[{"data":1,"prerenderedAt":771},["ShallowReactive",2],{"content-\u002Fresources\u002Fmore\u002Fbuild-vs-buy-automated-risk-monitoring":3,"resources-category-build-vs-buy-automated-risk-monitoring":661},{"id":4,"title":5,"authors":6,"body":7,"categories":6,"category":628,"categoryType":6,"compare":6,"contributors":6,"date":629,"description":630,"extension":631,"faq":632,"howto":6,"isBlog":651,"isChangelog":651,"meta":652,"navigation":654,"path":655,"pillar":651,"products":6,"rawbody":656,"role":6,"seo":657,"seoTitle":658,"stem":659,"thumbnail":6,"updated":629,"__hash__":660},"content\u002Fresources\u002Fmore\u002Fbuild-vs-buy-automated-risk-monitoring.md","Build vs. buy automated risk monitoring: a decision framework and 15 provider questions",null,{"type":8,"value":9,"toc":613},"minimark",[10,14,17,23,42,51,56,59,151,154,158,161,164,203,206,210,213,262,265,269,272,325,333,337,345,392,399,403,406,443,457,461,464,484,487,491,529,533,541,559,563,566,570,608],[11,12,13],"p",{},"Most fintechs should buy automated risk monitoring and build only the rules specific to their product. The real choice is between point solutions (separate KYC, screening, and monitoring vendors) and an integrated payments and compliance provider. Either way, regulatory responsibility stays with the fintech, so pick the option whose logic you can explain to an examiner.",[11,15,16],{},"This article is general information, not legal advice.",[11,18,19],{},[20,21,22],"strong",{},"Key takeaways",[24,25,26,30,33,36,39],"ul",{},[27,28,29],"li",{},"There are three operating models, not two: build in house, buy point solutions, or use a provider that runs compliance inside the payment flow.",[27,31,32],{},"Responsibility never transfers. Under 31 CFR 1022.210, the AML program belongs to the money services business, whoever runs the software.",[27,34,35],{},"The rules engine is the cheap part of building. List feeds, wallet analytics, case management, and audit evidence are the expensive parts.",[27,37,38],{},"Pick on six inputs: jurisdictions, volume, rails, team size, audit needs, and speed to market.",[27,40,41],{},"Evaluate providers on what they can export and explain, not on the demo.",[11,43,44,45,50],{},"Automated risk monitoring covers four jobs: verifying customers, monitoring transactions, screening against sanctions lists, and working the resulting alerts. The ",[46,47,49],"a",{"href":48},"\u002Fresources\u002Fmore\u002Fwhat-is-automated-risk-monitoring-fintech","automated risk monitoring explainer"," takes each one apart. This guide answers a different question: who should run them.",[52,53,55],"h2",{"id":54},"what-are-the-three-ways-to-run-automated-risk-monitoring","What are the three ways to run automated risk monitoring?",[11,57,58],{},"A fintech can build monitoring in house, buy point solutions and connect them, or use an integrated provider that runs the checks inside the payment flow. Each model trades control for time and maintenance.",[60,61,62,87],"table",{},[63,64,65],"thead",{},[66,67,68,72,75,78,81,84],"tr",{},[69,70,71],"th",{},"Option",[69,73,74],{},"Time to launch",[69,76,77],{},"Ongoing cost drivers",[69,79,80],{},"Control and customization",[69,82,83],{},"Regulatory responsibility",[69,85,86],{},"Best for",[88,89,90,111,131],"tbody",{},[66,91,92,96,99,102,105,108],{},[93,94,95],"td",{},"Build in house",[93,97,98],{},"Longest. Many months before an examination-ready program",[93,100,101],{},"Engineers, data feeds, analytics licenses, analysts, model validation, independent review",[93,103,104],{},"Full. Every rule, threshold, and model is yours",[93,106,107],{},"Fully yours, including every design choice",[93,109,110],{},"Firms where monitoring is the product, or with unusual risk no vendor covers",[66,112,113,116,119,122,125,128],{},[93,114,115],{},"Buy point solutions",[93,117,118],{},"Medium. Each vendor integrates fast; the joins between them take longer",[93,120,121],{},"Per-check or platform fees per vendor, integration upkeep, analysts",[93,123,124],{},"High per layer, limited across layers",[93,126,127],{},"Yours. Vendors supply tools, you own the program and the joins",[93,129,130],{},"Teams with a compliance function that want best-of-breed per layer",[66,132,133,136,139,142,145,148],{},[93,134,135],{},"Integrated payments and compliance provider",[93,137,138],{},"Shortest. Monitoring comes with the payment integration",[93,140,141],{},"Bundled in payment pricing, plus your own review and oversight time",[93,143,144],{},"Lower. You configure inside the provider's model and add your own rules on top",[93,146,147],{},"Yours for your program and your customers; the provider also carries its own obligations",[93,149,150],{},"Startups and fintechs that want to launch corridors without standing up a full stack",[11,152,153],{},"Look at the \"Regulatory responsibility\" column. It never says \"the vendor's.\"",[52,155,157],{"id":156},"does-buying-compliance-transfer-regulatory-responsibility","Does buying compliance transfer regulatory responsibility?",[11,159,160],{},"No. Buying a tool or a provider shifts who operates the checks, not who answers for them.",[11,162,163],{},"Three rules make that concrete:",[24,165,166,179,191],{},[27,167,168,171,172,178],{},[20,169,170],{},"FinCEN."," Under ",[46,173,177],{"href":174,"rel":175},"https:\u002F\u002Fwww.law.cornell.edu\u002Fcfr\u002Ftext\u002F31\u002F1022.210",[176],"nofollow","31 CFR 1022.210",", a money services business must have its own AML program: policies and internal controls, a designated compliance officer, training on detecting suspicious transactions, and independent review whose scope and frequency match the firm's risk. A vendor contract is an input to that program, not a substitute for it.",[27,180,181,184,185,190],{},[20,182,183],{},"OFAC."," OFAC's ",[46,186,189],{"href":187,"rel":188},"https:\u002F\u002Fofac.treasury.gov\u002Fmedia\u002F913571\u002Fdownload?inline",[176],"sanctions compliance guidance for the virtual currency industry"," states that civil penalties generally rest on a strict liability standard. A US person can be liable even without knowing or having reason to know. \"Our screening vendor missed it\" is not a defense.",[27,192,193,196,197,202],{},[20,194,195],{},"FCA."," The UK ",[46,198,201],{"href":199,"rel":200},"https:\u002F\u002Fhandbook.fca.org.uk\u002Fhandbook\u002FFCG\u002F3\u002F2.html",[176],"Financial Crime Guide"," lists, as poor practice, threshold-based monitoring that is poorly calibrated and firms that struggle to explain why particular