11/11/2025 | Press release | Distributed by Public on 11/11/2025 09:32
Nov 11, 2025
Categories:
Banking On ItPublications
Authors:
J. Dylan Grafe Nancy Eff Presnell William T. Repasky
Arkansas House Bill 1467 (HB1467), enacted into law in April of 2025, introduced a number of new money transmission registration and operation requirements, each of which are particularly relevant to operators of cryptocurrency kiosks.
HB1467 updates the currently enacted Arkansas Uniform Money Services Act, including adding onerous requirements for kiosk operators. Arkansas is taking a strong and broad stance to try to stop bad actors in the state from using cryptocurrency kiosks; however, this comes at the expense of money transmitters and kiosk operators who will see significant increases in compliance requirements and costs.
Generally, HB1467 implements changes which (1) establish a recission right for customers, (2) standardizes required disclosures to customers, (3) impact kiosk operators economically, and (4) require implementation of certain compliance and data security programs.
Certain financial regulatory regimes require that consumers be afforded the right to rescind certain transactions for a period of time. This occurs most notably with providers of remittance transfers (i.e., a transfer of funds from a U.S. person to a non-U.S. person) where a 30-minute cancellation window must be afforded to consumers after they initiate a remittance transfer.
With HB1467, Arkansas has built a statutory requirement where new customers may be afforded a recission right if certain criteria are met which relate to the customer believing that fraud is at play. HB1467requires that kiosk operators allow new customers the right to cancel and receive a full refund for any fraudulent virtual currency transactions that occurred not later than 72 hours after they registered as a customer of the owner or operator of the virtual currency kiosk. Refund requests must be submitted within 14 days after the last virtual currency transaction that occurred during the 72-hour period. Additionally, to exercise their recission right, new customers must: (1) contact the owner or operator of the virtual currency kiosk and a government or law enforcement agency to inform them of the fraudulent nature of the virtual currency transaction; and (2) file a report with a government or law enforcement agency memorializing the fraudulent nature of the virtual currency transaction.
This recission right poses a large operational hurdle, as kiosk operators must consider how to implement this right from a technological standpoint (building it into the machine's operating flows) and coordinate with sufficient staffing to be able to intake potential recission claims.
Often, kiosk operators have already adopted certain warnings and specific transaction information disclosures as part of standard kiosk operations. Arkansas HB1467, however, codifies a set of required warnings and disclosures, the latter of which may require operators to build out functionalities that allow kiosks to provide the following newly required-to-be-disclosed information to customers:
Additionally, before opening a customer's account, the kiosk operator needs to disclose (1) the customer's potential liability for unauthorized transactions, (2) any right for the customer to stop payment, (3) when a kiosk operator will disclose information about the customer to third parties, (4) the customer's right to get a receipt, (5) and any other customary disclosures.
In addition to the recission right, which will undoubtedly impact the required functionalities of kiosks, there are several other requirements impacting the ways that kiosk operators must design kiosks. Of note, though, many of these additional functionalities now required by Arkansas HB1467 have been commonplace among the industry. These requirements include:
Arkansas HB1467introduces a few key provisions which may impact the personnel and training of kiosk operators. While the Bank Secrecy Act (BSA) imposes certain requirements on money transmitters, HB1467 goes above this and prescribes certain requirements of compliance officers. This may impact the organizational structure within kiosk operators, particularly early-stage operators who are closely held and managed by a limited number of owners and managers. Consider the requirements below:
While money transmitters are required to comply with a number of requirements under the BSA, as well as other laws which states may adopt, HB1467adds additional requirements that are aimed at reducing elder financial abuse through the use of kiosks. These include:
Certain states proscribe rules regarding limitations on customers' use of the services of money transmitters. Recently, states, including Arkansas through HB1467, have significantly limited the ability for customers to freely interact with and use kiosk operator's services by implementing limitations on number and size of transactions in hopes that such limitations will prevent fraud and abuse. HB1467 sets forth other miscellaneous restrictions, while also providing a clear mechanism for consumers to make claims directly against the surety bond of money transmitters. Below are some provisions in this vein from HB1467:
HB1467 classifies all "money services business licensed under [the Uniform Money Services Act]" as "financial institutions" within its Data Security for Money Services provisions, in addition to traditional money services businesses. As such, virtual currency kiosk owners and operators are required to meet the information security program requirements enacted within HB1467.
These requirements may pose significant challenges to virtual currency kiosk owners and operators depending on the size of their business. While traditional money services providers will likely have more experience in dealing with the regulatory frameworks imposed by laws such as Arkansas' Uniform Money Services Act, the inclusion of virtual currency kiosk owners and operators may be these businesses' first encounter with government-imposed information security regulations.
HB1467 requires that financial institutions (financial institutions, as noted above, are defined as any money services business licensed under Arkansas' Uniform Money Services Act) put in place a written information security program. Broadly, this program is required to contain administrative, technical, and physical safeguards appropriate to the financial institution's size and complexity, the nature and scope of the financial institution's activities, and the sensitivity of any customer information the financial institution holds. However, on a more technical level, financial institutions in Arkansas are now required by law to institute what were previously merely industry best practices. Although these requirements are absolutely in the interest of all financial institutions to achieve, doing so may present a challenge to mid-size financial institutions that only just meet the applicability threshold of the Data Security for Money Services provisions of HB1467 but that do not have the resources to fully implement a robust information security program.
After the passage of Arkansas HB1467, financial institutions are required to designate a qualified individual to lead their information security program and base their information security program on a risk assessment which: "(A) identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of the information; and (B) assess the sufficiency of any safeguards in place to control these risks."
The risk assessment must be documented in writing and include: "(A) criteria for the evaluation and categorization of identified security risks or threats the financial institution faces; (B) criteria for the assessment of the confidentiality, integrity, and availability of the financial institution's information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats the financial institution faces; and (C) requirements describing how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks." Finally, financial institutions are now required to "periodically perform additional risk assessments that: (A) reexamine the reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of customer information; and (B) reassess the sufficiency of any safeguards in place to control these risks."
Once a risk assessment has been completed, financial institutions must design and implement safeguards to control the risks identified through their risk assessment. HB1467 gives a non-exhaustive list of controls that the financial institution is required to put in place. These safeguards include:
Financial institutions are also required to regularly test or otherwise monitor the effectiveness of their information security program and the requirements outlined above. Alternatively, they can conduct annual penetration tests and vulnerability assessments biannually and whenever there are material changes to the financial institution's operations or business arrangements and circumstances the financial institution knows or has reason to know may have a material impact on its information security program. Financial institutions are required adjust their information security program based on the steps taken above.
Arkansas HB1467 also requires that financial institution personnel be able to enact the information security policy by receiving security awareness training, utilizing qualified information security personnel, providing information security personnel with security updates and training, and verifying that key information security personnel maintain knowledge of changing information security threats and countermeasures.
HB1467additionally requires that financial institutions oversee their contractors by taking reasonable steps to select and retain service providers capable of maintaining appropriate safeguards, require contractual terms with their contractors, and assess their contractors based on a risk analysis.
HB1467 requires that financial institutions establish an incident response plan designed to respond to, and recover from, security incidents which materially affect the confidentiality, integrity, or availability of the customer information in their control. The incident response plan must address:
For more information or assistance navigating these new requirements under Arkansas HB1467, please contact the authors or any attorney with our Data, Digital Assets, and Technology or Consumer Financial Services and Protection practices.
Subscribe to receive email updates and choose your topics.