DashDevs Blog Fintech Anti-Money Laundering Compliance for Fintechs: What the 2026 Regulatory Shift Demands

Anti-Money Laundering Compliance for Fintechs: What the 2026 Regulatory Shift Demands

author image
Igor Tomych
CEO at DashDevs, Fintech Garden

September 15, 2026

Summary
  • Documentation is no longer proof. Regulators now check if controls produce evidence, driven by FATF's 2025 outcome-based shift and FinCEN's April 2026 NPRM.
  • Model-specific compliance is mandatory. Payments AML programs don't transfer to crypto or embedded finance. Each requires explicit, contractual CDD ownership and SAR accountability.
  • Ownership matters more than build-vs-buy. Regardless of your vendor choices, critical layers (such as the audit trail, risk-scoring logic, and SAR workflows) must remain under your direct governance.

Most fintechs understand that anti-money laundering compliance is required. The harder question is whether your AML program would survive a regulatory examination. What’s even more important is that it must be a live, evidence-producing control system.

That distinction is what regulators are now testing. According to Fenergo’s 2025 Global AML Fines Report, AML, KYC, sanctions, and CDD penalties totalled $3.8 billion globally in 2025, with digital-asset firms overrepresented in the top enforcement actions.

Nearly one quarter of the highest-value fines in 2025 involved crypto companies. Enforcement has only intensified in 2026, headlined by FinCEN’s $125 million penalty against UBS over automated monitoring failures. The pattern is consistent: firms that grew transaction volume faster than their compliance infrastructure paid the consequences.

This guide is written for compliance officers, heads of risk, and technical leaders at fintechs, neobanks, and digital-asset platforms. It covers what changes in 2026, what a complete AML compliance program looks like at the infrastructure level, and how to make the build-vs-buy decision before a regulator makes it for you.

What Is AML Compliance and Why It Looks Different for Fintechs

AML compliance refers to the policies, controls, and monitoring systems a financial institution uses to detect, prevent, and report illicit financial activity. It covers customer verification, transaction monitoring, suspicious activity reporting, and regulatory filings.

For traditional banks, these frameworks have existed for decades. For fintechs, the application is more complex. Frictionless digital onboarding creates identity risks that legacy AML rule sets weren’t designed to catch. As an example, AI-generated identities and deepfake KYC videos are active attack vectors. Cross-border customer bases add conflicting national regulations, unsynchronized sanctions lists, and varying Travel Rule thresholds across the US, EU, and MENA.

Regulators now explicitly apply the principle of “same risk, same regulation” to fintechs. Operating under a BaaS sponsor bank doesn’t reduce your compliance obligations.

FinCEN’s position is direct: partnering with a bank creates shared obligations, not transferred ones.

If you move money, you must comply with anti-money laundering fintech requirements. No exceptions for being a startup. No exceptions for being ‘just a platform.’ The fintech regulations landscape makes no exceptions.

Every obligation your bank partner carries, you carry in proportion to your transaction risk exposure.

The 2026 Regulatory Landscape: Three Changes That Affect Your Program

FATF’s Strengthened Risk-Based Approach

The Financial Action Task Force updated Recommendation 1 in February 2025, with implementation expected across member jurisdictions through 2026. The core change strengthens the risk-based approach — requiring controls to be proportionate to actual risk exposure, with simplified measures permitted where risks are demonstrably lower.

Under the updated risk-based approach, a firm must show that they work proportionately. A higher-risk customer segment should receive demonstrably stronger controls. A lower-risk onboarding flow may support simplified due diligence, but the rationale must be documented and defensible.

FATF’s revised recommendation 1 makes this explicit: risk models must be explainable. Your team must show why a customer, product, or transaction pattern received a specific control level and when that decision was last reviewed. Static risk scorecards set once at launch are no longer sufficient.

The practical implication is that anti-money laundering compliance moves from periodic reviews to a live governance function. Compliance officers need systems that log decisions.

