top of page

KYC AML for Card Programmes: A Business Guide

ccerqueda
12 hours ago
10 min read

.

Launching a business card programme involves more than choosing a card design, setting spending controls, or connecting an API. The programme must establish who its customers are. It must also understand the businesses and individuals behind them and monitor activity for potential financial crime risks.

KYC and AML for card programmes means applying proportionate customer identification, business verification, beneficial-owner checks, ongoing due diligence, and transaction monitoring across the issuing chain. The exact controls depend on the jurisdiction, issuer, customer type, programme structure, and risk profile. This guide is educational rather than legal advice.

Responsibilities are also distributed across the issuing bank, programme manager, and programme owner. FinCEN guidance, for example, distinguishes an issuing bank's obligations from requirements that may apply to programme managers and other parties in the prepaid-card chain. Understanding the terms first makes it easier to map those responsibilities in practice. For broader context, see our card programme management and compliance guide.

What KYC and AML Mean for Card Programmes

For businesses researching kyc aml for card programmes, the short answer is that KYC is one part of a wider AML framework. KYC establishes who a customer is. AML covers the policies, controls and ongoing activities used to prevent, detect and respond to money laundering and other financial-crime risks. A card programme needs both, with responsibilities allocated across the business, programme manager and issuing bank according to the applicable structure.

KYC and KYB: identifying the customer

Know Your Customer, or KYC, refers to verifying the identity of the people who use or control a financial product. In a card programme, this can involve collecting identity information and checking it against reliable sources. The precise documents and checks depend on the jurisdiction, customer type and issuer. For a business customer, Know Your Business, or KYB, adds checks on the legal entity itself, its activities and the people who ultimately own or control it.

AML: the wider control framework

Anti-Money Laundering, or AML, is broader than onboarding. It can include risk assessment, sanctions and other screening where applicable, transaction monitoring, escalation of unusual activity, reporting, staff training and governance. Identity verification alone does not establish that a programme is meeting every applicable AML responsibility. FinCEN describes customer identification as only one part of a bank's broader BSA/AML compliance programme. The guidance notes that it does not by itself satisfy other obligations such as suspicious-activity reporting: FinCEN customer-identification guidance.

CDD: understanding risk over time

Customer Due Diligence, or CDD, connects initial checks with an ongoing understanding of the relationship. It helps establish the nature and purpose of a customer relationship, the transactions that might reasonably be expected and when activity may be suspicious. The FFIEC describes risk-based CDD as including ongoing procedures to maintain and update customer information, including beneficial-owner information for legal-entity customers: FFIEC CDD guidance. In practice, KYC and KYB provide important identity and business data, CDD interprets that data in context, and AML uses the resulting risk picture to guide controls. Requirements vary, so programme owners should confirm the design with their issuing bank and qualified compliance advisers. Intercash's card programme management and compliance guide provides further context on how these responsibilities fit together.

What KYC Requirements Apply to Card Issuers and Programme Owners?

KYC requirements for a business card programme usually begin with identifying the people and organisations connected to the programme. Then assessing why the relationship exists and what activity is reasonably expected. The exact controls depend on the jurisdiction, issuing-bank arrangement, card product, customer type and risk profile. There is no universal checklist that applies to every issuer or programme owner.

For example, US interagency guidance says a bank's Customer Identification Program should use risk-based procedures and account for factors such as the account type. Onboarding method, available identity information and customer base. It also distinguishes the issuing bank's responsibilities from obligations that may apply to programme managers or other parties in the payment chain. See the guidance from FinCEN for the relevant US context.

A practical onboarding process for card issuing should typically address the following areas:

  1. Identify the individual.

    Collect appropriate identifying information for the customer, cardholder, authorised representative or other relevant person. Depending on the programme and jurisdiction, verification may involve government-issued identification and address information. The accepted documents, checks and refresh requirements should be set by the applicable compliance framework rather than assumed in advance.

  2. Verify the business.

    For a corporate, marketplace or financial-institution customer, KYB establishes what the organisation is, where it operates and who is authorised to act for it. Incorporation details, registered addresses, business activities and authority to open or operate the relationship may all be relevant.

  3. Understand beneficial ownership.

    Identify the natural persons who ultimately own or control a legal entity, including through layered structures where relevant. Beneficial-owner information should be verified using procedures appropriate to the risk and legal requirements. FinCEN's CDD guidance addresses beneficial ownership and its place within an AML programme.

  4. Record purpose and risk context.

    Document the intended use of the cards, expected transaction types, geography, funding flows and customer segments. This profile supports proportionate due diligence and gives monitoring teams a baseline for identifying activity that may require review.

