Keep Up with Addis Insight
Add us to your Google Preferred Sources to see updates first.
September 16, 2026
What Payza and Ping Express teach us about card-funded remittances, regulatory responsibility, and the questions every customer and partner should ask.
A question has come up in my recent discussions about cross-border payments: can a business avoid US money-transmission requirements by collecting a customer’s card payment through a payment gateway, then arranging a local-currency payout abroad?
The claim can sound persuasive. The business is incorporated overseas. The gateway handles the card. A local partner pays the recipient. Each participant appears to perform only one part of the transaction.
But dividing a service between several companies does not, by itself, establish an exemption. The legal analysis depends on what each business actually does, the applicable rules, and the arrangements between the parties—not simply the payment technology used. 1
Card-funded remittances are not inherently unlawful. The problem is treating a gateway integration as proof that the remittance service is authorized.
This article examines that distinction from a US regulatory perspective. It does not make allegations against any current provider.
1. Start with what the customer is actually buying
Consider an illustrative transaction: a customer in the United States pays $200 by card so that a relative in Kenya or Ethiopia receives the corresponding amount in local currency, after any disclosed fees and conversion.
The customer’s objective is to transfer value to another person. The checkout page is the funding mechanism.
Under FinCEN’s regulations, money transmission broadly involves accepting funds or equivalent value from one person and transmitting funds or value to another person or location. Whether a particular participant qualifies as a money transmitter is a facts-and-circumstances question, with specific exclusions. 1
There is an important difference between paying a foreign merchant directly for a genuine purchase and paying an intermediary to deliver money to a designated recipient abroad. The CFPB’s official interpretation of its remittance rules expressly distinguishes ordinary foreign-merchant card purchases from certain card-funded transfers to overseas recipients. 3
That does not mean every gateway, software supplier, or bank involved becomes the remittance provider. It means the role of each participant must be examined rather than inferred from the presence of a card-payment form. 1, 3
2. The payment-processor exemption is not a blanket remittance exemption
FinCEN’s 2014 administrative ruling, FIN-2014-R009, explains four conditions for its payment-processor exemption. In summary, the processor must facilitate payment for goods or services other than money transmission itself; use qualifying clearance and settlement systems admitting only Bank Secrecy Act-regulated financial institutions; act under a formal agreement; and have an agreement, at minimum, with the seller or creditor receiving payment. 2
The distinction between a purchase and money transmission is central. A business cannot establish this exemption merely by describing the transfer itself as the service being purchased.
Nor should an exemption available to one participant be assumed to apply automatically to another participant performing a different function. That is the practical lesson I draw from the ruling’s activity-specific analysis. 2
The question is not whether a payment processor is involved. It is whether the particular business and transaction satisfy the relevant legal requirements.
3. Registration, licensing, and a lawful partnership are different things
FinCEN registration is not a remittance licence
FinCEN maintains a registration system for money services businesses, commonly called MSBs. Registration should not be presented as government approval of a company’s business model.
FinCEN expressly warns that inclusion in its MSB database is not a recommendation, certification of legitimacy, or endorsement. The database reflects information supplied by registrants. 4
“FinCEN-registered” and “licensed to provide this service in the customer’s state” are different claims.
State authorization must be assessed separately
Washington provides a useful example. Its statute generally prohibits conducting, advertising, or holding oneself out as providing money transmission unless the person is licensed, an authorized delegate of a licensed transmitter, or within a statutory exclusion. 5
That is an example of one state’s law—not a substitute for an assessment of every jurisdiction a business serves.
A genuine authorized-agent arrangement can matter
It would also be wrong to assume that every customer-facing brand needs a separate licence of its own in every situation. Washington expressly recognizes authorized delegates. At the federal level, FinCEN states that a person whose MSB status arises solely from acting as another MSB’s agent is not required to register separately. That exception does not cover independent MSB activities conducted on the person’s own behalf. 5, 6
The important distinction is between a documented, legally sufficient relationship and a commercial claim that “our partner handles compliance.”
A gateway agreement, referral agreement, or partner logo does not, on its own, demonstrate the statutory status of an authorized delegate. That conclusion must be supported by the actual arrangement and applicable law. 5
4. Foreign incorporation does not automatically remove US obligations
Another assumption worth examining is that a business falls outside US requirements because its company, bank account, or payout partner is located abroad.