FinCEN’s AML/CFT Program Overhaul

In April 2026, the US Financial Crimes Enforcement Network published a Notice of Proposed Rulemaking. It represents the most significant overhaul of AML/CFT requirements in approximately 25 years. The NPRM signals that FinCEN will view the use of AI and automated monitoring systems as evidence of a program’s effectiveness during examination.

For fintechs registered as money services businesses or operating under a BSA program, this shifts technology from a capability choice to an examination factor. Manual review queues and static rule sets are no longer a defensible architecture for any institution at scale.

MiCA, AMLD6, and the Digital-Asset Compliance Threshold

For platforms operating in the EU, MiCA’s full application from December 2024 ends the national VASP registration patchwork. Any firm providing crypto-asset services to EU clients without full CASP authorization must have ceased or obtained that authorization by July 1, 2026, at the latest.

MiCA imposes a full suite of AML and counter-terrorism financing obligations equivalent to those of traditional financial institutions. This includes continuous transaction monitoring, suspicious activity reporting to the relevant Financial Intelligence Unit without delay, full CDD programs, and SAR/STR filing obligations under tipping-off prohibitions.

The EU Transfer of Funds Regulation applies the Travel Rule to CASP-to-CASP transactions with no minimum threshold. For transfers involving self-hosted (unhosted) wallets above €1,000, the sending VASP must verify whether the customer controls that wallet before processing. Across the 117 jurisdictions that permit VASP activity, FATF’s 2025 update found that 85 had passed Travel Rule legislation, but enforcement remains uneven, which creates both risk and competitive advantage for platforms that implement early.

Teams building or upgrading compliant crypto-fiat infrastructure should start with the regulatory perimeter across every corridor they operate, not just the most visible one.

The 8 Components of a Defensible AML Compliance Program

A defensible compliance program in 2026 is a control system. The following eight components represent what regulators in the US, EU, and UK now expect to see in operational form.

1. Written AML Policy with Senior Accountability

Every regulated fintech must have a written AML policy that designates a named AML compliance officer with explicit authority and direct reporting access to the board. The policy must map to the specific risks of your product.

Under FinCEN’s BSA requirements, the designated BSA officer is personally accountable for program effectiveness. Under AMLD6, the equivalent role is the Money Laundering Reporting Officer (MLRO). In both cases, senior accountability is a direct examination point.

2. Enterprise-Wide Risk Assessment

The foundation of any program is a documented risk assessment that identifies money laundering and terrorist financing risks specific to your business. This covers product risk (which financial products could facilitate illicit activity), customer risk categories, geographic exposure, and delivery channel risk.

The risk assessment is not a one-time filing. It should update when your product changes, your customer base expands into new corridors, or your regulatory environment shifts. A risk assessment that was last reviewed at product launch doesn’t meet the outcome-based standard FATF now applies.

The trade-off between compliance vs. speed in cross-border payments has its own risk dimension. The assumption that payment speed is the primary constraint for international fintechs undersells how much corridor-specific AML risk varies.

3. Customer Due Diligence and KYC Integration

AML compliance and KYC are distinct but inseparable. CDD is the risk-based process for understanding who your customer is, what they do, and whether their transaction behavior matches their stated profile. KYC is the identity verification layer that feeds CDD.

In 2026, CDD programs require four layers:

  • Identity verification at onboarding, including document verification and liveness detection for remote onboarding
  • Beneficial ownership identification for legal entities, down to the threshold set by your jurisdiction
  • Ongoing monitoring that updates the customer’s risk profile as their behavior changes
  • Enhanced due diligence (EDD) for high-risk customers, PEPs, and customers from high-risk jurisdictions

KYC integration services are standard fintech infrastructure. The question is how your KYC data connects to your transaction monitoring and case management system. Disconnected point solutions create exactly the blind spots that generate enforcement actions.

For asset managers and institutional clients, DashDevs’ work on KYC/AML automation for asset managers shows how structured onboarding workflows reduce both manual review time and compliance risk in high-AUM contexts.

