Compliance
What compliance requirements apply to cannabis payments?
Short answer
At minimum: maintain active licensing, verifiable ownership records, written KYC/AML and cash-handling procedures, accurate transaction and seed-to-sale records, tax remittance documentation, PCI obligations where card data is in scope, and prompt notification to your bank and processor when the business changes materially.
- Written by
- Cannabis Pay Hub editorial team
- Reviewed
- Reviewed by a Cannabis Pay Hub payments specialist
- Published
- Updated
The fuller explanation
Your provider's compliance obligations flow downhill into contractual requirements on you. Most cannabis merchant agreements require you to maintain licensing, cooperate with periodic reviews, report ownership changes and keep records for a defined period. Breaching those terms is a termination reason independent of anything a regulator does.
Build the evidence trail as part of daily operations rather than as an annual scramble: reconcile POS to settlement daily, keep license renewals calendared, retain authorization records for ACH, and version-control your written procedures.
Ongoing obligations that commonly get missed
- Notifying the bank and processor of ownership or license changes.
- Refreshing beneficial-owner documentation on schedule.
- Retaining ACH authorizations and refund records.
- Keeping POS, seed-to-sale and settlement figures reconciled.
- Annual PCI validation appropriate to your environment.
Important caveats
- Requirements vary by state, license type and institution.
- Compliance with your processor's terms is separate from regulatory compliance — you need both.
- This list is a starting point, not a compliance program.
Other ways people ask this
These phrasings share the same answer, so they live on this page rather than on duplicate URLs.
- Cannabis payment compliance checklist
- AML requirements for dispensaries
- What compliance do payment processors expect from cannabis merchants?
Sources
- BSA Expectations Regarding Marijuana-Related Businesses (FIN-2014-G001)
FinCEN, U.S. Department of the Treasury · checked
- PCI DSS v4.x document library
PCI Security Standards Council · checked
Was this helpful?


