Guides
Practical, plain-English guides from The Protocol Collective.
- Closing the gap between your compliance program as written and as operatedExaminers don't read your policy, they test it. Here's how to close the gap between the program on paper and the program in practice. Built from public frameworks.
- Why compliance teams are retiring the spreadsheet stackPolicies in one doc, evidence in another, trackers in a third. Here's why compliance leads are consolidating into single-file, owned dashboards. Built from public frameworks.
- Build your evidence binder before the examiner asksExaminers test what you can prove. Here's how to assemble an indexed evidence binder now, so an exam request is a lookup, not a fire drill. Built from public frameworks.
- The quiet cost of renting your compliance toolingPer-seat SaaS for policies, tracking and reporting adds up and holds your program hostage. The case for owning your compliance dashboards outright. Built from public frameworks.
- AML and KYC essentials for a new money services businessLaunching an MSB or fintech? Here are the core pieces of an AML/KYC program regulators expect to see from day one. Built from public frameworks, not legal advice.
- NYDFS Part 500: what a covered entity actually has to showA plain-English walk through the core obligations of NYDFS 23 NYCRR Part 500 and the records that prove them. Built from public frameworks, not legal advice.
- Beneficial ownership reporting: who files and what is neededA plain walk through the beneficial ownership information report — reporting company test, who counts as a beneficial owner, and the information required. Built from public frameworks.
- A practical third-party risk process for a small fintechYou inherit your vendors' risk. Here's a lean, defensible third-party risk management process — tiering, diligence, monitoring — for a small team. Built from public frameworks.
- A chief compliance officer's first hundred daysNew CCO seat? A structured first 100 days — assess, prioritise, evidence, report — so you build credibility fast instead of firefighting. Built from public frameworks.
- Running an AML and KYC forensic auditHow an AML and KYC forensic audit reconstructs customer risk, tests controls, and evidences your program end to end. Built from public frameworks.
- Building a sanctions and OFAC screening programHow to build a sanctions and OFAC screening program: list management, match handling, escalation, and blocking. Built from public frameworks.
- Running fraud operations at a fintechHow fintechs run fraud operations: detection rules, case queues, chargeback handling, and loss tracking. Built from public frameworks.
- Controls against wire fraud and business email compromiseControls that stop wire fraud and business email compromise: verification, callbacks, dual approval, and recovery. Built from public frameworks.
- Money transmission licensing basicsWhat money transmission licensing involves: state licenses, MSB registration, bonding, and ongoing reporting. Built from public frameworks.
- Running a whistleblower and ethics hotline programHow to run a whistleblower and ethics hotline: intake, anti-retaliation, investigation, and escalation. Built from public frameworks.
- Tax information reporting basics: 1099 and 1042-SHow 1099 and 1042-S information reporting works: payee data, thresholds, filing, and backup withholding. Built from public frameworks.
- Building a crypto and digital-asset compliance programA crypto and digital-asset compliance program covers BSA/AML, sanctions screening, the Travel Rule, and state money transmission. Built from public frameworks.
- What buy-now-pay-later compliance actually requiresBuy-now-pay-later compliance spans Reg Z coverage, UDAAP, dispute handling, and state installment lending rules for split-pay credit. Built from public frameworks.
- Card program compliance for fintechsCard program compliance for fintechs covers network rules, Reg E, Reg Z, settlement, and BIN sponsor oversight of program managers. Built from public frameworks.
- Lending compliance essentials for the loan lifecycleLending compliance essentials cover ECOA, Reg B, TILA, fair lending, adverse action notices, and servicing duties. Built from public frameworks.
- Open banking and CFPB Section 1033 obligationsOpen banking under CFPB Section 1033 covers consumer data access rights, authorized third parties, and developer interface duties. Built from public frameworks.
- Sponsor bank and BaaS compliance expectationsSponsor bank and BaaS compliance expectations: third-party risk, oversight, BSA/AML, and settlement duties between banks and fintechs. Built from public frameworks.
- Consumer compliance basics: UDAAP, Reg E, and Reg ZConsumer compliance basics cover UDAAP, Reg E error resolution, and Reg Z disclosures shaping how fintechs treat customers. Built from public frameworks.
- Model risk management: SR 11-7 basicsSR 11-7 model risk management basics: how to identify, validate, and govern models, and document controls across their lifecycle. Built from public frameworks.
- Operational risk and resilienceOperational risk and resilience: mapping critical processes, setting impact tolerances, and preparing to withstand disruption. Built from public frameworks.
