Fintech Rails

A common compliance language for fintech.

Fintech Rails is building an open, structured framework connecting fintech compliance requirements, practical implementation guidance, controls, and the technology that supports them.

Built for humans. Structured for machines.

framework · structure
01
Standardized Requirements
02
Implementation Guidelines
03
Controls & Evidence
04
Technology & Ecosystem
// requirement_id: REQ-KYC-001
links → guideline · control · evidence
// THE FRAMEWORK

Requirements → Guidelines → Controls & Evidence → Technology & Ecosystem

Four connected layers, being structured so that a single requirement carries through to how it is implemented, how it is evidenced, and which technology supports it.

01
Standardized Requirements
A logically organized, consistently numbered framework of fintech compliance requirements — intended to create a common language across companies, banks, advisors, and technology platforms.
02
Implementation Guidelines
Practical guidance on how requirements translate into policies, processes, operational workflows, and compliance programs.
03
Controls & Evidence
Connecting requirements to controls, documentation, evidence, monitoring, and testing so compliance can become operational and measurable.
04
Technology & Ecosystem
Mapping the infrastructure, vendors, banks, and technology supporting fintech products and compliance use cases.
// 01_STANDARDIZED_REQUIREMENTS

Structure that teams can actually cite.

Fintech compliance is fragmented — every company rebuilds the same interpretations from scratch. Fintech Rails is inspired by the usefulness of structured standards like SOC and NIST: not their content or authority, but the clarity that comes from organizing a domain well.

Logical organization
Domains and sub-domains that mirror how fintech teams actually operate.
Stable identifiers
Durable reference IDs so requirements can be cited, mapped, and versioned.
Consistent terminology
One vocabulary shared across legal, compliance, product, and engineering.
Explicit relationships
Requirements linked to guidance, controls, evidence, and capabilities.

Fintech Rails is independent and not affiliated with or endorsed by any standards body, regulator, or government agency.

Requirements LibraryIn development
REQ-KYC-001
Collect and verify government ID at consumer onboarding
KYC
REQ-BSA-014
Maintain an independent BSA/AML testing program
BSA
REQ-REGE-007
Provide provisional credit within 10 business days
Reg E
REQ-CARD-022
Document a cardholder dispute resolution process
Cards
Illustrative structure · identifiers subject to change
// 02_IMPLEMENTATION_GUIDELINES

From requirement to practice.

Guidance is being developed to describe how each requirement translates into policies, processes, operational workflows, and compliance programs — written for the people who have to build and run them.

  • Policy and procedure structure that maps back to requirement IDs
  • Operational workflows across product, engineering, and operations
  • Program-level guidance that scales past one-off interpretations
// 03_CONTROLS_AND_EVIDENCE

Compliance you can measure.

The framework is being structured to connect requirements to the controls, documentation, evidence, monitoring, and testing that demonstrate them — so compliance becomes operational rather than narrative.

// mapping model
REQUIREMENT → control
CONTROL → evidence · owner · frequency
EVIDENCE → monitoring · testing
// MACHINE-READABLE BY DESIGN

Built for humans. Structured for machines.

Fintech Rails is being structured from the beginning so the framework can be consumed by people and by software. The longer-term goal is for requirements, guidance, controls, evidence, and the relationships between them to be available in structured formats suitable for:

AI systems
Compliance platforms
Developer tools
APIs
Automated testing
Internal compliance systems
// 04_TECHNOLOGY_AND_ECOSYSTEM

Mapping the infrastructure behind fintech.

Fintech Rails is developing a structured view of the banks, technology providers, infrastructure companies, advisors, and capabilities supporting fintech products.

Use CaseRequirementCapabilityProvider

Over time, the goal is to connect a compliance requirement directly to the capabilities and providers that support it.

Ecosystem ResearchFoundation assembled
KYC / IDV
Identity & verification
BaaS
Sponsor bank platforms
Ledgers
Money movement
Card Issuing
Programs & processors
Payments
ACH · RTP · Wires
Advisory
Legal & compliance
500+
Providers Mapped
20+
Service Categories
350+
Capability Tags
// ABOUT

Open infrastructure for fintech compliance.

Fintech compliance knowledge is fragmented across firms, memos, spreadsheets, and institutional memory. Fintech Rails exists to make it more structured, interoperable, and usable — by practitioners and by the technology they rely on.

Common languageOpen infrastructurePractical implementationMachine-readable structureCollective expertiseInteroperability
Under Active Development

Fintech Rails is being developed iteratively with input from practitioners across legal, compliance, banking, operations, and technology. The framework and supporting resources will expand as the standard is pressure-tested against real-world use cases.

Built with input from people who run these programs day to day — and open to more.

Contribute