The Compliance Skeleton: Licenses, Identity, and Monitoring

Part V · Players and Risks (Chapters 20–25) Builds on: Chapter 13 (multi-hop cross-border), Chapter 18 (the cost of compliance checks), Chapter 20 (licensed vs. unlicensed), Chapter 23 (compliance risk) New concepts in this chapter: the three-tier reading of licenses, MTL, MSB, PI, EMI, passporting, the Payment Business License, the PS Act, SVF, KYC, KYB, UBO, OFAC, SAR, the Travel Rule

The Travel Rule in this chapter is a key prerequisite for judging stablecoins later in the course — slow down when you reach that section.


1. The Question the Previous Chapter Left Open

The previous chapter closed on this: for the first four risks, the tools sit in the institution's own hands. Compliance risk alone does not — the rules are written by regulators, and failing them is not a question of how much money you lose. It is a revoked license and a halted business.

This chapter splits compliance into three blocks: whether you may operate at all (entry), who you deal with (identity), and what was done (monitoring).


2. Entry: The License Decides What You Can Touch

The first of the three questions in the role map is "licensed or not." This section makes the license concrete.

Fix a way of reading them first, or the license names below will drown you. Payment licenses worldwide come in bewildering variety, but they are all grading the same line — the dividing line from the role map: whether customer money becomes your liability, and how deep. The cut comes out at basically three tiers:

Tier What you may do with the money Who sits here
Tier 1: touches data, not money Pass instructions, run systems The gateways and processors of the role map — registration or a filing is enough in most jurisdictions
Tier 2: touches money, but may not put it to work Hold customer balances, move funds, issue e-money The "payment institution / e-money institution" family of licenses
Tier 3: takes deposits and lends Do business with customers' money, earn the spread A banking license

Everything that differs across jurisdictions comes down to three things: how many licenses the three tiers get cut into, how high the bar sits, and how big a market one license covers. Read the six jurisdictions below with those three questions in hand.

The US: not many tiers, carved up by state lines

License What it permits The catch
MSB (Money Services Business) A federal-level registration; one of the preconditions for operating Registering is relatively easy, but it is no substitute for state licenses
MTL (Money Transmitter License) Hold and move money on customers' behalf (Tier 2) Applied for state by state — full coverage takes close to fifty, on a timeline measured in years
Banking license Take deposits and lend (Tier 3) The heaviest capital and supervisory requirements

What defines the US is not the tiers but the geography: the federal level only handles registration; the Tier 2 licenses sit in the hands of fifty states, each issuing its own.

The EU: the cleanest three-tier cut, with passporting thrown in

License What it permits Note
PI (Payment Institution) Move funds, acquire, remit — but not hold long-term balances The lower half of Tier 2
EMI (Electronic Money Institution) Everything a PI can do + issue e-money and hold customer balances The upper half of Tier 2
Banking license Take deposits and lend Tier 3

Two things make the EU the best value in licensing anywhere. One is passporting: obtain a PI or EMI license in any member state and you may operate across the whole European Economic Area — which is how Lithuania and Ireland became dedicated "license ports." The other is the fine cut: for acquiring alone, a PI is enough; add a wallet later and upgrade to an EMI. No need to buy the whole ladder on day one.

Two changes are in motion, and both are worth noting.

First, the PI and EMI licenses are merging. The next generation of payments legislation — PSD3 and its companion regulation, the PSR — reached political agreement in November 2025, completes its votes in the first half of 2026, is expected to be published around mid-2026, and applies about 21 months after that. Once merged, the "upper and lower halves of Tier 2" in the table above become one unified payment-institution framework. (This is still in the pipeline — check the current status when you need it.)

Second, stablecoins were filed into the "e-money" family. Under MiCA, the EU's crypto-asset regulation, issuing a stablecoin pegged to a single fiat currency requires the issuer to hold an EMI or banking license. The regulator's stance is unambiguous: not a new species — e-money on a different ledger.