These points are educational guidance, not legal advice. Programme owners should confirm the applicable requirements with their issuing bank and qualified compliance advisers before launch and whenever the programme, markets or risk profile changes.

What AML Controls Should a Card Programme Include?

An effective AML framework connects customer information with what happens after a card programme goes live. The right controls depend on the programme's jurisdiction, issuing-bank arrangement, customer types, products, distribution model and risk profile. There is no universal checklist, so programme owners should confirm the applicable obligations with their issuing bank and qualified compliance advisers.

For a business card programme, the control environment should usually address these areas:

  • Risk assessment and customer profiling:

    Assess the risks associated with the programme, customer segments, countries, funding sources, use cases and transaction channels. Establish an expected activity profile for each customer or relevant customer category. This gives the monitoring team a meaningful baseline. The

    FFIEC BSA/AML manual

    describes risk-based customer due diligence as a cornerstone of a strong BSA/AML programme.

  • Transaction monitoring:

    Monitor activity against the expected profile, including transaction amount, frequency, destination, velocity and other relevant indicators. Rules may flag unusual patterns or deviations for review. Thresholds should be calibrated to the programme's risk and reviewed when products, markets or customer behaviour changes. A threshold is an investigation trigger, not proof that activity is suspicious.

  • Escalation and reporting:

    Define who reviews alerts, what evidence they collect, when an alert is escalated, and who has authority to make a reporting decision. Document suspicious-activity handling and maintain a clear relationship between the programme manager, issuing bank and any relevant reporting function. Customer due diligence supports detection, but it does not replace separate reporting obligations where they apply.

  • Records and governance:

    Keep customer, beneficial-owner, risk-assessment, alert-review and decision records in line with applicable retention rules. Assign ownership for approving risk-profile changes and periodically test whether controls operate as designed.

  • Staff training:

    Train employees and relevant operational partners on red flags, escalation routes, confidentiality, documentation standards and their responsibilities. Refresh training when the programme, regulatory expectations or risk assessment changes.

Technology can support screening, monitoring and case management, but accountability still requires defined responsibilities, documented decisions and oversight from the appropriate compliance leadership.

How PCI DSS and Fraud Monitoring Fit the Compliance Model

A card programme needs several controls that address different risks. PCI DSS concerns the protection of payment card data and the systems that store, process or transmit it. Fraud monitoring focuses on suspicious or unauthorised use of cards and transactions. KYC and AML, meanwhile, establish who the customer or business is, who ultimately controls it, and whether its activity is consistent with the expected risk profile.

These controls work together, but none replaces the others. A secure environment can still be used to facilitate financial crime, while a strong onboarding process does not prevent a stolen card from being used. FinCEN describes customer identification as one part of a broader BSA/AML programme, not a complete substitute for other obligations such as suspicious-activity reporting. Its guidance also emphasises that controls should reflect the nature of the business and relevant risks.

Control

Main purpose

Example in a card programme

PCI DSS

Protect payment card data and the environments handling it.

Access, system and data-protection processes for systems involved in card payments.

Fraud monitoring

Identify potentially unauthorised or abnormal card activity.

Reviewing unusual transaction patterns, velocity or deviations from expected use.

KYC and KYB

Verify customers, businesses and relevant beneficial owners during onboarding and review.

Checking identity or business information before enabling a card account, using risk-based procedures.

AML monitoring

Detect and escalate activity that may indicate money laundering or other financial crime.

Comparing activity with the customer risk profile and investigating potentially suspicious behaviour.

The exact control design depends on the issuer, programme structure, customer type, jurisdiction and risk. A programme manager can coordinate technology, monitoring and compliance operations, but programme owners should confirm responsibilities with their issuing bank and qualified compliance advisers. Intercash's PrepaidGate platform includes reporting and fraud-monitoring functionality as part of its programme infrastructure.

Build or Outsource KYC and AML Operations for a Card Programme

Building KYC and AML operations in-house gives a programme owner direct control over policies, workflows, data and case management. It can suit an organisation that already has experienced compliance staff, established controls and the resources to maintain them across each market it serves. The cost is operational complexity: the team must design onboarding processes, define risk criteria. Monitor activity, investigate alerts, maintain records and keep procedures aligned with the applicable regulatory model.

Outsourcing can provide a more practical route when the business wants to launch a programme without assembling every issuing capability itself. A programme manager may coordinate onboarding, KYC verification, customer due diligence, transaction monitoring, escalation and related operational support. Intercash describes complete KYC verification and compliance management as part of its turnkey programme management service. Its documented AML framework includes monitoring unusual patterns, flagging activity outside transaction amount or frequency thresholds, reporting and employee training.

