Smarter Compliance for Fintech Growth
A Strategic Blueprint for U.S. Fintechs Navigating AML and FCC Pressures Part Two
Executive Summary
David Shapiro,
Regulatory Affairs, US
In the first half of this white paper, we examined the forces driving AML and financial crime compliance (FCC) to the centre of fintech risk management. We explored how regulators—from state agencies such as the New York Department of Financial Services (NYDFS) and California Department of Financial Protection and Innovation (DFPI) to federal bodies like FinCEN, CFPB, and the OCC—are now applying bank-grade oversight to money transmission and broader fintech operations.
Case studies of recent enforcement actions against Block (Cash App), Wise US, and OKX illustrated the severe financial, reputational, and operational consequences of scaling without robust controls. We also highlighted the hidden costs of inadequate compliance, from derisking by partners to customer attrition, and the operational drag of manual, siloed processes.
Part One made the case for intelligence-led compliance frameworks—embedding AI at the detection layer to cut false positives, streamline triage, and strengthen risk visibility in line with FATF’s risk-based approach and the Wolfsberg Group’s emphasis on quality over quantity in suspicious activity reporting.
Part Two builds on that foundation, shifting from the why to the how—focusing on advanced implementation strategies, governance best practices, and scalable models that enable fintechs to meet rising expectations while turning compliance into a driver of trust, efficiency, and growth.
Scaling operations and capturing market share puts fintechs in the same league as regulated financial institutions—where compliance is non-negotiable. Using AI-powered solutions turns this challenge into opportunity, delivering modern risk visibility that not only meets regulatory expectations but also drives revenue. By spotting underserved customer segments, emerging money-laundering patterns, and scalable growth channels that traditional systems miss, AI becomes both a compliance safeguard and a growth accelerator.
A 2024 Accenture study found that organizations using AI to improve risk visibility were 35% more likely to identify new growth opportunities, yet only a fraction of fintechs are fully leveraging tools like machine learning or cloud analytics.
Importantly, AI doesn’t just drive business performance. With better insights garnered from AI fintechs can:
- Streamline onboarding by distinguishing legitimate users from bad actors
- Improve conversion rates with fewer false positives and friction points
- Tailor risk strategies to specific segments (e.g., high-growth crypto or cross-border flows)
- Identify underserved customers and adjust services or thresholds accordingly
In a landscape where regulatory agility and customer-centric design are both essential, AI enables fintechs to meet both mandates, detecting risks with greater precision while enhancing the user experience and protecting margins.
ThetaRay Compliance Capability Matrix
| ThetaRay Capability | Key U.S. Regulatory Alignment | Global Regulatory Alignment | Wolfsberg/FATF Principles |
|---|---|---|---|
Risk-Based Transaction Monitoring |
31 CFR § 1020.210 – BSA Program Rule (risk-based monitoring requirement) 12 CFR Part 30, OCC Heightened Standards |
EU AMLD6 – |
FATF Rec. 1 – Risk-based |
Deep Cross-Border Payment Surveillance |
31 CFR § 1010.410(f) – |
FATF Rec. 13 – |
Wolfsberg Payment |
Explainability & Auditability |
OCC SR 11-7 – Model Risk |
EU AI Act (Art. 13) – Transparency & |
Wolfsberg MSA Principle |
Dynamic Risk Scoring |
31 CFR § 1022.210 – Ongoing |
FATF Rec. 1 & 10 – |
Wolfsberg MSA Principle |
Multi-Jurisdictional SAR Reporting |
31 CFR § 1020.320 – SAR |
goAML FIU |
FATF Rec. 20 – Timely |
Efficient Use of Compliance Resources |
OCC & FDIC Guidance – Resource allocation |
FATF Rec. 1 – |
Wolfsberg MSA |
Smarter, Faster Investigations |
31 CFR § 1020.320 – Timely |
FATF Rec. 10 |
Wolfsberg MSA |
Unified Compliance Platform |
OCC Bulletin 2013-29 – |
ISO 20022 data standards |
Wolfsberg CBDDQ – Consolidated AML |
Case Study
Background
Onafriq, one of Africa’s largest payment networks, connects over 500 million mobile wallets and bank accounts across more than 40 markets. Managing nearly 1,500 payment corridors, Onafriq faced the challenge of scaling its operations while ensuring robust security and compliance. To support its rapid growth and expansion, Onafriq sought a technology partner that could provide enhanced efficiency and effectiveness in transaction monitoring and compliance.
Enhancing Efficiency for Growth and Expansion
As Africa shifts towards digital payments, Onafriq needed real-time processing for both collections and disbursements. The goal was to make cross-border payments seamless and trustworthy by integrating a technological solution that enabled real-time transaction monitoring and screening. This would ensure that transactions are processed swiftly and accurately, building confidence among users and partners.
The successful implementation of AI-driven solutions has transformed Onafriq’s approach to risk management, turning compliance challenges into growth opportunities. The enhanced efficiency and effectiveness have not only supported rapid expansion but also reinforced Onafriq’s position as a leader in the digital payment industry.