Switzerland: outside the EU, with a half tier of its own

License What it permits Note
Fintech license Take public deposits up to CHF 100 million, but no lending and no paying interest Introduced in 2019; "half a banking license," between Tiers 2 and 3
Banking license Full deposit-taking and lending Supervised by FINMA, the Swiss Financial Market Supervisory Authority

Switzerland earns its spot here for two reasons. One: it cut an extra half tier between Tiers 2 and 3 — the fintech license may take deposits, but the deposits can only sit there, never be put to work. Two: a Swiss license carries no EU passporting. A Zurich company that wants EU customers still goes to Lithuania for an EMI. The value of a license = powers × reach — however complete the Swiss license's powers, its multiplier is one country.

China: one big license, and no new ones issued

License What it permits Note
Payment Business License Since the 2024 regulations, two categories: stored-value account operation (may take prepaid funds) and payment transaction processing (transactions only, no touching balances) Issued by the central bank; maps to the upper and lower halves of Tier 2
Banking license Take deposits and lend A separate system

What makes China unique is not the tier design but the supply side: the license count has shrunk from a peak of 271 to about 171 (2025), and for years virtually no new ones have been issued.

Which leaves exactly one way in — buy an institution that already holds one. Meituan, ByteDance, and Pinduoduo all bought their payment licenses. (When the role map said Alipay "is itself a licensed payment institution," this is the license it holds.)

The freeze turned the license from a cost into an asset with a market price — the extreme form of what this chapter's final section calls compliance as a moat.

Brazil: from "run first, license later" to "license first, run later"

License What it permits Note
IP (Instituição de Pagamento — payment institution) Four categories by activity: e-money issuance, card issuing, acquiring, payment initiation Issued by the central bank, the BCB; capital requirements computed module by module, per activity
Financial institution license Lending To earn the spread, you cross into this family

Brazil used to be famous for "run first, license later": a payment institution below the volume threshold could operate first and apply for authorization after crossing it. A whole generation of startups grew up through that door.

In 2025 the rule flipped: new institutions must be authorized before operating, and incumbents have a deadline in 2026 to regularize.

The episode is a teaching case in itself — when a market wants to switch from growth-first to order-first, the first lever it pulls is the licensing regime.

Elsewhere in Latin America, Mexico took the other road: it passed its first Fintech Law in 2018 and wrote a dedicated e-wallet license straight into it (the IFPE, Institución de Fondos de Pago Electrónico).

Singapore and Hong Kong: menu licenses, ticked by activity

Jurisdiction License Design
Singapore PS Act payment services license One license, seven activities to tick: account issuance, domestic transfers, cross-border transfers, merchant acquiring, e-money issuance, digital payment token services, money-changing; three classes by scale (money-changing / standard payment institution / major payment institution)
Hong Kong SVF (Stored Value Facility) license Covers e-wallets that hold customer balances; AlipayHK and its kind hold this one
Hong Kong Stablecoin issuer license In force since August 2025, one of the world's first stablecoin licensing regimes: HKD 25 million paid-up capital, reserves 100% in highly liquid assets, redemption at par

Singapore's PS Act is the "model answer" to the three-tier reading: it licenses by activity, not by institution type — tick the boxes for what you do, and the bigger you get, the stricter the requirements.

Hong Kong sent a different signal. Stablecoins were not squeezed into the existing SVF framework; they got a license class of their own — the regulator itself thinks this is a new species. Note that this is the exact opposite of the EU's MiCA position: the EU files stablecoins under e-money, Hong Kong gives them their own box. Same thing, two classifications — and for anyone building products across jurisdictions, that difference is a hard constraint.

The rest of Southeast Asia mostly runs simplified versions of these two: Indonesia has the central bank's PJP license, classified by activity; in the Philippines, GCash and Maya both hold central-bank EMI licenses.

