Skip to content
Free guide: How to use AI in compliance
Built for fintechs, BaaS platforms, embedded finance, and instant-payment apps

AML for Fintech: How to Satisfy Your Partner Bank's Audit Without Killing Onboarding Speed

The Cash App / Block USD 160 million FinCEN penalty (March 2025) was the bellwether for what regulators expect from fintech AML in 2026. Identity-linkage gaps, alert backlog, and weak sanctions coverage at scale. The TD Bank USD 1.3 billion penalty (October 2024) raised the partner-bank-side audit bar across every BaaS relationship in the US. Fintechs operating on FedNow, SEPA Instant, UPI, or Pix can no longer run end-of-day batch monitoring and call it a program. Done well in 2026, this layer is real-time, identity-linked at the alert layer, partner-bank ready, and built on an architecture with no central store of customer PII.

AML for fintech architecture for BaaS, embedded finance, and direct fintech showing real-time monitoring, identity-linked alerts, partner-bank audit-export, and FedNow SEPA Instant integration
Used by fintechs, BaaS platforms, and embedded-finance apps to satisfy partner-bank audits and instant-payment monitoring without storing copies of the underlying identity documents.
  • FinCEN BSA
  • FCA SYSC
  • EU AMLD6
  • FedNow ready
  • SEPA Instant
  • Partner-bank audit-ready
  • No central PII store

AML for fintech is the transaction-monitoring, sanctions-screening, and SAR filing layer that fintechs, embedded-finance platforms, and BaaS-powered apps operate to satisfy partner-bank audit obligations, FinCEN BSA, FCA SYSC, and EU AMLR/AMLD6 requirements. It runs in real time at instant-payment speed and produces a case file the partner bank’s compliance team can audit on demand.

What does fintech AML actually have to do?

The AML for fintech category covers the same regulatory floor as bank AML but at fintech operating tempo (real-time payments, fast onboarding) and under partner-bank governance overlay (the partner bank inherits the fintech’s compliance failures). Four functions running simultaneously.

  • Real-time transaction monitoring at instant-payment speed. FedNow settles in seconds. SEPA Instant settles in seconds. UPI settles in seconds. The AML for fintech system has to score the transaction at authorisation time and block, hold, or alert before settlement, not after.
  • Identity-linked alerts. Every alert carries the verified KYC credential, the KYC tier, and the perpetual re-screening status. Mule networks scale on fintechs precisely because legacy stacks fire alerts on account IDs without joining identity.
  • Partner-bank audit-export. Where the fintech operates under a BaaS partnership (Cross River, Evolve, Choice, Patriot, Lead, Stearns), the partner bank’s compliance team conducts annual reviews and increasingly quarterly reviews. The AML for fintech program has to produce the case file the partner-bank auditor expects, in the format they expect, on demand.
  • SAR filing pipeline. SAR filing within 30 days (US), per-jurisdiction-specific timing elsewhere.

For the broader transaction-monitoring architecture, see our AML transaction monitoring 2026 piece. For the underlying KYC pattern, see our KYC for fintech industry page.

How does the partner-bank model shape fintech AML?

Most fintechs in the US operate under BaaS partnerships with sponsor banks. The partner bank holds the BSA obligation under FinCEN supervision; the fintech operates the customer relationship and the technology. After the TD Bank USD 1.3 billion FinCEN penalty (October 2024), partner banks materially raised the bar:

  • Quarterly fintech compliance reviews instead of annual.
  • Real-time visibility into the fintech’s alert pipeline rather than monthly summaries.
  • Per-decision triage records for every alert, with the partner bank’s compliance team able to spot-check.
  • Pre-approval on rule changes above a threshold of materiality.
  • Exit clauses tightened so a partner bank can offboard a non-performing fintech in weeks rather than months.

A senior compliance lead at a US instant-payment-fintech we work with described the post-TD Bank dynamic on a customer call in March 2026: “we used to send the partner bank a monthly summary report. Now they ask for the case file on individual customers within 24 hours of request, and our review cycle is quarterly with weekly metric reporting in between. The technology had to follow the change.” The fintech program has to clear two audit bars simultaneously, and the partner-bank bar is currently the higher one.

What are the regulatory baselines for fintech AML?

Three jurisdictions set the operating floor for any cross-border fintech in 2026.

United States: FinCEN BSA, partner-bank governance, state MTL

Fintech obligations flow through the partner-bank’s BSA program in BaaS relationships, or directly through the fintech’s own MSB or Money Transmitter License (MTL) registration. Either way the program has to be reasonably designed and risk-based under 31 U.S.C. 5318(h)(2)(B)(iv), as amended by the Anti-Money Laundering Act of 2020. FinCEN proposed new AML/CFT program regulations on April 7, 2026, withdrawing its July 2024 proposal, with comments closed on June 9, 2026 and a 12-month implementation period proposed after any final rule. Nothing in it binds yet, and in a BaaS relationship the partner bank’s own program bar moves first. State-level MTL obligations in California, New York, Texas, Florida, and others layer on top.