4. Transaction Monitoring

Real-time transaction monitoring is a hard requirement for any fintech operating at scale. Static rule sets (fixed thresholds that fire alerts regardless of customer profile or behavioral baseline) produce false-positive rates that make the alerts effectively meaningless.

Modern transaction monitoring operates on behavioral baselines per customer segment, dynamic rule sets that adjust to product risk, and network-level analysis that identifies relationships between accounts rather than reviewing each account in isolation.

One of the most frequently cited violations in BSA enforcement actions is failure to file Suspicious Activity Reports within the 30-day window after detection. That clock starts when your transaction monitoring system surfaces the event. The gap between system flag and human review is where most SARs are missed.

5. SAR and CTR Filing

A suspicious activity report (SAR) must be filed when a transaction or pattern of behavior indicates potential money laundering, terrorist financing, or other financial crime, regardless of whether the activity results in confirmed fraud. The failure-to-file finding is among the most common in BSA examinations.

Currency Transaction Reports (CTRs) apply to cash transactions above $10,000 in the US. For crypto platforms, most EU member states have transaction reporting equivalents aligned to AMLD6 thresholds.

Tipping-off prohibitions apply to both SARs and their crypto equivalents: you cannot disclose to a customer why their transaction was blocked if that disclosure would compromise a pending SAR.

6. Sanctions Screening

Sanctions screening covers real-time checks against OFAC, UN, EU, FATF grey/black lists, and jurisdiction-specific watchlists at onboarding and on an ongoing basis. The “ongoing” requirement is critical. Sanctions lists update with no fixed schedule, and a customer who passed screening at onboarding may be added to a list six months later.

Politically exposed person (PEP) screening operates on similar logic. PEP status creates a risk indicator. The presence of a PEP in your customer base requires documented enhanced due diligence with a clear rationale for the risk level assigned.

For fintech platforms with cross-border corridors, cross-industry fraud data sharing is an additional layer relevant in UK-regulated contexts.

7. Employee Training

Anti-money laundering compliance training is a regulatory requirement, not an optional feature of compliance culture. It is a function the anti-money laundering compliance officer is accountable for documenting and maintaining. Staff must be trained to recognize suspicious behavior, understand escalation procedures, and know the specific red flags relevant to your product.

Training must be documented and repeated. A compliance officer who completed a single onboarding module three years ago does not satisfy the current standard. The training program should be role-specific: a customer support agent and a payments operations analyst carry different AML risk touchpoints. For the designated compliance officer, anti-money laundering compliance certification through an accredited body is increasingly treated as a baseline credential by regulators in the UK and EU.

8. Independent Audit and Testing

An anti-money laundering compliance program must be independently tested at regular intervals. This means an audit that examines whether your controls actually work.

Common audit findings include monitoring rules that have not been calibrated since implementation. Alert volumes too high for the review team to process meaningfully is another pattern. SAR decisions without sufficient documented rationale and risk assessments that do not reflect the current product are also frequent findings.

Under DORA compliance requirements, which apply to EU-regulated fintechs from January 2025, operational resilience regulations add a technology audit dimension to compliance programs that maintain AML infrastructure, including third-party vendors.

Your compliance program is only as strong as your weakest undocumented decision. Regulators do not examine your policy; they examine your audit trail.

Is your AML program built to pass a 2026 examination?
DashDevs has built AML infrastructure for licensed banks, EMIs, and crypto trading platforms across regulated jurisdictions.

The Build-vs-Buy Decision for AML Infrastructure

The most consequential technology decision in AML compliance is not which vendor to select. It is where to draw the line between what you build, what you buy, and what you integrate. Most vendors position their offering as end-to-end anti-money laundering compliance software, but no single platform covers every layer your program requires.

