The Cash App account was five weeks old. The user had run six transactions between $9,200 and $9,800, always to different recipients, always just below the reporting threshold. On the seventh, the transaction monitoring engine flagged the pattern. Compliance opened a case. Within seventy-two hours the account was frozen and a Suspicious Activity Report was on its way to FinCEN.
This is what modern anti-money-laundering compliance looks like at the operational level. It is not paperwork sitting in a filing cabinet. It is a real-time system built around identity verification (KYC), business verification (KYB), and transaction monitoring (the AML program), all of it powered by software and layered on top of a regulatory framework that goes back to 1970.
Founders who build platforms in fintech, marketplaces, capital-formation, or any product that touches money and personal data end up here at some point. Sometimes on day one, when a bank partner insists. Sometimes at Series A, when a regulator writes a letter. Sometimes after a fraud incident that costs six figures and forces a policy overhaul. The right time to build the verification stack is before any of those happen. This article is the working guide I wish had existed when we started thinking about the stack for OBridge.
Why platforms need this
Three arguments matter, in this order.
The regulatory argument. Platforms that hold, transmit, or facilitate the movement of value in the United States are usually classified as Money Services Businesses (MSBs), broker-dealers, funding portals, or bank service providers, and each classification triggers a Bank Secrecy Act (BSA) obligation. Non-compliance produces enforcement actions. In 2024 alone, U.S. banking regulators and FinCEN imposed multi-hundred-million-dollar penalties on institutions with weak AML programs. TD Bank's October 2024 settlement for BSA violations totaled $3.09 billion. Regulators do not treat this softly.
The business argument. Bank partners, payment processors, and card networks will not touch a platform without a defined KYC and AML program. Stripe requires it. Modern Treasury requires it. Every U.S. bank sponsor requires it. Building a verification stack is not a legal cost center; it is a precondition for the platform to receive money at all.
The user argument. Verification protects both sides of a two-sided platform. Investors on OBridge need to know that founders are real people at real companies. Founders need to know that investors are who they say they are, and that pledged capital is not tied to a sanctioned individual or a fraudulent entity. The people who complain loudest about verification friction are often the people it is designed to protect.
The regulatory foundation
The verification requirements every U.S. platform builds against come from a single stack of statutes and rules that has grown steadily since 1970. Understanding the shape of that stack helps founders make sense of vendor pitches and legal advice.
1970: the Bank Secrecy Act
The Bank Secrecy Act, officially the Currency and Foreign Transactions Reporting Act of 1970, is the foundation of U.S. anti-money-laundering law. It created the requirement that financial institutions maintain records of certain transactions, report suspicious activity, and file Currency Transaction Reports for cash transactions above a threshold (originally $10,000, unchanged since). It also gave the Treasury Department authority to designate additional recordkeeping and reporting obligations by rule.
2001: the USA PATRIOT Act
Title III of the USA PATRIOT Act, passed six weeks after September 11, 2001, is the source of most modern KYC obligations. Section 326 required financial institutions to implement a Customer Identification Program (CIP). Sections 311 through 314 expanded information-sharing between institutions and law enforcement. Section 352 required all "financial institutions" (defined broadly to include broker-dealers, MSBs, and funding portals) to establish AML programs with at least four elements: internal policies, a designated compliance officer, employee training, and independent testing.
2001-present: FinCEN rulemaking
The Financial Crimes Enforcement Network, a bureau of the Treasury Department, writes the implementing rules for BSA and Title III. FinCEN rules live at 31 CFR Chapter X and are organized by institution type: banks in Part 1020, MSBs in Part 1022, broker-dealers in Part 1023, funding portals in Part 1031, and so on. Each institution type has its own CIP, CDD, and reporting obligations.
2016: the CDD Rule
The Customer Due Diligence (CDD) Rule, finalized by FinCEN in May 2016 and effective May 11, 2018, added the current beneficial-ownership requirement to KYB. Covered institutions must identify and verify any individual who owns 25% or more of a legal-entity customer, plus one individual with "significant responsibility to control, manage, or direct" the entity (usually the CEO or CFO). The 25% threshold is the number that shows up on every KYB screen you have ever filled out.
2024: the Corporate Transparency Act
The Corporate Transparency Act, effective January 1, 2024, extends beneficial-ownership reporting to almost all U.S. legal entities (with narrow exemptions for large operating companies, regulated entities, and inactive entities). Every covered entity must file a Beneficial Ownership Information (BOI) report with FinCEN identifying its ultimate beneficial owners. Enforcement of the CTA has been the subject of ongoing litigation, and the compliance deadline has been adjusted several times, but the underlying rule is now part of the U.S. framework and platforms performing KYB should include CTA reporting status in their verification workflows.
