Opening contribution…
Opening contribution…
candid_remit_107212 September 2026
AI summary · What this changes
Proposal adds requirement that customers can reach a human when something goes wrong to Consumer Protection and Market Conduct pillar definition.
The proposal modifies the definition of the Consumer Protection and Market Conduct pillar. The before text states the pillar assesses what customers can do when something goes wrong and reads conduct regulation by remedies rather than principles. The after text adds a new clause: "and whether a customer can actually reach a human when it goes wrong." This substantively expands the pillar's scope to include accessibility to human contact as part of assessing redress mechanisms, beyond the existing focus on customer remedies and conduct regulation interpretation.
Author’s reasonRedress is scored on whether a process exists. A process nobody can reach is not redress, and assessors have no indicator that catches it.
On the board and under discussion. Nothing in the methodology has changed.
From the moderators
Good catch. The reachability point is not covered by any current indicator.
01 · Edit · p02.wii1
reworked · 1 word out, 14 words in
Consumer Protection and Market Conduct assesses what a customer can actually do when something goes wrong. It reads conduct regulation by its remedies rather than by the number of principles in the rulebook.rulebook, and whether a customer can actually reach a human when it goes wrong.
Full recorded document context, including this proposal’s other changes. Surrounding passages use their current wording. Edits against older wording are marked separately.
Preview only. Red strikethrough marks removals; green underlining marks additions. Unchanged passages remain in place.
Whether customers have rights they can enforce, a route to redress that does not answer to the firms, and visibility of what firms have been found to do.
Conduct regulation is judged here by what a customer can actually do when something goes wrong, not by the number of principles in the rulebook.
The pillar covers enforceable rights over one's own records, independent dispute resolution, published enforcement with its reasoning, disclosure obligations that can be tested rather than asserted, and public identification of firms operating outside the perimeter.
Publication runs through all of it. A regulator that sets clear conduct standards and enforces them privately produces a market where only the firms already under investigation know where the line is.
Covers independent dispute resolution, customer rights over their own records, published enforcement and penalty reasoning, disclosure specified by content and timing, and firm level complaint data. Excludes general consumer law, advertising standards run outside the financial regulator, and individual case outcomes.
Consumer Protection & Market Conduct assesses what a customer can actually do when something goes wrong. It reads conduct regulation by its remedies rather than by the number of principles in the rulebook.
Source differs: this edit was written against another version. Current text is above; the original proposal is below. It has not been applied to the current passage.
Consumer Protection and Market Conduct assesses what a customer can actually do when something goes wrong. It reads conduct regulation by its remedies rather than by the number of principles in the rulebook.rulebook, and whether a customer can actually reach a human when it goes wrong.
Publication runs through the whole pillar. A regulator that sets clear conduct standards and enforces them privately produces a market where only the firms already under investigation know where the line is.
Independent dispute resolution: jurisdiction, funding, appointment, binding effect
Customer rights over their own transaction records, and the remedy for refusal
Enforcement publication, including settled cases and penalty reasoning
Disclosure requirements specified by content, placement and timing
Firm level complaint data, normalised and broken down by outcome
Public identification of firms operating outside the perimeter
General consumer law not directed at financial services
Advertising standards administered outside the financial regulator
Individual case outcomes, which are the redress body's work rather than the framework's
Independent redress and its reach
Enforceable rights over customer records
Published enforcement and reasoning
Disclosure obligations that can be tested
Complaint data published at firm level
Weights are a starting point. The working group may revise them with documented rationale, which means they are open to an edit too.
A body handling many complaints may be accessible or may be failing to prevent them. The assessment reads structure and independence, not caseload.
Where categories differ between firms, published data is counted as present but its comparability is not assessed.
Six indicators. This is the canonical text. Select any passage to propose an alternative.
Pillar definition
Rules Clarity & Comprehensiveness (RCC) measures whether a jurisdiction’s fintech‑relevant rules are:
Findable and understandable (“clarity”), and complete enough to cover common fintech activities and risks (“comprehensiveness”), in a way that a regulated firm, or prospective entrant, can determine what licence it needs, what obligations apply, and how to comply, using publicly available materials.
This is not a “friendliness” or deregulatory score. It does not reward laxity; it rewards clarity, coherence, and coverage of the fintech rulebook itself.
Scope and boundaries
In scope (fintech‑relevant rule corpus):
Primary laws and regulations covering:
Core: Payments / payment systems / e-money Banking / lending / credit Securities / investment / advice / management Insurance Digital assets: custody, issuance of crypto tokens / asset tokenisation / stablecoins, crypto‑asset services (if applicable) Subareas within core: Regtech / suptech Digital banking / fintech licensing / regulation digital lending / BNPL Roboadvisory / automated trading Financial infrastructure / trading systems Data analytics / AI Internal IT systems Crowdfunding (if applicable)
Cross‑cutting supervisory requirements that materially affect fintech operations, including:
Core: AML/CFT / (e)kyc Data protection Data use / portability / consent in financial services Identity Subareas: Outsourcing / cloud Cybersecurity Operational resilience Safeguarding of funds Market conduct requirements
Out of scope:
Ecosystem outcomes (e.g. investment levels, number of fintechs). Enforcement “toughness” (except as it affects interpretive clarity and transparency). Broader “quality of regulation” debates unrelated to clarity or coverage.
RCC evaluates the quality and navigability of the rulebook as a rulebook, not the substantive policy stance or outcomes.
Scoring conventions and evidence rule
RCC uses a 0–3 evidence‑based scale:
0 = Opaque / materially unclear: key requirements are hard to find, ambiguous, contradictory, or not operational. No regulation at all.
1 = Partially clear: some guidance exists but significant ambiguity or gaps remain, creating material uncertainty for common models. Advisory / policy statements etc, providing some level of clarification. Role of supervisory processes.
2 = Clear and workable: most relevant rules are findable and understandable; some gaps or fragmentation remain.
3 = Highly clear, coherent, and comprehensive: rules are well‑organised, well‑defined, publicly accessible, consistently explained, and cover the core fintech perimeter with clear compliance pathways.
Across the RCC matrix, a score of 3 should normally require all of the conditions for a 2, plus evidence that the framework is clearly organised and easy to navigate. In practice, this should usually mean that a firm can see how the relevant pieces fit together through a clear official entry point such as a portal, consolidated handbook, licensing map, rulebook structure, or equivalent public navigational tool.
For any score of 3, the evidence log should normally include at least:
a public navigational or mapping tool (for example, portal, handbook, licensing map, or guidance that helps users find obligations), and at least one public binding instrument (law, regulation, rulebook or equivalent) supporting the underlying obligations.
Every score must be supported by public sources (laws / regulations, regulator handbooks, licensing pages, official FAQs / guidance, consultation documents, official portals, policy statements / judicial decisions etc.). “Reputation” or private information cannot be used as evidence.
Conduct of review
The initial review will typically be undertaken as a desk review process. Ideally, it will be followed by direct engagement with participants, similarly to other international standards review processes.
For purposes of FRFI scoring, the RCC Working Group has adopted the following definition of Fintech:
“Fintech businesses use existing or new technology via centralised or decentralised systems to disrupt, to reimagine, to expand a services offering, to create financial instruments, to inhabit a niche, or to offer new ways for people to participate in their financial lives, either directly or through existing financial services providers, from a business, sales, information, analytics, product, regulatory or risk management standpoint.”
This definition is intentionally broad and inclusive. It encompasses new entrants and legacy players, retail and institutional services, and both the provision of financial services directly to end users and the provision of technology that enables others to provide such services. It covers activities conducted on both centralised systems (traditional software, cloud infrastructure) and decentralised systems (blockchain, distributed ledger technology).
A regulatory framework that does not keep pace with new technologies and fintech business models slows the realisation of these potential benefits, by creating uncertainty and friction around licensing, obligations, and compliance
Implication for Scoring: The Regulatory Status Problem
A critical feature of this definition is that it deliberately spans the full spectrum of regulatory status. Fintech businesses as defined above may be:
Category A, Directly Regulated: The firm itself holds a license or registration and is subject to direct regulatory obligations. Forward looking approach. Category B, Unregulated: The firm’s activities do not trigger a licensing or registration requirement and the firm is not subject to direct regulatory obligations. Category C, Unregulated but Indirectly Regulated: The firm is not itself licensed or registered, but provides services to a regulated entity that enable regulated functions, and as a result is subject to regulatory requirements imposed through the regulated entity’s obligations via outsourcing rules, vendor management requirements, or contractual terms imposed by regulatory compulsion.
This three-way distinction creates the following two scoring challenges.
