# What is AML?

A plain-language introduction for everyone at Artha — no compliance background needed. It covers what money laundering is, what we have to do about it as a Canadian money services business, how our systems catch it in real time, and why we chose Checkmarble.

> **In one sentence:** Anti-Money Laundering (AML) is the set of laws, checks and systems that stop criminals from using businesses like ours to make dirty money look clean.

## 1. AML in one minute

**Money laundering** is, in FINTRAC's words, *"the process used to disguise the source of money or assets derived from criminal activity."* A drug dealer, a fraudster or a ransomware gang ends up with money they cannot openly spend. Laundering is how they disguise where it came from, so it looks like it was earned honestly.

**Terrorist financing** is the reverse problem. The money may be perfectly clean — a salary, a donation — but it is being sent to *fund* terrorism. FINTRAC describes it as using funds or property *"to encourage, plan, assist or engage in acts of terrorism, where the primary motivation is not financial gain."*

AML (often written **AML/CTF** — anti-money laundering and counter-terrorist financing) covers both.

**Why it matters:** the United Nations Office on Drugs and Crime estimates that **2–5% of global GDP — roughly US$800 billion to US$2 trillion — is laundered every year**. Crypto is attractive to criminals because it moves fast, crosses borders instantly, and can be split across many wallets. That is why platforms like ours are on the front line.

## 2. How laundering works — the three stages

FINTRAC describes laundering in three stages. Real schemes blur them, but the model makes the pattern easy to spot.

```mermaid
flowchart LR
  A["Criminal cash<br/>or stolen crypto"] --> P["1 · Placement<br/>get it into the system"]
  P --> L["2 · Layering<br/>hide the trail"]
  L --> I["3 · Integration<br/>spend it as 'clean'"]
  I --> C["Looks legitimate:<br/>house, car, business"]
```

| Stage | FINTRAC's definition | What it can look like on a crypto platform |
| --- | --- | --- |
| **1. Placement** | *"placing the proceeds of crime in the financial system"* | Many small CAD deposits kept just under reporting limits, or depositing crypto that came straight from a scam or ransomware wallet |
| **2. Layering** | *"converting the proceeds of crime into another form and creating complex layers of financial transactions to disguise the trail and the source and ownership of funds"* | Swapping between coins, bouncing funds through mixers, bridges and dozens of fresh wallets, moving money between accounts that share a device or bank account |
| **3. Integration** | *"placing the laundered proceeds back into the economy to create the perception of legitimacy"* | Cashing out to a bank account and buying property, paying a front company's "invoices", or settling fake merchant sales |

**Our job is to catch it at stage 1 or 2** — before the money leaves our platform looking clean.

## 3. A real-time example — one suspicious customer, step by step

This is an **illustrative scenario** (not a real customer) that walks one person through our actual compliance stack, showing what happens in the seconds after each action.

**Meet "Sam".** Sam opens an account, passes identity checks, and over five days deposits USDT that adds up to about CAD 33,000 — then asks to withdraw everything to a brand-new private wallet.

### What happens every time Sam deposits — in about a second

```mermaid
sequenceDiagram
  participant S as Sam
  participant P as Artha platform
  participant O as Compliance orchestrator
  participant A as AMLBot
  participant M as Checkmarble (Marble)
  participant Q as Alert & case queue
  S->>P: Deposit 9,500 CAD of USDT
  P->>O: Send the transaction event
  O->>A: Where did these coins come from?
  A-->>O: Risk score + exposure (e.g. mixer)
  O->>M: Run the rules (amount, history, risk)
  M-->>O: Decision: Approve / Review / Decline
  O-->>P: Release, hold, or reject the deposit
  O->>Q: If Review or worse → alert for an analyst
  Note over O,M: The 24-hour total and reporting duties are checked every time, whatever the decision
```

