[{"data":1,"prerenderedAt":878},["ShallowReactive",2],{"content-\u002Fresources\u002Fmore\u002Ftransaction-monitoring-red-flags-stablecoin-payments":3,"resources-category-transaction-monitoring-red-flags-stablecoin-payments":765},{"id":4,"title":5,"authors":6,"body":7,"categories":6,"category":713,"categoryType":6,"compare":6,"contributors":6,"date":714,"description":715,"extension":716,"faq":717,"howto":736,"isBlog":755,"isChangelog":755,"meta":756,"navigation":758,"path":759,"pillar":755,"products":6,"rawbody":760,"role":6,"seo":761,"seoTitle":762,"stem":763,"thumbnail":6,"updated":714,"__hash__":764},"content\u002Fresources\u002Fmore\u002Ftransaction-monitoring-red-flags-stablecoin-payments.md","Transaction monitoring red flags for stablecoin payments: 12 rules to automate",null,{"type":8,"value":9,"toc":698},"minimark",[10,14,17,23,42,47,50,64,68,71,151,154,158,161,382,385,409,421,427,431,439,442,446,449,488,491,495,498,504,521,524,527,536,545,549,558,561,565,568,606,610,613,635,639,647,651,692],[11,12,13],"p",{},"An automated transaction monitoring system should flag structuring, velocity spikes, rapid in-and-out movement, round amounts, high-risk corridors, activity that contradicts the customer's declared business, fan-in patterns, risky wallet addresses, dormant accounts waking up, changed customer data, bridge or mixer hops, and near-threshold payments across linked accounts. Each rule pairs a condition with an action: pass, hold, block, or review.",[11,15,16],{},"This article is general information, not legal advice. Thresholds below are illustrative, not recommendations.",[11,18,19],{},[20,21,22],"strong",{},"Key takeaways",[24,25,26,30,33,36,39],"ul",{},[27,28,29],"li",{},"A red flag only works in automation when it's written as a rule: a condition, a threshold, an action, and the data it needs.",[27,31,32],{},"Fixed rules, behavioral baselines, and risk scoring do different jobs. A working system uses all three.",[27,34,35],{},"Stablecoin transfers are final once confirmed, so the rules have to run before settlement, not on yesterday's file.",[27,37,38],{},"Structuring rules raise alerts, not reports. FinCEN says amounts near a threshold alone don't require a suspicious activity report.",[27,40,41],{},"Every rule needs a documented reason and a test case. Copied vendor defaults fail both.",[43,44,46],"h2",{"id":45},"what-is-automated-transaction-monitoring","What is automated transaction monitoring?",[11,48,49],{},"Automated transaction monitoring is software that checks every payment against a set of rules and models, and flags the ones that look like money laundering, sanctions evasion, or fraud. It replaces a person reading every transaction with a person reviewing only the flagged ones.",[11,51,52,53,58,59,63],{},"It's one of four parts of a ",[54,55,57],"a",{"href":56},"\u002Fresources\u002Fmore\u002Fwhat-is-automated-risk-monitoring-fintech","risk monitoring program",", next to KYC and KYB, sanctions screening, and alert handling. This guide is about the rule library itself: what to flag, how each rule works, and what happens next. The signals behind a stablecoin risk score, and why real-time beats batch, are covered in ",[54,60,62],{"href":61},"\u002Fresources\u002Fmore\u002Freal-time-transaction-monitoring-stablecoin-payments","real-time transaction monitoring for stablecoin payments",".",[43,65,67],{"id":66},"how-do-rules-behavioral-baselines-and-risk-scoring-differ","How do rules, behavioral baselines, and risk scoring differ?",[11,69,70],{},"Rules check a fixed condition, baselines compare a customer with its own past and its peers, and risk scoring combines both into one number that drives the action. Most red flags below use more than one.",[72,73,74,96],"table",{},[75,76,77],"thead",{},[78,79,80,84,87,90,93],"tr",{},[81,82,83],"th",{},"Method",[81,85,86],{},"How it works",[81,88,89],{},"Good at",[81,91,92],{},"Weak at",[81,94,95],{},"Illustrative example",[97,98,99,117,134],"tbody",{},[78,100,101,105,108,111,114],{},[102,103,104],"td",{},"Rule-based alerts",[102,106,107],{},"A fixed condition fires when met",[102,109,110],{},"Hard limits, sanctions hits, known typologies",[102,112,113],{},"Too many alerts on large customers, easy to game once known",[102,115,116],{},"Any transfer to a wallet on the SDN List",[78,118,119,122,125,128,131],{},[102,120,121],{},"Behavioral baselines (peer groups)",[102,123,124],{},"Compares activity with the customer's history and with similar customers",[102,126,127],{},"Catching change: spikes, new corridors, dormancy",[102,129,130],{},"Needs history; new customers have no baseline",[102,132,133],{},"7-day volume at 3 times the customer's 90-day average",[78,135,136,139,142,145,148],{},[102,137,138],{},"Risk scoring",[102,140,141],{},"Weights rule hits, baselines, and customer risk into one score",[102,143,144],{},"Ranking alerts, routing to pass, hold, or review",[102,146,147],{},"Hard to explain if weights aren't documented",[102,149,150],{},"Score above 70 holds the payment for review",[11,152,153],{},"A peer group is a set of customers with similar type, size, and declared activity. A new marketplace seller gets compared with other new marketplace sellers until it has a history of its own.",[43,155,157],{"id":156},"what-are-the-12-red-flags-an-automated-system-should-flag","What are the 12 red flags an automated system should flag?",[11,159,160],{},"These 12 cover the patterns that show up most often in stablecoin and cross-border payment flows. The thresholds are illustrative. Set yours from your own data and your risk assessment.",[72,162,163,182],{},[75,164,165],{},[78,166,167,170,173,176,179],{},[81,168,169],{},"#",[81,171,172],{},"Red flag",[81,174,175],{},"Rule logic (illustrative thresholds)",[81,177,178],{},"Typical action",[81,180,181],{},"Data needed",[97,183,184,201,217,233,250,267,283,299,316,333,349,366],{},[78,185,186,189,192,195,198],{},[102,187,188],{},"1",[102,190,191],{},"Structuring below a reporting threshold",[102,193,194],{},"3 or more transfers between 90 and 99.9 percent of a threshold (USD 10,000 cash, USD 3,000 US travel rule, or an internal limit) within 48 hours",[102,196,197],{},"Review",[102,199,200],{},"Amounts, timestamps, customer ID",[78,202,203,206,209,212,214],{},[102,204,205],{},"2",[102,207,208],{},"Velocity spike against baseline",[102,210,211],{},"7-day volume above 3 times the customer's 90-day weekly average",[102,213,197],{},[102,215,216],{},"Transaction history, customer baseline",[78,218,219,222,225,228,230],{},[102,220,221],{},"3",[102,223,224],{},"Rapid in-and-out movement",[102,226,227],{},"80 percent or more of an incoming amount sent onward to a different party within 24 hours",[102,229,197],{},[102,231,232],{},"Payin and payout records, timestamps",[78,234,235,238,241,244,247],{},[102,236,237],{},"4",[102,239,240],{},"Round amount patterns",[102,242,243],{},"5 or more transfers in exact multiples of USD 1,000 in 30 days with no matching invoices",[102,245,246],{},"Review (low weight in score)",[102,248,249],{},"Amounts, declared activity",[78,251,252,255,258,261,264],{},[102,253,254],{},"5",[102,256,257],{},"High-risk corridor",[102,259,260],{},"Origin or destination