The Cash App account was five weeks old. The user had run six transactions between $9,200 and $9,800, always to different recipients, always just below the reporting threshold. On the seventh, the transaction monitoring engine flagged the pattern. Compliance opened a case. Within seventy-two hours the account was frozen and a Suspicious Activity Report was on its way to FinCEN.

This is what modern anti-money-laundering compliance looks like at the operational level. It is not paperwork sitting in a filing cabinet. It is a real-time system built around identity verification (KYC), business verification (KYB), and transaction monitoring (the AML program), all of it powered by software and layered on top of a regulatory framework that goes back to 1970.

Founders who build platforms in fintech, marketplaces, capital-formation, or any product that touches money and personal data end up here at some point. Sometimes on day one, when a bank partner insists. Sometimes at Series A, when a regulator writes a letter. Sometimes after a fraud incident that costs six figures and forces a policy overhaul. The right time to build the verification stack is before any of those happen. This article is the working guide I wish had existed when we started thinking about the stack for OBridge.

Why platforms need this

Three arguments matter, in this order.

The regulatory argument. Platforms that hold, transmit, or facilitate the movement of value in the United States are usually classified as Money Services Businesses (MSBs), broker-dealers, funding portals, or bank service providers, and each classification triggers a Bank Secrecy Act (BSA) obligation. Non-compliance produces enforcement actions. In 2024 alone, U.S. banking regulators and FinCEN imposed multi-hundred-million-dollar penalties on institutions with weak AML programs. TD Bank's October 2024 settlement for BSA violations totaled $3.09 billion. Regulators do not treat this softly.

The business argument. Bank partners, payment processors, and card networks will not touch a platform without a defined KYC and AML program. Stripe requires it. Modern Treasury requires it. Every U.S. bank sponsor requires it. Building a verification stack is not a legal cost center; it is a precondition for the platform to receive money at all.

The user argument. Verification protects both sides of a two-sided platform. Investors on OBridge need to know that founders are real people at real companies. Founders need to know that investors are who they say they are, and that pledged capital is not tied to a sanctioned individual or a fraudulent entity. The people who complain loudest about verification friction are often the people it is designed to protect.

The regulatory foundation

The verification requirements every U.S. platform builds against come from a single stack of statutes and rules that has grown steadily since 1970. Understanding the shape of that stack helps founders make sense of vendor pitches and legal advice.

1970: the Bank Secrecy Act

The Bank Secrecy Act, officially the Currency and Foreign Transactions Reporting Act of 1970, is the foundation of U.S. anti-money-laundering law. It created the requirement that financial institutions maintain records of certain transactions, report suspicious activity, and file Currency Transaction Reports for cash transactions above a threshold (originally $10,000, unchanged since). It also gave the Treasury Department authority to designate additional recordkeeping and reporting obligations by rule.

2001: the USA PATRIOT Act

Title III of the USA PATRIOT Act, passed six weeks after September 11, 2001, is the source of most modern KYC obligations. Section 326 required financial institutions to implement a Customer Identification Program (CIP). Sections 311 through 314 expanded information-sharing between institutions and law enforcement. Section 352 required all "financial institutions" (defined broadly to include broker-dealers, MSBs, and funding portals) to establish AML programs with at least four elements: internal policies, a designated compliance officer, employee training, and independent testing.

2001-present: FinCEN rulemaking

The Financial Crimes Enforcement Network, a bureau of the Treasury Department, writes the implementing rules for BSA and Title III. FinCEN rules live at 31 CFR Chapter X and are organized by institution type: banks in Part 1020, MSBs in Part 1022, broker-dealers in Part 1023, funding portals in Part 1031, and so on. Each institution type has its own CIP, CDD, and reporting obligations.

2016: the CDD Rule

The Customer Due Diligence (CDD) Rule, finalized by FinCEN in May 2016 and effective May 11, 2018, added the current beneficial-ownership requirement to KYB. Covered institutions must identify and verify any individual who owns 25% or more of a legal-entity customer, plus one individual with "significant responsibility to control, manage, or direct" the entity (usually the CEO or CFO). The 25% threshold is the number that shows up on every KYB screen you have ever filled out.

