AML for fintech is the transaction-monitoring, sanctions-screening, and SAR filing layer that fintechs, embedded-finance platforms, and BaaS-powered apps operate to satisfy partner-bank audit obligations, FinCEN BSA, FCA SYSC, and EU AMLR/AMLD6 requirements. It runs in real time at instant-payment speed and produces a case file the partner bank’s compliance team can audit on demand.
What does fintech AML actually have to do?
The AML for fintech category covers the same regulatory floor as bank AML but at fintech operating tempo (real-time payments, fast onboarding) and under partner-bank governance overlay (the partner bank inherits the fintech’s compliance failures). Four functions running simultaneously.
- Real-time transaction monitoring at instant-payment speed. FedNow settles in seconds. SEPA Instant settles in seconds. UPI settles in seconds. The AML for fintech system has to score the transaction at authorisation time and block, hold, or alert before settlement, not after.
- Identity-linked alerts. Every alert carries the verified KYC credential, the KYC tier, and the perpetual re-screening status. Mule networks scale on fintechs precisely because legacy stacks fire alerts on account IDs without joining identity.
- Partner-bank audit-export. Where the fintech operates under a BaaS partnership (Cross River, Evolve, Choice, Patriot, Lead, Stearns), the partner bank’s compliance team conducts annual reviews and increasingly quarterly reviews. The AML for fintech program has to produce the case file the partner-bank auditor expects, in the format they expect, on demand.
- SAR filing pipeline. SAR filing within 30 days (US), per-jurisdiction-specific timing elsewhere.
For the broader transaction-monitoring architecture, see our AML transaction monitoring 2026 piece. For the underlying KYC pattern, see our KYC for fintech industry page.
How does the partner-bank model shape fintech AML?
Most fintechs in the US operate under BaaS partnerships with sponsor banks. The partner bank holds the BSA obligation under FinCEN supervision; the fintech operates the customer relationship and the technology. After the TD Bank USD 1.3 billion FinCEN penalty (October 2024), partner banks materially raised the bar:
- Quarterly fintech compliance reviews instead of annual.
- Real-time visibility into the fintech’s alert pipeline rather than monthly summaries.
- Per-decision triage records for every alert, with the partner bank’s compliance team able to spot-check.
- Pre-approval on rule changes above a threshold of materiality.
- Exit clauses tightened so a partner bank can offboard a non-performing fintech in weeks rather than months.
A senior compliance lead at a US instant-payment-fintech we work with described the post-TD Bank dynamic on a customer call in March 2026: “we used to send the partner bank a monthly summary report. Now they ask for the case file on individual customers within 24 hours of request, and our review cycle is quarterly with weekly metric reporting in between. The technology had to follow the change.” The fintech program has to clear two audit bars simultaneously, and the partner-bank bar is currently the higher one.
What are the regulatory baselines for fintech AML?
Three jurisdictions set the operating floor for any cross-border fintech in 2026.
United States: FinCEN BSA, partner-bank governance, state MTL
Fintech obligations flow through the partner-bank’s BSA program in BaaS relationships, or directly through the fintech’s own MSB or Money Transmitter License (MTL) registration. Either way the program has to be reasonably designed and risk-based under 31 U.S.C. 5318(h)(2)(B)(iv), as amended by the Anti-Money Laundering Act of 2020. FinCEN proposed new AML/CFT program regulations on April 7, 2026, withdrawing its July 2024 proposal, with comments closed on June 9, 2026 and a 12-month implementation period proposed after any final rule. Nothing in it binds yet, and in a BaaS relationship the partner bank’s own program bar moves first. State-level MTL obligations in California, New York, Texas, Florida, and others layer on top.
European Union: AMLR, AMLD6, AMLA, instant-payment regulation
EU fintechs operate under the AMLR single rulebook (effective in phases through 2025-2027), AMLD6 transposed by member states, and AMLA direct supervision for the largest entities. Per-decision defensibility applies to every alert closure. The Instant Payment Regulation (Regulation 2024/886) phased in across 2025 for euro-area PSPs: receiving instant credit transfers from 9 January 2025, sending them from 9 October 2025, with PSPs in non-euro-area member states following in 2027. Execution has to complete within ten seconds at any hour, so any control that acts before settlement has to run at authorisation. Its sanctions provision runs the other way and is worth reading carefully: Article 5d replaced per-transaction EU sanctions screening during execution with screening the customer base at least once each calendar day and immediately after any listing change.
United Kingdom: FCA, MLR 2017, Faster Payments
UK fintechs operate under the FCA (and PRA for those with banking licences), Money Laundering Regulations 2017, and FCA Handbook SYSC. The 2024-2025 enforcement wave landed at GBP-billion-scale: Starling Bank GBP 29M (October 2024), Monzo Bank GBP 21M (July 2025).
Side-by-side: fintech AML obligations
| Dimension | US | EU | UK |
|---|---|---|---|
| Primary regulator | FinCEN + partner bank’s federal regulator + state MTL | National + AMLA (top entities) | FCA + PRA |
| Real-time monitoring | FedNow rails standard | Instant Payment Regulation, phased 2025 to 2027 | Faster Payments since 2008 |
| Audit standard | Reasonably designed and risk-based | Per-decision defensibility (AMLA) | SYSC + risk-based MLR |
| Partner-bank model | Common (Cross River, Evolve, Choice) | Less common, more direct authorisation | Direct authorisation typical |
| Recent landmark | Cash App / Block USD 160M (Mar 2025) | Revolut UAB EUR 3.5M (Apr 2025) | Starling GBP 29M, Monzo GBP 21M |
Where do fintech AML programs fail, and what does it cost?
