[{"data":1,"prerenderedAt":868},["ShallowReactive",2],{"content-\u002Fresources\u002Fmore\u002Faml-audit-readiness-risk-monitoring":3,"resources-category-aml-audit-readiness-risk-monitoring":755},{"id":4,"title":5,"authors":6,"body":7,"categories":6,"category":707,"categoryType":6,"compare":6,"contributors":6,"date":708,"description":709,"extension":710,"faq":711,"howto":730,"isBlog":745,"isChangelog":745,"meta":746,"navigation":748,"path":749,"pillar":745,"products":6,"rawbody":750,"role":6,"seo":751,"seoTitle":752,"stem":753,"thumbnail":6,"updated":708,"__hash__":754},"content\u002Fresources\u002Fmore\u002Faml-audit-readiness-risk-monitoring.md","AML audit readiness: what regulators ask for and how to prove your risk monitoring works",null,{"type":8,"value":9,"toc":692},"minimark",[10,14,17,23,45,50,53,62,72,99,108,112,115,130,138,142,145,308,316,320,323,406,409,413,422,425,428,442,445,462,466,469,500,506,510,513,516,533,541,545,548,586,590,598,636,640,643,647,686],[11,12,13],"p",{},"Regulators expect proof that automated risk monitoring fits your risks and actually works. In practice that means a written AML policy, a customer risk rating method, a documented reason for every rule and threshold, tuning records, independent testing, timestamped case trails, SAR decision records, sanctions list update logs, management reporting, and records kept for five years.",[11,15,16],{},"This article is general information, not legal advice. Exam scope differs by regulator and license, so confirm yours with counsel.",[11,18,19],{},[20,21,22],"strong",{},"Key takeaways",[24,25,26,30,33,36,39,42],"ul",{},[27,28,29],"li",{},"Examiners test whether the system matches the policy, not whether the policy reads well.",[27,31,32],{},"Every rule needs a written rationale tied to a risk you identified. \"The vendor set it\" is not a rationale.",[27,34,35],{},"A case file should let a stranger reconstruct the decision: alert, evidence, reviewer, reason, date.",[27,37,38],{},"US money services businesses file SARs within 30 calendar days of initial detection and keep records for five years.",[27,40,41],{},"Independent testing is a legal requirement for MSBs, scoped to risk, and run by someone other than the compliance officer.",[27,43,44],{},"Thirty focused days can close most documentation gaps before an exam or a partner bank review.",[46,47,49],"h2",{"id":48},"what-do-regulators-expect-from-an-automated-risk-monitoring-program","What do regulators expect from an automated risk monitoring program?",[11,51,52],{},"They expect a program that is risk based, documented, tested, and able to show its own work. Automation doesn't change the standard. It changes the evidence, because every decision now leaves a record.",[11,54,55,56,61],{},"The global baseline is FATF Recommendation 1, the risk-based approach: identify and assess your money laundering and terrorist financing risks, then apply controls proportionate to them. FATF Recommendation 20 adds prompt reporting of suspicious transactions. The ",[57,58,60],"a",{"href":59},"\u002Fresources\u002Fmore\u002Fwhat-is-automated-risk-monitoring-fintech","automated risk monitoring explainer"," covers the components that sit under those obligations.",[11,63,64,65,71],{},"For a US money services business (MSB), the requirement is concrete. ",[57,66,70],{"href":67,"rel":68},"https:\u002F\u002Fwww.law.cornell.edu\u002Fcfr\u002Ftext\u002F31\u002F1022.210",[69],"nofollow","31 CFR 1022.210"," sets four minimum pillars for the AML program:",[73,74,75,81,87,93],"ol",{},[27,76,77,80],{},[20,78,79],{},"Policies, procedures, and internal controls",", covering customer identification, filing reports, keeping records, and responding to law enforcement.",[27,82,83,86],{},[20,84,85],{},"A designated compliance officer"," who owns day-to-day compliance.",[27,88,89,92],{},[20,90,91],{},"Training"," for the right staff, including how to detect suspicious transactions.",[27,94,95,98],{},[20,96,97],{},"Independent review",", with scope and frequency matched to the risk of the services offered. The reviewer can be internal, but can't be the compliance officer.",[11,100,101,102,107],{},"FinCEN and the IRS publish the ",[57,103,106],{"href":104,"rel":105},"https:\u002F\u002Fwww.fincen.gov\u002Fsites\u002Fdefault\u002Ffiles\u002Fshared\u002FMSB_Exam_Manual.pdf",[69],"Bank Secrecy Act\u002FAML Examination Manual for Money Services Businesses",". It dates from 2008, but the method holds: scope the risk, read the program, test transactions against it.",[46,109,111],{"id":110},"why-do-vendor-default-rules-fail-an-exam","Why do vendor default rules fail an exam?",[11,113,114],{},"Because a default rule was tuned for someone else's customers. When an examiner asks why a velocity rule fires at five transfers a day for a freelancer segment, the answer has to come from your risk assessment, not from a vendor's setup guide.",[11,116,117,118,123,124,129],{},"FinCEN said this directly in its ",[57,119,122],{"href":120,"rel":121},"https:\u002F\u002Fwww.fincen.gov\u002Fsystem\u002Ffiles\u002F2025-10\u002FSAR-FAQs-October-2025.pdf",[69],"October 2025 SAR FAQs",": monitoring parameters should be commensurate with the money laundering and terrorist financing risk of the specific institution, considering its products, locations, and customers. The UK's ",[57,125,128],{"href":126,"rel":127},"https:\u002F\u002Fhandbook.fca.org.uk\u002Fhandbook\u002FFCG\u002F3\u002F2.html",[69],"FCA Financial Crime Guide"," lists, as poor practice, threshold-based systems that are poorly calibrated, where the firm struggles to explain why a particular rule exists.",[11,131,132,133,137],{},"So the default isn't the problem. The undocumented default is. The ",[57,134,136],{"href":135},"\u002Fresources\u002Fmore\u002Ftransaction-monitoring-red-flags-stablecoin-payments","12 red flags rule library"," is a useful starting point for that inventory.",[46,139,141],{"id":140},"what-evidence-do-examiners-ask-for","What evidence do examiners ask for?",[11,143,144],{},"Examiners ask for artifacts that prove each control exists, runs, and gets reviewed. The table below covers the ten items that come up most in reviews of automated monitoring.",[146,147,148,167],"table",{},[149,150,151],"thead",{},[152,153,154,158,161,164],"tr",{},[155,156,157],"th",{},"Evidence item",[155,159,160],{},"What examiners look for",[155,162,163],{},"Example artifact",[155,165,166],{},"Owner",[168,169,170,185,199,213,226,240,254,267,281,294],"tbody",{},[152,171,172,176,179,182],{},[173,174,175],"td",{},"Written AML policy",[173,177,178],{},"Approved, current, and matching what the system does",[173,180,181],{},"Policy with version history and approval date",[173,183,184],{},"Compliance officer",[152,186,187,190,193,196],{},[173,188,189],{},"Customer risk rating methodology",[173,191,192],{},"Clear factors, how ratings change, who can override",[173,194,195],{},"Methodology document plus rating distribution",[173,197,198],{},"Compliance",[152,200,201,204,207,210],{},[173,202,203],{},"Rule