July's regulatory updates show merchant onboarding becoming more complex and more interconnected. Regulators are expanding AML/CTF obligations, preparing for emerging payment models, and placing greater emphasis on risk-based decision-making throughout the merchant lifecycle. While the topics vary, the direction is consistent: merchant onboarding needs to become more dynamic, adaptable, and resilient as regulatory expectations continue to evolve.
In this update (for merchant onboarding and compliance teams):
What changed: New FATF findings on virtual asset risks, updated FINTRAC jurisdiction guidance, the UK's evolving cryptoasset regime and consultation on tokenized and agentic payments, the ECB's digital euro pilot, Australia's Tranche 2 AML/CTF reforms, Scams Prevention Framework and A2A Payments Vision, and stronger beneficial ownership transparency requirements in ADGM.
Why it matters: Together, these developments expand the scope of merchant onboarding beyond traditional identity and business verification. Payment providers are increasingly expected to understand how merchants operate, which payment methods they support, where risks originate, and how those risks change over time.
Regulatory signals: Wider AML/CTF perimeters, closer scrutiny of virtual asset and stablecoin exposure, and greater expectations around jurisdiction and ownership transparency are reshaping merchant onboarding. Regulators increasingly expect firms to verify key information at onboarding, keep it current, monitor material changes over time, and use it to drive risk-based decisions.
What to do next:
- Review onboarding processes to ensure they can adapt to evolving regulatory obligations across different merchant types and jurisdictions.
- Prepare onboarding workflows for emerging payment models, including digital assets, stablecoins, tokenized payments, and account-to-account payments.
- Strengthen risk-based decision-making through ongoing monitoring, flexible workflows, and proportionate due diligence.
- Monitor upcoming consultations, pilots, and implementation timelines to ensure onboarding processes remain aligned with emerging requirements.
🌍 Global
Initiative name: FATF 7th Targeted Update on Virtual Assets and VASPs
Effective date: 16 July 2026
Issued by: Financial Action Task Force (FATF)
Applies to: Financial institutions, PSPs, VASPs, stablecoin issuers, and merchant onboarding/compliance teams assessing crypto-adjacent or virtual asset-related customer risk.
Summary:
- What: FATF's 7th Targeted Update (16 July 2026) found that while more countries are introducing virtual asset regulations, many are still struggling to implement, supervise, and enforce them effectively.
- Why: Criminal networks continue to exploit gaps in virtual asset regulation, using increasingly sophisticated methods to support fraud, sanctions evasion, and money laundering.
- What's Next: Under the UK FATF Presidency, priority actions include stronger risk-based supervision and enforcement, better implementation of the Travel Rule, greater international cooperation, and closer attention to risks involving stablecoins, offshore VASPs, unhosted wallets, and DeFi arrangements.
Key changes:
- Travel Rule legislation adoption rose to 83% of surveyed jurisdictions, up from 73% in 2025, though enforcement action against non-compliance remains limited in most cases.
- The proportion of surveyed jurisdictions reporting VASP licensing or registration in practice declined from 65% in 2025 to 58% in 2026, despite continued progress in establishing regulatory frameworks.
- The number of jurisdictions prohibiting VASPs increased from 20% in 2025 to 23% in 2026.
- A new risk emerged when a criminal network launched its own stablecoin designed to resist freezing, after more than USD 29 million linked to the group was frozen by another issuer.
- AI-enabled fraud is newly flagged as a cross-cutting risk, with deepfakes and synthetic identities used to recruit and defraud victims.
What this means for merchant onboarding teams:
Merchant onboarding teams should expect identity fraud and business impersonation attempts to become more difficult to detect as AI-enabled fraud continues to evolve. This increases the importance of verifying both the business and the people behind it, rather than relying solely on submitted documents or point-in-time checks.
For merchants operating in higher-risk industries, onboarding teams may also need enhanced due diligence and ongoing monitoring to identify changes in licensing, ownership, or risk profile after onboarding.
Recommended actions:
- Verify a VASP's actual jurisdiction of operation during onboarding, not just its claimed licensing status.
- Review identity verification controls to reduce the risk of AI-enabled fraud, including deepfakes and synthetic identities.
- Apply enhanced due diligence for merchants operating in higher-risk industries or jurisdictions.
- Implement ongoing monitoring for changes in licensing, jurisdiction, ownership, or risk profile after onboarding, rather than relying on point-in-time verification alone.
How OnBoard helps:
OnBoard helps merchant onboarding teams respond to FATF's recommendations by strengthening merchant verification, supporting risk-based due diligence, and enabling ongoing monitoring for higher-risk businesses.
- Automated KYB and business verification helps onboarding teams verify a merchant's jurisdiction, licensing, and registration status against trusted global data sources, supporting stronger due diligence for higher-risk businesses.
- OnBoard AIQ™ reads and extracts data from onboarding documents in real time, flagging inconsistencies that may indicate fraud or require additional review before a merchant is approved.