Sanctions: the OFAC layer
Separate from BSA and running in parallel, the Office of Foreign Assets Control administers economic sanctions. U.S. persons and any entity operating in the United States must screen customers against the OFAC Specially Designated Nationals (SDN) list and prevent transactions with sanctioned parties. OFAC violations are strict liability: intent does not matter, and penalties are enforced regardless of whether the platform "knew." Every KYC vendor bundles OFAC screening because there is no realistic operating model that skips it.
Beyond the U.S.: FATF, AMLD, and MiCA
The Financial Action Task Force sets international AML standards. Its 40 Recommendations shape national regulation across G20 countries and beyond. FATF-derived rules typically require KYC on customers, ongoing monitoring, and reporting of suspicious activity, with variation in thresholds and exemptions.
In the European Union, the current framework is the Fifth Anti-Money Laundering Directive (5AMLD), effective January 2020, with the Sixth Directive (6AMLD) adding harmonized criminal penalties. In 2024, the EU adopted the AML Package, which creates a new EU AML Authority (AMLA) headquartered in Frankfurt and replaces the directive-based approach with a directly applicable regulation. Full application dates roll out through 2027.
The EU's Markets in Crypto-Assets Regulation (MiCA), effective in phases through 2024 and 2025, imposes AML and KYC obligations on crypto-asset service providers, extending the traditional framework into token issuance and trading. Platforms with any crypto exposure need MiCA compliance in the EU.
The United Kingdom, post-Brexit, is regulated by the Money Laundering Regulations 2017, administered by the FCA and HMRC. Rules are broadly aligned with the FATF standard.
What KYC actually checks
Know Your Customer is the process of verifying that an individual is who they claim to be. In the platform context, it usually means five layers of check running against a submitted user profile.
Identity data verification
The user submits name, date of birth, address, and a government-issued identifier (Social Security Number in the U.S., National Insurance Number in the U.K., national ID in most EU countries). The verification vendor cross-references these against authoritative databases: credit-bureau data (Experian, Equifax, TransUnion in the U.S.; Schufa in Germany), electoral rolls, utility records, and tax authority records where accessible. A pass usually indicates the name and address are consistent across at least two authoritative sources.
Document verification
The user uploads a photograph of an identity document: passport, driver's license, national ID card, or residence permit. Document verification runs three checks: the document is a legitimate template for the issuing country (font, holograms, MRZ format), the document is not on a known-fraud blacklist, and the data on the document matches the data submitted in step one. Modern vendors use machine-vision models to detect tampering, screen-recaptures, and printed forgeries.
Biometric verification
The user takes a live selfie. A face-matching engine compares the selfie to the photograph on the identity document. A liveness engine checks that the selfie is a real person and not a photograph of a photograph, a mask, or a deepfake. Liveness has become the meaningful battleground: deepfake identity fraud has grown fast enough that vendors like Onfido have shipped generation-3 liveness detection specifically to counter it. See the Onfido Identity Fraud Report for annual industry data on fraud trends.
Sanctions and PEP screening
The user's name is checked against the OFAC SDN list, the U.N. consolidated sanctions list, the EU consolidated list, and any relevant national lists. A separate screen checks a global database of Politically Exposed Persons (heads of state, ministers, senior officials, their family members and close associates). A PEP match does not automatically block onboarding but triggers Enhanced Due Diligence.
Adverse media screening
An automated news search checks whether the user has been the subject of adverse media coverage related to financial crime, corruption, or sanctions evasion. Vendors use natural language processing to distinguish subject-of-story matches from mere name mentions. A hit here triggers a manual review.
Not every platform runs every layer. A U.S. broker-dealer running under FINRA Rule 3310 must run all five. A retail app doing peer-to-peer payments under a state money-transmitter license typically runs the first three plus sanctions. A funding portal under Reg CF runs a lighter version, but sanctions screening is universal. The layers you run depend on your regulatory classification, your bank partner's requirements, and your own fraud tolerance.
What KYB actually checks
Know Your Business is the KYC analog for legal entities. It is significantly more complex, because legal entities do not have faces or fingerprints and their ownership structures can be nested arbitrarily deeply.
