Reference stack
Build a KYC and AML stack
A layered customer-lifecycle control stack covering identity, business verification, screening, transaction monitoring, fraud, cases and crypto-specific controls.
Intended audience and markets
Audience
Markets
Infrastructure layers
Identity verification
RequiredVerify individuals, documents and biometrics.
Selection criteria
- Document and country coverage
- Liveness and fraud controls
- Manual review
Business verification and UBO
RequiredVerify companies, registries and beneficial owners.
Selection criteria
- Registry coverage
- UBO resolution
- Complex ownership support
Sanctions, PEP and adverse media
RequiredScreen customers and counterparties against risk data.
Selection criteria
- Data provenance
- Matching and transliteration
- Ongoing screening
Transaction monitoring and cases
RequiredDetect unusual behaviour and manage investigations.
Selection criteria
- Rule and model configurability
- Case workflow
- Audit and regulatory reporting
Fraud intelligence
OptionalAdd device, behavioural and payment-risk signals.
Selection criteria
- Signal coverage
- Latency
- Explainability and review tooling
Blockchain analytics and Travel Rule
OptionalAdd onchain screening and counterparty information where digital assets are in scope.
Selection criteria
- Chain coverage
- Risk methodology
- Travel Rule interoperability
Implementation sequence
- Identity verification
- Business verification and UBO
- Sanctions, PEP and adverse media
- Transaction monitoring and cases
- Fraud intelligence
- Blockchain analytics and Travel Rule
Regulatory considerations
- The regulated business remains responsible for its risk assessment, policies, decisions and reporting.
- Vendor scores should not replace documented risk-based judgement.
Technical considerations
- Unify customer, account, device and transaction identifiers across vendors.
- Retain decision evidence and model or rule versions for audit.
Questions to ask providers
- Which legal entity contracts for each service and in which jurisdictions?
- Which responsibilities remain with the product operator rather than the provider?
- What are the implementation, approval, testing and migration timelines?
- How are incidents, exits, data portability and business continuity handled?
- How will false positives be measured and tuned?
- Which alerts require human review and who makes the final decision?
What this stack does not cover
- Policies, MLRO responsibilities and regulatory filings are not outsourced by this stack.
Related stacks
Reviewed on 2026-07-07.
Provider options are examples of infrastructure roles, not endorsements or a guarantee of suitability, availability or regulatory compliance. Confirm requirements for your product with each provider and qualified advisers.