Reference / Sources

Sources & editorial notes

Edition 01 · September 17, 2026. Primary sources, original explanations, and a clear boundary between rules and examples.

Scope and audience

This book covers payments and fintech risk engineering with a U.S. focus and global context. It connects payment mechanics, fraud, underwriting, credit, AML, sanctions, compliance, data, models, and operations. Read it in order for the full system, or use the chapter list and search for a specific subject.

The examples explain engineering choices. They are not production policies, legal advice, or an institution-specific compliance program. Legal duties depend on the entity, product, activity, jurisdiction, and facts. Network rules and provider behavior can also differ. Chapters identify those boundaries where they affect the design.

How sources are used

Chapter sources link to regulators, standards bodies, official technical documentation, and provider documentation. Provider examples explain a particular implementation; they are not universal rail rules. Older examination material is read with current rules and agency updates. Source links were checked for this edition on September 17, 2026.

The edition includes FinCEN’s 2026 beneficial-owner relief, the September 2, 2026 statement on SAR confidentiality and customer communication, Nacha’s 2026 Phase 2 monitoring changes, and the revised federal model-risk guidance in SR 26-2. These dates describe the source edition, not a guarantee that future requirements will remain unchanged.

Original cases and illustrations

Lantern, its customers, and all case records are fictional. Amounts, rates, thresholds, service targets, and stress assumptions are teaching examples unless a passage explicitly identifies an authoritative rule. The 800 illustrations show flows, distinctions, annotated records, and control failure modes. They are original vector images, with readable text versions on small screens.

Explanations and diagrams were authored with AI assistance. Automated checks verify structure, links within the book, image coverage, and selected calculations. They do not establish legal accuracy or constitute independent human subject-matter review. No independent human review is claimed.

Corrections and maintenance

Review a correction together with its chapter text, diagrams, glossary terms, source references, and relevant calculations. Record the changed source and effective date. A rule update can affect customer messages, data requirements, and operations as well as the rule itself.

Privacy

The textbook has no accounts, assessments, tracking profile, or analytics integration. Search runs in your browser. The color preference is stored locally. A hosting provider may process ordinary request data when the site is hosted.

Design attribution

The reading interface follows the existing ca-re book and its adaptation of Rubix Documents. The original MIT license is preserved. The interface uses Next.js, shadcn/ui, and Radix. No affiliation with a regulator, payment network, or source publisher is implied.

Book coverage

UnitChaptersIllustrations
Payments & money movement5100
Fraud & transaction risk5100
Underwriting & credit risk5100
AML & financial crime5100
Sanctions & global risk5100
Compliance by design5100
Risk systems & models5100
Risk operations & resilience5100

Topic map

Payments & money movement5 topics
Textbook topicChapters
Money movement and the risk mapMoney movement and the risk map
Cards, authorization, and disputesCards, authorization, and disputes
ACH, bank debits, and returnsACH, bank debits, and returns
Instant payments and cross-border transfersInstant payments and cross-border transfers
Ledgers, reconciliation, and settlement riskLedgers, reconciliation, and settlement risk
Fraud & transaction risk5 topics
Textbook topicChapters
Identity, credentials, and synthetic profilesIdentity, credentials, and synthetic profiles
Account takeover and account recoveryAccount takeover and account recovery
Transaction risk and decision economicsTransaction risk and decision economics
Scams, money mules, and social engineeringScams, money mules, and social engineering
First-party misuse, merchant abuse, and feedbackFirst-party misuse, merchant abuse, and feedback
Underwriting & credit risk5 topics
Textbook topicChapters
Underwrite the merchant businessUnderwrite the merchant business
Credit risk and repayment capacityCredit risk and repayment capacity
Cash-flow analysis and financial evidenceCash-flow analysis and financial evidence
Reserves, limits, and payout policyReserves, limits, and payout policy
Portfolio monitoring and credit deteriorationPortfolio monitoring and credit deterioration
AML & financial crime5 topics
Textbook topicChapters
AML programs and the risk-based approachAML programs and the risk-based approach
Customer due diligence and beneficial ownershipCustomer due diligence and beneficial ownership
Entity resolution and financial networksEntity resolution and financial networks
Transaction monitoring and alert qualityTransaction monitoring and alert quality
Investigations, reporting, and confidentialityInvestigations, reporting, and confidentiality
Sanctions & global risk5 topics
Textbook topicChapters
Sanctions scope, prohibitions, and licensesSanctions scope, prohibitions, and licenses
Screening engines and match resolutionScreening engines and match resolution
Ownership graphs and the 50 Percent RuleOwnership graphs and the 50 Percent Rule
Trade, corridors, and restricted activityTrade, corridors, and restricted activity
Digital assets, stablecoins, and wallet riskDigital assets, stablecoins, and wallet risk
Compliance by design5 topics
Textbook topicChapters
Compliance architecture and policy as codeCompliance architecture and policy as code
Consumer protection, errors, and complaintsConsumer protection, errors, and complaints
Fair lending, explainability, and adverse actionFair lending, explainability, and adverse action
Privacy, payment data, and secure evidencePrivacy, payment data, and secure evidence
Sponsor banks, vendors, and third-party riskSponsor banks, vendors, and third-party risk
Risk systems & models5 topics
Textbook topicChapters
Risk data contracts and event timeRisk data contracts and event time
Decision engines, rules, and reliable executionDecision engines, rules, and reliable execution
Risk models, calibration, and delayed outcomesRisk models, calibration, and delayed outcomes
Experiments, causal effects, and risk tradeoffsExperiments, causal effects, and risk tradeoffs
Model governance and AI-assisted risk workModel governance and AI-assisted risk work
Risk operations & resilience5 topics
Textbook topicChapters
Case operations and human decisionsCase operations and human decisions
Treasury, liquidity, and settlement operationsTreasury, liquidity, and settlement operations
Operational resilience and failure designOperational resilience and failure design
Risk incidents, containment, and learningRisk incidents, containment, and learning
A complete risk system: the Lantern caseA complete risk system: the Lantern case