rules exist. A black-box vendor makes that failure likely.",[11,204,205],{},"The practical test: could your compliance officer explain, in writing, every rule running on your customers and why its threshold sits where it does? If the answer depends on a vendor support ticket, the program has a gap.",[52,207,209],{"id":208},"how-do-you-decide-which-model-fits","How do you decide which model fits?",[11,211,212],{},"Answer six questions in order. The first three decide what has to be covered; the last three decide how much of it you can run yourself.",[214,215,216,222,233,239,245,256],"ol",{},[27,217,218,221],{},[20,219,220],{},"Which jurisdictions?"," Count the markets where customers sit and where money lands. Each one adds sanctions lists, Travel Rule thresholds, and registry checks. Two or more markets push hard toward buying.",[27,223,224,227,228,232],{},[20,225,226],{},"What volume, now and in 18 months?"," Low volume makes per-check pricing cheap and in-house analysts affordable. High volume makes alert noise the main cost. See ",[46,229,231],{"href":230},"\u002Fresources\u002Fmore\u002Freduce-false-positives-transaction-monitoring","how to reduce false positives"," before modeling analyst headcount.",[27,234,235,238],{},[20,236,237],{},"Which rails?"," Stablecoin transfers are final once confirmed, so checks must run before settlement. Bank rails add their own screening and data rules. Mixed rails favor a provider that monitors the whole payment, not just one leg.",[27,240,241,244],{},[20,242,243],{},"How big is the compliance team?"," One part-time officer cannot maintain list feeds, tune rules, and work cases. Two or three people can run point solutions. A full team with data engineering can consider building.",[27,246,247,250,251,255],{},[20,248,249],{},"What will auditors and partners ask for?"," Partner banks and examiners want case trails, rule rationale, and testing records. If you can't produce those from a vendor, you'll be building them anyway. ",[46,252,254],{"href":253},"\u002Fresources\u002Fmore\u002Faml-audit-readiness-risk-monitoring","Audit-ready risk monitoring"," lists the evidence.",[27,257,258,261],{},[20,259,260],{},"How fast do you need to launch?"," If a corridor launch is weeks away, only the integrated model fits. Building is a multi-quarter project, not a sprint.",[11,263,264],{},"Most teams land on a hybrid: buy the core checks, then write product-specific rules and own the oversight.",[52,266,268],{"id":267},"what-does-building-in-house-actually-involve","What does building in house actually involve?",[11,270,271],{},"Building means owning five systems, and the rules engine is the smallest one.",[24,273,274,285,297,308,319],{},[27,275,276,279,280,284],{},[20,277,278],{},"Data feeds."," OFAC, UN, EU, and UK lists, PEP data, and adverse media, refreshed every time a list changes. ",[46,281,283],{"href":282},"\u002Fresources\u002Fmore\u002Fongoing-sanctions-screening-how-often-to-rescreen","Ongoing sanctions screening"," covers why cadence matters.",[27,286,287,290,291,296],{},[20,288,289],{},"Wallet analytics."," OFAC lists some wallet addresses, but its ",[46,292,295],{"href":293,"rel":294},"https:\u002F\u002Fofac.treasury.gov\u002Ffaqs\u002F562",[176],"FAQ 562"," says those listings are not likely to be exhaustive. Address risk needs blockchain analytics.",[27,298,299,302,303,307],{},[20,300,301],{},"Rules and models."," The ",[46,304,306],{"href":305},"\u002Fresources\u002Fmore\u002Ftransaction-monitoring-red-flags-stablecoin-payments","12 red flags"," are a starting library. Each rule needs a documented rationale, test cases, and a recalibration date.",[27,309,310,313,314,318],{},[20,311,312],{},"Travel Rule handling."," Counterparty identification, data validation, and hold or return logic. The ",[46,315,317],{"href":316},"\u002Fresources\u002Fmore\u002Ftravel-rule-workflow-hold-return-reject","Travel Rule workflow"," shows the decision points.",[27,320,321,324],{},[20,322,323],{},"Case management and audit logs."," Every alert, decision, reviewer, and timestamp, retained for five years.",[11,326,327,328,332],{},"Then the program around it: independent review, training, and change control. The broader payments version of this question, wallets and rails included, sits in ",[46,329,331],{"href":330},"\u002Fresources\u002Fmore\u002Fbuild-vs-buy-stablecoin-payments","build vs buy stablecoin payments",".",[52,334,336],{"id":335},"what-are-15-questions-to-ask-a-compliance-provider","What are 15 questions to ask a compliance provider?",[11,338,339,340,344],{},"These complement the five criteria in ",[46,341,343],{"href":342},"\u002Fresources\u002Fmore\u002Fhow-to-choose-automated-risk-monitoring-vendor","how to choose a risk monitoring vendor",". That page covers coverage, integration, false positives, pricing, and audit output at a high level. These questions go into operations and exit.",[214,346,347,350,353,356,359,362,365,368,371,374,377,380,383,386,389],{},[27,348,349],{},"Which sanctions, PEP, and adverse media lists do you screen, and how soon after a list update does rescreening run?",[27,351,352],{},"Do you screen wallet addresses, on which chains, and against what beyond the SDN List?",[27,354,355],{},"How do you handle the Travel Rule: which thresholds, which data, and what happens when a counterparty sends incomplete data?",[27,357,358],{},"Can my team see and tune thresholds, or only request changes through support?",[27,360,361],{},"How is a rule change validated before it goes live, and is the before-and-after alert volume recorded?",[27,363,364],{},"Can I export the full audit log (inputs, checks, results, reviewer, timestamps) in a structured format, on demand?",[27,366,367],{},"Do you provide case management, or do alerts land in my own tooling?",[27,369,370],{},"What is the SLA for manual review, and what happens to the payment while it waits?",[27,372,373],{},"Where is customer data stored and processed, and under which privacy regimes?",[27,375,376],{},"How are failed or rejected payments handled: refunded to the source, held, or failed for support to resolve?",[27,378,379],{},"Is pricing published, and which checks cost extra?",[27,381,382],{},"Which regulators are you registered or licensed with, and where can I verify it?",[27,384,385],{},"What is your incident process when a screening feed or rule breaks, and how fast am I told?",[27,387,388],{},"Is the API documented publicly, with a sandbox that returns approve, review, and reject outcomes?",[27,390,391],{},"If we leave, how