First, for firms in Category B: how does the regulatory framework communicate to an unregulated FinTech firm that it is unregulated, and do so with sufficient clarity that the firm can rely on that determination? A firm that is simply silent in the regulatory framework faces uncertainty, which is itself a form of regulatory unclarity. A well-functioning regulatory environment provides clear negative perimeter guidance, affirmative statements about what is not regulated, not just positive licensing requirements.
Second, for firms in Category C: how does the regulatory framework communicate to an indirectly regulated FinTech firm what obligations flow to it through its regulated clients, and does it do so in a way that is publicly accessible and operationally usable? This category is growing rapidly as regulators extend supervisory reach to critical third-party technology providers, and the clarity, or lack thereof, of those indirect obligations is a material issue for FinTech firms operating as vendors to the regulated sector.
These are addressed through the indicators in the instructions and considerations .
Why this Distinction Matters for RCC
Regulatory regimes differ fundamentally in how they express obligations, and this difference has direct consequences for how RCC indicators should be scored. The RCC pillar measures whether a jurisdiction’s fintech-relevant rules are clear, findable, and complete. But “clear” means something different depending on the regulatory philosophy underlying the framework being assessed. Scorers who fail to account for this distinction will systematically undervalue sophisticated principles-based systems and overvalue prescriptive rules-based systems that may in practice be less navigable.
Rules-Based Regimes
A rules-based regime specifies obligations in precise, detailed terms. It tells regulated firms exactly what they must do, when, how, and in what form. Typical features include numerical thresholds, prescribed reporting formats, mandatory contract terms, defined timelines, enumerated prohibited activities, and specific procedural requirements. The firm’s compliance question is essentially binary: did it follow the specified rule or not?
Rules-based regimes are strong on operational clarity: a firm generally knows exactly what it must file, in what format, and by when. Their limitation is that detailed rules can become outdated quickly as technology and business models evolve, may produce compliance-with-the-letter-but-not-the-spirit behaviour, and can create rigidity that impedes legitimate innovation.
Principles-Based Regimes
A principles-based regime specifies obligations in terms of outcomes or standards of conduct, leaving firms to determine how to achieve them. It tells regulated firms what to achieve, treat customers fairly, maintain adequate capital, manage risk prudently, act with integrity, without dictating the specific means. The firm exercises judgment about how to comply.
Principles-based regimes are strong on outcome clarity: a firm generally knows what standard it is expected to meet and what objective it is expected to achieve. Their limitation is operational ambiguity: a firm may understand perfectly well that it must “treat customers fairly” while remaining genuinely uncertain about whether a specific product feature, disclosure format, or complaint-handling procedure satisfies that obligation. In a principles-based system, that operational content is typically supplied not by the rules themselves but by supplementary interpretive mechanisms, supervisory guidance, published case studies, regulatory speeches, enforcement decisions, and FAQs, which accumulate over time to give the principles practical meaning.
Outcomes-based Regimes
An outcomes-based regime focuses on a particular set of results. The system is then designed to achieve the results which are being targeted.
Such systems - to be effective - must have clear outcomes. Those outcomes must then be clearly tied to the elements of the regulatory system. [add example]
Merit-based Regimes
Merit-based regimes focus on qualitative results: decisions are based on intentions. A merit-based regime may thus be similar in some ways to an outcome based system. However, an outcome based system typically seeks objective results while a merit-based system targets more subjectively. An outcome based system may target “better quality financial products and services” while a merit-based system may target “good financial products and services”.
Merit-based systems often lack clarity of merits being targeted. For clarity, a merits-based regime would need to have clear targets enabled by a regulatory system designed to achieve those targets.
The Spectrum in Practice
Real regulatory systems sit at various points on a spectrum between these categories and most are hybrids. A jurisdiction may use principles for conduct and outcomes while using precise rules for technical requirements such as capital ratios, prescribed reporting taxonomies, and defined timelines for complaint resolution. The UK’s FCA Handbook is a well-known example of a sophisticated hybrid: it contains both high-level principles (the FCA’s Principles for Businesses) and highly detailed prescriptive rules. The EU’s approach under MiCA tends toward greater prescriptiveness. The US operates differently again, with some agencies using a mix of principles and rules while others rely more heavily on supervisory guidance.
How This Affects RCC Scoring
The key analytical point for RCC scoring is this: a principles-based regime can be highly clear on outcomes while being less clear on operations; a rules-based regime tends toward the opposite: clearer on operations but potentially less adaptable and less clear on the underlying purpose of the obligation. To be effective, an outcomes or a merit based regime must have clear outcomes or targets and a system designed to achieve these. No approach is inherently superior from a clarity standpoint, and the FRFI does not take a position on which regulatory philosophy produces better outcomes. What the FRFI measures is how well each jurisdiction achieves clarity within its own chosen approach, and whether the mechanisms it uses to supply operational content are adequate for a regulated firm to determine and implement its obligations.
This has three practical consequences for scoring:
Multiple paths to a high score exist. For indicators where this tension arises, principally RCC-2, RCC-4, RCC-5, RCC-6, and RCC-7, a jurisdiction can reach a score of 3 via a rules-based path, a principles-based path, an outcomes-based path or a merits-based path. The evidence required differs and these paths are specified explicitly in the affected indicators. A principles-based regime should not receive a 3 solely because the underlying principles are well expressed at a high level. A 3 requires that those principles be made operationally usable through a sufficiently mature public interpretive infrastructure, for example through FAQs, speeches, case studies, examples, supervisory statements, enforcement summaries, or equivalent materials that show how the principles are applied in practice. RCC-6 carries greater weight in principles-based systems. In a rules-based system, the rules themselves supply operational content. In a principles-based system, that content is supplied through guidance, FAQs, supervisory statements, and enforcement precedent. For principles-based jurisdictions, RCC-6 is the mechanism by which principles acquire operational clarity. Scorers should read RCC-5 and RCC-6 together for principles-based jurisdictions. Scorers must identify the regulatory philosophy before scoring and note it in the evidence log. This affects both the evidence sought and the rubric path applied. See Section 7 (Evaluator Instructions) for the required procedure.
Sub-dimension: Weight / Indicators A: Accessibility & Usability: 20%: RCC-1, RCC-2 B: Definitions & Perimeter Clarity: 30%: RCC-3, RCC-4, RCC-8, RCC-9 C: Coverage & Completeness: 30%: RCC-4, RCC-5 D: Consistency, Change Management & Interpretive Support: 20%: RCC-6, RCC-7
Working Group decision required on whether to adjust weights following addition of RCC-8 and the elevated importance of RCC-6 in principles-based systems. [Weights are indicative and subject to revision; there is no strict scientific basis for their distribution.]
RCC currently uses eight core indicators. The detailed objective-trigger tables in Section 4 specify how to score 0–3; this overview summarises the purpose of each indicator.
RCC-1 Public accessibility & findability: Whether fintech-relevant rules are freely available online and easy to locate via official sources. RCC-2 Regulatory “map” of obligations: Whether regulators provide an official, usable pathway explaining how a fintech firm, across all three regulatory status categories, determines what license it needs, what licensing conditions apply, what obligations apply, and how to navigate the regulatory framework.. RCC-3 Definitions, Taxonomy & Perimeter Clarity for Common Fintech Activities: Whether key regulatory terms and fintech-relevant activity categories are defined clearly enough that a firm can tell, from public sources, whether it falls within the regulatory perimeter and which regime applies. RCC-4 Coverage across core fintech verticals: Whether the rule corpus covers the major fintech activity verticals without large gaps. RCC-5 Compliance operability: Whether a regulated firm, and where applicable an indirectly regulated vendor, can determine how to implement its obligations in practice RCC-6 Interpretive support & Q&A mechanisms: Whether regulators provide reliable public mechanisms (FAQs, guidance, interpretive processes) to reduce uncertainty. RCC-7 Change management & version control: Whether rule changes, whether to prescriptive rules or to principles and their interpretive elaboration, are made transparently and predictably, with sufficient notice for firms to adapt.. RCC-8: Outsourcing Perimeter & Indirect Supervision Clarity: Whether a regulated FinTech firm, or a regulated entity that uses FinTech vendors, can determine from publicly available sources which of its outsourced or delegated functions remain subject to regulatory oversight, and what it must therefore ensure of the third parties to whom those functions have been delegated.
Consumer Protection & Market Conduct assesses whether a jurisdiction’s rules and supervisory practices protect consumers using digital financial services (payments, e-money, digital banking, digital lending/BNPL, crypto-asset services where applicable) through clear conduct standards, transparency, redress, and safeguards — especially in digital channels.
Section 0
Overview
It measures clarity, coverage, and operational enforceability of consumer protection frameworks in fintech contexts. It does not reward “laxity” or punish “strictness.” Strong consumer protection can score highly if it is clear, fair, and workable.
