[{"data":1,"prerenderedAt":4023},["ShallowReactive",2],{"content-\u002Fresources\u002Fmore\u002Freal-time-transaction-monitoring-stablecoin-payments":3,"resources-category-real-time-transaction-monitoring-stablecoin-payments":349},{"id":4,"title":5,"authors":6,"body":7,"categories":6,"category":323,"categoryType":6,"compare":6,"contributors":6,"date":324,"description":325,"extension":326,"faq":327,"howto":6,"isBlog":340,"isChangelog":340,"meta":341,"navigation":343,"path":344,"pillar":340,"products":6,"rawbody":345,"role":6,"seo":346,"stem":347,"thumbnail":6,"updated":324,"__hash__":348},"content\u002Fresources\u002Fmore\u002Freal-time-transaction-monitoring-stablecoin-payments.md","Real-time transaction monitoring for cross-border stablecoin payments",null,{"type":8,"value":9,"toc":306},"minimark",[10,17,24,27,32,35,41,53,59,62,66,74,79,82,86,89,93,96,100,103,107,110,113,117,120,209,212,216,219,222,225,271,274,278,281,294,298,301],[11,12,13],"p",{},[14,15,16],"em",{},"Reading time: about 7 minutes.",[11,18,19,23],{},[20,21,22],"strong",{},"Summary:"," Cross-border stablecoin payments need real-time transaction monitoring because they settle in minutes at any hour, are final once confirmed, and touch counterparties in at least two jurisdictions on every transfer. A wire can be reviewed overnight and recalled; a stablecoin transfer has to be scored before it moves, using signals that include the wallet address itself.",[11,25,26],{},"This post covers what those signals are, how pre-settlement monitoring differs from the end-of-day batch model banks grew up with, and what happens to a transaction that gets flagged.",[28,29,31],"h2",{"id":30},"why-stablecoin-flows-need-different-monitoring-than-wires","Why stablecoin flows need different monitoring than wires",[11,33,34],{},"Three properties of a stablecoin transfer change the monitoring problem.",[11,36,37,40],{},[20,38,39],{},"Settlement is continuous."," A SWIFT wire moves during banking hours and takes one to five days, which leaves room for a compliance team to review the day's batch before value is final. A USDC transfer confirms in seconds to minutes, on a Sunday, at 3 a.m. There is no overnight window.",[11,42,43,46,47,52],{},[20,44,45],{},"Settlement is final."," Wires can be recalled, and card payments can be charged back. A confirmed blockchain transaction ",[48,49,51],"a",{"href":50},"\u002Fresources\u002Fmore\u002Fare-stablecoin-payments-reversible","cannot be reversed",". A monitoring decision that arrives after confirmation is a report, not a control.",[11,54,55,58],{},[20,56,57],{},"The counterparty is a wallet."," A wire carries a beneficiary bank, and that bank carries its own KYC obligations. A wallet address carries nothing. The monitoring system has to establish who is behind it, or at least what it has been exposed to, and it has to do that for a sender in one jurisdiction and a receiver in another.",[11,60,61],{},"The upside is visibility. Every on-chain transfer is public, which means the history of an address can be traced in a way a bank account's cannot. Monitoring for stablecoins is harder on timing and easier on data.",[28,63,65],{"id":64},"what-signals-get-monitored-in-a-stablecoin-transaction","What signals get monitored in a stablecoin transaction?",[11,67,68,69,73],{},"A pre-settlement risk score for a cross-border stablecoin payment typically combines five signal groups. The ",[48,70,72],{"href":71},"\u002Fresources\u002Fmore\u002Fwhat-is-automated-risk-monitoring-fintech","automated risk monitoring explainer"," covers the broader program these sit inside.",[75,76,78],"h3",{"id":77},"_1-wallet-address-risk","1. Wallet address risk",[11,80,81],{},"The source and destination addresses are checked against OFAC-listed addresses and against blockchain analytics that score an address by its exposure: direct or indirect flows from mixers, darknet markets, sanctioned exchanges, ransomware wallets, or known hacks. Exposure is measured in hops and in share of funds, so an address one hop from a sanctioned service scores very differently from one with a trace of indirect exposure.",[75,83,85],{"id":84},"_2-sanctions-and-pep-rescreening-on-the-parties","2. Sanctions and PEP rescreening on the parties",[11,87,88],{},"The named sender, receiver, and beneficial owners are screened again at transaction time, not only at onboarding, because lists change. OFAC updates the SDN list several times a month, and EU, UN, and UK OFSI lists move on their own schedules.",[75,90,92],{"id":91},"_3-velocity-and-pattern-rules","3. Velocity and pattern rules",[11,94,95],{},"The transaction is compared with the customer's own baseline and with pattern rules drawn from FinCEN and FATF typologies: total volume over 24 hours and 30 days, number of transfers per hour, amounts clustered just under a reporting threshold (structuring), funds received and forwarded within minutes (pass-through), and repeated round-number transfers to a new counterparty.",[75,97,99],{"id":98},"_4-corridor-risk","4. Corridor risk",[11,101,102],{},"Cross-border adds the pair of jurisdictions as a signal. A USD-to-BRL payout to a verified Brazilian company is routine. The same amount to a receiver whose bank is in a FATF grey-list country, or whose declared country differs from the IP geolocation and the bank country, is not. Corridor rules also carry the Travel Rule thresholds, which differ by market: USD 3,000 in the US, no minimum in the EU, SGD 1,500 in Singapore.",[75,104,106],{"id":105},"_5-on-ramp-and-off-ramp-counterparty-checks","5. On-ramp and off-ramp counterparty checks",[11,108,109],{},"Where the stablecoin came from and where the fiat is going. An on-ramp from a licensed exchange with its own KYC scores differently from a self-custodied wallet with no history. An off-ramp to a bank account in the receiver's verified name scores differently from one in a third party's name, which is a classic mule pattern.",[11,111,112],{},"Each group produces a score, and the combined score lands in one of three bands: settle, hold for review, or block.",[28,114,116],{"id":115},"real-time-vs-batch-monitoring","Real-time vs. batch monitoring",[11,118,119],{},"Banks built transaction monitoring as a batch process because their rails gave them the time: the end-of-day file runs through the rules engine, analysts work the alert queue over the following days, and a wire that looks wrong is recalled or reported.",[121,122,123,139],"table",{},[124,125,126],"thead",{},[127,128,129,133,136],"tr",{},[130,131,132],"th",{},"Dimension",[130,134,135],{},"Batch (end-of-day) monitoring",[130,137,138],{},"Real-time (pre-settlement) monitoring",[140,141,142,154,165,176,187,198],"tbody",{},[127,143,144,148,151],{},[145,146,147],"td",{},"When rules run",[145,149,150],{},"After settlement, on the day's file",[145,152,153],{},"Before settlement, on each transaction",[127,155,156,159,162],{},[145,157,158],{},"Can it stop a payment",[145,160,161],{},"Only if the rail supports recall",[145,163,164],{},"Yes, by holding or blocking before funds move",[127,166,167,170,173],{},[145,168,169],{},"Latency added to a clean payment",[145,171,172],{},"None",[145,174,175],{},"Sub-second scoring in most implementations",[127,177,178,181,184],{},[145,179,180],{},"Analyst workload",[145,182,183],{},"Alerts reviewed over days",[145,185,186],{},"Held transactions reviewed within hours, since a customer is waiting",[127,188,189,192,195],{},[145,190,191],{},"Fit for stablecoins",[145,193,194],{},"Poor: the transfer is final before the batch runs",[145,196,197],{},"Required",[127,199,200,203,206],{},[145,201,202],{},"Fit for wires and ACH",[145,204,205],{},"Standard practice",[145,207,208],{},"Increasingly used, especially for faster-payment rails",[11,210,211],{},"The row that matters is the second one. For a payment that is final within minutes, batch monitoring is detection with no enforcement. Real-time does not mean instant approval for everything; it means the score is computed before settlement, and the small share of transactions in the review band waits for a person while the rest go through.",[28,213,215],{"id":214},"a-worked-example-a-flagged-pattern-and-what-happens-next","A worked example: a flagged pattern and what happens next",[11,217,218],{},"A hypothetical, with the mechanics kept realistic.",[11,220,221],{},"A marketplace in the US pays sellers in Colombia through a stablecoin payout API. One seller, verified six months ago, has a baseline of two payouts a month, each around USD 1,800, to a bank account in their own name. Over one Saturday, the marketplace submits eleven payouts to that seller, each between USD 2,700 and USD 2,950, and the destination bank account has changed to one in a different person's name.",[11,223,224],{},"Here is what the monitoring layer does before any of them settles.",[226,227,228,235,241,247,253,259,265],"ol",{},[229,230,231,234],"li",{},[20,232,233],{},"Velocity rule fires."," Eleven transfers in a day against a baseline of two a month is a spike of over a hundred times the expected rate.",[229,236,237,240],{},[20,238,239],{},"Structuring rule fires."," Every amount sits just below USD 3,000, the US Travel Rule threshold. On its own that is weak evidence; combined with the velocity spike it is strong.",[229,242,243,246],{},[20,244,245],{},"Off-ramp counterparty check fires."," The bank account name does not match the verified receiver. That is the mule pattern, and it is the signal that pushes the combined score from hold into block.",[229,248,249,252],{},[20,250,251],{},"Sanctions rescreen and wallet risk return clean."," Both are noted in the case file, because a clean screen is evidence too.",[229,254,255,258],{},[20,256,257],{},"The first payout is held before settlement and the remaining ten are queued behind it."," The marketplace receives a webhook with a status change and a reason category, and the seller sees a pending state instead of a failure.",[229,260,261,264],{},[20,262,263],{},"A compliance analyst opens the case."," The file already contains the baseline, the eleven transactions, the rules that fired, the screening results, and a draft narrative. The analyst requests proof of ownership of the new bank account and an explanation of the volume.",[229,266,267,270],{},[20,268,269],{},"Two outcomes."," If the seller shows a legitimate reason (a business account opened under a partner's name, with documents), the analyst releases the payouts and notes the new baseline. If not, the payouts are rejected, the receiver is moved to a restricted state, and the case is evaluated against the Suspicious Activity Report standard, which gives 30 days from detection to file with FinCEN, or 60 if no suspect has been identified.",[11,272,273],{},"The machine part took under a minute. The eleven payouts never left.",[28,275,277],{"id":276},"how-blindpay-applies-this","How BlindPay applies this",[11,279,280],{},"BlindPay runs transaction monitoring inside the payout flow rather than as a separate vendor step. KYC or KYB runs once per receiver, and on every payout the receiver and destination are rescreened against OFAC, EU, UN, and UK lists, the wallet address is risk-scored, and velocity, corridor, and counterparty rules produce the settle, hold, or block decision before funds move. Because BlindPay settles without pre-funding and in real time, that pre-settlement step is the only place a control can sit; there is no float period to review a batch in.",[11,282,283,284,288,289,293],{},"Held payouts surface as a status change over webhook with a reason category, so the customer's product can show a pending state rather than an error. The program is described on the ",[48,285,287],{"href":286},"\u002Fcompliance","compliance page",", and the jurisdiction rules it applies are covered in the ",[48,290,292],{"href":291},"\u002Fresources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments","cross-border compliance guide",".",[28,295,297],{"id":296},"what-to-do-with-this","What to do with this",[11,299,300],{},"If monitoring runs on an end-of-day file, move the scoring step before settlement first, even with the same rules. Then add wallet address risk as a signal, since it is the one check a bank-style program does not have. Tune velocity and structuring thresholds after the first month of alerts shows where the noise is.",[11,302,303],{},[14,304,305],{},"This article is for general information only and is not legal, tax, or financial advice.",{"title":307,"searchDepth":308,"depth":308,"links":309},"",2,[310,311,319,320,321,322],{"id":30,"depth":308,"text":31},{"id":64,"depth":308,"text":65,"children":312},[313,315,316,317,318],{"id":77,"depth":314,"text":78},3,{"id":84,"depth":314,"text":85},{"id":91,"depth":314,"text":92},{"id":98,"depth":314,"text":99},{"id":105,"depth":314,"text":106},{"id":115,"depth":308,"text":116},{"id":214,"depth":308,"text":215},{"id":276,"depth":308,"text":277},{"id":296,"depth":308,"text":297},"compliance","2026-09-15","Why stablecoin cross-border flows need different monitoring than wires: the signals that get scored (wallet address risk, velocity, corridor risk, on\u002Foff-ramp counterparties), real-time vs. batch monitoring, and a worked example of a flagged pattern from alert to decision.","md",[328,331,334,337],{"q":329,"a":330},"Does transaction monitoring slow down stablecoin settlement speed?","Not meaningfully when it runs pre-settlement as a scoring step. Sanctions rescreening, wallet address risk, and velocity rules evaluate in well under a second for most transactions, so a clean payment still settles in minutes. Only the small share that scores into the review band waits on a person, and that wait is the point.",{"q":332,"a":333},"Can transaction monitoring be automated for multiple blockchains at once?","Yes. Address risk scoring, sanctions list matching, and velocity rules operate on normalized transaction data, so the same rule set covers USDC on Ethereum, Base, Polygon, Solana, Stellar, or Tron. The chain-specific work is the indexer and the address format; the risk logic is shared.",{"q":335,"a":336},"What is the difference between real-time and batch transaction monitoring?","Batch monitoring reviews the day's transactions after they settle, which suits payments that can be recalled. Real-time monitoring scores each transaction before funds move and can hold it. For stablecoin transfers, which are final within minutes and cannot be reversed, only real-time monitoring can stop a bad payment.",{"q":338,"a":339},"What is wallet address risk scoring?","A check on the destination or source wallet against OFAC-listed addresses and against blockchain analytics that trace the address's exposure to mixers, darknet markets, sanctioned exchanges, or hacked funds. It replaces the bank-name check a wire transfer relies on, since a wallet carries no institution behind it.",false,{"author":342},"BlindPay Team",true,"\u002Fresources\u002Fmore\u002Freal-time-transaction-monitoring-stablecoin-payments","---\ntitle: \"Real-time transaction monitoring for cross-border stablecoin payments\"\ndescription: \"Why stablecoin cross-border flows need different monitoring than wires: the signals that get scored (wallet address risk, velocity, corridor risk, on\u002Foff-ramp counterparties), real-time vs. batch monitoring, and a worked example of a flagged pattern from alert to decision.\"\ndate: \"2026-09-15\"\nupdated: \"2026-09-15\"\nauthor: \"BlindPay Team\"\ncategory: \"compliance\"\nfaq:\n  - q: \"Does transaction monitoring slow down stablecoin settlement speed?\"\n    a: \"Not meaningfully when it runs pre-settlement as a scoring step. Sanctions rescreening, wallet address risk, and velocity rules evaluate in well under a second for most transactions, so a clean payment still settles in minutes. Only the small share that scores into the review band waits on a person, and that wait is the point.\"\n  - q: \"Can transaction monitoring be automated for multiple blockchains at once?\"\n    a: \"Yes. Address risk scoring, sanctions list matching, and velocity rules operate on normalized transaction data, so the same rule set covers USDC on Ethereum, Base, Polygon, Solana, Stellar, or Tron. The chain-specific work is the indexer and the address format; the risk logic is shared.\"\n  - q: \"What is the difference between real-time and batch transaction monitoring?\"\n    a: \"Batch monitoring reviews the day's transactions after they settle, which suits payments that can be recalled. Real-time monitoring scores each transaction before funds move and can hold it. For stablecoin transfers, which are final within minutes and cannot be reversed, only real-time monitoring can stop a bad payment.\"\n  - q: \"What is wallet address risk scoring?\"\n    a: \"A check on the destination or source wallet against OFAC-listed addresses and against blockchain analytics that trace the address's exposure to mixers, darknet markets, sanctioned exchanges, or hacked funds. It replaces the bank-name check a wire transfer relies on, since a wallet carries no institution behind it.\"\n---\n\n*Reading time: about 7 minutes.*\n\n**Summary:** Cross-border stablecoin payments need real-time transaction monitoring because they settle in minutes at any hour, are final once confirmed, and touch counterparties in at least two jurisdictions on every transfer. A wire can be reviewed overnight and recalled; a stablecoin transfer has to be scored before it moves, using signals that include the wallet address itself.\n\nThis post covers what those signals are, how pre-settlement monitoring differs from the end-of-day batch model banks grew up with, and what happens to a transaction that gets flagged.\n\n## Why stablecoin flows need different monitoring than wires\n\nThree properties of a stablecoin transfer change the monitoring problem.\n\n**Settlement is continuous.** A SWIFT wire moves during banking hours and takes one to five days, which leaves room for a compliance team to review the day's batch before value is final. A USDC transfer confirms in seconds to minutes, on a Sunday, at 3 a.m. There is no overnight window.\n\n**Settlement is final.** Wires can be recalled, and card payments can be charged back. A confirmed blockchain transaction [cannot be reversed](\u002Fresources\u002Fmore\u002Fare-stablecoin-payments-reversible). A monitoring decision that arrives after confirmation is a report, not a control.\n\n**The counterparty is a wallet.** A wire carries a beneficiary bank, and that bank carries its own KYC obligations. A wallet address carries nothing. The monitoring system has to establish who is behind it, or at least what it has been exposed to, and it has to do that for a sender in one jurisdiction and a receiver in another.\n\nThe upside is visibility. Every on-chain transfer is public, which means the history of an address can be traced in a way a bank account's cannot. Monitoring for stablecoins is harder on timing and easier on data.\n\n## What signals get monitored in a stablecoin transaction?\n\nA pre-settlement risk score for a cross-border stablecoin payment typically combines five signal groups. The [automated risk monitoring explainer](\u002Fresources\u002Fmore\u002Fwhat-is-automated-risk-monitoring-fintech) covers the broader program these sit inside.\n\n### 1. Wallet address risk\n\nThe source and destination addresses are checked against OFAC-listed addresses and against blockchain analytics that score an address by its exposure: direct or indirect flows from mixers, darknet markets, sanctioned exchanges, ransomware wallets, or known hacks. Exposure is measured in hops and in share of funds, so an address one hop from a sanctioned service scores very differently from one with a trace of indirect exposure.\n\n### 2. Sanctions and PEP rescreening on the parties\n\nThe named sender, receiver, and beneficial owners are screened again at transaction time, not only at onboarding, because lists change. OFAC updates the SDN list several times a month, and EU, UN, and UK OFSI lists move on their own schedules.\n\n### 3. Velocity and pattern rules\n\nThe transaction is compared with the customer's own baseline and with pattern rules drawn from FinCEN and FATF typologies: total volume over 24 hours and 30 days, number of transfers per hour, amounts clustered just under a reporting threshold (structuring), funds received and forwarded within minutes (pass-through), and repeated round-number transfers to a new counterparty.\n\n### 4. Corridor risk\n\nCross-border adds the pair of jurisdictions as a signal. A USD-to-BRL payout to a verified Brazilian company is routine. The same amount to a receiver whose bank is in a FATF grey-list country, or whose declared country differs from the IP geolocation and the bank country, is not. Corridor rules also carry the Travel Rule thresholds, which differ by market: USD 3,000 in the US, no minimum in the EU, SGD 1,500 in Singapore.\n\n### 5. On-ramp and off-ramp counterparty checks\n\nWhere the stablecoin came from and where the fiat is going. An on-ramp from a licensed exchange with its own KYC scores differently from a self-custodied wallet with no history. An off-ramp to a bank account in the receiver's verified name scores differently from one in a third party's name, which is a classic mule pattern.\n\nEach group produces a score, and the combined score lands in one of three bands: settle, hold for review, or block.\n\n## Real-time vs. batch monitoring\n\nBanks built transaction monitoring as a batch process because their rails gave them the time: the end-of-day file runs through the rules engine, analysts work the alert queue over the following days, and a wire that looks wrong is recalled or reported.\n\n| Dimension | Batch (end-of-day) monitoring | Real-time (pre-settlement) monitoring |\n|---|---|---|\n| When rules run | After settlement, on the day's file | Before settlement, on each transaction |\n| Can it stop a payment | Only if the rail supports recall | Yes, by holding or blocking before funds move |\n| Latency added to a clean payment | None | Sub-second scoring in most implementations |\n| Analyst workload | Alerts reviewed over days | Held transactions reviewed within hours, since a customer is waiting |\n| Fit for stablecoins | Poor: the transfer is final before the batch runs | Required |\n| Fit for wires and ACH | Standard practice | Increasingly used, especially for faster-payment rails |\n\nThe row that matters is the second one. For a payment that is final within minutes, batch monitoring is detection with no enforcement. Real-time does not mean instant approval for everything; it means the score is computed before settlement, and the small share of transactions in the review band waits for a person while the rest go through.\n\n## A worked example: a flagged pattern and what happens next\n\nA hypothetical, with the mechanics kept realistic.\n\nA marketplace in the US pays sellers in Colombia through a stablecoin payout API. One seller, verified six months ago, has a baseline of two payouts a month, each around USD 1,800, to a bank account in their own name. Over one Saturday, the marketplace submits eleven payouts to that seller, each between USD 2,700 and USD 2,950, and the destination bank account has changed to one in a different person's name.\n\nHere is what the monitoring layer does before any of them settles.\n\n1. **Velocity rule fires.** Eleven transfers in a day against a baseline of two a month is a spike of over a hundred times the expected rate.\n2. **Structuring rule fires.** Every amount sits just below USD 3,000, the US Travel Rule threshold. On its own that is weak evidence; combined with the velocity spike it is strong.\n3. **Off-ramp counterparty check fires.** The bank account name does not match the verified receiver. That is the mule pattern, and it is the signal that pushes the combined score from hold into block.\n4. **Sanctions rescreen and wallet risk return clean.** Both are noted in the case file, because a clean screen is evidence too.\n5. **The first payout is held before settlement and the remaining ten are queued behind it.** The marketplace receives a webhook with a status change and a reason category, and the seller sees a pending state instead of a failure.\n6. **A compliance analyst opens the case.** The file already contains the baseline, the eleven transactions, the rules that fired, the screening results, and a draft narrative. The analyst requests proof of ownership of the new bank account and an explanation of the volume.\n7. **Two outcomes.** If the seller shows a legitimate reason (a business account opened under a partner's name, with documents), the analyst releases the payouts and notes the new baseline. If not, the payouts are rejected, the receiver is moved to a restricted state, and the case is evaluated against the Suspicious Activity Report standard, which gives 30 days from detection to file with FinCEN, or 60 if no suspect has been identified.\n\nThe machine part took under a minute. The eleven payouts never left.\n\n## How BlindPay applies this\n\nBlindPay runs transaction monitoring inside the payout flow rather than as a separate vendor step. KYC or KYB runs once per receiver, and on every payout the receiver and destination are rescreened against OFAC, EU, UN, and UK lists, the wallet address is risk-scored, and velocity, corridor, and counterparty rules produce the settle, hold, or block decision before funds move. Because BlindPay settles without pre-funding and in real time, that pre-settlement step is the only place a control can sit; there is no float period to review a batch in.\n\nHeld payouts surface as a status change over webhook with a reason category, so the customer's product can show a pending state rather than an error. The program is described on the [compliance page](\u002Fcompliance), and the jurisdiction rules it applies are covered in the [cross-border compliance guide](\u002Fresources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments).\n\n## What to do with this\n\nIf monitoring runs on an end-of-day file, move the scoring step before settlement first, even with the same rules. Then add wallet address risk as a signal, since it is the one check a bank-style program does not have. Tune velocity and structuring thresholds after the first month of alerts shows where the noise is.\n\n*This article is for general information only and is not legal, tax, or financial advice.*\n",{"title":5,"description":325},"resources\u002Fmore\u002Freal-time-transaction-monitoring-stablecoin-payments","ESsawEMlTeBHKhBRF9tSsW4alfedvsonfsuyLajvZ6w",[350,536,834,1164,1592,1898,2184,2413,2621,2951,3365,3503,3651],{"id":351,"title":352,"authors":6,"body":353,"categories":6,"category":323,"categoryType":6,"compare":6,"contributors":6,"date":510,"description":511,"extension":326,"faq":512,"howto":6,"isBlog":340,"isChangelog":340,"meta":531,"navigation":343,"path":50,"pillar":340,"products":6,"rawbody":532,"role":6,"seo":533,"stem":534,"thumbnail":6,"updated":6,"__hash__":535},"content\u002Fresources\u002Fmore\u002Fare-stablecoin-payments-reversible.md","Are stablecoin payments reversible? Finality, custody, and fraud explained",{"type":8,"value":354,"toc":502},[355,358,362,365,373,376,380,383,386,390,393,396,400,403,411,415,443,475,479,482],[11,356,357],{},"Most stablecoin explainers treat irreversibility as a warning: once a transfer settles, nobody can undo it. That framing misses the more useful half of the story. A stablecoin transfer being final is exactly what lets anyone trace who held custody of the funds at every step. The real weak point sits elsewhere: the ordinary bank transfer that funds the stablecoin leg, because that side of the payment stays reversible for days after the stablecoin side has already closed.",[28,359,361],{"id":360},"how-custody-actually-gets-proven","How custody actually gets proven",[11,363,364],{},"A stablecoin payment moves value through a set sequence: a bank account, a pooled account held for the benefit of customers, a conversion between fiat and stablecoin, an operational wallet, then the counterparty's wallet. At each step, one party and only one party legally holds the funds, and that fact locks in the moment the transfer settles.",[11,366,367,368,372],{},"Compare that to a wire routed through correspondent banks. Each intermediary bank confirms its leg only after the money has already moved, using SWIFT messaging customers never see. Reconstructing who held the money, and when, means asking each bank in the chain and waiting for an answer, sometimes over days. See our ",[48,369,371],{"href":370},"\u002Fresources\u002Fmore\u002Fwhat-is-a-stablecoin-api","stablecoin API primer"," for how this custody chain fits into a broader payment integration.",[11,374,375],{},"Whether a wallet is custodial or non-custodial gets treated as a minor implementation detail in most explainers, but it decides who is legally on the hook. A custodial wallet means the platform holds the private keys and carries legal responsibility for the asset. A non-custodial wallet means that responsibility ends the instant the stablecoin lands somewhere the counterparty controls.",[28,377,379],{"id":378},"what-finality-is-actually-worth","What finality is actually worth",[11,381,382],{},"With a reversible instrument, \"who held this money and when\" stays open to dispute after the fact, which is why reconciling a correspondent-banking wire is slow: two institutions comparing notes on a settlement that took days, based on messages sent back and forth.",[11,384,385],{},"An irreversible instrument closes that question the moment it settles: named custody, timestamped, no argument later. That is the real payoff of finality, and it barely gets mentioned across the wave of near-identical stablecoin explainers published through 2026.",[28,387,389],{"id":388},"where-the-exposure-really-sits","Where the exposure really sits",[11,391,392],{},"Stablecoin settlement closes in minutes. The fiat transfer that funds or receives it, an ACH payment or a wire, stays open to reversal for days afterward.",[11,394,395],{},"That gap is what a fraudster exploits: fund the fiat leg, receive stablecoins for it, then reverse the original ACH or wire while the return window is still open. The stablecoins have already moved on by then, and whoever processed the payment eats the loss. The fiat rail's dispute window simply outlasts the stablecoin rail's finality window. Fast finality on the stablecoin side isn't what creates the exposure; a fiat leg that stays reversible after the stablecoin leg has closed is.",[28,397,399],{"id":398},"why-identity-checks-alone-dont-catch-it","Why identity checks alone don't catch it",[11,401,402],{},"This scheme only exists because two settlement systems with different finality timelines sit next to each other, which is why it tends to get discovered by whoever ends up eating the loss rather than by a compliance checklist.",[11,404,405,406,410],{},"Know-your-customer checks at signup answer who a customer is, once. They don't answer whether a given transaction is timed to exploit a mismatch between two rails' settlement windows. Catching that takes continuous monitoring on the incoming fiat leg: velocity checks, funding-source risk scoring, and holds sized to the real reversal window of the rail in play, not a single gate that only fires at account opening. Our ",[48,407,409],{"href":408},"\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026","stablecoin regulation tracker"," covers where AML and sanctions rulemaking currently stands.",[28,412,414],{"id":413},"regulation-is-still-catching-up-and-volume-already-outpaces-it","Regulation is still catching up, and volume already outpaces it",[11,416,417,418,424,425,430,431,436,437,442],{},"Congress signed the GENIUS Act on July 18, 2025, but regulators ",[48,419,423],{"href":420,"rel":421},"https:\u002F\u002Fhome.treasury.gov\u002Fnews\u002Fpress-releases\u002Fsb0605",[422],"nofollow","missed their own July 18, 2026 deadline"," to finalize implementing rules, so the effective date stays January 18, 2027. Treasury's proposed rule on who qualifies as a permitted issuer only ",[48,426,429],{"href":427,"rel":428},"https:\u002F\u002Fwww.federalregister.gov\u002Fdocuments\u002F2026\u002F08\u002F18\u002F2026-16796\u002Fgenius-act-regulations-on-payment-stablecoin-issuance-offer-and-sale",[422],"appeared August 18, 2026",", with comments open until October 19. The ",[48,432,435],{"href":433,"rel":434},"https:\u002F\u002Fwww.federalregister.gov\u002Fdocuments\u002F2026\u002F04\u002F10\u002F2026-06963\u002F",[422],"OCC's BSA\u002FAML and sanctions proposal"," closed for comment June 9, and the ",[48,438,441],{"href":439,"rel":440},"https:\u002F\u002Fwww.federalregister.gov\u002Fdocuments\u002F2026\u002F06\u002F05\u002F2026-11342\u002F",[422],"FDIC's parallel version"," closed August 4. More than a year after signing, no business holds a completed federal stablecoin issuer license.",[11,444,445,446,451,452,457,458,463,464,469,470,474],{},"The volume moving through this exact structure keeps growing regardless. McKinsey and Artemis put annualized B2B stablecoin flow at ",[48,447,450],{"href":448,"rel":449},"https:\u002F\u002Fwww.mckinsey.com\u002Ffeatured-insights\u002Fweek-in-charts\u002Fstablecoins-find-their-niche",[422],"$226 billion in 2025, a 733% jump year over year",". Mastercard ",[48,453,456],{"href":454,"rel":455},"https:\u002F\u002Fwww.mastercard.com\u002Fus\u002Fen\u002Fnews-and-trends\u002Fpress\u002F2026\u002Faugust\u002Fmastercard-completes-acquisition-of-bvnk-to-advance-global-stabl.html",[422],"finished acquiring BVNK for up to $1.8 billion on August 3, 2026",", CoinDesk reports ",[48,459,462],{"href":460,"rel":461},"https:\u002F\u002Fwww.coindesk.com\u002Fbusiness\u002F2026\u002F08\u002F18\u002Fvisa-is-looking-for-a-new-stablecoin-settlement-partner-now-that-bvnk-is-owned-by-mastercard",[422],"Visa is now shopping for a new stablecoin settlement partner",", and Western Union rolled out ",[48,465,468],{"href":466,"rel":467},"https:\u002F\u002Fwww.theblock.co\u002Fpost\u002F399890\u002Fwestern-union-launches-usdpt-stablecoin-anchorage-solana",[422],"USDPT on Solana"," back in May. Larger sums keep crossing rails with mismatched finality while the compliance framework everyone assumes is settled sits in open rulemaking dockets. Our ",[48,471,473],{"href":472},"\u002Fresources\u002Fmore\u002Fstablecoin-payments-guide","stablecoin payments guide"," covers how these flows work end to end.",[28,476,478],{"id":477},"what-to-ask-before-trusting-a-provider","What to ask before trusting a provider",[11,480,481],{},"Whether it can name the custodian at every hop, from the originating bank account to the counterparty's wallet, with a timestamped record for each one. Without that, \"compliant by design\" is marketing copy, not a working control. Whether the fiat leg gets monitored continuously or only checked once at onboarding. And whether the backup provider clears payouts on the same approval and settlement timeline as the primary, since a backup that technically works but settles slower just delays the same exposure.",[11,483,484,485,490,491,496,497,293],{},"See how this custody chain works in practice in ",[48,486,489],{"href":487,"rel":488},"https:\u002F\u002Fwww.blindpay.com\u002Fdocs\u002Fgetting-started\u002Foverview",[422],"BlindPay's flow of funds documentation",", or look at a live corridor like ",[48,492,495],{"href":493,"rel":494},"https:\u002F\u002Fwww.blindpay.com\u002Fusdc-to-brl",[422],"USDC to BRL",". If a current provider cannot answer the three questions above, ",[48,498,501],{"href":499,"rel":500},"https:\u002F\u002Fwww.blindpay.com\u002Fcontact",[422],"talk to BlindPay",{"title":307,"searchDepth":308,"depth":308,"links":503},[504,505,506,507,508,509],{"id":360,"depth":308,"text":361},{"id":378,"depth":308,"text":379},{"id":388,"depth":308,"text":389},{"id":398,"depth":308,"text":399},{"id":413,"depth":308,"text":414},{"id":477,"depth":308,"text":478},"2026-09-01","Stablecoin transfers settle final in minutes and cannot be reversed. That finality proves custody at every step, but it also opens a fraud gap on the fiat side of the payment.",[513,516,519,522,525,528],{"q":514,"a":515},"Can a stablecoin payment be reversed once it settles?","No. Once a stablecoin transfer confirms on-chain, it is final. There is no chargeback or recall mechanism the way there is with a card payment or a wire. That finality is usually framed as the downside of stablecoins, but it is also what lets a provider prove, hop by hop, who legally held the funds at every point in the transfer.",{"q":517,"a":518},"Does irreversibility create a fraud risk in stablecoin payments?","The risk is not the stablecoin leg. It is the fiat leg sitting next to it. A payment typically pairs a stablecoin transfer, final in minutes, with an ACH or wire transfer, which stays open to reversal for days. A bad actor can exploit that gap: fund the fiat side, receive stablecoins, then claw back the original fiat payment after the stablecoins have already moved on.",{"q":520,"a":521},"How does the fiat-leg reversal scheme actually work?","Someone sends a fiat deposit by ACH or wire and receives stablecoins in return. Days later, they trigger a standard ACH return or wire recall on that original deposit, well within the normal window banks allow for reversals. By then the stablecoins are long gone, and the provider is left holding the loss. It is not a hack or a stolen-wallet scam. It is two settlement rails with mismatched finality windows being played against each other.",{"q":523,"a":524},"What controls actually catch fiat-leg reversal fraud?","Onboarding KYC tells a provider who a customer is, once, at signup. It does not tell them whether a given transaction is timed to exploit the gap between fiat and stablecoin finality. Stopping this requires ongoing monitoring on the incoming fiat leg: velocity limits, funding-source risk scoring, and holds sized to the actual reversal window of whichever fiat rail is in play, not a one-time check done at account opening.",{"q":526,"a":527},"Has the GENIUS Act finalized US stablecoin regulation?","Not yet, as of September 2026. The law was signed in July 2025 with a January 18, 2027 effective date, but regulators missed their own July 2026 deadline to finish implementing rules. Treasury's proposal for who qualifies as a permitted issuer only came out August 18, 2026, with comments open into October. OCC and FDIC each have parallel proposals on BSA\u002FAML and sanctions compliance still pending. No federal stablecoin issuer license has been finalized more than a year after signing.",{"q":529,"a":530},"What should a business ask a stablecoin payment provider about reversibility and fraud?","Three things. First, can they trace custody at every hop from bank account to counterparty wallet, with timestamps, not just a summary. Second, do they monitor the fiat-in leg continuously, or only check identity once at signup. Third, does their backup provider clear payouts on the same schedule as the primary, since a slower backup just delays the same exposure rather than closing it.",{},"---\ntitle: \"Are stablecoin payments reversible? Finality, custody, and fraud explained\"\ndescription: \"Stablecoin transfers settle final in minutes and cannot be reversed. That finality proves custody at every step, but it also opens a fraud gap on the fiat side of the payment.\"\ndate: \"2026-09-01\"\ncategory: \"compliance\"\nfaq:\n  - q: \"Can a stablecoin payment be reversed once it settles?\"\n    a: \"No. Once a stablecoin transfer confirms on-chain, it is final. There is no chargeback or recall mechanism the way there is with a card payment or a wire. That finality is usually framed as the downside of stablecoins, but it is also what lets a provider prove, hop by hop, who legally held the funds at every point in the transfer.\"\n  - q: \"Does irreversibility create a fraud risk in stablecoin payments?\"\n    a: \"The risk is not the stablecoin leg. It is the fiat leg sitting next to it. A payment typically pairs a stablecoin transfer, final in minutes, with an ACH or wire transfer, which stays open to reversal for days. A bad actor can exploit that gap: fund the fiat side, receive stablecoins, then claw back the original fiat payment after the stablecoins have already moved on.\"\n  - q: \"How does the fiat-leg reversal scheme actually work?\"\n    a: \"Someone sends a fiat deposit by ACH or wire and receives stablecoins in return. Days later, they trigger a standard ACH return or wire recall on that original deposit, well within the normal window banks allow for reversals. By then the stablecoins are long gone, and the provider is left holding the loss. It is not a hack or a stolen-wallet scam. It is two settlement rails with mismatched finality windows being played against each other.\"\n  - q: \"What controls actually catch fiat-leg reversal fraud?\"\n    a: \"Onboarding KYC tells a provider who a customer is, once, at signup. It does not tell them whether a given transaction is timed to exploit the gap between fiat and stablecoin finality. Stopping this requires ongoing monitoring on the incoming fiat leg: velocity limits, funding-source risk scoring, and holds sized to the actual reversal window of whichever fiat rail is in play, not a one-time check done at account opening.\"\n  - q: \"Has the GENIUS Act finalized US stablecoin regulation?\"\n    a: \"Not yet, as of September 2026. The law was signed in July 2025 with a January 18, 2027 effective date, but regulators missed their own July 2026 deadline to finish implementing rules. Treasury's proposal for who qualifies as a permitted issuer only came out August 18, 2026, with comments open into October. OCC and FDIC each have parallel proposals on BSA\u002FAML and sanctions compliance still pending. No federal stablecoin issuer license has been finalized more than a year after signing.