do we get customer records, case history, and audit logs out, and in what format?",[11,393,394,395,332],{},"For the payment side of the same due diligence (custody, liquidity, rails), use the ",[46,396,398],{"href":397},"\u002Fresources\u002Fmore\u002Fstablecoin-payments-provider-due-diligence","provider due diligence checklist",[52,400,402],{"id":401},"when-is-a-human-reviewer-still-required","When is a human reviewer still required?",[11,404,405],{},"A human must decide whenever the outcome carries legal weight or ends a customer relationship. Automation prepares those cases; it does not close them.",[24,407,408,414,420,431,437],{},[27,409,410,413],{},[20,411,412],{},"Possible sanctions matches"," that secondary identifiers can't clear.",[27,415,416,419],{},[20,417,418],{},"Enhanced due diligence"," for high-risk customers and jurisdictions.",[27,421,422,171,425,430],{},[20,423,424],{},"SAR decisions.",[46,426,429],{"href":427,"rel":428},"https:\u002F\u002Fwww.law.cornell.edu\u002Fcfr\u002Ftext\u002F31\u002F1022.320",[176],"31 CFR 1022.320",", an MSB files within 30 calendar days of initial detection, and a person owns that call.",[27,432,433,436],{},[20,434,435],{},"Customer exits"," and blocked payments.",[27,438,439,442],{},[20,440,441],{},"Rule changes",", which a compliance officer signs off.",[11,444,445,446,451,452,456],{},"This matches the direction in the ",[46,447,450],{"href":448,"rel":449},"https:\u002F\u002Fwolfsberg-group.org\u002Fresources\u002F202",[176],"Wolfsberg Group's 2025 statement"," on monitoring innovation: new tools are fine, but they need validation and explainable outputs. Automation can score, deduplicate, gather evidence, and draft narratives, which is what ",[46,453,455],{"href":454},"\u002Fresources\u002Fmore\u002Fwhat-are-compliance-agents-in-fintech","compliance agents"," do.",[52,458,460],{"id":459},"what-does-this-look-like-in-practice","What does this look like in practice?",[11,462,463],{},"Illustrative example (all numbers hypothetical): a fintech pays contractors in Brazil and Mexico in USDC, with 2,000 customers and two people in compliance.",[24,465,466,472,478],{},[27,467,468,471],{},[20,469,470],{},"Build:"," list feeds, wallet analytics, a rules engine, case management, and audit logging. Two compliance staff can't maintain all of that and work cases. Launch slips by quarters.",[27,473,474,477],{},[20,475,476],{},"Point solutions:"," a KYC vendor, a screening vendor, and a monitoring vendor. Each integrates in weeks. The team then writes the join between customer profiles and alerts, and every exam question becomes a lookup across three systems.",[27,479,480,483],{},[20,481,482],{},"Integrated provider:"," KYC, screening, and monitoring run inside the payout flow. The team spends its time on oversight: reviewing held payouts, writing two product-specific rules (contractor payments above a monthly baseline, new bank accounts added within 24 hours of a payout), and testing them.",[11,485,486],{},"With two people and a launch date, the third option wins. With ten people and a regulator asking for model governance, the second may.",[52,488,490],{"id":489},"what-are-the-common-mistakes-in-build-vs-buy-decisions","What are the common mistakes in build vs. buy decisions?",[24,492,493,499,505,511,517,523],{},[27,494,495,498],{},[20,496,497],{},"Buying on the demo."," A demo shows the happy path. Ask for a sample case file and an audit export instead.",[27,500,501,504],{},[20,502,503],{},"Accepting a black box."," If the provider can't explain why a rule fired, your compliance officer can't either. That fails the FCA's calibration test and most partner bank reviews.",[27,506,507,510],{},[20,508,509],{},"Ignoring audit exports."," Data you can't export is evidence you can't show. Check the format before signing.",[27,512,513,516],{},[20,514,515],{},"Underestimating in-house maintenance."," Lists change, typologies shift, and thresholds drift. Rules written at launch are wrong within a year without recalibration.",[27,518,519,522],{},[20,520,521],{},"Treating the vendor as the compliance officer."," The vendor operates tools. Someone on your team owns the program.",[27,524,525,528],{},[20,526,527],{},"Forgetting exit."," Five years of records must survive a vendor change.",[52,530,532],{"id":531},"how-does-blindpay-fit-the-integrated-model","How does BlindPay fit the integrated model?",[11,534,535,536,540],{},"BlindPay is one example of the integrated model. It is registered with FinCEN as a money services business, with registrations on the ",[46,537,539],{"href":538},"\u002Flicenses","licenses page",". KYC, KYB, sanctions screening, Travel Rule compliance, and transaction monitoring run inside the API flow, before money moves. KYC Standard is automated and takes about 60 seconds; KYC Enhanced and KYB Standard are manual reviews that take 3 hours to 1 business day.",[11,542,543,544,548,549,553,554,558],{},"A flagged payment moves to ",[545,546,547],"code",{},"on_hold"," and compliance reviews it, as described in ",[46,550,552],{"href":551},"\u002Fdocs\u002Fkb\u002Fon-hold-transactions","on-hold transactions",". A refunded payout returns stablecoins to the wallet that funded it; a failed payout doesn't refund automatically. Plans are published on the ",[46,555,557],{"href":556},"\u002Fpricing","pricing page",". Your team still owns its program, its customers, and its oversight, and the 15 questions above apply to BlindPay the same way they apply to anyone else.",[52,560,562],{"id":561},"what-to-do-next","What to do next",[11,564,565],{},"Answer the six framework questions on one page, then send the 15 provider questions to two or three candidates, including any payment provider already in your stack. Ask each for a sample audit export and case file. The provider that sends real artifacts within a day is usually the one whose product does the work.",[52,567,569],{"id":568},"sources-and-further-reading","Sources and further reading",[24,571,572,578,584,590,596,602],{},[27,573,574],{},[46,575,577],{"href":174,"rel":576},[176],"31 CFR 1022.210, AML programs for money services businesses",[27,579,580],{},[46,581,583],{"href":427,"rel":582},[176],"31 CFR 1022.320, suspicious activity reports by money services businesses",[27,585,586],{},[46,587,589],{"href":187,"rel":588},[176],"OFAC, Sanctions Compliance Guidance for the Virtual Currency Industry",[27,591,592],{},[46,593,595],{"href":293,"rel":594},[176],"OFAC FAQ 562, digital currency addresses on the SDN List",[27,597,598],{},[46,599,601],{"href":199,"rel":600},[176],"FCA