AML 101: What every fintech needs to know before launching and what established firms still get wrong


This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.


For a fintech company just starting out, Anti-Money Laundering (AML) compliance can sometimes feel like something youโ€™ll get to once your product is live and customers are signing up, but the truth is regulators and financial crime risks donโ€™t wait until youโ€™re ready. Getting the fundamentals in place early is not only essential but will give your business the confidence to scale without stumbling over mistakes that could have been avoided. 

The basics may not sound exciting, but overlooking them can leave fintechs exposed to devastating fines and unwanted regulatory action. Clear policies and processes, sensible controls and a culture that takes compliance seriously will not only keep regulators happy, but also protect your reputation and build trust with customers and partners.

As weโ€™ve seen in recent enforcement action, even the biggest firms with vast compliance teams still get AML wrong, so what should you focus on from the very beginning to avoid falling foul of the regulator?

Why the basics still matter

Itโ€™s easy to think that AML failures and fines from the regulator are only a risk for the largest institutions with vast customer bases and legacy systems. 

In reality, smaller firms often face bigger challenges. You donโ€™t have a big compliance team or endless resources to manage compliance processes and frameworks. What you do have, though, is the chance to build a foundation of good practices into your business from the very start before shortcuts creep in.

Every fintech authorised in the UK must meet the requirements of the Money Laundering Regulations. That means firms need clear policies, proper due diligence on customers, comprehensive screening for political exposure, sanctions, and adverse media, ongoing monitoring protocols, and a way to flag and report suspicious activity. 

For peace of mind when it comes to complying with regulatory requirements, having a solid foundation for AML compliance is non-negotiable and will protect the integrity, reputation, and compliance standing of your business. 

Common pitfalls for start-ups

One of the biggest mistakes new fintechs make is underestimating how much effort it takes to carry out proper customer due diligence. Itโ€™s easy to assume that slick user interfaces and digital customer journeys automatically equal compliance. But your Know Your Customer (KYC) and Know Your Business (KYB) processes are only as good as the policies and oversight that sit behind them. 

Itโ€™s just as important to establish workflows and processes that clearly define when a customer should be flagged for enhanced due diligence, when transactions or behaviour need further investigation, or when a relationship needs to be paused or offboarded altogether. Without these processes in place, even the smoothest onboarding journey can leave your firm exposed to significant financial crime risks.

Another common stumbling block for fintechs is trying to handle everything manually. Reviewing documents, running checks, and monitoring customer risk profiles for any changes by hand might work when you have a handful of customers, but it quickly becomes unmanageable as you scale. Manual processes increase the chance of mistakes, slow down investigations, and make it easy for suspicious activity to slip through unnoticed. Without at least some level of automated support, your compliance team can be buried in admin instead of actively preventing risk.

Similarly, thinking that AML compliance is a one-off task carried out at the point of onboarding a new client is another common pitfall. Plenty of firms invest in initial checks but fail to keep up with ongoing monitoring. Bad actors are smart enough to pass initial screening but can quickly change their behaviour and risk profiles once onboarded. Without continuous customer monitoring in place, suspicious activity can go unnoticed for months, exposing your firm to regulatory breaches, financial penalties, and serious reputational damage.

Lessons from AML failures in established firms

Itโ€™s easy to think these are rookie mistakes only made by the latest entrant to the market, but even established firms with seasoned compliance departments keep falling into the same traps.

Take Starling Bank, for example. Despite rapid growth and a reputation for slick digital banking, the Financial Conduct Authority (FCA) handed the firm a ยฃ28.9 million fine in October 2024 after finding major weaknesses in its AML and sanctions controls. Automated systems were misconfigured, large parts of its customer base werenโ€™t screened properly, and the bank even breached a regulatory restriction by opening tens of thousands of high-risk accounts. 

Less than a year later, Barclays was fined ยฃ42 million for its โ€œpoor handling of financial crime risks.โ€ In one case, the bank opened a client money account for a firm without checking if it was duly authorised. It wasnโ€™t, and ยฃ34 million flowed through the bank before regulators intervened. In another, Barclays kept servicing a firm even after police raids and clear ties to a major money laundering operation.ย 

For both firms, these werenโ€™t complicated grey areas or technical edge cases that led to regulatory penalties. Both lapses boiled down to the same basic building blocks of compliance: failing to ask the right questions at the start of a commercial relationship, not tracking customer risk profiles, and neglecting clear warning signs. For two industry giants to miss such fundamentals shows how easy it is to lose sight of core controls and how just costly it becomes when you do.

Getting the foundations of AML right

So, what should a fintech prioritise when building the foundations of an AML framework? 

Start with ownership. Make sure senior management understands the risk and compliance responsibilities of your firm, and that someone is appointed with clear accountability for AML compliance. 

Thereafter, make sure they have a direct line to the senior management, give them time with the product and engineering teams working on your product or service so they can identify and address potential AML risks at the point of design and implementation, and the power to say โ€œnoโ€ when something puts your firmโ€™s compliance at risk. AML only works when senior leaders own it and treat it as part of the wider business strategy, not a department of perceived red tape and bottlenecks. 

Next, conduct a risk assessment that actually guides decision-making, and is tailored to the unique set-up of your business. It should describe how your products are used, who uses them, how money moves through them, and where things may go wrong. A payments firm serving SMEs across multiple countries will face different exposure to a consumer app serving UK residents only. 

Every firm needs to understand the risks it faces based on its products, services, customers, and jurisdictions. This assessment should, in turn, be used to shape everything else, from customer due diligence to monitoring, reporting, staff training, and awareness. The best risk assessments are living documents and get revisited whenever new products are launched, markets change, or emerging financial crime techniques appear, so your controls remain relevant and proportionate. 

With your risk assessment in place, everything else starts to fall into line. The way you onboard customers, the checks you run, and the thresholds you set for monitoring should all reflect the risks youโ€™ve identified. Technology is a key enabler here: reliable identity verification, real-time sanctions and PEP screening, and ongoing monitoring make it easier to act on risks efficiently. Together with case management functionality, your team will stay organised with complete audit trails and able to provide clear evidence for regulators if (and when) they come knocking.

But, even the best tools need the right people. Alerts donโ€™t review themselves, and someone has to investigate, escalate, and make judgment calls. That means thinking ahead about staffing, ensuring your compliance team has the right skills, and giving them authority and time to act decisively. Technology can undoubtedly speed things up, but people are the lifeblood of AML to spot the nuances and make onboarding decisions, especially in particularly complex or high-risk cases where their expertise is needed most.

More from our Opinions section

Andrew Doyle, CEO, NorthRow
Andrew Doyle

Andrew Doyle is the CEO of Anti-Money Laundering compliance software, NorthRow. He has written for TechFinitive under its Opinions section.