Airwallex logo

Compliance and risk overview

Understand the compliance framework for connected accounts, what Airwallex handles on your behalf, and what your platform is responsible for implementing.

Copy for LLMView as Markdown

Compliance is central to connected accounts. Compliance requirements vary by account capability: most withdrawal and full connected account flows require identity verification before full activation, while some platforms may use deferred identity verification or ledger-account models with lighter upfront checks. Ongoing compliance monitoring continues throughout the account's life. Understanding the compliance framework before you build helps you design an integration that handles verification smoothly, responds correctly to compliance events, and meets your platform's regulatory obligations.

Division of responsibility

Airwallex holds the financial services licenses and operates the compliance infrastructure. Airwallex contracts with your platform, making your platform the entity responsible for operating within Airwallex's compliance requirements. Your customers interact with financial services through your product—Airwallex has no direct relationship with them.

In practice, this means:

  • Airwallex defines the compliance requirements and runs the verification and screening processes.
  • Your platform collects the required information from your customers and submits it through the API.
  • Airwallex makes the compliance determination and informs you of the result via webhooks.
  • Your platform manages the customer experience around compliance events—communicating status, collecting additional information when requested, and routing customers through appropriate flows.

Onboarding verification

All connected accounts—both Business and Individual—require onboarding verification, also known as Know Your Customer (KYC). This is the process of verifying the account holder's identity in compliance with regulatory requirements. Airwallex also conducts Anti-Money Laundering (AML) screening and sanctions screening as part of onboarding.

For Individual accounts, the required information typically includes:

  • Full name, date of birth, and residential address.
  • Government-issued identification document.
  • Contact information (phone number and email address).

For Business accounts, the required information typically includes:

  • Business registration details and registration documents.
  • Information for beneficial owners and controllers (name, date of birth, address, and government-issued ID for each individual owning 25% or more of the business).
  • Business contact information.

The specific requirements vary by market. See the individual and business verification requirement pages for country-specific details.

Payment activation verification

Business accounts that will accept payments from end customers as the Merchant of Record require additional payment activation verification. This process—also referred to as Know Your Business (KYB) verification—verifies the business entity itself, its ownership structure, and its legitimacy to accept payments.

Payment activation verification is required when connected accounts will accept card payments or other payment methods from end customers, operating as the Merchant of Record in a marketplace or SaaS context. Business accounts using only treasury capabilities do not require payment activation verification. The applicable KYB requirements also depend on the payment gateway model.

For business accounts requiring payment activation verification, you'll collect:

  • Business registration documents.
  • Business address and contact information.
  • Beneficial ownership information (individuals owning 25% or more of the business).
  • Business type, industry, and expected transaction volumes and amounts.

Identity verification and deferred IDV

Identity verification (IDV) is the process of confirming that an individual is who they claim to be—typically by comparing a submitted identity document against a live selfie or biometric check. IDV is required for Individual accounts and for beneficial owner information collected as part of Business account onboarding.

Deferred identity verification

If enabled for your platform, deferred identity verification allows you to create accounts and let customers begin transacting before they provide complete identity documentation. Full identity verification is required once the account reaches transaction thresholds that Airwallex specifies.

Deferred IDV is designed for high-volume consumer use cases where onboarding friction is a concern and the risk profile can be managed within transaction limits. It is available for Hosted Flow, Embedded Component, and Native API integrations.

See Deferred identity verification for implementation details.

Ongoing compliance: Requests for Information

After an account is onboarded, compliance monitoring continues. Airwallex may issue a Request for Information (RFI) to request additional documentation or clarification at any point in the account's life. RFIs can arise for several reasons, including:

  • Submitted documents have expired or are insufficient.
  • Additional identity verification is needed.
  • Business details require clarification.
  • Transaction patterns trigger a compliance review.

Airwallex issues three primary types of RFIs for connected accounts:

RFI typeTrigger
Onboarding verification RFIAdditional identity verification required during or after onboarding
Payment Enablement RFIAdditional information needed to activate or maintain payment acceptance capability
Transaction RFICompliance review triggered by transaction patterns or activity

RFIs are normal and expected. They are not a sign of a problem with your platform or your customer—they are part of the ongoing compliance process. Design your integration to handle RFIs programmatically, so your customers can resolve them without requiring support intervention.

AML and sanctions screening

AML and sanctions screening are performed by Airwallex on an ongoing basis, not just at onboarding. Airwallex's compliance systems monitor transactions and account activity against international sanctions lists and AML indicators throughout the account's life. Your platform does not need to implement its own AML or sanctions screening; this is handled by Airwallex as part of the compliance infrastructure.

Platform compliance obligations

While Airwallex handles the compliance infrastructure, your platform has obligations too. You are responsible for:

  • Collecting accurate information from your customers and submitting it faithfully to Airwallex.
  • Implementing the user experience for onboarding verification flows.
  • Responding to RFIs in a timely manner by collecting and submitting the requested information.
  • Designing your platform's product to support compliance events—account suspension, capability restrictions, and information requests.
  • Ensuring that your platform does not facilitate activity that circumvents Airwallex's compliance processes.
Was this page helpful?