Results:
By deploying ThetaRay’s AML Transaction Monitoring and Screening solutions, Onafriq achieved four primary objectives:
Enhanced Operational Efficiency: Streamline transaction monitoring and compliance processes to support rapid expansion.
Improved Effectiveness in Risk Detection: Utilize advanced technology to accurately identify and address genuine risks, reducing false positives.
Supported Growth and Expansion: Implement scalable solutions to meet diverse regulatory requirements across markets.
Boosted Trust and Compliance: Demonstrate a robust compliance framework to partners, ensuring Onafriq’s reliability.
“Together with ThetaRay, we believe that we can actually help shape the compliance layer and what good compliance and good transaction monitoring looks like across the African continent.”
Patrick Gutmann, Group Managing Director, Corporate Affairs, Onafriq
With the Financial Crimes Enforcement Network (FinCEN) ramping up enforcement3, the OCC and FDIC increasing oversight of fintech–bank partnerships, and global bodies like FATF and the Wolfsberg Group pushing for more sophisticated monitoring, U.S. fintechs face growing scrutiny over their AML and FCC controls. ThetaRay’s platform is purpose-built to help meet these evolving expectations—turning compliance from a reactive cost center into a proactive driver of trust, resilience, and growth.
Risk-Based Transaction Monitoring
Regulatory Drivers:
- FATF Recommendation 1 – Implement a risk-based approach, allocating resources to the highest risks.
- FinCEN AML Program Rule – Ongoing monitoring to identify and report suspicious activity.
- OCC Heightened Standards Guidelines – Comprehensive risk governance.
How ThetaRay Helps:
ThetaRay’s Cognitive AI surfaces nuanced and complex typologies such as mule account networks, nested structures, and cross-border layering that rule-based systems miss. This ensures institutions meet the intelligence-led requirements of FATF and FinCEN, focusing monitoring on the highest-priority threats.
Deep Cross-Border Payment Surveillance
Regulatory Drivers:
- AMLA 2020 – Enhanced due diligence for correspondent banking relationships.
- BSA/AML Travel Rule – Recordkeeping and information sharing for cross-border payments.
- FATF Recommendation 13 – Transparency for wire transfers.
How ThetaRay Helps:
Our platform traces transactions end to-end across SWIFT, SEPA, and other networks, meeting enhanced due diligence obligations and supporting detailed reporting across jurisdictions. This addresses both regulatory expectations and correspondent bank risk requirements.
Explainability & Auditability
Regulatory Drivers:
- FinCEN AML Act of 2020 – Requires programs to be effective, risk-based, and documented.
- OCC Model Risk Management Guidance (SR 11-7) – Transparency in model governance.
How ThetaRay Helps:
Every detection is fully explainable, showing why an alert was triggered, how features contributed to the risk score, and documenting decision making for internal audit and regulator review. This eliminates “black box” concerns and streamlines regulatory reporting.
Risk-Based Transaction Monitoring
Regulatory Drivers:
- FATF Recommendation 1 – Implement a risk-based approach, allocating resources to the highest risks.
- FinCEN AML Program Rule – Ongoing monitoring to identify and report suspicious activity.
- OCC Heightened Standards Guidelines – Comprehensive risk governance.
How ThetaRay Helps:
ThetaRay’s scoring adjusts dynamically to emerging typologies and behavioral shifts, eliminating the months-long lag between new threat identification and operational response common in legacy tools.
Deep Cross-Border Payment Surveillance
Regulatory Drivers:
- FinCEN SAR Requirements – U.S. suspicious activity reporting.
- goAML & Other FIU Regimes – Country specific e-filing mandates.
- FATF Recommendation 20 – Timely reporting to Financial Intelligence Units.
How ThetaRay Helps:
Supports e-filing for multiple jurisdictions from a single platform, standardizing reporting processes and ensuring timely submissions across different legal regimes.
Efficient Use of Compliance Resources
Regulatory Drivers:
- FFIEC BSA/AML Manual – Efficiency in monitoring and investigations.
- OCC & FDIC – Stress on cost-effective compliance scaling.
How ThetaRay Helps:
By cutting false positives by up to 90% and accelerating investigations with GenAI-powered summaries, institutions can redeploy analyst time to higher-value compliance activities—meeting productivity expectations without adding headcount.
Smarter, Faster Investigations
Regulatory Drivers:
- FinCEN – Effective investigation processes to support SAR filings.
- FATF Recommendation 10 & 11 – Customer due diligence and ongoing monitoring.
How ThetaRay Helps:
Provides network visualizations, entity link analysis, and contextual guidance to accelerate time-to-decision, ensuring investigative completeness while supporting timely SAR submissions.
Unified Compliance Platform
Regulatory Drivers:
- OCC & CFPB Vendor Risk Guidance – Avoid operational fragmentation that increases compliance risk.
- BSA/AML – Integrated monitoring for customer activity.
How ThetaRay Helps:
Screening, transaction monitoring, and customer risk assessment operate from a single platform, eliminating data silos and reducing operational complexity—making it easier to demonstrate comprehensive coverage during regulatory exams.
