Liveness detection is often confused with face recognition, credited with absolute protection against forgeries, or tied to a nonexistent legal requirement. We break down the precise definition from the ISO/IEC 30107 standard, how liveness detection differs from the broader concept of presentation attack detection, how active mode differs from passive, where the technology sits in the customer verification chain, and what its real limitations are.
KYT (Know Your Transaction) isn't a statutory term and isn't a FATF requirement — it's the industry name for the practice of ongoing transaction monitoring. We break down how KYT differs from KYC and AML, how the path from a transaction to a specialist's decision works, which signs raise a transaction's risk, what the Travel Rule actually requires, and how it relates to Russia's 115-FZ.
The federal law on the platform economy will take effect on 1 October 2026. Operators of intermediary digital platforms included in the register will be required, when concluding a contract, to check information about partners and order pickup point owners — against a closed list and within timeframes that depend on the method the operator chooses. We break down who the new rules affect, exactly what will be checked, and what needs to be ready before 1 October.
Checking a counterparty by its tax ID confirms the company exists — and tells you almost nothing beyond that. It doesn't tell you who actually controls the business, whether the person signing the contract is authorized to do so, or whether the company is headed for removal from the register. We break down what to check and in what order before a deal, who is legally required to do it and who isn't, and why you won't find the ultimate beneficial owner in any Russian public registry.
In everyday use, “face recognition” can mean anything from unlocking a phone to finding a person in a crowd — even though these are tasks of very different complexity, with different accuracy levels and different error risks. We break down how a system actually gets from a frame to a result, how face detection differs from face recognition, why accuracy can’t be captured in a single percentage, and where this technology is genuinely used — not just in banks.
The Unified Biometric System is often confused with a specific bank’s own biometrics, with paying by face at checkout, or with any other recognition system. In reality, the EBS is a distinct piece of state infrastructure with its own law, operator, and rules. We break down what it actually is, how to enroll in it, where it’s actually used, and how it differs from the commercial biometric systems businesses build for themselves.
“Financial monitoring,” “AML/CFT,” “115-FZ,” “mandatory control,” and “suspicious transaction” are often blurred together into one vague topic, even though they are distinct concepts with different rules and different consequences for a business. We break each one down separately: what the state actually controls, exactly whom 115-FZ obligates, how the formal mandatory-control threshold differs from the substantive indicators of a suspicious transaction, and what this system looks like inside a company.
Onboarding a company is not the same as onboarding an individual. Behind every legal entity stands a chain of ownership, directors, founders, and ultimate beneficiaries, each of whom must be identified and checked against sanctions, PEP, and reputational databases.
A KYB check (Know Your Business) is a set of procedures by which an organization establishes the legal standing, ownership structure, and reputation of a corporate customer or counterparty. Unlike KYC, where the object is an individual, KYB is directed at a legal entity and all persons associated with it: directors, founders, authorized signatories, and ultimate beneficiaries.
The practical goal of KYB is to form a substantiated judgment: does the company exist de facto, does it operate lawfully, who stands behind it, and what risks does interacting with it carry. Without this judgment it is impossible to assign the customer a risk level, to fulfill the requirements of Federal Law 115-FZ and the FATF Recommendations, or to protect one's own business from regulatory and financial consequences.
International onboarding requires screening customers against three sanctions regimes at once — OFAC, the EU, and the UK. Each of them maintains its own lists, sets its own ownership thresholds, and interprets the concept of control differently. An error at any stage — incomplete input data, a missed alias, an unaccounted-for chain of beneficiaries — results either in a false positive that slows down the funnel or in a missed real match, for which the regulator will hold you liable under a strict-liability regime. This article provides a concrete order of actions: which data to collect, where to look for records in the SDN, the EU consolidated list, and the UK Sanctions List, how to apply the 50 percent rule in each jurisdiction, and how to document an alert decision so that it withstands an audit.
Up to 95% of alerts in AML screening turn out to be false — each of them takes up the compliance team's time, slows down onboarding, and reduces conversion without adding real protection. In this article we break down how to configure thresholds, filtering rules, and escalation logic to cut the volume of manual reviews by tens of percent, preserve the speed of customer passage, and not raise regulatory risk.
Customer identification is completed in seconds, but it is precisely after it that the chain of checks begins that determines whether this customer will become a source of a regulatory fine or a safe business partner. Sanctions screening, PEP checks, and risk profiling use the data collected at the KYC stage to determine whether the customer is connected to restrictive lists, public authority, or other factors of elevated risk — and what level of control to apply to them. Below we break down how each of these stages is arranged after identification, what data flows into them, by what algorithms decisions are made, and why continuous monitoring turns a one-time check into an ongoing process, without which the compliance loop loses relevance within a few days.
A fintech company that falls under Federal Law 115-FZ is obliged to build a full-fledged KYC and AML loop — from customer identification to submitting information to Rosfinmonitoring. In practice, the main difficulty lies not in the requirements of the law itself but in implementing them without an avalanche of manual reviews that paralyzes the compliance team even at a few thousand customers. Here we break down what the minimum loop under Federal Law 115-FZ consists of, how to automate KYC at onboarding and AML monitoring during service, and which engineering solutions make it possible to scale compliance without a proportional increase in headcount.