country on the internal high-risk list; prohibited countries stopped outright",[102,262,263],{},"Review or block",[102,265,266],{},"Customer country, bank country, IP and geolocation",[78,268,269,272,275,278,280],{},[102,270,271],{},"6",[102,273,274],{},"Declared activity mismatch",[102,276,277],{},"Monthly volume above 2 times declared expected volume, or payments to industries outside the profile",[102,279,197],{},[102,281,282],{},"KYB profile, expected volume, counterparties",[78,284,285,288,291,294,296],{},[102,286,287],{},"7",[102,289,290],{},"Many senders to one receiver",[102,292,293],{},"10 or more distinct senders paying one beneficiary in 7 days",[102,295,197],{},[102,297,298],{},"Sender and beneficiary identifiers",[78,300,301,304,307,310,313],{},[102,302,303],{},"8",[102,305,306],{},"Wallet linked to sanctions or illicit clusters",[102,308,309],{},"Address on the SDN List, or analytics exposure to sanctioned, mixer, or stolen-funds clusters above risk appetite",[102,311,312],{},"Block (direct hit) or hold",[102,314,315],{},"Wallet address, list data, analytics score",[78,317,318,321,324,327,330],{},[102,319,320],{},"9",[102,322,323],{},"Activity after a dormant period",[102,325,326],{},"No activity for 180 days, then a transfer above the customer's historical maximum",[102,328,329],{},"Hold",[102,331,332],{},"Account history",[78,334,335,338,341,344,346],{},[102,336,337],{},"10",[102,339,340],{},"Sudden change in verified data",[102,342,343],{},"New bank account, wallet, email, or phone within 72 hours before a large payout",[102,345,329],{},[102,347,348],{},"Profile change log, timestamps",[78,350,351,354,357,360,363],{},[102,352,353],{},"11",[102,355,356],{},"Bridge or mixer hops before deposit",[102,358,359],{},"Funds reach the deposit address through a mixer, or through 2 or more bridge hops within 24 hours",[102,361,362],{},"Hold or block",[102,364,365],{},"On-chain trace, analytics data",[78,367,368,371,374,377,379],{},[102,369,370],{},"12",[102,372,373],{},"Near-threshold payments across linked accounts",[102,375,376],{},"Customers sharing an owner, address, device, or bank account each send just under a threshold on the same day",[102,378,197],{},[102,380,381],{},"Entity links: shared identifiers",[11,383,384],{},"A few notes on the rows that trip teams up.",[11,386,387,390,391,397,398,402,403,408],{},[20,388,389],{},"Row 1 needs care with the threshold."," The currency transaction report (CTR) under ",[54,392,396],{"href":393,"rel":394},"https:\u002F\u002Fwww.law.cornell.edu\u002Fcfr\u002Ftext\u002F31\u002F1010.311",[395],"nofollow","31 CFR 1010.311"," covers transactions in currency of more than USD 10,000, which means cash. A stablecoin payout isn't cash. The same splitting behavior still matters, though: under the USD 3,000 US ",[54,399,401],{"href":400},"\u002Fresources\u002Fmore\u002Ftravel-rule-stablecoin-off-ramps","travel rule threshold",", under a provider's per-transfer limit, or on the cash side of an on-ramp. Structuring to evade a reporting requirement is a crime under ",[54,404,407],{"href":405,"rel":406},"https:\u002F\u002Fwww.law.cornell.edu\u002Fuscode\u002Ftext\u002F31\u002F5324",[395],"31 USC 5324",", whether or not the money is dirty.",[11,410,411,414,415,420],{},[20,412,413],{},"Row 8 is the one rule with no judgment call on a direct hit."," OFAC ",[54,416,419],{"href":417,"rel":418},"https:\u002F\u002Fofac.treasury.gov\u002Ffaqs\u002F562",[395],"adds some wallet addresses to SDN List entries"," and says those listings are not likely to be exhaustive. So a clean list check isn't the end of it. Analytics exposure covers what the list misses.",[11,422,423,426],{},[20,424,425],{},"Row 12 depends on entity resolution."," Entity resolution means linking customers that share identifiers. Without it, a structuring ring split across five accounts looks like five clean customers.",[43,428,430],{"id":429},"why-do-stablecoin-transfers-need-pre-settlement-checks","Why do stablecoin transfers need pre-settlement checks?",[11,432,433,434,438],{},"Because a confirmed on-chain transfer is final. There is no recall and no chargeback, as covered in ",[54,435,437],{"href":436},"\u002Fresources\u002Fmore\u002Fare-stablecoin-payments-reversible","are stablecoin payments reversible",", so a rule that fires after settlement can only produce a report.",[11,440,441],{},"That changes where the rules sit. In a wire program, monitoring can review yesterday's batch and still ask a bank to recall a payment. In a stablecoin program, the rule library has to run between the payment request and the transfer. That's why the holds in the table above exist at all: a hold is only possible if the check runs first.",[43,443,445],{"id":444},"what-happens-from-alert-to-decision","What happens from alert to decision?",[11,447,448],{},"Every transaction gets scored, and the score decides whether it passes, waits for a person, or stops. The flow below is the standard shape.",[450,451,452,458,464,470,476,482],"ol",{},[27,453,454,457],{},[20,455,456],{},"Score."," Run every rule, baseline comparison, and wallet check before settlement. Combine them into one score, with the rules that fired attached.",[27,459,460,463],{},[20,461,462],{},"Pass."," Below the review band, release the payment. Keep the score anyway.",[27,465,466,469],{},[20,467,468],{},"Hold."," Inside the review band, pause the payment. The customer sees a pending state.",[27,471,472,475],{},[20,473,474],{},"Block."," On a hard rule, such as a confirmed sanctions match or a prohibited country, stop it. No analyst is needed for the block to take effect.",[27,477,478,481],{},[20,479,480],{},"Review."," An analyst works the held and edge cases: checks the evidence, asks the customer for information, and decides to release, reject, or escalate.",[27,483,484,487],{},[20,485,486],{},"Log."," Store the score, the rules, the evidence, the analyst, the decision, and the timestamps, for every case.",[11,489,490],{},"Step 6 is the one teams skip, and it's the one an examiner asks for first. A decision you can't reconstruct is a decision you can't defend.",[43,492,494],{"id":493},"how-does-a-structuring-rule-work-on-a-real-pattern","How does a structuring rule work on a real pattern?",[11,496,497],{},"The rule raises the question; the analyst answers it. Here's how one pattern moves through the flow.",[11,499,500,503],{},[20,501,502],{},"Illustrative example: nine transfers of USD 9,800 in two days."," A small import business, onboarded three months ago, declared expected monthly volume of USD 40,000. Over two days it requests nine stablecoin payouts of USD 9,800 each to three bank accounts in Mexico. Its provider caps single payouts at USD 10,000 (an illustrative internal limit).",[24,505,506,509,512,515,518],{},[27,507,508],{},"Total: 9 × USD 9,800 = USD 88,200, more than twice the declared monthly volume, in 48 hours.",[27,510,511],{},"Rule 1 fires on the third transfer: three amounts at 98 percent of the internal limit within 48 hours.",[27,513,514],{},"Rule 2 fires: weekly volume is far above the customer's baseline.",[27,516,517],{},"Rule 6 fires: volume contradicts the declared profile.",[27,519,520],{},"The score lands in the