AML Program Requirements for Cross-Border Payment Operators
Operators must build AML programs satisfying multiple overlapping jurisdictions simultaneously.

Cross-border payment operators do not answer to one AML regime. They answer to several at once, and those regimes stack, overlap, and at times pull in different directions. A domestic institution can build a program around a single statute and a single examiner relationship. An operator moving money across borders cannot, because the money itself does not move in a straight line: it passes through payment processors, currency exchangers, and clearing agents, and each of those intermediaries sits under its own regulatory jurisdiction, creating a fresh compliance gap at every hop. No single global standard sits above this chain to harmonize it. Fenergo's February 2026 guide names the Bank Secrecy Act (BSA) in the United States, the 5th and 6th EU AML Directives, and FATF guidelines globally as the principal frameworks that a single operator may need to satisfy at once.
The chain's opacity makes the jurisdictional overlap worse rather than better. Intermediary banks sitting between an originator and a beneficiary can truncate or omit data as a payment passes through, and that loss of data hampers accurate screening across the full length of the transaction. Alessa's December 2025 analysis treats this as a structural feature of cross-border payments rather than an exception that careful operators can engineer around. Add to that the speed of modern payment rails: real-time and near-instant settlement compresses the window compliance teams have to screen, review, and intervene before funds have already moved. An operator cannot opt into the one framework it finds most convenient and ignore the rest. It has to design a single program capable of satisfying every framework that applies to its corridors, at the same time, without contradiction.
The written AML program as the legal baseline every jurisdiction requires
Whatever jurisdictional complexity an operator faces downstream, every applicable framework starts from the same demand: a documented, four-component AML program has to exist before anything else is built on top of it. In the United States, the BSA/AML framework requires written policies and procedures, a designated compliance officer, an ongoing staff training program, and independent testing. These four elements are not enhancements an operator adds once it reaches a certain size or risk profile. They are the statutory floor.
U.S. Money Services Businesses carry a further obligation on top of that floor: registration with FinCEN within a defined window after the business is established, renewed periodically thereafter. Failure to register is itself a BSA violation, independent of anything else the operator may or may not have done wrong, and the penalty for getting this wrong is not theoretical. Brink's Global Services USA was fined $37 million by FinCEN in January 2025 for operating as a money transmitter without registering.
Every operator must have a documented, four-component AML program in place, a baseline that the U.S., EU, and FATF frameworks all require in some form. A policy an operator cannot produce, or one that does not match what the business actually does day to day, is treated by examiners as no policy. Independent testing is what closes the loop on the other three: the audit function verifies that the designated compliance officer is actually performing the role, that training is reaching the staff who need it, and that the written policies are being followed in practice rather than sitting unused in a binder. Regulators read the absence of a functional audit function as a signal that the entire program is nominal rather than operational, and the EU and FATF frameworks build on that same four-part logic, even where the specific statutory language differs; the jurisdiction-specific detail that separates them matters most once an operator starts applying the program to real corridors, and that detail is where the rest of this piece picks up.
KYC and KYB requirements at onboarding
The written program exists to govern something, and the first thing it governs is the customer relationship itself. KYC and KYB are not a one-time document collection exercise at the start of a relationship. They form the foundation every subsequent monitoring and reporting function rests on, and for cross-border operators that foundation has to cover not just the party directly opening the account but every party standing behind the transaction. Fenergo's guide for payment processors calls KYC the cornerstone of the entire AML program: verifying identity at onboarding means gathering identifying information, validating the documents behind it, and screening the customer against watchlists that include Politically Exposed Persons and sanctioned parties.
For business customers, that obligation extends further, into beneficial ownership. KYB due diligence has to reach originators, beneficiaries, intermediaries, and Ultimate Beneficial Owners, and Alessa's analysis frames UBO verification as a baseline regulatory expectation rather than an enhanced measure reserved for unusual cases. The reason KYB has to go this deep is the technique it is designed to catch: layering ownership through offshore entities, shell companies, and trade documentation is the primary method used to obscure who actually controls a cross-border transaction, so name-and-address verification alone misses the structures that matter most. China's amended Anti-Money Laundering Law, effective January 1, 2025, adds a jurisdiction-specific version of this requirement: it codified and reinforced a national UBO registry, first established by the BOI Measures effective November 1, 2024, and extended compliance obligations to nonfinancial institutions, meaning operators active in that corridor face a mandatory verification layer with reach beyond China's own borders.
