Reference🧭 Global overviewsIntermediate⏱ 22 min read

🚨 Anti-money laundering in payments

The FATF and its 40 Recommendations, the travel rule for credit transfers and crypto-assets, suspicious transaction reporting market by market, corridor de-risking, and transaction monitoring

The FATF: a standard without binding force

The Financial Action Task Force (FATF, Groupe d'action financière in French) is the intergovernmental body that sets international standards for combating money laundering and terrorist financing. It was created in July 1989 by a decision of the G7 summit in Paris. It has three functions: writing the Recommendations, assessing the countries that implement them, and maintaining two public lists that compliance teams around the world consult. The FATF does not legislate. None of these three outputs has the force of law, and a legal obligation arises only when each jurisdiction's legislature writes the standard into national law. Yet the standards shape account opening, corridor pricing, and onboarding times in almost every market, because institutions and their supervisors treat them as the common benchmark.

The standards consist of 40 Recommendations, first published in 1990 and revised in 1996 and 2003. In February 2012, they absorbed the nine Special Recommendations on terrorist financing adopted after 2001, and the two sets have formed a single text ever since. About 10 of the Recommendations govern payment activity directly, chief among them customer due diligence, wire transfers, and suspicious transaction reporting. The rest cover criminal law, international judicial cooperation, and non-financial professions.

July 1989
The FATF is founded
The G7 summit in Paris sets up a task force on money laundering, administratively hosted by the OECD.
1990
The 40 Recommendations
First edition of the standards, focused on the proceeds of drug trafficking. Fully revised in 1996.
October 2001
Eight Special Recommendations
Terrorist financing enters the mandate after the September 11 attacks. A ninth recommendation follows in October 2004. Special Recommendation VII is the basis of the travel rule.
2003
Second full revision
Scope extended to designated non-financial businesses and professions, and beneficial ownership gains prominence.
February 2012
Merged into a single set of standards
The 40 and the nine become 40. The risk-based approach becomes the core of the framework, and Recommendation 16 codifies the data a wire transfer must carry.
June 2019
Extended to virtual assets
The interpretive note to Recommendation 15 subjects virtual asset service providers to the same obligations as financial institutions, including the travel rule.
February 13, 2026
Where the two lists stand
Three jurisdictions under a call for action and 23 under increased monitoring (FATF, February 2026 plenary).
RecommendationTopicWhat it requires in practice
R. 10Customer due diligenceIdentify the customer, verify identity against reliable documents, understand the purpose of the relationship, and keep records up to date
R. 12Politically exposed personsScreening at onboarding and on an ongoing basis, senior management approval, and establishing the source of funds
R. 13Correspondent bankingDue diligence on the respondent bank, a ban on shell banks, and controls on payable-through accounts
R. 14Money or value transfer servicesLicensing or registration of MTOs, mobile money, and informal systems; listing and supervision of agents
R. 15New technologiesLicensing or registration of virtual asset service providers, under the same regime as banks
R. 16Wire transfersOriginator and beneficiary information travels with the payment through the entire chain of intermediaries
R. 20Suspicious transaction reportingPrompt report to the financial intelligence unit, with no amount threshold, attempted transactions included
R. 21Protection and confidentialityLegal immunity for good-faith reporting, and a ban on tipping off the customer
R. 24 and 25Beneficial ownershipAccurate, current information, available to authorities in a timely manner, for companies and legal arrangements
The Recommendations a payments professional works with
40
FATF members: 38 jurisdictions plus two regional organizations, the European Commission and the Gulf Cooperation Council
FATF, 2023
9
FATF-style regional bodies (MONEYVAL, GAFILAT, MENAFATF, GIABA, ESAAMLG, APG…) that assess non-member countries
GAFI
3
jurisdictions under a call for action as of February 13, 2026
FATF, February 2026 plenary
23
jurisdictions under increased monitoring on the same date
FATF, February 2026 plenary
🔑
What a mutual evaluation actually rates
A mutual evaluation is the review in which the FATF, or the relevant regional body, assesses a jurisdiction's AML/CFT framework. It produces two separate ratings. Technical compliance measures whether the laws exist, recommendation by recommendation. Effectiveness measures what the framework actually achieves across 11 immediate outcomes, rated from high to low. The two ratings do not move together. A country can transpose every line of the standards and still fail to deliver the expected results. Gray-listing almost always follows from the second rating.

