An electronic-money institution or payment institution sits between its customers and the wider financial system, and that position carries a duty: to know who its customers are and to keep criminal money out of the flows it operates. AML — the set of controls that prevent a platform from being used to launder money or move funds for sanctioned or illicit purposes — and KYC — the verification of a customer's identity at the point they are admitted — are how a firm discharges that duty. For an EMI or payment institution they are not features added at the edge of a product; they are the conditions under which the firm is allowed to hold customer money and move it at all.

These controls are often filed under compliance cost, but for a payment or e-money firm they are closer to a condition of operating than to an overhead. They decide whether the firm can admit a customer, whether it can satisfy the regulator that examines it, and whether the banks and schemes it depends on will keep it connected. A firm that cannot verify identity reliably, screen against the relevant lists and monitor for changing risk cannot demonstrate that it is a safe place for money to pass through, whatever the strength of its commercial proposition.

The subject reaches every senior role in its own terms. For a chief executive, AML and KYC set the balance between admitting customers smoothly and admitting risk the firm cannot carry. For a technology leader, they are controls the platform has to be built to support — identity verification, screening and monitoring wired into onboarding and into the ledger rather than bolted on afterwards. For a compliance function or an MLRO, they are a daily discipline and a body of evidence that has to stand up to examination. This article sets out how AML and KYC fit into an EMI or payment institution at the level of concept, control and risk, and how to judge a platform by its ability to support them — not to prescribe screening thresholds or a due-diligence procedure.

What AML and KYC Mean for an EMI or Payment Institution

KYC and AML are related but distinct. KYC is the work of establishing, at onboarding, that a customer is who they claim to be and gathering enough about them to understand the risk they represent. AML is the wider programme — screening, monitoring, risk assessment and the escalation of concerns — through which the firm keeps its platform from being used for money laundering or sanctions evasion over the whole life of the relationship. KYC is the gate; AML is the discipline that keeps watch after the gate. A firm needs both, and needs them to work together, because a clean identity check at onboarding says nothing about how an account behaves a year later, and monitoring is only as good as the identity it is attached to.

For an EMI or payment institution the point of these controls is specific: the firm operates accounts and moves money on behalf of others, which makes it exactly the kind of conduit that criminal money seeks. The controls exist so that the firm can admit legitimate customers, recognise those it should not admit, and notice when a legitimate customer starts to behave in a way that warrants attention. None of this is achieved by a single check. It is achieved by a set of controls that establish identity, test it against the relevant lists, and keep testing the relationship as it evolves, each answering a different question and none sufficient on its own.

Identity and Onboarding at the Point of Entry

Onboarding is where AML and KYC first meet the customer, and it is where much of the firm's later risk is decided. Verifying an individual means confirming that a real person is present, that the identity they present is genuine, and that the two belong together — typically through a document check, a biometric or liveness check that ties the document to the live person, and corroborating data. Verifying a business is a broader exercise: understanding the entity, who stands behind it and who ultimately controls it, so that the firm is not admitting an opaque structure whose real owner it never sees. The depth of this work should follow the risk the customer represents rather than a single fixed routine applied to everyone.

The onboarding experience also carries a commercial weight that AML and KYC discussions sometimes overlook. Every additional step loses some proportion of genuine applicants, so a firm has a real interest in verification that is thorough and quick rather than thorough and slow. This is where automation earns its place: identity verification that resolves in the flow, using document, biometric and data checks together, admits good customers without friction while still establishing identity properly. Grumpio approaches this through KYC verification software that returns an automated result from document, NFC, liveness and face-matching checks, so onboarding stays fast without the firm giving up the rigour the control depends on.

Note: A verified identity is the foundation of every later control, not a control in itself. Confirming who a customer is does not establish that their money is clean or that their behaviour will stay within expectation; it establishes the subject against which screening and monitoring can then be applied. A firm that treats successful identity verification as the end of its obligation has built its AML programme on a foundation with nothing on top of it.

Screening Against Sanctions, PEPs and Adverse Media

Once a customer is identified, the firm has to test that identity against what is known about risk in the wider world. Sanctions screening checks whether a customer or counterparty appears on the lists that make dealing with them prohibited or restricted; this is not risk-based but absolute, because a sanctions breach is a breach regardless of intent. PEP screening establishes whether a customer is a politically exposed person, whose position warrants closer attention rather than exclusion. Adverse media screening surfaces credible negative information publicly associated with a customer, which may signal risk that the lists do not yet reflect. Each of these answers a different question, and together they turn a verified identity into an assessed one.

What screening produces is signals, not verdicts. A name matching a sanctions entry may be the sanctioned party or an unrelated person who shares the name; a PEP match identifies a status, not a wrongdoing; an adverse-media hit reports an association, not a proven fact. The discipline lies in resolving what a match means before acting on it, and in doing so consistently and with a record. Consolidating these checks into one workflow, rather than running identity in one system and screening in another, is what allows a firm to see a customer whole and to keep its evidence in one place. Grumpio's AML screening software brings person and company screening, sanctions, PEP and adverse-media checks and blockchain wallet risk scoring into a single workflow with API and web-panel access and periodic re-screening; details are set out at legichain.com. Screening establishes what the lists and the public record say; the firm still decides what a signal means.

