Skip to main content
Category: AML and KYC

Source of Funds

Also known as: SOF, SOF
Simply put

Source of funds refers to where the money used in a specific transaction actually comes from, including the account it was paid from and the activity that generated it. It is used by firms to confirm that money being used in a transaction was legitimately earned or acquired. It focuses on the immediate origin of the money being paid, rather than a person's overall accumulated wealth.

Formal definition

Source of Funds (SOF) is the origin of the particular funds used, or to be used, in a specific transaction, encompassing both the account from which payment is made and the economic activity or origin that generated those funds. In an anti-money-laundering context, establishing SOF requires a firm to understand and, where appropriate, verify the immediate provenance of the specific monies involved in a transaction. SOF is distinct from Source of Wealth (SOW), which addresses the origin of a person's total accumulated financial assets rather than the specific funds in a given transaction; the two are related but separate concepts and should not be conflated.

Why it matters

Establishing source of funds is a core control in anti-money-laundering and financial crime compliance because it helps a firm confirm that the specific money involved in a transaction was legitimately earned or acquired, rather than derived from criminal activity. Without understanding the immediate origin of funds, a firm has limited ability to detect when a transaction is being used to introduce or move illicit proceeds, which is a central objective of money laundering. SOF checks are intended to support this assurance at the transaction level, focusing on where the money actually came from and the account it was paid from.

A frequent point of confusion is treating source of funds and source of wealth as interchangeable. They are related but distinct: SOF addresses the immediate origin of the particular funds used in a given transaction, while source of wealth addresses the origin of a person's total accumulated financial assets. Conflating the two can lead to inadequate due diligence, because confirming that someone has substantial overall wealth does not by itself explain where the specific monies in a single transaction came from. Firms should treat them as separate but complementary inquiries.

The depth and rigour of SOF checks depend on the risk profile of the customer and transaction, and on the applicable regulatory framework, which varies by jurisdiction and firm type. Readers should confirm specific obligations against the relevant local regulations and guidance rather than assuming a single universal standard applies.

Who it's relevant to

AML and Financial Crime Compliance Teams
Compliance officers rely on source of funds checks as part of customer due diligence to confirm that money used in a specific transaction was legitimately earned or acquired. They are responsible for setting risk-based thresholds for when SOF must be established and verified, and for keeping SOF distinct from source of wealth in their procedures.
Onboarding and Transaction Monitoring Analysts
Analysts who review transactions and customer relationships use SOF information to assess whether the immediate origin of funds is consistent with what is known about the customer and the payment. Where explanations or supporting evidence do not adequately account for the specific funds, this may prompt further inquiry or escalation.
Regulated Firms Handling Client Funds
Firms that receive or handle money on behalf of clients need to understand the immediate origin of the particular funds involved in a transaction, including the account from which payment is made. The specific obligations and expected level of verification depend on the applicable jurisdiction and regulatory framework, which such firms should confirm against current local requirements.

Inside SOF

Origin of Funds
The verifiable source from which a customer's money is derived, such as employment income, business revenue, investment returns, or the sale of assets. It answers where the money ultimately came from, as distinct from where it is currently held.
Source of Wealth vs. Source of Funds
Source of funds refers to the origin of the specific funds used in a given transaction or account, while source of wealth describes how the customer's overall net worth was accumulated. The two are related but assessed separately in due diligence.
Payment Instrument and Account Provenance
The funding mechanism used to move value, such as a payment card, bank transfer, or other instrument, along with the account or entity from which funds flow. Establishing provenance may involve confirming that the funding account belongs to the customer.
Supporting Documentation
Evidence used to substantiate a stated source of funds, which may include payslips, bank statements, sale agreements, or other records. The sufficiency of documentation depends on the risk level, jurisdiction, and the obligated entity's policies.
Risk-Based Verification
The practice of calibrating the depth of source-of-funds checks to the assessed risk of the customer, transaction, or relationship, applying enhanced scrutiny to higher-risk cases rather than uniform checks.
Relationship to Cardholder Verification
In payments, confirming the source of funds is distinct from authenticating the cardholder or authorizing the transaction. Source-of-funds review addresses financial-crime and risk concerns, not the technical validity of a payment credential.

Common questions

Answers to the questions practitioners most commonly ask about SOF.

