All countries
United States

United States

Largely Compliant Effectiveness: Substantial Assessed 2016 by FATF

111

Regulations covered

7,630

Rules extracted

109,211

Obligations scored

Largely Compliant

FATF rating

Country overview

Key facts

Capital Washington, D.C.
Population 334.0M
GDP (USD) $27.4T
Currency US Dollar (USD)
Region North America
CPI Score 69/100

FATF assessment

Assessment body FATF
Assessment year 2016
Overall compliance Largely Compliant
Overall effectiveness Substantial
FATF profile View source →

Technical compliance

FATF Recommendations R1-R40 ratings from the 2016 mutual evaluation

9

Compliant

23

Largely Compliant

5

Partially Compliant

3

Non-Compliant

Effectiveness ratings

Immediate Outcomes IO1-IO11 from the 2016 mutual evaluation

IO1 Substantial
IO2 Substantial
IO3 Moderate
IO4 Moderate
IO5 Low
IO6 Substantial
IO7 Substantial
IO8 Substantial
IO9 Substantial
IO10 Substantial
IO11 Moderate

AuditDSS regulation coverage

We cover 111 United States regulations with 7,630 rules and 109,211 obligations scored

Healthcare

🇺🇸 regulation

ADA Title III

Prohibits discrimination on the basis of disability in places of public accommodation and commercial facilities, requiring accessible design and reasonable modifications to policies and practices.

55 rules 548 obligations DOJ
🇺🇸 regulation

Anti-Kickback Statute

Prohibits offering, paying, soliciting, or receiving anything of value to induce or reward referrals of items or services covered by federal healthcare programs. Relevant to healthcare providers, suppliers, and entities participating in Medicare or Medicaid.

38 rules 1,238 obligations HHS-OIG
🇺🇸 regulation

CLIA Lab Standards

Establishes quality standards for laboratory testing to ensure the accuracy, reliability, and timeliness of patient test results. Applies to all facilities performing clinical laboratory testing on human specimens in the United States.

104 rules 1,119 obligations CMS
🇺🇸 regulation

Stark Law

Prohibits physician self-referrals for designated health services payable by Medicare or Medicaid, unless a specific exception applies. Applies to physicians and entities that furnish designated health services.

94 rules 1,871 obligations CMS
🇺🇸 statute

CIRCIA

Requires US critical infrastructure operators to report significant cyber incidents to CISA.

13 rules 159 obligations US-CISA
🇺🇸 regulation

Medicare Conditions of Participation

CMS conditions that hospitals must meet to participate in Medicare and Medicaid covering patient rights, quality assessment, infection control, and medical staff. Applies to Medicare-certified hospitals.

12 rules 192 obligations US-CMS
🇺🇸 regulation

42 CFR 483 Nursing Facility CoP

CMS conditions of participation for skilled nursing facilities covering resident rights, quality of care, pharmacy services, and infection control. Applies to nursing facilities participating in Medicare and Medicaid.

12 rules 194 obligations US-CMS

Banking & Financial Services

🇺🇸 regulation

BSA CDD

Requires financial institutions to establish and maintain written customer due diligence procedures, including identifying and verifying beneficial owners of legal entity customers. Applies to banks, brokers, mutual funds, and other covered financial institutions.

67 rules 1,047 obligations FINCEN
🇺🇸 legislation

CCPA/CPRA

Grants California consumers rights over their personal information, including the right to know, delete, and opt out of the sale or sharing of their data. Applies to businesses meeting specified revenue, data volume, or data sale thresholds.

46 rules 572 obligations CA-AG
🇺🇸 regulation

CPSC Information Disclosure 16 CFR 1101

Governs the Consumer Product Safety Commission's procedures for disclosing product safety information to the public, including manufacturer notification and comment requirements. Relevant to consumer product manufacturers and importers.

27 rules 151 obligations CPSC
🇺🇸 regulation

CRA Reg BB

Requires federal financial regulators to assess how well banks and thrifts meet the credit needs of their communities, including low- and moderate-income neighborhoods. Applies to depository institutions.

27 rules 950 obligations FRB
🇺🇸 regulation

DHS Privacy / FOIA

Governs the Department of Homeland Security's handling of personally identifiable information and Freedom of Information Act requests, including privacy impact assessments and data protection requirements.