European Union: AMLR, AMLD6, AMLA, instant-payment regulation

EU fintechs operate under the AMLR single rulebook (effective in phases through 2025-2027), AMLD6 transposed by member states, and AMLA direct supervision for the largest entities. Per-decision defensibility applies to every alert closure. The Instant Payment Regulation (Regulation 2024/886) phased in across 2025 for euro-area PSPs: receiving instant credit transfers from 9 January 2025, sending them from 9 October 2025, with PSPs in non-euro-area member states following in 2027. Execution has to complete within ten seconds at any hour, so any control that acts before settlement has to run at authorisation. Its sanctions provision runs the other way and is worth reading carefully: Article 5d replaced per-transaction EU sanctions screening during execution with screening the customer base at least once each calendar day and immediately after any listing change.

United Kingdom: FCA, MLR 2017, Faster Payments

UK fintechs operate under the FCA (and PRA for those with banking licences), Money Laundering Regulations 2017, and FCA Handbook SYSC. The 2024-2025 enforcement wave landed at GBP-billion-scale: Starling Bank GBP 29M (October 2024), Monzo Bank GBP 21M (July 2025).

Side-by-side: fintech AML obligations

Dimension US EU UK
Primary regulator FinCEN + partner bank’s federal regulator + state MTL National + AMLA (top entities) FCA + PRA
Real-time monitoring FedNow rails standard Instant Payment Regulation, phased 2025 to 2027 Faster Payments since 2008
Audit standard Reasonably designed and risk-based Per-decision defensibility (AMLA) SYSC + risk-based MLR
Partner-bank model Common (Cross River, Evolve, Choice) Less common, more direct authorisation Direct authorisation typical
Recent landmark Cash App / Block USD 160M (Mar 2025) Revolut UAB EUR 3.5M (Apr 2025) Starling GBP 29M, Monzo GBP 21M

Where do fintech AML programs fail, and what does it cost?

Five reproducible failure modes show up across recent fintech enforcement.

Batch monitoring on instant-payment rails

A fintech running end-of-day batch against FedNow, SEPA Instant, or Faster Payments cannot block or hold a fraudulent transfer before settlement. Real-time scoring is now the regulatory expectation.

Identity-linkage gaps that let mule networks scale

Cash App / Block USD 160 million (March 2025) cited identity-linkage gaps explicitly. Mule networks scale on fintechs because account-level alerts without identity context cannot distinguish the mule from the legitimate user.

Alert backlog that ages SARs out of compliance

A 30-day-plus alert backlog means SARs file late or not at all. Starling and Monzo Final Notices both cited specific backlog figures.

Sanctions screening gap on partner-bank counterparties

A fintech running OFAC SDN screening on its own customers but not on the counterparties of its customers’ transactions has the Binance USD 4.3 billion-pattern gap, scaled down.

No partner-bank audit-export readiness

The partner bank’s compliance team requests a 12-month case file on a single customer. The fintech takes three weeks to produce it. The partner bank schedules a remediation review.

Recent enforcement timeline

Date Action Penalty Why it matters for fintech AML
2023 Binance settlement USD 4.3B Sanctions screening gaps cascade to BaaS-fintechs
Oct 2024 TD Bank USD 1.3B FinCEN, USD 3.1B combined Partner-bank audit bar reset
Oct 2024 Starling Bank GBP 29M FCA Control framework inconsistency in monitoring
2024 Revolut FCA Final Notice GBP 3.1M Same control-framework finding
Mar 2025 Cash App / Block USD 160M Identity-linkage and monitoring gaps
Apr 2025 Revolut Bank UAB EUR 3.5M AMLA-era documentation expectations
Jul 2025 Monzo GBP 21M FCA High-risk customer onboarding gaps
Apr 2026 FinCEN AML/CFT program reform NPRM n/a Proposed only, comments closed Jun 2026, 12-month runway after any final rule

How does Zyphe deliver fintech AML at instant-payment speed?

Zyphe ships four primitives.

Real-time scoring at instant-payment authorisation time. FedNow, SEPA Instant, Faster Payments, UPI, Pix. Zyphe’s AML monitoring product scores transactions in single-digit milliseconds at the authorisation step and can block, hold, or flag before settlement. Cliff-edge rules (sanctioned counterparty, structuring at deposit, mule signatures) fire deterministically.

Identity-linked alerts. Every alert carries the verified KYC credential, the KYC tier, and the perpetual re-screening status. Mule indicators fire at the rule level. See our perpetual KYC piece.

Partner-bank audit-export ready. Case files exportable in the formats US partner banks expect, with per-decision triage records, SAR clock tracking, and rule-version history. The partner bank’s quarterly review goes from a three-week scramble to a one-day desk review.

No central store of customer PII. Source documents are sharded across thousands of decentralised storage nodes. The fintech holds the credential and the audit trail, not copies of the underlying documents.

How do you implement fintech AML across BaaS, embedded finance, and direct fintech?