Section 1
SCOPE AND BOUNDARIES
22
- Conduct-of-business rules for digital financial products (disclosure, marketing, fairness) - Complaints handling, dispute resolution, ombudsman/redress mechanisms - Rules addressing fraud/unauthorized transactions in digital payments and digital channels - Safeguarding/segregation of customer funds for e-money/payments (where relevant) - Responsible digital lending / BNPL protections (creditworthiness, affordability, collections, caps if applicable) - Data rights and consent frameworks as they apply to financial services and consumer outcomes
03
- General macro inclusion outcomes (e.g., account penetration) unless directly tied to consumer protection rules - Purely prudential standards (capital adequacy) unless directly connected to customer harm prevention (e.g., safeguarding) - Broad “internet safety” policy not specific to financial services
Section 2
SCORING CONVENTIONS
Applies the index-wide 0 to 3 scale and four scoring paths specific to this pillar.
0
Absent / unclear
No meaningful protections or very ambiguous/non-operational protections for digital financial services.
1
Emerging
Partial protections; fragmented coverage; limited applicability to digital channels; weak clarity.
2
Established
Framework exists and is usable across most fintech products; some gaps or uneven implementation.
3
Comprehensive & implemented
Clear, coherent, product-appropriate protections with demonstrable operationalization (guidance, supervision, consistent treatment of common fintech models).
Evidence rule:
Every score must be supported by public sources (laws/regulations, regulatory guidance, rulebooks, official ombudsman rules, enforcement communications, etc.). Avoid scoring based on anecdotes or reputation.
Four-scale scoring
CPMC does not score an indicator on a single rubric. Each indicator carries a main rubric plus three further 0–3 scales, and all four are recorded for every jurisdiction:
Main rubric
The substance of the requirement itself.
Evidence rating
The legal force of the sources found, graded against four levels: Level 1 primary legislation; Level 2 binding subordinate legislation; Level 3 binding supervisory requirements; Level 4 non-binding guidance. A Level 4 source alone cannot justify a score of 3.
Applicability rating
How far the requirement reaches across regulated fintech provider categories, and whether any exclusions are explicitly risk-based and proportionate.
Outcome-based rating
What consumers actually receive in practice as a result of the framework.
Section 3
Sub-Dimensions
Sub-dimension
Weight / Indicators
A — Transparency & Fair Conduct
30% — CPMC-1, CPMC-2
B — Redress & Accountability
20% — CPMC-3
C — Digital Risk & Fraud Protection
25% — CPMC-4
D — Product Safeguards in Digital Credit & Stored Value
25% — CPMC-5, CPMC-6
4
Section 4
Indicator Matrix
06
A
B
C
D
CPMC-1
Digital product disclosure & fee transparency
Sub-dim A
00 sug
RCC-1
Public Accessibility & Findability
Sub-dimension:
What it measures
Whether consumers receive clear, standardized, comparable disclosures for digital financial products (fees, terms, risks, APR/total cost where applicable)
Scoring Rubric
Score
Proposed Objective Trigger
No clear requirements. No regulatory provisions require disclosure of product features, terms and conditions, fees charged or pricing of digital financial products. Channel Test - No requirements reference digital channels or electronic delivery of disclosures.
No evidence found in Levels 1 - 4.
No regulated Fintech Provider is subject to the requirement.
No consumer protection outcome. Consumers are not guaranteed to receive information about digital products or fees. No Binding regulatory obligation exists.
Partial rules; limited to some products or offline contexts. Limited disclosure requirements exist but are limited in scope, applying to only certain products, providers, or non-digital channels, or requiring only general information without standardised fee disclosures. Channel Test - Regulations do not require disclosures to be presented through the same digital channel used to market, purchase or manage the product. (permit electronic disclosures).
Evidence only found in Level 4, or limited provisions in Levels 1-3 that apply only to specific products, providers or channels.
Requirement applies only to a limited provider category or only to traditional financial institutions, excluding most fintech providers.
Limited Consumer protection outcome Some consumers receive disclosures, but coverage is fragmented (eg, certain products, providers or channels only). Consumers cannot reasonably expect consistent disclosure across digital financial services.
Broad disclosure rules apply to most relevant products; some digital gaps. Regulation requires disclosure of key product features and material fees for most digital financial products before the consumers enter into an agreement. However, requirements are incomplete, with limited provisions on standardised presentation, ongoing fee updates, digital delivery or comparison costs. Channel Test - Electronic disclosures are required for some digital channels, but requirements are not consistently applied across all digital interfaces or providers. (require digital disclosure where products are offered digitally).
Binding Requirements found in Level 1-3, but they are incomplete in scope, coverage, timing or digital application.
Requirement applies to several major fintech providers categories but excludes one or more significant categories without a clear risk based justification.
Functional Consumer Protection Outcome Most consumers receive standardised disclosures before purchasing or using digital financial products. Material fees and product features are disclosed, but gaps remain in coverage, digital presentation, ongoing updates, or supervisory monitoring.
Strong, digital-appropriate disclosure standards (incl. clear pricing, standardized formats, key facts) + guidance. Regulations require standardised, clear and accessible digital disclosures of key product features, terms and conditions, all applicable fees and charges (including recurring, transaction, and contingent fees) total costs where applicable, and material changes. The framework specifies the timing of disclosures (eg before purchase and upon changes), permits or requires digital delivery and provides supervisory oversight or enforcement for non-compliance. Channel Test - The framework requires disclosures to be delivered through the digital channel used by the consumer (eg, mobile app, website, digital wallet), in a format that is accessible before the consumer proceeds with the transaction, and compliance is subject to supervisory oversight or enforcement. To assign a 3, there must be evidence that the framework has been applied to actual digital product flows through a supervisory, licensing, or enforcement act directed at a named provider or an identified product flow; for example, a published supervisory review, an enforcement action, or a licensing condition applied in practice. A regulator's own guidance implementing its rule does not, by itself, discharge this requirement. A framework that nominally subjects firms to enforcement without a verifiable operationalization record scores 2.
Comprehensive, enforceable requirements established through Levels 1-3, supported where appropriate by supervisory guidance. A Level 4 source alone cannot justify a score of 3. To assign a 3, there must be evidence that the framework has been applied to actual digital product flows through a supervisory, licensing, or enforcement act directed at a named provider or an identified product flow; for example, a published supervisory review, an enforcement action, or a licensing condition applied in practice. A regulator's own guidance implementing its rule does not, by itself, discharge this requirement. A framework that nominally subjects firms to enforcement without a verifiable operationalization record scores 2.
Requirement applies consistently across all relevant regulated fintech provider categories offering the affected digital financial services, with any exclusions being explicitly risk based and proportionate. Coder note - common CPMC-1 applicability gaps: PSPs and general-purpose digital wallets (excluded from credit-era rules); BNPL providers (outside consumer credit regulation where interest is zero or deferred); crypto asset service providers (disclosure regimes enacted in few jurisdictions as of 2026); embedded finance/BaaS (obligation allocation between bank partner and fintech frontend frequently ambiguous). Where one of these is the binding constraint, name it in the evidence log. Risk-based exclusion: A score of 3 requires that any exclusions be 'explicitly risk-based and proportionate.' Coders should verify this means the regulator has published a rationale for the exclusion - not merely that the exclusion exists. An undocumented carve-out for a provider type is an unexplained gap, not a risk-based exclusion, and should score 2 not 3.
Effective Consumer Protection Outcome Consumers consistently receive standardized, timely, and channel appropriate disclosures of key product features, total costs, fees and material changes across all relevant digital financial services. Providers are subject to enforceable obligations, supervisory monitoring, and corrective action where disclosures are deficient.
Scoring paths
One path — the anchors apply to all four approaches
Primary evidence sources
level
Primary Legislation (Acts of Parliament, Financial Services Acts, Consumer Protection Acts, Electronic Transaction Acts.
Binding Subordinate Legislation (Regulations, Legally binding Rules, Prudential Standards, Licensing Conditions, Mandatory regulatory Instruments.
Binding Supervisory Requirements (Regulatory Directives, Notices, Circulars Enforceable Guidelines, Codes incorporated by reference into regulation).
Non Binding Guidance (Guidance Notes, Best Practice Papers, supervisory expectations, FAQs.
