Blog / Compliance

KYC and Compliance for Card Programmes: A Primer

What KYC, AML and sanctions screening require of a card programme, who is responsible for what, and how obligations differ between sponsored and network models.

10 min read

COMPLIANCE KYC and Compliance for Card Programmes: A Primer CARD NETWORK

In short

Every card programme has to know who holds its cards, screen them against sanctions lists, monitor for suspicious activity, and keep records. Who performs each duty differs by model, but the duties themselves never disappear.

Compliance is where card programmes stall. Not because the requirements are exotic, but because they are usually discovered late — after the engineering is done and someone asks who verified the cardholders.

The four obligations

Almost every regime asks for the same four things, whatever it calls them.

ObligationWhat it means
Know Your CustomerEstablish and verify who the customer is before providing the service.
Sanctions screeningCheck customers against sanctions and watchlists, at onboarding and continuously.
Transaction monitoringWatch for patterns suggesting money laundering or fraud, and escalate them.
Record keepingRetain identification and transaction records for a defined period, retrievable on request.

These do not vanish because you use a provider. They are performed by someone, and part of choosing a model is deciding who.

Who does what, by model

DutySponsored programmeCard issuing network
Cardholder KYCYou, to the sponsor's standardThe network, as part of the programme
Sanctions screeningYou, usually with a vendorThe network
Transaction monitoringYou, with sponsor oversightThe network
Suspicious activity reportingYou, to the regulatorThe network
KYB on your own businessThe sponsor does this to youThe network does this to you
Compliance officerRequired, in-houseNot required for the card programme itself

The bottom row is the practical difference. A sponsored programme needs a named compliance function from before launch. A network programme does not, because you are a customer of a programme rather than the operator of one.

This does not make you obligation-free. You still have your own regulatory position — data protection, consumer duties, tax reporting, and whatever your own sector requires — and those are unaffected by who issues the cards.

What KYC actually involves

For individuals, typically: full legal name, date of birth, residential address, and a government identity document verified against the person, often with a liveness check. For businesses: incorporation details, registered address, directors, and beneficial owners above a threshold — usually 25%.

Two things make this harder than it sounds:

  • Beneficial ownership can be genuinely difficult. Layered corporate structures are legal and common, and unwinding them to real people takes work.
  • Verification is not collection. Collecting a passport number is not KYC. Verifying the document is genuine and belongs to the person in front of you is.

Where programmes actually fail

  • Treating KYC as a signup form. Data collected but never verified satisfies nobody and is discovered at the first audit.
  • Screening once. Sanctions lists change. A customer clean at onboarding may not be clean next month, which is why ongoing screening is a requirement rather than a nicety.
  • No escalation path. Monitoring that flags things nobody reviews is worse than no monitoring, because it documents that you noticed and did nothing.
  • Records that cannot be retrieved. "We have it somewhere" is not record keeping. The test is producing a specific customer's file quickly on request.
  • Assuming the provider covers your obligations. They cover the card programme's. Your own regulatory position is still yours.

Data protection sits alongside all of this

KYC requires collecting exactly the kind of data privacy regimes care most about. The two obligations pull in opposite directions — one says keep records, the other says minimise and delete — and the resolution is usually a documented retention policy with a lawful basis.

Practically: encrypt identity data at rest, restrict who can read it, log access, and never put it somewhere it will end up in an application log. On ON5, cardholder profile fields are encrypted at rest and the platform logs redact sensitive fields globally, so a stray object logged during debugging cannot leak them.

A minimum viable posture

If you are launching on a network and want to be defensible without building a compliance function:

  1. Know which duties the network performs and get that in writing.
  2. Document your own position: what data you hold, why, on what lawful basis, for how long.
  3. Keep the identity data you do hold encrypted and access-controlled.
  4. Have a written process for a cardholder complaint and for a law enforcement request. Both will happen.
  5. Review it when you change what you offer. A programme that grows into new geographies or customer types has changed its risk profile whether or not anyone noticed.

Frequently asked questions

What compliance obligations does a card programme have?

Four recur in almost every regime: knowing and verifying your customers, screening them against sanctions lists, monitoring transactions for suspicious activity, and keeping retrievable records. Who performs them depends on the model.

Do I need a compliance officer to issue cards?

For a sponsored programme, yes — a named in-house compliance function is normally required before launch. On a card issuing network you are a customer of a programme rather than its operator, so the card programme itself does not require one, though your own regulatory obligations remain.

Who performs KYC on a card issuing network?

The network, as part of operating the programme. Your own obligations — data protection, consumer duties, sector-specific rules — are unaffected.

Is one-time sanctions screening enough?

No. Sanctions lists change, so screening must be ongoing rather than only at onboarding.

Issue your first card on ON5

Fund an account with USDT or USDC and issue a branded Visa or Mastercard virtual card. The minimum is $5.

Open the dashboard

Related reading