KYT and AML in payments: what gets checked, why it stalls
KYT screens every payment, not just the identity behind the account, which is why a transaction can stall even after the account is fully verified.
KYT (Know Your Transaction) is the continuous monitoring that screens every payment, not just the identity of whoever sends it, and it is the reason a transaction can be held even when the account is already verified. A payment leaves a company's account, moves normally, and then sits pending with no obvious explanation. The finance team checks that the beneficiary details are correct, that the account is fully verified, and that there is no visible error, yet the payment does not clear right away. What is happening behind the scenes is not a technical glitch: it is transaction monitoring doing its job.
In Soulbit Academy we explain what KYT (Know Your Transaction) is, how it differs from the identity checks a company already passed when it opened its account, which specific signals every payment is screened against, and what a finance team can do so its transactions move without unnecessary friction. The goal is not to dodge monitoring, which is mandatory and protects the company itself, but to understand how it works so it does not get triggered by accident.
What KYT is and how it differs from KYC and KYB
KYT, Know Your Transaction, is the ongoing monitoring of an account's transactional behavior, distinct from the identity checks that KYC and KYB perform when an account opens. KYC (Know Your Customer) confirms who an individual is; KYB (Know Your Business) confirms who a company is and who controls it. Both happen once, or get refreshed periodically. KYT happens on every payment, every day, for as long as the account stays active.
The practical difference is that KYC and KYB answer an identity question: is this person or company who they claim to be? KYT answers a different question: does this payment, at this moment, at this amount, going to this destination, match the account's expected behavior? A company can have a perfectly up to date KYB file and still trigger a KYT alert if, for example, it starts sending payments to a country it never transacted with before.
Does KYT replace KYC and KYB?
No. KYT complements identity verification rather than replacing it. A company that already cleared its KYB verification, the document process covered in the KYB checklist for opening an account and in what is KYB, still has every one of its payments screened by transaction monitoring afterward. These are two separate control layers, and neither one substitutes for the other.
Which sanctions lists and PEP checks a KYT engine runs on every payment
A KYT engine screens the sender and the recipient of every payment against sanctions lists from the United Nations, the European Union, and the US Office of Foreign Assets Control (OFAC), and checks both against politically exposed person databases. This screening runs automatically, in seconds, before the payment reaches its destination.
A politically exposed person, or PEP, is someone who holds or held a senior public office (a minister, a mayor, a senior military officer, or an executive at a state owned company), or a close family member or known associate of that person. Being flagged as a PEP does not mean a payment is illicit; it means it warrants extra review, because the structural risk that a public position gets used to move funds of irregular origin is higher.
| Signal a KYT engine checks | What it evaluates | What triggers an alert |
|---|---|---|
| Sanctions lists | Whether the sender or recipient matches a sanctioned entity | A name, alias, or entity that appears on UN, EU, or OFAC lists |
| Politically exposed persons | Whether either party holds or has ties to a senior public office | A match against a national or international PEP database |
| Counterparty exposure | Whether the counterparty has a history or reputation of prior risk | A counterparty linked to prior risk reports or high risk jurisdictions |
| Structuring patterns | Whether an amount was split to avoid a reporting threshold | Several small payments to the same destination in a short window |
| Origin and destination country | Whether the payment route matches jurisdictions flagged by international bodies | A destination in a high risk country under FATF or another body |
| Consistency with account history | Whether amount, frequency, or destination departs from usual behavior | A volume spike or a new destination with no prior pattern |
The most cited screening list at an operational level is the Specially Designated Nationals (SDN) List maintained by the US Treasury's Office of Foreign Assets Control. It freezes the assets of listed individuals and entities and bars transacting with them, with extraterritorial effect on any operation that touches the dollar based financial system.
Which structuring and geography patterns trigger an alert
Structuring is splitting one payment into several smaller amounts to keep any single one below a reporting threshold, and it is one of the patterns transaction monitoring is built to catch. The stated intent does not matter: the pattern itself, several similar payments to the same destination in a short window, is the signal that triggers a review.
Payment geography carries as much weight as the amount. A payment to a country flagged by the Financial Action Task Force (FATF) as a high risk jurisdiction, or to a destination the company never operated with before, gets a higher level of scrutiny than one to a familiar destination. This connects directly to the logic behind the FATF Travel Rule for crypto payments: traceability of a transfer's origin and destination is the foundation the rest of the monitoring is built on.
A common example: a company that regularly invoices a client in one country and, with no advance notice, starts receiving payments from an unrelated country with no apparent tie to its declared business activity. That shift, even with a legitimate explanation such as a new client or a new subsidiary, is exactly the kind of pattern change monitoring flags for manual review.
What happens operationally when a payment gets flagged for review
When a payment gets flagged for review, it sits in pending status while a compliance analyst evaluates the alert against the account's existing information and, if needed, against additional documentation. The payment is not automatically rejected; it is paused until the alert resolves one way or another.
Does the company find out exactly why its payment was flagged?
