01
One product may be in several regulatory circuits
PBOC regulates payment institutions and coordinates AML; NFRA covers banking, insurance and many non-securities financial activities; CSRC - securities, futures and funds; SAFE manages foreign exchange; CAC and industry bodies - data, cybersecurity and online content. SAMR and local financial authorities add consumer, advertising, competition and local financial layers.
- PBOC
- Non-bank payments, payment systems, AML coordination and e-CNY
- NFRA
- Banks, insurers, trusts, consumer finance, financial leasing and wealth management
- CSRC
- Securities, futures, public/private funds and market intermediaries
- SAFE
- FX settlement, cross-border receipts, capital account and reporting
- CAC
- Personal information, important data, cybersecurity and cross-border data
- Local regulators
- Micro-lending, financing guarantees and other local financial forms
02
The license is determined by control over money and the client's decision
Regulatory mapping breaks down the product into actions: opening a payment account, accepting and transferring funds, acquiring, custody, FX, issuing a loan, matching, investment advice, asset management, selling insurance, credit scoring and storing financial data. The marketing name “technology platform” does not remove the activity from financial regulation.
- Money flow
- Who accepts, stores, transfers and returns client funds
- Decision
- Who determines credit, investment allocation, pricing or insurance coverage
- Customer
- Retail, SME, institutional, qualified investor or financial institution
- Revenue
- Fee, spread, interest, commission, performance fee or data monetization
- Geography
- Mainland client, server, merchant, asset, payer and recipient
- Partners
- Which licensed entity has a regulated function and customer duty?
03
Overseas license does not transfer to mainland China
A foreign group chooses between a licensed Chinese company, strategic participation in an existing institution, a technology supplier to a regulated partner, and an offshore model without prohibited solicitation in the PRC. Negative List, sector rules, ownership, controller approval, capital, fit-and-proper, source of funds and national-security/data implications are checked.
If a technology company actually determines onboarding, pricing, risk decision, fund flow or customer relationship, regulatory analysis is carried out by substance, and not just by the contractual name of the parties.
04
Reception and transfer of client funds require separate payment analysis
A non-bank payment institution must be established in China and obtain a payment business license PBOC. Regulation covers establishment, shareholders and controllers, business scope, governance, reserves/customer funds, risk, data, fees and termination. The basic minimum registered capital according to detailed rules starts from 100 million RMB, and geography and types of business may increase the requirements.
Wallet and payment account create custody, safeguarding, fraud and AML perimeter.
Acquiring, network connection and transfer instruction are analyzed along the actual chain.
Settlement, reserve, refunds, chargebacks and sub-merchant control must be transparent.
Can only remain off-license if there is no means control and no regulated function.
05
The loan product is regulated from the source of money to collection
Bank lending, consumer finance, micro-loan, auto finance, factoring, financing guarantee and loan facilitation refer to different modes. Even without its own balance sheet, the platform may have requirements for marketing, borrower assessment, disclosure, pricing, data, joint lending, partner governance and debt collection.
- Funding
- Own balance sheet, bank partner, securitization or investor funds
- Underwriting
- Who makes the decision and is responsible for the model and adverse outcome
- Pricing
- Interest, fees, guarantee, membership and total cost
- Disbursement
- Direct transfer, entrusted payment and fitness for purpose
- Servicing
- Repayment, complaints, restructuring and prohibited collection practices
- Credit data
- Source, consent, purpose, reporting and correction rights
06
Advice and portfolio management - more than just content
Brokerage, securities investment consulting, fund management, fund distribution, custody, robo-advice and public offering of products require separate CSRC qualifications and self-regulatory rules. Algorithmic interface does not change the nature of advice or discretionary management. For cross-border offerings, QFII, Stock/Bond Connect and other official channels are checked, rather than direct access bypassing the rules.
Availability of the application in China does not confirm the right to advertise a foreign fund, accept orders or manage the assets of a mainland client.
