Multi-country payment compliance. 7 chapters and a final quiz.
A field manual for compliance officers opening new markets. It covers classifying a service before applying for a license; choosing between your own license, agent status, and a licensed partner; knowing what passporting does not cover; building a KYC matrix market by market; tuning a sanctions screening program; mapping where data is stored; meeting platform reporting obligations; and building a licensing timeline that does not slip.
Classify a payment service in a given market by applying the funds-holding test, and produce a defensible classification memo
Choose between your own license, agent or distributor status, and a licensed partner, based on time, cost of oversight, and risk
Define what a European passport carries and what stays with the host country, then plan notifications around the PSD2 deadlines
Build a KYC matrix market by market, starting from local identity infrastructure rather than a single onboarding flow
Chapter 1. Business model classification before licensing.
An international expansion project does not start with a license application. It starts with a flow map showing where the money comes in, where it stops, who controls it, and when it moves on to its recipient. Draw that map country by country and service by service, because two neighboring markets sometimes classify the same product in opposite ways. Classification comes first. The choice of license follows from it, never the other way around.
The funds-holding test, applied flow by flow
The collection account: whose name is it in, and who gives the debit instructions?
How long the funds sit: under most regimes, a single night is enough to tip the classification
The legal owner of the funds before payout: the end customer, the merchant, or the provider
Discharge of the debt: at exactly what moment is the customer released from their debt to the merchant?
What happens to the funds in bankruptcy: the answer has to hold up before a liquidator, not a sales director
Structure
Who holds the funds
What it requires
Where it breaks
Your own license
The group’s local entity
Paid-in capital, local governance, safeguarding, periodic reporting, connection to the national payment rail
Time. The regulatory clock starts only once the application is complete, and no legal text limits the phase before that
Agent or distributor of a licensed institution
The principal institution
Registration with the principal’s regulator, and an AML program described and then monitored by the principal
The principal is liable for its agent’s actions, so it imposes its rules, its customer refusals, and its go-to-market pace
Licensed partner that contracts with the customer
The partner
A referral or technical services agreement, with no holding of funds and no authority to give payment orders
The customer relationship belongs to the partner. Switching partners means onboarding every customer again
Three market access models, and what each one really costs
🔑
Holding funds is proven, not declared
A regulator does not read the sales deck for an arrangement. It reads the account agreements, the signing mandates, and the payment order log. Those three documents are usually enough to contradict a classification written in good faith. The account agreement names the account holder, the signing authority names who gives the orders, and the order log shows who actually decided. Gather these documents before drafting the classification memo, not when the supervisor asks for them.
The classification memo is the deliverable for this step: one page per country, dated, signed by the compliance officer, and binding within the group. It describes the service in the terms of the local law rather than in marketing language, cites the article that supports the classification, and names the entity that will bear the obligation. Finally, it lists the assumptions that would force a new analysis if they changed, such as a shorter payout period. The date ties the analysis to the assumptions that held when it was written.
3 months
time the authority has to inform an applicant that a payment institution license has been granted or refused, counted from a complete application
Directive (EU) 2015/2366, Article 12
2 months
time for the home authority to say whether an agent has been entered in the register
Directive (EU) 2015/2366, Article 19(2)
25 %
ownership stake that indicates a beneficial owner of a legal entity in the EU
Regulation (EU) 2024/1624, Article 52(1)
🎯 Quick question
Your platform collects funds into its own account and pays the merchant out within 48 hours. What determines the classification first?
Chapter 2. Passporting: what it carries and what it leaves behind.
The European passport carries a license, not compliance. A payment institution licensed in one member state can serve the others, either by establishing a presence there or under the freedom to provide services. That right exempts it from nothing else. The host country retains control over several areas, and those areas are what keep a compliance team busy day to day.
Area
Who decides
What it means for the project
License, capital, and solvency
Home authority
One prudential file, one supervisor for the group’s capital and governance
Anti-money laundering
Host country, for activities carried out there
Procedures, training, and suspicious activity reports under local law, including under the freedom to provide services
Consumer protection and pre-contractual disclosures
Host country
Document language, mandatory disclosures, complaint handling, local dispute resolution
Tax and sector-specific reporting obligations
Host country
VAT, withholding, and seller reporting for platforms (see Chapter 6)
Agents and distributors
Notification through the home authority
Each agent is registered before it operates, service by service and country by country
What the passport carries, and what stays with the host country
PSD2 clocks, as they actually run
License: the authority informs the applicant within 3 months of receiving the application or, if the application was incomplete, all the required information (Directive (EU) 2015/2366, Article 12)
Agent: the home authority says within 2 months whether the agent has been entered in the register (Article 19(2))
Passport, transmission: the home authority forwards the file to the host country within one month; the host country assesses the information within the following month (Article 28(2))
Passport, decision: the home authority communicates its decision within 3 months of receiving the information (Article 28(3))
Proof of operation: an agent may operate only once it is entered in the register. The register entry is binding; the agency contract is not
⚠️
An EU license is worthless in the UK
The passport stops at the borders of the European Economic Area. Since the transition period ended on December 31, 2020, an institution licensed in the EU has had no right to operate in the UK on the strength of its license alone, and the reverse is also true. The result shows up on the org chart: two licenses, two supervisors, two sets of reporting, two compliance functions. That line belongs in the first expansion budget, not the second.