39 rules 340 obligations DHS
🇺🇸 regulation

ERISA Fiduciary

Sets standards of conduct for fiduciaries managing employee benefit plans, including duties of loyalty, prudence, and diversification. Applies to plan administrators, trustees, and investment managers of private-sector retirement and health plans.

26 rules 920 obligations DOL-EBSA
🇺🇸 statute

FCPA

Prohibits the payment of bribes to foreign government officials to obtain or retain business and requires issuers to maintain accurate books and records and adequate internal accounting controls. Applies to U.S. persons, domestic concerns, and issuers of securities.

13 rules 94 obligations DOJ-FCPA
🇺🇸 regulation

FCRA Reg V

Regulates the collection, dissemination, and use of consumer credit information, establishing accuracy, fairness, and privacy requirements. Applies to consumer reporting agencies, furnishers of information, and users of consumer reports.

43 rules 751 obligations CFPB
🇺🇸 regulation

FinCEN BSA

Bank Secrecy Act / Anti-Money Laundering — 31 CFR Chapter X

291 rules 2,640 obligations FINCEN
🇺🇸 regulation

Safeguards Rule

Requires non-banking financial institutions to develop, implement, and maintain a comprehensive information security program to protect customer information. Applies to mortgage brokers, motor vehicle dealers, payday lenders, and other entities under FTC jurisdiction.

6 rules 176 obligations FTC
🇺🇸 regulation

GLBA Reg P

Requires financial institutions to explain their information-sharing practices to customers and to safeguard sensitive data, including providing opt-out rights for certain disclosures. Applies to banks, securities firms, insurance companies, and other financial service providers.

17 rules 496 obligations CFPB
🇺🇸 standard

AICPA TSC (SOC 2)

AICPA criteria for evaluating controls over security, availability, processing integrity, confidentiality, and privacy of information systems. Applies to service organisations undergoing SOC 2 examinations.

13 rules 58 obligations US-AICPA
🇺🇸 regulation

NCUA Credit Unions

Sets organizational, operational, and regulatory requirements for federal credit unions, covering membership, lending, investments, and governance. Applies to federally chartered credit unions.

24 rules 511 obligations NCUA
🇺🇸 standard

NIST SP 800-53 Rev 5

Provides a comprehensive catalog of security and privacy controls for federal information systems and organizations. Used by federal agencies and contractors to protect information systems in accordance with FISMA requirements.

1196 rules 2,844 obligations NIST
🇺🇸 framework

NIST CSF 2.0

Provides a voluntary framework of cybersecurity outcomes organized around six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. Applicable to organizations of all sizes and sectors seeking to manage cybersecurity risk.

6 rules 103 obligations NIST
🇺🇸 state-regulation

23 NYCRR 500

Requires financial services companies regulated by the New York Department of Financial Services to implement and maintain a cybersecurity program, including risk assessments, access controls, and incident response. Applies to banks, insurers, and other DFS-regulated entities operating in New York.

21 rules 183 obligations NYDFS
🇺🇸 regulation

OFAC Sanctions

Administers and enforces economic and trade sanctions based on U.S. foreign policy and national security goals, prohibiting transactions with sanctioned countries, entities, and individuals. Applies to all U.S. persons and entities.

65 rules 491 obligations OFAC
🇺🇸 regulation

OSHA Recordkeeping

Requires employers to record and report work-related injuries, illnesses, and fatalities. Applies to most private-sector employers, with limited exemptions based on industry and establishment size.

30 rules 313 obligations OSHA
🇺🇸 regulation

OSHA General Industry

Establishes occupational safety and health standards for general industry workplaces, covering hazard communication, electrical safety, machine guarding, personal protective equipment, and numerous other hazards. Applies to most private-sector employers.

203 rules 15,824 obligations OSHA
🇺🇸 standard

PCI DSS

Defines security requirements for organizations that store, process, or transmit payment card data, covering network security, access control, encryption, and monitoring. Applies to merchants, payment processors, acquirers, and service providers in the payment card ecosystem.

342 rules 1,532 obligations PCI-SSC
🇺🇸 regulation

Regulation B

Prohibits discrimination in credit transactions on the basis of race, color, religion, national origin, sex, marital status, age, or receipt of public assistance. Applies to creditors, including banks, finance companies, and retailers that extend credit.

30 rules 428 obligations CFPB
🇺🇸 regulation

Reg CC

Governs the availability of funds deposited in transaction accounts, check collection procedures, and return of unpaid checks. Applies to depository institutions including banks, savings associations, and credit unions.