\"\n  - q: \"What should a business ask a stablecoin payment provider about reversibility and fraud?\"\n    a: \"Three things. First, can they trace custody at every hop from bank account to counterparty wallet, with timestamps, not just a summary. Second, do they monitor the fiat-in leg continuously, or only check identity once at signup. Third, does their backup provider clear payouts on the same schedule as the primary, since a slower backup just delays the same exposure rather than closing it.\"\n---\n\nMost stablecoin explainers treat irreversibility as a warning: once a transfer settles, nobody can undo it. That framing misses the more useful half of the story. A stablecoin transfer being final is exactly what lets anyone trace who held custody of the funds at every step. The real weak point sits elsewhere: the ordinary bank transfer that funds the stablecoin leg, because that side of the payment stays reversible for days after the stablecoin side has already closed.\n\n## How custody actually gets proven\n\nA stablecoin payment moves value through a set sequence: a bank account, a pooled account held for the benefit of customers, a conversion between fiat and stablecoin, an operational wallet, then the counterparty's wallet. At each step, one party and only one party legally holds the funds, and that fact locks in the moment the transfer settles.\n\nCompare that to a wire routed through correspondent banks. Each intermediary bank confirms its leg only after the money has already moved, using SWIFT messaging customers never see. Reconstructing who held the money, and when, means asking each bank in the chain and waiting for an answer, sometimes over days. See our [stablecoin API primer](\u002Fresources\u002Fmore\u002Fwhat-is-a-stablecoin-api) for how this custody chain fits into a broader payment integration.\n\nWhether a wallet is custodial or non-custodial gets treated as a minor implementation detail in most explainers, but it decides who is legally on the hook. A custodial wallet means the platform holds the private keys and carries legal responsibility for the asset. A non-custodial wallet means that responsibility ends the instant the stablecoin lands somewhere the counterparty controls.\n\n## What finality is actually worth\n\nWith a reversible instrument, \"who held this money and when\" stays open to dispute after the fact, which is why reconciling a correspondent-banking wire is slow: two institutions comparing notes on a settlement that took days, based on messages sent back and forth.\n\nAn irreversible instrument closes that question the moment it settles: named custody, timestamped, no argument later. That is the real payoff of finality, and it barely gets mentioned across the wave of near-identical stablecoin explainers published through 2026.\n\n## Where the exposure really sits\n\nStablecoin settlement closes in minutes. The fiat transfer that funds or receives it, an ACH payment or a wire, stays open to reversal for days afterward.\n\nThat gap is what a fraudster exploits: fund the fiat leg, receive stablecoins for it, then reverse the original ACH or wire while the return window is still open. The stablecoins have already moved on by then, and whoever processed the payment eats the loss. The fiat rail's dispute window simply outlasts the stablecoin rail's finality window. Fast finality on the stablecoin side isn't what creates the exposure; a fiat leg that stays reversible after the stablecoin leg has closed is.\n\n## Why identity checks alone don't catch it\n\nThis scheme only exists because two settlement systems with different finality timelines sit next to each other, which is why it tends to get discovered by whoever ends up eating the loss rather than by a compliance checklist.\n\nKnow-your-customer checks at signup answer who a customer is, once. They don't answer whether a given transaction is timed to exploit a mismatch between two rails' settlement windows. Catching that takes continuous monitoring on the incoming fiat leg: velocity checks, funding-source risk scoring, and holds sized to the real reversal window of the rail in play, not a single gate that only fires at account opening. Our [stablecoin regulation tracker](\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026) covers where AML and sanctions rulemaking currently stands.\n\n## Regulation is still catching up, and volume already outpaces it\n\nCongress signed the GENIUS Act on July 18, 2025, but regulators [missed their own July 18, 2026 deadline](https:\u002F\u002Fhome.treasury.gov\u002Fnews\u002Fpress-releases\u002Fsb0605) to finalize implementing rules, so the effective date stays January 18, 2027. Treasury's proposed rule on who qualifies as a permitted issuer only [appeared August 18, 2026](https:\u002F\u002Fwww.federalregister.gov\u002Fdocuments\u002F2026\u002F08\u002F18\u002F2026-16796\u002Fgenius-act-regulations-on-payment-stablecoin-issuance-offer-and-sale), with comments open until October 19. The [OCC's BSA\u002FAML and sanctions proposal](https:\u002F\u002Fwww.federalregister.gov\u002Fdocuments\u002F2026\u002F04\u002F10\u002F2026-06963\u002F) closed for comment June 9, and the [FDIC's parallel version](https:\u002F\u002Fwww.federalregister.gov\u002Fdocuments\u002F2026\u002F06\u002F05\u002F2026-11342\u002F) closed August 4. More than a year after signing, no business holds a completed federal stablecoin issuer license.\n\nThe volume moving through this exact structure keeps growing regardless. McKinsey and Artemis put annualized B2B stablecoin flow at [$226 billion in 2025, a 733% jump year over year](https:\u002F\u002Fwww.mckinsey.com\u002Ffeatured-insights\u002Fweek-in-charts\u002Fstablecoins-find-their-niche). Mastercard [finished acquiring BVNK for up to $1.8 billion on August 3, 2026](https:\u002F\u002Fwww.mastercard.com\u002Fus\u002Fen\u002Fnews-and-trends\u002Fpress\u002F2026\u002Faugust\u002Fmastercard-completes-acquisition-of-bvnk-to-advance-global-stabl.html), CoinDesk reports [Visa is now shopping for a new stablecoin settlement partner](https:\u002F\u002Fwww.coindesk.com\u002Fbusiness\u002F2026\u002F08\u002F18\u002Fvisa-is-looking-for-a-new-stablecoin-settlement-partner-now-that-bvnk-is-owned-by-mastercard), and Western Union rolled out [USDPT on Solana](https:\u002F\u002Fwww.theblock.co\u002Fpost\u002F399890\u002Fwestern-union-launches-usdpt-stablecoin-anchorage-solana) back in May. Larger sums keep crossing rails with mismatched finality while the compliance framework everyone assumes is settled sits in open rulemaking dockets. Our [stablecoin payments guide](\u002Fresources\u002Fmore\u002Fstablecoin-payments-guide) covers how these flows work end to end.\n\n## What to ask before trusting a provider\n\nWhether it can name the custodian at every hop, from the originating bank account to the counterparty's wallet, with a timestamped record for each one. Without that, \"compliant by design\" is marketing copy, not a working control. Whether the fiat leg gets monitored continuously or only checked once at onboarding. And whether the backup provider clears payouts on the same approval and settlement timeline as the primary, since a backup that technically works but settles slower just delays the same exposure.\n\nSee how this custody chain works in practice in [BlindPay's flow of funds documentation](https:\u002F\u002Fwww.blindpay.com\u002Fdocs\u002Fgetting-started\u002Foverview), or look at a live corridor like [USDC to BRL](https:\u002F\u002Fwww.blindpay.com\u002Fusdc-to-brl). If a current provider cannot answer the three questions above, [talk to BlindPay](https:\u002F\u002Fwww.blindpay.com\u002Fcontact).\n",{"title":352,"description":511},"resources\u002Fmore\u002Fare-stablecoin-payments-reversible","J9gmRaRp5XGFppeEc6KYpp1XSlEPlGIiVLsIqchfSsQ",{"id":537,"title":538,"authors":6,"body":539,"categories":6,"category":323,"categoryType":6,"compare":6,"contributors":6,"date":324,"description":811,"extension":326,"faq":812,"howto":6,"isBlog":340,"isChangelog":340,"meta":828,"navigation":343,"path":829,"pillar":340,"products":6,"rawbody":830,"role":6,"seo":831,"stem":832,"thumbnail":6,"updated":324,"__hash__":833},"content\u002Fresources\u002Fmore\u002Fautomated-kyc-kyb-vs-manual-onboarding.md","Automated KYC\u002FKYB vs. manual onboarding: what actually changes",{"type":8,"value":540,"toc":802},[541,546,551,554,558,561,564,572,576,579,582,586,589,596,600,603,696,699,705,711,715,722,761,764,768,771,785,788,792,795,798],[11,542,543],{},[14,544,545],{},"Reading time: about 6 minutes.",[11,547,548,550],{},[20,549,22],{}," Automated KYC\u002FKYB trades manual judgment on every case for speed, consistency, and scale, reserving humans for the cases the system cannot decide. Onboarding drops from days to minutes for most customers, cost per check falls sharply, and the audit trail becomes structured data instead of email threads.",[11,552,553],{},"That is the whole tradeoff in one line. The rest of this post is about what it looks like row by row, and where the \"most customers\" caveat bites.",[28,555,557],{"id":556},"what-is-the-difference-between-kyc-and-kyb","What is the difference between KYC and KYB?",[11,559,560],{},"Know Your Customer (KYC) verifies an individual before they can transact: identity document, liveness check, address, tax ID, and screening against sanctions and politically exposed person (PEP) lists.",[11,562,563],{},"Know Your Business (KYB) verifies a company. It confirms the entity exists and is active in the corporate registry, maps who owns and controls it, and then runs KYC on each beneficial owner. In the US, FinCEN's customer due diligence rule sets the ownership threshold at 25 percent, plus one individual with control.",[11,565,566,567,571],{},"So KYB is KYC plus an entity layer. A fintech paying contractors needs KYC. A fintech paying vendors, marketplaces, or corporate customers needs KYB, and inherits the KYC work for every owner. The ",[48,568,570],{"href":569},"\u002Fresources\u002Fmore\u002Fwhat-is-kyb","KYB explainer"," covers the ownership rules in detail.",[28,573,575],{"id":574},"what-is-manual-onboarding","What is manual onboarding?",[11,577,578],{},"Manual onboarding means an analyst reads the submitted documents, looks up the registry, runs the screening tool, decides, and writes it up. Every case gets human attention, which is the appeal.",[11,580,581],{},"It works until it doesn't. The queue grows linearly with signups, decisions vary by analyst, and the record of why a customer was approved lives in whatever the analyst wrote down that day.",[28,583,585],{"id":584},"what-is-automated-onboarding","What is automated onboarding?",[11,587,588],{},"Automated onboarding turns the same checks into a pipeline: document extraction and authenticity, liveness and face match, registry lookup, ownership mapping, screening, and a risk score that decides between approve, reject, and hold for review. A clean case clears the pipeline without anyone opening it. A case with a screening hit or a data mismatch stops and waits for a person.",[11,590,591,592,293],{},"The step-by-step version of that pipeline is in the ",[48,593,595],{"href":594},"\u002Fresources\u002Fmore\u002Fhow-to-automate-kyc-kyb-stablecoin-payments","KYC\u002FKYB automation guide",[28,597,599],{"id":598},"automated-vs-manual-the-comparison","Automated vs. manual: the comparison",[11,601,602],{},"Figures are typical ranges observed across fintech onboarding programs, not guarantees for any specific vendor or company. Ranges marked with an asterisk vary widely with volume and jurisdiction.",[121,604,605,617],{},[124,606,607],{},[127,608,609,611,614],{},[130,610,132],{},[130,612,613],{},"Manual onboarding",[130,615,616],{},"Automated onboarding",[140,618,619,630,641,652,663,674,685],{},[127,620,621,624,627],{},[145,622,623],{},"Onboarding time, individual",[145,625,626],{},"Hours to 1-2 business days per case",[145,628,629],{},"Under a minute for a clean case; edge cases routed to review",[127,631,632,635,638],{},[145,633,634],{},"Onboarding time, business (KYB)",[145,636,637],{},"2-5 business days per entity, longer with layered ownership",[145,639,640],{},"Minutes to same day with digital registries and simple ownership; days for complex structures",[127,642,643,646,649],{},[145,644,645],{},"Error and false-positive rate",[145,647,648],{},"Varies by analyst; inconsistent between reviewers, and fatigue raises misses at volume",[145,650,651],{},"Tunable per rule and measurable; poorly tuned name screening can make false positives the large majority of alerts*",[127,653,654,657,660],{},[145,655,656],{},"Cost per verification",[145,658,659],{},"Tens of dollars per case in analyst time, more for KYB*",[145,661,662],{},"Low single dollars per individual check at volume; more for KYB with ownership lookups*",[127,664,665,668,671],{},[145,666,667],{},"Scaling across jurisdictions",[145,669,670],{},"Each new country needs analysts who know its documents and registries",[145,672,673],{},"Each new country is a rule set and a registry integration; the pipeline is the same",[127,675,676,679,682],{},[145,677,678],{},"Audit-trail quality",[145,680,681],{},"Emails, spreadsheets, screenshots; reconstructed on request",[145,683,684],{},"Structured log of inputs, checks, scores, decisions, and reviewer identity, queryable per customer",[127,686,687,690,693],{},[145,688,689],{},"Consistency",[145,691,692],{},"Depends on who reviewed the case",[145,694,695],{},"Same inputs produce the same decision every time",[11,697,698],{},"Two rows deserve a closer look.",[11,700,701,704],{},[20,702,703],{},"False positives."," Automation does not remove false positives; it makes them visible and tunable. Name screening is the classic source: \"Mohammed Ali\" against a global watchlist returns hundreds of matches unless date of birth and country are used to narrow it. A manual program has the same problem but hides it inside analyst time. An automated program reports it as a number, and that number is what compliance teams spend their first months driving down.",[11,706,707,710],{},[20,708,709],{},"Audit trail."," This is the row that decides examinations. FinCEN expects a money services business to show, for any customer, what was collected, what was checked, what the result was, and who signed off. An automated pipeline produces that record as a side effect. A manual program has to build it by hand, and usually after the fact.",[28,712,714],{"id":713},"when-is-manual-review-still-necessary","When is manual review still necessary?",[11,716,717,718,293],{},"Even a fully automated stack needs humans on a defined set of cases. The list below is what most programs route to review, and it lines up with the enhanced due diligence described in BlindPay's ",[48,719,721],{"href":720},"\u002Faml-sanctions-policy-statement","AML policy statement",[723,724,725,731,737,743,749,755],"ul",{},[229,726,727,730],{},[20,728,729],{},"Sanctions and PEP matches."," OFAC compliance is strict liability, so a potential match is never auto-cleared. An analyst confirms or rejects it against the list entry's identifiers. A confirmed sanctions match ends the relationship; a PEP match changes the risk tier and, under some programs, is declined outright.",[229,732,733,736],{},[20,734,735],{},"High-risk jurisdictions."," Customers or beneficial owners in countries on the FATF grey or black lists, or in jurisdictions the company's risk appetite excludes, get enhanced due diligence: source of funds, purpose of transactions, and often a call.",[229,738,739,742],{},[20,740,741],{},"Complex ownership."," Trusts, nominee shareholders, ownership chains through multiple countries, or a registry that is not digitized. The system can flag that ownership does not resolve to individuals; a person has to trace it.",[229,744,745,748],{},[20,746,747],{},"Document and data mismatches."," Name on the ID differs from the typed name, address on the proof of address is older than the allowed window, or the selfie fails liveness on a device that looks legitimate. Some are fraud, most are typos, and the system cannot tell which.",[229,750,751,754],{},[20,752,753],{},"Limit increases."," A customer asking to move more than their tier allows triggers a source-of-funds review, which is inherently a judgment call.",[229,756,757,760],{},[20,758,759],{},"Regulated counterparties."," Onboarding another money services business, a virtual asset service provider, or a payment service provider means reviewing their AML program, not just their registration.",[11,762,763],{},"The goal is not zero manual review. It is manual review on the cases where judgment changes the outcome, with everything else handled by rules.",[28,765,767],{"id":766},"what-changes-for-the-engineering-team","What changes for the engineering team?",[11,769,770],{},"Manual onboarding is invisible to engineering: a form submits, a ticket opens, someone emails the customer days later. Automated onboarding is an integration.",[723,772,773,776,779,782],{},[229,774,775],{},"The onboarding form maps to an API request that creates the customer or receiver with identity or entity data.",[229,777,778],{},"The result comes back as a status, typically verifying, approved, or rejected, and a webhook fires when it changes.",[229,780,781],{},"The product gates money movement on that status, so a rejected receiver cannot be paid and a verifying one waits.",[229,783,784],{},"Rejections carry a reason category so the app can tell the user what to fix, where the rules allow.",[11,786,787],{},"When verification is embedded in the payment API, as it is with BlindPay, the integration is one vendor and one webhook rather than a KYC vendor, a screening vendor, and glue code between them and the payout system.",[28,789,791],{"id":790},"which-should-a-fintech-choose","Which should a fintech choose?",[11,793,794],{},"At launch with a handful of customers, manual review is fine and cheaper to set up. Past a few hundred customers, or the first non-domestic market, the queue and the audit trail both become problems at once, and that is the point to automate.",[11,796,797],{},"The practical move is to automate the pipeline first and keep the review queue, then spend the following quarter tuning rules until the queue holds only the cases in the section above. Start with sanctions screening thresholds, since that is where most of the noise comes from.",[11,799,800],{},[14,801,305],{},{"title":307,"searchDepth":308,"depth":308,"links":803},[804,805,806,807,808,809,810],{"id":556,"depth":308,"text":557},{"id":574,"depth":308,"text":575},{"id":584,"depth":308,"text":585},{"id":598,"depth":308,"text":599},{"id":713,"depth":308,"text":714},{"id":766,"depth":308,"text":767},{"id":790,"depth":308,"text":791},"A side-by-side comparison of automated and manual KYC\u002FKYB for fintechs: onboarding time, false-positive rates, cost per verification, scaling across jurisdictions, and audit-trail quality, plus the cases where a human reviewer is still required.",[813,816,819,822,825],{"q":814,"a":815},"Can automated KYC fully replace manual review?","No. Automation handles the clean majority of cases end to end, but sanctions and PEP matches, document mismatches, complex ownership structures, and high-risk jurisdictions still need a human decision. A well-tuned program sends a small share of cases to review; a badly tuned one sends most of them.",{"q":817,"a":818},"What is KYB and how is it different from KYC?","KYC (Know Your Customer) verifies an individual: identity document, liveness, address, and screening. KYB (Know Your Business) verifies a company: registry status, good standing, ownership structure, and then KYC on each beneficial owner and controller. KYB always contains KYC; the reverse is not true.",{"q":820,"a":821},"How long does automated business verification take?","Minutes to same day when the registry is digital and ownership is simple, because the entity lookup, document checks, and owner screening run in parallel. Layered holding companies, trusts, or paper registries push it to several days because ownership has to be traced to real people by hand.",{"q":823,"a":824},"What does automated KYC cost compared to manual review?","Automated individual verification typically runs in the low single dollars per check at volume, while a manual review costs an analyst's time, usually tens of dollars per case once salary and tooling are counted. Business verification costs more in both models because of the ownership work.",{"q":826,"a":827},"Does automated onboarding hold up in a regulatory examination?","Yes, and often better than manual. Examiners ask for the inputs, the checks that ran, the decision, and who made it, for a sample of customers. An automated pipeline stores that as structured data; a manual program has to reconstruct it from emails and spreadsheets.",{"author":342},"\u002Fresources\u002Fmore\u002Fautomated-kyc-kyb-vs-manual-onboarding","---\ntitle: \"Automated KYC\u002FKYB vs. manual onboarding: what actually changes\"\ndescription: \"A side-by-side comparison of automated and manual KYC\u002FKYB for fintechs: onboarding time, false-positive rates, cost per verification, scaling across jurisdictions, and audit-trail quality, plus the cases where a human reviewer is still required.\"\ndate: \"2026-09-15\"\nupdated: \"2026-09-15\"\nauthor: \"BlindPay Team\"\ncategory: \"compliance\"\nfaq:\n  - q: \"Can automated KYC fully replace manual review?\"\n    a: \"No. Automation handles the clean majority of cases end to end, but sanctions and PEP matches, document mismatches, complex ownership structures, and high-risk jurisdictions still need a human decision. A well-tuned program sends a small share of cases to review; a badly tuned one sends most of them.\"\n  - q: \"What is KYB and how is it different from KYC?\"\n    a: \"KYC (Know Your Customer) verifies an individual: identity document, liveness, address, and screening. KYB (Know Your Business) verifies a company: registry status, good standing, ownership structure, and then KYC on each beneficial owner and controller. KYB always contains KYC; the reverse is not true.\"\n  - q: \"How long does automated business verification take?\"\n    a: \"Minutes to same day when the registry is digital and ownership is simple, because the entity lookup, document checks, and owner screening run in parallel. Layered holding companies, trusts, or paper registries push it to several days because ownership has to be traced to real people by hand.\"\n  - q: \"What does automated KYC cost compared to manual review?\"\n    a: \"Automated individual verification typically runs in the low single dollars per check at volume, while a manual review costs an analyst's time, usually tens of dollars per case once salary and tooling are counted. Business verification costs more in both models because of the ownership work.\"\n  - q: \"Does automated onboarding hold up in a regulatory examination?\"\n    a: \"Yes, and often better than manual. Examiners ask for the inputs, the checks that ran, the decision, and who made it, for a sample of customers. An automated pipeline stores that as structured data; a manual program has to reconstruct it from emails and spreadsheets.\"\n---\n\n*Reading time: about 6 minutes.*\n\n**Summary:** Automated KYC\u002FKYB trades manual judgment on every case for speed, consistency, and scale, reserving humans for the cases the system cannot decide. Onboarding drops from days to minutes for most customers, cost per check falls sharply, and the audit trail becomes structured data instead of email threads.\n\nThat is the whole tradeoff in one line. The rest of this post is about what it looks like row by row, and where the \"most customers\" caveat bites.\n\n## What is the difference between KYC and KYB?\n\nKnow Your Customer (KYC) verifies an individual before they can transact: identity document, liveness check, address, tax ID, and screening against sanctions and politically exposed person (PEP) lists.\n\nKnow Your Business (KYB) verifies a company. It confirms the entity exists and is active in the corporate registry, maps who owns and controls it, and then runs KYC on each beneficial owner. In the US, FinCEN's customer due diligence rule sets the ownership threshold at 25 percent, plus one individual with control.\n\nSo KYB is KYC plus an entity layer. A fintech paying contractors needs KYC. A fintech paying vendors, marketplaces, or corporate customers needs KYB, and inherits the KYC work for every owner. The [KYB explainer](\u002Fresources\u002Fmore\u002Fwhat-is-kyb) covers the ownership rules in detail.\n\n## What is manual onboarding?\n\nManual onboarding means an analyst reads the submitted documents, looks up the registry, runs the screening tool, decides, and writes it up. Every case gets human attention, which is the appeal.\n\nIt works until it doesn't. The queue grows linearly with signups, decisions vary by analyst, and the record of why a customer was approved lives in whatever the analyst wrote down that day.\n\n## What is automated onboarding?\n\nAutomated onboarding turns the same checks into a pipeline: document extraction and authenticity, liveness and face match, registry lookup, ownership mapping, screening, and a risk score that decides between approve, reject, and hold for review. A clean case clears the pipeline without anyone opening it. A case with a screening hit or a data mismatch stops and waits for a person.\n\nThe step-by-step version of that pipeline is in the [KYC\u002FKYB automation guide](\u002Fresources\u002Fmore\u002Fhow-to-automate-kyc-kyb-stablecoin-payments).\n\n## Automated vs. manual: the comparison\n\nFigures are typical ranges observed across fintech onboarding programs, not guarantees for any specific vendor or company. Ranges marked with an asterisk vary widely with volume and jurisdiction.\n\n| Dimension | Manual onboarding | Automated onboarding |\n|---|---|---|\n| Onboarding time, individual | Hours to 1-2 business days per case | Under a minute for a clean case; edge cases routed to review |\n| Onboarding time, business (KYB) | 2-5 business days per entity, longer with layered ownership | Minutes to same day with digital registries and simple ownership; days for complex structures |\n| Error and false-positive rate | Varies by analyst; inconsistent between reviewers, and fatigue raises misses at volume | Tunable per rule and measurable; poorly tuned name screening can make false positives the large majority of alerts* |\n| Cost per verification | Tens of dollars per case in analyst time, more for KYB* | Low single dollars per individual check at volume; more for KYB with ownership lookups* |\n| Scaling across jurisdictions | Each new country needs analysts who know its documents and registries | Each new country is a rule set and a registry integration; the pipeline is the same |\n| Audit-trail quality | Emails, spreadsheets, screenshots; reconstructed on request | Structured log of inputs, checks, scores, decisions, and reviewer identity, queryable per customer |\n| Consistency | Depends on who reviewed the case | Same inputs produce the same decision every time |\n\nTwo rows deserve a closer look.\n\n**False positives.** Automation does not remove false positives; it makes them visible and tunable. Name screening is the classic source: \"Mohammed Ali\" against a global watchlist returns hundreds of matches unless date of birth and country are used to narrow it. A manual program has the same problem but hides it inside analyst time. An automated program reports it as a number, and that number is what compliance teams spend their first months driving down.\n\n**Audit trail.** This is the row that decides examinations. FinCEN expects a money services business to show, for any customer, what was collected, what was checked, what the result was, and who signed off. An automated pipeline produces that record as a side effect. A manual program has to build it by hand, and usually after the fact.\n\n## When is manual review still necessary?\n\nEven a fully automated stack needs humans on a defined set of cases. The list below is what most programs route to review, and it lines up with the enhanced due diligence described in BlindPay's [AML policy statement](\u002Faml-sanctions-policy-statement).\n\n- **Sanctions and PEP matches.** OFAC compliance is strict liability, so a potential match is never auto-cleared. An analyst confirms or rejects it against the list entry's identifiers. A confirmed sanctions match ends the relationship; a PEP match changes the risk tier and, under some programs, is declined outright.\n- **High-risk jurisdictions.** Customers or beneficial owners in countries on the FATF grey or black lists, or in jurisdictions the company's risk appetite excludes, get enhanced due diligence: source of funds, purpose of transactions, and often a call.\n- **Complex ownership.** Trusts, nominee shareholders, ownership chains through multiple countries, or a registry that is not digitized. The system can flag that ownership does not resolve to individuals; a person has to trace it.\n- **Document and data mismatches.** Name on the ID differs from the typed name, address on the proof of address is older than the allowed window, or the selfie fails liveness on a device that looks legitimate. Some are fraud, most are typos, and the system cannot tell which.\n- **Limit increases.** A customer asking to move more than their tier allows triggers a source-of-funds review, which is inherently a judgment call.\n- **Regulated counterparties.** Onboarding another money services business, a virtual asset service provider, or a payment service provider means reviewing their AML program, not just their registration.\n\nThe goal is not zero manual review. It is manual review on the cases where judgment changes the outcome, with everything else handled by rules.\n\n## What changes for the engineering team?\n\nManual onboarding is invisible to engineering: a form submits, a ticket opens, someone emails the customer days later. Automated onboarding is an integration.\n\n- The onboarding form maps to an API request that creates the customer or receiver with identity or entity data.\n- The result comes back as a status, typically verifying, approved, or rejected, and a webhook fires when it changes.\n- The product gates money movement on that status, so a rejected receiver cannot be paid and a verifying one waits.\n- Rejections carry a reason category so the app can tell the user what to fix, where the rules allow.\n\nWhen verification is embedded in the payment API, as it is with BlindPay, the integration is one vendor and one webhook rather than a KYC vendor, a screening vendor, and glue code between them and the payout system.\n\n## Which should a fintech choose?\n\nAt launch with a handful of customers, manual review is fine and cheaper to set up. Past a few hundred customers, or the first non-domestic market, the queue and the audit trail both become problems at once, and that is the point to automate.\n\nThe practical move is to automate the pipeline first and keep the review queue, then spend the following quarter tuning rules until the queue holds only the cases in the section above. Start with sanctions screening thresholds, since that is where most of the noise comes from.\n\n*This article is for general information only and is not legal, tax, or financial advice.*\n",{"title":538,"description":811},"resources\u002Fmore\u002Fautomated-kyc-kyb-vs-manual-onboarding","Q_8u6YYXnud4Rl_M7Yi1Jzrr_dN5oTHPyPNyUGX-P6Q",{"id":835,"title":836,"authors":6,"body":837,"categories":6,"category":323,"categoryType":6,"compare":6,"contributors":6,"date":1138,"description":1139,"extension":326,"faq":1140,"howto":6,"isBlog":340,"isChangelog":340,"meta":1159,"navigation":343,"path":291,"pillar":340,"products":6,"rawbody":1160,"role":6,"seo":1161,"stem":1162,"thumbnail":6,"updated":1138,"__hash__":1163},"content\u002Fresources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments.md","Compliance agents for cross-border stablecoin payments: a global regulatory guide",{"type":8,"value":838,"toc":1123},[839,844,849,852,856,859,862,865,869,872,875,958,961,965,968,971,974,977,980,984,987,990,993,996,1000,1003,1006,1009,1016,1020,1023,1027,1035,1039,1046,1050,1053,1057,1060,1064,1067,1093,1096,1100,1103,1119],[11,840,841],{},[14,842,843],{},"Reading time: about 8 minutes.",[11,845,846,848],{},[20,847,22],{}," Compliance agents handle cross-border stablecoin payment regulation by reading the context of each transaction, selecting the rule set for the jurisdictions involved, and running identity checks, sanctions screening, Travel Rule data exchange, and reporting before funds settle. The rules are maintained at the infrastructure level, so a business does not rebuild its compliance stack for every new market.",[11,850,851],{},"Cross-border stablecoin payments touch at least two regulatory regimes on every transfer: the sender's and the receiver's. Each regime has its own licensing body, sanctions authority, data-sharing threshold, and reporting obligation. This guide sets out what those regimes require and how a compliance layer can satisfy them without per-country engineering.",[28,853,855],{"id":854},"how-do-compliance-agents-handle-cross-border-stablecoin-payment-regulation","How do compliance agents handle cross-border stablecoin payment regulation?",[11,857,858],{},"A compliance agent is an automated component that sits in the payment flow and evaluates each transaction against the rules that apply to it. It reads the transaction context, meaning the sender's jurisdiction, the receiver's jurisdiction, the counterparty type, the asset, and the amount, and then selects the matching rule set.",[11,860,861],{},"The agent then runs the checks that rule set requires: customer verification status, sanctions screening across the relevant lists, Travel Rule data exchange with the counterparty institution, and threshold-based reporting. The transaction proceeds, holds for review, or is rejected based on the result.",[11,863,864],{},"The alternative is writing compliance logic per market inside the payment application. That approach works for one or two corridors and breaks when the third market has a different threshold, a different data format, or a different regulator.",[28,866,868],{"id":867},"what-are-the-global-regulatory-requirements-for-stablecoin-transfers","What are the global regulatory requirements for stablecoin transfers?",[11,870,871],{},"Every major market now regulates stablecoin transfers through a licensing regime for the intermediary and an anti-money laundering (AML) regime for the transaction. The licensing regime decides who may operate; the AML regime decides what each transfer must carry and when it must be reported.",[11,873,874],{},"The table below summarizes the primary requirement in six markets relevant to cross-border stablecoin payments.",[121,876,877,890],{},[124,878,879],{},[127,880,881,884,887],{},[130,882,883],{},"Jurisdiction",[130,885,886],{},"Regulatory body",[130,888,889],{},"Primary requirement",[140,891,892,903,914,925,936,947],{},[127,893,894,897,900],{},[145,895,896],{},"United States",[145,898,899],{},"Financial Crimes Enforcement Network (FinCEN), with state money transmitter regulators",[145,901,902],{},"Money Services Business (MSB) registration under the Bank Secrecy Act (BSA), an AML program, Travel Rule compliance at USD 3,000, and strict-liability sanctions compliance under the Office of Foreign Assets Control (OFAC)",[127,904,905,908,911],{},[145,906,907],{},"European Union",[145,909,910],{},"National competent authorities under the Markets in Crypto-Assets Regulation (MiCA), with the Anti-Money Laundering Directives (AMLD)",[145,912,913],{},"Crypto-Asset Service Provider (CASP) authorization, Travel Rule under the Transfer of Funds Regulation (TFR) with no minimum threshold, and use of MiCA-compliant e-money tokens",[127,915,916,919,922],{},[145,917,918],{},"United Kingdom",[145,920,921],{},"Financial Conduct Authority (FCA)",[145,923,924],{},"Cryptoasset registration under the Money Laundering Regulations (MLRs), Travel Rule compliance in force since September 2023, and sanctions compliance under the Office of Financial Sanctions Implementation (OFSI)",[127,926,927,930,933],{},[145,928,929],{},"Singapore",[145,931,932],{},"Monetary Authority of Singapore (MAS)",[145,934,935],{},"Digital Payment Token (DPT) service license under the Payment Services Act (PSA), with AML and Travel Rule obligations under MAS Notice PSN02 at SGD 1,500",[127,937,938,941,944],{},[145,939,940],{},"Brazil",[145,942,943],{},"Banco Central do Brasil (BCB)",[145,945,946],{},"Authorization as a Sociedade Prestadora de Serviços de Ativos Virtuais (SPSAV) under Resolutions 519, 520, and 521 of 2025, with AML reporting to the Conselho de Controle de Atividades Financeiras (COAF)",[127,948,949,952,955],{},[145,950,951],{},"Japan",[145,953,954],{},"Financial Services Agency (FSA)",[145,956,957],{},"Registration under the revised Payment Services Act, with stablecoin issuance limited to banks, trust companies, and licensed funds transfer providers",[11,959,960],{},"The pattern is consistent: the activity is regulated everywhere, but the regulator, the threshold, and the data format differ. A compliance program that hardcodes one market's assumptions will fail an examination in another.",[28,962,964],{"id":963},"what-does-the-fatf-travel-rule-require-for-stablecoin-payments","What does the FATF Travel Rule require for stablecoin payments?",[11,966,967],{},"The Financial Action Task Force (FATF) is the intergovernmental body that sets global AML standards. Its Recommendation 16, known as the Travel Rule, requires that originator and beneficiary information accompany a funds transfer so that each institution in the chain can screen the parties and respond to law enforcement requests.",[11,969,970],{},"In June 2019, FATF extended the Travel Rule to virtual assets and Virtual Asset Service Providers (VASPs) through an interpretive note to Recommendation 15. Stablecoins are virtual assets under that standard, so a USDC transfer between two VASPs carries the same data obligation as a wire transfer between two banks.",[11,972,973],{},"The required data set is the originator's name, account or wallet identifier, and one of address, national identity number, or date and place of birth, plus the beneficiary's name and account or wallet identifier. FATF recommends a USD or EUR 1,000 threshold, but each country sets its own.",[11,975,976],{},"Thresholds and formats diverge by market. The EU's Transfer of Funds Regulation applies with no minimum since December 30, 2024. The US applies the Bank Secrecy Act Travel Rule at USD 3,000. Singapore's threshold is SGD 1,500. The UK applies the rule to all transfers, with a reduced data set below EUR 1,000.",[11,978,979],{},"The Travel Rule matters for stablecoins specifically because a blockchain transfer carries no identity data by default. The information must move through a separate channel between the two VASPs, matched to the on-chain transaction, and the compliance layer has to do that matching before the payment is treated as complete.",[28,981,983],{"id":982},"how-does-sanctions-screening-work-for-cross-border-usdc-payments","How does sanctions screening work for cross-border USDC payments?",[11,985,986],{},"Sanctions screening checks every party to a payment against the lists maintained by the sanctioning authorities in the jurisdictions involved. For a cross-border USDC payment, that means screening the sender, the receiver, any beneficial owners, and the wallet addresses on both sides.",[11,988,989],{},"The core lists are the OFAC Specially Designated Nationals (SDN) and consolidated lists in the US, the EU consolidated sanctions list, the United Nations (UN) Security Council consolidated list, and the UK OFSI consolidated list. A payment from a US entity to a Brazilian receiver over EU rails must clear all of them, not just the sender's.",[11,991,992],{},"OFAC compliance is strict liability. A payment that reaches a sanctioned party is a violation regardless of intent, which is why screening runs before funds move and again when lists update, not only at onboarding.",[11,994,995],{},"Wallet address screening is the piece that has no analog in bank payments. OFAC has added blockchain addresses to the SDN list since 2018, and a compliance layer must screen the destination address against those entries and against analytics that flag exposure to sanctioned or illicit sources.",[28,997,999],{"id":998},"how-do-you-comply-with-regulations-across-multiple-jurisdictions-without-rebuilding-per-market","How do you comply with regulations across multiple jurisdictions without rebuilding per market?",[11,1001,1002],{},"Multi-jurisdictional compliance for crypto payments comes down to one architectural decision: whether jurisdiction-specific rules live in the payment application or in a compliance layer beneath it. The first approach means one codebase change per market per regulatory update. The second means the rules are data, selected at runtime by transaction context.",[11,1004,1005],{},"In a rule-set model, each jurisdiction has a definition of its licensing scope, Travel Rule threshold and data format, sanctions lists, reporting triggers, and receiver verification requirements. The agent loads the definitions for the sender's and receiver's jurisdictions and applies the stricter requirement wherever they