FinCEN’s advisory on foreign-located MSBs explains that a business can fall within the US framework even without a physical US office. The definition reaches covered business conducted wholly or in substantial part within the United States, and relevant factors include providing services to customers located there. 7
That is not the same as saying every foreign website accepting an American card is an MSB. The nature of the activity and its US connection remain essential.
For a proposed US-to-Africa remittance service, my recommendation is to obtain a legal assessment of the US-origin activity as well as the destination-country arrangements. Approval of one part of the service should not be assumed to resolve the whole structure.
5. Historical cases show why the distinction matters
Enforcement cases are useful because they replace abstract warnings with documented outcomes. But they must be described accurately: an arrest is not a conviction, different charges have different elements, and additional misconduct can materially affect a sentence.
Payza / AlertPay: arrest, convictions, and forfeiture
On 18 March 2018, Canadian Payza co-founder Ferhan Patel was arrested in Detroit. The US Department of Justice announced the arrest alongside charges against Ferhan Patel, Firoz Patel, and the business. At that stage, those were allegations. 8
The case subsequently resulted in guilty pleas. On 10 November 2020, Firoz Patel received 36 months in prison and Ferhan Patel received 18 months. Their company received three years of corporate probation, and the defendants were ordered to forfeit more than $4.5 million already seized by the United States. 9
The DOJ’s sentencing account describes unlicensed money transmission together with money laundering, failures in customer due diligence, and continued operations despite regulatory warnings. This was not a case of an otherwise compliant company being imprisoned merely for using a payment gateway. 9
There was also a later, separate proceeding. On 6 February 2025, Firoz Patel received a 41-month sentence for obstruction of an official proceeding, arising from efforts to conceal 450 Bitcoin connected to the earlier case. That sentence must not be misrepresented as a new penalty solely for lacking a remittance licence. 10
The lesson is accountability for the underlying activity—not guilt by association with a particular payment technology.
Ping Express: licensing did not replace operational compliance
In July 2022, the DOJ reported that Ping Express U.S. LLC, which transferred money from the United States to Africa, pleaded guilty to failing to maintain an effective anti-money-laundering programme. 11
Its CEO, Anslem Oshionebo, and COO, Opeyemi Odeyale, also pleaded guilty to that offence and had each received 27-month prison sentences. The company admitted operating in states where it lacked authorization, despite claims that its software would prevent those transactions. 11
According to the DOJ, Ping also admitted failing to file a suspicious activity report over a three-year period despite significant suspicious activity, and allowing customers to exceed the limits described in its policies. 11
My takeaway is straightforward: obtaining some licences and writing a compliance policy are not substitutes for operating within the permitted scope and making the controls work.
Neither case proves that an unnamed modern provider is operating illegally. Neither establishes that every gateway partnership follows the same model.
Criminal exposure is possible, but not automatic
Federal law, 18 U.S.C. § 1960, provides for fines, imprisonment of up to five years, or both, where the offence’s elements are established. Its definition addresses certain state-licensing violations, failures to meet federal registration requirements, and specified activity involving criminal funds. 12
This is a reason to obtain a proper legal assessment—not a basis for declaring that every unfamiliar remittance product is criminal.
6. Customers need more than a successful card charge
The compliance question is also about what the customer is told and what happens when the transfer goes wrong.
For transfers covered by the US Remittance Transfer Rule, providers generally must supply specified disclosures, including applicable fees, the exchange rate, and the amount to be received, subject to the rule’s qualifications. 13
The rule also provides cancellation and refund rights under specified conditions. For example, its ordinary cancellation provision requires a qualifying request within 30 minutes of payment and applies where the recipient has not yet picked up the funds or received them into an account. Separate rules address certain advance-scheduled transfers. 14
Covered senders also have error-resolution rights. The regulations generally require providers to respond to qualifying error notices received within 180 days of the disclosed availability date, with investigation and remedy requirements. 15
When evaluating a service, I would therefore look beyond its exchange-rate quote. I would want to know which company is accountable for delivery, who receives a complaint, and how a refund or correction is handled.
A customer should not have to untangle a disagreement between the app, the gateway, and the payout partner to find someone willing to address a failed transfer.
7. Five questions to ask before using or partnering with a provider
These are starting points for due diligence—not a substitute for legal advice or a complete licensing review.
