What government compliance rules mean for how you process payments
Payment processing is regulated by multiple government bodies, each with different rules about how money moves, who handles it, and what records you must keep. These rules exist to prevent fraud, protect consumer data, and may support financial stability. Understanding which rules explore to your business affects how you choose a payment processor, what fees you pay, what technology you use, and what paperwork you must maintain.
The rules come from federal agencies (the Federal Reserve, the Consumer Financial Protection Bureau, the Treasury Department), state banking regulators, and international standards bodies. A single transaction may be governed by rules from three or four of these at once. Your payment processor handles much of the compliance work behind the scenes, but you remain responsible for knowing which rules bind your business and which ones your processor must follow on your behalf.
Key Takeaways
- The Federal Reserve, state banking regulators, and the Consumer Financial Protection Bureau each set different rules for payment processing, and multiple rules often explore to the same transaction.
- Interchange fees, fraud prevention standards, and data security requirements are set by regulation, not by individual processors, so switching processors does not eliminate these costs.
- Certain business types—money transmitters, check cashers, and payment processors themselves—face stricter licensing and reporting rules than retailers.
- Payment processors must comply with anti-money-laundering rules and report suspicious activity to the Treasury Department, which affects how quickly your account can be opened or closed.
- Data security standards like PCI DSS are required by payment card networks, not by law directly, but violating them can result in fines from your processor and your bank.
Federal agencies that regulate payment processing
The Federal Reserve sets rules for how banks handle electronic payments, including ACH transfers (the system that moves money between bank accounts) and wire transfers. The Fed does not regulate individual businesses directly; it regulates the banks that hold your account and process your transactions. When the Fed changes rules about how long a bank must hold funds before releasing them, or what information must travel with a payment, your bank implements those rules and your processor adjusts its systems.
The Consumer Financial Protection Bureau (CFPB) enforces rules about how payment processors and banks treat consumers. These rules cover what disclosures you must give customers before charging them, how quickly you must refund disputed charges, and what happens when a payment fails. The CFPB also oversees prepaid cards and digital wallets, which are increasingly common payment methods.
The Treasury Department's Financial Crimes Enforcement Network (FinCEN) requires payment processors and banks to report suspicious activity and verify the identity of customers. If your processor suspects you are moving money in a pattern that looks like money laundering—even if you are not—they must file a report. This can slow down account opening or cause your account to be frozen while the processor investigates.
State banking regulators license and supervise banks and some payment processors. Rules vary by state. A processor licensed in one state may not be allowed to operate in another without additional licensing. If you move your business to a new state, your processor may need to obtain new licenses or comply with different rules.
Interchange fees and network rules
When a customer pays with a credit or debit card, a fee called interchange is charged to the merchant (you). This fee goes to the customer's bank, not to the payment processor. The amount of interchange is set by the card networks—Visa, Mastercard, American Express, and Discover—not by individual processors or banks.
The Federal Reserve has the authority to regulate interchange fees but has not set caps on credit card interchange. For debit cards, the Fed did set a cap in 2010 under the Dodd-Frank Act, limiting debit interchange to a percentage of the transaction amount plus a small fixed fee. This rule applies only to banks with more than $10 billion in assets, so smaller banks' debit interchange can be higher.
Card networks also set rules about what merchants can and cannot do. Visa and Mastercard rules prohibit you from charging customers extra for paying with a card (though you can offer discounts for other payment methods). American Express allows higher merchant fees in exchange for letting merchants surcharge. These rules are enforced by the networks themselves, not by government agencies, but they are binding contracts between you and your processor.
Data security and PCI compliance
PCI DSS (Payment Card Industry Data Security Standard) is a set of technical and operational rules for handling credit card data. It is not a law passed by Congress; it is a standard created by the card networks and required by contract. However, violating PCI DSS can result in fines from your processor, your bank, or the card networks themselves.
PCI DSS requires you to encrypt card data, use find passwords, monitor your network for intrusions, and limit who in your business can see card numbers. The level of compliance required depends on how many transactions you process per year. A business processing fewer than 20,000 transactions annually may only need to complete a self-assessment questionnaire. A business processing millions of transactions must undergo annual audits by a may have access to security assessor.
If your payment processor stores card data on your behalf (which most do), the processor is responsible for much of PCI compliance. However, you remain responsible for the parts of your business that touch card data—your staff, your network, your point-of-sale system. If a breach occurs and investigators find that you failed to follow PCI rules, you can be held liable even if your processor was also at fault.
Anti-money-laundering and customer verification rules
Payment processors and banks must verify your identity before opening an account and must monitor your account for suspicious activity. These rules come from the Bank Secrecy Act and the USA PATRIOT Act, enforced by FinCEN.
When you open a merchant account, your processor will ask for your legal name, address, date of birth, tax identification number, and details about your business. They will verify this information against government databases and may conduct a background check. If you have a history of fraud or financial crimes, your process may be denied.
