Compliance is the new payments rail

April 16, 2026

Table of contents

cover

When a cross-border stablecoin payment fails or stalls, the instinct is to look at the rails. Wrong network. Wrong provider. Wrong corridor. The infrastructure is the problem. In most cases, it is not. The infrastructure moved the value. What stopped it was a missing piece of counterparty information, a sanctions screening flag, a KYB process that had not been completed, or a Travel Rule message that the receiving platform did not support. The payment did not fail because the rails broke. It failed because the compliance layer did not have what it needed to let the payment through.

This distinction matters more than it might appear. A business that frames its payment friction as an infrastructure problem will keep switching providers looking for a better rail. A business that understands it has a compliance problem will invest in the layer that is actually blocking the flow. The two problems have different solutions, different costs, and very different trajectories as regulatory requirements tighten. TrustLinq’s 2026 analysis of bank freezes on crypto-linked transfers is direct on this point: transfers are being delayed, reviewed, or frozen more frequently than ever, and in the majority of cases the cause is compliance systems in banks and correspondent networks, not the underlying legality of the funds.

What the Compliance Layer Actually Does to a Payment

A B2B stablecoin payment does not travel in a straight line from sender to recipient. It passes through a compliance checkpoint at every point where it touches a regulated institution, and in a mixed fiat/crypto flow, it touches several. Each checkpoint requires data, and if the data is missing or flagged, the payment stops.

KYB onboarding at the provider level. Before a business can send or receive payments through any regulated provider, it has to complete a Know Your Business verification, submitting corporate documents, ownership structures, beneficial ownership information, and in many cases source-of-funds documentation. For crypto-native businesses with complex entity structures, offshore incorporations, or multi-jurisdiction footprints, this process is materially longer and more document-intensive than for conventional businesses. Until it is complete, the payment rails are closed. The rail is not the constraint. The onboarding is.

Sanctions screening at every hop. Every transaction is screened against sanctions lists: OFAC in the US, consolidated lists in the EU, and equivalent regimes in other jurisdictions. Screening applies to the sending business, the receiving business, the wallet addresses involved, and in many systems the onchain history of the funds being moved. As KYC-Chain’s 2025 compliance guide documents, modern screening tools use fuzzy matching to catch aliases and near-matches, which raises false positive rates and triggers manual reviews. A false positive does not mean the funds are frozen permanently. It means they are frozen until a human has reviewed the case, gathered documentation, and cleared it, a process that can take days to weeks depending on the complexity of the match and the responsiveness of the institutions involved.

The Travel Rule and missing metadata. The Financial Action Task Force’s Travel Rule requires that originator and beneficiary information travel alongside cryptocurrency transactions above a defined threshold, the same way wire transfer information travels with bank payments. The rule has been implemented in the EU through the Transfer of Funds Regulation, and in major hubs including the UK, Singapore, and Hong Kong. FATF updated the rule in June 2025, with full implementation across remaining jurisdictions expected by 2030. The operational consequence of uneven implementation is concrete: when the sending and receiving platforms are in different regulatory regimes, one may require Travel Rule data that the other is not yet set up to provide. According to Notabene’s 2025 State of Crypto Travel Rule report, the share of platforms blocking withdrawals until beneficiary information is confirmed grew from 2.9 percent to 15.4 percent in a single year, a 431 percent increase. Nearly 20 percent of platforms now return deposits when originator data is missing. These are not edge cases. They are the operating norm for a growing share of cross-border flows.

Correspondent bank compliance in fiat legs. Many crypto-to-fiat flows ultimately pass through SWIFT and correspondent banking networks, each of which applies its own risk rules independently of the originating bank. A transfer can clear the originating institution’s compliance checks and still be frozen by an intermediary correspondent that applies stricter criteria or has less appetite for crypto-adjacent flows. The sender typically receives a generic compliance rejection code with no detail about where in the chain the block occurred or how to resolve it.

The Cost of Getting This Wrong

The direct cost of compliance infrastructure for a small to mid-sized crypto payments business is substantial. CoinLaw’s 2025 analysis of regulatory costs puts the average annual compliance spend for firms in this category at around $620,000 — up approximately 28 percent year on year — covering staff, tooling, licensing, legal, and audits. That figure is likely to continue rising as Travel Rule requirements tighten and stablecoin issuers face bank-equivalent compliance obligations under frameworks like the US GENIUS Act.

