Join our Newsletter — 33% off our NHI Course

What should payment processors do first to reduce money laundering risk before scaling into new markets?

Payment processors should start with jurisdiction-specific risk mapping, then build a due diligence framework that verifies merchant identities, business models, and transaction patterns. From there, they should add sanctions screening, transaction monitoring, employee training, and a named compliance owner. The practical goal is not box-ticking. It is to create controls that can withstand regulator scrutiny and catch suspicious activity early.

Why the First AML Step Is Jurisdiction Scoping, Not Control Expansion

Before a payment processor scales into a new market, the first task is to map the local AML and KYC obligations that will govern merchant onboarding, transaction monitoring, sanctions screening, reporting, and recordkeeping. That jurisdictional map should drive the rest of the control design, because a processor that builds the wrong due diligence workflow can end up with compliant-looking controls that do not satisfy the local regulator.

For processors, market entry risk is rarely about a single missing control. It is usually about applying a standardised program across countries that have different thresholds, reporting triggers, merchant definitions, and beneficial ownership expectations.

What the Due Diligence Framework Has to Prove

A usable due diligence framework does more than collect paperwork. It should verify who the merchant is, what activity the merchant actually performs, how funds will flow, and whether the expected transaction profile matches the business model. That matters because laundering risk often shows up as a mismatch between declared activity and real payment behaviour, especially when higher-risk verticals, cross-border activity, or third-party payment flows are involved.

This is where the processor should build a repeatable intake standard for onboarding and refresh reviews. The framework needs to separate ordinary low-risk merchants from cases that require enhanced due diligence, tighter limits, or manual approval before volume scales.

Processors also need evidence that due diligence is not just front-end onboarding theatre. The control should be able to support downstream monitoring, escalation, and case review with the same merchant data that was gathered at entry. For a sector benchmark on customer due diligence and beneficial ownership expectations, see FATF Recommendations, the AML and KYC framework.

Controls That Matter Once Volume Starts Rising

Once the merchant base begins to grow, the main failure mode is control drift. Sanctions screening, transaction monitoring, employee training, and a named compliance owner all need to scale with the business rather than lag behind it. If screening rules are too loose, if monitoring thresholds are never tuned, or if no one owns exceptions, the processor can expand exposure faster than it can detect suspicious activity.

That is why the first build should favour traceability over automation for its own sake. Screening and monitoring need documented decision rules, escalation paths, and evidence retention so the processor can explain why a merchant was approved, why an alert was closed, and why a higher-risk relationship was allowed to continue.

In payment environments, least privilege and account governance also become relevant once staff, contractors, and service accounts touch onboarding, case management, or settlement workflows. If operational teams can approve, suppress, and reconcile the same activity without review, the AML program loses both separation of duties and auditability. For payment-sector control expectations, PCI DSS v4.0 is useful as a companion reference for access control discipline and account management.

How to Scale Without Creating a Weak Compliance Model

The safest scaling pattern is to treat market entry as a control-design problem, not a sales milestone. Start with a country-specific risk map, then set onboarding tiers, escalation thresholds, and monitoring rules that match the actual product, channel, and merchant mix in that market. If the business model changes, the control model should change with it.

Practitioners should also plan for a governance check before launch, not after the first incidents. The most common mistake is assuming that a process that works in one corridor will generalise cleanly to another. In practice, market-by-market differences in sanctions exposure, cash intensity, third-party intermediaries, and regulator expectations mean the processor needs a localised operating model with a clear compliance owner.

Practitioner takeaway: The right first move is to design for the market you are entering, not the one you already know. If jurisdiction scoping and merchant due diligence are weak at launch, every later control, including screening and monitoring, will sit on an unstable foundation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022, SOC 2 (AICPA) and GDPR define the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-6 — Least Privilege Least privilege limits who can approve or override AML controls.
AU-6 — Audit Review, Analysis, and Reporting Audit review supports suspicious activity detection and regulator traceability.
IA-5 — Authenticator Management Credential governance matters for staff and system access to AML workflows.
Recommendation — Restrict AML approval, case review, and override access to the minimum needed. Review monitoring and screening logs for suspicious patterns and escalation gaps. Manage credentials tightly for systems that handle onboarding and monitoring decisions.
ISO/IEC 27001:2022 A.5.31 — Legal, statutory, regulatory and contractual requirements Jurisdiction scoping depends on local AML and reporting obligations.
A.5.15 — Access control Access control supports segregation of duties in AML operations.
Recommendation — Map each new market to its applicable AML and sanctions obligations before launch. Separate onboarding, monitoring, and approval privileges across staff roles.
CIS Controls v8 CIS-6 — Access Control Management Access control helps prevent unauthorized changes to AML decisions and cases.
Recommendation — Limit who can approve merchants, tune alerts, or override compliance decisions.
SOC 2 (AICPA) CC7.2 — Detects anomalous system behavior Monitoring merchants and transactions needs anomaly detection and escalation.
Recommendation — Use monitoring signals to detect unusual merchant and payment behavior early.
GDPR Art.5 — Principles relating to processing of personal data Merchant and screening data handling must remain lawful and purpose-limited.
Recommendation — Limit merchant data use to documented AML purposes and retain it appropriately.