review band. Transfer three and everything after it are held. Transfers one and two have already settled.",[11,522,523],{},"The analyst asks the customer for invoices and the relationship with the three recipients. Two outcomes are possible.",[11,525,526],{},"If the customer shows three supplier invoices for USD 29,400 each, split because of the payout cap, the analyst clears the alert, writes down why, and the team considers a limit increase. The pattern was the limit, not the customer.",[11,528,529,530,535],{},"If the customer can't explain the split, or the recipients don't match the invoices, the case escalates. Here the line FinCEN draws matters. Its ",[54,531,534],{"href":532,"rel":533},"https:\u002F\u002Fwww.fincen.gov\u002Fsystem\u002Ffiles\u002F2025-10\u002FSAR-FAQs-October-2025.pdf",[395],"October 2025 SAR FAQs"," say amounts at or near a threshold alone don't require a suspicious activity report (SAR). A SAR is required when the institution knows, suspects, or has reason to suspect the transactions were designed to evade reporting, or are otherwise suspicious. Splitting with no business reason, after a request for invoices, is that kind of reason.",[11,537,538,539,544],{},"For a money services business, ",[54,540,543],{"href":541,"rel":542},"https:\u002F\u002Fwww.law.cornell.edu\u002Fcfr\u002Ftext\u002F31\u002F1022.320",[395],"31 CFR 1022.320"," requires a SAR on suspicious transactions of at least USD 2,000, filed no later than 30 calendar days after initial detection, with the SAR and supporting documents kept for five years. The USD 88,200 here is well over the line.",[43,546,548],{"id":547},"what-do-fatf-and-fincen-require-from-a-monitoring-program","What do FATF and FinCEN require from a monitoring program?",[11,550,551,552,557],{},"They require that suspicious activity gets detected and reported; they don't prescribe a rule list. ",[54,553,556],{"href":554,"rel":555},"https:\u002F\u002Fwww.fatf-gafi.org\u002Fen\u002Fpublications\u002FFatfrecommendations\u002FFatf-recommendations.html",[395],"FATF Recommendation 20"," requires financial institutions to report promptly to their financial intelligence unit when they suspect funds are the proceeds of crime or linked to terrorist financing. Countries implement that through their own laws.",[11,559,560],{},"In the US, the Bank Secrecy Act and FinCEN's rules carry it out. FinCEN's SAR FAQs say monitoring parameters should be commensurate with the institution's money laundering and terrorist financing risk, given its products, locations, and customers. That sentence is the reason a rule library has to be your own. A cross-border stablecoin business with Latin American payout corridors has different risk than a domestic payroll app, and its rules should show it.",[43,562,564],{"id":563},"what-are-the-common-mistakes-when-building-a-rule-library","What are the common mistakes when building a rule library?",[11,566,567],{},"Most weak programs fail in the same five or six places.",[24,569,570,576,582,588,594,600],{},[27,571,572,575],{},[20,573,574],{},"Copying vendor default rules."," Defaults are a starting point. Shipping them unchanged means the rules reflect someone else's customers, and you can't explain why a threshold is what it is.",[27,577,578,581],{},[20,579,580],{},"One threshold for all customers."," A USD 50,000 weekly trigger is noise for a marketplace and blind for a freelancer. Segment first.",[27,583,584,587],{},[20,585,586],{},"No peer groups."," Without them, new customers have no baseline, and the system can't tell unusual from normal for the first 90 days.",[27,589,590,593],{},[20,591,592],{},"No documented rationale per rule."," Every rule needs a sentence on what risk it covers, why the threshold sits where it does, and when it was last reviewed.",[27,595,596,599],{},[20,597,598],{},"No scenario testing."," Build test cases, like the nine-transfer pattern above, and prove each rule fires on them before and after every change.",[27,601,602,605],{},[20,603,604],{},"Rules that run after settlement."," For stablecoin flows, a post-settlement rule is a report generator, not a control.",[43,607,609],{"id":608},"how-does-blindpay-run-these-checks-inside-the-payment-flow","How does BlindPay run these checks inside the payment flow?",[11,611,612],{},"BlindPay runs KYC, KYB, sanctions screening, travel rule compliance, and transaction monitoring inside the API flow, before money moves. Customers are verified first: KYC Standard is automated and takes about 60 seconds for standard-risk individuals, while KYC Enhanced and KYB are reviewed manually in 3 hours to 1 business day.",[11,614,615,616,620,621,625,626,630,631,63],{},"On each payin or payout, monitoring can move a transaction to ",[617,618,619],"code",{},"on_hold",". The ",[54,622,624],{"href":623},"\u002Fdocs\u002Fkb\u002Fcut-off-times","documented triggers"," include first-time withdrawals or unusual activity, amounts large relative to the customer's history, and sanctions or watchlist matches. Compliance reviews each held transaction for false positives and may send a request for information about the sender relationship, the purpose, and the expected outcome. An unanswered transaction request can lead to a refund to the sender after 24 hours, and a hold can take up to 30 days to resolve. The process is in ",[54,627,629],{"href":628},"\u002Fdocs\u002Fkb\u002Fon-hold-transactions","on-hold transactions",", and each status is explained in ",[54,632,634],{"href":633},"\u002Fresources\u002Fmore\u002Fstablecoin-payout-statuses-explained","stablecoin payout statuses explained",[43,636,638],{"id":637},"what-to-do-next","What to do next",[11,640,641,642,646],{},"Take the 12-row table and mark each row: covered, partly covered, or missing. For every covered row, write down the threshold, why it's set there, and the test case that proves it fires. Start with rows 1, 8, and 12. They're the ones where a gap turns into a reportable failure fastest. If you're still choosing tools, ",[54,643,645],{"href":644},"\u002Fresources\u002Fmore\u002Fhow-to-choose-automated-risk-monitoring-vendor","how to choose an automated risk monitoring vendor"," covers what to ask.",[43,648,650],{"id":649},"sources-and-further-reading","Sources and further reading",[24,652,653,660,666,673,679,685],{},[27,654,655,659],{},[54,656,658],{"href":554,"rel":657},[395],"FATF Recommendations",", including Recommendation 20 on suspicious transaction reporting.",[27,661,662,665],{},[54,663,543],{"href":541,"rel":664},[395],", suspicious activity reports by money services businesses.",[27,667,668,672],{},[54,669,671],{"href":532,"rel":670},[395],"FinCEN SAR FAQs, October 2025",", on structuring and continuing activity.",[27,674,675,678],{},[54,676,407],{"href":405,"rel":677},[395],", structuring transactions to evade reporting requirements.",[27,680,681,684],{},[54,682,396],{"href":393,"rel":683},[395],", currency transaction reports.",[27,686,687,691],{},[54,688,690],{"href":417,"rel":689},[395],"OFAC FAQ 562",", digital currency addresses on the SDN List.",[11,693,694],{},[695,696,697],"em",{},"This article is general information, not legal