conflict.",[11,1007,1008],{},"Regulatory updates then land in the rule set, not in customer code. When a threshold changes or a list is amended, the provider updates the definition once and every payment evaluated after that point uses it.",[11,1010,1011,1012,293],{},"This is how BlindPay's compliance layer is built. Rule sets are maintained for the regimes described in this guide, including FinCEN, MiCA and AMLD, FCA, MAS, and BCB requirements, and customers inherit updates without code changes. Entity and license details by market are published on the ",[48,1013,1015],{"href":1014},"\u002Flicenses","licenses page",[28,1017,1019],{"id":1018},"what-are-the-4-structural-components-of-a-compliant-stablecoin-payment-program","What are the 4 structural components of a compliant stablecoin payment program?",[11,1021,1022],{},"A compliant stablecoin payment program has four structural components. Regulators in every major market examine all four, and a gap in any one is a finding.",[75,1024,1026],{"id":1025},"_1-licensing-and-registration","1. Licensing and registration",[11,1028,1029,1030,1034],{},"The entity performing the regulated activity must hold the authorization the jurisdiction requires: MSB registration and state licenses in the US, CASP authorization in the EU, FCA registration in the UK, a DPT license in Singapore, SPSAV authorization in Brazil. A business that builds on a licensed provider does not need these itself, but it must confirm the provider holds them for each market it serves. Our ",[48,1031,1033],{"href":1032},"\u002Fresources\u002Fmore\u002Fwhat-is-a-vasp","VASP explainer"," covers who falls inside the licensing perimeter.",[75,1036,1038],{"id":1037},"_2-customer-due-diligence","2. Customer due diligence",[11,1040,1041,1042,1045],{},"Know Your Customer (KYC) on individuals and ",[48,1043,1044],{"href":569},"Know Your Business (KYB)"," on companies establish who the sender and receiver are before money moves. Due diligence includes identity verification, beneficial ownership, politically exposed person (PEP) checks, and risk rating, with enhanced due diligence on higher-risk relationships.",[75,1047,1049],{"id":1048},"_3-transaction-controls","3. Transaction controls",[11,1051,1052],{},"Transaction controls are the checks that run on every payment: sanctions screening across all applicable lists, Travel Rule data exchange, wallet address analytics, and monitoring for patterns that indicate structuring or layering. These controls are where a compliance agent does most of its work, and they must complete before settlement, not after.",[75,1054,1056],{"id":1055},"_4-reporting-and-recordkeeping","4. Reporting and recordkeeping",[11,1058,1059],{},"Each jurisdiction requires suspicious activity reports to its financial intelligence unit: FinCEN in the US, national units under AMLD in the EU, the National Crime Agency in the UK, the Suspicious Transaction Reporting Office in Singapore, and COAF in Brazil. Records of due diligence, screening results, and Travel Rule exchanges must be retained for the period each regulator sets, typically five years or more.",[28,1061,1063],{"id":1062},"what-questions-should-you-ask-before-choosing-a-compliance-provider","What questions should you ask before choosing a compliance provider?",[11,1065,1066],{},"The questions below separate providers that hold compliance infrastructure from providers that hold a compliance vendor contract. Ask each one for every market you plan to serve.",[723,1068,1069,1072,1075,1078,1081,1084,1087,1090],{},[229,1070,1071],{},"Which entity holds the license or registration in each of my target markets, and can you show the public register entry?",[229,1073,1074],{},"How does the compliance layer determine which jurisdiction's rules apply to a given transaction, and what happens when the sender's and receiver's rules conflict?",[229,1076,1077],{},"Which sanctions lists are screened on every payment, how often are they refreshed, and are wallet addresses screened as well as named parties?",[229,1079,1080],{},"How is Travel Rule data exchanged with the counterparty VASP, and what happens when the counterparty cannot receive it?",[229,1082,1083],{},"When a regulator changes a threshold or a data requirement, what changes on my side?",[229,1085,1086],{},"Where does the compliance decision sit in the payment flow: before funds move, or as a post-settlement review?",[229,1088,1089],{},"What records are retained, for how long, and how do I retrieve them for an audit or regulatory request?",[229,1091,1092],{},"Which suspicious activity reporting obligations does the provider carry, and which remain mine?",[11,1094,1095],{},"A provider that answers these with references to its own registrations and rule sets is holding infrastructure. A provider that answers by naming a third-party vendor for each question is passing the integration and the regulatory risk back to you.",[28,1097,1099],{"id":1098},"what-should-a-stablecoin-payment-company-do-next","What should a stablecoin payment company do next?",[11,1101,1102],{},"Cross-border stablecoin payments are regulated in every major market, and the requirements converge on the same four components: licensing, customer due diligence, transaction controls, and reporting. The details diverge by jurisdiction, which is why compliance logic belongs in a rule-set layer that selects the right requirements at runtime rather than in application code rewritten per market.",[11,1104,1105,1106,1108,1109,1113,1114,293],{},"BlindPay provides cross-border stablecoin payment infrastructure with that compliance layer built in: jurisdiction-specific rule sets applied by transaction context, multi-list sanctions screening across OFAC, EU, UN, and UK lists, Travel Rule data exchange inside the payment flow, and regulatory updates applied at the infrastructure level. Receivers get local currency over Pix, SPEI, ACH, or SWIFT (POBO\u002FCOBO) after the checks clear. The compliance program is described on the ",[48,1107,287],{"href":286},", and the team can walk through jurisdiction-specific questions via ",[48,1110,1112],{"href":1111},"\u002Fcontact","contact"," at ",[48,1115,1118],{"href":1116,"rel":1117},"https:\u002F\u002Fblindpay.com",[422],"blindpay.com",[11,1120,1121],{},[14,1122,305],{},{"title":307,"searchDepth":308,"depth":308,"links":1124},[1125,1126,1127,1128,1129,1130,1136,1137],{"id":854,"depth":308,"text":855},{"id":867,"depth":308,"text":868},{"id":963,"depth":308,"text":964},{"id":982,"depth":308,"text":983},{"id":998,"depth":308,"text":999},{"id":1018,"depth":308,"text":1019,"children":1131},[1132,1133,1134,1135],{"id":1025,"depth":314,"text":1026},{"id":1037,"depth":314,"text":1038},{"id":1048,"depth":314,"text":1049},{"id":1055,"depth":314,"text":1056},{"id":1062,"depth":308,"text":1063},{"id":1098,"depth":308,"text":1099},"2026-09-04","How compliance agents apply FinCEN, MiCA, FCA, MAS, and Banco Central do Brasil rules to cross-border stablecoin payments: jurisdiction table, the FATF Travel Rule, multi-list sanctions screening, the four components of a compliant program, and questions to ask a compliance provider.",[1141,1144,1147,1150,1153,1156],{"q":1142,"a":1143},"Does the FATF Travel Rule apply to stablecoin payments?","Yes. FATF extended Recommendation 16 to virtual assets in 2019, and stablecoins are virtual assets under that standard. Any transfer between two virtual asset service providers must carry originator and beneficiary information, subject to each country's threshold.",{"q":1145,"a":1146},"What is the Travel Rule threshold for stablecoin transfers?","FATF recommends a threshold of USD or EUR 1,000, but countries set their own. The EU applies the rule with no minimum, the US uses USD 3,000 under the Bank Secrecy Act, Singapore uses SGD 1,500, and the UK applies it to all transfers with reduced data below EUR 1,000.",{"q":1148,"a":1149},"Which sanctions lists should a cross-border USDC payment be screened against?","At minimum the OFAC Specially Designated Nationals list, the EU consolidated sanctions list, the UN Security Council consolidated list, and the UK OFSI consolidated list. The set expands with each market served, and the wallet address itself should be screened, not just the named parties.",{"q":1151,"a":1152},"Do I need a license in every country where I send stablecoin payments?","Not if a licensed provider performs the regulated activity in that country. The provider carries registration, custody, and reporting obligations, and you remain responsible for giving it accurate customer and payment data.",{"q":1154,"a":1155},"What is a compliance agent in stablecoin payments?","A compliance agent is an automated component that evaluates a transaction against the rules of the jurisdictions involved and decides whether it proceeds, holds for review, or is rejected. It replaces per-country compliance code with a rule set selected at runtime.",{"q":1157,"a":1158},"How do regulatory updates reach a payment company using embedded compliance?","The provider updates the rule set at the infrastructure level and every customer inherits the change on the next transaction. No customer code changes, redeploys, or per-market patches are required.",{"author":342},"---\ntitle: \"Compliance agents for cross-border stablecoin payments: a global regulatory guide\"\ndescription: \"How compliance agents apply FinCEN, MiCA, FCA, MAS, and Banco Central do Brasil rules to cross-border stablecoin payments: jurisdiction table, the FATF Travel Rule, multi-list sanctions screening, the four components of a compliant program, and questions to ask a compliance provider.\"\ndate: \"2026-09-04\"\nupdated: \"2026-09-04\"\nauthor: \"BlindPay Team\"\ncategory: \"compliance\"\nfaq:\n  - q: \"Does the FATF Travel Rule apply to stablecoin payments?\"\n    a: \"Yes. FATF extended Recommendation 16 to virtual assets in 2019, and stablecoins are virtual assets under that standard. Any transfer between two virtual asset service providers must carry originator and beneficiary information, subject to each country's threshold.\"\n  - q: \"What is the Travel Rule threshold for stablecoin transfers?\"\n    a: \"FATF recommends a threshold of USD or EUR 1,000, but countries set their own. The EU applies the rule with no minimum, the US uses USD 3,000 under the Bank Secrecy Act, Singapore uses SGD 1,500, and the UK applies it to all transfers with reduced data below EUR 1,000.\"\n  - q: \"Which sanctions lists should a cross-border USDC payment be screened against?\"\n    a: \"At minimum the OFAC Specially Designated Nationals list, the EU consolidated sanctions list, the UN Security Council consolidated list, and the UK OFSI consolidated list. The set expands with each market served, and the wallet address itself should be screened, not just the named parties.\"\n  - q: \"Do I need a license in every country where I send stablecoin payments?\"\n    a: \"Not if a licensed provider performs the regulated activity in that country. The provider carries registration, custody, and reporting obligations, and you remain responsible for giving it accurate customer and payment data.\"\n  - q: \"What is a compliance agent in stablecoin payments?\"\n    a: \"A compliance agent is an automated component that evaluates a transaction against the rules of the jurisdictions involved and decides whether it proceeds, holds for review, or is rejected. It replaces per-country compliance code with a rule set selected at runtime.\"\n  - q: \"How do regulatory updates reach a payment company using embedded compliance?\"\n    a: \"The provider updates the rule set at the infrastructure level and every customer inherits the change on the next transaction. No customer code changes, redeploys, or per-market patches are required.\"\n---\n\n*Reading time: about 8 minutes.*\n\n**Summary:** Compliance agents handle cross-border stablecoin payment regulation by reading the context of each transaction, selecting the rule set for the jurisdictions involved, and running identity checks, sanctions screening, Travel Rule data exchange, and reporting before funds settle. The rules are maintained at the infrastructure level, so a business does not rebuild its compliance stack for every new market.\n\nCross-border stablecoin payments touch at least two regulatory regimes on every transfer: the sender's and the receiver's. Each regime has its own licensing body, sanctions authority, data-sharing threshold, and reporting obligation. This guide sets out what those regimes require and how a compliance layer can satisfy them without per-country engineering.\n\n## How do compliance agents handle cross-border stablecoin payment regulation?\n\nA compliance agent is an automated component that sits in the payment flow and evaluates each transaction against the rules that apply to it. It reads the transaction context, meaning the sender's jurisdiction, the receiver's jurisdiction, the counterparty type, the asset, and the amount, and then selects the matching rule set.\n\nThe agent then runs the checks that rule set requires: customer verification status, sanctions screening across the relevant lists, Travel Rule data exchange with the counterparty institution, and threshold-based reporting. The transaction proceeds, holds for review, or is rejected based on the result.\n\nThe alternative is writing compliance logic per market inside the payment application. That approach works for one or two corridors and breaks when the third market has a different threshold, a different data format, or a different regulator.\n\n## What are the global regulatory requirements for stablecoin transfers?\n\nEvery major market now regulates stablecoin transfers through a licensing regime for the intermediary and an anti-money laundering (AML) regime for the transaction. The licensing regime decides who may operate; the AML regime decides what each transfer must carry and when it must be reported.\n\nThe table below summarizes the primary requirement in six markets relevant to cross-border stablecoin payments.\n\n| Jurisdiction | Regulatory body | Primary requirement |\n|---|---|---|\n| United States | Financial Crimes Enforcement Network (FinCEN), with state money transmitter regulators | Money Services Business (MSB) registration under the Bank Secrecy Act (BSA), an AML program, Travel Rule compliance at USD 3,000, and strict-liability sanctions compliance under the Office of Foreign Assets Control (OFAC) |\n| European Union | National competent authorities under the Markets in Crypto-Assets Regulation (MiCA), with the Anti-Money Laundering Directives (AMLD) | Crypto-Asset Service Provider (CASP) authorization, Travel Rule under the Transfer of Funds Regulation (TFR) with no minimum threshold, and use of MiCA-compliant e-money tokens |\n| United Kingdom | Financial Conduct Authority (FCA) | Cryptoasset registration under the Money Laundering Regulations (MLRs), Travel Rule compliance in force since September 2023, and sanctions compliance under the Office of Financial Sanctions Implementation (OFSI) |\n| Singapore | Monetary Authority of Singapore (MAS) | Digital Payment Token (DPT) service license under the Payment Services Act (PSA), with AML and Travel Rule obligations under MAS Notice PSN02 at SGD 1,500 |\n| Brazil | Banco Central do Brasil (BCB) | Authorization as a Sociedade Prestadora de Serviços de Ativos Virtuais (SPSAV) under Resolutions 519, 520, and 521 of 2025, with AML reporting to the Conselho de Controle de Atividades Financeiras (COAF) |\n| Japan | Financial Services Agency (FSA) | Registration under the revised Payment Services Act, with stablecoin issuance limited to banks, trust companies, and licensed funds transfer providers |\n\nThe pattern is consistent: the activity is regulated everywhere, but the regulator, the threshold, and the data format differ. A compliance program that hardcodes one market's assumptions will fail an examination in another.\n\n## What does the FATF Travel Rule require for stablecoin payments?\n\nThe Financial Action Task Force (FATF) is the intergovernmental body that sets global AML standards. Its Recommendation 16, known as the Travel Rule, requires that originator and beneficiary information accompany a funds transfer so that each institution in the chain can screen the parties and respond to law enforcement requests.\n\nIn June 2019, FATF extended the Travel Rule to virtual assets and Virtual Asset Service Providers (VASPs) through an interpretive note to Recommendation 15. Stablecoins are virtual assets under that standard, so a USDC transfer between two VASPs carries the same data obligation as a wire transfer between two banks.\n\nThe required data set is the originator's name, account or wallet identifier, and one of address, national identity number, or date and place of birth, plus the beneficiary's name and account or wallet identifier. FATF recommends a USD or EUR 1,000 threshold, but each country sets its own.\n\nThresholds and formats diverge by market. The EU's Transfer of Funds Regulation applies with no minimum since December 30, 2024. The US applies the Bank Secrecy Act Travel Rule at USD 3,000. Singapore's threshold is SGD 1,500. The UK applies the rule to all transfers, with a reduced data set below EUR 1,000.\n\nThe Travel Rule matters for stablecoins specifically because a blockchain transfer carries no identity data by default. The information must move through a separate channel between the two VASPs, matched to the on-chain transaction, and the compliance layer has to do that matching before the payment is treated as complete.\n\n## How does sanctions screening work for cross-border USDC payments?\n\nSanctions screening checks every party to a payment against the lists maintained by the sanctioning authorities in the jurisdictions involved. For a cross-border USDC payment, that means screening the sender, the receiver, any beneficial owners, and the wallet addresses on both sides.\n\nThe core lists are the OFAC Specially Designated Nationals (SDN) and consolidated lists in the US, the EU consolidated sanctions list, the United Nations (UN) Security Council consolidated list, and the UK OFSI consolidated list. A payment from a US entity to a Brazilian receiver over EU rails must clear all of them, not just the sender's.\n\nOFAC compliance is strict liability. A payment that reaches a sanctioned party is a violation regardless of intent, which is why screening runs before funds move and again when lists update, not only at onboarding.\n\nWallet address screening is the piece that has no analog in bank payments. OFAC has added blockchain addresses to the SDN list since 2018, and a compliance layer must screen the destination address against those entries and against analytics that flag exposure to sanctioned or illicit sources.\n\n## How do you comply with regulations across multiple jurisdictions without rebuilding per market?\n\nMulti-jurisdictional compliance for crypto payments comes down to one architectural decision: whether jurisdiction-specific rules live in the payment application or in a compliance layer beneath it. The first approach means one codebase change per market per regulatory update. The second means the rules are data, selected at runtime by transaction context.\n\nIn a rule-set model, each jurisdiction has a definition of its licensing scope, Travel Rule threshold and data format, sanctions lists, reporting triggers, and receiver verification requirements. The agent loads the definitions for the sender's and receiver's jurisdictions and applies the stricter requirement wherever they conflict.\n\nRegulatory updates then land in the rule set, not in customer code. When a threshold changes or a list is amended, the provider updates the definition once and every payment evaluated after that point uses it.\n\nThis is how BlindPay's compliance layer is built. Rule sets are maintained for the regimes described in this guide, including FinCEN, MiCA and AMLD, FCA, MAS, and BCB requirements, and customers inherit updates without code changes. Entity and license details by market are published on the [licenses page](\u002Flicenses).\n\n## What are the 4 structural components of a compliant stablecoin payment program?\n\nA compliant stablecoin payment program has four structural components. Regulators in every major market examine all four, and a gap in any one is a finding.\n\n### 1. Licensing and registration\n\nThe entity performing the regulated activity must hold the authorization the jurisdiction requires: MSB registration and state licenses in the US, CASP authorization in the EU, FCA registration in the UK, a DPT license in Singapore, SPSAV authorization in Brazil. A business that builds on a licensed provider does not need these itself, but it must confirm the provider holds them for each market it serves. Our [VASP explainer](\u002Fresources\u002Fmore\u002Fwhat-is-a-vasp) covers who falls inside the licensing perimeter.\n\n### 2. Customer due diligence\n\nKnow Your Customer (KYC) on individuals and [Know Your Business (KYB)](\u002Fresources\u002Fmore\u002Fwhat-is-kyb) on companies establish who the sender and receiver are before money moves. Due diligence includes identity verification, beneficial ownership, politically exposed person (PEP) checks, and risk rating, with enhanced due diligence on higher-risk relationships.\n\n### 3. Transaction controls\n\nTransaction controls are the checks that run on every payment: sanctions screening across all applicable lists, Travel Rule data exchange, wallet address analytics, and monitoring for patterns that indicate structuring or layering. These controls are where a compliance agent does most of its work, and they must complete before settlement, not after.\n\n### 4. Reporting and recordkeeping\n\nEach jurisdiction requires suspicious activity reports to its financial intelligence unit: FinCEN in the US, national units under AMLD in the EU, the National Crime Agency in the UK, the Suspicious Transaction Reporting Office in Singapore, and COAF in Brazil. Records of due diligence, screening results, and Travel Rule exchanges must be retained for the period each regulator sets, typically five years or more.\n\n## What questions should you ask before choosing a compliance provider?\n\nThe questions below separate providers that hold compliance infrastructure from providers that hold a compliance vendor contract. Ask each one for every market you plan to serve.\n\n- Which entity holds the license or registration in each of my target markets, and can you show the public register entry?\n- How does the compliance layer determine which jurisdiction's rules apply to a given transaction, and what happens when the sender's and receiver's rules conflict?\n- Which sanctions lists are screened on every payment, how often are they refreshed, and are wallet addresses screened as well as named parties?\n- How is Travel Rule data exchanged with the counterparty VASP, and what happens when the counterparty cannot receive it?\n- When a regulator changes a threshold or a data requirement, what changes on my side?\n- Where does the compliance decision sit in the payment flow: before funds move, or as a post-settlement review?\n- What records are retained, for how long, and how do I retrieve them for an audit or regulatory request?\n- Which suspicious activity reporting obligations does the provider carry, and which remain mine?\n\nA provider that answers these with references to its own registrations and rule sets is holding infrastructure. A provider that answers by naming a third-party vendor for each question is passing the integration and the regulatory risk back to you.\n\n## What should a stablecoin payment company do next?\n\nCross-border stablecoin payments are regulated in every major market, and the requirements converge on the same four components: licensing, customer due diligence, transaction controls, and reporting. The details diverge by jurisdiction, which is why compliance logic belongs in a rule-set layer that selects the right requirements at runtime rather than in application code rewritten per market.\n\nBlindPay provides cross-border stablecoin payment infrastructure with that compliance layer built in: jurisdiction-specific rule sets applied by transaction context, multi-list sanctions screening across OFAC, EU, UN, and UK lists, Travel Rule data exchange inside the payment flow, and regulatory updates applied at the infrastructure level. Receivers get local currency over Pix, SPEI, ACH, or SWIFT (POBO\u002FCOBO) after the checks clear. The compliance program is described on the [compliance page](\u002Fcompliance), and the team can walk through jurisdiction-specific questions via [contact](\u002Fcontact) at [blindpay.com](https:\u002F\u002Fblindpay.com).\n\n*This article is for general information only and is not legal, tax, or financial advice.*\n",{"title":836,"description":1139},"resources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments","V8KQxgiB7Lc7lGBz9igyCt4xP74wDgsIrkkA9O9BJg4",{"id":1165,"title":1166,"authors":6,"body":1167,"categories":6,"category":323,"categoryType":6,"compare":6,"contributors":6,"date":1572,"description":1573,"extension":326,"faq":1574,"howto":6,"isBlog":340,"isChangelog":340,"meta":1587,"navigation":343,"path":594,"pillar":340,"products":6,"rawbody":1588,"role":6,"seo":1589,"stem":1590,"thumbnail":6,"updated":1572,"__hash__":1591},"content\u002Fresources\u002Fmore\u002Fhow-to-automate-kyc-kyb-stablecoin-payments.md","How to automate KYC and KYB for stablecoin payments",{"type":8,"value":1168,"toc":1560},[1169,1173,1178,1181,1185,1188,1191,1197,1201,1204,1248,1251,1255,1258,1302,1305,1309,1312,1344,1352,1356,1359,1424,1436,1440,1443,1446,1449,1453,1456,1459,1463,1466,1497,1501,1506,1512,1518,1524,1530,1536,1540,1543,1556],[11,1170,1171],{},[14,1172,843],{},[11,1174,1175,1177],{},[20,1176,22],{}," You automate KYC and KYB for stablecoin payments by making verification a step in the payment API itself. Create a receiver with identity or entity data, let automated KYC run document checks, sanctions screening, and risk scoring, receive the result by webhook, and only allow payouts once the receiver status is approved.",[11,1179,1180],{},"KYC automation matters for stablecoin companies because a payout on a public blockchain cannot be reversed. Every check has to finish before funds move, and manual review does not scale past a few hundred receivers.",[28,1182,1184],{"id":1183},"what-is-the-difference-between-kyc-and-kyb-for-stablecoin-payments","What is the difference between KYC and KYB for stablecoin payments?",[11,1186,1187],{},"KYC, Know Your Customer, verifies an individual person. It confirms that a government ID is authentic, that the person presenting it is real and present, and that they are not on a sanctions or watch list.",[11,1189,1190],{},"KYB, Know Your Business, verifies a business entity. It confirms the company is registered and active, maps who owns and controls it, and then runs KYC on each of those individuals.",[11,1192,1193,1194,1196],{},"The split maps onto who you pay. Contractors and remittance recipients need KYC. Vendors, marketplaces, and corporate customers need KYB, which always includes KYC on their owners. The ",[48,1195,570],{"href":569}," covers beneficial ownership rules in detail.",[28,1198,1200],{"id":1199},"how-does-automated-kyc-work-for-stablecoin-users","How does automated KYC work for stablecoin users?",[11,1202,1203],{},"Automated KYC replaces an analyst reviewing a PDF with a pipeline of machine checks that return a decision and an audit trail.",[226,1205,1206,1212,1218,1224,1230,1236,1242],{},[229,1207,1208,1211],{},[20,1209,1210],{},"Data collection."," Your app collects name, date of birth, address, tax ID, and ID document images, then sends them in one API request that creates the receiver.",[229,1213,1214,1217],{},[20,1215,1216],{},"Document verification."," The system extracts fields from the document, checks security features and expiry, and compares the extracted data against what the user typed.",[229,1219,1220,1223],{},[20,1221,1222],{},"Liveness and face match."," A selfie or short video is checked for presentation attacks, then matched against the document photo.",[229,1225,1226,1229],{},[20,1227,1228],{},"Sanctions and PEP screening."," The name, date of birth, and country are screened against OFAC, EU, UK, UN, and local lists, plus politically exposed person databases.",[229,1231,1232,1235],{},[20,1233,1234],{},"Risk scoring."," Country, document type, IP geolocation, and screening results combine into a risk tier that decides between auto-approval and manual review.",[229,1237,1238,1241],{},[20,1239,1240],{},"Decision and webhook."," The receiver status becomes approved, rejected, or verifying, and your backend receives a webhook so it can unlock or block payouts.",[229,1243,1244,1247],{},[20,1245,1246],{},"Audit logging."," Every input, check result, and decision is stored with timestamps so a regulator or bank partner can reconstruct the case.",[11,1249,1250],{},"A clean case clears all seven stages in under a minute. A name mismatch or screening hit stops at stage five for a human decision.",[28,1252,1254],{"id":1253},"how-does-kyb-automation-work-for-business-receivers","How does KYB automation work for business receivers?",[11,1256,1257],{},"KYB automation follows the same shape but adds an entity layer before the individual checks. Ownership tracing is the hard part, because it has to end at real people.",[226,1259,1260,1266,1272,1278,1284,1290,1296],{},[229,1261,1262,1265],{},[20,1263,1264],{},"Entity data collection."," Collect legal name, registration number, tax ID, incorporation date, registered address, business type, and industry, plus the incorporation document.",[229,1267,1268,1271],{},[20,1269,1270],{},"Registry verification."," The registration number is checked against the jurisdiction's corporate registry to confirm the entity exists, is active, and matches the stated name and address.",[229,1273,1274,1277],{},[20,1275,1276],{},"Ownership mapping."," The ownership structure is unwound through holding companies until every individual with 25 percent or more, or with control, is identified.",[229,1279,1280,1283],{},[20,1281,1282],{},"Beneficial owner KYC."," Each identified owner and controller goes through the full individual KYC flow described above.",[229,1285,1286,1289],{},[20,1287,1288],{},"Entity screening."," The company name and its owners are screened against sanctions lists, adverse media, and industry restrictions.",[229,1291,1292,1295],{},[20,1293,1294],{},"Risk scoring and decision."," Entity type, industry, jurisdiction, and owner results combine into a tier. High-risk industries or complex ownership route to enhanced due diligence.",[229,1297,1298,1301],{},[20,1299,1300],{},"Decision and monitoring."," The business receiver is approved or rejected, and the record is re-screened on a schedule and on every payout.",[11,1303,1304],{},"Registry availability sets the speed. A US LLC or UK Ltd clears in minutes, while an entity in a paper-registry jurisdiction can take days.",[28,1306,1308],{"id":1307},"how-do-you-integrate-kyc-compliance-into-a-stablecoin-payment-api","How do you integrate KYC compliance into a stablecoin payment API?",[11,1310,1311],{},"The integration pattern that works at scale treats verification as a state machine on the receiver record, not as a separate system you poll.",[226,1313,1314,1320,1326,1332,1338],{},[229,1315,1316,1319],{},[20,1317,1318],{},"Create the receiver."," Call the receivers endpoint with the KYC type, individual or business, and the collected data. The record is created with status verifying.",[229,1321,1322,1325],{},[20,1323,1324],{},"Subscribe to status webhooks."," Register a webhook for receiver status changes so your backend learns about approval or rejection without polling.",[229,1327,1328,1331],{},[20,1329,1330],{},"Gate payouts on status."," Your payout code checks that the receiver is approved before creating a quote. The API enforces this too, so a race cannot slip a payout through.",[229,1333,1334,1337],{},[20,1335,1336],{},"Handle rejection and resubmission."," Surface the rejection reason to the user, collect corrected documents, and update the receiver to trigger a new verification run.",[229,1339,1340,1343],{},[20,1341,1342],{},"Store the receiver ID, not the documents."," Keep the provider's receiver ID in your database and let the provider hold documents and audit logs.",[11,1345,1346,1347,1351],{},"With BlindPay, these steps use the same REST API and API key as quotes and payouts. The ",[48,1348,1350],{"href":1349},"\u002Fdocs\u002Fapi\u002Freference","OpenAPI specification"," describes the receiver schema, status values, and webhook payloads, so client code can be generated rather than hand-written.",[28,1353,1355],{"id":1354},"which-jurisdictions-have-specific-kyc-and-kyb-requirements-for-stablecoin-payments","Which jurisdictions have specific KYC and KYB requirements for stablecoin payments?",[11,1357,1358],{},"Requirements differ by country in thresholds, beneficial ownership definitions, and the licensing regulator. A multi-corridor provider needs a rule set per jurisdiction, applied automatically from the receiver country.",[121,1360,1361,1372],{},[124,1362,1363],{},[127,1364,1365,1367,1369],{},[130,1366,883],{},[130,1368,886],{},[130,1370,1371],{},"Primary KYC\u002FKYB requirements",[140,1373,1374,1384,1394,1404,1414],{},[127,1375,1376,1378,1381],{},[145,1377,896],{},[145,1379,1380],{},"FinCEN, state regulators",[145,1382,1383],{},"Customer Identification Program, beneficial ownership at 25 percent plus control prong under 31 CFR 1010.230, OFAC screening, SAR filing",[127,1385,1386,1388,1391],{},[145,1387,907],{},[145,1389,1390],{},"National competent authorities under AMLD and MiCA",[145,1392,1393],{},"Customer due diligence, beneficial ownership at 25 percent, travel rule under the Transfer of Funds Regulation, CASP licensing under MiCA",[127,1395,1396,1398,1401],{},[145,1397,918],{},[145,1399,1400],{},"FCA",[145,1402,1403],{},"Money Laundering Regulations 2017, cryptoasset firm registration, PSC register checks for beneficial owners, travel rule since September 2023",[127,1405,1406,1408,1411],{},[145,1407,929],{},[145,1409,1410],{},"MAS",[145,1412,1413],{},"Payment Services Act licensing, MAS Notice PSN02 customer due diligence, travel rule for digital payment token transfers",[127,1415,1416,1418,1421],{},[145,1417,940],{},[145,1419,1420],{},"Banco Central do Brasil, Receita Federal",[145,1422,1423],{},"CPF and CNPJ validation, name and tax ID matching on Pix, PSAV registration for virtual asset providers, Circular 3978 AML controls",[11,1425,1426,1427,1430,1431,1435],{},"The ",[48,1428,1429],{"href":408},"regulation tracker"," and ",[48,1432,1434],{"href":1433},"\u002Fresources\u002Fmore\u002Fmica-stablecoin-rules-explained","MiCA explainer"," go deeper on EU and Brazil rules.",[28,1437,1439],{"id":1438},"why-should-compliance-checks-run-before-settlement-instead-of-after","Why should compliance checks run before settlement instead of after?",[11,1441,1442],{},"On a card or ACH network, a payment flagged after the fact can be reversed. A stablecoin transfer on a public chain is final once confirmed, so a check that runs after settlement is a report, not a control.",[11,1444,1445],{},"Verification before the payout is created means a sanctions hit or failed document check blocks the transaction at zero cost. After settlement, the funds are already in a wallet you do not control.",[11,1447,1448],{},"BlindPay runs KYC, KYB, and per-payout sanctions screening before any quote is executed. A receiver that is not approved cannot receive a payout, and a payout that fails screening is rejected before funds move.",[28,1450,1452],{"id":1451},"can-a-stablecoin-company-reuse-kyc-it-already-performs","Can a stablecoin company reuse KYC it already performs?",[11,1454,1455],{},"Partly. A fintech with its own onboarding program can pass verified data through the payment API instead of running users through a second document flow, once the provider has reviewed that program against its own standard.",[11,1457,1458],{},"BlindPay applies this as a reliance model. Onboarding, fraud checks, and limit increase reviews can be relied upon after a review of the partner's policies, while transaction monitoring on every payout always runs on BlindPay's side. All customer data still flows through the API, and BlindPay keeps the right to inspect any partner check.",[28,1460,1462],{"id":1461},"what-should-developers-check-when-choosing-automated-identity-verification-for-a-stablecoin-company","What should developers check when choosing automated identity verification for a stablecoin company?",[11,1464,1465],{},"The decision comes down to whether verification is part of the payment flow or bolted on beside it. A separate KYC vendor means a second contract, a second SDK, and a sync problem between verification state and payout permission.",[723,1467,1468,1474,1480,1486],{},[229,1469,1470,1473],{},[20,1471,1472],{},"Single API surface."," Verification and payouts should share one authentication scheme, one webhook system, and one set of IDs.",[229,1475,1476,1479],{},[20,1477,1478],{},"Enforcement at the payout layer."," The API itself should refuse a payout to an unverified receiver, not just return a status your code has to remember to check.",[229,1481,1482,1485],{},[20,1483,1484],{},"Jurisdiction coverage."," Confirm the provider applies the right rules for every country you pay into, including local tax ID formats and name matching rules.",[229,1487,1488,1491,1492,1496],{},[20,1489,1490],{},"Sandbox parity."," The ",[48,1493,1495],{"href":1494},"\u002Fresources\u002Fmore\u002Fstablecoin-api-sandbox-vs-production","sandbox"," should return realistic verification states, including rejected and verifying, so every branch is tested before go-live.",[28,1498,1500],{"id":1499},"faq","FAQ",[11,1502,1503,1505],{},[20,1504,557],{},"\nKYC verifies an individual person: identity document, liveness, address, and sanctions screening. KYB verifies a business entity: registration, good standing, ownership structure, and then KYC on each beneficial owner and controller. A business account needs both.",[11,1507,1508,1511],{},[20,1509,1510],{},"Can KYC for stablecoin payments be fully automated?","\nFor most users, yes. Document extraction, face matching, sanctions screening, and risk scoring run without a human, and a clean case is approved in seconds to minutes. A small share of cases with mismatched data or screening hits still goes to manual review.",[11,1513,1514,1517],{},[20,1515,1516],{},"Do I need a separate KYC vendor if I use a stablecoin payment API?","\nNot if the payment API includes verification. BlindPay runs KYC and KYB through the same REST API used to create payouts, so there is no second vendor contract, SDK, or webhook pipeline to maintain.",[11,1519,1520,1523],{},[20,1521,1522],{},"What happens if a user fails automated KYC?","\nThe receiver record moves to a rejected status and no payout can be created for it. Your app should show the reason category returned by the API and, where allowed, offer a resubmission path with corrected documents.",[11,1525,1526,1529],{},[20,1527,1528],{},"How long does automated KYB take for a business?","\nMinutes to same day when registry data is available and ownership is simple. Entities with layered holding companies, trusts, or non-digitized registries can take several days because ownership must be traced to real people.",[11,1531,1532,1535],{},[20,1533,1534],{},"Does KYC need to run before every stablecoin payout?","\nVerification runs once per receiver, not per transaction. Sanctions screening and risk checks then run on each payout against the verified record, and the payout is blocked before settlement if anything changed.",[28,1537,1539],{"id":1538},"how-does-blindpay-fit-in","How does BlindPay fit in?",[11,1541,1542],{},"Automating KYC and KYB for stablecoin payments means treating verification as a state on the receiver, running every check before settlement, and letting the payment API enforce the result. Doing it inside the payment infrastructure removes the separate vendor integration and its synchronization bugs.",[11,1544,1545,1549,1550,1552,1553,293],{},[48,1546,1548],{"href":1116,"rel":1547},[422],"BlindPay"," embeds KYC and KYB in the same REST API used for quotes and payouts, covering document verification, sanctions screening, risk scoring, and audit logging across the US, EU, UK, Singapore, Brazil, and other supported countries. The ",[48,1551,287],{"href":286}," covers the full program, and specific corridors are worth a ",[48,1554,1555],{"href":1111},"conversation",[11,1557,1558],{},[14,1559,305],{},{"title":307,"searchDepth":308,"depth":308,"links":1561},[1562,1563,1564,1565,1566,1567,1568,1569,1570,1571],{"id":1183,"depth":308,"text":1184},{"id":1199,"depth":308,"text":1200},{"id":1253,"depth":308,"text":1254},{"id":1307,"depth":308,"text":1308},{"id":1354,"depth":308,"text":1355},{"id":1438,"depth":308,"text":1439},{"id":1451,"depth":308,"text":1452},{"id":1461,"depth":308,"text":1462},{"id":1499,"depth":308,"text":1500},{"id":1538,"depth":308,"text":1539},"2026-08-25","A developer guide to automated KYC and KYB for stablecoin payment flows: how verification runs inside a payment API, step-by-step workflows for individuals and businesses, jurisdiction requirements for the US, EU, UK, Singapore, and Brazil, and what to check before settlement.",[1575,1577,1579,1581,1583,1585],{"q":557,"a":1576},"KYC verifies an individual person: identity document, liveness, address, and sanctions screening. KYB verifies a business entity: registration, good standing, ownership structure, and then KYC on each beneficial owner and controller. A business account needs both.",{"q":1510,"a":1578},"For most users, yes. Document extraction, face matching, sanctions screening, and risk scoring run without a human, and a clean case is approved in seconds to minutes. A small share of cases with mismatched data or screening hits still goes to manual review.",{"q":1516,"a":1580},"Not if the payment API includes verification. BlindPay runs KYC and KYB through the same REST API used to create payouts, so there is no second vendor contract, SDK, or webhook pipeline to maintain.",{"q":1522,"a":1582},"The receiver record moves to a rejected status and no payout can be created for it. Your app should show the reason category returned by the API and, where allowed, offer a resubmission path with corrected documents.",{"q":1528,"a":1584},"Minutes to same day when registry data is available and ownership is simple. Entities with layered holding companies, trusts, or non-digitized registries can take several days because ownership must be traced to real people.",{"q":1534,"a":1586},"Verification runs once per receiver, not per transaction. Sanctions screening and risk checks then run on each payout against the verified record, and the payout is blocked before settlement if anything changed.",{"author":342},"---\ntitle: \"How to automate KYC and KYB for stablecoin payments\"\ndescription: \"A developer guide to automated KYC and KYB for stablecoin payment flows: how verification runs inside a payment API, step-by-step workflows for individuals and businesses, jurisdiction requirements for the US, EU, UK, Singapore, and Brazil, and what to check before settlement.