Skip to main content
Third-Country Payment Apps: Your AML Review ChecklistAML and KYC
5 min readFor AML/KYC Compliance Officers

Third-Country Payment Apps: Your AML Review Checklist

When your merchant acquirer or payment gateway offers integration with a foreign-issued payment app, you're not just evaluating a technical connection. You're inheriting cross-border money laundering risk, regulatory exposure in multiple jurisdictions, and potential enforcement action if those rails get used for illicit fund flows.

Japanese retailers stopping acceptance of WeChat Pay and Alipay starting February 13 isn't just a geopolitical story. It's a compliance decision driven by Japan's Act on Prevention of Transfer of Criminal Proceeds and documented concerns that Chinese criminal groups have been using these platforms to purchase high-value goods for resale, converting currency outside formal banking channels. In October, Japanese authorities dismantled a ring using luxury condominium purchases for money laundering. Last week, police called for harsher penalties for illegal bank account trading under the same Act.

This checklist helps you assess whether a third-country payment app belongs in your acceptance portfolio, or whether the AML risk outweighs the revenue potential.

Prerequisites

Before you start this review, confirm you have:

  • Current merchant agreement and payment app integration documentation
  • Access to your institution's KYC/CDD files for the payment facilitator or processor
  • Copies of applicable licensing or registration in your jurisdiction
  • Transaction data showing volume, average ticket, and geographic distribution for the app in question
  • Your AML program's risk appetite statement and board-approved risk tolerance thresholds

If you're evaluating a new payment app before integration, substitute "proposed" documentation and vendor due diligence materials.

Checklist

1. Verify the payment app operator holds valid money services business (MSB) or payment institution licensing in your jurisdiction.

Check your financial regulator's public registry. If the operator relies on a local agent or payment facilitator, verify that entity's license status as well. Look for a current license number, no enforcement actions in the past 24 months, and clear regulatory standing.

2. Confirm the operator is subject to Bank Secrecy Act (BSA) obligations or equivalent AML framework in their home jurisdiction.

Review the operator's regulatory filings or compliance attestations. If they operate under a jurisdiction not aligned with FATF Recommendations, document the gap and escalate to your AML officer. Look for written confirmation of SAR filing obligations, transaction monitoring requirements, and KYC standards equivalent to your own jurisdiction.

3. Obtain and review the operator's most recent independent AML audit or certification.

Request a copy of their SOC 2 Type II report (if available) or equivalent third-party AML program assessment. If they can't provide one, that's a red flag. Look for an unqualified opinion from a recognized auditor, dated within the past 12 months, covering transaction monitoring, sanctions screening, and SAR filing procedures.

4. Document the operator's sanctions screening process and watchlist coverage.

Ask for their written sanctions compliance policy. Confirm they screen against OFAC, UN, EU, and home-country sanctions lists in real time. If they rely on batch screening, document the frequency. Look for real-time screening at transaction initiation, coverage of all major sanctions lists, and documented escalation procedures for hits.

5. Identify whether the payment app allows peer-to-peer transfers or only merchant payments.

Review the app's terms of service and technical documentation. P2P functionality creates structuring risk and informal value transfer channels. Look for merchant-only payment flows with no user-to-user transfer capability, or if P2P exists, documented transaction limits and velocity controls.

6. Assess transaction monitoring coverage for cross-border currency conversion patterns.

Request sample transaction monitoring rules from the operator. Specifically look for detection of high-value goods purchases followed by rapid fund movement, which indicates potential trade-based money laundering. Look for scenario-based rules targeting goods-to-cash conversion patterns, with documented tuning based on typology analysis.

7. Determine whether you can obtain beneficial ownership information for app users conducting high-value transactions.

Test the operator's KYC data-sharing process. Under your merchant agreement, can you request enhanced due diligence information when a transaction exceeds your risk threshold? Look for a documented process to request and receive beneficial ownership data within 48 hours for transactions above your CDD threshold.

8. Verify your ability to file independent SARs on suspicious transactions processed through the app.

Confirm you have access to sufficient transaction detail (originating account identifier, IP address, device fingerprint, goods purchased) to meet SAR narrative requirements. Look for real-time data feed or API access providing all elements required under FinCEN SAR instructions, with no contractual restrictions on your filing obligations.

9. Review recent enforcement actions or regulatory warnings in the operator's home jurisdiction.

Search your home regulator's enforcement database and the operator's home regulator for public actions, consent orders, or advisory notices. Chinese-language money-laundering networks processed nearly $40 million in crypto per day in 2025 according to Chainalysis, which estimates these networks now launder more than 10% of funds stolen worldwide through pig butchering scams. Look for a clean enforcement record, or if actions exist, documented remediation with regulatory sign-off.

10. Quantify your institution's exposure if the payment app loses its license or faces sudden regulatory action.

Calculate total monthly volume, average transaction value, and percentage of your payment acceptance attributable to this app. Model the operational impact of a 30-day wind-down scenario. Look for exposure below 5% of total payment volume, documented contingency plan, and alternative payment methods already enabled for affected merchants.

Common Mistakes

Treating payment apps as pure technology vendors. They're money transmitters. Your AML obligations don't stop at the API boundary.

Assuming the operator's home-country AML regime is equivalent to yours. U.S. Treasury estimates Chinese networks launder as much as $150 billion annually. If the operator's jurisdiction has weak enforcement, your institution inherits that risk.

Failing to distinguish between tourist payment convenience and systematic cross-border fund flows. When hotel bookings from China to Japan decreased by 57% following a travel advisory but payment app transaction volumes remained flat, that's a typology signal, not a customer service feature.

Relying on contractual indemnification instead of operational controls. Your regulator will examine your due diligence and monitoring, not your vendor contract.

Next Steps

If any item above shows "not done," document the gap and assign remediation ownership. For items 1, 2, 7, or 8 (licensing, AML framework, beneficial ownership access, or SAR capability), escalate immediately to your AML officer and halt new transaction acceptance until resolved.

If your review identifies material deficiencies the operator won't remediate, you're facing the same decision Japanese retailers made: accepting the revenue loss now beats the enforcement action later. Schedule the discussion with your business line and compliance committee within 30 days. Bring the completed checklist and your risk quantification from item 10.

Your payment acceptance strategy isn't just about customer convenience. It's about knowing whose money laundering risk you're willing to own.

You Might Also Like