- AIQ SiteScanner™ analyzes merchant websites for risk signals, including activity that does not align with the merchant’s declared business model, supporting stronger assessment of virtual asset-related businesses.
- Ongoing Customer Due Diligence (OCDD) monitors onboarded merchants across more than 80 checks and alerts teams when a VASP’s licensing status, jurisdiction, ownership, or risk profile changes after approval.
- Customizable risk workflows automatically trigger enhanced due diligence and escalation based on predefined rules for merchants exposed to offshore VASPs, unhosted wallets, stablecoin issuers, or other higher-risk virtual asset activity.
Source: FATF
🇺🇸 United States
Regulatory Plan: U.S. Treasury 2026 Regulatory Plan and the Unified Agenda
Effective date: Agenda released July 2026; individual rulemakings due between July 2026 and December 2027, per the timeline listed.
Issued by: U.S. Department of the Treasury, via the White House Office of Management and Budget’s 2026 Regulatory Plan and Unified Agenda
Applies to: Banks, financial institutions, PSPs, and merchant onboarding/compliance teams tracking upcoming US financial crime rulemakings.
Summary:
- What: The U.S. Treasury released its 2026 Regulatory Agenda, outlining upcoming FinCEN and financial crime rulemakings, including the finalization of beneficial ownership reporting rules and proposed special measures involving foreign financial institutions.
- Why: To provide a dated roadmap of the administration’s financial crime priorities, following an already active year of AML/CFT program and stablecoin issuer compliance proposals.
- What’s Next: Beneficial ownership rule and the MBaer Merchant Bank special measure are listed for anticipated final action in July 2026, with further rulemakings on CDD, whistleblowers, and virtual currency mixing expected through 2027.
Key Changes:
- FinCEN is expected to finalize its beneficial ownership reporting rule following the March 2025 interim final rule (IFR), which removed beneficial ownership reporting requirements for domestic reporting companies and U.S. persons while retaining reporting obligations for foreign reporting companies.
- Foreign reporting companies must continue reporting beneficial ownership information (excluding U.S. persons) to FinCEN and comply with the updated filing deadlines until the final rule is issued.
- FinCEN has proposed a special measure under Section 311 of the USA PATRIOT Act that would identify MBaer Merchant Bank AG as a financial institution of primary money laundering concern.
- The proposal would require U.S. financial institutions to prohibit correspondent accounts for, or on behalf of, MBaer, take reasonable steps to prevent transactions involving MBaer through foreign correspondent accounts, and apply special due diligence to guard against such transactions.
What this means for merchant onboarding teams:
The Treasury's Regulatory Agenda gives merchant onboarding teams an early indication of potential AML/CFT rulemaking priorities and implementation timelines. The final beneficial ownership reporting rule may influence the information collected during KYB, while the proposed Section 311 special measure reinforces the importance of ongoing screening for higher-risk financial institutions.
These planned rulemakings reinforce the value of onboarding processes that can adapt data collection, screening, and decisioning rules as requirements change, without requiring a full workflow redesign.
Recommended actions:
- Monitor the final MBaer Merchant Bank AG special measure this month and screen for any related merchant correspondent relationships immediately upon designation.
- Track the final beneficial ownership reporting rule to understand its scope and any changes to the beneficial ownership information required during KYB.
- Review onboarding processes for foreign reporting companies to ensure beneficial ownership information is collected and maintained in line with the final rule.
- Prepare onboarding workflows for upcoming AML/CFT and Customer Identification Program (CIP) requirements for stablecoin issuers as additional rulemakings are finalized.
- Build flexibility into onboarding processes now so new regulatory requirements can be implemented quickly without redesigning existing workflows.
How OnBoard helps:
OnBoard supports merchant onboarding in the US with flexible policy-driven workflows that adapt as AML/CFT, beneficial ownership, and customer identification requirements change.
- Automated KYB and beneficial ownership verification collects, verifies, and validates beneficial ownership information in real time, helping teams keep pace with evolving reporting requirements.
- PEP and Sanctions Screening screens merchants and related entities against sanctions lists and high-risk designations in real time, helping identify potential risks before onboarding decisions are made.
- Customizable risk workflows dynamically adapt data collection, screening, and decisioning rules based on changing regulatory requirements, without rebuilding onboarding workflows from scratch.
- Ongoing Customer Due Diligence (OCDD) continuously monitors merchant risk profiles after onboarding, automatically identifying changes that may require further review or action.
Source: Office of Management and Budget
🇨🇦 Canada
Advisory: FINTRAC FATF-Aligned Advisory on High-Risk Jurisdictions
Effective date: 15 July 2026 (advisory), reflecting FATF's 19 June 2026 plenary outcomes
Issued by: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada) and the Department of Finance Canada
Applies to: All Canadian reporting entities under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, including banks, MSBs, payment processors, and fintechs.
Summary:
- What: FINTRAC republished its FATF-aligned advisory following the June 19, 2026 FATF plenary, updating high-risk and grey-listed jurisdictions and reaffirming binding Ministerial Directives for Canadian reporting entities.