\"\ndate: \"2026-08-25\"\nupdated: \"2026-08-25\"\nauthor: \"BlindPay Team\"\ncategory: \"compliance\"\nfaq:\n  - q: \"What is the difference between KYC and KYB?\"\n    a: \"KYC verifies an individual person: identity document, liveness, address, and sanctions screening. KYB verifies a business entity: registration, good standing, ownership structure, and then KYC on each beneficial owner and controller. A business account needs both.\"\n  - q: \"Can KYC for stablecoin payments be fully automated?\"\n    a: \"For most users, yes. Document extraction, face matching, sanctions screening, and risk scoring run without a human, and a clean case is approved in seconds to minutes. A small share of cases with mismatched data or screening hits still goes to manual review.\"\n  - q: \"Do I need a separate KYC vendor if I use a stablecoin payment API?\"\n    a: \"Not if the payment API includes verification. BlindPay runs KYC and KYB through the same REST API used to create payouts, so there is no second vendor contract, SDK, or webhook pipeline to maintain.\"\n  - q: \"What happens if a user fails automated KYC?\"\n    a: \"The receiver record moves to a rejected status and no payout can be created for it. Your app should show the reason category returned by the API and, where allowed, offer a resubmission path with corrected documents.\"\n  - q: \"How long does automated KYB take for a business?\"\n    a: \"Minutes to same day when registry data is available and ownership is simple. Entities with layered holding companies, trusts, or non-digitized registries can take several days because ownership must be traced to real people.\"\n  - q: \"Does KYC need to run before every stablecoin payout?\"\n    a: \"Verification runs once per receiver, not per transaction. Sanctions screening and risk checks then run on each payout against the verified record, and the payout is blocked before settlement if anything changed.\"\n---\n\n*Reading time: about 8 minutes.*\n\n**Summary:** You automate KYC and KYB for stablecoin payments by making verification a step in the payment API itself. Create a receiver with identity or entity data, let automated KYC run document checks, sanctions screening, and risk scoring, receive the result by webhook, and only allow payouts once the receiver status is approved.\n\nKYC automation matters for stablecoin companies because a payout on a public blockchain cannot be reversed. Every check has to finish before funds move, and manual review does not scale past a few hundred receivers.\n\n## What is the difference between KYC and KYB for stablecoin payments?\n\nKYC, Know Your Customer, verifies an individual person. It confirms that a government ID is authentic, that the person presenting it is real and present, and that they are not on a sanctions or watch list.\n\nKYB, Know Your Business, verifies a business entity. It confirms the company is registered and active, maps who owns and controls it, and then runs KYC on each of those individuals.\n\nThe split maps onto who you pay. Contractors and remittance recipients need KYC. Vendors, marketplaces, and corporate customers need KYB, which always includes KYC on their owners. The [KYB explainer](\u002Fresources\u002Fmore\u002Fwhat-is-kyb) covers beneficial ownership rules in detail.\n\n## How does automated KYC work for stablecoin users?\n\nAutomated KYC replaces an analyst reviewing a PDF with a pipeline of machine checks that return a decision and an audit trail.\n\n1. **Data collection.** Your app collects name, date of birth, address, tax ID, and ID document images, then sends them in one API request that creates the receiver.\n2. **Document verification.** The system extracts fields from the document, checks security features and expiry, and compares the extracted data against what the user typed.\n3. **Liveness and face match.** A selfie or short video is checked for presentation attacks, then matched against the document photo.\n4. **Sanctions and PEP screening.** The name, date of birth, and country are screened against OFAC, EU, UK, UN, and local lists, plus politically exposed person databases.\n5. **Risk scoring.** Country, document type, IP geolocation, and screening results combine into a risk tier that decides between auto-approval and manual review.\n6. **Decision and webhook.** The receiver status becomes approved, rejected, or verifying, and your backend receives a webhook so it can unlock or block payouts.\n7. **Audit logging.** Every input, check result, and decision is stored with timestamps so a regulator or bank partner can reconstruct the case.\n\nA clean case clears all seven stages in under a minute. A name mismatch or screening hit stops at stage five for a human decision.\n\n## How does KYB automation work for business receivers?\n\nKYB automation follows the same shape but adds an entity layer before the individual checks. Ownership tracing is the hard part, because it has to end at real people.\n\n1. **Entity data collection.** Collect legal name, registration number, tax ID, incorporation date, registered address, business type, and industry, plus the incorporation document.\n2. **Registry verification.** The registration number is checked against the jurisdiction's corporate registry to confirm the entity exists, is active, and matches the stated name and address.\n3. **Ownership mapping.** The ownership structure is unwound through holding companies until every individual with 25 percent or more, or with control, is identified.\n4. **Beneficial owner KYC.** Each identified owner and controller goes through the full individual KYC flow described above.\n5. **Entity screening.** The company name and its owners are screened against sanctions lists, adverse media, and industry restrictions.\n6. **Risk scoring and decision.** Entity type, industry, jurisdiction, and owner results combine into a tier. High-risk industries or complex ownership route to enhanced due diligence.\n7. **Decision and monitoring.** The business receiver is approved or rejected, and the record is re-screened on a schedule and on every payout.\n\nRegistry availability sets the speed. A US LLC or UK Ltd clears in minutes, while an entity in a paper-registry jurisdiction can take days.\n\n## How do you integrate KYC compliance into a stablecoin payment API?\n\nThe integration pattern that works at scale treats verification as a state machine on the receiver record, not as a separate system you poll.\n\n1. **Create the receiver.** Call the receivers endpoint with the KYC type, individual or business, and the collected data. The record is created with status verifying.\n2. **Subscribe to status webhooks.** Register a webhook for receiver status changes so your backend learns about approval or rejection without polling.\n3. **Gate payouts on status.** Your payout code checks that the receiver is approved before creating a quote. The API enforces this too, so a race cannot slip a payout through.\n4. **Handle rejection and resubmission.** Surface the rejection reason to the user, collect corrected documents, and update the receiver to trigger a new verification run.\n5. **Store the receiver ID, not the documents.** Keep the provider's receiver ID in your database and let the provider hold documents and audit logs.\n\nWith BlindPay, these steps use the same REST API and API key as quotes and payouts. The [OpenAPI specification](\u002Fdocs\u002Fapi\u002Freference) describes the receiver schema, status values, and webhook payloads, so client code can be generated rather than hand-written.\n\n## Which jurisdictions have specific KYC and KYB requirements for stablecoin payments?\n\nRequirements differ by country in thresholds, beneficial ownership definitions, and the licensing regulator. A multi-corridor provider needs a rule set per jurisdiction, applied automatically from the receiver country.\n\n| Jurisdiction | Regulatory body | Primary KYC\u002FKYB requirements |\n|---|---|---|\n| United States | FinCEN, state regulators | Customer Identification Program, beneficial ownership at 25 percent plus control prong under 31 CFR 1010.230, OFAC screening, SAR filing |\n| European Union | National competent authorities under AMLD and MiCA | Customer due diligence, beneficial ownership at 25 percent, travel rule under the Transfer of Funds Regulation, CASP licensing under MiCA |\n| United Kingdom | FCA | Money Laundering Regulations 2017, cryptoasset firm registration, PSC register checks for beneficial owners, travel rule since September 2023 |\n| Singapore | MAS | Payment Services Act licensing, MAS Notice PSN02 customer due diligence, travel rule for digital payment token transfers |\n| Brazil | Banco Central do Brasil, Receita Federal | CPF and CNPJ validation, name and tax ID matching on Pix, PSAV registration for virtual asset providers, Circular 3978 AML controls |\n\nThe [regulation tracker](\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026) and [MiCA explainer](\u002Fresources\u002Fmore\u002Fmica-stablecoin-rules-explained) go deeper on EU and Brazil rules.\n\n## Why should compliance checks run before settlement instead of after?\n\nOn a card or ACH network, a payment flagged after the fact can be reversed. A stablecoin transfer on a public chain is final once confirmed, so a check that runs after settlement is a report, not a control.\n\nVerification before the payout is created means a sanctions hit or failed document check blocks the transaction at zero cost. After settlement, the funds are already in a wallet you do not control.\n\nBlindPay runs KYC, KYB, and per-payout sanctions screening before any quote is executed. A receiver that is not approved cannot receive a payout, and a payout that fails screening is rejected before funds move.\n\n## Can a stablecoin company reuse KYC it already performs?\n\nPartly. A fintech with its own onboarding program can pass verified data through the payment API instead of running users through a second document flow, once the provider has reviewed that program against its own standard.\n\nBlindPay applies this as a reliance model. Onboarding, fraud checks, and limit increase reviews can be relied upon after a review of the partner's policies, while transaction monitoring on every payout always runs on BlindPay's side. All customer data still flows through the API, and BlindPay keeps the right to inspect any partner check.\n\n## What should developers check when choosing automated identity verification for a stablecoin company?\n\nThe decision comes down to whether verification is part of the payment flow or bolted on beside it. A separate KYC vendor means a second contract, a second SDK, and a sync problem between verification state and payout permission.\n\n- **Single API surface.** Verification and payouts should share one authentication scheme, one webhook system, and one set of IDs.\n- **Enforcement at the payout layer.** The API itself should refuse a payout to an unverified receiver, not just return a status your code has to remember to check.\n- **Jurisdiction coverage.** Confirm the provider applies the right rules for every country you pay into, including local tax ID formats and name matching rules.\n- **Sandbox parity.** The [sandbox](\u002Fresources\u002Fmore\u002Fstablecoin-api-sandbox-vs-production) should return realistic verification states, including rejected and verifying, so every branch is tested before go-live.\n\n## FAQ\n\n**What is the difference between KYC and KYB?**\nKYC verifies an individual person: identity document, liveness, address, and sanctions screening. KYB verifies a business entity: registration, good standing, ownership structure, and then KYC on each beneficial owner and controller. A business account needs both.\n\n**Can KYC for stablecoin payments be fully automated?**\nFor most users, yes. Document extraction, face matching, sanctions screening, and risk scoring run without a human, and a clean case is approved in seconds to minutes. A small share of cases with mismatched data or screening hits still goes to manual review.\n\n**Do I need a separate KYC vendor if I use a stablecoin payment API?**\nNot if the payment API includes verification. BlindPay runs KYC and KYB through the same REST API used to create payouts, so there is no second vendor contract, SDK, or webhook pipeline to maintain.\n\n**What happens if a user fails automated KYC?**\nThe receiver record moves to a rejected status and no payout can be created for it. Your app should show the reason category returned by the API and, where allowed, offer a resubmission path with corrected documents.\n\n**How long does automated KYB take for a business?**\nMinutes to same day when registry data is available and ownership is simple. Entities with layered holding companies, trusts, or non-digitized registries can take several days because ownership must be traced to real people.\n\n**Does KYC need to run before every stablecoin payout?**\nVerification runs once per receiver, not per transaction. Sanctions screening and risk checks then run on each payout against the verified record, and the payout is blocked before settlement if anything changed.\n\n## How does BlindPay fit in?\n\nAutomating KYC and KYB for stablecoin payments means treating verification as a state on the receiver, running every check before settlement, and letting the payment API enforce the result. Doing it inside the payment infrastructure removes the separate vendor integration and its synchronization bugs.\n\n[BlindPay](https:\u002F\u002Fblindpay.com) embeds KYC and KYB in the same REST API used for quotes and payouts, covering document verification, sanctions screening, risk scoring, and audit logging across the US, EU, UK, Singapore, Brazil, and other supported countries. The [compliance page](\u002Fcompliance) covers the full program, and specific corridors are worth a [conversation](\u002Fcontact).\n\n*This article is for general information only and is not legal, tax, or financial advice.*\n",{"title":1166,"description":1573},"resources\u002Fmore\u002Fhow-to-automate-kyc-kyb-stablecoin-payments","6wZlRcWtt3Qf3TF6MEvq1r2m19THP7hIWWLDnzRjlsc",{"id":1593,"title":1594,"authors":6,"body":1595,"categories":6,"category":323,"categoryType":6,"compare":6,"contributors":6,"date":324,"description":1875,"extension":326,"faq":1876,"howto":6,"isBlog":340,"isChangelog":340,"meta":1892,"navigation":343,"path":1893,"pillar":340,"products":6,"rawbody":1894,"role":6,"seo":1895,"stem":1896,"thumbnail":6,"updated":324,"__hash__":1897},"content\u002Fresources\u002Fmore\u002Fhow-to-choose-automated-risk-monitoring-vendor.md","How to choose an automated risk monitoring vendor for a fintech startup",{"type":8,"value":1596,"toc":1864},[1597,1601,1606,1609,1613,1616,1622,1625,1629,1632,1635,1638,1644,1647,1651,1654,1657,1664,1669,1673,1676,1679,1682,1687,1691,1694,1714,1717,1722,1726,1729,1732,1735,1740,1744,1834,1838,1841,1844,1847,1853,1857,1860],[11,1598,1599],{},[14,1600,843],{},[11,1602,1603,1605],{},[20,1604,22],{}," Choose an automated risk monitoring vendor on five criteria: regulatory coverage (which jurisdictions and lists it screens), integration effort (API quality and time to live), false-positive rate and alert tuning, pricing model (per-check, flat, or volume-based), and the audit and reporting output it produces for regulators and investors. Everything else on a vendor's feature list is downstream of those five.",[11,1607,1608],{},"This guide gives each criterion a short explanation and the one question to ask, then compresses it into a checklist. It is written as buyer guidance. BlindPay embeds risk monitoring in its payment API, and where that is relevant it is noted, but the criteria apply to any vendor.",[28,1610,1612],{"id":1611},"what-a-risk-monitoring-vendor-actually-sells","What a risk monitoring vendor actually sells",[11,1614,1615],{},"Before the criteria, a quick map of the category, because vendors bundle it differently.",[11,1617,1426,1618,1621],{},[48,1619,1620],{"href":71},"four components"," are KYC\u002FKYB verification, transaction monitoring, sanctions and watchlist screening, and compliance automation (alert triage, case narratives, filings). Some vendors sell one, some sell all four, and some payment providers include all four inside the payment API so the fintech never contracts them separately.",[11,1623,1624],{},"That last model matters for a startup because it changes the question from \"which vendor\" to \"which layer of the stack does this belong in.\" Keep that in mind through the criteria.",[28,1626,1628],{"id":1627},"_1-regulatory-coverage","1. Regulatory coverage",[11,1630,1631],{},"Regulatory coverage is the set of jurisdictions, lists, and rules the vendor actually screens and monitors against, as opposed to the set on the website.",[11,1633,1634],{},"A US-only fintech needs the OFAC SDN and consolidated lists, FinCEN's Bank Secrecy Act monitoring expectations, and PEP and adverse media screening. The moment the product touches a second market, the requirement expands: EU consolidated and UK OFSI lists, FATF Travel Rule data exchange at that market's threshold, and local registry integrations for KYB. A vendor that covers the US well and \"supports\" Brazil may mean it accepts a Brazilian document, not that it checks the CNPJ registry or knows the SPSAV regime.",[11,1636,1637],{},"For stablecoin payments, add wallet address screening. OFAC has listed blockchain addresses since 2018, and a vendor that screens names but not addresses leaves the gap open.",[11,1639,1640,1643],{},[20,1641,1642],{},"Question to ask:"," \"For each of my target markets, which lists do you screen, how often do they refresh, which registries do you query for business verification, and do you screen wallet addresses as well as names?\"",[11,1645,1646],{},"A good answer names lists, refresh intervals, and registries per country. A weak answer says \"global coverage.\"",[28,1648,1650],{"id":1649},"_2-integration-effort","2. Integration effort",[11,1652,1653],{},"Integration effort is the engineering time between signing and the first production verification, plus the ongoing cost of keeping the integration working.",[11,1655,1656],{},"The details that decide it: a REST API with typed responses, a sandbox that returns realistic approve, reject, and review outcomes, webhooks for status changes so the product does not poll, idempotent requests, and SDKs in the languages the team uses. Also whether the vendor's data model matches the product's. If the fintech's core object is a payout receiver, and the vendor's is a \"case,\" someone has to maintain the mapping forever.",[11,1658,1659,1660,1663],{},"Time to live is a fair proxy. A standalone KYC integration with a sandbox typically takes one to three weeks of engineering time to reach production; a full stack of KYC, screening, and transaction monitoring from separate vendors takes longer because the joins between them are the fintech's job. Embedded monitoring in a ",[48,1661,1662],{"href":370},"payment API"," collapses that to the payment integration itself.",[11,1665,1666,1668],{},[20,1667,1642],{}," \"Can I get sandbox credentials today, and what did the last three customers of my size take, in engineering weeks, from signing to production?\"",[28,1670,1672],{"id":1671},"_3-false-positive-rate-and-alert-tuning","3. False-positive rate and alert tuning",[11,1674,1675],{},"The false-positive rate is the share of alerts that an analyst closes as nothing. It is the number that decides whether the compliance team works cases or clears noise.",[11,1677,1678],{},"Sanctions name screening is the worst offender. Fuzzy matching a common name against global lists without date of birth and country narrowing can produce alert rates where most alerts are false, and a startup with one part-time compliance analyst drowns in a week. Transaction rules have the same problem in a milder form: a velocity threshold set for a marketplace will fire constantly for a payroll customer.",[11,1680,1681],{},"What separates vendors is who tunes it. Some ship fixed rules. Some expose thresholds the customer sets. The best expose thresholds, show the alert volume each setting would have produced against the customer's own history, and let the compliance officer sign off on the change, which is what an examiner will ask for.",[11,1683,1684,1686],{},[20,1685,1642],{}," \"At reference customers with my profile, what share of alerts is closed as false positive, who tunes the rules, and can I see the tuning history for audit?\"",[28,1688,1690],{"id":1689},"_4-pricing-model","4. Pricing model",[11,1692,1693],{},"Vendors price in three ways, and the right one depends on the shape of the fintech's volume.",[723,1695,1696,1702,1708],{},[229,1697,1698,1701],{},[20,1699,1700],{},"Per-check."," A price per verification, per screened record, or per monitored transaction. Cheap at low volume, predictable, and painful at scale, since every new customer adds cost even when nothing is found.",[229,1703,1704,1707],{},[20,1705,1706],{},"Flat platform fee."," A monthly or annual fee with a volume ceiling. Predictable, but a startup pays for capacity it does not use yet, and the ceiling arrives at the worst time.",[229,1709,1710,1713],{},[20,1711,1712],{},"Volume-based tiers."," Per-unit prices that fall as volume grows. Usually the best fit for a fintech that expects to grow, with the caveat that tier boundaries and minimum commitments deserve a close read.",[11,1715,1716],{},"A fourth model applies when monitoring is embedded in the payment provider: there is no separate line item, and the cost is inside the payment fee. That is the cheapest model at every stage, provided the provider's coverage passes criterion 1.",[11,1718,1719,1721],{},[20,1720,1642],{}," \"Model my cost at current volume, ten times current volume, and a hundred times, including minimums, overage rates, and every add-on I would need for my markets.\"",[28,1723,1725],{"id":1724},"_5-audit-and-reporting-output","5. Audit and reporting output",[11,1727,1728],{},"Audit output is what the vendor gives a regulator, a bank partner, or an investor when they ask how a customer was verified or why a transaction was allowed.",[11,1730,1731],{},"Concretely: a per-customer record of inputs collected, checks run, results, risk score, decision, and who made it; a per-transaction record of rules evaluated and their outcomes; an exportable case file with the evidence and narrative; and periodic reports (alert volumes, dispositions, SAR counts, screening coverage) that a compliance officer can put in front of a board or a bank partner without editing. FinCEN expects five years of retention on all of it.",[11,1733,1734],{},"Investors ask a lighter version of the same question in diligence: show the program, show the metrics, show one case end to end. A vendor whose output is a dashboard screenshot fails both audiences.",[11,1736,1737,1739],{},[20,1738,1642],{}," \"Send me a sample customer audit record, a sample case file, and the regulator-facing report you generate, exactly as a customer receives them.\"",[28,1741,1743],{"id":1742},"vendor-evaluation-checklist","Vendor evaluation checklist",[121,1745,1746,1762],{},[124,1747,1748],{},[127,1749,1750,1753,1756,1759],{},[130,1751,1752],{},"Criterion",[130,1754,1755],{},"What to verify",[130,1757,1758],{},"Question to ask",[130,1760,1761],{},"Pass signal",[140,1763,1764,1778,1792,1806,1820],{},[127,1765,1766,1769,1772,1775],{},[145,1767,1768],{},"Regulatory coverage",[145,1770,1771],{},"Lists, refresh cadence, registries, wallet screening, per market",[145,1773,1774],{},"Which lists, registries, and refresh intervals, per country?",[145,1776,1777],{},"Named lists and registries, address screening included",[127,1779,1780,1783,1786,1789],{},[145,1781,1782],{},"Integration effort",[145,1784,1785],{},"REST API, sandbox, webhooks, SDKs, data model fit",[145,1787,1788],{},"Sandbox today, and real time-to-live at customers my size?",[145,1790,1791],{},"Credentials same day, weeks not months",[127,1793,1794,1797,1800,1803],{},[145,1795,1796],{},"False-positive rate",[145,1798,1799],{},"Alert-to-case ratio, who tunes, tuning audit trail",[145,1801,1802],{},"Share of alerts closed as false positive at reference customers?",[145,1804,1805],{},"A number, and customer-controlled thresholds",[127,1807,1808,1811,1814,1817],{},[145,1809,1810],{},"Pricing model",[145,1812,1813],{},"Unit, minimums, tiers, add-ons, cost at 10x and 100x",[145,1815,1816],{},"Model my cost at three volume levels, all-in?",[145,1818,1819],{},"Cost falls per unit as volume grows",[127,1821,1822,1825,1828,1831],{},[145,1823,1824],{},"Audit output",[145,1826,1827],{},"Customer record, case file, regulator report, retention",[145,1829,1830],{},"Send samples exactly as a customer receives them?",[145,1832,1833],{},"Structured exports, five-year retention",[28,1835,1837],{"id":1836},"one-vendor-or-several","One vendor or several?",[11,1839,1840],{},"The honest answer for most startups is: as few as possible, and usually one.",[11,1842,1843],{},"Alerts are only useful with the verified customer profile next to them. When verification lives in one vendor and monitoring in another, the fintech builds and maintains the join, and every examination question about a customer becomes a two-system lookup. A single platform, or a payment provider with the full layer embedded, removes that work.",[11,1845,1846],{},"Separate vendors earn their place in two cases: a specific risk that needs a best-of-breed tool (deep blockchain analytics for a crypto-native product, for example), or a stack where the payment provider already runs transaction monitoring and screening on every payout and only the onboarding piece needs sourcing.",[11,1848,1849,1850,1852],{},"BlindPay falls into the embedded category: KYC and KYB run through the same API that creates payouts, every payout is rescreened and risk-scored before settlement, held payouts surface over webhook, and the program is described on the ",[48,1851,287],{"href":286},". That is one option among the models above, and the checklist should be applied to it the same way as to anyone else.",[28,1854,1856],{"id":1855},"what-to-do-next","What to do next",[11,1858,1859],{},"Run the checklist against three vendors, including the payment provider already in the stack, and ask for the samples in criterion 5 before any commercial conversation. The vendor that sends real artifacts in a day is usually the one whose product does the work; the one that schedules a demo instead is usually selling the slide.",[11,1861,1862],{},[14,1863,305],{},{"title":307,"searchDepth":308,"depth":308,"links":1865},[1866,1867,1868,1869,1870,1871,1872,1873,1874],{"id":1611,"depth":308,"text":1612},{"id":1627,"depth":308,"text":1628},{"id":1649,"depth":308,"text":1650},{"id":1671,"depth":308,"text":1672},{"id":1689,"depth":308,"text":1690},{"id":1724,"depth":308,"text":1725},{"id":1742,"depth":308,"text":1743},{"id":1836,"depth":308,"text":1837},{"id":1855,"depth":308,"text":1856},"A buyer's guide to automated risk monitoring vendors for early-stage fintechs: the five criteria that matter (regulatory coverage, integration effort, false-positive rate, pricing model, audit output), the question to ask a vendor on each, a checklist table, and what it costs.",[1877,1880,1883,1886,1889],{"q":1878,"a":1879},"What does automated risk monitoring cost for an early-stage fintech?","Standalone KYC vendors typically charge in the low single dollars per individual verification and more per business, transaction monitoring is usually a monthly platform fee plus volume tiers that start in the low thousands of dollars a month, and sanctions screening is often bundled or priced per screened record. A startup stitching three vendors together commonly lands in the low to mid five figures a year before analyst time; a payment provider with monitoring embedded charges nothing separately for it.",{"q":1881,"a":1882},"Do I need a separate vendor for KYC and transaction monitoring, or one platform?","One platform if it covers both well, because alerts are only useful with the customer's verified profile next to them, and two vendors means building that join yourself. Separate vendors make sense when a best-of-breed screening or analytics tool is required for a specific risk, or when the payment provider already embeds the transaction layer and only onboarding is missing.",{"q":1884,"a":1885},"What questions should I ask a risk monitoring vendor before signing?","Which lists and jurisdictions are screened and how often lists refresh; how long a real integration takes and whether there is a sandbox; the false-positive rate at reference customers and who tunes the rules; the pricing unit and what happens at ten times the volume; and what audit output an examiner or investor receives. Ask for a sample case file and a sample regulator report, not a slide.",{"q":1887,"a":1888},"Should a fintech startup build its own risk monitoring?","Rarely. The rules engine is the easy part; the list feeds, blockchain analytics, registry integrations, and case management are not, and a regulator will examine all of them. Most startups buy or inherit the monitoring layer from their payment provider and build only the product-specific rules on top.",{"q":1890,"a":1891},"What is the difference between a risk monitoring vendor and a compliance agent?","A vendor provides the checks: verification, screening, monitoring, case management. A compliance agent is software, increasingly AI-driven, that works the output of those checks: triaging alerts, assembling evidence, and drafting narratives. Some vendors include an agent layer; the filing decision stays with a named human in either case.",{"author":342},"\u002Fresources\u002Fmore\u002Fhow-to-choose-automated-risk-monitoring-vendor","---\ntitle: \"How to choose an automated risk monitoring vendor for a fintech startup\"\ndescription: \"A buyer's guide to automated risk monitoring vendors for early-stage fintechs: the five criteria that matter (regulatory coverage, integration effort, false-positive rate, pricing model, audit output), the question to ask a vendor on each, a checklist table, and what it costs.\"\ndate: \"2026-09-15\"\nupdated: \"2026-09-15\"\nauthor: \"BlindPay Team\"\ncategory: \"compliance\"\nfaq:\n  - q: \"What does automated risk monitoring cost for an early-stage fintech?\"\n    a: \"Standalone KYC vendors typically charge in the low single dollars per individual verification and more per business, transaction monitoring is usually a monthly platform fee plus volume tiers that start in the low thousands of dollars a month, and sanctions screening is often bundled or priced per screened record. A startup stitching three vendors together commonly lands in the low to mid five figures a year before analyst time; a payment provider with monitoring embedded charges nothing separately for it.\"\n  - q: \"Do I need a separate vendor for KYC and transaction monitoring, or one platform?\"\n    a: \"One platform if it covers both well, because alerts are only useful with the customer's verified profile next to them, and two vendors means building that join yourself. Separate vendors make sense when a best-of-breed screening or analytics tool is required for a specific risk, or when the payment provider already embeds the transaction layer and only onboarding is missing.\"\n  - q: \"What questions should I ask a risk monitoring vendor before signing?\"\n    a: \"Which lists and jurisdictions are screened and how often lists refresh; how long a real integration takes and whether there is a sandbox; the false-positive rate at reference customers and who tunes the rules; the pricing unit and what happens at ten times the volume; and what audit output an examiner or investor receives. Ask for a sample case file and a sample regulator report, not a slide.\"\n  - q: \"Should a fintech startup build its own risk monitoring?\"\n    a: \"Rarely. The rules engine is the easy part; the list feeds, blockchain analytics, registry integrations, and case management are not, and a regulator will examine all of them. Most startups buy or inherit the monitoring layer from their payment provider and build only the product-specific rules on top.\"\n  - q: \"What is the difference between a risk monitoring vendor and a compliance agent?\"\n    a: \"A vendor provides the checks: verification, screening, monitoring, case management. A compliance agent is software, increasingly AI-driven, that works the output of those checks: triaging alerts, assembling evidence, and drafting narratives. Some vendors include an agent layer; the filing decision stays with a named human in either case.\"\n---\n\n*Reading time: about 8 minutes.*\n\n**Summary:** Choose an automated risk monitoring vendor on five criteria: regulatory coverage (which jurisdictions and lists it screens), integration effort (API quality and time to live), false-positive rate and alert tuning, pricing model (per-check, flat, or volume-based), and the audit and reporting output it produces for regulators and investors. Everything else on a vendor's feature list is downstream of those five.\n\nThis guide gives each criterion a short explanation and the one question to ask, then compresses it into a checklist. It is written as buyer guidance. BlindPay embeds risk monitoring in its payment API, and where that is relevant it is noted, but the criteria apply to any vendor.\n\n## What a risk monitoring vendor actually sells\n\nBefore the criteria, a quick map of the category, because vendors bundle it differently.\n\nThe [four components](\u002Fresources\u002Fmore\u002Fwhat-is-automated-risk-monitoring-fintech) are KYC\u002FKYB verification, transaction monitoring, sanctions and watchlist screening, and compliance automation (alert triage, case narratives, filings). Some vendors sell one, some sell all four, and some payment providers include all four inside the payment API so the fintech never contracts them separately.\n\nThat last model matters for a startup because it changes the question from \"which vendor\" to \"which layer of the stack does this belong in.\" Keep that in mind through the criteria.\n\n## 1. Regulatory coverage\n\nRegulatory coverage is the set of jurisdictions, lists, and rules the vendor actually screens and monitors against, as opposed to the set on the website.\n\nA US-only fintech needs the OFAC SDN and consolidated lists, FinCEN's Bank Secrecy Act monitoring expectations, and PEP and adverse media screening. The moment the product touches a second market, the requirement expands: EU consolidated and UK OFSI lists, FATF Travel Rule data exchange at that market's threshold, and local registry integrations for KYB. A vendor that covers the US well and \"supports\" Brazil may mean it accepts a Brazilian document, not that it checks the CNPJ registry or knows the SPSAV regime.\n\nFor stablecoin payments, add wallet address screening. OFAC has listed blockchain addresses since 2018, and a vendor that screens names but not addresses leaves the gap open.\n\n**Question to ask:** \"For each of my target markets, which lists do you screen, how often do they refresh, which registries do you query for business verification, and do you screen wallet addresses as well as names?\"\n\nA good answer names lists, refresh intervals, and registries per country. A weak answer says \"global coverage.\"\n\n## 2. Integration effort\n\nIntegration effort is the engineering time between signing and the first production verification, plus the ongoing cost of keeping the integration working.\n\nThe details that decide it: a REST API with typed responses, a sandbox that returns realistic approve, reject, and review outcomes, webhooks for status changes so the product does not poll, idempotent requests, and SDKs in the languages the team uses. Also whether the vendor's data model matches the product's. If the fintech's core object is a payout receiver, and the vendor's is a \"case,\" someone has to maintain the mapping forever.\n\nTime to live is a fair proxy. A standalone KYC integration with a sandbox typically takes one to three weeks of engineering time to reach production; a full stack of KYC, screening, and transaction monitoring from separate vendors takes longer because the joins between them are the fintech's job. Embedded monitoring in a [payment API](\u002Fresources\u002Fmore\u002Fwhat-is-a-stablecoin-api) collapses that to the payment integration itself.\n\n**Question to ask:** \"Can I get sandbox credentials today, and what did the last three customers of my size take, in engineering weeks, from signing to production?\"\n\n## 3. False-positive rate and alert tuning\n\nThe false-positive rate is the share of alerts that an analyst closes as nothing. It is the number that decides whether the compliance team works cases or clears noise.\n\nSanctions name screening is the worst offender. Fuzzy matching a common name against global lists without date of birth and country narrowing can produce alert rates where most alerts are false, and a startup with one part-time compliance analyst drowns in a week. Transaction rules have the same problem in a milder form: a velocity threshold set for a marketplace will fire constantly for a payroll customer.\n\nWhat separates vendors is who tunes it. Some ship fixed rules. Some expose thresholds the customer sets. The best expose thresholds, show the alert volume each setting would have produced against the customer's own history, and let the compliance officer sign off on the change, which is what an examiner will ask for.\n\n**Question to ask:** \"At reference customers with my profile, what share of alerts is closed as false positive, who tunes the rules, and can I see the tuning history for audit?\"\n\n## 4. Pricing model\n\nVendors price in three ways, and the right one depends on the shape of the fintech's volume.\n\n- **Per-check.** A price per verification, per screened record, or per monitored transaction. Cheap at low volume, predictable, and painful at scale, since every new customer adds cost even when nothing is found.\n- **Flat platform fee.** A monthly or annual fee with a volume ceiling. Predictable, but a startup pays for capacity it does not use yet, and the ceiling arrives at the worst time.\n- **Volume-based tiers.** Per-unit prices that fall as volume grows. Usually the best fit for a fintech that expects to grow, with the caveat that tier boundaries and minimum commitments deserve a close read.\n\nA fourth model applies when monitoring is embedded in the payment provider: there is no separate line item, and the cost is inside the payment fee. That is the cheapest model at every stage, provided the provider's coverage passes criterion 1.\n\n**Question to ask:** \"Model my cost at current volume, ten times current volume, and a hundred times, including minimums, overage rates, and every add-on I would need for my markets.\"\n\n## 5. Audit and reporting output\n\nAudit output is what the vendor gives a regulator, a bank partner, or an investor when they ask how a customer was verified or why a transaction was allowed.\n\nConcretely: a per-customer record of inputs collected, checks run, results, risk score, decision, and who made it; a per-transaction record of rules evaluated and their outcomes; an exportable case file with the evidence and narrative; and periodic reports (alert volumes, dispositions, SAR counts, screening coverage) that a compliance officer can put in front of a board or a bank partner without editing. FinCEN expects five years of retention on all of it.\n\nInvestors ask a lighter version of the same question in diligence: show the program, show the metrics, show one case end to end. A vendor whose output is a dashboard screenshot fails both audiences.\n\n**Question to ask:** \"Send me a sample customer audit record, a sample case file, and the regulator-facing report you generate, exactly as a customer receives them.