The two lists and what they do to corridor pricing

The FATF publishes two lists of jurisdictions after each plenary, in February, June, and October. The first covers high-risk jurisdictions subject to a call for action, commonly called the blacklist. The second covers jurisdictions under increased monitoring, the gray list, whose governments have committed to an action plan with deadlines. Neither list creates a direct prohibition, because the FATF has no binding power over institutions. The effects are still immediate. They come through the decisions of the banks and supervisors that read the lists, and they reach both account opening and transaction pricing.

ListJurisdictionsWhat an institution does
Call for action (“blacklist”)North Korea, Iran, MyanmarCountermeasures and systematic enhanced due diligence, up to refusing to do business. Applies alongside sanctions regimes, which are separate and often stricter
Increased monitoring (“gray list”)Algeria, Angola, Bolivia, Bulgaria, Cameroon, Côte d'Ivoire, Haiti, British Virgin Islands, Kenya, Kuwait, Laos, Lebanon, Monaco, Namibia, Nepal, Papua New Guinea, Democratic Republic of the Congo, Senegal, South Sudan, Syria, Venezuela, Vietnam, YemenCase-by-case enhanced due diligence, heavier correspondent questionnaires, longer onboarding, and review of existing accounts
The two FATF lists as of February 13, 2026

Gray-listing does not close a single account on its own. It shifts the burden onto the institution, which must now show that it has its flows under control. The correspondent bank asks for more documents, requires documented governance, and charges for the extra work. Two jurisdictions on the February 2026 list matter directly for European payments. Bulgaria is an EU member state, and Monaco participates in SEPA. Belonging to an integrated regulatory area therefore says nothing about a FATF rating. The rating covers the national framework itself: its laws and the results they achieve.

  • Onboarding time stretches from a few weeks to several months for an institution whose headquarters or flows touch a listed jurisdiction.
  • The correspondent questionnaire gets heavier: the Wolfsberg Group's CBDDQ, the industry standard since 2018, becomes the minimum expected.
  • The corridor gets more expensive, because the correspondent passes its due diligence costs on to volumes that stay small.
  • Delistings matter as much as listings: the FATF removed Burkina Faso, Mozambique, Nigeria, and South Africa in October 2025, and the United Arab Emirates in February 2024.
  • The latest additions, in February 2026, are Kuwait and Papua New Guinea.
⚠️
FATF lists are not sanctions
An international financial sanction is an asset freeze or a prohibition targeting a person, an entity, or a state designated by a competent authority. The FATF imposes none. Sanctions regimes (the UN Security Council, the EU, the US Treasury's OFAC, national authorities) are strict-liability obligations, whereas the FATF Recommendations follow a risk-based approach. A payment can therefore be fully compliant with the FATF Recommendations and still be a criminal offense under a sanctions regime. The two frameworks apply side by side and call for different tools.

The travel rule for credit transfers

The travel rule requires every institution in the payment chain to pass along the originator's and the beneficiary's identifying information with the payment. Recommendation 16 codifies it and requires that information to travel from one end of the chain to the other. It descends from Special Recommendation VII of 2001, which was folded into the standards in the 2012 overhaul. The rule addresses a basic feature of cross-border transfers: they pass through intermediaries that know neither the payer nor the payee, and no intermediary can screen information it never received.

