For a debt buying company, RMAI business certification is an industry designation—not a government license and not a finding that every collection activity is lawful. RMAI’s current credential is the Certified Receivables Business (CRB) designation; its program uses documented standards, an application process, and audits, while legal duties continue to depend on the account, the company’s role, and the jurisdictions involved. RMAI’s current business-certification materials describe the credential and program resources.

What RMAI certification means

RMAI describes its Receivables Management Certification Program as an industry self-regulatory program. For debt buying companies, the business credential is CRB. The program’s purpose is to apply uniform best-practice standards, including standards intended to address consumer protections and compliance awareness. That is meaningful operational evidence, but it is different from a state license, a regulator’s approval, or a legal conclusion about a particular account.

This distinction matters for institutional buyers and sellers. Certification can help establish a repeatable control framework, but it does not transfer responsibility for legal compliance from an owner, servicer, law firm, or vendor. A sound due-diligence review should evaluate both the certification record and the actual controls used for the assets and services in scope.

What the business standards examine

RMAI states that business certification is for organizations that meet its standards and pass its background-check process. Its published materials identify subjects such as account documentation, chain of title, consumer complaints and disputes, statute-of-limitations compliance, vendor management, credit reporting, and resale. The current governance document also separates standards that apply to certified companies generally from standards specifically for debt buying companies. See RMAI’s business-certification overview and the current governance document for the controlling program materials.

  • Account provenance: A buyer needs procedures that connect account-level information to the purchase and sale documentation.
  • Operational controls: Policies should cover disputes, complaints, vendor oversight, and the handling of consumer information.
  • Legal-change management: Certification standards can reinforce a compliance process, but they cannot make a jurisdiction-specific rule inapplicable.

How the current CRB process is structured

RMAI’s published CRB certification steps provide a practical outline for a debt buying company. The exact requirements, documents, fees, and timing can change, so an applicant should use the current governance document and application materials rather than relying on a summary.

  1. Review the governance document and the standards applicable to debt buying companies.
  2. Complete a pre-certification audit through an RMAI-authorized audit provider and complete the CRB application’s self-audit checklist.
  3. Ensure the company’s chief compliance officer holds the individual Certified Receivables Compliance Professional credential before the CRB application is submitted.
  4. Prepare the required insurance evidence, CFPB Consumer Complaint Portal registration, and consumer-facing website information specified by RMAI.
  5. Submit the application and supporting materials, then plan for the full compliance audit during the certification cycle.

RMAI’s current governance document, version 14.0, is effective March 1, 2026. It describes a pre-certification assessment and an audit period beginning in the sixteenth month after certification or recertification. Those program requirements are not the same as a regulator’s examination, and they should not be presented to consumers or counterparties as one.

Federal debt-collection rules do not turn on certification

For consumer debt, whether a company is a federal “debt collector” is a scope question under the Fair Debt Collection Practices Act and Regulation F. The current regulation defines a debt collector in part by whether the business’s principal purpose is debt collection or whether it regularly collects debts owed to another. Its official interpretation also explains that a person collecting defaulted debts it purchased is not automatically a debt collector when it neither collects for another nor has debt collection as its principal business. Read the current Regulation F definition and official interpretation for the precise language.

Accordingly, a company should not assume that purchasing debt either always triggers or always avoids federal debt-collector status. The result can depend on its business model, collection activity, account type, relationships with vendors, and applicable law. State and local rules may impose separate licensing, collection, litigation, privacy, or servicing obligations; RMAI’s current standards expressly require certified companies to comply with applicable local, state, and federal laws and regulations.

Validation information and dispute handling

When Regulation F applies, a debt collector generally must provide validation information in the initial communication or send a validation notice within five days. The regulation specifies the content and the validation period; see the CFPB’s current rule on validation notices. The CFPB’s consumer guidance explains that the notice generally identifies the collector, the creditor, the amount, and an end date for the 30-day dispute period.

For companies, this means the quality of account documentation and dispute workflows matters well before the first communication. For consumers, a certification label does not resolve whether a particular balance is accurate or enforceable. The CFPB advises people to identify the company and debt, ask for key information in writing, and keep copies of communications. Its guidance on responding when a debt collector contacts you is a useful starting point.

Due diligence for institutional counterparties

A certification check is most useful as one part of a broader review. Buyers, sellers, and service providers can ask whether the scope of certification matches the legal entity and business activity at issue; request the current certification status; review policies for documentation, complaints, disputes, vendors, and information security; and confirm how state-specific requirements are identified and monitored.

They should also distinguish between a company’s internal processes and proof that a particular account is collectible. Account ownership, balances, disclosures, limitations periods, consumer disputes, bankruptcy, credit reporting, and litigation posture are fact- and jurisdiction-dependent. Certification supports governance; it does not eliminate the need for transaction-level diligence and qualified legal or compliance review.

Frequently asked questions

What is a debt buyer?

A debt buyer is a company that purchases receivables or defaulted accounts. It may collect through its own operations, place accounts with another company, or sell accounts, depending on its business model. Whether it is a “debt collector” for a particular federal rule requires the role-and-activity analysis in Regulation F; ownership alone does not answer every scope question.

What is the difference between a debt buyer and a debt collector?

A debt buyer acquires an interest in receivables, while a debt collector collects or attempts to collect debts as defined by applicable law. One company can perform both functions, but the terms are not interchangeable. The federal definition and exclusions in 12 CFR Part 1006 should be applied to the actual facts.

Can a charged-off debt be sold?

RMAI’s current debt-buyer standards address purchase and sale documentation for charged-off receivables, so such transactions are contemplated by its program. Whether a specific account can be sold, collected, reported, or litigated depends on the account documents, transaction terms, consumer protections, and applicable law. RMAI’s governance document is an industry standard, not a substitute for that legal analysis.