Edge cases & scoring notes
Focus on clarity/coverage, not whether prices are low. Provider type gaps:
For applicability rating purposes, the following provider types represent the most common sources of below-3 scores on coverage: PSPs and general-purpose digital wallets (frequently excluded from credit-era disclosure rules); BNPL providers (often outside consumer credit regulation where interest is zero or deferred); crypto asset service providers (disclosure regimes enacted in few jurisdictions as of 2026); and embedded finance/BaaS arrangements (disclosure obligation allocation between bank partner and fintech frontend frequently ambiguous). Where one of these is the binding constraint, name it in the evidence log. Failure mode distinction - Where a jurisdiction scores below 3, coders should distinguish between two failure modes that call for different responses: (a) regulatory design gap - rules do not reach a particular product type, provider, or transaction context; identifiable by absence of binding instrument; addressable by rulemaking or legislation; and (b) design/business-model gap - rules technically apply but permit firms to comply by disclosure in terms of service rather than at the point of transaction; identifiable where binding rules exist but no digital-channel guidance or enforcement record specifies placement, timing, or format within a product flow. Note which failure mode applies in the evidence log. A score of 2 arising from (a) calls for rulemaking advocacy; a score of 2 arising from (b) calls for design standards and supervisory guidance. Agentic and AI mediated disclosure - Most existing disclosure rules were written for human-readable, point-of-sale contexts. Where transactions are initiated or completed by an AI agent or authorized third party acting on behalf of the consumer, the moment and recipient of disclosure becomes ambiguous under most current frameworks. Coders should note where a jurisdiction's rules are silent on agentic transaction contexts. Do not penalize jurisdictions for this gap at this stage - it is too novel for most to have addressed - but flag it as a v1.1 improvement item. The group agreed to include this as a forward-looking consideration in the framework.
Aggregation rule
Direct
single integer score 0–3 on the main rubric. The same score is also rated on three further 0–3 scales — evidence, applicability and outcome-based. All four sit together in each score cell, each under its own label.
Suggest an edit
Endorse a level
Cite this indicator
CPMC-2
Marketing, sales practices & fairness rules (including digital channels)
Rules governing mis-selling, misleading advertising, and fair treatment in digital distribution
No meaningful consumer financial protection/ ambiguous protection. No laws or regulations that clearly protect consumers from unfair or deceptive marketing and sales practices in the distribution of digital financial products and services, including prohibitions on unfair and deceptive sales and marketing practices; and affirmative obligations to support consumer decision-making, such as disclosure of paid promotions. Includes general consumer protection laws where application to (digital) consumer financial products is very ambiguous. Channel Test: No/very ambiguous legal basis for redressing unfair or deceptive financial marketing and sales through digital channels.
No fintech provider is subject to the relevant legal or regulatory requirements.
Consumers lack meaningful protection from unfair or deceptive marketing and sales practices in the distribution of digital financial products and services.
Limited or fragmented consumer financial protection. Laws/regulations protect consumers from unfair or deceptive marketing and sales practices for digital financial products and providers, but coverage is narrow, indirect, fragmented (may apply only to specified products, providers/ intermediaries, distribution channels/stages and marketing practices), or primarily grounded in general consumer protection law rather than financial law. Technology-neutral binding requirements in financial or general consumer law are sufficient where they provide a clear, enforceable legal basis for addressing the relevant conduct. Channel Test: General consumer protection or some financial sector-specific consumer protection for unfair or deceptive digital financial marketing and sales practices, but coverage is limited, fragmented, or unclear.
Requirements apply only to a limited category of fintech providers or primarily to traditional financial institutions, excluding most fintech providers and digital/fintech distribution models.
Some binding protections exist, but consumers remain exposed to inconsistent or limited safeguards across products, providers, intermediaries, promoters, or digital channels.
Established consumer financial protection but with material gaps. Financial laws/regulations protect consumers from unfair and deceptive marketing and sales practices in digital financial product distribution across the principal regulated financial products, providers, intermediaries, digital distribution channels (web, mobile, social media) and stages (inc. advertising, targeting, comparison, recommendation, application, and sale). Includes provider conduct; sales incentives or conflicts where relevant; marketing performed through agents, promoters, affiliates, or other third parties. Includes both prohibitions on unfair and deceptive practice and affirmative obligations, such as disclosure of paid promotions, to improve consumer decision-making. But material gaps remain in coverage of providers/intermediaries, products, or distribution channels/stages coverage; supervisory guidance; enforcement mechanisms; affirmative duties (such as commission disclosure), or negative restrictions (such as prohibitions on deceptive conduct). Technology-neutral binding requirements are sufficient where they provide a clear enforceable legal basis for addressing the relevant conduct. Channel Test: Financial sector-specific consumer protections apply to unfair or deceptive digital financial marketing and sales across principal digital financial products, providers/ intermediaries, and distribution channel/stage, including authoritative application of tech-neutral financial conduct rules; but material gaps remain.
Binding requirements are established at Levels 1–3 and clearly reach material digital marketing or sales conduct, including where authoritative Level 4 guidance clarifies the application of technology-neutral rules to social media, financial influencers, affiliates, or other digital practices; but they are incomplete in scope, coverage, timing or digital application.
Requirements apply to several major fintech provider categories but exclude one or more significant categories without a clear risk-based justification.
Consumers are generally protected from unfair or deceptive marketing and sales practices in the distribution of digital financial products and services, but material gaps remain.
Comprehensive consumer financial protection. Financial laws/regulations protect consumers from unfair and deceptive marketing and sales practices in digital financial product distribution across the principal regulated financial products, providers, intermediaries, and distribution channels and stages. Regulatory framework includes both comprehensive prohibitions on unfair and deceptive sales and marketing practices and comprehensive affirmative obligations, such as disclosure of paid promotions, to support consumer decision-making; clear enforcement mechanisms; and supervisory guidance. Technology-neutral binding requirements provide a clear, enforceable legal basis for addressing the relevant conduct, and authoritative regulatory guidance establishes that those requirements extend to emerging digital practices. A score of 3 does not require a single omnibus law or regulation: multiple binding public laws or regulations may cumulatively satisfy the score where they form a coherent regulatory framework and leave no material coverage gaps across the principal financial products and distribution channels. Channel Test: Financial sector-specific consumer protections for unfair or deceptive digital financial marketing and sales across principal digital financial products, providers, intermediaries, distribution channels and stages, including authoritative application of tech-neutral rules. Publicly available or otherwise verifiable evidence that the framework is applied in practice, such as supervisory findings, enforcement actions, thematic reviews, digital interface assessments, market monitoring results, complaints analysis, consumer testing, or equivalent evidence.
Comprehensive, enforceable requirements established through Levels 1-3, supported where appropriate by supervisory guidance. A Level 4 source alone cannot justify a score of 3. Score 3 additionally requires publicly available or otherwise verifiable operational evidence that the binding framework has been applied to actual digital marketing or sales conduct, such as a published enforcement action, supervisory finding, or equivalent.
Requirements apply consistently across all relevant fintech provider categories engaged in the affected digital marketing, recommendation, distribution, or sales activities. Any exclusions are explicitly risk-based, proportionate, and supported by a documented or otherwise verifiable regulatory rationale.
Consumers receive consistent and effective protection throughout the digital financial marketing and sales journey, including, where relevant, safeguards against misleading claims, mis-selling, manipulative design, inappropriate targeting or steering, conflicted recommendations, and unfair third-party, finfluencer, or automated distribution practices. Operational effectiveness is demonstrated through publicly available or otherwise verifiable supervisory reviews, enforcement actions, digital interface assessments, market monitoring findings, or equivalent evidence.
Primary Legislation (Financial Services Acts, Consumer (Protection) Acts, Advertising Acts, Privacy Acts, Communications Acts, Anti-Discrimination Acts).
Binding Subordinate Legislation (Regulations/Regulatory Instruments, includes Interpretive Rules)
Binding Supervisory or SRO Requirements (Directives, Notices, Codes, Interpretive Guidance, Circulars; binding self-regulatory rules such as applicable FINRA rules).
Non-Binding Guidance (Guidance Notes, Best Practices, Principles, Supervisory Expectations, FAQs, Thematic Findings, Recommendations).
Scoring focus:
Fairness and conduct coverage, not whether products are inexpensive or commercially attractive. A jurisdiction should not score lower solely because financial products have high prices, fees, or interest rates.
Binding vs supplementary guidance:
Non-binding guidance may be probative where it clearly interprets or operationalizes identified binding legal/regulatory requirements. For example, social media or finfluencer guidance may establish that a technology-neutral financial promotion rule reaches “finfluencers” or social media promotions. Guidance should not be treated as creating binding protection where no underlying binding regulation exists.
General law vs financial law:
General UDAP/consumer law can support a baseline score where it legally reaches financial marketing, but it should not automatically receive the same credit as a financial sector or product-specific regime that addresses financial promotions, disclosures, conflicts, suitability, steering, third-party promoters, or other finance-specific risks. Conversely, a jurisdiction should not be treated as relying only on general law where binding product-specific regimes also exist (for example, U.S. TILA/Regulation Z credit advertising rules or SEC securities marketing rules).