Financial Crime Guide, FCG 3.2",[27,603,604],{},[46,605,607],{"href":448,"rel":606},[176],"Wolfsberg Group Statement on Effective Monitoring for Suspicious Activity, Part II",[11,609,610],{},[611,612,16],"em",{},{"title":614,"searchDepth":615,"depth":615,"links":616},"",2,[617,618,619,620,621,622,623,624,625,626,627],{"id":54,"depth":615,"text":55},{"id":156,"depth":615,"text":157},{"id":208,"depth":615,"text":209},{"id":267,"depth":615,"text":268},{"id":335,"depth":615,"text":336},{"id":401,"depth":615,"text":402},{"id":459,"depth":615,"text":460},{"id":489,"depth":615,"text":490},{"id":531,"depth":615,"text":532},{"id":561,"depth":615,"text":562},{"id":568,"depth":615,"text":569},"compliance","2026-10-05","Build, buy point solutions, or use an integrated provider? Compare three ways to run automated risk monitoring, who stays responsible, and 15 questions.","md",[633,636,639,642,645,648],{"q":634,"a":635},"Should a fintech build or buy automated risk monitoring?","Most fintechs should buy, either as point solutions or inside an integrated payments and compliance provider, and build only the product-specific rules on top. Building in house makes sense when monitoring is the product, when volume and risk are unusual enough that no provider fits, or when the team already runs a mature compliance function with data engineers and model validation.",{"q":637,"a":638},"Does outsourcing compliance transfer regulatory responsibility to the vendor?","No. A money services business must maintain its own AML program under 31 CFR 1022.210, and OFAC sanctions liability is strict for US persons. A vendor can run checks, but the firm still answers to its regulator and its partner bank. It must be able to explain which rules run, why the thresholds sit where they do, and how alerts were decided.",{"q":640,"a":641},"What is the difference between point solutions and an integrated compliance provider?","Point solutions are separate vendors for KYC, sanctions screening, and transaction monitoring that the fintech connects itself. An integrated provider runs those checks inside the payment flow, so the customer profile, the screening result, and the payment decision sit in one system. Point solutions offer more control per layer; integration removes the joins the fintech would otherwise build and maintain.",{"q":643,"a":644},"What should I ask a compliance provider before signing?","Ask which lists are screened and how often they refresh, whether wallet addresses are covered, how the Travel Rule is handled, who can tune rules and how changes are validated, what the audit log export contains, the SLA for manual review, how failed payments are handled, and how you leave with your data. Ask for sample exports, not a demo.",{"q":646,"a":647},"How long does it take to build transaction monitoring in house?","The rules engine is the short part. Sanctions list feeds, wallet address analytics, case management, audit logging, rule testing, and staff to work the alerts take far longer, and each needs documentation an examiner will read. Teams starting from zero usually spend many months before the program is examination-ready, and the maintenance never stops.",{"q":649,"a":650},"When does a human still need to review automated monitoring alerts?","Always for decisions with legal weight: clearing a possible sanctions match, approving a high-risk customer under enhanced due diligence, deciding whether to file a suspicious activity report, and exiting a customer. Automation can score, deduplicate, gather evidence, and draft a narrative. A named person signs off on the outcome and owns the reasoning.",false,{"author":653},"BlindPay Team",true,"\u002Fresources\u002Fmore\u002Fbuild-vs-buy-automated-risk-monitoring","---\ntitle: \"Build vs. buy automated risk monitoring: a decision framework and 15 provider questions\"\nseoTitle: \"Build vs buy risk monitoring: framework and 15 questions\"\ndescription: \"Build, buy point solutions, or use an integrated provider? Compare three ways to run automated risk monitoring, who stays responsible, and 15 questions.\"\ndate: \"2026-10-05\"\nupdated: \"2026-10-05\"\ncategory: \"compliance\"\nauthor: \"BlindPay Team\"\nfaq:\n  - q: \"Should a fintech build or buy automated risk monitoring?\"\n    a: \"Most fintechs should buy, either as point solutions or inside an integrated payments and compliance provider, and build only the product-specific rules on top. Building in house makes sense when monitoring is the product, when volume and risk are unusual enough that no provider fits, or when the team already runs a mature compliance function with data engineers and model validation.\"\n  - q: \"Does outsourcing compliance transfer regulatory responsibility to the vendor?\"\n    a: \"No. A money services business must maintain its own AML program under 31 CFR 1022.210, and OFAC sanctions liability is strict for US persons. A vendor can run checks, but the firm still answers to its regulator and its partner bank. It must be able to explain which rules run, why the thresholds sit where they do, and how alerts were decided.\"\n  - q: \"What is the difference between point solutions and an integrated compliance provider?\"\n    a: \"Point solutions are separate vendors for KYC, sanctions screening, and transaction monitoring that the fintech connects itself. An integrated provider runs those checks inside the payment flow, so the customer profile, the screening result, and the payment decision sit in one system. Point solutions offer more control per layer; integration removes the joins the fintech would otherwise build and maintain.\"\n  - q: \"What should I ask a compliance provider before signing?\"\n    a: \"Ask which lists are screened and how often they refresh, whether wallet addresses are covered, how the Travel Rule is handled, who can tune rules and how changes are validated, what the audit log export contains, the SLA for manual review, how failed payments are handled, and how you leave with your data. Ask for sample exports, not a demo.\"\n  - q: \"How long does it take to build transaction monitoring in house?\"\n    a: \"The rules engine is the short part. Sanctions list feeds, wallet address analytics, case management, audit logging, rule testing, and staff to work the alerts take far longer, and each needs documentation an examiner will read. Teams starting from zero usually spend many months before the program is examination-ready, and the maintenance never stops.