DataAmount above thresholdAmount below threshold
Originator nameRequired, verified against documentsRequired, verified only if there is suspicion
Account number or unique transaction referenceMandatoryMandatory
Address, national ID number, date and place of birth, or customer numberAt least one of theseNot required
Beneficiary nameMandatoryMandatory
Beneficiary account numberMandatoryMandatory
Data required by Recommendation 16 on a cross-border wire transfer
MarketApplicable lawThresholdWatch out for
International standardFATF Recommendation 16 and its interpretive note$1,000 or €1,000A floor only. Each jurisdiction can be stricter, and many are
European UnionRegulation (EU) 2023/1113 of May 31, 2023, in force since December 30, 2024€1,000 for verification on intra-EU transfers; no threshold for crypto-assetsReplaces Regulation (EU) 2015/847 and extends the regime to crypto-asset transfers
United StatesBank Secrecy Act; 31 CFR 1010.410(f) for the travel rule$3,000A 2020 proposed rule to lower the threshold to $250 for cross-border transfers was never finalized
Travel rule thresholds by market
How the data travels in a cross-border correspondent transfer
Originator's bank
Compiles, verifies, and sends
Name, account number, and one additional identifier. Sanctions screening of both originator and beneficiary before sending
Correspondent bank
Relays without changes
Must retain all the data received and pass it on in full. Screens against its own regulatory scope, which differs from the sender's
Next intermediary
Detects missing data
A risk-based policy decides whether to execute, suspend, or reject the payment, or to ask the previous institution for the missing data
Payee’s bank
Checks, then credits
Looks for missing fields, verifies the beneficiary's identity where local law requires it, and decides whether to report
Financial intelligence unit
Receives what the chain produced
Its view is only as good as the data carried. A field truncated upstream cannot be rebuilt downstream
The ISO 20022 pacs.008 fields the travel rule looks at
<CdtTrfTxInf>
  <PmtId>
    <EndToEndId>INV-2026-004821</EndToEndId>
    <UETR>4c8a1f70-2b1e-4c9a-9d33-7b0e5a1c8f42</UETR>
  </PmtId>
  <IntrBkSttlmAmt Ccy="USD">18500.00</IntrBkSttlmAmt>

  <Dbtr>                            <!-- originator -->
    <Nm>NOVA TEXTILES LIMITED</Nm>
    <PstlAdr>                       <!-- STRUCTURED address, not free text -->
      <StrtNm>Jalan Sudirman</StrtNm>
      <BldgNb>52</BldgNb>
      <TwnNm>Jakarta</TwnNm>
      <Ctry>ID</Ctry>
    </PstlAdr>
    <Id><OrgId><LEI>529900T8BM49AURSDO55</LEI></OrgId></Id>
  </Dbtr>
  <DbtrAcct><Id><Othr><Id>0123456789</Id></Othr></Id></DbtrAcct>
  <DbtrAgt><FinInstnId><BICFI>BMRIIDJAXXX</BICFI></FinInstnId></DbtrAgt>

  <Cdtr>                            <!-- beneficiary -->
    <Nm>ATLAS IMPORT GMBH</Nm>
    <PstlAdr><TwnNm>Hamburg</TwnNm><Ctry>DE</Ctry></PstlAdr>
  </Cdtr>
  <CdtrAcct><Id><IBAN>DE89370400440532013000</IBAN></Id></CdtrAcct>
</CdtTrfTxInf>
⚠️
What breaks in production
Three execution failures show up in every audit. Truncated fields in legacy systems cut names off after 35 characters, and screening an incomplete name no longer produces a usable match. Free-text addresses, where a machine cannot pick out the city and country, multiply false positives. Cover payments, where the customer instruction and the interbank settlement traveled in two separate messages, hid the real originator's identity from the intermediary. The move to ISO 20022 fixes the first two structurally, because the format requires separate fields for the name and for each part of the address. The MT/MX coexistence period for cross-border payments ended on November 22, 2025 (Swift), and the legacy format is no longer an excuse for incomplete data.

The travel rule for crypto-assets

Virtual asset service providers (VASPs) are entities that exchange, transfer, or hold virtual assets on behalf of others. In June 2019, the FATF extended Recommendation 15 to them and made them subject to the same obligations as financial institutions. Since then, a token transfer between two platforms has had to carry the same data as a bank transfer, even though the underlying protocol has no field for it. The industry has therefore built an off-chain messaging layer that runs alongside the ledger and attaches both parties' identities to each transfer.