advice.",{"title":699,"searchDepth":700,"depth":700,"links":701},"",2,[702,703,704,705,706,707,708,709,710,711,712],{"id":45,"depth":700,"text":46},{"id":66,"depth":700,"text":67},{"id":156,"depth":700,"text":157},{"id":429,"depth":700,"text":430},{"id":444,"depth":700,"text":445},{"id":493,"depth":700,"text":494},{"id":547,"depth":700,"text":548},{"id":563,"depth":700,"text":564},{"id":608,"depth":700,"text":609},{"id":637,"depth":700,"text":638},{"id":649,"depth":700,"text":650},"compliance","2026-09-30","The 12 red flags automated transaction monitoring should catch in stablecoin and cross-border payments, with rule logic, actions, and the data each needs.","md",[718,721,724,727,730,733],{"q":719,"a":720},"What is a red flag in transaction monitoring?","A red flag is a pattern that suggests a payment may be linked to money laundering, sanctions evasion, or fraud, such as transfers split just under a threshold or funds that leave minutes after they arrive. A red flag is not proof. In an automated system, each red flag becomes a rule that raises an alert, and an analyst decides what it means.",{"q":722,"a":723},"How is structuring detected in stablecoin payments?","With a rule that counts transfers just under a threshold within a time window, per customer and across linked customers. The classic US threshold is the USD 10,000 currency transaction report, which applies to cash. In stablecoin and wire flows, the same splitting shows up under the USD 3,000 US travel rule threshold and under a provider's own per-transfer limits.",{"q":725,"a":726},"Does a transaction near USD 10,000 require a suspicious activity report?","Not on its own. FinCEN's October 2025 SAR FAQs say that transactions at or near the USD 10,000 threshold are not enough by themselves to require a SAR. A filing is required when the institution knows, suspects, or has reason to suspect the transactions were designed to evade reporting. The rule raises the alert, and the analyst makes that call.",{"q":728,"a":729},"How many rules should a transaction monitoring system start with?","Enough to cover every risk in your own risk assessment, and no more than your team can explain. There is no regulatory rule count. The 12 red flags in this guide are a reasonable starting library for stablecoin and cross-border flows. Each rule needs a written reason, a threshold set from your data, and a test case that proves it fires.",{"q":731,"a":732},"What is the difference between holding and blocking a transaction?","A hold pauses a transaction until an analyst reviews it, and most held payments are released once the evidence checks out. A block stops a transaction outright because it hit a hard rule, such as a confirmed sanctions match or a prohibited country. Holds are for doubt. Blocks are for cases where the answer is already known.",{"q":734,"a":735},"Should transaction monitoring thresholds be the same for every customer?","No. A single threshold floods analysts with alerts on large, legitimate customers and misses unusual activity from small ones. Segment customers by type, risk rating, and expected volume, then compare each customer with its own history and with a peer group of similar customers. Fixed thresholds still make sense for hard rules like sanctions hits.",{"name":737,"steps":738},"How an automated transaction monitoring alert becomes a decision",[739,742,745,747,750,752],{"name":740,"text":741},"Score","Run every rule, baseline comparison, and wallet check against the transaction before it settles, and combine the results into one risk score with the rules that fired attached.",{"name":743,"text":744},"Pass","Release transactions that score below the review band. Keep the score and the rule results, even for clean payments, so the decision can be reconstructed later.",{"name":329,"text":746},"Pause transactions that score into the review band. Funds stay where they are and the customer sees a pending state, not an error.",{"name":748,"text":749},"Block","Stop transactions that hit a hard rule, such as a confirmed sanctions match or a prohibited country. A block needs no analyst to take effect.",{"name":197,"text":751},"Send held transactions and blocked edge cases to an analyst, who gathers evidence, asks the customer for information if needed, and decides to release, reject, or escalate to a suspicious activity report.",{"name":753,"text":754},"Log","Record the score, the rules that fired, the evidence, the analyst, the decision, and the timestamps for every case, so an examiner can follow it from alert to closure.",false,{"author":757},"BlindPay Team",true,"\u002Fresources\u002Fmore\u002Ftransaction-monitoring-red-flags-stablecoin-payments","---\ntitle: \"Transaction monitoring red flags for stablecoin payments: 12 rules to automate\"\nseoTitle: \"12 transaction monitoring red flags for stablecoin payments\"\ndescription: \"The 12 red flags automated transaction monitoring should catch in stablecoin and cross-border payments, with rule logic, actions, and the data each needs.\"\ndate: \"2026-09-30\"\nupdated: \"2026-09-30\"\ncategory: \"compliance\"\nauthor: \"BlindPay Team\"\nhowto:\n  name: \"How an automated transaction monitoring alert becomes a decision\"\n  steps:\n    - name: \"Score\"\n      text: \"Run every rule, baseline comparison, and wallet check against the transaction before it settles, and combine the results into one risk score with the rules that fired attached.\"\n    - name: \"Pass\"\n      text: \"Release transactions that score below the review band. Keep the score and the rule results, even for clean payments, so the decision can be reconstructed later.\"\n    - name: \"Hold\"\n      text: \"Pause transactions that score into the review band. Funds stay where they are and the customer sees a pending state, not an error.\"\n    - name: \"Block\"\n      text: \"Stop transactions that hit a hard rule, such as a confirmed sanctions match or a prohibited country. A block needs no analyst to take effect.\"\n    - name: \"Review\"\n      text: \"Send held transactions and blocked edge cases to an analyst, who gathers evidence, asks the customer for information if needed, and decides to release, reject, or escalate to a suspicious activity report.\"\n    - name: \"Log\"\n      text: \"Record the score, the rules that fired, the evidence, the analyst, the decision, and the timestamps for every case, so an examiner can follow it from alert to closure.\"\nfaq:\n  - q: \"What is a red flag in transaction monitoring?\"\n    a: \"A red flag is a pattern that suggests a payment may be linked to money laundering, sanctions evasion, or fraud, such as transfers split just under a threshold or funds that leave minutes after they arrive. A red flag is not proof. In an automated system, each red flag becomes a rule that raises an alert, and an analyst decides what it means.\"\n  - q: \"How is structuring detected in stablecoin payments?\"\n    a: \"With a rule that counts transfers just under a threshold within a time window, per customer and across linked customers. The classic US threshold is the USD 10,000 currency transaction report, which applies to cash. In stablecoin and wire flows, the same splitting shows up under the USD 3,000 US travel rule threshold and under a provider's own per-transfer limits.