverse action); Section 1071 from 2028
Canada
No equivalent found
Enforced by
CFPB

Tax and employment law

US
IRC 62 and 274; FLSA; state reimbursement laws
Canada
Income Tax Act; Excise Tax Act; Canada Labour Code; Quebec labour law
Enforced by
IRS, DOL, states; CRA, ESDC, Quebec

Anti-money laundering, money movement

US
Bank Secrecy Act, through the bank; state money transmission if the platform holds funds
Canada
FINTRAC registration; RPAA registration
Enforced by
FinCEN, states; FINTRAC, Bank of Canada

License

US
The bank's charter; money transmitter licenses or an exemption; Visa agent registration
Canada
A bank or trust company issuer, or a fintech under its own Visa licence
Enforced by
Regulators; the network

Network rules

US
No zero liability on Corporate and Purchasing cards; misuse insurance; dispute windows
Canada
Same; misuse insurance of at least CAD 100,000 per cardholder
Enforced by
Networks, through issuers

Attestation

US
PCI DSS v4.0.1 for issuers and their agents; SOC 1 and 2
Canada
Same
Enforced by
Networks; customers

Bank policy

US
Credit box, KYB depth, reserves, prohibited industries
Canada
Same
Enforced by
The sponsor bank

Three things to know. Reg Z's $50 cap reaches business credit cards, but at 10 or more cards the company and issuer may agree other terms, and employees keep the cap only against use by someone else. Business debit, prepaid and just-in-time cards have no statutory cap, because Reg E covers only consumer accounts. And where a bank has primary oversight and control of a prepaid program, FinCEN says no participant must register as the provider of prepaid access.

In Canada, a platform that holds end-user funds or moves reimbursements likely needs FINTRAC registration (since April 2022) and RPAA registration (since September 8, 2025). Banks are excluded from the RPAA, and so are agents of registered payment service providers, but agents of banks aren't named. My reading: "we act for the issuing bank" is no obvious exclusion for a Canadian card program manager. That needs counsel.

Sources: 15 U.S.C. 1645, Reg Z 1026.12 and 1026.3, Reg E, Reg B, FinCEN (search result), Bank Act, RPAA, Bank of Canada, FINTRAC, Visa Rules.

Ask an expert: which bank requirement costs us the most growth, and is it a legal rule or the bank's own risk appetite?

Telco: numbers and senders

Separate six layers, because each has a different enforcer and a different penalty.

Law

US and Canada
TCPA (the US consent law for calls and texts); state laws (Texas treats texts as telephone solicitation since Sept 2025); CASL (Canada's anti-spam law); Kari's Law and RAY BAUM'S Act for 911
Elsewhere
Spain's Orden TDF/149/2025; Colombia's Ley 2300
Enforced by
Courts, plaintiffs, regulators

Regulator rule

US and Canada
FCC rules: 47 CFR Part 9 (911), Part 52 (numbering), Part 64 (consent, robocalls); CRTC decisions
Elsewhere
India's TCCCPR, ACMA's register, CNMC's alias registry, CRC resolutions
Enforced by
FCC, CRTC, national regulators

Industry guideline

US and Canada
CTIA principles and handbook; Canadian short code guidelines; token policy from STI-GA (the industry board that governs SHAKEN)
Elsewhere
MEF's SenderID registry (UK)
Enforced by
Audits, contracts, token revocation

Carrier policy

US and Canada
Codes of conduct, filtering, fines, throughput tiers
Elsewhere
Allowlists, per-carrier ID approval
Enforced by
Blocking and fines

Platform-owner policy

US and Canada
Meta's Business Messaging Policy; Google's RCS acceptable use policy
Elsewhere
Same
Enforced by
Rejections, pauses, bans

Your policy

US and Canada
Acceptable use, KYC
Elsewhere
Same
Enforced by
You

Sources: Morgan Lewis, ISED, CTIA, WhatsApp policy.

Carrier policy is routinely stricter than the law. The 11th Circuit vacated the FCC's one-to-one consent rule on January 24, 2025 and the FCC later deleted it (Goodwin), yet providers report that toll-free and campaign reviewers still reject consent gathered by lead generators for unnamed "partners". The FCC's opt-out ceiling is 10 business days; carriers expect STOP to work immediately.

Canada is the useful contrast. CASL requires consent, sender identification and a working unsubscribe, with penalties up to CAD 10M for a business, but its private right of action has been suspended since 2017. Providers report there's no 10DLC-style registry for Canada-to-Canada traffic, while Canadian numbers texting US recipients must register with TCR. Toll-free reaches both countries, and Canadian short codes must answer STOP, ARRET, HELP, AIDE and INFO in English and French (CSC guidelines).

Ask an expert: when the law allows something carrier reviewers reject (lead-generator consent is the live case), who decides what the product enforces?

Field Guides are learning notes, not legal or compliance advice. Rules and fees change; check the cited primary sources before you act on anything here.