- Why: The changes require reporting entities to ensure their jurisdiction risk assessments and customer due diligence processes reflect the latest FATF classifications and FINTRAC guidance.
- What's Next: Reporting entities must apply the measures required under applicable Ministerial Directives and FINTRAC guidance, including mandatory treatment for DPRK and Iran and risk-based measures for other listed jurisdictions.
Key changes:
- Bosnia and Herzegovina and Iraq were added to FATF's list of jurisdictions under increased monitoring.
- Algeria and Namibia were removed from the grey list after addressing identified AML/CFT deficiencies.
- DPRK and Iran remain subject to mandatory countermeasures, including high-risk treatment of all transactions regardless of amount.
- Reporting entities must continue assessing transactions linked to Myanmar for suspicious activity and incorporate geographic risk into customer risk assessments.
- Iran's directive was reaffirmed and strengthened, with new counter-measures introduced building on the October 2025 statement.
- Existing FINTRAC guidance and Ministerial Directives covering Russia, Islamic State-controlled jurisdictions, Afghanistan, and the Middle East remain in effect.
What this means for merchant onboarding teams:
Changes to FATF jurisdiction classifications can quickly affect how merchant risk should be assessed. Merchant onboarding teams should regularly review jurisdiction risk settings and due diligence controls to ensure higher-risk relationships receive the appropriate level of scrutiny while existing merchant risk profiles remain aligned with the latest regulatory guidance.
Recommended actions:
- Update jurisdiction risk ratings to reflect Bosnia and Herzegovina and Iraq's addition to the FATF grey list.
- Review existing merchants and beneficial owners affected by the latest jurisdiction updates to confirm current risk classifications remain appropriate.
- Apply mandatory, no-threshold high-risk treatment to any transaction connected to DPRK or Iran, regardless of amount.
- Apply enhanced due diligence measures appropriate to each higher-risk jurisdiction, including identity verification, customer due diligence, and geographic risk assessments where required.
- Assess correspondent banking relationships for exposure to sanctions evasion risk tied to DPRK or Iran.
- Maintain clear audit records showing how updated jurisdiction risk was assessed, escalated, and approved during onboarding.
How OnBoard helps:
OnBoard helps merchant onboarding teams keep jurisdiction risk assessments, due diligence, and onboarding controls aligned with the latest FINTRAC guidance and FATF classifications.
- Smart Forms dynamically adapt the onboarding experience based on a merchant's responses, collecting the right information upfront to support accurate jurisdiction risk assessments and ensure downstream due diligence processes begin with complete, structured data.
- Automated KYB and beneficial ownership verification identifies indirect links to high-risk jurisdictions through ownership structures, correspondent relationships, or related parties.
- PEP & Sanctions Screening checks merchants and beneficial owners against more than 200 global sanctions lists and watchlists, helping teams identify relationships subject to mandatory or enhanced controls.
- Ongoing Customer Due Diligence (OCDD) continuously re-screens onboarded merchants as jurisdiction risk classifications change, flagging exposure that emerges after approval.
- Audit-ready reporting maintains a clear record of jurisdiction risk assessments and due diligence decisions to support regulatory review.
Source: FINTRAC
🇬🇧 United Kingdom
Research and Policy Update: FCA Structure of UK Cryptoasset Markets
Effective date: Research paper published July 2026; new cryptoasset regime rules (PS 26/9–13) already finalized, with applications window opening later in 2026.
Issued by: Financial Conduct Authority (FCA)
Applies to: Cryptoasset firms (custody providers, stablecoin issuers, trading platforms, intermediaries) and merchant onboarding/compliance teams assessing crypto-adjacent merchants.
Summary:
- What: The FCA published research on the structure of UK cryptoasset markets alongside five final policy statements (PS26/9–PS26/13) setting out key elements of the new authorization and regulatory regime for cryptoasset firms.
- Why: To support its Cost Benefit Analysis of the new cryptoasset regulatory regime and explain how consumers and firms engage with crypto products ahead of full authorization.
- What's Next: Firms undertaking specified cryptoasset activities will need FCA authorization under the new regime. Authorized firms will remain subject to applicable financial crime obligations, although separate MLR registration requirements will change under the new framework. Systemic stablecoins will face joint FCA and Bank of England oversight once recognized by HM Treasury.
Key changes:
- Firms undertaking specified cryptoasset activities, including cryptoasset custody and stablecoin issuance, will require FCA authorization under the new regime.
- Once authorized under the new regime, cryptoasset firms will no longer need to separately register under the MLRs, although they will remain subject to MLR requirements and other relevant financial crime legislation.
- Systemic stablecoins used widely in payments will face joint oversight by the Bank of England and FCA, once recognized by HM Treasury.
- New Admission and Disclosure Regime (PS 26/9) introduces mandatory disclosures for issuers admitting tokens to trading on UK platforms.
What this means for merchant onboarding teams:
Although these reforms do not directly change merchant onboarding processes, they do change how cryptoasset firms should be assessed during onboarding. As the new FCA regime is introduced, authorization will become an increasingly important regulatory status to verify for eligible cryptoasset businesses.
