Your product is moving into regulated territory. Answer these questions first.
June 17, 2026 · Michael Rosselli
A product roadmap rarely announces the moment it crosses into regulated territory. One quarter you are building software. The next, a feature holds customer funds, routes a trade, or offers something that looks a lot like an investment. The code ships the same way it always has. The legal exposure does not.
The companies that handle this well deal with it before launch, while the answers can still change the design. The ones that struggle find out after a regulator, a bank partner, or an acquirer’s diligence team asks a question they cannot answer. Here are the six questions worth working through early.
1. Which regulator cares about this?
Start by naming the agency. A feature that touches securities points toward the SEC. Derivatives and commodities point toward the CFTC. Money movement and storage point toward FinCEN and state regulators. Consumer-facing claims can draw the FTC or a state attorney general.
You do not need a final answer on day one. You need to know which doors the feature opens, because each regulator expects something different, and a feature can open more than one at once.
2. Are you holding customer money or assets?
Custody changes everything. The moment you hold someone else’s funds or assets, you are closer to money transmission, trust, or custodial rules than to plain software. Ask exactly where the money sits, who controls it, and for how long. “It only passes through for a second” is still a question worth answering, not a reason to skip the analysis.
3. Does any part of this look like an investment?
Regulators look at economic reality, not the label you put on it. If users hand over money expecting a return that depends on your effort, that structure draws securities scrutiny no matter what you call the product. Tokens, revenue-share features, and rewards programs all raise this question. Answer it before the marketing copy promises anything.
4. Do you need a license, and where?
Licensing is rarely a single yes or no. Money transmitter licensing runs state by state, with different thresholds, timelines, and costs in each one. A federal registration may sit on top of that. The practical questions are which licenses the feature triggers, how long they take to obtain, and whether you can launch in some states while others are pending.
This is the question most likely to move a launch date, which is the reason to ask it first rather than last.
5. What do you have to tell users?
Regulated products come with disclosure obligations. Terms of service, fee disclosures, risk warnings, and privacy notices stop being marketing decisions and become compliance ones. Vague or missing disclosures are among the easiest things for a regulator to point to, and among the cheapest to fix while you are still drafting the launch materials.
6. Who inside the company owns this?
Compliance is not a document you file once. Someone has to own the program, keep the records, monitor for problems, and respond when a regulator asks. For an early-stage company that person is often a founder, supported by outside counsel. The point is to decide on purpose, not to discover after the fact that no one was watching.
When to bring in counsel
The cheapest time to involve a lawyer is while the feature is still a design decision. A short conversation before the build can tell you whether you are holding custody, whether the structure looks like a security, and which licenses are in play. That same conversation after launch becomes a remediation project, and remediation always costs more than design.
You do not need a full compliance program to ship your first regulated feature. You need a clear read on the risk, a plan for the licenses and disclosures that matter, and someone accountable for the rest. Get those three things in place and the launch stops being a gamble.
If your roadmap is heading into regulated territory and you want a straight answer on where the risk sits, that is the kind of question a discovery call is built for.