\"\n  - q: \"Does a transaction near USD 10,000 require a suspicious activity report?\"\n    a: \"Not on its own. FinCEN's October 2025 SAR FAQs say that transactions at or near the USD 10,000 threshold are not enough by themselves to require a SAR. A filing is required when the institution knows, suspects, or has reason to suspect the transactions were designed to evade reporting. The rule raises the alert, and the analyst makes that call.\"\n  - q: \"How many rules should a transaction monitoring system start with?\"\n    a: \"Enough to cover every risk in your own risk assessment, and no more than your team can explain. There is no regulatory rule count. The 12 red flags in this guide are a reasonable starting library for stablecoin and cross-border flows. Each rule needs a written reason, a threshold set from your data, and a test case that proves it fires.\"\n  - q: \"What is the difference between holding and blocking a transaction?\"\n    a: \"A hold pauses a transaction until an analyst reviews it, and most held payments are released once the evidence checks out. A block stops a transaction outright because it hit a hard rule, such as a confirmed sanctions match or a prohibited country. Holds are for doubt. Blocks are for cases where the answer is already known.\"\n  - q: \"Should transaction monitoring thresholds be the same for every customer?\"\n    a: \"No. A single threshold floods analysts with alerts on large, legitimate customers and misses unusual activity from small ones. Segment customers by type, risk rating, and expected volume, then compare each customer with its own history and with a peer group of similar customers. Fixed thresholds still make sense for hard rules like sanctions hits.\"\n---\n\nAn automated transaction monitoring system should flag structuring, velocity spikes, rapid in-and-out movement, round amounts, high-risk corridors, activity that contradicts the customer's declared business, fan-in patterns, risky wallet addresses, dormant accounts waking up, changed customer data, bridge or mixer hops, and near-threshold payments across linked accounts. Each rule pairs a condition with an action: pass, hold, block, or review.\n\nThis article is general information, not legal advice. Thresholds below are illustrative, not recommendations.\n\n**Key takeaways**\n\n- A red flag only works in automation when it's written as a rule: a condition, a threshold, an action, and the data it needs.\n- Fixed rules, behavioral baselines, and risk scoring do different jobs. A working system uses all three.\n- Stablecoin transfers are final once confirmed, so the rules have to run before settlement, not on yesterday's file.\n- Structuring rules raise alerts, not reports. FinCEN says amounts near a threshold alone don't require a suspicious activity report.\n- Every rule needs a documented reason and a test case. Copied vendor defaults fail both.\n\n## What is automated transaction monitoring?\n\nAutomated transaction monitoring is software that checks every payment against a set of rules and models, and flags the ones that look like money laundering, sanctions evasion, or fraud. It replaces a person reading every transaction with a person reviewing only the flagged ones.\n\nIt's one of four parts of a [risk monitoring program](\u002Fresources\u002Fmore\u002Fwhat-is-automated-risk-monitoring-fintech), next to KYC and KYB, sanctions screening, and alert handling. This guide is about the rule library itself: what to flag, how each rule works, and what happens next. The signals behind a stablecoin risk score, and why real-time beats batch, are covered in [real-time transaction monitoring for stablecoin payments](\u002Fresources\u002Fmore\u002Freal-time-transaction-monitoring-stablecoin-payments).\n\n## How do rules, behavioral baselines, and risk scoring differ?\n\nRules check a fixed condition, baselines compare a customer with its own past and its peers, and risk scoring combines both into one number that drives the action. Most red flags below use more than one.\n\n| Method | How it works | Good at | Weak at | Illustrative example |\n| --- | --- | --- | --- | --- |\n| Rule-based alerts | A fixed condition fires when met | Hard limits, sanctions hits, known typologies | Too many alerts on large customers, easy to game once known | Any transfer to a wallet on the SDN List |\n| Behavioral baselines (peer groups) | Compares activity with the customer's history and with similar customers | Catching change: spikes, new corridors, dormancy | Needs history; new customers have no baseline | 7-day volume at 3 times the customer's 90-day average |\n| Risk scoring | Weights rule hits, baselines, and customer risk into one score | Ranking alerts, routing to pass, hold, or review | Hard to explain if weights aren't documented | Score above 70 holds the payment for review |\n\nA peer group is a set of customers with similar type, size, and declared activity. A new marketplace seller gets compared with other new marketplace sellers until it has a history of its own.\n\n## What are the 12 red flags an automated system should flag?\n\nThese 12 cover the patterns that show up most often in stablecoin and cross-border payment flows. The thresholds are illustrative. Set yours from your own data and your risk assessment.\n\n| # | Red flag | Rule logic (illustrative thresholds) | Typical action | Data needed |\n| --- | --- | --- | --- | --- |\n| 1 | Structuring below a reporting threshold | 3 or more transfers between 90 and 99.9 percent of a threshold (USD 10,000 cash, USD 3,000 US travel rule, or an internal limit) within 48 hours | Review | Amounts, timestamps, customer ID |\n| 2 | Velocity spike against baseline | 7-day volume above 3 times the customer's 90-day weekly average | Review | Transaction history, customer baseline |\n| 3 | Rapid in-and-out movement | 80 percent or more of an incoming amount sent onward to a different party within 24 hours | Review | Payin and payout records, timestamps |\n| 4 | Round amount patterns | 5 or more transfers in exact multiples of USD 1,000 in 30 days with no matching invoices | Review (low weight in score) | Amounts, declared activity |\n| 5 | High-risk corridor | Origin or destination country on the internal high-risk list; prohibited countries stopped outright | Review or block | Customer country, bank country, IP and geolocation |\n| 6 | Declared activity mismatch | Monthly volume above 2 times declared expected volume, or payments to industries outside the profile | Review | KYB profile, expected volume, counterparties |\n| 7 | Many senders to one receiver | 10 or more distinct senders paying one beneficiary in 7 days | Review | Sender and beneficiary identifiers |\n| 8 | Wallet linked to sanctions or illicit clusters | Address on the SDN List, or analytics exposure to sanctioned, mixer, or stolen-funds clusters above risk appetite | Block (direct hit) or hold | Wallet address, list data, analytics score |\n| 9 | Activity after a dormant period | No activity for 180 days, then a transfer above the customer's historical maximum | Hold | Account history |\n| 10 | Sudden change in verified data | New bank account, wallet, email, or phone within 72 hours before a large payout | Hold | Profile change log, timestamps |\n| 11 | Bridge or mixer hops before deposit | Funds reach the deposit address through a mixer, or through 2 or more bridge hops within 24 hours | Hold or block | On-chain trace, analytics data |\n| 12 | Near-threshold payments across linked accounts | Customers sharing an owner, address, device, or bank account each send just under a threshold on the same day | Review | Entity links: shared identifiers |\n\nA few notes on the rows that trip teams up.