The indirect cost is harder to quantify but often larger. Every payment that stalls in a compliance review is a delayed supplier settlement, a missed payroll window, or a customer whose funds are frozen with no clear explanation. Every KYB process that takes weeks instead of days is a business relationship that cannot transact during that window. Every false positive sanctions hit is a finance team member spending hours on documentation instead of running the business. Under the GENIUS Act, permitted stablecoin issuers are now treated as financial institutions under the Bank Secrecy Act, subject to full anti-money-laundering and sanctions obligations. That means compliance requirements flow not just from the provider a business chooses but from the stablecoin itself.

At many crypto payments companies, compliance teams represent a meaningful share of total headcount — in some cases double-digit percentages — significantly higher than in traditional businesses of equivalent size. That is not a sign of over-investment in compliance. It is a sign of how much operational weight the compliance layer currently carries.

Where the Gaps Are Widest

The compliance bottleneck is not uniform. It concentrates in specific scenarios that are predictable and worth designing around.

Cross-border flows between uneven regulatory regimes. A payment from a platform in a Travel Rule-compliant jurisdiction to one in a non-compliant jurisdiction creates a data gap that neither side can fully bridge with current tooling. TRM Labs’ analysis of Travel Rule implementation globally identifies the major financial hubs as broadly compliant, but implementation outside those hubs remains uneven. The corridors with the most compliance friction are often the same corridors with the most compelling economic case for stablecoin payments: emerging markets with expensive traditional rails and fast-growing digital asset adoption.

Transactions involving self-hosted wallets. The Travel Rule was designed around flows between regulated platforms — Virtual Asset Service Providers, or VASPs — where both sides of a transaction have compliance infrastructure in place. Payments involving self-hosted or unhosted wallets fall into a grey zone: the regulated platform must collect information about the wallet owner, but there is no standardised mechanism for doing so at scale. This creates friction on every transaction that touches a self-hosted wallet, which for many crypto-native businesses is a significant share of their payment flows.

Stablecoin-to-fiat hybrid payments. A business using stablecoins to pay a supplier who receives fiat is, in compliance terms, executing a crypto-to-fiat conversion that triggers both crypto compliance requirements at the stablecoin leg and traditional payment compliance requirements at the fiat leg. Both sets of requirements apply simultaneously. The compliance infrastructure on either side was typically not built with the other in mind, which is why hybrid payments generate disproportionate compliance overhead relative to their complexity.

Compliance as Infrastructure, Not Overhead

The businesses that have solved this share a specific architectural choice: they treat compliance as part of the payment infrastructure, not as a separate function that sits beside it. That distinction changes how compliance is built, how it is staffed, and how it performs under transaction volume.

In practice, it means compliance checks run before transaction execution, not after. Sanctions screening happens in real time, at the point of payment instruction, not during a batch review the following morning. Travel Rule data is collected and transmitted as part of the payment flow itself, not as a separate step that can be skipped or delayed. KYB onboarding is risk-tiered and automated for standard cases, with manual review reserved for genuinely complex situations. The compliance architecture that regulators now expect — continuous transaction monitoring, real-time screening, automated suspicious activity reporting — is also the architecture that makes a payment system fast rather than slow, because it catches problems before they become freezes rather than after.

The alternative is a compliance function that reviews transactions after they have already been submitted, catching problems too late to prevent freezes, generating manual workload from false positives, producing audit trails reconstructed after the fact. That is not a compliance problem. It is an architecture problem that shows up as compliance cost.

The direction of travel is clear. MiCA, the GENIUS Act, FATF’s ongoing Travel Rule rollout, and the treatment of stablecoin issuers as financial institutions are all moving toward the same standard: compliance requirements for crypto payments converging toward what has long applied to traditional banking. The businesses that build compliance infrastructure capable of meeting those standards will find that their payment rails work reliably. The ones that treat compliance as overhead to minimise will find that their rails work in test and fail in production.