Skip to content

Reference stack

Build a KYC and AML stack

A layered customer-lifecycle control stack covering identity, business verification, screening, transaction monitoring, fraud, cases and crypto-specific controls.

Compliance teamsBanksFintechsDigital-asset businesses

Intended audience and markets

Audience

Compliance teamsBanksFintechsDigital-asset businesses

Markets

Global

Infrastructure layers

01

Identity verification

Required

Verify individuals, documents and biometrics.

Selection criteria

  • Document and country coverage
  • Liveness and fraud controls
  • Manual review
02

Business verification and UBO

Required

Verify companies, registries and beneficial owners.

Selection criteria

  • Registry coverage
  • UBO resolution
  • Complex ownership support
03

Sanctions, PEP and adverse media

Required

Screen customers and counterparties against risk data.

Selection criteria

  • Data provenance
  • Matching and transliteration
  • Ongoing screening
04

Transaction monitoring and cases

Required

Detect unusual behaviour and manage investigations.

Selection criteria

  • Rule and model configurability
  • Case workflow
  • Audit and regulatory reporting
05

Fraud intelligence

Optional

Add device, behavioural and payment-risk signals.

Selection criteria

  • Signal coverage
  • Latency
  • Explainability and review tooling
06

Blockchain analytics and Travel Rule

Optional

Add onchain screening and counterparty information where digital assets are in scope.

Selection criteria

  • Chain coverage
  • Risk methodology
  • Travel Rule interoperability

Implementation sequence

  • Identity verification
  • Business verification and UBO
  • Sanctions, PEP and adverse media
  • Transaction monitoring and cases
  • Fraud intelligence
  • Blockchain analytics and Travel Rule

Regulatory considerations

  • The regulated business remains responsible for its risk assessment, policies, decisions and reporting.
  • Vendor scores should not replace documented risk-based judgement.

Technical considerations

  • Unify customer, account, device and transaction identifiers across vendors.
  • Retain decision evidence and model or rule versions for audit.

Questions to ask providers

  • Which legal entity contracts for each service and in which jurisdictions?
  • Which responsibilities remain with the product operator rather than the provider?
  • What are the implementation, approval, testing and migration timelines?
  • How are incidents, exits, data portability and business continuity handled?
  • How will false positives be measured and tuned?
  • Which alerts require human review and who makes the final decision?

What this stack does not cover

  • Policies, MLRO responsibilities and regulatory filings are not outsourced by this stack.

Related stacks

Reviewed on 2026-07-07.

Provider options are examples of infrastructure roles, not endorsements or a guarantee of suitability, availability or regulatory compliance. Confirm requirements for your product with each provider and qualified advisers.