← Member Trust Union

§13.10

Jurisdictional Compliance

§13.7 Section C (“Legal and Regulatory Anchoring”) describes the Member Trust Union (MTU) — the network’s credit-union-like financial institution — as operating through a three-layer federated legal wrapper: a Local MTU structured as a “Co-op, Mutual Society, or CDFI-equivalent,” a Regional Network as a “Multi-Stakeholder Cooperative or Umbrella Org,” and a Global Coordination Layer as a “Public Benefit Corporation / DAO LLC.” These are category names, not jurisdiction-specific entity types. §13.7 Section D (“Regulatory Interface Models”) names four compliance domains by function rather than by law — AML/KYC equivalents addressed through verifiable-credential identity and trust-path risk scoring rather than Bank Secrecy Act terminology, tax compliance through flow accounting and smart trust contracts, consumer protection through member-triggered Collective Protective Protocols, and financial-instrument classification through token design intended to avoid securities status. Neither section names a statute, a regulator, or a dollar figure. Chapter 08’s overview (§8, “Legal and Regulatory Architecture”) frames a modular legal architecture for HAOs (Humanized Autonomous Organizations — the network’s coordinating framework) and their constituent units at the same level of abstraction, and §8.1 (“Modular Legal Forms and Multi-Level Structures”) supplies a generic entity-form menu — LLC, worker cooperative, B-Corporation, UK Community Interest Company, and DAO-LLC for United Micro Enterprises (UMEs) — small, self-managing venture teams of up to ~15 people; Swiss Verein, Dutch Stichting, nonprofit LLC, federated DAO LLC, and holding cooperative for the HAO Core — again without naming a specific statute, regulator, or figure.

This section supplies the concrete layer beneath that framing, for the MTU specifically: the United States federal and state statutes and regulators a staged source names, a four-state money-transmitter comparison, and European Union, United Kingdom, and Asia-Pacific regulatory material. It does not replace §13.7 or chapter 08’s abstract treatment; it names candidate concrete instances of it. §13.11 continues with the legal vehicle options and phased entity strategy the same source describes.

Source and marker convention. This section is drawn from a single staged extraction of source material located at ~/code/mtu-to, unreviewed single-pass generative output produced over a year ago and never checked against a primary source — a statute’s own text, a regulator’s own publication, or a state financial-regulator filing. Unlike the source underlying §13.9, the staging extraction reports that none of the six source files reviewed for this material contain invented first-person testimony; nothing is withheld here on that basis. Every named statute, named regulator, dollar figure, bond amount, fee, percentage, and jurisdictional threshold below is nonetheless a real claim nobody has checked, and each carries the marker (unverified) once, at its point of introduction — immediately after a named statute or regulator, or via a Status column where the material is tabular. A figure or requirement stated in the same clause as an already-marked statute or regulator is covered by that marker rather than tagged a second time. The marker does not mean a claim is false; it means the claim has not been checked against a primary source, and should be before use. Generic descriptive statements that name no specific statute or regulator and give no figure — for example, that state banking departments generally regulate state-chartered institutions — are not individually marked, consistent with this being a claim about category, not a specific unverified fact.


A. United States — Federal Statutes and Regulators

AML and sanctions. The source names the Bank Secrecy Act (BSA) (unverified) as the parent federal framework, requiring a Customer Identification Program (CIP), Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD), Suspicious Activity Reporting (SAR) filing, and Currency Transaction Reports (CTR) for transactions over $10,000. The Financial Crimes Enforcement Network (FinCEN) (unverified) is named as the federal body administering BSA regulation and enforcement. The Office of Foreign Assets Control (OFAC) (unverified) is named separately, covering screening against the Specially Designated Nationals (SDN) list, sanctions-program compliance, transaction monitoring, and blocking procedures for matches; the source attaches no figure to OFAC compliance.

Consumer protection. Three federal statutes are named, each with an implementing regulation: the Truth in Lending Act (TILA) and Regulation Z (unverified) (credit-term disclosure, APR calculation and disclosure, right of rescission, advertising restrictions); the Electronic Fund Transfer Act (EFTA) and Regulation E (unverified) (electronic-transfer disclosures, error-resolution procedures, limits on consumer liability, preauthorized-transfer requirements); and the Equal Credit Opportunity Act (ECOA) and Regulation B (unverified) (prohibition on discriminatory lending, adverse-action notice requirements, record retention, fair-lending monitoring). The source attaches no dollar figure or threshold to any of the three.

