Compliance

What compliance requirements apply to cannabis payments?

Short answer

At minimum: maintain active licensing, verifiable ownership records, written KYC/AML and cash-handling procedures, accurate transaction and seed-to-sale records, tax remittance documentation, PCI obligations where card data is in scope, and prompt notification to your bank and processor when the business changes materially.

Written by
Cannabis Pay Hub editorial team
Reviewed
Reviewed by a Cannabis Pay Hub payments specialist
Published
Updated

The fuller explanation

Your provider's compliance obligations flow downhill into contractual requirements on you. Most cannabis merchant agreements require you to maintain licensing, cooperate with periodic reviews, report ownership changes and keep records for a defined period. Breaching those terms is a termination reason independent of anything a regulator does.

Build the evidence trail as part of daily operations rather than as an annual scramble: reconcile POS to settlement daily, keep license renewals calendared, retain authorization records for ACH, and version-control your written procedures.

Ongoing obligations that commonly get missed

  • Notifying the bank and processor of ownership or license changes.
  • Refreshing beneficial-owner documentation on schedule.
  • Retaining ACH authorizations and refund records.
  • Keeping POS, seed-to-sale and settlement figures reconciled.
  • Annual PCI validation appropriate to your environment.

Important caveats

  • Requirements vary by state, license type and institution.
  • Compliance with your processor's terms is separate from regulatory compliance — you need both.
  • This list is a starting point, not a compliance program.

Other ways people ask this

These phrasings share the same answer, so they live on this page rather than on duplicate URLs.

  • Cannabis payment compliance checklist
  • AML requirements for dispensaries
  • What compliance do payment processors expect from cannabis merchants?

Sources

  1. BSA Expectations Regarding Marijuana-Related Businesses (FIN-2014-G001)

    FinCEN, U.S. Department of the Treasury · checked

  2. PCI DSS v4.x document library

    PCI Security Standards Council · checked

Was this helpful?

Read next

  1. 1Is PCI required for cannabis POSYes, whenever your environment stores, processes or transmits cardholder data — including debit-based acceptance — PCI DSS applies, and your provider will usually require annual validation appropriate to your scope. Solutions that keep card data out of your systems reduce scope but do not eliminate obligations.
  2. 2our directoryThe primary sources that govern cannabis payments in the United States are federal financial-crime guidance, banking regulators, card and debit network rules, and state cannabis regulators. This directory links each one with its publisher and the date we last checked it.
  3. 3our analysis of cannabis card network rulesEven where cards are available, as they often are for CBD and hemp sellers, the account is judged against network rules on accurate merchant coding, truthful…

Talk it through with a specialist

Bring your license type, POS, monthly volume and current provider. We will tell you what is workable and what is not.

Talk to a Cannabis Payment Specialist