INDUSTRY WORKFLOWS · GUIDEUPDATED 2026-08-20
    Industry Workflows

    Fintech and Payments Counterparty Screening

    Sanctions and AML screening for fintechs, payment institutions and EMIs: the obligations that drive it, merchant and agent onboarding, the travel rule, and how to keep false positives from swamping a live payment flow.

    For a licensed fintech, screening is not a discretionary risk control — it is a condition of the licence. Payment institutions and electronic money institutions authorised in the European Union are obliged entities under the EU anti-money laundering framework, which requires customer due diligence, beneficial ownership identification, PEP treatment and ongoing monitoring; the framework is being replaced by the 2024 AML package, comprising Regulation (EU) 2024/1624, Directive (EU) 2024/1640 and the Authority for Anti-Money Laundering and Countering the Financing of Terrorism established in Frankfurt under Regulation (EU) 2024/1620. Alongside it, Regulation (EU) 2023/1113 applies the travel rule to transfers of funds and crypto-assets, requiring payer and payee information to accompany a transfer and to be screened. Sanctions obligations run in parallel and are absolute rather than risk-based: an asset freeze applies to every transaction regardless of the customer's risk rating. The operational challenge in payments is therefore not whether to screen but how to screen at transaction tempo without an unmanageable false-positive queue. This page sets out the workflow.

    What this workflow covers

    SCOPE
    • Screen at onboarding and at transaction: customer due diligence covers the account, but sanctions obligations attach to each payment, counterparty and beneficiary.
    • Screen the whole merchant structure — legal entity, trading names, directors, beneficial owners and, for marketplaces, the underlying sellers or sub-merchants.
    • Treat agents and distributors as in-scope: payment institutions and EMIs operating through agent networks carry responsibility for who is in that network.
    • Apply PEP screening with an actual policy on close associates and family members, not just a list hit, and record the enhanced due diligence that follows a PEP match.
    • Meet travel-rule obligations under Regulation (EU) 2023/1113 by ensuring payer and payee data accompanies transfers and is screened, including for crypto-asset transfers.
    • Keep sanctions screening absolute and unconditional — an asset freeze has no de minimis threshold and no risk-based exemption, unlike much of the AML framework.
    • Tune matching for the real population: transliterated names, romanisation variants, aliases and common names drive most false positives in high-volume payment flows.
    • Route hits to a review queue with the match context attached — list, programme, identifiers matched and identifiers that differ — so an analyst can clear or escalate without leaving the case.
    • Re-screen the live customer and counterparty portfolio whenever lists change, not only at scheduled reviews, so a newly designated counterparty is caught before the next payment.
    • Retain the screening record, list version, reviewer and rationale per decision; supervisors test the audit trail as much as the outcome.

    Key statistics

    DATA
    EU AML rulebook
    Regulation (EU) 2024/1624 (AMLR)
    Official Journal of the European Union
    EU AML supervisor
    AMLA, Frankfurt — Regulation (EU) 2024/1620
    Official Journal of the European Union
    Travel rule instrument
    Regulation (EU) 2023/1113 — funds and crypto-asset transfers
    Official Journal of the European Union

    Compliance glossary

    TERMS
    Obliged entity
    A business required by anti-money laundering law to apply customer due diligence, monitor transactions and report suspicions. In the EU the category includes credit institutions, payment institutions, electronic money institutions, crypto-asset service providers and a range of non-financial professions.
    Travel rule
    The requirement that specified payer and payee information accompany a transfer of funds or crypto-assets through the payment chain so that providers can screen it. Implemented in the EU by Regulation (EU) 2023/1113.
    AMLA
    The EU Authority for Anti-Money Laundering and Countering the Financing of Terrorism, created by Regulation (EU) 2024/1620 and headquartered in Frankfurt, with powers of direct supervision over selected high-risk obliged entities and of coordination over national supervisors.
    Sub-merchant
    A seller operating under the payment facilitator's or marketplace's master merchant account rather than holding its own acquiring relationship. Sub-merchants are the effective risk surface in marketplace payments and require screening in their own right.

    Expert perspective

    NOTE

    Risk controls perform best when sanctions checks and ownership context are reviewed together.

    ScreenVeritAI Compliance Team · RegTech Research

    Frequently asked questions

    Q&A
    Q.01
    Why do fintechs and payment firms have to run sanctions screening?
    Because two separate obligations apply. Sanctions law prohibits dealing with designated persons and making funds available to them, and it binds every firm regardless of licence. Separately, payment institutions and electronic money institutions authorised in the EU are obliged entities under the anti-money laundering framework, which requires customer due diligence, beneficial ownership identification and ongoing monitoring as a licence condition.
    Q.02
    What is changing under the EU AML package?
    The 2024 package replaces the directive-based framework with a directly applicable rulebook: Regulation (EU) 2024/1624 harmonises customer due diligence and beneficial ownership rules across member states, Directive (EU) 2024/1640 covers supervision and financial intelligence units, and Regulation (EU) 2024/1620 creates the Authority for Anti-Money Laundering, headquartered in Frankfurt, with direct supervision of selected high-risk institutions.
    Q.03
    What is the travel rule for payments?
    The travel rule requires that specified information about the payer and payee accompany a transfer of funds through the payment chain, so that intermediaries and receiving providers can screen and, where necessary, act on it. In the European Union it is set out in Regulation (EU) 2023/1113, which extends the obligation to transfers of crypto-assets alongside conventional funds transfers.
    Q.04
    Should merchants be screened as well as customers?
    Yes, and usually more thoroughly. A merchant relationship exposes an acquirer or payment facilitator to everything flowing through that merchant, so the check should cover the legal entity, its trading names, its directors and its beneficial owners, plus adverse media. For marketplaces and payment facilitators, the underlying sellers are the real risk surface and should be screened in their own right.
    Q.05
    How do you screen in a payment flow without creating a false-positive backlog?
    Match on identifiers rather than name strings alone — date of birth, country, registration number and passport data where present — and tune for the alias, transliteration and romanisation variants your customer population actually produces. Then triage: automatic clearance for clear non-matches with strong discriminating data, analyst review for the rest, with the match context attached to the case.
    Q.06
    Does sanctions screening apply to low-value transactions?
    Yes. Asset-freeze obligations contain no de minimis threshold: making funds or economic resources available to a designated person is prohibited regardless of amount. Risk-based calibration is a feature of anti-money laundering rules, not of sanctions law, and applying an AML threshold to sanctions screening is a common and consequential design error.
    Q.07
    How often should a fintech re-screen its existing customer base?
    Whenever the underlying lists change, in practice on every list update rather than on a fixed calendar. Designations take effect on publication, so a portfolio screened last month contains unverified positions today. Event-driven re-screening on list refresh, combined with periodic full-portfolio passes, is the standard pattern.