The enforcement record shows what happens when KYC fails at onboarding, and the penalties attached to those failures are the largest in the compliance landscape. The DOJ's February 24, 2025 action against OKX found that the exchange let users bypass KYC checks entirely, with employees helping customers falsify identification, while OKX also knowingly allowed its IP ban to be circumvented via widely available VPN technology. That failure produced a $504 million penalty and a three-year compliance monitor. KuCoin, operating as Peken Global Limited, pleaded guilty in January 2025 to running an unlicensed money transmitting business, with a penalty combining a fine and forfeiture, rooted in part in its failure to implement an effective KYC program and its parallel failure to register with FinCEN. Those two failures are not separate problems. An operator without a functioning KYC program has no reliable way to even assess whether it falls under MSB registration requirements in the first place.
Customer Due Diligence as a continuous obligation, not an onboarding checkpoint
Everything KYC and KYB establish at onboarding has a shelf life. Customer Due Diligence is the mechanism that keeps a customer's risk profile current after that first moment, and for a cross-border operator, treating the onboarding snapshot as permanent is itself a compliance liability, because customer behavior, counterparty relationships, and geographic exposure all shift over the life of the relationship. Fenergo's guide draws a clear line between CDD and onboarding KYC: CDD includes identity verification and ongoing monitoring calibrated to the customer's risk profile, applied at different levels of intensity depending on how risky that customer turns out to be.
Enhanced Due Diligence is the heightened version of that obligation, reserved for high-risk entities: customers in high-risk geographies, in industries known to attract financial crime, or those who triggered a PEP or adverse media match during screening. EDD has to be documented when it is applied and refreshed on a regular schedule rather than performed once. The risk-based approach is what governs how an operator allocates its CDD resources across its whole customer base: by categorizing customer, product, and geographic risk factors, an operator can concentrate scrutiny where it is actually warranted instead of applying the same uniform level of review to every account, and regulators expect exactly this kind of proportionality rather than a flat, undifferentiated standard. Fenergo's analysis identifies the most common ways this goes wrong in payment processor examinations: generic rule sets that were never tailored to the operator's actual business model, risk assessments that are never updated as customer circumstances change, and manual review processes that cannot keep pace with real transaction volume. A CDD program that is current and risk-differentiated is what makes transaction monitoring possible in the first place, because monitoring models depend on an accurate, live picture of who the customer is and how risky that customer has been classified.
Designing transaction monitoring for cross-border payment flows
That live risk classification feeds directly into transaction monitoring, which is the operational center of an AML program for any high-volume payment operator. Fenergo's guide describes monitoring as a dynamic, ongoing process that combines rule-based systems with AI-enhanced detection, and the pairing matters because rule-based systems running alone tend to generate the kind of false-positive volume that produces alert fatigue in compliance teams. For cross-border flows specifically, Alessa's December 2025 red-flag taxonomy lays out the patterns a monitoring model has to be configured to catch. A sudden spike in international transfer volume with no clear business rationale behind it is one signal. So is the rapid movement of funds through several countries in quick sequence. Structuring, where a customer breaks a large transfer into multiple small-value transactions designed to stay under reporting thresholds, is another. Round-tripping, where funds travel out and return to the apparent original sender, is a fourth. Transfers touching sanctioned regions, jurisdictions known for high corruption, or offshore financial secrecy havens form a fifth category, and payments that simply do not match a customer's established account history or stated business purpose round out the list.