  • What counts as a VASP: exchange between fiat currency and virtual assets, exchange between virtual assets, transfer, custody on behalf of others, and financial services related to issuance or sale.
  • The data standard: IVMS 101, published by the InterVASP Messaging Standards Group, standardizes how the identities exchanged between providers are represented.
  • Transport: several competing protocols coexist with no guaranteed interoperability, which remains the weak point of the system.
  • Self-hosted wallets: in the EU, a transfer of more than €1,000 to or from a self-hosted address requires the provider to verify that the customer actually owns it.
  • Address screening: blockchain analytics partly replaces conventional transaction monitoring, with its own limits when privacy-enhancing protocols are involved.
MarketLegal basisImplementation statusObserved effect
European UnionMiCA, Regulation (EU) 2023/1114, supplemented by Regulation (EU) 2023/1113 on transfersTitles III and IV in force since June 30, 2024; the transfer regime since December 30, 2024Non-compliant stablecoins, USDT first among them, have been delisted from platforms serving the EU
Hong KongStablecoins Ordinance (Cap. 656), passed May 21, 2025In force since August 1, 202577 expressions of interest received by the HKMA as of August 31, 2025; no license granted before the first quarter of 2026
United StatesGENIUS Act, the federal framework for payment stablecoinsSigned into law July 18, 2025; takes effect January 18, 2027 at the earliestFull reserve backing required, not classified as securities, no direct access to the Federal Reserve
Three benchmark regimes for payment tokens
⚠️
The sunrise issue
The sunrise issue is the uneven application of the travel rule across jurisdictions, depending on when each one implemented Recommendation 15. A European provider subject to the rule sends data to a counterparty in a country that has not implemented it yet. That recipient has neither the obligation to receive the data nor the systems to process it, so the compliance burden falls on one side of the transaction only. The imbalance pushes regulated providers to shrink their list of counterparties, which reproduces in virtual assets the de-risking seen in correspondent banking.

The biggest blind spot in the system is geographic. Tether's USDT, the leading stablecoin rail by real-world use, serves as a substitute dollar in economies with capital controls or high inflation, from Turkey to Argentina and from Nigeria to Southeast Asia. Its market capitalization exceeds $183 billion (CoinGecko, late July 2026). It does not comply with MiCA, and platforms serving the EU have delisted it. The rail keeps running outside those platforms. Bringing one market into compliance therefore pushes transfers outside the supervised scope rather than eliminating them.

Suspicious transaction reporting by market

A suspicious transaction report (STR) is how a regulated institution alerts its country's financial intelligence unit (FIU) to a transaction it suspects is linked to a crime. Recommendation 20 requires prompt reporting of any transaction suspected of involving criminal proceeds or terrorist financing. No amount threshold applies, and attempted transactions count as much as completed ones. Recommendation 21 adds two rules that go together: immunity for good-faith reporting and an absolute ban on tipping off the customer.

MarketFinancial intelligence unitReport nameOperational specifics
United StatesFinCEN, created April 25, 1990 (Treasury)Suspicious Activity Report (SAR)Obligation stems from the Annunzio-Wylie Act of 1992. Filed within 30 calendar days. $2,000 trigger threshold for money services businesses. Tipping off the customer is a criminal offense
United KingdomUK Financial Intelligence Unit, part of the National Crime AgencySuspicious Activity Report (SAR)Consent regime specific to the Proceeds of Crime Act 2002: a defence against money laundering request holds the transaction for 7 working days, followed by a 31-calendar-day moratorium
European UnionOne FIU per member state, coordinated by AMLASuspicious transaction reportAMLA is based in Frankfurt and has been operating since July 1, 2025. It is expected to start directly supervising a first group of institutions in 2028
FranceTracfin, France's FIU, created in 1990Suspicious transaction reportA national agency under the economy ministry, with the power to block a transaction before it is executed
AustraliaAUSTRACSuspicious matter report (SMR)Three separate reports that add up: the SMR, reporting of cash transactions above A$10,000, and reporting of every international funds transfer instruction (IFTI)
IndiaFIU-INDSuspicious Transaction Report (STR)Governed by the Prevention of Money Laundering Act of 2002. Digital asset providers have been covered since March 2023, including offshore platforms that serve Indian residents
BrazilCOAFComunicação de operação suspeitaFiled electronically, with specific obligations for payment institutions under Banco Central do Brasil rules
SingaporeSuspicious Transaction Reporting Office, part of the policeSuspicious Transaction Report (STR)Payment service providers are subject to the Monetary Authority of Singapore's AML/CFT notices issued under the Payment Services Act of 2019
KenyaFinancial Reporting CentreSuspicious Transaction ReportUnder FATF increased monitoring since February 2024, which adds to any foreign correspondent's due diligence
NigeriaNigerian Financial Intelligence UnitSuspicious Transaction ReportRemoved from the FATF gray list in October 2025, after an action plan that covered supervision of money transfer operators, among other things
Reporting a suspicious transaction, market by market

FIUs communicate with each other through the Egmont Group, founded in 1995 at the Egmont Palace in Brussels, which now has more than 170 members. Its encrypted network, the Egmont Secure Web, carries their requests for assistance. Only the FIUs themselves have access; regulated institutions do not. A payment provider feels its effects only when its supervisor or its bank passes on a request for information about a customer or a transaction.

