KYC, KYB, and AML/CFT: compliance for payment companies. 6 chapters and a final quiz.
The go-to course on anti-money laundering and counter-terrorist financing (AML/CFT) in payments: KYC for individuals, KYB for businesses and their beneficial owners, PEPs, sanctions and asset freezes, ongoing monitoring, suspicious activity reports to TRACFIN (France’s financial intelligence unit), and the risk-based approach. It also covers the 2024 EU AML package and the daily screening required by the Instant Payments Regulation.
Map the AML/CFT framework that applies to payment companies: the FATF, the 2024 EU AML package, the French Monetary and Financial Code, the ACPR, and TRACFIN
Build a complete KYC/KYB file: supporting documents, remote identity verification (PVID), beneficial owners, and complex ownership structures
Detect and handle PEPs and sanctioned persons, and apply asset freezes without delay, including the daily screening required by Regulation (EU) 2024/886
Organize ongoing monitoring of a business relationship and know when and how to report a suspicion to TRACFIN
Chapter 1. AML/CFT overview: framework, players, and what is at stake.
AML/CFT (anti-money laundering and countering the financing of terrorism) targets two mirror-image phenomena. Money laundering gives money of criminal origin the appearance of legitimacy. Terrorist financing channels funds, sometimes perfectly legal at the outset, toward terrorist activity. Payment companies are on the front line, since every transaction they process is a potential channel.
💵
1. Placement
Getting illicit funds into the financial system: cash deposits split into smaller amounts, front businesses with high cash volumes, purchases of e-money.
🌀
2. Layering
Stacking up transactions to blur the trail: cascading transfers, shell companies, crypto-assets, fast cross-border transfers.
🏠
3. Integration
Reinjecting the “clean” funds into the legitimate economy: real estate, artwork, equity stakes, repayments of sham loans.
In France, the list of obliged entities is set out in Article L. 561-2 of the Monetary and Financial Code: banks, but also payment institutions, e-money institutions, crypto-asset service providers, currency exchange offices, and others. A licensed PSP therefore has exactly the same obligations as a bank. It must identify its customers, monitor their transactions, and report its suspicions, under the supervision of the ACPR (Autorité de contrôle prudentiel et de résolution, France’s banking supervisor), with TRACFIN as the financial intelligence unit.
All subject to AML/CFT rules as licensed institutions in the EUStripeAdyenPayPalKlarna
1989
The FATF is founded
The G7’s Summit of the Arch creates the Financial Action Task Force, which sets the 40 global recommendations.
1990
TRACFIN is created
France creates its financial intelligence unit, under the Ministry of the Economy and Finance.
2015-2018
4th and 5th Anti-Money Laundering Directives
Beneficial ownership registers, tighter rules on anonymous e-money, and extension to crypto platforms.
June 2024
EU AML package adopted
The directly applicable AMLR (Regulation (EU) 2024/1624), the AMLD6 (Directive (EU) 2024/1640), the creation of the AMLA, and a €10,000 cap on cash payments across the EU.
2025
AMLA sets up in Frankfurt
The new EU Anti-Money Laundering Authority ramps up.
July 10, 2027
AMLR applies
Harmonized, directly applicable rules; direct AMLA supervision of about 40 cross-border financial groups from 2028.
2% to 5%
of global GDP laundered each year, or $800 billion to $2 trillion
ONUDC
186 556
suspicious activity reports received by TRACFIN in 2023 (up 15% year over year)
TRACFIN 2023 annual report
10 000 €
EU-wide cap on cash payments under the AMLR
Regulation (EU) 2024/1624
≈ 40
financial groups directly supervised by the AMLA from 2028
Regulation (EU) 2024/1620
🔑
The backbone: the risk-based approach
Since the 3rd Directive, AML/CFT is no longer a box-ticking exercise. Each obliged entity must assess its own risks (customers, products, channels, geographies) and scale its measures accordingly. Everything in this course follows from that.
🎯 Quick question
In the money laundering cycle, what is the “layering” stage?
Chapter 2. KYC: identifying and verifying an individual.
KYC (Know Your Customer) rests on two separate steps that Article L. 561-5 of the Monetary and Financial Code requires before the business relationship begins. First, identify the customer by collecting their identity details. Then, verify that identity against a reliable document. A payment account cannot be opened “in the meantime.” No completed verification, no relationship.
