FK-R010 — "Becoming a U.S. Authorized Delegate," Faisal Khan LLC. The commercial, regulatory, compliance, banking and technical substance around the process. Companion to FK-R008 (document 284): "Read R008 for the process, this for the substance."
You are not renting a licence
"You are not renting a license. You are becoming part of the regulated operating framework of the license holder." The delegate never acquires the licences, and because the principal stakes its licences, regulatory standing, banking relationships and reputation, it demands control over onboarding, processing, funds movement, disclosures and escalation.
The distinction from API access is central: "API access does not automatically provide regulatory coverage." "Authorized-delegate status is a regulatory and contractual relationship, not merely a technical integration. The APIs are simply the mechanism."
Structure before applying
"One corridor. One customer type. One funding method. One payout model. One principal."
On entity selection: "Do not build an unnecessary triangular structure." "Use the simplest legally defensible corporate structure... Complexity can always be introduced later. It is far harder to remove."
And accounts must match the regulatory structure — it is "generally problematic" to contract with regulated Entity A but settle customer funds into an unrelated sister company: "That breaks the chain of accountability."
Onboarding and diligence
The principal requests corporate documents, UBO identification with source-of-wealth and background checks, the full compliance suite, questionnaires and financials — "Financial review is not a formality." A fifteen-phase sequence runs from principal selection through NDA, diligence, commercial negotiation, technical access "as early as permitted," architecture, agreement, activation, training and testing to controlled launch, then monitor and expand.
A concise mini business plan suffices, with a warning against inflated numbers: a credible ramp-up story "is a far stronger proposition than claiming tens of millions of dollars will appear immediately after launch. Credibility is worth more than an impressive number."
The compliance framework
"The principal's manual becomes your rulebook". "Read it before you build": conflicts must surface before development, because "Redesigning a customer journey after the app is built is the single most expensive avoidable mistake in this process."
US requirements are not uniform Consumer cross-border remittances can fall under the CFPB's Regulation E Remittance Transfer Rule a 30-minute cancellation right which does not survive pickup or deposit.
Two precision points: it is inaccurate to describe the arrangement as "getting a FinCEN license" — FinCEN registration is not a money-transmitter licence; and becoming a delegate does not cover activity conducted outside the agency programme.
Critically, the delegate still carries compliance responsibility: FinCEN guidance makes clear principals and agents can each have BSA and AML responsibilities, and contractual allocation does not automatically eliminate either party's regulatory liability. As the party facing the customer, the delegate is first line of defence — "'Compliance belongs to the principal, so anything suspicious is the principal's problem' is not how the relationship works." And: "The principal may manage the regulatory relationship. The delegate must operate as though every transaction could eventually be examined."
Product and technology
Identity verification is where applicants expect more independence than they receive.
The US version of the app will differ. "Treat the U.S. flow as its own regulated product configuration." On data residency there is "no responsible universal answer" — neither assume domestic hosting is required nor that foreign hosting is acceptable; get the data architecture explicitly approved before production.
Banking, settlement and risk
Customer funds move through the principal's approved mechanism — pooled, FBO, custodial or prefunded — and "The delegate should not improvise the funds flow." Two payout models: funds good and settled (slower, materially lower settlement risk) versus risk-based immediate payout (faster, and "Somebody carries settlement risk, and it is usually the delegate").
Prefunding: the principal "provides regulatory infrastructure. It is generally not financing the delegate's remittance business." Near-instant overseas payout before US collection settles requires the delegate's own liquidity on the payout side — and at meaningful volume "liquidity management becomes a treasury function rather than an operational task."
ACH risk: initiation is not the end of exposure. And fraud should be measured as a ratio, not a count — against total payment volume and against transaction revenue, since "Seemingly small fraud percentages can destroy a low-margin remittance product."
Commercial terms
"Never evaluate only the headline rate."
"Do not negotiate only how much. Negotiate when charging begins."
Personal guarantees should not be treated as routine: And the agreement itself is "not a commercial-team document" — compliance, legal, finance, treasury and technology must each understand the obligations they will discharge.
Operating, and the strategic point
Records must allow a reviewer to reconstruct a transaction end to end, and "Poor reconciliation is one of the fastest ways to destroy confidence in a payment program." Compliance's key deliverable is a written responsibility matrix, line by line: principal, delegate, or shared — ambiguity there "is only ever discovered at the worst possible moment."
Expansion is not automatic: authorisation for one corridor does not permit another, and an existing agreement should never be assumed to cover a new product merely because the same API can technically process it.
Strategically, the delegate model is "not necessarily the final destination" but stage one of a five-stage US strategy. It "does not guarantee future licensing approval, but it can demonstrate that the applicant understands the market and has previously operated under regulated supervision."
The named common mistakes: treating it as API sponsorship, overcomplicating the structure, building before reading the compliance manual, assuming existing KYC transfers, ignoring settlement risk ("Authorization is not the same thing as irreversible money"), underestimating ACH fraud, settling to unrelated accounts, inflating volume claims, accepting the first commercial proposal, and ignoring billing commencement.