Federal reporting. Beyond BSA/CTR/SAR, the source names an NCUA Form 5300 (“Call Report”) (unverified) as a required financial report for credit-union-structured MTUs; Home Mortgage Disclosure Act (HMDA) (unverified) reporting, qualified in the source only as “if applicable”; Community Reinvestment Act (CRA) (unverified) documentation, qualified only as “for certain structures”; and a Foreign Bank and Financial Accounts Report (FBAR) (unverified) filing, named as an example of foreign-account compliance for cross-border operation. Beyond these named items, the source separately catalogs federal reporting content in more granular form, without tying any of it to a further named report or statute: annual audited financial statements, a BSA compliance certification, business-continuity and disaster-recovery testing results, information-security program assessments, and material outsourcing-arrangement evaluations. Nothing comparable — a specific report name, a specific filing cadence — appears in §13.7, which treats transparency only as a cultural and architectural principle (open ledger views, participatory budgeting) rather than as a set of regulatory filing obligations.

Federal regulatory bodies. Four bodies are named. The National Credit Union Administration (NCUA) (unverified) is described as the primary regulator for federally chartered credit unions and as administrator of the National Credit Union Share Insurance Fund (NCUSIF) (unverified) — named elsewhere in the source as the applicable deposit-insurance mechanism for a credit-union-structured MTU, with unnamed “private deposit insurance alternatives” mentioned as a fallback for other structures and no specific insurer or coverage limit given. The Consumer Financial Protection Bureau (CFPB) (unverified) is described as the federal consumer financial law enforcer. FinCEN is described again in its AML-administration role. The Federal Reserve System (unverified) is described as relevant if an MTU interfaces with traditional banking, and for electronic-funds-transfer regulation. That second attribution looks stale rather than wrong: rulemaking authority for the electronic-funds-transfer rules moved to the Consumer Financial Protection Bureau under the 2010 Dodd-Frank Act, which predates the source. It is recorded as the source states it, with the discrepancy noted.

Entity-classification ambiguity. The source frames the MTU model as falling between three existing regulatory categories, with an open question attached to each: a credit union (similar member-ownership structure, a differing loan-distribution mechanism, open questions about field-of-membership requirements); a peer-to-peer lending platform (shared direct member-to-member lending, a differing risk-pooling approach, regulatory treatment described as varying by jurisdiction); and a mutual aid society (historical precedent for community-based financial support, which the source states modern regulatory frameworks “often fail to account for,” with potential for exemptions or special classification in some jurisdictions). This is a classification argument rather than a statute, a regulator, a figure, or a bond amount, and carries a correspondingly lower verification burden than the material above, so it is not tagged with the marker; it is retained because no equivalent discussion of where the MTU sits relative to existing regulatory categories appears anywhere else in the corpus.


B. United States — State-Level Requirements

Four states appear in the source with money-transmitter figures attached; no other state is covered. Every figure in the table below is (unverified).

State License Type Bond Requirement Application Fee Annual Renewal Status
California Money Transmitter $250,000–$7,000,000 $5,000 $2,500 (unverified)
New York BitLicense / Money Transmitter $500,000 $5,000 $5,000 (unverified)
Texas Money Service Business $300,000–$2,000,000 $2,500 $1,500 (unverified)
Wyoming Special Purpose Depository Institution Risk-based; no figure given $15,000 Variable; no figure given (unverified)

The source states these figures as current “as of” an unspecified date, with no citation to a state statute or regulator publication for any row. It describes state banking departments generically as the primary regulators for state-chartered financial institutions, with requirements it says vary significantly across states, and describes money-transmitter licensing as required in most U.S. states for entities transferring funds between parties. Beyond the four figures above, state-level MTU reporting is described only categorically — annual license renewals, quarterly activity reports, change-in-control notifications, and agent-location reporting — with no specific state statute named for any of the four.