2024: the Corporate Transparency Act

The Corporate Transparency Act, effective January 1, 2024, extends beneficial-ownership reporting to almost all U.S. legal entities (with narrow exemptions for large operating companies, regulated entities, and inactive entities). Every covered entity must file a Beneficial Ownership Information (BOI) report with FinCEN identifying its ultimate beneficial owners. Enforcement of the CTA has been the subject of ongoing litigation, and the compliance deadline has been adjusted several times, but the underlying rule is now part of the U.S. framework and platforms performing KYB should include CTA reporting status in their verification workflows.

Sanctions: the OFAC layer

Separate from BSA and running in parallel, the Office of Foreign Assets Control administers economic sanctions. U.S. persons and any entity operating in the United States must screen customers against the OFAC Specially Designated Nationals (SDN) list and prevent transactions with sanctioned parties. OFAC violations are strict liability: intent does not matter, and penalties are enforced regardless of whether the platform "knew." Every KYC vendor bundles OFAC screening because there is no realistic operating model that skips it.

Beyond the U.S.: FATF, AMLD, and MiCA

The Financial Action Task Force sets international AML standards. Its 40 Recommendations shape national regulation across G20 countries and beyond. FATF-derived rules typically require KYC on customers, ongoing monitoring, and reporting of suspicious activity, with variation in thresholds and exemptions.

In the European Union, the current framework is the Fifth Anti-Money Laundering Directive (5AMLD), effective January 2020, with the Sixth Directive (6AMLD) adding harmonized criminal penalties. In 2024, the EU adopted the AML Package, which creates a new EU AML Authority (AMLA) headquartered in Frankfurt and replaces the directive-based approach with a directly applicable regulation. Full application dates roll out through 2027.

The EU's Markets in Crypto-Assets Regulation (MiCA), effective in phases through 2024 and 2025, imposes AML and KYC obligations on crypto-asset service providers, extending the traditional framework into token issuance and trading. Platforms with any crypto exposure need MiCA compliance in the EU.

The United Kingdom, post-Brexit, is regulated by the Money Laundering Regulations 2017, administered by the FCA and HMRC. Rules are broadly aligned with the FATF standard.

What KYC actually checks

Know Your Customer is the process of verifying that an individual is who they claim to be. In the platform context, it usually means five layers of check running against a submitted user profile.

Identity data verification

The user submits name, date of birth, address, and a government-issued identifier (Social Security Number in the U.S., National Insurance Number in the U.K., national ID in most EU countries). The verification vendor cross-references these against authoritative databases: credit-bureau data (Experian, Equifax, TransUnion in the U.S.; Schufa in Germany), electoral rolls, utility records, and tax authority records where accessible. A pass usually indicates the name and address are consistent across at least two authoritative sources.

Document verification

The user uploads a photograph of an identity document: passport, driver's license, national ID card, or residence permit. Document verification runs three checks: the document is a legitimate template for the issuing country (font, holograms, MRZ format), the document is not on a known-fraud blacklist, and the data on the document matches the data submitted in step one. Modern vendors use machine-vision models to detect tampering, screen-recaptures, and printed forgeries.

Biometric verification

The user takes a live selfie. A face-matching engine compares the selfie to the photograph on the identity document. A liveness engine checks that the selfie is a real person and not a photograph of a photograph, a mask, or a deepfake. Liveness has become the meaningful battleground: deepfake identity fraud has grown fast enough that vendors like Onfido have shipped generation-3 liveness detection specifically to counter it. See the Onfido Identity Fraud Report for annual industry data on fraud trends.

Sanctions and PEP screening

The user's name is checked against the OFAC SDN list, the U.N. consolidated sanctions list, the EU consolidated list, and any relevant national lists. A separate screen checks a global database of Politically Exposed Persons (heads of state, ministers, senior officials, their family members and close associates). A PEP match does not automatically block onboarding but triggers Enhanced Due Diligence.

Adverse media screening

An automated news search checks whether the user has been the subject of adverse media coverage related to financial crime, corruption, or sanctions evasion. Vendors use natural language processing to distinguish subject-of-story matches from mere name mentions. A hit here triggers a manual review.

Practical note

Not every platform runs every layer. A U.S. broker-dealer running under FINRA Rule 3310 must run all five. A retail app doing peer-to-peer payments under a state money-transmitter license typically runs the first three plus sanctions. A funding portal under Reg CF runs a lighter version, but sanctions screening is universal. The layers you run depend on your regulatory classification, your bank partner's requirements, and your own fraud tolerance.

What KYB actually checks

Know Your Business is the KYC analog for legal entities. It is significantly more complex, because legal entities do not have faces or fingerprints and their ownership structures can be nested arbitrarily deeply.