and threshold rationale",[173,205,206],{},"Each rule tied to a risk and a customer segment",[173,208,209],{},"Rule inventory with typology, threshold, rationale",[173,211,212],{},"Compliance with engineering",[152,214,215,218,221,224],{},[173,216,217],{},"Calibration and tuning records",[173,219,220],{},"Changes tested before release and approved",[173,222,223],{},"Change log with before and after alert counts",[173,225,212],{},[152,227,228,231,234,237],{},[173,229,230],{},"Independent testing results",[173,232,233],{},"Scope matched to risk, findings tracked to closure",[173,235,236],{},"Review report and remediation tracker",[173,238,239],{},"Independent reviewer",[152,241,242,245,248,251],{},[173,243,244],{},"Alert to closure case trails",[173,246,247],{},"Timestamps, reviewer, evidence, and a reason",[173,249,250],{},"Case export for a sample period",[173,252,253],{},"Compliance analysts",[152,255,256,259,262,265],{},[173,257,258],{},"SAR decision records",[173,260,261],{},"Filed on time, consistent reasoning",[173,263,264],{},"SAR log with detection, decision, and filing dates",[173,266,184],{},[152,268,269,272,275,278],{},[173,270,271],{},"Sanctions list update logs",[173,273,274],{},"Lists loaded promptly and rescreening ran",[173,276,277],{},"List version log and rescreen job output",[173,279,280],{},"Engineering with compliance",[152,282,283,286,289,292],{},[173,284,285],{},"Management information and board reporting",[173,287,288],{},"Leadership sees volumes, backlog, SARs, findings",[173,290,291],{},"Monthly report pack and meeting minutes",[173,293,184],{},[152,295,296,299,302,305],{},[173,297,298],{},"Record retention",[173,300,301],{},"Five years, and retrievable on request",[173,303,304],{},"Retention policy plus a retrieval test",[173,306,307],{},"Operations",[11,309,310,311,315],{},"Two rows go missing most. Sanctions list logs, because list refreshes run as a background job nobody watches (the ",[57,312,314],{"href":313},"\u002Fresources\u002Fmore\u002Fongoing-sanctions-screening-how-often-to-rescreen","ongoing sanctions screening guide"," covers what to log). And tuning records, because rule changes ship like ordinary code. Route both through one approval step.",[46,317,319],{"id":318},"what-does-good-practice-look-like-compared-with-poor-practice","What does good practice look like compared with poor practice?",[11,321,322],{},"Good practice shows the program understands its own output. The table below is drawn from the FCA Financial Crime Guide's good and poor practice examples on monitoring, paraphrased.",[146,324,325,338],{},[149,326,327],{},[152,328,329,332,335],{},[155,330,331],{},"Area",[155,333,334],{},"Good practice",[155,336,337],{},"Poor practice",[168,339,340,351,362,373,384,395],{},[152,341,342,345,348],{},[173,343,344],{},"Monitoring design",[173,346,347],{},"Looks at customer behavior as a whole, at several levels of aggregation",[173,349,350],{},"Single-transaction thresholds used where they don't fit the risk",[152,352,353,356,359],{},[173,354,355],{},"Rule calibration",[173,357,358],{},"The firm can explain the rationale for each rule",[173,360,361],{},"Rules are poorly calibrated and their rationale is unclear",[152,363,364,367,370],{},[173,365,366],{},"New approaches",[173,368,369],{},"New monitoring methods are piloted and tested before replacing old ones",[173,371,372],{},"Systems are swapped without comparing alert quality",[152,374,375,378,381],{},[173,376,377],{},"Control framework",[173,379,380],{},"Management oversees performance and resolves issues",[173,382,383],{},"The control framework around automated monitoring is weak",[152,385,386,389,392],{},[173,387,388],{},"Customer explanations",[173,390,391],{},"Staff test explanations against evidence",[173,393,394],{},"Staff accept a customer's explanation at face value",[152,396,397,400,403],{},[173,398,399],{},"Use of results",[173,401,402],{},"Monitoring results show whether due diligence is still adequate",[173,404,405],{},"Little evidence that unusual transactions reach the compliance officer",[11,407,408],{},"One more contrast that isn't from the FCA guide, but that examiners everywhere probe: a customer risk rating that refreshes on triggers (new corridor, volume jump, ownership change) versus a rating set once at onboarding and never touched. The second is a snapshot, not a control.",[46,410,412],{"id":411},"how-do-sar-timelines-work-and-what-happens-when-a-deadline-slips","How do SAR timelines work, and what happens when a deadline slips?",[11,414,415,416,421],{},"Under ",[57,417,420],{"href":418,"rel":419},"https:\u002F\u002Fwww.law.cornell.edu\u002Fcfr\u002Ftext\u002F31\u002F1022.320",[69],"31 CFR 1022.320",", a US MSB must report suspicious transactions that involve or aggregate at least USD 2,000, no later than 30 calendar days after initial detection. It keeps the SAR and supporting documents for five years from filing. Timelines differ in other jurisdictions, so check the local rule for each license.",[11,423,424],{},"The 30-day clock is where programs get caught. Examiners compare three dates in every sampled case: when the alert fired, when someone decided it was suspicious, and when the SAR was filed. Long unexplained gaps between them are findings even if the filing itself was \"on time.\"",[11,426,427],{},"FinCEN's October 2025 FAQs clarified two points that many programs over-engineered:",[24,429,430,436],{},[27,431,432,435],{},[20,433,434],{},"Continuing activity."," Earlier guidance suggested reviewing and filing on continuing activity every 90 days, with a deadline 120 days after the previous SAR. FinCEN now says that cadence isn't required; risk-based procedures can govern it.",[27,437,438,441],{},[20,439,440],{},"No-SAR decisions."," Documenting a decision not to file is encouraged, not required. A short statement usually suffices.",[11,443,444],{},"When an internal deadline slips, escalate it, don't hide it:",[73,446,447,450,453,456,459],{},[27,448,449],{},"Flag any case past its internal review target automatically, before it nears the filing deadline.",[27,451,452],{},"Escalate to the compliance officer with the case age and the blocker.",[27,454,455],{},"File as soon as the decision is made, and record why the review took longer.",[27,457,458],{},"Never backdate a detection or decision date. A late filing with an honest record is a finding; a falsified date is a much bigger problem.",[27,460,461],{},"Report late cases in the monthly management pack, with the root cause.",[46,463,465],{"id":464},"what-is-a-30-day-readiness-plan","What is a 30-day readiness plan?",[11,467,468],{},"A 30-day plan turns \"we think we're ready\" into an indexed evidence folder. Run it before a scheduled exam, a partner bank review, or a funding round's compliance diligence.",[73,470,471,477,483,494],{},[27,472,473,476],{},[20,474,475],{},"Week 1: inventory."," List every control the policy claims, its owner, and the artifact that proves it. Use the evidence table above as the index.",[27,478,479,482],{},[20,480,481],{},"Week 