Two further categories of state law are named: state Unfair, Deceptive, or Abusive Acts or Practices (UDAAP) laws (unverified), described as often more stringent than federal requirements, with a private right of action in many states and potential for “significant penalties”; and state privacy statutes — the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) (unverified), the Virginia Consumer Data Protection Act (VCDPA) (unverified), and the Colorado Privacy Act (CPA) (unverified) — described only by function (disclosure, consent, and data-subject-rights requirements that vary by state), with no penalty figure given for any of the three.


C. European Union

  • Payment Services Directive 2 (PSD2) (unverified) — Strong Customer Authentication (SCA) requirements, Access to Account (XS2A) provisions, requirements for Payment Initiation Service Providers (PISPs), and Open Banking interface standards.
  • Electronic Money Directive 2 (EMD2) (unverified) — requirements for e-money issuers, safeguarding of customer funds, redemption requirements, and limitations on interest.
  • General Data Protection Regulation (GDPR) (unverified) — legal basis for processing personal data; data-subject rights of access, rectification, erasure, and portability; Data Protection Impact Assessment requirements; breach-notification obligations; and potential fines “of up to 4% of global annual revenue or €20 million, whichever is higher.”
  • 5th Anti-Money Laundering Directive (AMLD5) (unverified) — customer due-diligence requirements, beneficial-ownership identification, enhanced measures for high-risk transactions, and requirements for virtual asset service providers.

The source attaches no fee, bond, or capital figure to the EU material beyond the GDPR penalty figure above.


D. United Kingdom

  • Payment Services Regulations (PSR) (unverified) — described as similar to PSD2 with UK-specific variation, a Financial Conduct Authority (FCA) authorization process, safeguarding requirements, and conduct-of-business rules.
  • UK GDPR and Data Protection Act 2018 (unverified) — the UK’s post-Brexit GDPR analogue, described as “largely aligned” with EU GDPR with potential for future divergence; guidance issued through the Information Commissioner’s Office (ICO) (unverified).
  • Competition and Markets Authority (CMA) (unverified) Open Banking requirements — the UK Open Banking Standard, a directory of participants, technical API specifications, and security profiles and standards.

The source attaches no fee or bond figure to any UK item.


E. Asia-Pacific

  • Singapore — Payment Services Act (unverified) — an activity-based licensing framework, a risk-focused regulatory approach, requirements for digital payment token services, and customer-money protection requirements.
  • Singapore — Personal Data Protection Act (PDPA) (unverified) — consent requirements for data collection and use, purpose-limitation principles, breach-notification requirements, and data-transfer restrictions.
  • Australia — Australian Financial Services License (AFSL) (unverified) — licensing for financial product advice and dealing, compliance with financial-services law, risk-management systems, and an “adequate resources” requirement.
  • Australia — Consumer Data Right (CDR) (unverified) — Australia’s open-banking framework: data-sharing obligations, consumer consent management, and accreditation requirements.

The source adds only high-level characterization beyond these four items, with no statute or regulator named: Singapore is described as taking a “progressive regulatory sandbox approach”; China is described as exercising “tight control over financial services innovation,” with no statute or regulator named for that characterization; and Australia’s open-banking initiatives are described as similar to the EU approach. No jurisdiction outside the United States, the European Union, the United Kingdom, Singapore, and Australia appears anywhere in the source. China is named only in this one passing characterization, with no regime cited.


Conclusion of 13.10

Read together with §13.7 and chapter 08, this section and §13.11 supply the layer those chapters leave abstract: named statutes and regulators for the United States, the European Union, the United Kingdom, and two Asia-Pacific jurisdictions, with figures for the United States only, plus a four-state money-transmitter comparison. All of it derives from a single unreviewed source and none of it has been checked against a primary source; every named statute, named regulator, dollar figure, bond amount, fee, percentage, and jurisdictional threshold above carries the (unverified) marker for exactly that reason, and should be confirmed against the statute’s own text or the regulator’s own publication before any of it is relied upon. Where the source gives a category without a figure — OFAC compliance, the three federal consumer-protection statutes, the UK and EU material beyond the one GDPR penalty figure — this section says so rather than supplying one. §13.11 continues with the ten legal vehicle options and the three-phase entity strategy the same source describes.