All insights
8 July 2025·6 min read

AML controls for electronic money institutions: what the FCA expects

Electronic money institutions face a specific regulatory pressure point: rapid digital onboarding, high transaction volumes and novel products create distinct AML risks that standard bank controls do not always address. This guide outlines what the FCA expects and the controls that matter.

EMIelectronic moneyAML controlsFCAtransaction monitoring

Electronic money institutions have emerged as one of the most closely scrutinised firm types in FCA financial crime supervision. The combination of rapid customer onboarding, high transaction velocity and a customer base that may include individuals with limited banking history creates a distinct risk profile that standard bank-era controls do not always address well.

The Starling Bank enforcement action in 2024, resulting in a GBP 29 million fine, crystallised the FCA's expectations for the sector. At its core the case reflected the same three failures that appear across the broader enforcement record: monitoring coverage gaps, inadequate screening, and a control framework that did not scale with the business.

The EMI risk profile

EMIs typically onboard customers at higher velocity than traditional banks and with lower upfront friction. This creates a specific vulnerability to money mule recruitment, account takeover, and the use of accounts to layer proceeds of fraud or other predicate offences. Because accounts are opened quickly and transaction limits are initially low, the first sign of misuse is often a pattern of low-value rapid-movement activity rather than a single large suspicious transaction.

EMIs that operate in the remittance or cross-border payment space also carry elevated sanctions and high-risk-corridor exposure. Where products allow customers to send funds internationally, the screening and monitoring controls need to reflect the specific corridors the firm serves and the customer base using them.

Transaction monitoring for high-velocity accounts

Standard transaction monitoring rules designed for infrequent, higher-value bank transactions often generate too many false positives or too few true positives when applied to EMI customer behaviour. EMI-specific monitoring needs to be calibrated to the typical transaction patterns for each customer segment and product type.

The key indicators for EMIs are pass-through velocity (funds in and out within a short window with minimal balance retained), accounts that receive funds from multiple unrelated sources, and accounts that begin transacting immediately after opening with patterns inconsistent with the stated purpose. JMLSG Guidance and the FCA Financial Crime Guide both expect monitoring rules to be tuned to the firm's specific products and risk profile rather than applied generically.

Coverage is as important as calibration. Several EMI enforcement outcomes involved monitoring that was not applied consistently across all product lines or that excluded certain account types or payment channels from the rule set.

Screening obligations

EMIs must screen customers, beneficial owners and counterparties against sanctions lists at onboarding and on an ongoing basis as lists are updated. The Starling enforcement action specifically highlighted screening weaknesses, including a financial sanctions screening system that was not updated when the firm's product range expanded.

Name screening requires fuzzy matching to catch name variations, transliterations and aliases. The FCA expects firms to document their matching threshold and the rationale for it, and to test periodically that the threshold is not generating systematic false negatives.

CDD in a digital onboarding environment

Digital identity verification has expanded significantly since the pandemic, and the FCA has published guidance on the use of digital identity solutions for CDD purposes. However, the ease of digital verification has also made it easier for fraudsters to create synthetic or stolen-identity accounts at scale.

EMIs need device fingerprinting, IP analysis and behavioural signals to complement document verification. The FCA expects the CDD process to identify not just the identity document but signals about whether the identity is being used genuinely. A customer who opens an account, sets up a payee and transacts immediately, without any of the exploratory behaviour typical of a new account holder, is a pattern worth flagging.

Scaling the control framework

The Starling case emphasised that a control framework needs to scale with the business. Controls that were adequate for a firm with ten thousand customers may not be adequate for one with seven million. The FCA expects firms to have a process for reviewing the adequacy of their controls as their customer base, product range and transaction volumes grow, and to document that review.

For EMIs approaching scale, the question is not just whether the existing rules fire on new account types but whether the team behind the rules is sized to review and close the alerts they generate. An alert that is generated but not reviewed within a reasonable timeframe is not a functioning control.

Try the tool

Select your products, customer types and risk themes in TypologyIQ to generate a tailored control set for your EMI, grounded in JMLSG, FCA and Wolfsberg frameworks.

Generate AML controls for your EMI

Sources

  1. JJMLSG · JMLSG Guidance
  2. FFCA · FCG
  3. MMLR · MLR 2017
  4. WWolfsberg · Wolfsberg Principles