Finance
Money Transmission Act: authentication
California will require licensed money transmitters to use stronger login authentication starting January 1, 2028.
The law adds account-access safeguards for services that send, receive, or manage money transfers. It also requires an accessible way for users to report login errors or suspected fraud.
What the law does
- Requires two-factor authentication, multifactor authentication, or an equally secure or more secure access control before a user can log in.
- Requires licensees to reverify the user, device, or system through secure authentication processes.
- Requires the access-control method to receive written approval from the person overseeing the licensee’s information security program.
- Requires risk-based reverification that considers transaction risk, unusual behavior, and transaction sensitivity without weakening security.
- Requires a way to report errors or suspected fraud through the service platform or a reasonably accessible alternative.
- Makes the requirements operative on January 1, 2028.
Who it affects
- Businesses licensed under California’s Money Transmission Act.
- Users accessing money-transmission accounts or platforms.
Context
The requirements apply to licensees regulated by the Money Transmission Act.