AML compliance for payment businesses
Anti-money-laundering compliance is the set of controls a payments or crypto business uses to detect and prevent illicit funds moving through it. It is a legal obligation in every jurisdiction that matters, and in practice it is the thing that decides whether you can hold a banking relationship at all.
Anti-money-laundering compliance is how a regulated business stops illicit funds moving through it: verifying who its customers are, screening them and their transactions, monitoring what they actually do, and reporting what it cannot explain.
It is worth being blunt about the incentive. The severe consequence of a weak programme is usually not the fine. It is that your bank, your electronic money institution and your liquidity partners each conclude you are a risk they do not need, and leave — generally at short notice and generally at once. For a payments business, AML failure presents as a sudden loss of the ability to operate.
The six controls
There is no jurisdiction where a programme can be assembled from a subset of these.
1. Customer due diligence
Verify identity, ownership and legitimacy before onboarding, and keep it current afterwards. For individuals this is KYC; for companies it is KYB — registry verification, the ownership chain down to the natural persons who ultimately control the business, and the directors.
FATF Recommendation 10 is the source. The detail that catches firms is that customer due diligence is a continuing obligation, not an onboarding event. Ownership captured accurately two years ago and never refreshed is not compliance; it is a record of what was once true.
2. Sanctions, PEP and adverse-media screening
Screen customers, beneficial owners and counterparties against the sanctions lists applicable to you, against politically-exposed-person data, and against adverse media — at onboarding and continuously thereafter, because lists change and your customers do not tell you when they have been added to one.
Sanctions screening is strict liability in most regimes: you breach by dealing with a listed party, whether or not you knew. PEP status is different — FATF Recommendation 12 requires enhanced scrutiny, not refusal. A PEP is not a criminal, and de-risking an entire category is its own supervisory problem.
3. Transaction monitoring
Watch the flows for patterns that do not fit: structuring beneath reporting thresholds, long dormancy then sudden volume, funds passing straight through, activity inconsistent with the customer’s stated business, or counterparties with sanctions or high-risk-jurisdiction exposure.
The common failure is calibration. A system tuned to alert on everything produces a queue no team can clear, and a backlog of uninvestigated alerts is worse evidence than no alerts at all — it shows you saw something and did nothing.
4. Suspicious-activity reporting
Where suspicion cannot be cleared, report it to the relevant financial intelligence unit — FINTRAC in Canada, the National Crime Agency in the UK, the national FIU in EEA states. FATF Recommendation 20 sets the standard.
Two rules govern conduct afterwards. Reporting is mandatory once the threshold is met, and it is based on suspicion rather than proof. And “tipping off” — telling the customer a report has been made — is a criminal offence in most jurisdictions.
5. The Travel Rule
Originator and beneficiary information must travel with qualifying transfers. FATF Recommendation 16 sets the principle; the EU implements it for crypto-assets through the Transfer of Funds Regulation, and Canada and the UK through their own instruments. The Travel Rule guide covers the detail.
6. Record-keeping
Retain customer records and transaction data for the period your regime requires — commonly five years from the end of the relationship or the date of the transaction. The purpose is reconstruction: a supervisor or investigator must be able to rebuild what you knew and when you knew it.
The risk-based approach, and what it actually demands
FATF Recommendation 1 requires controls proportionate to assessed risk. This is widely misunderstood as licence to do less.
It is the opposite. A risk-based approach obliges you to hold a documented view of your own risk — by customer type, product, delivery channel and geography — to apply controls that follow from it, and to justify both. A firm applying identical checks to a domestic sole trader and to a cross-border crypto-asset business has not simplified anything. It has demonstrated it never performed the assessment.
The practical test is whether you can answer, for any given customer: why this level of scrutiny, decided by whom, and on what evidence.