\n\n**Row 1 needs care with the threshold.** The currency transaction report (CTR) under [31 CFR 1010.311](https:\u002F\u002Fwww.law.cornell.edu\u002Fcfr\u002Ftext\u002F31\u002F1010.311) covers transactions in currency of more than USD 10,000, which means cash. A stablecoin payout isn't cash. The same splitting behavior still matters, though: under the USD 3,000 US [travel rule threshold](\u002Fresources\u002Fmore\u002Ftravel-rule-stablecoin-off-ramps), under a provider's per-transfer limit, or on the cash side of an on-ramp. Structuring to evade a reporting requirement is a crime under [31 USC 5324](https:\u002F\u002Fwww.law.cornell.edu\u002Fuscode\u002Ftext\u002F31\u002F5324), whether or not the money is dirty.\n\n**Row 8 is the one rule with no judgment call on a direct hit.** OFAC [adds some wallet addresses to SDN List entries](https:\u002F\u002Fofac.treasury.gov\u002Ffaqs\u002F562) and says those listings are not likely to be exhaustive. So a clean list check isn't the end of it. Analytics exposure covers what the list misses.\n\n**Row 12 depends on entity resolution.** Entity resolution means linking customers that share identifiers. Without it, a structuring ring split across five accounts looks like five clean customers.\n\n## Why do stablecoin transfers need pre-settlement checks?\n\nBecause a confirmed on-chain transfer is final. There is no recall and no chargeback, as covered in [are stablecoin payments reversible](\u002Fresources\u002Fmore\u002Fare-stablecoin-payments-reversible), so a rule that fires after settlement can only produce a report.\n\nThat changes where the rules sit. In a wire program, monitoring can review yesterday's batch and still ask a bank to recall a payment. In a stablecoin program, the rule library has to run between the payment request and the transfer. That's why the holds in the table above exist at all: a hold is only possible if the check runs first.\n\n## What happens from alert to decision?\n\nEvery transaction gets scored, and the score decides whether it passes, waits for a person, or stops. The flow below is the standard shape.\n\n1. **Score.** Run every rule, baseline comparison, and wallet check before settlement. Combine them into one score, with the rules that fired attached.\n2. **Pass.** Below the review band, release the payment. Keep the score anyway.\n3. **Hold.** Inside the review band, pause the payment. The customer sees a pending state.\n4. **Block.** On a hard rule, such as a confirmed sanctions match or a prohibited country, stop it. No analyst is needed for the block to take effect.\n5. **Review.** An analyst works the held and edge cases: checks the evidence, asks the customer for information, and decides to release, reject, or escalate.\n6. **Log.** Store the score, the rules, the evidence, the analyst, the decision, and the timestamps, for every case.\n\nStep 6 is the one teams skip, and it's the one an examiner asks for first. A decision you can't reconstruct is a decision you can't defend.\n\n## How does a structuring rule work on a real pattern?\n\nThe rule raises the question; the analyst answers it. Here's how one pattern moves through the flow.\n\n**Illustrative example: nine transfers of USD 9,800 in two days.** A small import business, onboarded three months ago, declared expected monthly volume of USD 40,000. Over two days it requests nine stablecoin payouts of USD 9,800 each to three bank accounts in Mexico. Its provider caps single payouts at USD 10,000 (an illustrative internal limit).\n\n- Total: 9 × USD 9,800 = USD 88,200, more than twice the declared monthly volume, in 48 hours.\n- Rule 1 fires on the third transfer: three amounts at 98 percent of the internal limit within 48 hours.\n- Rule 2 fires: weekly volume is far above the customer's baseline.\n- Rule 6 fires: volume contradicts the declared profile.\n- The score lands in the review band. Transfer three and everything after it are held. Transfers one and two have already settled.\n\nThe analyst asks the customer for invoices and the relationship with the three recipients. Two outcomes are possible.\n\nIf the customer shows three supplier invoices for USD 29,400 each, split because of the payout cap, the analyst clears the alert, writes down why, and the team considers a limit increase. The pattern was the limit, not the customer.\n\nIf the customer can't explain the split, or the recipients don't match the invoices, the case escalates. Here the line FinCEN draws matters. Its [October 2025 SAR FAQs](https:\u002F\u002Fwww.fincen.gov\u002Fsystem\u002Ffiles\u002F2025-10\u002FSAR-FAQs-October-2025.pdf) say amounts at or near a threshold alone don't require a suspicious activity report (SAR). A SAR is required when the institution knows, suspects, or has reason to suspect the transactions were designed to evade reporting, or are otherwise suspicious. Splitting with no business reason, after a request for invoices, is that kind of reason.\n\nFor a money services business, [31 CFR 1022.320](https:\u002F\u002Fwww.law.cornell.edu\u002Fcfr\u002Ftext\u002F31\u002F1022.320) requires a SAR on suspicious transactions of at least USD 2,000, filed no later than 30 calendar days after initial detection, with the SAR and supporting documents kept for five years. The USD 88,200 here is well over the line.\n\n## What do FATF and FinCEN require from a monitoring program?\n\nThey require that suspicious activity gets detected and reported; they don't prescribe a rule list. [FATF Recommendation 20](https:\u002F\u002Fwww.fatf-gafi.org\u002Fen\u002Fpublications\u002FFatfrecommendations\u002FFatf-recommendations.html) requires financial institutions to report promptly to their financial intelligence unit when they suspect funds are the proceeds of crime or linked to terrorist financing. Countries implement that through their own laws.\n\nIn the US, the Bank Secrecy Act and FinCEN's rules carry it out. FinCEN's SAR FAQs say monitoring parameters should be commensurate with the institution's money laundering and terrorist financing risk, given its products, locations, and customers. That sentence is the reason a rule library has to be your own. A cross-border stablecoin business with Latin American payout corridors has different risk than a domestic payroll app, and its rules should show it.\n\n## What are the common mistakes when building a rule library?\n\nMost weak programs fail in the same five or six places.\n\n- **Copying vendor default rules.** Defaults are a starting point. Shipping them unchanged means the rules reflect someone else's customers, and you can't explain why a threshold is what it is.