The six jurisdictions in one table

Jurisdiction What Tier 2 is called Cut granularity Reach In one line
US MTL (state-issued) + MSB (federal registration) Coarse One state per license Few tiers, carved up by state lines
EU PI / EMI Fine: Tier 2 split into halves One license, the whole EEA Passporting created the "license ports"
Switzerland Fintech license Fine: a half tier between 2 and 3 Home country only Full powers, multiplier of one
China Payment Business License (two categories) Medium One license, nationwide Issuance frozen; licenses became tradable assets
Brazil IP (four categories by activity) Fine One license, nationwide Flipped in 2025 from "run first, license later" to the reverse
Singapore PS Act license (seven activities, three classes) Finest Home country Menu-style: tick by activity, class by scale

Three structural rules fall out of this table.

One: reach decides a license's value. One EU license covers thirty countries; the US is one state per license; Switzerland one country per license. That explains why so many payment startups spread faster in Europe than in the US — interchange's method again: not that European teams are better, but that the institutional structure differs. It also explains why BaaS — the role map's business of renting out a bank license's powers in packaged form — is so developed in the US: years collecting fifty licenses yourself, or borrow someone else's.

Two: cut granularity decides the startup path. In finely cut markets (the EU, Singapore), a company starts on a low-tier license and upgrades as the business grows. In coarsely cut markets (China's one big license), it's all or nothing: hold everything, or borrow everything.

Three: supply decides whether a license is a cost or an asset. When issuance is normal, a license is a cost. When issuance stops, or a full set is brutally hard to assemble (China's existing stock; near-fifty-state coverage in the US), the license itself becomes a moat with a market price. The final section of this chapter comes back to this.


3. Identity: Know Your Customer

Step Full name What it does
KYC Know Your Customer Verify an individual's identity: documents, face, address
KYB Know Your Business Verify a business customer: registration documents, scope of business, controlling parties
UBO Ultimate Beneficial Owner Pierce the shareholding structure down to the natural person who ultimately benefits

UBO is the hardest part of KYB. A company's shareholder can be another company, nested layers deep before any human appears. A standard money-laundering move exploits exactly this — stacking shell companies until the real controller disappears.

The product trade-off is blunt:

Approach Pass rate Risk
Screen loosely High; good user experience You may let in people you shouldn't, and answer to regulators later
Screen strictly Low; legitimate users get wrongly rejected Compliance-safe, but acquisition costs climb

This is the same structure as the fraud defenses in card-not-present: every verification you add cuts risk and cuts conversion. The point you want is where the sum of the two losses is smallest.


4. Monitoring: What Was Done

Step What it does On a hit
Sanctions list screening Match both parties' names against sanctions lists — in the US, chiefly OFAC's (the Office of Foreign Assets Control) Freeze on the spot; the payment must not go through
Transaction monitoring Spot abnormal patterns: structuring, rapid in-and-out, flows that don't fit the business Escalate to human review
SAR (Suspicious Activity Report) File a report with the regulator As a rule, the customer must not be told one was filed

Sanctions screening has one technical problem it can never escape: the list is text, and a name has endless spellings.

The same person's name can be written a dozen ways across languages and transliteration rules. So screening has to fuzzy-match, and fuzzy matching necessarily produces false positives in bulk — a big slice of the "cross-border is slow" from the four cost sources is burned right here, on humans reviewing those false positives.

Matching threshold Consequence
Loosen it Fewer false positives, better experience — but a real sanctions target may slip through
Tighten it Nothing slips through, but piles of normal payments sit waiting for human review

Where to set this threshold is the most recurring fight between compliance and product. There is no standard answer, because missing one costs a massive fine, and wrongly blocking a thousand costs you your users.


5. The Travel Rule: One Rule to Remember

The rule was originally written for traditional wires:

With every transfer, the sending institution must pass the payer's and the payee's identity information to the receiving institution, along with the funds.

The purpose is blunt: make every transfer between institutions carry "who is paying whom," and cut off anonymous transfers for good. The chapter on no global central bank said a SWIFT message carries instructions — a large share of its fields exist precisely to satisfy this rule.