Aggregation across regimes:
A jurisdiction may satisfy higher scores through multiple binding regimes rather than one omnibus law, but coders should test whether the combined regimes cover the principal financial products, providers, and digital distribution channels without material gaps.
BNPL current status caution (U.S.):
Do not use the CFPB's 2024 BNPL interpretive rule as current affirmative evidence of Regulation Z coverage/financial sector specific protection for this market segment: the CFPB withdrew that interpretive rule in May 2025. TILA/Regulation Z remains binding for covered consumer credit, so BNPL coverage must be assessed under current law and the characteristics of the product rather than the withdrawn interpretation.
CPMC-3
Complaints handling & dispute resolution (including ombudsman access)
Sub-dim B
Whether consumers have clear, accessible redress pathways for digital finance firms
No structured redress. No regulatory provisions require financial institutions to maintain a complaints-handling function, observe defined response or resolution timeframes, or provide consumers with a route to independent review of digital finance complaints. Channel Test - No requirements reference digital channels or electronic submission/tracking of complaints.
No consumer protection outcome. Consumers have no guaranteed route to have a digital finance complaint answered or escalated; no binding regulatory obligation exists.
Basic complaints rules; unclear escalation; limited coverage. Institutions may be required to accept and log complaints, but there are no binding response or resolution deadlines, no defined escalation pathway beyond the institution, and/or coverage is limited to certain products, providers or non-digital contexts. Channel Test - Regulations do not require complaint submission or status tracking to be available through the same digital channel used to purchase or manage the product (permits, but does not require, electronic submission).
Applicability rating — Requirement applies only to a limited provider category or only to traditional financial institutions, excluding most fintech providers.
Limited Consumer Protection Outcome. Some consumers can complain and receive a response, but escalation is inconsistent, deadlines are absent or unenforced, and coverage is fragmented (e.g., certain products, providers or channels only). Consumers cannot reasonably expect a timely answer or independent review across digital financial services.
Established complaints + escalation mechanisms; some gaps for fintechs. Binding rules require an internal complaints function with defined response and resolution timeframes, and consumers have access to at least one public escalation route (a regulator complaint channel, a state-run online dispute-resolution platform, or small-claims court) below the institution. However, there is no independent ADR/ombudsman scheme with decisional authority binding on the firm, and/or the regime does not extend consistently to fintech, BNPL or crypto-asset providers. Channel Test - Digital submission of complaints is required for some products/providers but is not consistently required across all digital interfaces.
Binding requirements found in Levels 1-3 establishing internal complaints handling and response/resolution deadlines, but incomplete in scope, coverage, digital accessibility, or lacking a binding independent ADR/ombudsman layer (or documented functional equivalent).
Requirement applies to several major fintech provider categories but excludes one or more significant categories without a clear risk-based justification.
Functional Consumer Protection Outcome. Most consumers obtain an answered complaint within a defined deadline at no cost and can escalate through a free public channel (regulator complaint channel, state-run ODR platform, or accessible small-claims court). Binding third-party adjudication, however, is unavailable, slower, or outcome-variable, because no independent ADR/ombudsman scheme with decisional authority (or documented functional equivalent) exists.
Mature system: clear timeframes, independent ADR/ombudsman coverage, digital accessibility, published process. Regulations require: (i) a numeric deadline for initial response and final resolution, with any extension both individually justified and capped as a share of monthly complaint volume; (ii) an independent ADR scheme or ombudsman with decisional authority binding on the firm, with express coverage of digital/fintech payment providers, OR a demonstrated functional equivalent meeting the private-law-substitution test below; (iii) digital accessibility of complaint submission and status tracking within the channel the product was purchased or used; and (iv) published, institution-level process and outcome data (response times, volumes, resolution/upheld rates) enabling public verification. Channel Test - The framework requires complaint submission and tracking to be available through the digital channel used by the consumer, and compliance is subject to supervisory oversight or enforcement. Evidence of at least one supervisory review, published complaint ranking, or ADR case-outcome record demonstrating the framework operates in practice is required to assign a score of 3. A framework that nominally provides these rights without a verifiable operationalization record scores 2. NOTE - Private-law-substitution test: where no independent ADR/ombudsman with decisional authority exists, a free, digitally accessible, small-claims (or equivalent) court pathway below a defined value threshold, requiring no filing fee, available for online filing, and not requiring mandatory legal representation, may be treated as a functional equivalent. This is an anchor-sensitivity decision for plenary; coders should record in the evidence log which reading was applied and flag the case as a close call where the score turns on it.
Comprehensive, enforceable requirements established through Levels 1-3, covering internal handling, numeric deadlines, an independent ADR/ombudsman with decisional authority (or documented functional equivalent), and digital accessibility, supported where appropriate by supervisory guidance. A Level 4 source alone cannot justify a score of 3. Score 3 additionally requires evidence that the framework has been applied in practice - through published complaint rankings, published quality evaluations, ADR/ombudsman case-outcome statistics, or equivalent supervisory record.
Requirement applies consistently across all relevant regulated Fintech Provider categories offering the affected digital financial services, with any exclusions being explicitly risk-based and proportionate. Coder note - common CPMC-3 applicability gaps: unlicensed fintech front-ends and merchant-funded BNPL/installment providers (frequently outside the regulated ombudsman perimeter); crypto-asset service providers (complaint-handling duties extended in few jurisdictions as of 2026); embedded finance/BaaS arrangements (ambiguity over which entity owns the complaint). Where one of these is the binding constraint, name it in the evidence log. Risk-based exclusion: A score of 3 requires that any exclusions be 'explicitly risk-based and proportionate.' Coders should verify this means the regulator has published a rationale for the exclusion - not merely that the exclusion exists. An undocumented carve-out for a provider type is an unexplained gap, not a risk-based exclusion, and should score 2 not 3.
Effective Consumer Protection Outcome. Consumers consistently obtain a timely, defined-deadline response and can escalate free of charge to an independent ADR/ombudsman scheme (or documented functional equivalent) with decisional authority binding on the firm and express coverage of digital/fintech providers. Response and resolution data are published at institution level, and providers are subject to supervisory monitoring and corrective action where complaint handling is deficient.
Primary Legislation (Consumer Protection Acts, Financial Ombudsman/ADR Acts, Financial Services Acts, Electronic Transactions Acts).
Binding Subordinate Legislation (Regulations establishing mandatory internal complaints-handling/ouvidoria functions, ombudsman or ADR scheme rules, response and resolution deadline rules, complaint-data reporting and publication requirements).
Binding Supervisory Requirements (Regulatory directives, notices, circulars on complaint-handling standards; mandatory institution-level complaint-data publication or ranking requirements; codes incorporated by reference into regulation).
Non-Binding Guidance (Guidance notes, best-practice papers on complaints handling, supervisory expectations, FAQs).
Score availability and applicability to fintech providers, not whether it is “easy to sue”. Provider type gaps:
For applicability rating purposes, the following provider types represent the most common sources of below-3 scores on coverage: unlicensed fintech front-ends and merchant-funded BNPL/installment providers (frequently outside the regulated ombudsman/ouvidoria perimeter); crypto-asset service providers (complaint-handling duties extended to this category in few jurisdictions as of 2026); and embedded finance/BaaS arrangements (ambiguity over whether the bank partner or the fintech front-end owns the complaint). Where one of these is the binding constraint, name it in the evidence log.
Failure mode distinction
Where a jurisdiction scores below 3, coders should distinguish between two failure modes that call for different responses: (a) design gap - the independent ADR/ombudsman layer does not exist at all, and no functional equivalent meets the private-law-substitution test; identifiable by absence of a binding instrument creating decisional authority beyond the firm; addressable by legislation establishing a sectoral ombudsman or binding ADR scheme; and (b) design/business-model gap - complaints and escalation rules exist and bind the firm, but coverage, deadlines or digital accessibility are incomplete (e.g., deadlines apply to some products only, or digital submission is permitted but not mandated); identifiable where binding rules exist but no digital-channel guidance or enforcement record specifies availability of online submission or tracking. Note which failure mode applies in the evidence log. A score of 2 arising from (a) calls for institutional design (a sectoral ombudsman or ADR scheme); a score of 2 arising from (b) calls for design standards and supervisory guidance on channel accessibility.
Private-law-substitution rule (anchor-sensitivity flag)
Coders applying the level-3 private-law-substitution test should confirm all three conditions (no fee, online filing, no mandatory legal representation) are independently evidenced, not assumed from general small-claims availability; absent clear evidence on any one condition, treat the ADR/ombudsman trigger as unmet.
Agentic and AI-mediated complaints
Most existing complaints frameworks assume a human complainant contacting the institution directly. Where a complaint arises from a transaction initiated by an AI agent or authorized third party acting on the consumer's behalf, it is often unclear under current frameworks who may file, track or be awarded redress. Coders should note where a jurisdiction's rules are silent on agentic complaint contexts. Do not penalize jurisdictions for this gap at this stage - it is too novel for most to have addressed - but flag it as a v1.1 improvement item.
