From entities to activities: The evolution of the regulatory perimeter of the financial sector

From entities to activities: The evolution of the regulatory perimeter of the financial sector

For decades, much of financial regulation was built around a relatively straightforward question: What type of entity provides the service? The answer largely determined the applicable legal framework: banks, finance companies, insurers, cooperatives, electronic money institutions, and other institutions subject to authorization and supervision.

That model remains fundamental. However, the technological transformation of financial services is making the legal question increasingly complex.

Today, a company can offer payment services without being a bank, facilitate credit without necessarily assuming the credit risk, operate a digital wallet without directly holding users’ funds, or develop technology infrastructure through which a regulated entity provides certain financial services.

In this context, a company’s designation no longer necessarily determines, by itself, the regulatory treatment applicable to its activities.

 

From entity type to the nature of the activity

The evolution of financial services has resulted in a fragmentation of functions that were previously concentrated within a single institution.

A financial product may now involve a bank, payment service provider, technology company, remittance operator, infrastructure provider, commercial originator, and other participants, each performing a different function within the same transaction.

This raises a key question for legal analysis: What activity does each participant actually perform, and what risks does it assume?

The answer may be more relevant than how the company presents itself commercially.

A platform that defines itself as a “technology company” does not automatically fall outside the regulatory perimeter if, in practice, it performs activities that applicable law reserves for authorized entities. Likewise, a company participating in a financial process is not necessarily subject to the same regulatory framework as the regulated institution with which it works.

The key is to analyze the economic and legal substance of the transaction.

 

The business model as the starting point for regulatory analysis

This shift has an important implication for companies developing new financial products: regulatory analysis should no longer begin solely by reviewing the corporate structure or stated corporate purpose.

It should begin by understanding the business model.

 

Among other considerations, it is necessary to determine:

  • What does the product actually do, and what are its functionalities?
  • Who receives, manages, transfers, or holds the funds, and at what stage of the transaction?
  • Who assumes the financial risk, particularly credit, liquidity, or counterparty risk?
  • What role does each participant play: principal, agent, intermediary, technology provider, or infrastructure provider?
  • What contractual relationship exists among the different participants and with the end user?
  • What financial or personal information is collected, processed, and shared?

This analysis makes it possible to identify where the regulated activity actually takes place and, consequently, which authorizations, registrations, obligations, or restrictions may apply.

 

Relevance for Central America

The importance of this approach is particularly evident in Central America, where financial markets are incorporating new models involving payments, remittances, electronic money, digital lending, technology platforms, and embedded finance, while regulatory frameworks evolve at different speeds.

The region does not have a single regulatory model. Each jurisdiction has developed its own categories, authorization requirements, and supervisory mechanisms.

Therefore, a structure that is legally viable in one country cannot necessarily be replicated identically in another.

For a company seeking to operate regionally, this means that the analysis should not be limited to determining whether a license with the same name exists in each country. The real question is whether the activities comprising the business model fit within the regulatory categories existing in each jurisdiction and under what conditions those activities may be conducted.

This distinction is particularly important for cross-border models, in which a company may be incorporated in one country, use regulated providers in another, and provide services to users across several markets.

 

The regulatory perimeter challenge

The shift toward more activity-based regulation does not necessarily mean that entities have ceased to be relevant. Banks, insurers, financial institutions, and other authorized entities remain fundamental pillars of the financial system.

What is changing is how regulators determine which activities should fall within the regulatory perimeter and where responsibility should lie for the risks they generate.

This also presents a challenge for regulators: preventing technological innovation from being used to circumvent obligations designed to protect consumers, preserve the integrity of the financial system, and prevent money laundering and terrorist financing risks, while at the same time avoiding overly rigid regulation based on traditional categories that could create unnecessary barriers for business models that do not generate the same risks as conventional financial institutions.

The question, therefore, is not simply whether to regulate more or less. It is to determine what should be regulated, why, and at what point in the financial value chain responsibility should lie.

 

From “who are you?” to “what do you do?”

For financial and technology companies, this shift in perspective has a practical consequence: regulatory analysis should be part of product design rather than a review conducted after development is complete.

Before launching a new service, entering a market, or replicating an existing model in another jurisdiction, it is essential to map the activities that actually comprise the operation, the flow of funds, the participants involved, and the risks assumed by each of them.

The question is no longer simply: Are we a regulated entity?

We should also ask: Is any of the activity we perform regulated?

And, from there: What regulatory framework applies, what obligations does it create, and what structure would allow the business model to operate in a legally viable manner?

This evolution from entities toward activities, functions, and risks does not eliminate the importance of licenses or traditional regulatory categories. Rather, it complements them with a more precise understanding of the economic reality underlying new financial models.

In an increasingly modular, technology-driven, and cross-border financial market, understanding where the regulatory perimeter begins and ends will be one of the most relevant legal considerations for those designing, investing in, and operating new financial services in Central America.

Author

Carlos Romero Rizo

Carlos Romero Rizo

Senior Counsel

Nicaragua