Equal AccountabilityDoes Not Mean Identical Compliance
Why bootstrapped financial startups should be judged by the seriousness of their controls, not by whether they can reproduce the compliance machinery of JPMorgan Chase or Western Union
Founder & CEO, Crypto Dispensers
I was born in the United States and have lived in Chicago my entire life. My father came to this country from Palestine. My mother was born here in Chicago. I grew up believing in the American Dream because I watched my parents work for it.
My father operated a grocery store. I spent years working there with him. That store taught me lessons no classroom could have taught me about money, responsibility, reputation, and survival. When you run a neighborhood business, every mistake has a face. You know the customer standing across the counter. You know the employee depending on Friday's paycheck. You know that trust can take years to build and one careless decision to lose.
I later studied philosophy and political science. I attended law school for one year before deciding that my future was in entrepreneurship. Philosophy taught me how to examine first principles. Politics taught me how institutions use power. Law school taught me that words, intent, evidence, and procedure matter. Entrepreneurship taught me that every idea eventually has to survive contact with reality.
At 37 years old, after nearly a decade building in financial technology, I have learned that compliance lives at the intersection of all those lessons.
It is about rules, but it is also about judgment. It is about systems, but it is also about people. It is about protecting the public, but it is also about making sure regulation does not become a wall that only the largest corporations can afford to climb.
That is the concern I want to address.
There is an expectation forming around financial compliance that almost no bootstrapped startup can satisfy. It is not simply the expectation that a company follow the law. Every financial company should follow the law. The deeper problem is the assumption that a young company should somehow possess the people, software, institutional knowledge, legal budget, and operational machinery of the largest financial corporations in the world.
A startup may have one compliance officer working directly with its founders, engineers, customer support staff, banking partners, consultants, and outside attorneys. JPMorgan Chase can distribute those responsibilities across specialized departments, proprietary systems, internal investigators, global law firms, audit teams, committees, and layers of management.
These organizations do not begin in the same place. They do not have the same resources. They do not create the same scale of risk.
They should be held to the same expectation of honesty and integrity. They should not be expected to build identical compliance machinery.
A Small Company Does Not Get a Pass
I want to be clear about something from the beginning. A startup does not deserve an exemption from the law because it is small.
If a company moves money or provides access to financial assets, compliance is part of the product. Identity verification, transaction monitoring, fraud prevention, recordkeeping, reporting, cybersecurity, escalation procedures, training, and customer protection cannot be postponed until the company becomes profitable.
Customers should not carry the cost of a founder's inexperience. Neither should the financial system.
But demanding responsibility is not the same as demanding perfection. Requiring an effective program is not the same as requiring every company to recreate the infrastructure of a global bank.
A fifteen-person company cannot employ hundreds of specialists. It cannot purchase every available compliance platform. It cannot build proprietary surveillance software for every conceivable risk. It cannot retain an army of lawyers every time a difficult question appears.
What it can do is take its actual risks seriously. It can build reasonable controls around its products, customers, transaction volume, payment methods, and geographic reach. It can give its compliance officer real authority. It can retain outside expertise where internal experience is limited. It can train its people, document its decisions, investigate warning signs, file required reports, test its program, and improve when weaknesses are found.
That is serious compliance.
If the practical condition for being treated as legitimate is possessing the same compliance department as a Fortune 500 corporation, then compliance becomes more than a public safeguard. It becomes a competitive moat protecting the largest corporations from the companies trying to challenge them.
No Compliance Program Prevents Everything
Compliance is often judged with the benefit of hindsight.
After a fraud occurs, every missed signal can appear obvious. Every imperfect judgment can be made to look suspicious. Every alert that did not produce the correct conclusion can be described as proof that the company never cared.
That is not how risk appears in real time.
Financial companies process legitimate activity while criminals are actively trying to disguise illegitimate activity. Scammers manipulate victims outside the company's systems. Customers can present valid identification while acting under another person's instructions. Information arrives in fragments. A transaction that appears ordinary when it occurs can look completely different months or years later, after investigators have collected evidence the company did not possess.
No honest compliance professional can promise that every unlawful transaction will be prevented. The proper questions are more demanding and more useful.
