The rule requires a written information security program and, unless exempt, specific written risk-assessment, testing, incident-response, and reporting records. Citation: 16 CFR 314.4 and 314.6.
Primary source: 16 CFR 314.2(h)(2)(vi)-(vii)
What documents does the Safeguards Rule actually require for a check casher, wire transferor, or money transmitter?
Details
Policywright splits the operating record into a WISP, incident response plan, acceptable use policy, and access control policy. For a check casher, wire transferor, or money transmitter, those documents should map to Customer information lives in teller systems, ID scans, transaction logs, OFAC or fraud-screening tools, agent portals, receipts, SAR-supporting notes, and money-transmission platforms. The WISP should map agent locations and hosted provider access separately from headquarters systems.
Primary source: 16 CFR 314.2(h)(2)(vi)-(vii).
Related obligations - not covered by this packet: money services businesses may have BSA/AML registration, reporting, agent-list, and AML-program duties. Policywright's WISP packet does not satisfy BSA/AML program requirements.
FAQ
What documents does the Safeguards Rule actually require for a check casher, wire transferor, or money transmitter?
The rule requires a written information security program and, unless exempt, specific written risk-assessment, testing, incident-response, and reporting records. Citation: 16 CFR 314.4 and 314.6.
What is the data-flow issue for a check casher, wire transferor, or money transmitter?
Customer information lives in teller systems, ID scans, transaction logs, OFAC or fraud-screening tools, agent portals, receipts, SAR-supporting notes, and money-transmission platforms. The WISP should map agent locations and hosted provider access separately from headquarters systems.
Is this legal advice?
No. It is source-cited educational content for a template product, not legal advice.