Entity existence and registration
The vendor verifies that the entity is registered with the relevant state or national business registry, is in good standing, and matches the details submitted (legal name, entity type, jurisdiction). U.S. verification cross-references state Secretary-of-State databases; U.K. verification uses Companies House; EU verification uses national business registries connected through the Business Registers Interconnection System (BRIS).
Tax identifier verification
In the U.S., the vendor validates the Employer Identification Number (EIN) against IRS records. In the EU, VAT numbers are checked through VIES. Mismatches between the entity name and the tax ID are a leading indicator of shell-company fraud.
Beneficial ownership identification (the 25% threshold)
This is where KYB gets structurally difficult. Under the FinCEN CDD Rule, the platform must identify every natural person who owns 25% or more of the entity, directly or indirectly through intermediate entities. For a simple two-founder LLC, that means identifying both founders. For a fund-of-funds with layered LP interests, it means walking up the ownership tree until you find natural persons.
KYB vendors handle this in one of two ways. The direct-collect approach asks the business to declare its beneficial owners on a form. The vendor then runs individual KYC on each declared UBO. The discovery approach cross-references corporate registry data, Panama Papers-style leak databases, and paid ownership databases (Dun and Bradstreet, LexisNexis, Bureau van Dijk) to independently map the ownership structure. The best vendors do both and reconcile.
Authorized signer verification
The person opening the account on behalf of the business must have authority to bind the business. KYB flows verify this by requiring corporate resolution documents, articles of incorporation with named officers, or a signed authorization letter from the entity's registered agent.
Business purpose validation
Enhanced Due Diligence for higher-risk businesses (money services businesses, cannabis-adjacent businesses, high-cash-volume retail) requires the platform to understand and document the nature of the business, the expected transaction volume, and the source of funds. This is qualitative work that vendors surface but do not usually complete on their own; a compliance officer reviews and signs off.
The AML program: what a platform needs to run continuously
KYC and KYB are point-in-time checks that happen at onboarding. AML is the continuous program that runs for the life of the customer relationship. FinCEN and FATF both require covered institutions to maintain the "four pillars" (five for some institution types), plus a set of ongoing operations.
Written policies and procedures
Every AML program starts with a written manual: how the platform verifies customers, what triggers additional review, what constitutes suspicious activity, when to file SARs, how to handle sanctions hits, how records are kept. The manual must be approved by the board (or equivalent governance body) and reviewed at least annually. Template manuals exist but should be customized to the platform's actual operating model, because regulators read manuals looking for evidence that the platform has actually thought about its own risks.
Designated compliance officer
The platform designates a BSA/AML compliance officer with authority and resources to run the program. For small platforms this is often the founder or a senior operations lead. As the platform grows, the role becomes a dedicated hire, then a team. The compliance officer is personally accountable for the program to the regulator.
Training
All employees who interact with customers or handle transactions must receive AML training on hire and at least annually thereafter. Training documentation is a common item on regulatory examination checklists.
Independent testing
An independent party (an outside consultant, an internal auditor, or a rotating internal team not part of the compliance function) must periodically test the AML program's effectiveness. Small platforms often outsource this. Testing frequency is typically annual, though higher-risk platforms may do it more often.
Transaction monitoring
Every transaction the platform processes runs through rules (or an ML model) designed to flag patterns consistent with money laundering: structuring (breaking transactions into pieces below reporting thresholds), rapid movement of funds through the platform, transactions to or from high-risk jurisdictions, unusual patterns relative to the customer's expected profile. Flagged transactions are queued for compliance review.
SAR filing
When compliance concludes a transaction (or pattern) is suspicious, the platform files a Suspicious Activity Report with FinCEN within 30 days of detection (60 days if a suspect has not been identified). SARs are confidential. The platform cannot tell the customer a SAR was filed. Missed or late SARs are the most common enforcement finding.
CTR filing
Currency Transaction Reports are filed for cash transactions over $10,000 (or aggregated same-day transactions from the same customer above the threshold). Platforms that do not accept cash rarely file CTRs. Platforms that do (crypto on-ramps, prepaid card issuers, some payment platforms) file them constantly.
Recordkeeping
Every KYC/KYB record, every transaction, every SAR filing, every training log must be retained for at least five years (some rules require longer). Records must be accessible on demand during a regulatory examination.
The vendor landscape
Almost no platform builds its own verification stack. The vendor market is deep and specialized. Here is what matters, organized by function.