\"\n\n## Vendor evaluation checklist\n\n| Criterion | What to verify | Question to ask | Pass signal |\n|---|---|---|---|\n| Regulatory coverage | Lists, refresh cadence, registries, wallet screening, per market | Which lists, registries, and refresh intervals, per country? | Named lists and registries, address screening included |\n| Integration effort | REST API, sandbox, webhooks, SDKs, data model fit | Sandbox today, and real time-to-live at customers my size? | Credentials same day, weeks not months |\n| False-positive rate | Alert-to-case ratio, who tunes, tuning audit trail | Share of alerts closed as false positive at reference customers? | A number, and customer-controlled thresholds |\n| Pricing model | Unit, minimums, tiers, add-ons, cost at 10x and 100x | Model my cost at three volume levels, all-in? | Cost falls per unit as volume grows |\n| Audit output | Customer record, case file, regulator report, retention | Send samples exactly as a customer receives them? | Structured exports, five-year retention |\n\n## One vendor or several?\n\nThe honest answer for most startups is: as few as possible, and usually one.\n\nAlerts are only useful with the verified customer profile next to them. When verification lives in one vendor and monitoring in another, the fintech builds and maintains the join, and every examination question about a customer becomes a two-system lookup. A single platform, or a payment provider with the full layer embedded, removes that work.\n\nSeparate vendors earn their place in two cases: a specific risk that needs a best-of-breed tool (deep blockchain analytics for a crypto-native product, for example), or a stack where the payment provider already runs transaction monitoring and screening on every payout and only the onboarding piece needs sourcing.\n\nBlindPay falls into the embedded category: KYC and KYB run through the same API that creates payouts, every payout is rescreened and risk-scored before settlement, held payouts surface over webhook, and the program is described on the [compliance page](\u002Fcompliance). That is one option among the models above, and the checklist should be applied to it the same way as to anyone else.\n\n## What to do next\n\nRun the checklist against three vendors, including the payment provider already in the stack, and ask for the samples in criterion 5 before any commercial conversation. The vendor that sends real artifacts in a day is usually the one whose product does the work; the one that schedules a demo instead is usually selling the slide.\n\n*This article is for general information only and is not legal, tax, or financial advice.*\n",{"title":1594,"description":1875},"resources\u002Fmore\u002Fhow-to-choose-automated-risk-monitoring-vendor","86-Qvli08wF7J4PScCIcbckUrDVwmwhvdVC-mmmCvHQ",{"id":1899,"title":1900,"authors":6,"body":1901,"categories":6,"category":323,"categoryType":6,"compare":6,"contributors":6,"date":2164,"description":2165,"extension":326,"faq":2166,"howto":6,"isBlog":340,"isChangelog":340,"meta":2179,"navigation":343,"path":1433,"pillar":340,"products":6,"rawbody":2180,"role":6,"seo":2181,"stem":2182,"thumbnail":6,"updated":6,"__hash__":2183},"content\u002Fresources\u002Fmore\u002Fmica-stablecoin-rules-explained.md","MiCA stablecoin rules explained for payment companies",{"type":8,"value":1902,"toc":2152},[1903,1906,1911,1915,1918,1921,1925,1928,1931,1934,1938,1941,1979,1983,1986,1989,1996,2000,2003,2025,2029,2032,2058,2061,2065,2068,2071,2075,2078,2082,2085,2102,2106,2126,2147],[11,1904,1905],{},"MiCA, the EU's Markets in Crypto-Assets regulation (Regulation (EU) 2023\u002F1114), is the single rulebook that decides which stablecoins can circulate in the European Union and who may issue them. Its stablecoin provisions have applied since June 30, 2024. The practical outcome for payment companies is simple: dollar and euro stablecoins in the EU must be e-money tokens issued by licensed institutions, USDC qualifies, USDT does not, and businesses that use compliant tokens through licensed providers carry none of the issuer obligations themselves.",[11,1907,1908,1909,293],{},"This article explains the parts of MiCA that matter if you pay or get paid with stablecoins. For the wider global picture, see our ",[48,1910,409],{"href":408},[28,1912,1914],{"id":1913},"what-does-mica-actually-regulate","What does MiCA actually regulate?",[11,1916,1917],{},"MiCA covers crypto-assets that were not already regulated under EU financial law. It creates three regimes: one for e-money tokens (EMTs), one for asset-referenced tokens (ARTs), and one for other crypto-assets, plus a licensing regime for crypto-asset service providers (CASPs) such as exchanges and custodians.",[11,1919,1920],{},"The stablecoin rules (Titles III and IV) took effect June 30, 2024. CASP rules followed on December 30, 2024, with national grandfathering periods that ran into 2026 for firms already operating. As of 2026, the transition is essentially over: the EU market runs on authorized issuers and licensed service providers.",[28,1922,1924],{"id":1923},"what-is-the-difference-between-an-emt-and-an-art","What is the difference between an EMT and an ART?",[11,1926,1927],{},"An e-money token references a single official currency: a dollar stablecoin or a euro stablecoin is an EMT. Under MiCA, only authorized credit institutions and electronic money institutions may issue EMTs, holders get a legal claim to redeem at par at any time, and issuers may not pay interest on holdings.",[11,1929,1930],{},"An asset-referenced token references a basket: multiple currencies, commodities, or crypto-assets. ARTs carry heavier capital, governance, and disclosure requirements and are rare in practice.",[11,1932,1933],{},"For payment flows, the distinction is almost academic: every stablecoin a business would use for payouts or settlement (USDC, EURC, and their peers) is an EMT. The label to look for is whether the issuer holds an EU authorization.",[28,1935,1937],{"id":1936},"what-must-emt-issuers-do-under-mica","What must EMT issuers do under MiCA?",[11,1939,1940],{},"The issuer requirements explain why the compliant list is short:",[723,1942,1943,1949,1955,1961,1967,1973],{},[229,1944,1945,1948],{},[20,1946,1947],{},"Authorization."," The issuer must be a licensed credit institution or electronic money institution in an EU member state.",[229,1950,1951,1954],{},[20,1952,1953],{},"A white paper"," notified to the regulator, describing the token, the reserve, and redemption rights.",[229,1956,1957,1960],{},[20,1958,1959],{},"Full reserves"," backing every token, segregated from the issuer's own assets, invested conservatively, with strict custody rules.",[229,1962,1963,1966],{},[20,1964,1965],{},"Redemption at par, at any time",", free of charge for holders.",[229,1968,1969,1972],{},[20,1970,1971],{},"No interest"," paid on the token, which draws the line between payment instruments and deposit-like products.",[229,1974,1975,1978],{},[20,1976,1977],{},"Significant EMT rules."," Tokens above thresholds for holders, market value, or transaction volume face extra requirements supervised by the European Banking Authority, including transaction-volume monitoring for tokens denominated in non-EU currencies used as a means of exchange.",[28,1980,1982],{"id":1981},"why-is-usdc-available-in-the-eu-and-usdt-not","Why is USDC available in the EU and USDT not?",[11,1984,1985],{},"Circle became the first major global stablecoin issuer to comply: it obtained an electronic money institution license in France (supervised by the ACPR) on July 1, 2024, and issues both USDC and EURC as MiCA-compliant EMTs. That license passports across all EU member states.",[11,1987,1988],{},"Tether publicly chose not to seek MiCA authorization, criticizing the reserve requirements. The consequence arrived through the service-provider side: CASPs cannot offer non-compliant EMTs to EU customers, so regulated exchanges (Coinbase, Crypto.com, Binance for EEA users, and others) delisted USDT for EU customers between late 2024 and the first quarter of 2025.",[11,1990,1991,1992,293],{},"The market read the signal. For any product that touches EU users, USDC became the default dollar stablecoin. Our comparison of the two tokens for payment use cases: ",[48,1993,1995],{"href":1994},"\u002Fresources\u002Fmore\u002Fusdc-vs-usdt-for-payments","USDC vs USDT for payments",[28,1997,1999],{"id":1998},"what-does-mica-mean-for-a-business-that-uses-stablecoins","What does MiCA mean for a business that uses stablecoins?",[11,2001,2002],{},"If your company sends payouts, settles invoices, or holds working balances in stablecoins, MiCA does not turn you into a regulated entity. The obligations attach to issuers and service providers. Your responsibilities are choices:",[723,2004,2005,2011,2019],{},[229,2006,2007,2010],{},[20,2008,2009],{},"Choose compliant tokens for EU-touching flows."," USDC (and EURC for euro flows) as of 2026. A payout that starts in USDT can still reach an EU-adjacent receiver in local fiat, but the stablecoin leg should not be marketed or offered to EU users.",[229,2012,2013,2016,2017,293],{},[20,2014,2015],{},"Choose licensed partners."," If a provider custodies stablecoins or converts them for you in the EU, it should hold CASP authorization or operate through appropriately licensed entities. Ask; serious providers publish this. Ours is documented on the ",[48,2018,287],{"href":286},[229,2020,2021,2024],{},[20,2022,2023],{},"Mind where your users are."," MiCA applies to tokens offered to persons in the EU. A LatAm payout flow run by a US company is outside its scope, but the same company onboarding EU businesses is not.",[28,2026,2028],{"id":2027},"how-did-the-mica-timeline-unfold","How did the MiCA timeline unfold?",[11,2030,2031],{},"The rollout took three years and explains why 2026 feels settled:",[723,2033,2034,2040,2046,2052],{},[229,2035,2036,2039],{},[20,2037,2038],{},"June 2023",": MiCA entered into force, starting the clock.",[229,2041,2042,2045],{},[20,2043,2044],{},"June 30, 2024",": Titles III and IV applied; EMT and ART issuance without authorization became unlawful in the EU. Circle's French EMI license landed on July 1, 2024, making USDC the first major compliant dollar stablecoin.",[229,2047,2048,2051],{},[20,2049,2050],{},"Late 2024 to Q1 2025",": CASP rules applied (December 30, 2024) and regulated exchanges completed USDT delistings for EU customers, following ESMA's guidance that non-compliant EMTs should be restricted.",[229,2053,2054,2057],{},[20,2055,2056],{},"Through 2026",": national grandfathering periods for existing CASPs expired member state by member state; the EU market now runs end to end on authorized firms.",[11,2059,2060],{},"The lesson for payment companies watching other jurisdictions (Brazil's VASP transition, GENIUS Act rulemaking in the US): the binding date is rarely the law's publication, it is the moment service providers must drop non-compliant tokens. Distribution, not issuance, is where enforcement bites.",[28,2062,2064],{"id":2063},"who-enforces-mica","Who enforces MiCA?",[11,2066,2067],{},"Supervision is layered. National competent authorities (the AMF and ACPR in France, BaFin in Germany, and their peers) license issuers and CASPs and police conduct in their markets. The European Banking Authority (EBA) takes direct supervision of significant EMTs and ARTs, the tokens large enough to matter for financial stability, and the European Securities and Markets Authority (ESMA) coordinates the CASP side and keeps the public registers of authorized firms.",[11,2069,2070],{},"Enforcement so far has been structural rather than punitive: the effective sanction for a non-compliant token is exclusion from regulated distribution, as the USDT delistings showed. For a payment business, the practical check is not reading enforcement actions, it is checking the registers: an issuer should appear as an authorized EMI or credit institution, and an exchange or custodian should appear in ESMA's CASP register. If a partner is on neither list and claims EU coverage, that is the red flag.",[28,2072,2074],{"id":2073},"what-about-euro-stablecoins","What about euro stablecoins?",[11,2076,2077],{},"MiCA did for the euro what no market force had: it created a regulated euro stablecoin category. EURC (Circle) and a handful of bank-issued euro EMTs now circulate, and EU merchants and platforms increasingly quote in them for on-chain settlement. Volumes remain a fraction of dollar tokens, but for EU-domestic flows a euro EMT avoids FX entirely: a payout that starts and ends in euros has no reason to route through a dollar. Significant-EMT rules also cap how far a non-euro (that is, dollar) token can go as a day-to-day means of exchange inside the EU, a deliberate nudge toward euro-denominated tokens for domestic European payments.",[28,2079,2081],{"id":2080},"what-is-the-practical-checklist","What is the practical checklist?",[11,2083,2084],{},"For a payment company reviewing MiCA exposure in 2026:",[226,2086,2087,2090,2093,2096,2099],{},[229,2088,2089],{},"Inventory which stablecoins your flows touch and which user geographies can hold them.",[229,2091,2092],{},"Default EU-facing flows to MiCA-compliant EMTs (USDC, EURC).",[229,2094,2095],{},"Verify your providers' licensing: EMI or credit institution status for issuers, CASP status for exchanges and custodians.",[229,2097,2098],{},"Check redemption terms: compliant tokens redeem at par, always, free.",[229,2100,2101],{},"Document the above; MiCA compliance questions now appear in enterprise procurement and bank due diligence.",[28,2103,2105],{"id":2104},"how-blindpay-fits-in","How BlindPay fits in",[11,2107,2108,2109,2113,2114,2118,2119,2123,2124,293],{},"BlindPay is a stablecoin API for ",[48,2110,2112],{"href":2111},"\u002Fglobal-payments","global payments",": businesses send USDC or USDT and receivers get local currency over Pix, SPEI, ACH, or wire in ",[48,2115,2117],{"href":2116},"\u002Fcoverage","100+ countries",", with KYC, sanctions screening, and travel rule handling built into the flow. USDC, the EU-compliant token, is a first-class asset across the platform, including ",[48,2120,2122],{"href":2121},"\u002Fvirtual-accounts","virtual accounts"," that convert incoming bank transfers to USDC automatically. Regulatory questions about a specific corridor are the kind of thing worth a ",[48,2125,1555],{"href":1111},[11,2127,2128,2129,2134,2135,2140,2141,2146],{},"Primary sources: the MiCA text on ",[48,2130,2133],{"href":2131,"rel":2132},"https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002F?uri=CELEX%3A32023R1114",[422],"EUR-Lex",", ESMA's ",[48,2136,2139],{"href":2137,"rel":2138},"https:\u002F\u002Fwww.esma.europa.eu\u002Fesmas-activities\u002Fdigital-finance-and-innovation\u002Fmarkets-crypto-assets-regulation-mica",[422],"MiCA hub",", and the EBA's guidance on ARTs and EMTs (",[48,2142,2145],{"href":2143,"rel":2144},"https:\u002F\u002Fwww.eba.europa.eu\u002Fregulation-and-policy\u002Fmarkets-crypto-assets-mica",[422],"eba.europa.eu","). Status described as of August 2026.",[11,2148,2149],{},[14,2150,2151],{},"This article is general information, not legal, tax, or financial advice.",{"title":307,"searchDepth":308,"depth":308,"links":2153},[2154,2155,2156,2157,2158,2159,2160,2161,2162,2163],{"id":1913,"depth":308,"text":1914},{"id":1923,"depth":308,"text":1924},{"id":1936,"depth":308,"text":1937},{"id":1981,"depth":308,"text":1982},{"id":1998,"depth":308,"text":1999},{"id":2027,"depth":308,"text":2028},{"id":2063,"depth":308,"text":2064},{"id":2073,"depth":308,"text":2074},{"id":2080,"depth":308,"text":2081},{"id":2104,"depth":308,"text":2105},"2026-08-15","What MiCA means if your business uses stablecoins in the EU: EMTs vs ARTs, issuer requirements, why USDC is compliant and USDT was delisted, and a practical checklist.",[2167,2170,2173,2176],{"q":2168,"a":2169},"Is USDC MiCA-compliant?","Yes. Circle obtained an electronic money institution license in France in 2024 and issues USDC and EURC as MiCA-compliant e-money tokens. As of 2026, USDC is the most widely supported compliant dollar stablecoin in the EU.",{"q":2171,"a":2172},"Can EU businesses still use USDT?","Not through regulated channels. Tether did not pursue MiCA authorization, and EU-regulated exchanges delisted USDT for EU customers starting in early 2025. Businesses serving EU users should default to MiCA-compliant tokens like USDC.",{"q":2174,"a":2175},"Does MiCA apply to my company if we only use stablecoins for payouts?","Using a compliant stablecoin through a licensed provider does not itself make you an issuer or a crypto-asset service provider. The obligations sit with the issuer and the provider. You are responsible for choosing compliant tokens and licensed partners.",{"q":2177,"a":2178},"What is the difference between an EMT and an ART under MiCA?","An e-money token (EMT) references a single fiat currency, like a dollar or euro stablecoin. An asset-referenced token (ART) references a basket of assets. EMTs can only be issued by licensed credit institutions or electronic money institutions, and payment stablecoins are almost always EMTs.",{"author":342},"---\ntitle: \"MiCA stablecoin rules explained for payment companies\"\ndescription: \"What MiCA means if your business uses stablecoins in the EU: EMTs vs ARTs, issuer requirements, why USDC is compliant and USDT was delisted, and a practical checklist.\"\ndate: \"2026-08-15\"\ncategory: \"compliance\"\nauthor: \"BlindPay Team\"\nfaq:\n  - q: \"Is USDC MiCA-compliant?\"\n    a: \"Yes. Circle obtained an electronic money institution license in France in 2024 and issues USDC and EURC as MiCA-compliant e-money tokens. As of 2026, USDC is the most widely supported compliant dollar stablecoin in the EU.\"\n  - q: \"Can EU businesses still use USDT?\"\n    a: \"Not through regulated channels. Tether did not pursue MiCA authorization, and EU-regulated exchanges delisted USDT for EU customers starting in early 2025. Businesses serving EU users should default to MiCA-compliant tokens like USDC.\"\n  - q: \"Does MiCA apply to my company if we only use stablecoins for payouts?\"\n    a: \"Using a compliant stablecoin through a licensed provider does not itself make you an issuer or a crypto-asset service provider. The obligations sit with the issuer and the provider. You are responsible for choosing compliant tokens and licensed partners.\"\n  - q: \"What is the difference between an EMT and an ART under MiCA?\"\n    a: \"An e-money token (EMT) references a single fiat currency, like a dollar or euro stablecoin. An asset-referenced token (ART) references a basket of assets. EMTs can only be issued by licensed credit institutions or electronic money institutions, and payment stablecoins are almost always EMTs.\"\n---\n\nMiCA, the EU's Markets in Crypto-Assets regulation (Regulation (EU) 2023\u002F1114), is the single rulebook that decides which stablecoins can circulate in the European Union and who may issue them. Its stablecoin provisions have applied since June 30, 2024. The practical outcome for payment companies is simple: dollar and euro stablecoins in the EU must be e-money tokens issued by licensed institutions, USDC qualifies, USDT does not, and businesses that use compliant tokens through licensed providers carry none of the issuer obligations themselves.\n\nThis article explains the parts of MiCA that matter if you pay or get paid with stablecoins. For the wider global picture, see our [stablecoin regulation tracker](\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026).\n\n## What does MiCA actually regulate?\n\nMiCA covers crypto-assets that were not already regulated under EU financial law. It creates three regimes: one for e-money tokens (EMTs), one for asset-referenced tokens (ARTs), and one for other crypto-assets, plus a licensing regime for crypto-asset service providers (CASPs) such as exchanges and custodians.\n\nThe stablecoin rules (Titles III and IV) took effect June 30, 2024. CASP rules followed on December 30, 2024, with national grandfathering periods that ran into 2026 for firms already operating. As of 2026, the transition is essentially over: the EU market runs on authorized issuers and licensed service providers.\n\n## What is the difference between an EMT and an ART?\n\nAn e-money token references a single official currency: a dollar stablecoin or a euro stablecoin is an EMT. Under MiCA, only authorized credit institutions and electronic money institutions may issue EMTs, holders get a legal claim to redeem at par at any time, and issuers may not pay interest on holdings.\n\nAn asset-referenced token references a basket: multiple currencies, commodities, or crypto-assets. ARTs carry heavier capital, governance, and disclosure requirements and are rare in practice.\n\nFor payment flows, the distinction is almost academic: every stablecoin a business would use for payouts or settlement (USDC, EURC, and their peers) is an EMT. The label to look for is whether the issuer holds an EU authorization.\n\n## What must EMT issuers do under MiCA?\n\nThe issuer requirements explain why the compliant list is short:\n\n- **Authorization.** The issuer must be a licensed credit institution or electronic money institution in an EU member state.\n- **A white paper** notified to the regulator, describing the token, the reserve, and redemption rights.\n- **Full reserves** backing every token, segregated from the issuer's own assets, invested conservatively, with strict custody rules.\n- **Redemption at par, at any time**, free of charge for holders.\n- **No interest** paid on the token, which draws the line between payment instruments and deposit-like products.\n- **Significant EMT rules.** Tokens above thresholds for holders, market value, or transaction volume face extra requirements supervised by the European Banking Authority, including transaction-volume monitoring for tokens denominated in non-EU currencies used as a means of exchange.\n\n## Why is USDC available in the EU and USDT not?\n\nCircle became the first major global stablecoin issuer to comply: it obtained an electronic money institution license in France (supervised by the ACPR) on July 1, 2024, and issues both USDC and EURC as MiCA-compliant EMTs. That license passports across all EU member states.\n\nTether publicly chose not to seek MiCA authorization, criticizing the reserve requirements. The consequence arrived through the service-provider side: CASPs cannot offer non-compliant EMTs to EU customers, so regulated exchanges (Coinbase, Crypto.com, Binance for EEA users, and others) delisted USDT for EU customers between late 2024 and the first quarter of 2025.\n\nThe market read the signal. For any product that touches EU users, USDC became the default dollar stablecoin. Our comparison of the two tokens for payment use cases: [USDC vs USDT for payments](\u002Fresources\u002Fmore\u002Fusdc-vs-usdt-for-payments).\n\n## What does MiCA mean for a business that uses stablecoins?\n\nIf your company sends payouts, settles invoices, or holds working balances in stablecoins, MiCA does not turn you into a regulated entity. The obligations attach to issuers and service providers. Your responsibilities are choices:\n\n- **Choose compliant tokens for EU-touching flows.** USDC (and EURC for euro flows) as of 2026. A payout that starts in USDT can still reach an EU-adjacent receiver in local fiat, but the stablecoin leg should not be marketed or offered to EU users.\n- **Choose licensed partners.** If a provider custodies stablecoins or converts them for you in the EU, it should hold CASP authorization or operate through appropriately licensed entities. Ask; serious providers publish this. Ours is documented on the [compliance page](\u002Fcompliance).\n- **Mind where your users are.** MiCA applies to tokens offered to persons in the EU. A LatAm payout flow run by a US company is outside its scope, but the same company onboarding EU businesses is not.\n\n## How did the MiCA timeline unfold?\n\nThe rollout took three years and explains why 2026 feels settled:\n\n- **June 2023**: MiCA entered into force, starting the clock.\n- **June 30, 2024**: Titles III and IV applied; EMT and ART issuance without authorization became unlawful in the EU. Circle's French EMI license landed on July 1, 2024, making USDC the first major compliant dollar stablecoin.\n- **Late 2024 to Q1 2025**: CASP rules applied (December 30, 2024) and regulated exchanges completed USDT delistings for EU customers, following ESMA's guidance that non-compliant EMTs should be restricted.\n- **Through 2026**: national grandfathering periods for existing CASPs expired member state by member state; the EU market now runs end to end on authorized firms.\n\nThe lesson for payment companies watching other jurisdictions (Brazil's VASP transition, GENIUS Act rulemaking in the US): the binding date is rarely the law's publication, it is the moment service providers must drop non-compliant tokens. Distribution, not issuance, is where enforcement bites.\n\n## Who enforces MiCA?\n\nSupervision is layered. National competent authorities (the AMF and ACPR in France, BaFin in Germany, and their peers) license issuers and CASPs and police conduct in their markets. The European Banking Authority (EBA) takes direct supervision of significant EMTs and ARTs, the tokens large enough to matter for financial stability, and the European Securities and Markets Authority (ESMA) coordinates the CASP side and keeps the public registers of authorized firms.\n\nEnforcement so far has been structural rather than punitive: the effective sanction for a non-compliant token is exclusion from regulated distribution, as the USDT delistings showed. For a payment business, the practical check is not reading enforcement actions, it is checking the registers: an issuer should appear as an authorized EMI or credit institution, and an exchange or custodian should appear in ESMA's CASP register. If a partner is on neither list and claims EU coverage, that is the red flag.\n\n## What about euro stablecoins?\n\nMiCA did for the euro what no market force had: it created a regulated euro stablecoin category. EURC (Circle) and a handful of bank-issued euro EMTs now circulate, and EU merchants and platforms increasingly quote in them for on-chain settlement. Volumes remain a fraction of dollar tokens, but for EU-domestic flows a euro EMT avoids FX entirely: a payout that starts and ends in euros has no reason to route through a dollar. Significant-EMT rules also cap how far a non-euro (that is, dollar) token can go as a day-to-day means of exchange inside the EU, a deliberate nudge toward euro-denominated tokens for domestic European payments.\n\n## What is the practical checklist?\n\nFor a payment company reviewing MiCA exposure in 2026:\n\n1. Inventory which stablecoins your flows touch and which user geographies can hold them.\n2. Default EU-facing flows to MiCA-compliant EMTs (USDC, EURC).\n3. Verify your providers' licensing: EMI or credit institution status for issuers, CASP status for exchanges and custodians.\n4. Check redemption terms: compliant tokens redeem at par, always, free.\n5. Document the above; MiCA compliance questions now appear in enterprise procurement and bank due diligence.\n\n## How BlindPay fits in\n\nBlindPay is a stablecoin API for [global payments](\u002Fglobal-payments): businesses send USDC or USDT and receivers get local currency over Pix, SPEI, ACH, or wire in [100+ countries](\u002Fcoverage), with KYC, sanctions screening, and travel rule handling built into the flow. USDC, the EU-compliant token, is a first-class asset across the platform, including [virtual accounts](\u002Fvirtual-accounts) that convert incoming bank transfers to USDC automatically. Regulatory questions about a specific corridor are the kind of thing worth a [conversation](\u002Fcontact).\n\nPrimary sources: the MiCA text on [EUR-Lex](https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002F?uri=CELEX%3A32023R1114), ESMA's [MiCA hub](https:\u002F\u002Fwww.esma.europa.eu\u002Fesmas-activities\u002Fdigital-finance-and-innovation\u002Fmarkets-crypto-assets-regulation-mica), and the EBA's guidance on ARTs and EMTs ([eba.europa.eu](https:\u002F\u002Fwww.eba.europa.eu\u002Fregulation-and-policy\u002Fmarkets-crypto-assets-mica)). Status described as of August 2026.\n\n*This article is general information, not legal, tax, or financial advice.*\n",{"title":1900,"description":2165},"resources\u002Fmore\u002Fmica-stablecoin-rules-explained","qKN0jEvvvNS2dYel7qetoRnWpzaUxogDKuJFU9g_-K4",{"id":2185,"title":2186,"authors":6,"body":2187,"categories":6,"category":323,"categoryType":6,"compare":6,"contributors":6,"date":2164,"description":2393,"extension":326,"faq":2394,"howto":6,"isBlog":340,"isChangelog":340,"meta":2407,"navigation":343,"path":2408,"pillar":340,"products":6,"rawbody":2409,"role":6,"seo":2410,"stem":2411,"thumbnail":6,"updated":6,"__hash__":2412},"content\u002Fresources\u002Fmore\u002Fpsav-brazil-explained.md","PSAV in Brazil: the Central Bank's virtual asset license explained",{"type":8,"value":2188,"toc":2384},[2189,2192,2195,2199,2202,2209,2213,2216,2242,2247,2251,2254,2257,2261,2264,2296,2299,2303,2306,2334,2338,2352,2356,2379],[11,2190,2191],{},"PSAV (Prestadora de Serviços de Ativos Virtuais) is Brazil's regulatory regime for companies that provide virtual asset services: exchanging, transferring, custodying, or intermediating crypto and stablecoins for Brazilian customers. The Banco Central do Brasil created the authorization framework in Resolutions 519, 520, and 521, published November 10, 2025 and effective February 2, 2026, under the legal foundation of Law 14.478\u002F2022. Since that date, providing these services in Brazil without authorization or a transitional-regime position is illegal.",[11,2193,2194],{},"Brazil is not a side market for this regime. It is one of the largest stablecoin markets in the world, and Pix, the Central Bank's instant payment system used by over 150 million people, is where most stablecoin conversions land. The PSAV rules are the Central Bank taking direct supervision of the companies connecting those two worlds.",[28,2196,2198],{"id":2197},"what-is-a-psav","What is a PSAV?",[11,2200,2201],{},"A PSAV is a company authorized by the Banco Central do Brasil to provide virtual asset services. The resolutions define the authorized corporate form as an SPSAV, a Sociedade Prestadora de Serviços de Ativos Virtuais: a Brazilian legal entity whose corporate purpose is virtual asset services and which meets the Central Bank's requirements for capital, governance, and compliance. In practice the terms PSAV and SPSAV describe the same regime from two angles: the activity and the entity that performs it.",[11,2203,2204,2205,293],{},"The covered services follow the FATF definition of a virtual asset service provider (VASP): exchange between virtual assets and fiat currency, exchange between virtual assets, transfer of virtual assets, custody or administration of virtual assets, and participation in financial services related to an issuer's offer or sale of a virtual asset. A stablecoin off-ramp that converts USDC into reais over Pix sits squarely inside the first category. How those conversions work route by route is covered in ",[48,2206,2208],{"href":2207},"\u002Fresources\u002Fmore\u002Fusdc-to-brl-routes-2026","USDC to BRL in 2026",[28,2210,2212],{"id":2211},"which-rules-make-up-the-regime","Which rules make up the regime?",[11,2214,2215],{},"Three resolutions, one law, as of 2026:",[723,2217,2218,2224,2230,2236],{},[229,2219,2220,2223],{},[20,2221,2222],{},"Law 14.478\u002F2022"," created the legal framework for virtual asset services in Brazil and assigned supervision to the Banco Central do Brasil.",[229,2225,2226,2229],{},[20,2227,2228],{},"Resolution 519\u002F2025"," defines the regulated activities and classifies virtual asset services within the national financial system.",[229,2231,2232,2235],{},[20,2233,2234],{},"Resolution 520\u002F2025"," is the authorization rulebook: entity form, minimum capital, governance, fit-and-proper requirements for controllers and officers, and the application process. Its Article 88 created the transitional regime for companies already operating.",[229,2237,2238,2241],{},[20,2239,2240],{},"Resolution 521\u002F2025"," sets the ongoing conduct rules: AML\u002FCFT obligations, customer asset segregation, reporting, and operational requirements.",[11,2243,2244,2245,293],{},"Together they moved Brazil from a market where crypto companies operated under general law to one where the Central Bank licenses and supervises them the way it supervises payment institutions. The broader global picture, including MiCA and the GENIUS Act, is in the ",[48,2246,409],{"href":408},[28,2248,2250],{"id":2249},"who-needs-the-authorization","Who needs the authorization?",[11,2252,2253],{},"Any company serving Brazilian residents with virtual asset services, whether from inside Brazil or offshore. The regime deliberately closes the offshore loophole: targeting the Brazilian market triggers the requirement regardless of where the servers or the corporate entity sit. Foreign exchanges and stablecoin infrastructure companies serving Brazil face the same choice as local ones: incorporate an SPSAV and apply, or exit the market.",[11,2255,2256],{},"Two groups matter for the transition. Companies that started operating before the regime took effect could invoke Article 88 of Resolution 520: they file for authorization within the transitional window and continue operating legally while the Central Bank processes the application. Companies that were not operating before the cutoff must obtain authorization first and operate second. The Central Bank has shown it will enforce the boundary; it has moved against institutions running virtual asset operations outside the permitted structure.",[28,2258,2260],{"id":2259},"what-does-a-psav-have-to-do-in-practice","What does a PSAV have to do in practice?",[11,2262,2263],{},"The obligations look like what Brazil already requires of payment institutions, adapted to virtual assets:",[723,2265,2266,2272,2278,2284,2290],{},[229,2267,2268,2271],{},[20,2269,2270],{},"Corporate substance."," A Brazilian entity (the SPSAV) with the required minimum capital, local governance, and named responsible officers who pass fit-and-proper review.",[229,2273,2274,2277],{},[20,2275,2276],{},"AML\u002FCFT program."," Customer identification (CPF\u002FCNPJ), transaction monitoring, sanctions screening, suspicious activity reporting to COAF, and travel rule data handling on transfers.",[229,2279,2280,2283],{},[20,2281,2282],{},"Asset segregation."," Customer virtual assets separated from the company's own, with controls the Central Bank can examine.",[229,2285,2286,2289],{},[20,2287,2288],{},"Reporting and transparency."," Periodic regulatory reporting, incident notification, and cooperation with Central Bank supervision.",[229,2291,2292,2295],{},[20,2293,2294],{},"Tax reporting."," Alongside the BCB regime, Receita Federal expanded crypto transaction reporting through Normative Instruction 2,291\u002F2025.",[11,2297,2298],{},"For a business using a provider rather than becoming one, the checklist inverts: you do not need your own PSAV authorization to pay contractors in Brazil through an authorized provider. You need your provider to have one, or to be lawfully inside the transitional regime, because that is what makes the reais leg of your payout legal, supervised, and recoverable if something breaks.",[28,2300,2302],{"id":2301},"how-does-this-affect-stablecoin-payouts-to-brazil","How does this affect stablecoin payouts to Brazil?",[11,2304,2305],{},"Concretely, three things changed for cross-border money movement in 2026:",[226,2307,2308,2314,2323],{},[229,2309,2310,2313],{},[20,2311,2312],{},"Provider due diligence became a compliance requirement, not a preference."," If your payout provider's Brazil leg runs through an unauthorized intermediary, your payments inherit that risk. Ask any provider for its SPSAV entity, CNPJ, and regime status; a serious one publishes them.",[229,2315,2316,2319,2320,293],{},[20,2317,2318],{},"Receiver verification got stricter rails."," Pix already rejects transfers where the beneficiary name and CPF\u002FCNPJ do not match the receiving account, and PSAV-regulated providers must run KYC and sanctions screening on receivers before converting. The full picture of what providers verify is in ",[48,2321,2322],{"href":472},"stablecoin payments explained",[229,2324,2325,2328,2329,2333],{},[20,2326,2327],{},"The market cleaned up."," Offshore providers without a Brazilian entity are exiting or restructuring, which concentrates volume in authorized providers and makes the \"which provider\" question, covered in ",[48,2330,2332],{"href":2331},"\u002Fresources\u002Fmore\u002Fbest-stablecoin-payment-providers-2026","best stablecoin payment providers in 2026",", largely a regulatory question in Brazil.",[28,2335,2337],{"id":2336},"how-does-blindpay-operate-under-the-psav-regime","How does BlindPay operate under the PSAV regime?",[11,2339,2340,2341,2343,2344,2346,2347,2351],{},"BlindPay's Brazilian operating entity is BLIND PAY SOCIEDADE PRESTADORA DE SERVIÇOS DE ATIVOS VIRTUAIS LTDA, a dedicated SPSAV. The company is completing the regulatory adaptation process required by Central Bank Resolution 520\u002F2025 and operates under the transitional regime set forth in Article 88 of that Resolution, which authorizes continued operation while the application is processed. Entity details, CNPJ numbers, and the full registration picture across markets are published on the ",[48,2342,1015],{"href":1014},", and our ",[48,2345,287],{"href":286}," describes the program that runs on top: KYC and KYB, sanctions screening, and travel rule handling on every ",[48,2348,2350],{"href":2349},"\u002Fusdc-to-brl","USDC or USDT to BRL"," payout.",[28,2353,2355],{"id":2354},"methodology-and-sources","Methodology and sources",[11,2357,2358,2359,2364,2365,2370,2371,2376,2377,293],{},"Regulatory facts from primary sources as of August 2026: Law 14.478\u002F2022 (",[48,2360,2363],{"href":2361,"rel":2362},"https:\u002F\u002Fwww.planalto.gov.br\u002Fccivil_03\u002F_ato2019-2022\u002F2022\u002Flei\u002FL14478.htm",[422],"planalto.gov.br","), Banco Central do Brasil Resolutions 519, 520, and 521 of November 10, 2025 (",[48,2366,2369],{"href":2367,"rel":2368},"https:\u002F\u002Fwww.bcb.gov.br",[422],"bcb.gov.br","), the BCB's Pix documentation (",[48,2372,2375],{"href":2373,"rel":2374},"https:\u002F\u002Fwww.bcb.gov.br\u002Fen\u002Ffinancialstability\u002Fpix_en",[422],"bcb.gov.br\u002Fen\u002Ffinancialstability\u002Fpix_en","), and Receita Federal Normative Instruction 2,291\u002F2025. BlindPay entity and status details from the published ",[48,2378,1015],{"href":1014},[11,2380,2381],{},[14,2382,2383],{},"This article is general information, not legal, tax, or financial advice. Businesses operating in or serving Brazil should consult Brazilian counsel on their specific regulatory position.",{"title":307,"searchDepth":308,"depth":308,"links":2385},[2386,2387,2388,2389,2390,2391,2392],{"id":2197,"depth":308,"text":2198},{"id":2211,"depth":308,"text":2212},{"id":2249,"depth":308,"text":2250},{"id":2259,"depth":308,"text":2260},{"id":2301,"depth":308,"text":2302},{"id":2336,"depth":308,"text":2337},{"id":2354,"depth":308,"text":2355},"PSAV is Brazil's authorization for virtual asset service providers, created by BCB Resolutions 519, 520, and 521 under Law 14.478\u002F2022. What it requires and who needs it.",[2395,2398,2401,2404],{"q":2396,"a":2397},"What does PSAV stand for?","Prestadora de Serviços de Ativos Virtuais, provider of virtual asset services. The Central Bank's resolutions use the corporate form SPSAV, Sociedade Prestadora de Serviços de Ativos Virtuais, for the authorized entity. Both refer to the same regime.",{"q":2399,"a":2400},"Who needs a PSAV authorization in Brazil?","Any company providing virtual asset services to people or businesses in Brazil: exchanging crypto for reais, transferring virtual assets, custodying them, or intermediating those services. This includes stablecoin on-ramps and off-ramps.",{"q":2402,"a":2403},"When did Brazil's PSAV rules take effect?","The Central Bank published Resolutions 519, 520, and 521 on November 10, 2025, effective February 2, 2026. Companies already operating got a transitional window under Article 88 of Resolution 520 to apply for authorization while continuing to operate.",{"q":2405,"a":2406},"Is BlindPay authorized to operate in Brazil?","BlindPay's Brazilian operating entity is a Sociedade Prestadora de Serviços de Ativos Virtuais completing the adaptation process required by Resolution 520\u002F2025, and operates under the transitional regime of Article 88. Details are on the licenses page.",{"author":342},"\u002Fresources\u002Fmore\u002Fpsav-brazil-explained","---\ntitle: \"PSAV in Brazil: the Central Bank's virtual asset license explained\"\ndescription: \"PSAV is Brazil's authorization for virtual asset service providers, created by BCB Resolutions 519, 520, and 521 under Law 14.478\u002F2022. What it requires and who needs it.\"\ndate: \"2026-08-15\"\ncategory: \"compliance\"\nauthor: \"BlindPay Team\"\nfaq:\n  - q: \"What does PSAV stand for?\"\n    a: \"Prestadora de Serviços de Ativos Virtuais, provider of virtual asset services. The Central Bank's resolutions use the corporate form SPSAV, Sociedade Prestadora de Serviços de Ativos Virtuais, for the authorized entity. Both refer to the same regime.\"\n  - q: \"Who needs a PSAV authorization in Brazil?\"\n    a: \"Any company providing virtual asset services to people or businesses in Brazil: exchanging crypto for reais, transferring virtual assets, custodying them, or intermediating those services. This includes stablecoin on-ramps and off-ramps.