By NHI Mgmt Group Editorial TeamBased on SumSub: “Sumsub Calls for Continuous Compliance as Indonesia's Payment Sector Shifts to Activity-Based Regulation” (June 8, 2026)

TL;DR: Indonesia's payment infrastructure is forecast to grow from US$110.69 billion in 2025 to US$294.85 billion by 2031, while Sumsub says the country is the second least protected against fraud out of 112 nations, making continuous, activity-based compliance a regulatory necessity. Point-in-time checks no longer match the scale or fraud dynamics of modern payment ecosystems.


At a glance

What this is: This whitepaper explains how Indonesia's payment rules are shifting from entity-based licensing to activity-based compliance, making ongoing verification and monitoring central to regulated payments.

Why it matters: IAM, fraud, and compliance teams need to adapt controls so identity verification, transaction monitoring, and AML screening remain aligned to each payment activity across the full customer lifecycle.


Context

Activity-based regulation means the compliance obligation follows the specific payment activity, not just the organisation's licence. In Indonesia, that shift changes how providers must prove control over onboarding, transaction monitoring, and AML screening across the customer lifecycle.

The governance problem is not simply stricter supervision. It is that point-in-time checks no longer map cleanly to payment ecosystems where one compromised identity can touch multiple services through integrated platforms and super-app distribution.

SumSub frames this as a structural change in Indonesia's payment market, where compliance is becoming continuous rather than episodic. That is typical of modern digital payment environments, but the regulatory model is now catching up with the operational reality.


Key questions

Q: What breaks when payment compliance is still organised around legacy entity licences?

A: Controls become misaligned with the regulated activity, so a provider may appear compliant at the corporate level while failing activity-specific requirements for e-money, gateway services, or fund transfers. That mismatch creates audit gaps, inconsistent monitoring, and weak evidence that current controls match current risk.

Q: Why do continuous verification and transaction monitoring belong in the same control loop?

A: Because onboarding decisions age quickly in payment ecosystems. If verification is separated from monitoring, the provider keeps approving customers against old risk assumptions while their behaviour, devices, or network relationships change. A single lifecycle loop keeps identity evidence, fraud signals, and AML screening aligned.

Q: How can payment teams tell whether activity-based compliance is actually working?

A: Look for evidence that controls re-evaluate risk as activity changes, not just at onboarding or periodic review. Effective programmes can show updated risk profiles, consistent audit trails, and escalation paths that trigger from behaviour, transaction patterns, and device signals rather than static thresholds alone.

Q: What should teams prioritise first when moving to activity-based regulation?

A: Start by mapping each regulated payment activity to its required controls and evidence trail. Once the activity boundary is clear, teams can align identity verification, monitoring, and AML screening to the right risk level instead of applying a one-size-fits-all compliance model.


Technical breakdown

How activity-based licensing changes compliance scope

Activity-based regulation ties obligations to the exact service being delivered, such as issuing e-money, operating a payment gateway, or facilitating fund transfers. That matters because the compliance boundary is no longer the corporate entity alone. Licensing, capital treatment, and control expectations shift with the activity, which means providers must map controls at the service level instead of assuming one enterprise control set covers every payment flow.

Practical implication: map each payment activity to its own control set, rather than treating the corporate licence as the control boundary.

Why continuous verification replaces point-in-time checks

Continuous compliance links identity verification, transaction monitoring, and AML screening into one lifecycle rather than three disconnected checkpoints. The technical difference is that signals from onboarding do not stop at account creation. They feed ongoing decisions as behaviour changes, allowing the provider to maintain an audit trail that reflects current risk rather than historical approval.

Practical implication: design monitoring so verification data is reusable across the customer lifecycle and not stranded at onboarding.

How behavioural intelligence supports mule detection and risk scoring

Rule thresholds alone struggle when fraud is distributed across networks, devices, and small-value transactions. Behavioural intelligence looks at device patterns, network relationships, and activity sequences to identify mule activity that appears low risk at a single point in time. In practice, this turns AML re-screening into an event-driven control rather than a periodic review exercise.

Practical implication: add behavioural and network-based signals to re-screening logic so mule patterns are detected as they emerge.