Did the company understand its material risks? Did it establish reasonable controls? Did the compliance officer have authority? Were alerts reviewed? Were suspicious facts investigated? Were required reports filed? Were consequential decisions documented? Did the company improve its program when experience exposed a weakness?
Intent also matters.
There is a profound legal and moral difference between knowingly joining a criminal agreement and operating a legitimate service that a criminal or scammer later chooses to misuse. Processing a transaction does not automatically establish knowledge of the crime behind it. It certainly does not, by itself, establish an agreement to participate in that crime.
That distinction should matter whether the financial institution operates from a skyscraper in Manhattan or a small office in Chicago.
The Largest Institutions Have Failed With Every Advantage
The public record shows that enormous resources do not produce perfect compliance.
In 2017, Western Union admitted that it willfully failed to maintain an effective anti-money-laundering program and failed to take effective action against agents involved in fraud and structuring. According to the Department of Justice, company employees repeatedly identified problematic agent locations, yet effective corrective action was not taken. Western Union forfeited $586 million, entered a deferred prosecution agreement, and agreed to strengthen its anti-fraud program.
JPMorgan Chase entered a deferred prosecution agreement in 2014 for Bank Secrecy Act violations connected to Bernard Madoff's multibillion-dollar Ponzi scheme. The bank paid $1.7 billion. The government stated that the bank failed to file a suspicious activity report in the United States despite maintaining its relationship with Madoff for decades.
JPMorgan entered another deferred prosecution agreement in 2020 involving criminal charges related to unlawful trading activity in precious-metals and United States Treasury markets. The company agreed to pay more than $920 million and enhance its compliance program. After the three-year term expired, the government moved to dismiss the case because JPMorgan had fulfilled its obligations under the agreement.
Wells Fargo admitted that employees opened millions of accounts or products without customer authorization or under false pretenses. According to the Department of Justice, the conduct continued for years, involved false records and misuse of customer identities, and was driven by unrealistic sales goals. Wells Fargo paid $3 billion and received a deferred prosecution agreement that credited cooperation, management changes, remediation, and improvements to its compliance program.
These were significant penalties. I am not arguing that nothing happened to these companies.
My point is different.
When some of the largest financial institutions in the world experienced widespread failures, the government still recognized degrees of responsibility. It considered cooperation. It credited remediation. It allowed new management, stronger controls, and institutional reform to matter. It used deferred prosecution agreements and structured oversight instead of treating every failure as proof that the entire organization shared a criminal purpose.
Those principles should not belong only to corporations large enough to negotiate from a position of strength.
The Unequal Value of a Second Chance
A multibillion-dollar corporation can pay a substantial penalty, hire new executives, enter an oversight agreement, and continue operating. Its shareholders may suffer. Its reputation may be damaged. Individual employees may face consequences. But the institution usually survives.
For a bootstrapped company, an accusation alone can become an existential event.
Banks may close accounts. Vendors may terminate contracts. Partners may withdraw. Investors may disappear. Customers may lose confidence before a court has heard the evidence. The cost of defending the company can consume the same resources needed to operate, protect customers, and strengthen compliance.
This creates a disturbing imbalance. The institutions with the greatest resources to prevent misconduct are often the institutions most capable of surviving it. The companies with the fewest resources can be destroyed before they receive a meaningful opportunity to show that an imperfect decision was not intentional participation in a crime.
Government should not ignore wrongdoing by a small company. It should not reserve cooperation credit, proportionality, remediation, and the possibility of institutional survival for the largest companies in America either.
If a global bank can be evaluated according to its intent, cooperation, corrective action, management changes, and improved compliance, then a startup deserves to be evaluated under the same principles.
Competence Is Built, Not Merely Inherited From a Résumé
The same misunderstanding appears in the way people evaluate a startup's compliance officer.
A major bank can recruit someone who has already spent twenty years working inside another major bank. A startup may designate a founder, cofounder, or early employee who understands the company's customers, technology, transaction flows, and risks more intimately than any outside executive could understand them on the first day.