Not always in detail. Anti money laundering rules, including those a US based company must respect when receiving funds from a Colombian counterparty, prohibit tipping off a client when a transaction gets reported as suspicious to a regulator, so as not to compromise the investigation. In practice, the usual outcome is that the company gets asked for additional documentation, such as an invoice, a contract, or a clarification of the payment's purpose, without that necessarily meaning a formal report was filed.
When an analyst confirms a transaction warrants a formal report, the underlying legal basis for that obligation sits in the recipient's jurisdiction, not the sender's. For a payment tied to Colombia, the relevant authority is the Unidad de Información y Análisis Financiero (UIAF). The company on either end of the payment, unless asked for specific documentation, does not take part in that process or learn its outcome.
How long a KYT and AML review takes
There is no fixed timeline for resolving a KYT alert, because the time depends on how complex the review is and how fast the company provides whatever it is asked for. An alert that resolves using data already on file moves in minutes or hours; one that requires requesting additional documentation from the company depends on when the company delivers it.
That has a direct practical implication for a treasury team operating across borders: the biggest factor within the company's control is not the system's speed, it is how quickly and completely it responds once asked for a document. Keeping invoices, contracts, and payment orders organized for every transaction, following the same discipline covered in counterparty risk in treasury, shortens that time directly.
What a finance team can do to keep its payments clean
A finance team can lower the odds a payment gets held by completing the beneficiary's data, writing a specific payment description, keeping documentary support for every transaction on file, and giving advance notice of predictable volume spikes such as the month end payroll run.
| Good practice | What it prevents | Example |
|---|---|---|
| Complete beneficiary data | The system failing to confirm the identity of the payment recipient | The recipient's full legal name, not a nickname or a shortened business name |
| Specific payment description | A payment reading as generic or with no identifiable business purpose | "Invoice 0452, October services" instead of "vendor payment" |
| Documentation on file | That an analyst has to request additional justification for the transaction | Invoice, contract, or purchase order available before it gets requested |
| Advance notice of predictable spikes | An unusual but legitimate volume being read as a risk deviation | Flagging a larger than usual payroll run the week before it runs |
| Consistency of destinations | A new payment country reading as an unexplained deviation | Explaining in advance a new vendor or client opening in another country |
The same discipline applies to the relationship with each counterparty, not just the individual payment. A company that already assessed the risk profile of its recurring vendors and clients, as covered in what Soulbit is and how it works for a company, reaches every payment with less uncertainty about who is on the other side of the transaction.
What Soulbit's V1 delivers on AML and KYT, and what it does not
Soulbit's V1 applies transaction monitoring (KYT) and anti money laundering (AML) controls to every payment it processes, with automatic screening against sanctions lists and evaluation of risk patterns, as a built in part of its operation. It is not an optional feature or an add on service; it runs on every transaction, without exception.
What Soulbit's V1 does not deliver is detailed visibility into the monitoring engine for the company itself. A company does not see a payment's internal risk score, or the technical detail of exactly which rule triggered a review, because that information is part of the compliance control and disclosing it fully would undermine its own effectiveness. There is also no self service dashboard today where a company can check the detailed status of an alert in real time; communication about a pending review comes through Soulbit's human support channels.
It is worth saying this as plainly as the rest of the product gets described: transaction monitoring is not an avoidable friction point or a system error when it shows up. It is the same control layer any regulated financial institution applies, running on stablecoin payments with the same logic it applies to a traditional wire transfer.
Does a held payment mean the company did something wrong?
Not necessarily. Most payments flagged for review clear after confirming information that was legitimate from the start. Monitoring is built to review risk patterns, not to presume bad faith, and an alert that clears without findings leaves no negative record on the account.
Frequently asked questions
What is KYT and how does it differ from KYC?
KYT, Know Your Transaction, is the ongoing monitoring of every payment moving in or out of an account. KYC verifies a person's identity once, when the account opens. KYT reviews transactional behavior every day, after identity has already been confirmed.
What signals does a KYT engine check on every payment?
It screens the sender and the recipient against sanctions lists from the UN, the EU, and the US Office of Foreign Assets Control, checks whether either party is a politically exposed person, evaluates the origin and destination country, and looks for structuring patterns, such as splitting one amount into several smaller payments.
How long does a payment held for review take to clear?
There is no fixed timeline. It depends on whether the alert resolves using information the company already has on file, or whether an analyst needs to request additional documentation, such as an invoice or a contract. A payment with complete beneficiary data and a clear description tends to clear faster than one without it.
Why does the month end payroll run get flagged so often?
Because an unusual volume spike relative to an account's history is exactly the kind of pattern monitoring is built to catch, even when it is entirely legitimate. Giving advance notice of a large payroll disbursement or an out of pattern payment lowers the odds it gets held.
What can a finance team do to keep its payments clean?
Always enter the beneficiary's full legal name and country, write a specific payment description instead of a generic one, keep the invoice or contract that backs each transaction on file, and give advance notice of predictable spikes such as the month end payroll run or an unusually large one off payment.
Want your company to add stablecoins to its operations?
Join the Soulbit waitlist and start paying payroll, collecting and managing treasury without SWIFT.
Join the waitlist