39 rules 668 obligations FRB
🇺🇸 regulation

Reg DD

Requires depository institutions to provide uniform disclosures about interest rates, fees, and terms for deposit accounts so consumers can make informed comparisons. Applies to banks, savings associations, and credit unions.

11 rules 152 obligations CFPB
🇺🇸 regulation

Regulation E

Establishes the rights, liabilities, and responsibilities of participants in electronic fund transfer systems, including ATM transactions, debit card payments, and direct deposits. Applies to financial institutions offering electronic fund transfer services to consumers.

27 rules 741 obligations CFPB
🇺🇸 regulation

Regulation O (Insider Lending)

Restricts extensions of credit by member banks to their executive officers, directors, and principal shareholders, imposing lending limits and requiring board approval. Applies to Federal Reserve member banks and their insiders.

12 rules 175 obligations FRB
🇺🇸 regulation

Regulation W (Affiliate Transactions)

Imposes quantitative limits and collateral requirements on transactions between banks and their affiliates to protect depository institutions from inter-affiliate risk. Applies to Federal Reserve member banks and their affiliates.

28 rules 428 obligations FRB
🇺🇸 regulation

Regulation X

Governs the servicing of federally related mortgage loans and requires disclosures to borrowers about settlement costs, escrow accounts, and mortgage servicing transfers. Applies to mortgage lenders, brokers, and servicers.

31 rules 766 obligations CFPB
🇺🇸 regulation

Regulation Y

Governs bank holding company formations, acquisitions, and permissible nonbanking activities, and sets capital adequacy and risk management requirements. Applies to bank holding companies and their subsidiaries.

114 rules 1,928 obligations FRB
🇺🇸 regulation

Regulation Z

Requires creditors to provide uniform disclosures of credit terms, including annual percentage rates, finance charges, and payment schedules, to enable consumers to compare credit offers. Applies to most consumer credit transactions including mortgages, credit cards, and installment loans.

59 rules 3,133 obligations CFPB
🇺🇸 rule

S7-10-22

Requires public companies to disclose climate-related risks, governance, strategy, greenhouse gas emissions, and the financial impacts of severe weather events and transition activities. Applies to SEC-registered domestic and foreign private issuers.

13 rules 78 obligations SEC
🇺🇸 legislation

SOX (Sarbanes-Oxley)

Establishes requirements for corporate governance, internal controls, financial reporting, and auditor independence to protect investors from fraudulent accounting practices. Applies to publicly traded companies and their audit firms.

69 rules 249 obligations SEC
🇺🇸 standard

AICPA DC Section 200 (SOC 2 Description Criteria)

AICPA criteria for describing a service organisation system in SOC 1 and SOC 2 reports, covering system boundaries, controls, and complementary controls. Applies to service organisations and their auditors.

9 rules 27 obligations US-AICPA
🇺🇸 standard

FedRAMP Rev 5

US federal government security control baselines for cloud service providers at Low, Moderate, and High impact levels. Applies to cloud service providers seeking FedRAMP authorisation.

19 rules 183 obligations US-GSA
🇺🇸 legislation

FLSA

US federal law establishing minimum wage, overtime pay, recordkeeping, and child labour standards. Applies to employers and employees in the private sector and government.

10 rules 157 obligations US-DOL
🇺🇸 legislation

FMLA

US federal law entitling eligible employees to unpaid, job-protected leave for family and medical reasons. Applies to employers with 50 or more employees and their eligible workers.

10 rules 158 obligations US-DOL
🇺🇸 standard

HITRUST CSF v11

Certifiable security framework harmonising requirements from regulations and standards including HIPAA, NIST, and ISO 27001. Applies to healthcare organisations and their business associates handling sensitive data.

14 rules 137 obligations US-HITRUST
🇺🇸 standard

NIST AI RMF 1.0

NIST framework for managing risks from AI systems covering governance, mapping, measuring, and managing AI risks throughout the AI lifecycle. Applies to organisations developing or deploying AI systems.

16 rules 62 obligations NIST
🇺🇸 standard

SOC for Cybersecurity

AICPA framework for examining an organisation cybersecurity risk management programme, covering description criteria and control criteria. Applies to organisations seeking independent cybersecurity assurance.

12 rules 32 obligations US-AICPA
🇺🇸 standard

SSAE 18

AICPA attestation standard governing examination, review, and agreed-upon procedures engagements including SOC 1 and SOC 2 reports. Applies to service auditors and service organisations.