\"\n  - q: \"When did Brazil's PSAV rules take effect?\"\n    a: \"The Central Bank published Resolutions 519, 520, and 521 on November 10, 2025, effective February 2, 2026. Companies already operating got a transitional window under Article 88 of Resolution 520 to apply for authorization while continuing to operate.\"\n  - q: \"Is BlindPay authorized to operate in Brazil?\"\n    a: \"BlindPay's Brazilian operating entity is a Sociedade Prestadora de Serviços de Ativos Virtuais completing the adaptation process required by Resolution 520\u002F2025, and operates under the transitional regime of Article 88. Details are on the licenses page.\"\n---\n\nPSAV (Prestadora de Serviços de Ativos Virtuais) is Brazil's regulatory regime for companies that provide virtual asset services: exchanging, transferring, custodying, or intermediating crypto and stablecoins for Brazilian customers. The Banco Central do Brasil created the authorization framework in Resolutions 519, 520, and 521, published November 10, 2025 and effective February 2, 2026, under the legal foundation of Law 14.478\u002F2022. Since that date, providing these services in Brazil without authorization or a transitional-regime position is illegal.\n\nBrazil is not a side market for this regime. It is one of the largest stablecoin markets in the world, and Pix, the Central Bank's instant payment system used by over 150 million people, is where most stablecoin conversions land. The PSAV rules are the Central Bank taking direct supervision of the companies connecting those two worlds.\n\n## What is a PSAV?\n\nA PSAV is a company authorized by the Banco Central do Brasil to provide virtual asset services. The resolutions define the authorized corporate form as an SPSAV, a Sociedade Prestadora de Serviços de Ativos Virtuais: a Brazilian legal entity whose corporate purpose is virtual asset services and which meets the Central Bank's requirements for capital, governance, and compliance. In practice the terms PSAV and SPSAV describe the same regime from two angles: the activity and the entity that performs it.\n\nThe covered services follow the FATF definition of a virtual asset service provider (VASP): exchange between virtual assets and fiat currency, exchange between virtual assets, transfer of virtual assets, custody or administration of virtual assets, and participation in financial services related to an issuer's offer or sale of a virtual asset. A stablecoin off-ramp that converts USDC into reais over Pix sits squarely inside the first category. How those conversions work route by route is covered in [USDC to BRL in 2026](\u002Fresources\u002Fmore\u002Fusdc-to-brl-routes-2026).\n\n## Which rules make up the regime?\n\nThree resolutions, one law, as of 2026:\n\n- **Law 14.478\u002F2022** created the legal framework for virtual asset services in Brazil and assigned supervision to the Banco Central do Brasil.\n- **Resolution 519\u002F2025** defines the regulated activities and classifies virtual asset services within the national financial system.\n- **Resolution 520\u002F2025** is the authorization rulebook: entity form, minimum capital, governance, fit-and-proper requirements for controllers and officers, and the application process. Its Article 88 created the transitional regime for companies already operating.\n- **Resolution 521\u002F2025** sets the ongoing conduct rules: AML\u002FCFT obligations, customer asset segregation, reporting, and operational requirements.\n\nTogether they moved Brazil from a market where crypto companies operated under general law to one where the Central Bank licenses and supervises them the way it supervises payment institutions. The broader global picture, including MiCA and the GENIUS Act, is in the [stablecoin regulation tracker](\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026).\n\n## Who needs the authorization?\n\nAny company serving Brazilian residents with virtual asset services, whether from inside Brazil or offshore. The regime deliberately closes the offshore loophole: targeting the Brazilian market triggers the requirement regardless of where the servers or the corporate entity sit. Foreign exchanges and stablecoin infrastructure companies serving Brazil face the same choice as local ones: incorporate an SPSAV and apply, or exit the market.\n\nTwo groups matter for the transition. Companies that started operating before the regime took effect could invoke Article 88 of Resolution 520: they file for authorization within the transitional window and continue operating legally while the Central Bank processes the application. Companies that were not operating before the cutoff must obtain authorization first and operate second. The Central Bank has shown it will enforce the boundary; it has moved against institutions running virtual asset operations outside the permitted structure.\n\n## What does a PSAV have to do in practice?\n\nThe obligations look like what Brazil already requires of payment institutions, adapted to virtual assets:\n\n- **Corporate substance.** A Brazilian entity (the SPSAV) with the required minimum capital, local governance, and named responsible officers who pass fit-and-proper review.\n- **AML\u002FCFT program.** Customer identification (CPF\u002FCNPJ), transaction monitoring, sanctions screening, suspicious activity reporting to COAF, and travel rule data handling on transfers.\n- **Asset segregation.** Customer virtual assets separated from the company's own, with controls the Central Bank can examine.\n- **Reporting and transparency.** Periodic regulatory reporting, incident notification, and cooperation with Central Bank supervision.\n- **Tax reporting.** Alongside the BCB regime, Receita Federal expanded crypto transaction reporting through Normative Instruction 2,291\u002F2025.\n\nFor a business using a provider rather than becoming one, the checklist inverts: you do not need your own PSAV authorization to pay contractors in Brazil through an authorized provider. You need your provider to have one, or to be lawfully inside the transitional regime, because that is what makes the reais leg of your payout legal, supervised, and recoverable if something breaks.\n\n## How does this affect stablecoin payouts to Brazil?\n\nConcretely, three things changed for cross-border money movement in 2026:\n\n1. **Provider due diligence became a compliance requirement, not a preference.** If your payout provider's Brazil leg runs through an unauthorized intermediary, your payments inherit that risk. Ask any provider for its SPSAV entity, CNPJ, and regime status; a serious one publishes them.\n2. **Receiver verification got stricter rails.** Pix already rejects transfers where the beneficiary name and CPF\u002FCNPJ do not match the receiving account, and PSAV-regulated providers must run KYC and sanctions screening on receivers before converting. The full picture of what providers verify is in [stablecoin payments explained](\u002Fresources\u002Fmore\u002Fstablecoin-payments-guide).\n3. **The market cleaned up.** Offshore providers without a Brazilian entity are exiting or restructuring, which concentrates volume in authorized providers and makes the \"which provider\" question, covered in [best stablecoin payment providers in 2026](\u002Fresources\u002Fmore\u002Fbest-stablecoin-payment-providers-2026), largely a regulatory question in Brazil.\n\n## How does BlindPay operate under the PSAV regime?\n\nBlindPay's Brazilian operating entity is BLIND PAY SOCIEDADE PRESTADORA DE SERVIÇOS DE ATIVOS VIRTUAIS LTDA, a dedicated SPSAV. The company is completing the regulatory adaptation process required by Central Bank Resolution 520\u002F2025 and operates under the transitional regime set forth in Article 88 of that Resolution, which authorizes continued operation while the application is processed. Entity details, CNPJ numbers, and the full registration picture across markets are published on the [licenses page](\u002Flicenses), and our [compliance page](\u002Fcompliance) describes the program that runs on top: KYC and KYB, sanctions screening, and travel rule handling on every [USDC or USDT to BRL](\u002Fusdc-to-brl) payout.\n\n## Methodology and sources\n\nRegulatory facts from primary sources as of August 2026: Law 14.478\u002F2022 ([planalto.gov.br](https:\u002F\u002Fwww.planalto.gov.br\u002Fccivil_03\u002F_ato2019-2022\u002F2022\u002Flei\u002FL14478.htm)), Banco Central do Brasil Resolutions 519, 520, and 521 of November 10, 2025 ([bcb.gov.br](https:\u002F\u002Fwww.bcb.gov.br)), the BCB's Pix documentation ([bcb.gov.br\u002Fen\u002Ffinancialstability\u002Fpix_en](https:\u002F\u002Fwww.bcb.gov.br\u002Fen\u002Ffinancialstability\u002Fpix_en)), and Receita Federal Normative Instruction 2,291\u002F2025. BlindPay entity and status details from the published [licenses page](\u002Flicenses).\n\n*This article is general information, not legal, tax, or financial advice. Businesses operating in or serving Brazil should consult Brazilian counsel on their specific regulatory position.*\n",{"title":2186,"description":2393},"resources\u002Fmore\u002Fpsav-brazil-explained","izsoHKzc-8SrLHNoXqpjLzhjPwH0qqPJcsmle-MNcH0",{"id":4,"title":5,"authors":6,"body":2414,"categories":6,"category":323,"categoryType":6,"compare":6,"contributors":6,"date":324,"description":325,"extension":326,"faq":2614,"howto":6,"isBlog":340,"isChangelog":340,"meta":2619,"navigation":343,"path":344,"pillar":340,"products":6,"rawbody":345,"role":6,"seo":2620,"stem":347,"thumbnail":6,"updated":324,"__hash__":348},{"type":8,"value":2415,"toc":2600},[2416,2420,2424,2426,2428,2430,2434,2440,2444,2446,2448,2452,2454,2456,2458,2460,2462,2464,2466,2468,2470,2472,2474,2476,2478,2540,2542,2544,2546,2548,2550,2580,2582,2584,2586,2592,2594,2596],[11,2417,2418],{},[14,2419,16],{},[11,2421,2422,23],{},[20,2423,22],{},[11,2425,26],{},[28,2427,31],{"id":30},[11,2429,34],{},[11,2431,2432,40],{},[20,2433,39],{},[11,2435,2436,46,2438,52],{},[20,2437,45],{},[48,2439,51],{"href":50},[11,2441,2442,58],{},[20,2443,57],{},[11,2445,61],{},[28,2447,65],{"id":64},[11,2449,68,2450,73],{},[48,2451,72],{"href":71},[75,2453,78],{"id":77},[11,2455,81],{},[75,2457,85],{"id":84},[11,2459,88],{},[75,2461,92],{"id":91},[11,2463,95],{},[75,2465,99],{"id":98},[11,2467,102],{},[75,2469,106],{"id":105},[11,2471,109],{},[11,2473,112],{},[28,2475,116],{"id":115},[11,2477,119],{},[121,2479,2480,2490],{},[124,2481,2482],{},[127,2483,2484,2486,2488],{},[130,2485,132],{},[130,2487,135],{},[130,2489,138],{},[140,2491,2492,2500,2508,2516,2524,2532],{},[127,2493,2494,2496,2498],{},[145,2495,147],{},[145,2497,150],{},[145,2499,153],{},[127,2501,2502,2504,2506],{},[145,2503,158],{},[145,2505,161],{},[145,2507,164],{},[127,2509,2510,2512,2514],{},[145,2511,169],{},[145,2513,172],{},[145,2515,175],{},[127,2517,2518,2520,2522],{},[145,2519,180],{},[145,2521,183],{},[145,2523,186],{},[127,2525,2526,2528,2530],{},[145,2527,191],{},[145,2529,194],{},[145,2531,197],{},[127,2533,2534,2536,2538],{},[145,2535,202],{},[145,2537,205],{},[145,2539,208],{},[11,2541,211],{},[28,2543,215],{"id":214},[11,2545,218],{},[11,2547,221],{},[11,2549,224],{},[226,2551,2552,2556,2560,2564,2568,2572,2576],{},[229,2553,2554,234],{},[20,2555,233],{},[229,2557,2558,240],{},[20,2559,239],{},[229,2561,2562,246],{},[20,2563,245],{},[229,2565,2566,252],{},[20,2567,251],{},[229,2569,2570,258],{},[20,2571,257],{},[229,2573,2574,264],{},[20,2575,263],{},[229,2577,2578,270],{},[20,2579,269],{},[11,2581,273],{},[28,2583,277],{"id":276},[11,2585,280],{},[11,2587,283,2588,288,2590,293],{},[48,2589,287],{"href":286},[48,2591,292],{"href":291},[28,2593,297],{"id":296},[11,2595,300],{},[11,2597,2598],{},[14,2599,305],{},{"title":307,"searchDepth":308,"depth":308,"links":2601},[2602,2603,2610,2611,2612,2613],{"id":30,"depth":308,"text":31},{"id":64,"depth":308,"text":65,"children":2604},[2605,2606,2607,2608,2609],{"id":77,"depth":314,"text":78},{"id":84,"depth":314,"text":85},{"id":91,"depth":314,"text":92},{"id":98,"depth":314,"text":99},{"id":105,"depth":314,"text":106},{"id":115,"depth":308,"text":116},{"id":214,"depth":308,"text":215},{"id":276,"depth":308,"text":277},{"id":296,"depth":308,"text":297},[2615,2616,2617,2618],{"q":329,"a":330},{"q":332,"a":333},{"q":335,"a":336},{"q":338,"a":339},{"author":342},{"title":5,"description":325},{"id":2622,"title":2623,"authors":6,"body":2624,"categories":6,"category":323,"categoryType":6,"compare":6,"contributors":6,"date":2164,"description":2932,"extension":326,"faq":2933,"howto":6,"isBlog":340,"isChangelog":340,"meta":2946,"navigation":343,"path":408,"pillar":340,"products":6,"rawbody":2947,"role":6,"seo":2948,"stem":2949,"thumbnail":6,"updated":6,"__hash__":2950},"content\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026.md","Stablecoin regulation in 2026: MiCA, the GENIUS Act, Brazil, and Japan",{"type":8,"value":2625,"toc":2921},[2626,2629,2635,2639,2642,2645,2652,2656,2659,2662,2665,2669,2672,2675,2685,2689,2692,2695,2699,2790,2793,2797,2800,2820,2823,2827,2830,2858,2865,2869,2886,2888,2917],[11,2627,2628],{},"Stablecoin regulation stopped being a gray zone. As of 2026, the four markets that matter most to cross-border payment businesses all have dedicated rules in force: the EU's Markets in Crypto-Assets regulation (MiCA), the US GENIUS Act, Brazil's virtual asset framework under Law 14.478\u002F2022 and Central Bank Resolutions 519, 520, and 521, and Japan's revised Payment Services Act. The direction is the same everywhere: fully reserved, licensed, auditable digital dollars (and euros, and yen) are welcome; everything else is being pushed out of the regulated system.",[11,2630,2631,2632,293],{},"This tracker summarizes each regime and what it means in practice for businesses that pay or get paid with stablecoins. For the basics of how these payments work, start with our ",[48,2633,2634],{"href":472},"guide to stablecoin payments",[28,2636,2638],{"id":2637},"what-does-mica-require-of-stablecoin-issuers","What does MiCA require of stablecoin issuers?",[11,2640,2641],{},"MiCA (Regulation (EU) 2023\u002F1114) is the EU's single rulebook for crypto-assets. Its stablecoin provisions have applied since June 30, 2024, and full application for crypto-asset service providers began at the end of 2024, with national transition periods running through 2026.",[11,2643,2644],{},"MiCA splits stablecoins into two categories. E-money tokens (EMTs) reference a single fiat currency and can only be issued by licensed credit institutions or electronic money institutions. Asset-referenced tokens (ARTs) reference baskets of assets and carry heavier requirements. For payment businesses, EMTs are the category that matters: a dollar or euro stablecoin used for payouts is an EMT.",[11,2646,2647,2648,2651],{},"The practical consequences showed up fast. Circle obtained an electronic money institution license in France and issues USDC and EURC as MiCA-compliant EMTs. Tether chose not to pursue authorization, and USDT was delisted from most EU-regulated exchanges. If your business touches EU customers or EU rails, your stablecoin choice is effectively made for you. Our ",[48,2649,2650],{"href":1433},"MiCA explainer for payment companies"," covers the details.",[28,2653,2655],{"id":2654},"what-is-the-genius-act","What is the GENIUS Act?",[11,2657,2658],{},"The GENIUS Act (Guiding and Establishing National Innovation for US Stablecoins Act), signed in July 2025, is the first US federal law dedicated to payment stablecoins. Before it, US stablecoin issuers operated under a patchwork of state money transmitter licenses and trust charters.",[11,2660,2661],{},"The core requirements: payment stablecoin issuers must hold reserves 1:1 in cash, insured deposits, and short-term US Treasuries; they must be licensed either federally or under a qualifying state regime; they must publish monthly reserve disclosures; and they face restrictions on paying interest to holders. Issuers of a certain size fall under federal supervision.",[11,2663,2664],{},"For payment businesses, the GENIUS Act removed the biggest US legal question: whether regulated companies could rely on stablecoins at all. The answer is now yes, provided the stablecoin comes from a licensed issuer. It also accelerated bank and fintech adoption; Reuters reported stablecoin circulation passing 250 billion dollars in 2025, with regulated issuers taking a growing share.",[28,2666,2668],{"id":2667},"how-does-brazil-regulate-stablecoins-and-vasps","How does Brazil regulate stablecoins and VASPs?",[11,2670,2671],{},"Brazil moved earlier than most. Law 14.478\u002F2022 created the legal framework for virtual asset service providers (VASPs) and assigned supervision to the Banco Central do Brasil (BCB). In November 2025 the BCB published Resolutions 519, 520, and 521, which took effect on February 2, 2026, and created the SPSAV regime: companies providing virtual asset services in Brazil must obtain authorization, with a transition window under Article 88 of Resolution 520 for companies already operating.",[11,2673,2674],{},"Two things make Brazil special for stablecoin payments. First, Pix: the BCB's instant payment system settles transfers in seconds, 24\u002F7, and is the default way Brazilians move money. A stablecoin payout that ends in Pix reaches the receiver faster than an international wire by days. Second, enforcement is practical: Pix payouts require the receiver's name and tax ID (CPF or CNPJ) to match the receiving account, so accurate beneficiary data is a hard requirement, not a nice-to-have.",[11,2676,2677,2678,2681,2682,293],{},"The authorization regime itself, who needs it, and what it requires are covered in ",[48,2679,2680],{"href":2408},"PSAV in Brazil explained",", and we compare the concrete cash-out options, fees, and rules in ",[48,2683,2684],{"href":2207},"USDC to BRL in 2026: routes, fees, and rules compared",[28,2686,2688],{"id":2687},"what-are-japans-stablecoin-rules","What are Japan's stablecoin rules?",[11,2690,2691],{},"Japan regulated stablecoins before either the EU or the US. The revised Payment Services Act, in force since June 2023, treats fiat-pegged stablecoins as electronic payment instruments. Only licensed banks, registered money transfer agents, and trust companies may issue them, and issuers must guarantee redemption at face value. Distribution requires registration as an electronic payment instruments service provider with the Financial Services Agency (FSA).",[11,2693,2694],{},"The first yen-denominated stablecoins under this regime launched in 2025, and Japan continues to refine the framework, with the FSA studying reserve flexibility and intermediary rules. For global payment businesses, Japan matters less for day-to-day payouts than the EU, US, or Brazil, but it shows where regulation converges: licensed issuers, full reserves, guaranteed redemption.",[28,2696,2698],{"id":2697},"how-do-the-four-regimes-compare","How do the four regimes compare?",[121,2700,2701,2720],{},[124,2702,2703],{},[127,2704,2705,2708,2711,2714,2717],{},[130,2706,2707],{},"Regime",[130,2709,2710],{},"In force",[130,2712,2713],{},"Who may issue",[130,2715,2716],{},"Reserve rule",[130,2718,2719],{},"Supervisor",[140,2721,2722,2739,2756,2773],{},[127,2723,2724,2727,2730,2733,2736],{},[145,2725,2726],{},"MiCA (EU)",[145,2728,2729],{},"Stablecoin titles since June 2024",[145,2731,2732],{},"Credit institutions, licensed EMIs",[145,2734,2735],{},"Full backing, segregated, redemption at par",[145,2737,2738],{},"National regulators, EBA for significant tokens",[127,2740,2741,2744,2747,2750,2753],{},[145,2742,2743],{},"GENIUS Act (US)",[145,2745,2746],{},"Signed July 2025",[145,2748,2749],{},"Federally or state-licensed payment stablecoin issuers",[145,2751,2752],{},"1:1 in cash, insured deposits, short-term Treasuries; monthly disclosure",[145,2754,2755],{},"OCC and state regulators",[127,2757,2758,2761,2764,2767,2770],{},[145,2759,2760],{},"Brazil (Law 14.478 + BCB 519\u002F520\u002F521)",[145,2762,2763],{},"VASP regime effective February 2026",[145,2765,2766],{},"Issuance and services by authorized SPSAVs",[145,2768,2769],{},"Governance and segregation duties under BCB rules",[145,2771,2772],{},"Banco Central do Brasil",[127,2774,2775,2778,2781,2784,2787],{},[145,2776,2777],{},"Japan (Payment Services Act)",[145,2779,2780],{},"Revised rules since June 2023",[145,2782,2783],{},"Banks, money transfer agents, trust companies",[145,2785,2786],{},"Redemption at face value guaranteed",[145,2788,2789],{},"Financial Services Agency",[11,2791,2792],{},"Differences remain in the details (interest bans, disclosure cadence, licensing paths), but the convergence is unmistakable. A stablecoin that is fully reserved, redeemable at par, and issued by a licensed institution clears the bar everywhere; anything else faces shrinking room.",[28,2794,2796],{"id":2795},"where-is-regulation-still-unsettled","Where is regulation still unsettled?",[11,2798,2799],{},"Three open fronts worth tracking through the rest of 2026:",[723,2801,2802,2808,2814],{},[229,2803,2804,2807],{},[20,2805,2806],{},"Interest and yield."," The GENIUS Act bars issuers from paying interest on payment stablecoins, and MiCA does the same for EMTs. Yield-bearing wrappers and tokenized money market funds sit outside these definitions, and regulators on both sides of the Atlantic are still deciding how to treat them when they behave like payment balances.",[229,2809,2810,2813],{},[20,2811,2812],{},"Foreign-issuer access."," Both the EU and the US are refining how offshore issuers reach their markets: MiCA through equivalence-style conditions on non-EU EMTs, the US through GENIUS Act rules on foreign payment stablecoin issuers. Where these land will decide how global a single token's distribution can be.",[229,2815,2816,2819],{},[20,2817,2818],{},"Brazil's transition window."," Companies operating before Resolutions 519\u002F520\u002F521 have Article 88 transition status while their SPSAV authorizations process. Expect the authorized list to firm up through 2026 and diligence questions to shift from \"are you applying?\" to \"are you authorized?\".",[11,2821,2822],{},"None of these change the direction. They change who is allowed to distribute, and how fast.",[28,2824,2826],{"id":2825},"what-should-payment-businesses-do-about-it","What should payment businesses do about it?",[11,2828,2829],{},"The pattern across all four regimes is consistent, and it points to a short checklist:",[723,2831,2832,2838,2844,2852],{},[229,2833,2834,2837],{},[20,2835,2836],{},"Use stablecoins from regulated issuers."," USDC and other licensed EMT\u002FGENIUS-compliant tokens are accepted across all four regimes. Unregulated tokens increasingly are not.",[229,2839,2840,2843],{},[20,2841,2842],{},"Let a licensed provider carry the regulatory load."," Payout providers that hold the required registrations (money transmission in the US, VASP authorization in Brazil, CASP status in the EU) take on custody, KYC, sanctions screening, and travel rule obligations. Building this yourself means acquiring licenses market by market.",[229,2845,2846,2849,2850,293],{},[20,2847,2848],{},"Get beneficiary data right."," Brazil's name and tax ID matching is the strictest example, but every regime requires accurate sender and receiver information under travel rule requirements. Thresholds and data formats by market are in our ",[48,2851,292],{"href":291},[229,2853,2854,2857],{},[20,2855,2856],{},"Watch reserve and redemption terms."," Regulation now guarantees that a compliant stablecoin redeems 1:1. If a token's terms do not say that plainly, it does not belong in a payment flow.",[11,2859,2860,2861,2864],{},"Compliance is becoming the differentiator between providers, not an afterthought. Our own ",[48,2862,2863],{"href":286},"compliance framework"," documents how we approach it.",[28,2866,2868],{"id":2867},"how-blindpay-handles-regulation-for-you","How BlindPay handles regulation for you",[11,2870,2871,2872,2874,2875,2878,2879,2883,2884,293],{},"BlindPay is a stablecoin API for global payments: businesses send USDC or USDT and receivers get local currency over Pix, SPEI, ACH, or wire, in ",[48,2873,2117],{"href":2116},". The regulatory work is built into the flow: KYC and KYB on receivers before money moves, sanctions screening, travel rule data handling, and local rail requirements like Brazil's name and tax ID matching. ",[48,2876,2877],{"href":2121},"Virtual accounts"," extend the same model to collections, converting incoming bank transfers to stablecoins automatically. Pricing is public on the ",[48,2880,2882],{"href":2881},"\u002Fpricing","pricing page",", and the team can walk through specific regulatory questions via ",[48,2885,1112],{"href":1111},[28,2887,2355],{"id":2354},[11,2889,2890,2891,2895,2896,2900,2901,2906,2907,2910,2911,2916],{},"Regime details from primary sources: MiCA text, Regulation (EU) 2023\u002F1114 (",[48,2892,2894],{"href":2131,"rel":2893},[422],"eur-lex.europa.eu",") and ESMA's MiCA hub (",[48,2897,2899],{"href":2137,"rel":2898},[422],"esma.europa.eu","); the GENIUS Act, S.1582, 119th Congress (",[48,2902,2905],{"href":2903,"rel":2904},"https:\u002F\u002Fwww.congress.gov\u002Fbill\u002F119th-congress\u002Fsenate-bill\u002F1582",[422],"congress.gov","); Brazil's Law 14.478\u002F2022 and BCB Resolutions 519, 520, and 521 plus the Pix system description (",[48,2908,2369],{"href":2373,"rel":2909},[422],"); Japan's Payment Services Act framework via the Financial Services Agency (",[48,2912,2915],{"href":2913,"rel":2914},"https:\u002F\u002Fwww.fsa.go.jp\u002Fen\u002F",[422],"fsa.go.jp","). Regulatory status described as of August 2026.",[11,2918,2919],{},[14,2920,2151],{},{"title":307,"searchDepth":308,"depth":308,"links":2922},[2923,2924,2925,2926,2927,2928,2929,2930,2931],{"id":2637,"depth":308,"text":2638},{"id":2654,"depth":308,"text":2655},{"id":2667,"depth":308,"text":2668},{"id":2687,"depth":308,"text":2688},{"id":2697,"depth":308,"text":2698},{"id":2795,"depth":308,"text":2796},{"id":2825,"depth":308,"text":2826},{"id":2867,"depth":308,"text":2868},{"id":2354,"depth":308,"text":2355},"Where stablecoin regulation stands in 2026: MiCA in the EU, the GENIUS Act in the US, Brazil's VASP regime, and Japan's issuer rules, compared for payment businesses.",[2934,2937,2940,2943],{"q":2935,"a":2936},"Is it legal for businesses to use stablecoins for payments?","Yes, in most major markets, provided the business or its provider complies with local rules. The EU regulates stablecoins under MiCA, the US under the GENIUS Act and money transmission laws, Brazil under Law 14.478\u002F2022 and BCB resolutions, and Japan under the revised Payment Services Act. What matters is who issues the stablecoin and who handles the conversion to fiat.",{"q":2938,"a":2939},"Which stablecoins are compliant in the EU under MiCA?","As of 2026, USDC is available in the EU because Circle obtained an electronic money institution license in France and issues USDC as a MiCA-compliant e-money token. USDT has been delisted from most EU-regulated exchanges because Tether did not pursue MiCA authorization.",{"q":2941,"a":2942},"What is the GENIUS Act in simple terms?","The GENIUS Act is the first US federal law dedicated to payment stablecoins. It requires issuers to hold 1:1 reserves in cash and short-term Treasuries, to be licensed at the federal or state level, and to publish regular reserve disclosures. It gives US businesses a clear legal footing for using regulated dollar stablecoins.",{"q":2944,"a":2945},"Do I need my own license to send stablecoin payouts?","Usually not. If you build on a licensed provider, the provider carries the regulatory obligations: registration, custody arrangements, KYC, sanctions screening, and travel rule compliance. You are still responsible for giving the provider accurate customer and payment information.",{"author":342},"---\ntitle: \"Stablecoin regulation in 2026: MiCA, the GENIUS Act, Brazil, and Japan\"\ndescription: \"Where stablecoin regulation stands in 2026: MiCA in the EU, the GENIUS Act in the US, Brazil's VASP regime, and Japan's issuer rules, compared for payment businesses.\"\ndate: \"2026-08-15\"\ncategory: \"compliance\"\nauthor: \"BlindPay Team\"\nfaq:\n  - q: \"Is it legal for businesses to use stablecoins for payments?\"\n    a: \"Yes, in most major markets, provided the business or its provider complies with local rules. The EU regulates stablecoins under MiCA, the US under the GENIUS Act and money transmission laws, Brazil under Law 14.478\u002F2022 and BCB resolutions, and Japan under the revised Payment Services Act. What matters is who issues the stablecoin and who handles the conversion to fiat.\"\n  - q: \"Which stablecoins are compliant in the EU under MiCA?\"\n    a: \"As of 2026, USDC is available in the EU because Circle obtained an electronic money institution license in France and issues USDC as a MiCA-compliant e-money token. USDT has been delisted from most EU-regulated exchanges because Tether did not pursue MiCA authorization.\"\n  - q: \"What is the GENIUS Act in simple terms?\"\n    a: \"The GENIUS Act is the first US federal law dedicated to payment stablecoins. It requires issuers to hold 1:1 reserves in cash and short-term Treasuries, to be licensed at the federal or state level, and to publish regular reserve disclosures. It gives US businesses a clear legal footing for using regulated dollar stablecoins.\"\n  - q: \"Do I need my own license to send stablecoin payouts?\"\n    a: \"Usually not. If you build on a licensed provider, the provider carries the regulatory obligations: registration, custody arrangements, KYC, sanctions screening, and travel rule compliance. You are still responsible for giving the provider accurate customer and payment information.\"\n---\n\nStablecoin regulation stopped being a gray zone. As of 2026, the four markets that matter most to cross-border payment businesses all have dedicated rules in force: the EU's Markets in Crypto-Assets regulation (MiCA), the US GENIUS Act, Brazil's virtual asset framework under Law 14.478\u002F2022 and Central Bank Resolutions 519, 520, and 521, and Japan's revised Payment Services Act. The direction is the same everywhere: fully reserved, licensed, auditable digital dollars (and euros, and yen) are welcome; everything else is being pushed out of the regulated system.\n\nThis tracker summarizes each regime and what it means in practice for businesses that pay or get paid with stablecoins. For the basics of how these payments work, start with our [guide to stablecoin payments](\u002Fresources\u002Fmore\u002Fstablecoin-payments-guide).\n\n## What does MiCA require of stablecoin issuers?\n\nMiCA (Regulation (EU) 2023\u002F1114) is the EU's single rulebook for crypto-assets. Its stablecoin provisions have applied since June 30, 2024, and full application for crypto-asset service providers began at the end of 2024, with national transition periods running through 2026.\n\nMiCA splits stablecoins into two categories. E-money tokens (EMTs) reference a single fiat currency and can only be issued by licensed credit institutions or electronic money institutions. Asset-referenced tokens (ARTs) reference baskets of assets and carry heavier requirements. For payment businesses, EMTs are the category that matters: a dollar or euro stablecoin used for payouts is an EMT.\n\nThe practical consequences showed up fast. Circle obtained an electronic money institution license in France and issues USDC and EURC as MiCA-compliant EMTs. Tether chose not to pursue authorization, and USDT was delisted from most EU-regulated exchanges. If your business touches EU customers or EU rails, your stablecoin choice is effectively made for you. Our [MiCA explainer for payment companies](\u002Fresources\u002Fmore\u002Fmica-stablecoin-rules-explained) covers the details.\n\n## What is the GENIUS Act?\n\nThe GENIUS Act (Guiding and Establishing National Innovation for US Stablecoins Act), signed in July 2025, is the first US federal law dedicated to payment stablecoins. Before it, US stablecoin issuers operated under a patchwork of state money transmitter licenses and trust charters.\n\nThe core requirements: payment stablecoin issuers must hold reserves 1:1 in cash, insured deposits, and short-term US Treasuries; they must be licensed either federally or under a qualifying state regime; they must publish monthly reserve disclosures; and they face restrictions on paying interest to holders. Issuers of a certain size fall under federal supervision.\n\nFor payment businesses, the GENIUS Act removed the biggest US legal question: whether regulated companies could rely on stablecoins at all. The answer is now yes, provided the stablecoin comes from a licensed issuer. It also accelerated bank and fintech adoption; Reuters reported stablecoin circulation passing 250 billion dollars in 2025, with regulated issuers taking a growing share.\n\n## How does Brazil regulate stablecoins and VASPs?\n\nBrazil moved earlier than most. Law 14.478\u002F2022 created the legal framework for virtual asset service providers (VASPs) and assigned supervision to the Banco Central do Brasil (BCB). In November 2025 the BCB published Resolutions 519, 520, and 521, which took effect on February 2, 2026, and created the SPSAV regime: companies providing virtual asset services in Brazil must obtain authorization, with a transition window under Article 88 of Resolution 520 for companies already operating.\n\nTwo things make Brazil special for stablecoin payments. First, Pix: the BCB's instant payment system settles transfers in seconds, 24\u002F7, and is the default way Brazilians move money. A stablecoin payout that ends in Pix reaches the receiver faster than an international wire by days. Second, enforcement is practical: Pix payouts require the receiver's name and tax ID (CPF or CNPJ) to match the receiving account, so accurate beneficiary data is a hard requirement, not a nice-to-have.\n\nThe authorization regime itself, who needs it, and what it requires are covered in [PSAV in Brazil explained](\u002Fresources\u002Fmore\u002Fpsav-brazil-explained), and we compare the concrete cash-out options, fees, and rules in [USDC to BRL in 2026: routes, fees, and rules compared](\u002Fresources\u002Fmore\u002Fusdc-to-brl-routes-2026).\n\n## What are Japan's stablecoin rules?\n\nJapan regulated stablecoins before either the EU or the US. The revised Payment Services Act, in force since June 2023, treats fiat-pegged stablecoins as electronic payment instruments. Only licensed banks, registered money transfer agents, and trust companies may issue them, and issuers must guarantee redemption at face value. Distribution requires registration as an electronic payment instruments service provider with the Financial Services Agency (FSA).\n\nThe first yen-denominated stablecoins under this regime launched in 2025, and Japan continues to refine the framework, with the FSA studying reserve flexibility and intermediary rules. For global payment businesses, Japan matters less for day-to-day payouts than the EU, US, or Brazil, but it shows where regulation converges: licensed issuers, full reserves, guaranteed redemption.\n\n## How do the four regimes compare?\n\n| Regime | In force | Who may issue | Reserve rule | Supervisor |\n|---|---|---|---|---|\n| MiCA (EU) | Stablecoin titles since June 2024 | Credit institutions, licensed EMIs | Full backing, segregated, redemption at par | National regulators, EBA for significant tokens |\n| GENIUS Act (US) | Signed July 2025 | Federally or state-licensed payment stablecoin issuers | 1:1 in cash, insured deposits, short-term Treasuries; monthly disclosure | OCC and state regulators |\n| Brazil (Law 14.478 + BCB 519\u002F520\u002F521) | VASP regime effective February 2026 | Issuance and services by authorized SPSAVs | Governance and segregation duties under BCB rules | Banco Central do Brasil |\n| Japan (Payment Services Act) | Revised rules since June 2023 | Banks, money transfer agents, trust companies | Redemption at face value guaranteed | Financial Services Agency |\n\nDifferences remain in the details (interest bans, disclosure cadence, licensing paths), but the convergence is unmistakable. A stablecoin that is fully reserved, redeemable at par, and issued by a licensed institution clears the bar everywhere; anything else faces shrinking room.\n\n## Where is regulation still unsettled?\n\nThree open fronts worth tracking through the rest of 2026:\n\n- **Interest and yield.** The GENIUS Act bars issuers from paying interest on payment stablecoins, and MiCA does the same for EMTs. Yield-bearing wrappers and tokenized money market funds sit outside these definitions, and regulators on both sides of the Atlantic are still deciding how to treat them when they behave like payment balances.\n- **Foreign-issuer access.** Both the EU and the US are refining how offshore issuers reach their markets: MiCA through equivalence-style conditions on non-EU EMTs, the US through GENIUS Act rules on foreign payment stablecoin issuers. Where these land will decide how global a single token's distribution can be.\n- **Brazil's transition window.** Companies operating before Resolutions 519\u002F520\u002F521 have Article 88 transition status while their SPSAV authorizations process. Expect the authorized list to firm up through 2026 and diligence questions to shift from \"are you applying?\" to \"are you authorized?\".\n\nNone of these change the direction. They change who is allowed to distribute, and how fast.\n\n## What should payment businesses do about it?\n\nThe pattern across all four regimes is consistent, and it points to a short checklist:\n\n- **Use stablecoins from regulated issuers.** USDC and other licensed EMT\u002FGENIUS-compliant tokens are accepted across all four regimes. Unregulated tokens increasingly are not.\n- **Let a licensed provider carry the regulatory load.** Payout providers that hold the required registrations (money transmission in the US, VASP authorization in Brazil, CASP status in the EU) take on custody, KYC, sanctions screening, and travel rule obligations. Building this yourself means acquiring licenses market by market.\n- **Get beneficiary data right.** Brazil's name and tax ID matching is the strictest example, but every regime requires accurate sender and receiver information under travel rule requirements. Thresholds and data formats by market are in our [cross-border compliance guide](\u002Fresources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments).\n- **Watch reserve and redemption terms.** Regulation now guarantees that a compliant stablecoin redeems 1:1. If a token's terms do not say that plainly, it does not belong in a payment flow.\n\nCompliance is becoming the differentiator between providers, not an afterthought. Our own [compliance framework](\u002Fcompliance) documents how we approach it.\n\n## How BlindPay handles regulation for you\n\nBlindPay is a stablecoin API for global payments: businesses send USDC or USDT and receivers get local currency over Pix, SPEI, ACH, or wire, in [100+ countries](\u002Fcoverage). The regulatory work is built into the flow: KYC and KYB on receivers before money moves, sanctions screening, travel rule data handling, and local rail requirements like Brazil's name and tax ID matching. [Virtual accounts](\u002Fvirtual-accounts) extend the same model to collections, converting incoming bank transfers to stablecoins automatically. Pricing is public on the [pricing page](\u002Fpricing), and the team can walk through specific regulatory questions via [contact](\u002Fcontact).\n\n## Methodology and sources\n\nRegime details from primary sources: MiCA text, Regulation (EU) 2023\u002F1114 ([eur-lex.europa.eu](https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002F?uri=CELEX%3A32023R1114)) and ESMA's MiCA hub ([esma.europa.eu](https:\u002F\u002Fwww.esma.europa.eu\u002Fesmas-activities\u002Fdigital-finance-and-innovation\u002Fmarkets-crypto-assets-regulation-mica)); the GENIUS Act, S.1582, 119th Congress ([congress.gov](https:\u002F\u002Fwww.congress.gov\u002Fbill\u002F119th-congress\u002Fsenate-bill\u002F1582)); Brazil's Law 14.478\u002F2022 and BCB Resolutions 519, 520, and 521 plus the Pix system description ([bcb.gov.br](https:\u002F\u002Fwww.bcb.gov.br\u002Fen\u002Ffinancialstability\u002Fpix_en)); Japan's Payment Services Act framework via the Financial Services Agency ([fsa.go.jp](https:\u002F\u002Fwww.fsa.go.jp\u002Fen\u002F)). Regulatory status described as of August 2026.\n\n*This article is general information, not legal, tax, or financial advice.