\"\n  - q: \"When does a human still need to review automated monitoring alerts?\"\n    a: \"Always for decisions with legal weight: clearing a possible sanctions match, approving a high-risk customer under enhanced due diligence, deciding whether to file a suspicious activity report, and exiting a customer. Automation can score, deduplicate, gather evidence, and draft a narrative. A named person signs off on the outcome and owns the reasoning.\"\n---\n\nMost fintechs should buy automated risk monitoring and build only the rules specific to their product. The real choice is between point solutions (separate KYC, screening, and monitoring vendors) and an integrated payments and compliance provider. Either way, regulatory responsibility stays with the fintech, so pick the option whose logic you can explain to an examiner.\n\nThis article is general information, not legal advice.\n\n**Key takeaways**\n\n- There are three operating models, not two: build in house, buy point solutions, or use a provider that runs compliance inside the payment flow.\n- Responsibility never transfers. Under 31 CFR 1022.210, the AML program belongs to the money services business, whoever runs the software.\n- The rules engine is the cheap part of building. List feeds, wallet analytics, case management, and audit evidence are the expensive parts.\n- Pick on six inputs: jurisdictions, volume, rails, team size, audit needs, and speed to market.\n- Evaluate providers on what they can export and explain, not on the demo.\n\nAutomated risk monitoring covers four jobs: verifying customers, monitoring transactions, screening against sanctions lists, and working the resulting alerts. The [automated risk monitoring explainer](\u002Fresources\u002Fmore\u002Fwhat-is-automated-risk-monitoring-fintech) takes each one apart. This guide answers a different question: who should run them.\n\n## What are the three ways to run automated risk monitoring?\n\nA fintech can build monitoring in house, buy point solutions and connect them, or use an integrated provider that runs the checks inside the payment flow. Each model trades control for time and maintenance.\n\n| Option | Time to launch | Ongoing cost drivers | Control and customization | Regulatory responsibility | Best for |\n| --- | --- | --- | --- | --- | --- |\n| Build in house | Longest. Many months before an examination-ready program | Engineers, data feeds, analytics licenses, analysts, model validation, independent review | Full. Every rule, threshold, and model is yours | Fully yours, including every design choice | Firms where monitoring is the product, or with unusual risk no vendor covers |\n| Buy point solutions | Medium. Each vendor integrates fast; the joins between them take longer | Per-check or platform fees per vendor, integration upkeep, analysts | High per layer, limited across layers | Yours. Vendors supply tools, you own the program and the joins | Teams with a compliance function that want best-of-breed per layer |\n| Integrated payments and compliance provider | Shortest. Monitoring comes with the payment integration | Bundled in payment pricing, plus your own review and oversight time | Lower. You configure inside the provider's model and add your own rules on top | Yours for your program and your customers; the provider also carries its own obligations | Startups and fintechs that want to launch corridors without standing up a full stack |\n\nLook at the \"Regulatory responsibility\" column. It never says \"the vendor's.\"\n\n## Does buying compliance transfer regulatory responsibility?\n\nNo. Buying a tool or a provider shifts who operates the checks, not who answers for them.\n\nThree rules make that concrete:\n\n- **FinCEN.** Under [31 CFR 1022.210](https:\u002F\u002Fwww.law.cornell.edu\u002Fcfr\u002Ftext\u002F31\u002F1022.210), a money services business must have its own AML program: policies and internal controls, a designated compliance officer, training on detecting suspicious transactions, and independent review whose scope and frequency match the firm's risk. A vendor contract is an input to that program, not a substitute for it.\n- **OFAC.** OFAC's [sanctions compliance guidance for the virtual currency industry](https:\u002F\u002Fofac.treasury.gov\u002Fmedia\u002F913571\u002Fdownload?inline) states that civil penalties generally rest on a strict liability standard. A US person can be liable even without knowing or having reason to know. \"Our screening vendor missed it\" is not a defense.\n- **FCA.** The UK [Financial Crime Guide](https:\u002F\u002Fhandbook.fca.org.uk\u002Fhandbook\u002FFCG\u002F3\u002F2.html) lists, as poor practice, threshold-based monitoring that is poorly calibrated and firms that struggle to explain why particular rules exist. A black-box vendor makes that failure likely.\n\nThe practical test: could your compliance officer explain, in writing, every rule running on your customers and why its threshold sits where it does? If the answer depends on a vendor support ticket, the program has a gap.\n\n## How do you decide which model fits?\n\nAnswer six questions in order. The first three decide what has to be covered; the last three decide how much of it you can run yourself.\n\n1. **Which jurisdictions?** Count the markets where customers sit and where money lands. Each one adds sanctions lists, Travel Rule thresholds, and registry checks. Two or more markets push hard toward buying.\n2. **What volume, now and in 18 months?** Low volume makes per-check pricing cheap and in-house analysts affordable. High volume makes alert noise the main cost. See [how to reduce false positives](\u002Fresources\u002Fmore\u002Freduce-false-positives-transaction-monitoring) before modeling analyst headcount.\n3. **Which rails?** Stablecoin transfers are final once confirmed, so checks must run before settlement. Bank rails add their own screening and data rules. Mixed rails favor a provider that monitors the whole payment, not just one leg.\n4. **How big is the compliance team?** One part-time officer cannot maintain list feeds, tune rules, and work cases. Two or three people can run point solutions. A full team with data engineering can consider building.\n5. **What will auditors and partners ask for?** Partner banks and examiners want case trails, rule rationale, and testing records. If you can't produce those from a vendor, you'll be building them anyway. [Audit-ready risk monitoring](\u002Fresources\u002Fmore\u002Faml-audit-readiness-risk-monitoring) lists the evidence.\n6. **How fast do you need to launch?