Who is providing the remittance? Identify the exact legal entity named in the customer terms, not just the app’s trading name or the company processing the card.
What authorization covers the service? Ask for the relevant licence details, authorized-delegate relationship, or explanation of the exemption relied upon. Check the actual entity, permitted activity, and geographic coverage rather than treating a registration number as a universal approval. 4, 5
What does the partner actually do? Request a clear explanation of the principal-agent relationship, where applicable, and the division of responsibilities. “We use a regulated partner” should begin the discussion, not end it.
How does the money move? Ask for a funds-flow diagram showing collection, settlement, conversion, payout, and refunds. Use it to identify who controls each stage and what happens when a transaction fails.
Who operates the compliance and customer-protection processes? Ask who manages customer checks, transaction monitoring, required reporting, sanctions controls, complaints, and remediation. Seek evidence of implementation—not simply a policy document.
Missing information is a reason to investigate further. It is not, by itself, proof of wrongdoing.
8. For founders: make the legal model as clear as the technical model
My recommendation to founders is to establish the operating model before treating the payment integration as launch-ready.
Document the customer relationship and movement of funds. Have qualified counsel assess the actual jurisdictions and activities. Confirm that any licensed-principal or authorized-agent arrangement covers the service being offered. Then make the product’s permissions, geographic restrictions, records, and escalation procedures match that structure.
For MSBs subject to the applicable federal AML-programme rule, the requirements include a risk-based programme, a designated person responsible for day-to-day compliance, appropriate staff training, and independent review. These are operational responsibilities, not just documents to upload during onboarding. 16
The same discipline should apply to consumer-facing promises: fees, delivery expectations, cancellation, and complaints should reflect what the service can actually support.
The bottom line
This is not an argument against card-funded remittances, payment gateways, or lawful partnerships. It is an argument for asking the right question.
Not simply: “Which gateway processes the card?”
But: “Which entity provides the remittance, what authorizes that activity, and who remains accountable to the customer?”
A successful card charge proves that the payment worked. It does not prove that the remittance is authorized.
This article provides general information, not legal advice. It focuses on US requirements and selected historical enforcement cases; it is not a complete assessment of any US state or destination country’s law. The cases discussed are not allegations against any current provider.
#Remittances #Fintech #Payments #Compliance #CrossBorderPayments
Sources
- 31 CFR § 1010.100(ff)(5). Money-transmitter definition and activity-specific exclusions; regulatory text hosted by Cornell Legal Information Institute.
- FinCEN, FIN-2014-R009 — 27 August 2014. Administrative ruling on independent sales organizations and the payment-processor exemption.
- CFPB, 12 CFR § 1005.30 and official interpretation. Remittance-transfer definitions and the distinction between foreign-merchant purchases and certain card-funded transfers.
- FinCEN MSB Registrant Search. Registration information and the express warning that listing does not establish endorsement or legitimacy.
- Washington, RCW 19.230.030. State licensing, authorized delegates, and statutory exclusions. Cited as a state-specific example.
- FinCEN, Money Services Business Registration. Federal registration rules, including the exception for persons acting solely as agents of another MSB.
- FinCEN, FIN-2012-A001 — 15 February 2012. Advisory on foreign-located money services businesses serving the United States.
- US DOJ — 20 March 2018. Payza charges and the arrest of Ferhan Patel on 18 March 2018.
- US DOJ — 12 November 2020. Payza guilty pleas, sentences imposed on 10 November 2020, and forfeiture.
- US DOJ — 6 February 2025. Firoz Patel’s separate obstruction sentence arising from concealment of cryptocurrency proceeds.
- US DOJ — 7 July 2022. Ping Express guilty pleas, executive sentences, and admissions concerning AML controls and unlicensed states.
- 18 U.S.C. § 1960. Federal offence and penalties for unlicensed money-transmitting businesses; statutory text hosted by Cornell Legal Information Institute.
- CFPB, 12 CFR § 1005.31. Disclosure requirements for covered remittance transfers.
- CFPB, 12 CFR § 1005.34. Cancellation and refund requirements and conditions.
- CFPB, 12 CFR § 1005.33. Error-resolution procedures for covered remittance transfers.
- 31 CFR § 1022.210. Federal anti-money-laundering programme requirements for covered money services businesses.