*\n",{"title":2623,"description":2932},"resources\u002Fmore\u002Fstablecoin-regulation-tracker-2026","KfUTaTxaMHOlYBlAjXIyAGB1GrvNcWm75RrgNLV3n0Y",{"id":2952,"title":2953,"authors":6,"body":2954,"categories":6,"category":323,"categoryType":6,"compare":6,"contributors":6,"date":3338,"description":3339,"extension":326,"faq":3340,"howto":6,"isBlog":340,"isChangelog":340,"meta":3359,"navigation":343,"path":3360,"pillar":340,"products":6,"rawbody":3361,"role":6,"seo":3362,"stem":3363,"thumbnail":6,"updated":3338,"__hash__":3364},"content\u002Fresources\u002Fmore\u002Fwhat-are-compliance-agents-in-fintech.md","What are compliance agents in fintech? How they work and what they do for payments",{"type":8,"value":2955,"toc":3331},[2956,2960,2965,2969,2972,2975,2978,3014,3018,3021,3059,3062,3069,3073,3076,3079,3117,3124,3128,3131,3134,3238,3241,3245,3250,3253,3256,3294,3297,3318,3321,3327],[11,2957,2958],{},[14,2959,16],{},[11,2961,2962,2964],{},[20,2963,22],{}," Compliance agents are autonomous software components that execute regulatory checks inside a payment flow. They verify identities (KYC and KYB), screen counterparties against sanctions lists, monitor transactions for money laundering patterns, and write an audit record for every decision. Unlike traditional compliance software, which produces alerts for humans to work, compliance agents act on the result and escalate only the cases that need judgment.",[28,2966,2968],{"id":2967},"what-are-compliance-agents-in-fintech","What are compliance agents in fintech?",[11,2970,2971],{},"A compliance agent is a piece of software that owns one regulatory task end to end: it gathers the inputs, applies the rules, reaches a decision, and records the evidence. The word \"agent\" signals that it acts rather than reports.",[11,2973,2974],{},"In a payments company, compliance agents sit between the request to move money and the movement itself. A payout does not settle until the relevant agents return a pass.",[11,2976,2977],{},"Most fintech compliance programs decompose into a small set of agents, each mapped to a regulatory obligation:",[723,2979,2980,2990,2996,3002,3008],{},[229,2981,2982,2985,2986,2989],{},[20,2983,2984],{},"Identity agent."," Runs KYC on individuals and ",[48,2987,2988],{"href":569},"KYB"," on businesses, reading documents, matching them to registries, and verifying beneficial owners.",[229,2991,2992,2995],{},[20,2993,2994],{},"Sanctions agent."," Screens names, addresses, wallet addresses, and bank accounts against OFAC, UN, EU, and local lists, and resolves fuzzy matches.",[229,2997,2998,3001],{},[20,2999,3000],{},"Monitoring agent."," Watches transaction patterns for structuring, velocity spikes, and counterparties that do not fit the customer's stated profile.",[229,3003,3004,3007],{},[20,3005,3006],{},"Blockchain screening agent."," Traces the source of on-chain funds and blocks deposits linked to mixers, hacks, or sanctioned wallets.",[229,3009,3010,3013],{},[20,3011,3012],{},"Audit agent."," Stores the inputs, the rule version, the decision, and the timestamp for every check so a regulator can reconstruct it later.",[28,3015,3017],{"id":3016},"how-do-compliance-agents-work","How do compliance agents work?",[11,3019,3020],{},"Compliance agents run a loop: observe, decide, act, record. Each step is deterministic enough to audit and fast enough to run before a payment settles.",[226,3022,3023,3029,3035,3041,3047,3053],{},[229,3024,3025,3028],{},[20,3026,3027],{},"Trigger."," An event in the payment system fires the agent: a new customer, a new bank account, a payout request, or an on-chain deposit.",[229,3030,3031,3034],{},[20,3032,3033],{},"Collect."," The agent pulls what it needs: uploaded documents, registry data, list feeds, transaction history, and blockchain analytics.",[229,3036,3037,3040],{},[20,3038,3039],{},"Evaluate."," It applies the rule set for the customer's jurisdiction and risk tier. Rules can be deterministic thresholds, machine learning scores, or both.",[229,3042,3043,3046],{},[20,3044,3045],{},"Decide."," The output is one of three states: pass, block, or escalate to a human reviewer.",[229,3048,3049,3052],{},[20,3050,3051],{},"Act."," A pass lets the payment proceed. A block stops it and notifies the customer. An escalation opens a case with the evidence already attached.",[229,3054,3055,3058],{},[20,3056,3057],{},"Record."," Every input and decision is written to an immutable log tied to the transaction ID.",[11,3060,3061],{},"The escalation path is what separates a well-designed agent from a black box. The agent does not guess on ambiguous cases; it routes them to a person with the file already assembled.",[11,3063,3064,3065,3068],{},"Rule sets change by jurisdiction. A single agent may hold one policy for Brazilian virtual asset service providers, another for US money transmitters, and a third for ",[48,3066,3067],{"href":1433},"MiCA"," in the EU, selecting the right one from the customer's country and entity type.",[28,3070,3072],{"id":3071},"what-do-compliance-agents-do-for-payments","What do compliance agents do for payments?",[11,3074,3075],{},"For a payments company, compliance agents turn a set of legal obligations into checks that execute on every transaction without slowing it down. They are the reason a cross-border payout can be both instant and defensible.",[11,3077,3078],{},"The concrete jobs are:",[723,3080,3081,3087,3093,3099,3105,3111],{},[229,3082,3083,3086],{},[20,3084,3085],{},"Onboarding."," Verify the sender and the receiver before the first payment, so the money never touches an unverified account.",[229,3088,3089,3092],{},[20,3090,3091],{},"Pre-settlement screening."," Screen every payout against sanctions lists at the moment it is created, not in a nightly batch, because a stablecoin transfer is final once confirmed.",[229,3094,3095,3098],{},[20,3096,3097],{},"Ongoing monitoring."," Re-screen existing customers as lists update and flag transaction patterns that drift from the profile established at onboarding.",[229,3100,3101,3104],{},[20,3102,3103],{},"Source-of-funds checks."," Trace inbound stablecoin deposits to confirm they did not originate from a sanctioned or hacked wallet.",[229,3106,3107,3110],{},[20,3108,3109],{},"Regulatory reporting."," Assemble suspicious activity reports and threshold reports from the audit log instead of from analyst memory.",[229,3112,3113,3116],{},[20,3114,3115],{},"Evidence retention."," Keep the decision trail for the five to ten years most regulators require.",[11,3118,3119,3120,3123],{},"Stablecoin payments raise the stakes. A wire can be recalled; an on-chain transfer ",[48,3121,3122],{"href":50},"cannot",". Compliance agents that run inline are the only practical way to check a transaction before an irreversible settlement.",[28,3125,3127],{"id":3126},"what-is-the-difference-between-compliance-agents-and-traditional-compliance-software","What is the difference between compliance agents and traditional compliance software?",[11,3129,3130],{},"Traditional compliance software is a system of record and alerting. It ingests transactions, flags the ones that match a rule, and queues them for analysts to review. The software informs; people decide.",[11,3132,3133],{},"Compliance agents invert that division of labor. The agent decides the routine cases and reserves human attention for the exceptions.",[121,3135,3136,3148],{},[124,3137,3138],{},[127,3139,3140,3142,3145],{},[130,3141],{},[130,3143,3144],{},"Compliance agents",[130,3146,3147],{},"Traditional compliance software",[140,3149,3150,3161,3172,3183,3194,3205,3216,3227],{},[127,3151,3152,3155,3158],{},[145,3153,3154],{},"Where it runs",[145,3156,3157],{},"Inside the payment API, before settlement",[145,3159,3160],{},"Alongside the payment system, often in batch",[127,3162,3163,3166,3169],{},[145,3164,3165],{},"Output",[145,3167,3168],{},"A decision: pass, block, or escalate",[145,3170,3171],{},"An alert for a human to review",[127,3173,3174,3177,3180],{},[145,3175,3176],{},"Speed",[145,3178,3179],{},"Milliseconds to minutes, per transaction",[145,3181,3182],{},"Hours to days, per alert queue",[127,3184,3185,3188,3191],{},[145,3186,3187],{},"Human role",[145,3189,3190],{},"Handles escalations and owns the policy",[145,3192,3193],{},"Works every alert, including the obvious ones",[127,3195,3196,3199,3202],{},[145,3197,3198],{},"Integration",[145,3200,3201],{},"Inherited with the payment API",[145,3203,3204],{},"Separate vendor, separate contract, separate integration",[127,3206,3207,3210,3213],{},[145,3208,3209],{},"Audit trail",[145,3211,3212],{},"Written automatically with each decision",[145,3214,3215],{},"Assembled from case notes and system exports",[127,3217,3218,3221,3224],{},[145,3219,3220],{},"Jurisdiction coverage",[145,3222,3223],{},"Rule set selected per customer and country",[145,3225,3226],{},"Usually configured for one primary jurisdiction",[127,3228,3229,3232,3235],{},[145,3230,3231],{},"Scaling cost",[145,3233,3234],{},"Flat per transaction",[145,3236,3237],{},"Grows with analyst headcount",[11,3239,3240],{},"The trade-off is control. Traditional software gives a compliance team full visibility into every rule and every case. Agents require the team to trust the rules, review the escalation rate, and audit decisions by sampling rather than by reviewing each one.",[28,3242,3244],{"id":3243},"how-does-blindpay-use-compliance-agents","How does BlindPay use compliance agents?",[11,3246,3247,3249],{},[48,3248,1548],{"href":2111}," embeds its compliance layer directly in the payment API. There is no separate compliance product to buy, integrate, or keep in sync with the money movement.",[11,3251,3252],{},"When a developer creates a receiver, BlindPay runs KYC or KYB on that entity before it can send or receive funds. When the developer requests a payout, sanctions screening and AML monitoring execute inline, and the payout does not settle until they pass.",[11,3254,3255],{},"What a developer inherits by integrating the API:",[723,3257,3258,3264,3270,3276,3282,3288],{},[229,3259,3260,3263],{},[20,3261,3262],{},"KYC and KYB"," for individuals and businesses, including beneficial owner verification, run at receiver creation.",[229,3265,3266,3269],{},[20,3267,3268],{},"Sanctions screening"," on every counterparty, bank account, and wallet address, at onboarding and at each transaction.",[229,3271,3272,3275],{},[20,3273,3274],{},"AML transaction monitoring"," that watches patterns across the customer's payment history, not just the current payout.",[229,3277,3278,3281],{},[20,3279,3280],{},"Blockchain screening"," on inbound stablecoin deposits to block funds from sanctioned or compromised wallets.",[229,3283,3284,3287],{},[20,3285,3286],{},"Audit logging"," for every decision, retained and available for regulatory review.",[229,3289,3290,3293],{},[20,3291,3292],{},"Multi-jurisdiction rule sets"," covering the countries BlindPay operates in, including Brazil, Mexico, Colombia, Argentina, the US, and the EU.",[11,3295,3296],{},"The developer writes one integration. Compliance state surfaces through the same objects and webhooks used for payments, so a blocked payout looks like any other failed payout with a reason attached.",[11,3298,3299,3300,3302,3303,3305,3306,3310,3311,3314,3315,293],{},"BlindPay holds the licenses and registrations the agents enforce against, listed on the ",[48,3301,1015],{"href":1014},". The ",[48,3304,287],{"href":286}," describes the full program, and the ",[48,3307,3309],{"href":3308},"\u002Fresources\u002Fmore","resources hub"," has related explainers on ",[48,3312,3313],{"href":1032},"what a VASP is"," and how ",[48,3316,3317],{"href":408},"regulation is changing",[3319,3320],"hr",{},[11,3322,3323,3324,293],{},"Compliance agents are autonomous components that run KYC, KYB, sanctions screening, AML monitoring, and audit logging inside the payment flow, deciding routine cases and escalating exceptions. They differ from traditional compliance software by acting on results rather than producing alerts, which is what makes instant, irreversible stablecoin settlement defensible. BlindPay builds this layer into its payment API, so developers inherit global compliance coverage with a single integration. See how it works at ",[48,3325,1118],{"href":1116,"rel":3326},[422],[11,3328,3329],{},[14,3330,2151],{},{"title":307,"searchDepth":308,"depth":308,"links":3332},[3333,3334,3335,3336,3337],{"id":2967,"depth":308,"text":2968},{"id":3016,"depth":308,"text":3017},{"id":3071,"depth":308,"text":3072},{"id":3126,"depth":308,"text":3127},{"id":3243,"depth":308,"text":3244},"2026-08-12","Compliance agents are autonomous software components that run KYC, KYB, sanctions screening, and transaction monitoring inside a payment flow, then document every decision. How they work, what they do for payments, how they differ from traditional compliance software, and how BlindPay embeds them in its API.",[3341,3344,3347,3350,3353,3356],{"q":3342,"a":3343},"What is a compliance agent in simple terms?","A compliance agent is software that performs a regulatory check on its own, decides whether a payment or customer passes, and records why. It replaces a human analyst for routine work and hands the unusual cases to one.",{"q":3345,"a":3346},"Do compliance agents replace a compliance officer?","No. Agents handle volume: document checks, list screening, and routine alert review. A compliance officer still owns the policy, approves high-risk decisions, and answers to the regulator.",{"q":3348,"a":3349},"Are compliance agents the same as AI?","Not always. Many agents combine deterministic rules with machine learning for document reading, entity matching, and anomaly detection. The defining feature is autonomous action inside a workflow, not the model behind it.",{"q":3351,"a":3352},"How fast do compliance agents make a decision?","Sanctions screening and transaction monitoring return in milliseconds, so they run inline before a payment settles. Identity verification takes seconds to a few minutes when a document must be read and matched to a face or a registry.",{"q":3354,"a":3355},"Can compliance agents work across multiple countries?","Yes, if the provider maintains rules and data sources per jurisdiction. The same agent screens a Brazilian company against Central Bank requirements and a US company against FinCEN and OFAC requirements, using the rule set that applies to each.",{"q":3357,"a":3358},"How does BlindPay handle compliance for developers?","Compliance runs inside the BlindPay payment API. When a developer creates a receiver or a payout, KYC or KYB, sanctions screening, AML monitoring, and audit logging execute automatically, with no separate compliance vendor to integrate.",{"author":342},"\u002Fresources\u002Fmore\u002Fwhat-are-compliance-agents-in-fintech","---\ntitle: \"What are compliance agents in fintech? How they work and what they do for payments\"\ndescription: \"Compliance agents are autonomous software components that run KYC, KYB, sanctions screening, and transaction monitoring inside a payment flow, then document every decision. How they work, what they do for payments, how they differ from traditional compliance software, and how BlindPay embeds them in its API.\"\ndate: \"2026-08-12\"\nupdated: \"2026-08-12\"\nauthor: \"BlindPay Team\"\ncategory: \"compliance\"\nfaq:\n  - q: \"What is a compliance agent in simple terms?\"\n    a: \"A compliance agent is software that performs a regulatory check on its own, decides whether a payment or customer passes, and records why. It replaces a human analyst for routine work and hands the unusual cases to one.\"\n  - q: \"Do compliance agents replace a compliance officer?\"\n    a: \"No. Agents handle volume: document checks, list screening, and routine alert review. A compliance officer still owns the policy, approves high-risk decisions, and answers to the regulator.\"\n  - q: \"Are compliance agents the same as AI?\"\n    a: \"Not always. Many agents combine deterministic rules with machine learning for document reading, entity matching, and anomaly detection. The defining feature is autonomous action inside a workflow, not the model behind it.\"\n  - q: \"How fast do compliance agents make a decision?\"\n    a: \"Sanctions screening and transaction monitoring return in milliseconds, so they run inline before a payment settles. Identity verification takes seconds to a few minutes when a document must be read and matched to a face or a registry.\"\n  - q: \"Can compliance agents work across multiple countries?\"\n    a: \"Yes, if the provider maintains rules and data sources per jurisdiction. The same agent screens a Brazilian company against Central Bank requirements and a US company against FinCEN and OFAC requirements, using the rule set that applies to each.\"\n  - q: \"How does BlindPay handle compliance for developers?\"\n    a: \"Compliance runs inside the BlindPay payment API. When a developer creates a receiver or a payout, KYC or KYB, sanctions screening, AML monitoring, and audit logging execute automatically, with no separate compliance vendor to integrate.\"\n---\n\n*Reading time: about 7 minutes.*\n\n**Summary:** Compliance agents are autonomous software components that execute regulatory checks inside a payment flow. They verify identities (KYC and KYB), screen counterparties against sanctions lists, monitor transactions for money laundering patterns, and write an audit record for every decision. Unlike traditional compliance software, which produces alerts for humans to work, compliance agents act on the result and escalate only the cases that need judgment.\n\n## What are compliance agents in fintech?\n\nA compliance agent is a piece of software that owns one regulatory task end to end: it gathers the inputs, applies the rules, reaches a decision, and records the evidence. The word \"agent\" signals that it acts rather than reports.\n\nIn a payments company, compliance agents sit between the request to move money and the movement itself. A payout does not settle until the relevant agents return a pass.\n\nMost fintech compliance programs decompose into a small set of agents, each mapped to a regulatory obligation:\n\n- **Identity agent.** Runs KYC on individuals and [KYB](\u002Fresources\u002Fmore\u002Fwhat-is-kyb) on businesses, reading documents, matching them to registries, and verifying beneficial owners.\n- **Sanctions agent.** Screens names, addresses, wallet addresses, and bank accounts against OFAC, UN, EU, and local lists, and resolves fuzzy matches.\n- **Monitoring agent.** Watches transaction patterns for structuring, velocity spikes, and counterparties that do not fit the customer's stated profile.\n- **Blockchain screening agent.** Traces the source of on-chain funds and blocks deposits linked to mixers, hacks, or sanctioned wallets.\n- **Audit agent.** Stores the inputs, the rule version, the decision, and the timestamp for every check so a regulator can reconstruct it later.\n\n## How do compliance agents work?\n\nCompliance agents run a loop: observe, decide, act, record. Each step is deterministic enough to audit and fast enough to run before a payment settles.\n\n1. **Trigger.** An event in the payment system fires the agent: a new customer, a new bank account, a payout request, or an on-chain deposit.\n2. **Collect.** The agent pulls what it needs: uploaded documents, registry data, list feeds, transaction history, and blockchain analytics.\n3. **Evaluate.** It applies the rule set for the customer's jurisdiction and risk tier. Rules can be deterministic thresholds, machine learning scores, or both.\n4. **Decide.** The output is one of three states: pass, block, or escalate to a human reviewer.\n5. **Act.** A pass lets the payment proceed. A block stops it and notifies the customer. An escalation opens a case with the evidence already attached.\n6. **Record.** Every input and decision is written to an immutable log tied to the transaction ID.\n\nThe escalation path is what separates a well-designed agent from a black box. The agent does not guess on ambiguous cases; it routes them to a person with the file already assembled.\n\nRule sets change by jurisdiction. A single agent may hold one policy for Brazilian virtual asset service providers, another for US money transmitters, and a third for [MiCA](\u002Fresources\u002Fmore\u002Fmica-stablecoin-rules-explained) in the EU, selecting the right one from the customer's country and entity type.\n\n## What do compliance agents do for payments?\n\nFor a payments company, compliance agents turn a set of legal obligations into checks that execute on every transaction without slowing it down. They are the reason a cross-border payout can be both instant and defensible.\n\nThe concrete jobs are:\n\n- **Onboarding.** Verify the sender and the receiver before the first payment, so the money never touches an unverified account.\n- **Pre-settlement screening.** Screen every payout against sanctions lists at the moment it is created, not in a nightly batch, because a stablecoin transfer is final once confirmed.\n- **Ongoing monitoring.** Re-screen existing customers as lists update and flag transaction patterns that drift from the profile established at onboarding.\n- **Source-of-funds checks.** Trace inbound stablecoin deposits to confirm they did not originate from a sanctioned or hacked wallet.\n- **Regulatory reporting.** Assemble suspicious activity reports and threshold reports from the audit log instead of from analyst memory.\n- **Evidence retention.** Keep the decision trail for the five to ten years most regulators require.\n\nStablecoin payments raise the stakes. A wire can be recalled; an on-chain transfer [cannot](\u002Fresources\u002Fmore\u002Fare-stablecoin-payments-reversible). Compliance agents that run inline are the only practical way to check a transaction before an irreversible settlement.\n\n## What is the difference between compliance agents and traditional compliance software?\n\nTraditional compliance software is a system of record and alerting. It ingests transactions, flags the ones that match a rule, and queues them for analysts to review. The software informs; people decide.\n\nCompliance agents invert that division of labor. The agent decides the routine cases and reserves human attention for the exceptions.\n\n| | Compliance agents | Traditional compliance software |\n| --- | --- | --- |\n| Where it runs | Inside the payment API, before settlement | Alongside the payment system, often in batch |\n| Output | A decision: pass, block, or escalate | An alert for a human to review |\n| Speed | Milliseconds to minutes, per transaction | Hours to days, per alert queue |\n| Human role | Handles escalations and owns the policy | Works every alert, including the obvious ones |\n| Integration | Inherited with the payment API | Separate vendor, separate contract, separate integration |\n| Audit trail | Written automatically with each decision | Assembled from case notes and system exports |\n| Jurisdiction coverage | Rule set selected per customer and country | Usually configured for one primary jurisdiction |\n| Scaling cost | Flat per transaction | Grows with analyst headcount |\n\nThe trade-off is control. Traditional software gives a compliance team full visibility into every rule and every case. Agents require the team to trust the rules, review the escalation rate, and audit decisions by sampling rather than by reviewing each one.\n\n## How does BlindPay use compliance agents?\n\n[BlindPay](\u002Fglobal-payments) embeds its compliance layer directly in the payment API. There is no separate compliance product to buy, integrate, or keep in sync with the money movement.\n\nWhen a developer creates a receiver, BlindPay runs KYC or KYB on that entity before it can send or receive funds. When the developer requests a payout, sanctions screening and AML monitoring execute inline, and the payout does not settle until they pass.\n\nWhat a developer inherits by integrating the API:\n\n- **KYC and KYB** for individuals and businesses, including beneficial owner verification, run at receiver creation.\n- **Sanctions screening** on every counterparty, bank account, and wallet address, at onboarding and at each transaction.\n- **AML transaction monitoring** that watches patterns across the customer's payment history, not just the current payout.\n- **Blockchain screening** on inbound stablecoin deposits to block funds from sanctioned or compromised wallets.\n- **Audit logging** for every decision, retained and available for regulatory review.\n- **Multi-jurisdiction rule sets** covering the countries BlindPay operates in, including Brazil, Mexico, Colombia, Argentina, the US, and the EU.\n\nThe developer writes one integration. Compliance state surfaces through the same objects and webhooks used for payments, so a blocked payout looks like any other failed payout with a reason attached.\n\nBlindPay holds the licenses and registrations the agents enforce against, listed on the [licenses page](\u002Flicenses). The [compliance page](\u002Fcompliance) describes the full program, and the [resources hub](\u002Fresources\u002Fmore) has related explainers on [what a VASP is](\u002Fresources\u002Fmore\u002Fwhat-is-a-vasp) and how [regulation is changing](\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026).\n\n---\n\nCompliance agents are autonomous components that run KYC, KYB, sanctions screening, AML monitoring, and audit logging inside the payment flow, deciding routine cases and escalating exceptions. They differ from traditional compliance software by acting on results rather than producing alerts, which is what makes instant, irreversible stablecoin settlement defensible. BlindPay builds this layer into its payment API, so developers inherit global compliance coverage with a single integration. See how it works at [blindpay.com](https:\u002F\u002Fblindpay.com).\n\n*This article is general information, not legal, tax, or financial advice.*\n",{"title":2953,"description":3339},"resources\u002Fmore\u002Fwhat-are-compliance-agents-in-fintech","xjB_AGiwceylzXCKJn1eMwpr1-fVKaIRdykDqTobXoM",{"id":3366,"title":3367,"authors":6,"body":3368,"categories":6,"category":323,"categoryType":6,"compare":6,"contributors":6,"date":510,"description":3485,"extension":326,"faq":3486,"howto":6,"isBlog":340,"isChangelog":340,"meta":3498,"navigation":343,"path":569,"pillar":340,"products":6,"rawbody":3499,"role":6,"seo":3500,"stem":3501,"thumbnail":6,"updated":510,"__hash__":3502},"content\u002Fresources\u002Fmore\u002Fwhat-is-kyb.md","What is KYB? Know Your Business verification explained",{"type":8,"value":3369,"toc":3478},[3370,3373,3376,3380,3383,3409,3412,3416,3424,3427,3431,3434,3437,3441,3453,3455,3474],[11,3371,3372],{},"KYB, Know Your Business, verifies that a company legally exists, confirms who owns and controls it, and screens those individuals before the company is allowed to send or receive money. It is the business-side counterpart to KYC: a payment provider cannot know whether it is safe to pay a company without first knowing who actually stands behind it.",[11,3374,3375],{},"KYB exists because a shell company is an easy way to hide who is really moving money. A registered business name and a bank account look legitimate on the surface; the ownership and control behind them are where risk actually lives, which is why regulators require providers to look past the entity to the humans running it.",[28,3377,3379],{"id":3378},"what-does-kyb-actually-verify","What does KYB actually verify?",[11,3381,3382],{},"A complete KYB check covers four layers:",[723,3384,3385,3391,3397,3403],{},[229,3386,3387,3390],{},[20,3388,3389],{},"Legal existence."," Confirming the company is registered, active, and in good standing with the relevant corporate registry, not dissolved or dormant.",[229,3392,3393,3396],{},[20,3394,3395],{},"Ownership structure."," Mapping who owns what percentage of the company, including through holding companies or trusts, until it reaches actual people.",[229,3398,3399,3402],{},[20,3400,3401],{},"Beneficial owners."," Identifying and verifying the individuals who meet the ownership or control threshold, then running standard identity and sanctions checks on each of them.",[229,3404,3405,3408],{},[20,3406,3407],{},"Business activity."," Confirming the company's stated business matches what it actually does, since a mismatch between registered activity and real transaction patterns is a common fraud and money laundering signal.",[11,3410,3411],{},"Skipping any layer leaves a gap. A provider that checks only registration, without tracing ownership to real people, can end up doing business with a company controlled by someone on a sanctions list.",[28,3413,3415],{"id":3414},"who-counts-as-a-beneficial-owner","Who counts as a beneficial owner?",[11,3417,3418,3419,293],{},"The clearest definition comes from FinCEN's Customer Due Diligence rule, built on two prongs. The ownership prong: any individual who, \"directly or indirectly, through any contract, arrangement, understanding, relationship or otherwise, owns 25 percent or more of the equity interests of a legal entity customer.\" The control prong: at least one individual with \"significant responsibility to control, manage, or direct\" the entity, such as a CEO, CFO, or managing member, regardless of ownership percentage. Full detail is in ",[48,3420,3423],{"href":3421,"rel":3422},"https:\u002F\u002Fwww.ecfr.gov\u002Fcurrent\u002Ftitle-31\u002Fsubtitle-B\u002Fchapter-X\u002Fpart-1010\u002Fsubpart-C\u002Fsection-1010.230",[422],"31 CFR 1010.230(d)",[11,3425,3426],{},"That two-prong structure exists because ownership alone misses control. A company can be owned by a diffuse group of investors, none crossing 25 percent, while one individual runs every decision. The control prong catches that person even when the ownership math would not.",[28,3428,3430],{"id":3429},"how-is-kyb-different-from-kyc","How is KYB different from KYC?",[11,3432,3433],{},"KYC (Know Your Customer) verifies one individual: identity documents, address, and screening against sanctions and watchlists. KYB verifies a legal entity and then applies KYC to the people who own or control it. Opening a business account almost always triggers both: KYB on the company, KYC on each beneficial owner and often on signers and directors too.",[11,3435,3436],{},"The practical difference shows up in documentation. KYC needs a passport or ID and a selfie. KYB needs incorporation documents, a certificate of good standing, an ownership chart, and identity documents for every beneficial owner identified along the way, which is why KYB usually takes longer and involves more back-and-forth than an individual signup.",[28,3438,3440],{"id":3439},"when-does-a-payments-company-require-kyb","When does a payments company require KYB?",[11,3442,3443,3444,3446,3447,3450,3451,293],{},"Any time a business, not an individual, is the account holder or the counterparty receiving payment above a threshold set by the provider's risk policy. Marketplaces onboarding seller accounts, platforms paying out to vendor companies rather than individual contractors, and any B2B cross-border payment all trigger KYB somewhere in the flow. Our ",[48,3445,473],{"href":472}," covers where compliance checks like KYB sit inside a payout flow, and the broader VASP licensing context that requires programs like this is in ",[48,3448,3449],{"href":1032},"what is a VASP",". Requirements also shift as rules like MiCA and the GENIUS Act take effect, tracked in our ",[48,3452,1429],{"href":408},[28,3454,1539],{"id":1538},[11,3456,3457,3459,3460,3462,3463,3465,3466,3469,3470,3473],{},[48,3458,1548],{"href":2111}," runs KYB on every business account before it can send or receive a payout: entity verification, ownership mapping, beneficial owner screening, and sanctions checks, built into the same API used to move USDC and USDT over local rails like Pix and SPEI. The ",[48,3461,287],{"href":286}," covers the full program, and the ",[48,3464,3309],{"href":3308}," has more on how the pieces fit together, including ",[48,3467,3468],{"href":370},"what a stablecoin API does"," end to end and ",[48,3471,3472],{"href":594},"how to automate KYC and KYB"," inside a payment flow.",[11,3475,3476],{},[14,3477,305],{},{"title":307,"searchDepth":308,"depth":308,"links":3479},[3480,3481,3482,3483,3484],{"id":3378,"depth":308,"text":3379},{"id":3414,"depth":308,"text":3415},{"id":3429,"depth":308,"text":3430},{"id":3439,"depth":308,"text":3440},{"id":1538,"depth":308,"text":1539},"KYB verifies a company's legal existence, ownership, and control before it can transact. What it checks, who counts as a beneficial owner, and how it differs from KYC.",[3487,3490,3493,3495],{"q":3488,"a":3489},"What does KYB stand for?","Know Your Business. It is the process of verifying a company's legal existence, ownership structure, and the individuals who own or control it before that company is allowed to open an account or transact.",{"q":3491,"a":3492},"What is a beneficial owner?","Under FinCEN's rule, an individual who directly or indirectly owns 25 percent or more of a legal entity's equity, or who controls and directs it, such as a CEO or managing member. A company can have several beneficial owners.",{"q":3430,"a":3494},"KYC verifies an individual person. KYB verifies a company, and then applies KYC-style checks to the individuals who own or control that company. A business account almost always requires both.",{"q":3496,"a":3497},"How long does KYB take?","With registry data available and clean documents, minutes to same-day. It slows down for entities with layered ownership, trusts, or jurisdictions where corporate registries are not digitized, sometimes taking days.",{"author":342},"---\ntitle: \"What is KYB? Know Your Business verification explained\"\ndescription: \"KYB verifies a company's legal existence, ownership, and control before it can transact. What it checks, who counts as a beneficial owner, and how it differs from KYC.\"\ndate: \"2026-09-01\"\nauthor: \"BlindPay Team\"\nupdated: \"2026-09-01\"\ncategory: \"compliance\"\nfaq:\n  - q: \"What does KYB stand for?\"\n    a: \"Know Your Business. It is the process of verifying a company's legal existence, ownership structure, and the individuals who own or control it before that company is allowed to open an account or transact.\"\n  - q: \"What is a beneficial owner?\"\n    a: \"Under FinCEN's rule, an individual who directly or indirectly owns 25 percent or more of a legal entity's equity, or who controls and directs it, such as a CEO or managing member. A company can have several beneficial owners.\"\n  - q: \"How is KYB different from KYC?\"\n    a: \"KYC verifies an individual person. KYB verifies a company, and then applies KYC-style checks to the individuals who own or control that company. A business account almost always requires both.\"\n  - q: \"How long does KYB take?\"\n    a: \"With registry data available and clean documents, minutes to same-day. It slows down for entities with layered ownership, trusts, or jurisdictions where corporate registries are not digitized, sometimes taking days.\"\n---\n\nKYB, Know Your Business, verifies that a company legally exists, confirms who owns and controls it, and screens those individuals before the company is allowed to send or receive money. It is the business-side counterpart to KYC: a payment provider cannot know whether it is safe to pay a company without first knowing who actually stands behind it.\n\nKYB exists because a shell company is an easy way to hide who is really moving money. A registered business name and a bank account look legitimate on the surface; the ownership and control behind them are where risk actually lives, which is why regulators require providers to look past the entity to the humans running it.\n\n## What does KYB actually verify?\n\nA complete KYB check covers four layers:\n\n- **Legal existence.** Confirming the company is registered, active, and in good standing with the relevant corporate registry, not dissolved or dormant.\n- **Ownership structure.** Mapping who owns what percentage of the company, including through holding companies or trusts, until it reaches actual people.\n- **Beneficial owners.** Identifying and verifying the individuals who meet the ownership or control threshold, then running standard identity and sanctions checks on each of them.\n- **Business activity.** Confirming the company's stated business matches what it actually does, since a mismatch between registered activity and real transaction patterns is a common fraud and money laundering signal.\n\nSkipping any layer leaves a gap. A provider that checks only registration, without tracing ownership to real people, can end up doing business with a company controlled by someone on a sanctions list.\n\n## Who counts as a beneficial owner?\n\nThe clearest definition comes from FinCEN's Customer Due Diligence rule, built on two prongs. The ownership prong: any individual who, \"directly or indirectly, through any contract, arrangement, understanding, relationship or otherwise, owns 25 percent or more of the equity interests of a legal entity customer.\" The control prong: at least one individual with \"significant responsibility to control, manage, or direct\" the entity, such as a CEO, CFO, or managing member, regardless of ownership percentage. Full detail is in [31 CFR 1010.230(d)](https:\u002F\u002Fwww.ecfr.gov\u002Fcurrent\u002Ftitle-31\u002Fsubtitle-B\u002Fchapter-X\u002Fpart-1010\u002Fsubpart-C\u002Fsection-1010.230).\n\nThat two-prong structure exists because ownership alone misses control. A company can be owned by a diffuse group of investors, none crossing 25 percent, while one individual runs every decision. The control prong catches that person even when the ownership math would not.\n\n## How is KYB different from KYC?\n\nKYC (Know Your Customer) verifies one individual: identity documents, address, and screening against sanctions and watchlists. KYB verifies a legal entity and then applies KYC to the people who own or control it. Opening a business account almost always triggers both: KYB on the company, KYC on each beneficial owner and often on signers and directors too.\n\nThe practical difference shows up in documentation. KYC needs a passport or ID and a selfie. KYB needs incorporation documents, a certificate of good standing, an ownership chart, and identity documents for every beneficial owner identified along the way, which is why KYB usually takes longer and involves more back-and-forth than an individual signup.\n\n## When does a payments company require KYB?\n\nAny time a business, not an individual, is the account holder or the counterparty receiving payment above a threshold set by the provider's risk policy. Marketplaces onboarding seller accounts, platforms paying out to vendor companies rather than individual contractors, and any B2B cross-border payment all trigger KYB somewhere in the flow. Our [stablecoin payments guide](\u002Fresources\u002Fmore\u002Fstablecoin-payments-guide) covers where compliance checks like KYB sit inside a payout flow, and the broader VASP licensing context that requires programs like this is in [what is a VASP](\u002Fresources\u002Fmore\u002Fwhat-is-a-vasp). Requirements also shift as rules like MiCA and the GENIUS Act take effect, tracked in our [regulation tracker](\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026).\n\n## How does BlindPay fit in?\n\n[BlindPay](\u002Fglobal-payments) runs KYB on every business account before it can send or receive a payout: entity verification, ownership mapping, beneficial owner screening, and sanctions checks, built into the same API used to move USDC and USDT over local rails like Pix and SPEI. The [compliance page](\u002Fcompliance) covers the full program, and the [resources hub](\u002Fresources\u002Fmore) has more on how the pieces fit together, including [what a stablecoin API does](\u002Fresources\u002Fmore\u002Fwhat-is-a-stablecoin-api) end to end and [how to automate KYC and KYB](\u002Fresources\u002Fmore\u002Fhow-to-automate-kyc-kyb-stablecoin-payments) inside a payment flow.\n\n*This article is for general information only and is not legal, tax, or financial advice.