Merchant onboarding teams should begin preparing to incorporate FCA authorization into their KYB and compliance reviews while continuing to verify AML and financial crime obligations. Organizations onboarding cryptoasset firms, particularly stablecoin issuers, should also monitor the rollout of the new regime as additional regulatory requirements take effect.
Recommended actions:
- Update KYB checks to verify FCA authorization status for cryptoasset firms, rather than relying solely on MLR registration checks.
- Continue verifying compliance with AML and financial crime obligations, noting that FCA-authorized firms will no longer require separate MLR registration.
- Review onboarding checklists for cryptoasset merchants to ensure they reflect the new FCA authorization requirements for regulated activities, including custody and stablecoin issuance.
- Prepare onboarding workflows for increased volume of crypto-adjacent merchant applications as stablecoin payment adoption grows.
- Track HM Treasury's designation of "systemic" stablecoins, as this will determine which issuers face additional Bank of England oversight.
How OnBoard helps:
OnBoard supports merchant onboarding in the UK with configurable, risk-based workflows that incorporate FCA authorization, regulated activities, and financial crime requirements for cryptoasset firms.
- Automated KYB and business verification checks a merchant's FCA authorization and registration status against available regulatory data, reducing manual checks and supporting more consistent regulatory-status assessment.
- Customizable risk workflows identify higher-risk cryptoasset activities, automatically route those applications for additional review, and support straight-through processing for lower-risk cases.
- Ongoing Customer Due Diligence (OCDD) continuously monitors crypto merchants for changes in authorization or regulatory status after onboarding.
- Smart Forms capture structured information about a merchant's cryptoasset activities during the application process, ensuring onboarding teams collect the information needed to support accurate risk assessments and downstream compliance workflows.
Source: Financial Conduct Authority
Consultation: HM Treasury Modernizing Payment Services Regulation
Effective date: Consultation published 14 July 2026, closing 6 October 2026; any resulting changes to be implemented via secondary legislation following the consultation.
Issued by: HM Treasury
Applies to: Payment institutions, e-money institutions, banks, PSPs, ASPSPs, PISPs, AISPs, and any firm authorized or registered under the PSRs and EMRs in the UK.
Summary:
- What: HM Treasury consulted on a major overhaul of the Payment Services Regulations 2017 (PSRs) and Electronic Money Regulations 2011 (EMRs), covering tokenized payments, agentic payments, and a new Open Banking framework.
- Why: The current regime predates blockchain and AI-driven payments, and the Government wants the UK to lead in tokenized deposits, stablecoins, and agentic commerce.
- What's Next: Consultation runs 12 weeks, closing 6 October 2026, before secondary legislation implements any changes to the payment services framework.
Key changes proposed:
- UK-issued stablecoins backed under the new article 9M RAO regime would be treated as "money-like" and brought into the payments perimeter, distinct from other cryptoassets.
- Firms would need to seek a variation of permission from the FCA before offering tokenized payment services alongside existing fiat services.
- The regulated activity of "issuing payment instruments or acquiring payment transactions" would be split into two separate activities.
- A new right of access is proposed for Variable Recurring Payments, giving PISPs the ability to lodge standing payment mandates with Account Servicing Payment Service Providers (ASPSPs).
- The consultation explicitly asks how authentication, consent, and liability rules need to change to safely support agentic AI-initiated payments.
What this means for merchant onboarding teams:
If these reforms proceed, PSPs may need to identify the payment services merchants intend to use during onboarding, particularly where tokenized payment services, UK-issued qualifying stablecoins, or Variable Recurring Payments are involved. Onboarding teams may also need to confirm that the required FCA permissions are in place before enabling these payment services.
Recommended actions:
- Track the consultation and its October 2026 close date, as any changes will flow through to onboarding requirements through secondary legislation.
- Review whether your existing FCA permissions would support tokenized payment services.
- Assess whether your merchant onboarding process is ready to support tokenized payment services, UK-issued qualifying stablecoins, and Variable Recurring Payments.
- Identify any onboarding workflows that may need updating if the proposed reforms are implemented.
- Consider submitting a consultation response if reforms would materially affect your onboarding or payment processing model.
How OnBoard helps:
OnBoard supports merchant onboarding in the UK with configurable workflows that help payment providers introduce new payment services and regulatory permissions while maintaining consistent governance across existing payment rails.
- Smart Forms dynamically adapt onboarding questions and requirements based on merchant inputs, allowing PSPs to introduce new payment services or regulatory requirements without rebuilding every onboarding form or disrupting existing onboarding journeys.
- Automated Decision Engine can route applications based on configurable business rules, helping onboarding teams manage exceptions as new payment services and regulatory requirements are introduced.
- OnBoard AIQ™ reads and validates onboarding documents in real time, helping teams keep pace as data requirements evolve alongside the regulatory framework.
- Ongoing Customer Due Diligence (OCDD) monitors relevant merchant data and risk indicators after onboarding, helping teams identify changes in payment methods, business activity, or risk profile where that information is available.