CPMC-4
Fraud/unauthorized transaction liability framework in digital payments
Sub-dim C
Clarity of consumer liability and provider obligations for scams/unauthorized payments; protections like strong authentication where applicable
No clear framework No binding legal or regulatory framework allocates liability for unauthorized transactions or digital payment fraud. Consumers have no defined dispute pathway or statutory protection specific to digital payments. Channel Test: No digital payment-specific requirements.
No regulated fintech providers covered.
Consumers have no predictable protection against digital payment fraud.
Partial framework Binding rules address certain forms of unauthorized transactions or payment fraud, but liability allocation remains unclear or inconsistent across providers, payment types or digital channels. Authentication expectations or dispute mechanisms are limited. Channel Test: Fraud reporting or dispute processes are largely offline or not consistently available through digital payment channels.
Only Level 4 guidance exists, or binding rules cover only limited payment products, providers or channels.
Applies primarily to traditional banks or only one provider category.
Some protections exist, but liability and dispute outcomes remain inconsistent and uncertain.
Established framework Binding rules clearly allocate liability for unauthorized transactions and establish a structured dispute process. Providers are subject to authentication and fraud management requirements, but important gaps remain (for example APP scam liability, digital dispute handling, ecosystem coordination or operational implementation). Channel Test: Digital reporting or dispute mechanisms exist for some providers or payment channels, but are not consistently mandated across all regulated digital payment providers.
Binding requirements exist in Levels 1 - 3 but remain incomplete in scope, digital implementation, liability allocation or operational processes.
Applies to several major fintech provider categories but excludes one or more significant provider types without a published risk-based justification.
Consumers generally benefit from clear unauthorized transaction protections and structured dispute mechanisms, although significant gaps remain for APP scams, digital reporting or operational implementation.
Comprehensive, operational digital fraud framework Binding rules establish: clear liability allocation for both unauthorized transactions and authorized push payment scams; binding fraud prevention and authentication requirements (e.g. MFA, behavioural monitoring, device controls, transaction risk management); operational dispute handling embedded within the same digital payment channel used by the consumer; defined investigation, fund preservation and resolution timeframes; ecosystem-level fraud intelligence or information-sharing mechanisms where applicable; and demonstrated supervisory oversight through published enforcement actions, supervisory reviews, operational statistics or equivalent evidence. Channel Test: Consumers can report and manage fraud directly through the digital payment channel (mobile app, wallet, internet banking, etc.) used to initiate the payment, with compliance subject to supervisory oversight. Operationalisation requirement: A score of 3 requires evidence that the framework has been applied in practice through published supervisory findings, enforcement actions, scheme statistics, fraud recovery data or equivalent operational evidence.
Comprehensive binding requirements established through Levels 1 - 3, supported by demonstrated supervisory implementation including enforcement actions, supervisory reviews, operational statistics or published scheme outcomes.
Applies consistently across all relevant regulated providers offering digital payment services, including banks, PSPs, e-money issuers and other applicable providers, with any exclusions being explicitly documented, proportionate and risk-based.
Consumers benefit from an end-to-end fraud protection framework covering prevention, authentication, liability allocation, digital dispute handling, ecosystem coordination and supervisory oversight, resulting in consistent and predictable consumer outcomes across digital payment services.
Primary legislation → Payment Services Acts → Electronic Transactions Acts → Consumer Protection legislation → Financial Services legislation
Binding subordinate legislation → Payment system regulations → Scheme rules → Regulatory regulations → Mandatory authentication requirements → AML/CFT regulations where directly relevant to fraud prevention
Binding supervisory requirements → Regulatory notices → Supervisory directives → Enforceable circulars → Mandatory fraud management requirements
Non-binding guidance → Regulatory guidance → Industry codes → Best practice papers → FAQs
Replace subjective language such as "strong fraud protection" with objective requirements, including:
Binding liability allocation; mandatory authentication requirements; mandatory fraud reporting process; prescribed dispute timelines; mandatory fraud monitoring; mandatory fraud information sharing; published enforcement or supervisory evidence.
Cross-pillar boundary note
Fraud and unauthorized-transaction liability in digital channels is scored by CPMC, not RI; RI scores AML/CFT regime quality for digital channels. (CPMC module, Section 8 — section borrowed from the RI module pending a CPMC-drafted version.)
CPMC-5
Safeguarding of customer funds (e-money/stored value/payment institutions)
Sub-dim d
Whether customer funds are protected via mandatory segregation, property right or a special insolvency regime
No meaningful safeguarding framework. No binding legal or regulatory provisions require relevant non-bank financial providers holding customer funds to safeguard those funds through segregation, trust, escrow, insurance, guarantees, or an equivalent mechanism. No binding framework clearly addresses the treatment or return of customer funds if the provider fails or becomes insolvent. Digital Applicability Test: No safeguarding requirements clearly apply to customer funds held through digital wallets, e-money accounts, payment applications, or comparable digital financial products.
No regulated fintech provider is subject to binding customer-fund safeguarding requirements.
Customer funds are not subject to clear safeguarding or insolvency protections.
Limited or unclear safeguarding framework. Safeguarding requirements exist, but they are narrow, fragmented, or unclear. They may apply only to specified products, providers, or account structures, or rely on general prudential, fiduciary, or licensing obligations without clearly establishing how customer funds must be protected. Requirements concerning segregation, reconciliation, eligible safeguarding assets, custodial arrangements, or treatment upon provider failure are limited or uncertain. Digital Applicability Test: Safeguarding requirements apply to selected providers or digital products, but their application to significant categories such as non-bank payment service providers, e-money issuers, digital wallets, or embedded-finance arrangements remains unclear or inconsistent.
Evidence is found only at Level 4, or Levels 1–3 contain limited provisions applying only to specific products, providers, safeguarding methods, or customer-fund arrangements.
Safeguarding requirements apply primarily to banks or to only one provider category, excluding most non-bank fintech providers that hold or control customer funds.
Some safeguards exist, but their application, coverage, or effectiveness remains limited or uncertain.
Established safeguarding framework with identifiable gaps. Binding rules require the principal categories of regulated non-bank providers holding customer funds to protect those funds through segregation, trust, escrow, insurance, guarantees, or legally effective equivalent arrangements. The framework addresses core operational requirements, including reconciliation and restrictions on the use of safeguarded funds. However, identifiable gaps remain in provider coverage, the legal effectiveness or protective quality of permitted safeguarding mechanisms, eligible safeguarding mechanisms or assets, audit and reporting requirements, intermediary arrangements, or funds-in-transit coverage, legal protection upon provider failure, or procedures for returning funds to customers. Digital Applicability Test: Safeguarding requirements clearly apply to major categories of digital financial products or providers, but coverage or implementation is not consistent across all relevant payment service providers, e-money issuers, digital wallets, embedded-finance arrangements, or other regulated entities holding customer funds.
Binding requirements are found at Levels 1–3, but they remain incomplete in provider coverage, requirements governing the applicable safeguarding mechanism or reconciliation, eligible safeguarding methods, audit and reporting obligations, intermediary responsibility, insolvency treatment, or procedures for returning customer funds.
Safeguarding requirements apply to several major regulated provider categories but exclude one or more significant types, or apply inconsistently across provider models, without a documented or otherwise verifiable risk-based justification.
Customer funds are generally protected under established safeguarding arrangements, but important gaps remain in provider coverage, operational requirements, oversight, or insolvency treatment.