⚠️
The ban on tipping off the customer
Tipping off, or telling a customer that a report has been filed, is a criminal offense in most jurisdictions, including the US and the UK. The ban extends to customer-facing roles: customer service, relationship managers, and technical support. These employees must explain a frozen account or a held transaction without revealing why, which calls for neutral wording drafted in advance and approved by the legal team. An improvised explanation over the phone exposes both the institution and the person speaking. The risk is personal as much as institutional.

Report quality is the system's acknowledged weakness. An institution that fears penalties files defensively, and the receiving FIU gets a growing volume of reports with nothing actionable in them. In 2020, the Bank Policy Institute found that US authorities followed up on a median of just 4% of reports. The number of reports filed therefore says nothing about how well the underlying program works. Supervisors look instead at the alert-to-report conversion rate, the written rationale for alerts closed without a filing, and the time from detection to filing.

De-risking and its impact on corridors

De-risking means terminating or refusing business relationships wholesale, for entire categories of customers or countries, instead of managing risk case by case. It typically takes one of two forms: a bank closes the accounts of every money transfer operator, or a correspondent pulls out of an entire region. The FATF has condemned the practice since 2014, and in 2021 it launched work on the unintended consequences of its own standards. Correspondent relationships have kept declining since then.

De-risking shows up most clearly in correspondent banking, the layer of bilateral relationships that makes any payment possible between two banks with no direct link. The Committee on Payments and Market Infrastructures (CPMI) of the Bank for International Settlements publishes the benchmark indicator. Built from Swift messages under a mandate from the Financial Stability Board, it covers more than 200 jurisdictions. The network has been shrinking and concentrating since the early 2010s. Every relationship that disappears lengthens the chain of intermediaries needed to reach a destination, and the cost of that chain falls on corridors whose volumes are too small to absorb it.

≈ $656B
remittances received by low- and middle-income countries in 2023
World Bank / KNOMAD
6,7 %
global average cost of sending $200 in the second quarter of 2024, down from 6.2% a year earlier
World Bank, Remittance Prices Worldwide, cited in the UN's 2025 SDG report
3 %
cost target set by Sustainable Development Goal 10.c, never met
United Nations
> 200
jurisdictions covered by the CPMI correspondent banking indicator
CPMI, Bank for International Settlements
🇲🇽
SPID (Banco de México, 2016)
A dollar settlement system for accounts held at banks based in Mexico, with a stricter compliance regime. Set up after US correspondents pulled back, it has become essential for Mexican exporters.
🌏
Pacific Transfers / MyCash
Direct mobile transfers between users in Fiji, Samoa, Tonga, and Vanuatu, run by Digicel Pacific. One of the few intra-Pacific rails that bypass correspondents, in a region where banks pulled out on a massive scale.
🇨🇳
XTransfer
Multicurrency and local accounts in about 60 territories for Chinese exporting SMEs. It replaces the correspondent bank, which this segment lost access to after due diligence rules were tightened.
🕸️
Hawala
A network of independent brokers who settle among themselves, with no cross-border movement of funds for each transaction. The FATF and the IMF classify it as an informal value transfer system. Its lack of a usable audit trail has kept it under constant regulatory pressure since 2001.
🇦🇫
HesabPay
A digital aid distribution channel in Afghanistan, used by the World Food Programme and World Bank-backed programs. A payment rail has replaced the banking system in a country under sanctions.
🌍
TCIB (PayInc, 2021)
Low-value instant push credits in the SADC region, cleared immediately and settled later. It aims to formalize the largely informal corridors from South Africa to Zimbabwe, Malawi, and Mozambique.
🔑
A closed corridor does not disappear
Closing a banking corridor does not eliminate the need that fed it. Diaspora remittances move to mobile money, unregistered operators, hawala, or stablecoins, channels that fall wholly or partly outside the reporting regime. The FIU then loses the visibility it had into the banking flow. De-risking thus achieves the opposite of its stated goal, which is to reduce money laundering exposure. The criticism comes from the standard setters themselves: the FATF has condemned the practice since 2014.
  • Document your risk appetite by country, business line, and channel, and be ready to present it. A written, dated policy approved by the board holds up in front of a supervisor or a correspondent, which an improvised call in a credit committee never will.
  • Complete the Wolfsberg Group CBDDQ before anyone asks. It has become the entry ticket to any correspondent relationship.
  • Secure a fallback route to settlement: CENTROlink, run by the Bank of Lithuania since 2016, gives payment institutions and e-money institutions direct access to SEPA without a sponsor bank.
  • Watch concentration: relying on a single correspondent for a corridor exposes you to a unilateral exit with no meaningful notice.
  • Prepare for the portfolio reviews that a gray-listing triggers, even when the institution's exposure to the country is only indirect.