2: gap review."," Compare the policy with system behavior. Flag rules with no rationale, tuning changes with no approval, cases with no closure note, and list refreshes with no log.",[27,484,485,488,489,493],{},[20,486,487],{},"Week 3: test scenarios."," Run known typologies through the system and confirm the right alerts fire. Pull a sample of closed alerts and rebuild each decision from the records alone. The ",[57,490,492],{"href":491},"\u002Fresources\u002Fmore\u002Freduce-false-positives-transaction-monitoring","false positive tuning guide"," explains how to test below-the-line cases.",[27,495,496,499],{},[20,497,498],{},"Week 4: fix and document."," Close high-risk gaps first, update the policy to match reality, and log every change with an approver and a date.",[11,501,502,505],{},[20,503,504],{},"Illustrative example."," A fintech pulls 40 closed alerts from the last quarter as a mock exam sample. Six have no closure reason, three were closed by the analyst who also tuned the rule, and one SAR shows 41 days between alert and filing with no note. That's ten findings from one sample, and all ten are documentation gaps a regulator would find in the first week. The fix took two weeks: a mandatory closure reason field, a separation rule for tuning and review, and an aging alert on open cases. These numbers are illustrative, not drawn from a real program.",[46,507,509],{"id":508},"how-do-you-respond-to-a-compliance-request-for-information","How do you respond to a compliance request for information?",[11,511,512],{},"Answer completely, once, with documents rather than assertions. A request for information (RFI) from a regulator, partner bank, or payment provider usually covers a customer or a transaction, and a partial answer invites a second round.",[11,514,515],{},"Prepare these before you need them:",[24,517,518,521,524,527,530],{},[27,519,520],{},"The customer's verified identity or business file, including beneficial owners.",[27,522,523],{},"Transaction history for the period in question, with counterparties.",[27,525,526],{},"The relationship between sender and receiver and the purpose of the payment.",[27,528,529],{},"Source of funds evidence where the amount or pattern calls for it.",[27,531,532],{},"Your own case notes, if the activity already raised an alert.",[11,534,535,536,540],{},"Response windows are set by whoever asks, and they vary from hours to weeks. BlindPay, for example, gives partners 27 days to answer a customer KYC or KYB request for information before the customer is automatically rejected. The window is printed on the request. Read it on day one, not day twenty. Travel Rule data gaps follow their own hold and return logic, covered in the ",[57,537,539],{"href":538},"\u002Fresources\u002Fmore\u002Ftravel-rule-workflow-hold-return-reject","travel rule workflow guide",".",[46,542,544],{"id":543},"what-are-the-common-mistakes-in-aml-audit-readiness","What are the common mistakes in AML audit readiness?",[11,546,547],{},"The common mistakes are records that don't explain decisions and controls that nobody re-checks.",[24,549,550,556,562,568,574,580],{},[27,551,552,555],{},[20,553,554],{},"Gaps in case notes."," \"Closed, no concern\" without the evidence reviewed tells an examiner nothing.",[27,557,558,561],{},[20,559,560],{},"No validation after rule changes."," A threshold edit that ships without a before and after comparison is an untested control.",[27,563,564,567],{},[20,565,566],{},"No board or management reporting."," If leadership never sees alert volumes, backlog, and SAR counts, the program has no oversight on record.",[27,569,570,573],{},[20,571,572],{},"A policy nobody has reviewed."," A policy that still describes last year's products is evidence the program and the business drifted apart.",[27,575,576,579],{},[20,577,578],{},"Unjustified risk rating overrides."," Staff able to lower a customer's risk rating without a written reason and a second approver is one of the first things examiners test.",[27,581,582,585],{},[20,583,584],{},"Same person tunes and reviews."," Separation between whoever writes the rules and whoever checks them is basic independence.",[46,587,589],{"id":588},"how-does-blindpay-support-audit-readiness","How does BlindPay support audit readiness?",[11,591,592,593,597],{},"BlindPay is registered with FinCEN as a money services business and lists its registrations on the ",[57,594,596],{"href":595},"\u002Flicenses","licenses page",". KYC, KYB, sanctions screening, travel rule compliance, and transaction monitoring run inside the API before money moves, so each customer and payment carries a status rather than a decision buried in email.",[11,599,600,601,605,606,605,609,612,613,616,617,621,622,626,627,630,631,635],{},"For partners, that means the evidence trail starts in the data. Customers move through documented statuses such as ",[602,603,604],"code",{},"verifying",", ",[602,607,608],{},"approved",[602,610,611],{},"compliance_request",", and ",[602,614,615],{},"rejected",", described in the ",[57,618,620],{"href":619},"\u002Fdocs\u002Fkb\u002Fkyc","KYC reference",". RFIs can be handled through the ",[57,623,625],{"href":624},"\u002Fdocs\u002Flearn\u002Frfi","RFI API",", which returns the deadline as ",[602,628,629],{},"expires_at",". Flagged payments land on hold for manual review, as described in ",[57,632,634],{"href":633},"\u002Fdocs\u002Fkb\u002Fon-hold-transactions","on-hold transactions",". Your own AML program remains yours to document; these records make that easier to evidence.",[46,637,639],{"id":638},"what-to-do-next","What to do next",[11,641,642],{},"Pull 25 closed alerts from last month and try to rebuild each decision from the records alone. Every case you can't rebuild is a finding waiting for an examiner. Start the 30-day plan with those.",[46,644,646],{"id":645},"sources-and-further-reading","Sources and further reading",[24,648,649,655,661,667,673,680],{},[27,650,651],{},[57,652,654],{"href":67,"rel":653},[69],"31 CFR 1022.210: AML programs for money services businesses",[27,656,657],{},[57,658,660],{"href":418,"rel":659},[69],"31 CFR 1022.320: SAR reporting by money services businesses",[27,662,663],{},[57,664,666],{"href":120,"rel":665},[69],"FinCEN: SAR frequently asked questions, October 2025",[27,668,669],{},[57,670,672],{"href":104,"rel":671},[69],"FinCEN and IRS: BSA\u002FAML Examination Manual for Money Services Businesses",[27,674,675],{},[57,676,679],{"href":677,"rel":678},"https:\u002F\u002Fwww.fatf-gafi.org\u002Fen\u002Fpublications\u002FFatfrecommendations\u002FFatf-recommendations.html",[69],"FATF Recommendations",[27,681,682],{},[57,683,685],{"href":126,"rel":684},[69],"FCA Financial Crime Guide, FCG 3.2",[11,687,688],{},[689,690,691],"em",{},"This article is general information, not legal