Primary-source library

Federal Reserve: payment systemswww.federalreserve.govStripe: PaymentIntent lifecycle (provider example)docs.stripe.comStripe: how disputes work (provider example)docs.stripe.comPCI Security Standards Council: PCI DSSwww.pcisecuritystandards.orgNacha: 2026 fraud monitoring, Phase 2www.nacha.orgNacha: ACH network risk and enforcement topicswww.nacha.orgFederal Reserve: Fedwire finality and settlementwww.federalreserve.govOFAC: A Framework for Compliance Commitmentsofac.treasury.govStripe: idempotent requests (provider example)docs.stripe.comNIST SP 800-63A-4: identity proofingpages.nist.govNIST SP 800-63B-4: authenticationpages.nist.govNIST: AI Risk Management Frameworkwww.nist.govFinCEN: deepfake fraud alertwww.fincen.govOCC Comptroller’s Handbook: merchant processingwww.occ.treas.govOCC Comptroller’s Handbook: rating credit riskwww.occ.treas.govRegulation B, 12 CFR 1002.6: evaluation of applicationswww.consumerfinance.govRegulation B, 12 CFR 1002.9: notificationswww.consumerfinance.govFinCEN: Customer Due Diligence Rule and current resourceswww.fincen.govFATF Recommendations: international standardswww.fatf-gafi.orgFFIEC: BSA/AML Examination Manualbsaaml.ffiec.govFinCEN: FIN-2026-R001 beneficial-owner exceptive reliefwww.fincen.govFFIEC: Customer Due Diligence (historical examination material; read with current FinCEN rules)bsaaml.ffiec.govFFIEC: suspicious activity reportingbsaaml.ffiec.govFinCEN: SAR confidentiality advisory FIN-2010-A014www.fincen.govFinCEN and banking agencies: September 2, 2026 statement on SAR confidentiality and customer communicationswww.fincen.govOFAC: sanctions programs and country informationofac.treasury.govOFAC FAQ 11: general and specific licensesofac.treasury.govOFAC FAQ 9: blocked propertyofac.treasury.govOFAC FAQ 5: resolving matches and choosing a dispositionofac.treasury.govOFAC: Sanctions List Serviceofac.treasury.govOFAC FAQ 401: indirect ownership and the 50 Percent Ruleofac.treasury.govOFAC FAQ 398: ownership and controlofac.treasury.govBIS: Export Administration Regulationswww.bis.govFATF: trade-based money launderingwww.fatf-gafi.orgOFAC: sanctions compliance guidance for virtual currencyofac.treasury.govFATF: virtual assetswww.fatf-gafi.orgRegulation E, 12 CFR 1005.11: error resolutionwww.consumerfinance.govFederal Reserve SR 23-4: third-party relationshipswww.federalreserve.govRegulation E, 12 CFR 1005.6: unauthorized-transfer liabilitywww.consumerfinance.govFTC: Safeguards Rule business guidancewww.ftc.govNIST: Cybersecurity Frameworkwww.nist.govPostgreSQL: transaction isolationwww.postgresql.orgscikit-learn: model evaluation metricsscikit-learn.orgGoogle SRE: handling overloadsre.googlescikit-learn: probability calibrationscikit-learn.orgFederal Reserve SR 26-2: revised model-risk guidance (2026)www.federalreserve.govNIST: Generative AI Profile, AI 600-1nvlpubs.nist.govMIT: queueing models and Little’s Lawweb.mit.edu