Compliance
Fintech compliance checklist for Texas startups
Partner banks, licensing examiners and enterprise customers ask the same questions. This checklist collects them so you can answer before they ask.
Company foundations
- Entity formed and in good standing with the Texas Secretary of State, with franchise tax reports filed (see Texas sales and franchise tax)
- Sales tax permit, if you sell taxable services such as data processing
- A named compliance officer with authority and a direct line to leadership
- Board or leadership approval of written compliance policies, reviewed at least yearly
- A map of every license, registration and exemption the business relies on, including money transmission exemptions
- FinCEN registration, if the business is a money services business (how it works)
Anti-money laundering and sanctions
How to build these controls, and in what order, is covered in building a BSA/AML program.
- A Bank Secrecy Act/AML program with internal controls, a compliance officer, training and independent testing
- Customer identification and due diligence, including beneficial ownership for business customers (KYC and KYB requirements)
- Transaction monitoring, with a documented process for investigating alerts
- Suspicious activity and currency transaction reporting where your business is required to file
- OFAC sanctions screening of customers and counterparties, at onboarding and on an ongoing basis
- Record retention that meets the Bank Secrecy Act's requirements
Privacy and data security
- Gramm-Leach-Bliley Act: privacy notices, opt-out rights where required, and a written information security program under the FTC Safeguards Rule if you are a non-bank financial institution
- Texas Data Privacy and Security Act (in effect since July 1, 2024): check whether it applies. Financial institutions and data subject to GLBA Title V are excluded, but a fintech that is not a GLBA financial institution may be covered. See the Texas privacy guide.
- Texas breach notification: notify affected individuals without unreasonable delay and no later than 60 days after determining a breach occurred, and notify the Texas Attorney General no later than 30 days after that determination if at least 250 Texas residents are involved (Texas Business and Commerce Code §521.053).
- Encryption in transit and at rest, access control, logging and a tested incident response plan
- Vendor risk management for every provider that touches customer data
Payments
- PCI DSS v4.0.1 compliance if you store, process or transmit card data. Hosted payment fields and tokenization through a processor can shrink your scope considerably (PCI DSS for startups).
- Nacha Operating Rules for ACH, including authorizations, return-rate thresholds and data security requirements
- Regulation E error-resolution procedures for consumer electronic transfers
- Operating rules for any instant payment network you use, flowed down by your bank (ACH vs RTP vs FedNow)
- Clear customer disclosures on fees, timing and where funds are held, including whether they are insured and on what basis
Consumer protection
- Marketing review for UDAAP risk: claims, fees and "free" offers
- A complaint-handling process that logs, resolves and analyzes complaints
- Accessibility and plain-language disclosures
- Fair lending testing if you make credit decisions, including model-based ones
Bank-partner readiness
What a bank will ask for, and what to check about the bank, is in sponsor bank due diligence.
- A due-diligence package: policies, audits, financials, org chart, the flow of funds and a risk assessment
- Clear allocation of responsibilities in the program agreement
- Reporting the bank will require, such as complaints, AML metrics and incidents
- An exit and wind-down plan that protects customer funds
- A daily reconciliation between your ledger and the bank's records
Digital assets
- Classification of each asset against the stablecoin definition in Texas Finance Code §152.003
- A check against Chapter 160 if you hold customers' digital assets (Texas crypto and stablecoin rules)
Using the checklist
- Mark each line as applies, does not apply (with the reason), or unknown.
- Assign an owner to every line that applies, and a date to every unknown.
- Attach the evidence: the policy, the filing, the report or the test result.
- Review it before launching a product, adding a state, or signing a new bank or processor, and at least once a year.
Common questions
What compliance does a fintech startup need before launch?
It depends on the product. Most need a map of licenses and exemptions, a BSA/AML and sanctions program if they move money, privacy and security controls, and whatever their partner bank and processor require by contract. Use the sections above to decide which apply.
Who should own compliance at an early-stage fintech?
A named compliance officer with authority and access to leadership. Outside advisers and vendors can do much of the work, but regulators and banks expect a person inside the company to be accountable.
How often should the program be reviewed?
At least yearly, and whenever the product, the partners or the states you serve change. Some rules set their own cycles, such as yearly PCI validation and periodic independent AML testing.
For how licensing fits in, see money transmission and lending licenses.
Last reviewed 2026-09-17