- Audit-ready reporting maintains a clear record of onboarding decisions and data captured, supporting defensibility as new rules on liability and authentication take shape.
Source: HM Treasury
🇪🇺 European Union
Pilot: European Central Bank (ECB) Digital Euro Innovation Platform
Effective date: Announced 14 July 2026; pilot to run for 12 months starting in the second half of 2027.
Issued by: European Central Bank (ECB), in coordination with 19 Eurosystem national central banks.
Applies to: Payment service providers (banks and non-banks) participating in the pilot as distributing or acquiring PSPs, and merchant onboarding teams preparing for eventual digital euro acceptance.
Summary:
- What: The ECB selected 36 PSPs from over 50 applicants to participate in the digital euro pilot, testing beta digital euro functionality starting H2 2027.
- Why: To test technical functionality, operational processes, and user experience ahead of a potential digital euro issuance, with strong market interest reflected in applicant volume.
- What's Next: Selected PSPs will work with national central banks and the ECB to prepare for the 12-month pilot, involving both distributing and acquiring roles.
Key changes:
- 36 PSPs selected from over 50 applicants, spanning both banks and non-bank providers across diverse business models and sizes.
- Selected participants include Adyen, Stripe, Worldline, Nexi, Revolut, and SumUp, reflecting participation from a broad mix of bank and non-bank payment service providers.
- Two distinct PSP roles: distributing PSPs (giving users beta digital euro accounts) and acquiring PSPs (enabling merchants to accept payments), with some playing both.
- Pilot will run across the ECB and 19 national central banks, covering Belgium, Germany, Estonia, Ireland, Greece, Spain, France, Croatia, Italy, Cyprus, Latvia, Lithuania, Luxembourg, Netherlands, Austria, Portugal, Slovenia, Slovakia, and Finland.
- Merchant acceptance is explicitly in scope, covering e-commerce and physical point-of-sale, including Software Point of Sale and mobile payments.
- Pilot will use a beta version functionally close to the digital euro but without legal tender status.
- Pilot scheduled to start in the second half of 2027, running for a 12-month period.
What this means for merchant onboarding teams:
While this announcement does not directly affect how payment providers onboard merchants today, it signals a broader shift toward refining the user experience and operational processes that support digital euro acceptance.
As the pilot progresses, PSPs can use the lessons learned to understand how emerging payment methods can be introduced with minimal friction. Delivering a seamless end-to-end merchant onboarding experience, from onboarding through to payment acceptance, will become increasingly important as new payment methods are introduced and merchant expectations continue to evolve.
Recommended actions:
- Check the ECB's dedicated digital euro pilot webpage for progress updates and key learnings throughout the 12-month pilot.
- Review how emerging payment methods could affect your end-to-end merchant onboarding and payment acceptance experience over time.
- Identify opportunities to make your merchant onboarding journey more flexible as new payment methods and payment experiences emerge.
- Track the pilot’s findings and any subsequent policy decisions that could affect merchant acceptance requirements or PSP participation.
How OnBoard helps:
OnBoard helps PSPs adapt merchant onboarding to new payment methods and acceptance models while maintaining consistent governance across the merchant lifecycle.
- End-to-end merchant onboarding brings digital onboarding, KYB, AML screening, underwriting, and ongoing due diligence (OCDD) together in one system, giving PSPs a governed foundation for introducing digital euro acceptance and other emerging payment methods.
- Smart Forms dynamically adapt onboarding journeys based on merchant responses, allowing PSPs to introduce new payment methods or requirements while maintaining a frictionless end-to-end merchant experience.
- Management by Exception automatically routes applications requiring additional review, allowing low-risk merchants to move through onboarding faster while teams focus on the applications that need attention.
- OnBoard AIQ™ extracts and validates onboarding documents in real time, reducing manual effort and helping deliver a faster, more consistent onboarding experience for merchants.
- Automated KYB, KYC, and AML checks verify merchants through configurable compliance workflows that adapt as payment services and regulatory requirements evolve, without adding unnecessary friction to the onboarding journey.
Source: European Central Bank
🇦🇺 Australia
Regulatory Reforms: Australia's AML/CTF Reforms
Effective date: 1 July 2026 (in force); enrolment deadline for newly regulated businesses is 29 July 2026.
Issued by: AUSTRAC (Australian Transaction Reports and Analysis Centre)
Applies to: Newly regulated sectors including real estate, conveyancing, legal services, accounting, and precious metals and stones businesses, together with remittance and virtual asset service providers subject to separate enrollment and registration requirements.
Summary:
- What: Australia's Tranche 2 AML/CTF reforms took effect 1 July 2026, bringing thousands of new businesses (including real estate, legal, accounting, and precious stones/metals) under AUSTRAC regulation for the first time.
- Why: To strengthen Australia's anti-money laundering and counter-terrorism financing framework by closing regulatory gaps in previously unregulated sectors.