That person may not arrive with a wall of certificates, industry awards, or a résumé filled with previous compliance-officer titles. That fact alone does not make the appointment illegitimate.
Every experienced professional was inexperienced once. Competence is developed through serious work, training, study, testing, independent review, mentorship, judgment, and time. In a new industry, expertise often develops inside the companies confronting the problems first. There was no established career path for many cryptocurrency compliance roles when the industry began to grow. Someone had to learn the work while doing it.
The meaningful questions are whether the compliance officer became competent, understood the business and its risks, possessed real authority, had access to necessary information and resources, received appropriate training, and actually administered the program.
Even federal examination guidance focuses on competence, authority, independence, and access to resources. A prior title may be relevant evidence. It is not the complete test of whether someone can do the job.
A startup's compliance officer also does not have to build every component alone.
A responsible young company can retain experienced AML consultants to help design and update its written program. It can work with attorneys who specialize in cryptocurrency, fintech, licensing, the Bank Secrecy Act, and regulatory matters. Those attorneys can interpret changing requirements, advise leadership, communicate with regulators, and help the company respond when questions arise.
Independent firms can review the AML program and test whether controls are functioning. Transaction-monitoring providers and trained analysts can help identify activity requiring further investigation. Outside experts can recommend remediation and help the company develop stronger procedures as its products and volume grow.
The designated compliance officer can coordinate that work, oversee day-to-day compliance, understand the decisions being made, and ensure that required reports, including suspicious activity reports and currency transaction reports when applicable, are properly considered and filed.
Hiring outside professionals does not transfer the company's legal responsibility. The company remains accountable for the program. But seeking qualified help is evidence of an effort to build responsibly. It should not be twisted into evidence that the designated compliance officer was a figurehead.
At Crypto Dispensers, Sabreen Rihan was not simply my wife. She was my cofounder and the company's designated compliance officer. We started the business together. She understood its customers, operations, and risks because she helped build those systems from the beginning.
Sabreen did not enter the role after a conventional career inside the compliance department of a major bank. She learned the company and its obligations while helping build it. We did not expect her to perform that work alone.
At different stages, Crypto Dispensers engaged outside AML professionals, digital-asset and fintech attorneys, licensing advisers, independent reviewers, transaction-monitoring resources, and other specialists to help develop, examine, and strengthen our compliance systems.
It is fair to examine whether that structure worked. It is fair to examine Sabreen's knowledge, authority, training, decisions, and execution. It is fair to identify a control that should have been stronger and ask whether the company responded appropriately.
It is not fair to begin with the conclusion that a compliance officer without prestigious badges or a long institutional résumé must have been decorative, unqualified, or part of a sham.
That is not analysis. It is a credential bias that favors incumbents.
If previous employment at a major bank becomes the unwritten qualification for leading compliance at a startup, then the largest institutions will control both the market and the acceptable definition of professional legitimacy. New expertise will have no place to develop. New companies will be told they need experience that can only be acquired by first working for the competitors they are trying to challenge.
That cannot be the only path to legitimacy in America.
What My Experience Has Forced Me to Ask
I founded Crypto Dispensers in 2017 and built it without the balance sheet of a bank, the backing of a public corporation, or a family fortune waiting behind me.
The company began with physical Bitcoin ATMs and developed into an account-based platform designed to connect ordinary customers with digital assets through cash and other payment methods. Behind that access sat identity verification, transaction controls, banking relationships, fraud prevention, customer support, reporting obligations, outside vendors, attorneys, consultants, and a regulatory environment that was changing while we were building inside it.
We were learning a new industry while the industry itself was being defined.
We were not JPMorgan Chase. We were not Western Union. We did not have unlimited personnel, proprietary global surveillance systems, or hundreds of lawyers. We had to select tools, build processes, listen to advisers, study the rules, respond to emerging threats, make difficult judgment calls, and improve the company while keeping it alive.
That does not make every decision correct. It does not make the company immune from examination. It does not place Sabreen, me, or Crypto Dispensers above the law.
It does mean our conduct should be judged according to what we knew, what we intended, what controls we established, what professional support we sought, what actions we took, and what risks were reasonably visible at the time. It should not be judged according to an imaginary standard of perfect prevention.