9 rules 48 obligations US-AICPA
🇺🇸 legislation

Title VII

US federal law prohibiting employment discrimination based on race, colour, religion, sex, and national origin. Applies to employers with 15 or more employees, employment agencies, and labour organisations.

11 rules 174 obligations US-EEOC

Energy & Utilities

🇺🇸 statute

SB 253

Requires large public and private companies doing business in California to publicly disclose their Scope 1, 2, and 3 greenhouse gas emissions. Applies to entities with annual revenues exceeding $1 billion.

23 rules 120 obligations CA-LEG
🇺🇸 statute

SB 261

Requires covered entities doing business in California to prepare and disclose climate-related financial risk reports consistent with TCFD recommendations. Applies to entities with annual revenues exceeding $500 million.

24 rules 120 obligations CA-LEG
🇺🇸 regulation

EPA Lead RRP

Requires contractors performing renovation, repair, and painting activities that disturb lead-based paint in pre-1978 housing and child-occupied facilities to be certified and follow specific work practices. Relevant to renovation contractors and property owners.

47 rules 1,220 obligations EPA
🇺🇸 regulation

FERC 18 CFR 35

Governs the filing and regulation of rates, terms, and conditions for the sale and transmission of electric energy and natural gas in interstate commerce. Applies to public utilities, power marketers, and natural gas companies.

50 rules 1,059 obligations FERC
🇺🇸 regulation

CFATS Chemical Security

Establishes security standards for high-risk chemical facilities, requiring vulnerability assessments, site security plans, and personnel surety measures. Applies to facilities possessing specified chemicals of interest above threshold quantities.

33 rules 343 obligations DHS-CISA
🇺🇸 regulation

PHMSA HMR Part 171

Governs the classification, packaging, labeling, and transportation of hazardous materials by highway, rail, vessel, and air in the United States. Applies to shippers, carriers, and packaging manufacturers handling hazardous materials.

24 rules 987 obligations PHMSA
🇺🇸 regulation

49 CFR 1580

Sets security requirements for pipeline and rail transportation systems, including cybersecurity measures, personnel vetting, and security planning. Applies to owners and operators of pipeline facilities and freight and passenger rail systems.

10 rules 81 obligations TSA
🇺🇸 regulation

TSCA PCB Rules 40 CFR 761

Regulates the manufacture, processing, distribution, use, and disposal of polychlorinated biphenyls (PCBs) and PCB-containing items. Applies to facilities and persons that handle, store, or dispose of PCB materials.

109 rules 1,970 obligations EPA
🇺🇸 standard

NERC CIP

Mandates cybersecurity standards for operators of the North American bulk electric system.

11 rules 46 obligations US-NERC
🇺🇸 standard

NERC Reliability Standards

NERC reliability standards for bulk electric system planning, operations, and performance excluding critical infrastructure protection. Applies to utilities, grid operators, and generation owners in North America.

12 rules 183 obligations US-NERC

Securities & Capital Markets

🇺🇸 regulation

CFTC General Regulations

Sets general regulations for commodity futures and derivatives markets, covering registration, reporting, recordkeeping, and business conduct standards for market participants. Applies to futures commission merchants, commodity pool operators, and other CFTC-regulated entities.

70 rules 2,105 obligations CFTC
🇺🇸 regulation

Investment Advisers Act

Regulates the registration, conduct, and fiduciary obligations of investment advisers, including recordkeeping, disclosure, and custody requirements. Applies to persons or firms that provide investment advice for compensation.

39 rules 784 obligations SEC
🇺🇸 regulation

Investment Company Act Rules

Sets regulatory requirements for publicly offered investment companies, including governance, capital structure, and operational restrictions. Applies to mutual funds, closed-end funds, unit investment trusts, and their advisers.

194 rules 2,456 obligations SEC
🇺🇸 regulation

Regulation S-K

Prescribes the non-financial disclosure requirements for registration statements and periodic reports filed with the SEC, covering business descriptions, risk factors, management discussion, executive compensation, and corporate governance. Applies to public reporting companies.

131 rules 2,622 obligations SEC
🇺🇸 regulation

Regulation S-X

Prescribes the form and content of financial statements and related schedules required in filings with the SEC. Applies to public reporting companies, investment companies, and their independent auditors.