07
Insurtech divides underwriting, distribution and technology
The insurer accepts the risk, the licensed intermediary sells or arranges coverage, and the technology provider provides software within the scope of the contract. Lead generation, comparison, embedded insurance, claims automation and telematics are checked by who recommends the product, receives a commission, collects a premium, concludes a policy and makes a claim decision.
- Product
- Who developed and approved the insurance product
- Distribution
- Who explains, recommends, arranges and receives remuneration
- Premium
- Through which account do the funds move and who makes the refund?
- Claims
- Who collects evidence and makes decisions
- Data
- Health, biometric, vehicle and location data require enhanced protection
08
Cross-border payment exists only together with the underlying transaction
SAFE and servicing banks verify the trade, service, investment or other acceptable basis of payment. Payment institution with cross-border FX business operates in the permitted scope, through a partner bank, with KYC/KYB, transaction authenticity, records and reporting. Split transactions or fictitious trades do not become valid due to automation.
- Parties
- Payer, beneficiary, merchant, marketplace and beneficial owner
- Purpose
- Goods, services, royalty, dividend, investment or financing
- Documents
- Contract, invoice, customs/tax evidence and platform data
- Currency
- RMB or FX, conversion, account type and bank route
- Reconciliation
- Order, payment, refund, chargeback and settlement file
- Reporting
- Regulatory data, retention and abnormal-transaction escalation
09
e-CNY does not legalize private virtual-currency services
e-CNY is a digital form of legal currency within the government circuit. Bitcoin, Ether, stablecoins and other virtual currencies do not have the status of legal tender; exchange, trading, token issuance, derivatives, pricing/intermediation and servicing mainland residents of a foreign crypto platform are considered by the authorities as illegal financial activities. Blockchain software is assessed separately, but cannot mask a prohibited financial function.
The official position of the PBOC, confirmed in 2025, maintains a tough approach to trading virtual currencies and related services.
10
AML is built by customer, product, channel and geography risk
The revised Anti-Money Laundering Law is effective January 1, 2025. The obligated institution identifies the customer and beneficial owner, understands the purpose of the relationship, conducts ongoing monitoring, maintains records, reports large/suspicious transactions according to applicable rules, and manages high-risk relationships. The model must simultaneously protect the client's legal rights and confidentiality of information.
- 01Enterprise risk assessment
Products, clients, countries, delivery channels and typologies.
- 02CDD
Identity, beneficial ownership, purpose, source and risk rating.
- 03Monitoring
Expected activity, scenario tuning, alert, investigation and decision.
- 04Governance
MLRO/function, board reporting, training, testing and remediation.
11
Financial data cannot be projected after product launch
PIPL, Data Security Law, Cybersecurity Law, financial-sector rules and outsourcing requirements overlap each other. The architecture defines controller/processor roles, sensitive PI, credit and transaction data, localization, access from abroad, cloud/vendor risk, encryption, model training, incident reporting and exit.
- Inventory
- Customer, account, payment, credit, biometric, device and complaint data
- Purpose
- Onboarding, fraud, scoring, marketing, reporting and model improvement
- Vendor
- Cloud, KYC, call center, collection, analytics and overseas support
- Model risk
- Training data, bias, explainability, change control and human review
- Resilience
- BCP, disaster recovery, cyber incident and regulator access
- Cross-border
- PIPIA and applicable CAC route to remote access or export
12
Fintech launch roadmap
- 01
Draw a customer journey, money flow, data flow and decision map.
- 02
Qualify each function according to PBOC, NFRA, CSRC, SAFE, CAC and local rules.
- 03
Select licensed entity, partner model, ownership and business scope.
- 04
Check capital, controller, management, systems and outsourcing requirements.
- 05
Collect AML, safeguarding, consumer, complaints, fraud and operational-risk framework.
- 06
Integrate privacy, localization, cybersecurity, model risk and regulatory reporting.
- 07
Conduct pre-launch legal sign-off and dry run of end-to-end client operation.
+7 (495) 221 31 46