Where the obligations actually come from
FATF sets the standard and issues no law. It reaches you through national implementation, and the differences matter operationally.
| Jurisdiction | Principal instruments | Supervisor |
|---|---|---|
| Global standard | The FATF Recommendations, with interpretive notes | None — FATF assesses states, not firms |
| European Economic Area | The 2024 anti-money-laundering package (a directly applicable regulation, a directive, and a new EU-level authority), plus MiCA for crypto-asset services and the Transfer of Funds Regulation | National competent authorities, moving toward direct EU-level supervision for some entities |
| United Kingdom | The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, as amended | The relevant sectoral supervisor |
| Canada | The Proceeds of Crime (Money Laundering) and Terrorist Financing Act; separately the Retail Payment Activities Act for payment service providers | FINTRAC; the Bank of Canada for RPAA registration |
Two consequences follow for anyone operating across borders. First, obligations stack rather than substitute — meeting Canadian requirements does not discharge EEA ones for EEA customers. Second, the EEA regime is mid-transition: the 2024 package moves substantial ground out of directives, which each member state transposed differently, and into a directly applicable regulation. If your EEA compliance analysis predates that package, it is due a review.
What supervisors actually find
Enforcement rarely turns on a missing policy. Almost every firm has the document. The findings cluster in the gap between the document and the practice:
- Periodic review that slipped. A customer risk-rated high, scheduled for annual review, still unreviewed two years later.
- Alerts closed without rationale. Cleared with no recorded reasoning, so the decision cannot be defended afterwards.
- Stale beneficial ownership. Correct when captured, never refreshed, and wrong since a restructure nobody told you about.
- A nominated officer without authority. Someone holds the title but cannot decline a commercially attractive relationship. That is a governance failure, and it is visible in the file.
- Screening that never ran again. Onboarding screening completed, ongoing screening configured but never verified, and nobody noticed until a list update was missed.
Every one of these is a failure of operation rather than design, which is why buying a system is not the same as having a programme.
How KwiikPay approaches it
KwiikPay is a trading name of KWP Finance Limited, registered in Canada as a Payment Service Provider under the Retail Payment Activities Act, supervised by the Bank of Canada, and as a FINTRAC-registered Money Services Business including dealing in virtual currency. Both are registrations, not licences, and we describe them that way deliberately.
The programme runs all six controls: KYB and KYC at onboarding with ongoing refresh, sanctions, PEP and adverse-media screening, transaction monitoring, suspicious-activity reporting through a named MLRO, the Travel Rule on qualifying transfers, and record-keeping to the applicable retention period. Enhanced due diligence is applied to higher-risk profiles rather than used as a reason to refuse whole categories, and fiat balances are held in segregated safeguarding accounts. The sectors and jurisdictions we will not serve are published in the risk appetite statement rather than left to interpretation.
If you are assessing us as a counterparty, talk to us — we will complete your due-diligence questionnaire, and we run the same checks on you.
FAQs
What are the core pillars of AML compliance?
Six: customer due diligence (KYC and KYB), sanctions and PEP screening, ongoing transaction monitoring, suspicious-activity reporting, the Travel Rule on qualifying transfers, and record-keeping. They are not a menu — a programme missing any one of them is not a programme, and a supervisor will treat it that way.
Which regulations govern AML?
The FATF Recommendations are the global standard, but FATF issues no law. Obligations reach you through national implementation: in the EU the 2024 anti-money-laundering package and MiCA for crypto-asset services; in the UK the Money Laundering Regulations 2017; in Canada the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, supervised by FINTRAC. Your exact duties follow from where you are authorised and where your customers are.
What is a risk-based approach?
The principle, set out in FATF Recommendation 1, that controls should be proportionate to assessed risk rather than uniform. It means you must be able to explain why a given customer received the scrutiny they did. Applying identical checks to everyone is not neutrality — it is an absence of a risk assessment, and supervisors read it that way.
What is transaction monitoring?
Automated and manual review of payment flows for patterns suggesting laundering or fraud — structuring below thresholds, dormancy followed by spikes, rapid pass-through, volumes inconsistent with the customer's stated profile, or exposure to sanctioned parties. Alerts go to a human analyst. The quality of a monitoring system is judged by how few false positives it generates, not how many alerts.
Does AML apply to stablecoin payments?
Yes, and treating them as an exception is a common and expensive mistake. Stablecoin transfers are transfers of crypto-assets: customer due diligence, screening, monitoring and the Travel Rule all apply. The rail being fast does not make it out of scope.
What usually goes wrong?
Rarely the absence of a policy. Usually the gap between the written policy and what the business actually does — periodic reviews that slip, alerts closed without a recorded rationale, ownership data captured at onboarding and never refreshed, or a nominated officer with the title but no real authority. Supervisors test the practice, not the document.