advice.",{"title":693,"searchDepth":694,"depth":694,"links":695},"",2,[696,697,698,699,700,701,702,703,704,705,706],{"id":48,"depth":694,"text":49},{"id":110,"depth":694,"text":111},{"id":140,"depth":694,"text":141},{"id":318,"depth":694,"text":319},{"id":411,"depth":694,"text":412},{"id":464,"depth":694,"text":465},{"id":508,"depth":694,"text":509},{"id":543,"depth":694,"text":544},{"id":588,"depth":694,"text":589},{"id":638,"depth":694,"text":639},{"id":645,"depth":694,"text":646},"compliance","2026-10-04","The evidence examiners expect from automated risk monitoring: a 10-item evidence table, good vs poor practice, SAR timelines, RFIs, and a 30-day plan.","md",[712,715,718,721,724,727],{"q":713,"a":714},"What do AML examiners usually ask for first?","The written AML policy, the risk assessment behind it, and a list of the monitoring rules with their thresholds. Then they pull a sample of alerts, cases, and SAR decisions and check whether the records match the policy. A program that can produce those documents in a day starts the exam in a much better position than one that has to rebuild them.",{"q":716,"a":717},"How long must a money services business keep AML records?","Five years. FinCEN's general rule in 31 CFR 1010.430 requires records kept under the Bank Secrecy Act to be retained for five years, and the MSB SAR rule requires a copy of each SAR and its supporting documentation to be kept for five years from the filing date. Retrievable matters as much as retained: an examiner will ask for specific files.",{"q":719,"a":720},"When does a money services business have to file a SAR?","A US money services business files a suspicious activity report when a transaction involves or aggregates at least USD 2,000 and it knows, suspects, or has reason to suspect the activity is suspicious under 31 CFR 1022.320. The report is due no later than 30 calendar days after the date of initial detection. Other countries set their own thresholds and deadlines.",{"q":722,"a":723},"Do you have to document a decision not to file a SAR?","Not under US rules. FinCEN's October 2025 SAR FAQs say a financial institution is not required to document a decision not to file, though FinCEN encourages it, and a short, concise statement usually suffices. Most programs record one anyway, because it is the only way to show an examiner why a closed alert was closed.",{"q":725,"a":726},"What is independent testing in an AML program?","It is a review of whether the AML program is adequate and working, done by someone other than the compliance officer who runs it. For money services businesses, 31 CFR 1022.210 requires it and says its scope and frequency must match the risk of the services offered. It can be internal staff or an outside firm, as long as the reviewer is independent.",{"q":728,"a":729},"How should a fintech prepare for a partner bank compliance review?","Treat it like an exam. Have the policy, risk assessment, rule inventory, tuning log, independent test report, sample case files, SAR statistics, and sanctions list logs ready in one indexed folder. Partner banks focus on whether your controls cover the flows they carry for you, so map each control to a product and corridor.",{"name":731,"steps":732},"30-day AML audit readiness plan for automated risk monitoring",[733,736,739,742],{"name":734,"text":735},"Week 1: inventory","List every control the program claims to run: the AML policy, the customer risk rating method, each monitoring rule and threshold, sanctions lists and refresh jobs, case management, SAR process, reporting, and retention. Name an owner and the artifact that proves each one.",{"name":737,"text":738},"Week 2: gap review","Compare the policy with what the system actually does. Flag rules with no written rationale, tuning changes with no approval, cases with no closure note, and list updates with no log. Rank gaps by risk, not by how easy they are to fix.",{"name":740,"text":741},"Week 3: test scenarios","Run known typologies through the system, such as split payments under a threshold or a counterparty added to a sanctions list, and confirm the right alert fires. Pull a sample of closed alerts and SAR decisions and check that each one can be reconstructed from the records alone.",{"name":743,"text":744},"Week 4: fix and document","Close the high-risk gaps, write the missing rule rationales, update the policy to match reality, and record every change with an approver and a date. Package the evidence in one place, indexed to the examiner's likely request list.",false,{"author":747},"BlindPay Team",true,"\u002Fresources\u002Fmore\u002Faml-audit-readiness-risk-monitoring","---\ntitle: \"AML audit readiness: what regulators ask for and how to prove your risk monitoring works\"\nseoTitle: \"AML audit readiness: the evidence examiners ask for\"\ndescription: \"The evidence examiners expect from automated risk monitoring: a 10-item evidence table, good vs poor practice, SAR timelines, RFIs, and a 30-day plan.\"\ndate: \"2026-10-04\"\nupdated: \"2026-10-04\"\ncategory: \"compliance\"\nauthor: \"BlindPay Team\"\nhowto:\n  name: \"30-day AML audit readiness plan for automated risk monitoring\"\n  steps:\n    - name: \"Week 1: inventory\"\n      text: \"List every control the program claims to run: the AML policy, the customer risk rating method, each monitoring rule and threshold, sanctions lists and refresh jobs, case management, SAR process, reporting, and retention. Name an owner and the artifact that proves each one.\"\n    - name: \"Week 2: gap review\"\n      text: \"Compare the policy with what the system actually does. Flag rules with no written rationale, tuning changes with no approval, cases with no closure note, and list updates with no log. Rank gaps by risk, not by how easy they are to fix.\"\n    - name: \"Week 3: test scenarios\"\n      text: \"Run known typologies through the system, such as split payments under a threshold or a counterparty added to a sanctions list, and confirm the right alert fires. Pull a sample of closed alerts and SAR decisions and check that each one can be reconstructed from the records alone.\"\n    - name: \"Week 4: fix and document\"\n      text: \"Close the high-risk gaps, write the missing rule rationales, update the policy to match reality, and record every change with an approver and a date. Package the evidence in one place, indexed to the examiner's likely request list.\"\nfaq:\n  - q: \"What do AML examiners usually ask for first?\"\n    a: \"The written AML policy, the risk assessment behind it, and a list of the monitoring rules with their thresholds. Then they pull a sample of alerts, cases, and SAR decisions and check whether the records match the policy. A program that can produce those documents in a day starts the exam in a much better position than one that has to rebuild them.\"\n  - q: \"How long must a money services business keep AML records?\"\n    a: \"Five years. FinCEN's general rule in 31 CFR 1010.430 requires records kept under the Bank Secrecy Act to be retained for five years, and the MSB SAR rule requires a copy of each SAR and its supporting documentation to be kept for five years from the filing date. Retrievable matters as much as retained: an examiner will ask for specific files.