Entity existence and registration

The vendor verifies that the entity is registered with the relevant state or national business registry, is in good standing, and matches the details submitted (legal name, entity type, jurisdiction). U.S. verification cross-references state Secretary-of-State databases; U.K. verification uses Companies House; EU verification uses national business registries connected through the Business Registers Interconnection System (BRIS).

Tax identifier verification

In the U.S., the vendor validates the Employer Identification Number (EIN) against IRS records. In the EU, VAT numbers are checked through VIES. Mismatches between the entity name and the tax ID are a leading indicator of shell-company fraud.

Beneficial ownership identification (the 25% threshold)

This is where KYB gets structurally difficult. Under the FinCEN CDD Rule, the platform must identify every natural person who owns 25% or more of the entity, directly or indirectly through intermediate entities. For a simple two-founder LLC, that means identifying both founders. For a fund-of-funds with layered LP interests, it means walking up the ownership tree until you find natural persons.

KYB vendors handle this in one of two ways. The direct-collect approach asks the business to declare its beneficial owners on a form. The vendor then runs individual KYC on each declared UBO. The discovery approach cross-references corporate registry data, Panama Papers-style leak databases, and paid ownership databases (Dun and Bradstreet, LexisNexis, Bureau van Dijk) to independently map the ownership structure. The best vendors do both and reconcile.

Authorized signer verification

The person opening the account on behalf of the business must have authority to bind the business. KYB flows verify this by requiring corporate resolution documents, articles of incorporation with named officers, or a signed authorization letter from the entity's registered agent.

Business purpose validation

Enhanced Due Diligence for higher-risk businesses (money services businesses, cannabis-adjacent businesses, high-cash-volume retail) requires the platform to understand and document the nature of the business, the expected transaction volume, and the source of funds. This is qualitative work that vendors surface but do not usually complete on their own; a compliance officer reviews and signs off.

The AML program: what a platform needs to run continuously

KYC and KYB are point-in-time checks that happen at onboarding. AML is the continuous program that runs for the life of the customer relationship. FinCEN and FATF both require covered institutions to maintain the "four pillars" (five for some institution types), plus a set of ongoing operations.

Written policies and procedures

Every AML program starts with a written manual: how the platform verifies customers, what triggers additional review, what constitutes suspicious activity, when to file SARs, how to handle sanctions hits, how records are kept. The manual must be approved by the board (or equivalent governance body) and reviewed at least annually. Template manuals exist but should be customized to the platform's actual operating model, because regulators read manuals looking for evidence that the platform has actually thought about its own risks.

Designated compliance officer

The platform designates a BSA/AML compliance officer with authority and resources to run the program. For small platforms this is often the founder or a senior operations lead. As the platform grows, the role becomes a dedicated hire, then a team. The compliance officer is personally accountable for the program to the regulator.

Training

All employees who interact with customers or handle transactions must receive AML training on hire and at least annually thereafter. Training documentation is a common item on regulatory examination checklists.

Independent testing

An independent party (an outside consultant, an internal auditor, or a rotating internal team not part of the compliance function) must periodically test the AML program's effectiveness. Small platforms often outsource this. Testing frequency is typically annual, though higher-risk platforms may do it more often.

Transaction monitoring

Every transaction the platform processes runs through rules (or an ML model) designed to flag patterns consistent with money laundering: structuring (breaking transactions into pieces below reporting thresholds), rapid movement of funds through the platform, transactions to or from high-risk jurisdictions, unusual patterns relative to the customer's expected profile. Flagged transactions are queued for compliance review.

SAR filing

When compliance concludes a transaction (or pattern) is suspicious, the platform files a Suspicious Activity Report with FinCEN within 30 days of detection (60 days if a suspect has not been identified). SARs are confidential. The platform cannot tell the customer a SAR was filed. Missed or late SARs are the most common enforcement finding.

CTR filing

Currency Transaction Reports are filed for cash transactions over $10,000 (or aggregated same-day transactions from the same customer above the threshold). Platforms that do not accept cash rarely file CTRs. Platforms that do (crypto on-ramps, prepaid card issuers, some payment platforms) file them constantly.

Recordkeeping

Every KYC/KYB record, every transaction, every SAR filing, every training log must be retained for at least five years (some rules require longer). Records must be accessible on demand during a regulatory examination.