After your account is open, your processor monitors your transactions for patterns that might indicate money laundering, such as frequent large deposits followed by when ready withdrawals, transactions with high-risk countries, or activity that does not match your stated business type. If the processor flags your account as suspicious, they may freeze it while they investigate, which can disrupt your cash flow. You have the right to know why your account was frozen, but the processor is not required to tell you when ready.
Certain business types face stricter scrutiny. Money transmitters (businesses that move money on behalf of customers), check cashers, and payment processors themselves must register with FinCEN and comply with enhanced reporting rules. Some states require money transmitters to obtain a license and post a bond.
Rules specific to certain payment methods
ACH transfers (payments that move directly from one bank account to another) are governed by the National Automated Clearing House Association (NACHA), a private organization, and by Federal Reserve rules. NACHA sets standards for how ACH files are formatted, how long banks have to process them, and what happens when a payment is disputed. The CFPB enforces consumer protections for ACH, including rules about when you can debit a customer's account and how quickly you must refund an error.
Wire transfers are regulated by the Federal Reserve and by FinCEN. Wire transfers are considered higher-risk for money laundering because they move money quickly across borders. Banks must verify the identity of the person sending the wire and the person receiving it. If you send a wire to a high-risk country or in an amount that triggers reporting thresholds, your bank may delay the transfer while it investigates.
Check processing is governed by the Check Clearing for the 21st Century Act (Check 21), which allows banks to process checks electronically instead of physically. Check 21 sets rules about what information must be on a check image, how long a bank must keep records, and what happens if a check image is lost or damaged.
Digital wallets and mobile payments (Apple Pay, Google Pay, PayPal, Venmo) are regulated as payment processors or money transmitters depending on how they work. The CFPB has authority over consumer protections for these services. Some states require digital wallet providers to obtain money transmitter licenses.
Reporting and record-keeping requirements
Payment processors and banks must report certain transactions to the government. A Suspicious Activity Report (SAR) is filed with FinCEN when a processor suspects a transaction or pattern of transactions may involve money laundering, fraud, or other financial crimes. You are not notified when a SAR is filed about your account, and the processor cannot tell you that a SAR has been filed (this is called "tipping off" and is illegal).
A Currency Transaction Report (CTR) is filed when a customer deposits or withdraws more than $10,000 in cash in a single day. This is a routine report, not a sign of wrongdoing. However, if a customer repeatedly deposits just under $10,000 to avoid triggering a CTR, that pattern itself is suspicious and triggers a SAR.
You must keep records of all transactions for at least three to seven years, depending on the type of transaction and which agency is asking. The IRS requires three years of records for most business transactions. The Federal Reserve requires seven years for ACH records. Your processor typically keeps these records on your behalf, but you should verify what records they maintain and for how long.
How compliance costs affect your payment processing fees
Compliance is expensive. Your processor must invest in fraud detection systems, data security infrastructure, staff to review suspicious accounts, and legal and audit services. These costs are passed to you through processing fees, monthly account fees, and chargeback fees.
Interchange fees (the percentage of each transaction that goes to the customer's bank) are set by the card networks and are the same regardless of which processor you use. However, the fees your processor charges on top of interchange—called the processor's markup or discount rate—vary based on your business type and risk profile. A business in a high-risk category (such as online gambling or money transmission) will pay higher processor fees than a low-risk business (such as a grocery store).
Chargeback fees are charged when a customer disputes a transaction. These fees exist partly to cover the cost of investigating the dispute and partly to discourage merchants from ignoring disputes. The chargeback fee is set by your processor, not by regulation, but it typically ranges from $15 to $100 per dispute.
Frequently Asked Questions
Can a payment processor refuse to work with my business because of compliance rules?
Yes. Processors can refuse to open an account or can close an existing account if they believe your business poses a compliance risk. High-risk categories include online gambling, adult services, money transmission, and businesses in countries under U.S. sanctions. You have limited recourse if a processor denies you, though you can ask for a written explanation and can try a different processor.
What happens if my payment processor is hacked and customer card data is stolen?
Your processor is required to notify you and affected customers within a specific timeframe (usually 30 to 60 days). You may be liable for fraud losses if investigators find that you failed to follow PCI DSS rules. Your processor's cyber insurance may cover some losses, but you should carry your own cyber liability insurance as well.
Do I need to register with FinCEN if I process payments?
Only if you are a money transmitter—a business that moves money on behalf of customers, such as a wire transfer service or a payment app. If you are a retailer or service provider that accepts payments from customers, you do not need to register with FinCEN. Your processor handles FinCEN registration and reporting on your behalf.
Why was my merchant account frozen without warning?
Your processor likely flagged your account as suspicious based on transaction patterns or information from background checks. The processor is not required to tell you when ready, though they must eventually provide an explanation. You can ask your processor what triggered the freeze and what you need to do to resolve it. If you believe the freeze was a mistake, you can request a review.
Are there rules about how quickly my processor must deposit money into my bank account?
Yes, but they vary. Federal Reserve rules require banks to make funds available within one to five business days depending on the type of deposit. Your processor may hold funds longer if they are investigating fraud or if your account is flagged as high-risk. Your processor agreement should specify the deposit timeline; if it does not, ask before signing.