Why bring it up early, here?

Because the international anti-money-laundering standards later extended the rule to virtual-asset transfers. Meaning: when exchanges and crypto service providers move assets between one another, they too must pass both parties' identity information.

But an on-chain transfer is, by design, all address, no identity. Hence a structural contradiction:

Traditional wire On-chain transfer
Does the transfer itself carry identity? Yes — it's in the message No — addresses only
How the Travel Rule is satisfied The message carries it natively A separate off-chain channel must be built to pass the information

The course returns to this contradiction later, when it tallies the compliance bill for stablecoins.


6. A Counterintuitive Conclusion: Compliance Is a Moat

Compliance is usually filed under cost. Flip the angle:

Fact Implication
US licenses come state by state, on a timeline of years A new entrant needs years just to pull even
Sanctions screening and transaction monitoring run on rules and data accumulated over years Can't be bought — can only be grown
A company rarely recovers from one major compliance failure An incumbent's clean record is itself an asset

This is why, in payments, "we hold licenses in 45 states" persuades more than "our technology is better." Technology can be copied in six months. Licenses can't.

When the course reaches the value of networks like CPN, you'll see that part of what they sell is exactly this layer — sparing participants the work of negotiating channels and collecting credentials country by country.


7. The Question This Chapter Leaves Open

Entry, identity, monitoring — all three blocks are covered. But every one of these rules ultimately lands in the same place — on the books.

Sanctions screening intercepts a payment: whose money is it counted as, right now? A transaction is returned: what happens to the original record? A user's balance: what proves it is that number?

The Synapse case in neobank anatomy already previewed the answer: when the ledger breaks, everything breaks.

The next chapter is about how that ledger should be kept — so it doesn't break.


8. Self-check questions

  1. Why is the US BaaS industry more developed than Europe's? Answer with this chapter's section on entry.
  2. Should the sanctions-screening threshold be set loose or tight? Give your reasoning — "it depends" is not an answer.
  3. How does satisfying the Travel Rule differ, at bottom, between a traditional wire and an on-chain transfer?
  4. A Zurich company already holds a Swiss fintech license. Why does it still apply for an EMI in Lithuania?

9. Answers

Answer for yourself before reading on.

  1. Because US money transmitter licenses are issued at the state level: national coverage takes close to fifty of them, on a timeline of years, so getting licensed yourself carries an enormous time cost. That makes "borrow the powers of an already-licensed institution" a business with real demand. In Europe, the EMI passports — one license covers many countries — so getting your own is the better deal, and the middleman's room to add value is far smaller. Institutional structure decides industry structure.

  2. The basis: the two errors carry asymmetric costs. Missing a real sanctions target costs a massive fine, regulatory penalties, possibly the license itself — and it is irreversible. Wrongly holding a normal payment costs user experience and review labor — and process can recover it. When the costs are asymmetric, the rational choice is to over-block rather than miss: tighten the threshold, then pour resources into making human review faster and better — not loosen the threshold to improve the experience.

  3. A traditional wire's message format already contains identity fields for payer and payee; satisfying the rule takes nothing extra — information and funds travel one channel. An on-chain transfer has only addresses; the protocol carries no identity at all, so a separate off-chain channel has to be built for institutions to pass identity to each other — and its information has to be matched to the specific on-chain transaction. The difference at bottom: in one, the information travels with the money; in the other, information and money take two separate roads and still must be matched up at both ends.

  4. Because Switzerland is not in the EU: a Swiss license has no passporting, and serving EU customers requires a license from an EU member state — while a Lithuanian EMI, once granted, covers the whole European Economic Area. The textbook "license port."

    By this chapter's yardstick — the value of a license = powers × reach — the fintech license's powers are not small, but its reach is one country. The multiplier is too small.


Previous: Chapter 23 · The Five Risks of Payments Next: Chapter 25 · Ledgers and Reconciliation: The Real Skeleton of a Payment System