Research only

Fintech and payment processors

Explore the policy documents and regulatory sources relevant to this industry. Assessment checks for this profile are in development.

Research listings are separate from implemented scans. No quote or assessment is available for this profile yet. Public uploads must contain no patient data or other restricted information.

Documents to review

  • Kyc procedureResearch document type
  • Transaction monitoring procedureResearch document type
  • Incident response planResearch document type
  • Payment security policyResearch document type

Scope questions

Industry alone does not establish legal applicability. Confirm location, activities, role, data and relevant thresholds.

  • Where does the organization operate, and which regulator, license, permit or contract governs the activity?
  • Which business activities, data types and organization roles does the document describe?
  • Do the relevant thresholds or exceptions change which requirements apply?

Unknown answers stay unresolved. Document detection does not answer these questions for you.

A fictional example to explore

This short policy outline demonstrates the document's structure and research questions. It is a navigation example; scans for this profile are not available yet.

PDF pages are counted exactly. DOCX and TXT use the disclosed word-count estimate, so the same policy can have different billable page counts.

Regulations and frameworks to explore

These are research candidates for this profile. Confirm the exact organization and activity before concluding that a rule applies.

Research only

FTC Safeguards Rule

16 CFR Part 314

Certain financial institutions under FTC jurisdiction must safeguard customer information; activities and regulator routing determine coverage. Banks supervised under other GLBA regulators must be routed to their own rules. An MSP is not automatically a covered financial institution: assess customer-contract duties and any external Qualified Individual role separately from direct institutional duties.

Jurisdictions: US-FEDERAL

Research applicability questions
  • Does the organization engage in a financial activity covered by the applicable GLBA rule?
  • Is the organization subject to FTC jurisdiction for the activity being assessed?
  • Does the organization maintain customer information covered by the rule?
  • How many consumers’ customer information records do you maintain, and do any section 314.6 exemptions apply?
Research only

Bank Secrecy Act and AML program requirements

31 CFR Chapter X

For institutions subject to the appropriate Bank Secrecy Act rules. Banks must review 31 CFR Parts 1010 and 1020; other financial businesses have different institution-specific parts. The FFIEC examination manual is guidance, and a written policy alone does not demonstrate implementation of a risk-based AML program.

Jurisdictions: US-FEDERAL

Research applicability questions
  • Are you a bank, MSB, casino or another defined financial institution, and which Chapter X part applies?
  • What products, customers, jurisdictions and delivery channels determine your money-laundering risk?
Content rights required

PCI DSS v4.0.1

PCI DSS v4.0.1

PCI DSS v4.0.1 is a payment-account security standard. Check whether the organization stores, processes or transmits account data, or can affect the cardholder-data environment, and confirm its merchant/service-provider role. Customer and payment-brand arrangements determine validation obligations. Content permission and qualified review remain required; AuditReady readiness is not PCI validation.

Jurisdictions: GLOBAL

Research applicability questions
  • Do you store, process or transmit payment-account data, or provide services that can affect a cardholder-data environment?
  • What payment-brand/acquirer validation requirements apply to your merchant volume and channels?
  • Do you store, process or transmit cardholder data, or provide services that can affect payment-data security?
  • Which systems and services are within or can affect the cardholder-data environment?
Research only

Regulation S-P and financial privacy

17 CFR Part 248 · 16 CFR Part 313 · 12 CFR Part 1016

The SEC Regulation S-P regime applies to defined SEC-covered institutions; FTC Part 313 and CFPB Regulation P are separate privacy regimes. The 2024 S-P safeguards and incident-response amendments had phased compliance dates in December 2025 and June 2026. Confirm institution category, covered customer information and the correct regulator before selecting requirements.

Jurisdictions: US-FEDERAL

Research applicability questions
  • Is this an SEC-covered broker-dealer, investment company, registered adviser or covered transfer agent?
  • Which SEC, FTC or CFPB privacy regime governs the institution and consumer relationship?
  • Which 2024 S-P amendment provisions apply to your institution’s category and size?
Research only

NYDFS Cybersecurity Regulation

23 NYCRR Part 500

Scope follows a New York DFS license, registration, charter or similar authorization under the Banking, Insurance or Financial Services Laws, with full/limited exemptions to review. An ICT supplier is not automatically a Covered Entity; customer contracts can require third-party controls. Review the current amended regulation and applicable phase-in dates. DFS also published risk-assessment guidance on September 10, 2026.

Jurisdictions: US-NY

Research applicability questions
  • Which New York DFS licenses, registrations or authorizations does the organization hold?
  • Does the licensed organization fall within the covered-entity definition for Part 500?
  • Which specific exemption conditions can the organization substantiate, and which duties remain?
  • Does the organization meet the Part 500 Class A definition or another applicable entity classification?