The freedom to provide services is attractive because it looks light, and it has a blind spot that supervisors know well. As soon as an employee, an agent, or an office is located in the host country, the analysis shifts to establishment, with all the local obligations that come with it. Authorities look at the facts, not at the box ticked on the notification form. A billing address does not make a branch; a sales team on the ground often does. Document your actual presence in each country, and update that record every quarter.
🎯 Quick question
A payment institution licensed in one member state operates in three others under the freedom to provide services. Which AML rules apply to its activities in those three countries?
Chapter 3. KYC, market by market.
Onboarding is not designed as one flow translated into several languages. It is designed market by market, and the reason is practical more than legal. Each country has built its own identity infrastructure, and none of it crosses borders: an Indian registry cannot verify a Nigerian customer. A flow designed for one market is rewritten for the next, from the first screen to the archived evidence.
Identity infrastructure: the flow’s non-exportable foundation
Market
Identity foundation
Impact on the onboarding flow
India
Aadhaar (e-KYC authentication by OTP or offline verification), DigiLocker documents, the CKYCR central registry
Video KYC (V-CIP) is accepted on a par with in-person verification; recordings are stored on systems located in India (RBI, Master Direction on KYC)
Brazil
CPF for individuals, CNPJ for legal entities
The same identifier doubles as a Pix key: identity data and payment data overlap, which shifts the risk toward enrollment fraud
Nigeria
BVN and NIN
The identifier is national and unique. It is required both to open and to reactivate an account, and it substitutes for nothing outside the country
Ghana
Ghana Card
A national identity foundation with no regional equivalent: a West African flow is built country by country, never as variants of a single template
Singapore
Singpass and MyInfo
Verified attributes are shared with the customer’s consent, which shortens the flow and shifts the evidence to the consent log
European Union
National identity documents and electronic identification
Beneficial owner from 25% of shares, voting rights, or other ownership interests (Regulation (EU) 2024/1624, Article 52(1))
What onboarding relies on, by market
The Indian case deserves a closer look, because it affects system architecture, not just the content of a form. CKYCR is a central registry of KYC records: an institution uploads the records it creates and can download others with the customer’s consent. Two practical consequences follow. The flow must handle explicit, logged consent before any retrieval from the registry. And V-CIP video recordings stay on Indian soil, which rules out centralizing them in a European data center.
ℹ️
Beneficial ownership is not defined the same way everywhere
The EU uses a threshold of 25% or more of the shares, voting rights, or any other ownership interest (Regulation (EU) 2024/1624, Article 52(1)). Control exercised through other means comes on top, with no numerical threshold. A KYC matrix therefore has two separate columns: the threshold that applies in the country and the local definition of control. Merging them produces false negatives on layered ownership structures.
The deliverable: a matrix, not a manual
Accepted documents: a closed list, by customer type, with the accepted validity period for each
Remote verification: allowed, restricted, or prohibited, and in what technical form
Beneficial owner: numerical threshold, definition of control, and how far up ownership chains you must trace
Refresh: required frequency, trigger events, and what happens to customers whose records are not refreshed
Retention: period, format, and permitted storage location; this column links to Chapter 5
Evidence: what an examiner will ask to see, and exactly where it sits in the system
⚠️
The column everyone forgets: refresh
Projects invest in onboarding and neglect periodic review. The customer base then degrades quietly, until three years later part of the portfolio is no longer documented to the required standard. Remediation costs more than the original onboarding flow, and it runs on a timeline the supervisor imposes. Budget for periodic review in the market’s business plan, starting with the market entry study.
🎯 Quick question
You are scaling KYC in India. What must you have in place before retrieving a record from the CKYCR central registry?
Chapter 4. Sanctions: list coverage, screening, and alerts.
Sanctions screening follows a different logic from AML, because there is no risk-based approach to the prohibition itself. A transaction with a designated person is prohibited, whatever the amount and however long the customer has been with you. The risk-based approach applies to the means of detection, never to the expected outcome. That distinction drives the entire design of the program.