False positives in this environment are not a tuning problem an operator can eventually engineer away. They are a structural feature of cross-border monitoring itself: names get spelled or transliterated inconsistently across jurisdictions, originator and beneficiary details arrive incomplete, and geographic risk flags trigger on transactions that are entirely legitimate. Alessa's analysis identifies the analyst fatigue that results from this volume of false alerts as one of the primary operational risks facing cross-border AML programs. Sanctions.io's analysis points to AI and machine learning moving from pilot projects into production in 2026 as the main tool operators are using to bring that false-positive rate down, through adaptive feedback loops that recalibrate detection logic based on emerging typologies and the outcomes investigators actually reach. That shift reduces the manual tuning cycle compliance teams used to carry, but it does not arrive free of obligation: documented model governance, audit trails, explainability, and ongoing validation are regulatory expectations attached to the technology, not internal best practices an operator can choose to skip. Generative AI is moving into a related workflow, drafting structured SAR narratives that investigators then review and validate, which shifts the compliance team's role toward oversight rather than first-draft documentation. That shift changes how the work gets done, but it leaves the operator's legal responsibility for the accuracy of what gets filed exactly where it was. When a monitoring alert escalates all the way to a Suspicious Activity Report, the filing has to meet the regulatory standard of whichever jurisdiction the obligation arose in, so an operator working multiple corridors has to map its SAR and STR filing obligations corridor by corridor rather than apply one template everywhere.
Sanctions screening as a parallel, real-time obligation distinct from transaction monitoring
Transaction monitoring and sanctions screening get collapsed into one function more often than the regulatory record supports, and operators that make that collapse do so at real cost. Sanctions screening runs against its own authorities, on its own update cadence, with its own legal consequences, separate from the broader AML monitoring described above. For a cross-border operator, screening has to cover every named party in a payment chain, including parties beyond the customer who initiated the transfer. Alessa's analysis specifies that comprehensive sanctions and PEP screening has to extend to all parties involved, to intermediary institutions, to free-text message fields, and to routing details, not merely to the instructing customer.
The pace of change in sanctions regimes is what makes this a real-time obligation rather than a periodic one. OFAC, the EU, the UN, and various regional authorities each issue updates independently of one another, and enforcement actions are increasingly built around sanctions-related failures as the primary violation, which has raised the compliance bar across institutions of every size. FinCEN's 2026 enforcement record shows that bar reaching well beyond the financial institutions traditionally thought of as the main targets: the $125 million penalty against UBS Financial Services in August 2026, alongside a separate FinCEN penalty against Canaccord Genuity, shows enforcement extending to a wider range of regulated entities than before. For cross-border payment operators specifically, FATF's revised Recommendation 16 adds a sanctions dimension at the level of the payment message itself, requiring standardized and enhanced data for originator and beneficiary information above a defined threshold. That data requirement means payment-level sanctions screening now has to match the data quality the message itself is required to carry, a connection sanctions.io's March 2026 analysis identifies as a direct operational consequence of the revision. The fuller mechanics of that threshold, and how it interacts with the Travel Rule more broadly, follow below.
The Travel Rule: thresholds and the June 2025 changes
The Travel Rule requires an operator to pass originator and beneficiary data along with every qualifying transfer, but the threshold that triggers the obligation, and the technical requirements governing how that data has to travel with the payment, vary by jurisdiction in ways that cannot be solved with one system configuration applied everywhere. The variation is not a minor technical footnote. The threshold variation is concrete and significant: the U.S. sets a dollar-denominated trigger, the U.K. a sterling-denominated one, and the EU applies no threshold at all for crypto-assets, so an operator active across all three corridors has to apply three different trigger points to the same underlying transaction type.
FATF's June 2025 revision to Recommendation 16 ties the Travel Rule's originator and beneficiary data directly to the sanctions-screening data quality described in the previous section, raising the stakes on getting this right. An operator cannot treat the Travel Rule as a standalone data-transmission requirement separate from the rest of its compliance stack. The data that satisfies the Travel Rule is the same data a sanctions screening system depends on to do its job, and the same data a transaction monitoring model needs to assess a cross-border flow accurately. Building toward three different jurisdictional thresholds, on top of the KYC, KYB, CDD, monitoring, and sanctions obligations already described, is the practical test of whether an operator has actually built one coherent AML program or three disconnected ones wearing the same name.


