2022-11-24

Added · Updated

Transaction monitoring requirements for account information services (service 8)

Account information service providers (AISPs) must monitor transactions conducted by customers to prevent money laundering and terrorist financing, as required by Section 3(2) of the Anti-Money Laundering and Anti-Terrorist Financing Act. Monitoring must be risk-based, utilizing aggregated data from multiple sources to identify unusual features such as transactions involving high-risk jurisdictions, large sums without economic rationale, or patterns suggesting threshold evasion. The intensity of monitoring varies with the number of applicable risk factors, allowing for less intensive measures for AISPs compared to traditional banks due to the lower inherent risk of the service.

De Nederlandsche Bank logo

Netherlands

De Nederlandsche Bank

Click to view thumbnail

Q&A

Read aloud

Question:

Do account information service providers (AISPs) have to perform transaction monitoring?

Published: 24 November 2022

On 1 March 2021, the European Banking Authority (EBA) published the final revised Guidelines on money laundering and terrorist financing (ML/TF) risk factors . The EBA has included new ML/TF risk factors. We have amended these Q&As on the basis of the revised Guidelines.

Answer:

Pursuant to Section 3(2) of the Anti-Money Laundering and Anti-Terrorist Financing Act (Wet ter voorkoming van witwassen en financieren van terrorisme – Wwft), AISPs must monitor transactions conducted by their customers 1 to prevent their services from being used for money laundering or terrorist financing.

The Financial Supervision Act (Wet op het financieel toezicht - Wft) defines an account information service as:

“an online service for providing consolidated information on one or more payment accounts held by a payment service user with one or more other payment service providers”.

These service providers fall under the Wwft pursuant to Section 1a(1) of that act. We qualify the risks of money laundering and terrorist financing inherent in this specific type of service provider as low. This is because an AISP does not conduct any transaction itself or hold any funds for a payment service user. Nevertheless, AISPs have aggregated data from multiple sources at their disposal, providing opportunities for monitoring transactions that are related to money laundering or terrorist financing. Even when the data received is limited on an aggregated level, it provides additional possibilities for identifying specific patterns that can be used to detect unusual transactions. Accordingly, the low risk inherent in this type of payment institution means that it has to take less far-reaching measures in terms of customer due diligence and transaction monitoring than institutions with an elevated risk.

Information available to an AISP

Under PSD2, banks are not required to share all available data with an AISP. The requirement relates to information that the bank shares with the account holder. The exact data depends on the bank's policy. As a result, the information the account information service provider receives is of a varied and dynamic nature. Information from bank A may be different to that from bank B. The data used by the AISP for transaction monitoring can therefore differ from one bank to another. We require AISPs to take appropriate measures to identify and assess the risk of money laundering and terrorist financing related to their services, taking into account all data available for with payment service users have given their explicit consent.

Risk factors

Using the information from the payment service provider offering the account, it will be possible for the AISP to monitor transactions between linked accounts and transactions to third parties, taking at least the following risk factors into account:

The customer receives funds from, or sends funds to, jurisdictions associated with higher ML/TF risk or from/to someone with known links to those jurisdictions.

The customer connects payment accounts held at multiple account servicing payment service providers.

The customer connects payment accounts held in the name of multiple persons in more than one jurisdiction.

The customer transfers funds from different payment accounts to the same payee that, together, amount to a large sum without a clear economic rationale.

The customer receives funds in different payment accounts from the same payer that, together, amount to a large sum without a clear economic rationale.

The customer receives funds in different payment accounts from the same payer that give the AISP reasonable grounds to suspect that the customer is trying to evade specific monitoring thresholds.

The customer transfers funds from different payment accounts to the same payee that give the AISP reasonable grounds to suspect that the customer is trying to evade specific monitoring thresholds.

Further risk factors that can be considered:

The number of transactions per period

Amounts that differ from the transaction pattern

The currency of each transaction

The value of the transaction

The transaction volume per period

The number of accounts that are connected

The banks where these accounts are held The number of banks whose accounts are connected

Connected payment accounts held in a country in the European Economic Area (EEA) could contribute to a lower risk.

Conclusion

Pursuant to Section 3(2) under d of the Wwft, AISPs must monitor transactions conducted between accounts connected by the customer in the account overview for unusual features. They must also monitor transactions to and from third parties for unusual features. These are mostly subjective indicators, such as deviating amounts, unusual frequency of payments, multiple payment accounts to and from which funds are sent and received, and the absence of logic or economic rationale underlying transactions. Transaction monitoring processes must always be risk-based. The foregoing warrants the conclusion that monitoring must be of a higher intensity as more risk factors apply. Conversely, the fewer risk factors apply, the lower the intensity of transaction monitoring can be.

The above also means that an institution where a customer holds a bank account, and also links its accounts to accounts at other institutions (where account information on these linked accounts is transmitted), may apply less intensive monitoring in its role as an AISP than that applied to the customer's bank account held at the institution. After all, as a bank it is directly involved in the execution of transactions over this account. In its role as an AISP, however, the institution is expected to include all the information made available to it (i.e. including account information provided by a third party) in its assessment of the customer's money laundering and terrorist financing risk because of its central knowledge of all accounts in the context of its service.

[1]Section 1(1) of the Wwft defines a customer as the natural or legal person with which a business relationship is entered into or on whose behalf a transaction is conducted.

Transaction monitoring requirements for payment initiation services (service 7)

Customer due diligence requirements for payment initiation services (service 7)

Due diligence requirements for account information services (service 8)

Discover related articles

Q&A

Integrity & sanctions

Payment institutions

Share:

Share on LinkedIn

Share on X

Share on Facebook

Share via Email

Interesting articles

De Nederlandsche Bank publishes ‘Integrity Supervision in Focus 2026’

25 June 2026

News item supervision

In the third edition of ‘Integrity Supervision in Focus’ (ISF), we share the key insights from our integrity supervision.

Read more De Nederlandsche Bank publishes ‘Integrity Supervision in Focus 2026’

News item supervision

25 June 2026

DNB email on technical adjustments

25 June 2026

News item supervision

This week, you may receive an email from De Nederlandsche Bank (DNB). This email concerns technical adjustments required to continue corresponding with DNB by email.

Read more DNB email on technical adjustments

News item supervision

25 June 2026

Update FATF-warning lists June 2026

23 June 2026

News item supervision

FATF released an update of its ‘grey’ and ‘black’ lists.

Read more Update FATF-warning lists June 2026

News item supervision

23 June 2026

Banks and payment institutions are actively combating payment fraud but could adopt a more targeted approach

03 June 2026

News item supervision

Payment fraud has a significant impact on society. We therefore consider the management of external payment fraud to be an important topic, as secure and reliable payment systems are central to our public mandate, as emphasised in our Payments Strategy 2026-2028.

Read more Banks and payment institutions are actively combating payment fraud but could adopt a more targeted approach

News item supervision

03 June 2026

Necessary cookies

To ensure the proper operation of the website, De Nederlandsche Bank (DNB) uses functional cookies and analytics cookies, and has taken measures to ensure that these cookies have little or no impact on the privacy of website users.

Optional cookies

Some pages include embedded content from external websites. These websites may use proprietary (tracking) cookies. This allows third parties to track visitor statistics, show personalised content and display targeted ads, for example.

You can make your choice about allowing these optional cookies both when you first visit the website and when you navigate to a page with embedded content.