Menu+

Why prepaid vouchers attract anti-money-laundering rules

Nobody drafted a rulebook about Neosurf. The obligations that shape this service come from anti-money-laundering law written for cash, which turns out to apply to voucher codes rather neatly.

Published
2026-08-21
Reading
6 min

A prepaid voucher is a bearer instrument. Whoever holds the code holds the value, exactly as whoever holds a banknote holds the money. Value that belongs to the holder of a string of digits, rather than to a named account, is the property regulators treat as high risk — and it makes a business converting those codes into crypto or bank money more heavily regulated than its size would suggest.

What a voucher does that a bank transfer cannot

Set the two side by side.

A bank transfer carries a named sender, a named recipient, two supervised institutions, a record on both sides and, in some circumstances, a route to recall it. A voucher carries a number. It is bought over a counter, often with cash, in a shop whose staff have no obligation to know the customer and no means to check them. It travels to the other side of the world as a photograph, a line of text, or digits read aloud on the telephone. Once the value is redeemed it is gone, and nothing in the code records who redeemed it.

Add that a code bought in one country is frequently spendable on services in another, and you have an instrument that moves value across borders instantly, anonymously and irreversibly, in denominations small enough that nobody at the till looks up.

None of that makes vouchers illegitimate. They exist for sound reasons: paying online without a card, giving a gift, capping a teenager's spending, letting people without a bank account buy things on the internet. Most voucher use is ordinary and lawful. But the properties that make a voucher useful to somebody without a bank account are precisely the properties that make it useful to somebody laundering money, and rules follow properties rather than intentions.

Where vouchers fit into a laundering chain

The textbook divides laundering into three stages. Placement puts criminal cash into the financial system. Layering moves it through enough transactions to break the link with its origin. Integration brings it back as apparently clean wealth.

Prepaid instruments are useful in the first two stages. Cash buys a code without an account opening, a bank counter or a conversation with anyone required to record who was standing there. Codes then pass between people leaving no trace at all, because passing a code is a conversation rather than a transaction.

The conversion step is where control becomes possible. Turning a code into USDT, a bank transfer or a PayPal balance is the moment an anonymous bearer instrument becomes named, spendable value sitting in an identified account. Structurally that is the work of a bureau de change, and it is regulated for the same reason: it is the one point in the chain where a name can be attached to the money.

What the obligations actually are

There is no single law. The Financial Action Task Force publishes recommendations and countries write them into domestic legislation — in the European Union through a series of anti-money-laundering directives, and in the United Arab Emirates chiefly through Federal Decree-Law No. 20 of 2018 and the regulations made under it. The wording varies. The obligations are broadly the same everywhere.

  • Customer due diligence. Identify the customer and verify that identity against documents before providing the service. Here, no KYC documents are required — a full name and a country of residence, screened against sanctions lists, is all we ask for at any amount. The reasons are set out in why no KYC is required here.
  • Source of funds. Establish where the value came from and whether the explanation is consistent with everything else known about the customer.
  • Ongoing monitoring. Watch behaviour across transactions and over time, not one transaction at a time.
  • Record keeping. Retain identity and transaction records for a set period after the relationship ends. Five years is the common minimum.
  • Suspicious activity reporting. Where suspicion arises, report it to the national financial intelligence unit. Suspicion is deliberately a low bar: it requires neither proof nor a settled belief that a crime has occurred.
  • Tipping off. Having reported, the business must not tell the customer it has done so. In most regimes that is a criminal offence in itself, which is why a refusal sometimes comes with an unsatisfying explanation.
  • Sanctions screening. A separate obligation with a different logic, described in how sanctions and PEP screening work.

The question that matters most for vouchers

For most regulated businesses the central question is who the customer is. For a voucher exchange that is only half of it. The other half is where the code came from.

An honest, fully identified customer may be holding a voucher bought an hour earlier by someone who had been telephoned and told her computer was infected. Nothing in the customer's documents reveals that. Only the instrument's history does.

So the questions are about the voucher: which shop, which day, paid for how, and why it is being sold rather than spent. A receipt matters. An account that does not fit the receipt matters more. And the verification call to the issuer — a person reading the code back to the company that issued it — is where a code already spent, already blocked, or already reported stolen makes itself known.

Structuring, and why limits are not arbitrary

Wherever a rule bites at a threshold, somebody will arrange transactions to fall below it. Deliberately breaking a sum into smaller pieces to stay under a reporting or verification limit is called structuring, and in many jurisdictions the arrangement is an offence on its own, separate from whatever the money was. Vouchers suit it unusually well: fixed small denominations, sold at unconnected retailers on almost any high street, buyable across a single afternoon.

Monitoring therefore looks across transactions rather than at each one alone. The same seller returning every week. Different sellers paying into one wallet. Codes bought minutes apart in different towns. Amounts that sit consistently a little below a published ceiling. It is also why limits are published in the terms and applied uniformly rather than negotiated privately: a limit that bends for a persuasive customer is not a control.

What a monitoring rule set looks for

None of the following proves anything by itself. Each is a reason to slow down and ask.

  • Several codes bought at different retailers within a short window, particularly in different towns.
  • A seller who cannot say where a voucher was bought, or whose account of it changes between tellings.
  • Signs of coaching: long pauses before answers, another voice in the room, replies arriving in fully formed paragraphs.
  • Urgency out of all proportion to a routine sale, or plain distress.
  • A payout destination in somebody else's name.
  • A stated reason with the shape of a script — a fine to be paid today, a technician waiting on the line, a deposit before a job starts, a partner stranded abroad. Those patterns are catalogued in how prepaid voucher scams work.

The rules and the victims overlap

Vouchers offered to an exchange are commonly not the proceeds of organised crime at all. They are the proceeds of a scam, offered by the person the scammer sent to the shop. From the outside the two look identical: an unexplained code, a nervous seller, a hurry.

Anti-money-laundering procedure catches both, which is a happier accident than it sounds. A refusal is often the first outside opinion a person in the middle of a scam has heard, and the questions asked during due diligence — who told you to buy this, what were you told would happen — are the questions nobody else has thought to ask them.

Where this operator stands

The virtual asset licence application is in progress and has not been granted. Trading is not enabled, and the operator has not begun buying or selling vouchers. Nothing here describes a track record, because there is none.

What is settled is the design. A person verifies every voucher with its issuer before any payment is released. Identity precedes any payout at every amount, declared and verified against a document at or above it. Screening runs on every counterparty, whatever the size of the order. Records are kept. Where the picture does not hold together, the transaction does not proceed, and that decision is not for sale at a higher commission.

If a voucher of yours is involved in something that is happening right now, tell us before you do anything else. Speed is what decides whether funds can still be held.

Contact support