** If a corridor launch is weeks away, only the integrated model fits. Building is a multi-quarter project, not a sprint.\n\nMost teams land on a hybrid: buy the core checks, then write product-specific rules and own the oversight.\n\n## What does building in house actually involve?\n\nBuilding means owning five systems, and the rules engine is the smallest one.\n\n- **Data feeds.** OFAC, UN, EU, and UK lists, PEP data, and adverse media, refreshed every time a list changes. [Ongoing sanctions screening](\u002Fresources\u002Fmore\u002Fongoing-sanctions-screening-how-often-to-rescreen) covers why cadence matters.\n- **Wallet analytics.** OFAC lists some wallet addresses, but its [FAQ 562](https:\u002F\u002Fofac.treasury.gov\u002Ffaqs\u002F562) says those listings are not likely to be exhaustive. Address risk needs blockchain analytics.\n- **Rules and models.** The [12 red flags](\u002Fresources\u002Fmore\u002Ftransaction-monitoring-red-flags-stablecoin-payments) are a starting library. Each rule needs a documented rationale, test cases, and a recalibration date.\n- **Travel Rule handling.** Counterparty identification, data validation, and hold or return logic. The [Travel Rule workflow](\u002Fresources\u002Fmore\u002Ftravel-rule-workflow-hold-return-reject) shows the decision points.\n- **Case management and audit logs.** Every alert, decision, reviewer, and timestamp, retained for five years.\n\nThen the program around it: independent review, training, and change control. The broader payments version of this question, wallets and rails included, sits in [build vs buy stablecoin payments](\u002Fresources\u002Fmore\u002Fbuild-vs-buy-stablecoin-payments).\n\n## What are 15 questions to ask a compliance provider?\n\nThese complement the five criteria in [how to choose a risk monitoring vendor](\u002Fresources\u002Fmore\u002Fhow-to-choose-automated-risk-monitoring-vendor). That page covers coverage, integration, false positives, pricing, and audit output at a high level. These questions go into operations and exit.\n\n1. Which sanctions, PEP, and adverse media lists do you screen, and how soon after a list update does rescreening run?\n2. Do you screen wallet addresses, on which chains, and against what beyond the SDN List?\n3. How do you handle the Travel Rule: which thresholds, which data, and what happens when a counterparty sends incomplete data?\n4. Can my team see and tune thresholds, or only request changes through support?\n5. How is a rule change validated before it goes live, and is the before-and-after alert volume recorded?\n6. Can I export the full audit log (inputs, checks, results, reviewer, timestamps) in a structured format, on demand?\n7. Do you provide case management, or do alerts land in my own tooling?\n8. What is the SLA for manual review, and what happens to the payment while it waits?\n9. Where is customer data stored and processed, and under which privacy regimes?\n10. How are failed or rejected payments handled: refunded to the source, held, or failed for support to resolve?\n11. Is pricing published, and which checks cost extra?\n12. Which regulators are you registered or licensed with, and where can I verify it?\n13. What is your incident process when a screening feed or rule breaks, and how fast am I told?\n14. Is the API documented publicly, with a sandbox that returns approve, review, and reject outcomes?\n15. If we leave, how do we get customer records, case history, and audit logs out, and in what format?\n\nFor the payment side of the same due diligence (custody, liquidity, rails), use the [provider due diligence checklist](\u002Fresources\u002Fmore\u002Fstablecoin-payments-provider-due-diligence).\n\n## When is a human reviewer still required?\n\nA human must decide whenever the outcome carries legal weight or ends a customer relationship. Automation prepares those cases; it does not close them.\n\n- **Possible sanctions matches** that secondary identifiers can't clear.\n- **Enhanced due diligence** for high-risk customers and jurisdictions.\n- **SAR decisions.** Under [31 CFR 1022.320](https:\u002F\u002Fwww.law.cornell.edu\u002Fcfr\u002Ftext\u002F31\u002F1022.320), an MSB files within 30 calendar days of initial detection, and a person owns that call.\n- **Customer exits** and blocked payments.\n- **Rule changes**, which a compliance officer signs off.\n\nThis matches the direction in the [Wolfsberg Group's 2025 statement](https:\u002F\u002Fwolfsberg-group.org\u002Fresources\u002F202) on monitoring innovation: new tools are fine, but they need validation and explainable outputs. Automation can score, deduplicate, gather evidence, and draft narratives, which is what [compliance agents](\u002Fresources\u002Fmore\u002Fwhat-are-compliance-agents-in-fintech) do.\n\n## What does this look like in practice?\n\nIllustrative example (all numbers hypothetical): a fintech pays contractors in Brazil and Mexico in USDC, with 2,000 customers and two people in compliance.\n\n- **Build:** list feeds, wallet analytics, a rules engine, case management, and audit logging. Two compliance staff can't maintain all of that and work cases. Launch slips by quarters.\n- **Point solutions:** a KYC vendor, a screening vendor, and a monitoring vendor. Each integrates in weeks. The team then writes the join between customer profiles and alerts, and every exam question becomes a lookup across three systems.\n- **Integrated provider:** KYC, screening, and monitoring run inside the payout flow. The team spends its time on oversight: reviewing held payouts, writing two product-specific rules (contractor payments above a monthly baseline, new bank accounts added within 24 hours of a payout), and testing them.\n\nWith two people and a launch date, the third option wins. With ten people and a regulator asking for model governance, the second may.\n\n## What are the common mistakes in build vs. buy decisions?\n\n- **Buying on the demo.** A demo shows the happy path. Ask for a sample case file and an audit export instead.\n- **Accepting a black box.** If the provider can't explain why a rule fired, your compliance officer can't either. That fails the FCA's calibration test and most partner bank reviews.\n- **Ignoring audit exports.** Data you can't export is evidence you can't show. Check the format before signing.\n- **Underestimating in-house maintenance.** Lists change, typologies shift, and thresholds drift. Rules written at launch are wrong within a year without recalibration.\n- **Treating the vendor as the compliance officer.