### Sam's week, and what each control does

| When | What Sam does | What our systems do | Why |
| --- | --- | --- | --- |
| Sign-up | Uploads a passport and a selfie | **Sumsub** verifies the ID and records the FINTRAC identification method used | Know your client — FINTRAC requires ID verification for crypto transfers and exchanges of $1,000 or more |
| Day 1, 9:00 | Deposits CAD 9,500 of USDT | **AMLBot** checks the sending wallet; **Checkmarble** scores the deposit | Every deposit address is screened before funds are credited |
| Day 1, 18:00 | Deposits CAD 4,000 more | Checkmarble's **24-hour total** reaches CAD 13,500 | $10,000+ in virtual currency within 24 hours = a **Large Virtual Currency Transaction Report (LVCTR)** to FINTRAC within 5 working days — even if nothing is suspicious |
| Day 3 | Deposits CAD 9,800 — AMLBot shows the coins passed through a **mixer** | Deposit is **held for review** | Mixers hide where coins came from — a classic *layering* signal |
| Day 5 | Deposits CAD 9,600 | The **structuring rule** fires: 3+ deposits between CAD 8,000 and 9,999 in 7 days | Staying just under $10,000 on purpose is a classic *placement* signal |
| Day 5 | Asks to withdraw everything to a new self-hosted wallet | Withdrawal is **held**; an **alert** goes to an analyst | Large first transfer to an unhosted wallet |
| Day 6 | — | Analyst opens a **case**, reviews history and sends a polite request for source of funds — **never** mentioning suspicion | "Tipping off" a customer is prohibited |
| Day 7 | Sends vague answers | Analyst concludes there are reasonable grounds to suspect; a second reviewer and the CCO approve | Four-eyes: the person who drafts a report never approves it alone |
| Day 7 | — | **Suspicious Transaction Report (STR)** filed with FINTRAC as soon as practicable; account restricted | An STR has **no minimum amount** and covers attempted transactions too |

Two things beginners often miss:

- **Reporting is not accusing.** An STR says "we have reasonable grounds to suspect". FINTRAC investigates; we don't.
- **Reports are independent.** Filing the STR does **not** replace the LVCTR from Day 1. Both are required.

> **Where we are today:** Sumsub, AMLBot and the Checkmarble rule engine are live. The alert queue, the link into case management, sanctions screening and FINTRAC reporting are being built — see the [Requirements](01-Requirements.md) tab, section 4.

## 4. Real cases — what happens when AML fails

These are real enforcement actions, most of them in Canada. Every one comes down to the basics in this page.

| Who | Penalty | What went wrong |
| --- | --- | --- |
| **Xeltox Enterprises Ltd. (Cryptomus)** — Canadian crypto MSB | **$176,960,190** — FINTRAC, October 2025 (FINTRAC's largest penalty ever) | 1,068 suspicious transactions not reported in a single month (July 2024), linked to child sexual abuse material, fraud, ransomware and sanctions evasion; 1,518 large virtual currency transactions not reported; failed to follow the Ministerial Directive on Iran; weak policies and no proper risk assessment |
| **TD Bank** | **$9,185,000** — FINTRAC, 2024. **About US$3 billion** — United States, guilty plea October 2024 | In the US, about 92% of transaction volume was never put through automated monitoring. Three laundering networks moved over US$670 million through TD accounts, and five employees helped one of them |
| **Binance** | **$6,002,000** — FINTRAC, May 2024 (under appeal). **US$4.3 billion** — United States, November 2023 | In Canada: operated without registering as a foreign MSB and failed to report 5,902 large virtual currency transactions. In the US: pleaded guilty to AML, unlicensed money transmission and sanctions violations |

**The lesson:** regulators don't only punish laundering that happened — they punish **missing controls**. Unfiled reports, unmonitored transactions and missing risk assessments are violations on their own.

## 5. What our Canadian registration means

We are registered with **FINTRAC** (the Financial Transactions and Reports Analysis Centre of Canada) as a **Money Services Business (MSB)** that deals in virtual currency. FINTRAC is Canada's financial intelligence unit and AML supervisor. The law behind it is the *Proceeds of Crime (Money Laundering) and Terrorist Financing Act* (PCMLTFA).

