This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.
When fintechs talk about “going global”, the headlines usually focus on new customers, bigger markets, and soaring valuations. What rarely makes the press release is the other side of the story: the Anti-Money Laundering (AML) compliance headaches that can come with expanding into new jurisdictions. Every new market can bring a fresh regulator with its own set of rules, and for fast-moving fintechs, that can mean expansion plans stall before they even get started.
Going global will test your product, but it will also test whether your AML framework is strong enough to hold up under completely different regulatory expectations. Scaling across borders sounds like a story about growth, but for compliance teams, itโs equally a story about unprecedented complexity.
So the real question is: are your AML systems truly built for global scale, or are they only fit for home turf?
Global dreams meet regulatory reality
Take Revolut, for example. After launching in Lithuania, the London-headquartered fintech ran into regulatory trouble a few years later. By April 2025, Lithuaniaโs central bank fined the firm โฌ3.5 million for failings in its AML controls. The regulator found deficiencies in the firmโs monitoring and due diligence processes, flagging weaknesses soon after Revolut began operating in the market.
A firm that is confident in its AML controls in London can find itself scrambling to meet very different requirements in New York, Singapore, or Dubai. Each jurisdiction has its own regulatory expectations, from enhanced due diligence and beneficial ownership thresholds to ongoing monitoring standards, reporting timelines, and sanctions lists. AML compliance standards and processes that satisfy one regulator may fall short under another.
Systems, workflows, and even staff training that work perfectly at home may need to be refined or redesigned entirely to keep pace with overseas regulators. Expansion can quickly expose gaps that werenโt visible when operating solely under a single, familiar regulatory framework.
A maze of multiple jurisdictions
Every country has its own approach to fighting financial crime, and the differences can be stark. Some regulators demand enhanced checks for politically exposed persons at every level, others impose strict thresholds on transaction values, or define beneficial ownership in different ways. For fintechs operating internationally, these differences mean that a process that works perfectly in one country might fall short or even be non-compliant in another, adding layers of operational and regulatory complexity.
In the United States, for example, the Bank Secrecy Act and the USA PATRIOT Act require financial institutions to verify identities, monitor transactions, and report suspicious activity, placing heavy emphasis on record-keeping to support law enforcement. In contrast, the UKโs Money Laundering Regulations 2017 apply not only to financial institutions but also to professional sectors such as law firms, accountancy firms, and high-value dealers. These regulations require firms to take a risk-based approach and implement tailored preventive measures to address the specific risks each firm faces.
Conversely, jurisdictions like the Cayman Islands and British Virgin Islands are often considered regulatory havens, with lighter financial regulation and minimal verification requirements, attracting individuals and businesses looking for more flexible environments. Which may be great if you are operating there, but it would be a real challenge if you are trying to onboard customers who are based there.
For fintechs trying to operate across borders, this patchwork of rules can be a major headache. Compliance teams must navigate differing legal definitions, thresholds, and reporting obligations, often in multiple languages. Accessing reliable local data, verifying corporate ownership structures, and maintaining up-to-date monitoring becomes much harder when rules arenโt harmonised.
Processes that work in one market may not translate directly to another, creating a constant challenge to keep controls effective, compliant, and scalable while still delivering a seamless experience for customers.
Building a compliance framework that scales across borders
So how do you build a compliance function that can keep pace with global expansion? It starts with design. Many fintechs fall into the trap of building processes market by market, bolting on new processes as they expand. The result is often a patchwork of systems and policies that donโt talk to each other, creating inefficiencies, duplicated effort, and dangerous blind spots where risky activity can slip through.
A more effective approach is to set a consistent standard for your AML compliance process that applies across jurisdictions. Build your framework with a minimum level of due diligence, ongoing monitoring, record-keeping, and reporting that every market must meet. Even if this baseline goes beyond what some regulators demand, it gives you peace of mind that your controls are consistently strong everywhere.
On top of that baseline, each jurisdiction should have its own defined workflows tailored to local requirements. That means building processes around the specific thresholds, AML screening obligations, and record-keeping requirements that apply in that country. For example, a customer flagged for enhanced due diligence in the UK might trigger one set of steps, while the same scenario in Singapore could follow a slightly different path based on local law.
How tech can support cross-border compliance
Technology should be at the heart of any compliance framework that needs to operate across borders. Without the right systems, customer data ends up scattered across regions, stored in different formats in a myriad of tools that donโt talk to each other. That leaves compliance teams wasting valuable time reconciling spreadsheets and chasing down documents, rather than actually identifying and managing risks. The more fragmented the tech stack, the higher the chance that red flags slip through the cracks.
A unified platform designed for global AML compliance changes that. By creating a single source of truth for customer data, compliance teams can see and act on the same information no matter which market theyโre working in. Whatโs more, firms can create workflows that reflect both global policies and local requirements. Rather than forcing teams to bend one rigid process to fit every market, firms can build and trigger workflows that reflect local rules, tailored to its reporting thresholds, enhanced due diligence rules, or monitoring requirements. That way, analysts everywhere follow clear, consistent steps tailored to their regulatory environment.
Real-time individual and business checks, identity verification, and ongoing monitoring can all be built into one workflow, instead of running in separate silos. When those checks feed into a central case management system, analysts can document reviews, escalate issues, and close investigations in a standardised way. This not only reduces the risk of error but also makes it easier to demonstrate to regulators that processes are consistent and repeatable across jurisdictions.
Compliance as a measure of true success
Expanding into new markets will always bring commercial opportunity, but it also magnifies the risks if AML compliance isnโt built to scale from the very beginning. Regulators are watching closely, customers expect seamless onboarding, and the cost of mistakes, both financial and reputational, can be steep.
For fintechs with global ambitions, the real measure of success wonโt just be how quickly they grow, but how well their compliance frameworks hold up under pressure in every jurisdiction they enter.
More articles by Andrew Doyle