Item
Document or source
What to check
Identity
National ID card, passport, or residence permit, still valid
Consistent MRZ, holograms, no tampering, photo match
Contact details
Recent proof of address (if the risk profile requires it)
Consistency with the declared country of residence and the sign-up IP address
Occupation and income
Self-declared, pay stubs, or tax assessments, depending on risk
Consistency between the declared profile and expected volumes
Screening
Sanctions, asset-freeze, PEP, and adverse media databases
At onboarding and then continuously (see chapter 4)
Typical KYC file for an individual at a PSP
Remote KYC onboarding at a PSP
Customer
Enters their identity details and uploads their ID
Mobile or web flow
➜
PVID provider
Verifies the document and face over video
Liveness detection, check of the document’s security features
➜
Screening engine
Checks the identity against sanctions, asset-freeze, and PEP lists
Fuzzy matching on name, date of birth, country
➜
Scoring engine
Assigns the customer a risk rating
Country, occupation, product requested, distribution channel
➜
Compliance
Approves, requests more information, or declines to onboard
Doubtful cases go to level 2 manual review
For remote onboarding, which is a PSP’s daily business, French law requires enhanced safeguards under Articles R. 561-5-1 and R. 561-5-2 of the CMF. Three main routes are available. The first is to use a remote identity verification provider (PVID) certified under the ANSSI framework. The second relies on a digital identity or a qualified eIDAS electronic signature. The third combines two complementary measures, for example a first transfer sent from an account in the customer’s name at a bank in the EEA, plus a copy of an additional ID document.
⚠️
Document fraud and deepfakes
High-quality fake IDs and video deepfakes that can fool liveness detection are now produced at industrial scale. A serious KYC process goes beyond document checks. It adds biometrics with presentation attack detection, technical signals (device, IP address, sign-up velocity), and human review of borderline cases. ANSSI-certified PVID providers are audited on their resistance to these attacks.
Collect only what is necessary for the level of risk: KYC is not a data vacuum (see the GDPR course).
Record who verified what, when, and against which document: in an ACPR inspection, an undocumented file is a file that does not exist.
Plan for remediation: older, incomplete files must be brought up to date, starting with high-risk customers.
🎯 Quick question
What is the purpose of the PVID framework published by ANSSI?
KYB (Know Your Business) applies the same logic to legal entities (merchants, marketplaces, nonprofits). It adds one difficulty: behind a company there may be an ownership chain designed to hide who really controls the funds. At a PSP, KYB is the core of merchant onboarding, because you cannot collect payments for a merchant you do not know.
Document
What it proves
Watch out for
Kbis extract (company registration) under 3 months old
Legal existence, registered office, officers, declared business activity
Consistency between the APE code (French activity code) and what the website actually sells
Up-to-date articles of association
Capital breakdown, governance rules
Unusual clauses, preferred shares
IDs of officers and authorized representatives
Identity of the people who can bind the company
Same checks as for individual KYC
Beneficial ownership filing (RBE register)
Individuals who control the entity
Cross-check it: the register is self-declared, not proof
Ownership chart
Ownership chain up to individuals
Required once the structure has more than one level
RIB (French bank details) / settlement IBAN
Account receiving payouts of collected funds
The account holder must be the merchant itself
Typical KYB file for a merchant (French company)
Article R. 561-1 of the CMF defines the beneficial owner as any individual who holds, directly or indirectly, more than 25% of the capital or voting rights. The article also covers anyone who exercises control by any other means, such as through a shareholders’ agreement or the right to appoint management. Failing that, the senior managing official is designated. This fallback must remain a documented exception, not the easy way out. The calculation runs through the ownership chain, multiplying the stakes at each level.
🔑
Calculating through the chain: an analyst’s reflex
Ms. A owns 60% of holding company H, which owns 50% of operating company S. Her indirect stake in S is 60% × 50% = 30%, above 25%, which makes Ms. A a beneficial owner of S. The same exercise must be carried out branch by branch, including for trusts and fiducies (settlor, trustee, beneficiaries).
Public registers are not enough. Since the CJEU judgment of November 22, 2022 (Case C-37/20), public access to beneficial ownership registers has been restricted on privacy grounds. Obliged entities can still consult them, and the AMLD6 reopens access to journalists and NGOs that can show a legitimate interest. Above all, the register remains self-declared, so the obliged entity must report to the registry any discrepancy between what it finds and what has been filed.
🕳️
Opaque ownership chain
Cascading holding companies across non-cooperative jurisdictions, bearer shares, opaque trusts. The more complex the structure, the stronger the justification must be.