\"\n  - q: \"When does a money services business have to file a SAR?\"\n    a: \"A US money services business files a suspicious activity report when a transaction involves or aggregates at least USD 2,000 and it knows, suspects, or has reason to suspect the activity is suspicious under 31 CFR 1022.320. The report is due no later than 30 calendar days after the date of initial detection. Other countries set their own thresholds and deadlines.\"\n  - q: \"Do you have to document a decision not to file a SAR?\"\n    a: \"Not under US rules. FinCEN's October 2025 SAR FAQs say a financial institution is not required to document a decision not to file, though FinCEN encourages it, and a short, concise statement usually suffices. Most programs record one anyway, because it is the only way to show an examiner why a closed alert was closed.\"\n  - q: \"What is independent testing in an AML program?\"\n    a: \"It is a review of whether the AML program is adequate and working, done by someone other than the compliance officer who runs it. For money services businesses, 31 CFR 1022.210 requires it and says its scope and frequency must match the risk of the services offered. It can be internal staff or an outside firm, as long as the reviewer is independent.\"\n  - q: \"How should a fintech prepare for a partner bank compliance review?\"\n    a: \"Treat it like an exam. Have the policy, risk assessment, rule inventory, tuning log, independent test report, sample case files, SAR statistics, and sanctions list logs ready in one indexed folder. Partner banks focus on whether your controls cover the flows they carry for you, so map each control to a product and corridor.\"\n---\n\nRegulators expect proof that automated risk monitoring fits your risks and actually works. In practice that means a written AML policy, a customer risk rating method, a documented reason for every rule and threshold, tuning records, independent testing, timestamped case trails, SAR decision records, sanctions list update logs, management reporting, and records kept for five years.\n\nThis article is general information, not legal advice. Exam scope differs by regulator and license, so confirm yours with counsel.\n\n**Key takeaways**\n\n- Examiners test whether the system matches the policy, not whether the policy reads well.\n- Every rule needs a written rationale tied to a risk you identified. \"The vendor set it\" is not a rationale.\n- A case file should let a stranger reconstruct the decision: alert, evidence, reviewer, reason, date.\n- US money services businesses file SARs within 30 calendar days of initial detection and keep records for five years.\n- Independent testing is a legal requirement for MSBs, scoped to risk, and run by someone other than the compliance officer.\n- Thirty focused days can close most documentation gaps before an exam or a partner bank review.\n\n## What do regulators expect from an automated risk monitoring program?\n\nThey expect a program that is risk based, documented, tested, and able to show its own work. Automation doesn't change the standard. It changes the evidence, because every decision now leaves a record.\n\nThe global baseline is FATF Recommendation 1, the risk-based approach: identify and assess your money laundering and terrorist financing risks, then apply controls proportionate to them. FATF Recommendation 20 adds prompt reporting of suspicious transactions. The [automated risk monitoring explainer](\u002Fresources\u002Fmore\u002Fwhat-is-automated-risk-monitoring-fintech) covers the components that sit under those obligations.\n\nFor a US money services business (MSB), the requirement is concrete. [31 CFR 1022.210](https:\u002F\u002Fwww.law.cornell.edu\u002Fcfr\u002Ftext\u002F31\u002F1022.210) sets four minimum pillars for the AML program:\n\n1. **Policies, procedures, and internal controls**, covering customer identification, filing reports, keeping records, and responding to law enforcement.\n2. **A designated compliance officer** who owns day-to-day compliance.\n3. **Training** for the right staff, including how to detect suspicious transactions.\n4. **Independent review**, with scope and frequency matched to the risk of the services offered. The reviewer can be internal, but can't be the compliance officer.\n\nFinCEN and the IRS publish the [Bank Secrecy Act\u002FAML Examination Manual for Money Services Businesses](https:\u002F\u002Fwww.fincen.gov\u002Fsites\u002Fdefault\u002Ffiles\u002Fshared\u002FMSB_Exam_Manual.pdf). It dates from 2008, but the method holds: scope the risk, read the program, test transactions against it.\n\n## Why do vendor default rules fail an exam?\n\nBecause a default rule was tuned for someone else's customers. When an examiner asks why a velocity rule fires at five transfers a day for a freelancer segment, the answer has to come from your risk assessment, not from a vendor's setup guide.\n\nFinCEN said this directly in its [October 2025 SAR FAQs](https:\u002F\u002Fwww.fincen.gov\u002Fsystem\u002Ffiles\u002F2025-10\u002FSAR-FAQs-October-2025.pdf): monitoring parameters should be commensurate with the money laundering and terrorist financing risk of the specific institution, considering its products, locations, and customers. The UK's [FCA Financial Crime Guide](https:\u002F\u002Fhandbook.fca.org.uk\u002Fhandbook\u002FFCG\u002F3\u002F2.html) lists, as poor practice, threshold-based systems that are poorly calibrated, where the firm struggles to explain why a particular rule exists.\n\nSo the default isn't the problem. The undocumented default is. The [12 red flags rule library](\u002Fresources\u002Fmore\u002Ftransaction-monitoring-red-flags-stablecoin-payments) is a useful starting point for that inventory.\n\n## What evidence do examiners ask for?\n\nExaminers ask for artifacts that prove each control exists, runs, and gets reviewed. The table below covers the ten items that come up most in reviews of automated monitoring.\n\n| Evidence item | What examiners look for | Example artifact | Owner |\n| --- | --- | --- | --- |\n| Written AML policy | Approved, current, and matching what the system does | Policy with version history and approval date | Compliance officer |\n| Customer risk rating methodology | Clear factors, how ratings change, who can override | Methodology document plus rating distribution | Compliance |\n| Rule and threshold rationale | Each rule tied to a risk and a customer segment | Rule inventory with typology, threshold, rationale | Compliance with engineering |\n| Calibration and tuning records | Changes tested before release and approved | Change log with before and after alert counts | Compliance with engineering |\n| Independent testing results | Scope matched to risk, findings tracked to closure | Review report and remediation tracker | Independent reviewer |\n| Alert to closure case trails | Timestamps, reviewer, evidence, and a reason | Case export for a sample period | Compliance analysts |\n| SAR decision records | Filed on time, consistent reasoning | SAR log with detection, decision, and filing dates | Compliance officer |\n| Sanctions list update logs | Lists loaded promptly and rescreening ran | List version log and rescreen job output | Engineering with compliance |\n| Management information and board reporting | Leadership sees volumes, backlog, SARs, findings | Monthly report pack and meeting minutes | Compliance officer |\n| Record retention | Five years, and retrievable on request | Retention policy plus a retrieval test | Operations |\n\nTwo rows go missing most. Sanctions list logs, because list refreshes run as a background job nobody watches (the [ongoing sanctions screening guide](\u002Fresources\u002Fmore\u002Fongoing-sanctions-screening-how-often-to-rescreen) covers what to log). And tuning records, because rule changes ship like ordinary code. Route both through one approval step.