Crypto Dispensers and I have been charged with conspiracy to commit money laundering. We have pleaded not guilty and contest the allegations. An indictment is an accusation. It is not proof of guilt. The government retains the burden of proving its case in court.
I will not attempt to try that case through an essay. The courtroom is where the evidence must be tested.
But this experience has forced me to ask a question that reaches far beyond one company and one founder.
Are enforcement principles being applied consistently when a small cryptocurrency business is examined under a microscope while major financial institutions with documented, large-scale compliance failures receive structured opportunities to cooperate, remediate, and continue?
I cannot claim to know another person's motives. I can describe the effect.
A small financial company can face destruction while an enormous institution can treat even a historic penalty as a survivable cost followed by another compliance plan. The large institution receives an opportunity to demonstrate improvement. The startup may be presumed illegitimate because it did not begin with the resources of the institution it hoped to compete against.
That difference deserves serious public scrutiny.
A Fairer Standard
A fair compliance standard would not ask whether a startup looked like a global bank. It would ask whether the company's program was reasonably designed for its actual products, customers, transaction volume, payment methods, geography, and risk.
It would examine:
- whether leadership treated compliance as a real responsibility;
- whether the designated officer developed the necessary competence;
- whether that officer had sufficient authority, independence, information, and resources;
- whether the company used qualified outside support where internal expertise was limited;
- whether controls addressed the risks the company could reasonably identify;
- whether employees escalated warning signs and investigated suspicious activity;
- whether required reports were properly evaluated and filed;
- whether the company preserved evidence of its decisions;
- whether failures were isolated, negligent, reckless, or intentional;
- whether leadership cooperated, learned, and remediated problems;
- and whether the government can prove knowledge and criminal intent instead of inferring them from imperfection.
Resources should be considered honestly. A startup should fund compliance before executive luxuries or reckless expansion. A founder who chooses personal enrichment over basic controls should not blame the company's size.
But a responsible startup should not be condemned because it could not buy technology designed for the largest banks in the world.
Expectations should rise as the company grows. A program that is responsible at ten thousand transactions may be inadequate at ten million. Every new product, payment rail, jurisdiction, vendor, and customer segment can create new obligations and require stronger controls.
Proportionality is not permission to remain immature. It is the obligation to build responsibly at every stage.
Compliance Must Not Become an Incumbent Moat
My father came to this country because America offered the possibility that hard work could become ownership and that ownership could become independence.
I still believe in that promise.
America benefits when people build companies without first asking established institutions for permission. It benefits when new businesses challenge concentrated industries, create better products, and reach customers the old system has overlooked.
Innovation rarely begins with the resources of the incumbent it hopes to challenge.
If regulators expect a startup to possess JPMorgan's infrastructure before the startup can be treated as acting in good faith, then only JPMorgan-sized companies will be able to enter regulated markets. That does not make the system safer. It makes the system less competitive and places even more power in institutions whose own records demonstrate that size does not eliminate misconduct.
A startup should not receive a pass because it is small. A large corporation should not receive practical immunity because it is too important, too connected, or too expensive to prosecute into failure.
Equal accountability does not mean identical machinery. It means a consistent examination of risk, intent, conduct, cooperation, and remediation, whether the company employs fifteen people or two hundred thousand.
A Fortune 500 compliance department should not become the minimum price of being presumed legitimate.
The law should demand responsibility from every company. It should also recognize the difference between a business that knowingly participates in crime and a business that builds in good faith, relies on professional guidance, develops its people, makes imperfect decisions, and continues trying to improve.
That distinction is not a favor to startups.
It is part of what equal justice requires.
Editorial disclaimer: This essay presents the author's perspective and general commentary. It does not constitute legal or regulatory advice. The criminal charges referenced above are allegations. Firas Isa and Crypto Dispensers have pleaded not guilty, and guilt may be determined only through the judicial process.
Equal standards require equal principles.
Responsibility should be demanded from every company. Proportionality, intent, cooperation, and remediation should be available to every company too.
Firas IsaFounder & CEO, Crypto Dispensers, Chicago