- What's Next: Newly regulated businesses must enrol with AUSTRAC by 29 July 2026; those providing remittance or virtual asset services must both enrol and register.
Key changes:
- Real estate, conveyancing, legal services, accounting, and precious stones/metals businesses are now regulated under AML/CTF laws for the first time.
- Newly regulated businesses must implement AML/CTF programs, conduct customer due diligence, report suspicious matters, and keep records.
- All newly regulated businesses must enrol with AUSTRAC by 29 July 2026.
- Businesses providing remittance or virtual asset designated services face a higher bar, requiring both enrolment and registration.
- Updated threshold transaction report and suspicious matter report forms are now live in AUSTRAC Online, supporting a more risk-based reporting framework.
What this means for merchant onboarding teams:
As more Australian business sectors become regulated under AML/CTF laws, merchant onboarding teams must be prepared to support a broader range of compliance requirements without slowing the onboarding experience. This increases the importance of flexible onboarding processes that can identify different merchant types early and apply the appropriate verification and compliance checks from the start.
Recommended actions:
- Review merchant onboarding workflows to ensure they can support businesses with different AML/CTF obligations.
- Update merchant segmentation and risk rules to correctly identify newly regulated business types during onboarding.
- Verify AUSTRAC enrolment and registration where required as part of merchant due diligence.
- Maintain flexible onboarding processes that can adapt to evolving regulatory requirements without creating unnecessary friction for merchants.
- Monitor future AUSTRAC guidance as the Tranche 2 reforms continue to be implemented.
How OnBoard helps:
OnBoard helps streamline merchant onboarding in Australia by verifying AUSTRAC compliance status without slowing down applications from newly regulated sectors.
- Automated KYB, KYC, and AML checks verify business information and beneficial owners, and screen merchants against relevant AML requirements through configurable workflows that adapt to evolving AUSTRAC obligations.
- OnBoard AIQ™ extracts and classifies merchant information and supporting documentation, helping onboarding teams identify business activities that may fall within Australia's expanded AML/CTF regime and require further review.
- Customizable risk workflows allow payment providers to seamlessly update onboarding workflows, risk appetite, and due diligence requirements as new industries become regulated under AUSTRAC's AML/CTF framework, without disrupting existing merchant onboarding journeys.
- Ongoing Customer Due Diligence (OCDD) monitors changes in merchant information, regulatory standing, ownership, and risk indicators after onboarding, helping teams identify when further due diligence may be required.
- AML On Demand provides specialist support for onboarding merchants in newly regulated sectors or other complex cases where additional AML expertise is required.
Source: AUSTRAC
Framework: Australian Government Scams Prevention Framework (SPF)
Effective date: 1 July 2026 (AFCA authorized as EDR scheme); AFCA membership required by 1 September 2026; complaint handling begins 31 March 2027.
Issued by: Australian Financial Complaints Authority (AFCA), under the Scams Prevention Framework Act
Applies to: Banks, telecommunications providers, and digital platforms operating in Australia, with merchant onboarding teams assessing these sectors' compliance readiness.
Summary:
- What: AFCA became the authorized external dispute resolution scheme for scam complaints under Australia's new Scams Prevention Framework (SPF), effective 1 July 2026, initially covering banking, telecommunications, and digital platforms.
- Why: Australians lost over $2.74 billion to scams in 2023, with 65% of victims receiving no refund, prompting world-first legislation placing scam-prevention obligations on banks, telcos, and digital platforms.
- What's Next: Regulated entities must become AFCA members by 1 September 2026 (applications open now), though AFCA won't handle actual complaints until 31 March 2027.
Key changes:
- AFCA is now the single, authorized EDR scheme for SPF scam complaints across banking, telecommunications, and digital platforms.
- Regulated entities must become AFCA members by 1 September 2026, with applications open from 1 July and encouraged by 14 August.
- Regulated entities now face new legal obligations to prevent, detect, report, disrupt, and respond to scam activity, with consequences for non-compliance.
- A multi-regulator model (ACCC, ASIC, ACMA) plus an intelligence-sharing system will now coordinate scam responses across industry and government.
- Sector-specific Codes and AFCA Rules will be finalised between July and September 2026, defining the detailed scam prevention obligations and complaint handling requirements for regulated businesses.
- Complaints involving multiple organizations across sectors can now be considered together, rather than handled separately by each firm.
What this means for merchant onboarding teams:
Although the SPF primarily applies to designated banks, telecommunications providers, and digital platforms, it reinforces the importance of identifying fraud and scam exposure early when onboarding in-scope merchants, partners, or service providers.
Traditional onboarding processes that rely on manual reviews, disconnected systems, and fragmented data make it harder to detect fraudulent merchants, identify emerging risks, and respond consistently to evolving regulatory expectations.
Recommended actions:
- Review merchant onboarding processes to identify manual steps, fragmented data, or disconnected systems that may limit fraud detection and risk visibility.
- Monitor the final Sector Codes and AFCA Rules as they are published, as these will define the detailed scam prevention obligations for regulated sectors.