\n\n## What does good practice look like compared with poor practice?\n\nGood practice shows the program understands its own output. The table below is drawn from the FCA Financial Crime Guide's good and poor practice examples on monitoring, paraphrased.\n\n| Area | Good practice | Poor practice |\n| --- | --- | --- |\n| Monitoring design | Looks at customer behavior as a whole, at several levels of aggregation | Single-transaction thresholds used where they don't fit the risk |\n| Rule calibration | The firm can explain the rationale for each rule | Rules are poorly calibrated and their rationale is unclear |\n| New approaches | New monitoring methods are piloted and tested before replacing old ones | Systems are swapped without comparing alert quality |\n| Control framework | Management oversees performance and resolves issues | The control framework around automated monitoring is weak |\n| Customer explanations | Staff test explanations against evidence | Staff accept a customer's explanation at face value |\n| Use of results | Monitoring results show whether due diligence is still adequate | Little evidence that unusual transactions reach the compliance officer |\n\nOne more contrast that isn't from the FCA guide, but that examiners everywhere probe: a customer risk rating that refreshes on triggers (new corridor, volume jump, ownership change) versus a rating set once at onboarding and never touched. The second is a snapshot, not a control.\n\n## How do SAR timelines work, and what happens when a deadline slips?\n\nUnder [31 CFR 1022.320](https:\u002F\u002Fwww.law.cornell.edu\u002Fcfr\u002Ftext\u002F31\u002F1022.320), a US MSB must report suspicious transactions that involve or aggregate at least USD 2,000, no later than 30 calendar days after initial detection. It keeps the SAR and supporting documents for five years from filing. Timelines differ in other jurisdictions, so check the local rule for each license.\n\nThe 30-day clock is where programs get caught. Examiners compare three dates in every sampled case: when the alert fired, when someone decided it was suspicious, and when the SAR was filed. Long unexplained gaps between them are findings even if the filing itself was \"on time.\"\n\nFinCEN's October 2025 FAQs clarified two points that many programs over-engineered:\n\n- **Continuing activity.** Earlier guidance suggested reviewing and filing on continuing activity every 90 days, with a deadline 120 days after the previous SAR. FinCEN now says that cadence isn't required; risk-based procedures can govern it.\n- **No-SAR decisions.** Documenting a decision not to file is encouraged, not required. A short statement usually suffices.\n\nWhen an internal deadline slips, escalate it, don't hide it:\n\n1. Flag any case past its internal review target automatically, before it nears the filing deadline.\n2. Escalate to the compliance officer with the case age and the blocker.\n3. File as soon as the decision is made, and record why the review took longer.\n4. Never backdate a detection or decision date. A late filing with an honest record is a finding; a falsified date is a much bigger problem.\n5. Report late cases in the monthly management pack, with the root cause.\n\n## What is a 30-day readiness plan?\n\nA 30-day plan turns \"we think we're ready\" into an indexed evidence folder. Run it before a scheduled exam, a partner bank review, or a funding round's compliance diligence.\n\n1. **Week 1: inventory.** List every control the policy claims, its owner, and the artifact that proves it. Use the evidence table above as the index.\n2. **Week 2: gap review.** Compare the policy with system behavior. Flag rules with no rationale, tuning changes with no approval, cases with no closure note, and list refreshes with no log.\n3. **Week 3: test scenarios.** Run known typologies through the system and confirm the right alerts fire. Pull a sample of closed alerts and rebuild each decision from the records alone. The [false positive tuning guide](\u002Fresources\u002Fmore\u002Freduce-false-positives-transaction-monitoring) explains how to test below-the-line cases.\n4. **Week 4: fix and document.** Close high-risk gaps first, update the policy to match reality, and log every change with an approver and a date.\n\n**Illustrative example.** A fintech pulls 40 closed alerts from the last quarter as a mock exam sample. Six have no closure reason, three were closed by the analyst who also tuned the rule, and one SAR shows 41 days between alert and filing with no note. That's ten findings from one sample, and all ten are documentation gaps a regulator would find in the first week. The fix took two weeks: a mandatory closure reason field, a separation rule for tuning and review, and an aging alert on open cases. These numbers are illustrative, not drawn from a real program.\n\n## How do you respond to a compliance request for information?\n\nAnswer completely, once, with documents rather than assertions. A request for information (RFI) from a regulator, partner bank, or payment provider usually covers a customer or a transaction, and a partial answer invites a second round.\n\nPrepare these before you need them:\n\n- The customer's verified identity or business file, including beneficial owners.\n- Transaction history for the period in question, with counterparties.\n- The relationship between sender and receiver and the purpose of the payment.\n- Source of funds evidence where the amount or pattern calls for it.\n- Your own case notes, if the activity already raised an alert.\n\nResponse windows are set by whoever asks, and they vary from hours to weeks. BlindPay, for example, gives partners 27 days to answer a customer KYC or KYB request for information before the customer is automatically rejected. The window is printed on the request. Read it on day one, not day twenty. Travel Rule data gaps follow their own hold and return logic, covered in the [travel rule workflow guide](\u002Fresources\u002Fmore\u002Ftravel-rule-workflow-hold-return-reject).\n\n## What are the common mistakes in AML audit readiness?