- Third-party and vendor risk managementThird-party and vendor risk management: due diligence, contracts, ongoing monitoring, and exit planning across the lifecycle. Built from public frameworks.
- Auditing your regtech vendorsAuditing your regtech vendors: what evidence to request, how to test control claims, and how to document findings for examiners. Built from public frameworks.
- Capital and liquidity management basicsCapital and liquidity management basics: capital ratios, buffers, liquidity coverage, and the reporting that keeps a firm sound. Built from public frameworks.
- Treasury operations controlsTreasury operations controls: segregation of duties, payment authorization, reconciliation, and cash safeguards that prevent loss. Built from public frameworks.
- Records management and retentionRecords management and retention: classifying records, setting retention schedules, honoring legal holds, and safe disposal. Built from public frameworks.
- The compliance officer's operating systemA compliance officer juggles duties, deadlines, and evidence. One single-file operating system keeps every obligation current. Built from public frameworks.
- Regulatory change managementRules change often. A process to spot, assess, and implement regulatory updates keeps controls aligned with current law. Built from public frameworks.
- Policy lifecycle and maintenancePolicies drift out of date without a plan. See how a clear lifecycle keeps every policy owned, reviewed, and current. Built from public frameworks.
- Consumer complaints managementComplaints are early warnings. A structured intake, tracking, and root-cause process turns them into fixes you can prove. Built from public frameworks.
- Marketing and advertising compliance reviewEvery claim carries risk. A consistent review workflow catches unsupported statements and missing disclosures before they ship. Built from public frameworks.
- Standing up an internal audit functionAn internal audit function tests whether controls actually work. See how to stand one up with independence and a clear plan. Built from public frameworks.
- Privacy and data governance basicsYou cannot protect data you have not mapped. See how privacy and data governance basics turn principles into working controls. Built from public frameworks.
- Information security and SOC 2 readinessSOC 2 readiness is about evidence, not promises. See how to map security controls to the proof an auditor expects. Built from public frameworks.
- The fintech Chief Compliance officer roleWhat a fintech Chief Compliance Officer owns day to day, the public rules that shape the mandate, and how to make the work legible. Built from public frameworks.
- The fintech Chief Risk officer roleWhat a fintech Chief Risk Officer owns, the public risk frameworks that shape the mandate, and how to make risk decisions legible. Built from public frameworks.
- The fintech General Counsel roleWhat a fintech General Counsel owns across product, regulation, and contracts, and how to make legal obligations legible. Built from public frameworks.
- A quality-of-service system for CPA firmsHow CPA firms turn professional standards and client work into a repeatable quality-of-service system with clear ownership and evidence. Built from public frameworks.
- Australian bookkeeping and BAS essentialsThe core obligations behind Australian bookkeeping and BAS work, from GST to super and payroll, made legible and repeatable. Built from public frameworks.
- Registered investment adviser compliance basicsThe core duties behind registered investment adviser compliance, from fiduciary standards to books and records, made legible. Built from public frameworks.
- Cross-border and international complianceHow to keep cross-border and international compliance legible when several regimes apply at once, from data to sanctions to tax. Built from public frameworks.
- Pricing your professional servicesA practical way to price professional services with confidence, moving from hourly guesswork to value and clear scope. Built from public frameworks.
- Building a personal operating system for foundersBuild a personal operating system that keeps a founder steady when the company will not sit still. Owned outright, built from established frameworks.
- The personal operator OSA personal operator OS that turns scattered effort into a small set of routines you actually run. Owned outright, built from established frameworks.
- The solo-CEO operating systemA solo-CEO operating system for running a whole company from one seat without losing the thread. Owned outright, built from established frameworks.
- A framework for better decisionsA framework for making better decisions under pressure, so hard calls get clearer instead of louder. Owned outright, built from established frameworks.
- Designing habits that holdHow to design habits that hold when motivation fades, using structure instead of willpower to stay. Owned outright, built from established frameworks.
- Negotiation fundamentals for operatorsNegotiation fundamentals for operators who want fair deals without games, guesswork, or wasted leverage. Owned outright, built from established frameworks.
- A personal wealth operating systemA personal wealth operating system that turns income into durable assets through rules you can keep. Owned outright, built from established frameworks.
- Running your career like an operatorHow to run your career like an operator, with strategy, positioning, and compounding moves you control. Owned outright, built from established frameworks.