Reading List
Financial Crime and Onboarding Risk Reading List
This is the compliance-and-abuse side of payments, as distinct from the fraud-decisioning stack that scores card transactions in real time. It starts at onboarding — verifying a business is what it claims, screening it against lists that change weekly — and continues for the life of the relationship, because the entity you approved is not the entity you have a year later. The last three entries cover abuse patterns that specifically exploit onboarding and payout rails rather than card authorisation, which is why they sit here rather than in the fraud list.
Who this is for
Compliance and risk teams at PSPs, payfacs and acquirers; onboarding and underwriting teams; and product managers designing verification, screening or payout-abuse controls.
Reading order
The full reading list
-
KYB vs KYC: Why Business Verification Differs for Payment Operators
Start here. Why verifying a business is structurally harder than verifying a person — UBO thresholds and the control prong, layered ownership structures, and what actually drives an initial risk tier.
13 min read
-
Sanctions Screening: OFAC, EU, and UN Lists and the Dynamic Risk Layer
OFAC, EU and UN lists, what a match actually obliges you to do, and the re-screening cadence question — because a merchant clean at onboarding can be designated later without telling you.
11 min read
-
Ongoing Merchant Monitoring: KYB Does Not End at Onboarding
KYB does not end at onboarding. Risk-tier review, the monitoring signals that indicate drift, the graduated response ladder from enhanced review to suspension, and the offboarding decision — including MATCH and its cross-acquirer consequences.
11 min read
-
LLMs in AML Transaction Monitoring: What Operators Can Deploy Today
Where language models genuinely help in AML — alert triage, narrative generation, typology detection — and the places where their use is constrained by explainability and model-risk obligations.
12 min read
-
Synthetic Identity Fraud: The Pattern Banks Miss and Operators Pay For
The pattern that defeats identity verification by not being an identity theft at all. How synthetic identities are constructed and aged, and why they surface as credit loss rather than fraud loss in most reporting.
11 min read
-
Authorized Push Payment Fraud and the Real-Time Rail Liability Problem
The abuse pattern real-time rails amplify by design: the victim authorises the payment, so there is no unauthorised transaction to dispute. Reimbursement frameworks, the receiving-PSP problem, and pre-payment controls.
11 min read
-
Promo and Referral Abuse: Controls for Payment Operators
The quietest revenue leak on this list. Promo, referral and incentive abuse is a payments problem as much as a growth one, and the controls that work are the ones applied at the payment layer rather than the campaign layer.
11 min read