By NHI Mgmt Group Editorial TeamBased on SumSub: “Sumsub and GOE Alliance Sign MoU at WEF 2026 to Support Compliant Crypto Payments in Vietnam” (June 8, 2026)

TL;DR: Compliant crypto and stablecoin payments for tourism in Vietnam’s planned International Financial Center are the focus of a new use case aimed at cross-border spending and fraud prevention, after SumSub signed an MoU with the GOE Alliance at WEF 2026, according to SumSub. The real issue is not payment novelty but whether identity verification, fraud controls, and onboarding governance can scale without creating new trust gaps.


At a glance

What this is: This is an analysis of SumSub's MoU with the GOE Alliance on compliant crypto and stablecoin payments for tourism, with identity verification and fraud prevention positioned as core controls rather than back-office add-ons.

Why it matters: It matters because tourism payments are high-frequency, cross-border, and fraud-prone, so IAM, KYC, and fraud teams need governance that scales with real transaction flow, not just customer onboarding.


Context

Crypto payments in tourism create a governance problem as much as a payments problem: the more transactions move across borders and service types, the more the control plane depends on who can be verified, trusted, and monitored at onboarding and at payment time. In this case, the primary identity issue is whether compliant access decisions can keep up with real-world spending across accommodation, transport, dining, shopping, and related services.

The article frames the MoU as part of Vietnam's International Financial Center push, but the practical question for identity teams is simpler. If crypto and stablecoin payments are going to work in regulated tourism flows, identity verification, fraud prevention, and ongoing customer trust checks have to be designed for throughput, reuse, and cross-party coordination from the start.


Key questions

Q: How should security teams govern crypto payments in high-volume tourism flows?

A: Security teams should govern crypto payments as identity-led transactions, not just payment events. That means verified identity before settlement, risk-based rechecks for repeated activity, and preserved evidence for exceptions. The strongest programmes align fraud review, sanctions awareness, and lifecycle governance across merchants and partners so trust does not depend on a single onboarding decision.

Q: Why do tourism payments need stronger identity verification than ordinary retail flows?

A: Tourism payments are high-frequency, cross-border, and often irregular, which makes them easier to abuse with synthetic identities, account reuse, or fraud rings. Stronger verification matters because the same traveller-facing convenience can otherwise become a reusable trust path across many merchants and services.

Q: What are the main compliance risks when stablecoins are used for travel spending?

A: The main risks are weak identity binding, inconsistent screening across participants, and fragmented accountability when multiple entities touch the same payment flow. If each party applies different standards, compliance becomes uneven and fraud teams lose visibility across the full customer journey.

Q: When should organisations prioritise fraud controls over checkout convenience in crypto tourism use cases?

A: They should prioritise fraud controls whenever transaction volume, cross-border exposure, or repeated merchant use makes abuse harder to spot. The goal is not to slow every payment, but to make the risk engine strong enough that convenience does not become a blind spot.


Technical breakdown

Why compliant crypto payments depend on identity verification

Crypto and stablecoin payments do not remove the need for identity controls; they change where those controls sit. In tourism, high-volume cross-border spending increases exposure to account misuse, synthetic identities, and fraud rings, so verification must be tied to risk signals rather than treated as a one-time gate. Compliance becomes an ongoing trust decision across onboarding, payment authorisation, and post-transaction monitoring. That is especially true when a payment experience is meant to be seamless across multiple merchants and services. Practical implication: design identity checks that follow the transaction lifecycle, not just the customer registration step.

Practical implication: tie verification and fraud review to payment flow stages, not only to initial enrolment.

Stablecoin settlement and the identity control plane

Stablecoins can reduce conversion friction, but they do not simplify identity governance. The operational challenge is that a low-friction payment rail can increase the number of parties touching the same transaction, from tourist wallets to merchants, issuers, and platform intermediaries. That expands the control surface for KYC, sanctions screening, fraud analytics, and exception handling. If those controls are fragmented, organisations inherit speed without assurance. Practical implication: map each participant in the payment journey to the specific identity and compliance control it owns.

Practical implication: assign control ownership to each participant in the payment journey.

Cross-border tourism creates a high-noise fraud environment

Tourism payments are structurally noisy because legitimate spending patterns are irregular, geographically distributed, and often time-sensitive. That makes static rules weak on their own. A strong compliance model blends identity proofing, behavioural signals, transaction monitoring, and escalation logic so legitimate travellers are not blocked while suspicious patterns are still caught. The control problem is not whether crypto can be used in tourism, but whether governance can distinguish expected travel behaviour from abuse at scale. Practical implication: use layered fraud and identity signals that adapt to travel context and spend velocity.

Practical implication: use layered signals that adapt to travel context and spend velocity.


Threat narrative

Attacker objective: The objective is to move value through tourism payment rails while avoiding identity scrutiny, fraud detection, and compliance enforcement.

