Compliance Hub

Cross-Border Payment Compliance: Three Decisions Before the Money Moves

Site Logo
Tookitaki
14 Sep 2026
5 min
read

Domestic instant payments now reach their destination in seconds in more than 70 countries. The Bank for International Settlements says interlinking these systems could allow many cross-border payments to move from sender to recipient within 60 seconds.

Yet speed across the network does not always mean speed for the customer. Swift data shows that 90% of payments sent over its network reach the destination bank within an hour, while only 43% are credited to the end customer within that time. The World Bank also reported that sending a US$200 remittance cost 6.36% on average in the third quarter of 2025, compared with the United Nations Sustainable Development Goal of 3% by 2030. Digital remittances were cheaper, but still averaged 4.59%.

These figures describe a market moving toward faster and cheaper payments while the operational chain remains fragmented. For banks, fintechs and payment service providers, the central compliance question is no longer whether controls can review a transaction. It is whether they can reach a defensible decision before the money moves.

Talk to an Expert

Why cross border payments create a harder control problem

A domestic payment may already involve several systems. A cross-border payment can add correspondent banks, payment processors, currency conversion, local clearing arrangements and different legal regimes. Each participant sees only part of the transaction, and the information carried in the payment message may not tell the full story of the parties or purpose.

The compliance decision must often be made while several uncertainties remain:

  • Names, addresses and other party information may be incomplete, abbreviated or represented differently across languages and systems.
  • A payment may be normal for the customer but unusual for the corridor, counterparty or beneficiary network.
  • Sanctions obligations, reporting rules, data restrictions and institutional risk appetite can vary between jurisdictions.
  • Fraud and money-laundering indicators may sit in different systems even when they relate to the same customer or flow of funds.
  • A false positive can delay legitimate commerce, while a missed risk can expose several institutions in the payment chain.

Sequential checks and overnight monitoring were designed for a slower operating model. Instant and near-instant rails compress the time available to assemble the relevant information, assess the risk and choose an intervention.

The three decisions behind cross border payment control

A practical way to organise the control problem is through three connected decisions: Identity, Legitimacy and Permission. They are not separate stages that always occur one after another. In a real-time environment, the evidence supporting them may need to be assessed together.

Identity

Identity asks who is really behind the payment. The answer can extend beyond the originator and beneficiary names in the message. Depending on the product and risk, the institution may need to understand the customer, beneficial owner, merchant, counterparty, intermediary institutions and any other connected party.

Customer due diligence establishes the starting point, while transaction screening checks relevant parties and payment information against applicable sanctions lists, watchlists and other risk sources. Effective screening also has to manage spelling differences, aliases, transliteration, incomplete fields and cross-language names without generating unmanageable volumes of false alerts.

Identity is not settled permanently at onboarding. Ownership, PEP status, sanctions exposure and the parties connected to a customer can change. Institutions therefore need event-driven and ongoing processes that keep the customer and counterparty view current.

Legitimacy

Legitimacy asks whether the payment makes sense in context. A transaction can pass name screening and still be inconsistent with the customer's business, expected activity or previous behaviour. Conversely, an unfamiliar corridor or new beneficiary does not by itself prove financial crime.

A stronger assessment combines the individual payment with customer history, transaction velocity, corridor risk, counterparty relationships and known financial-crime patterns. Relevant questions can include:

  • Does the value and frequency fit the customer's profile and stated business purpose?
  • Is the payment part of rapid pass-through activity or a wider pattern of linked transactions?
  • Are several unrelated senders paying the same beneficiary or merchant?
  • Has the customer suddenly moved into new countries, currencies, products or counterparties?
  • Does the behaviour resemble an emerging typology involving mule accounts, trade-based laundering, sanctions evasion or fraud?

This is where real-time transaction monitoring becomes important. The control needs to evaluate the transaction early enough to influence the payment outcome, while retaining the data and reason codes needed to explain why it generated concern.

Permission

Permission asks whether the payment should proceed. The answer depends on the evidence from screening and monitoring, the applicable legal obligations, the institution's policies, corridor-specific requirements and its risk appetite.

A mature decision model is more precise than a universal approve-or-block rule. Depending on the legal and operational context, an institution may:

  • allow the payment and retain the decision evidence;
  • allow it with enhanced monitoring;
  • request additional information or verification;
  • hold it for review;
  • reject or block it where required; or
  • open a case for investigation and any necessary reporting.

Not every unusual payment should be stopped. Unnecessary holds can harm customers and disrupt legitimate trade. The objective is a consistent, explainable intervention that matches the identified risk and the institution's obligations.

Regulation is moving toward better payment information

The policy direction is clear. The G20 roadmap seeks faster, cheaper, more transparent and more accessible cross-border payments, while preserving their safety and integrity. That requires better data and clearer responsibility across the payment chain, not simply faster infrastructure.

In June 2025, the Financial Action Task Force revised Recommendation 16 on payment transparency. The changes clarify responsibilities for information in the payment chain, standardise specified originator and beneficiary information for certain peer-to-peer cross-border payments above USD or EUR 1,000, and require tools that protect against fraud and error, such as verification of recipient banking information. FATF states that the revised standards will take effect by the end of 2030; each jurisdiction will still need to implement them through its own framework.

