ATLAS/BRIEFINGLaw, organized for consequential decisions.

FIN · PRACTICE DESK

Financial Regulation & Digital Assets

Payments, consumer financial protection, bank-partner credit, entity transparency reporting, and the compliance obligations that attach to how money and data actually move.

Foundational briefing

Start here

FIN-01 · 01

Regulation E Error Resolution for Digital Wallets and Payment Applications

7 MIN · FIN

Regulation E turns a consumer complaint into a regulated clock. This brief sets out when the clock starts, which investigation window applies, when provisional credit becomes mandatory, and what must be sent in writing.

  • A consumer has 60 days from the periodic statement showing the problem to assert an error; late notice generally ends the institution's resolution duty.
  • The default investigation window is 10 business days, extendable to 45 calendar days only if provisional credit is given and the consumer notified.
  • New accounts, point-of-sale debit transactions, and foreign-initiated transfers use longer windows — 20 business days and 90 calendar days.
Read the full brief →
Current dossiers

Multi-brief clusters

Brief stack

All Financial Regulation & Digital Assets briefs

Search this desk →

FIN-02 · 02

GLBA Privacy Notices and the Safeguards Rule for Financial Technology Companies

8 MIN · FIN

GLBA runs on two tracks that are often confused: what you must tell customers about data sharing, and what you must build to protect the data. This brief separates them and lists what each demands.

  • Coverage turns on activity, not on holding a bank charter. A company significantly engaged in financial activities can be a financial institution under GLBA.
  • The privacy track requires an initial notice, an opt-out where nonaffiliated sharing triggers one, and an annual notice unless a statutory exception applies.
  • The Safeguards Rule requires a written program with a named qualified individual, risk assessment, access controls, encryption, MFA, monitoring, training, and vendor oversight.
Read the full brief →

FIN-03 · 03

Beneficial Ownership Reporting: How to Verify the Rules That Apply Now

7 MIN · FIN

The federal beneficial-ownership regime has shifted through litigation and rulemaking more than once. This brief gives the position as of mid-2026 and a method for confirming what is in force today.

  • The Corporate Transparency Act created a federal reporting duty at 31 U.S.C. 5336, implemented by FinCEN regulation, with reporting first required in 2024.
  • Litigation and enforcement pauses through 2024 and early 2025 repeatedly changed what was required, and of whom, within weeks.
  • A FinCEN interim final rule issued in March 2025 exempted domestic companies and U.S. persons, leaving foreign reporting companies in scope.
Read the full brief →

FIN-04 · 04

ACH Authorization, Returns, and Account-Freezing Risk for Payment Platforms

9 MIN · FIN

A debit can be contractually agreed, network-compliant, and still returned. This brief separates the three rulebooks that govern ACH authorization, returns, and funds holds for a platform operator.

  • Nacha rules make the originating bank warrant that each entry is authorized, and require proof of authorization to be retained and produced on request.
  • Retention for consumer debit authorizations generally runs two years from the date the authorization is terminated or revoked.
  • Return-rate levels are measured against the originator: 0.5% unauthorized, 3% administrative, and 15% overall, each triggering network review.
Read the full brief →

FIN-05 · 05

State Lending Licenses and Bank-Partner Models for Online Credit Products

8 MIN · FIN

Licensing exposure in online credit is decided by structure, not by branding. This brief works through who lends, who must be licensed, and why bank-partner programs remain contested.

  • Lending licenses are state law: the analysis runs state by state on making, brokering, purchasing, and servicing credit for residents of that state.
  • Rate exportation lets a bank apply its home-state rate law, but the benefit belongs to the bank — not automatically to a partner that buys the loan.
  • OCC and FDIC valid-when-made rules issued in 2020 survived court challenge; the separate OCC true-lender rule was repealed by Congress in 2021.
Read the full brief →

FIN-06 · 06

Suspicious Activity Reports: Filing Standards and the Confidentiality Rule

8 MIN · FIN

A SAR is the one filing a customer must never learn about. This brief sets out what triggers the obligation, how the 30-day clock runs, who may lawfully be told, and what the statutory safe harbour actually protects.