Five reproducible failure modes show up across recent fintech enforcement.
Batch monitoring on instant-payment rails
A fintech running end-of-day batch against FedNow, SEPA Instant, or Faster Payments cannot block or hold a fraudulent transfer before settlement. Real-time scoring is now the regulatory expectation.
Identity-linkage gaps that let mule networks scale
Cash App / Block USD 160 million (March 2025) cited identity-linkage gaps explicitly. Mule networks scale on fintechs because account-level alerts without identity context cannot distinguish the mule from the legitimate user.
Alert backlog that ages SARs out of compliance
A 30-day-plus alert backlog means SARs file late or not at all. Starling and Monzo Final Notices both cited specific backlog figures.
Sanctions screening gap on partner-bank counterparties
A fintech running OFAC SDN screening on its own customers but not on the counterparties of its customers’ transactions has the Binance USD 4.3 billion-pattern gap, scaled down.
No partner-bank audit-export readiness
The partner bank’s compliance team requests a 12-month case file on a single customer. The fintech takes three weeks to produce it. The partner bank schedules a remediation review.
Recent enforcement timeline
| Date | Action | Penalty | Why it matters for fintech AML |
|---|---|---|---|
| 2023 | Binance settlement | USD 4.3B | Sanctions screening gaps cascade to BaaS-fintechs |
| Oct 2024 | TD Bank | USD 1.3B FinCEN, USD 3.1B combined | Partner-bank audit bar reset |
| Oct 2024 | Starling Bank | GBP 29M FCA | Control framework inconsistency in monitoring |
| 2024 | Revolut FCA Final Notice | GBP 3.1M | Same control-framework finding |
| Mar 2025 | Cash App / Block | USD 160M | Identity-linkage and monitoring gaps |
| Apr 2025 | Revolut Bank UAB | EUR 3.5M | AMLA-era documentation expectations |
| Jul 2025 | Monzo | GBP 21M FCA | High-risk customer onboarding gaps |
| Apr 2026 | FinCEN AML/CFT program reform NPRM | n/a | Proposed only, comments closed Jun 2026, 12-month runway after any final rule |
How does Zyphe deliver fintech AML at instant-payment speed?
Zyphe ships four primitives.
Real-time scoring at instant-payment authorisation time. FedNow, SEPA Instant, Faster Payments, UPI, Pix. Zyphe’s AML monitoring product scores transactions in single-digit milliseconds at the authorisation step and can block, hold, or flag before settlement. Cliff-edge rules (sanctioned counterparty, structuring at deposit, mule signatures) fire deterministically.
Identity-linked alerts. Every alert carries the verified KYC credential, the KYC tier, and the perpetual re-screening status. Mule indicators fire at the rule level. See our perpetual KYC piece.
Partner-bank audit-export ready. Case files exportable in the formats US partner banks expect, with per-decision triage records, SAR clock tracking, and rule-version history. The partner bank’s quarterly review goes from a three-week scramble to a one-day desk review.
No central store of customer PII. Source documents are sharded across thousands of decentralised storage nodes. The fintech holds the credential and the audit trail, not copies of the underlying documents.
How do you implement fintech AML across BaaS, embedded finance, and direct fintech?
Three patterns covering the most common deployment shapes.
BaaS / sponsor-bank fintech
Real-time scoring at authorisation, identity-linked alerts, partner-bank audit-export ready. Quarterly compliance review pre-loaded with case-file evidence. Rule-change pre-approval workflow integrated with the partner bank’s compliance team.
Embedded finance platform
The platform offers financial services to its end-customers but does not hold the regulatory licence directly. Obligations flow through the licensed partner. The fintech program here is the AML for fintech layer that keeps every partner relationship on the same evidence base.
Direct fintech with own MTL or banking licence
Standard bank-style obligations. Real-time monitoring, identity-linked alerts, SAR filing, regulatory examination preparedness. Higher per-decision defensibility documentation depth than BaaS-fintechs because the regulator interfaces directly. See our KYC for banking page for the deeper pattern.
What are the real edge cases fintech AML still struggles with?
Five edge cases worth flagging.
Embedded-finance multi-partner fan-out. Where the platform spans multiple licensed partners with different audit cadences and case-file format expectations.
Cross-border SCA exemption logic under PSD2. Risk-based exemption routing requires monitoring stack to surface buyer credential status to the payment processor.
Real-time fraud cliff-edges colliding with chargeback windows. Where chargeback and AML signal triage compete for the same alert queue.
Crypto-fintech overlap. Where the fintech offers crypto rails alongside fiat, the AML obligations from both regimes apply simultaneously. See our AML for crypto page.
Open banking data ingestion for AML signal. Where account aggregation through open banking creates new counterparty visibility but also data-protection complexity.
How do you evaluate fintech AML in the next 30 days?
Five concrete moves.
- Audit your real-time monitoring coverage. If any instant-payment rail (FedNow, SEPA Instant, Faster Payments) runs through batch, the audit gap is structural.
- Pressure-test partner-bank audit-export readiness. Ask the partner bank for the case file format they expect. Can you produce it in under 24 hours?
- Inventory typology coverage. Pull current rules and check coverage against FATF Recommendation 20 plus fintech-specific patterns (mule indicators, instant-payment fraud signatures).
- Pressure-test identity linkage. Pull 50 random alerts from the last 30 days. Confirm each carried the verified credential.
- Update DPIA and partner-bank audit documentation. Documentation depth is now the partner-bank-review focus, not just the regulator’s.