AML rules govern how payment firms onboard customers, monitor transactions and report suspicious activity. Here is Payment Expert’s guide to what they demand
Anti-money laundering rules set the terms on which a payment firm can operate, governing which customers it takes on and which transactions it lets through. For banks, payment processors and fintechs, they are a direct constraint on the core business of moving money.
Money laundering pushes criminal proceeds through legitimate financial systems to disguise where they came from, and anti-money laundering (AML) rules exist to detect that activity, block it and report it. Payments carry particular exposure, because high volumes, fast settlement and cross-border reach give criminals room to hide illicit funds among genuine transactions.
Payment institutions, e-money firms and money service businesses hold licences that place them directly in scope, while merchants generally fall outside direct regulation unless they operate in high-risk categories.
What AML rules require
The framework rests on a handful of controls:
- Know your customer (KYC) checks verify a customer’s identity at onboarding, using documents, electronic checks and, for companies, the beneficial owners behind the entity.
- Customer due diligence (CDD) assesses the risk each customer carries and applies enhanced checks to higher-risk clients.
- Sanctions and politically exposed person (PEP) screening tests customers and payments against watchlists that update constantly.
- Transaction monitoring examines payment patterns for behaviour consistent with laundering.
- Suspicious activity reports alert financial intelligence units when a firm cannot explain what it sees.
- Cash and value thresholds trigger additional reporting, and deliberately splitting payments to stay beneath them, known as structuring, is itself a reportable red flag.

These controls run across the customer relationship rather than at a single gate. “AML isn’t a single checkpoint, it runs throughout the customer and transaction lifecycle,” said Laurence Booth, Group CEO of Trust Payments to Payment Expert. Controls begin before a payment is processed, with due diligence and risk assessment, and post-settlement activity feeds back into a customer’s risk profile, so the assessment is never final, Booth said.
The obligations come from national and international law. The Financial Action Task Force (FATF), the intergovernmental body that sets global AML standards, issues recommendations that governments translate into statute. The EU‘s Anti-Money Laundering Directives, the US Bank Secrecy Act and the UK’s Money Laundering Regulations 2017 all build on that base. A firm operating across borders answers to several of these at once.
How the rules shape processing

Compliance is built into the payment process, it doesn’t run alongside it. Screening starts at onboarding, before an account goes live, and continues once money begins to move. Kevin McGuinness, Global Head of Strategy at Napier AI, said to Payment Expert that payment screening is a pre-transaction control that reads the sender, the recipient, the amount and the countries involved and can halt a transfer “even if the customer’s past behaviour appears legitimate.”
In the EU, the Instant Payments Regulation now requires name screening to run before a payment is submitted for clearing at all, a move, he notes, from screening transactions to screening the people behind them.
“A business in a supposedly high-risk sector with clean, well-documented flows can warrant less scrutiny than a lower-risk business showing erratic behaviour,” Jovi Overo said to Payment Expert, whose firm ONE.io makes a point of banking the iGaming, Web3 and commodities clients mainstream banks turn away.
It follows the FATF’s risk-based approach, and the principle that scrutiny should follow the risk. Sector, in his account, is a crude proxy. What counts more is the shape of the activity; where the money comes from and goes, who is on the other side, how large and fast the payments are, and whether the firm can see who is involved.
Real-time rails place the problem, under the spotlight, because a payment that settles in seconds leaves almost no room to question it before the money is gone. Manual review cannot keep up, so the checks run inside the flow, where they are only as good as the data feeding them.
Nick Fernando, Co-founder and Director of Aqua Global Solutions, told Payment Expert AML, sanctions and fraud tools can only make sound decisions on clean, complete and timely data, and that fragmenting it across systems leaves a firm either missing the pattern or generating too many false positives.
Real-time rails, he says, “need real-time controls, and that only works when payments infrastructure and financial crime systems are properly joined up.”
Who owns the risk

No one in the payment chain sees all of it. The merchant knows its customer and the reason for the payment; the payment service provider sees how payments behave across its book; the bank sees the account and the wider movement of funds, and each is partly blind to what the others hold.
The instinct is to hand the problem down the chain, an instinct Alex Clements, Head of AML at TransferMate, suggested to Payment Expert he no time for. “AML responsibility is not a relay baton that can simply be passed from the merchant to the PSP and then to the bank,” he says.
A firm can lawfully rely on another regulated party’s checks, but relying is not the same as offloading the accountability, which still demands clear standards, sight of the evidence and a working route to escalate. Failures, in his experience, fall into the space between institutions rather than inside any one of them.

Enforcement has hardened. Germany’s BaFin fined J.P. Morgan SE $52m (€45m) in November 2025 for filing its suspicious transaction reports too slowly, the regulator’s largest AML penalty to date, and the regulatory intelligence firm Vixio counted $40.7m (€36m) in fines against European payment and e-money firms across 30 enforcement actions in a single year, as Payment Expert reported in May 2025.
The published fine is only the visible part of the cost. For James Owusu, CEO and founder of Kord, “the fine is usually the smallest number on the bill.” Regulators tend to cap a firm’s growth while it remediates, at a cost that often runs to several times the penalty, and the harder loss is trust, as banking partners and clients leave fast and return slowly, if they return at all.
He told Payment Expert a serious failure is closer to existential than merely expensive for a business that exists to handle client money.
Transaction laundering lies behind many enforcement actions, where a legitimate merchant account quietly processes payments for someone else’s illegal trade. It is a payments-specific problem, and it is why the damage from weak controls runs past the fine.
A firm can lose the licence and the banking relationships it needs to process anything at all.