** The vendor operates tools. Someone on your team owns the program.\n- **Forgetting exit.** Five years of records must survive a vendor change.\n\n## How does BlindPay fit the integrated model?\n\nBlindPay is one example of the integrated model. It is registered with FinCEN as a money services business, with registrations on the [licenses page](\u002Flicenses). KYC, KYB, sanctions screening, Travel Rule compliance, and transaction monitoring run inside the API flow, before money moves. KYC Standard is automated and takes about 60 seconds; KYC Enhanced and KYB Standard are manual reviews that take 3 hours to 1 business day.\n\nA flagged payment moves to `on_hold` and compliance reviews it, as described in [on-hold transactions](\u002Fdocs\u002Fkb\u002Fon-hold-transactions). A refunded payout returns stablecoins to the wallet that funded it; a failed payout doesn't refund automatically. Plans are published on the [pricing page](\u002Fpricing). Your team still owns its program, its customers, and its oversight, and the 15 questions above apply to BlindPay the same way they apply to anyone else.\n\n## What to do next\n\nAnswer the six framework questions on one page, then send the 15 provider questions to two or three candidates, including any payment provider already in your stack. Ask each for a sample audit export and case file. The provider that sends real artifacts within a day is usually the one whose product does the work.\n\n## Sources and further reading\n\n- [31 CFR 1022.210, AML programs for money services businesses](https:\u002F\u002Fwww.law.cornell.edu\u002Fcfr\u002Ftext\u002F31\u002F1022.210)\n- [31 CFR 1022.320, suspicious activity reports by money services businesses](https:\u002F\u002Fwww.law.cornell.edu\u002Fcfr\u002Ftext\u002F31\u002F1022.320)\n- [OFAC, Sanctions Compliance Guidance for the Virtual Currency Industry](https:\u002F\u002Fofac.treasury.gov\u002Fmedia\u002F913571\u002Fdownload?inline)\n- [OFAC FAQ 562, digital currency addresses on the SDN List](https:\u002F\u002Fofac.treasury.gov\u002Ffaqs\u002F562)\n- [FCA Financial Crime Guide, FCG 3.2](https:\u002F\u002Fhandbook.fca.org.uk\u002Fhandbook\u002FFCG\u002F3\u002F2.html)\n- [Wolfsberg Group Statement on Effective Monitoring for Suspicious Activity, Part II](https:\u002F\u002Fwolfsberg-group.org\u002Fresources\u002F202)\n\n*This article is general information, not legal advice.*\n",{"title":5,"description":630},"Build vs buy risk monitoring: framework and 15 questions","resources\u002Fmore\u002Fbuild-vs-buy-automated-risk-monitoring","UzJp18o4KN_3ieFTk1xlY_Jim4UAXwzdJQKiVcQg7GY",[662,665,669,673,677,678,682,686,690,694,698,701,704,708,711,715,719,723,727,731,735,738,741,745,748,752,756,759,763,767],{"path":253,"title":663,"description":664},"AML audit readiness: what regulators ask for and how to prove your risk monitoring works","The evidence examiners expect from automated risk monitoring: a 10-item evidence table, good vs poor practice, SAR timelines, RFIs, and a 30-day plan.",{"path":666,"title":667,"description":668},"\u002Fresources\u002Fmore\u002Fare-blockchain-payments-legal","Are blockchain payments legal? Rules in the US, EU, UK, Brazil, and Mexico","Blockchain payments are legal for businesses in the US, EU, UK, Brazil, and Mexico, under different rules. What each country regulates, as of October 2026.",{"path":670,"title":671,"description":672},"\u002Fresources\u002Fmore\u002Fare-stablecoin-payments-reversible","Are stablecoin payments reversible? Finality, custody, and fraud explained","Stablecoin transfers settle final in minutes and cannot be reversed. That finality proves custody at every step, but it also opens a fraud gap on the fiat side of the payment.",{"path":674,"title":675,"description":676},"\u002Fresources\u002Fmore\u002Fautomated-kyc-kyb-vs-manual-onboarding","Automated KYC\u002FKYB vs. manual onboarding: what actually changes","A side-by-side comparison of automated and manual KYC\u002FKYB for fintechs: onboarding time, false-positive rates, cost per verification, scaling across jurisdictions, and audit-trail quality, plus the cases where a human reviewer is still required.",{"path":655,"title":5,"description":630},{"path":679,"title":680,"description":681},"\u002Fresources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments","Compliance agents for cross-border stablecoin payments: a global regulatory guide","How compliance agents apply FinCEN, MiCA, FCA, MAS, and Banco Central do Brasil rules to cross-border stablecoin payments: jurisdiction table, the FATF Travel Rule, multi-list sanctions screening, the four components of a compliant program, and questions to ask a compliance provider.",{"path":683,"title":684,"description":685},"\u002Fresources\u002Fmore\u002Fcrypto-wallet-compliance-checklist","Crypto wallet compliance checklist: KYC, KYT, and Travel Rule","The compliance that comes with crypto wallets and stablecoin payments: KYC and KYB, KYT, the Travel Rule, address screening, MSB rules, and 15 checks.",{"path":687,"title":688,"description":689},"\u002Fresources\u002Fmore\u002Fdirect-vs-indirect-stablecoin-exchange","Direct vs indirect stablecoin exchange: who holds the stablecoin, and who carries compliance","In direct exchange, both parties hold stablecoins and own compliance. In indirect exchange, a provider settles in stablecoins behind a normal bank payment.",{"path":691,"title":692,"description":693},"\u002Fresources\u002Fmore\u002Fdo-merchants-need-a-license-to-accept-stablecoins","Do merchants need a license to accept stablecoin payments? KYC, KYB, and compliance explained","Usually no: the license sits with the provider that moves the funds. What merchants still owe on KYB, sanctions, tax, and records in the US, EU, Brazil.",{"path":695,"title":696,"description":697},"\u002Fresources\u002Fmore\u002Fhow-to-automate-kyc-kyb-stablecoin-payments","How to automate KYC and KYB for stablecoin payments","A developer guide to automated KYC and KYB for stablecoin payment flows: how verification runs inside a payment API, step-by-step workflows for individuals and businesses, jurisdiction requirements for the US, EU, UK, Singapore, and Brazil, and what to check before settlement.",{"path":342,"title":699,"description":700},"How to choose an automated risk monitoring vendor for a fintech startup","A buyer's guide to automated risk monitoring vendors for early-stage fintechs: the five criteria that matter (regulatory coverage, integration effort, false-positive rate, pricing model, audit output), the question to ask a vendor on each, a