Transaction monitoring

Transaction monitoring is the review of transactions that have already been executed, designed to flag those that deviate from a customer's expected behavior. It is distinct from two related controls it is often confused with, even in requirements documents. Sanctions screening runs before execution and blocks the transaction. Transaction monitoring detects after the fact. Onboarding due diligence builds the customer file when the account is opened. The confusion is costly, because each control has its own legal regime and its own tolerance for error.

Sanctions screeningTransaction monitoringOnboarding due diligence
TimingBefore execution, in real timeAfter execution, continuously or in batchesAt account opening, then periodic refresh
Legal basisNational and international sanctions regimesFATF Recommendation 20FATF Recommendations 10 and 12
LogicName matching, strict liabilityRisk-based approach, best-efforts obligationRisk-based approach, documented file
Typical failureFalse positive on a namesake or a transliterationAlert not cleared within the internal deadlineOutdated file, beneficial owner not updated
Consequence of a failureCriminal offense, asset freeze, fine, loss of the correspondentFailure to report, supervisory penaltySupervisory penalty, mandated remediation
Three controls, three logics
From alert to report
Collection
Aggregates transaction and customer data
Amount, currency, counterparty, country, channel, history, stated line of business
Scenario engine
Applies rules and models
Thresholds, structuring, velocity, deviation from the expected profile, exposure to a listed jurisdiction
Level 1 analyst
Works the alert
Closes it with a written rationale or escalates it. That rationale is what the supervisor will read, years later
Level 2 analyst
Investigates
Traces the flow of funds, runs open-source research, and queries the relationship managers
AML/CFT officer
Decides to file
A personal decision, in the officer's own name, in most regimes. The person who makes it is accountable for it
Retention
Archives the audit trail
At least five years under Recommendation 11, longer in several jurisdictions
Monitoring scenario for structuring below the reporting threshold
SCENARIO  ST-014  "structuring / splitting"
SCOPE     consumer payment accounts, account age < 180 days

TRIGGER
  nb_inbound_transactions(window = 10 days) >= 5
  AND each amount between 0.80 x THRESHOLD and 0.99 x THRESHOLD
  AND cumulative_total > 3 x THRESHOLD
  AND nb_distinct_counterparties >= 3

AUTOMATIC ENRICHMENT
  + counterparty country on a FATF list            -> score +30
  + account credited, then > 90% drained in 48 h -> score +40
  + IP address outside the declared country        -> score +10

OUTPUT
  score >= 60  -> level 2 alert, 5 business days to process
  score <  60  -> level 1 alert, written closing rationale required

TUNING    thresholds reviewed every six months, deviations justified in writing,
          test set replayed before any production release
⚠️
Instant payments have eliminated the review window
A conventional SEPA credit transfer left several hours between the payment instruction and settlement, and an alert could still be worked in that window. Pix in Brazil, UPI in India, PromptPay in Thailand, PayNow in Singapore, DuitNow in Malaysia, QRIS in Indonesia, and SCT Inst in Europe settle in seconds, with no recall. Detection now necessarily comes after settlement. The mule account, opened to receive fraudulent funds, is where this gap is exploited. Opened in minutes through a fully digital flow, it receives the funds, splits them, and drains them within an hour. By the time the rules engine reaches a verdict, settlement is already irrevocable. The point of control therefore shifts to the quality of onboarding.

