KYC, AML, and Risk: What to Build First (and What to Defer)
A staged plan for fintech compliance: ship the non-negotiable controls on day one, defer the heavy machinery until your data earns it, and document everything in between.
Ship the non-negotiable KYC and audit controls at launch, defer sophisticated AML until you have data to feed it, and document every decision because compliance is about proving what you did.
Know what the regulators actually require
Before you write a line of code, get clear on three things that people lump together and shouldn't. KYC is identity: confirm the person is who they say. That means collecting name, address, and date of birth, verifying a government ID, and matching the human to the document with a liveness check and selfie. AML is behavior: watch transactions for suspicious patterns, file SARs when something looks wrong, and run enhanced diligence on the customers who warrant it. Sanctions screening is a hard gate: check every customer and transaction against OFAC, UN, and EU lists at onboarding and on an ongoing basis, and block anything that hits.
Jurisdiction changes the answer more than founders expect. In the US it's FinCEN and the BSA. The UK runs through the FCA. The EU is AMLD6 with local regulators enforcing it. Singapore is MAS. The controls rhyme across all of them, but the thresholds, filing formats, and retention rules don't. Pick your launch markets early, because that decision quietly sets half your compliance scope.
One thing modern rules give you: you don't have to treat every customer the same. A risk-based approach means heavier scrutiny for PEPs, high-risk countries, and large transactions, and a lighter touch for small payments from established identities. The catch is that your risk methodology has to be written down and defensible. An examiner won't accept "it felt right." They'll ask to see the policy and the evidence you followed it.
Phase 1: the MVP controls you cannot skip
At launch you need a floor, and the floor is non-negotiable because going below it puts your license and your founders personally at risk. Verify identity with full legal name, date of birth, address, a government ID, and a selfie for liveness. Don't build the verification stack yourself. Wire in Onfido or Persona and ship in days instead of quarters. Their global coverage and document handling are years of work you don't need to redo.
Pair that with three more things and you have a real program. Hard transaction limits, because a dumb cap you can explain beats a clever model you can't. Transaction logging with enough metadata that you can reconstruct what happened months later. And immutable audit logging on every action that touches a compliance decision. That last one is the whole game. When a regulator shows up, the question is never "were you perfect." It's "can you prove what you did and why." If you can't replay the decision, it didn't happen.
Phase 2: what to add once you have volume
Sophisticated AML on day one is wasted effort. Pattern detection needs a baseline, and you don't have one until real transactions are flowing. So defer it on purpose. Once volume shows up, layer in enhanced due diligence for high-risk customers: source-of-funds documentation, ownership structure for business accounts, PEP screening, and adverse media checks. Trigger EDD off risk indicators rather than running it on everyone, or you'll drown your team and annoy good customers.
This is also when you graduate from hard limits to actual pattern monitoring and stand up a real SAR filing workflow. Detection without a process behind it is theater. When monitoring flags something, someone needs to investigate, decide, and file inside the regulatory clock, with every step recorded. Build the workflow before you need it, because the first SAR is a bad time to discover you don't have one.
Phase 3: enterprise, when scale forces it
At institutional scale, rules alone stop holding. You move to ML-based risk scoring, real-time sanctions screening on every transaction rather than batch sweeps, and proper case management: assignment and workload balancing, investigation workflows with audit trails, automated regulatory reporting, compliance dashboards, and direct integration into filing systems. This is expensive infrastructure. Build it when volume and your examiners demand it, not because it looks impressive on a roadmap.
Picking a KYC provider
The market is mature, so choose on fit, not features. Onfido has great UX and strong global coverage, which suits consumer fintech. Persona is the most customizable when your workflows get weird. Jumio is enterprise-grade and accurate, aimed at banks and high volume. Veriff is fast, around six seconds, when speed is the product. Alloy is an orchestration layer that lets you run several providers behind one integration. Whichever you pick, plan for rejection up front. Not everyone passes, and a graceful re-verification path keeps you from losing legitimate customers at the door.
Transaction monitoring: what to actually watch
Regulators expect you to catch a known set of patterns, so start there and don't overcomplicate it.
Velocity checks and peer-group analysis cover most of this cheaply. Comparing a customer against their cohort catches the deviations that fixed thresholds miss, and you can build the first version in-house before paying for a vendor.
Audit trails and retention
Log everything an investigation might ever touch: onboarding data and verification results, who approved each KYC decision and on what evidence, full transaction details with risk scores, account changes with old and new values, investigator notes and escalations, and who accessed which customer data and when. The standard is simple. If you might have to defend it, capture it. Retention is one of the few easy parts: the US (BSA), UK (FCA), EU (AMLD), and Singapore all land at five years, with the UK and EU counting from when the relationship ends.
Make your compliance team's life easier while you're at it, because the tooling pays for itself in faster investigations. A customer-360 view, case management with deadlines, search across any attribute, regulator-ready exports, and a dashboard with approval rates, alert counts, and case backlog will do more for your audit outcomes than another monitoring rule.
What we'd actually pick early on
Here's the stack we reach for at early stage, where the goal is coverage without overspending.
The throughline across all three phases is restraint. Build the floor on day one, defer the sophisticated machinery until your data makes it meaningful, and document every decision as you go. Compliance isn't about being clever. It's about proving you did the right thing, in order, with the evidence to back it.
We help teams design and ship production-grade software in eLearning, fintech, and AI. Let's talk about your project.
Book a call