Three patterns covering the most common deployment shapes.

BaaS / sponsor-bank fintech

Real-time scoring at authorisation, identity-linked alerts, partner-bank audit-export ready. Quarterly compliance review pre-loaded with case-file evidence. Rule-change pre-approval workflow integrated with the partner bank’s compliance team.

Embedded finance platform

The platform offers financial services to its end-customers but does not hold the regulatory licence directly. Obligations flow through the licensed partner. The fintech program here is the AML for fintech layer that keeps every partner relationship on the same evidence base.

Direct fintech with own MTL or banking licence

Standard bank-style obligations. Real-time monitoring, identity-linked alerts, SAR filing, regulatory examination preparedness. Higher per-decision defensibility documentation depth than BaaS-fintechs because the regulator interfaces directly. See our KYC for banking page for the deeper pattern.

What are the real edge cases fintech AML still struggles with?

Five edge cases worth flagging.

Embedded-finance multi-partner fan-out. Where the platform spans multiple licensed partners with different audit cadences and case-file format expectations.

Cross-border SCA exemption logic under PSD2. Risk-based exemption routing requires monitoring stack to surface buyer credential status to the payment processor.

Real-time fraud cliff-edges colliding with chargeback windows. Where chargeback and AML signal triage compete for the same alert queue.

Crypto-fintech overlap. Where the fintech offers crypto rails alongside fiat, the AML obligations from both regimes apply simultaneously. See our AML for crypto page.

Open banking data ingestion for AML signal. Where account aggregation through open banking creates new counterparty visibility but also data-protection complexity.

How do you evaluate fintech AML in the next 30 days?

Five concrete moves.

  1. Audit your real-time monitoring coverage. If any instant-payment rail (FedNow, SEPA Instant, Faster Payments) runs through batch, the audit gap is structural.
  2. Pressure-test partner-bank audit-export readiness. Ask the partner bank for the case file format they expect. Can you produce it in under 24 hours?
  3. Inventory typology coverage. Pull current rules and check coverage against FATF Recommendation 20 plus fintech-specific patterns (mule indicators, instant-payment fraud signatures).
  4. Pressure-test identity linkage. Pull 50 random alerts from the last 30 days. Confirm each carried the verified credential.
  5. Update DPIA and partner-bank audit documentation. Documentation depth is now the partner-bank-review focus, not just the regulator’s.

Stop running AML on yesterday's batch.

If you are running AML for a fintech programme, you already feel the gap between what your stack reports and what your regulator asks. Book a 30-minute walkthrough and we will run a real monitoring scenario, show you the audit trail, and price it against your current vendor.

Frequently asked questions

AML for fintech is the transaction-monitoring, sanctions-screening, and SAR filing layer that fintechs, embedded-finance platforms, and BaaS-powered apps operate to satisfy partner-bank audit obligations, FinCEN BSA, FCA SYSC, and EU AMLR/AMLD6 requirements. It runs in real time at instant-payment speed and produces a case file the partner bank's compliance team can audit on demand.

The category operates at fintech tempo (real-time payments, fast onboarding) under potential partner-bank governance overlay where the partner bank inherits the fintech's compliance failures. Fintech programs in 2026 have to satisfy two audit bars simultaneously, with the partner-bank bar often being the higher one.

The Cash App / Block penalty (March 2025) cited identity-linkage gaps, alert backlog, and weak sanctions coverage at scale. It became the operational benchmark for fintech-side expectations. Identity-linked alerts at the rule level, real-time scoring, and per-decision triage records are the architectural fix.

Real-time scoring at authorisation time can block, hold, or flag before settlement on FedNow and SEPA Instant. Single-digit-millisecond scoring is the operational target. Under the EU Instant Payment Regulation, euro-area PSPs have had to receive instant credit transfers since 9 January 2025 and send them since 9 October 2025, executing inside ten seconds at any hour. Any control that has to act before settlement therefore has to run at authorisation, because an end-of-day batch job cannot stop a payment that already settled.

Quarterly reviews instead of annual, real-time visibility into the alert pipeline, per-decision triage records spot-checkable by the partner bank's compliance team, pre-approval on material rule changes, and tightened exit clauses. Post-TD Bank, partner banks treat the fintech audit cycle as the partner bank's own.

Yes. Embedded-finance platforms with multiple licensed partners can run one architecture with per-partner policy configuration. Each partner bank's audit-export format and review cadence is configured separately. The underlying alert data, identity linkage, and SAR pipeline are shared.

End-to-end Zyphe integration fits in 2 to 4 weeks against the sandbox for a BaaS or direct fintech. Production hardening with full partner-bank audit-export and quarterly-review documentation adds another 2 to 4 weeks. Total typically 4 to 8 weeks for an in-house engineering team.

Sanctions, PEP, and adverse media re-screening run continuously at the credential layer. Real-time transaction scoring runs at authorisation. Per-decision triage records and SAR clock tracking surface metrics to the CCO weekly. Partner-bank audit-export available on demand in their preferred format.