🎭
Nominees
Straw-man directors (age, profile, or address inconsistent with the business), serial directors of dozens of companies, a declared beneficial owner who knows nothing about the business.
🏪
Front business
A storefront website with no real inventory, payment volumes out of proportion to the declared business, an abnormal refund rate. KYB continues after onboarding.
🧩
Inconsistencies across sources
A Kbis address at a virtual office provider, a payout IBAN in a third party’s name, a mismatch between the APE code and the actual product catalog. Every inconsistency is either explained or reported.
🎯 Quick question
No individual owns more than 25% of a client company, and no control by other means has been identified. What does the obliged entity do?
Chapter 4. PEPs, sanctions, and asset freezes.
A politically exposed person (PEP) holds, or has held within the past 12 months, a prominent public function: head of state, minister, member of parliament, supreme court justice, ambassador, general officer, head of a state-owned company, and so on. PEP status extends to immediate family members and close associates. Being a PEP is not an offense. The exposure signals a corruption risk, and it automatically triggers enhanced due diligence.
Approval from a member of senior management (or an authorized body) to establish or continue the business relationship.
Establishing the source of wealth and source of funds involved in the relationship.
Enhanced, ongoing monitoring of transactions, with lower alert thresholds.
Financial sanctions follow a different logic. You are no longer assessing a risk; you are applying a prohibition. The lists come from the UN, the European Union (directly applicable regulations), and individual countries. In France, the Treasury (Direction générale du Trésor) keeps the national register of persons and entities subject to an asset freeze. An asset freeze is a strict obligation that applies without delay: from the moment of publication, no funds or economic resources may be made available to the designated person.
List
Issuer
Relevance for a French PSP
Security Council lists
ONU
Transposed into EU and national law; basis of counterterrorism regimes
EU restrictive measures
Council of the EU
Directly applicable regulations, the foundation of EU screening
National asset-freeze register
French Treasury (DG Trésor)
Consolidated national + EU + UN; the operational reference in France
SDN List (OFAC)
United States
Not directly binding under EU law, but a risk through dollar exposure and correspondent banks
Main lists to screen against
⚠️
The BNP Paribas precedent: $8.97 billion
In June 2014, BNP Paribas agreed to pay $8.97 billion to US authorities for processing dollar transactions linked to Sudan, Iran, and Cuba in violation of OFAC sanctions. The same mechanism applies to any PSP. As soon as a transaction touches the dollar or a US counterparty, the extraterritorial exposure becomes real.
Regulation (EU) 2024/886 on instant payments (the IPR) changed how screening works. For SEPA instant credit transfers, transaction-by-transaction filtering generated mass rejections and false positives that were incompatible with ten-second processing. It has been replaced by an obligation to screen your own customers against EU asset-freeze lists immediately after each new designation and at least once a day. This requirement has applied since January 9, 2025. Daily screening of the customer base (“IPR screening”) has therefore become an industrial process, with proof of execution to be retained.
Daily screening alert: sample output from a screening engine
Day to day, screening comes down to managing false positives: namesakes, transliterations (Cyrillic, Arabic, Chinese), partial dates of birth. A mature setup calibrates its fuzzy matching (similarity score, secondary identifiers), logs every alert-clearing decision, and tracks its false positive rate. Conversely, a false negative (a sanctioned person who slips through) exposes the firm to criminal and disciplinary penalties: violating an asset freeze can carry up to five years in prison.
🎯 Quick question
Since January 9, 2025, what must a PSP do under Regulation (EU) 2024/886 for instant credit transfers?
Chapter 5. Ongoing monitoring and TRACFIN reporting.
KYC continues long after onboarding. Article L. 561-6 of the CMF requires ongoing monitoring throughout the business relationship: transactions must remain consistent with up-to-date knowledge of the customer, their business, and their risk profile. In practice, that means transaction monitoring, periodic file reviews (at a frequency proportionate to risk), and updated documents.
Structuring (smurfing): repeated deposits or payments just below reporting or alert thresholds.
Pass-through account: funds received and then transferred out almost in full within a very short time, with no economic rationale.
Money mules: individuals recruited (often through social media) to move fraudulent funds in exchange for a commission.
Profile mismatch: a student receiving large business transfers, a local shop receiving payments from countries unrelated to its business.
Product misuse: prepaid cards loaded with cash and then drained abroad, diverted crowdfunding pots, back-and-forth refunds between related merchants.