\n\nThe common mistakes are records that don't explain decisions and controls that nobody re-checks.\n\n- **Gaps in case notes.** \"Closed, no concern\" without the evidence reviewed tells an examiner nothing.\n- **No validation after rule changes.** A threshold edit that ships without a before and after comparison is an untested control.\n- **No board or management reporting.** If leadership never sees alert volumes, backlog, and SAR counts, the program has no oversight on record.\n- **A policy nobody has reviewed.** A policy that still describes last year's products is evidence the program and the business drifted apart.\n- **Unjustified risk rating overrides.** Staff able to lower a customer's risk rating without a written reason and a second approver is one of the first things examiners test.\n- **Same person tunes and reviews.** Separation between whoever writes the rules and whoever checks them is basic independence.\n\n## How does BlindPay support audit readiness?\n\nBlindPay is registered with FinCEN as a money services business and lists its registrations on the [licenses page](\u002Flicenses). KYC, KYB, sanctions screening, travel rule compliance, and transaction monitoring run inside the API before money moves, so each customer and payment carries a status rather than a decision buried in email.\n\nFor partners, that means the evidence trail starts in the data. Customers move through documented statuses such as `verifying`, `approved`, `compliance_request`, and `rejected`, described in the [KYC reference](\u002Fdocs\u002Fkb\u002Fkyc). RFIs can be handled through the [RFI API](\u002Fdocs\u002Flearn\u002Frfi), which returns the deadline as `expires_at`. Flagged payments land on hold for manual review, as described in [on-hold transactions](\u002Fdocs\u002Fkb\u002Fon-hold-transactions). Your own AML program remains yours to document; these records make that easier to evidence.\n\n## What to do next\n\nPull 25 closed alerts from last month and try to rebuild each decision from the records alone. Every case you can't rebuild is a finding waiting for an examiner. Start the 30-day plan with those.\n\n## Sources and further reading\n\n- [31 CFR 1022.210: AML programs for money services businesses](https:\u002F\u002Fwww.law.cornell.edu\u002Fcfr\u002Ftext\u002F31\u002F1022.210)\n- [31 CFR 1022.320: SAR reporting by money services businesses](https:\u002F\u002Fwww.law.cornell.edu\u002Fcfr\u002Ftext\u002F31\u002F1022.320)\n- [FinCEN: SAR frequently asked questions, October 2025](https:\u002F\u002Fwww.fincen.gov\u002Fsystem\u002Ffiles\u002F2025-10\u002FSAR-FAQs-October-2025.pdf)\n- [FinCEN and IRS: BSA\u002FAML Examination Manual for Money Services Businesses](https:\u002F\u002Fwww.fincen.gov\u002Fsites\u002Fdefault\u002Ffiles\u002Fshared\u002FMSB_Exam_Manual.pdf)\n- [FATF Recommendations](https:\u002F\u002Fwww.fatf-gafi.org\u002Fen\u002Fpublications\u002FFatfrecommendations\u002FFatf-recommendations.html)\n- [FCA Financial Crime Guide, FCG 3.2](https:\u002F\u002Fhandbook.fca.org.uk\u002Fhandbook\u002FFCG\u002F3\u002F2.html)\n\n*This article is general information, not legal advice.*\n",{"title":5,"description":709},"AML audit readiness: the evidence examiners ask for","resources\u002Fmore\u002Faml-audit-readiness-risk-monitoring","sAYjMzuEgQqanXBdoCXKPK_plfwqvPNICC0yMRDVek0",[756,757,761,765,769,773,777,781,785,789,793,797,800,804,807,811,815,819,823,827,831,834,837,841,845,849,853,856,860,864],{"path":749,"title":5,"description":709},{"path":758,"title":759,"description":760},"\u002Fresources\u002Fmore\u002Fare-blockchain-payments-legal","Are blockchain payments legal? Rules in the US, EU, UK, Brazil, and Mexico","Blockchain payments are legal for businesses in the US, EU, UK, Brazil, and Mexico, under different rules. What each country regulates, as of October 2026.",{"path":762,"title":763,"description":764},"\u002Fresources\u002Fmore\u002Fare-stablecoin-payments-reversible","Are stablecoin payments reversible? Finality, custody, and fraud explained","Stablecoin transfers settle final in minutes and cannot be reversed. That finality proves custody at every step, but it also opens a fraud gap on the fiat side of the payment.",{"path":766,"title":767,"description":768},"\u002Fresources\u002Fmore\u002Fautomated-kyc-kyb-vs-manual-onboarding","Automated KYC\u002FKYB vs. manual onboarding: what actually changes","A side-by-side comparison of automated and manual KYC\u002FKYB for fintechs: onboarding time, false-positive rates, cost per verification, scaling across jurisdictions, and audit-trail quality, plus the cases where a human reviewer is still required.",{"path":770,"title":771,"description":772},"\u002Fresources\u002Fmore\u002Fbuild-vs-buy-automated-risk-monitoring","Build vs. buy automated risk monitoring: a decision framework and 15 provider questions","Build, buy point solutions, or use an integrated provider? Compare three ways to run automated risk monitoring, who stays responsible, and 15 questions.",{"path":774,"title":775,"description":776},"\u002Fresources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments","Compliance agents for cross-border stablecoin payments: a global regulatory guide","How compliance agents apply FinCEN, MiCA, FCA, MAS, and Banco Central do Brasil rules to cross-border stablecoin payments: jurisdiction table, the FATF Travel Rule, multi-list sanctions screening, the four components of a compliant program, and questions to ask a compliance provider.",{"path":778,"title":779,"description":780},"\u002Fresources\u002Fmore\u002Fcrypto-wallet-compliance-checklist","Crypto wallet compliance checklist: KYC, KYT, and Travel Rule","The compliance that comes with crypto wallets and stablecoin payments: KYC and KYB, KYT, the Travel Rule, address screening, MSB rules, and 15 checks.",{"path":782,"title":783,"description":784},"\u002Fresources\u002Fmore\u002Fdirect-vs-indirect-stablecoin-exchange","Direct vs indirect stablecoin exchange: who holds the stablecoin, and who carries compliance","In direct exchange, both parties hold stablecoins and own compliance. In indirect exchange, a provider settles in stablecoins behind a normal bank payment.",{"path":786,"title":787,"description":788},"\u002Fresources\u002Fmore\u002Fdo-merchants-need-a-license-to-accept-stablecoins","Do merchants need a license to accept stablecoin payments? KYC, KYB, and compliance explained","Usually no: the license sits with the provider that moves the funds. What merchants still owe on KYB, sanctions, tax, and records in the US, EU, Brazil.",{"path":790,"title":791,"description":792},"\u002Fresources\u002Fmore\u002Fhow-to-automate-kyc-kyb-stablecoin-payments","How to automate KYC and KYB for stablecoin payments","A developer guide to automated KYC and KYB for stablecoin payment flows: how verification runs inside a payment API, step-by-step workflows for individuals and businesses, jurisdiction requirements for the US, EU, UK, Singapore, and Brazil, and what to check before