The vendor landscape

Almost no platform builds its own verification stack. The vendor market is deep and specialized. Here is what matters, organized by function.

End-to-end identity verification (KYC)

VendorStrengthTypical use case
PersonaConfigurable flows, strong document + biometric, U.S.-focused with global expansionFintech, marketplaces, gig platforms
Onfido (Entrust)Deep global coverage, strong on document verification, mature livenessBanks, regulated fintech, cross-border platforms
SumsubDeep EU + emerging-market coverage, strong crypto AML integrationCrypto exchanges, EU-focused fintech
JumioEnterprise-grade, deep integrations, higher enterprise pricingLarge banks, gaming, insurance
VeriffFast implementation, strong liveness, good for startupsConsumer fintech, marketplaces
TruliooVery deep global identity data coverage, ID + AML combinedCross-border platforms, embedded fintech

Business verification (KYB)

VendorStrength
MiddeskBest-in-class U.S. business verification, deep beneficial ownership discovery
AlloyOrchestration platform that stitches together KYC + KYB + AML across multiple vendors
Kompany (Moody's)Global corporate data, deep EU coverage
Dun & BradstreetLegacy business data, D-U-N-S numbers, credit and financial data

Orchestration and workflow

As platforms grow, they usually add a second layer between the identity vendor and the internal system: an orchestration platform that lets compliance teams tune decisioning rules, add manual review queues, and swap out underlying vendors without engineering rewrites. Alloy is the market leader here. Footprint is a newer entrant focused on vault-and-verify architecture. Larger fintechs sometimes build orchestration internally.

Sanctions and adverse media

Refinitiv World-Check (now part of London Stock Exchange Group) and ComplyAdvantage are the two most common standalone sanctions and PEP screening providers. Most end-to-end KYC vendors also bundle sanctions screening from these or equivalent sources.

Transaction monitoring

Unit21, Hummingbird, and Alloy all offer modern transaction-monitoring products with rules engines, case management, and SAR filing built in. Older enterprise offerings from Actimize (NICE), Prime, and SAS still dominate the largest banks.

Crypto-specific AML

Any platform touching crypto adds a specialized layer for on-chain analytics. Chainalysis, Elliptic, and TRM Labs are the market leaders. These vendors flag transactions involving mixers, sanctioned addresses, darknet markets, and known laundering patterns.

What this actually costs

Pricing has become more transparent in the past three years as vendors compete for startup accounts. Typical published or negotiated pricing in 2026:

CheckPer-verification cost
Basic KYC (data + document + selfie)$1.50 to $4.00 per user
Enhanced KYC (adds sanctions + PEP + adverse media)$3.00 to $8.00 per user
KYB (business + beneficial ownership + adverse media)$5.00 to $25.00 per business
Sanctions screening (standalone, ongoing)$0.10 to $0.50 per screen per month
Transaction monitoring$0.01 to $0.10 per transaction reviewed
Manual review of a flagged case$5 to $20 per case (internal or outsourced)

At platform scale, these numbers get compressed by volume commitments (typically 20-50% off list). At startup scale, pay-as-you-go is standard and the numbers above are close to reality. For a platform onboarding 10,000 users and 500 businesses in a year with modest transaction volume, total verification spend runs $50,000 to $150,000 annually before the compliance officer's salary.

UX and the tiered-verification model

The single biggest lever a platform has over verification friction is deciding what to check when. Blanket full-KYC at signup will burn 20-40% of new users during onboarding, most of them in the document-and-selfie step. Deferred KYC that only kicks in when a user hits a monetary threshold preserves early activation but adds cost complexity.

The progressive-verification pattern

Modern platforms use tiered verification tied to user actions. A user can sign up with an email address and browse. Adding basic profile info unlocks additional features. Attempting to send or receive money above a threshold triggers KYC. Attempting to send or receive money above a higher threshold triggers Enhanced Due Diligence (address confirmation, source-of-funds documentation, sometimes a video call).

Example tier structure · U.S. investment platform

Tier 0: email verification, browse only.

Tier 1: basic KYC (data + document + selfie). Unlocks investment up to $10,000/year.

Tier 2: enhanced KYC (adds source-of-funds, address verification, adverse media). Unlocks investment up to $124,000/year.

Tier 3: accredited investor verification. Removes annual cap.

This pattern works because most users at Tier 0 will never trigger a KYC check, so the platform pays nothing for them. The users who do progress are the users who have already indicated meaningful engagement, which improves conversion rates on the verification step.

