Modulr’s €722,160 DNB Fine Exposes AML Risks in Partner-Led Crypto Payments
A €722,160 Dutch fine against Modulr exposes a costly weakness in partner-led payments: the regulated firm may lack the customer information it needs. Explore what DNB’s findings mean for crypto partnerships, transaction monitoring and unusual transaction reporting—and why contractual access to data is no substitute for controls that actually work.

Paris, France
Oct 6, 2026
De Nederlandsche Bank has fined Modulr Finance B.V. €722,160 for deficiencies in customer due diligence and anti-money-laundering controls, finding that its reliance on intermediary partners—including crypto-asset service providers—left the electronic money institution without adequate visibility over its customer base.
The Dutch central bank imposed the administrative penalty on 30 September 2026 and published details on 5 October. According to its enforcement notice, Modulr acknowledged the non-compliance and waived its right to object under a simplified settlement procedure. The procedure reduced the fine by 15%, from €849,600.
The case concerns obligations under the Dutch Anti-Money Laundering and Anti-Terrorist Financing Act, known as the Wwft. Its significance extends beyond one payment provider: it exposes the gap that can emerge when the firm responsible for financial-crime controls does not hold enough information about the customers and activity passing through its services.
Where DNB found the controls fell short
DNB said Modulr insufficiently monitored high-risk customers and transactions involving high-risk jurisdictions. In some cases, it did not investigate the lawful origin of funds. The regulator also identified late or missing reports to the Financial Intelligence Unit Netherlands, or FIU-NL.
These are supervisory findings concerning failures in controls and reporting. They are not, by themselves, findings that the underlying customers committed money laundering or that every transaction identified was illicit. Nor does the notice establish a general prohibition on payment firms working with crypto businesses or other intermediaries.
The narrower—and commercially important—point is that a partner-led distribution model must leave the regulated firm able to discharge its own obligations. Bringing customers into a service through another business does not remove the need to understand the relevant relationships, assess their risks and investigate activity that warrants scrutiny.
That distinction matters in embedded payments. A platform may manage onboarding and maintain the closest relationship with users, while an electronic money institution supplies payment infrastructure. In a crypto-related arrangement, information explaining a transfer may sit with the trading platform rather than the payment provider. Each business can see a different part of the same financial activity.
The difficulty is not simply collecting more data. It is ensuring that the information available to the responsible institution is sufficient, timely and usable.
Partner checks do not settle the legal question
The Wwft requires obliged institutions to conduct customer due diligence, understand the purpose and intended nature of business relationships, and monitor those relationships on an ongoing basis. That includes scrutinising transactions against the institution’s knowledge of the customer and risk profile, and investigating the source of funds where necessary.
The precise obligations depend on the relationship and applicable legal provisions. A platform’s end user does not automatically become the payment firm’s direct customer in every arrangement. Institutions nevertheless need a defensible understanding of who their customers are, how their services are being used and which information is necessary to assess the resulting risks.
A partner’s assurance that it has completed onboarding is therefore not a substitute for determining whether the payment firm can satisfy its own duties. Licensing status is relevant, but it cannot answer every question about a partner’s customer base, geographic exposure, products or effectiveness of controls.
Reporting also requires care in terminology. The Dutch framework requires reports of unusual transactions, using the applicable reporting indicators; it is not limited to transactions that a firm has already concluded are criminal. An unresolved information gap may require further investigation, but firms cannot allow partner escalation processes to delay a report that is legally required.
The practical test: information that arrives in time
For payment firms, the implications begin before a partnership launches. They need to establish what information they will receive, what they can request, how quickly it will arrive and how they will check its reliability. Depending on the arrangement and risk, that may include customer identification records, beneficial ownership information, transaction context and evidence relevant to the origin of funds.
Contractual access alone offers limited protection. A right to request records is of little operational value if the partner cannot retrieve them promptly, supplies incomplete information or uses systems that cannot connect a payment to the underlying customer activity.
Monitoring arrangements must also address the boundary between the two businesses. A payment provider may identify an unexpected transfer pattern without knowing whether it reflects trading, withdrawals or another activity on the platform. The partner may understand that activity but lack the broader payment history. Clear investigative responsibilities and workable information-sharing processes are needed to connect those views.
The same arrangements should specify what happens when information remains unavailable: who escalates the issue, when additional checks are required and whether activity must be restricted. Decisions need an evidential trail showing what the institution knew, how it assessed the risk and why it reported—or did not report—a transaction.
For crypto businesses, the case also illustrates the limits of treating authorisation as a complete compliance credential. The EU’s Markets in Crypto-Assets Regulation establishes a framework for crypto-asset service providers, but it does not replace the separate AML obligations applicable to a payment institution supporting them.
Credible supervision should make those boundaries clearer, not turn every partnership into a presumption of wrongdoing. The lesson from DNB’s findings is more specific: partner-led services remain viable only if the responsible institution can obtain enough information to make its controls effective. In Modulr’s case, DNB concluded that it could not.