> **"Licence" or "registration"?** We often say "MSB licence", but FINTRAC's own wording is **registration**: *"FINTRAC does not issue licenses or certificates of registration."* Registration must be renewed every 2 years. Use "FINTRAC MSB registration" in anything formal.

### What the registration requires of us

| Obligation | In plain words | Key number |
| --- | --- | --- |
| **Compliance program** | A named Compliance Officer, written policies, a documented risk assessment, ongoing training with a training plan, and an effectiveness review. FINTRAC lists these as six elements; our Requirements document groups them as five pillars | Effectiveness review at least every **2 years** |
| **Know your client** | Verify who customers are before they move meaningful amounts | Crypto transfers or exchanges of **$1,000+** |
| **Record keeping** | Keep identification and transaction records | **5 years**; hand them to FINTRAC within **30 days** of a request |
| **Suspicious Transaction Report (STR)** | Report anything with reasonable grounds to suspect ML/TF — including attempts | **Any amount**, as soon as practicable |
| **Large Virtual Currency Transaction Report (LVCTR)** | Report receiving large amounts of crypto | **$10,000+**, including via the 24-hour rule; within **5 working days** |
| **Large Cash Transaction Report (LCTR)** | Report receiving large cash amounts | **$10,000+**; within **15 calendar days** |
| **Electronic Funds Transfer Report (EFTR)** | Report large international fiat transfers | **$10,000+**; within **5 business days** |
| **Listed Person or Entity Property Report** | Report property of terrorist groups or listed persons | **Immediately** |
| **Travel Rule** | Send the sender's and receiver's name, address and account details with crypto transfers, and look for them on incoming ones | In force since June 2021 |
| **24-hour rule** | Add up same-type transactions within a rolling 24 hours | Totals of **$10,000+** become reportable |
| **Ministerial Directives** | Extra measures for designated countries (currently including Iran) | Reportable **regardless of amount** |

## 6. Future licences — same ideas, different rulebooks

If we expand beyond Canada, the **building blocks stay the same** — identify customers, screen names and wallets, monitor transactions, report suspicion, keep records, apply the Travel Rule. What changes is the **regulator, the report names, the thresholds and the deadlines**.

International standards come from the **FATF** (Financial Action Task Force), the Paris-based *"global money laundering and terrorist financing watchdog"* whose standards more than 200 jurisdictions have committed to. That is why every regime looks familiar.

| | **Canada** (today) | **United States** | **European Union** | **United Kingdom** |
| --- | --- | --- | --- | --- |
| **Regulator** | FINTRAC | FinCEN (federal) + each state | National regulator in each member state | FCA |
| **What you get** | MSB registration | FinCEN MSB registration **plus** a money transmitter licence from each state you operate in | MiCA authorisation as a crypto-asset service provider (CASP) — transition periods ended 1 July 2026 | FCA cryptoasset registration under the Money Laundering Regulations (a new authorisation regime is scheduled for October 2027) |
| **Suspicious report** | STR to FINTRAC | SAR to FinCEN | STR to the national financial intelligence unit | SAR to the National Crime Agency |
| **Travel Rule** | Applies to virtual currency transfers | Transfers of **US$3,000+** | **Every transfer, any amount**; extra ownership checks above €1,000 for self-hosted wallets | In force since 1 September 2023 |

**What this means for how we build:** keep thresholds, report types and deadlines as **configuration per jurisdiction**, not hard-coded logic. A new licence should mean new rules and report formats — not a new platform. Checkmarble scenarios and the compliance orchestrator are designed for exactly that.

## 7. What is Checkmarble?

**Checkmarble** is a Paris-based company (Marble SAS), founded by people who previously ran fraud, AML and compliance at the French fintech Shine. Its product, **Marble**, describes itself as *"the real time decision engine for fraud and AML"* — a platform for transaction monitoring, AML screening and case investigation, built for *"banks, fintechs, crypto exchange and any company moving money."*