Comprehensive and operational safeguarding framework. Binding rules require all relevant regulated non-bank providers holding customer funds to maintain clear and effective safeguarding arrangements. The framework establishes: separation of customer funds from the provider’s own assets through segregation, trust, escrow, insurance, guarantees, or another legally effective mechanism; where multiple safeguarding mechanisms are permitted, the framework establishes requirements sufficient to ensure that each provides substantively effective protection against the relevant risks, including shortfall, misuse, creditor claims, third-party failure, and delay in returning customer funds; requirements that account for material differences in provider legal status, regulated activity, and custodial structure, without allowing differences in entity form, custody model, or accounting treatment to create gaps in the identification, safeguarding, or return of customer funds; regular reconciliation of customer liabilities against safeguarded assets; restrictions on the use, investment, transfer, encumbrance, or commingling of safeguarded funds; requirements governing eligible safeguarding assets, accounts, custodians, insurers, guarantors, or equivalent arrangements; with proportionate treatment of materially different safeguarding risks where supported by a documented risk-based rationale; requirements addressing the failure of a bank, custodian, or other third party holding safeguarded funds, including where appropriate eligibility standards, concentration or diversification controls, legal segregation, and applicable deposit-protection, compensation, or recovery arrangements; clear allocation of responsibility among providers, custodians, partner banks, fintech interfaces, and other intermediaries; clear rules specifying when safeguarding obligations attach and cease as customer funds move through a payment chain, including which entity bears responsibility at each stage from receipt or control of the funds through delivery to the payee or transfer to another regulated provider subject to applicable safeguarding obligations, so that intermediary arrangements do not create material gaps in protection; governance, audit, reporting, recordkeeping, and supervisory requirements; clear requirements, where relevant, for providers to disclose to customers the nature and material limitations of applicable safeguarding arrangements, including whether customer funds are protected by safeguarding, deposit insurance, compensation arrangements, or another mechanism, and any material conditions or exclusions affecting recovery; and legally effective protection upon provider failure or insolvency, including a clear basis for identifying affected customers, determining their entitlements, protecting safeguarded assets from general creditor claims where applicable, and returning funds without unreasonable delay. The framework may use different legal mechanisms depending on the jurisdiction, provided those mechanisms offer substantively equivalent protection. Digital Applicability Test: Customer funds held through relevant digital products—including e-money accounts, digital wallets, payment applications, and embedded-finance arrangements—receive equivalent safeguarding protection regardless of the interface, distribution arrangement, or provider structure. Compliance is subject to supervisory oversight or enforcement. Operationalisation Requirement: A score of 3 requires publicly available or otherwise verifiable evidence that the safeguarding framework has been applied in practice to regulated providers holding customer funds. Evidence may include supervisory reviews, enforcement actions, thematic inspections, required independent audits, remediation of safeguarding shortfalls, insolvency guidance, tested customer-fund return procedures, or equivalent evidence. The evidence should demonstrate that supervisory authorities assess compliance with safeguarding, reconciliation, asset sufficiency, use restrictions, and arrangements for protecting and returning funds upon provider failure. A framework that establishes safeguarding requirements but lacks verifiable evidence of implementation should receive no more than a score of 2.
Comprehensive and enforceable safeguarding requirements are established through Levels 1–3 and supported, where appropriate, by supervisory guidance. Pathways note: A Level 4 source alone cannot justify a score of 3. A score of 3 additionally requires evidence that the framework operates in practice through publicly available or otherwise verifiable supervisory reviews, enforcement actions, required safeguarding audits, shortfall-remediation findings, insolvency guidance, fund-return procedures, or equivalent operational evidence.
Safeguarding requirements apply consistently across all relevant regulated provider categories holding customer funds, including PSPs, e-money issuers, digital wallets, remittance providers, prepaid providers, and applicable embedded-finance arrangements. Any exclusions are explicitly documented, proportionate, and supported by a documented or otherwise verifiable risk-based rationale. Coder note - common applicability gaps: Common sources of below-3 scores include non-bank PSPs, e-money issuers, general-purpose digital wallets, remittance providers, prepaid products, crypto-asset or stablecoin arrangements where applicable, and embedded-finance or BaaS models where responsibility is unclear between the fintech frontend, bank partner, and custodian. Where one of these is the binding constraint, identify it in the evidence log. Risk-based exclusion: A score of 3 requires more than a formal carve-out. Coders should verify that any exclusion is supported by a documented or otherwise verifiable rationale tied to whether the provider holds customer funds, the nature of the safeguarding risk, or the availability of an equivalent protection mechanism. An exclusion lacking a documented or otherwise verifiable rationale, or a legacy omission, is an unexplained coverage gap and should receive a score of 2, not 3.
Customer funds are consistently protected through comprehensive safeguarding arrangements, effective supervisory oversight, and clear rules governing the applicable safeguarding mechanism, reconciliation, protection upon provider failure, and the timely return of funds.
Primary Legislation: Payment services acts, e-money legislation, financial services acts, insolvency statutes, trust laws, and other primary legislation establishing requirements for the protection or preferential treatment of customer funds.
Binding Subordinate Legislation: E-money and payment regulations, legally binding safeguarding rules, licensing conditions, mandatory segregation and reconciliation requirements, eligible-asset restrictions, audit and reporting requirements, and binding rules governing the treatment of customer funds in insolvency.
Binding Supervisory Requirements: Enforceable regulatory directives, notices, circulars, safeguarding standards, supervisory codes, or guidelines incorporated into regulation or otherwise subject to supervisory enforcement, including requirements concerning custodians, safeguarding accounts, shortfall remediation, audits, and fund-return procedures.
Non-Binding Guidance: Regulator guidance, supervisory expectations, safeguarding FAQs, best-practice materials, thematic review findings, insolvency guidance, and other non-binding explanations of expected safeguarding arrangements.
protection, legal certainty, and operational coverage—not whether providers appear financially stable.
Scope Note – Narrower Approach (Proposal):
This indicator assesses customer funds held or controlled by regulated non-bank financial providers. It does not independently assess custody of securities, crypto-assets, investment assets, or other customer property. Providers such as custodians, trust entities, or digital-asset service providers should be assessed only to the extent that they hold, receive, control, or safeguard customer funds. Broader customer-asset protections could be addressed through a separate indicator or future expansion of the framework.
Objective requirements:
Replace subjective descriptions such as “strong safeguarding” with objective requirements, including segregation or an equivalent protection mechanism, regular reconciliation, restrictions on the use of customer funds, eligible custodian or asset requirements, clear insolvency treatment, procedures for returning funds, and publicly available or otherwise verifiable supervisory or enforcement evidence.
Entity Structure and Accounting Treatment:
Assessors should account for differences in provider legal status, regulated activity, and custodial structure, including payment institutions, e-money issuers, money transmitters, trust entities, custodians, wallet providers, and comparable entities. Neither regulatory classification nor accounting presentation should independently determine the score. Whether customer funds are treated as a provider liability, trust property, custodial property, client money, or another legally recognized interest, assessors should focus on the substantive protections provided, including customer entitlement, segregation, reconciliation, restrictions on use, creditor protection, and return upon provider failure.
Provider and product gaps:
Common sources of below-3 scores include non-bank PSPs, e-money issuers, general-purpose digital wallets, remittance providers, prepaid products, crypto-asset or stablecoin arrangements where applicable, and embedded-finance or BaaS models. In embedded arrangements, coders should determine which entity is legally responsible for safeguarding and whether customers retain protection if the fintech frontend, bank partner, or custodian fails. Identify the binding coverage gap in the evidence log.
Funds-in-Transit / Payment-Chain Coverage:
In multi-entity payment arrangements, assess whether binding rules identify when customer funds become subject to safeguarding, which entity is responsible while the funds are in transit, and when that responsibility legally terminates or passes to another entity. A framework should not receive comprehensive credit where transfers between PSPs, banks, custodians, processors, or other intermediaries create an identifiable period in which no entity bears clear responsibility for safeguarding the customer funds.
Safeguarding Mechanism- Effectiveness:
Safeguarding mechanisms should not receive equivalent credit solely because they are legally permitted. Assess the substantive protection provided by the mechanism, including whether it covers the full customer-fund liability, limits shortfall and counterparty risk, prevents unauthorized use or encumbrance, remains legally effective upon failure or insolvency, and permits timely return of customer funds. Different mechanisms may receive equivalent treatment where they demonstrably achieve substantively equivalent protection.
Safeguarding Mechanisms and Insolvency:
Segregation, trust accounts, escrow, insurance, guarantees, and comparable mechanisms should not automatically be treated as equivalent. Assess whether the arrangement covers the full customer-fund liability, prevents use for the provider’s own purposes, is regularly reconciled, and remains legally effective upon failure or insolvency. This assessment should distinguish failure of the regulated provider from failure of a bank, custodian, or other third party holding or administering the safeguarded funds. A general safeguarding obligation is insufficient for a comprehensive score if customer entitlements, creditor protection, administration of the return process, or the treatment of shortfalls, fees, and delays remains unclear. No particular legal mechanism is required where another arrangement provides substantively equivalent protection.
Risk-Proportionate Safeguarding:
Safeguarding requirements may vary according to the nature and duration of the provider’s control over customer funds and the risks presented by the relevant product, transaction, or intermediary arrangement. The indicator does not require identical safeguarding measures for all categories of customer funds. Where a jurisdiction applies less intensive requirements, exemptions, or alternative mechanisms to particular categories of funds, assessors should determine whether the distinction is supported by a documented or otherwise verifiable risk-based rationale and whether the resulting arrangement continues to provide protection proportionate to the customer’s exposure. Product labels alone should not determine the score.