Two markets show how regulators have responded to this upstream shift in controls. In China, NetsUnion Clearing Corporation has required since June 2018 that all online payments by non-bank institutions be routed through it rather than through direct connections to banks. Since then, the central bank has had a centralized view of Alipay and Tenpay flows, and in 2025 it placed the three entities under direct AML/CFT supervision. In India, the Reserve Bank of India tightened onboarding rules in 2025 for operators of the Aadhaar Enabled Payment System, a rural inclusion rail that has become a documented fraud vector.

  • Model governance is examined as closely as model performance: who approves a threshold, based on what data, and with what independent review.
  • Tuning decisions must be justified in writing. Raising a threshold to cut alert volume without a documented analysis is the most common finding in examinations.
  • Typology coverage must be demonstrable: every risk identified in the risk assessment needs at least one active scenario.
  • Data completeness matters more than engine sophistication. A channel that is not connected to the engine is a complete blind spot.
  • Name screening must handle transliteration and non-Latin scripts. Without that, the real detection rate collapses on exactly the corridors where customer names are not written in the Latin alphabet.

What compliance costs and what gets penalized

An AML/CFT penalty is a measure imposed on an institution by a supervisor or a court for failures in its due diligence, monitoring, and reporting obligations. Nothing else in payments comes close in scale. Amounts run into the billions, some settlements include a guilty plea, and some measures cap an institution's growth for years. The table below lists public decisions only. They rarely rest on proven money laundering; most often, they target the failure of the control framework itself.

YearInstitutionAuthorityAmount or measureGrounds
2020WestpacAUSTRAC (Australia)A$1.3BFailure to report international transfers and no due diligence on flows to Southeast Asia
2022Danske BankUS Department of Justice$2.059BGuilty plea to bank fraud over flows that went through the Estonian branch
2023BinanceUS authorities$4.3BBank Secrecy Act violations and no effective compliance program
2024TD BankUS authorities≈ $3.09BAML/CFT program failures, guilty plea, and an asset cap
2024Qiwi BankBank of RussiaLicense revoked (February 21, 2024)Repeated AML/CFT failures; wallets shut down and removal from the Contact transfer system
Landmark public AML/CFT enforcement actions

The day-to-day cost of the framework does not come from penalties. It falls into three buckets: designated roles, third-party software, and building an audit trail. The AML/CFT officer is personally liable in most regimes, and the decision to file remains a personal one. Screening and monitoring tools are priced per active customer or per transaction, and tuning them takes more time than deploying them. A clean external audit matters as much for keeping banking relationships as for keeping the license.

  • Risk assessment documented by business line, channel, product, customer segment, and geography, and updated whenever the scope changes.
  • Policies and procedures approved by the board, with quantified thresholds and binding handling times.
  • A proportionate due diligence framework, including simplified rules for low-value accounts. Colombia's Daviplata, a low-value deposit product launched in 2011, became the regulatory template for the entire Andean region.
  • Screening and monitoring connected to every channel, with an inventory of active scenarios and the rationale for each.
  • Reporting and record-keeping: an internal escalation path, neutral wording for customers, and records kept for at least five years.
  • Training and independent testing: an annual plan for each at-risk group of employees, and periodic audits reported to the board.

Payment infrastructure offers one possible path forward. Project Mandala tested encoding regulatory checks into the payment protocol itself, so that compliance checks run before the transfer. The BIS Innovation Hub ran it with the Reserve Bank of Australia, the Bank of Korea, Bank Negara Malaysia, and the Monetary Authority of Singapore. The project starts from the premise that cross-border payments are held back by compliance, not by transfer technology.

🔑
What compliance actually buys
The AML/CFT framework controls access to the infrastructure the business depends on: the settlement account, the correspondent bank, the card network, and the license. An operator that loses its correspondent loses access to the corridor it serves, however good its product. Entering a new market therefore takes two separate assessments. The first asks whether a local way to collect payments exists. The second identifies which institution is willing to provide settlement and on what terms, and the answer depends as much on the operator's compliance framework as on the correspondent's risk appetite.