*\n",{"title":3367,"description":3485},"resources\u002Fmore\u002Fwhat-is-kyb","sJ5tfF_xGlHGnK0fZst797HTfRmA4RPhiqJIstbvT1o",{"id":3504,"title":3505,"authors":6,"body":3506,"categories":6,"category":323,"categoryType":6,"compare":6,"contributors":6,"date":510,"description":3633,"extension":326,"faq":3634,"howto":6,"isBlog":340,"isChangelog":340,"meta":3646,"navigation":343,"path":1032,"pillar":340,"products":6,"rawbody":3647,"role":6,"seo":3648,"stem":3649,"thumbnail":6,"updated":510,"__hash__":3650},"content\u002Fresources\u002Fmore\u002Fwhat-is-a-vasp.md","What is a VASP? Virtual asset service provider explained",{"type":8,"value":3507,"toc":3626},[3508,3511,3514,3518,3521,3553,3565,3569,3572,3578,3582,3594,3597,3601,3607,3609,3622],[11,3509,3510],{},"A VASP, virtual asset service provider, is any business that exchanges, transfers, custodies, or safeguards virtual assets like stablecoins on behalf of customers. FATF, the intergovernmental body that sets global anti-money laundering standards, created the category in 2019 to pull crypto and stablecoin companies under the same AML rules banks already follow.",[11,3512,3513],{},"The category matters because it decides who needs a license. If a company's activity fits FATF's VASP definition, the countries it operates in expect registration, AML controls, and reporting, the same obligations a bank or money transmitter carries, not a lighter version built for crypto.",[28,3515,3517],{"id":3516},"what-activities-make-a-company-a-vasp","What activities make a company a VASP?",[11,3519,3520],{},"FATF Recommendation 15 defines a VASP as any natural or legal person who, as a business, conducts one or more of the following on behalf of another person:",[723,3522,3523,3529,3535,3541,3547],{},[229,3524,3525,3528],{},[20,3526,3527],{},"Exchange between virtual assets and fiat currency."," Converting crypto or stablecoins to dollars, reais, or any other fiat currency, and back.",[229,3530,3531,3534],{},[20,3532,3533],{},"Exchange between forms of virtual assets."," Swapping one token for another, including stablecoin pairs.",[229,3536,3537,3540],{},[20,3538,3539],{},"Transfer of virtual assets."," Moving a virtual asset from one address or account to another on behalf of a customer.",[229,3542,3543,3546],{},[20,3544,3545],{},"Safekeeping or administration."," Custodying virtual assets or the instruments that control them, such as private keys.",[229,3548,3549,3552],{},[20,3550,3551],{},"Participation in financial services related to an issuer's offer or sale of a virtual asset."," Involvement in a token issuance or sale, such as underwriting or distribution.",[11,3554,3555,3556,3560,3561,3564],{},"Classification is activity-based: a company doing any one of these as a business, for someone else, is a VASP, regardless of what it calls itself. A stablecoin off-ramp that converts USDC to reais sits directly in the first category; background on that specific flow is in ",[48,3557,3559],{"href":3558},"\u002Fresources\u002Fmore\u002Fwhat-is-a-stablecoin-offramp","what is a stablecoin off-ramp",". Most VASPs package these activities behind a ",[48,3562,3563],{"href":370},"stablecoin API"," rather than exposing raw wallets and exchange rails.",[28,3566,3568],{"id":3567},"who-has-to-register-or-license-as-a-vasp","Who has to register or license as a VASP?",[11,3570,3571],{},"Any business performing the activities above, in a jurisdiction that has implemented Recommendation 15. That covers most of the world's major markets by now, since FATF membership and mutual evaluation pressure pushed adoption broadly through the early 2020s. The details, though, are set by each country individually: registration with a financial intelligence unit in some places, a full authorization regime with capital and governance requirements in others.",[11,3573,3574,3575,293],{},"Brazil is a concrete example worth studying because the rules are recent and specific: the Banco Central do Brasil built its PSAV authorization directly on the FATF categories, requiring companies that exchange, transfer, or custody virtual assets for Brazilian customers to obtain a license under Resolutions 519, 520, and 521. The full breakdown is in our ",[48,3576,3577],{"href":2408},"PSAV explainer",[28,3579,3581],{"id":3580},"what-does-vasp-status-require-in-practice","What does VASP status require in practice?",[11,3583,3584,3585,3587,3588,3590,3591,3593],{},"Once a company is classified as a VASP, the recurring obligations look similar everywhere: customer identification and KYC on individuals, ",[48,3586,2988],{"href":569}," on business customers, sanctions and watchlist screening, transaction monitoring for suspicious activity, and increasingly the travel rule, which requires sharing sender and receiver information on transfers above a threshold, the same way a wire transfer carries originator data today. How the travel rule and sanctions screening work across jurisdictions is covered in our ",[48,3589,292],{"href":291},". Our ",[48,3592,473],{"href":472}," covers how these checks sit inside an actual payout.",[11,3595,3596],{},"None of this is optional once the activity test is met. A company that calls itself a \"technology platform\" rather than a payment provider is still a VASP if it exchanges or transfers virtual assets for customers; regulators evaluate the activity, not the label on the pitch deck.",[28,3598,3600],{"id":3599},"how-does-vasp-regulation-differ-by-country","How does VASP regulation differ by country?",[11,3602,3603,3604,3606],{},"The activities FATF defines are consistent; the implementation is not. The EU folds virtual asset services into MiCA's authorization regime. The US applies its existing money transmitter and money services business framework, state by state, to the same activities. Brazil built a dedicated PSAV license from scratch in 2025. Details on how these regimes compare are in our ",[48,3605,409],{"href":408},". A company operating across borders typically needs a different license, or license-equivalent, in each market it serves, which is one reason global stablecoin payment coverage is hard to build and harder to fake.",[28,3608,1539],{"id":1538},[11,3610,3611,3613,3614,3616,3617,3619,3620,293],{},[48,3612,1548],{"href":2111}," operates as a licensed entity in the markets it serves, including as a VASP-equivalent authorized provider in Brazil under the transitional PSAV regime, with KYC, KYB, sanctions screening, and travel rule handling built into every payout. Entity and license details by market are published on the ",[48,3615,1015],{"href":1014},", and how the full compliance program runs is on the ",[48,3618,287],{"href":286},". More on the mechanics behind the API is in the ",[48,3621,3309],{"href":3308},[11,3623,3624],{},[14,3625,305],{},{"title":307,"searchDepth":308,"depth":308,"links":3627},[3628,3629,3630,3631,3632],{"id":3516,"depth":308,"text":3517},{"id":3567,"depth":308,"text":3568},{"id":3580,"depth":308,"text":3581},{"id":3599,"depth":308,"text":3600},{"id":1538,"depth":308,"text":1539},"A VASP is any business that exchanges, transfers, or custodies virtual assets like stablecoins for customers. FATF's definition and what it requires in practice.",[3635,3638,3640,3643],{"q":3636,"a":3637},"What does VASP stand for?","Virtual Asset Service Provider. FATF, the global anti-money laundering standard setter, uses the term to define any business that handles virtual assets, including stablecoins, on behalf of customers.",{"q":3517,"a":3639},"Exchanging virtual assets for fiat, exchanging one virtual asset for another, transferring virtual assets, safekeeping or administering them, or participating in financial services tied to an issuer's offer or sale of a virtual asset. Doing any one of these as a business, for someone else, is enough.",{"q":3641,"a":3642},"Does a stablecoin payments company count as a VASP?","Yes, in almost every case. Converting stablecoins to fiat and transferring them for customers falls squarely under the exchange and transfer categories, which is why payment providers built on stablecoins need VASP-equivalent licenses wherever they operate.",{"q":3644,"a":3645},"Is VASP regulation the same in every country?","No. FATF sets the standard, but each country implements it through its own law. Brazil's PSAV, the EU's MiCA authorization, and US state money transmitter licenses are three different implementations of roughly the same underlying activities.",{"author":342},"---\ntitle: \"What is a VASP? Virtual asset service provider explained\"\ndescription: \"A VASP is any business that exchanges, transfers, or custodies virtual assets like stablecoins for customers. FATF's definition and what it requires in practice.\"\ndate: \"2026-09-01\"\nauthor: \"BlindPay Team\"\nupdated: \"2026-09-01\"\ncategory: \"compliance\"\nfaq:\n  - q: \"What does VASP stand for?\"\n    a: \"Virtual Asset Service Provider. FATF, the global anti-money laundering standard setter, uses the term to define any business that handles virtual assets, including stablecoins, on behalf of customers.\"\n  - q: \"What activities make a company a VASP?\"\n    a: \"Exchanging virtual assets for fiat, exchanging one virtual asset for another, transferring virtual assets, safekeeping or administering them, or participating in financial services tied to an issuer's offer or sale of a virtual asset. Doing any one of these as a business, for someone else, is enough.\"\n  - q: \"Does a stablecoin payments company count as a VASP?\"\n    a: \"Yes, in almost every case. Converting stablecoins to fiat and transferring them for customers falls squarely under the exchange and transfer categories, which is why payment providers built on stablecoins need VASP-equivalent licenses wherever they operate.\"\n  - q: \"Is VASP regulation the same in every country?\"\n    a: \"No. FATF sets the standard, but each country implements it through its own law. Brazil's PSAV, the EU's MiCA authorization, and US state money transmitter licenses are three different implementations of roughly the same underlying activities.\"\n---\n\nA VASP, virtual asset service provider, is any business that exchanges, transfers, custodies, or safeguards virtual assets like stablecoins on behalf of customers. FATF, the intergovernmental body that sets global anti-money laundering standards, created the category in 2019 to pull crypto and stablecoin companies under the same AML rules banks already follow.\n\nThe category matters because it decides who needs a license. If a company's activity fits FATF's VASP definition, the countries it operates in expect registration, AML controls, and reporting, the same obligations a bank or money transmitter carries, not a lighter version built for crypto.\n\n## What activities make a company a VASP?\n\nFATF Recommendation 15 defines a VASP as any natural or legal person who, as a business, conducts one or more of the following on behalf of another person:\n\n- **Exchange between virtual assets and fiat currency.** Converting crypto or stablecoins to dollars, reais, or any other fiat currency, and back.\n- **Exchange between forms of virtual assets.** Swapping one token for another, including stablecoin pairs.\n- **Transfer of virtual assets.** Moving a virtual asset from one address or account to another on behalf of a customer.\n- **Safekeeping or administration.** Custodying virtual assets or the instruments that control them, such as private keys.\n- **Participation in financial services related to an issuer's offer or sale of a virtual asset.** Involvement in a token issuance or sale, such as underwriting or distribution.\n\nClassification is activity-based: a company doing any one of these as a business, for someone else, is a VASP, regardless of what it calls itself. A stablecoin off-ramp that converts USDC to reais sits directly in the first category; background on that specific flow is in [what is a stablecoin off-ramp](\u002Fresources\u002Fmore\u002Fwhat-is-a-stablecoin-offramp). Most VASPs package these activities behind a [stablecoin API](\u002Fresources\u002Fmore\u002Fwhat-is-a-stablecoin-api) rather than exposing raw wallets and exchange rails.\n\n## Who has to register or license as a VASP?\n\nAny business performing the activities above, in a jurisdiction that has implemented Recommendation 15. That covers most of the world's major markets by now, since FATF membership and mutual evaluation pressure pushed adoption broadly through the early 2020s. The details, though, are set by each country individually: registration with a financial intelligence unit in some places, a full authorization regime with capital and governance requirements in others.\n\nBrazil is a concrete example worth studying because the rules are recent and specific: the Banco Central do Brasil built its PSAV authorization directly on the FATF categories, requiring companies that exchange, transfer, or custody virtual assets for Brazilian customers to obtain a license under Resolutions 519, 520, and 521. The full breakdown is in our [PSAV explainer](\u002Fresources\u002Fmore\u002Fpsav-brazil-explained).\n\n## What does VASP status require in practice?\n\nOnce a company is classified as a VASP, the recurring obligations look similar everywhere: customer identification and KYC on individuals, [KYB](\u002Fresources\u002Fmore\u002Fwhat-is-kyb) on business customers, sanctions and watchlist screening, transaction monitoring for suspicious activity, and increasingly the travel rule, which requires sharing sender and receiver information on transfers above a threshold, the same way a wire transfer carries originator data today. How the travel rule and sanctions screening work across jurisdictions is covered in our [cross-border compliance guide](\u002Fresources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments). Our [stablecoin payments guide](\u002Fresources\u002Fmore\u002Fstablecoin-payments-guide) covers how these checks sit inside an actual payout.\n\nNone of this is optional once the activity test is met. A company that calls itself a \"technology platform\" rather than a payment provider is still a VASP if it exchanges or transfers virtual assets for customers; regulators evaluate the activity, not the label on the pitch deck.\n\n## How does VASP regulation differ by country?\n\nThe activities FATF defines are consistent; the implementation is not. The EU folds virtual asset services into MiCA's authorization regime. The US applies its existing money transmitter and money services business framework, state by state, to the same activities. Brazil built a dedicated PSAV license from scratch in 2025. Details on how these regimes compare are in our [stablecoin regulation tracker](\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026). A company operating across borders typically needs a different license, or license-equivalent, in each market it serves, which is one reason global stablecoin payment coverage is hard to build and harder to fake.\n\n## How does BlindPay fit in?\n\n[BlindPay](\u002Fglobal-payments) operates as a licensed entity in the markets it serves, including as a VASP-equivalent authorized provider in Brazil under the transitional PSAV regime, with KYC, KYB, sanctions screening, and travel rule handling built into every payout. Entity and license details by market are published on the [licenses page](\u002Flicenses), and how the full compliance program runs is on the [compliance page](\u002Fcompliance). More on the mechanics behind the API is in the [resources hub](\u002Fresources\u002Fmore).\n\n*This article is for general information only and is not legal, tax, or financial advice.*\n",{"title":3505,"description":3633},"resources\u002Fmore\u002Fwhat-is-a-vasp","joZMszqPnTFcRs7OMnZQEEEIML07RJzsx7YrlJvAgyw",{"id":3652,"title":3653,"authors":6,"body":3654,"categories":6,"category":323,"categoryType":6,"compare":6,"contributors":6,"date":324,"description":4001,"extension":326,"faq":4002,"howto":6,"isBlog":340,"isChangelog":340,"meta":4018,"navigation":343,"path":71,"pillar":340,"products":6,"rawbody":4019,"role":6,"seo":4020,"stem":4021,"thumbnail":6,"updated":324,"__hash__":4022},"content\u002Fresources\u002Fmore\u002Fwhat-is-automated-risk-monitoring-fintech.md","What is automated risk monitoring in fintech?",{"type":8,"value":3655,"toc":3991},[3656,3660,3665,3668,3672,3675,3678,3681,3685,3688,3691,3711,3716,3720,3723,3726,3752,3755,3759,3762,3765,3785,3788,3792,3795,3798,3818,3825,3829,3832,3924,3927,3931,3934,3940,3946,3952,3958,3962,3967,3984,3987],[11,3657,3658],{},[14,3659,16],{},[11,3661,3662,3664],{},[20,3663,22],{}," Automated risk monitoring is the set of systems a fintech runs to continuously screen customers, transactions, and counterparties for money laundering, sanctions exposure, and fraud without a human reviewing every case. It combines identity verification at onboarding, transaction monitoring on every payment, ongoing sanctions screening, and software that triages the resulting alerts.",[11,3666,3667],{},"The term covers a lot of ground, so this explainer takes it apart into its four components, shows what each one actually checks, and compares the manual and automated versions of the same work. It is written as a reference, not a pitch.",[28,3669,3671],{"id":3670},"what-does-automated-risk-monitoring-do","What does automated risk monitoring do?",[11,3673,3674],{},"Every fintech that moves money is a target for people trying to steal from it and for people trying to move illicit funds through it. Regulators care mostly about the second. The Financial Crimes Enforcement Network (FinCEN) in the US, the Financial Action Task Force (FATF) globally, and the Office of Foreign Assets Control (OFAC) for sanctions all expect a company to know who its customers are, watch what they do, and report what looks wrong.",[11,3676,3677],{},"Doing that by hand works up to a few hundred customers. After that, the review queue grows faster than the compliance team.",[11,3679,3680],{},"Automated risk monitoring replaces per-case human review with rules and models that run on every customer and every transaction, and reserves human judgment for the cases the system cannot decide. The four components below are the standard shape of that system.",[28,3682,3684],{"id":3683},"_1-kyc-and-kyb-verification","1. KYC and KYB verification",[11,3686,3687],{},"Know Your Customer (KYC) verifies that an individual is who they claim to be; Know Your Business (KYB) verifies that a company exists, is in good standing, and is owned and controlled by identifiable people.",[11,3689,3690],{},"Both run at onboarding, before the customer can move money. Automated verification checks things like:",[723,3692,3693,3699,3705],{},[229,3694,3695,3698],{},[20,3696,3697],{},"Document authenticity."," The ID's security features, fonts, and machine-readable zone are checked against the issuing template, and the expiry date is validated. A liveness check and face match confirm the person presenting the document is real and present.",[229,3700,3701,3704],{},[20,3702,3703],{},"Registry data for businesses."," The registration number is looked up in the corporate registry (Companies House, a Secretary of State database, the Brazilian CNPJ registry) to confirm the entity is active and the stated name and address match.",[229,3706,3707,3710],{},[20,3708,3709],{},"Beneficial ownership."," Under FinCEN's customer due diligence rule, every individual owning 25 percent or more of a legal entity customer, plus one controller, must be identified and verified. The system unwinds holding companies until it reaches real people, then runs KYC on each.",[11,3712,1426,3713,3715],{},[48,3714,570],{"href":569}," covers the ownership rules in more depth.",[28,3717,3719],{"id":3718},"_2-transaction-monitoring","2. Transaction monitoring",[11,3721,3722],{},"Transaction monitoring evaluates each payment, and the pattern of payments over time, against rules that describe suspicious behavior.",[11,3724,3725],{},"The classic patterns come straight from FinCEN and FATF guidance:",[723,3727,3728,3734,3740,3746],{},[229,3729,3730,3733],{},[20,3731,3732],{},"Structuring."," Several deposits or transfers each just below a reporting threshold (USD 10,000 for a Currency Transaction Report in the US) within a short window. Nine transfers of USD 9,800 in two days is the textbook case.",[229,3735,3736,3739],{},[20,3737,3738],{},"Velocity spikes."," A customer whose baseline is two payments a month suddenly sends forty in a week, or an account that receives funds and forwards nearly all of them within minutes.",[229,3741,3742,3745],{},[20,3743,3744],{},"Geographic mismatch."," A business registered in Colombia whose payments all originate from IP addresses in a third country, or a receiver whose bank account is in a jurisdiction that never appeared in onboarding.",[229,3747,3748,3751],{},[20,3749,3750],{},"Round-tripping."," Funds leaving an account and returning through a different counterparty at a similar amount, which is a layering pattern.",[11,3753,3754],{},"Each rule produces a score or a hard alert. Low scores pass. High scores hold the transaction before settlement. The rest go to a queue.",[28,3756,3758],{"id":3757},"_3-sanctions-and-watchlist-screening","3. Sanctions and watchlist screening",[11,3760,3761],{},"Sanctions screening checks the names, identifiers, and (for stablecoin payments) wallet addresses of every party against government lists, on an ongoing basis rather than only at signup.",[11,3763,3764],{},"The core lists a fintech serving US or international customers screens against are:",[723,3766,3767,3773,3779],{},[229,3768,3769,3772],{},[20,3770,3771],{},"OFAC Specially Designated Nationals (SDN) and consolidated lists."," OFAC compliance is strict liability: a payment that reaches a listed party is a violation regardless of intent. OFAC has listed blockchain addresses on the SDN list since 2018.",[229,3774,3775,3778],{},[20,3776,3777],{},"UN Security Council, EU consolidated, and UK OFSI lists."," Required as soon as the business touches those markets or their currencies.",[229,3780,3781,3784],{},[20,3782,3783],{},"Politically exposed person (PEP) databases and adverse media."," Not sanctions, but FATF Recommendation 12 requires enhanced due diligence on PEPs, so a PEP match changes the risk tier.",[11,3786,3787],{},"The word \"ongoing\" is what separates screening from a signup check. OFAC updates the SDN list several times a month. A customer who was clean in January can become a match in March without doing anything, and the system has to catch that by rescreening the customer base each time a list changes.",[28,3789,3791],{"id":3790},"_4-compliance-automation","4. Compliance automation",[11,3793,3794],{},"Compliance automation is the layer that handles the output of the other three: it triages alerts, gathers evidence, drafts case narratives, and prepares regulatory filings so analysts spend their time on decisions rather than paperwork.",[11,3796,3797],{},"In practice this covers:",[723,3799,3800,3806,3812],{},[229,3801,3802,3805],{},[20,3803,3804],{},"Alert triage."," Deduplicating alerts on the same customer, closing obvious false positives (a name match with a different date of birth and country), and ranking the remainder by risk so an analyst opens the worst case first.",[229,3807,3808,3811],{},[20,3809,3810],{},"Case narratives."," Assembling the customer profile, the transactions that fired the rule, the screening results, and a draft explanation into a case file. Suspicious Activity Reports (SARs) filed with FinCEN require a written narrative, and drafting it is most of an analyst's time.",[229,3813,3814,3817],{},[20,3815,3816],{},"Recordkeeping."," Storing every input, check result, and decision with timestamps. The Bank Secrecy Act requires five years of retention, and an examiner will ask for the full trail on a sample of cases.",[11,3819,3820,3821,3824],{},"This is where AI has landed most recently. A ",[48,3822,3823],{"href":3360},"compliance agent"," can read a case, pull the supporting data, and write the first draft of the narrative, but the filing decision stays with a named human.",[28,3826,3828],{"id":3827},"manual-vs-automated-risk-monitoring","Manual vs. automated risk monitoring",[11,3830,3831],{},"The comparison below describes the same obligations met two ways. Figures are typical ranges from industry practice rather than a guarantee for any given program.",[121,3833,3834,3846],{},[124,3835,3836],{},[127,3837,3838,3840,3843],{},[130,3839,132],{},[130,3841,3842],{},"Manual program",[130,3844,3845],{},"Automated program",[140,3847,3848,3859,3870,3881,3892,3902,3913],{},[127,3849,3850,3853,3856],{},[145,3851,3852],{},"Coverage",[145,3854,3855],{},"A sample of transactions, or only those above a threshold",[145,3857,3858],{},"Every customer and every transaction",[127,3860,3861,3864,3867],{},[145,3862,3863],{},"Onboarding decision",[145,3865,3866],{},"Hours to days per case",[145,3868,3869],{},"Seconds to minutes for a clean case; edge cases routed to review",[127,3871,3872,3875,3878],{},[145,3873,3874],{},"Sanctions rescreening",[145,3876,3877],{},"Periodic, often quarterly",[145,3879,3880],{},"On every list update and every transaction",[127,3882,3883,3886,3889],{},[145,3884,3885],{},"False positives",[145,3887,3888],{},"Depend on the analyst; inconsistent between reviewers",[145,3890,3891],{},"Tunable per rule; consistent, and measurable",[127,3893,3894,3896,3899],{},[145,3895,3209],{},[145,3897,3898],{},"Emails, spreadsheets, and PDFs",[145,3900,3901],{},"Structured log of inputs, rules fired, and decisions",[127,3903,3904,3907,3910],{},[145,3905,3906],{},"Scaling",[145,3908,3909],{},"Headcount grows with volume",[145,3911,3912],{},"Rules and models scale; analysts handle exceptions",[127,3914,3915,3918,3921],{},[145,3916,3917],{},"Human judgment",[145,3919,3920],{},"On everything",[145,3922,3923],{},"On the cases the system cannot decide",[11,3925,3926],{},"Automation does not remove the need for analysts; it changes what they look at. Badly tuned rules generate thousands of alerts and bury the real ones, which is why alert tuning is ongoing work rather than a one-time setup.",[28,3928,3930],{"id":3929},"who-requires-it","Who requires it?",[11,3932,3933],{},"Three bodies come up in nearly every conversation about risk monitoring, and they play different roles.",[11,3935,3936,3939],{},[20,3937,3938],{},"FinCEN"," is the US financial intelligence unit and the administrator of the Bank Secrecy Act. Money services businesses, which include most fintechs that transmit funds or exchange stablecoins, must register with FinCEN, maintain a written AML program with ongoing monitoring, file SARs, and keep records for five years.",[11,3941,3942,3945],{},[20,3943,3944],{},"OFAC"," administers US sanctions. Any US person, and any transaction touching the US financial system, must not deal with listed parties. There is no volume threshold and no intent defense.",[11,3947,3948,3951],{},[20,3949,3950],{},"FATF"," does not regulate companies directly. It sets the standards that national regulators implement, including Recommendation 10 (ongoing customer due diligence), Recommendation 12 (PEPs), and Recommendation 16 (the Travel Rule, extended to virtual assets in 2019). When a regulator in Brazil, Singapore, or the EU writes its AML rules, it starts from FATF.",[11,3953,3954,3955,3957],{},"For a fintech moving stablecoins across borders, all three apply on the same transaction. The ",[48,3956,292],{"href":291}," walks through how the jurisdictions stack.",[28,3959,3961],{"id":3960},"where-risk-monitoring-sits-in-a-payment-flow","Where risk monitoring sits in a payment flow",[11,3963,3964,3965,293],{},"Verification runs once per customer before they can transact. Screening and transaction monitoring run on every payment, and for stablecoins the checks must finish before funds move, because a transfer on a public blockchain ",[48,3966,51],{"href":50},[226,3968,3969,3972,3975,3978,3981],{},[229,3970,3971],{},"Customer or receiver is created with identity or entity data, and KYC or KYB runs.",[229,3973,3974],{},"On approval, the record is eligible for payments. On a screening hit or data mismatch, it holds for review.",[229,3976,3977],{},"Each payment is scored: sanctions rescreen, velocity and pattern rules, corridor risk, wallet address risk.",[229,3979,3980],{},"Low risk settles. High risk is blocked. Medium risk holds for an analyst.",[229,3982,3983],{},"Every decision is logged, and cases that meet the SAR standard are drafted for filing.",[11,3985,3986],{},"For a company still reviewing cases by hand, sanctions rescreening and transaction rules are the two places to automate first, because those are where a manual program fails an examination first.",[11,3988,3989],{},[14,3990,305],{},{"title":307,"searchDepth":308,"depth":308,"links":3992},[3993,3994,3995,3996,3997,3998,3999,4000],{"id":3670,"depth":308,"text":3671},{"id":3683,"depth":308,"text":3684},{"id":3718,"depth":308,"text":3719},{"id":3757,"depth":308,"text":3758},{"id":3790,"depth":308,"text":3791},{"id":3827,"depth":308,"text":3828},{"id":3929,"depth":308,"text":3930},{"id":3960,"depth":308,"text":3961},"A reference explainer on automated risk monitoring for fintechs: the four components (KYC\u002FKYB, transaction monitoring, sanctions and watchlist screening, compliance automation), what each one flags, a manual vs. automated comparison, and what FinCEN, FATF, and OFAC actually require.",[4003,4006,4009,4012,4015],{"q":4004,"a":4005},"What triggers a risk monitoring alert?","A rule or model threshold being crossed: a name or wallet matching a sanctions list, a transaction above a reporting threshold, several transactions just under a threshold in a short window, a sudden jump in volume against the customer's baseline, a payment to a high-risk country, or a change in the customer's verified data. Each alert carries the rule that fired and the evidence behind it.",{"q":4007,"a":4008},"Is automated risk monitoring required by regulation?","The monitoring is required; automation is not named. FinCEN requires money services businesses under the Bank Secrecy Act to maintain an AML program with ongoing transaction monitoring, OFAC sanctions compliance is strict liability, and FATF Recommendation 10 requires ongoing due diligence. At any real transaction volume, only automated systems can meet those obligations on every transaction.",{"q":4010,"a":4011},"How is automated risk monitoring different from fraud detection?","Fraud detection protects the company and its customers from losing money to theft, account takeover, or chargebacks. Risk monitoring protects the company from being used to launder money or breach sanctions, which is a regulatory obligation. They share signals like velocity and device data, but fraud alerts are resolved commercially while AML alerts can end in a suspicious activity report to FinCEN.",{"q":4013,"a":4014},"What are the four components of automated risk monitoring?","KYC and KYB verification at onboarding, transaction monitoring on every payment, sanctions and watchlist screening on an ongoing basis, and compliance automation that triages alerts, drafts case narratives, and files reports.",{"q":4016,"a":4017},"How often should sanctions screening run?","At onboarding, on every transaction, and again each time a sanctions list is updated. OFAC updates the SDN list several times a month, so a customer cleared at signup can become a match later without any change on their side.",{"author":342},"---\ntitle: \"What is automated risk monitoring in fintech?\"\ndescription: \"A reference explainer on automated risk monitoring for fintechs: the four components (KYC\u002FKYB, transaction monitoring, sanctions and watchlist screening, compliance automation), what each one flags, a manual vs. automated comparison, and what FinCEN, FATF, and OFAC actually require.\"\ndate: \"2026-09-15\"\nupdated: \"2026-09-15\"\nauthor: \"BlindPay Team\"\ncategory: \"compliance\"\nfaq:\n  - q: \"What triggers a risk monitoring alert?\"\n    a: \"A rule or model threshold being crossed: a name or wallet matching a sanctions list, a transaction above a reporting threshold, several transactions just under a threshold in a short window, a sudden jump in volume against the customer's baseline, a payment to a high-risk country, or a change in the customer's verified data. Each alert carries the rule that fired and the evidence behind it.\"\n  - q: \"Is automated risk monitoring required by regulation?\"\n    a: \"The monitoring is required; automation is not named. FinCEN requires money services businesses under the Bank Secrecy Act to maintain an AML program with ongoing transaction monitoring, OFAC sanctions compliance is strict liability, and FATF Recommendation 10 requires ongoing due diligence. At any real transaction volume, only automated systems can meet those obligations on every transaction.\"\n  - q: \"How is automated risk monitoring different from fraud detection?\"\n    a: \"Fraud detection protects the company and its customers from losing money to theft, account takeover, or chargebacks. Risk monitoring protects the company from being used to launder money or breach sanctions, which is a regulatory obligation. They share signals like velocity and device data, but fraud alerts are resolved commercially while AML alerts can end in a suspicious activity report to FinCEN.\"\n  - q: \"What are the four components of automated risk monitoring?\"\n    a: \"KYC and KYB verification at onboarding, transaction monitoring on every payment, sanctions and watchlist screening on an ongoing basis, and compliance automation that triages alerts, drafts case narratives, and files reports.\"\n  - q: \"How often should sanctions screening run?\"\n    a: \"At onboarding, on every transaction, and again each time a sanctions list is updated. OFAC updates the SDN list several times a month, so a customer cleared at signup can become a match later without any change on their side.\"\n---\n\n*Reading time: about 7 minutes.*\n\n**Summary:** Automated risk monitoring is the set of systems a fintech runs to continuously screen customers, transactions, and counterparties for money laundering, sanctions exposure, and fraud without a human reviewing every case. It combines identity verification at onboarding, transaction monitoring on every payment, ongoing sanctions screening, and software that triages the resulting alerts.\n\nThe term covers a lot of ground, so this explainer takes it apart into its four components, shows what each one actually checks, and compares the manual and automated versions of the same work. It is written as a reference, not a pitch.\n\n## What does automated risk monitoring do?\n\nEvery fintech that moves money is a target for people trying to steal from it and for people trying to move illicit funds through it. Regulators care mostly about the second. The Financial Crimes Enforcement Network (FinCEN) in the US, the Financial Action Task Force (FATF) globally, and the Office of Foreign Assets Control (OFAC) for sanctions all expect a company to know who its customers are, watch what they do, and report what looks wrong.\n\nDoing that by hand works up to a few hundred customers. After that, the review queue grows faster than the compliance team.\n\nAutomated risk monitoring replaces per-case human review with rules and models that run on every customer and every transaction, and reserves human judgment for the cases the system cannot decide. The four components below are the standard shape of that system.\n\n## 1. KYC and KYB verification\n\nKnow Your Customer (KYC) verifies that an individual is who they claim to be; Know Your Business (KYB) verifies that a company exists, is in good standing, and is owned and controlled by identifiable people.\n\nBoth run at onboarding, before the customer can move money. Automated verification checks things like:\n\n- **Document authenticity.** The ID's security features, fonts, and machine-readable zone are checked against the issuing template, and the expiry date is validated. A liveness check and face match confirm the person presenting the document is real and present.\n- **Registry data for businesses.** The registration number is looked up in the corporate registry (Companies House, a Secretary of State database, the Brazilian CNPJ registry) to confirm the entity is active and the stated name and address match.\n- **Beneficial ownership.** Under FinCEN's customer due diligence rule, every individual owning 25 percent or more of a legal entity customer, plus one controller, must be identified and verified. The system unwinds holding companies until it reaches real people, then runs KYC on each.\n\nThe [KYB explainer](\u002Fresources\u002Fmore\u002Fwhat-is-kyb) covers the ownership rules in more depth.\n\n## 2. Transaction monitoring\n\nTransaction monitoring evaluates each payment, and the pattern of payments over time, against rules that describe suspicious behavior.\n\nThe classic patterns come straight from FinCEN and FATF guidance:\n\n- **Structuring.** Several deposits or transfers each just below a reporting threshold (USD 10,000 for a Currency Transaction Report in the US) within a short window. Nine transfers of USD 9,800 in two days is the textbook case.\n- **Velocity spikes.** A customer whose baseline is two payments a month suddenly sends forty in a week, or an account that receives funds and forwards nearly all of them within minutes.\n- **Geographic mismatch.** A business registered in Colombia whose payments all originate from IP addresses in a third country, or a receiver whose bank account is in a jurisdiction that never appeared in onboarding.\n- **Round-tripping.** Funds leaving an account and returning through a different counterparty at a similar amount, which is a layering pattern.\n\nEach rule produces a score or a hard alert. Low scores pass. High scores hold the transaction before settlement. The rest go to a queue.\n\n## 3. Sanctions and watchlist screening\n\nSanctions screening checks the names, identifiers, and (for stablecoin payments) wallet addresses of every party against government lists, on an ongoing basis rather than only at signup.\n\nThe core lists a fintech serving US or international customers screens against are:\n\n- **OFAC Specially Designated Nationals (SDN) and consolidated lists.** OFAC compliance is strict liability: a payment that reaches a listed party is a violation regardless of intent. OFAC has listed blockchain addresses on the SDN list since 2018.\n- **UN Security Council, EU consolidated, and UK OFSI lists.** Required as soon as the business touches those markets or their currencies.\n- **Politically exposed person (PEP) databases and adverse media.** Not sanctions, but FATF Recommendation 12 requires enhanced due diligence on PEPs, so a PEP match changes the risk tier.\n\nThe word \"ongoing\" is what separates screening from a signup check. OFAC updates the SDN list several times a month. A customer who was clean in January can become a match in March without doing anything, and the system has to catch that by rescreening the customer base each time a list changes.\n\n## 4. Compliance automation\n\nCompliance automation is the layer that handles the output of the other three: it triages alerts, gathers evidence, drafts case narratives, and prepares regulatory filings so analysts spend their time on decisions rather than paperwork.\n\nIn practice this covers:\n\n- **Alert triage.** Deduplicating alerts on the same customer, closing obvious false positives (a name match with a different date of birth and country), and ranking the remainder by risk so an analyst opens the worst case first.\n- **Case narratives.** Assembling the customer profile, the transactions that fired the rule, the screening results, and a draft explanation into a case file. Suspicious Activity Reports (SARs) filed with FinCEN require a written narrative, and drafting it is most of an analyst's time.\n- **Recordkeeping.** Storing every input, check result, and decision with timestamps. The Bank Secrecy Act requires five years of retention, and an examiner will ask for the full trail on a sample of cases.\n\nThis is where AI has landed most recently. A [compliance agent](\u002Fresources\u002Fmore\u002Fwhat-are-compliance-agents-in-fintech) can read a case, pull the supporting data, and write the first draft of the narrative, but the filing decision stays with a named human.\n\n## Manual vs. automated risk monitoring\n\nThe comparison below describes the same obligations met two ways. Figures are typical ranges from industry practice rather than a guarantee for any given program.\n\n| Dimension | Manual program | Automated program |\n|---|---|---|\n| Coverage | A sample of transactions, or only those above a threshold | Every customer and every transaction |\n| Onboarding decision | Hours to days per case | Seconds to minutes for a clean case; edge cases routed to review |\n| Sanctions rescreening | Periodic, often quarterly | On every list update and every transaction |\n| False positives | Depend on the analyst; inconsistent between reviewers | Tunable per rule; consistent, and measurable |\n| Audit trail | Emails, spreadsheets, and PDFs | Structured log of inputs, rules fired, and decisions |\n| Scaling | Headcount grows with volume | Rules and models scale; analysts handle exceptions |\n| Human judgment | On everything | On the cases the system cannot decide |\n\nAutomation does not remove the need for analysts; it changes what they look at. Badly tuned rules generate thousands of alerts and bury the real ones, which is why alert tuning is ongoing work rather than a one-time setup.\n\n## Who requires it?\n\nThree bodies come up in nearly every conversation about risk monitoring, and they play different roles.\n\n**FinCEN** is the US financial intelligence unit and the administrator of the Bank Secrecy Act. Money services businesses, which include most fintechs that transmit funds or exchange stablecoins, must register with FinCEN, maintain a written AML program with ongoing monitoring, file SARs, and keep records for five years.\n\n**OFAC** administers US sanctions. Any US person, and any transaction touching the US financial system, must not deal with listed parties. There is no volume threshold and no intent defense.\n\n**FATF** does not regulate companies directly. It sets the standards that national regulators implement, including Recommendation 10 (ongoing customer due diligence), Recommendation 12 (PEPs), and Recommendation 16 (the Travel Rule, extended to virtual assets in 2019). When a regulator in Brazil, Singapore, or the EU writes its AML rules, it starts from FATF.\n\nFor a fintech moving stablecoins across borders, all three apply on the same transaction. The [cross-border compliance guide](\u002Fresources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments) walks through how the jurisdictions stack.\n\n## Where risk monitoring sits in a payment flow\n\nVerification runs once per customer before they can transact. Screening and transaction monitoring run on every payment, and for stablecoins the checks must finish before funds move, because a transfer on a public blockchain [cannot be reversed](\u002Fresources\u002Fmore\u002Fare-stablecoin-payments-reversible).\n\n1. Customer or receiver is created with identity or entity data, and KYC or KYB runs.\n2. On approval, the record is eligible for payments. On a screening hit or data mismatch, it holds for review.\n3. Each payment is scored: sanctions rescreen, velocity and pattern rules, corridor risk, wallet address risk.\n4. Low risk settles. High risk is blocked. Medium risk holds for an analyst.\n5. Every decision is logged, and cases that meet the SAR standard are drafted for filing.\n\nFor a company still reviewing cases by hand, sanctions rescreening and transaction rules are the two places to automate first, because those are where a manual program fails an examination first.\n\n*This article is for general information only and is not legal, tax, or financial advice.*\n",{"title":3653,"description":4001},"resources\u002Fmore\u002Fwhat-is-automated-risk-monitoring-fintech","LT9JZlqieEyGTzEfKeLNX_pgZom92tQxAXfEMy1qpiM",1789483213896]