AML LayerApproachRationale
Transaction monitoring engineBuy/integrateMarket-mature; building offers limited advantage over established vendors
Sanctions and PEP screeningBuy/integrateList management is a vendor function; your value is in how you act on alerts
KYC/identity verificationIntegrateLiveness detection, document verification, and specialized capability requiring constant model updates
Risk scoring and segmentationBuild or configureYour customer risk model should reflect your product’s specific risk profile, not a generic template
Case management and audit trailBuild or configureAudit trail integrity is yours to own; a vendor’s case management system may not produce documentation to your regulator’s standard
SAR/CTR workflowBuildFiling obligations, escalation authority, and tipping-off controls must be under your governance
Beneficial ownership registryIntegrateJurisdictional data sources: build the intake workflow, not the data infrastructure

The critical mistake most teams make is buying a complete AML platform and assuming that the vendor’s compliance perimeter is also their own. The fintech board and management remain ultimately responsible for program effectiveness, regardless of which technology powers the controls. Selecting anti-money laundering compliance software is a procurement decision. Owning the compliance perimeter is a governance one.

A second mistake is investing in monitoring engines before solving the data layer. At one large US bank (anonymized), a BSA/AML data engineering project covering entity resolution, signal enrichment, and governed data lineage produced a 68% reduction in false positives and a 43% reduction in compliance overhead. Most of the gain came from the data layer, not from changing the monitoring rules.

For fintechs operating across multiple product lines (embedded finance, crypto, and payments), the architecture decision is even more consequential. DashDevs’ fintech infrastructure for licensed financial institutions is structured around exactly this separation: the compliance perimeter is configurable by product line, not a single shared rule set applied across all transaction types.

AML for Crypto and Embedded Finance: Where Standard Programs Break

Standard AML compliance programs designed for payments or lending break in two specific contexts: crypto and embedded finance. Both are worth treating separately.

Crypto and VASP Obligations

For platforms classified as VASPs or CASPs, the AML program must cover on-chain transaction analysis in addition to off-chain KYC. Wallet screening, KYT (Know Your Transaction) monitoring for on-chain activity, and Travel Rule data exchange between VASPs are distinct technical requirements that payment-native AML tools do not handle. Teams building fiat-crypto compliance infrastructure need to account for this stack from day one.

The Travel Rule requires VASPs to transmit originator and beneficiary information for qualifying transfers. Travel Rule interoperability remains technically inconsistent across the market. Platforms that implement early gain an operational advantage.

That is what our KYC/KYB/AML build for a licensed crypto trading platform case study reflects in practice. A licensed crypto trading platform requires separate KYC/KYB flows, AML transaction monitoring, and on-chain KYT. None of those mapped directly to the payments AML framework the team had used before.

Embedded Finance

Embedded finance introduces a layered compliance model. The infrastructure provider, the program manager, and the end-facing brand each carry a portion of the AML obligation, and those portions are not always clearly defined in commercial agreements.

The practical risk: each party assumes the other handles compliance, and no one owns the control gap. This is exactly the failure mode behind OCC enforcement actions against sponsor banks in 2025.

For embedded finance programs, the anti-money laundering aml compliance program must explicitly map who performs CDD, who monitors transactions, who files SARs, and who manages sanctions screening. That mapping must exist in both the commercial agreement and the operational workflow.

Teams without that mapping should start with fintech regulatory and compliance consulting before any architecture decisions.

Building an embedded finance or crypto platform?
DashDevs structures AML programs for EMI, VASP, and embedded finance models, including the compliance layer between infrastructure and end product.

How DashDevs Structures AML Programs for Licensed Fintech Platforms

Most fintech teams encounter AML as a design problem when the product is built, the licensing application is pending, and the compliance architecture needs to be retrofitted into an existing system.

The teams that avoid this outcome treat AML compliance as a product surface from day one. When DashDevs built AML/compliance platform for a Saudi digital bank, the AML program wasn’t a post-launch addition. Transaction monitoring rules, risk-scoring logic, and automated reporting workflows were designed as modules within the core platform.

The platform now supports a full digital banking product under regulatory supervision, with AML controls that produce audit-ready documentation at the transaction level. The regulator-facing output was part of the design spec, not a reporting layer added during examination preparation.