- Evaluate whether existing fraud controls and risk workflows can adapt to evolving scam prevention expectations across regulated industries.
- Use the implementation period before 31 March 2027 to strengthen internal fraud prevention and operational readiness where appropriate.
How OnBoard helps:
OnBoard supports merchant onboarding in Australia by helping payment providers collect and assess relevant fraud, governance, and regulatory-readiness information for merchants or partners operating in SPF-designated sectors.
- Automated KYB centralizes business verification and risk information, giving onboarding teams greater visibility into merchant risk from the start.
- Customizable risk workflows enable payment providers to adapt onboarding and risk processes as scam prevention expectations evolve, without redesigning existing workflows.
- OnBoard AIQ™ helps reduce manual review by extracting and validating merchant information from supporting documents, improving consistency across onboarding.
- Ongoing Customer Due Diligence (OCDD) monitors changes in merchant risk indicators after onboarding, helping teams identify information that may require further fraud or compliance review.
- AML On Demand gives payment providers access to experienced compliance specialists who can carry out additional onboarding, AML, and enhanced due diligence work for merchants or partners in SPF-designated sectors, without adding pressure to internal teams.
Source: Australian Financial Complaints Authority
Initiative name: Australia's Account-to-Account (A2A) Payments Vision
Effective date: Vision released 8 July 2026; roadmap development now underway, with no implementation timeline yet published.
Issued by: A2A Payments Roundtable (AusPayNet, Australian Payments Plus, Reserve Bank of Australia, and Commonwealth Treasury)
Applies to: Banks, payment service providers, fintechs, merchants, and other stakeholders in Australia's account-to-account payments ecosystem.
Summary:
- What: The A2A Payments Roundtable (AusPayNet, AP+, RBA, and Treasury) released its finalized vision for Australia's account-to-account payments system after public consultation.
- Why: A2A payments underpin millions of daily transactions, and the vision aims to guide future development amid rapid technology change, rising fraud/cyber threats, and shifting user expectations.
- What's Next: Focus shifts to developing the A2A payments roadmap, defining deliverables, implementation timelines, and governance, with structured stakeholder input mechanisms already established.
Key insights:
- The vision defines five outcomes for A2A payments: safe, reliable, affordable, easy to use, and inclusive.
- The vision identifies six characteristics for the A2A payments system: secure and protected, highly available and resilient, feature-rich, accessible for providers, commercially viable, and appropriately standardized.
- The vision was finalised following a public consultation, with a summary of feedback and all submissions now published alongside the report.
- Development now shifts to an A2A payments roadmap, covering deliverables, timelines, and governance arrangements.
- Structured mechanisms have been established for banks, PSPs, and other stakeholders to provide ongoing input during roadmap development.
What this means for merchant onboarding teams:
The A2A Payments Vision sets a clear direction for the future of Australia's payments ecosystem. As payment providers work towards faster, more secure, and more connected payment experiences, merchant onboarding will play a much bigger role in delivering those outcomes. The roadmap may still be to come, but the direction of travel is already clear.
For payment providers, the vision is a strategic signal to assess whether existing onboarding systems and data flows can accommodate more connected and standardized payment services as the roadmap develops. The payment providers best positioned for the next generation of A2A payments will be those with onboarding processes that are scalable, connected, and able to adapt as the ecosystem continues to evolve.
Recommended actions:
- Monitor the release of the A2A Payments Roadmap, which will define implementation priorities, timelines, and governance arrangements.
- Assess whether your current merchant onboarding processes can support a more connected, scalable, and standardized payments ecosystem as Australia's A2A capabilities continue to evolve.
- Identify manual processes, disconnected systems, and data silos that could limit your organization's ability to adapt to future payments initiatives.
- Engage with industry consultations and stakeholder feedback opportunities if your organization wants to help shape the future direction of Australia's A2A payments ecosystem.
- Treat the vision as a strategic planning signal, using the roadmap to guide future investment and operational decisions rather than expecting immediate implementation requirements.
How OnBoard helps:
OnBoard supports merchant onboarding in Australia with adaptable workflows that help payment providers respond as the A2A Payments Roadmap and supporting industry standards develop.
- Customizable workflows enable onboarding processes to evolve as the A2A Payments Roadmap is implemented, allowing teams to adapt workflows and business rules without redesigning their onboarding operations.
- OnBoard AIQ™ reduces reliance on manual reviews by extracting, validating, and structuring merchant information, helping teams build more connected and scalable onboarding processes.
- White-label Onboarding allows payment providers to introduce A2A capabilities through acquiring partners, brands, or distribution channels while keeping merchant data, compliance controls, approvals, and reporting centrally governed.
- AML On Demand gives payment providers access to experienced compliance specialists who can carry out additional onboarding and AML work where emerging A2A services introduce new merchant types, payment models, or higher-risk cases, without adding pressure to internal teams.