\n- **One threshold for all customers.** A USD 50,000 weekly trigger is noise for a marketplace and blind for a freelancer. Segment first.\n- **No peer groups.** Without them, new customers have no baseline, and the system can't tell unusual from normal for the first 90 days.\n- **No documented rationale per rule.** Every rule needs a sentence on what risk it covers, why the threshold sits where it does, and when it was last reviewed.\n- **No scenario testing.** Build test cases, like the nine-transfer pattern above, and prove each rule fires on them before and after every change.\n- **Rules that run after settlement.** For stablecoin flows, a post-settlement rule is a report generator, not a control.\n\n## How does BlindPay run these checks inside the payment flow?\n\nBlindPay runs KYC, KYB, sanctions screening, travel rule compliance, and transaction monitoring inside the API flow, before money moves. Customers are verified first: KYC Standard is automated and takes about 60 seconds for standard-risk individuals, while KYC Enhanced and KYB are reviewed manually in 3 hours to 1 business day.\n\nOn each payin or payout, monitoring can move a transaction to `on_hold`. The [documented triggers](\u002Fdocs\u002Fkb\u002Fcut-off-times) include first-time withdrawals or unusual activity, amounts large relative to the customer's history, and sanctions or watchlist matches. Compliance reviews each held transaction for false positives and may send a request for information about the sender relationship, the purpose, and the expected outcome. An unanswered transaction request can lead to a refund to the sender after 24 hours, and a hold can take up to 30 days to resolve. The process is in [on-hold transactions](\u002Fdocs\u002Fkb\u002Fon-hold-transactions), and each status is explained in [stablecoin payout statuses explained](\u002Fresources\u002Fmore\u002Fstablecoin-payout-statuses-explained).\n\n## What to do next\n\nTake the 12-row table and mark each row: covered, partly covered, or missing. For every covered row, write down the threshold, why it's set there, and the test case that proves it fires. Start with rows 1, 8, and 12. They're the ones where a gap turns into a reportable failure fastest. If you're still choosing tools, [how to choose an automated risk monitoring vendor](\u002Fresources\u002Fmore\u002Fhow-to-choose-automated-risk-monitoring-vendor) covers what to ask.\n\n## Sources and further reading\n\n- [FATF Recommendations](https:\u002F\u002Fwww.fatf-gafi.org\u002Fen\u002Fpublications\u002FFatfrecommendations\u002FFatf-recommendations.html), including Recommendation 20 on suspicious transaction reporting.\n- [31 CFR 1022.320](https:\u002F\u002Fwww.law.cornell.edu\u002Fcfr\u002Ftext\u002F31\u002F1022.320), suspicious activity reports by money services businesses.\n- [FinCEN SAR FAQs, October 2025](https:\u002F\u002Fwww.fincen.gov\u002Fsystem\u002Ffiles\u002F2025-10\u002FSAR-FAQs-October-2025.pdf), on structuring and continuing activity.\n- [31 USC 5324](https:\u002F\u002Fwww.law.cornell.edu\u002Fuscode\u002Ftext\u002F31\u002F5324), structuring transactions to evade reporting requirements.\n- [31 CFR 1010.311](https:\u002F\u002Fwww.law.cornell.edu\u002Fcfr\u002Ftext\u002F31\u002F1010.311), currency transaction reports.\n- [OFAC FAQ 562](https:\u002F\u002Fofac.treasury.gov\u002Ffaqs\u002F562), digital currency addresses on the SDN List.\n\n*This article is general information, not legal advice.*\n",{"title":5,"description":715},"12 transaction monitoring red flags for stablecoin payments","resources\u002Fmore\u002Ftransaction-monitoring-red-flags-stablecoin-payments","pUKFpX7LInFxkPKDCJaT-hl9uyEvB4yuw5CnCOptwnk",[766,770,774,777,781,785,789,793,797,801,805,808,812,816,820,824,827,831,835,839,843,847,848,852,856,860,864,867,870,874],{"path":767,"title":768,"description":769},"\u002Fresources\u002Fmore\u002Faml-audit-readiness-risk-monitoring","AML audit readiness: what regulators ask for and how to prove your risk monitoring works","The evidence examiners expect from automated risk monitoring: a 10-item evidence table, good vs poor practice, SAR timelines, RFIs, and a 30-day plan.",{"path":771,"title":772,"description":773},"\u002Fresources\u002Fmore\u002Fare-blockchain-payments-legal","Are blockchain payments legal? Rules in the US, EU, UK, Brazil, and Mexico","Blockchain payments are legal for businesses in the US, EU, UK, Brazil, and Mexico, under different rules. What each country regulates, as of October 2026.",{"path":436,"title":775,"description":776},"Are stablecoin payments reversible? Finality, custody, and fraud explained","Stablecoin transfers settle final in minutes and cannot be reversed. That finality proves custody at every step, but it also opens a fraud gap on the fiat side of the payment.",{"path":778,"title":779,"description":780},"\u002Fresources\u002Fmore\u002Fautomated-kyc-kyb-vs-manual-onboarding","Automated KYC\u002FKYB vs. manual onboarding: what actually changes","A side-by-side comparison of automated and manual KYC\u002FKYB for fintechs: onboarding time, false-positive rates, cost per verification, scaling across jurisdictions, and audit-trail quality, plus the cases where a human reviewer is still required.",{"path":782,"title":783,"description":784},"\u002Fresources\u002Fmore\u002Fbuild-vs-buy-automated-risk-monitoring","Build vs. buy automated risk monitoring: a decision framework and 15 provider questions","Build, buy point solutions, or use an integrated provider? Compare three ways to run automated risk monitoring, who stays responsible, and 15 questions.",{"path":786,"title":787,"description":788},"\u002Fresources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments","Compliance agents for cross-border stablecoin payments: a global regulatory guide","How compliance agents apply FinCEN, MiCA, FCA, MAS, and Banco Central do Brasil rules to cross-border stablecoin payments: jurisdiction table, the FATF Travel Rule, multi-list sanctions screening, the four components of a compliant program, and questions to ask a compliance provider.",{"path":790,"title":791,"description":792},"\u002Fresources\u002Fmore\u002Fcrypto-wallet-compliance-checklist","Crypto wallet compliance checklist: KYC, KYT, and Travel Rule","The compliance that comes with crypto wallets and stablecoin payments: KYC and KYB, KYT, the Travel Rule, address screening, MSB rules, and 15 checks.",{"path":794,"title":795,"description":796},"\u002Fresources\u002Fmore\u002Fdirect-vs-indirect-stablecoin-exchange","Direct vs indirect stablecoin exchange: who holds the stablecoin, and who carries compliance","In direct exchange, both parties hold stablecoins and own compliance. In indirect exchange, a provider settles in stablecoins behind a normal bank payment.",{"path":798,"title":799,"description":800},"\u002Fresources\u002Fmore\u002Fdo-merchants-need-a-license-to-accept-stablecoins","Do merchants need a license to accept stablecoin payments? KYC, KYB, and compliance explained","Usually no: the license sits with the provider that moves the funds. What merchants still owe on KYB, sanctions, tax, and records in the US, EU, Brazil.",{"path":802,"title":803,"description":804},"\u002Fresources\u002Fmore\u002Fhow-to-automate-kyc-kyb-stablecoin-payments","How