### How Marble works

```mermaid
flowchart LR
  D["Our data<br/>customers, accounts,<br/>transactions"] -->|Ingestion API| M["Marble"]
  T["A new transaction"] -->|Decision API| M
  M --> R["Scenarios<br/>rules that add or<br/>subtract risk score"]
  R --> X{"Score vs<br/>thresholds"}
  X --> A1["Approve"]
  X --> A2["Review"]
  X --> A3["Block and Review"]
  X --> A4["Decline"]
  A2 --> C["Case manager<br/>& audit trail"]
  A3 --> C
```

- **Data in.** We send Marble our customers, accounts and transactions through its **Ingestion API**, so rules can look at history — not just one payment.
- **Scenarios.** Compliance builds **rules without writing code**. Each rule adds or subtracts risk score, for example "3+ deposits between CAD 8,000 and 9,999 in 7 days" or "coins came through a mixer".
- **Decisions in real time.** For each transaction our platform calls the **Decision API** and gets an outcome back. Marble's outcomes are **Approve, Review, Block and Review, Decline**. Our Requirements document names three actions — APPROVE, REVIEW, BLOCK — and maps them onto these.
- **Batch runs.** Scenarios can also run on a schedule, to catch slow patterns such as structuring over a week.
- **Case manager and audit trail.** Marble includes a case manager and *"searchable and unalterable"* audit logs. Whether we use it or connect our own case management is open item O-05 in the Requirements.
- **Screening (add-on).** **Marble Screening** checks names against sanctions lists, politically exposed persons and adverse media, using OpenSanctions or LexisNexis data.

## 8. Why Checkmarble?

| Reason | Why it matters to us |
| --- | --- |
| **Already integrated** | The Marble rule engine is live and making decisions today. The remaining work is capturing its output, not replacing it |
| **Self-hosted — data stays with us** | The core product can run on our own infrastructure, so customer data can stay in a Canadian region, as our data-residency requirement expects |
| **Rules the compliance team can change** | The no-code builder lets the compliance team add or tune rules without waiting for an engineering release |
| **Explainable to an examiner** | Rules are versioned — a committed version can't be edited, only one is live at a time — and decisions sit in an unalterable audit trail. We can show exactly which rule made which decision, and when |
| **One platform, one alert stream** | Rules, screening and cases in one place means one audit trail and one queue for analysts, instead of stitching several vendors together |
| **Test before going live** | Scenarios can be run against past data and tested live without affecting customers, so rule changes are evidence-based |
| **Built for crypto and fintech** | Its public customers include fintechs and crypto exchanges, such as CoinSwitch |
| **Actively maintained** | Frequent releases — v1.9.0 on 7 September 2026, about every two weeks before that |

### Honest caveats

- **"Open source" means source-available.** The core is free under the Elastic License 2.0. That licence allows self-hosting, but it is not an OSI-approved open-source licence, and it forbids offering Marble as a service to third parties.
- **Screening is a paid feature.** Marble Screening needs a licence key from Checkmarble, and the sanctions data (OpenSanctions) needs its own commercial licence. Self-hosted screening also needs extra infrastructure (Elasticsearch and OpenSanctions indexing).
- **Not everything is available self-hosted.** Checkmarble's documentation says its AI case-review features are currently for their SaaS customers.
- **Canada is our job, not the vendor's.** Marble doesn't come pre-configured for FINTRAC. Canadian thresholds, lists and reports are ours to configure and prove. A vendor performs a function; it never takes on our obligation.

## 9. Quick glossary

| Term | Meaning |
| --- | --- |
| **AML / CTF** | Anti-money laundering / counter-terrorist financing |
| **FINTRAC** | Canada's financial intelligence unit and AML supervisor |
| **MSB** | Money Services Business — includes businesses dealing in virtual currency |
| **KYC / KYB** | Know Your Customer (people) / Know Your Business (companies) |
| **STR** | Suspicious Transaction Report — any amount, as soon as practicable |
| **LVCTR** | Large Virtual Currency Transaction Report — $10,000+ in crypto |
| **Travel Rule** | Sender and receiver details must travel with a crypto transfer |
| **Structuring** | Splitting money into smaller amounts to stay under reporting limits |
| **Mixer** | A service that pools and shuffles crypto to hide where it came from |
| **Tipping off** | Letting a customer know they are suspected or reported — prohibited |
| **PEP** | Politically Exposed Person — higher risk, needs extra checks |
| **FATF** | Financial Action Task Force — sets the global AML standards |

For the full detail, see the [Requirements](01-Requirements.md) tab.