NHI Mgmt Group analysis

Activity-based compliance is really control scoping by behaviour, not by organisation. That shift matters because payment risk now follows what a service does, not merely who owns it. When one identity or workflow can span multiple services, the governance model has to bind controls to activity state and not just legal entity state. Practitioners should treat service-level control mapping as the new baseline for regulated payments.

Continuous verification is the only model that survives integrated payment ecosystems. Super-app distribution, shared identities, and cross-service journeys make static approval snapshots stale almost immediately. A control set that cannot re-evaluate risk as behaviour changes will miss the point of activity-based regulation. The implication is that verification, monitoring, and AML screening must function as a single operating loop.

Behavioral intelligence has become a governance requirement, not an analytics luxury. The article's fraud context shows that threshold-based checks are too coarse for mule networks, especially when the attack path relies on low-value, distributed activity. This is where identity signals and transaction signals need to converge into one risk model. Practitioners should align fraud detection with lifecycle governance, not keep them in separate silos.

Indonesia's regulatory shift signals a broader move from permissioned access to observable conduct. That direction matters beyond one market because it changes what auditors and regulators can reasonably expect from payment providers. If activity defines obligation, then evidence must be continuously generated at the same granularity. Identity teams should expect more markets to adopt this model as digital payment ecosystems mature.

What this signals

Activity-based regulation is forcing payment teams to redesign controls around observable conduct, not static entity labels. That shift will matter wherever licensing, onboarding, and AML evidence were previously managed as separate governance streams.

Continuous compliance loop: providers that can connect identity verification, transaction monitoring, and AML screening into one lifecycle will be better placed to satisfy regulators when risk changes mid-journey. The operational test is whether evidence updates as fast as customer behaviour does.


For practitioners

  • Map controls to payment activities, not only entities Build a control inventory that ties onboarding, monitoring, and AML requirements to each regulated activity such as e-money issuance, gateway operation, or fund transfer facilitation.
  • Unify identity and transaction monitoring Connect verification, device behaviour, and transaction monitoring so risk scoring updates as customer behaviour changes across the lifecycle.
  • Replace periodic review with event-driven re-screening Trigger AML and fraud checks when behavioural thresholds, network patterns, or transaction sequences change instead of waiting for a fixed review cycle.
  • Calibrate onboarding depth to activity risk Use lower-friction checks for low-risk activity while reserving deeper verification for higher-risk payment functions and customer journeys.

Key takeaways

  • Indonesia's move to activity-based regulation changes the control boundary from company licence to regulated payment activity.
  • The main governance challenge is keeping verification, monitoring, and AML evidence current as customer behaviour and transaction risk evolve.
  • Teams that align controls to activity and re-screen on events rather than schedules will be better positioned to meet the new model.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyActivity-based regulation forces risk decisions to follow payment activity, not just entity structure.
PR.AA-05 — Access Permissions, Entitlements and AuthorizationsPayment activity scope determines which identities and entitlements should be allowed at each stage.
Recommendation — Align your risk strategy to regulated payment activities and keep control evidence current across the lifecycle. Constrain access and authorizations to the specific payment activity being performed.
CIS Controls v8CIS-5 — Account ManagementContinuous compliance depends on controlling lifecycle changes to identities used in payment services.
Recommendation — Keep account inventories and lifecycle reviews aligned to payment activity changes.

Key terms

  • Activity-based regulation: A regulatory model that attaches compliance obligations to the specific service or transaction being performed rather than only to the legal entity. For payments, this means controls, evidence, and capital expectations follow the activity itself, which forces continuous operational governance instead of one-time certification.
  • Continuous Compliance: Continuous compliance is the practice of keeping controls and evidence current as the environment changes, rather than proving compliance after a review cycle. For identity and NHI programmes, it means access, logging, and revocation must operate together in real time.
  • Behavioral Intelligence: Behavioral intelligence is the use of session patterns to judge whether an action looks normal for a specific user. In banking, it compares cadence, navigation, pauses, and correction patterns against prior sessions to detect coercion, guidance, or automation that authentication alone cannot reveal.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org