Define your list coverage
Territorial nexus: the lists of the country where the entity is established always apply, unconditionally
Currency and infrastructure nexus: a flow that touches the US dollar or a US institution falls within OFAC’s reach
Personal nexus: the nationality of a director or employee can bring a transaction under an additional regime
United Nations lists, adopted by national regimes on implementation timelines that vary from country to country
Contractually imposed lists: a correspondent bank or a card network often imposes its own list coverage, broader than the legal requirement
⚠️
The 50% rule captures entities that appear on no list
OFAC revised its rule on August 13, 2014. An entity owned 50% or more, directly or indirectly, by one or more blocked persons is itself blocked. Stakes are aggregated, so two designated persons each holding 25% are enough to block the entity. That entity appears on no published list, yet it is off-limits, and screening that only compares names against a list will never catch it. You need ownership data, maintained and dated.
Life cycle of a screening alert
Screening engine
Generates an alert
Fuzzy match on a name, address, country, date of birth, or identifier
➜
Level 1 analyst
Dismisses or escalates
Comparison of the distinguishing attributes available in the customer file and in the payment message
➜
Level 2 analyst
Confirms the match
Ownership research, review of the primary sources for the relevant regime, legal opinion if needed
➜
Decision
Block, reject, or release
Blocking freezes the funds; rejecting returns the payment order to the sender. The applicable regime dictates which one
➜
Compliance
Reports and retains
Report to the competent authority within the regime’s deadline, with the full audit trail of the decision
Audit trail of a screening decision: sample structure, fictional values
A screening engine is tuned, not just installed. The team faces two mirror-image errors: a threshold that is too strict lets transliterations and reversed names slip through, and one that is too loose buries analysts in meaningless alerts until processing capacity collapses. Tuning is measured against a hand-built test set. You load it with known designations written ten different ways, then count what the engine finds. The test set is kept and rerun. The Wolfsberg Group describes this approach in its Guidance on Sanctions Screening of January 2019, which treats screening of reference data separately from screening of messages.
🎯 Quick question
Two people on the Specially Designated Nationals list each own 25% of a company. The company itself is not listed. What does the OFAC rule say?
Chapter 5. Data localization and transfers.
Data localization is not a contract clause; it is an architecture constraint. An encryption commitment does not satisfy any in-country storage obligation, and neither does an audit clause. An examiner checks the physical location of servers and backups, and backups are exactly what projects forget.
Jurisdiction
Obligation
The document to produce
India
Storage of all payment system data only on systems located in India, with compliance required by October 15, 2018 (RBI circular DPSS.CO.OD No. 2785/06.08.005/2017-2018 of April 6, 2018)
A system audit report by a CERT-In empaneled auditor, due by December 31, 2018: the document the supervisor asks for
Vietnam
Payment intermediary services are among the services covered by Decree 53/2022/NĐ-CP, in force since October 1, 2022. Data must be retained for at least 24 months from the authority’s request
Compliance is due within 12 months of the Minister of Public Security’s decision, so each company runs on its own countdown
European Union
No general localization requirement. Transfers outside the EU fall under Chapter V of the GDPR
The chosen transfer mechanism, its supporting assessment, and an up-to-date list of sub-processors
Three localization regimes, and what each requires you to prove
The data flow register: five columns at a minimum
Collection: where the data is captured, and through which channel
Processing: where the engines run, including fraud and scoring models
Primary storage: the country of the system of record
Backup and replication: the country of the copies, often different and almost always undocumented
Access: which countries people view the data from; under several regimes, remote access counts as a transfer
⚠️
A local data center is not always enough
Two separate questions arise, and people almost always conflate them. The first is whether the data sits in the country; the second is who can access it from abroad. Local hosting administered by a team based elsewhere passes the first test and sometimes fails the second, depending on how the applicable law is worded. The answer depends on each text. Document administrator access rights, not just the building’s address.
In the EU, a transfer to a third country must rest on a specific mechanism, chosen and documented: an adequacy decision, standard contractual clauses, or binding corporate rules. The mechanism is never presumed. The Commission adopted a new set of standard clauses in Implementing Decision (EU) 2021/914, then recognized the adequacy of the EU-US Data Privacy Framework on July 10, 2023. A US provider that is not certified under the framework therefore falls under the standard clauses, along with their supporting assessment.
🎯 Quick question
Your PSP processes payments in India from a system hosted in Europe, with an encrypted replica in India. Does that comply with the RBI circular of April 6, 2018?
Chapter 6. Platform and seller reporting.
A marketplace reports not only its own income but also its sellers’. The obligation comes from the OECD Model Rules for digital platforms, since adopted by several jurisdictions. The real work happens at seller registration, where the platform collects the data the annual report will use.
