Cross-border payment institutions operating under multiple regulatory regimes face a compliance challenge that goes beyond holding the right licences. KYC, AML, KYT, and Travel Rule are each required by regulators — but the question for any multi-licensed institution is whether those processes work together as a coherent compliance programme, or operate as four separate functions with no structural relationship.
PhotonPay holds active licences in eight jurisdictions: Hong Kong, the United Kingdom, Canada, the United States, the UAE (DIFC), Poland, the British Virgin Islands, and Switzerland. That licensing footprint means the compliance framework must satisfy the enforcement standards of regulators including the FCA, FINTRAC, DFSA, FinCEN, and the Hong Kong FSTB — each with its own specific requirements, not calibrated to the most permissive standard in the group.
PhotonPay integrates KYC identity verification, AML sanctions screening, KYT transaction monitoring, and Travel Rule compliance within a unified compliance framework. The customer risk assessment produced during onboarding supports ongoing compliance decisions across the account relationship — not just a one-time check at the point of account opening.
KYC: The Risk Foundation Across the Account Lifecycle
What PhotonPay's KYC Process Covers
PhotonPay's KYC process goes beyond confirming that a customer exists. The outcome is a structured risk assessment that supports ongoing compliance decisions throughout the account relationship. Key elements include:
-
Identity verification — individuals and corporate entities verified to applicable regulatory standards
-
UBO identification — beneficial ownership traced to any individual holding or controlling 25% or more
-
PEP screening — Politically Exposed Persons identified and subject to Enhanced Due Diligence
-
Source of funds — declared business purpose and funding sources assessed at onboarding
-
Jurisdiction risk — the regulatory risk classification of the customer's operating jurisdiction
Jurisdiction-Specific Execution Standards
KYC execution standards reflect the requirements of each licensed market:
-
Hong Kong: Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO, Cap. 615)
-
United Kingdom: FCA authorised payment institution requirements
-
Canada: FINTRAC Money Services Business obligations
Customers identified as higher risk — including PEPs and customers from FATF high-risk jurisdictions — require Enhanced Due Diligence and senior management approval before onboarding.
KYC as an Ongoing Process
Customer risk assessments are not fixed at the point of onboarding. When customer information changes, or where new risk indicators become relevant during the account relationship,
PhotonPay can conduct further review in line with applicable regulatory requirements. This ongoing due diligence approach supports the accuracy of customer risk assessments over time.
For businesses managing
international wire transfers through PhotonPay, the customer risk assessment completed at onboarding provides a foundation for ongoing compliance handling across the account lifecycle.
AML Screening: Multi-List Coverage and Continuous Risk Monitoring
Sanctions Screening Across Jurisdictions
PhotonPay's licensed markets each carry distinct sanctions obligations that do not fully overlap. To meet those obligations across its multi-jurisdiction footprint, PhotonPay conducts sanctions screening against multiple lists, including:
-
OFAC SDN (United States)
-
UN Security Council consolidated sanctions
-
HM Treasury UK financial sanctions register
-
Applicable local sanctions lists per licensed jurisdiction
A single-list approach would not satisfy the compliance requirements across eight licensed markets. Multi-list screening helps identify potential exposure that a narrower approach might miss.
Ongoing Risk Monitoring
AML compliance at PhotonPay extends beyond the checks conducted at account opening. PhotonPay incorporates ongoing risk monitoring into its AML approach — covering changes in sanctions status, PEP designation updates, and other compliance risk indicators that may arise after an account has been opened.
Where new risk signals are identified, PhotonPay can update a customer's risk assessment and, where appropriate, initiate further review or enhanced due diligence. This supports more timely identification of potential risk across the account relationship, rather than relying solely on scheduled review points.
Why it matters for digital asset transactions: For businesses using
stablecoins for settlement — where transaction velocity can be high — ongoing AML monitoring supports risk identification that is not limited to periodic review cycles.
KYT: Transaction Monitoring Within the Compliance Framework
How PhotonPay Approaches Transaction Monitoring
KYT (Know Your Transaction) focuses on the continuous monitoring of transaction behaviour to identify potential anomalies. PhotonPay applies AI-assisted transaction monitoring to help identify patterns that may indicate compliance risk, including:
-
Structuring — splitting larger transfers into multiple sub-threshold amounts
-
Unusual fund flows — transaction activity inconsistent with a customer's declared business profile
-
High-risk address exposure — for digital asset transactions, blockchain address risk assessment covering mixers and known high-risk addresses
When transaction monitoring identifies patterns that warrant further review, PhotonPay can assess the activity against the customer's risk profile and applicable regulatory requirements, and take appropriate compliance action.
Coverage Across Traditional and Digital Asset Channels
PhotonPay's transaction monitoring covers both traditional payment flows and
blockchain-based transactions within the same compliance framework. On-chain and off-chain activity is subject to the same monitoring approach — digital asset transactions are not treated as a separate compliance category handled under different standards.