117 rules 1,038 obligations SEC
🇺🇸 regulation

Regulation SHO/NMS/ATS

Establishes rules governing short selling, order execution, and alternative trading systems in U.S. securities markets, including locate and close-out requirements for short sales. Applies to broker-dealers, exchanges, and alternative trading systems.

97 rules 2,497 obligations SEC
🇺🇸 regulation

SEC Exchange Act Rules

Governs the trading of securities on secondary markets, establishing registration, reporting, proxy solicitation, and anti-fraud requirements. Applies to exchanges, broker-dealers, and publicly traded companies.

594 rules 10,161 obligations SEC
🇺🇸 regulation

SEC Securities Act Rules

Provides exemptions from SEC registration for certain private offerings of securities, establishing conditions under which issuers may sell securities without full public registration. Applies to issuers conducting private placements and their investors.

214 rules 2,888 obligations SEC

Technology & Software

🇺🇸 regulation

CMMC 2.0

Establishes a tiered cybersecurity maturity model that defense contractors must achieve to handle controlled unclassified information. Applies to organizations in the Department of Defense supply chain.

24 rules 584 obligations DOD
🇺🇸 regulation

COPPA

Imposes requirements on operators of websites and online services directed to children under 13, including obtaining verifiable parental consent before collecting personal information. Applies to commercial website and app operators.

13 rules 156 obligations FTC
🇺🇸 regulation

DFARS Cybersecurity

Imposes cybersecurity requirements on defense contractors for safeguarding covered defense information and reporting cyber incidents to the Department of Defense. Applies to contractors and subcontractors handling controlled unclassified information in the defense supply chain.

346 rules 7,483 obligations DOD
🇺🇸 regulation

FCC CPNI

Protects the confidentiality of customer proprietary network information held by telecommunications carriers, restricting its use and disclosure. Applies to telephone companies and interconnected VoIP providers.

8 rules 99 obligations FCC
🇺🇸 standard

NIST SP 800-171 Rev 2

Specifies security requirements for protecting controlled unclassified information (CUI) in nonfederal systems and organizations. Applies to contractors and other organizations that process, store, or transmit CUI on behalf of federal agencies.

124 rules 234 obligations NIST
🇺🇸 statute

FedRAMP

Provides a standardised security authorisation framework for cloud products used by US federal agencies.

14 rules 172 obligations US-GSA
🇺🇸 statute

FISMA

Requires US federal agencies to develop, implement, and maintain information security programs.

12 rules 174 obligations US-OMB

Insurance

🇺🇸 legislation

HIPAA

Establishes national standards for the protection of individually identifiable health information, including privacy, security, and breach notification requirements. Applies to covered entities such as health plans, healthcare providers, and healthcare clearinghouses, as well as their business associates.

102 rules 1,696 obligations HHS-OCR
🇺🇸 model-law

Model Law #668

Requires insurance licensees to develop, implement, and maintain an information security program to protect nonpublic information from unauthorized access. Applies to insurers, agents, and other entities licensed by state insurance departments.

11 rules 96 obligations NAIC
🇺🇸 model-law

Model Law #440

Regulates transactions within insurance holding company systems, requiring registration, reporting, and prior approval of material transactions between affiliated insurers and their parent companies. Applies to insurers that are part of a holding company group.

12 rules 84 obligations NAIC
🇺🇸 model-law

Model Law #205

Requires insurers to engage independent auditors and establish internal audit functions, including audit committee requirements and management reporting on internal controls. Applies to insurance companies subject to state financial regulation.

12 rules 87 obligations NAIC
🇺🇸 model-law

Model Law #505

Requires large insurers and insurance groups to conduct an Own Risk and Solvency Assessment, evaluating the adequacy of their risk management framework and capital position. Applies to insurers meeting specified premium or group premium thresholds.

7 rules 70 obligations NAIC
🇺🇸 model-law

Model Law #785

Establishes the conditions under which a ceding insurer may take credit for reinsurance on its financial statements, including collateral and reinsurer certification requirements. Applies to insurers entering into reinsurance agreements.

10 rules 72 obligations NAIC
🇺🇸 model-law

Model Law #880

Defines and prohibits unfair or deceptive acts and practices in the insurance business, including misrepresentation, false advertising, and unfair claims settlement. Applies to insurers, agents, and other persons engaged in the business of insurance.

15 rules 80 obligations NAIC

Score your United States compliance

Run probabilistic risk scores across 109,211 United States obligations. See exactly where your gaps are.

Get started