Online Payment Systems -Are You a Payment Processor or a Money Transmitter?
The term “Online Payment System” encompasses all of the procedures for transferring money online between two parties in ecommerce. Online Payment Systems provide businesses and customers a secure method for conducting payments related to ecommerce. The two primary components of an online payment system are the payment processor and the money transmitter.
The term “Payment Processor” is something of a misnomer, since a typical Payment Processor delivers data and other information to the parties that need to approve a particular payment but does not get involved in the actual remittance of funds between two businesses. A “Money Transmitter”, as such term is defined in 31 C.F.R. 1010.100 (ff)(5), is an entity that remits money from one entity to another.
Diagram and Overview of Simplified Online Payment System

In Phase 1, once an ecommerce trasaction is initiated by a customer with the E-Store, a notice of the transction is automatically transmitted to the E-Store’s Bank, the Card Issuing Bank, and the Payment Processor. The Card Issuing Bank and the E-Store’s Bank send additional information directly to the Payment Processor. The Payment Processor is typically responsible to verify the transaction and perform other anti-fraud procedures.
In Phase 2, the Payment Processor, after reviewing the information it received and performing appropriate due diligence on the parties and the transaction, sends verification of the information to the Card Issuing Bank, the E-Store’s Bank and the E-Store. In Phase 3, if the Card Issuer has approved the transaction, it sends a payment to the E-Store’s Bank, for credit to the account of the E-Store.
Comparison of Regulations Applicable to Money Transmitters and Payment Processors
From the regulatory perspective, Money Transmitters are subject to federal and state regulation, while a Payment Processor is subject to the Payment Card Industry Data Security Standard and any applicable individual payment card network rules (“Payment Card Network Rules”) but is not subject to direct federal or state regulation.
Regulation | Money Transmitters | Payment Processors |
FinCen Registration (31 CFR § 1033.390), Compliance (31 CFR §1022.210), and Reporting Requirements (31 CFR § 1022.300 – 380). | Yes | No |
State Licensing | Yes | No |
Payment Card Industry Data Security Standard (PCI DSS). | Yes | Yes |
Payment Card Network Rules | Yes | Yes |
Brief Overview of the Applicable Regulations
Financial Crimes Enforcement Network Regulations.
Money Transmitters are required to register with the Financial Crimes Enforcement Network (“FinCEN”). Certain entities are exempt, including (i) banks (whether domestic or foreign); (ii) entities that are registered with the Securities and Exchange (“SEC”) or the Commodity Futures Trading Commission (“CFTC”); (iii) providers of delivery, communication or network access to registered or exempt Money Transmitters (such as provider of a secure communication conduit between registered or exempt Money Transmitters); (iv) providers of payment processing services to facilitate the purchase or sale of goods and services through a clearance and settlement system (such as the Payment Processor described above); (v) entities that operate a clearance and settlement system or otherwise act as an intermediary solely between entities that are subject to regulation pursuant to the Bank Secrecy Act (such as clearance, settlement and payment between two banks that are subject to regulation under the Bank Secrecy Act); (vi) transporters of physical currency or other financial instruments (such are armored car companies); and (vii) providers of prepaid access (such as issuers of gift cards). Entities that accept and transmit funds only integral to the sale of goods or the provision of services (such as payments made by and between a seller and a purchaser in the ordinary course of business), other than the business of money transmission, are also exempt.
Entities that fall under the definition of a Money Transmitter are required to register with FinCEN. FinCEN registration requires the Money Transmitter to (i) to develop a written Anti-Money Laundering compliance program, including the appointment of a senior officer to oversee and enforce the policy and (ii) report certain currency transactions and suspicious activities to the Treasury Department. The applicable regulations are substantially equivalent to the regulations imposed on financial institutions pursuant to anti-money laundering and bank secrecy act regulations). Failure to register or otherwise comply with the regulations may give rise to civil and criminal sanctions and fines.
State Level Regulations
Forty-nine states, all but Montana, require Money Transmitters that are licensed as such by FinCEN to obtain state licensing. The licensing requirements will vary depending on the scope of the transmission operations, and will require, at a minimum, the posting of a surety bond and the maintenance of a minimum capital requirement.
The Conference of State Banking Regulators has proposed the Money Transmission Modernization Act as a single set of nationwide standards and requirements to modernize the supervision and regulation of Money Transmitters. Nineteen states have adopted the law in full or in part and 16 have already introduced legislation in 2024.
Payment Card Industry Data Security Standards (PCI DSS).
The PCI DSS requirements focus on the protection of cardholder data, and require, but are not limited to (i) installation and maintenance of a firewall configuration to protect cardholder data; (ii) utilization of system passwords and security parameters that are unique (and not based on a third party); (iii) protection of stored cardholder data; (iv) encryption of cardholder data that is transmitted over public networks; (v) usage and timely updating of all anti-virus software or programs; (vi) development and maintenance of secure systems and applications: (vii) restriction of access to cardholder data based on “need to know” criteria; (viii) assignment of a unique ID to each person with system access; (ix) restriction of physical access to cardholder data; (x) tracking and monitoring of all access to network resources and cardholder data; (xi) regular testing of security systems and processes; and (xii) maintenance of a policy that addresses information security for all personnel.
Payment Card Network Rules
Payment Card Network Rules focus primarily on operational matters such as (i) transaction processing rules, (ii) security rules and procedures, (iii) setting transaction limits, (iv) chargeback rules; and (v) various guidelines with respect to billing procedures.
Conclusions
Due to the scope of the federal and state regulations applicable to Money Transmitters, it is best practice to have the Payment Processor operate through an entity that is separate from the Money Transmitter. Once the two components of the Online Payment System are housed in separate corporate entities, it is advisable to examine the exemptions available pursuant to 31 C.F.R. §1010)(ff)(5)(ii). If an exemption applies, the Money Transmitter will not be required to register with FinCEN, but certain State regulations will continue to apply.
One evolving solution is entering into a partnership with a bank, and having the bank undertake all actions otherwise taken by a Money Transmitter. The technology used is what is known as “banking as a service” or “BaaS”. In this approach, the Online Payment System enters into an agreement with a bank which will permit the process to be “white-labeled”, meaning the Online Payment System is the outward facing application seen by users, with the bank undertaking all money transmissions on the part of the Online Payment System.