For payment firms, the operational implication is broader than adding fields to a message. Information must remain sufficiently accurate and structured to support screening, monitoring, exception handling and investigation. Controls must also preserve who made the decision, what information was available and why the payment was allowed, held or rejected.

APAC payment links are shortening the decision window

Asia Pacific is already moving from bilateral links toward more scalable connectivity. The BIS-led Project Nexus produced a scheme and technology blueprint for connecting domestic instant-payment systems. In 2025, the central banks of India, Indonesia, Malaysia, the Philippines, Singapore and Thailand incorporated Nexus Global Payments to take the initiative toward live implementation.

These connections can expand access and reduce payment friction. They also mean that compliance controls must operate at the speed of the rail. A risk decision that arrives after settlement may still support investigation and reporting, but it cannot prevent the payment from moving onward.

cross_border_payment_compliance_under_200kb

How screening monitoring and investigations should connect

The three decisions require different capabilities, but they should share data and decision context.

Screen the parties and payment data

Screen originators, beneficiaries, intermediaries and relevant payment fields against the lists and risk sources applicable to the institution and corridor. Matching logic should account for language, name variation and incomplete data while maintaining explainable thresholds and review procedures.

Assess behaviour while intervention remains possible

Evaluate the payment against customer behaviour, peer patterns, velocity, counterparties, corridors and financial-crime scenarios in real time. Institutions should define which signals can stop or hold a payment automatically, which require step-up verification and which support post-event monitoring.

Manage exceptions through a governed workflow

Alerts that require human review should enter a connected case management process with the relevant customer, transaction, screening and monitoring evidence. Investigators need clear reason codes, escalation paths, service-level controls, decision history and an audit trail.

Case management does not itself decide whether every payment is permitted. It supports the exceptions that require investigation or escalation and preserves the evidence behind the outcome.

Questions payment firms should test

  • Can the institution identify all relevant parties and screen them within the payment window?
  • Can monitoring combine customer, transaction, counterparty and corridor context before settlement?
  • Are AML, fraud and sanctions signals available to the same decision process where legally and operationally appropriate?
  • Can different jurisdictional rules and risk tolerances be applied without building disconnected control stacks for every corridor?
  • Are approve, hold, reject and escalation outcomes governed by documented policy?
  • Can investigators reconstruct the data, rules, model version and human actions behind a decision?
  • How quickly can the institution test and deploy a new scenario when an emerging cross-border typology appears?

Frequently asked questions

What is cross border payment compliance

Cross-border payment compliance is the set of controls used to identify the parties to a payment, assess whether the activity is legitimate, apply relevant sanctions and AML requirements, and decide whether the transaction should proceed. The precise obligations depend on the jurisdictions, products, payment chain and role of the institution.

Why do cross border payments create more AML risk

They can involve several institutions, currencies and legal regimes, while each participant may see only part of the transaction. Differences in payment data, customer visibility, sanctions requirements and reporting rules can create gaps that criminals seek to exploit.

What is the difference between transaction screening and transaction monitoring

Transaction screening compares parties and payment information with sanctions lists, watchlists and other relevant risk sources. Transaction monitoring evaluates behaviour and patterns across transactions, customers, counterparties and time. Cross-border controls commonly require both.

Should every suspicious cross border payment be stopped

No. An unusual signal is not always proof of prohibited or criminal activity. The appropriate outcome may be approval, enhanced monitoring, additional verification, a temporary hold, rejection or escalation. Institutions should define these outcomes through applicable law and documented risk policy.

What changed in FATF Recommendation 16

FATF revised Recommendation 16 in June 2025 to improve payment transparency. The changes clarify responsibility for payment information, standardise specified information for certain peer-to-peer cross-border payments above USD or EUR 1,000, and introduce protections against fraud and error. FATF says the revised standards will take effect by the end of 2030, subject to implementation by jurisdictions.

Why is real time monitoring important for cross border payments

When a payment settles in seconds or minutes, post-event review cannot prevent the funds from moving onward. Real-time monitoring allows the institution to assess relevant behavioural and typology-based risk while intervention remains possible.

Talk to an Expert

Ready to Streamline Your Anti-Financial Crime Compliance?

Our Thought Leadership Guides

Blogs
14 Sep 2026
5 min
read

KYC Requirements in Singapore: MAS CDD Rules for Banks and Payment Companies

Understand Singapore KYC requirements under MAS Notice 626, PSN01 and PSN02, including CDD triggers, beneficial ownership, eKYC, EDD and record keeping.

KYC Requirements in Singapore: MAS CDD Rules for Banks and Payment Companies
Blogs
08 Sep 2026
5 min
read

AI Voices, Fake Romance, Real Money Trails: Taiwan’s NT$900 Million Scam

Explore AML lessons from Taiwan’s AI-enabled romance scam, where fake voices, pig-butchering tactics and asset conversion exposed money trail risks.

AI Voices, Fake Romance, Real Money Trails: Taiwan’s NT$900 Million Scam
Blogs
07 Sep 2026
6 min
read

Fraud Prevention in Malaysia: BNM Requirements for Banks

Malaysia recorded RM2.97 billion in online fraud losses in 2025. Learn what BNM's November 2025 RMiT, SEFT and National Fraud Portal mean for banks.

Fraud Prevention in Malaysia: BNM Requirements for Banks