  • A SAR is due within 30 calendar days of initial detection of facts that may form a basis for filing, extendable to 60 if no suspect is identified.
  • Federal law makes both the report and its very existence confidential; a bank may not tell the customer, and disclosure carries its own penalties.
  • The statute grants a safe harbour from liability to the filer and its people for reporting a possible violation, whether or not the suspicion proves correct.
Read the full brief →

FIN-07 · 07

Custodial and FBO Account Structures: Whose Money Is It

8 MIN · FIN

An FBO account holds one balance at a bank and many claims outside it. This brief separates legal ownership from operational control, and sets out the titling, records, and disclosure conditions the structure depends on.

  • An FBO account is a single deposit at a bank held by an intermediary for identified end users, whose individual claims exist only in the intermediary's ledger.
  • Pass-through insurance conditions include custodial titling, records identifying the true owners and their interests, and a genuine disclosed agency relationship.
  • The label 'FBO' on an account title creates nothing by itself; the underlying agreements and state law determine whether a trust or agency actually exists.
Read the full brief →

FIN-08 · 08

Wire Transfer Losses Under UCC Article 4A: Who Bears the Fraud

8 MIN · FIN

Article 4A does not ask who was at fault. It asks whether the bank and the customer agreed a commercially reasonable security procedure and whether the bank followed it. This brief walks that analysis and its exits.

  • Article 4A allocates unauthorised payment-order loss through the security procedure: an order verified under a commercially reasonable procedure can bind the customer.
  • A customer can shift the loss back by proving the order did not come from anyone entrusted with, or who obtained access through, the customer's own systems.
  • Consumer transfers governed in any part by the Electronic Fund Transfer Act are excluded from Article 4A, so the two regimes rarely overlap.
Read the full brief →

FIN-09 · 09

Deposit Insurance and Pass-Through Coverage for Pooled Accounts

8 MIN · FIN

Pass-through coverage turns one pooled deposit into many insured claims — but only if titling, records, and the underlying relationship all hold. This brief sets out the conditions and the failure modes.

  • Coverage runs per depositor, per insured bank, per ownership category, at a standard maximum of $250,000; pooling does not by itself increase or reduce it.
  • Pass-through requires custodial titling at the bank, records identifying each true owner and interest, and a genuine disclosed custodial relationship.
  • Deposit insurance responds only to the failure of the insured bank, not to the failure of a fintech, program manager, or ledger provider.
Read the full brief →

FIN-10 · 10

Overdraft and NSF Fee Practices: Disclosure, Opt-In, and Enforcement Risk

8 MIN · FIN

Most overdraft exposure is not about the size of the fee. It is about whether the consumer could have predicted it. This brief maps the opt-in rule, the disclosure regime, and the fee patterns that draw enforcement.

  • Regulation E bars fees for ATM and one-time debit card overdrafts unless the consumer receives a segregated notice and affirmatively opts in.
  • Checks and recurring debits fall outside the opt-in rule, so a consumer who declined the service can still be charged on those items.
  • Authorize-positive-settle-negative fees and repeat fees on re-presented items are the two patterns that most often draw unfairness findings.
Read the full brief →

FIN-11 · 11

Truth in Lending for Closed-End Credit: Disclosure Timing and Accuracy

8 MIN · FIN

Regulation Z fixes four numbers a closed-end borrower must see, and for most mortgages it fixes when they must see them. This brief sets out the content, the timing, the tolerances, and where errors become liability.

  • Closed-end disclosures must state the annual percentage rate, the finance charge, the amount financed, and the total of payments, grouped and conspicuous.
  • For most closed-end mortgages, a Loan Estimate is due within three business days of application and a Closing Disclosure three business days before consummation.
  • A changed APR beyond tolerance, a changed loan product, or an added prepayment penalty restarts the three-business-day waiting period before closing.
Read the full brief →
Scope

Questions this desk answers

  • Who owes the consumer an error investigation?
  • Does this product need a state license?
  • What must we disclose, and when?
  • Which reporting rule is actually in force?