Compliance and governance
A white-label programme only works if the division of regulatory responsibility is unambiguous. This page states it plainly.
Who is responsible for what
| Obligation | Issuing institution | Zen Card |
|---|---|---|
| Holding the licence and permissions | Accountable | None |
| Customer due diligence and KYC | Accountable, performs | Technical integration |
| AML programme and policy | Accountable, owns | Tooling and monitoring surfaces |
| Sanctions screening policy | Accountable, sets | Applies exclusion list at programme level |
| Suspicious activity reporting | Accountable, files | Supplies evidence and data |
| Transaction monitoring thresholds | Sets | Operates the engine |
| Dispute and chargeback handling | Customer decision | Scheme process and evidence |
| Data protection as controller | Accountable | Acts as processor |
| Regulatory reporting | Accountable, files | Provides programme data |
| Scheme rule adherence | Oversees | Operates to Visa requirements |
What the platform provides
Transaction monitoring
Rule-based screening at authorisation with configurable thresholds, so patterns that breach your policy are surfaced rather than discovered later.
Alerting and anomalies
Automated alerts on anomalous spending behaviour, with severity so your team triages rather than reads everything.
Case management
A case surface for investigation, with the transaction evidence, device and session context attached.
Jurisdiction controls
Country exclusion list applied at programme level for scheme, sanctions and regulatory compliance, reviewed on an ongoing basis.
Merchant risk
Merchant risk assessment and fraud rate visibility for programmes with an acquiring or gateway component.
Audit trail
Programme actions are logged and exportable for internal audit and regulatory submissions.
Frequently asked questions
Is Zen Card a regulated financial institution?+
No. Zen Card is a technology and programme-management provider. It does not hold a banking or e-money licence, does not take deposits, and does not issue cards in its own right. Cards are issued by licensed institutions that hold the relevant permissions in their jurisdictions.
Who performs KYC and AML on cardholders?+
The issuing institution, under its own regulated process and its own risk appetite. Zen Card provides technical hooks so the outcome of your process gates issuance and funding, but the decision and the regulatory responsibility remain yours.
How are sanctions and prohibited jurisdictions handled?+
A country exclusion list is maintained for scheme, sanctions and regulatory compliance, and is applied at the programme level. The list is reviewed on an ongoing basis and any material change is communicated with prior notice.
What transaction monitoring is available?+
The platform provides transaction monitoring, rule-based alerting, anomaly detection and case management surfaces. These support your compliance function; they do not replace it, and monitoring thresholds are configured to your policy.
Request the compliance pack
Institutions evaluating a programme can request the detailed responsibility matrix, data-processing terms and control documentation.