Neobank app development that doesn’t account for AML architecture at the infrastructure level creates technical debt that compounds with transaction volume and produces the control gaps that appear in enforcement actions.

The fintech regulations landscape across the US, EU, UK, and MENA differs enough that a single AML program design rarely survives expansion unchanged. Teams that build modular compliance infrastructure spend significantly less time on compliance retrofits.

The Fintech Garden Podcast (Episode 159) with Adam McLaughlin covers this shift in detail: the move from compliance-as-documentation to compliance-as-evidence is a fundamental change in how regulators evaluate programs.

KYC Provider Selection: Where AML Programs Depend on Infrastructure Choices

The quality of your anti-money laundering compliance program has a direct dependency on your KYC infrastructure. A transaction monitoring system that receives poor-quality identity data will generate poor-quality alerts, regardless of how sophisticated the monitoring rules are.

When selecting KYC providers for a fintech AML stack, four criteria matter at the implementation level:

  1. Liveness detection is required for MiCA, AMLD6, and increasingly for US-regulated platforms. Not all providers offer the same robustness against deepfake video attacks.
  2. Data residency matters for EU-regulated platforms: some providers route verification data through infrastructure that creates a GDPR compliance conflict.
  3. Beneficial ownership coverage determines whether you can satisfy KYB CDD requirements programmatically or whether every business onboarding requires manual review.
  4. Integration architecture is the most underrated factor. KYC should feed your AML risk scoring and case management in near real-time. A provider whose data output is a periodic batch file creates a monitoring lag that appears directly in your SAR timeline.

The top KYC service providers in 2026 guide covers the evaluation criteria in more depth.

Where payment card data is part of the transaction record, understanding PCI DSS compliance helps technical teams align their AML and data security audit preparation.

Cross-border KYB compliance has its own complexity layer, particularly for platforms serving MENA or operating under an EMI license in multiple EU states.

Episode 166 of the Fintech Garden Podcast with Marwan Forzley covers the compliance realities of cross-border KYC/KYB programs from an operator’s perspective.

Anti-Money Laundering Compliance Checklist: 8-Point Program Audit

Use this checklist to assess your current AML program against 2026 regulatory expectations.

ComponentMinimum Requirement2026 Standard
Written AML policyExists and names an officerReviewed within 12 months; senior board accountability documented
Risk assessmentConducted at launchUpdated on product changes, customer base expansion, regulatory changes
CDD programIdentity verification at onboardingRisk-based tiers, beneficial ownership, and ongoing monitoring with behavioral baseline
Transaction monitoringRule-based alertsBehavioral baselines per segment; false-positive rates tracked and calibrated
SAR filingProcess existsFiling within 30 days of detection; all decisions documented in case management
Sanctions screeningOnboarding checkReal-time ongoing screening; alerts actioned within defined SLA
Employee trainingAnnual all-staff trainingRole-specific; documented completion; red flags relevant to your product
Independent auditAnnual reviewControls tested for effectiveness; findings remediated with documented timeline

AML compliance in 2026 is an operational discipline. Regulators across the US, EU, and UK are now examining whether controls produce outcomes.

For fintechs, neobanks, and digital-asset platforms, the practical mandate is clear: design the compliance infrastructure alongside the product, not after it. The risk assessment, monitoring rules, CDD tiers, and SAR workflow must be configurable, auditable, and specific to your product’s risk profile.

The build-vs-buy decision matters less than the governance question: do you own the audit trail, the decision logic, and the escalation chain? If any of those sit entirely with a vendor, you have a compliance dependency that regulators will find.

PSD3 payment regulations and the EU AML Regulation add further requirements for PSPs and payment institutions. Operational resilience and DORA controls apply in parallel for EU-regulated platforms that maintain AML technology.

The fintech platforms that scale through regulatory scrutiny are the ones that treat compliance as infrastructure.

Ready to build a compliance program that survives examination?
DashDevs has delivered AML infrastructure for Saudi digital banks, EMIs, and licensed crypto trading platforms across three regulatory jurisdictions.

