Use a computer

For full performance and fluidity, please open Pay Engineers on a desktop or laptop. On mobile, the experience is limited — especially authenticated sections and advanced tools after login.

Compliance

Regulatory standards and frameworks for payment systems, ranging from card-industry security requirements to regional data protection and open banking directives. Meeting these frameworks is not a one-time certification exercise; most require ongoing evidence collection, monitoring and periodic re-assessment for the life of the platform.

Use in configurator

PCI DSS

The Payment Card Industry Data Security Standard defines the baseline security controls required for any organization that stores, processes or transmits cardholder data, enforced through the card networks rather than a single government regulator. Achieving and maintaining compliance is an ongoing program, encompassing network segmentation, encryption, access control and regular testing, not a document you produce once and file away.

Advantages

Required for any card-handling platform, so compliance directly enables card acceptance and processor relationships; the standard's control requirements are well-documented and battle-tested across the industry, giving clear implementation guidance; scoping strategies like tokenization can significantly reduce the systems that need full controls applied.

Limitations

Certification via QSA assessment or SAQ, and the underlying control implementation, represent a genuinely costly, ongoing program rather than a one-time cost; scope creep from new systems inadvertently touching cardholder data is a common and expensive problem if architecture isn't deliberate about containment; requires continuous evidence gathering such as scans, penetration tests and log reviews year-round, not just before an audit.

Use cases

Any platform storing, processing or transmitting cardholder data; card-present and card-not-present acquiring and issuing systems; third-party vendor risk assessments for card-data-adjacent services.

KYC

Know Your Customer requirements obligate financial institutions to verify the identity of individual customers before establishing a relationship or processing transactions above certain thresholds, as a core defense against identity fraud and financial crime. Requirements vary by jurisdiction and risk tier, but nearly every consumer-facing wallet or payment account needs some form of KYC.

Advantages

Meaningfully reduces identity fraud and impersonation risk in consumer-facing products; well-established regulatory frameworks and vendor ecosystems exist to automate most of the process; builds a foundation of trust that supports higher transaction limits and reduced downstream fraud losses.

Limitations

Onboarding friction from identity checks can measurably reduce conversion if not carefully designed for the specific risk tier; requirements and acceptable document types vary significantly by jurisdiction, complicating multi-market products; ongoing re-verification obligations for periodic refresh add long-term operational cost.

Use cases

Consumer wallet and payment account onboarding; step-up verification for higher transaction limits; periodic customer due diligence refresh cycles.

KYB

Know Your Business extends identity verification principles to corporate entities, verifying company registration, beneficial ownership and the legitimacy of the business before onboarding it as a merchant or partner. This is the primary control preventing shell companies and fraudulent merchants from gaining access to a platform's payment rails.

Advantages

Directly reduces merchant fraud and money-laundering risk by verifying the legitimacy and ownership structure of onboarded businesses; automated registry and beneficial-ownership checks can significantly speed up otherwise manual due diligence; strengthens a platform's overall risk posture for acquirer and card scheme relationships.

Limitations

Document collection for beneficial ownership can be genuinely burdensome for legitimate small businesses, requiring careful UX design to minimize drop-off; verification data quality and registry coverage varies significantly by country, complicating global merchant onboarding; ongoing monitoring for ownership or structure changes adds continuous operational overhead.

Use cases

Merchant and business partner onboarding for PSPs and marketplaces; beneficial ownership verification for acquirer sponsorship; ongoing merchant risk monitoring.

AML

Anti-money laundering regulation requires payment platforms to monitor transactions for suspicious patterns, screen against sanctions and PEP lists, and file suspicious activity reports with regulators when warranted. It is one of the most consistently enforced compliance areas across jurisdictions, with meaningful financial and even criminal liability for institutions that fail to maintain an adequate program.

Advantages

A well-defined regulatory requirement with established frameworks and vendor tooling to support implementation; strong AML programs protect the platform's banking and scheme relationships, which can be jeopardized by regulatory enforcement actions; demonstrates institutional maturity that facilitates partnerships with banks and acquirers.

Limitations

Ongoing transaction monitoring, alert investigation and reporting represent a genuine, continuous staffing and tooling cost, not a one-time setup; false-positive rates in monitoring tools require active tuning to keep investigation workloads manageable; regulatory expectations and typologies evolve, requiring the program to be reviewed and updated regularly.

Use cases

Money transfer and remittance platforms; transaction monitoring and suspicious activity reporting programs; sanctions and PEP screening across onboarding and ongoing relationships.

GDPR

The EU General Data Protection Regulation governs how personal data of EU residents is collected, processed, stored and shared, granting individuals specific rights such as access, erasure and portability, and imposing strict obligations on organizations handling that data, including payment platforms processing customer and transaction information. Non-compliance carries some of the highest potential fines of any data protection framework globally.

Advantages

Provides a clear, well-documented framework for data protection practices, reducing ambiguity about what 'good' data handling looks like; compliance builds genuine customer trust, particularly in European markets where data protection awareness is high; the discipline it enforces, such as data minimization and purpose limitation, often improves overall data architecture quality.

Limitations

Requires meaningful ongoing process and legal overhead, including data mapping, subject access request handling and breach notification procedures, not a one-time technical fix; potential fines for serious violations are among the highest of any data protection regime globally, raising the stakes of getting it wrong; cross-border data transfer rules add complexity for platforms operating outside the EU.

Use cases

Any platform processing personal data of EU residents; customer data subject rights request handling; cross-border data transfer compliance for EU operations.

PSD2

The EU's second Payment Services Directive established the regulatory framework for open banking, requiring account-holding banks to provide regulated third parties API access to account information and payment initiation, and mandating Strong Customer Authentication for most electronic payments. It fundamentally reshaped how European payment institutions are licensed and how checkout authentication flows are designed.

Advantages

Open banking access requirements have created substantial new product opportunities such as account information and payment initiation services beyond traditional card rails; standardized Strong Customer Authentication requirements have measurably reduced card fraud rates across the EU since implementation; the licensing framework for payment and e-money institutions is well-established with clear application processes.

Limitations

Strong Customer Authentication requirements add checkout friction that must be carefully designed, using exemptions where legitimately applicable, to avoid unnecessary conversion loss; API and technical standard implementation requires genuine engineering investment; licensing and passporting processes across EU member states involve real regulatory lead time.

Use cases

EU-licensed payment and e-money institutions; open banking account information and payment initiation services; SCA-compliant checkout flow design.

3-D Secure

3-D Secure is the cardholder authentication protocol, now predominantly version 2, used to verify a cardholder's identity during an online card transaction, typically via a one-time code, biometric confirmation or risk-based frictionless authentication. It also shifts fraud liability from the merchant to the issuing bank when correctly applied, making it both a fraud-prevention and a commercial risk-management tool.

Advantages

Meaningfully reduces card-not-present fraud when properly implemented; shifts fraud liability from the merchant to the card issuer in most successful authentication scenarios, directly protecting merchant margin; version 2's risk-based frictionless flow authenticates many low-risk transactions without any visible customer challenge at all.

Limitations

Poorly implemented or overly conservative configurations introduce checkout friction that can measurably hurt conversion, sometimes outweighing the fraud-reduction benefit; issuer-side authentication reliability varies, and some legitimate transactions still fail authentication unnecessarily; requires ongoing integration maintenance as card schemes update protocol versions and requirements.

Use cases

E-commerce card-not-present checkout flows; PSD2 SCA compliance for EU card transactions; high-risk transaction step-up authentication.