Consumer Transparency:
Assess whether binding rules require customers to receive clear and accurate information concerning the protection applicable to their funds, including the nature of the safeguarding arrangement, material limitations or exclusions, the applicability or non-applicability of deposit insurance or compensation schemes, and relevant procedures for recovering funds following provider or safeguarding-institution failure. Disclosure should complement, rather than substitute for, substantive safeguarding protections. A provider should not receive additional safeguarding credit merely because risks are disclosed where the underlying protections are inadequate.
Failure-mode distinction:
Where a jurisdiction scores below 3, distinguish between: (a) a regulatory-design gap, where binding rules do not cover a provider, product, safeguarding method, intermediary arrangement, or insolvency issue; and (b) an operational gap, where rules formally require safeguarding but reconciliation, audits, shortfall remediation, supervisory monitoring, or fund-return procedures are inconsistent in practice. Record which failure mode applies in the evidence log.
Operational evidence:
A score of 3 should be supported by evidence that safeguarding requirements are actively implemented, such as supervisory reviews, enforcement actions, required independent audits, publicly available or otherwise verifiable shortfall findings, insolvency guidance, or documented customer-fund return procedures. The absence of provider failure should not itself establish that the framework is operational.
AI-enabled safeguarding and fund management:
Existing safeguarding frameworks generally apply regardless of whether providers use AI to monitor balances, reconcile accounts, detect shortfalls, select safeguarding assets, or manage fund movements. Coders should assess whether providers remain legally accountable for the applicable safeguarding mechanism, reconciliation, asset sufficiency, shortfall remediation, and protection upon provider failure when these functions are automated or outsourced to AI-enabled systems. Do not penalize jurisdictions solely for lacking AI-specific safeguarding rules at this stage, but flag silence on automated control failures, human oversight, auditability, third-party accountability, and operational resilience as a v1.1 improvement item.
Safeguarding: CPMC scores the substantive adequacy of customer-fund protection; RCC scores the clarity and findability of the safeguarding rulebook; RI scores the operational resilience of safeguarding arrangements. (CPMC module, Section 8 — section borrowed from the RI module pending a CPMC-drafted version.)
CPMC-6
Responsible digital credit / BNPL consumer safeguards
Sub-dim D
Whether digital lending and BNPL-type products carry consumer safeguards: affordability / creditworthiness assessment, total cost-of-credit transparency, fair-collections standards, and cooling-off for distance contracting — including coverage of zero-interest and installment (BNPL) structures. Scored on presence and clarity, not on how "tight" or cheap lending is.
No relevant consumer safeguards No binding legal or regulatory framework imposes consumer safeguards on digital credit or BNPL (affordability, cost-of-credit transparency, collections conduct or cooling-off). General contract or consumer law alone does not qualify. Channel Test: No requirement references digital origination, app-based lending or point-of-sale installment flows.
Consumers have no predictable safeguards when taking digital credit or BNPL; affordability, cost and collections outcomes are undefined.
Partial rules; gaps for fintech / BNPL Binding credit rules exist but: (a) are written for traditional / offline lending with no explicit digital application; or (b) cover only some product or provider types (e.g. licensed banks but not fintech lenders); or (c) impose disclosure or conduct duties without an affordability assessment, without a fair-collections standard, or without coverage of zero-interest installment structures. Channel Test: Rules do not require cost or terms to be presented within the digital credit flow before the consumer becomes bound.
Only Level 4 guidance exists, or binding rules cover only limited credit products, providers or channels (e.g. licensed banks but not BNPL or fintech lenders).
Applies primarily to traditional banks / licensed lenders, or only one provider category, excluding most fintech and BNPL providers.
Some safeguards exist but coverage is fragmented (certain products, providers or channels only); consumers cannot reasonably expect consistent affordability checks, cost transparency or fair collections across digital credit.
Established framework applies broadly; some digital / BNPL gaps Binding safeguards cover most regulated digital credit — including at least an affordability / creditworthiness expectation and standardised cost-of-credit disclosure — and are either drafted for digital channels or carry explicit digital guidance. However, at least one significant gap remains, for example: BNPL / zero-interest installment structures excluded from the credit perimeter; no fair-collections standard reaching first-party digital lenders; no cooling-off for distance credit; or no in-flow disclosure / timing rule. Channel Test: Cost and affordability rules apply to some providers or products but are not consistently mandated across BNPL and app-based lenders.
Binding requirements exist in Levels 1 - 3 but remain incomplete in scope, digital application, or coverage of zero-interest / installment structures, or lack a fair-collections or cooling-off element.
Applies to several major provider categories but excludes one or more significant types — most commonly zero-interest BNPL — without a published risk-based justification.
Most consumers benefit from affordability expectations and standardised cost disclosure for regulated credit, but significant gaps remain — typically zero-interest BNPL outside the perimeter, first-party collections, or cooling-off.
Mature safeguards tailored to digital credit Binding rules establish all of: affordability or creditworthiness assessment duty with defined consequences for breach; standardised total-cost-of-credit disclosure required before the consumer is bound, delivered through the digital channel; fair-collections standards applicable to digital lenders (including first-party); cooling-off / withdrawal right for distance credit contracting; explicit coverage of zero-interest and installment (BNPL) structures within the safeguard perimeter; and demonstrated supervisory oversight through published enforcement actions, supervisory reviews or equivalent evidence. Channel Test: Safeguards reach the point-of-sale / in-app credit flow before the consumer is bound, with compliance subject to supervisory oversight or enforcement. Operationalisation requirement: A score of 3 requires evidence that the framework has been applied in practice to actual digital credit / BNPL flows through a published enforcement action, supervisory review finding, complaints / scheme data or equivalent operational evidence. A framework strong on paper but with no verifiable application record — or that exempts BNPL (see proposed scoring rule in Notes) — scores 2.
Comprehensive binding requirements established through Levels 1 - 3, supported by demonstrated supervisory implementation (enforcement actions, supervisory reviews, complaints / scheme data or equivalent). A Level 4 source alone cannot justify a score of 3.
Applies consistently across all relevant regulated providers offering digital credit, including BNPL and installment structures, with any exclusions explicitly documented, proportionate and risk-based. An undocumented carve-out for BNPL is an unexplained gap, not a risk-based exclusion, and scores 2.
Consumers consistently benefit from end-to-end safeguards — affordability assessment, total-cost transparency at the point of transaction, fair collections, cooling-off, and coverage of zero-interest / installment structures — subject to supervisory oversight and corrective action, producing predictable and consistent outcomes across digital credit and BNPL.
Primary legislation → Consumer Credit Acts → Consumer Protection Acts / Codes → Financial Services legislation → Electronic Transactions Acts
Binding subordinate legislation → Consumer credit / responsible-lending regulations → BNPL or installment-credit regulations where enacted → Affordability / creditworthiness assessment rules → Debt-collection regulations → Licensing conditions for credit and BNPL providers
Binding supervisory requirements → Regulatory notices, directives and enforceable circulars → Mandatory affordability or fair-collections requirements → Codes incorporated by reference into regulation
Non-binding guidance → Responsible-lending guidance → Industry codes (e.g. BNPL codes of practice) → Best-practice papers, supervisory expectations, FAQs
Score presence and clarity
Not whether lending is "tight" or cheap. Replace subjective language such as "mature safeguards" with objective requirements, including: affordability / creditworthiness assessment duty with consequences; standardised total-cost-of-credit disclosure at the point of transaction; fair-collections standards reaching first-party digital lenders; cooling-off / withdrawal right for distance credit; explicit coverage of zero-interest and installment (BNPL) structures; published enforcement or supervisory evidence.
where a jurisdiction scores below 3, distinguish (a) regulatory design gap — rules do not reach zero-interest / installment structures or fintech lenders; addressable by rulemaking or statutory extension; from (b) design / business-model gap — rules technically apply but firms comply via terms of service rather than at the transaction moment; addressable by design standards and supervisory guidance. Name which applies in the evidence log.
Reversal / recency:
BNPL is the fastest-moving indicator in the pillar; enacted rules have been withdrawn or abandoned within months (e.g. US CFPB interpretive rule withdrawn May 2025; Brazil "Pix Parcelado" regulation abandoned Dec 2025). Record a documented-reversal flag and re-verify every source at each scoring pass.
Federal / sub-national systems:
where sub-national regimes (e.g. US states) supply safeguards the national level does not, record them on a watchlist and note the scoring convention (strongest applicable regime vs. national floor) — pending WG decision.
Proposed scoring rule (for WG decision) — BNPL perimeter ceiling:
because the dominant consumer-harm pattern is zero-interest / pay-in-four credit falling outside the credit perimeter, exclusion of these structures caps a jurisdiction at score 2. Proposed, not yet agreed.
Sign in to endorse or challenge. It takes one email and no password.
Reply within an argument, quote a contributor, or link directly to a comment.
Sign in to reply. It takes one email and no password.