Source: A2A Payments Roundtable and Reserve Bank of Australia
🇦🇪 United Arab Emirates
Legislative Amendments: Abu Dhabi Global Market (ADGM) Commercial Legislation Amendments
Effective date: 9 July 2026
Issued by: ADGM Registration Authority (RA)
Applies to: ADGM-registered companies, trusts connected to ADGM, DNFBPs (legal, accounting, company service, and real estate businesses), and branches of foreign legal persons registered in ADGM.
Summary:
- What: ADGM Registration Authority published amendments to its commercial legislation strengthening beneficial ownership transparency and AML/CTF oversight, effective immediately upon publication.
- Why: To improve availability of beneficial ownership information, increase transparency of legal persons and arrangements, and support compliance with international AML/CTF standards.
- What's Next: Changes are already in force; affected entities must comply with new disclosure, cash transaction, and beneficial ownership requirements now.
Key changes:
- The public register will now indicate whether a shareholder or director is acting in a nominee capacity, exposing previously hidden ownership arrangements.
- The Registrar gained express powers to request beneficial ownership information relating to trusts connected to ADGM.
- Legal, accounting, company service, and real estate businesses are now prohibited from accepting or distributing cash payments above prescribed thresholds.
- Registered branches of foreign legal persons must now maintain and provide beneficial ownership information relating to their foreign parent entity.
- All changes took effect immediately upon publication, with no transition or grace period provided.
What this means for merchant onboarding teams:
The ADGM amendments reinforce the growing importance of transparency in business ownership by making beneficial ownership information more accessible and strengthening oversight of complex ownership structures. For merchant onboarding teams, this provides greater visibility during KYB and supports a more complete understanding of who ultimately owns and controls a business.
As greater ownership transparency becomes available, it is equally important that this information is verified in real time rather than accepted at face value. Assessing beneficial ownership alongside sanctions, adverse media, AML screening, and other risk indicators helps payment providers move beyond isolated checks and make faster, more informed, trusted onboarding decisions.
Recommended actions:
- Integrate business and beneficial ownership verification into the merchant onboarding workflow.
- Use risk-based workflows to tailor due diligence based on merchant risk and ownership complexity.
- Automate KYB, AML, sanctions, and adverse media checks to support faster onboarding decisions.
- Regularly review your onboarding processes as beneficial ownership and transparency requirements continue to evolve.
How OnBoard helps:
OnBoard helps merchant onboarding teams incorporate ADGM's enhanced beneficial ownership transparency into a more automated, risk-based onboarding process.
- Automated KYB and business verification helps validate merchant information against trusted data sources, supporting greater confidence in beneficial ownership assessments.
- Integrated AML, sanctions, PEP, and adverse media screening provides additional context alongside beneficial ownership information, helping teams build a more complete merchant risk profile.
- OnBoard AIQ™ interprets submitted business and ownership documentation, makes automated verification decisions against predefined rules, and triggers the appropriate next steps based on the outcome, helping providers process complex ADGM merchant applications without unnecessary manual review.
- Customizable risk workflows automatically route merchants with complex ownership structures or foreign entities to the appropriate review teams, while allowing lower-risk merchants to progress through straight-through processing.
- Ongoing Customer Due Diligence (OCDD) helps identify changes to business information and ownership over time, supporting ongoing compliance beyond initial onboarding.
Source: Abu Dhabi Global Market
Cross-market signals for onboarding and compliance teams
July 2026 demonstrates that merchant onboarding is evolving well beyond traditional compliance checks. Regulators are expanding AML/CTF obligations into new industries, increasing oversight of digital assets and emerging payment models, strengthening expectations around ownership transparency, and placing greater emphasis on ongoing, risk-based oversight throughout the merchant lifecycle.
Several common themes emerged this month:
- AML/CTF obligations continue to expand across new industries, business models, and jurisdictions.
- Merchant onboarding is becoming increasingly risk-based, with greater emphasis on ongoing monitoring rather than point-in-time verification.
- Digital assets, stablecoins, tokenized payments, account-to-account payments, and other emerging payment models are driving new onboarding and compliance considerations.
- Greater ownership transparency, jurisdiction risk, and licensing verification are becoming increasingly important when assessing merchant risk.
- Flexible, scalable onboarding processes are becoming essential as payment providers adapt to evolving regulatory expectations without increasing operational complexity.
This month's updates reinforce that merchant onboarding is no longer just about meeting today's regulatory requirements or confirming that individual checks have passed. It is about bringing identity, ownership, regulatory status, payment models, and risk together, giving providers the confidence to make trusted onboarding decisions as payment ecosystems, emerging risks, and compliance obligations evolve.
OnBoard by MVSI supports that approach by bringing digital onboarding, KYB, KYC, AML screening, underwriting, AI-assisted verification, and ongoing due diligence (OCDD) together in one system built for regulated payments, fintech, and financial services.
By combining adaptive data collection, policy-driven decisioning, AI-powered workflow automation, and continuous monitoring, OnBoard helps payment providers build onboarding processes that are scalable, auditable, and able to respond as regulatory expectations change.
This content is provided for general information only and does not constitute legal or regulatory advice.


.png)
_compressed.webp)