## Sources

Checked 18 September 2026.

- FINTRAC — money laundering, terrorist financing and the three stages: <https://fintrac-canafe.canada.ca/fintrac-canafe/1-eng>
- FINTRAC — MSB definition: <https://fintrac-canafe.canada.ca/msb-esm/msb-eng>
- FINTRAC — registration is not a licence: <https://fintrac-canafe.canada.ca/msb-esm/reg-eng>
- FINTRAC — compliance program requirements: <https://fintrac-canafe.canada.ca/guidance-directives/compliance-conformite/guide4/4-eng>
- FINTRAC — record keeping for MSBs: <https://fintrac-canafe.canada.ca/guidance-directives/recordkeeping-document/record/msb-eng>
- FINTRAC — LVCTR: <https://fintrac-canafe.canada.ca/guidance-directives/transaction-operation/lvctr/lvctr-eng>
- FINTRAC — Travel Rule: <https://fintrac-canafe.canada.ca/guidance-directives/transaction-operation/travel-acheminement/1-eng>
- FINTRAC — 24-hour rule: <https://fintrac-canafe.canada.ca/guidance-directives/transaction-operation/24hour/1-eng>
- FINTRAC — Xeltox Enterprises (Cryptomus) penalty: <https://fintrac-canafe.canada.ca/new-neuf/nr/2025-10-22-eng>
- FINTRAC — TD Bank penalty: <https://fintrac-canafe.canada.ca/new-neuf/nr/2024-05-02-eng>
- FINTRAC — Binance penalty: <https://fintrac-canafe.canada.ca/new-neuf/nr/2024-05-09-eng>
- US Department of Justice — TD Bank guilty plea: <https://www.justice.gov/archives/opa/pr/td-bank-pleads-guilty-bank-secrecy-act-and-money-laundering-conspiracy-violations-18b>
- US Department of Justice — Binance guilty plea: <https://www.justice.gov/archives/opa/pr/binance-and-ceo-plead-guilty-federal-charges-4b-resolution>
- UNODC — global money laundering estimate: <https://www.unodc.org/unodc/en/money-laundering/overview.html>
- FATF — who we are: <https://www.fatf-gafi.org/en/the-fatf/who-we-are.html>
- FinCEN — MSB registration: <https://www.fincen.gov/resources/money-services-business-msb-registration>
- FinCEN — funds Travel Rule: <https://www.fincen.gov/resources/statutes-regulations/guidance/funds-travel-regulations-questions-answers>
- ESMA — end of MiCA transitional periods: <https://www.esma.europa.eu/sites/default/files/2026-04/ESMA75-113276571-1679_Statement_on_the_end_of_transitional_periods_under_MiCA.pdf>
- European Parliament — EU crypto transfer tracing rules: <https://www.europarl.europa.eu/news/en/press-room/20230414IPR80133/crypto-assets-green-light-to-new-rules-for-tracing-transfers-in-the-eu>
- FCA — cryptoasset registration: <https://www.fca.org.uk/firms/cryptoassets-aml-ctf-regime/cryptoasset-registration-information-applicants>
- FCA — UK Travel Rule expectations: <https://www.fca.org.uk/news/statements/fca-sets-out-expectations-uk-cryptoasset-businesses-complying-travel-rule>
- Checkmarble — Marble on GitHub: <https://github.com/checkmarble/marble>
- Checkmarble — what is Marble: <https://docs.checkmarble.com/docs/what-is-marble>
- Checkmarble — decision outcomes: <https://docs.checkmarble.com/docs/decision-1>
- Checkmarble — scenario versioning: <https://docs.checkmarble.com/docs/versioning>
- Checkmarble — Marble Screening: <https://docs.checkmarble.com/docs/introduction-9>
- Checkmarble — about the company: <https://www.checkmarble.com/about>
