New Guidance on Customer Identification in Prepaid and Other Card Programs
The U.S. federal banking regulators and the Financial Crimes Enforcement Network ("FinCEN") recently released guidance (the "Guidance") clarifying the applicability of the "know-your-customer" or "customer identification program" regulations (the "Regulations") under Section 326 of the USA PATRIOT Act to prepaid cards deemed issued by banks, thrifts, credit unions, and branches of foreign banks ("banks"). The Guidance applies, effective March 21, 2016, to cards that are sold and distributed by banks or by third parties that design, manage, and operate prepaid card programs for banks. Noncompliance could result in material adverse regulatory action, especially where anti-money laundering compliance is affected.
- General purpose, reloadable prepaid card programs are "accounts" of the issuing banks, and the cardholders are bank "customers" under the Regulations.
- Cardholders in employee payroll card programs and government electronic benefit transfer card programs are not bank "customers" under the Regulations, unless the bank's program offers cardholders access to credit or overdraft features or allows cardholders to deposit funds onto the card other than through the employer or the government program.
Prepaid cards are recognized, mainstream financial products, used by individuals and private- and public-sector entities. General-purpose prepaid cards can be used at multiple, unaffiliated merchants and permit cardholders to perform a variety of functions, including some that have traditionally been conducted using other mechanisms, such as checks or debit cards tied to bank deposit accounts or credit cards. These functions include withdrawing cash at automated teller machines, paying bills, and transferring funds.
The features that make prepaid cards attractive to consumers also pose risks for banks that issue prepaid cards and process prepaid card transactions. For example, easy access to prepaid cards, the ability to use them anonymously, and the potential for relatively high volumes of funds to flow through pooled prepaid access accounts make prepaid cards potentially vulnerable to money laundering and other crimes.
Controls implemented by depository institutions and the prepaid card industry, such as limits on card values and the frequency and number of transfers permitted, as well as due diligence on third parties and cardholders, have reduced the risks posed by prepaid cards. The Guidance provides interpretations of the Regulations and offers additional steps that should be taken to comply with the Regulations, including:
- Issuing a general-purpose prepaid card that may be reloaded by the cardholder or another party on behalf of the cardholder, in a manner that is similar to the way in which funds can be added to a traditional deposit, asset, or transaction account, creates a formal banking relationship and is equivalent to opening an account for purposes of the Regulations.
- Cards that offer non-card transfers by ACH, wire, check, mobile phone, or cardholder-to-cardholder transfer, or to another account of the cardholder at the issuing bank, if such transfers result in the reloading of the general-purpose prepaid card, create an account with the bank.
- Prepaid cards issued without any reloadable functionalities or credit features will not result in the establishment of an account with the bank until those functions or features are activated by the cardholder.
- Cardholders should be treated as the bank's customers for purposes of the Regulations, even if the cardholders are not the named accountholder, but have obtained the cards from a third party who uses a pooled account with the bank to fund the cards.
- Payroll and health benefit cards (e.g., health savings account cards or flexible spending arrangement cards) create a bank–customer relationship with the employer (not the individual employees), unless the individual employees are permitted to access credit through the card or to reload the payroll card account from sources other than the employer.
- Similarly, no customer relationship with a government entity or the beneficiary is created where government benefit cards (electronic benefit transfer cards) do not permit the beneficiaries to load funds unconnected to the government program onto the card and do not permit access to credit.
Banks should consider their prepaid card programs carefully, especially their third-party and pooled prepaid card programs, as well as their know-your-customer controls and procedures, in light of the Guidance. At a minimum, prepaid card programs should:
- Be established and monitored in accordance with appropriate bank vendor management programs and in accordance with banks' internal product approval and risk committee processes.
- Identify third-party marketers and distribution channels to be used in the program. These considerations are helpful not only to reduce anti-money laundering compliance risks, but also other bank regulatory policy risks, such as regulatory policies regarding overdrafts and other short-term consumer loans.
- Be documented by contracts that allocate obligations and risks between the bank and its program managers and that require adequate recordkeeping. Any agency relationship described in the Guidance should be appropriately limited to avoid unexpected liabilities to the banks or their program managers.
- Require compliance with applicable bank rules and policies, including the Regulations, the Guidance, FDIC deposit insurance rules and, as applicable, the FFIEC IT Handbook.
- Specify the respective parties' know-your-customer obligations.
- Ensure the bank's right to transfer, store, or otherwise obtain immediate access to all customer and account information held by the third-party program manager. Such information also should be kept in accordance with FDIC deposit regulations to maintain as much FDIC insurance as possible. Special care should be used for pooled accounts to provide pass-through FDIC insurance coverage to the extent possible.
- Permit the bank to audit the program managers and to monitor their performance.
- Consider the Bank Service Company Act and, where it is applicable, permit the appropriate regulatory agency to examine the third-party program manager.
- Consider the Guidance in connection with mobile and internet banking applications and in programs where prepaid cards are only an ancillary feature or delivery mechanism.
For further information, please contact your principal Firm representative or one of the lawyers listed below. General email messages may be sent using our "Contact Us" form, which can be found at www.jonesday.com/contactus/.
Heith D. Rodman
Lisa M. Ledbetter
David F. Adler
Albert J. Rota
Jones Day publications should not be construed as legal advice on any specific facts or circumstances. The contents are intended for general information purposes only and may not be quoted or referred to in any other publication or proceeding without the prior written consent of the Firm, to be given or withheld at our discretion. To request reprint permission for any of our publications, please use our "Contact Us" form, which can be found on our website at www.jonesday.com. The mailing of this publication is not intended to create, and receipt of it does not constitute, an attorney-client relationship. The views set forth herein are the personal views of the authors and do not necessarily reflect those of the Firm.