checklist table, and what it costs.",{"path":230,"title":702,"description":703},"How to reduce false positives in transaction monitoring without missing real risk","Cut AML alert noise without losing real cases: a 7-step tuning process, the levers that work, the metrics to watch, and what automation should never close.",{"path":705,"title":706,"description":707},"\u002Fresources\u002Fmore\u002Fmica-stablecoin-rules-explained","MiCA stablecoin rules explained for payment companies","What MiCA means if your business uses stablecoins in the EU: EMTs vs ARTs, issuer requirements, why USDC is compliant and USDT was delisted, and a practical checklist.",{"path":282,"title":709,"description":710},"Ongoing sanctions screening: how often to rescreen and what to screen","How often to rescreen customers against sanctions lists, what to screen beyond names, and a cadence that holds up under OFAC strict liability.",{"path":712,"title":713,"description":714},"\u002Fresources\u002Fmore\u002Fpsav-brazil-explained","PSAV in Brazil: the Central Bank's virtual asset license explained","PSAV is Brazil's authorization for virtual asset service providers, created by BCB Resolutions 519, 520, and 521 under Law 14.478\u002F2022. What it requires and who needs it.",{"path":716,"title":717,"description":718},"\u002Fresources\u002Fmore\u002Freal-time-transaction-monitoring-stablecoin-payments","Real-time transaction monitoring for cross-border stablecoin payments","Why stablecoin cross-border flows need different monitoring than wires: the signals that get scored (wallet address risk, velocity, corridor risk, on\u002Foff-ramp counterparties), real-time vs. batch monitoring, and a worked example of a flagged pattern from alert to decision.",{"path":720,"title":721,"description":722},"\u002Fresources\u002Fmore\u002Fstablecoin-card-issuing-compliance","Stablecoin card issuing compliance: KYC, KYB, and regulatory coverage explained","What compliance stablecoin card issuing requires: KYC vs. KYB, who is responsible for what, how rules differ in the US, EU, UK, and Latin America, and ongoing monitoring.",{"path":724,"title":725,"description":726},"\u002Fresources\u002Fmore\u002Fstablecoin-off-ramp-limits","Stablecoin off-ramp limits: per-transaction, daily, and monthly caps explained","Why off-ramps cap how much you can convert per transaction, day, and month, how the caps map to KYC and KYB tiers, and the documents that raise them.",{"path":728,"title":729,"description":730},"\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026","Stablecoin regulation in 2026: MiCA, the GENIUS Act, Brazil, and Japan","Where stablecoin regulation stands in 2026: MiCA in the EU, the GENIUS Act in the US, Brazil's VASP regime, and Japan's issuer rules, compared for payment businesses.",{"path":732,"title":733,"description":734},"\u002Fresources\u002Fmore\u002Fgenius-act-for-businesses","The GENIUS Act explained for businesses that use stablecoins","What the GENIUS Act means if your business sends, receives, or holds stablecoins: who it regulates, the dates that matter, and what to do before 2027.",{"path":316,"title":736,"description":737},"The Travel Rule in an automated workflow: what to collect, when to hold, when to return","How to automate Travel Rule compliance for stablecoin transfers: what data to collect, the checks before release, and when to hold, reject, or return.",{"path":305,"title":739,"description":740},"Transaction monitoring red flags for stablecoin payments: 12 rules to automate","The 12 red flags automated transaction monitoring should catch in stablecoin and cross-border payments, with rule logic, actions, and the data each needs.",{"path":742,"title":743,"description":744},"\u002Fresources\u002Fmore\u002Fvirtual-account-requirements-kyc-kyb","Virtual account requirements: KYC, KYB, and what the bank reviews before it says yes","What you need to open a virtual account: KYC or KYB, the extra fields and source of funds documents the bank reviews, who owns each step, and timelines.",{"path":454,"title":746,"description":747},"What are compliance agents in fintech? How they work and what they do for payments","Compliance agents are autonomous software components that run KYC, KYB, sanctions screening, and transaction monitoring inside a payment flow, then document every decision. How they work, what they do for payments, how they differ from traditional compliance software, and how BlindPay embeds them in its API.",{"path":749,"title":750,"description":751},"\u002Fresources\u002Fmore\u002Fwhat-is-kyb","What is KYB? Know Your Business verification explained","KYB verifies a company's legal existence, ownership, and control before it can transact. What it checks, who counts as a beneficial owner, and how it differs from KYC.",{"path":753,"title":754,"description":755},"\u002Fresources\u002Fmore\u002Fwhat-is-a-vasp","What is a VASP? Virtual asset service provider explained","A VASP is any business that exchanges, transfers, or custodies virtual assets like stablecoins for customers. FATF's definition and what it requires in practice.",{"path":48,"title":757,"description":758},"What is automated risk monitoring in fintech?","A reference explainer on automated risk monitoring for fintechs: the four components (KYC\u002FKYB, transaction monitoring, sanctions and watchlist screening, compliance automation), what each one flags, a manual vs. automated comparison, and what FinCEN, FATF, and OFAC actually require.",{"path":760,"title":761,"description":762},"\u002Fresources\u002Fmore\u002Ftravel-rule-stablecoin-off-ramps","What is the travel rule for stablecoin off-ramps? Thresholds, data, and failed checks","The travel rule makes off-ramps pass sender and receiver data with transfers. Thresholds by country, required data, and what happens when checks fail.",{"path":764,"title":765,"description":766},"\u002Fresources\u002Fmore\u002Fcrypto-on-ramp-compliance-who-owns-what","Who owns compliance when you integrate a crypto on-ramp API? KYC, KYB, KYT, and holds","An on-ramp API splits compliance between the provider and you. Who runs KYC, KYB, KYT, sanctions, and the travel rule, and what stays on your side.",{"path":768,"title":769,"description":770},"\u002Fresources\u002Fmore\u002Fsource-of-funds-crypto-off-ramps","Why do crypto off-ramps ask for source of funds? Documents, triggers, and on-chain proof","Why off-ramps ask where your stablecoins came from, how source of funds differs from source of wealth, what triggers a request, and which documents pass.",1791301931318]