That support does not mean the client can ignore governance. The division of responsibility depends on the contract, the customer journey, the issuing arrangement, the countries involved and the relevant regulatory expectations. FinCEN guidance, for example, distinguishes responsibilities held by an issuing bank from requirements that may apply to a third-party programme manager or another party in the payment chain: see the interagency prepaid-card guidance. Buyers should therefore agree who owns policy approval, alert decisions, suspicious-activity escalation, record access, reporting and oversight before launch.

Intercash operates as a BIN sponsor and programme manager working with licensed issuing-bank partners. It is not a directly licensed financial institution. Through its Cards-as-a-Service model, businesses can use established issuer relationships and a more complete issuing chain while retaining clarity about their own responsibilities. The right model is the one that matches the programme's risk, jurisdictions and internal capability, with qualified compliance advisers confirming the applicable requirements.

A Practical KYC and AML Readiness Checklist

Before selecting a provider or finalising an issuing model, use this checklist to test whether your programme can support consistent, risk-based controls. Requirements vary by jurisdiction, issuer, customer type and programme structure, so treat this as an implementation guide, not legal advice.

  1. Define the programme scope and jurisdictions.

    Document who will receive cards, where those customers are located, the products and use cases involved, expected transaction patterns, and the currencies or corridors supported. Confirm which rules apply in each market with the issuing bank and qualified compliance advisers.

  2. Map responsibilities across the issuing chain.

    Record what the issuing bank, BIN sponsor, programme manager and your business each own. Include approval authority for risk decisions, escalation routes, suspicious-activity handling and changes to the customer risk profile. FinCEN guidance distinguishes an issuing bank's responsibilities from requirements that may apply to programme managers and other parties in the payment chain.

    Read the guidance

    .

  3. Specify onboarding data and verification.

    Decide what information is needed for individuals and business customers, including beneficial ownership where relevant, and how identity or business details will be verified. Build exception handling for incomplete, inconsistent or higher-risk applications rather than treating every applicant identically.

  4. Set monitoring and escalation rules.

    Define expected activity, transaction amount and frequency thresholds, review triggers, investigation ownership and escalation timelines. KYC is only one part of a wider AML framework. Ongoing customer due diligence should help maintain risk profiles and identify potentially suspicious activity, with controls proportionate to risk.

    See FFIEC guidance

    .

  5. Govern records, integrations and review.

    Confirm retention, access controls, audit evidence and data-protection responsibilities. Test how onboarding, monitoring and reporting data moves between your systems and the programme platform. Intercash's

    PrepaidGate platform

    supports issuance management, transaction history, reporting and fraud monitoring, but agree the operating model and review it as products, risks or jurisdictions change.

Frequently Asked Questions

What is the difference between KYC and AML for a card programme?

KYC focuses on identifying and understanding customers, while AML is the wider framework for preventing, detecting and responding to financial crime. KYC and customer due diligence help establish the expected customer and transaction profile; monitoring and escalation then help identify activity that may be suspicious.

Is KYC enough to meet AML requirements?

No. Identity verification is an important onboarding control, but it does not replace ongoing due diligence, transaction monitoring, risk reviews or suspicious-activity processes. FinCEN states that a Customer Identification Programme alone does not satisfy other Bank Secrecy Act obligations, including suspicious-activity reporting: FinCEN guidance.

What checks are commonly used when onboarding card programme customers?

Depending on the programme and jurisdiction, checks may cover individual identity, business details, beneficial ownership, sanctions and watchlist screening, politically exposed person risk, and adverse media. The appropriate checks should follow a documented risk assessment rather than a universal checklist.

How does a risk-based approach work in a card programme?

The programme sets customer and transaction risk factors, then applies proportionate controls. Higher-risk customers or activity may require additional information, enhanced review and closer monitoring. FFIEC guidance describes risk-based ongoing customer due diligence and increased focus on higher-risk customers: FFIEC guidance.

Can a programme manager support KYC and AML operations?

Yes. A programme manager may provide onboarding workflows, KYC verification, monitoring, reporting processes and operational technology. The exact allocation of responsibilities depends on the issuing-bank relationship, contracts, jurisdiction and programme design, so the client should confirm its obligations with qualified compliance advisers.

Ready to strengthen your card programme?

A clear KYC and AML operating model can help your team align responsibilities, controls and oversight as the programme develops. Confirm the requirements for your jurisdictions and customer base with qualified advisers, then discuss the practical next steps with our team.

 
 
bottom of page