Why It Matters Now
From Block Inc’s $80M fine against a payments platform for AML gaps4, to FinCEN’s first-ever enforcement action against a crypto mixer, regulators are making it clear: speed, accuracy, and adaptability in AML/FCC are non-negotiable. ThetaRay equips fintechs to meet these heightened standards while enabling growth, competitive differentiation, and consumer trust.
Across this two-part white paper, we have moved from understanding the drivers of regulatory change to building the frameworks and governance needed to thrive under them. The path forward for fintechs is clear: adopt intelligence-led, explainable compliance; embed governance that meets both the letter and the spirit of the law; and scale with agility to keep pace with evolving risks and opportunities.
The most successful fintechs will be those that:
- Integrate advanced AI to detect complex risks early while reducing false positives.
- Collaborate with regulators to anticipate evolving standards and shape practical, risk-based approaches.
- Strengthen data governance to ensure quality, security, and transparency in compliance decisions.
- Foster innovation and adaptability to respond quickly to new threats, market trends, and regulatory shifts.
- Embed explainability into technology to build trust with regulators, partners, and customers.
In a landscape where compliance failures can halt expansion and damage reputations overnight, investing in dynamic, intelligence-led compliance frameworks delivers a dual benefit: regulatory resilience and market growth. As demonstrated by industry leaders, compliance done right is no longer a cost of doing business—it is a strategic growth engine that protects reputation, deepens customer trust, and opens the door to sustainable market expansion.
Glossary
AI – Artificial Intelligence
The simulation of human intelligence processes by machines, especially computer systems, used in fintech for tasks like anomaly detection and transaction monitoring.
AFC – Anti-Financial Crime
A collective term for measures, processes, and systems designed to prevent, detect, and respond to financial crimes such as money laundering, fraud, and terrorist financing.
AML – Anti-Money Laundering
Regulations, laws, and processes designed to detect and prevent the laundering of illicit funds.
AMLA 2020 – Anti-Money Laundering Act of 2020
A US law that expands and modernizes the Bank Secrecy Act framework, emphasizing beneficial ownership transparency and risk-based approaches.
BaaS – Banking-as-a-Service
A model that allows fintechs to offer banking products and services by leveraging the licensed infrastructure of partner banks.
BSA – Bank Secrecy Act
US law requiring financial institutions to assist government agencies in detecting and preventing money laundering, including reporting suspicious activity.
CDD – Customer Due Diligence
The process of verifying customer identities and assessing risk profiles as part of AML obligations.
CFT – Counter Financing of Terrorism
Laws, regulations, and measures designed to detect and prevent the financing of terrorist activities.
CFPB – Consumer Financial Protection Bureau
A US regulatory agency overseeing consumer protection in the financial sector, including fintech compliance obligations.
DFPI – California Department of Financial Protection and Innovation
California’s state financial regulator oversees a broad range of financial services, including state-chartered banks, credit unions, money transmitters, fintechs, and consumer financial products. DFPI enforces compliance with California’s financial laws and the federal Bank Secrecy Act (BSA) where applicable, and conducts examinations and enforcement actions to ensure AML and consumer protection standards are met.
FCC – Financial Crime Compliance
The systems and processes financial institutions implement to comply with AML, CFT, sanctions, and other financial crime regulations.
FATF – Financial Action Task Force
An intergovernmental body that sets international standards for AML/CFT and counter-proliferation financing.
FinCEN – Financial Crimes Enforcement Network
A bureau of the US Treasury responsible for collecting and analyzing financial transaction data to combat financial crimes.
FFIEC – Federal Financial Institutions Examination Council
A US interagency body that prescribes uniform principles, standards, and guidelines for financial institutions, including AML program requirements.
MSA – Monitoring and Surveillance Activities
Processes and tools used to detect suspicious activity and financial crime patterns.
NYDFS – New York Department of Financial Services
New York State’s primary financial regulator, responsible for supervising and regulating the activities of state-chartered banks, licensed lenders, insurance companies, virtual currency businesses, and money transmitters. NYDFS enforces compliance with New York’s banking and financial laws, including anti–money laundering (AML) and cybersecurity regulations, and is known for high-profile enforcement actions in both traditional finance and fintech sectors.
OCC – Office of the Comptroller of the Currency
A US federal agency that regulates and supervises national banks and federal savings associations.
SAR – Suspicious Activity Report
A report filed with FinCEN when a financial institution detects activity that may involve money laundering or other financial crimes.
SEPA – Single Euro Payments Area
A European Union initiative that harmonizes euro-denominated bank transfers across participating countries.
STR – Suspicious Transaction Report
A report to financial intelligence units (outside the US) of potentially suspicious financial transactions.
SWIFT – Society for Worldwide Interbank Financial Telecommunication
A global messaging network used by financial institutions to securely transmit information and instructions through a standardized system of codes.
Sources:
- Accenture Risk Study 2024
- Applying AI to drive superior customer outcomes, Deloitte AI Institute, 2024.
- Notice of Proposed rulemaking RIN1506-AB52, Financial Crimes Enforcement Network (FinCEN)
- Reuters, January 2025