From the outside, a payment hold looks arbitrary: the same kind of transfer you've made twenty times, suddenly "under review." From the inside, that hold is the visible edge of a layered system that examined the payment in milliseconds, compared it to everything it knows about your account, and concluded — this once — that a human should look. This article walks through those layers, what actually triggers them, and the harder problem underneath: keeping the system suspicious enough to matter and quiet enough to live with.

Layer one: sanctions and watchlist screening

Every payment's parties are screened against sanctions lists, politically-exposed-person registers, and adverse-media databases — before anything else happens, with no exceptions and no thresholds. This is the one layer where a platform has zero discretion: a true sanctions match doesn't get a judgment call.

Almost everything this layer stops, however, is not a true match. Screening uses fuzzy matching — it must, because sanctioned parties don't spell their names helpfully — and fuzzy matching over millions of payments means common names collide with listed ones constantly. These false positives are typically resolved in seconds to hours by comparing dates of birth, countries, and identifiers already in your verified file. Which points at something useful: the completeness of your verification file is what speeds up your worst screening day.

Layer two: rules and thresholds

The second layer runs deterministic rules: amounts above defined levels, velocity (many payments in a short window), patterns that resemble structuring — amounts hovering just under reporting thresholds — first-time counterparties in higher-risk corridors, rapid pass-through where funds arrive and leave almost immediately.

Rules are blunt on purpose. They exist to guarantee that certain patterns are never missed, and they accept false positives as the price. A legitimate business having its best sales week ever can look, to a velocity rule, like an account being drained. Which is why rules don't act alone.

Layer three: the behavioural profile

This layer is the reason two identical payments can have different outcomes on two different accounts. At onboarding, every account declares an expected profile — activity, volumes, counterparty types, corridors — and monitoring continuously compares actual behaviour against it. A €50,000 payment is unremarkable on an account that declared six-figure monthly flows and alarming on one that declared five; a first crypto conversion is expected on an account that stated crypto exposure and an anomaly on one that didn't.

This is also the layer you have the most influence over. Most behavioural alerts are not suspicious activity — they're outdated profiles. The business grew, added a corridor, took on a new supplier type, and never told anyone. Monitoring then does exactly its job: it notices that reality no longer matches the file.

The single most effective thing you can do Update your declared profile before the change hits your account — new markets, bigger volumes, new counterparty types, planned large one-offs. Five minutes of notice converts a would-be anomaly into expected behaviour, and expected behaviour clears in seconds.

Layer four: what a human actually does

A payment that trips the layers above lands with an analyst, whose job is narrower than people imagine: not "is this business suspicious?" but "does this specific payment have a plausible explanation consistent with this specific account?" They look at the account's history, the counterparty, the declared profile, and the flagged pattern. Most reviews end right there, in clearance, without you ever knowing they happened.

When the picture is incomplete, you get an RFI — a request for information, usually asking for the document that makes the payment self-explanatory: the invoice, the contract, the loan agreement. An RFI is not an accusation; it's the fastest path back to cleared. The single best response is a specific document, sent quickly — the payment holds until the question is answered, and the clock is on your side of the table.

Reviews end one of four ways: cleared (the overwhelming majority), cleared after RFI, returned to sender, or — rarely — reported to the financial intelligence unit. On that last one, a legal fact worth knowing: platforms are prohibited by law from telling you a report was filed. It's called tipping off, and it's why questions about specific holds sometimes receive answers that feel incomplete. They're not evasive; they're legally constrained.

The calibration problem — and what we won't publish

Anyone can build monitoring that catches everything: flag every payment. Anyone can build monitoring nobody notices: flag nothing. The entire craft is in between, and it's a moving target, tuned through feedback — every false positive an analyst clears teaches the system what normal looks like for accounts like yours, narrowing future alerts. Fresh profiles feed the same loop: risk-based calibration only works when the "expected" it calibrates against is current.

One thing you won't find here or anywhere on this site: the actual thresholds and rules. Publishing them would hand a routing map to precisely the actors the system exists to catch — structure at threshold-minus-one, pace transfers under the velocity rule. Every serious platform keeps this layer opaque, and the honest trade is the one this article tries to make instead: full transparency about how the system works, deliberate opacity about the exact numbers inside it.

The signals, summarised

What firedWhat it usually meansTypical resolution
Name screening matchA common-name collision with a watchlist entrySeconds to hours, using identifiers already on file
Amount or velocity rulePayment size or frequency outside the rule's bandAutomatic clear if consistent with profile; brief review if not
Profile deviationActivity the account never declared — often just growthFast after an RFI; instant if the profile was updated in advance
Pattern flag (structuring, pass-through)A shape that matches known typologiesManual review; documentation resolves the legitimate cases

Monitoring is easy to experience as friction and easier still to resent. But it's the same machinery that keeps this platform's banking and liquidity partners willing to serve crypto-touching businesses at all — the alternative to monitored accounts isn't unmonitored accounts; it's closed ones. The system runs best when both sides do their part: we keep the false positives falling, and you keep the file current.

This article is for general information only and is not financial, legal, or tax advice. Product availability, fees, and features depend on verification, account type, jurisdiction, and applicable regulatory requirements, and may change over time.