BINK

Compliance

The certifications, programmes and controls that govern how BINK operates as a regulated financial platform.

Version 2.0 · Effective 1 September 2026 · Approximately 7 minutes to read

Summary

Certified and audited

PCI DSS Level 1, ISO 27001 and SOC 2 Type II, renewed annually.

Every payment screened

Sanctions and transaction monitoring run before funds move.

Independent oversight

A compliance function reporting to the board, with external audit.

Framework#

A dedicated compliance function operates independently of commercial teams and reports to the board. Policies are reviewed annually, and each control has a named owner and a testing schedule.

Certifications#

StandardScopeCycle
PCI DSS Level 1Card data environmentAnnual
ISO 27001Information security managementAnnual surveillance
SOC 2 Type IISecurity and availabilityAnnual
Penetration testingPlatform and APIsTwice yearly

Attestation reports are available to business customers under NDA through your account contact.

AML and KYC#

We verify identity before an account is opened, understand the expected purpose and volume of activity, and refresh due diligence on a risk-based schedule. Enhanced diligence applies to higher-risk relationships.

We may request documents at any point in the relationship. Functionality can be limited until a request is satisfied.

Sanctions screening#

Customers, counterparties and payments are screened against applicable sanctions lists in real time. Matches are held for review, and confirmed matches are reported and blocked.

Transaction monitoring#

Automated rules and behavioural models review activity continuously. Alerts are investigated by trained analysts, and suspicious activity is reported to the relevant financial intelligence unit.

Third-party risk#

Every partner and processor is assessed before onboarding and reviewed annually, covering regulatory standing, security posture, resilience and data protection.

Training and culture#

All staff complete financial crime, security and data protection training at onboarding and annually. Escalation routes are confidential and protected.

Regulatory requests#

We respond to lawful requests from regulators and law enforcement, disclosing only what is required and notifying affected customers where legally permitted.

Need help understanding these terms?

Our legal and compliance teams answer questions about any clause on this page.