to automate KYC and KYB for stablecoin payments","A developer guide to automated KYC and KYB for stablecoin payment flows: how verification runs inside a payment API, step-by-step workflows for individuals and businesses, jurisdiction requirements for the US, EU, UK, Singapore, and Brazil, and what to check before settlement.",{"path":644,"title":806,"description":807},"How to choose an automated risk monitoring vendor for a fintech startup","A buyer's guide to automated risk monitoring vendors for early-stage fintechs: the five criteria that matter (regulatory coverage, integration effort, false-positive rate, pricing model, audit output), the question to ask a vendor on each, a checklist table, and what it costs.",{"path":809,"title":810,"description":811},"\u002Fresources\u002Fmore\u002Freduce-false-positives-transaction-monitoring","How to reduce false positives in transaction monitoring without missing real risk","Cut AML alert noise without losing real cases: a 7-step tuning process, the levers that work, the metrics to watch, and what automation should never close.",{"path":813,"title":814,"description":815},"\u002Fresources\u002Fmore\u002Fmica-stablecoin-rules-explained","MiCA stablecoin rules explained for payment companies","What MiCA means if your business uses stablecoins in the EU: EMTs vs ARTs, issuer requirements, why USDC is compliant and USDT was delisted, and a practical checklist.",{"path":817,"title":818,"description":819},"\u002Fresources\u002Fmore\u002Fongoing-sanctions-screening-how-often-to-rescreen","Ongoing sanctions screening: how often to rescreen and what to screen","How often to rescreen customers against sanctions lists, what to screen beyond names, and a cadence that holds up under OFAC strict liability.",{"path":821,"title":822,"description":823},"\u002Fresources\u002Fmore\u002Fpsav-brazil-explained","PSAV in Brazil: the Central Bank's virtual asset license explained","PSAV is Brazil's authorization for virtual asset service providers, created by BCB Resolutions 519, 520, and 521 under Law 14.478\u002F2022. What it requires and who needs it.",{"path":61,"title":825,"description":826},"Real-time transaction monitoring for cross-border stablecoin payments","Why stablecoin cross-border flows need different monitoring than wires: the signals that get scored (wallet address risk, velocity, corridor risk, on\u002Foff-ramp counterparties), real-time vs. batch monitoring, and a worked example of a flagged pattern from alert to decision.",{"path":828,"title":829,"description":830},"\u002Fresources\u002Fmore\u002Fstablecoin-card-issuing-compliance","Stablecoin card issuing compliance: KYC, KYB, and regulatory coverage explained","What compliance stablecoin card issuing requires: KYC vs. KYB, who is responsible for what, how rules differ in the US, EU, UK, and Latin America, and ongoing monitoring.",{"path":832,"title":833,"description":834},"\u002Fresources\u002Fmore\u002Fstablecoin-off-ramp-limits","Stablecoin off-ramp limits: per-transaction, daily, and monthly caps explained","Why off-ramps cap how much you can convert per transaction, day, and month, how the caps map to KYC and KYB tiers, and the documents that raise them.",{"path":836,"title":837,"description":838},"\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026","Stablecoin regulation in 2026: MiCA, the GENIUS Act, Brazil, and Japan","Where stablecoin regulation stands in 2026: MiCA in the EU, the GENIUS Act in the US, Brazil's VASP regime, and Japan's issuer rules, compared for payment businesses.",{"path":840,"title":841,"description":842},"\u002Fresources\u002Fmore\u002Fgenius-act-for-businesses","The GENIUS Act explained for businesses that use stablecoins","What the GENIUS Act means if your business sends, receives, or holds stablecoins: who it regulates, the dates that matter, and what to do before 2027.",{"path":844,"title":845,"description":846},"\u002Fresources\u002Fmore\u002Ftravel-rule-workflow-hold-return-reject","The Travel Rule in an automated workflow: what to collect, when to hold, when to return","How to automate Travel Rule compliance for stablecoin transfers: what data to collect, the checks before release, and when to hold, reject, or return.",{"path":759,"title":5,"description":715},{"path":849,"title":850,"description":851},"\u002Fresources\u002Fmore\u002Fvirtual-account-requirements-kyc-kyb","Virtual account requirements: KYC, KYB, and what the bank reviews before it says yes","What you need to open a virtual account: KYC or KYB, the extra fields and source of funds documents the bank reviews, who owns each step, and timelines.",{"path":853,"title":854,"description":855},"\u002Fresources\u002Fmore\u002Fwhat-are-compliance-agents-in-fintech","What are compliance agents in fintech? How they work and what they do for payments","Compliance agents are autonomous software components that run KYC, KYB, sanctions screening, and transaction monitoring inside a payment flow, then document every decision. How they work, what they do for payments, how they differ from traditional compliance software, and how BlindPay embeds them in its API.",{"path":857,"title":858,"description":859},"\u002Fresources\u002Fmore\u002Fwhat-is-kyb","What is KYB? Know Your Business verification explained","KYB verifies a company's legal existence, ownership, and control before it can transact. What it checks, who counts as a beneficial owner, and how it differs from KYC.",{"path":861,"title":862,"description":863},"\u002Fresources\u002Fmore\u002Fwhat-is-a-vasp","What is a VASP? Virtual asset service provider explained","A VASP is any business that exchanges, transfers, or custodies virtual assets like stablecoins for customers. FATF's definition and what it requires in practice.",{"path":56,"title":865,"description":866},"What is automated risk monitoring in fintech?","A reference explainer on automated risk monitoring for fintechs: the four components (KYC\u002FKYB, transaction monitoring, sanctions and watchlist screening, compliance automation), what each one flags, a manual vs. automated comparison, and what FinCEN, FATF, and OFAC actually require.",{"path":400,"title":868,"description":869},"What is the travel rule for stablecoin off-ramps? Thresholds, data, and failed checks","The travel rule makes off-ramps pass sender and receiver data with transfers. Thresholds by country, required data, and what happens when checks fail.",{"path":871,"title":872,"description":873},"\u002Fresources\u002Fmore\u002Fcrypto-on-ramp-compliance-who-owns-what","Who owns compliance when you integrate a crypto on-ramp API? KYC, KYB, KYT, and holds","An on-ramp API splits compliance between the provider and you. Who runs KYC, KYB, KYT, sanctions, and the travel rule, and what stays on your side.",{"path":875,"title":876,"description":877},"\u002Fresources\u002Fmore\u002Fsource-of-funds-crypto-off-ramps","Why do crypto off-ramps ask for source of funds? Documents, triggers, and on-chain proof","Why off-ramps ask where your stablecoins came from, how source of funds differs from source of wealth, what triggers a request, and which documents pass.",1791301932007]