End-to-end identity verification (KYC)
| Vendor | Strength | Typical use case |
|---|---|---|
| Persona | Configurable flows, strong document + biometric, U.S.-focused with global expansion | Fintech, marketplaces, gig platforms |
| Onfido (Entrust) | Deep global coverage, strong on document verification, mature liveness | Banks, regulated fintech, cross-border platforms |
| Sumsub | Deep EU + emerging-market coverage, strong crypto AML integration | Crypto exchanges, EU-focused fintech |
| Jumio | Enterprise-grade, deep integrations, higher enterprise pricing | Large banks, gaming, insurance |
| Veriff | Fast implementation, strong liveness, good for startups | Consumer fintech, marketplaces |
| Trulioo | Very deep global identity data coverage, ID + AML combined | Cross-border platforms, embedded fintech |
Business verification (KYB)
| Vendor | Strength |
|---|---|
| Middesk | Best-in-class U.S. business verification, deep beneficial ownership discovery |
| Alloy | Orchestration platform that stitches together KYC + KYB + AML across multiple vendors |
| Kompany (Moody's) | Global corporate data, deep EU coverage |
| Dun & Bradstreet | Legacy business data, D-U-N-S numbers, credit and financial data |
Orchestration and workflow
As platforms grow, they usually add a second layer between the identity vendor and the internal system: an orchestration platform that lets compliance teams tune decisioning rules, add manual review queues, and swap out underlying vendors without engineering rewrites. Alloy is the market leader here. Footprint is a newer entrant focused on vault-and-verify architecture. Larger fintechs sometimes build orchestration internally.
Sanctions and adverse media
Refinitiv World-Check (now part of London Stock Exchange Group) and ComplyAdvantage are the two most common standalone sanctions and PEP screening providers. Most end-to-end KYC vendors also bundle sanctions screening from these or equivalent sources.
Transaction monitoring
Unit21, Hummingbird, and Alloy all offer modern transaction-monitoring products with rules engines, case management, and SAR filing built in. Older enterprise offerings from Actimize (NICE), Prime, and SAS still dominate the largest banks.
Crypto-specific AML
Any platform touching crypto adds a specialized layer for on-chain analytics. Chainalysis, Elliptic, and TRM Labs are the market leaders. These vendors flag transactions involving mixers, sanctioned addresses, darknet markets, and known laundering patterns.
What this actually costs
Pricing has become more transparent in the past three years as vendors compete for startup accounts. Typical published or negotiated pricing in 2026:
| Check | Per-verification cost |
|---|---|
| Basic KYC (data + document + selfie) | $1.50 to $4.00 per user |
| Enhanced KYC (adds sanctions + PEP + adverse media) | $3.00 to $8.00 per user |
| KYB (business + beneficial ownership + adverse media) | $5.00 to $25.00 per business |
| Sanctions screening (standalone, ongoing) | $0.10 to $0.50 per screen per month |
| Transaction monitoring | $0.01 to $0.10 per transaction reviewed |
| Manual review of a flagged case | $5 to $20 per case (internal or outsourced) |
At platform scale, these numbers get compressed by volume commitments (typically 20-50% off list). At startup scale, pay-as-you-go is standard and the numbers above are close to reality. For a platform onboarding 10,000 users and 500 businesses in a year with modest transaction volume, total verification spend runs $50,000 to $150,000 annually before the compliance officer's salary.
UX and the tiered-verification model
The single biggest lever a platform has over verification friction is deciding what to check when. Blanket full-KYC at signup will burn 20-40% of new users during onboarding, most of them in the document-and-selfie step. Deferred KYC that only kicks in when a user hits a monetary threshold preserves early activation but adds cost complexity.
The progressive-verification pattern
Modern platforms use tiered verification tied to user actions. A user can sign up with an email address and browse. Adding basic profile info unlocks additional features. Attempting to send or receive money above a threshold triggers KYC. Attempting to send or receive money above a higher threshold triggers Enhanced Due Diligence (address confirmation, source-of-funds documentation, sometimes a video call).
Tier 0: email verification, browse only.
Tier 1: basic KYC (data + document + selfie). Unlocks investment up to $10,000/year.
Tier 2: enhanced KYC (adds source-of-funds, address verification, adverse media). Unlocks investment up to $124,000/year.
Tier 3: accredited investor verification. Removes annual cap.
This pattern works because most users at Tier 0 will never trigger a KYC check, so the platform pays nothing for them. The users who do progress are the users who have already indicated meaningful engagement, which improves conversion rates on the verification step.