For
B2B stablecoin payments, this means digital asset transactions are monitored within the same compliance framework as traditional payment channels, not managed as an edge case.
Travel Rule: Supporting Information Transmission Requirements
The Travel Rule requires that cross-border transfers meeting applicable regulatory thresholds carry originator and beneficiary identification data to the receiving institution, supporting AML and counter-terrorist financing requirements. PhotonPay supports Travel Rule compliance processes in line with the requirements of its licensed jurisdictions.
For customers who have already completed identity verification, PhotonPay can draw on existing KYC information to support Travel Rule data transmission — reducing duplicative data collection for qualifying transfers.
Applicable Thresholds by Jurisdiction
|
Jurisdiction
|
Travel Rule Threshold
|
|
Hong Kong
|
HK$8,000 (under AMLO)
|
|
EU / Poland
|
€1,000 (Transfer of Funds Regulation)
|
|
United States
|
Applicable FinCEN requirements
|
Travel Rule obligations apply to both traditional wire transfers and digital asset transfers where applicable thresholds are met. For businesses building on
stablecoin payments infrastructure, this means qualifying digital asset transfers carry the same information transmission requirements as traditional payment channels — both are handled within the same compliance framework.
Multi-Jurisdiction Licensing: The Regulatory Foundation
PhotonPay holds active regulatory licences across eight jurisdictions. All licence details are publicly listed at photonpay.com/hk/licenses and independently verifiable through each regulator's official register.
|
Jurisdiction
|
Regulator / Licence
|
|
Hong Kong
|
MSO 15-04-01638, TCSP TC010478, SFC BWJ859, Moneylender 0288/2025
|
|
United Kingdom
|
FCA 801082
|
|
Canada
|
FINTRAC M21161397
|
|
United States
|
FinCEN/NMLS 2756066 (active in 11 states: Alabama, Arkansas, Iowa, Michigan, Missouri, Oregon, Rhode Island, Utah, West Virginia, Wyoming)
|
|
UAE (DIFC)
|
DFSA F010944
|
|
Poland
|
KNF 0000998751
|
|
British Virgin Islands
|
BVI FSC IBR/AIM/25/2337
|
|
Switzerland
|
VQF SRO 101257
|
What Multi-Jurisdiction Licensing Requires in Practice
Holding licences across eight jurisdictions means the compliance framework must meet each market's specific regulatory standards independently. The FCA's Enhanced Due Diligence requirements, FINTRAC's record-keeping obligations, and DFSA's transaction monitoring standards are each reflected in how the framework operates within those markets — compliance is not calibrated to the minimum acceptable standard across the group.
SOC 2 Type I Certification
In addition to its regulatory licences, PhotonPay has completed a SOC 2 Type I audit conducted by an independent auditing firm against AICPA (American Institute of Certified Public Accountants) standards. SOC 2 provides third-party assurance of the technical infrastructure supporting the compliance framework, addressing security and operational controls independently of the regulatory authorisation provided by each licence.
The distinction matters: Regulatory licences confirm PhotonPay is authorised to operate in each market. SOC 2 provides independent verification of the systems that support that operation. Together, they form the verifiable evidence base for PhotonPay's compliance posture.
Frequently Asked Questions
How does PhotonPay's KYT approach identify structuring and other anomalous patterns?
PhotonPay applies AI-assisted transaction monitoring to help identify anomalous patterns in transaction behaviour, including structuring — where larger transfers are split into multiple sub-threshold amounts. Where monitoring identifies activity that warrants further review, PhotonPay can assess the transaction against the customer's risk profile and applicable regulatory requirements, and take appropriate compliance action.
What are the Travel Rule thresholds PhotonPay applies?
Travel Rule thresholds are set by regulation in each licensed jurisdiction. In Hong Kong, the applicable threshold under AMLO is HK$8,000. In the EU (applicable to PhotonPay's Poland-licensed operations), the Transfer of Funds Regulation sets a threshold of €1,000. US-regulated flows are subject to FinCEN's applicable requirements. Both traditional wire transfers and digital asset transfers are subject to Travel Rule obligations where thresholds are met.
How can I verify PhotonPay's regulatory licences?
All
PhotonPay licence information is publicly listed at license page. Each licence can be independently verified through the relevant regulator's public register: the FCA Financial Services Register, FINTRAC's MSB registry, the DFSA public register, the FinCEN MSB registrant search, and the corresponding registries for Hong Kong, Poland, the BVI, and Switzerland.
What is the difference between PhotonPay's regulatory licences and its SOC 2 certification?
Regulatory licences are issued by financial regulators in each jurisdiction and confirm that PhotonPay is authorised to provide payment services in that market. SOC 2 Type I certification is issued by an independent auditing firm and provides third-party assurance that the technical infrastructure supporting the compliance framework meets audited standards for security and operational controls. The two address different dimensions of compliance: operational authorisation (licences) and technical assurance (SOC 2).