Is "Source of Funds" a PCI DSS term or requirement?
No. "Source of Funds" is not a PCI DSS concept and does not map to any PCI DSS requirement. It originates in anti-money-laundering (AML) and know-your-customer (KYC) compliance contexts, where it refers to the origin of the money involved in a transaction or relationship. PCI DSS governs the protection of cardholder data and sensitive authentication data, not the legitimacy or origin of funds. Readers should not treat Source of Funds documentation or checks as contributing to PCI DSS scope reduction or validation, and should confirm applicable AML obligations against the relevant regulatory framework rather than PCI standards.
Does verifying Source of Funds prevent payment fraud or chargebacks?
No. Source of Funds verification addresses AML and financial-crime risk, such as money laundering or illicit fund flows, and is a different objective from payment fraud detection. It is not designed to stop card-not-present fraud, account takeover, friendly or first-party fraud, chargeback fraud, or synthetic identity fraud, and it does not alter card brand liability shift or chargeback rules. It may help identify certain suspicious activity, but it does not prevent fraud on its own and should be treated as complementary to, not a substitute for, dedicated fraud controls and authentication measures.
How does Source of Funds differ from Source of Wealth in KYC processes?
Source of Funds typically refers to the origin of the specific money used in a given transaction or funding event, while Source of Wealth generally refers to the origin of an individual's or entity's overall assets accumulated over time. Programs often collect and document both, using each to support different risk assessments. The precise definitions, expected evidence, and thresholds depend on the applicable regulatory framework and the organization's own AML policy, so implementation details should be confirmed against those sources rather than assumed to be uniform.
What kinds of evidence are commonly used to establish Source of Funds?
Evidence commonly cited in AML and KYC contexts may include documentation of the transaction's funding origin, such as records tied to salary, business proceeds, sale of assets, or other described origins. The specific evidence considered acceptable, and the degree of scrutiny applied, depend on the customer risk rating, jurisdiction, and the organization's policy. Because requirements vary by regulator and change over time, teams should define acceptable evidence in their own AML program documentation and confirm it against current applicable regulations.
How should Source of Funds handling interact with cardholder data controls?
Source of Funds documentation should be kept operationally distinct from cardholder data. If such documentation is stored or processed alongside systems that also handle cardholder data, that storage does not remove those systems from PCI DSS considerations, and any cardholder data present remains subject to applicable PCI DSS controls. Sensitive authentication data must not be retained after authorization regardless of the business justification, so Source of Funds workflows must not become a reason to store prohibited data. Segregating AML records from payment data helps keep the respective control obligations clear.
Where does Source of Funds review typically fit in the transaction and onboarding lifecycle?
Source of Funds review is generally part of customer due diligence during onboarding and of ongoing monitoring, rather than being tied to the real-time authorization steps that involve controls such as EMV chip authentication, 3-D Secure, or strong customer authentication. It is intended to support AML risk assessment over the relationship, and its timing and depth depend on the organization's risk-based approach and applicable regulations. Because it operates on a different axis than transaction authentication and authorization, it should be coordinated with, but not confused with, those payment-time controls.

Common misconceptions

Source of funds and source of wealth mean the same thing and can be used interchangeably.
They are distinct concepts. Source of funds concerns the origin of the specific money used in a transaction or account, whereas source of wealth concerns how a person's overall net worth was accumulated. Assessments may require both, evaluated separately.
Verifying the source of funds is a payment-processing or authentication control that helps confirm a transaction is legitimate.
Source-of-funds review is a due-diligence and risk-management activity, not a payment authorization, cardholder authentication, or PCI DSS control. Authenticating a cardholder (for example via 3-D Secure or EMV chip authentication) and confirming the origin of funds address different risks at different points and should not be conflated.
A single documented source-of-funds check confirms that all future activity on an account is legitimate.
Source-of-funds assessment is intended to help reduce financial-crime and fraud risk, not to guarantee legitimacy. It is typically applied on a risk-based, ongoing basis, and its effectiveness depends on the quality of documentation, the accuracy of information provided, and continued monitoring.

Best practices

Apply a risk-based approach, reserving enhanced source-of-funds scrutiny and additional documentation for higher-risk customers, transactions, and relationships rather than applying uniform checks everywhere.
Assess source of funds and source of wealth as separate questions where relevant, and document which was reviewed and why.
Collect and retain supporting documentation appropriate to the assessed risk, and record the rationale for accepting a stated source, so decisions can be reviewed and evidenced.
Keep source-of-funds review distinct from payment authorization and cardholder authentication controls, and avoid treating any one control as confirmation of overall legitimacy.
Treat source-of-funds assessment as an ongoing activity, revisiting it when customer behavior, transaction patterns, or risk profile changes rather than relying solely on onboarding checks.
Confirm your obligations against the current applicable regulatory and card brand or network requirements for your jurisdiction, as expectations and documentation standards vary by region and change over time.