The Short Answer: Payment Gateways Inherit the Full AML/CFT Duty Set
A crypto payment gateway is not a neutral pipe. The moment a business converts fiat to crypto or crypto to fiat on behalf of customers, it moves value and sits at the exact point regulators watch most closely: the on/off-ramp. Under the FATF risk-based approach, a crypto payment gateway that moves value on behalf of customers is a virtual asset service provider (VASP) and inherits the same AML/CFT duties as an exchange or a custodian.
The FATF risk-based approach turns an abstract duty into four concrete controls: know the other side, watch the transaction flow, report what looks suspicious, and keep an auditable record of every decision. The rest of this article maps those controls to the specific duties a crypto payment gateway faces and the features that meet them.
That status is not a technicality. The on/off-ramp is the choke point of the crypto economy, the place where a fiat identity meets pseudonymous on-chain value. It is also where examiners most often test whether a company's AML program is real or only written down. A gateway that treats compliance as a back-office afterthought is carrying more risk than it realizes.
The pressure is rising. The FATF's targeted updates count only 1 of 138 assessed jurisdictions as fully compliant and 29% as largely compliant, with 59% not yet implementing the required measures (July 2026 update). A payment gateway operating across borders therefore faces rules that are uneven, still maturing, and enforced with growing seriousness.
The AML Duties Payment Gateways Face
The duty set starts with the obvious: a payment gateway must know who it is moving money for and where that money has been. On-chain, this means screening every inbound and outbound address before the transaction settles, not after. Off-chain, it means tying each transfer to a verified identity and keeping that link auditable.
The second duty is continuous monitoring. A payment gateway that screens a deposit once and never looks again carries a structural blind spot, because a clean address can become risky the moment new funds arrive. Industry data puts the contamination at roughly 13 U of illicit money in every 10,000 U transacted.
That is why screening cannot stop at onboarding. A gateway that checks an address only at sign-up is running yesterday's risk picture against today's flow, and the gap between the two is exactly where illicit funds enter. Screening, monitoring, and reporting are three stages of one duty, and a weakness in any stage undermines the other two.
The third duty is reporting. When a transaction trips a risk threshold, the gateway must file a suspicious transaction report that a regulator can actually read, with the underlying evidence attached. A gateway that detects risk but cannot document it has not met the duty.
The common thread across all three is a record. Regulators do not ask only whether a gateway found a risky transaction. They ask whether the gateway can show, with a complete audit trail, that it screened, watched, escalated, and filed in the right order. For a payment gateway, that record is also a commercial asset, because it is what lets the business onboard legitimate merchants quickly while keeping the risky ones out.
| Duty | What it means at the on/off ramp | What a weakness there costs |
|---|---|---|
| Know the other side | Screen every inbound and outbound address before settlement, tied to a verified identity | Moving money for a party nobody can identify |
| Monitor continuously | Re-screen as new funds arrive, not only at onboarding | Yesterday's risk picture against today's flow |
| Report what looks suspicious | File a report a regulator can read, with the evidence attached | Detecting risk without documenting it does not meet the duty |
| Keep the record auditable | Preserve the decision trail for every transfer | Nothing to show an examiner |
The Core Features Required
These duties translate into four technical features that every crypto payment gateway needs.
Each capability maps to one of the four controls, and together they form the minimum viable compliance stack for an on/off-ramp.
The first is labeled address data. KYA builds a deep address profile through deep multi-hop fund tracing that crosses chains and entities. This lets a gateway see past the immediate address to the source of funds behind it.
Deep multi-hop tracing matters because one hop hides most of the story. An address that looks clean one hop away may be funded by a mixer or a sanctioned cluster two hops away, and a gateway that cannot see those hops cannot price the risk accurately.
The second is transaction monitoring. KYT delivers millisecond-level transaction monitoring and pushes risk alerts through seven channels in real time. Risk is surfaced the moment it enters the flow rather than days later.
Speed is a compliance property, not only a performance one. A risk flag that lands after funds have settled is a forensic finding, while a flag that lands before settlement is an intervention.
The third is a risk engine. The risk engine fuses AI behavioral analysis with more than 200 risk signals to flag money laundering and high-risk activity such as pig-butchering scams.
A rules-only engine catches what it already knows. A signal-driven engine catches what it has not seen before, and that difference is the line between a filter and actual detection.
The fourth is reporting. Phalcon Compliance generates a standardized suspicious transaction report (STR) in one click with a complete audit trail. This turns a detection into a filing rather than a manual write-up.

How Phalcon Compliance Meets Payment Gateway Needs
Phalcon Compliance is built as a high-performance real-time AML/CFT solution for crypto payment businesses, centralized exchanges, e-commerce platforms, ad networks, and gaming and social applications. That targeting matters, because a payment gateway is not an exchange and needs a screening layer designed for the on/off-ramp flow rather than retrofitted from a custody product.
A gateway's flow is high-velocity and low-touch. Deposits and withdrawals move constantly, and the compliance layer has to keep up without forcing a manual review on every transfer, which is why the capability set is built around speed and automation.
The platform screens against a label library of more than 600M+ blockchain addresses, updated continuously. Phalcon Compliance aligns with FATF standards and supports reporting across multiple key jurisdictions. The combination of KYA profiling, KYT monitoring, and one-click STR reporting lets a gateway run the full duty set inside one system instead of stitching together point tools.
This is what Phalcon Compliance does for crypto payment businesses: it turns the FATF duty set into an operating control layer that screens, watches, reports, and documents.

What to Do Next
Start by mapping your current gateway flow against the four controls above. Where do you screen the other side today, and does that screening happen before settlement? Where does monitoring run, and does it re-evaluate addresses as new funds arrive? Where does your STR workflow live, and can it produce a regulator-ready report in one step? The goal is not to add more manual steps; it is to make the four controls run automatically, in the background, with an audit trail that survives an examiner's read.
Manage stablecoin freeze risk with Phalcon Compliance to bring screening, monitoring, and reporting into one system. Download the stablecoin freeze risk whitepaper to understand the freeze risk your payment flow is exposed to.
Two pieces pair with this one: why crypto payment businesses need AML explains where the duties come from, and stablecoin cross-border payments puts the controls on a settlement corridor.
For the full picture of stablecoin rules, freezing risk, and payment AML, start from the Stablecoin Compliance guide.