The Risk-Based Approach

AML and KYC in a payment or e-money firm are governed by a risk-based approach rather than a uniform one. The principle is that controls should be proportionate to the risk a customer, product or transaction represents: a low-risk customer using a low-risk service is verified and monitored to a lighter standard than a high-risk customer, and resource is concentrated where the risk is greatest. This is not a licence to do less; it is a requirement to do the right amount in the right place, and to be able to explain why a given customer received the treatment they did. A firm applying the same heavy process to everyone wastes effort and loses good customers; one applying the same light process to everyone leaves its worst risks under-examined.

Making the risk-based approach real depends on the firm being able to assign and record risk, and to vary its controls accordingly. That means capturing the factors that bear on a customer's risk, arriving at an assessment, and applying due diligence, screening frequency and monitoring intensity that follow from it — then keeping a record of the assessment and the treatment so that the logic can be shown later. The specific factors, weightings and thresholds a firm uses are a matter of its own risk methodology and are beyond the scope of this article; the platform's role is to make a risk-based approach possible to operate and to evidence, rather than forcing every customer down an identical path.

Ongoing Monitoring and Periodic Review

Identity verified at onboarding and screening run on day one describe a customer at a single moment. Risk, however, moves. A customer may appear on a sanctions list after they were admitted, become a PEP through a change in role, or begin to behave in a way that no longer fits the profile on which they were onboarded. Ongoing monitoring and periodic re-screening exist because a control performed only at the start goes stale, and a firm that never looks again cannot claim to know its customers as time passes. Re-screening against updated lists, and reviewing customers on a cadence that follows their risk, is what keeps knowledge current rather than frozen at the point of entry.

Monitoring spans two related things: keeping the standing checks fresh, and watching how an account actually behaves. The first is periodic re-screening — testing existing customers against lists that change constantly, so a newly sanctioned party is caught rather than missed. The second is attention to activity that departs from what a customer's profile would predict, which may warrant review. This article does not set out how transaction monitoring rules or review cadences should be designed — those are operational matters shaped by a firm's own risk appetite — but the platform must make ongoing monitoring and periodic review possible to run and to evidence, because an AML programme that stops at onboarding is not an AML programme.

AML and KYC as an Evidenced Control

AML and KYC are not only activities; they are controls, and a control that cannot be evidenced provides little assurance however diligently it was performed. It is not enough for a firm to verify identity, screen and monitor; it has to be able to show that it did, to whom, when and with what result, and to retain that record for as long as the relationship and the rules require. The evidence is what turns a set of internal actions into something a regulator, an auditor or a partner bank can rely on. A firm that performs strong controls but cannot produce the record of them is, from the outside, indistinguishable from a firm that did not perform them at all.

This is why the way a platform captures and retains AML and KYC evidence matters as much as the checks themselves. A verification result, a screening outcome, the resolution of a match, a risk assessment and a monitoring decision each need to be recorded in a durable, retrievable form, so that the firm can reconstruct why a customer was admitted and how they were treated afterwards. A structured evidence report for each check, retained and retrievable, is part of what makes an AML programme examinable rather than merely asserted. Judging an EMI or payment platform by how well it supports AML and KYC as evidenced controls — not only whether it can run the checks — is one of the more revealing tests an operator can apply.

AML, KYC and the Regulatory Frame

For an EMI or payment institution these controls sit inside a regulatory expectation rather than beside it. In the United Kingdom, electronic-money and payment firms operate under the electronic-money and payment-services regulations together with the FCA's rules, and their AML obligations arise under the Money Laundering Regulations, which require customer due diligence, sanctions and PEP screening, and ongoing monitoring applied on a risk-based basis. Registration under one regime is not authorisation under another, and a firm has to be able to demonstrate its AML and KYC controls to whichever body examines it. Grumpio's position here is deliberately bounded. We do not provide legal opinions or guarantee authorisation. We implement regulatory and audit requirements across technology, infrastructure and operations.

In the European Union, electronic-money and payment institutions operate under the established payment-services and e-money framework, with further payment-services reform incoming rather than yet in force, so a platform should be built around the current requirements while remaining adaptable. The EU's AML framework is also consolidating: a dedicated AML authority is now operational and took on EU-level anti-money-laundering tasks at the start of 2026, with a single AML rulebook whose main provisions apply from mid-2027 and direct supervision of selected firms expected from 2028. The practical implication is not to wait but to build controls that already meet current obligations and can absorb a tightening, harmonised regime. How AML and KYC fit within a broader posture is developed in the regulatory readiness pages, which treat the ability to evidence these controls as a component of readiness rather than a report produced after the fact.

Summary and Next Steps

AML and KYC are how an EMI or payment institution earns the right to hold and move customer money: KYC establishes who a customer is, and AML keeps the platform from being used against its purpose over the life of the relationship. They rest on identity verified properly at onboarding, screening against sanctions, PEP and adverse-media sources, a risk-based approach that puts effort where risk is greatest, and ongoing monitoring that keeps knowledge current. As controls they draw their value from consistency and from evidence, and they are among the clearest signals an auditor, a regulator or a partner bank reads of how well a firm is run. A platform should be judged not only on whether it can run the checks but on whether it makes AML and KYC, and the evidence of them, straightforward to operate. The strongest position is one in which an operator owns and understands the platform its controls depend on, with identity verification and screening consolidated into a workflow it can evidence at any time.

Build an EMI or payment platform with AML and KYC wired in, not bolted on, and evidenced at every step. Grumpio delivers e-money platform software as source code you can own, operate and extend, with identity verification and sanctions, PEP, adverse-media and wallet screening available through Legichain as a single, evidenced workflow.