AML Program Effectiveness: What Payment Facilitators and Sponsor Banks Need to Demonstrate
For Payment Facilitators and the banks that sponsor them, anti-money laundering compliance cannot be measured simply by whether the right policies exist. The more important question is whether the AML program actually works.
An organization may have a well-written AML policy and experienced compliance personnel and still have significant gaps between what the program says should happen and what occurs in day-to-day operations. That distinction between program design and program effectiveness is increasingly important as payment ecosystems become more complex.
Sponsor banks must understand not only the PayFac itself, but also whether the controls used to manage that downstream merchant population are functioning effectively.
The Federal Financial Institutions Examination Council (FFIEC) emphasizes that banks working with third-party payment processors should understand their merchant bases, transaction activity, risk characteristics, and suspicious-activity controls. Its examination procedures specifically contemplate reviewing merchant due diligence, comparing expected activity with actual transactions, and evaluating monitoring systems.
The result is an important shift in focus: PayFacs will be asked to demonstrate that their AML controls are producing the outcomes they were designed to produce.
Effectiveness Starts With the Actual Risk
An effective AML program begins with a risk assessment that reflects the business as it operates today. For a Payment Facilitator, that means considering factors such as:
merchant MCCs
payment channels
card-present versus card-not-present activity
transaction volume and velocity
cross-border activity
expected versus actual merchant behavior
higher-risk products and services
ownership structures
changes in the merchant portfolio over time
The risk assessment should be a living document not only reviewed annually but also as the PayFac grows in terms of new merchants and increased transaction volume. Risk profiles often evolve over time.
Controls should evolve as well. Sponsor banks should similarly evaluate whether the risk assessment they have for a PayFac remains consistent with the activity actually flowing through the program.
The FFIEC's approach to BSA/AML supervision is explicitly risk-focused: the adequacy of a program is considered relative to the institution's risk profile rather than against a single standardized model.
Onboarding Is Only the Beginning
Many payment companies devote substantial resources to onboarding. They implement KYB tools, identity verification, beneficial ownership processes, sanctions screening, website reviews, underwriting rules, and risk scoring. Those controls are essential, but AML effectiveness does not stop at account opening.
A merchant that appeared low risk during onboarding may behave very differently six months later. Transaction volumes may suddenly increase. Processing may move from primarily card-present to online. International activity may emerge. Refunds, chargebacks, ACH returns, or unusual transaction patterns may begin appearing. That makes the connection between onboarding and ongoing monitoring critical.
An effective program connects the original merchant profile to ongoing transaction behavior rather than treating underwriting and transaction monitoring as separate compliance functions.
Technology Does Not Equal Effectiveness
Today, PayFacs usually use multiple platforms for KYB, sanctions screening, transaction monitoring and fraud detection. It is not uncommon for more than one CRM to be used. Each platform may work exactly as designed yet there is limited or no connectivity between the platforms. This leads to inefficiencies and gaps in AML program management.
For example, a merchant may receive a higher risk classification in one platform without that information reaching the transaction-monitoring system. An alert may be generated but not escalated appropriately. A merchant may change beneficial ownership without triggering a review.
Regardless of the level of automation, organizations must still test whether information moves correctly through the entire compliance process. For both PayFacs and sponsor banks, the question is not:
“Do you have a transaction-monitoring system?”
Instead, the question is:
“How do you know your transaction-monitoring process is identifying the risks it is supposed to identify?”
And further, can a resolution in some form be tied directly to each alert or item flagged as a risk?
Governance Matters
AML effectiveness also depends on accountability. Someone must own the program. Management should receive meaningful information about AML performance, including trends such as:
Merchant risk distribution
Alert volumes and aging
Escalations
Investigations
Sanctions-screening results
Remediations
Escalation processes are critical. Employees should know what constitutes a material issue, who should receive it, how quickly it must be addressed, and who has authority to restrict or terminate a merchant relationship.
For sponsor banks, governance must extend to oversight of the PayFac relationship. Bank regulators have made clear that using third parties does not diminish a banking organization's responsibility for operating safely and complying with applicable requirements.
Sponsor-Bank Oversight Should Go Beyond Document Collection
One of the biggest mistakes in third-party oversight is confusing document collection with oversight. A bank may receive an AML policy, annual certification, organizational chart, risk assessment, and independent audit report from a Payment Facilitator. Those documents are useful and essential, but they do not necessarily establish effectiveness.
Meaningful oversight means asking operational questions:
· How are merchants’ risk-rated?
· Are alerts being addressed on time?
· What percentage of merchants require enhanced due diligence?
· What exceptions have occurred?
· What trends are emerging?
· How quickly are significant issues communicated to the sponsor bank?
· Have previously identified findings been remediated?
The FFIEC specifically notes that banks should periodically audit third-party payment-processing relationships and verify that processors are fulfilling contractual obligations relating to their merchants. Good oversight therefore requires evidence, not simply assurances.
Independent Testing Should Test Operations
Independent AML testing provides an important opportunity to determine whether the program functions as intended. A meaningful review should sample actual merchants and transactions, trace activity through systems, review alerts and investigations, evaluate risk ratings, examine escalation decisions, and ultimately, determine whether written procedures match actual operating practices.
It should also examine whether previous findings were resolved sustainably rather than temporarily corrected before the next review. Independent testing is most valuable when it answers a practical question:
If this program were challenged by unusual merchant behavior tomorrow, would its controls identify, escalate, investigate, and address the risk appropriately?
From Compliance Program to Control Environment
Strong AML programs are defined by how consistently risk information moves through the organization:
· Merchant onboarding informs monitoring
· Monitoring informs investigations
· Investigations inform risk ratings
· Risk trends reach management
· Findings lead to remediation
· Independent testing validates whether the entire process works
· AND, Material issues reach the sponsor bank
Strong sponsor banks know that understanding the operational effectiveness of a PayFac's controls provides greater confidence that risk is being identified and managed throughout the downstream merchant portfolio.
At RPY Innovations, we understand both sides of this relationship. Our experience across payment facilitation, sponsor-bank oversight, risk management, compliance operations, and independent AML reviews allows us to evaluate how programs actually operate, not simply whether the correct policies exist. An effective AML program should withstand more than a document review. It should withstand operational testing.
If your organization is evaluating the effectiveness of its AML program, preparing for an independent review, or strengthening oversight of a Payment Facilitator portfolio, contact RPY Innovations to discuss how we can help.