New fintechs and payment startups need AML controls early — regulators expect it, and retro-fitting compliance is painful and expensive. But “early” doesn’t mean copying a tier-1 bank’s programme; it means building controls proportionate to your actual risk. Here is where to begin without over-engineering, from someone who has seen both sides.
Start risk-based
Assess the money-laundering risk of your products, customer types and geographies before you buy or build anything. Concretely: can your product move value fast or anonymously? Do you onboard remotely? Do you serve higher-risk industries or corridors? Write the assessment down, have leadership own it, and let it drive every control decision that follows. Your controls should be proportionate to that documented risk — not to a template.
KYC and customer due diligence
Verify identity at onboarding, apply enhanced due diligence to higher-risk customers, and capture beneficial ownership for business accounts. The design challenge is balance: friction kills conversion, but gaps create risk. Modern eKYC (document capture plus liveness) keeps onboarding smooth while meeting the requirement — provided you tune it and test it like any other control, and treat the identity data it produces as the foundation your monitoring and screening will later depend on.
Monitoring and screening
Add transaction monitoring and sanctions/PEP screening sized to your risk. Start with a handful of well-tuned scenarios rather than dozens that generate noise — and plan for evidence-based tuning from day one, because your first thresholds will be wrong in both directions. The same goes for screening: calibrate matching and use secondary identifiers early, or analyst time disappears into false hits.
Governance: the part startups skip
- Name an accountable owner (MLRO or equivalent) with real authority and access to the board.
- Write the policy you actually follow — a short, honest AML policy beats a 60-page template nobody has read.
- Train the team — especially engineering and support, who see the product’s abuse patterns first.
- Keep records — onboarding evidence, alerts, decisions and reports, retained per your regulator’s rules.
- Review independently — an annual health check catches drift while it’s still cheap to fix.
Tooling and RegTech
Decide buy vs build early. For most startups, buying screening and monitoring and building the integration is the right split — your engineers’ time belongs in your product. Plan integrations properly and validate them with real API testing: a screening service your checkout never actually calls is an expensive false comfort. The right RegTech, configured well, scales with you; the wrong one, configured badly, is a compliance incident on a subscription.
Mistakes that cost startups later
- Treating AML as a launch blocker to minimise rather than a control to design — regulators read that story in your file later.
- Buying tools before writing the risk assessment — you’ll configure them to the vendor’s defaults, not your risk.
- No plan for growth — thresholds and headcount that work at 10k customers collapse at 100k. Build the tuning habit early.
- Ignoring security — your KYC data is exactly what attackers want. Compliance and information security mature together or not at all.
These notes are educational — shared so founders know what “good” looks like before the first regulator meeting. If you’re weighing up outside help, here’s what to look for when hiring a consultant. And for the cybersecurity, GRC and data-protection side of your build — securing the stack that holds all this data — see my services or get in touch.