  1. Entry occurs when fraudsters use weak or synthetic identities to open payment relationships in a high-volume tourism flow.
  2. Credential or account abuse follows if onboarding controls fail to bind the payment relationship to a verifiable person or trusted entity.
  3. Escalation happens when the same identity can reuse payment access across multiple merchants, services, or channels without renewed risk checks.
  4. Impact is fraudulent or non-compliant cross-border spending that erodes trust in regulated crypto tourism use cases.
  • Poland ArcGIS password leak 2023: An ArcGIS login emailed in 2020 was published from stolen mail in 2023 and still worked, exposing Polish military and infrastructure maps.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Compliance for tourism crypto payments is an identity governance problem first. The article is not really about payment novelty; it is about whether trust decisions can scale across a high-frequency, cross-border merchant environment. When accommodation, transport, dining, and retail all sit inside one payment journey, identity verification and fraud prevention become operational controls, not policy statements. Practitioners should treat the payment flow as a governed access path, not a checkout convenience.

Cross-border tourism creates a reusable identity trust surface that fraud teams often underestimate. A traveller-friendly payment model can unintentionally become a reusable trust lane if onboarding, device, and behavioural controls are too loose. That is where identity verification and transaction monitoring must work together, because a one-time check rarely covers repeated use across multiple services. The practitioner conclusion is straightforward: trust must be re-evaluated at the point of use, not assumed from first acceptance.

Crypto and stablecoin rails do not reduce compliance scope, they redistribute it. The on-chain economy may change settlement mechanics, but it does not eliminate KYC, fraud, or accountability requirements. In regulated tourism, the hard part is coordinating controls across issuers, platform operators, merchants, and public-sector stakeholders. Identity leaders should reframe the program as shared control ownership across a payment ecosystem, not as a single onboarding project.

Shared standards are the only defensible way to scale regulated tourism payments. The article's partnership model reflects a broader market shift toward ecosystem governance rather than isolated checks. That matters because high-volume tourism use cases fail when identity, fraud, and compliance teams operate as disconnected control points. The practitioner takeaway is to align policy, monitoring, and escalation paths around the transaction lifecycle, not around organisational silos.

From our research library:

What this signals

Compliance architecture will matter more than payment novelty. As crypto and stablecoin use cases move into regulated tourism, practitioners should expect the bottleneck to shift from payment acceptance to governance consistency. Identity proofing, fraud monitoring, and dispute handling must be designed as one operating model, or the programme will fragment at the first sign of scale.

Tourism is a useful stress test for identity controls in on-chain payments. The sector combines cross-border friction, fast transactions, and variable merchant types, which exposes weak onboarding assumptions very quickly. Teams that can govern this flow well will have a transferable pattern for other real-world crypto use cases, especially where customer experience and regulatory assurance have to coexist.


For practitioners

  • Define identity checks for the payment lifecycle Map verification, sanctions screening, and fraud review to each stage of the tourism payment journey, including onboarding, payment authorisation, and exception handling.
  • Separate low-friction checkout from low-trust decisions Allow the payment experience to stay seamless for legitimate travellers while escalating only the transactions or identities that present higher risk.
  • Assign control ownership across ecosystem participants Document which party owns customer identity proofing, merchant acceptance, fraud detection, and dispute escalation in a regulated crypto tourism flow.
  • Tune fraud rules for travel behaviour Use spend velocity, geography, merchant type, and repeat-use patterns to distinguish normal tourism activity from account abuse.

Key takeaways

  • Crypto payments for tourism only scale when identity verification, fraud detection, and compliance controls are designed as one workflow.
  • The hardest problem is not settling value on-chain, but maintaining trust across high-volume, cross-border spending.
  • Identity and payments teams should govern tourism crypto flows by transaction stage, participant ownership, and risk-based escalation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationTourism crypto flows still depend on trustworthy identity binding at onboarding and payment time.
NHI-10 — Human Use of NHITourism payments often mix human travellers with payment infrastructure and delegated access paths.
Recommendation — Tighten authentication and proofing for travel payment accounts so weak identity binding does not enable misuse. Separate traveller identity from payment-service credentials and prevent human reuse of machine access.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on governing who is authorised to use payment flows and under what conditions.
Recommendation — Apply PR.AA-05 to align payment authorisation with verified identity and transaction risk.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementPayment onboarding and reuse depend on lifecycle control of authenticators and verification artefacts.
Recommendation — Use IA-5 to manage authenticator lifecycle across onboarding, reuse, and revocation.
MITRE ATT&CKTA0006; TA0009 — Credential Access; CollectionFraud and abuse in high-volume payment journeys often depend on credential abuse and transaction collection.
Recommendation — Map payment fraud scenarios to TA0006 and TA0009 to hunt for credential abuse and suspicious aggregation.

Key terms

  • Identity proofing: The process of verifying that a person is who they claim to be before granting or restoring access. In higher-risk recovery paths, proofing can include stronger evidence checks such as government ID validation or liveness-based facial verification so the assurance level matches the sensitivity of the request.
  • Fraud Controls: Fraud controls are the policies, checks, and detection mechanisms used to stop or limit fraudulent activity. In generative AI environments, they must account for synthetic identities, manipulated content, impersonation attempts, and automated abuse patterns that can bypass traditional verification or monitoring steps.
  • Cross-Border Payment Governance: Cross-border payment governance is the set of policies and operational controls that determine how international transactions are authorised, screened, monitored, and reviewed. It matters when different parties, jurisdictions, and currencies are involved, because accountability can fragment quickly without a shared control model.
  • Stablecoin Rail: A stablecoin rail is the payment infrastructure used to move value using tokenised assets rather than traditional card or bank settlement. In governance terms, it shifts control from intermediary-heavy processing to wallet, key, and policy management, which creates a stronger need for privileged access oversight.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org