A transaction that is particularly complex or unusually large, with no apparent economic rationale or lawful purpose, triggers the enhanced review required by Article L. 561-10-2. The firm must inquire into the source and destination of the funds, the purpose of the transaction, and the identity of the beneficiary, and record everything in writing. The review ends either with a documented decision to close the alert or with a suspicious activity report.
Supporting documents, customer contact if needed, without revealing the suspicion
➜
TRACFIN reporting officer
Files the suspicious activity report on ERMES
TRACFIN’s secure online reporting platform
➜
TRACFIN
Analyzes, enriches, cross-checks
Right to request information, exchanges with foreign FIUs
➜
Judicial authorities
Receives a referral if the facts warrant it
TRACFIN does not prosecute: it provides intelligence
A suspicious activity report (Article L. 561-15) follows precise rules. There is no minimum amount, since suspicion is enough, and it must be filed before the transaction is executed whenever possible. A reporter acting in good faith enjoys civil, criminal, and professional immunity. Do not confuse it with COSI (systematic information reports), automatic filings made without any suspicion. They cover money remittance transactions from €1,000 per transaction in cash or e-money (€2,000 cumulative per customer over a month). They also cover cash deposits or withdrawals above €10,000 per month on an account.
⚠️
Tipping off is strictly prohibited
Telling a customer that a suspicious activity report or an investigation exists is a criminal offense, and one careless remark is enough: “your file has been blocked by compliance.” Customer-facing teams need neutral scripts for handling a relationship under review.
186 556
suspicious activity reports received in 2023, an all-time high
TRACFIN 2023 annual report
2e
payment institutions have become the second-largest reporting sector, after banks
TRACFIN
0 €
minimum amount for a suspicious activity report: suspicion triggers it, not the amount
Art. L. 561-15 CMF
🎯 Quick question
Above what minimum amount must a suspicious activity report be filed with TRACFIN?
Chapter 6. Risk-based approach and compliance governance.
The risk-based approach focuses resources where risk is highest. It takes the form of a formal risk classification, reviewed at least once a year, that combines four dimensions and feeds each customer’s risk score. That score in turn sets the due diligence level, review frequency, and alert thresholds.
Anonymous e-money, money remittance, crypto-assets, prepaid cards, collecting payments on behalf of third parties.
📡
Distribution channels
Fully remote relationships, agent and distributor networks, introducers, marketplaces.
🗺️
Geographies
FATF lists, the EU list of high-risk third countries, sanctions regimes, regulatory havens.
Level
When
Example measures
Simplified due diligence
Demonstrably low risk (capped products, regulated customers in the EEA…)
Lighter identification, less frequent reviews, but never a full exemption from monitoring
Standard due diligence
Default case
Full KYC, screening, monitoring, periodic review based on the score
Enhanced due diligence
PEPs, high-risk third countries, unusual transactions, correspondent banking
Senior management approval, source of funds and wealth, lower thresholds, closer review
The three due diligence levels under the CMF
The geographic dimension relies on FATF lists. The blacklist (countermeasures) covers Iran, North Korea, and Myanmar. The gray list (increased monitoring) changes at every plenary, and the listing of Monaco in June 2024 was a reminder that no financial center is immune. On top of that comes the EU list of high-risk third countries, which automatically triggers enhanced due diligence.
The governance the ACPR expects rests on named roles: a person responsible for running the AML/CFT program, plus a designated TRACFIN reporting officer and liaison officer. Then come regular, documented training for all exposed staff and a two-tier internal control system. Permanent control covers first- and second-level checks on an ongoing basis; periodic control is internal audit. Outsourcing a task (screening, KYC) never outsources the responsibility.
€100M
maximum fine the ACPR sanctions committee can impose (or 10% of revenue)
Monetary and Financial Code
€1M
fine and reprimand imposed by the ACPR on French BaaS provider Treezor for AML/CFT failings (April 2024)
ACPR sanctions committee
€9.2M
BaFin fine against N26 for late suspicious activity reports (May 2024)
BaFin
$4.3B
Binance’s settlement with US authorities over AML and sanctions violations (November 2023)
DOJ / FinCEN / OFAC
🔑
Compliance: the condition for keeping a license
Danske Bank (€200 billion in suspicious flows through its Estonian branch, a $2 billion US penalty in 2022), N26 (growth cap imposed by BaFin), Treezor. These recent cases show that penalties are not only financial. They can freeze growth, drive away banking partners, and in extreme cases cost the firm its license. For a payment company, AML/CFT compliance is a condition of its license to operate.
🎯 Quick question
What is the maximum fine the ACPR sanctions committee can impose?