settlement.",{"path":794,"title":795,"description":796},"\u002Fresources\u002Fmore\u002Fhow-to-choose-automated-risk-monitoring-vendor","How to choose an automated risk monitoring vendor for a fintech startup","A buyer's guide to automated risk monitoring vendors for early-stage fintechs: the five criteria that matter (regulatory coverage, integration effort, false-positive rate, pricing model, audit output), the question to ask a vendor on each, a checklist table, and what it costs.",{"path":491,"title":798,"description":799},"How to reduce false positives in transaction monitoring without missing real risk","Cut AML alert noise without losing real cases: a 7-step tuning process, the levers that work, the metrics to watch, and what automation should never close.",{"path":801,"title":802,"description":803},"\u002Fresources\u002Fmore\u002Fmica-stablecoin-rules-explained","MiCA stablecoin rules explained for payment companies","What MiCA means if your business uses stablecoins in the EU: EMTs vs ARTs, issuer requirements, why USDC is compliant and USDT was delisted, and a practical checklist.",{"path":313,"title":805,"description":806},"Ongoing sanctions screening: how often to rescreen and what to screen","How often to rescreen customers against sanctions lists, what to screen beyond names, and a cadence that holds up under OFAC strict liability.",{"path":808,"title":809,"description":810},"\u002Fresources\u002Fmore\u002Fpsav-brazil-explained","PSAV in Brazil: the Central Bank's virtual asset license explained","PSAV is Brazil's authorization for virtual asset service providers, created by BCB Resolutions 519, 520, and 521 under Law 14.478\u002F2022. What it requires and who needs it.",{"path":812,"title":813,"description":814},"\u002Fresources\u002Fmore\u002Freal-time-transaction-monitoring-stablecoin-payments","Real-time transaction monitoring for cross-border stablecoin payments","Why stablecoin cross-border flows need different monitoring than wires: the signals that get scored (wallet address risk, velocity, corridor risk, on\u002Foff-ramp counterparties), real-time vs. batch monitoring, and a worked example of a flagged pattern from alert to decision.",{"path":816,"title":817,"description":818},"\u002Fresources\u002Fmore\u002Fstablecoin-card-issuing-compliance","Stablecoin card issuing compliance: KYC, KYB, and regulatory coverage explained","What compliance stablecoin card issuing requires: KYC vs. KYB, who is responsible for what, how rules differ in the US, EU, UK, and Latin America, and ongoing monitoring.",{"path":820,"title":821,"description":822},"\u002Fresources\u002Fmore\u002Fstablecoin-off-ramp-limits","Stablecoin off-ramp limits: per-transaction, daily, and monthly caps explained","Why off-ramps cap how much you can convert per transaction, day, and month, how the caps map to KYC and KYB tiers, and the documents that raise them.",{"path":824,"title":825,"description":826},"\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026","Stablecoin regulation in 2026: MiCA, the GENIUS Act, Brazil, and Japan","Where stablecoin regulation stands in 2026: MiCA in the EU, the GENIUS Act in the US, Brazil's VASP regime, and Japan's issuer rules, compared for payment businesses.",{"path":828,"title":829,"description":830},"\u002Fresources\u002Fmore\u002Fgenius-act-for-businesses","The GENIUS Act explained for businesses that use stablecoins","What the GENIUS Act means if your business sends, receives, or holds stablecoins: who it regulates, the dates that matter, and what to do before 2027.",{"path":538,"title":832,"description":833},"The Travel Rule in an automated workflow: what to collect, when to hold, when to return","How to automate Travel Rule compliance for stablecoin transfers: what data to collect, the checks before release, and when to hold, reject, or return.",{"path":135,"title":835,"description":836},"Transaction monitoring red flags for stablecoin payments: 12 rules to automate","The 12 red flags automated transaction monitoring should catch in stablecoin and cross-border payments, with rule logic, actions, and the data each needs.",{"path":838,"title":839,"description":840},"\u002Fresources\u002Fmore\u002Fvirtual-account-requirements-kyc-kyb","Virtual account requirements: KYC, KYB, and what the bank reviews before it says yes","What you need to open a virtual account: KYC or KYB, the extra fields and source of funds documents the bank reviews, who owns each step, and timelines.",{"path":842,"title":843,"description":844},"\u002Fresources\u002Fmore\u002Fwhat-are-compliance-agents-in-fintech","What are compliance agents in fintech? How they work and what they do for payments","Compliance agents are autonomous software components that run KYC, KYB, sanctions screening, and transaction monitoring inside a payment flow, then document every decision. How they work, what they do for payments, how they differ from traditional compliance software, and how BlindPay embeds them in its API.",{"path":846,"title":847,"description":848},"\u002Fresources\u002Fmore\u002Fwhat-is-kyb","What is KYB? Know Your Business verification explained","KYB verifies a company's legal existence, ownership, and control before it can transact. What it checks, who counts as a beneficial owner, and how it differs from KYC.",{"path":850,"title":851,"description":852},"\u002Fresources\u002Fmore\u002Fwhat-is-a-vasp","What is a VASP? Virtual asset service provider explained","A VASP is any business that exchanges, transfers, or custodies virtual assets like stablecoins for customers. FATF's definition and what it requires in practice.",{"path":59,"title":854,"description":855},"What is automated risk monitoring in fintech?","A reference explainer on automated risk monitoring for fintechs: the four components (KYC\u002FKYB, transaction monitoring, sanctions and watchlist screening, compliance automation), what each one flags, a manual vs. automated comparison, and what FinCEN, FATF, and OFAC actually require.",{"path":857,"title":858,"description":859},"\u002Fresources\u002Fmore\u002Ftravel-rule-stablecoin-off-ramps","What is the travel rule for stablecoin off-ramps? Thresholds, data, and failed checks","The travel rule makes off-ramps pass sender and receiver data with transfers. Thresholds by country, required data, and what happens when checks fail.",{"path":861,"title":862,"description":863},"\u002Fresources\u002Fmore\u002Fcrypto-on-ramp-compliance-who-owns-what","Who owns compliance when you integrate a crypto on-ramp API? KYC, KYB, KYT, and holds","An on-ramp API splits compliance between the provider and you. Who runs KYC, KYB, KYT, sanctions, and the travel rule, and what stays on your side.",{"path":865,"title":866,"description":867},"\u002Fresources\u002Fmore\u002Fsource-of-funds-crypto-off-ramps","Why do crypto off-ramps ask for source of funds? Documents, triggers, and on-chain proof","Why off-ramps ask where your stablecoins came from, how source of funds differs from source of wealth, what triggers a request, and which documents pass.",1791301910302]