WISP for check cashers, wire transferors, and money transmitters
Check cashers, wire transferors, and money transmitters need a WISP when the business is covered by the FTC Safeguards Rule category check casher / wire transferor. The practical coverage trigger is that the firm cashes checks, wires money, transmits funds, or handles money-transfer transactions for consumers. Customer information lives in teller systems, ID scans, transaction logs, OFAC or fraud-screening tools, agent portals, receipts, SAR-supporting notes, and money-transmission platforms. The WISP should map agent locations and hosted provider access separately from headquarters systems.
Key facts
- Check cashers, wire transferors, and money transmitters should evaluate coverage under the FTC Safeguards Rule and document the factual trigger: cashes checks, wires money, transmits funds, or handles money-transfer transactions for consumers.
- The data map should be vertical-specific: Customer information lives in teller systems, ID scans, transaction logs, OFAC or fraud-screening tools, agent portals, receipts, SAR-supporting notes, and money-transmission platforms. The WISP should map agent locations and hosted provider access separately from headquarters systems.
- Transaction volume can push even small storefronts above 5,000 consumers. If the firm is below the threshold, 16 CFR 314.6 still does not remove security-program duties.
Key takeaways
- Check cashers, wire transferors, and money transmitters should evaluate coverage under the FTC Safeguards Rule and document the factual trigger: cashes checks, wires money, transmits funds, or handles money-transfer transactions for consumers.
- The data map should be vertical-specific: Customer information lives in teller systems, ID scans, transaction logs, OFAC or fraud-screening tools, agent portals, receipts, SAR-supporting notes, and money-transmission platforms. The WISP should map agent locations and hosted provider access separately from headquarters systems.
- Transaction volume can push even small storefronts above 5,000 consumers. If the firm is below the threshold, 16 CFR 314.6 still does not remove security-program duties.
- We already have AML controls. AML controls and Safeguards controls overlap in evidence, but they answer different legal questions; a WISP is not an AML program.
Why check cashers, wire transferors, and money transmitters are covered
Check cashers, wire transferors, and money transmitters are covered when their business activity fits check casher / wire transferor. 16 CFR 314.2(h)(2)(vi)-(vii) names regular wire-transfer businesses and check cashers as financial institutions.
The coverage test is factual. For this vertical, Policywright treats the trigger as: cashes checks, wires money, transmits funds, or handles money-transfer transactions for consumers. The sources block below is limited to primary-source or regulator materials so the page does not drift into unsourced compliance folklore.
The page does not invent a coverage theory beyond the cited category and factual trigger.
Where customer information lives
Customer information lives in teller systems, ID scans, transaction logs, OFAC or fraud-screening tools, agent portals, receipts, SAR-supporting notes, and money-transmission platforms. The WISP should map agent locations and hosted provider access separately from headquarters systems.
That data-flow map changes the WISP. A tax preparer worries about portals and e-file records; a collection agency worries about placement files, dialers, and dispute queues; an auto dealer worries about the credit application, F&I office, DMS, and lender portals.
A useful written program should name the systems, roles, vendors, access paths, retention points, and evidence records that fit the trade.
Common objection
We already have AML controls. AML controls and Safeguards controls overlap in evidence, but they answer different legal questions; a WISP is not an AML program.
Policywright handles that objection by writing the factual basis into the packet rather than hiding it. If coverage is unclear, the firm should preserve the question for counsel instead of turning a WISP into an unsupported legal conclusion.
Related obligations - not covered by this packet: money services businesses may have BSA/AML registration, reporting, agent-list, and AML-program duties. Policywright's WISP packet does not satisfy BSA/AML program requirements.
Under-5,000-consumer analysis
Transaction volume can push even small storefronts above 5,000 consumers. If the firm is below the threshold, 16 CFR 314.6 still does not remove security-program duties.
16 CFR 314.6 exempts smaller covered firms only from 314.4(b)(1), (d)(2), (h), and (i). It does not remove the written-program duty or the need to protect customer information with reasonable administrative, technical, and physical safeguards.
A serious small-firm packet should document the count assumption and keep the fuller controls where they are operationally useful.
| Question | Vertical-specific answer | Source |
|---|---|---|
| Coverage trigger | cashes checks, wires money, transmits funds, or handles money-transfer transactions for consumers | 16 CFR 314.2(h)(2)(vi)-(vii) |
| Customer data flow | Customer information lives in teller systems, ID scans, transaction logs, OFAC or fraud-screening tools, agent portals, receipts, SAR-supporting notes, and money-transmission platforms. The WISP should map agent locations and hosted provider access separately from headquarters systems. | Document in WISP data inventory |
| Common objection | We already have AML controls. AML controls and Safeguards controls overlap in evidence, but they answer different legal questions; a WISP is not an AML program. | 16 CFR 314.2(h)(2)(vi)-(vii) |
| Small-firm exception | Transaction volume can push even small storefronts above 5,000 consumers. If the firm is below the threshold, 16 CFR 314.6 still does not remove security-program duties. | 16 CFR 314.6 |
FAQ
Is this legal advice?
No. Policywright is a configurable template product, not a law firm and not legal advice. A qualified lawyer should review state-law reliance or breach-notification decisions.
Does a small firm still need a written plan?
Yes. The Safeguards Rule requires a written information security program for covered financial institutions, and IRS guidance tells paid tax preparers to maintain a written data security plan.
What if a control is not in place yet?
A serious WISP should not pretend. It should identify the gap, assign an owner, set a target date, and preserve a dated remediation record.
What makes check cashers, wire transferors, and money transmitters different from tax preparers?
The data flow and objection pattern are different. Check cashers, wire transferors, and money transmitters need a WISP that follows Customer information lives in teller systems, ID scans, transaction logs, OFAC or fraud-screening tools, agent portals, receipts, SAR-supporting notes, and money-transmission platforms. The WISP should map agent locations and hosted provider access separately from headquarters systems.
Does Policywright cover related non-Safeguards obligations?
Related obligations - not covered by this packet: money services businesses may have BSA/AML registration, reporting, agent-list, and AML-program duties. Policywright's WISP packet does not satisfy BSA/AML program requirements.
Sources
Build a WISP for check cashers, wire transferors, and money transmitters.
Answer plain questions and receive a source-cited policy packet tailored to the firm's systems, vendors, and gaps.
Build my plan