The Compliance Reckoning Is Already Here

The 2026 regulatory shift is the standard examiners are applying right now.

FATF, FinCEN, and MiCA have one thing in common: they require evidence, not documentation.

The practical mandate is clear. Design compliance infrastructure alongside the product. Own the audit trail, the risk-scoring logic, and the SAR workflow. If any of those sit entirely with a vendor, you have a dependency that regulators will find.

The cost of retrofitting a defensible program after a license review is an order of magnitude higher than building it in from the start. Run this anti-money laundering compliance checklist whenever your product changes, your customer base expands, or a new regulatory requirement takes effect.

Share article

Table of contents
FAQ
What is anti-money laundering compliance, and why does it matter for fintechs?
Anti-money laundering compliance is the system of policies, controls, and monitoring processes a financial institution uses to detect, prevent, and report illicit financial activity. For fintechs, it matters because regulators now apply the same obligations to digital-first platforms as to traditional banks. A weak AML program is grounds for license revocation, not just a fine.
What are the core requirements of an anti-money laundering compliance program?
A defensible compliance program includes eight components: a written policy with designated officer accountability, an enterprise-wide risk assessment, a CDD and KYC program, real-time transaction monitoring, SAR and CTR filing procedures, ongoing sanctions and PEP screening, employee training, and independent audit and testing. All eight must exist in operational form, not only as documentation.
How does FATF's risk-based approach affect my AML program?
FATF's updated Recommendations require that your controls be proportionate to your specific risk exposure, and that you can demonstrate why each control level was chosen. The risk model must be documented, explainable, and reviewed whenever your product or customer base changes.
What AML obligations apply to crypto platforms and VASPs in 2026?
Platforms classified as VASPs or CASPs under MiCA must implement a full AML program equivalent to traditional financial institutions. For EU-authorized CASPs, AMLD6 requirements apply directly. For US-registered crypto MSBs, FinCEN's BSA program requirements apply.
What is the Travel Rule and how does it apply to my platform?
The Travel Rule requires VASPs to collect and transmit originator and beneficiary information when sending or receiving qualifying virtual asset transfers to other VASPs. Thresholds vary by jurisdiction: no minimum in the EU under the Transfer of Funds Regulation for CASP-to-CASP transactions, $3,000 in the US, and varying amounts elsewhere.
Should my fintech build or buy AML compliance technology?
The right answer depends on which layer you are evaluating. Transaction monitoring engines, sanctions screening, and KYC verification are best bought or integrated; the market is mature and building offers limited advantage. Risk scoring logic, case management, SAR workflows, and your audit trail architecture should be owned or closely configured by your team.
What is a compliance officer responsible for?
The anti-money laundering compliance officer in UK-regulated contexts is personally accountable for the effectiveness of the AML program. Responsibilities include maintaining the risk assessment, overseeing transaction monitoring and SAR filing, managing regulatory correspondence, reporting to the board, and ensuring the training program is current and documented.
What are the consequences of weak AML compliance for fintechs?
Consequences range from regulatory fines to license revocation and personal liability for the designated compliance officer. Globally, AML, KYC, sanctions, and CDD penalties totalled $3.8 billion in 2025 (Fenergo). Digital-asset firms were overrepresented in the largest enforcement actions.
Author author image
author image
Igor Tomych
CEO at DashDevs, Fintech Garden

Igor Tomych, fintech expert with 17+ years of experience. He launched 20+ fintech products in the UK, US and MENA region. Igor led the development of 2 white label banking platforms, worked with 10+ financial institutions over the world and integrated more than 50 fintech vendors. He successfully re-engineered the business process for established products, which allowed those products to grow the user base and revenue up to 5 times.

Let’s turn
your fintech
into a market
contender

It’s your capital. Let’s make it work harder. Share your needs, and our team will promptly reach out to you with assistance and tailored solutions.

Cross icon

Stay Ahead 
in Fintech!

Join the community and learn from the world’s top fintech minds. New episodes weekly on trends, regulations, and innovations shaping finance.