The dropout question
Dropout during KYC is the single biggest UX metric to track. Vendors that publish their numbers report typical pass-through rates of 70-90% on first attempt (varies by document type, country, and user demographics). Anything below 70% is a signal that either the vendor is misconfigured or the platform is asking for KYC too early. Above 90% often means the platform is not screening tightly enough, which shows up later in fraud rates. The right number is somewhere in between and platform-specific.
The common mistakes
Building the KYC before knowing the regulatory classification
The verification requirements for an MSB, a funding portal, a broker-dealer, and an unregulated marketplace are different. Founders who spec their verification stack before their legal team has classified the platform sometimes end up rebuilding it twice.
Treating KYC as a one-time event
Sanctions lists update daily. PEPs enter and exit political office. A user who passed KYC in January and appeared on a sanctions list in June is a live compliance problem, and the platform has an ongoing screening obligation. Most vendors offer "monitoring" as a separate line item that many startups skip in the first year and regret in the second.
Under-scoping KYB
Founders who assume KYB is "just KYC for businesses" underestimate the beneficial-ownership walk. A layered LLC-of-LLCs ownership structure requires meaningful investigative work to unwind, and vendors vary widely in how well they handle it. Middesk and Alloy are the most reliable at this. Some cheaper vendors let the customer self-attest and effectively skip verification, which shifts liability to the platform.
Missing SAR obligations
The SAR filing obligation is triggered by knowledge or reasonable suspicion of suspicious activity, not by a formal internal escalation. A compliance officer who receives a fraud complaint from a user and does not file within 30 days is exposed. Documentation of the decision to file or not file is what protects the platform in a regulatory examination.
Confusing consent with compliance
Users signing terms of service does not substitute for KYC. Regulators do not accept "the user agreed" as a defense against under-verification. The verification obligation is on the platform, not the user.
How OBridge thinks about it
OBridge sits at a specific spot in the regulatory landscape. The core product, a discovery network where founders post their build and investors browse, is not itself a securities offering. The Pledge Interest surface, where investors indicate a check-size they would commit to a specific startup, is a pre-transaction signal, not a binding commitment. Actual capital flow happens through partner rails (see our companion piece on SPVs for the execution model).
That structure lets us tier verification. A founder can sign up and post with basic KYC. An investor can browse and follow without accreditation. Verification steps up in three stages:
- To publish a public founder profile: identity verification (Tier 1 KYC), plus basic KYB on the company being represented.
- To pledge interest on a startup: accredited-investor verification through our verification vendor, in compliance with Rule 506(c).
- To execute a pledge into a real investment: full KYC + sanctions + source-of-funds documentation, handled by our SPV execution partner, meeting their bank sponsor's requirements.
The tradeoff is that early browsers experience light friction, and the friction increases exactly as the regulatory stakes increase. Founders never have to re-verify to move between the profile and the raise. Investors do their heavy verification once, at pledge time, and then move between deals without repeating it.
The infrastructure for this tiered flow is not novel. Persona, Middesk, and Alloy all support it. The design work is deciding what to check when, so that the platform stays compliant, users stay engaged, and no one has to sit through a document upload before they know if OBridge is a product they even want.
The right time to build this
The best time to design the verification stack is before the platform accepts a single dollar of transaction flow. The second-best time is now. Retrofitting verification onto a live platform means grandfathering thousands of unverified users, negotiating with a bank partner about how to handle the migration, and taking on a real risk of enforcement in the interim.
For founders building anything that touches money and identity, the sequence is: regulatory classification with securities and financial-services counsel, then vendor selection matched to that classification, then integration and policy manual, then live testing with the compliance officer running the first cases. This sequence typically takes eight to twelve weeks of focused work. It is expensive in time and cheap in dollars relative to the alternative of finding out after launch that the bank partner will not send the platform's money.
Verified founders, verified investors, verified pledges.
OBridge is designed so trust travels with the founder and the investor across every stage of a raise. Launching July 19, 2026.
Join the founding cohort →Sources and further reading. FinCEN regulatory guidance at fincen.gov. BSA rules at 31 CFR Chapter X. USA PATRIOT Act at H.R. 3162 (107th Congress). FinCEN's Customer Due Diligence FAQ at fincen.gov/customer-due-diligence. Corporate Transparency Act at fincen.gov/boi. OFAC sanctions programs at ofac.treasury.gov. FATF recommendations at fatf-gafi.org. EU AML Package at European Commission finance. MiCA at ESMA.
Nothing here is legal advice. Verification requirements depend on jurisdiction, regulatory classification, and specific bank partner requirements. Every platform needs its own AML counsel and compliance officer before going live.