Regime
Legal basis
Deadline
What you must have collected
DAC7
Directive (EU) 2021/514
Applicable since January 1, 2023; first report due January 31, 2024 for the 2023 reporting year; first exchange between tax authorities at the end of February 2024
Seller identification, tax identification number, country of residence, consideration paid, identifier of the financial account used for payouts
UK regime
The Platform Operators (Due Diligence and Reporting Requirements) Regulations 2023 (SI 2023/817)
In force since January 1, 2024; first report to HMRC due by January 31, 2025
Same structure as the OECD Model Rules: goods, personal services, transportation, rental of real property
Form 1099-K (US)
Act of July 4, 2025, known as the One, Big, Beautiful Bill
Threshold retroactively restored to $20,000 and more than 200 transactions (IRS Fact Sheet 2025-08, October 23, 2025)
Taxpayer identification number and gross amount of reportable transactions, per payee
DAC8 / CARF
Directive (EU) 2023/2226, adopted October 17, 2023, implementing the OECD’s CARF framework
Applies from January 1, 2026; first report between January 1 and September 30, 2027
Due diligence on crypto-asset users and details of reportable transactions
Four reporting regimes that weigh on an international platform
Collect at registration, not in January
The tax identification number is requested when the seller account is opened, along with the jurisdiction that issued it
The primary address and country of residence determine the reporting jurisdiction: they are required fields, not optional ones
The identifier of the financial account used for payouts is part of the required data
Business sellers must provide a registration number and, where applicable, a VAT number
Corrections remain possible: build in automatic reminders and a payout hold when data is missing
🔑
Backfilling seller data costs you sellers
A platform that discovers the obligation in December has to contact its entire existing seller base. The response rate is low. The only lever it has is withholding payouts, which quickly leads to disputes and churn. Collecting at registration costs a few form fields; collecting after the fact costs part of the seller base. This decision is made at market launch, not at year-end close.
Under DAC7, a platform may file a single report in one member state. That choice must be documented and notified, and it does not exempt the platform from due diligence on sellers resident in other member states. Tax authorities then share the information through automatic exchange. The UK regime follows the same pattern, because both implement the same OECD Model Rules, so a platform serving both markets builds one data set with two schedules. One model, two filings.
🎯 Quick question
A European marketplace enters the UK market in 2026. What is the practical consequence of DAC7 and the UK regime implementing the same OECD model rules?
Chapter 7. Timeline: licensing and regulatory deadlines.
A licensing timeline cannot be planned sequentially, because four workstreams move in parallel and the slowest one sets the launch date. That is almost never the regulatory file. The safeguarding account, local governance, and the technical connection often come later, so a backward plan that runs them one after another doubles the length of the project.
December 30, 2024
EU: information accompanying transfers
Regulation (EU) 2023/1113 becomes applicable, along with the European Banking Authority guidelines published on July 4, 2024.
January 31, 2025
UK: first platform report
Deadline for the first report to HMRC under the Platform Operators (Due Diligence and Reporting Requirements) Regulations 2023.
June 18, 2025
FATF: revised Recommendation 16
The standard is published under the title Payment transparency and requires structured originator and beneficiary data.
July 4, 2025
US: Form 1099-K threshold
The law retroactively restores the threshold of $20,000 and more than 200 transactions, as the IRS confirmed on October 23, 2025.
January 1, 2026
EU: DAC8
Crypto-asset reporting obligations take effect; the first report is due between January 1 and September 30, 2027.
July 10, 2027
EU: Anti-Money Laundering Regulation
Regulation (EU) 2024/1624 becomes applicable, with a €10,000 limit on cash payments to businesses (Article 80).
January 1, 2028
EU: direct supervision by AMLA
The Frankfurt-based authority begins directly supervising 40 financial entities across the EU.
End of 2030
FATF: implementation of Recommendation 16
Deadline set for jurisdictions to implement the revised payment transparency standard.
The four workstreams and where each one gets stuck
Regulatory: drafting, then review. The legal clock starts only once the authority considers the application complete
Banking: opening the safeguarding account requires due diligence by the partner bank, which takes about as long as the regulatory review. Open both files on the same day
Governance: managers to appoint and qualify, sometimes required to live locally. A fit-and-proper assessment takes weeks and starts over with every change
Technical: connecting to the national payment rail comes with its own certifications and go-live windows, independent of the license
🔑
Filing the application does not start the clock
Directive (EU) 2015/2366 gives the authority three months to decide. The clock starts on receipt of the application, or of all the required information if it was incomplete (Article 12). The authority alone decides when the application is complete, so an applicant can go back and forth for months without being late in legal terms. Budget for the preparation phase: it determines the commercial launch date.
🎯 Quick question
Your plan promises an EU license in four months, on the grounds that the authority has three months to decide. Where is the flaw?