The dropout question

Dropout during KYC is the single biggest UX metric to track. Vendors that publish their numbers report typical pass-through rates of 70-90% on first attempt (varies by document type, country, and user demographics). Anything below 70% is a signal that either the vendor is misconfigured or the platform is asking for KYC too early. Above 90% often means the platform is not screening tightly enough, which shows up later in fraud rates. The right number is somewhere in between and platform-specific.

The common mistakes

Building the KYC before knowing the regulatory classification

The verification requirements for an MSB, a funding portal, a broker-dealer, and an unregulated marketplace are different. Founders who spec their verification stack before their legal team has classified the platform sometimes end up rebuilding it twice.

Treating KYC as a one-time event

Sanctions lists update daily. PEPs enter and exit political office. A user who passed KYC in January and appeared on a sanctions list in June is a live compliance problem, and the platform has an ongoing screening obligation. Most vendors offer "monitoring" as a separate line item that many startups skip in the first year and regret in the second.

Under-scoping KYB

Founders who assume KYB is "just KYC for businesses" underestimate the beneficial-ownership walk. A layered LLC-of-LLCs ownership structure requires meaningful investigative work to unwind, and vendors vary widely in how well they handle it. Middesk and Alloy are the most reliable at this. Some cheaper vendors let the customer self-attest and effectively skip verification, which shifts liability to the platform.

Missing SAR obligations

The SAR filing obligation is triggered by knowledge or reasonable suspicion of suspicious activity, not by a formal internal escalation. A compliance officer who receives a fraud complaint from a user and does not file within 30 days is exposed. Documentation of the decision to file or not file is what protects the platform in a regulatory examination.

Confusing consent with compliance

Users signing terms of service does not substitute for KYC. Regulators do not accept "the user agreed" as a defense against under-verification. The verification obligation is on the platform, not the user.

How OBridge thinks about it

OBridge sits at a specific spot in the regulatory landscape. The core product, a discovery network where founders post their build and investors browse, is not itself a securities offering. The Pledge Interest surface, where investors indicate a check-size they would commit to a specific startup, is a pre-transaction signal, not a binding commitment. Actual capital flow happens through partner rails (see our companion piece on SPVs for the execution model).

That structure lets us tier verification. A founder can sign up and post with basic KYC. An investor can browse and follow without accreditation. Verification steps up in three stages:

The tradeoff is that early browsers experience light friction, and the friction increases exactly as the regulatory stakes increase. Founders never have to re-verify to move between the profile and the raise. Investors do their heavy verification once, at pledge time, and then move between deals without repeating it.

The infrastructure for this tiered flow is not novel. Persona, Middesk, and Alloy all support it. The design work is deciding what to check when, so that the platform stays compliant, users stay engaged, and no one has to sit through a document upload before they know if OBridge is a product they even want.

The right time to build this

The best time to design the verification stack is before the platform accepts a single dollar of transaction flow. The second-best time is now. Retrofitting verification onto a live platform means grandfathering thousands of unverified users, negotiating with a bank partner about how to handle the migration, and taking on a real risk of enforcement in the interim.

For founders building anything that touches money and identity, the sequence is: regulatory classification with securities and financial-services counsel, then vendor selection matched to that classification, then integration and policy manual, then live testing with the compliance officer running the first cases. This sequence typically takes eight to twelve weeks of focused work. It is expensive in time and cheap in dollars relative to the alternative of finding out after launch that the bank partner will not send the platform's money.

Trust as infrastructure

Verified founders, verified investors, verified pledges.

OBridge is designed so trust travels with the founder and the investor across every stage of a raise. Launching July 19, 2026.

Join the founding cohort →

Sources and further reading. FinCEN regulatory guidance at fincen.gov. BSA rules at 31 CFR Chapter X. USA PATRIOT Act at H.R. 3162 (107th Congress). FinCEN's Customer Due Diligence FAQ at fincen.gov/customer-due-diligence. Corporate Transparency Act at fincen.gov/boi. OFAC sanctions programs at ofac.treasury.gov. FATF recommendations at fatf-gafi.org. EU AML Package at European Commission finance. MiCA at ESMA.

Nothing here is legal advice. Verification requirements depend on jurisdiction, regulatory classification, and specific bank partner requirements. Every platform needs its own AML counsel and compliance officer before going live.